
Security News
Ruby's Bundler 4.0.18 Extends Cooldown to bundle lock and bundle cache
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.
@attrove/mcp
Advanced tools
MCP server for Attrove — AI-powered context retrieval from Gmail, Slack, Calendar for Claude, Cursor, and ChatGPT
MCP (Model Context Protocol) server for Attrove. Enables AI assistants like Claude and Cursor to access your users' unified context from Gmail, Slack, Google Calendar, and more.
npm install @attrove/mcp
# or
yarn add @attrove/mcp
# or
pnpm add @attrove/mcp
Use the CLI as the install layer for hosted OAuth MCP:
npx @attrove/cli install claude-code
That writes a remote MCP config pointed at https://api.attrove.com/mcp, lets Claude Code, Cursor, and Claude Desktop discover OAuth automatically, and avoids embedding sk_ secrets directly into client JSON.
Other hosted install commands:
npx @attrove/cli install cursor
npx @attrove/cli install claude-desktop
Claude Code defaults to project scope (.mcp.json). Cursor and Claude Desktop default to user scope.
Use the local stdio server only if you explicitly want local credential-backed MCP:
npx @attrove/cli login
npx @attrove/cli local install claude-code
Claude Desktop supports two transport options:
HTTP transport (recommended) — uses OAuth discovery, no API key copy/paste needed:
{
"mcpServers": {
"attrove": {
"type": "streamable-http",
"url": "https://api.attrove.com/mcp"
}
}
}
Prefer npx @attrove/cli install claude-desktop to write this for you.
Legacy stdio transport — use only if you explicitly want local env-based auth:
{
"mcpServers": {
"attrove": {
"command": "npx",
"args": ["-y", "@attrove/mcp@latest"],
"env": {
"ATTROVE_SECRET_KEY": "sk_...",
"ATTROVE_USER_ID": "user-uuid"
}
}
}
}
Preferred hosted install:
npx @attrove/cli install cursor
Or use Cursor's install URL from a partner-issued connect session. Manual remote config also works:
{
"mcpServers": {
"attrove": {
"type": "http",
"url": "https://api.attrove.com/mcp"
}
}
}
On first use, Cursor discovers OAuth via .well-known/oauth-protected-resource and sends the user through the Attrove connect flow automatically.
Preferred hosted install:
npx @attrove/cli install claude-code
If you are onboarding a provisioned end user from a terminal or agent, use the durable connect-session handoff:
npx @attrove/cli connect --session <session-id>
Advanced local fallback is still supported:
npx @attrove/cli login
npx @attrove/cli local install claude-code
ChatGPT and other AI assistants that support MCP connectors can connect via the hosted HTTP endpoint.
ChatGPT's MCP install UX is still evolving. Treat it as a fallback path behind Claude Code, Cursor, and Claude Desktop.
Basic requirement: add https://api.attrove.com/mcp as a remote MCP server. OAuth-capable clients should discover the authorization flow automatically.
Example setup steps (may vary):
Attrovehttps://api.attrove.com/mcpOnce connected, you can ask ChatGPT questions like:
npx @attrove/cli install claude-code
# advanced local fallback:
npx @attrove/cli login
npx @attrove/cli local install claude-code
# or manual env injection:
ATTROVE_SECRET_KEY=sk_... ATTROVE_USER_ID=user-uuid npx @attrove/mcp
Once connected, you can ask your AI assistant natural language questions. Here are some examples:
Meeting prep:
"What context do I need for my 2pm meeting with the marketing team?"
Email follow-ups:
"Are there any emails from last week that I haven't responded to?"
Project status:
"What's the latest on the Q4 roadmap discussions?"
People search:
"What has John from Acme Corp been asking about recently?"
Historical context:
"Find the thread where we discussed the pricing changes last month"
attrove_queryAsk questions about the user's communications and get AI-generated answers.
Parameters:
query (required): The question to askintegration_ids (optional): Filter to specific integration IDs (array of UUID strings)include_sources (optional): Include source snippets in the responseinstructions (optional): Custom instructions for the AI — controls output format, filtering, and behavior. Takes priority over default style. Max 20,000 charscontext (optional): Authoritative reference data for answer generation. Treated as ground truth by the AI. Influences query rewriting but not used for vector search. Max 20,000 charsExample prompts:
attrove_searchSearch for specific messages or conversations.
Parameters:
query (required): The search queryafter_date (optional): Only messages after this date (YYYY-MM-DD)before_date (optional): Only messages before this date (YYYY-MM-DD)sender_domains (optional): Filter by sender domainsinclude_body_text (optional): Include message content in results (default: true, bodies truncated to 1000 characters)Example prompts:
attrove_integrationsList the user's connected integrations.
Parameters: None
Example prompts:
attrove_eventsList calendar events from the user's connected calendar accounts.
Parameters:
start_date (optional): Start of date range (YYYY-MM-DD)end_date (optional): End of date range (YYYY-MM-DD)limit (optional): Max events to return (default 25, max 100)Example prompts:
attrove_meetingsList meetings with AI-generated summaries and action items.
Parameters:
start_date (optional): Start of date range (YYYY-MM-DD)end_date (optional): End of date range (YYYY-MM-DD)provider (optional): Filter by meeting provider (google_meet, zoom, teams)limit (optional): Max meetings to return (default 10, max 50)Example prompts:
attrove_notesList notes — analyst observations, partner-pushed context, and session summaries that have been RAG-indexed into the user's context.
Parameters:
ref_type (optional): Filter by reference type (message, meeting, event, entity)ref_id (optional): Filter by referenced item ID (e.g. msg_xxx, mtg_xxx). Must be provided together with ref_type.limit (optional): Max notes to return (default 20, max 100)Example prompts:
attrove_push_noteSave a note to the user's Attrove context. Notes are RAG-indexed and become queryable via attrove_query and attrove_search, enabling AI assistants to capture decisions and session context that persists across conversations.
Parameters:
body (required): Note content (server-enforced max 10,000 characters)title (optional): Short title for the noteref_type (optional): Link to an existing item type. Must be provided together with ref_id.ref_id (optional): ID of the item to link (e.g. msg_xxx, mtg_xxx, evt_xxx, ent_xxx)external_id (optional): Dedup key. Re-pushing with the same external_id updates the existing note instead of creating a new one.Example prompts:
These are only required for stdio / manual installs. Remote HTTP MCP installs do not need them.
| Variable | Required | Description |
|---|---|---|
ATTROVE_SECRET_KEY | Yes | Your Attrove secret key (sk_...) |
ATTROVE_USER_ID | Yes | User ID to scope API calls |
ATTROVE_BASE_URL | No | Custom API base URL |
ATTROVE_DEBUG | No | Set to true for verbose error logging |
You can also use the server programmatically:
import { createServer, startServer } from '@attrove/mcp';
// Create a server instance
const server = createServer({
apiKey: 'sk_...',
userId: 'user-uuid'
});
// Or start directly with stdio transport
await startServer({
apiKey: 'sk_...',
userId: 'user-uuid'
});
For AI assistants that connect via HTTP, prefer adding the hosted endpoint directly and letting the client discover OAuth:
https://api.attrove.com/mcphttps://api.attrove.com/.well-known/oauth-protected-resourceManual curl testing can still use bearer auth:
# Test the endpoint
curl -X POST https://api.attrove.com/mcp \
-H "Authorization: Bearer sk_..." \
-H "X-Attrove-User-Id: user-uuid" \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","method":"tools/list","id":1}'
Or integrate in your own server using the HTTP handler:
import { createHttpHandler } from '@attrove/mcp';
const handler = createHttpHandler(
{
apiKey: 'sk_...',
userId: 'user-uuid',
baseUrl: 'https://api.attrove.com', // optional: custom API endpoint
},
{
enableJsonResponse: true, // optional: use JSON instead of SSE (default: true)
timeoutMs: 30000, // optional: request timeout in ms (default: 30000)
}
);
// With Fastify (recommended)
fastify.post('/mcp', async (request, reply) => {
const result = await handler.handleRequest(request.raw, reply.raw, request.body);
if (!result.handled) {
// Handle timeout with 504, other errors with 500
const statusCode = result.isTimeout ? 504 : 500;
const userMessage = result.isTimeout
? 'Request timed out. Try a simpler query or reduce the scope.'
: 'An unexpected error occurred. Please try again.';
// Only send response if headers haven't been sent (e.g., during streaming)
if (!reply.raw.headersSent) {
reply.code(statusCode).send({
success: false,
error: { code: result.isTimeout ? 'REQUEST_TIMEOUT' : 'INTERNAL_ERROR', message: userMessage }
});
} else if (!reply.raw.writableEnded) {
reply.raw.end(); // Ensure stream is closed
}
return;
}
// Optional: monitor cleanup failures for resource leak detection
if (result.cleanupFailed) {
console.warn('MCP cleanup failed - potential resource leak');
}
});
// With raw Node.js HTTP server
import { createServer } from 'node:http';
const server = createServer(async (req, res) => {
// Note: You'll need to parse the body yourself for raw HTTP
const result = await handler.handleRequest(req, res);
if (!result.handled) {
res.writeHead(500, { 'Content-Type': 'application/json' });
res.end(JSON.stringify({ error: result.error }));
}
});
sk_...)import { Attrove } from '@attrove/sdk';
const admin = Attrove.admin({
clientId: 'your-client-id',
clientSecret: 'your-client-secret'
});
// Create a user
const { id, apiKey } = await admin.users.create({
email: 'user@example.com'
});
// Use `apiKey` as ATTROVE_SECRET_KEY and `id` as ATTROVE_USER_ID
Make sure you've set the environment variables correctly in your MCP configuration.
Set ATTROVE_DEBUG=true to enable verbose error logging with stack traces:
{
"mcpServers": {
"attrove": {
"command": "npx",
"args": ["-y", "@attrove/mcp@latest"],
"env": {
"ATTROVE_SECRET_KEY": "sk_...",
"ATTROVE_USER_ID": "user-uuid",
"ATTROVE_DEBUG": "true"
}
}
}
}
The Attrove API has rate limits. If you're making many requests, you may need to wait before trying again.
For AI assistants and code generation tools, Attrove provides machine-readable documentation:
https://attrove.com/llms.txt - Condensed API reference for LLMshttps://github.com/attrove/examples - Example code with CLAUDE.md contextMIT
FAQs
Catch conversations going quiet — watch outcomes and search Gmail, Slack, and meetings. One MCP.
The npm package @attrove/mcp receives a total of 86 weekly downloads. As such, @attrove/mcp popularity was classified as not popular.
We found that @attrove/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.