
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
@audivo/mcp
Advanced tools
Official Audivo MCP server: podcast search, episode discovery, quotes, and transcripts for Claude, Codex, Cursor, and any other MCP client.
Podcast search, episode discovery, pricing, and transcripts for Claude, Codex, Cursor, and any other MCP client, backed by the Audivo API.
Two ways to connect, same nine tools:
| Hosted | Local | |
|---|---|---|
| Where it runs | Audivo's servers | Your machine, spawned by the client |
| Transport | Streamable HTTP at https://api.audivo.dev/mcp | stdio via npx -y @audivo/mcp |
| Credential | Authorization: Bearer hk_live_… header | AUDIVO_API_KEY environment variable |
| Good for | Claude on the web, ChatGPT, Claude Desktop connectors, anything that takes a URL | Claude Code, Codex, Cursor, VS Code, and every client that spawns a process |
You need an API key from the Audivo dashboard. Keys are shown once.
| Tool | What it does | Spends credits |
|---|---|---|
search_shows | Find shows by name, host, or topic | No |
chart_shows | The current chart for a category | No |
list_episodes | A show's episodes, newest first | No |
quote | Price a selection of episodes before anything runs | No |
confirm | Turn a quote into a job group | Yes, up to the quote's ceiling |
group_status | Where a group's jobs are, and which transcripts are ready | No |
list_groups | Your recent groups | No |
cancel_group | Stop what has not started and release its credits | No |
read_transcript | A finished transcript, fenced for the model | Only a cached read you have not paid for |
confirm is the one tool that spends. It refuses unless the model restates the quote's total, and it
takes an idempotency key so a retry cannot spend twice. Ask the user before calling it.
npxSet the key in the environment the client starts the server with, then add the server.
Claude Code
claude mcp add --scope user audivo -e AUDIVO_API_KEY=hk_live_... -- npx -y @audivo/mcp
Codex
codex mcp add audivo --env AUDIVO_API_KEY=hk_live_... -- npx -y @audivo/mcp
Cursor, Claude Desktop, Windsurf, and other JSON-configured clients
{
"mcpServers": {
"audivo": {
"command": "npx",
"args": ["-y", "@audivo/mcp"],
"env": { "AUDIVO_API_KEY": "hk_live_..." }
}
}
}
VS Code (.vscode/mcp.json)
{
"servers": {
"audivo": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@audivo/mcp"],
"env": { "AUDIVO_API_KEY": "hk_live_..." }
}
}
}
Keep files that contain a real key out of Git and shared chats.
| Variable | Required | Meaning |
|---|---|---|
AUDIVO_API_KEY | Yes | Your API key. Bearer in front of it is accepted and normalised. |
AUDIVO_API_BASE_URL | No | The API origin. Defaults to https://api.audivo.dev. Must be a public https origin: no userinfo, no loopback or private address. |
The server writes nothing to stdout except protocol messages. Log lines go to stderr as JSON, and the key never appears in them.
| Setting | Value |
|---|---|
| MCP URL | https://api.audivo.dev/mcp |
| Transport | Streamable HTTP |
| Authentication | Authorization: Bearer hk_live_... |
For example, in Claude Code:
claude mcp add --transport http --scope user audivo https://api.audivo.dev/mcp \
--header "Authorization: Bearer hk_live_..."
Per-client instructions for the hosted server, including ChatGPT and Claude on the web, are in the
connection guide. The hosted server is this package's lambda export,
deployed by Audivo.
confirm compares the total the model states with the total the quote carried and
refuses on a mismatch without sending anything. The API applies the same check on its side.src/contract/types.ts is generated from the published OpenAPI spec in
contract/openapi.yaml; a test fails the build when the two drift.npm ci
npm test # vitest
npm run typecheck
npm run lint
npm run build # dist/
To pick up a spec change: npm run contract:sync fetches the published spec and regenerates the
types. Run it locally against a key with:
AUDIVO_API_KEY=hk_live_... node dist/bin.js
Bump version in package.json, add a CHANGELOG.md entry, commit, then tag v<version> and push
the tag. The release workflow publishes to npm with provenance.
FAQs
Official Audivo MCP server: one call from an episode link to its transcript. Podcast search, episode discovery, transcripts, and on the local server YouTube audio, for Claude, ChatGPT, Codex, Cursor, and any other MCP client.
The npm package @audivo/mcp receives a total of 767 weekly downloads. As such, @audivo/mcp popularity was classified as not popular.
We found that @audivo/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.