
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@chrischall/eventbrite-mcp
Advanced tools
Eventbrite MCP server for Claude — developed and maintained by AI (Claude Code)
This project was developed and is maintained by AI (Claude Code). Use at your own discretion.
MCP server for Eventbrite: your tickets and orders, organizer data (events, attendees, orders), any public event by id, and public event search — which Eventbrite removed from its documented API in 2019 and now only exists on the consumer site.
Two data paths, matched to how Eventbrite is reachable:
eventbriteapi.com/v3) — plain server-side HTTPS with a
personal OAuth token (EVENTBRITE_TOKEN, free: create one).
Powers the account, organizer, event-by-id, and reference tools.www.eventbrite.com/api/v3/destination/…) — the
site WAF-blocks server-side clients, so search routes through your own
signed-in eventbrite.com browser tab via the
fetchproxy bridge (Transporter
extension), reusing your authenticated session. Powers eb_search_events,
eb_resolve_place, eb_event_details, eb_healthcheck.All tools are read-only.
npm install -g @chrischall/eventbrite-mcp
Claude Code (.mcp.json):
{
"mcpServers": {
"eventbrite": {
"command": "eventbrite-mcp",
"env": { "EVENTBRITE_TOKEN": "your-private-token" }
}
}
}
EVENTBRITE_TOKEN the server still boots; account tools error
helpfully on first use, and discovery tools work regardless.csrftoken cookie read the search POST needs). Run
eb_healthcheck to verify the hop.| Tool | Path | Notes |
|---|---|---|
eb_me | token | your profile |
eb_my_orders | token | your tickets, event expanded |
eb_my_organizations | token | organizer orgs |
eb_org_events / eb_org_attendees / eb_org_orders | token | organizer data |
eb_org_venues / eb_org_discounts / eb_org_ticket_groups / eb_org_webhooks | token | org-scoped collections |
eb_org_report | token | sales / attendees analytics, date-windowed |
eb_event / eb_event_description | token | any public event by id |
eb_ticket_classes / eb_ticket_class | token | an event's ticket types |
eb_event_attendees / eb_event_attendee | token | per-event attendees (changed_since polls incrementally) |
eb_event_orders | token | per-event orders |
eb_event_questions | token | registration questions (canned: true for the standard bank) |
eb_order | token | a single order by id |
eb_venue / eb_venue_events | token | venue detail and its events |
eb_organizer / eb_organizer_events | token | organizer profile and everything they run |
eb_series_events | token | occurrences of a recurring series |
eb_user | token | a public user profile |
eb_reference | token | categories / subcategories / formats / timezones / countries / regions |
eb_resolve_place | token | location → place id (Charlotte, NC → 85981333), plus browse shelves |
eb_search_events | token | the consumer search; compact: true for slim results, aggs for facets |
eb_event_details | token | batch event detail |
eb_healthcheck | bridge | bridge diagnostics (stdio only; the bridge is a fallback route) |
Search flow: eb_resolve_place {location: "Charlotte, NC"} →
eb_search_events {q: "blues", place_id: "85981333", compact: true}.
eb_resolve_place also accepts a raw slug (nc--charlotte). A bare city with
no state or country is rejected rather than guessed.
npm install
npm test # node suite
npm run build # tsc + esbuild bundle
API shape notes (captured + verified): docs/EVENTBRITE-API.md. A
shell-level access skill (curl + fpx, no server needed) ships in
skills/eventbrite/.
FAQs
Eventbrite MCP server for Claude — developed and maintained by AI (Claude Code)
The npm package @chrischall/eventbrite-mcp receives a total of 54 weekly downloads. As such, @chrischall/eventbrite-mcp popularity was classified as not popular.
We found that @chrischall/eventbrite-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.