
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
@collhub/mcp
Advanced tools
MCP server for CollHub: documents, projects, comments, workflows and data sources as tools for Claude Code, Claude Desktop, Cursor, VS Code and Codex
@collhub/mcp connects an MCP host — Claude Code, Claude Desktop, Cursor, VS Code, Codex — to your CollHub instance. The assistant can then search and read your documents, write and edit them, comment, run projects and tasks, move documents through workflows, follow relationships, query data sources and talk to CollHub's own chat threads.
The server runs on your machine and talks to the host over stdio. Its only configuration is the URL of your instance; you sign in with your browser, and no password is stored anywhere.
node --version tells you which one you have.https://acme.collhub.com.Every host launches the server the same way: npx -y @collhub/mcp with the instance URL in COLLHUB_URL. Replace https://acme.collhub.com below with your own instance.
claude mcp add -s user collhub -e COLLHUB_URL=https://acme.collhub.com -- npx -y @collhub/mcp
-s user makes the server available in every project; -s project registers it for the current project only, in its .mcp.json.
Settings → Developer → Edit Config, then add the server to claude_desktop_config.json:
{
"mcpServers": {
"collhub": {
"command": "npx",
"args": ["-y", "@collhub/mcp"],
"env": { "COLLHUB_URL": "https://acme.collhub.com" }
}
}
}
In .cursor/mcp.json (one project) or ~/.cursor/mcp.json (everywhere):
{
"mcpServers": {
"collhub": {
"command": "npx",
"args": ["-y", "@collhub/mcp"],
"env": { "COLLHUB_URL": "https://acme.collhub.com" }
}
}
}
In .vscode/mcp.json:
{
"servers": {
"collhub": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@collhub/mcp"],
"env": { "COLLHUB_URL": "https://acme.collhub.com" }
}
}
}
In ~/.codex/config.toml:
[mcp_servers.collhub]
command = "npx"
args = ["-y", "@collhub/mcp"]
[mcp_servers.collhub.env]
COLLHUB_URL = "https://acme.collhub.com"
The first time a host connects, the server opens your browser on the CollHub login and consent page (it also prints the URL on stderr, which the host shows in its MCP log). Once you approve, a refresh token stored on this machine keeps the session alive — under ~/.config/collhub-mcp/sessions/ (or $XDG_CONFIG_HOME/collhub-mcp), one file per instance and host, readable by you only. Claude Code, Claude Desktop, Cursor and Codex each sign in once and then keep their own session.
whoami says who the server is signed in as, logout ends the session on this host only, and login with switch user signs the browser out first so you can enter a different account. Without an assistant, delete the session file and reconnect.ssh -L 52180:127.0.0.1:52180 <host> — then open the URL the server prints.To reach more than one CollHub instance from a single server, configure COLLHUB_INSTANCES instead of COLLHUB_URL:
[
{ "name": "prod", "url": "https://acme.collhub.com" },
{ "name": "staging", "url": "https://staging.acme.collhub.com" }
]
(as one JSON string in the host's env). Each instance gets its own sign-in and its own stored session. Every tool then takes an optional instance argument naming the target, and a list_instances tool lists them; a call that omits it goes to the first instance. Routing is per call — there is no "current instance" that one conversation could switch under another.
| Variable | Description |
|---|---|
COLLHUB_URL | The instance URL (single-instance mode) |
COLLHUB_INSTANCES | JSON array of {name, url} objects (multi-instance mode) |
COLLHUB_PROFILE | Overrides the host name that keys the stored session (default: the connecting host's name) |
On connect the server also hands the host a short guide to working with CollHub — how documents are addressed, how edits are made, how projects are laid out — so the assistant knows the house rules before its first call.
CollHub MCP client.env of the registration (or the extension's settings in Claude Desktop).npx complains about the Node version — the server needs Node 22.19 or later; npx runs whatever node is first on your PATH.login with switch user, or delete the session file under ~/.config/collhub-mcp/sessions/.@collhub/mcp is part of CollHub and is released under the MIT license. Its source is not published as an open-source project; questions and requests go through your CollHub contact.
FAQs
MCP server for CollHub: documents, projects, comments, workflows and data sources as tools for Claude Code, Claude Desktop, Cursor, VS Code and Codex
We found that @collhub/mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.