New:Microsoft Teams Notifications Are Now Available in Socket.Learn more
Get Started

@houst-com/front-mcp

Package Overview
Dependencies
Maintainers
1
Versions
3
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@houst-com/front-mcp

Secure, fully-featured MCP server for the Front Platform API — 26 tools, 200+ actions, OAuth support, configurable policy engine

Source
npmnpm
Version
1.0.1
Version published
Weekly downloads
47
-50%
Maintainers
1
Weekly downloads
 
Created
Source

Front MCP Server

CI npm version License: MIT

A secure, fully-featured MCP server for the Front Platform API. Provides 26 tools with 200+ actions for LLM agents to read, search, manage, and act on Front data.

Why?

No official Front MCP server exists. Community alternatives have critical security issues: TypeScript strict mode disabled, security middleware excluded from compilation, read-only coverage. This project provides a secure, auditable, fully-featured alternative with OAuth support, a configurable operation policy engine, and proper rate limiting.

Quick Start (API Token — 30 seconds)

  • Get a Front API token from Settings > Developers > API tokens.

  • Add to your Claude Code settings (~/.claude/settings.json):

{
  "mcpServers": {
    "front": {
      "command": "npx",
      "args": ["-y", "@houst-com/front-mcp"],
      "env": {
        "FRONT_API_TOKEN": "your-front-api-token"
      }
    }
  }
}
  • Start Claude Code. The Front tools are now available.

OAuth provides automatic token refresh and better security than API tokens.

  • Create a Front app at Settings > Developers > OAuth apps.
  • Set the redirect URI to https://localhost:9876/callback.
  • Enable the resource permissions your MCP server needs (Read, Write, Delete, Send).
  • Save the app and copy your Client ID and Client Secret.
  • Create ~/.front-mcp/config.json:
{
  "auth": {
    "method": "oauth",
    "oauth": {
      "client_id": "your-client-id",
      "client_secret_env": "FRONT_MCP_OAUTH_SECRET",
      "redirect_port": 9876,
      "scopes": []
    }
  }
}
  • Configure Claude Code:
{
  "mcpServers": {
    "front": {
      "command": "npx",
      "args": ["-y", "@houst-com/front-mcp"],
      "env": {
        "FRONT_MCP_AUTH_METHOD": "oauth",
        "FRONT_MCP_OAUTH_SECRET": "your-client-secret"
      }
    }
  }
}
  • Run front-mcp auth to authenticate (opens browser).
  • Tokens are encrypted and stored locally (AES-256-GCM, 0600 permissions).

Auth CLI

front-mcp auth            # Start OAuth flow
front-mcp auth --status   # Check auth state (no token values shown)
front-mcp auth --clear    # Remove stored tokens

Architecture

MCP Layer (tools, policy, validation)
  |
Service Layer (resource services, pagination)
  |
Client Layer (HTTP client, OAuth, rate limiter, retry)
  • 3-layer architecture with strict unidirectional dependencies
  • 26 compound tools with discriminated union action parameters
  • Policy engine with configurable allow/confirm/deny per action
  • Rate limiter tracking all 5 Front rate limit headers
  • Retry engine with exponential backoff and retry-after respect

Tools Reference

ToolActions
accountslist, get, create, update, delete, list_contacts, add_contact, remove_contact
analyticscreate_export, get_export, create_report, get_report
channelslist, get, update, validate, create, list_for_teammate, list_for_team
commentslist, get, create, update, list_mentions, reply
contact_groupslist, create, delete, list_contacts, add_contacts, remove_contacts
contact_listslist, create, delete, list_contacts, add_contacts, remove_contacts
contact_noteslist, create
contactslist, get, create, update, delete, merge, list_conversations, add_handle, remove_handle
conversationslist, get, search, create, update, delete, assign, list_events, list_followers, add_followers, remove_followers, list_inboxes, add_link, remove_links, list_messages, update_reminders, add_tag, remove_tag
custom_fieldslist_for_accounts, list_for_contacts, list_for_conversations, list_for_inboxes, list_for_links, list_for_teammates
draftslist, create, create_reply, update, delete
eventslist, get
inboxeslist, get, create, list_channels, list_conversations, list_access, grant_access, revoke_access
knowledge_baseslist, get, create, update, list_categories, list_articles, get_article, create_article, update_article, delete_article, get_category, create_category, update_category, delete_category
linkslist, get, create, update, list_conversations
message_template_folderslist, get, create, update, delete, list_children, create_child
message_templateslist, get, create, update, delete, list_children, create_child
messagesget, create, reply, import, receive_custom, get_seen_status, mark_seen
ruleslist, list_for_inbox, get, list_for_teammate, list_for_team
shiftslist, get, create, update, list_teammates, add_teammates, remove_teammates
signatureslist, get, update, delete, create_for_teammate, create_for_team
tagslist, get, create, update, delete, list_children, create_child, list_conversations
teammate_groupslist, get, create, update, delete, list_inboxes, add_inboxes, remove_inboxes, list_teammates, add_teammates, remove_teammates, list_teams, add_teams, remove_teams
teammateslist, get, update, list_conversations, list_inboxes
teamslist, get, add_teammates, remove_teammates
token_identityget

Policy Engine

Every action is classified into a tier with a default decision:

TierDefaultExamples
readallowlist, get, search
writeconfirmcreate, update, assign
destructivedenydelete, remove

Confirmation Flow

Write actions require confirmation by default:

  • LLM calls conversations with action: "assign".
  • Tool returns: "CONFIRMATION REQUIRED: ... Call again with confirm: true."
  • LLM calls again with confirm: true to execute.

Custom Policy

Create ~/.front-mcp/policy.json:

{
  "defaults": {
    "read": "allow",
    "write": "allow",
    "destructive": "confirm"
  },
  "overrides": [
    { "tool": "conversations", "action": "delete", "decision": "deny" },
    { "tool": "tags", "action": "*", "decision": "allow" }
  ]
}

Override precedence: specific action > tool wildcard > tier default.

Security Model

  • HTTPS enforced — no HTTP fallback, ever
  • Token encryption — AES-256-GCM with PBKDF2 key derivation
  • File permissions — token file is 0600 (owner read/write only)
  • Output sanitization — configurable field redaction before LLM sees data
  • Log redaction — sensitive fields redacted from all log output
  • Policy engine — destructive actions denied by default
  • No secrets in stdout — stdout is reserved for MCP protocol only
  • Minimal dependencies — native fetch, Node.js crypto, no unnecessary packages
  • Pinned versions — all dependencies at exact versions

Configuration

Config file: ~/.front-mcp/config.json (or $XDG_CONFIG_HOME/front-mcp/config.json)

See config/config.example.json for all options.

Environment variable overrides:

  • FRONT_API_TOKEN — API token for authentication
  • FRONT_MCP_AUTH_METHODoauth or api_token
  • FRONT_MCP_LOG_LEVELerror, warn, info, debug
  • FRONT_MCP_POLICY_FILE — path to custom policy file

License

MIT

Keywords

mcp

FAQs

Package last updated on 03 Apr 2026

Related posts