
Security News
Ruby's Bundler 4.0.18 Extends Cooldown to bundle lock and bundle cache
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.
@lightsparkdev/grid-mcp
Advanced tools
It is generated with Stainless.
You can run the MCP Server directly via npx:
export GRID_CLIENT_ID="My Username"
export GRID_CLIENT_SECRET="My Password"
export GRID_AGENT_ACCESS_TOKEN="My Agent Access Token"
export GRID_WEBHOOK_PUBKEY="My Webhook Signature"
npx -y @lightsparkdev/grid-mcp@latest
There is a partial list of existing clients at modelcontextprotocol.io. If you already have a client, consult their documentation to install the MCP server.
For clients with a configuration JSON, it might look something like this:
{
"mcpServers": {
"lightsparkdev_grid_api": {
"command": "npx",
"args": ["-y", "@lightsparkdev/grid-mcp"],
"env": {
"GRID_CLIENT_ID": "My Username",
"GRID_CLIENT_SECRET": "My Password",
"GRID_AGENT_ACCESS_TOKEN": "My Agent Access Token",
"GRID_WEBHOOK_PUBKEY": "My Webhook Signature"
}
}
}
}
If you use Cursor, you can install the MCP server by using the button below. You will need to set your environment variables
in Cursor's mcp.json, which can be found in Cursor Settings > Tools & MCP > New MCP Server.
If you use MCP, you can install the MCP server by clicking the link below. You will need to set your environment variables
in VS Code's mcp.json, which can be found via Command Palette > MCP: Open User Configuration.
If you use Claude Code, you can install the MCP server by running the command below in your terminal. You will need to set your
environment variables in Claude Code's .claude.json, which can be found in your home directory.
claude mcp add lightsparkdev_grid_mcp_api --header "x-grid-client-id: My Username" --header "x-grid-client-secret: My Password" --header "x-grid-agent-access-token: My Agent Access Token" --header "X-Grid-Signature: My Webhook Signature" --transport http https://grid-mcp.stlmcp.com
This MCP server is built on the "Code Mode" tool scheme. In this MCP Server, your agent will write code against the TypeScript SDK, which will then be executed in an isolated sandbox. To accomplish this, the server will expose two tools to your agent:
The first tool is a docs search tool, which can be used to generically query for documentation about your API/SDK.
The second tool is a code tool, where the agent can write code against the TypeScript SDK. The code will be executed in a sandbox environment without web or filesystem access. Then, anything the code returns or prints will be returned to the agent as the result of the tool call.
Using this scheme, agents are capable of performing very complex tasks deterministically and repeatably.
Launching the client with --transport=http launches the server as a remote server using Streamable HTTP transport. The --port setting can choose the port it will run on, and the --socket setting allows it to run on a Unix socket.
Authorization can be provided via the Authorization header using the Basic or Bearer scheme.
Additionally, authorization can be provided via the following headers:
| Header | Equivalent client option | Security scheme |
|---|---|---|
x-grid-client-id | username | BasicAuth |
x-grid-client-secret | password | BasicAuth |
x-grid-agent-access-token | agentAccessToken | AgentAuth |
X-Grid-Signature | webhookSignature | WebhookSignature |
A configuration JSON for this server might look like this, assuming the server is hosted at http://localhost:3000:
{
"mcpServers": {
"lightsparkdev_grid_api": {
"url": "http://localhost:3000",
"headers": {
"Authorization": "Basic <auth value>"
}
}
}
}
FAQs
The official MCP Server for the Lightspark Grid API
We found that @lightsparkdev/grid-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.