
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
jetapi-mcp-server
Advanced tools
MCP server for JetAPI — send WhatsApp and Telegram messages from AI agents
Official MCP server for JetAPI — send WhatsApp, Telegram, SMS and MAX messages, files and bulk mailings from AI agents like Claude, Cursor and VS Code.
| Tool | Description |
|---|---|
get_account | Full account info: balance, dispatch routing, sender names, subscription, WhatsApp/Telegram session status (token is masked) |
get_balance | Balance, customer ID, dispatch routing channels and registered sender names |
get_utm_tags | List UTM tags used to track dispatches |
send_message | Send a text via WhatsApp, Telegram (tdlib), Telegram Bot, SMS, VK/OK or MAX — with cascade, scheduling, priority, reply-to and callbacks |
send_bulk | Send the same message to many phone numbers at once |
get_delivery_status | Status and details of a delivery, with the status explained in plain words |
delete_delivery | Delete a delivered WhatsApp/Telegram message on all recipient devices |
get_phone_info | Country, operator and normalized format of a phone number |
send_file | Send a document, image, audio or video from a local path, URL or base64 (up to 100 MB) |
create_webhook | Subscribe a URL to events: incoming messages, WhatsApp statuses, login/logout |
get_webhook | Details of one webhook |
list_webhooks | All registered webhooks |
delete_webhook | Delete a webhook |
update_webhook | Change a webhook's URL and/or event types |
Sign up at jetapi.io and copy the API token from the dashboard. To send through WhatsApp or Telegram, connect the messenger in the dashboard first.
jetapi-mcp-server.mcpb from the latest release.Requires Node.js 18.17 or newer. Open Settings → Developer → Edit Config (claude_desktop_config.json) and add:
{
"mcpServers": {
"jetapi": {
"command": "npx",
"args": ["-y", "jetapi-mcp-server"],
"env": { "JETAPI_TOKEN": "your_token_here" }
}
}
}
Restart Claude Desktop.
claude mcp add jetapi -- npx -y jetapi-mcp-server
The server needs JETAPI_TOKEN, so pass it when adding:
claude mcp add jetapi --env JETAPI_TOKEN=your_token_here -- npx -y jetapi-mcp-server
Add to ~/.cursor/mcp.json (or .cursor/mcp.json in a project):
{
"mcpServers": {
"jetapi": {
"command": "npx",
"args": ["-y", "jetapi-mcp-server"],
"env": { "JETAPI_TOKEN": "your_token_here" }
}
}
}
Add to .vscode/mcp.json — VS Code will prompt for the token and keep it out of the file:
{
"inputs": [
{ "type": "promptString", "id": "jetapi_token", "description": "JetAPI token", "password": true }
],
"servers": {
"jetapi": {
"type": "stdio",
"command": "npx",
"args": ["-y", "jetapi-mcp-server"],
"env": { "JETAPI_TOKEN": "${input:jetapi_token}" }
}
}
}
The server is listed in the official MCP Registry as io.github.jetapi/jetapi-mcp-server, so clients and catalogs that read the registry can install it directly.
Any client that supports stdio servers:
{
"command": "npx",
"args": ["-y", "jetapi-mcp-server"],
"env": { "JETAPI_TOKEN": "your_token_here" }
}
| Variable | Required | Default | Description |
|---|---|---|---|
JETAPI_TOKEN | yes | — | Bearer token from the JetAPI dashboard |
JETAPI_BASE_URL | no | https://api.jetapi.io | API host |
JETAPI_DEBUG | no | 0 | 1 logs every request to stderr |
dispatch_routing is an ordered list of channels. JetAPI tries them one by one and moves to the next channel only if delivery through the previous one fails. Without it, the default routing from your JetAPI dashboard is used.
| Value | Channel | Recipient |
|---|---|---|
whatsapp | phone or whatsapp_lid | |
tdlib | Personal Telegram account | phone, username or tdlib_user_id (negative ID = group chat) |
telegram | Telegram Bot | phone |
sms | SMS | phone |
notify | VK / OK notifications | phone |
max | MAX messenger | phone |
Ask Claude in plain language:
| Say | Tool |
|---|---|
| "Show my JetAPI account — is WhatsApp connected?" | get_account |
| "How much money is left on JetAPI?" | get_balance |
| "Which UTM tags do I have?" | get_utm_tags |
| "Send a WhatsApp message to +7 999 123-45-67: Your order has shipped." | send_message |
| "Message @john_doe on Telegram that the meeting moved to 3 pm." | send_message (tdlib) |
| "Try WhatsApp first, then SMS: Your code is 4821." | send_message (cascade) |
| "Remind 79991234567 tomorrow at 09:00 UTC about the appointment." | send_message (scheduled) |
| "Send 'Sale starts today!' to 79991234567, 79997654321 and 995598464533." | send_bulk |
| "Was message 94396942 delivered?" | get_delivery_status |
| "Delete message 94396942." | delete_delivery |
| "Which operator is +995 598 464 533?" | get_phone_info |
| "Send ~/Documents/invoice.pdf to 79991234567 on WhatsApp." | send_file |
| "Send incoming WhatsApp messages to https://example.com/hook." | create_webhook |
| "Show webhook 57." | get_webhook |
| "List my webhooks." | list_webhooks |
| "Delete webhook 57." | delete_webhook |
| "Point webhook 57 to https://example.com/new-hook." | update_webhook |
send_file uploads the file as multipart/form-data.username without the tdlib channel, or scheduled_at in the past) are rejected before any request is sent.Retry-After.send_message, send_bulk, send_file, create_webhook), so nothing is sent twice.Invalid JetAPI token. Check your JETAPI_TOKEN. or Validation error: text: the text cannot be empty.git clone https://github.com/jetapi/jetapi-mcp-server.git
cd jetapi-mcp-server
npm install
cp .env.example .env # put your token in .env
npm run build
npm start
| Script | What it does |
|---|---|
npm run dev | Run the TypeScript source directly |
npm run inspector | Open the MCP Inspector with all tools |
npm run check | Verify versions in package.json / server.json / manifest.json and that the server exposes all 14 tools |
npm run build:mcpb | Build the Claude Desktop extension into build/jetapi-mcp-server.mcpb |
package.json, server.json (both version fields) and manifest.json, and add a CHANGELOG.md entry.main, then push a tag: git tag v1.2.3 && git push origin v1.2.3..mcpb bundle and updates the MCP Registry.The extension runs locally, collects no analytics or telemetry, and sends data only to the JetAPI API to perform the actions you request. Your API token is stored by your MCP client (Claude Desktop keeps it in secure storage).
Questions: support@jetapi.io
FAQs
MCP server for JetAPI — send WhatsApp and Telegram messages from AI agents
We found that jetapi-mcp-server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.