
Company News
Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.
launchflag-mcp
Advanced tools
MCP server for LaunchFlag. It lets a coding agent create a feature flag, ship the risky path dark behind it, and flip it later without a deploy.
Seven tools, one token, no state.
You probably do not need this package. launchflag is the SDK and the CLI, and the hosted MCP server needs
nothing installed. launchflag-mcp is only for running that same server locally instead.
npx launchflag init --key lf_dev_… --token lfk_… --url https://launchflag.dev
From your project root. It installs launchflag, writes the key, downloads the agent skill and points your
client at the hosted MCP server.
Hosted (the default). Nothing to install. Point your client at https://launchflag.dev/mcp with your API
token (lfk_…) in the Authorization header.
Local stdio (the alternative). Runs on your machine and talks to the same API over HTTPS. Useful when your client does not speak Streamable HTTP, or when you self-host LaunchFlag.
npx -y launchflag-mcp@latest
| Variable | Required | Default | What it is |
|---|---|---|---|
LAUNCHFLAG_TOKEN | yes | none | Your API token (lfk_…), from the dashboard Install page. The server exits if it is missing. |
LAUNCHFLAG_URL | no | https://launchflag.dev | Base URL of the LaunchFlag instance. Set it only if you self-host. |
The token is a secret. Keep the file that holds it out of git.
| Tool | What it does |
|---|---|
list_flags | Every flag with its dev, staging and prod state, fail mode and variants. |
create_flag | Creates a flag OFF in all three environments and returns the snippet to wrap the new path in. |
set_flag | Turns a flag on or off, or changes who it targets, in one environment. |
promote_flag | Copies one environment's config forward: dev to staging, or staging to prod. |
delete_flag | Deletes a flag, once the code paths behind it are gone. |
emergency_off | Kill switch: disables every non-essential flag in the project at once, or lifts it. |
list_projects | Your projects and their env keys. |
Hosted:
claude mcp add --transport http launchflag https://launchflag.dev/mcp --header "Authorization: Bearer lfk_…"
Local, in .mcp.json:
{
"mcpServers": {
"launchflag": {
"command": "npx",
"args": ["-y", "launchflag-mcp@latest"],
"env": { "LAUNCHFLAG_TOKEN": "lfk_…" }
}
}
}
.cursor/mcp.json, hosted:
{
"mcpServers": {
"launchflag": {
"type": "http",
"url": "https://launchflag.dev/mcp",
"headers": { "Authorization": "Bearer lfk_…" }
}
}
}
Swap in the command/args/env block above to run it locally instead.
codex mcp add has no header flag: it reads a bearer token from an environment variable, which it
re-reads every time Codex starts, so put the export in your shell profile.
export LAUNCHFLAG_TOKEN=lfk_…
codex mcp add launchflag --url https://launchflag.dev/mcp --bearer-token-env-var LAUNCHFLAG_TOKEN
Local:
codex mcp add launchflag --env LAUNCHFLAG_TOKEN=lfk_… -- npx -y launchflag-mcp@latest
Full agent guide, including the skill file and the flag conventions agents should follow: launchflag.dev/docs/agents.
Questions or a bug: contact@launchflag.dev.
MIT licensed.
FAQs
MCP server that lets coding agents create and flip LaunchFlag flags.
We found that launchflag-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.