
Security News
GPT-6 Astra Attempts Supply Chain Attacks Against Open Source Maintainers in Testing
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.
osm-edit-mcp
Advanced tools
Review-first MCP server for previewed, version-checked OpenStreetMap road edits from local GPX surveys
A review-first Model Context Protocol server for inspecting OpenStreetMap and turning a selected part of a local GPX survey into a previewed road-edit proposal.
Alpha software. It does not autonomously edit OpenStreetMap. The normal profile can inspect data and prepare proposals, but a production write requires an exact preview, a separate MCP host confirmation of its SHA-256 digest, fresh OSM identity/version checks, and one atomic
osmChangeupload.
Most OpenStreetMap MCP servers focus on search, geocoding, or routing. OSM Edit MCP focuses on the risky last mile: helping a mapper review a narrowly selected survey before any road geometry reaches OSM.
local GPX → selected segment → current/proposed preview
→ exact digest confirmation → OSM changeset
The safe profile can:
highway=* ways without choosing one automatically;ui:// resource;It does not upload GPS traces, infer crossings, delete roads, restructure relations, copy geometry from restricted providers, or authorize a production edit from natural-language consent alone.
Requirements:
Recommended installation from PyPI:
uvx osm-edit-mcp
This command starts the stdio server and waits for an MCP client. For normal use, put the same command in a JSON-based MCP host configuration:
{
"mcpServers": {
"osm-edit": {
"command": "uvx",
"args": ["osm-edit-mcp"],
"env": {
"OSM_USE_DEV_API": "true",
"OSM_WRITE_PROFILE": "safe"
}
}
}
}
Restart the host, then call get_server_info or get_edit_capabilities.
The first uvx launch installs the released package in an isolated environment.
The development API is the default in this example; no OAuth credentials are
needed for read-only inspection.
For client-specific formats, including Codex TOML, see MCP client setup. A real read-only protocol smoke client is available at examples/quick_start.py.
MCP hosts can also start the guided review_gpx_road_edit prompt with a local
GPX path and edit goal. It requires explicit segment and target choices, builds
a non-writing preview, and stops at review of the complete proposal digest. It
never calls apply_osm_edit.
Keep private tracks outside the repository. Set OSM_TRACK_IMPORT_DIR to a
directory you control, or provide inline GPX XML. Files are limited to 10 MiB
and 100,000 raw points; path traversal and symlink escapes are rejected.
analyze_gpx_track(gpx_path="survey.gpx")
The result identifies stable track/segment IDs, bounds, distance, timestamps, and discontinuities. Separate GPX segments are never joined implicitly.
create_track_selection(
track_id="<track_id>",
segment_id="trk-0-seg-0",
start_point_index=1240,
end_point_index=1395
)
Timestamp and endpoint-coordinate selection are also supported. Review the
returned preview_uri or its GeoJSON fallback.
match_track_selection(selection_id="<selection_id>", costing="auto")
suggest_track_road_candidates(selection_id="<selection_id>")
Valhalla output is diagnostic only. Candidate discovery never selects the target way on the mapper's behalf.
Track analysis, segment selection, and the selection preview work without OAuth.
preview_track_road_edit still requires an authenticated OSM identity because
the proposal is bound to that exact account and API target, even though this
step does not write to OSM.
For a new road:
preview_track_road_edit(
selection_id="<selection_id>",
action="create",
tags={"highway":"residential"},
changeset_comment="Add surveyed residential road",
changeset_source="survey",
evidence_kind="survey_gpx"
)
For an existing contiguous chain:
preview_track_road_edit(
selection_id="<selection_id>",
action="update",
target_way_ids=[123456, 123457],
changeset_comment="Realign road from local survey",
changeset_source="survey",
evidence_kind="survey_gpx"
)
Review the current/proposed GeoJSON, exact operations and tags, preserved nodes,
endpoint connections, warnings, blocking issues, API target, expiry, and
proposal_digest. Ambiguous topology is reported rather than invented.
apply_osm_edit accepts the exact proposal ID and digest. In production, the
MCP host must display a separate elicitation request for that digest. Apply then
checks the live OSM account, write_api permission, referenced versions, and
affected highways before sending one transactional upload.
A network failure after an upload starts becomes RECONCILE_REQUIRED; the
server does not blindly retry an ambiguous write.
verify_osm_edit(proposal_id="<proposal_id>")
list_edit_proposals(status="APPLIED")
The normal safe profile enforces:
osmChange upload for creates and modifications.Raw write tools are available only in the explicit expert profile while
targeting the OSM development API.
GPX accuracy is not ground truth. Review every proposal against independent, permitted evidence and local knowledge. Follow OpenStreetMap's mapping, licensing, import, and automated-edit policies; systematic edits may require community discussion even when this software requires per-proposal review.
The package quick start is intentionally safe for inspection. Production setup is an advanced operator workflow:
Register separate development and production OAuth applications with only
read_prefs and write_api.
From an existing source checkout, create a private .env, configure the
development application, then authenticate it:
install -m 600 .env.example .env
uv sync --locked --extra dev
export OSM_EDIT_MCP_ENV_FILE="$PWD/.env"
uv run python oauth_auth.py --dev
Complete representative create/update preview and apply acceptance against the OSM development API.
Only after that development acceptance, configure and authenticate the separate production app:
export OSM_EDIT_MCP_ENV_FILE="$PWD/.env"
uv run python oauth_auth.py --prod
Tokens are keyring-first. Plaintext compatibility files are disabled by default
and, when explicitly enabled, must have mode 0600.
Do not switch to OSM_USE_DEV_API=false unless
get_edit_capabilities reports the expected account, production target,
safe profile, and digest-bound host confirmation.
Inspection:
get_server_infoget_edit_capabilitiesinspect_map_contextReview and editing:
analyze_gpx_trackcreate_track_selectionmatch_track_selectionsuggest_track_road_candidatespreview_track_road_editapply_osm_editlist_edit_proposalsverify_osm_editGuided prompt:
review_gpx_road_edit(gpx_path, edit_goal)From an existing source checkout:
uv sync --locked --extra dev
uv run --locked --extra dev pytest
uv run --locked --extra dev pytest --cov=src/osm_edit_mcp --cov-report=term-missing
Unit tests mock the network and force the development API at import time. Development-API acceptance is separate and opt-in; it must never point at production.
More documentation:
MIT. OpenStreetMap edits are also subject to the OSM contributor terms, community guidelines, and source-licensing requirements.
FAQs
Review-first MCP server for previewed, version-checked OpenStreetMap road edits from local GPX surveys
We found that osm-edit-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.