@honkio/mcp

MCPcommunitylive
v1.5.0UnknownMITUpdated 2d agonpmGitHub

HonkIO MCP server — lets AI coding agents send SMS, manage Canadian phone numbers, and handle CASL/DNCL compliance

Endpoint healthlive
checked 6h ago · 110ms · auth required
100% of the last 1 check reached this endpoint
Works in
ClaudeCursorCopilotChatGPTGemini

Inferred from the transports this listing declares (stdio, streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Automatically indexed from public sources. Not yet verified by the developer on Forge.Claim this listing →
247Downloads/wk
2d agoLast update
Needs 1 credential before it runs
  • HONKIO_API_KEYAPI keyrequired

    Your HonkIO API key (mk_test_... to explore for free, mk_live_... for real sends)

Declared by the author in the official MCP registry. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Package
AuthorUnknown
LicenseMIT
Version1.5.0
Sourcenpm+mcp-registry
Trust Status
B
60/100Good
Listed in Forge index+10/10
Publisher identity verified+0/20
Publisher: run `forge publish` from the package repo to claim ownership
Ed25519 publish signature+0/5
Included automatically when the publisher runs `forge publish`
Domain verification+0/5
Publisher: host /.well-known/forge.json on the package homepage with { "publisher": "<github-login>" }
npm Trusted Publishing (Sigstore)+0/5
Publish from GitHub Actions with --provenance so the attestation binds this package to this repo
npm maintainer match+0/5
Earned once your identity is verified above and that login is an npm maintainer of this package
CVE scan · clean+30/30
Static analysis · clean+20/20
Paste into Claude Code, Cursor, or any AI assistant to fix all gaps
StatusCommunity-indexed
PublisherUnverified
SignatureUnsigned
Domain
Provenance
Dependencies✓ 5 resolved · none vulnerable
Tool surface40 tools · 1 privileged
Security scan✓ Cleanv1.5.0 · todayHow well does this scan work?
EvalsNone
IndexedSep 8, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

40 tools · 1 privileged
Statically extracted from the published packagev1.5.0 · 2h ago

Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.

send_smsNo description published

This tool published no description. Forge does not invent one.

list_messagesList SMS messages for your account with optional filters. Returns paginated results. On each message, cost_cents is what it actually cost in CAD cents (settled to the carrier's part count; 0 on a TEST simulation or when the carrier refused the send outright — a message the carrier accepted but coul…

List SMS messages for your account with optional filters. Returns paginated results. On each message, cost_cents is what it actually cost in CAD cents (settled to the carrier's part count; 0 on a TEST simulation or when the carrier refused the send outright — a message the carrier accepted but coul…

No input schema was published for this tool.

get_messageGet full details of a single SMS message by its ID, including delivery events. cost_cents is what it actually cost in CAD cents (settled to the carrier's part count; 0 on a TEST simulation or when the carrier refused the send outright; an undelivered message keeps its charge) and segment_count is t…

Get full details of a single SMS message by its ID, including delivery events. cost_cents is what it actually cost in CAD cents (settled to the carrier's part count; 0 on a TEST simulation or when the carrier refused the send outright; an undelivered message keeps its charge) and segment_count is t…

No input schema was published for this tool.

search_phone_numbersSearch available Canadian phone numbers you can provision. Filter by area code to find numbers in a specific province.

Search available Canadian phone numbers you can provision. Filter by area code to find numbers in a specific province.

No input schema was published for this tool.

provision_phone_numberProvision (purchase) a Canadian phone number to your account. Get the phone_number value from search_phone_numbers first.

Provision (purchase) a Canadian phone number to your account. Get the phone_number value from search_phone_numbers first.

No input schema was published for this tool.

list_phone_numbersList all phone numbers provisioned on your account.

List all phone numbers provisioned on your account.

No input schema was published for this tool.

get_phone_numberGet details for a specific provisioned phone number.

Get details for a specific provisioned phone number.

No input schema was published for this tool.

release_phone_numberRelease (cancel) a provisioned phone number. This will stop monthly billing for the number; the one-time activation fee and the current month are not refunded. This action cannot be undone.

Release (cancel) a provisioned phone number. This will stop monthly billing for the number; the one-time activation fee and the current month are not refunded. This action cannot be undone.

No input schema was published for this tool.

record_consentRecord CASL consent for a phone number before sending commercial messages. Express consent requires source_description. Implied consent requires relationship_type and is valid for 2 years from last_transaction_date.

Record CASL consent for a phone number before sending commercial messages. Express consent requires source_description. Implied consent requires relationship_type and is valid for 2 years from last_transaction_date.

No input schema was published for this tool.

list_consentsList CASL consent records for your account, optionally filtered by phone number or status.

List CASL consent records for your account, optionally filtered by phone number or status.

No input schema was published for this tool.

check_consentCheck whether a phone number has valid CASL consent before sending a message.

Check whether a phone number has valid CASL consent before sending a message.

No input schema was published for this tool.

revoke_consentRevoke CASL consent for a phone number. Future messages to this number will be blocked unless new consent is recorded.

Revoke CASL consent for a phone number. Future messages to this number will be blocked unless new consent is recorded.

No input schema was published for this tool.

record_opt_outManually record an opt-out for a subscriber. Use this when a subscriber contacts you directly to opt out rather than replying STOP to a message.

Manually record an opt-out for a subscriber. Use this when a subscriber contacts you directly to opt out rather than replying STOP to a message.

No input schema was published for this tool.

list_opt_outsList opt-out records for your account.

List opt-out records for your account.

No input schema was published for this tool.

check_dnclComing soon: check if a Canadian phone number is on the CRTC Do Not Call List. CRTC DNCL checking is not available yet — this endpoint currently returns 501 (DNCL_COMING_SOON).

Coming soon: check if a Canadian phone number is on the CRTC Do Not Call List. CRTC DNCL checking is not available yet — this endpoint currently returns 501 (DNCL_COMING_SOON).

No input schema was published for this tool.

batch_check_dnclComing soon: check up to 100 Canadian phone numbers against the CRTC Do Not Call List in a single request. CRTC DNCL checking is not available yet — this endpoint currently returns 501 (DNCL_COMING_SOON).

Coming soon: check up to 100 Canadian phone numbers against the CRTC Do Not Call List in a single request. CRTC DNCL checking is not available yet — this endpoint currently returns 501 (DNCL_COMING_SOON).

No input schema was published for this tool.

request_erasureExecute a PIPEDA/Quebec Law 25 right-to-erasure request for a phone number. Purges message bodies, consent records, and opt-out records for the specified number. Creates an immutable audit log entry.

Execute a PIPEDA/Quebec Law 25 right-to-erasure request for a phone number. Purges message bodies, consent records, and opt-out records for the specified number. Creates an immutable audit log entry.

No input schema was published for this tool.

create_webhookRegister a webhook endpoint to receive HonkIO event notifications. The signing_secret in the response is shown once — store it to verify X-HonkIO-Signature on incoming requests.

Register a webhook endpoint to receive HonkIO event notifications. The signing_secret in the response is shown once — store it to verify X-HonkIO-Signature on incoming requests.

No input schema was published for this tool.

list_webhooksList all registered webhook endpoints for your account.

List all registered webhook endpoints for your account.

No input schema was published for this tool.

update_webhookUpdate a webhook endpoint URL, event subscriptions, or active status.

Update a webhook endpoint URL, event subscriptions, or active status.

No input schema was published for this tool.

delete_webhookprivilegedDelete a registered webhook endpoint.

Delete a registered webhook endpoint.

No input schema was published for this tool.

list_webhook_deliveriesList recent delivery attempts for a webhook (success/failure, HTTP status, duration, timestamp). Use this to debug why customer events are not arriving or why a webhook was auto-disabled.

List recent delivery attempts for a webhook (success/failure, HTTP status, duration, timestamp). Use this to debug why customer events are not arriving or why a webhook was auto-disabled.

No input schema was published for this tool.

reactivate_webhookRe-enable a webhook that was auto-disabled by repeated delivery failures. The destination URL is re-validated (SSRF check) before reactivation.

Re-enable a webhook that was auto-disabled by repeated delivery failures. The destination URL is re-validated (SSRF check) before reactivation.

No input schema was published for this tool.

list_webhook_dead_lettersList events that exhausted all retry attempts (dead-letter queue). These are events that failed delivery and were never received by your endpoint. Use replay_webhook_dead_letter to retry after fixing the issue.

List events that exhausted all retry attempts (dead-letter queue). These are events that failed delivery and were never received by your endpoint. Use replay_webhook_dead_letter to retry after fixing the issue.

No input schema was published for this tool.

replay_webhook_dead_letterResend a dead-lettered event against the original webhook URL. The event is re-signed with the current timestamp; on success the dead-letter row is marked as replayed.

Resend a dead-lettered event against the original webhook URL. The event is re-signed with the current timestamp; on success the dead-letter row is marked as replayed.

No input schema was published for this tool.

discard_webhook_dead_letterPermanently discard a dead-lettered event without replaying it. Use when the event is no longer relevant (e.g. the underlying message has expired).

Permanently discard a dead-lettered event without replaying it. Use when the event is no longer relevant (e.g. the underlying message has expired).

No input schema was published for this tool.

get_pricingNo description published

This tool published no description. Forge does not invent one.

start_verificationNo description published

This tool published no description. Forge does not invent one.

check_verificationSubmit the OTP a user entered to complete verification. Returns the verification status (verified, invalid_code, expired, max_attempts).

Submit the OTP a user entered to complete verification. Returns the verification status (verified, invalid_code, expired, max_attempts).

No input schema was published for this tool.

get_verificationLook up the current state of a verification (status, attempts, expiry, and whether it was real). The "mode" field is "LIVE" for a real billed SMS or "TEST" for a simulation; cost_cents is 0 on a TEST verification.

Look up the current state of a verification (status, attempts, expiry, and whether it was real). The "mode" field is "LIVE" for a real billed SMS or "TEST" for a simulation; cost_cents is 0 on a TEST verification.

No input schema was published for this tool.

list_verificationsList recent verifications for your account, optionally filtered by phone number or status.

List recent verifications for your account, optionally filtered by phone number or status.

No input schema was published for this tool.

get_send_limitYour account's sending limits and current usage: the daily cap (a rolling 24 hours, 250/day for new accounts until a volume request is approved),

Your account's sending limits and current usage: the daily cap (a rolling 24 hours, 250/day for new accounts until a volume request is approved),

No input schema was published for this tool.

request_send_limitFile a "request a higher volume" for HonkIO staff to review. Only available once the account has completed its probation period

File a "request a higher volume" for HonkIO staff to review. Only available once the account has completed its probation period

No input schema was published for this tool.

get_topup_allowanceHow much credit can be added to the account right now. Top-ups are capped by a maximum balance and a rolling 30-day total

How much credit can be added to the account right now. Top-ups are capped by a maximum balance and a rolling 30-day total

No input schema was published for this tool.

whoamiIdentify the HonkIO account the configured API key belongs to. Returns the account ID, name, credit balance and status. Call this first when you need an account ID, or to confirm which account and mode (live or test) the key is for.

Identify the HonkIO account the configured API key belongs to. Returns the account ID, name, credit balance and status. Call this first when you need an account ID, or to confirm which account and mode (live or test) the key is for.

No input schema was published for this tool.

get_accountGet details for your HonkIO account including name, credit balance, status, and active API keys.

Get details for your HonkIO account including name, credit balance, status, and active API keys.

No input schema was published for this tool.

update_accountUpdate your HonkIO account name.

Update your HonkIO account name.

No input schema was published for this tool.

get_usageGet usage statistics for your account including message counts, spending, and live delivery health: "delivery" (liveOutbound, delivered, failed, undelivered, pending, failureRatePct) and "byNumber" (the same per sending number). A rising failure rate usually means wrong numbers, landlines, or a scr…

Get usage statistics for your account including message counts, spending, and live delivery health: "delivery" (liveOutbound, delivered, failed, undelivered, pending, failureRatePct) and "byNumber" (the same per sending number). A rising failure rate usually means wrong numbers, landlines, or a scr…

No input schema was published for this tool.

create_api_keyIssue a new API key for your account. The raw key is shown once — store it securely.

Issue a new API key for your account. The raw key is shown once — store it securely.

No input schema was published for this tool.

revoke_api_keyRevoke an API key, immediately blocking all requests using that key. This cannot be undone.

Revoke an API key, immediately blocking all requests using that key. This cannot be undone.

No input schema was published for this tool.

37 of 40 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

HonkIO MCP server — lets AI coding agents send SMS, manage Canadian phone numbers, and handle CASL/DNCL compliance

Keywords
mcp
Alternatives
Comparing tool surfaces…

Dependency tree

What one Forge scan resolved from npm metadata on 2026-09-08 — observed resolution, not a publisher declaration.

5 packages resolved · 3 direct · none carrying advisories Resolution stops at depth 4 and 60 packages.

Not followed: peerDependencies. This tree covers runtime dependencies only, so anything those pull in was never resolved.