# horizon-mcp

MCP server for horizOn Backend-as-a-Service: documentation, live API tools, and workflow prompts for Godot, Unity, and Unreal Engine integration.

- **Type:** MCP server
- **Trust:** 85/100 (A), scored on the package rubric
- **Verification:** verified (build provenance)
- **Version:** 1.5.5
- **Author:** ProjectMakers
- **License:** MIT
- **npm:** horizon-mcp
- **Source:** https://github.com/ProjectMakersDE/horizOn-mcp
- **Compatible clients:** claude-code, cursor, copilot, gemini (basis: transport)

## Trust

85/100 (A), scored on the package rubric
- Publisher verified: no
- Build provenance: verified attestation
- npm trusted publishing (OIDC): yes
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 5 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-30T06:39:53.378Z
- **Version scanned:** 1.5.5
- **CVEs:** none found by OSV at scan time

## Tools

40 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `horizon_signup_anonymous` — Creates a guest account with only a display name, for players without email. For accounts with email and password, use horizon_signup_email.
- `horizon_signup_email` — Creates an account with email, password and display name. Use horizon_signin_email for existing accounts and horizon_signup_anonymous for guests.
- `horizon_signin_email` — Signs in an existing email account and starts a session. Use horizon_signup_email to create one and horizon_signin_anonymous for guest accounts.
- `horizon_signin_anonymous` — Signs in a guest account with the anonymousToken returned by horizon_signup_anonymous and starts a session. Use horizon_signin_email for email accounts.
- `horizon_check_auth` — Checks whether a session token from horizon_signin_email or horizon_signin_anonymous is still valid for this user, for example before a call that needs a sessio
- `horizon_admin_cloudsave_list` — Lists cloud saves for the authenticated account, optionally filtered by project API key. Default sort is createdAt DESC.
- `horizon_admin_cloudsave_get` — Fetches a single cloud save by its UUID, including the full saveData payload.
- `horizon_admin_cloudsave_update` — Replaces the saveData of an existing cloud save. The backend enforces both a hard 300KB request limit and a soft per-tier byte limit.
- `horizon_admin_cloudsave_delete` — Soft-deletes a cloud save. Deleted saves are no longer accessible to end-users and disappear from list results.
- `horizon_admin_cloudsave_getStats` — Returns aggregated cloud save statistics for the authenticated account (totals, storage used in bytes/KB/MB, average size, per-project breakdown). Note: the cur
- `horizon_admin_cloudsave_getLimits` — Returns the cloud save limits and current usage for the authenticated account (role, max bytes per save, current count, current storage used). Note: the current
- `horizon_save_cloud_data` — Stores a player's save game as a string, usually JSON, and replaces any earlier save of that player.
- `horizon_load_cloud_data` — Reads a player's save game that was stored with horizon_save_cloud_data.
- `horizon_test_connection` — Checks that HORIZON_API_KEY and HORIZON_BASE_URL work by fetching all remote configs of the app.
- `horizon_create_crash_report` — Submits a crash (CRASH), a caught exception (NON_FATAL) or a freeze (ANR) to horizOn Crash Reporting, where it shows up in the dashboard.
- `horizon_create_crash_session` — Registers a game session so horizOn can calculate the crash-free rate. Call it once at app start with a new unique sessionId,
- `horizon_admin_crashes_listGroups` — Lists crash groups for the authenticated account. Groups represent unique crash signatures; each group has many occurrences. Results are paginated and sorted by
- `horizon_admin_crashes_getGroup` — Fetches a single crash group by its UUID, including title, status, counts, and affected version range.
- `horizon_admin_crashes_updateStatus` — Updates the status of a crash group (OPEN, RESOLVED, REGRESSED). Optionally record the version in which the crash was resolved — useful for regression detection
- `horizon_admin_crashes_updateNotes` — Updates the free-form notes stored on a crash group. Used for triage and hand-off comments between engineers.
- `horizon_admin_crashes_listOccurrences` — Lists individual crash report occurrences for a specific crash group. Results are paginated and sorted by createdAt DESC.
- `horizon_admin_crashes_getReport` — Fetches a single crash report occurrence by its UUID, including stack trace, breadcrumbs, device metadata, and session reference.
- `horizon_admin_crashes_getStats` — Fetches account-level crash reporting statistics (totalCrashes, crashFreeRate, affectedUsers, session counts, quota usage). The projectApiKeyId argument is acce
- `horizon_admin_crashes_deleteGroup` — Soft-deletes a crash group by its UUID. The group and its occurrences are excluded from lists and stats afterwards.
- `horizon_send_email` — Sends a transactional email to a registered horizOn user using a pre-configured template.
- `horizon_cancel_email` — Cancels a pending or scheduled email. Only emails with status 'pending' can be cancelled.
- `horizon_get_email_status` — Gets the current status of a specific email (pending, processing, sent, or failed).
- `horizon_admin_emailtemplates_list` — Lists all email templates for a specific project API key. The response omits the body to keep the payload small — use the get tool for full details.
- `horizon_admin_emailtemplates_get` — Fetches a single email template by UUID, including all language variants for subject and body.
- `horizon_admin_emailtemplates_create` — Creates a new email template for a project API key. Slug must be unique per project and match /^_?[a-z0-9][a-z0-9_-]*$/ (optional leading underscore is reserved
- `horizon_admin_emailtemplates_update` — Updates an email template. All fields are optional — only provided fields are overwritten.
- `horizon_admin_emailtemplates_delete` — Soft-deletes an email template. Any pending emails that reference this template will fail on delivery.
- `horizon_admin_emailtemplates_preview` — Renders a template preview with sample variable values. Does not send any email. The backend parameter name is 'language' (not 'lang').
- `horizon_admin_feedback_list` — Lists user feedback entries for the authenticated account. Results are paginated and sorted by createdAt DESC. Optionally filter by a specific project API key U
- `horizon_admin_feedback_get` — Fetches a single user feedback entry by its UUID, including the full message, associated user, and API key metadata.
- `horizon_submit_feedback` — Sends player feedback, such as a bug report, a feature request or a general comment, to the horizOn dashboard, where the developer reads it.
- `horizon_admin_giftcodes_list` — Lists gift codes for the authenticated account. The backend paginates and returns non-deleted codes; the projectApiKeyId filter is applied client-side by the ca
- `horizon_admin_giftcodes_get` — Fetches a single gift code by its UUID, including gift data, redemption counters, revocation status and expiration.
- `horizon_admin_giftcodes_create` — Creates a new gift code linked to a specific project API key. The code value is immutable once created; use update to change title/description/rewards/limits/ex
- `horizon_admin_giftcodes_update` — Updates mutable properties of an existing gift code. Only the provided fields are changed. The code value itself cannot be changed — create a new gift code inst

## Install

**Verdict: install** — No blocking findings and no open coverage gaps — safe to install as configured.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"horizon\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"horizon-mcp\"\n      ],\n      \"env\": {\n        \"HORIZON_API_KEY\": \"<YOUR_HORIZON_API_KEY>\",\n        \"HORIZON_ACCOUNT_API_KEY\": \"<YOUR_HORIZON_ACCOUNT_API_KEY>\"\n      }\n    }\n  }\n}"
```
**Credentials it will ask for** (names only — Forge never holds a value):
- `HORIZON_API_KEY` — Horizon API Key (optional)
- `HORIZON_ACCOUNT_API_KEY` — Horizon Account API Key (optional)
Placeholders only. Forge never holds, brokers, or transmits a credential value — replace each <YOUR_NAME> in your own config file. Do not send a value back to Forge; no Forge endpoint accepts one.
- This entry needs 2 credentials (0 required). The generated config carries placeholders, so it will fail in the editor rather than at runtime if they are left unset.

## Blast radius

Extensive blast radius — deletes data; holds an api key.
- Floor 55, ceiling 55 (tier: extensive)
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/horizon-mcp
- Install plan: https://forgeregistry.com/api/v1/packages/horizon-mcp/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/horizon-mcp
- HTML page: https://forgeregistry.com/registry/horizon-mcp
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
