matrix42-mcp

MCPattested
v0.1.6S&S Technologies GmbHMITUpdated 4d agonpmGitHub

Model Context Protocol server for Matrix42 — lets AI assistants explore the API, read the data model, search the service desk, and act on tickets

Works in
ClaudeCursorCopilotGemini

Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Attested build
A verified provenance attestation binds this artifact to the listed repository. Nobody has claimed the listing yet — this proves where the code was built, not who stands behind it.
259Downloads/wk
4d agoLast update
Needs 1 credential before it runs
  • M42_API_TOKENAPI keyrequired

    API token created in the Matrix42 Administration application

Declared by the author in the official MCP registry. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Package
AuthorS&S Technologies GmbH
LicenseMIT
Version0.1.6
Sourcenpm+mcp-registry
Trust Status
A
85/100Trusted
✓Listed in Forge index+10/10
✓Identity verified · attested build+20/20
—Ed25519 publish signature+0/5
→ Included automatically when the publisher runs `forge publish`
—Domain verification+0/5
→ Publisher: host /.well-known/forge.json on the package homepage with { "publisher": "<github-login>" }
✓npm Trusted Publishing (Sigstore)+5/5
—npm maintainer match+0/5
→ Publisher: add the verified GitHub login to the npm package's maintainers (npm owner add <login>)
✓CVE scan · clean+30/30
✓Static analysis · clean+20/20
Paste into Claude Code, Cursor, or any AI assistant to fix all gaps
StatusIdentity verified
PublisherUnverified
SignatureUnsigned
Domain—
Provenance✓ Sigstore-verified · 5415972
Dependencies✓ 4 resolved · none vulnerable
Tool surface19 tools · none privileged
Security scan✓ Cleanv0.1.6 · todayHow well does this scan work?
EvalsNone
IndexedOct 4, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

19 tools · none privileged
Statically extracted from the published packagev0.1.6 · 15h ago

Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.

data_queryRead records from the connected Matrix42 instance (read-only).

Read records from the connected Matrix42 instance (read-only).

No input schema was published for this tool.

explore_instanceSurvey an unfamiliar instance: what it runs, which modules are installed, and where the data you care about lives.

Survey an unfamiliar instance: what it runs, which modules are installed, and where the data you care about lives.

No input schema was published for this tool.

interestWhat you care about, e.g. "assets" or "the service desk"

What you care about, e.g. "assets" or "the service desk"

No input schema was published for this tool.

build_queryTurn a question in plain language into a correct ASQL query, checking every attribute name against the live schema before running it.

Turn a question in plain language into a correct ASQL query, checking every attribute name against the live schema before running it.

No input schema was published for this tool.

goalWhat you want to find, in plain language

What you want to find, in plain language

No input schema was published for this tool.

data_definitionTarget data definition, if you already know it

Target data definition, if you already know it

No input schema was published for this tool.

triage_ticketWork through one ticket: what it is, who it belongs to, what the service level says, and what should happen next.

Work through one ticket: what it is, who it belongs to, what the service level says, and what should happen next.

No input schema was published for this tool.

ticketTicket number, object id, or a description of it

Ticket number, object id, or a description of it

No input schema was published for this tool.

concernWhat you specifically want to know or decide

What you specifically want to know or decide

No input schema was published for this tool.

safe_changeWalk a write through the preview-then-confirm protocol, so nothing reaches the instance before you have seen exactly what it will send.

Walk a write through the preview-then-confirm protocol, so nothing reaches the instance before you have seen exactly what it will send.

No input schema was published for this tool.

intentThe change you want to make, in plain language

The change you want to make, in plain language

No input schema was published for this tool.

find_endpointLocate the operation that does what you need and read its real contract — for writing integration code against Matrix42.

Locate the operation that does what you need and read its real contract — for writing integration code against Matrix42.

No input schema was published for this tool.

taskWhat the integration needs to do

What the integration needs to do

No input schema was published for this tool.

languageLanguage or tool you are writing it in

Language or tool you are writing it in

No input schema was published for this tool.

schema_discoveryExplore the Matrix42 data model of the connected instance (read-only metadata).

Explore the Matrix42 data model of the connected instance (read-only metadata).

No input schema was published for this tool.

server_infoReport which Matrix42 instance this MCP server is connected to (base URL, authentication mode, response language), which account the credentials authenticate as, and whether the connection works. Use the reported user fragment id to answer "my items" questions. Never returns credentials.

Report which Matrix42 instance this MCP server is connected to (base URL, authentication mode, response language), which account the credentials authenticate as, and whether the connection works. Use the reported user fragment id to answer "my items" questions. Never returns credentials.

No input schema was published for this tool.

service_deskRead the service desk and the business objects around it.

Read the service desk and the business objects around it.

No input schema was published for this tool.

ticket_actionsMODIFIES Matrix42 data. Every action here previews first: called WITHOUT confirm:true it returns the exact request it would send and changes nothing, so show that preview to the user and only then call again with confirm:true.

MODIFIES Matrix42 data. Every action here previews first: called WITHOUT confirm:true it returns the exact request it would send and changes nothing, so show that preview to the user and only then call again with confirm:true.

No input schema was published for this tool.

webservice_discoveryDiscover the Matrix42 REST API of the connected instance (read-only metadata).

Discover the Matrix42 REST API of the connected instance (read-only metadata).

No input schema was published for this tool.

19 of 19 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

Model Context Protocol server for Matrix42 — lets AI assistants explore the API, read the data model, search the service desk, and act on tickets

Keywords
mcpmodelcontextprotocolmodel-context-protocolmatrix42itsmesmaillmservice-deskitilmatrix42-apiclaudemcp-server
Alternatives
Comparing tool surfaces…

Dependency tree

What one Forge scan resolved from npm metadata on 2026-10-04 — observed resolution, not a publisher declaration.

4 packages resolved · 3 direct · none carrying advisories Resolution stops at depth 4 and 60 packages.