Back to Browse

Mcp MCP Server

Developer ToolsModerate6.6MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Manage Cosmic CMS content, media, object types, and AI generation from any MCP client.

About

Manage Cosmic CMS content, media, object types, and AI generation from any MCP client.

Remote endpoints: streamable-http: https://mcp.cosmicjs.com/v1/buckets/{bucket_slug}

Security Report

6.6
Moderate6.6Moderate Risk

This is a well-structured MCP server for Cosmic CMS with proper authentication, authorization controls, and appropriate permissions scoping. The code demonstrates good security practices including write-access checks, input validation via Zod schemas, and proper error handling. No critical vulnerabilities or malicious patterns were identified. Minor code quality observations do not significantly impact security. Supply chain analysis found 2 known vulnerabilities in dependencies (0 critical, 1 high severity). Package verification found 1 issue.

6 files analyzed · 7 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Slug of the Cosmic bucket to operate onOptional

Environment variable: COSMIC_BUCKET_SLUG

Bucket read key. Enables the read-only toolsRequired

Environment variable: COSMIC_READ_KEY

Bucket write key. Required for create, update, delete, and AI generationRequired

Environment variable: COSMIC_WRITE_KEY

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

Cosmic MCP Server

An MCP (Model Context Protocol) server that exposes Cosmic CMS functionality as tools for AI assistants. Manage your content, media, object types, and generate AI content directly through Claude, Cursor, or any MCP-compatible client.

Features

  • Content Management: Create, read, update, and delete objects in your Cosmic bucket
  • Media Management: Upload, list, and manage media files
  • Schema Management: Create and modify object types with custom metafields
  • AI Generation: Generate text, images, and videos using Cosmic's AI capabilities

Hosted endpoint (recommended)

Cosmic operates a hosted streamable-HTTP MCP server. No install required.

URL: https://mcp.cosmicjs.com/v1/buckets/{bucket-slug}

Cosmic uses separate read and write keys per bucket. Authenticate with one of:

Authorization: Bearer <read_key>                       # read-only tools
Authorization: Bearer <read_key>:<write_key>           # full access

You can also send the write key out-of-band via the X-Cosmic-Write-Key header if your client can't colon-pack the bearer token. Keys are issued in your bucket's API Access settings in the Cosmic dashboard.

Use the read key for read-only access (list/get tools), or the write key for full access including object creation, media upload, and AI generation.

Claude Desktop (remote MCP)

In Claude Desktop, Settings -> Connectors -> Add custom connector, enter:

  • URL: https://mcp.cosmicjs.com/v1/buckets/your-bucket-slug
  • Bearer token: <read_key> for read-only access, or <read_key>:<write_key> for full access

Cursor (remote MCP)

Add to .cursor/mcp.json:

{
  "mcpServers": {
    "cosmic": {
      "url": "https://mcp.cosmicjs.com/v1/buckets/your-bucket-slug",
      "headers": {
        "Authorization": "Bearer your-bucket-read-key:your-bucket-write-key"
      }
    }
  }
}

Local installation (stdio)

For environments without remote MCP support, the same server runs locally over stdio.

Using npx (recommended)

npx @cosmicjs/mcp

Global installation

npm install -g @cosmicjs/mcp
cosmic-mcp

From source

git clone https://github.com/cosmicjs/mcp.git
cd mcp
bun install
bun run build

Configuration

The server requires the following environment variables:

VariableRequiredDescription
COSMIC_BUCKET_SLUGYesYour Cosmic bucket slug
COSMIC_READ_KEYYesBucket read key for read operations
COSMIC_WRITE_KEYNoBucket write key for write operations

Getting your credentials

  1. Log in to your Cosmic dashboard
  2. Navigate to your bucket
  3. Go to SettingsAPI Access
  4. Copy your bucket slug, read key, and write key

Local stdio with Claude Desktop

If you prefer to run the MCP server locally rather than use the hosted endpoint, add the following to your Claude Desktop configuration file.

macOS: ~/Library/Application Support/Claude/claude_desktop_config.json Windows: %APPDATA%\Claude\claude_desktop_config.json

{
  "mcpServers": {
    "cosmic": {
      "command": "npx",
      "args": ["@cosmicjs/mcp"],
      "env": {
        "COSMIC_BUCKET_SLUG": "your-bucket-slug",
        "COSMIC_READ_KEY": "your-read-key",
        "COSMIC_WRITE_KEY": "your-write-key"
      }
    }
  }
}

Local stdio with Cursor

{
  "mcpServers": {
    "cosmic": {
      "command": "npx",
      "args": ["@cosmicjs/mcp"],
      "env": {
        "COSMIC_BUCKET_SLUG": "your-bucket-slug",
        "COSMIC_READ_KEY": "your-read-key",
        "COSMIC_WRITE_KEY": "your-write-key"
      }
    }
  }
}

Available Tools

Objects

ToolDescription
cosmic_objects_listList objects with optional type filter, status, and pagination
cosmic_objects_getGet a single object by ID or slug
cosmic_objects_createCreate a new object (requires write key)
cosmic_objects_updateUpdate an existing object (requires write key)
cosmic_objects_deleteDelete an object (requires write key)

Media

ToolDescription
cosmic_media_listList media files with optional folder filter
cosmic_media_getGet media details by ID
cosmic_media_uploadUpload media from URL or base64 (requires write key)
cosmic_media_deleteDelete a media file (requires write key)

Object Types

ToolDescription
cosmic_types_listList all object types in the bucket
cosmic_types_getGet object type schema by slug
cosmic_types_createCreate a new object type (requires write key)
cosmic_types_updateUpdate object type schema (requires write key)
cosmic_types_deleteDelete an object type (requires write key)

AI Generation

ToolDescription
cosmic_ai_generate_textGenerate text content using AI
cosmic_ai_generate_imageGenerate and upload an AI image (requires write key)
cosmic_ai_generate_videoGenerate and upload an AI video (requires write key)

Content Blocks

ToolDescription
cosmic_blocks_listList the bucket's reusable rich-text Content Blocks (the {{name /}} tokens available in rich-text fields)

Example Prompts

Here are some example prompts you can use with Claude or Cursor:

Content Management

List all blog posts in my Cosmic bucket
Create a new blog post titled "Getting Started with MCP" with the content "This is an introduction to the Model Context Protocol..."
Update the blog post with ID "abc123" to change its status to published

Media

Show me all images in the "blog-images" folder
Upload this image URL to my media library: https://example.com/image.jpg

Schema Management

Show me all object types in my bucket
Create a new object type called "Products" with fields for name, price, description, and image

AI Generation

Generate a product description for a wireless bluetooth headphone
Generate an image of a futuristic city skyline at sunset and upload it to my media library

Development

Build

bun run build

This produces two binaries:

  • dist/stdio.js - npm-published stdio entry (bin: cosmic-mcp)
  • dist/http.js - hosted streamable-HTTP entry (deployed to ECS Fargate)

Watch mode (stdio)

bun run dev

Run locally (stdio)

COSMIC_BUCKET_SLUG=your-bucket \
COSMIC_READ_KEY=your-read-key \
COSMIC_WRITE_KEY=your-write-key \
bun run start

Run locally (HTTP)

bun run dev:http
# Server listens on http://localhost:3000
# POST http://localhost:3000/v1/buckets/{slug} with Authorization: Bearer <key>

Deployment

Pushes to main deploy to https://mcp.cosmicjs.com via GitHub Actions. Workflow: .github/workflows/deploy.yml.

Releasing to npm

Releases are driven by Changesets. Every change that should ship adds a changeset (bunx changeset) describing the bump (patch | minor | major).

To cut a release, run one command from a clean main:

bun run release

This consumes the pending changesets to bump the version, refreshes the lockfile, commits chore(release): vX.Y.Z, then tags and pushes. It prompts once before the tag push (pass -- --yes to skip). Pushing the tag triggers the publish.yml workflow, which verifies the tag matches package.json, builds, and runs npm publish --provenance --access public (requires the NPM_TOKEN repo secret).

Do not hand-edit the version field in package.json; let the changeset bump it. The release also runs scripts/sync-version.mjs, which copies the new version into server.json and SERVER_VERSION in src/server.ts so all three always agree. If you ever need to publish directly from your machine (with a local npm token, no provenance), bun run release:direct runs changeset publish.

Publishing to the MCP registry

The server is listed on registry.modelcontextprotocol.io under the com.cosmicjs namespace, described by server.json.

Order matters: the registry verifies the listing against what is actually on npm, so release to npm first and publish the listing second. mcpName in package.json must always equal name in server.json, which is how the registry proves we own the npm package.

One-time setup to prove domain ownership. This uses ECDSA P-384 because macOS ships LibreSSL, which cannot generate Ed25519 keys (brew install openssl@3 if you prefer Ed25519):

openssl genpkey -algorithm EC -pkeyopt ec_paramgen_curve:secp384r1 -out key.pem

PUBLIC_KEY="$(openssl ec -in key.pem -text -noout -conv_form compressed | grep -A4 "pub:" | tail -n +2 | tr -d ' :\n' | xxd -r -p | base64)"
echo "cosmicjs.com. IN TXT \"v=MCPv1; k=ecdsap384; p=${PUBLIC_KEY}\""

Add that TXT record on the apex of cosmicjs.com. A selector such as _mcp-auth.cosmicjs.com will not be found and fails with a generic signature error. The apex TXT set also holds the SPF and Google verification records, so append to it rather than replacing it. Keep key.pem out of the repo; it lives in ~/.cosmic-mcp/key.pem.

Then, after each npm release, publish the listing (brew install mcp-publisher first):

PRIVATE_KEY="$(openssl ec -in ~/.cosmic-mcp/key.pem -noout -text | grep -A4 "priv:" | tail -n +2 | tr -d ' :\n')"
mcp-publisher login dns --algorithm ecdsap384 --domain cosmicjs.com --private-key "${PRIVATE_KEY}"
mcp-publisher publish

--algorithm ecdsap384 is required. The publisher defaults to ed25519 and rejects the P-384 key with invalid seed length: expected 32 bytes, got 48, which reads like a corrupt key rather than a wrong algorithm.

API Reference

For more information about the Cosmic API, see:

License

MIT

Contributing

Contributions are welcome! Please open an issue or submit a pull request.

Support

Reviews

No reviews yet

Be the first to review this server!