SimplePractice Client Portal — appointments, billing, documents, announcements
About
SimplePractice Client Portal — appointments, billing, documents, announcements
Security Report
This MCP server for SimplePractice Client Portal demonstrates solid security practices with proper authentication, read-only operations, and careful API interaction patterns. Session management uses secure file storage with appropriate permissions (0600), and sensitive data like payment card numbers are properly filtered from output. Minor code quality observations exist around error handling breadth and input validation, but these do not introduce meaningful security vulnerabilities. Permissions align well with the server's purpose of reading client portal data. Supply chain analysis found 2 known vulnerabilities in dependencies (0 critical, 1 high severity). Package verification found 1 issue.
7 files analyzed · 7 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
What You'll Need
Set these up before or after installing:
Environment variable: SIMPLEPRACTICE_PRACTICE
Environment variable: SIMPLEPRACTICE_SESSION_FILE
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-chrischall-simplepractice-mcp": {
"env": {
"SIMPLEPRACTICE_PRACTICE": "your-simplepractice-practice-here",
"SIMPLEPRACTICE_SESSION_FILE": "your-simplepractice-session-file-here"
},
"args": [
"-y",
"simplepractice-mcp"
],
"command": "npx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
simplepractice-mcp
MCP server for the SimplePractice Client Portal — the side a practice's clients log into, not the clinician side. Appointments, billing, paperwork, and announcements, read over the portal's own JSON:API.
Developed and maintained by AI (Claude Code). Use at your own discretion.
What it reads
| Tool | What it gives you |
|---|---|
simplepractice_get_account | practice, current client, every client this login covers, cancellation policy, feature permissions |
simplepractice_list_appointments | scheduled or requested appointments, with clinician and location |
simplepractice_list_billing_items | invoices · statements · superbills · receipts · account history |
simplepractice_get_billing_overview | balance due and per-category counts |
simplepractice_list_payment_methods | saved cards — brand, last four, expiry |
simplepractice_list_document_requests | paperwork sent to you, with an outstanding-only filter |
simplepractice_get_document_request | one request in full, with its questions and answers |
simplepractice_list_documents | files the practice has shared |
simplepractice_list_announcements | practice announcements, with unread counts |
simplepractice_session_status · _request_sign_in_link · _verify_sign_in_token · _verify_sign_in_pin · _sign_out | sign-in |
Everything is read-only. Cancelling, signing, and paying happen in the portal.
Setup
npm install -g simplepractice-mcp
export SIMPLEPRACTICE_PRACTICE=achievebalancetherapy # or the full host
SIMPLEPRACTICE_PRACTICE is the practice's portal address — the slug or the
whole <practice>.clientsecure.me host from the link your provider emailed.
| Variable | |
|---|---|
SIMPLEPRACTICE_PRACTICE | required — portal slug or host |
SIMPLEPRACTICE_SESSION_FILE | optional — session path (default ~/.simplepractice-mcp/session.json, written 0600) |
Signing in
The Client Portal has no password. SimplePractice emails a one-time link (or a 6-digit PIN); you trade it for a session cookie:
simplepractice_request_sign_in_link { email, confirm: true }- Open the email, copy the link.
simplepractice_verify_sign_in_token { link }— pass the whole link; the token is its#fragment and the tool extracts it.
Links are single-use — replaying one answers
401 "Authorization has already been used or expired" — and last 24 hours. The
request endpoint is rate-limited per address and per IP, which is why
sending is confirm-gated: a retry loop locks you out of the only way in. There
is no refresh token; when the session lapses, you sign in again.
The whole chain is verified end to end against a live portal — request, the
emailed link, the exchange returning verified plus a session cookie, and an
authenticated read with that new session.
Because that flow needs nothing but HTTP and your inbox, this server has no browser dependency and can run anywhere.
Without the server
skills/simplepractice-fpx does the same reads with curl, either signing in
by magic link or lifting the session cookie from a browser tab with
fpx.
Notes from building this
The portal is an Ember app that ships public sourcemaps, so its models,
adapters and routes are readable directly — docs/SIMPLEPRACTICE-API.md
records the endpoints and the traps, all confirmed against a live portal:
- The SPA catch-all answers HTTP 200 with
text/htmlfor any path the API does not define./cardsand/client-billing-overviewslook like working, empty endpoints and are not endpoints at all — both areincluderelationships of/clients/<id>. hasDocumentPdf, a card'sisDefault, and the client'spermissionsblob are all strings, not booleans or objects.- Billing pages by cursor (
page[before]= a row'scursorId), appointments page by number. The two are not interchangeable.
Development
npm install
npm run build
npm test # 151 tests
npm run test:coverage # 100% enforced
npm run typecheck # vitest does not run tsc — this does
License
MIT
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.