Back to Browse

Golf MCP Server

Developer ToolsLow Risk10.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

Proprietary mapped golf courses (laser, drone, satellite). 20 years, daily updates. Search is free.

About

Proprietary mapped golf courses (laser, drone, satellite). 20 years, daily updates. Search is free.

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (1 strong, 1 medium validity signals). No known CVEs in dependencies. Imported from the Official MCP Registry.

4 files analyzed · No issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

file_system

Check that this permission is expected for this type of plugin.

Shell Command Execution

Runs commands on your machine. Be cautious — only use if you trust this plugin.

What You'll Need

Set these up before or after installing:

Client ID from API Account at https://console.golfintelligence.com/.Optional

Environment variable: GI_CLIENT_ID

Active Token from API Account at https://console.golfintelligence.com/. It is exchanged for a bearer token; do not enter a bearer token.Required

Environment variable: GI_ACTIVE_TOKEN

Documentation

View on GitHub

From the project's GitHub README.

Golf Intelligence, by Stracka

Golf Intelligence, by Stracka. The highest-quality golf course dataset for developers building a golf app. 20 years of proprietary mapping (laser, drone, airplane, satellite), updated daily. Search is free. Scorecards, GPS, and 3D greens via API. Not a scrape.

Golf Intelligence is a proprietary dataset built through course-by-course mapping, not a clone of a GitHub golf course API. Ten people map every day, and the data has been continuously updated since 2007. Learn more at golfintelligence.com.

This repository is the installable Cursor / Grok Bot plugin with handle golf. The Cursor marketplace application source is the public GitHub URL:

https://github.com/golf-data/golf

Marketplace reviewers can submit that URL at cursor.com/marketplace/publish. The catalog title is Golf Intelligence, by Stracka.

The official MCP Registry name is io.github.golf-data/golf. The registry does not accept a bare golf name. Cursor, Agent Plugins, and Claude Code plugin handles remain golf.

Get API access

Create an API Account at console.golfintelligence.com, then configure the plugin's two required variables:

  • GI_CLIENT_ID: your Client ID
  • GI_ACTIVE_TOKEN: your Active Token

The Active Token is exchanged for a short-lived bearer token. It is not a bearer token; do not paste a bearer token into GI_ACTIVE_TOKEN.

Plans:

  • Personal: $49 for 50 test credits for your own-game Cursor, Grok, or Claude app. Buy Personal.
  • Starter: $399/month for 10,000 credits when shipping an app to other users. Email data@golfintelligence.com; Starter does not have a checkout link.

Questions about data, plans, or integration: data@golfintelligence.com.

Tools and credits

Always search first. search_course_groups is free. Before every paid call, the user must explicitly confirm the stated cost; the server refuses paid tools unless confirm_spend=true.

ToolWhat it returnsCredits
search_course_groupsCourse-group search results0
get_course_group_scorecardScorecard data1
get_course_group_gpsMapped course geometry and coordinates2
get_course_group_detailDetailed course-group data3
get_green_slope_imagePortrait or square green slope image1

Authentication

The server exchanges the configured credentials with:

POST https://api.golfintelligence.com/auth/authenticateToken
grant_type=client_credentials
code=<GI_ACTIVE_TOKEN>
client_id=<GI_CLIENT_ID>

It sends the returned access_token as Authorization: Bearer <access_token>, caches it only in memory, and refreshes once after an HTTP 401. Credentials are never logged.

Streamable HTTP

The production HTTP entrypoint serves the official MCP Streamable HTTP transport at /mcp and a health check at /health. The intended custom-domain URL shape is:

https://mcp.golfintelligence.com/mcp

This repository does not claim that URL is live; DNS and deployment must be completed before it is submitted for review. Start the HTTP server locally with:

npm run build
PORT=3000 npm run start:http

It binds to 0.0.0.0:$PORT. The existing node dist/index.js stdio entrypoint and all plugin packages remain unchanged.

The HTTP service resolves Golf Intelligence credentials in this order:

  1. X-GI-Client-ID and X-GI-Active-Token HTTP headers supplied together on every MCP request.
  2. Server-side GI_CLIENT_ID and GI_ACTIVE_TOKEN environment variables.

Codex supports static http_headers and environment-backed env_http_headers for Streamable HTTP MCP servers. For OpenAI review, either configure a dedicated review API account as deployment environment variables or provide the two custom headers if the review configuration supports them. The Active Token remains an exchange credential and must not be sent as an Authorization: Bearer value. A production deployment should use a dedicated account with an appropriate credit limit because environment-based credentials make the lookup tools available to every caller of the public endpoint.

Every tool explicitly advertises these MCP annotations:

  • readOnlyHint: true — each tool only retrieves course data.
  • openWorldHint: false — no tool writes to public or external systems.
  • destructiveHint: false — no tool deletes, overwrites, publishes, or sends anything.
  • idempotentHint: true — repeating a lookup has no additional side effect.

These sentences can also be used as the annotation justifications in the OpenAI submission form. Paid lookups still require confirm_spend=true at the same credit costs documented above.

Container deployment

Dockerfile builds both transports without embedding credentials. fly.toml configures a small Fly.io service and checks /health. Before the first deploy, confirm that the globally unique Fly app name is available (or change app), then set runtime secrets and deploy:

fly secrets set GI_CLIENT_ID=... GI_ACTIVE_TOKEN=...
fly deploy

Set the custom domain only after the deployed *.fly.dev endpoint passes an MCP Inspector check. No deployment is performed by this repository.

Repository layout

  • .cursor-plugin/plugin.json — Cursor marketplace manifest and required variables
  • plugin.json — Agent Plugins open-standard manifest (handle golf)
  • .claude-plugin/plugin.json — Claude Code / Cowork plugin manifest (handle golf)
  • server.json — official MCP Registry metadata (io.github.golf-data/golf)
  • manifest.json — MCPB bundle manifest for the stdio Node server
  • .github/workflows/publish-mcp.yml — publishes io.github.golf-data/golf to the official MCP Registry via GitHub OIDC
  • mcp.json — bundled golf MCP server configuration
  • skills/golf/SKILL.md — workflow and spend-confirmation guidance
  • src/ — TypeScript MCP server and API client
  • dist/index.js — committed stdio ESM bundle used by installers
  • dist/http.js — committed Streamable HTTP ESM bundle used by the container
  • Dockerfile and fly.toml — production HTTP container and Fly.io service

For development with Node.js 18 or newer:

npm install
npm test
npm run build
npm run pack:mcpb

pack:mcpb uses the official @anthropic-ai/mcpb pack CLI to produce golf.mcpb and writes its SHA-256 into server.json. GitHub Releases host that asset at https://github.com/golf-data/golf/releases/download/v1.0.0/golf.mcpb.

The plugin code is available under the MIT License. Golf Intelligence API data remains subject to the terms at golfintelligence.com.

Reviews

No reviews yet

Be the first to review this server!