{"_id":"@addiplus/vercel-deployment-mcp","_rev":"3-1b7428f1eec06168dc27a607423139b0","name":"@addiplus/vercel-deployment-mcp","dist-tags":{"latest":"0.2.1"},"versions":{"0.1.0":{"name":"@addiplus/vercel-deployment-mcp","version":"0.1.0","license":"MIT","_id":"@addiplus/vercel-deployment-mcp@0.1.0","maintainers":[{"name":"addiplus","email":"8ice8fire8@gmail.com"}],"homepage":"https://github.com/addiplus/vercel-deployment-mcp#readme","bugs":{"url":"https://github.com/addiplus/vercel-deployment-mcp/issues"},"bin":{"vercel-deployment-mcp":"dist/index.js"},"dist":{"shasum":"08ff46c4e227c0c643f3deb481977241f5403a1f","tarball":"https://registry.npmjs.org/@addiplus/vercel-deployment-mcp/-/vercel-deployment-mcp-0.1.0.tgz","fileCount":6,"integrity":"sha512-bCxMSy8ubaGovbVdjpwq1S4ApPmBhzhqmIvE1Ig7yUoY/w6cWCZT6GtPtuQxpTTxYxHP6wycMv+lnM+1hQXFnw==","signatures":[{"sig":"MEUCIQDqmZ/uTjySQAR3m1q/4Qv348kC/a7wYPI2iq6gHce9CwIgLm0sBwEyECUsmc/AA1mdkafWsUQjFKCBBVPZcriUaRs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":14726},"main":"dist/index.js","type":"module","engines":{"node":">=18"},"gitHead":"5f8637689d004598790605ec9bbf2b8e99ada8ac","mcpName":"io.github.addiplus/vercel-deployment-mcp","scripts":{"test":"vitest run","build":"tsc -p tsconfig.json","start":"node dist/index.js","pretest":"npm run build","prepublishOnly":"npm run build && npm test"},"_npmUser":{"name":"addiplus","email":"8ice8fire8@gmail.com"},"repository":{"url":"git+https://github.com/addiplus/vercel-deployment-mcp.git","type":"git"},"_npmVersion":"11.12.1","description":"Reference MCP server for observing Vercel projects and deployments — a stateless stdio server demonstrating clean configuration and credential handling for deployment workflows.","directories":{},"_nodeVersion":"24.14.1","dependencies":{"zod":"^4.4.3","@modelcontextprotocol/sdk":"^1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/vercel-deployment-mcp_0.1.0_1783593713155_0.08996377021960633","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@addiplus/vercel-deployment-mcp","version":"0.2.0","license":"MIT","_id":"@addiplus/vercel-deployment-mcp@0.2.0","maintainers":[{"name":"addiplus","email":"8ice8fire8@gmail.com"}],"homepage":"https://github.com/addiplus/vercel-deployment-mcp#readme","bugs":{"url":"https://github.com/addiplus/vercel-deployment-mcp/issues"},"bin":{"vercel-deployment-mcp":"dist/index.js"},"dist":{"shasum":"e344cbb4af744952208d5bfa5a26d36aebe1a45f","tarball":"https://registry.npmjs.org/@addiplus/vercel-deployment-mcp/-/vercel-deployment-mcp-0.2.0.tgz","fileCount":6,"integrity":"sha512-A6HfT7d4HWtJl8GRsEOiQgElW29VPj3ovfyj2eTSennvz/eGqoIThfOgTzY/FhU7b1IddRwsFalF2+uEGIr0TQ==","signatures":[{"sig":"MEYCIQDhGkY8MQU5GmBMt8aIRtysB4PTAENeZVZw4llqdgCMPQIhAKsMzz+PGCqtjqqiPNfN8FL1GqnKeISWAS0u5MJLOfbY","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":25453},"main":"dist/index.js","type":"module","engines":{"node":">=18"},"gitHead":"4d0784eabc407db06e5944142800e1642acfd359","mcpName":"io.github.addiplus/vercel-deployment-mcp","scripts":{"test":"vitest run","build":"tsc -p tsconfig.json","start":"node dist/index.js","pretest":"npm run build","prepublishOnly":"npm run build && npm test"},"_npmUser":{"name":"addiplus","email":"8ice8fire8@gmail.com"},"repository":{"url":"git+https://github.com/addiplus/vercel-deployment-mcp.git","type":"git"},"_npmVersion":"11.12.1","description":"Reference MCP server for observing Vercel projects and deployments — a stateless stdio server demonstrating clean configuration and credential handling for deployment workflows.","directories":{},"_nodeVersion":"24.14.1","dependencies":{"zod":"^4.4.3","@modelcontextprotocol/sdk":"^1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"8.20.0","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"tmp":"tmp/vercel-deployment-mcp_0.2.0_1783736165061_0.8945520069428112","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"_id":"@addiplus/vercel-deployment-mcp@0.2.1","bin":{"vercel-deployment-mcp":"dist/index.js"},"bugs":{"url":"https://github.com/addiplus/vercel-deployment-mcp/issues"},"dist":{"shasum":"f90fbf1817a98c1dfe9ee015e504e8393e077b50","tarball":"https://registry.npmjs.org/@addiplus/vercel-deployment-mcp/-/vercel-deployment-mcp-0.2.1.tgz","fileCount":6,"integrity":"sha512-sDsCT465GylesjYlEkHL4linrSO/IEcGJL9pa7joS19wfmat1Kam/mB7g+nfwpaFyhdeTYAFQRhaI2ANgvV7Dw==","signatures":[{"sig":"MEUCICSoCe74nYuPXnXAdQS/6cM+m3a+QQHePHk/KOqlZNhgAiEAggZJocNgbmfwOLqVTo/8fLbTsUzAhvXhb/wi5/Sbkd0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCICE/C0JsnglaIoqzriaKSgD/+OVh365VyCwKXyCouY8YAiEAi8BMzl8HUvr0neqCP3vLj+faCA4qepxAPfwb0mPKwQk="}],"unpackedSize":39773},"main":"dist/index.js","name":"@addiplus/vercel-deployment-mcp","type":"module","engines":{"node":">=18"},"gitHead":"6911b5b7e7612083b18b0f420345a012d3042b88","license":"MIT","mcpName":"io.github.addiplus/vercel-deployment-mcp","scripts":{"test":"vitest run","build":"tsc -p tsconfig.json","start":"node dist/index.js","pretest":"npm run build","prepublishOnly":"npm run build && npm test"},"version":"0.2.1","_npmUser":{"name":"addiplus","email":"8ice8fire8@gmail.com"},"homepage":"https://github.com/addiplus/vercel-deployment-mcp#readme","repository":{"url":"git+https://github.com/addiplus/vercel-deployment-mcp.git","type":"git"},"_npmVersion":"11.19.1","description":"Reference MCP server for observing Vercel projects and deployments. A stateless stdio server demonstrating clean configuration and credential handling for deployment workflows.","directories":{},"maintainers":[{"name":"addiplus","email":"8ice8fire8@gmail.com"}],"_nodeVersion":"26.8.2","dependencies":{"zod":"^4.4.3","@modelcontextprotocol/sdk":"^1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"8.20.0","vitest":"^4.1.10","typescript":"^7.0.2","@types/node":"^26.1.1"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/vercel-deployment-mcp_0.2.1_1789513799963_0.7392391275140724"}}},"time":{"created":"2026-07-09T10:41:53.022Z","modified":"2026-09-15T23:10:00.224Z","0.1.0":"2026-07-09T10:41:53.301Z","0.2.0":"2026-07-11T02:16:05.226Z","0.2.1":"2026-09-15T23:10:00.063Z"},"bugs":{"url":"https://github.com/addiplus/vercel-deployment-mcp/issues"},"license":"MIT","homepage":"https://github.com/addiplus/vercel-deployment-mcp#readme","repository":{"url":"git+https://github.com/addiplus/vercel-deployment-mcp.git","type":"git"},"description":"Reference MCP server for observing Vercel projects and deployments. A stateless stdio server demonstrating clean configuration and credential handling for deployment workflows.","maintainers":[{"name":"addiplus","email":"8ice8fire8@gmail.com"}],"readme":"# vercel-deployment-mcp\n\n[![CI](https://github.com/addiplus/vercel-deployment-mcp/actions/workflows/ci.yml/badge.svg)](https://github.com/addiplus/vercel-deployment-mcp/actions/workflows/ci.yml)\n\nA reference [Model Context Protocol](https://modelcontextprotocol.io) server for\nobserving Vercel projects and deployments over stdio.\n\nThis is a community reference implementation focused on deployment-workflow\npatterns. It is not a replacement for Vercel's own MCP offering. Its purpose\nis to demonstrate, in a small and readable codebase, how a deployment-focused\nMCP server can handle configuration cleanly and behave predictably on\nshort-lived infrastructure.\n\n## Tools\n\n| Tool | Description |\n| --- | --- |\n| `list_projects` | List projects visible to the configured account/team (search, limit) |\n| `get_project` | Fetch one project by ID or name |\n| `list_deployments` | List recent deployments (filter by project, state, limit) |\n| `get_deployment` | Fetch one deployment by ID or URL, including current state |\n\n`list_projects` and `list_deployments` each return a single page of up to\n`limit` results (default 20, max 100). There is no cursor pagination; narrow\nthe request with `search`, `projectId`, or `state` to see more specific\nresults.\n\n## Install\n\nFrom npm:\n\n```bash\nnpm install @addiplus/vercel-deployment-mcp\n```\n\nOr run it directly without installing:\n\n```bash\nnpx @addiplus/vercel-deployment-mcp\n```\n\nFrom source:\n\n```bash\ngit clone https://github.com/addiplus/vercel-deployment-mcp.git\ncd vercel-deployment-mcp\nnpm install\nnpm run build\nnpm test\n```\n\nRunning the test suite needs a newer Node than the server does. vitest 4.1.10\ndeclares `engines.node` of `^20.0.0 || ^22.0.0 || >=24.0.0`, and the vite 8.1.3\nthis lockfile pins narrows that to `^20.19.0 || >=22.12.0`. The suite runs on\nthe intersection of the two, `^20.19.0 || ^22.12.0 || >=24.0.0`: the 20 line\nfrom 20.19.0, the 22 line from 22.12.0, and 24 and above. The 23 line is\noutside it, because vitest does not cover 23. CI runs 22 and 24. The published\npackage itself still runs on Node >=18 per `engines`.\n\n## Configuration\n\n| Variable | Required | Purpose |\n| --- | --- | --- |\n| `VERCEL_TOKEN` | yes | Vercel access token (create in account settings) |\n| `VERCEL_TEAM_ID` | no | Scope requests to a team |\n| `VERCEL_MCP_MIN_INTERVAL_MS` | no | Minimum milliseconds between the start of one Vercel API request and the next (default `250`) |\n| `VERCEL_MCP_MAX_CONCURRENT` | no | Maximum number of Vercel API requests in flight at once (default `4`) |\n\nOn an HTTP 429 with a numeric `Retry-After` header of 10 seconds or less, the\nserver waits that long and retries the request once; any other 429 is\nsurfaced as an error on the first attempt.\n\n### Limits\n\n| Limit | Value |\n| --- | --- |\n| Longest `search` value | 4096 characters |\n| Longest `projectId`, `state`, `idOrName`, `idOrUrl` value | 512 characters |\n| Largest accepted protocol frame | 10485760 bytes |\n| Highest accepted `VERCEL_MCP_MIN_INTERVAL_MS` | 60000 |\n\nThe frame limit counts the message and not the newline that delimits it, so a\nmessage of exactly 10485760 bytes is accepted. Everything before that newline is\nthe message, a carriage return sitting just in front of it included.\n\nEach of these limits has its own behaviour above the value in the table. An\nover-long argument fails input validation: the call comes back as a JSON-RPC\n`-32602` invalid-params result, no Vercel API request is made, and nothing is\nwritten to stderr for it. A frame above the frame limit is dropped, one line on\nstderr says so, and the connection keeps serving. An interval above the ceiling\nis not refused, it is reduced to the ceiling: the server runs with the reduced\nvalue, and one line on stderr says so the first time it makes a Vercel API\nrequest. The same stderr report repeated back to back is written twice at most,\nthe second time to say that further identical reports are suppressed.\n\n`initialize` and `ping` are answered at any time. `tools/list` and `tools/call`\nare answered only once the client has completed the initialization handshake:\nan `initialize` request the server can answer, followed by\n`notifications/initialized`. Both halves are required, so the notification on\nits own completes nothing, and neither does an `initialize` the server rejects.\nA client that writes both halves and its first call in a single write is\nserved, rather than being refused for not waiting for the initialize response. Before the\nhandshake, those two methods are refused with JSON-RPC error `-32600` and no\nVercel API request is made.\n\nExample client configuration (Claude Desktop / Claude Code):\n\n```json\n{\n  \"mcpServers\": {\n    \"vercel-deployment\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@addiplus/vercel-deployment-mcp\"],\n      \"env\": { \"VERCEL_TOKEN\": \"…\" }\n    }\n  }\n}\n```\n\nWhen running from a source checkout, use `\"command\": \"node\"` with\n`\"args\": [\"/path/to/vercel-deployment-mcp/dist/index.js\"]` instead.\n\n## Design principles\n\nFirst written 2026-07-10 and kept current with the code since; claim 1 was\nrestated when error text began being redacted once, where it becomes\nclient-visible. Each claim below is implemented in code and verified by the\ntest suite where testable (`test/`); design properties cite the implementing\ncode.\n\n1. **Configured values never appear in an error.** The access token is read\n   only from the environment. Error text is shaped, size-bounded, and passed\n   through a redaction guard once, where it becomes client-visible text, so\n   an upstream API message cannot echo the token or the team id back\n   (`src/vercel.ts`); the fixed hint appended after that bound is text this\n   server writes and carries nothing to replace. A successful result is a fixed\n   projection of the\n   upstream body and is not redacted, so a team identifier that the Vercel\n   API itself returns inside a deployment URL still appears there.\n2. **stdout belongs to the protocol.** All diagnostics go to stderr\n   (`src/index.ts`), so no log line can leak into a tool response.\n3. **Minimal footprint.** The tools are read-only observations of projects\n   and deployments; the server requests nothing beyond what those reads need.\n4. **Stateless by design.** Configuration is re-read from the environment on\n   every tool call (verified in `test/tools.test.ts`), so behavior is\n   identical on long-lived hosts and short-lived workers. The one piece of\n   module-level state is a request throttle (`src/vercel.ts`) that spaces out\n   and caps concurrent Vercel API calls; its interval and concurrency\n   settings are read once at first use, and it holds no credentials or\n   response data.\n\n## Roadmap\n\n- Deployment actions with an explicit out-of-band approval step (exploring the\n  patterns discussed in MCP spec issues #2919/#2920 around multi-round tool\n  results on stateless transports).\n- Standardizing how `server.json` describes stdio package install manifests\n  and how clients convert them into local configuration files (spec issue\n  #2963, registry issue #749).\n\n## License\n\nMIT\n","readmeFilename":"README.md"}