{"_id":"@datorama/mci-mcp-sdk","_rev":"2-45ebd9a30af729d7e71b861fef1abc56","name":"@datorama/mci-mcp-sdk","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@datorama/mci-mcp-sdk","version":"0.1.0","keywords":["mci","mcp","model-context-protocol","marketing-cloud-intelligence","datorama"],"author":{"url":"Marketing Cloud Intelligence","name":"Salesforce"},"license":"SEE LICENSE IN LICENSE","_id":"@datorama/mci-mcp-sdk@0.1.0","maintainers":[{"name":"maliperlman","email":"mali.perlman@salesforce.com"},{"name":"aavgil","email":"avgalon@gmail.com"},{"name":"distroy123","email":"roydistler@gmail.com"},{"name":"ssegal","email":"ssegal@salesforce.com"},{"name":"gurdotan","email":"gurdotan@gmail.com"},{"name":"mperets","email":"mperets@salesforce.com"},{"name":"bdimand","email":"barakdimand@aol.com"},{"name":"omilitscher","email":"omilitscher@salesforce.com"},{"name":"natassor","email":"nassor@salesforce.com"},{"name":"rsvilemshema","email":"rsvilemshema@salesforce.com"},{"name":"meireliezer-salesforce","email":"meliezer@salesforce.com"},{"name":"nina.mordakhay","email":"nmordakhay@salesforce.com"},{"name":"ebelenki","email":"ebelenki@salesforce.com"},{"name":"mohamadhusari","email":"7osary@gmail.com"},{"name":"megbarya","email":"megbarya@salesforce.com"}],"homepage":"https://www.salesforce.com/marketing/data-intelligence/","bugs":{"url":"https://help.salesforce.com/s/"},"bin":{"mci-mcp-sdk":"dist/bin/mci-mcp-sdk.js"},"dist":{"shasum":"14d03afb392c8c6fc592b7b76e3d9f521a10b303","tarball":"https://registry.npmjs.org/@datorama/mci-mcp-sdk/-/mci-mcp-sdk-0.1.0.tgz","fileCount":25,"integrity":"sha512-UZH8o6o3hhCY2U2q8JXiq6zkmlZMopXI8pxWwKcgyxZcyjsacLeeTOCu2iQnH7aWjmfP6KboDHN4MBJvUQyBmw==","signatures":[{"sig":"MEQCIDTULXWvHldSiQBJWAkV1BhZy+BBwqpq6/Csr7iYHlxNAiBuDbTY9PvM84s1teO4QJJSDfi25jnSrcsImAMzJPX8Ww==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":35567},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"481666190f101f4471f45f2d252fb03f880a69b3","scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","clean":"rm -rf dist","start":"node dist/bin/mci-mcp-sdk.js","typecheck":"tsc -p tsconfig.json --noEmit","test:watch":"vitest","prepublishOnly":"npm run check:public-lock && npm run clean && npm run build && npm test","check:public-lock":"node scripts/check-public-lock.mjs"},"_npmUser":{"name":"megbarya","email":"megbarya@salesforce.com"},"repository":{"type":"git"},"_npmVersion":"10.8.2","description":"Local stdio MCP server for Marketing Cloud Intelligence (MCI). Owns the OAuth2 token lifecycle and pass-through-proxies MCP JSON-RPC to an MCI dato /api/mcp endpoint.","directories":{},"_nodeVersion":"18.20.8","dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^1.6.0","typescript":"^5.4.0","@types/node":"^20.11.0"},"_npmOperationalInternal":{"tmp":"tmp/mci-mcp-sdk_0.1.0_1784621025392_0.46624572731479264","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@datorama/mci-mcp-sdk","version":"0.1.1","description":"Local stdio MCP server for Marketing Cloud Intelligence (MCI). Owns the OAuth2 token lifecycle and pass-through-proxies MCP JSON-RPC to an MCI dato /api/mcp endpoint.","type":"module","license":"SEE LICENSE IN LICENSE","author":{"name":"Salesforce","url":"Marketing Cloud Intelligence"},"homepage":"https://www.salesforce.com/marketing/data-intelligence/","repository":{"type":"git"},"bugs":{"url":"https://help.salesforce.com/s/"},"keywords":["mci","mcp","model-context-protocol","marketing-cloud-intelligence","datorama"],"engines":{"node":">=18"},"publishConfig":{"access":"public"},"bin":{"mci-mcp-sdk":"dist/bin/mci-mcp-sdk.js"},"main":"dist/index.js","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"build":"tsc -p tsconfig.build.json","clean":"rm -rf dist","test":"vitest run","test:watch":"vitest","typecheck":"tsc -p tsconfig.json --noEmit","start":"node dist/bin/mci-mcp-sdk.js","check:public-lock":"node scripts/check-public-lock.mjs","prepublishOnly":"npm run check:public-lock && npm run clean && npm run build && npm test"},"dependencies":{"@modelcontextprotocol/sdk":"^1.0.0"},"devDependencies":{"@types/node":"^20.11.0","typescript":"^5.4.0","vitest":"^1.6.0"},"_id":"@datorama/mci-mcp-sdk@0.1.1","gitHead":"481666190f101f4471f45f2d252fb03f880a69b3","_nodeVersion":"18.20.8","_npmVersion":"10.8.2","dist":{"integrity":"sha512-LDs9+8kcI6QxLm7kaPcyuEWmnyzwvRw45ZvgtZCO8Tz8OWF9ZF/mOmUg3LjLMjPDfhwC8rBK6YETFIKShD457w==","shasum":"01ab0e7a708c8ea3a1780d07601cc77ca22fe327","tarball":"https://registry.npmjs.org/@datorama/mci-mcp-sdk/-/mci-mcp-sdk-0.1.1.tgz","fileCount":25,"unpackedSize":35563,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDGsoROfYiAUIgXHDurIbuT//1egRr1sqUZMWm7CJbLMwIgQY4dfeKKTU+joDsoy14aNmtK2Kjwp+ORuDYX/LGR8Uk="}]},"_npmUser":{"name":"megbarya","email":"megbarya@salesforce.com"},"directories":{},"maintainers":[{"name":"maliperlman","email":"mali.perlman@salesforce.com"},{"name":"aavgil","email":"avgalon@gmail.com"},{"name":"distroy123","email":"roydistler@gmail.com"},{"name":"ssegal","email":"ssegal@salesforce.com"},{"name":"gurdotan","email":"gurdotan@gmail.com"},{"name":"mperets","email":"mperets@salesforce.com"},{"name":"bdimand","email":"barakdimand@aol.com"},{"name":"omilitscher","email":"omilitscher@salesforce.com"},{"name":"natassor","email":"nassor@salesforce.com"},{"name":"rsvilemshema","email":"rsvilemshema@salesforce.com"},{"name":"meireliezer-salesforce","email":"meliezer@salesforce.com"},{"name":"nina.mordakhay","email":"nmordakhay@salesforce.com"},{"name":"ebelenki","email":"ebelenki@salesforce.com"},{"name":"mohamadhusari","email":"7osary@gmail.com"},{"name":"megbarya","email":"megbarya@salesforce.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mci-mcp-sdk_0.1.1_1784621472329_0.3119324263193515"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-21T08:03:45.254Z","modified":"2026-07-21T08:11:12.923Z","0.1.0":"2026-07-21T08:03:45.528Z","0.1.1":"2026-07-21T08:11:12.464Z"},"bugs":{"url":"https://help.salesforce.com/s/"},"author":{"name":"Salesforce","url":"Marketing Cloud Intelligence"},"license":"SEE LICENSE IN LICENSE","homepage":"https://www.salesforce.com/marketing/data-intelligence/","keywords":["mci","mcp","model-context-protocol","marketing-cloud-intelligence","datorama"],"repository":{"type":"git"},"description":"Local stdio MCP server for Marketing Cloud Intelligence (MCI). Owns the OAuth2 token lifecycle and pass-through-proxies MCP JSON-RPC to an MCI dato /api/mcp endpoint.","maintainers":[{"name":"maliperlman","email":"mali.perlman@salesforce.com"},{"name":"aavgil","email":"avgalon@gmail.com"},{"name":"distroy123","email":"roydistler@gmail.com"},{"name":"ssegal","email":"ssegal@salesforce.com"},{"name":"gurdotan","email":"gurdotan@gmail.com"},{"name":"mperets","email":"mperets@salesforce.com"},{"name":"bdimand","email":"barakdimand@aol.com"},{"name":"omilitscher","email":"omilitscher@salesforce.com"},{"name":"natassor","email":"nassor@salesforce.com"},{"name":"rsvilemshema","email":"rsvilemshema@salesforce.com"},{"name":"meireliezer-salesforce","email":"meliezer@salesforce.com"},{"name":"nina.mordakhay","email":"nmordakhay@salesforce.com"},{"name":"ebelenki","email":"ebelenki@salesforce.com"},{"name":"mohamadhusari","email":"7osary@gmail.com"},{"name":"megbarya","email":"megbarya@salesforce.com"}],"readme":"# @datorama/mci-mcp-sdk\n\nA tiny, local **stdio MCP server** for Marketing Cloud Intelligence (MCI). You launch it via `npx`\nfrom your MCP client's config; it owns the entire OAuth2 token lifecycle (mint from your\nservice-account key, cache, refresh on demand) and **pass-through-proxies** MCP JSON-RPC to an MCI\ndato `/api/mcp` endpoint.\n\nThere is **nothing to paste and nothing that expires on you**: no more copying a bearer header that\ndies every hour. You give the SDK a key file and a URL; it does the rest.\n\n## What it is (and isn't)\n\n- **It is** a pure relay + a token manager. Every MCP message — `initialize`, `tools/list`,\n  `tools/call`, and anything added later — is forwarded verbatim to your MCI endpoint with a fresh\n  `Authorization: Bearer …` injected. It defines **no tools of its own**; the tool list you see comes\n  from the server. New server-side tools appear automatically with **no SDK update**.\n- **It isn't** where any business logic lives. All validation, data access, and authorization happen\n  server-side; the SDK is treated as untrusted and the server re-validates every call.\n\n## Setup\n\nAdd this to your MCP client's server config (e.g. Claude Code / Cursor `mcpServers`):\n\n```json\n{\n  \"mcpServers\": {\n    \"mci-mcp\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@datorama/mci-mcp-sdk\"],\n      \"env\": {\n        \"PRIVATE_KEY_PATH\": \"<path to the step-1 service-account JSON>\",\n        \"HOST\": \"https://<your dato env>/api/mcp\"\n      }\n    }\n  }\n}\n```\n\n- **`PRIVATE_KEY_PATH`** — path to the service-account artifact JSON you were issued (it contains\n  `serviceAccountId`, `discoveryEndpoint`, and `privateKey`). The SDK derives the IdP/token URL from\n  this file; you don't configure an IdP URL. The key is read in-memory only — never logged, never put\n  on the command line, never written to disk.\n- **`HOST`** — your MCI dato MCP endpoint (`…/api/mcp`).\n\nReload your client. The `mci_*` tools appear with **no pasted header**. As you keep working, the SDK\ntransparently re-mints the bearer when it nears expiry — you never notice.\n\n### Optional env\n\n| Var | Default | Purpose |\n|---|---|---|\n| `MCI_INSECURE_TLS` | off | Allow a self-signed cert. Honored **only** for dev hosts (`localhost`, `127.0.0.1`, `*.dev.datorama.io`); ignored for production. |\n| `MCI_TIMEOUT_MS` | `30000` | Per-request timeout to `HOST`. |\n| `DATO_MCI_STATE_DIR` | OS state dir | Override the token-cache directory (tests/power users). |\n\n## Local development\n\n```bash\nnpm install\nnpm run build       # tsc → dist/\nnpm test            # vitest (unit + proxy relay)\n\n# Smoke-test the built binary against a live endpoint:\nPRIVATE_KEY_PATH=/path/to/sa.json HOST=https://127.0.0.1:8081/api/mcp MCI_INSECURE_TLS=1 \\\n  node scripts/stdio-smoke.mjs mci_list_workspaces\n```\n\n> **Local gotcha:** use `127.0.0.1`, not `localhost`, for a locally-run dato — Node resolves\n> `localhost` to IPv6 `::1`, but a local Jetty typically binds IPv4 only (`ECONNREFUSED ::1`).\n\n## Security\n\n- Private key: in-memory only. Never logged, never on argv, never persisted.\n- Token cache: only the short-lived bearer, written atomically at mode `0600` in a `0700` state dir.\n- `stdout` is reserved for the MCP protocol stream; all diagnostics go to `stderr`.\n- Tokens are masked and IdP error bodies redacted in any human-readable output.\n- The server is the security boundary — it enforces per-user authorization on the service-account\n  identity regardless of what the client (or a tampered SDK) sends.\n","readmeFilename":"README.md"}