# io.github.davidandradebar/ghl-master (npm · ghl-master)

The GoHighLevel MCP for Claude — 214 tools, programmatic workflow builder, multi-tenant.

- Trust score: 58/100 (low)
- Change this week: +19
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- npm · `ghl-master`: 58/100 (this document), [markdown](https://verifymcp.io/servers/davidandradebar-ghl-master/ghl-master.md), [page](https://verifymcp.io/servers/davidandradebar-ghl-master/ghl-master)

## Channel facts

- Registry: `npm`
- Package: `ghl-master`
- Version: `1.0.4`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Supply Chain Security**: 87/100
  - No malware found by supply-chain analysis.
  - Only part of the dependency tree could be resolved (96 of 100), so this covers what we could see, not the whole tree.
  - No install/post-install scripts declared.
  - Only part of the dependency tree could be resolved (96 of 100), so this covers what we could see, not the whole tree.
- **Provenance & Transparency**: 19/100
  - Repository check failed: no source repository is declared.
  - Provenance check failed: no build-provenance attestation is published.
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 2 days ago).
  - Security-disclosure policy not yet verified: we couldn't inspect the source repository.
- **Schema Quality & AI Usability**: 67/100
  - AI-judged instruction clarity (good).
  - Context-footprint check failed: tool/resource definitions use about 586 tokens (~146/item across 4 items; 4 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

**Unverified: 1 category.** A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

## Install

### Claude

```bash
claude mcp add davidandradebar-ghl-master -- npx -y ghl-master
```

### Codex

```bash
codex mcp add davidandradebar-ghl-master -- npx -y ghl-master
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "davidandradebar-ghl-master": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "ghl-master"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add davidandradebar-ghl-master --command npx --arg -y --arg ghl-master
```

### Hermes

```yaml
mcp_servers:
  davidandradebar-ghl-master:
    command: "npx"
    args: ["-y", "ghl-master"]
```

### Other

```json
{
  "mcpServers": {
    "davidandradebar-ghl-master": {
      "command": "npx",
      "args": [
        "-y",
        "ghl-master"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-02 (score 58, +43)

- [security regression] Provenance: unverified → fail
- [security improvement] Install scripts: unverified → pass
- [security improvement] Known CVEs: unverified → partial
- [security improvement] Malware scan: unverified → pass
- [security] Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window).
- [functional improvement] License: unverified → pass
- [functional improvement] Dependency health: unverified → partial
- [functional improvement] Maintenance: unverified → pass
- [functional improvement] MCP protocol: unverified → pass
- [functional improvement] Schema quality: unverified → good
- [functional] Licence: MIT

### 2026-08-01 (score 15, −5)

- [security] Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.
- [functional regression] Capabilities: pass → unverified

### 2026-07-31 (score 20, −19)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-27 (score 39)

First indexed and scored.

## MCP tools (4)

### `get_mcp_version` (~66 tokens)

Check the installed version of GHL Master (the GoHighLevel MCP server) against the latest version published to npm. Use this to confirm an upgrade landed after restarting Claude. Returns installed version, latest version, whether up-to-date, and the one-line restart instruction if not.

### `setup_ghl_mcp` (~302 tokens)

First-run setup for GHL Master MCP. Validates your license and GHL credentials, then writes them to a per-user credentials file. Restart Claude after this completes to load all 212 tools (163 if you skip the optional Firebase fields; add Firebase later with enable_workflow_builder).

Input parameters:

- `email` (string, required): Email used at purchase.
- `firebase_paste` (string): (Workflow Builder, one-paste path) Paste the JSON output from auto_capture_firebase_script here. Replaces the three separate Firebase fields below.
- `ghl_api_key` (string, required): GHL Private Integration key (starts with 'pit-'). Created INSIDE the sub-account at Settings > Integrations > Private Integrations.
- `ghl_company_id` (string): (Agency only) Company ID for multi-location access.
- `ghl_firebase_api_key` (string): (Workflow Builder, manual path) Firebase API Key starting with 'AIza'. Prefer firebase_paste instead.
- `ghl_firebase_refresh_token` (string): (Workflow Builder, manual path) Firebase refresh token. Prefer firebase_paste instead.
- `ghl_location_id` (string, required): GHL Location ID (sub-account ID). Found in your GHL URL: /location/THIS_PART/dashboard.
- `ghl_user_id` (string): (Workflow Builder, manual path) Firebase User ID. Prefer firebase_paste instead.
- `license_key` (string, required): License key from your purchase email.

### `request_license` (~122 tokens)

Get a GHL Master license. Use this if you installed from npm but don't have a license yet (or setup_ghl_mcp says your license is missing/invalid). GHL Master is $97 one-time — 212 tools across 43 modules, 3-machine activation, no subscription. Leave your email and we'll send the purchase link + setup help; the tool also returns where to buy right now.

Input parameters:

- `email` (string, required): Your email — where to send the purchase link and setup help.
- `name` (string): Your name (optional).

### `auto_capture_firebase_script` (~96 tokens)

Get the browser-console script that auto-extracts the 3 Firebase fields needed to enable the Workflow Builder. Run this, copy the script, paste it into Chrome DevTools Console on a tab logged into GHL, press Enter, and the result lands in your clipboard. Then paste the JSON into setup_ghl_mcp's firebase_paste field (or enable_workflow_builder's). No manual IndexedDB digging.

## Diagnostics

Captured diagnostic sections: Provenance, Dependencies. The full working is on the page: https://verifymcp.io/servers/davidandradebar-ghl-master/ghl-master#diagnostics

## Score history

- 2026-08-03: 58
- 2026-08-02: 58
- 2026-08-01: 15
- 2026-07-31: 20
- 2026-07-30: 39
- 2026-07-28: 39
- 2026-07-27: 39

## Links

- npm package: https://www.npmjs.com/package/ghl-master
- Socket report: https://socket.dev/npm/package/ghl-master
- Website: https://ghl-master.salesfactoryagency.com/
- Changelog RSS feed: https://verifymcp.io/servers/davidandradebar-ghl-master/ghl-master/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/davidandradebar-ghl-master/ghl-master/changelog.json
- HTML version of this page: https://verifymcp.io/servers/davidandradebar-ghl-master/ghl-master
