Back to Home
GravityKit icon

GravityMCP

Verified Safe

by GravityKit

Overview

Manage Gravity Forms data (forms, entries, feeds, fields) via Model Context Protocol, enabling programmatic interaction with WordPress forms.

Installation

Run Command
node src/index.js

Environment Variables

  • GRAVITY_FORMS_CONSUMER_KEY
  • GRAVITY_FORMS_CONSUMER_SECRET
  • GRAVITY_FORMS_BASE_URL
  • GRAVITY_FORMS_ALLOW_DELETE
  • GRAVITY_FORMS_TIMEOUT
  • GRAVITY_FORMS_MAX_RETRIES
  • GRAVITY_FORMS_RETRY_DELAY
  • GRAVITY_FORMS_DEBUG
  • GRAVITY_FORMS_RATE_LIMIT
  • GRAVITY_FORMS_RATE_WINDOW
  • MCP_ALLOW_SELF_SIGNED_CERTS

Security Notes

The server enforces HTTPS for Basic Authentication, falling back to OAuth 1.0a for HTTP connections. Sensitive data (keys, secrets, passwords) is obfuscated in logs using a dedicated sanitization utility (`sanitize.js`). Destructive operations (delete) are disabled by default and require explicit `GRAVITY_FORMS_ALLOW_DELETE=true` configuration. A `MCP_ALLOW_SELF_SIGNED_CERTS=true` option is available for local development with self-signed certificates, which carries an explicit security warning against its use in production.

Similar Servers

Stats

Interest Score41
Security Score9
Cost ClassMedium
Avg Tokens500
Stars13
Forks2
Last Update2025-12-05

Tags

WordPressGravity FormsForms ManagementData ManagementAPI Client