Intercom Mcp Server — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Intercom Mcp Server (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
MCP server for the Intercom REST API (v2.11).
102 tools covering every Intercom resource:
| Module | Tools |
|---|---|
| Admins | 5 |
| Articles | 6 |
| Companies | 12 |
| Contacts | 17 |
| Conversations | 12 |
| Data Attributes | 3 |
| Data Events | 3 |
| Help Center | 7 |
| Messages | 1 |
| News | 8 |
| Segments | 3 |
| Tags | 9 |
| Teams | 2 |
| Tickets | 11 |
| Visitors | 3 |
The server has three modes, in priority order:
If you already use the official Intercom MCP (mcp.intercom.com) via mcp-remote in Claude Code, this server will automatically proxy through that existing authenticated session. No tokens, no developer app required — just a regular Intercom workspace account.
Add both to ~/.claude.json:
{
"mcpServers": {
"intercom": {
"command": "npx",
"args": ["-y", "mcp-remote", "https://mcp.intercom.com/mcp"]
},
"intercom-local": {
"command": "node",
"args": ["/path/to/intercom-mcp-server/dist/index.js"]
}
}
}When intercom-local starts with no token set, it detects this and connects to mcp.intercom.com as a sub-process, reusing the mcp-remote session that is already authenticated. mcp-remote will prompt for browser login on first use.
If you have a workspace access token (from Intercom Settings → Developers → Access tokens):
{
"mcpServers": {
"intercom-local": {
"command": "node",
"args": ["/path/to/intercom-mcp-server/dist/index.js"],
"env": {
"INTERCOM_ACCESS_TOKEN": "your_token_here"
}
}
}
}If you have an Intercom developer account and want to register your own OAuth app, set INTERCOM_CLIENT_ID and INTERCOM_CLIENT_SECRET, then call the auth_start tool. It opens a local callback server, redirects your browser through Intercom's OAuth consent screen, and stores the token at ~/.intercom-mcp/token.json.
git clone <repo>
cd intercom-mcp-server
npm install # also runs tscauth_start — Begin OAuth login; returns a browser URL to openauth_status — Check if a token is stored and which source it came fromauth_logout — Remove the stored tokenadmin_identify — Get the current authenticated adminadmin_list — List all adminsadmin_get — Get a specific adminadmin_set_away — Set away mode for an adminadmin_list_activity_logs — List admin activity logsarticle_list — List all articlesarticle_create — Create an articlearticle_get — Get an articlearticle_update — Update an articlearticle_delete — Delete an articlearticle_search — Search articles by phrasecompany_list — List/filter companiescompany_create_or_update — Create or update a companycompany_get — Get a company by Intercom IDcompany_update — Update a companycompany_delete — Delete a companycompany_list_all — List all companies (paginated POST)company_scroll — Scroll through all companiescompany_list_contacts — List contacts for a companycompany_list_segments — List segments for a companyattach_contact_to_company — Attach a contact to a companylist_contact_companies — List companies for a contactdetach_contact_from_company — Detach a contact from a companycontact_list — List all contactscontact_create — Create a contactcontact_get — Get a contactcontact_update — Update a contactcontact_delete — Delete a contactcontact_archive / contact_unarchive — Archive/unarchive a contactmerge_contacts — Merge two contactssearch_contacts — Search contacts with filterscontact_list_notes / contact_create_note — Notescontact_list_tags / contact_attach_tag / contact_detach_tag — Tagscontact_list_subscriptions / contact_attach_subscription / contact_detach_subscription — Subscriptionsconversation_list — List conversationsconversation_create — Start a conversationconversation_get — Get a conversationconversation_update — Update a conversationsearch_conversations — Search conversationsconversation_reply — Reply to a conversationconversation_manage — Close, open, snooze, or assign a conversationconversation_run_assignment_rules — Run assignment rulesconversation_attach_contact / conversation_detach_contact — Manage contactsconversation_redact — Redact a part or sourceconversation_convert_to_ticket — Convert to a ticketdata_attribute_list — List data attributesdata_attribute_create — Create a data attributedata_attribute_update — Update a data attributedata_event_list — List events for a userdata_event_create — Track an eventdata_event_summaries — Submit event summarieshelp_center_list / help_center_get — Help centerscollection_list / collection_create / collection_get / collection_update / collection_delete — Collectionscreate_message — Send an email or in-app messagenews_list_items / news_create_item / news_get_item / news_update_item / news_delete_item — News itemsnews_list_newsfeeds / news_get_newsfeed / news_list_newsfeed_items — Newsfeedssegment_list — List segmentssegment_get — Get a segmentsegment_list_for_contact — List segments for a contacttag_list / tag_get / tag_create_or_update / tag_delete — Tag CRUDtag_companies — Tag companiestag_conversation / tag_detach_conversation — Tag conversationstag_ticket / tag_detach_ticket — Tag ticketsteam_list — List teamsteam_get — Get a teamticket_create / ticket_get / ticket_update / ticket_search / ticket_reply — Ticketsticket_type_list / ticket_type_create / ticket_type_get / ticket_type_update — Ticket typesticket_type_attribute_create / ticket_type_attribute_update — Ticket type attributesvisitor_get — Get a visitorvisitor_update — Update a visitorvisitor_convert — Convert a visitor to lead or user~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.