Webex Calling Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Webex Calling Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
An MCP (Model Context Protocol) server that lets you manage your entire Webex Calling infrastructure using natural language through an AI assistant like Claude.
Built for Cisco partners and network engineers to demonstrate the power of AI-driven network administration.
Node.js is the runtime needed to execute the MCP server. You must install it on every machine where you want to run the server.
<details> <summary><strong>macOS</strong></summary>
Option A — Installer:
.pkg file and follow the installer node --version
npm --versionOption B — Homebrew (if you have it):
brew install node</details>
<details> <summary><strong>Windows</strong></summary>
.msi installer — keep all default options (this adds node and npm to your PATH automatically) node --version
npm --versionTroubleshooting: If npm is not recognized after installation, restart your computer to ensure the PATH is updated.</details>
Git is needed to clone this repository.
<details> <summary><strong>macOS</strong></summary>
Git is pre-installed on macOS. Verify with:
git --versionIf prompted to install Xcode Command Line Tools, accept the installation.
</details>
<details> <summary><strong>Windows</strong></summary>
git --version</details>
| Natural Language Command | What it does |
|---|---|
| "Redirect all incoming calls from the Paris office to voicemail until Monday morning." | Uses call intercept to redirect calls |
| "Create a hunt group for the support team with these 5 numbers, using a round-robin distribution." | Creates a hunt group with CIRCULAR policy |
| "Show me which users in the organization do not have a phone assigned." | Audits users missing phone numbers |
| "Generate a report of missed calls over the last 24 hours." | Analyzes CDR data and produces a summary |
| "Set up a holiday schedule for all locations — close offices Dec 24-Jan 2." | Creates holiday schedules per location |
| "List all call queues and their average wait times." | Queries call queue configurations |
| "Enable Do Not Disturb for the entire executive team." | Batch-updates DND settings |
| "Find available phone numbers in the London office." | Queries number inventory |
list_people — List/search users with calling dataget_person — Get detailed user infofind_users_without_phones — Audit users without phone numbersget_call_forwarding / update_call_forwarding — Manage forwarding rulesget_voicemail / update_voicemail — Configure voicemailredirect_calls_to_voicemail — Quick call intercept (great for demos!)set_do_not_disturb — Enable/disable DNDlist_hunt_groups / get_hunt_group — View hunt groupscreate_hunt_group — Create with agents & routing policyupdate_hunt_group / delete_hunt_group — Manage existing groupslist_call_queues / get_call_queue — View queuescreate_call_queue — Create with agents & queue settingsupdate_call_queue / delete_call_queue — Manage existing queueslist_numbers — List all numbers with filteringfind_available_numbers — Find unassigned numbersget_call_history — Raw CDR dataget_missed_calls_report — Formatted missed call analysis with charts-ready datalist_locations / get_location — View office locationslist_schedules — View business hours & holiday schedulescreate_holiday_schedule — Create holiday scheduleslist_auto_attendants / get_auto_attendant — View IVR menuslist_devices / get_device — View device inventorylist_workspaces — View conference rooms & shared spacesget_caller_id / update_caller_id — Manage caller ID settingslist_org_contacts / get_org_contact — View org directory contactscreate_org_contact — Add external contacts to the org directoryupdate_org_contact / delete_org_contact — Manage existing contactslist_groups — List groups (used to scope contact visibility)<details> <summary><strong>macOS</strong></summary>
Open Terminal and run:
cd ~/Desktop
git clone https://github.com/rochaussee/webex-calling-mcp.git
cd webex-calling-mcp</details>
<details> <summary><strong>Windows</strong></summary>
Open PowerShell and run:
cd $HOME\Desktop
git clone https://github.com/rochaussee/webex-calling-mcp.git
cd webex-calling-mcp</details>
http://localhost:22991/callbacksrc/auth.ts for the default list)These commands are the same on macOS and Windows:
npm install
npm run buildNote: You must be in the project folder (e.g. cd webex-calling-mcp) before running these commands.<details> <summary><strong>macOS / Linux</strong></summary>
WEBEX_CLIENT_ID=xxx WEBEX_CLIENT_SECRET=yyy npm run auth</details>
<details> <summary><strong>Windows (PowerShell)</strong></summary>
On Windows, you must set environment variables separately — the VAR=value command syntax does not work in PowerShell:
$env:WEBEX_CLIENT_ID="xxx"
$env:WEBEX_CLIENT_SECRET="yyy"
npm run auth</details>
Replace xxx and yyy with the Client ID and Client Secret from step 2.
What happens:
~/.webex-mcp/tokens.json%USERPROFILE%\.webex-mcp\tokens.jsonAbout tokens:
npm run auth every ~90 days when the refresh token expiresUseful commands:
npm run auth -- --status # Check token status
npm run auth -- --logout # Clear stored tokens
npm run auth -- --help # Full helpThe MCP server needs your Client ID and Client Secret at runtime to automatically refresh expired access tokens. These are passed as environment variables in the MCP configuration.
Why are Client ID / Secret needed here too? The npm run auth step uses them to obtain tokens. The MCP server config needs them to refresh tokens automatically. Without them, you'd have to re-authenticate manually every ~14 days instead of every ~90 days.#### VS Code (Copilot / Claude Dev)
Add to your .vscode/mcp.json or VS Code global settings:
~/Library/Application Support/Code/User/mcp.json%APPDATA%\Code\User\mcp.json<details> <summary><strong>macOS example</strong></summary>
{
"mcpServers": {
"webex-calling": {
"command": "node",
"args": ["/Users/<your-username>/Desktop/webex-calling-mcp/dist/index.js"],
"env": {
"WEBEX_CLIENT_ID": "your-integration-client-id",
"WEBEX_CLIENT_SECRET": "your-integration-client-secret"
}
}
}
}</details>
<details> <summary><strong>Windows example</strong></summary>
{
"mcpServers": {
"webex-calling": {
"command": "node",
"args": ["C:\\Users\\<your-username>\\Desktop\\webex-calling-mcp\\dist\\index.js"],
"env": {
"WEBEX_CLIENT_ID": "your-integration-client-id",
"WEBEX_CLIENT_SECRET": "your-integration-client-secret"
}
}
}
}Note: Use double backslashes \\ in JSON paths on Windows.</details>
Security note: This file is local to your machine and not tracked by git. Never commit your credentials.
#### Claude Desktop
Add to your Claude Desktop config:
~/Library/Application Support/Claude/claude_desktop_config.json%APPDATA%\Claude\claude_desktop_config.json<details> <summary><strong>macOS example</strong></summary>
{
"mcpServers": {
"webex-calling": {
"command": "node",
"args": ["/Users/<your-username>/Desktop/webex-calling-mcp/dist/index.js"],
"env": {
"WEBEX_CLIENT_ID": "your-integration-client-id",
"WEBEX_CLIENT_SECRET": "your-integration-client-secret"
}
}
}
}</details>
<details> <summary><strong>Windows example</strong></summary>
{
"mcpServers": {
"webex-calling": {
"command": "node",
"args": ["C:\\Users\\<your-username>\\Desktop\\webex-calling-mcp\\dist\\index.js"],
"env": {
"WEBEX_CLIENT_ID": "your-integration-client-id",
"WEBEX_CLIENT_SECRET": "your-integration-client-secret"
}
}
}
}</details>
Once configured, restart VS Code or Claude Desktop, then just ask questions in natural language. The AI will automatically pick the right MCP tools.
┌─────────────────┐ stdio / JSON-RPC ┌──────────────────────┐
│ AI Assistant │ ◄──────────────────────► │ MCP Server │
│ (Claude/Copilot) │ │ (this project) │
└─────────────────┘ └──────┬───────────────┘
│ HTTPS
▼
┌──────────────────────┐
│ Webex REST APIs │
│ webexapis.com/v1 │
└──────────────────────┘@modelcontextprotocol/sdk (official MCP TypeScript SDK)src/
├── index.ts # MCP server entry point
├── auth.ts # OAuth2 authentication (PKCE flow + token refresh)
├── auth-cli.ts # CLI for login, status, logout
├── webex-api.ts # Webex REST API client
└── tools/
├── people.ts # People & user management
├── call-forwarding.ts # Call forwarding, voicemail, DND, intercept
├── hunt-groups.ts # Hunt group CRUD
├── call-queues.ts # Call queue CRUD
├── numbers.ts # Phone number management
├── analytics.ts # CDR & missed call reports
├── locations.ts # Locations, schedules, auto attendants
├── devices.ts # Devices, workspaces, caller ID
└── contacts.ts # Organization contacts & groups<details> <summary><strong>macOS / Linux</strong></summary>
# Run in development mode (no build step)
WEBEX_CLIENT_ID=xxx WEBEX_CLIENT_SECRET=yyy npx tsx src/index.ts
# Build for production
npm run build
# Run production build
WEBEX_CLIENT_ID=xxx WEBEX_CLIENT_SECRET=yyy node dist/index.js</details>
<details> <summary><strong>Windows (PowerShell)</strong></summary>
# Set environment variables (do this once per terminal session)
$env:WEBEX_CLIENT_ID="xxx"
$env:WEBEX_CLIENT_SECRET="yyy"
# Run in development mode
npx tsx src/index.ts
# Build for production
npm run build
# Run production build
node dist/index.js</details>
~/.webex-mcp/tokens.json (macOS/Linux) or %USERPROFILE%\.webex-mcp\tokens.json (Windows) with restricted permissionsspark-admin:people_read — people listingspark-admin:telephony_config_read / _write — calling configspark-admin:calling_cdr_read — call history/CDRspark-admin:devices_read — device inventoryMIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.