Skip to main content
Glama
decode-data

twentycrm-graphql-mcp

by decode-data

twentycrm-graphql-mcp

An MCP (Model Context Protocol) server for Twenty CRM that exposes GraphQL tools to AI assistants.

Usage

Run directly with npx (no install required):

TWENTY_API_TOKEN=your_token npx twentycrm-graphql-mcp

Related MCP server: twenty-mcp-server

Environment Variables

Variable

Required

Description

TWENTY_API_TOKEN

Yes

Your Twenty API token (Settings > API & Webhooks)

TWENTY_GQL_URL

No

Your Twenty instance's GraphQL endpoint. For cloud-hosted, it's https://[your-org].twenty.com/graphql. For self-hosted, it's https://[your-domain]/graphql.

Claude Desktop Configuration

Add to your claude_desktop_config.json:

{
  "mcpServers": {
    "twentycrm": {
      "command": "npx",
      "args": ["-y", "twentycrm-graphql-mcp"],
      "env": {
        "TWENTY_API_TOKEN": "your_token_here",
        "TWENTY_GQL_URL": "https://your-instance.com/graphql"
      }
    }
  }
}

Deploying to Google Cloud Run

Note: This deployment is not currently active. The recommended way to use this package is via npx as described above.

The terraform/ directory contains infrastructure-as-code to deploy this as a hosted MCP server on Cloud Run (GCP project decodedata-crm, region europe-west2).

Prerequisites

  • Terraform >= 1.5

  • gcloud CLI authenticated with the decodedata-crm project

  • Docker

Resources created

Resource

Description

Artifact Registry repo

europe-west2-docker.pkg.dev/decodedata-crm/mcp/

Cloud Run service

twentycrm-mcp — publicly accessible, auth enforced by app

Secret Manager secrets

twenty-api-token, mcp-auth-token

Service account

twentycrm-mcp@decodedata-crm.iam.gserviceaccount.com

Deploy

# 1. Build and push the Docker image
gcloud auth configure-docker europe-west2-docker.pkg.dev

IMAGE=europe-west2-docker.pkg.dev/decodedata-crm/mcp/twentycrm-graphql-mcp:latest
docker build -t $IMAGE .
docker push $IMAGE

# 2. Apply infrastructure
cd terraform
terraform init
terraform apply \
  -var="image=europe-west2-docker.pkg.dev/decodedata-crm/mcp/twentycrm-graphql-mcp:latest" \
  -var="twenty_gql_url=https://crm.decodedata.io/graphql"

Secrets

After first apply, populate the secrets in GCP Secret Manager:

# Twenty API token (from Twenty Settings > API & Webhooks)
echo -n "your-twenty-api-token" | gcloud secrets versions add twenty-api-token --data-file=-

# MCP bearer token (any strong random string — required by clients to call the service)
echo -n "your-mcp-auth-token" | gcloud secrets versions add mcp-auth-token --data-file=-

Destroy

cd terraform
terraform destroy \
  -var="image=europe-west2-docker.pkg.dev/decodedata-crm/mcp/twentycrm-graphql-mcp:latest" \
  -var="twenty_gql_url=https://crm.decodedata.io/graphql"

HTTP server

When deployed, the service exposes:

  • GET /sse — SSE endpoint for MCP clients (requires Authorization: Bearer <mcp-auth-token>)

  • POST /messages — MCP message endpoint

  • GET /health — Health check (unauthenticated)

Available Tools

inspect_schema

Lists all objects and fields in your workspace, including custom fields.

execute_graphql

Run any raw GraphQL query or mutation against Twenty.

Parameters:

  • query (string, required): The GraphQL query or mutation

  • variables (object, optional): Variables for the query

execute_metadata

Run any raw GraphQL query or mutation against the Twenty Metadata API (schema management: custom objects, fields, relations).

Parameters:

  • query (string, required): The GraphQL query or mutation

  • variables (object, optional): Variables for the query

Available Tools

3 tools
execute_graphqlB

Run any raw GraphQL query or mutation against Twenty.

ParametersJSON Schema
NameRequiredDescriptionDefault
queryYesThe GraphQL query or mutation string
variablesNoOptional variables for the query

TDQS

B3.2/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the full burden of behavioral disclosure. It acknowledges that mutations can be run, but it does not warn about destructive side effects, permission requirements, rate limits, or error behavior. For a raw GraphQL execution tool, this is a significant transparency gap.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single sentence with no filler or repetition. The core action is front-loaded and immediately understandable.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a powerful raw GraphQL execution tool with no annotations and no output schema, the description is too thin. It lacks guidance on when to use it, relationship to sibling tools, safety considerations, and what the agent should expect when executing arbitrary mutations.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the query and variables parameters are already documented in the input schema. The description adds no additional parameter-level meaning or usage examples, which is acceptable given the high schema coverage.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb ('Run'), a specific resource ('raw GraphQL query or mutation'), and a target system ('Twenty'). It clearly differentiates this from sibling tools like inspect_schema and execute_metadata by emphasizing raw, arbitrary GraphQL execution.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives no guidance about when to use this tool versus inspect_schema or execute_metadata. There is no mention of preferred use cases, exclusions, or conditions that would make another sibling more appropriate.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

execute_metadataA

Run any raw GraphQL query or mutation against the Twenty Metadata API (schema management: custom objects, fields, relations).

ParametersJSON Schema
NameRequiredDescriptionDefault
queryYesThe GraphQL query or mutation string
variablesNoOptional variables for the query

TDQS

A3.5/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are present, so the description must carry full behavioral disclosure. While 'any raw GraphQL query or mutation' hints at arbitrary operations, it does not disclose potential side effects such as schema modifications being irreversible or dangerous, authentication requirements, or error behavior. This is a significant gap for a powerful execution tool.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single, tightly constructed sentence. It front-loads the core action and adds a helpful parenthetical scope without any wasted words.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The tool is a raw GraphQL executor with no annotations and no output schema, so more context would be valuable. The description gives the domain and scope, but it omits risk information, usage alternatives, and expected response behavior, leaving the description only minimally complete for an agent to use it safely and effectively.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so parameters are already well-documented in the schema. The description adds no additional semantic detail about the query string or variables, but the baseline of 3 is appropriate because the schema carries the burden.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb ('Run'), a resource ('raw GraphQL query or mutation against the Twenty Metadata API'), and a scope ('schema management: custom objects, fields, relations'). It clearly distinguishes from likely siblings by naming the Metadata API and schema management domain.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage for raw GraphQL operations on the metadata API, but it does not explicitly say when to choose this tool over siblings like execute_graphql or inspect_schema. No alternatives or exclusion conditions are provided, leaving the agent to infer context from sibling names.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

inspect_schemaA

Lists all available objects and fields, including CUSTOM fields created in your workspace.

ParametersJSON Schema
NameRequiredDescriptionDefault

No parameters

TDQS

A3.9/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries the full disclosure burden. It clearly signals a read-only listing operation through the verb 'lists' and adds useful nuance by highlighting that custom fields created in the workspace are included. There is no hidden mutation or side-effect behavior implied.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single, front-loaded sentence that states the core behavior first and then adds the key detail about custom fields. Every word earns its place, with no fluff or repetition.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a zero-parameter introspection tool, the description is largely complete: it identifies the operation, the resource, and a notable scope detail. It does not describe the output shape, but the absence of an output schema and the low complexity make this a minor gap rather than a serious omission.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema has zero parameters, so there are no parameter semantics to compensate for. The baseline for zero-parameter tools is 4, and the description does not need to explain anything about parameters.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb and resource: it lists all available objects and fields, and explicitly calls out custom fields in the workspace. This makes the tool's purpose clear, though it does not explicitly distinguish itself from its siblings beyond the verb 'lists' versus their 'execute' naming.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies that the tool should be used when you need to discover available schema objects and fields, including custom ones. However, it gives no explicit guidance on when to prefer this tool over execute_graphql or execute_metadata, nor any exclusions or alternatives.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. 3 tool updatesv0.0.9
    • First observedexecute_graphql
    • First observedexecute_metadata
    • First observedinspect_schema

TDQS

A3.9/5.0
Disambiguation5/5

Each tool has a clear, distinct role: schema introspection, runtime data queries/mutations, and metadata schema management. Even though execute_graphql could theoretically run introspection, the dedicated inspect_schema tool removes ambiguity.

Naming Consistency5/5

All tool names follow a consistent snake_case verb_noun pattern: inspect_schema, execute_graphql, execute_metadata. The repeated execute prefix for the two raw query tools also reinforces their similarity without causing confusion.

Tool Count5/5

Three tools is appropriately minimal for a GraphQL gateway-style MCP server. Each tool covers a distinct need (schema discovery, data access, metadata management) and none feels redundant or extraneous.

Completeness5/5

The combination of raw GraphQL execution for both the standard API and metadata API covers the full CRUD/lifecycle surface of a Twenty CRM workspace, while inspect_schema supports discovery. There are no obvious dead ends because arbitrary queries and mutations can fill any domain-specific gap.

Maintenance

ActivityInactive
ResponsivenessNo issues

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    D
    maintenance
    A remote MCP server that connects Claude to a Twenty CRM workspace, enabling users to interact with CRM objects (People, Companies, Opportunities, and custom objects) through schema-driven tools for querying, creating, updating, and deleting records.
    1
    Apache 2.0
  • A
    license
    Not graded
    quality
    D
    maintenance
    A standalone MCP server that integrates with Twenty CRM to provide AI-powered CRM capabilities, enabling CRUD operations and real-time synchronization.
    1,089
    MIT
  • F
    license
    Not graded
    quality
    B
    maintenance
    MCP server that exposes the Moloni ON GraphQL API to AI clients, providing a curated set of operations as typed and documented tools.
    -
  • A
    license
    B
    quality
    C
    maintenance
    MCP server for Microsoft Dynamics 365 Business Central, enabling AI assistants to perform CRUD operations, query data, and retrieve schemas via Business Central API v2.0.
    6
    30
    MIT

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/decode-data/twentycrm-graphql-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server