benepass-mcp
benepass-mcp
非公式の読み取り専用MCPサーバーで、Benepassのemployee-web APIを利用します。
このプロジェクトはBenepassとは提携しておらず、承認もサポートもされていません。これはemployee-webクライアントをリバースエンジニアリングしたものです。この非公式ツールに関するサーバー、ログイン問題、不足しているエンドポイント、その他一切についてBenepassサポートに連絡しないでください。
公開レジストリのパッケージ名は既に取得されています。このリポジトリはprivate: trueを設定しており、公開されていません。
レイアウト
src/index.ts— stdioエントリ(serveStdio)src/server.tsMcpServerファクトリsrc/tools.ts— 薄いMCPアダプタ(TOOL_NAMES)src/app.ts— 構成ルートsrc/accounts.ts— 福利厚生の導出、HSA口座の選択src/hsa.ts— 投資GETパスのウォークsrc/api.ts— GET専用のBenepass HTTPクライアントsrc/http.ts— ky + ホスト許可リストsrc/cognito.ts— Cognito OTP + トークン更新src/session.ts— ローカルセッションファイルsrc/schemas.ts— Benepass JSON用のZodモデルsrc/errors.ts— 型付きエラーtest/— Vitest(インプロセスMCPクライアント + ユニットテスト)
Related MCP server: appstoreconnect-codex-mcp
セキュリティモデル
読み取り専用。
api.benefitsapi.com用のkyクライアントは、メソッドがGETでない場合に例外をスローします。入金、出金、経費の提出/更新/削除、カード/PIN、支払い、汎用のcall_apiのためのツールはありません。トークンはあなたのマシンに留まります。 OTPログイン後、Cognitoの更新トークンは
~/.config/benepass-mcp/session.json(env-pathsによるXDG)にモード0600で保存されます。BENEPASS_SESSION_PATH(Pは2つ)で上書きできます。ツールが更新トークンやアクセストークンを返すことはありません。トークンがログに記録されることはありません。セッションファイルはgitignoreされています。送信先ホストは次のみ:
cognito-idp.us-east-1.amazonaws.com、cognito.benefitsapi.com、api.benefitsapi.com。CognitoアプリクライアントID
6l7jeu4r44kgndgeab4aot355mは公開クライアントIDです(秘密ではありません)。これはemployee-webアプリに組み込まれています。
ログインフロー
start_loginをBenepassのメールアドレスで呼び出します。Cognito InitiateAuth CUSTOM_AUTHがOTPを送信します。complete_loginをメールアドレス、OTP、challenge_sessionで呼び出します。Cognito RespondToAuthChallenge CUSTOM_CHALLENGEが更新トークンを生成し、ローカルセッションファイルに書き込みます。ツールは{ ok, email }のみを返します。後のAPI呼び出しは、トークンURLに
grant_type=refresh_tokenをPOSTし、アクセストークンをAuthorization Bearerとして送信します。有効期限は尊重されます(expires_inとJWTexp)。workspace_idが省略された場合、GET/v2/me/workspaces/を実行し、最初のtype=employmentワークスペースを永続化します。
ツール
認証:start_login、complete_login、auth_status、logout。
読み取り:list_workspaces、list_accounts、list_benefits(アカウントのenrollment.benefit + 利用可能残高から導出)、list_transactions、get_hsa_account_details、get_hsa_investments、list_documents、get_document、get_current_user。
list_benefits:Benepassには/v2/me/benefits/はありません。福利厚生は各アカウントのenrollment.benefitと、/availableで終わる残高キーから導出されます。
get_hsa_investments:GETのみを試行し、最初の2xxが優先されます:
/v2/me/accounts/{id}/hsa-investments//v2/me/accounts/{id}/hsa-investments/portfolio//v2/me/accounts/{id}/hsa-investments/portfolio/allocation//v2/me/accounts/{id}/hsa-investments/asset-links/
account_idが省略された場合、HSA口座はZodで解析されたフィールド(enrollment.benefit.benefit_type、enrollment.benefit.key、account.key、account.account_type、account.type)から選択され、hsa / health_savings / health_savings_accountに一致します。口座名は検索されません。これらのフィールドが存在しない場合、ツールはGET /v2/me/hsa-account-details/の口座IDにフォールバックします。すべての候補が404の場合、ツールはエラーを返し、そのget_hsa_account_detailsペイロードを含めます。これらの投資GETパスはリバースエンジニアリングされたものであり、すべての口座に存在するとは限りません。
ライセンス
MIT
Stdio
このサーバーはMCPをstdoutで話し、ログをstderrに書き込みます。build後にstartスクリプトを使用するか、開発中はdevスクリプトを使用してください。
Cursor
MCP設定(mcp.json)にbenepassエントリを追加し、このパッケージのコンパイル済みエントリを起動します。start_loginで認証し、次にcomplete_loginで認証します。
Cursor設定の例はcursor-mcp.example.jsonにあります。
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- FlicenseBqualityDmaintenanceEnables read-only access to FileMaker databases through the Data API, allowing users to retrieve records, analyze metadata, search across layouts, and infer relationships while maintaining data security.16
- AlicenseNot gradedqualityBmaintenanceEnables read-only interaction with App Store Connect via MCP tools, including listing apps, versions, builds, and review submissions, with compliance boundaries and no write operations by default.MIT
- AlicenseNot gradedqualityCmaintenanceRead-only access to Stripe data including customers, charges, subscriptions, balance, and invoices.12MIT
- AlicenseNot gradedqualityCmaintenanceEnables read-only access to Bity cryptocurrency account balances, market data (ticker, order book, trades), and order history via the official API.MIT
Related MCP Connectors
Read-only MCP access to sessions, funnels, campaigns, errors, live visitors, and anomalies.
Read-only access to your VortexIQ store data: audits, KPIs, alerts, Brand DNA, reports, Ask VIQ.
Read your Savee saves, boards and home feed, and search its public library. Read-only.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/brian7989/benepass-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server