Skip to content

Releases: blackwaxxx/Buildium-MCP

buildium-mcp 0.2.1

Choose a tag to compare

@blackwaxxx blackwaxxx released this 23 Sep 12:49

Security hardening and usability fixes. Nothing breaks: in Claude Desktop, install this file over 0.2.0; your saved Client ID and Secret are kept.

Security

  • The build and release workflows are locked to exact code. Every GitHub Action they use is pinned to a specific commit instead of a version tag the action's owner could move. These workflows build the Claude Desktop bundle and publish to PyPI, so a compromised action can no longer slip into a release.

Usability

  • Every tool parameter is now described in the tool's schema, so clients can show what each one means.
  • The "Allow changes in production" setting now says what it actually allows. On its own, it lets Claude create new test records named with the ZZ-MCPTEST- prefix and work on those. Editing your existing records takes that toggle plus "Allow changing records this session did not create".
  • Startup errors now say to restart the server after you fix the problem. Configuration is read once, at startup, so before this a correct fix looked like it hadn't worked.
  • The custom-field values endpoint works. It takes a list, which buildium_call_endpoint couldn't send before.

Install

Claude Desktop: download buildium-mcp-0.2.1.mcpb below and double-click it. The dialog labels the bundle unsigned; that is expected, see KNOWN-LIMITATIONS.md.

Other MCP clients: pip install --upgrade buildium-mcp. The wheel and source archive are also attached below.

SHA-256:

ebe3d9fe510a2a4340839fe08e41a7d0e3a1d4a354208504630807a1c4df1a52  buildium-mcp-0.2.1.mcpb
30dfe093885140c875ea3f038c188e25deb28ef36a1bbdb60ee940168cae9ec9  buildium_mcp-0.2.1-py3-none-any.whl
84d6e7ede5e61c26c155419b47b60e74ea6fa758116535ff34a1761237c6146a  buildium_mcp-0.2.1.tar.gz

Full notes in CHANGELOG.md. Unofficial; not affiliated with Buildium.

buildium-mcp 0.2.0

Choose a tag to compare

@blackwaxxx blackwaxxx released this 23 Sep 12:24

Security update, with one breaking change to downloads (see Upgrading). In Claude Desktop, install this file over the old one; your saved Client ID and Secret are kept.

Security fixes

  • Downloads stay in one folder. buildium_download_file used to write wherever it was told. Text planted in a work order, plus a file a tenant uploaded, could have Claude save that file over ~/.zshrc. Files now go only into ~/Downloads/Buildium (or BUILDIUM_DOWNLOAD_DIR), symlinks can't escape it, and an existing file is kept unless you pass overwrite=true. The tool is no longer marked read-only, so clients ask before running it.
  • Uploads refuse the places credentials live: hidden files and folders (~/.ssh, .env), *.env files, and this server's own configuration and logs.
  • Fixtures mode no longer lets a create change an existing production record. A renewal of a real lease, or a charge on one, now needs that lease to have been created in the same session, the same rule that already applied to edits.
  • Logs and downloads are private to you. This mattered most on Linux, where the log folder is usually readable by other users.
  • Build hardening: CI runs with a read-only token, and the tool that packs this bundle is pinned to a fixed version.

New

  • buildium_get: a read-only tool for any Buildium read. Your client can approve it once and still ask before every write. Before, reads and writes shared one tool, so every read asked too.
  • buildium_health shows where downloads go.

Upgrading

  • Downloads: save_to is now a name or a path inside the download folder. A path outside it is an error. If you saved files somewhere else, set BUILDIUM_DOWNLOAD_DIR to that folder.
  • Tool count: there are now 20 tools instead of 19.

Install

Claude Desktop: download buildium-mcp-0.2.0.mcpb below and double-click it. The dialog labels the bundle unsigned; that is expected, see KNOWN-LIMITATIONS.md.

Other MCP clients: pip install --upgrade buildium-mcp. The wheel and source archive are also attached below.

SHA-256:

5a1c05893a76a04532f91ba45c7c30b469117bffd3b9192f7294dcdd15eae121  buildium-mcp-0.2.0.mcpb
963e952586f06d8aa6a3652a4c9c94c4aafb77052232fb6376036d58d4d3f6a5  buildium_mcp-0.2.0-py3-none-any.whl
52a4dfae3cc40701565a18de42622368656e591c795be9901043b9913befa7cc  buildium_mcp-0.2.0.tar.gz

Full notes in CHANGELOG.md. Unofficial; not affiliated with Buildium.

buildium-mcp 0.1.2

Choose a tag to compare

@blackwaxxx blackwaxxx released this 23 Sep 11:45

Security update. If you run 0.1.1 or 0.1.0, please upgrade. In Claude Desktop, install this file over the old one; your saved Client ID and Secret are kept.

Security fixes

  • A .env file could redirect your API traffic. The server imported every variable from any .env it found, including one in whatever folder your MCP client launched it from. A .env setting HTTPS_PROXY and SSL_CERT_FILE, such as one in a cloned repository opened in Claude Code, could send the request carrying your Buildium client secret through a proxy that could read it. Now only BUILDIUM_* settings are read, and the launch folder isn't searched.
  • Installing into another project's virtualenv made that project's .env look like this server's own. Fixed.
  • A blank BUILDIUM_FIXTURE_PREFIX switched off the fixtures-mode name check, because every name starts with an empty string. A blank value now means the default prefix.
  • Fixtures mode now checks nested names (a new lease's tenants, not just the lease), and refuses creates that have no name field when pointed at production.

Large accounts

  • buildium_lease_roster now reads the whole account. Before, it silently read only the first 100 tenants. It now reads up to 100,000 and reports complete. Looking up a single lease takes two requests, however big the account is. A new lease_status filter skips past tenants.
  • New count_only=true on every list tool and on buildium_call_endpoint. "How many active leases?" is one call in any account, counting up to 100,000 records.

Other fixes

  • A Retry-After header in date form no longer crashes a tool.
  • A broken TLS or proxy setting in the environment now shows up in buildium_health with a fix, instead of crashing every tool.

Heads-up

  • .env in the working directory is no longer read. If you relied on one, set BUILDIUM_ENV_FILE to its path, move it to the config directory buildium_health reports, or pass the keys in your MCP client's env block.
  • buildium_lease_roster's limit is now a page size. It doesn't cap the result.

Install

Claude Desktop: download buildium-mcp-0.1.2.mcpb below and double-click it. The dialog labels the bundle unsigned; that is expected, see KNOWN-LIMITATIONS.md.

Other MCP clients: pip install "git+https://github.com/blackwaxxx/Buildium-MCP@v0.1.2", or use the wheel attached below. This project isn't on PyPI yet, so don't pip install buildium-mcp: a package under that name wouldn't be this one.

SHA-256:

67eb761355e94feb88e71f4be488175c25eeaf794ca738136f48731bc75cbd88  buildium-mcp-0.1.2.mcpb
c0c5b32c79720075981a7acf3b9843bdcebe75d1ccd2b18575493e6e1321a31a  buildium_mcp-0.1.2-py3-none-any.whl
bcb574d3c5a610608ec8059abfe19ee9b2d689c979165f196cabb8f7a8701907  buildium_mcp-0.1.2.tar.gz

Full notes in CHANGELOG.md. Unofficial; not affiliated with Buildium.

buildium-mcp 0.1.1

Choose a tag to compare

@blackwaxxx blackwaxxx released this 19 Sep 03:03

Superseded by v0.1.2, which fixes security issues in this release. Please install that instead.

Settings-form update for the Claude Desktop extension. If you installed 0.1.0, install this file over it; your saved Client ID and Secret are kept.

What changed

  • Toggles instead of typing. The deployment mode is now three on/off switches — Connect to production, Allow changes in production, Allow file downloads in production — plus one for the write mode. Everything off is the sandbox. Live changes take two switches. The server's own safety checks are unchanged; the bundle just sets the same variables from the switches.
  • Fix: the bundle's launcher discarded the credentials from the settings form. Caught by the new bundle smoke test before this release was cut, but 0.1.0's bundle has it — please update.
  • The install dialog's "access to everything on this computer" text is shown for every local extension; mcpb/README.md now says exactly what this one touches.

Install in Claude Desktop (one click)

Download buildium-mcp-0.1.1.mcpb below and double-click it, or drag it onto the Claude Desktop window. Enter your Buildium Client ID and Client Secret when asked. The dialog labels the bundle unsigned; that is expected — see KNOWN-LIMITATIONS.md.

The wheel and source archive are attached for other MCP clients. Full notes in CHANGELOG.md. Unofficial; not affiliated with Buildium.

buildium-mcp 0.1.0

Choose a tag to compare

@blackwaxxx blackwaxxx released this 17 Sep 05:04

Superseded by v0.1.2, which fixes security issues in this release. Please install that instead.

First public release of buildium-mcp: an MCP server for the Buildium Open API. All 462 operations through 19 tools, sandbox by default, read-only production modes enforced at the transport layer.

Install in Claude Desktop (one click)

Download buildium-mcp-0.1.0.mcpb below and double-click it, or drag it onto the Claude Desktop window. Claude Desktop asks for your Buildium Client ID and Client Secret in a settings form and installs everything else itself, including Python if your machine has none. The install dialog labels the bundle unsigned; that is expected — see KNOWN-LIMITATIONS.md.

You need a Buildium Premium subscription with the Open API enabled and an API key from Settings → Developer Tools. Sandbox and production are separate Buildium accounts with separate keys.

Any other MCP client

The wheel and source archive are attached for pip install. See the README for configuration.

Safety model

  • Sandbox is the default. Reaching production takes two deliberate settings: BUILDIUM_DEPLOYMENT_MODE and a production BUILDIUM_BASE_URL.
  • production-readonly and production-readonly-files refuse every non-read request in the HTTP transport, before a socket opens. production-readonly-files exempts exactly Buildium's seven file-download endpoints.
  • In fixtures write mode (the default), created records must carry the ZZ-MCPTEST- prefix and only records created in the current session can be changed or deleted.

Full details in CHANGELOG.md, SECURITY.md and ARCHITECTURE.md. Unofficial; not affiliated with Buildium.