Releases: blackwaxxx/Buildium-MCP
Release list
buildium-mcp 0.2.1
Security hardening and usability fixes. Nothing breaks: in Claude Desktop, install this file over 0.2.0; your saved Client ID and Secret are kept.
Security
- The build and release workflows are locked to exact code. Every GitHub Action they use is pinned to a specific commit instead of a version tag the action's owner could move. These workflows build the Claude Desktop bundle and publish to PyPI, so a compromised action can no longer slip into a release.
Usability
- Every tool parameter is now described in the tool's schema, so clients can show what each one means.
- The "Allow changes in production" setting now says what it actually allows. On its own, it lets Claude create new test records named with the
ZZ-MCPTEST-prefix and work on those. Editing your existing records takes that toggle plus "Allow changing records this session did not create". - Startup errors now say to restart the server after you fix the problem. Configuration is read once, at startup, so before this a correct fix looked like it hadn't worked.
- The custom-field values endpoint works. It takes a list, which
buildium_call_endpointcouldn't send before.
Install
Claude Desktop: download buildium-mcp-0.2.1.mcpb below and double-click it. The dialog labels the bundle unsigned; that is expected, see KNOWN-LIMITATIONS.md.
Other MCP clients: pip install --upgrade buildium-mcp. The wheel and source archive are also attached below.
SHA-256:
ebe3d9fe510a2a4340839fe08e41a7d0e3a1d4a354208504630807a1c4df1a52 buildium-mcp-0.2.1.mcpb
30dfe093885140c875ea3f038c188e25deb28ef36a1bbdb60ee940168cae9ec9 buildium_mcp-0.2.1-py3-none-any.whl
84d6e7ede5e61c26c155419b47b60e74ea6fa758116535ff34a1761237c6146a buildium_mcp-0.2.1.tar.gz
Full notes in CHANGELOG.md. Unofficial; not affiliated with Buildium.
buildium-mcp 0.2.0
Security update, with one breaking change to downloads (see Upgrading). In Claude Desktop, install this file over the old one; your saved Client ID and Secret are kept.
Security fixes
- Downloads stay in one folder.
buildium_download_fileused to write wherever it was told. Text planted in a work order, plus a file a tenant uploaded, could have Claude save that file over~/.zshrc. Files now go only into~/Downloads/Buildium(orBUILDIUM_DOWNLOAD_DIR), symlinks can't escape it, and an existing file is kept unless you passoverwrite=true. The tool is no longer marked read-only, so clients ask before running it. - Uploads refuse the places credentials live: hidden files and folders (
~/.ssh,.env),*.envfiles, and this server's own configuration and logs. - Fixtures mode no longer lets a create change an existing production record. A renewal of a real lease, or a charge on one, now needs that lease to have been created in the same session, the same rule that already applied to edits.
- Logs and downloads are private to you. This mattered most on Linux, where the log folder is usually readable by other users.
- Build hardening: CI runs with a read-only token, and the tool that packs this bundle is pinned to a fixed version.
New
buildium_get: a read-only tool for any Buildium read. Your client can approve it once and still ask before every write. Before, reads and writes shared one tool, so every read asked too.buildium_healthshows where downloads go.
Upgrading
- Downloads:
save_tois now a name or a path inside the download folder. A path outside it is an error. If you saved files somewhere else, setBUILDIUM_DOWNLOAD_DIRto that folder. - Tool count: there are now 20 tools instead of 19.
Install
Claude Desktop: download buildium-mcp-0.2.0.mcpb below and double-click it. The dialog labels the bundle unsigned; that is expected, see KNOWN-LIMITATIONS.md.
Other MCP clients: pip install --upgrade buildium-mcp. The wheel and source archive are also attached below.
SHA-256:
5a1c05893a76a04532f91ba45c7c30b469117bffd3b9192f7294dcdd15eae121 buildium-mcp-0.2.0.mcpb
963e952586f06d8aa6a3652a4c9c94c4aafb77052232fb6376036d58d4d3f6a5 buildium_mcp-0.2.0-py3-none-any.whl
52a4dfae3cc40701565a18de42622368656e591c795be9901043b9913befa7cc buildium_mcp-0.2.0.tar.gz
Full notes in CHANGELOG.md. Unofficial; not affiliated with Buildium.
buildium-mcp 0.1.2
Security update. If you run 0.1.1 or 0.1.0, please upgrade. In Claude Desktop, install this file over the old one; your saved Client ID and Secret are kept.
Security fixes
- A
.envfile could redirect your API traffic. The server imported every variable from any.envit found, including one in whatever folder your MCP client launched it from. A.envsettingHTTPS_PROXYandSSL_CERT_FILE, such as one in a cloned repository opened in Claude Code, could send the request carrying your Buildium client secret through a proxy that could read it. Now onlyBUILDIUM_*settings are read, and the launch folder isn't searched. - Installing into another project's virtualenv made that project's
.envlook like this server's own. Fixed. - A blank
BUILDIUM_FIXTURE_PREFIXswitched off the fixtures-mode name check, because every name starts with an empty string. A blank value now means the default prefix. - Fixtures mode now checks nested names (a new lease's tenants, not just the lease), and refuses creates that have no name field when pointed at production.
Large accounts
buildium_lease_rosternow reads the whole account. Before, it silently read only the first 100 tenants. It now reads up to 100,000 and reportscomplete. Looking up a single lease takes two requests, however big the account is. A newlease_statusfilter skips past tenants.- New
count_only=trueon every list tool and onbuildium_call_endpoint. "How many active leases?" is one call in any account, counting up to 100,000 records.
Other fixes
- A
Retry-Afterheader in date form no longer crashes a tool. - A broken TLS or proxy setting in the environment now shows up in
buildium_healthwith a fix, instead of crashing every tool.
Heads-up
.envin the working directory is no longer read. If you relied on one, setBUILDIUM_ENV_FILEto its path, move it to the config directorybuildium_healthreports, or pass the keys in your MCP client'senvblock.buildium_lease_roster'slimitis now a page size. It doesn't cap the result.
Install
Claude Desktop: download buildium-mcp-0.1.2.mcpb below and double-click it. The dialog labels the bundle unsigned; that is expected, see KNOWN-LIMITATIONS.md.
Other MCP clients: pip install "git+https://github.com/blackwaxxx/Buildium-MCP@v0.1.2", or use the wheel attached below. This project isn't on PyPI yet, so don't pip install buildium-mcp: a package under that name wouldn't be this one.
SHA-256:
67eb761355e94feb88e71f4be488175c25eeaf794ca738136f48731bc75cbd88 buildium-mcp-0.1.2.mcpb
c0c5b32c79720075981a7acf3b9843bdcebe75d1ccd2b18575493e6e1321a31a buildium_mcp-0.1.2-py3-none-any.whl
bcb574d3c5a610608ec8059abfe19ee9b2d689c979165f196cabb8f7a8701907 buildium_mcp-0.1.2.tar.gz
Full notes in CHANGELOG.md. Unofficial; not affiliated with Buildium.
buildium-mcp 0.1.1
Superseded by v0.1.2, which fixes security issues in this release. Please install that instead.
Settings-form update for the Claude Desktop extension. If you installed 0.1.0, install this file over it; your saved Client ID and Secret are kept.
What changed
- Toggles instead of typing. The deployment mode is now three on/off switches — Connect to production, Allow changes in production, Allow file downloads in production — plus one for the write mode. Everything off is the sandbox. Live changes take two switches. The server's own safety checks are unchanged; the bundle just sets the same variables from the switches.
- Fix: the bundle's launcher discarded the credentials from the settings form. Caught by the new bundle smoke test before this release was cut, but 0.1.0's bundle has it — please update.
- The install dialog's "access to everything on this computer" text is shown for every local extension; mcpb/README.md now says exactly what this one touches.
Install in Claude Desktop (one click)
Download buildium-mcp-0.1.1.mcpb below and double-click it, or drag it onto the Claude Desktop window. Enter your Buildium Client ID and Client Secret when asked. The dialog labels the bundle unsigned; that is expected — see KNOWN-LIMITATIONS.md.
The wheel and source archive are attached for other MCP clients. Full notes in CHANGELOG.md. Unofficial; not affiliated with Buildium.
buildium-mcp 0.1.0
Superseded by v0.1.2, which fixes security issues in this release. Please install that instead.
First public release of buildium-mcp: an MCP server for the Buildium Open API. All 462 operations through 19 tools, sandbox by default, read-only production modes enforced at the transport layer.
Install in Claude Desktop (one click)
Download buildium-mcp-0.1.0.mcpb below and double-click it, or drag it onto the Claude Desktop window. Claude Desktop asks for your Buildium Client ID and Client Secret in a settings form and installs everything else itself, including Python if your machine has none. The install dialog labels the bundle unsigned; that is expected — see KNOWN-LIMITATIONS.md.
You need a Buildium Premium subscription with the Open API enabled and an API key from Settings → Developer Tools. Sandbox and production are separate Buildium accounts with separate keys.
Any other MCP client
The wheel and source archive are attached for pip install. See the README for configuration.
Safety model
- Sandbox is the default. Reaching production takes two deliberate settings:
BUILDIUM_DEPLOYMENT_MODEand a productionBUILDIUM_BASE_URL. production-readonlyandproduction-readonly-filesrefuse every non-read request in the HTTP transport, before a socket opens.production-readonly-filesexempts exactly Buildium's seven file-download endpoints.- In
fixtureswrite mode (the default), created records must carry theZZ-MCPTEST-prefix and only records created in the current session can be changed or deleted.
Full details in CHANGELOG.md, SECURITY.md and ARCHITECTURE.md. Unofficial; not affiliated with Buildium.