gateway
Server Details
Find and call the right MCP server for any task - pay per use, no install.
- Status
- Healthy
- Uptime
- 100.0% over 36 days
- Last Tested
- Transport
- Streamable HTTP · MCP 2025-11-25
- URL
- Repository
- toolhail/toolbroker
- GitHub Stars
- 0
- Server Listing
- ToolHail
TDQS
Scored across 2 tools
The two tools have clearly distinct purposes: one for proxying tool calls with security guards, the other for discovering servers. No overlap.
Both tool names follow a verb_noun pattern in snake_case, maintaining consistency.
With only 2 tools, the surface is minimal, but they cover the core proxy and discovery functions. Could benefit from additional tools like listing available servers or managing connections.
The tool set lacks basic discovery functionality (e.g., listing servers) and management tools, making it incomplete for a gateway's full lifecycle.
Available Tools
2 toolscall_toolAInspect
Proxy one tool call to a discovered remote MCP server (paid). Every call passes pre-execution guards before anything runs: tools on TOOLHAIL_BLOCKED_TOOLS are always refused; when TOOLHAIL_ALLOWED_TOOLS is set (non-empty, no "*") only listed tools may fire; write/mutating-looking tool names are refused unless allowWrite:true is passed or the tool is allowlisted; and TOOLHAIL_ARG_LIMITS can cap specific argument values per tool (e.g. daily_budget<=500) so an allowlisted broad tool still cannot push a value past its ceiling. Any refusal executes nothing and bills nothing, and every receipt records the gate decision.
| Name | Required | Description | Default |
|---|---|---|---|
| url | Yes | Remote MCP server URL (the "remotes[].url" from a find_mcp_server result). | |
| args | No | Arguments object to pass to the tool. | |
| toolName | Yes | Name of the tool to call on that server. | |
| allowWrite | No | Explicit acknowledgement that a write/mutating call is intended. Tool names that look like writes (create/update/delete/send/pay/deploy/...) are refused by default — nothing executed, nothing billed — unless this is true or the tool is on TOOLHAIL_ALLOWED_TOOLS. Set it only when the mutation is deliberate and vetted; never set it reflexively to get past a refusal. | |
| maxSpendUsd | No | Spend cap. Refuse the call — nothing executed, nothing billed — if the gateway fee would exceed this many USD. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description bears full responsibility for behavioral disclosure. It details pre-execution guards, refusal conditions, billing, and receipt recording. It explains that write tools are refused by default unless allowWrite or allowed, and that no execution or billing occurs on refusal. This is comprehensive and transparent.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is relatively long but every sentence adds unique value. It front-loads the core purpose and then elaborates on guards. While it could be restructured with bullet points for readability, it is not excessively verbose and earns its length.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity (5 parameters, no output schema, guards, billing), the description covers nearly all necessary aspects: purpose, guards, billing, refusal conditions. It does not detail the receipt structure but mentions it records the gate decision. This is reasonably complete for an agent.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so the schema already documents all parameters. The description adds valuable context: it explains allowWrite's role in bypassing write refusal and maxSpendUsd as a spend cap, and it links url to results from find_mcp_server. This adds meaning beyond the schema, though the schema already does heavy lifting.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose: 'Proxy one tool call to a discovered remote MCP server (paid).' It uses a specific verb (proxy) and resource (tool call to remote MCP server), and the sibling tool find_mcp_server is for discovery, so this tool is clearly for execution after discovery.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides strong guidance on when to use (after discovering a server via find_mcp_server) and explicit conditions for refusal (blocked tools, allowed tools, write lookahead, argument limits). It could explicitly state 'use this after find_mcp_server' but the context makes it clear.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
find_mcp_serverDInspect
| Name | Required | Description | Default |
|---|---|---|---|
| query | Yes | Plain-language description of the capability you need, e.g. 'query a Postgres database'. | |
| maxResults | No | How many ranked matches to return (default 5). | |
| requireRemote | No | Only return servers with a hosted remote endpoint (usable immediately). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Tool has no description.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Tool has no description.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Tool has no description.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Tool has no description.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Tool has no description.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Tool has no description.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
1 tool update
- Changed
call_tool1 field changed- added
Input schema / properties / allowWriteAdded value: +{ + "description": "Explicit acknowledgement that a write/mutating call is intended. Tool names that look like writes (create/update/delete/send/pay/deploy/...) are refused by default — nothing executed, nothing billed — unless this is true or the tool is on TOOLHAIL_ALLOWED_TOOLS. Set it only when the mutation is deliberate and vetted; never set it reflexively to get past a refusal.", + "type": "boolean" +}
2 tool updates
- First observed
call_tool - First observed
find_mcp_server
Related MCP Connectors
Search 33,000+ MCP servers by job, see safety grades and reviews, and call them from one endpoint.
Discover and call 10,000+ production APIs from one MCP server. Pay-per-call billing for AI agents.
Find an MCP server for any task: searches the official registry, Smithery and npm; remote-first.
Pay-per-use tool marketplace for AI agents. Search, price-check, and call APIs via MCP.
Related MCP Servers
AlicenseNot gradedqualityBmaintenanceHosted remote MCP server that gives AI assistants live tools to run jobs on demand and returns a receipt URL for each observed call. Connects via a single URL with no account required on the free tier, supporting optional paid access.MIT- FlicenseNot gradedqualityCmaintenancePay-per-use tool marketplace for AI agents. Search, price-check, and call APIs via MCP.-
- AlicenseNot gradedqualityBmaintenanceMarketplace of MCP servers and APIs that agents pay for per call in USDC over x402 on Base; connect anonymously, pay only when you callMIT
- AlicenseNot gradedqualityFmaintenanceTool search engine for AI agents. One API call to discover the best MCP server for any task. 900+ services indexed with 4-dimensional value ranking.MIT
Glama MCP Gateway
Add one secure layer between your agents and this server.