Skip to main content
Glama

mcp-web

An MCP server that gives a locally-run LLM access to the internet: web search, page fetching, raw HTTP, and optional headless rendering. Built for LM Studio, but it is a plain stdio MCP server and works with any MCP client.

Tools

Tool

What it does

web_search

DuckDuckGo search. Returns title, url, snippet.

fetch_url

Fetches a page and returns its main content as markdown.

http_request

Arbitrary HTTP method/headers/body. For JSON APIs.

render_page

Loads a page in headless Chromium, runs its JS, returns text. Registered only when the browser extra is installed.

Related MCP server: mcp-web-tools

Install

uv venv
uv pip install -e .

With headless rendering:

uv pip install -e ".[browser]"
uv run playwright install chromium

Wiring into LM Studio

LM Studio reads ~/.lmstudio/mcp.json (also reachable from the Program tab in the right sidebar → Install → Edit mcp.json). Add:

{
  "mcpServers": {
    "mcp-web": {
      "command": "/Users/YOU/mcp-web/.venv/bin/mcp-web"
    }
  }
}

Then load a tool-capable model and enable the server for the chat. LM Studio asks for confirmation before each tool call by default.

Security

Local models are talked into things. Every outbound request in this server — including redirects and browser navigations — goes through net/guard.py, which resolves the hostname and refuses:

  • loopback, RFC1918, link-local, reserved, and multicast addresses

  • cloud metadata endpoints (169.254.169.254)

  • anything but http and https

  • IPv4 addresses disguised as IPv6 (::ffff:127.0.0.1) or as integers (http://2130706433/)

Without this, http_request would hand the model your router admin page and every service you have bound to localhost.

Known gap: the guard resolves DNS, then httpx resolves it again to connect. A hostile authoritative nameserver can answer differently the second time (DNS rebinding) and reach a private address. Closing this needs a custom transport that connects to the already-validated IP. Acceptable for a local tool on a trusted network; not acceptable if you ever expose this server.

Configuration

All optional, all environment variables:

Variable

Default

Meaning

MCPWEB_ALLOW_PRIVATE

0

1 lets the model reach localhost and your LAN

MCPWEB_ALLOWLIST

empty

Comma-separated hosts; when set, nothing else is reachable

MCPWEB_TIMEOUT

20

Per-request timeout, seconds

MCPWEB_MAX_BYTES

2000000

Response body cap

MCPWEB_MAX_REDIRECTS

5

Redirect hop limit

MCPWEB_USER_AGENT

Chrome-ish

Sent on every request

Tests

uv run pytest

Available Tools

3 tools
fetch_urlA

Fetch a web page and return its main content as markdown.

Use this for ordinary pages and articles. If the result looks empty or is obviously a JavaScript shell, retry with render_page.

ParametersJSON Schema
NameRequiredDescriptionDefault
urlYes
max_charsNo

TDQS

A4.1/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are present, so the description carries the burden of behavior. It discloses the markdown-conversion behavior and hints that JavaScript-heavy pages are not handled, but it does not explicitly state that JavaScript is not executed, nor does it describe truncation via max_chars, error cases, or request-side effects.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three short sentences, with the core purpose first, usage guidance second, and the conditional fallback last. Every sentence contributes meaningful information with no filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a simple two-parameter fetch tool without an output schema, the description covers purpose, output format, and a key failure mode. It is slightly incomplete around max_chars semantics and does not mention whether the request is static-only, but it is otherwise sufficient.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0% and the description adds no parameter-level detail. 'url' is inferable from the first sentence, but 'max_chars' is never explained even though it has a default and likely controls output truncation.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description starts with a specific verb and resource ('Fetch a web page') and states the output format ('main content as markdown'). It also distinguishes itself from the JavaScript-rendering alternative by targeting 'ordinary pages and articles', making the tool's role clear relative to siblings.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It explicitly says when to use the tool ('ordinary pages and articles') and provides a concrete fallback condition ('If the result looks empty or is obviously a JavaScript shell, retry with render_page'). This is direct when/when-not guidance with a named alternative.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

http_requestA

Make an arbitrary HTTP request and return the raw response.

Use this for JSON APIs. For reading web pages prefer fetch_url, which strips navigation and boilerplate.

ParametersJSON Schema
NameRequiredDescriptionDefault
urlYes
bodyNo
methodNoGET
headersNo
max_charsNo

TDQS

A4/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the full burden. It does disclose that the tool returns the raw response and makes arbitrary requests, which is useful. However, it does not mention that the response may be truncated or limited by max_chars, nor does it discuss error behavior, redirects, or authentication. These are meaningful gaps for an unrestricted HTTP client.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is two sentences with no filler. The core function is front-loaded in the first sentence, and the second sentence provides direct routing guidance. Every word earns its place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a generic HTTP tool with 5 parameters, no output schema, and no annotations, the description is adequate but incomplete. It clearly explains what the tool does and when to use it, but leaves key invocation details such as response truncation, parameter roles, and error handling entirely to inference.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, so the description must compensate for undocumented parameters. It does not mention url, method, body, headers, or max_chars by name or explain their semantics. The phrase 'arbitrary HTTP request' loosely implies method and body flexibility, but max_chars is completely unexplained.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb and resource: 'Make an arbitrary HTTP request and return the raw response.' It also distinguishes itself from fetch_url by noting that fetch_url is preferred for web pages. This clearly separates the tool from its siblings.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explicitly says 'Use this for JSON APIs' and provides a direct alternative: 'For reading web pages prefer fetch_url.' This gives an agent a clear decision rule for when to use this tool versus a sibling.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

TDQS

A4/5.0
Disambiguation5/5

Each tool has a clearly distinct role: web_search finds pages, fetch_url converts pages to markdown, and http_request handles raw API calls. The descriptions also explicitly steer agents toward the right tool, so confusion is unlikely.

Naming Consistency4/5

web_search and fetch_url follow a clean verb_noun pattern, while http_request is a noun phrase and breaks the pattern. Overall the names are still simple, lowercase, and readable, with only one minor deviation.

Tool Count5/5

Three tools is a reasonable, well-scoped size for a focused web access server. Each tool earns its place and there is no obvious redundancy.

Completeness3/5

The basic search/fetch/request workflow is covered, but fetch_url explicitly tells agents to retry with render_page for JavaScript-heavy pages while render_page does not exist in the tool set. This creates a notable dead end for those pages and makes the surface feel incomplete.

Maintenance

ActivityMaintained
ResponsivenessNo issues

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    D
    maintenance
    Provides web search and page fetch capabilities using a browser-based approach, enabling LLMs to search DuckDuckGo, Google, or Yandex and retrieve rendered HTML from URLs.
    3
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables local LLMs to search the web, scrape pages, and extract structured data (tables, metadata) from sources like Wikipedia and IMDb, with caching and rate limiting.
    MIT

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/MrDadpool/mcp-web'

If you have feedback or need assistance with the MCP directory API, please join our Discord server