Swagger MCP Server
Fetches and parses Swagger/OpenAPI documentation from any URL, enabling exploration of API schemas, testing of endpoints, and validation of API responses. Supports various authentication methods including API keys, basic auth, and bearer tokens.
Processes Swagger/OpenAPI documentation in YAML format, enabling the parsing and exploration of API definitions specified in YAML.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Swagger MCP Serverlist all endpoints for the user management API"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Swagger MCP Server
A Model Context Protocol (MCP) server that provides tools for exploring and testing APIs through Swagger/OpenAPI documentation. This server automatically detects configuration files from multiple IDEs and provides comprehensive API interaction capabilities.
Features
๐ Fetch and parse Swagger/OpenAPI documentation from any URL
๐งช Test API endpoints directly through the MCP interface
๐ Explore API schemas and understand data structures
๐ง Multi-IDE support - automatically detects config from VS Code, Cursor, Windsurf, and more
๐ Flexible authentication - supports API keys, basic auth, and bearer tokens
โก Auto-discovery - can find documentation URLs automatically
Related MCP server: MCP-QA
Configuration
IDE Setup
Create an MCP configuration file in your IDE's configuration directory:
VS Code:
~/.vscode/mcp.jsonor.vscode/mcp.json(in your project)Cursor:
~/.cursor/mcp.jsonor.cursor/mcp.json(in your project)Windsurf:
~/.windsurf/mcp.jsonor.windsurf/mcp.json(in your project)Any IDE:
mcp.json(in your project root) or.mcp/config.json
Authentication Options
Option 1: Using API Key
"swagger-mcp": {
"command": "npx",
"args": [
"-y",
"swagger-mcp@latest"
],
"env": {
"API_BASE_URL": "https://api.example.com",
"API_DOCS_URL": "https://api.example.com/swagger.json",
"API_KEY": "your-api-key-here"
}
}Option 2: Using Username and Password
"swagger-mcp": {
"command": "npx",
"args": [
"-y",
"swagger-mcp@latest"
],
"env": {
"API_BASE_URL": "https://api.example.com",
"API_DOCS_URL": "https://api.example.com/swagger.json",
"API_USERNAME": "your-username",
"API_PASSWORD": "your-password"
}
}Configuration Options
API_BASE_URL- Base URL for your API (e.g.,https://api.example.com) [Required]API_DOCS_URL- Direct URL to Swagger/OpenAPI JSON/YAML (optional, will be auto-discovered)API_KEY- API key for authentication (used as Bearer token)API_USERNAME- Username for basic authenticationAPI_PASSWORD- Password for basic authentication
Authentication Flow
The server intelligently handles authentication:
For API requests: Uses API_KEY as Bearer token, falls back to Basic auth
For authentication endpoints: Auto-injects username/password credentials
Token management: Automatically stores and reuses tokens from login responses
Auto-refresh: Attempts to refresh tokens on 401 Unauthorized responses
Available Tools
fetch_swagger_info
Fetches and parses Swagger/OpenAPI documentation from a given URL to discover available API endpoints.
list_endpoints
Lists all available API endpoints after fetching Swagger documentation, showing methods, paths, and summaries.
get_endpoint_details
Gets detailed information about a specific API endpoint including parameters, request/response schemas, and examples.
execute_api_request
Executes an API request to a specific endpoint with authentication, parameters, headers, and body handling.
validate_api_response
Validates an API response against the schema definitions from Swagger documentation to ensure compliance.
Usage Examples
Once configured, you can use the MCP server in your AI-powered editor to:
Explore APIs: "Show me the available endpoints in this API"
Test endpoints: "Test the POST /users endpoint with this data"
Understand schemas: "Explain the User model structure"
Debug API calls: "Help me troubleshoot this API request"
Validate responses: "Check if this response matches the API schema"
Supported IDEs
The server automatically detects configuration files from:
VS Code (
.vscode/mcp.json)Cursor (
.cursor/mcp.json)Windsurf (
.windsurf/mcp.json)Root directory (
mcp.json)Alternative location (
.mcp/config.json)
Development
# Clone the repository
git clone https://github.com/amrsa1/SwaggerMCP.git
cd SwaggerMCP
# Install dependencies
npm install
# Run in development mode
npm run dev
# Build for production
npm run buildLicense
MIT License - see LICENSE file for details.
Contributing
Contributions are welcome! Please feel free to submit a Pull Request.
Available Tools
5 toolsexecute_api_requestC
Execute an API request to a specific endpoint
| Name | Required | Description | Default |
|---|---|---|---|
| method | Yes | HTTP method (GET, POST, PUT, DELETE, etc.) | |
| path | Yes | The endpoint path (e.g., '/users/123') | |
| params | No | Query parameters as key-value pairs | |
| body | No | Request body as a JSON object (for POST/PUT/PATCH) | |
| headers | No | Custom headers as key-value pairs |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden of behavioral disclosure. It mentions executing an API request but doesn't disclose critical traits like authentication requirements, rate limits, error handling, or whether it's read-only or destructive. For a tool that likely interacts with external systems, this lack of information is a significant gap.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, efficient sentence: 'Execute an API request to a specific endpoint'. It is front-loaded and wastes no words, making it easy to parse quickly. Every part of the sentence contributes to the core purpose without redundancy.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity (5 parameters, no output schema, no annotations), the description is incomplete. It doesn't explain return values, error cases, or behavioral nuances, leaving the agent with insufficient context for effective use. For a general-purpose API tool, more detail is needed to ensure correct invocation.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has 100% description coverage, with clear documentation for all 5 parameters (e.g., method, path, params). The description adds no additional meaning beyond what the schema provides, such as examples or constraints. Since the schema does the heavy lifting, the baseline score of 3 is appropriate, but the description doesn't compensate or enhance parameter understanding.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states the tool's purpose as 'Execute an API request to a specific endpoint', which is clear but vague. It specifies the verb ('execute') and resource ('API request'), but doesn't distinguish it from sibling tools like 'fetch_swagger_info' or 'get_endpoint_details', which might also involve API interactions. The purpose is understandable but lacks specificity about what makes this tool unique.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives. It doesn't mention sibling tools like 'fetch_swagger_info' for documentation or 'validate_api_response' for validation, nor does it specify prerequisites or contexts for usage. This leaves the agent without clear direction on tool selection.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
fetch_swagger_infoA
Fetch Swagger/OpenAPI documentation to discover available API endpoints
| Name | Required | Description | Default |
|---|---|---|---|
| url | No | URL to the swagger.json or swagger.yaml file. If not provided, will try to use the base URL with common Swagger paths. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden. It describes the core behavior (fetching documentation for discovery) but lacks details about error handling, authentication requirements, rate limits, or what format the fetched documentation is returned in. The description doesn't contradict any annotations, but provides only basic behavioral context.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, efficient sentence that immediately states the tool's purpose without unnecessary words. It's appropriately sized for a simple tool with one parameter and front-loads the essential information about what the tool does.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's moderate complexity (fetching documentation from URLs), no annotations, and no output schema, the description is adequate but incomplete. It explains what the tool does but lacks information about return format, error conditions, or authentication requirements that would help an agent use it effectively.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The description doesn't mention parameters directly, but the single parameter has 100% schema description coverage that clearly explains its purpose and default behavior. With only one well-documented parameter, the description doesn't need to add parameter semantics, earning a baseline score above minimum viable.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the verb 'fetch' and the resource 'Swagger/OpenAPI documentation', specifying the action of retrieving API endpoint discovery information. It distinguishes from siblings like 'execute_api_request' (which performs API calls) and 'list_endpoints' (which might list already-discovered endpoints) by focusing on documentation discovery.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage context ('to discover available API endpoints'), suggesting this tool should be used when exploring an API's capabilities. However, it doesn't explicitly state when NOT to use it or name specific alternatives among the siblings, though the purpose differentiation provides some guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_endpoint_detailsC
Get detailed information about a specific API endpoint
| Name | Required | Description | Default |
|---|---|---|---|
| path | Yes | The endpoint path to get details for (e.g., '/users/{id}') | |
| method | Yes | The HTTP method (GET, POST, PUT, DELETE, etc.) |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It states this is a read operation ('Get'), but doesn't mention whether it requires authentication, has rate limits, what format the detailed information is returned in, or any error conditions. For a tool with zero annotation coverage, this is inadequate.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, efficient sentence that gets straight to the point with zero wasted words. It's appropriately sized for a simple tool and front-loads the essential information.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a tool with no annotations and no output schema, the description is insufficient. It doesn't explain what 'detailed information' includes, how results are formatted, or any behavioral aspects. Given the complexity of API endpoints and the lack of structured data, more context is needed for the agent to use this tool effectively.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema description coverage is 100%, with both parameters clearly documented in the input schema. The description doesn't add any additional meaning about the parameters beyond what's already in the schema, so it meets the baseline score when the schema does the heavy lifting.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the verb ('Get') and resource ('detailed information about a specific API endpoint'), making the purpose immediately understandable. However, it doesn't differentiate this tool from sibling tools like 'fetch_swagger_info' or 'list_endpoints' that might also provide API information, so it doesn't reach the highest score.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives like 'fetch_swagger_info' or 'list_endpoints'. It doesn't mention prerequisites, exclusions, or specific contexts for usage, leaving the agent to infer this from the tool name alone.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_endpointsB
List all available API endpoints after fetching Swagger documentation
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries full burden for behavioral disclosure. It states the tool lists endpoints after fetching Swagger documentation, implying a two-step process, but doesn't detail what 'fetching' entails (e.g., network calls, caching, errors) or the output format. This leaves significant gaps in understanding the tool's behavior.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, efficient sentence that directly states the tool's purpose without any fluff. It's appropriately sized and front-loaded, making it easy to understand at a glance.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity (involving Swagger fetching) and lack of annotations or output schema, the description is minimally adequate. It mentions the Swagger dependency but doesn't explain the return format or error handling, leaving room for improvement in completeness.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has 0 parameters with 100% coverage, so no parameter documentation is needed. The description appropriately doesn't discuss parameters, earning a high baseline score for not adding unnecessary information.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the action ('List all available API endpoints') and the resource ('API endpoints'), making the purpose unambiguous. However, it doesn't explicitly differentiate from sibling tools like 'get_endpoint_details' or 'fetch_swagger_info', which prevents a perfect score.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives like 'get_endpoint_details' or 'fetch_swagger_info'. It mentions fetching Swagger documentation, but doesn't clarify if this is a prerequisite or how it relates to other tools, leaving usage context unclear.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
validate_api_responseC
Validate an API response against the schema from Swagger documentation
| Name | Required | Description | Default |
|---|---|---|---|
| path | Yes | The endpoint path | |
| method | Yes | The HTTP method | |
| statusCode | Yes | The HTTP status code | |
| responseBody | Yes | The response body to validate |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden of behavioral disclosure. It states what the tool does but doesn't describe how it behaves: e.g., whether it returns validation results, errors, or passes/fails; if it requires pre-loaded Swagger docs; or any performance or rate-limiting considerations. This leaves significant gaps for a validation tool.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, efficient sentence that directly states the tool's purpose without unnecessary words. It's appropriately sized and front-loaded, making it easy to understand quickly.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's complexity (validating API responses against schemas) and lack of annotations and output schema, the description is incomplete. It doesn't explain what the tool returns (e.g., validation results, errors), how it accesses Swagger documentation, or any behavioral traits, leaving the agent with insufficient context for effective use.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has 100% description coverage, with all parameters documented. The description doesn't add any meaning beyond what the schema provides (e.g., it doesn't explain parameter relationships or validation specifics). With high schema coverage, the baseline is 3, as the schema does the heavy lifting.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose: 'Validate an API response against the schema from Swagger documentation.' It specifies the verb ('validate') and resource ('API response'), but doesn't explicitly differentiate from sibling tools like 'execute_api_request' or 'fetch_swagger_info' that might handle related but different operations.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives. It doesn't mention prerequisites (e.g., needing Swagger documentation loaded), when not to use it, or how it relates to siblings like 'execute_api_request' (which might produce responses to validate) or 'fetch_swagger_info' (which might provide schemas).
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
TDQS
Each tool has a clearly distinct purpose with no overlap: fetching documentation, listing endpoints, getting endpoint details, executing requests, and validating responses. The descriptions make it easy to tell them apart, and there is no ambiguity in their functions.
All tool names follow a consistent verb_noun pattern (e.g., execute_api_request, fetch_swagger_info). The naming is uniform and predictable, using snake_case throughout without any deviations or mixed conventions.
With 5 tools, the server is well-scoped for its purpose of interacting with Swagger/OpenAPI documentation and executing API requests. Each tool serves a specific role in the workflow, and the count is neither too sparse nor excessive for the domain.
The tool set provides complete coverage for the Swagger/OpenAPI domain: it supports fetching documentation, discovering endpoints, getting details, executing requests, and validating responses. There are no obvious gaps, and agents can perform a full lifecycle from discovery to execution and validation.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
MCP server for AI access to Swagger by SmartBear.
Read-only MCP server over the APIs.io catalog โ discover APIs, providers, tags & artifacts.
APIs.guru MCP โ keyless directory of 2,500+ public APIs and their OpenAPI specs.
MCP server for AI access to SmartBear tools, including BugSnag, Reflect, Swagger, PactFlow, QTM4J.
Related MCP Servers
- AlicenseNot gradedqualityAmaintenanceMCP server providing token-efficient access to OpenAPI/Swagger specs via MCP Resources for client-side exploration.23476MIT
- FlicenseNot gradedqualityDmaintenanceAn MCP server for the comprehensive analysis of Swagger 2.0 and OpenAPI 3.x contracts. It allows users to extract detailed information about endpoints, request/response schemas, parameters, and security configurations from API documentation.
- AlicenseNot gradedqualityDmaintenanceA dynamic MCP server that automatically discovers and generates tools from any REST API using OpenAPI/Swagger specifications, enabling instant endpoint access with zero manual configuration.MIT
- AlicenseNot gradedqualityDmaintenanceAn MCP server that enables AI agents to explore, search, and query API definitions from OpenAPI/Swagger JSON files.59MIT
Appeared in Searches
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/amrsa1/swagger-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server