Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
FOFA_KEYNoFOFA API Key
QUAKE_KEYNo360 Quake API Key
FOFA_EMAILNoFOFA Email, optional
HUNTER_KEYNoHunter 通用 fallback API Key
ZOOMEYE_API_KEYNoZoomEye API Key
HUNTER_PERSONAL_KEYNoHunter 个人版 API Key,优先于 HUNTER_KEY
HUNTER_ENTERPRISE_KEYNoHunter 企业版 API Key,优先于 HUNTER_KEY

Capabilities

Features and capabilities supported by this server

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
fofa_searchB

Search FOFA assets with /api/v1/search/all. Query is encoded as qbase64. Supported fields include: ip, port, protocol, country, country_name, region, city, longitude, latitude, asn, org, host, domain, os, server, icp, title, jarm, header, banner, cert, base_protocol, link, cert.issuer.org, cert.issuer.cn, cert.subject.org, cert.subject.cn, tls.ja3s, tls.version, cert.sn, cert.not_before, cert.not_after, cert.domain, status_code, header_hash, banner_hash, banner_fid, cname, lastupdatetime, product, product_category, product.version, icon_hash, cert.is_valid, cname_domain, body, cert.is_match, cert.is_equal, icon, fid, structinfo.

fofa_search_nextB

Search FOFA assets with /api/v1/search/next. Use returned next value for stable continuous pagination over a large result set.

fofa_search_statsA

Aggregate FOFA search results with /api/v1/search/stats. Calls are throttled to one request every 5 seconds in this MCP process. Supported fields: protocol, domain, port, title, os, server, country, asn, org, asset_type, fid, icp.

fofa_hostB

Get FOFA host aggregation data with /api/v1/host/{host}. Calls are throttled to one request every 1 second in this MCP process.

fofa_user_infoA

Get FOFA account status, quota, and membership information with /api/v1/info/my.

quake_user_infoB

Get Quake user details, quota, token, and role information with /api/v3/user/info.

quake_filterable_fieldsB

Get Quake service fields usable in include/exclude with /api/v3/filterable/field/quake_service. Examples: components.product_level, components.product_catalog, location.country_cn, domain, service.http.favicon.hash, service.http.host, components.product_vendor, location.city_en, service.http.title, service.name, time, location.isp, transport, location.province_en, components.product_name_cn, asn, location.city_cn, location.province_cn, service.http.status_code, service.http.infomation.mail, org, service.http.icp.main_licence.unit, location.district_cn, service.cert, service.http.server, hostname, service.http.body, components.product_type, location.district_en, service.http.favicon.data, ip, service.http.icp.licence, components.version, location.country_en, port, service.response.

quake_service_searchA

Run real-time Quake service search with /api/v3/search/quake_service. Use this for small result sets; use quake_service_scroll for deep pagination.

quake_service_scrollA

Run deep-pagination Quake service search with /api/v3/scroll/quake_service. Use meta.pagination_id from the response as pagination_id for the next page.

quake_searchC

Backward-compatible alias for quake_service_scroll.

quake_aggregation_fieldsA

Get Quake service aggregation fields with /api/v3/aggregation/quake_service. Examples: ip, port, service, product, os, asn, org, title, server, app, catalog, type, level, vendor, isp, status_code, powered_by, meta_keywords, page_type, icp, app_and_version, service_and_version, unique_ip, unique_domain, unique_port, unique_product, unique_asn, unique_org, unique_isp, unique_title, unique_server, unique_app, unique_catalog, unique_type, unique_level, unique_vendor, unique_country, unique_province, unique_city, province, province_cn, country, country_cn, country_code, city, city_cn, district, district_cn, province_of_china.

quake_service_aggregationC

Run Quake service aggregation query with /api/v3/aggregation/quake_service.

hunter_personal_searchC

Search Hunter personal API /openApi/search. Personal fields: ip,port,domain,ip_tag,url,web_title,is_risk_protocol,protocol,base_protocol,status_code,os,company,number,icp_exception,country,province,city,is_web,isp,as_org,cert_sha256,ssl_certificate,component,asset_tag,updated_at,header,header_server,banner.

hunter_personal_batch_createC

Create a Hunter personal batch search task with query or CSV file upload.

hunter_personal_batch_statusC

Get Hunter personal batch task progress.

hunter_personal_batch_downloadB

Download Hunter personal batch task export file to output_path.

hunter_personal_user_infoA

Get Hunter personal account quota and account information.

hunter_enterprise_searchC

Search Hunter enterprise API /openApi/search. Enterprise fields: ip,port,domain,ip_tag,url,web_title,is_risk_protocol,protocol,base_protocol,status_code,os,company,number,icp_exception,country,province,city,is_web,isp,as_org,cert_sha256,ssl_certificate,component,asset_tag,updated_at,header,header_server,banner,whois,body,vul_list.

hunter_enterprise_batch_createB

Create a Hunter enterprise batch search task with query or CSV file upload.

hunter_enterprise_batch_statusA

Get Hunter enterprise batch task progress.

hunter_enterprise_batch_downloadA

Download Hunter enterprise batch task export file to output_path.

hunter_enterprise_batch_pullB

Pull Hunter enterprise batch task results as JSON. Enterprise-only.

hunter_enterprise_user_infoA

Get Hunter enterprise or sub-account quota and account information.

zoomeye_user_infoA

Get paid-account subscription and points information with POST /v2/userinfo.

zoomeye_searchA

Search ZoomEye paid-account assets with POST /v2/search. Provide a raw query for automatic Base64 encoding, or pass qbase64 directly. Free and legacy search APIs are not supported.

daydaymap_searchA

Search DayDayMap assets with POST /api/v1/raymap/search/all. Query is automatically Base64-encoded for the keyword parameter. Strings in queries must use English double quotes and are case-insensitive. Supported return fields: ip, is_ipv6, is_website, port, protocol, url, continent, country, country_code, province, city, postal_code, asn, asn_org, longitude, latitude, isp, domain, icp_reg_name, industry, title, icon_md5, banner, header, body, os, device_type, manufacturer, server, lang, device, product, service, tags, time_stamp, cert, cert_selfsigned, SSL. Query syntax categories: IP: ip, ip.port, ip.isp, ip.os_family, ip.os, ip.tag, ip.industry, is_ipv6; 域名: domain, domain.root, is_domain; 地理位置: ip.country, ip.province, ip.city, ip.district; ICP 备案: icp.number, icp.name, icp.name_prefix, icp.webname; AS 域: asn.number, asn.org; WEB: is_web, web.server, web.status_code, web.header, web.title, web.lang, web.body, web.icon; 协议: protocol.transport, protocol.service, protocol.banner; 应用: app.name; 组件: product; 设备: device.name, device.type, device.type_sub, brand, model, manufacturer; 证书: cert.issuer, cert.subject, cert.sn, cert.org, cert.md5, cert.is_expired, cert.is_trust, cert.startdate, cert.enddate; 时间: time; 漏洞: vul.cve, vul.dvb; 资产归属: org.name, org.name_prefix. Logical AND uses &&. Maximum 10,000 results total (page x page_size <= 10000).

Prompts

Interactive templates invoked by user choice

NameDescription
surveyhub_search_planCreate a safe, platform-aware asset search plan before calling SurveyHub tools.
surveyhub_query_helpExplain or improve a FOFA, Quake, Hunter, ZoomEye, or DayDayMap query.

Resources

Contextual data attached and managed by the client

NameDescription
fofa-syntaxReference document for FOFA Syntax.
quake-syntaxReference document for Quake Syntax.
hunter-syntaxReference document for Hunter Syntax.
zoomeye-syntaxReference document for ZoomEye Syntax.
fofa-apiReference document for FOFA API.
quake-apiReference document for Quake API.
hunter-personal-apiReference document for Hunter Personal API.
hunter-enterprise-apiReference document for Hunter Enterprise API.
zoomeye-apiReference document for ZoomEye API.
daydaymap-apiReference document for DayDayMap API.

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/helGayhub233/SurveyHub-MCP'

If you have feedback or need assistance with the MCP directory API, please join our Discord server