Skip to main content
Glama
README.md
# netip-mcp

The [whatismynetip.com](https://whatismynetip.com/) toolbox as tools your coding agent can call. Subnet
math, "what runs on this port and should it be open", MAC vendor lookups, DNS and blocklist checks,
the certificate a host actually serves, and the IP the internet sees you as.

Free, MIT, no account, no telemetry. The site's own tools run in your browser; this runs the same logic
next to your agent.

## Install

Pin the version.

**Claude Code**

```
claude mcp add netip -- npx -y github:labaccessnow/netip-mcp#v0.1.0
```

**Claude Desktop, Cursor, or any client with a JSON config**

```json
{
  "mcpServers": {
    "netip": {
      "command": "npx",
      "args": ["-y", "github:labaccessnow/netip-mcp#v0.1.0"]
    }
  }
}
```

**Docker**

```json
{
  "mcpServers": {
    "netip": {
      "command": "docker",
      "args": ["run", "-i", "--rm", "ghcr.io/labaccessnow/netip-mcp:0.1.0"]
    }
  }
}
```

Node 18 or newer for the npx route. Also in the official MCP registry as `io.github.labaccessnow/netip-mcp`.

## Tools

| Tool | What it answers | Network |
|---|---|---|
| `subnet_calc` | Network, mask, wildcard, broadcast, host range and counts for a CIDR — IPv4 and IPv6, /31 and /32 done right | none |
| `ip_in_subnet` | Is this address inside that block? | none |
| `ip_convert` | IPv4 as dotted, integer, hex, binary — from any of them | none |
| `ipv6_normalize` | Expanded and RFC 5952 compressed forms, and what kind of address it is | none |
| `mac_lookup` | Vendor from the full IEEE registry (~40,000 assignments, bundled), plus the multicast and locally-administered bits | none |
| `lookup_port` | What runs on a port, and whether to expose it — 100 ports written up by hand, searchable by service | none |
| `dns_lookup` | A, AAAA, MX, TXT, NS, CNAME, CAA, SOA, PTR, SRV over DNS-over-HTTPS | DoH |
| `reverse_dns` | PTR for an IPv4 or IPv6 address | DoH |
| `dnsbl_check` | Five common blocklists, honest about the ones that refuse public resolvers | DoH |
| `tls_inspect` | The certificate a host actually serves: expiry, SANs, chain verification, protocol, cipher | direct TLS |
| `my_public_ip` | The address the internet sees, edge location, ASN, reverse DNS, datacenter/VPN hint | Cloudflare trace + Team Cymru DNS |

### lookup_port

The one I reach for most. The port pages on the site are opinionated — every port carries a verdict:

```
Port 3389/tcp+udp — RDP (Remote Desktop Protocol)

  Category   remote access
  Software   Windows Remote Desktop Services, xrdp, FreeRDP server, Windows Admin Center hosts
  Exposure   NEVER — do not expose to the internet

Internet-facing RDP is the most common initial-access route for ransomware crews, who
credential-stuff it around the clock; put it behind WireGuard, Tailscale or an RD Gateway …
```

Ask by number, or search: `lookup_port` with `query: "redis"` finds 6379. `detail: true` adds the full
write-up and FAQ.

## What it does not do

- No account, no signup, no key.
- No telemetry. Nothing about your usage goes anywhere.
- Nothing of yours is read from disk. The only file it opens is its own bundled OUI table.
- The local tools never open a socket. The network tools talk only to public services — Cloudflare and
  Google's DNS-over-HTTPS resolvers, Cloudflare's trace endpoint, Team Cymru's ASN DNS, and whichever
  host you point `tls_inspect` at. `tls_inspect` refuses anything that resolves to private or reserved
  space, so it cannot be turned on your own network.
- "Is my port reachable from outside?" needs a machine outside your NAT to try the connection. That is
  what [whatismynetip.com/port-checker](https://whatismynetip.com/port-checker/) does; a local tool
  cannot.

The port data and the calculators are the same ones the site uses, so the two stay in step.

## Licence

MIT. Written by James Son — network, security, and automation engineer. Corrections and additions to the
port write-ups are welcome.

TDQS

A4/5.0

Scored across 11 tools

Disambiguation5/5

Every tool targets a distinct networking task: reverse DNS, public IP discovery, subnet math, membership testing, format conversion, MAC lookup, port information, DNS resolution, blocklist checks, and TLS inspection. The only mild adjacency is reverse_dns and dns_lookup's PTR support, but their stated inputs and purposes remain clearly separate.

Naming Consistency3/5

Most names use an object_action snake_case style like ip_convert, mac_lookup, and tls_inspect, but lookup_port reverses that pattern, and my_public_ip, reverse_dns, and ip_in_subnet are noun phrases. The style is readable and consistent in casing, but the verb placement and phrase structure are not uniform.

Tool Count5/5

Eleven tools is a well-scoped size for a network/IP utility server. Each tool contributes a meaningful, non-redundant capability, and the set does not feel padded or overwhelming.

Completeness4/5

The toolset covers IPv4/IPv6 conversion, subnetting, DNS and reverse DNS, blocklist checks, MAC vendor identification, port lookup, TLS cert inspection, and public IP details. The main minor gap is arbitrary-address ownership/ASN or WHOIS lookup, but the existing workflows are coherent and do not leave core IP tasks stranded.

Maintenance

ActivityMaintained
ResponsivenessNo issues