mcp-api-tools
# @rog0x/mcp-api-tools
HTTP/API testing tools for AI agents, built on the [Model Context Protocol](https://modelcontextprotocol.io).
## Tools
### `http_request`
Make any HTTP request (GET, POST, PUT, DELETE, PATCH, HEAD, OPTIONS) with full control over headers, body, authentication, and timeouts. Returns status code, response headers, body, and timing information.
### `api_health`
Check the health of multiple API endpoints in parallel. Returns HTTP status, response time, SSL certificate validity and expiry, and optional response body validation. Includes a summary with counts of healthy, unhealthy, and errored endpoints.
### `jwt_decode`
Decode a JWT token without cryptographic verification. Returns the decoded header and payload, issued-at time, expiry time, and whether the token is currently expired.
### `url_parse`
Parse a URL into its component parts (protocol, host, port, path, query parameters, hash) or build a URL from individual parts.
### `header_analyzer`
Analyze HTTP response headers for security posture (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy), caching directives, CORS configuration, and cookie attributes. Provides a letter grade for security. Can fetch headers from a live URL or analyze a provided headers object.
## Installation
```bash
npm install
npm run build
```
## Configuration
### Claude Desktop
Add to your `claude_desktop_config.json`:
```json
{
"mcpServers": {
"api-tools": {
"command": "node",
"args": ["D:/products/mcp-servers/mcp-api-tools/dist/index.js"]
}
}
}
```
### Claude Code
```bash
claude mcp add api-tools node D:/products/mcp-servers/mcp-api-tools/dist/index.js
```
## Examples
**Make a POST request:**
```
Use http_request to POST to https://httpbin.org/post with JSON body {"key": "value"}
```
**Check API health:**
```
Use api_health to check these endpoints: https://api.github.com, https://httpbin.org/get
```
**Decode a JWT:**
```
Use jwt_decode to decode this token: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...
```
**Parse a URL:**
```
Use url_parse to break down https://example.com:8080/api/v1?key=value&debug=true#section
```
**Analyze security headers:**
```
Use header_analyzer to check security headers for https://github.com
```
## License
MIT
TDQS
Scored across 5 tools
Each tool has a clearly distinct purpose with no overlap: health checks, header analysis, HTTP requests, JWT decoding, and URL parsing. The descriptions specify unique domains (API monitoring, security analysis, HTTP client, token inspection, URL manipulation), making misselection unlikely.
All tool names follow a consistent snake_case pattern with clear, descriptive verb_noun combinations (e.g., api_health, header_analyzer). The naming is uniform and predictable across all five tools, enhancing readability and agent usability.
With 5 tools, the count is well-scoped for an API utilities server, covering essential operations without bloat. Each tool earns its place by addressing a distinct aspect of API testing and analysis, making the set manageable and focused.
The tool surface is nearly complete for API testing and analysis, covering health checks, security headers, HTTP requests, JWT handling, and URL parsing. A minor gap exists in lacking tools for more advanced scenarios like API mocking or load testing, but core workflows are well-supported.