MCP Interactsh Bridge
This server bridges ProjectDiscovery's Interactsh service through MCP, enabling creation, management, and monitoring of out-of-band (OOB) interaction sessions for security testing and vulnerability detection.
Core capabilities:
Create sessions – Generate unique callback domains with RSA key pairs for capturing HTTP/DNS interactions
Poll interactions – Retrieve and decrypt captured events with optional filtering by HTTP method, protocol, path, query parameters, or text content
Manage lifecycle – List active sessions in memory and deregister them to clean up resources
Security testing – Test for blind vulnerabilities (SSRF, XXE, command injection) by monitoring callbacks to generated domains
Custom deployments – Configure private or self-hosted interactsh instances via environment variables, or use the public fleet (oast.pro) without code modification
Provides an MCP server implementation that exposes ProjectDiscovery's interactsh service for out-of-band interaction testing, including session management, polling for DNS/HTTP callbacks, and encryption/decryption of interaction data.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@MCP Interactsh Bridgecreate a new interactsh session for testing blind SSRF"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
A vibe code MCP Interactsh Bridge
This project exposes ProjectDiscovery's interactsh as a Model Context Protocol server implemented in Node.js. It lets MCP-compatible IDEs or agents provision interactsh sessions, poll for out-of-band interactions, and tear them down without modifying the upstream interactsh codebase.
Features
Session provisioning – Generates RSA key pairs, registers with the public interactsh fleet, and returns ready-to-use callback domains.
Polling & decryption – Retrieves encrypted interaction data and decrypts it locally using the session's private key.
Lifecycle management – Lists cached sessions and deregisters them when finished.
Demo script –
npm run demospins up a session, issues a real HTTP probe, and prints the captured DNS/HTTP events.
Related MCP server: pentestMCP
Requirements
Node.js 18 or newer (tested on Node 20.19)
Network access to the interactsh fleet (defaults to
https://oast.pro)
Installation (local)
git clone https://github.com/tachote/mcp-interactsh
cd mcp-interactsh
npm installRun via npx
npx -y mcp-interactshYou can also pass environment variables inline:
INTERACTSH_BASE_URL=https://oast.pro \
INTERACTSH_DOMAIN_SUFFIX=oast.pro \
npx -y mcp-interactshUsage
Run the MCP server
The MCP server communicates over stdio. Configure your MCP-compatible client (e.g. Claude Code, VS Code MCP, Cursor) to launch:
node src/server.jsOptional environment variables:
Variable | Default | Description |
|
| Base URL of the interactsh server to target. |
| host derived from | Domain suffix used to build callback hosts. Override when using a custom interactsh deployment. |
| (unset) | Authorization token if your interactsh server enforces auth. |
Available MCP tools
create_interactsh_session– Registers a new session and returns correlation ID, secret key, PEM private key, callback domain, server URL, plus explicit probe instructions.Probing rules:
Build host as
<correlation_id><nonce13>.<domain>.correlation_idis exactly 20 lowercase hex chars; do not alter or truncate.nonce13is exactly 13 lowercase alphanumeric chars[a-z0-9].The label before the first dot must be 33 chars total (20 + 13).
Requests to
<correlation_id>.<domain>(no nonce) are ignored by interactsh.Prefer plain HTTP for probes. Wait 2–3 seconds, then poll for events.
list_interactsh_sessions– Lists all sessions cached in memory for the current MCP process.poll_interactsh_session– Polls interactsh for new interactions, returning decrypted events. Optional arguments let you filter bymethod,path_contains,query_contains,protocol, ortext_containsto focus on specific callbacks.deregister_interactsh_session– Deregisters the session and removes it from local state.
Configure in Claude Code (JSON)
Claude Code supports MCP servers over stdio. If you prefer to configure via JSON, add an entry like the following in your Claude Code settings (Settings → MCP Servers or the equivalent config file):
{
"mcpServers": {
"interactsh": {
"transport": "stdio",
"command": "npx",
"args": ["-y", "mcp-interactsh"],
"env": {
"INTERACTSH_BASE_URL": "https://oast.pro",
"INTERACTSH_DOMAIN_SUFFIX": "oast.pro"
// "INTERACTSH_TOKEN": "your_server_token_if_required"
}
}
}
}If you prefer to use a local path (without npx), use:
{
"mcpServers": {
"interactsh": {
"transport": "stdio",
"command": "node",
"args": ["/absolute/path/to/src/server.js"],
"env": {
"INTERACTSH_BASE_URL": "https://oast.pro",
"INTERACTSH_DOMAIN_SUFFIX": "oast.pro"
}
}
}
}Or you can add it with:
claude mcp add --transport stdio interactsh \
-e INTERACTSH_BASE_URL=https://oast.pro \
-e INTERACTSH_DOMAIN_SUFFIX=oast.pro \
-- npx -y mcp-interactshConfigure in Codex (TOML)
Codex reads MCP server configuration from ~/.codex/config.toml. Add an entry like the following:
[mcp_servers.interactsh]
command = "npx"
args = ["-y", "mcp-interactsh"]
env = { INTERACTSH_BASE_URL = "https://oast.pro", INTERACTSH_DOMAIN_SUFFIX = "oast.pro" }If you prefer to reference a local clone instead of npx:
[mcp_servers.interactsh]
command = "node"
args = ["/absolute/path/to/src/server.js"]
env = { INTERACTSH_BASE_URL = "https://oast.pro", INTERACTSH_DOMAIN_SUFFIX = "oast.pro" }Or you can add it with:
codex mcp add --env INTERACTSH_BASE_URL=https://oast.pro --env INTERACTSH_DOMAIN_SUFFIX=oast.pro interactsh -- npx -y mcp-interactshYou can verify the configuration with:
codex mcp list
codex mcp get interactsh --jsonLicense
Released under the MIT License. See LICENSE for details.
Credits
This bridge builds on the excellent work by ProjectDiscovery. See the original interactsh project:
Interactsh repository: https://github.com/projectdiscovery/interactsh
Available Tools
4 toolscreate_interactsh_sessionCreate interactsh sessionB
Generates credentials, registers with interactsh, and returns the connection details.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden. It mentions generating credentials and registering, which implies a write operation, but lacks details on permissions, rate limits, or what happens if registration fails. This is a mutation tool with significant behavioral gaps in disclosure.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, efficient sentence that front-loads the key actions without unnecessary words. Every part ('generates credentials', 'registers', 'returns connection details') contributes directly to understanding the tool's purpose.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a mutation tool with no annotations and no output schema, the description is incomplete. It doesn't explain what 'connection details' include, error handling, or dependencies on other tools like 'deregister_interactsh_session', leaving gaps in contextual understanding.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has 0 parameters with 100% coverage, so no parameter documentation is needed. The description appropriately adds no parameter details, focusing on the tool's action, which aligns with the baseline for zero parameters.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose with specific verbs ('generates credentials', 'registers', 'returns connection details') and identifies the resource ('interactsh session'). It distinguishes from siblings like 'deregister_interactsh_session' and 'list_interactsh_sessions' by focusing on creation, though it doesn't explicitly contrast them.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No explicit guidance on when to use this tool versus alternatives is provided. The description implies usage for creating a new session but doesn't mention prerequisites, when not to use it, or refer to sibling tools like 'poll_interactsh_session' for related actions.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
deregister_interactsh_sessionDeregister sessionC
Removes a session from interactsh and local cache.
| Name | Required | Description | Default |
|---|---|---|---|
| correlation_id | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden of behavioral disclosure. It states the tool removes a session from both interactsh and local cache, implying a destructive operation, but doesn't clarify if this is irreversible, requires specific permissions, or has side effects (e.g., affecting ongoing interactions). More details on consequences or limitations are needed for a higher score.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, clear sentence with no wasted words. It's front-loaded with the core action and efficiently conveys the essential information without unnecessary elaboration, making it highly concise and well-structured.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's destructive nature (implied by 'Removes'), lack of annotations, no output schema, and incomplete parameter documentation, the description is insufficient. It doesn't address what happens post-deregistration, error conditions, or provide enough context for safe and effective use, leaving significant gaps for an AI agent.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The description doesn't mention the parameter 'correlation_id', and schema description coverage is 0%, so it adds no semantic information beyond the schema. However, with only one parameter, the baseline is 3, as the schema alone might suffice for a simple input, but the description fails to compensate for the lack of schema descriptions.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the action ('Removes') and the target ('a session from interactsh and local cache'), making the purpose understandable. However, it doesn't explicitly differentiate from sibling tools like 'list_interactsh_sessions' or 'poll_interactsh_session' beyond the obvious action difference, which prevents a perfect score.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance is provided on when to use this tool versus alternatives. For example, it doesn't mention prerequisites (e.g., requiring an existing session) or warn against misuse (e.g., deregistering active sessions). The description lacks context about its role relative to siblings like 'create_interactsh_session'.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_interactsh_sessionsList sessionsB
Lists interactsh sessions cached in memory.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden. It mentions that sessions are 'cached in memory', which adds some context about data persistence, but fails to disclose key behavioral traits like whether this is a read-only operation, potential rate limits, or the format of the returned list. The description is too minimal for a tool with no annotation coverage.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, efficient sentence that directly states the tool's function without any wasted words. It is front-loaded and appropriately sized for a simple listing tool.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's simplicity (0 parameters, no output schema, no annotations), the description is minimally adequate. However, it lacks details on output format or behavioral context, which could be important for an agent to use it correctly. It meets the basic requirement but has clear gaps in completeness.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has 0 parameters with 100% coverage, so no parameter documentation is needed. The description does not add parameter details, which is appropriate, but it implies the tool operates on cached data without requiring inputs, aligning well with the schema. A baseline of 4 is set for zero-parameter tools.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the verb ('Lists') and resource ('interactsh sessions cached in memory'), making the purpose unambiguous. However, it does not explicitly differentiate from sibling tools like 'poll_interactsh_session', which might also involve listing or retrieving session data, so it doesn't fully achieve sibling differentiation.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no guidance on when to use this tool versus alternatives like 'poll_interactsh_session' or 'create_interactsh_session'. It lacks context about prerequisites, such as whether sessions need to be created first, or exclusions for when not to use it.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
poll_interactsh_sessionPoll sessionB
Retrieves and decrypts interactions for a session. Optional filters let you match HTTP method, path, query, protocol, or free text.
| Name | Required | Description | Default |
|---|---|---|---|
| correlation_id | Yes | ||
| method | No | ||
| path_contains | No | ||
| query_contains | No | ||
| protocol | No | ||
| text_contains | No |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the full burden of behavioral disclosure. It mentions 'retrieves and decrypts' which implies read-only behavior, but doesn't address critical aspects like authentication requirements, rate limits, error conditions, or what 'decrypts' entails operationally. For a tool with 6 parameters and no annotation coverage, this leaves significant gaps.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is perfectly concise and well-structured in just two sentences. The first sentence states the core purpose, and the second explains the filtering capabilities. Every word earns its place with zero redundancy or unnecessary elaboration.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's moderate complexity (6 parameters, 1 required), no annotations, and no output schema, the description provides adequate but incomplete context. It covers the purpose and parameter semantics well but lacks behavioral details and usage guidelines. For a tool that 'decrypts' data and has multiple siblings, more comprehensive guidance would be beneficial.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The description provides excellent parameter semantics despite 0% schema description coverage. It clearly explains that 'optional filters let you match HTTP method, path, query, protocol, or free text,' which maps directly to 5 of the 6 parameters (method, path_contains, query_contains, protocol, text_contains). Only 'correlation_id' isn't explicitly mentioned, but its purpose is implied by 'for a session.' This effectively compensates for the schema's lack of descriptions.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose with specific verbs ('retrieves and decrypts') and resource ('interactions for a session'), making it easy to understand what the tool does. However, it doesn't explicitly distinguish this polling tool from its sibling tools (create, deregister, list sessions), which prevents a perfect score.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description mentions 'optional filters' but provides no guidance on when to use this tool versus its siblings (create_interactsh_session, deregister_interactsh_session, list_interactsh_sessions). There's no indication of prerequisites, sequencing, or alternative scenarios, leaving the agent with minimal context for tool selection.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
2 tool updates
v1.0.0- Changed
deregister_interactsh_session2 fields changed- added
Input schema / $schemaAdded value: +"http://json-schema.org/draft-07/schema#" - added
Input schema / additionalPropertiesAdded value: +false
- Changed
poll_interactsh_session2 fields changed- added
Input schema / $schemaAdded value: +"http://json-schema.org/draft-07/schema#" - added
Input schema / additionalPropertiesAdded value: +false
4 tool updates
- First observed
create_interactsh_session - First observed
deregister_interactsh_session - First observed
list_interactsh_sessions - First observed
poll_interactsh_session
TDQS
Each tool has a clearly distinct purpose: create (setup), deregister (cleanup), list (view sessions), and poll (retrieve interactions). There is no overlap in functionality, making it easy for an agent to select the correct tool without confusion.
All tool names follow a consistent verb_noun pattern with 'interactsh_session' as the common noun component. The verbs (create, deregister, list, poll) are distinct and descriptive, adhering to a predictable naming convention throughout.
With 4 tools, the server is well-scoped for managing Interactsh sessions. Each tool serves a clear role in the lifecycle (create, list, poll, deregister), and there are no extraneous or missing tools for this domain.
The tool set provides complete CRUD/lifecycle coverage for Interactsh sessions: create (setup), list (view), poll (retrieve data), and deregister (cleanup). There are no obvious gaps, and the optional filters in poll_interactsh_session enhance functionality without leaving dead ends.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
MCP server for Pentest-Tools.com: run scans, manage findings and reports via your preffered LLM.
MCP server for e-mail testing: create disposable inboxes, wait for delivery, and extract e-mail content or links - all from your AI agent or test automation workflow. Get a free API key on https://app.zyntra.app/
MCP server for secureFlows: token-free URL builders and integration-linting tools for AI agents.
MCP server connecting AI agents to 100+ apps (Gmail, Slack, Notion, GitHub) via one-click OAuth.
Related MCP Servers
- AlicenseNot gradedqualityNot gradedmaintenanceEnables AI-assisted penetration testing by connecting MCP clients to a Windows API server for executing penetration testing tools like nmap, ffuf, nuclei, and other security tools. Allows AI agents to perform automated security assessments, solve CTF challenges, and assist with ethical hacking tasks through natural language commands.10-
- FlicenseNot gradedqualityBmaintenanceAn MCP server that exposes over 20 standard penetration testing utilities, such as Nmap, SQLMap, and OWASP ZAP, as callable tools for AI agents. It enables natural language control over complex security workflows for automated and interactive penetration testing.93-
- FlicenseNot gradedqualityDmaintenanceAI-powered Attack Surface Intelligence server that exposes industry-standard penetration testing tools via MCP, enabling AI agents to perform comprehensive security assessments.3-
- AlicenseAqualityCmaintenanceAn MCP server for domain intelligence — WHOIS, DNS records, SSL certificate inspection, SPF/DMARC validation, security-header audits, and blacklist/reputation checks, callable by AI agents. Powered by domainintel.app; runs server-side, no local setup.799MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/tachote/mcp-interactsh'
If you have feedback or need assistance with the MCP directory API, please join our Discord server