api-test-mcp
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@api-test-mcpRun all contract tests against the staging API"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
api-test-mcp
An MCP server that gives Claude Code, Cursor, Windsurf, or any MCP-compatible AI agent the ability to actually call your API and check the response against what your OpenAPI spec promises — not just read the docs and guess.
No API keys, no config, no cost. Works with any OpenAPI/Swagger 3.x spec (URL or local file).
Why this exists
AI agents are great at reading an OpenAPI spec and writing code against it — but they're guessing about whether the real API actually behaves the way the spec says. This gives an agent (or you, in a normal chat) a way to find out for real: call the live endpoint, and check whether the response actually matches the documented schema.
Related MCP server: agent-validator-mcp-server
Install
git clone <this repo>
cd api-test-mcp
npm installAdd it to your MCP client config, e.g. for Claude Code:
claude mcp add api-test -- node /absolute/path/to/api-test-mcp/src/index.jsOr in claude_desktop_config.json / Cursor's MCP settings:
{
"mcpServers": {
"api-test": {
"command": "node",
"args": ["/absolute/path/to/api-test-mcp/src/index.js"]
}
}
}Tools
Tool | What it does |
| Load and dereference an OpenAPI/Swagger spec from a URL or local path. Returns the API title, servers, and every documented endpoint. Call this first. |
| List every endpoint currently loaded. |
| Make a real HTTP call to a documented endpoint. Returns the real status, headers, and body. |
| Check a response body against the JSON schema documented for a given method + path + status. |
|
|
| Best-effort contract-test pass across every GET endpoint that needs no required parameters. Pass |
| One-shot ping across a set of endpoints (or every parameter-free GET in the loaded spec): reports reachability and latency. Handy before a demo or as a CI step. |
| Compare two versions of a spec (e.g. an old tag vs. |
All of the above accept an optional auth preset (bearer, apiKey in a header or query param, or basic) so authenticated APIs aren't limited to hand-building raw headers, and an optional timeoutMs.
Example (what an agent conversation looks like)
You: Load my API spec at
https://api.example.com/openapi.jsonand check whether/users/{id}actually returns what it documents.Agent: (calls
load_api_spec, thentest_endpointwith a real user id) → "Called it — got a 200, but the response is missing thecreated_atfield your spec marks as required, androleis documented as an enum of 3 values but the API returned"superadmin", which isn't one of them."
For an authenticated API:
You: Run a full contract-test pass against my staging API using this bearer token, and include the write endpoints.
Agent: (calls
run_all_testswith{ auth: { type: "bearer", token: "..." }, includeMutating: true }) → "12 passed, 2 failed, 3 skipped.POST /ordersfailed schema validation —total_centscame back as a string, not the integer your spec documents."
Tested against real live traffic
npm test runs three real, unmocked checks, no canned fixtures pretending to be a server:
test/smoke-test.js— loads a spec, makes real HTTPS calls to a live public API, validates the real response, and deliberately feeds in a broken response to confirm validation actually catches mismatches (not just a happy-path check).test/new-features-test.js— auth presets applied to a real outgoing request URL, a real network timeout/abort, a real health-check call, and deterministic offline tests for the spec-diff logic.test/mcp-protocol-test.js— spawns the actual MCP server as a subprocess and talks to it over the real MCP protocol, the same way Claude Code or Cursor would.
CI runs the full suite on every push/PR against Node 18, 20, and 22.
Roadmap
v1.0 shipped contract testing, auth presets, auto-generated example data for mutating endpoints, spec diffing, and health checks. Ideas for what's next:
YAML output mode / a small CLI wrapper for non-MCP use
Configurable retry/backoff for flaky endpoints in
run_all_testsandcheck_healthPattern-aware example generation (respect JSON Schema
patterninstead of a placeholder string)Persisted health-check history (currently one-shot only)
Contributions welcome — see CONTRIBUTING.md. See an endpoint type or spec quirk this doesn't handle well? Open an issue.
License
MIT
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
AlicenseAqualityCmaintenanceTurn any OpenAPI 3.x spec into a runnable, stateful API environment for AI agents. Test real integration flows — multi-step workflows, persistent state, webhook delivery, retries, and edge cases — instead of guessing from docs or mocking endpoints. Generate committable markdown reports directly from Claude/Cursor. Includes 50+ pre-validated APIs like Stripe, GitHub, Twilio, OpenAI, and more.3115MIT- AlicenseAqualityDmaintenanceEnables testing and validation of APIs for AI agent compatibility, providing scores, grades, and actionable recommendations.3MIT
- AlicenseNot gradedqualityFmaintenanceProvides AI assistants with access to OpenAPI specifications, enabling API discovery, schema retrieval, and direct API execution with support for OAuth 2.0 and other authentication methods.251MIT
- AlicenseNot gradedqualityBmaintenanceProvides AI coding agents with accurate OpenAPI contract details to prevent hallucinated API calls, supporting multi-version pinning, endpoint discovery, and request validation.55Apache 2.0
Related MCP Connectors
Deterministic validation for AI-generated artifacts: JSON Schema, OpenAPI response, SQL syntax.
Stripe-native marketplace where AI agents discover and pay per call for API services.
Point Gecko at an OpenAPI spec; get first-call-correct, auth-hidden agent tools.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/thisis-najeeb/api-test-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server