internal-swagger-mcp
Allows AI agents to query internal Swagger platform API documentation, including listing services, searching APIs by keyword, viewing full parameters and mock examples, and refreshing the cache.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@internal-swagger-mcpsearch for endpoints related to user authentication"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
internal-swagger-mcp
Let AI agents query your internal Swagger platform's API docs via MCP.
This server talks to the internal Swagger management platform's private share endpoint (
/flow/swagger/share?uid=...), not a public OpenAPI URL.
Tools
Tool | Purpose |
| List all configured services and their cache status |
| Search APIs by keyword (filterable by method / service) |
| View an API's full parameters and mock example |
| Force-refresh the doc cache (default TTL is 30 minutes) |
Related MCP server: mcp-swagger
Connecting MCP clients
Requires Node.js ≥ 18. Swagger sources are always supplied by the client — this server holds no configuration. Pass them in stdio mode via the SWAGGER_SOURCES env var or --sources-file, and in HTTP mode via the X-Swagger-Sources header per request. Use project scope for every client's MCP config so each repo pins its own sources and the config can be committed to git. In the snippets below, <SOURCE> looks like http://your-server/...#/swaggerManage?uid=xxx; if swagger_list_sources works inside the client, the integration is up.
Start in HTTP mode (for deploying on a shared internal host):
npx -y internal-swagger-mcp --http # defaults to port 3000; override with --port or PORTClaude Code
Official docs — using --scope project writes to the project root's .mcp.json.
Local (stdio):
claude mcp add swagger --scope project --env SWAGGER_SOURCES='["<SOURCE>"]' -- npx -y internal-swagger-mcpRemote (HTTP):
claude mcp add --transport http swagger --scope project http://<internal-IP>:3000/mcp --header 'X-Swagger-Sources: ["<SOURCE>"]'opencode
Official docs — place this in opencode.json at the project root.
Local (stdio):
{
"mcp": {
"swagger": {
"type": "local",
"command": ["npx", "-y", "internal-swagger-mcp"],
"environment": {
"SWAGGER_SOURCES": "[\"<SOURCE>\"]"
}
}
}
}Remote (HTTP):
{
"mcp": {
"swagger": {
"type": "remote",
"url": "http://<internal-IP>:3000/mcp",
"headers": {
"X-Swagger-Sources": "[\"<SOURCE>\"]"
}
}
}
}Cursor
Official docs — place this in .cursor/mcp.json at the project root.
Local (stdio):
{
"mcpServers": {
"swagger": {
"command": "npx",
"args": ["-y", "internal-swagger-mcp"],
"env": {
"SWAGGER_SOURCES": "[\"<SOURCE>\"]"
}
}
}
}Remote (HTTP):
{
"mcpServers": {
"swagger": {
"url": "http://<internal-IP>:3000/mcp",
"headers": {
"X-Swagger-Sources": "[\"<SOURCE>\"]"
}
}
}
}Sources file
When the source list belongs to the project, pass --sources-file <path> instead of pasting the same JSON-as-string into every client's env. Use a path relative to the project root (e.g. ./swagger-sources.json) — it resolves from process.cwd(), which is the project root under project-scoped configs in Claude Code, Cursor, opencode, etc. — so the MCP config can be committed and shared as-is.
swagger-sources.json (each entry is a <SOURCE> URL as defined above):
[
"<SOURCE_1>",
"<SOURCE_2>"
]Each client config then becomes a thin wrapper around the same command:
Claude Code:
claude mcp add swagger --scope project -- npx -y internal-swagger-mcp --sources-file ./swagger-sources.jsonopencode (opencode.json):
{
"mcp": {
"swagger": {
"type": "local",
"command": ["npx", "-y", "internal-swagger-mcp", "--sources-file", "./swagger-sources.json"]
}
}
}Cursor (.cursor/mcp.json) — and other clients using the mcpServers shape:
{
"mcpServers": {
"swagger": {
"command": "npx",
"args": ["-y", "internal-swagger-mcp", "--sources-file", "./swagger-sources.json"]
}
}
}The file is read once at startup; the source list is fixed for the server's lifetime (clients relaunch on config change anyway). When both --sources-file and SWAGGER_SOURCES are provided, the file wins. The flag is rejected in --http mode because HTTP sources are inherently per-request.
HTTP deployment security
The server binds to 0.0.0.0 by default for easy intranet sharing, and prints a warning if started bare. In production, set at least one of the following:
Environment variable | Effect |
| Bind address; set to |
| Require an |
| Comma-separated Origin allowlist (DNS-rebinding protection) |
When
MCP_ALLOWED_ORIGINSis set, requests without anOriginheader are rejected — except for requests carrying a validMCP_BEARER_TOKEN, so server-to-server calls still work.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Flicense-quality-maintenanceProvides LLM-agnostic access to API documentation through MCP and REST endpoints, enabling AI assistants to retrieve, search, and proxy requests to whitelisted APIs across multiple platforms.
- AlicenseAqualityDmaintenanceExposes Swagger/OpenAPI API documentation to AI models, enabling exploration, search, and interaction with endpoints, schemas, and execution of API calls.14102MIT
- Alicense-qualityDmaintenanceA Swagger/OpenAPI query tool for MCP clients like Cursor, enabling AI assistants to browse, search, and retrieve detailed API type information.27MIT
- Flicense-qualityDmaintenanceAn MCP server that enables AI agents to explore, search, and query API definitions from OpenAPI/Swagger JSON files.
Related MCP Connectors
MCP server for AI access to Swagger by SmartBear.
Search, document and execute authenticated API calls across 500+ apps via one MCP server
MCP server for AI access to SmartBear tools, including BugSnag, Reflect, Swagger, PactFlow, QTM4J.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/zhangwanli09/internal-swagger-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server