ToolAPI by toolapi.org

MCP server · Workflow automation · indexed, not reviewed

Hostedvendor's own

Not reviewed

No score, grade or rank. This listing is facts from the official MCP registry and our own checks, and it stays out of the rankings until the panel reviews it.

How the index works

Free public MCP for AI agents — 193 tools, 44 workflows. No API key.

What the official MCP registry says

Facts

MCP registry
org.toolapi/hub · 2.8.2
Endpoint
https://toolapi.org/mcp
Also hosted
https://toolapi.org/sse sse
GitHub stars
2
Registry entry
updated 10 Jul 2026

From the official MCP registry, the package registries and our own checks. JSON · Markdown

Why it's listed

  • It's published in the registry under toolapi.org, a namespace the registry only gives to whoever proves they control that domain.

Being indexed says nothing about quality, and nobody can pay for it. Is this yours? Ask for a review.

Tools it lists 193 · about 11,783 tokens of context · checked 23 hours ago

ToolWhat it doesHint
json_validateValidate JSON text; return parsed object or error.
json_formatPretty-print JSON with indent. When: Pretty-print JSON when the agent needs readable output.
json_minifyMinify JSON (remove whitespace). When: Minify JSON for compact payloads or size checks.
csv_to_jsonConvert CSV text to JSON array of row objects. When: Convert CSV rows → JSON array of objects.
json_to_csvConvert JSON array of objects to CSV text.
yaml_validateValidate YAML text; return parsed object or error.
yaml_to_jsonParse YAML and return JSON-compatible object.
json_to_yamlConvert JSON text to YAML string. When: Convert JSON → YAML for config files agents write.
xml_validateValidate XML markup (well-formed check).
xml_formatPretty-print XML with indentation. When: Pretty-print XML after the agent edits markup.
jsonpath_queryQuery JSON with JSONPath expression; returns matching values.
json_mergeDeep-merge two JSON objects (second overlays first).
json_flattenFlatten nested JSON to dot-key map. When: Flatten nested JSON keys before comparing or exporting.
json_pretty_diffUnified diff of two JSON documents (pretty-printed).
json_sort_keysRecursively sort JSON object keys. When: Canonicalize JSON key order for stable diffs/hashes.
json_type_summarySummarize JSON value types (counts per type in tree).
json_schema_validateValidate JSON data against JSON Schema (Draft 7).
toml_validateValidate TOML text; return parsed object or error.
toml_to_jsonParse TOML and return JSON-compatible object.
json_to_tomlConvert JSON object text to TOML string.
toml_schema_validateValidate TOML config against JSON Schema (Draft 7) in one step.
sql_formatFormat SQL text (never executed; reindent + keyword case).
graphql_validateValidate GraphQL query or schema SDL syntax (parse only).
openapi_validateValidate OpenAPI 3.x document (JSON or YAML snippet).
openapi_diffCompare two OpenAPI specs and flag breaking vs non-breaking API changes.
package_manifest_auditAudit package.json or pyproject.toml — license, risky scripts, loose ranges; emit semver_checks for batch. Note: best-effort / heuristic — not a full language parser.
graphql_schema_diffDiff two GraphQL schemas for removed types/fields (breaking changes).
compose_validateValidate docker-compose YAML and flag privileged/host-network/secret env issues.
github_actions_lintLint GitHub Actions workflow YAML (triggers, unpinned actions, curl|bash).
requirements_auditAudit Python requirements.txt for unpinned/VCS/deprecated packages.
json_schema_validate_batchBatch JSON Schema (Draft 7) validation — up to 25 documents (agent favorite).
json_assert_pathsAssert JSONPath expressions against JSON (exists/equals/type) — agent self-check.
json_equalDeep-compare two JSON documents and list differing paths.
yaml_schema_validateParse YAML then validate against JSON Schema (Draft 7).
tsconfig_lintLint tsconfig.json structure (compilerOptions, strict hints).
json_pointer_getGet value by RFC 6901 JSON Pointer (e.g. /user/id). When: Read one field by RFC 6901 pointer without full walk in the agent.
json_patch_applyApply RFC 6902 JSON Patch ops (add/remove/replace/test/move/copy). When: Apply RFC 6902 ops (add/remove/replace/test/move/copy).
json_schema_inferInfer a Draft-7 JSON Schema from a sample JSON document (agent favorite).
jsonl_validateValidate JSON Lines (NDJSON); optional per-line JSON Schema. When: Validate NDJSON / JSON Lines logs or datasets.
xml_to_jsonConvert XML document to JSON (attributes as @attr). When: Convert XML → JSON for agents that prefer JSON tools.
json_merge_patchApply RFC 7396 JSON Merge Patch (null deletes keys). When: RFC 7396 merge patch — use when patching JSON configs.
csv_validateValidate CSV structure — consistent column counts / header. When: Check CSV column consistency before import.
ini_parseParse INI / simple key=value config into sections. When: Parse INI/section configs into structured maps.
openapi_operations_listList OpenAPI path operations (method, path, operationId, tags). When: List OpenAPI operations before validate/diff.
graphql_operations_listList GraphQL query/mutation/subscription names and type defs. When: List GraphQL ops/types from a document (best-effort).
properties_parseParse Java .properties key=value file. When: Parse Java .properties key=value configs (best-effort).
time_nowCurrent UTC unix timestamp and ISO-8601.
time_convertConvert unix seconds or ISO-8601 to both formats.
timezone_convertConvert datetime between IANA timezones (e.g. UTC to Asia/Shanghai).
timezone_listList common IANA timezone names for conversion.
datetime_parseParse unix timestamp or ISO-8601 into UTC ISO + unix.
duration_parseParse duration (ISO-8601 PnDTnHnMnS or human 1h30m / 90s) to seconds. When: Parse ISO-8601 / human durations to seconds.
regex_testTest regex pattern; returns match, groups, span.
regex_replaceReplace regex matches in text (supports backreferences in replacement).
text_diffUnified line diff between two texts (like git diff).
text_slugifyURL-safe slug from title or heading. When: Make URL-safe slugs from titles/filenames.
text_statsCount chars, words, lines, sentences; estimate reading time.
text_case_convertConvert case: lower, upper, title, snake, kebab, camel, pascal.
text_loremGenerate lorem ipsum placeholder paragraphs.
color_convertConvert color between hex, rgb(), and hsl().
unit_convertConvert units: length, weight, temperature, data, speed, time.
unit_listList supported units per category for unit_convert.
markdown_to_htmlConvert Markdown text to HTML. When: Render markdown → HTML for previews or emails.
html_to_markdownConvert HTML to Markdown text. When: Convert HTML → markdown for docs the agent edits.
pick_choicePick one item from a list (optional seed for reproducibility).
string_truncateTruncate text with ellipsis. When: Truncate long strings with ellipsis for UI/logs.
extract_urlsExtract HTTP/HTTPS URLs from arbitrary text.
extract_emailsExtract email addresses from text. When: Pull email addresses from free text / logs.
email_validateValidate email address format. When: Syntax-check a single email address.
text_wrapWrap text to a maximum line width. When: Hard-wrap text to a column width.
list_uniqueDeduplicate list items preserving order.
template_fillFill {{variable}} placeholders in a template string.
unicode_normalizeUnicode normalization (NFC/NFD/NFKC/NFKD).
user_agent_parseParse User-Agent string into browser, OS, and device hints.
secrets_scanScan text for hardcoded secrets (API keys, tokens, private keys). Returns redacted findings.
dockerfile_lintLint Dockerfile for common security/style issues (root user, curl|sh, secrets).
env_required_checkCheck .env text contains required keys (and non-empty values).
path_safety_checkCheck filesystem path for traversal / absolute / sensitive system paths.
spdx_license_checkValidate SPDX license expression against common license IDs.
robots_txt_validateValidate robots.txt syntax and User-agent rules.
csp_parseParse Content-Security-Policy header and flag unsafe directives.
cors_checkCheck CORS Allow-Origin vs credentials for unsafe combinations.
markdown_link_extractExtract markdown/bare links and flag javascript: URLs.
gitignore_checkReview .gitignore for common missing ignores (.env, node_modules, keys).
editorconfig_validateValidate .editorconfig syntax and common keys.
nginx_config_lintLint nginx config snippets (braces, SSLv3, server_tokens, HSTS hints).
sql_danger_scanScan SQL text for dangerous patterns (DROP/TRUNCATE/DELETE without WHERE). Note: best-effort / heuristic — not a full language parser.
html_security_scanScan HTML for XSS-prone patterns (javascript: URLs, inline handlers, eval). Note: best-effort / heuristic — not a full language parser.
conventional_commit_lintLint Conventional Commits message (feat/fix/chore…).
changelog_parseParse Keep-a-Changelog style markdown into version sections.
todo_comment_extractExtract TODO/FIXME/HACK/XXX comments with line numbers.
code_fence_extractExtract fenced code blocks from markdown (language + code).
unified_diff_parseParse unified diff — files changed, lines added/removed.
glob_match_batchMatch paths against glob patterns (gitignore-style fnmatch).
identifier_validateValidate identifier for python/javascript/typescript (keywords + syntax).
text_similaritySequenceMatcher similarity ratio between two texts.
import_list_analyzeList imports from python/js source and flag duplicates. Note: best-effort / heuristic — not a full language parser.
frontmatter_parseParse YAML frontmatter from markdown (--- ... ---). When: Split YAML frontmatter from markdown body.
markdown_tocBuild a table of contents from markdown headings. When: Build heading TOC from markdown docs.
gitignore_matchMatch paths against .gitignore rules (ignore / negate). When: Test paths against .gitignore rules (best-effort).
shell_escapeShell-escape a string for posix/powershell/cmd (safe quoting). When: Safely quote strings for posix/powershell/cmd.
path_normalizeNormalize filesystem path (resolve . and ..) for posix or windows. When: Resolve . and .. in filesystem paths.
env_diffDiff two .env files — only_in_a / only_in_b / changed values. When: Diff two .env files for missing/changed keys.
package_scripts_listList scripts from package.json or pyproject.toml (poetry/PEP 621). When: List npm/poetry/PEP 621 scripts from manifests.
line_ending_normalizeDetect and normalize line endings to lf/crlf/cr. When: Detect/normalize CRLF vs LF.
shebang_parseParse #! shebang line — interpreter and args. When: Parse #! interpreter lines in scripts.
trailing_whitespace_scanScan text for trailing whitespace and tab characters. Note: best-effort / heuristic — not a full language parser.
sql_tables_extractExtract table names from SQL (FROM/JOIN/INTO/UPDATE/TABLE). When: Heuristic extract of SQL table names (best-effort).
dependency_versions_extractExtract name@version from requirements/lockfile/go.mod/Cargo snippets. When: Extract name@version from lock/requirements snippets (best-effort).
color_contrastWCAG contrast ratio between two hex colors (AA/AAA). When: WCAG contrast ratio for UI color pairs.
human_bytesFormat bytes to human size, or parse '1.5 GB' to bytes. When: Format or parse human byte sizes (1.5 GB).
password_strengthOffline password strength heuristic (length/classes/common). When: Offline password strength heuristic (not a cracker).
hosts_file_parseParse /etc/hosts style file into IP → hostnames entries. When: Parse /etc/hosts style IP→hostname maps.
hash_md5MD5 hex digest of UTF-8 text. When: MD5 digest (non-crypto integrity / legacy checksums).
hash_sha256SHA256 hex digest.
hash_sha512SHA512 hex digest.
base64_encodeBase64-encode UTF-8.
base64_decodeBase64-decode to UTF-8.
base64url_encodeBase64url-encode UTF-8 (no padding, URL-safe).
base64url_decodeBase64url-decode to UTF-8.
url_encodePercent-encode URL component.
url_decodeDecode percent-encoded string.
html_encodeEscape HTML entities.
html_decodeUnescape HTML entities.
hex_encodeUTF-8 text to hex string.
hex_decodeHex string to UTF-8 text.
uuid_generateGenerate UUID v1/v3/v4/v5 (batch supported). v3/v5 need name + namespace.
uuid_parseParse UUID string: version, variant, hex bytes.
nanoid_generateGenerate URL-friendly nanoid (like npm nanoid).
password_generateCryptographically secure random password.
jwt_decodeDecode JWT payload and header (no signature verification).
jwt_verifyVerify JWT signature (HS* with secret, RS* with public_key PEM).
jwt_signSign JWT payload (HS* with secret, RS* with private_key PEM).
hmac_signHMAC sign message (sha1/sha256/sha512); hex or base64 output.
hmac_verifyVerify HMAC signature (hex or base64).
bcrypt_hashBcrypt-hash a password for storage.
bcrypt_verifyVerify password against bcrypt hash.
radix_convertConvert number between bases 2-36 (binary, octal, decimal, hex).
qr_generateGenerate QR code as SVG (base64 data URI included).
random_intRandom integer in inclusive range (optional seed).
random_stringRandom string (alphanumeric, hex, base64 charset or custom).
hash_compareCompare two hash digests (case-insensitive).
jwt_claims_auditDecode JWT header/claims (no verify) and flag alg=none, missing exp, privileged roles.
remote_matrixRemote desktop tools comparison JSON for AI citation.
url_parseParse URL into scheme, host, path, query components.
http_status_lookupExplain HTTP status code (e.g. 404, 429, 503).
semver_parseParse semver string into major, minor, patch, prerelease.
semver_compareCompare two semver strings (less / equal / greater).
semver_satisfiesCheck if version satisfies npm-style range (^ ~ >= <= > <).
semver_satisfies_batchBatch semver range checks for dependency audits (max 50).
semver_range_intersectsHeuristic check whether two semver ranges share any sample versions (conflict hint).
semver_sortSort a list of semver versions ascending or descending. When: Sort semver lists before picking latest/oldest.
semver_max_satisfyingPick the highest version that satisfies a semver range (npm-style).
semver_incBump a semver version by major/minor/patch. When: Bump major/minor/patch when cutting a release.
cidr_calcCalculate IPv4/IPv6 network info from CIDR (hosts, broadcast, private).
cidr_containsCheck if IP address falls within a CIDR range.
ip_geolocationGeolocate public IP: country, city, lat/lon, timezone, ISP.
env_parseParse .env / dotenv text into key-value variables.
pem_decodeList PEM blocks in text (label, DER size, SHA256 fingerprint).
x509_parseParse X.509 certificate PEM: subject, issuer, validity, SAN, fingerprint.
dns_lookupDNS lookup for domain (A, AAAA, MX, TXT, NS, CNAME, SOA).
whois_lookupDomain registration lookup via RDAP (registrar, dates, nameservers).
ssl_cert_fetchFetch live TLS certificate from host:port (expiry, issuer, SAN).
reverse_dnsReverse DNS (PTR) lookup for IP address.
port_checkTCP port open/closed check with latency ms.
http_headers_fetchFetch HTTP response headers (HEAD/GET) for URL.
currency_listList supported fiat currencies (Frankfurter/ECB, no API key).
currency_ratesLatest exchange rates (Frankfurter ECB data, no API key).
currency_convertConvert amount between currencies using latest ECB rates.
url_ssrf_checkCheck URL for SSRF risk (localhost, private IP, metadata hosts).
ipv4_private_checkClassify IP as private/loopback/link-local/global (SSRF helper).
url_normalizeNormalize URL (lowercase host, sort query, drop fragment).
content_type_parseParse Content-Type header into mime/charset/params.
http_status_classifyClassify HTTP status codes into 2xx/3xx/4xx/5xx buckets.
query_string_parseParse URL query string into key/value map (supports multi-values). When: Parse URL query strings into maps.
query_string_buildBuild URL query string from params object. When: Build query strings from param objects.
cookie_header_parseParse Cookie request header into name/value map. When: Parse Cookie request headers.
mime_lookupLookup MIME type by file extension/path, or extensions by MIME. When: Map file extension ↔ MIME type.
url_joinJoin base URL with relative path (urllib urljoin). When: Join base URL + relative path correctly.
domain_parseParse domain into labels, TLD, registrable domain, subdomain. When: Split domain into subdomain/registrable/TLD (best-effort eTLD).
git_url_parseParse git remote URL (ssh/https) into host/owner/repo. When: Parse git@ / https remotes into owner/repo.
http_headers_parseParse raw HTTP request/response header block into map. When: Parse raw HTTP header blocks.
ip_version_detectDetect IPv4/IPv6 and classify private/loopback/global. When: Classify IPv4/IPv6 and private/global.
cron_parseParse 5-field cron into named fields (minute hour dom month dow).
cron_validateCheck cron string has exactly five fields.
cron_semantic_validateValidate cron field syntax and value ranges (minute 0-59, hour 0-23, etc.).
cron_next_runsPreview next N execution times for a 5-field cron expression.
cron_describeHuman-readable natural language description of cron expression (EN + ZH).
cron_matchesCheck if a cron expression matches a specific datetime (ISO-8601).
cron_validate_batchBatch semantic validate of 5-field cron expressions.
mail_inbox_createCreate disposable receive-only inbox @mail.toolapi.org (24h TTL). Returns address + secret token.
mail_inbox_listList messages in a temp inbox (requires token from mail_inbox_create).
mail_inbox_readRead full message body from temp inbox.

What https://toolapi.org/mcp answered to tools/list, asked without credentials. answered without the initialize handshake. The token figure is the size of the list as sent, divided by four; a model sees about that much before it calls anything. Full definitions, input schemas included, are in the listing's JSON under mcpTools.

How its tools read to an agent 0 errors · 394 warnings · 1 note

  • warnTC06base64_decodethe description is "Base64-decode to UTF-8."
  • warnTC06base64_encodethe description is "Base64-encode UTF-8."
  • warnTC06base64url_decodethe description is "Base64url-decode to UTF-8."
  • warnTC06hash_sha256the description is "SHA256 hex digest."
  • warnTC06hash_sha512the description is "SHA512 hex digest."
  • warnTC06html_decodethe description is "Unescape HTML entities."
  • warnTC06html_encodethe description is "Escape HTML entities."
  • warnTC06unicode_normalizethe description is "Unicode normalization (NFC/NFD/NFKC/NFKD)."
  • warnTC06url_decodethe description is "Decode percent-encoded string."
  • warnTC06url_encodethe description is "Percent-encode URL component."
  • warnTC11base64_decodeits one parameter, text, has no description
  • warnTC11base64_encodeits one parameter, text, has no description
  • warnTC11base64url_decodeits one parameter, text, has no description
  • warnTC11base64url_encodeits one parameter, text, has no description
  • warnTC11bcrypt_hashnone of its 2 parameters has a description
  • warnTC11bcrypt_verifynone of its 2 parameters has a description
  • warnTC11changelog_parseits one parameter, text, has no description
  • warnTC11cidr_containsnone of its 2 parameters has a description
  • warnTC11code_fence_extractits one parameter, text, has no description
  • warnTC11color_contrastnone of its 2 parameters has a description
  • warnTC11color_convert1 parameter without a description: to_format
  • warnTC11compose_validateits one parameter, text, has no description
  • warnTC11content_type_parseits one parameter, header, has no description
  • warnTC11conventional_commit_lintits one parameter, message, has no description

The first 24 of 395; every finding is in the listing's JSON under mcpTools.check.

The checks from /check and anchor check, run each day on the list above: about 11,783 tokens of definitions. Not part of the score yet. Check your own server.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.