DecodoSAFE
The Decodo MCP server which enables MCP clients to interface with services.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://discord.gg/Ja8dqKgvbZ) [](https://cursor.com/en-US/install-mcp?name=Decodo&config=eyJ1cmwiOiJodHRwczovL21jcC5kZWNvZG8uY29tL21jcCIsImhlYWRlcnMiOnsiQXV0aG9yaXphdGlvbiI6IkJhc2ljIDx3ZWJfYWR2YW5jZWRfdG9rZW4%2BIn19)
Connect LLMs and AI agents to live web data using MCP (Model Context Protocol). The Decodo MCP Server lets you scrape websites, search engines, eCommerce platforms, and social media directly from AI tools like Claude, Cursor, and Windsurf, all without the need to build scraping infrastructure from scratch.
- Structured outputs in JSON, Markdown, and screenshots
- Server-side JavaScript rendering and anti-bot handling
- 125M+ IPs across 195+ locations
What is Decodo MCP server?
The Decodo MCP Server is a web scraping layer for AI agents. It connects MCP-compatible clients to Decodo's Web Scraping API, enabling:
- Web scraping for LLMs
- Real-time data retrieval for RAG
- AI agent browsing and research
- Structured data extraction from dynamic websites
Instead of maintaining proxies, parsers, and retry logic, you get a single integration point for reliable web data access.
Why use MCP for web scraping?
Model Context Protocol (MCP) is the emerging standard for connecting AI agents to external tools and data sources. With MCP:
- Agents can call tools dynamically
- Integrations stay standardized
- Workflows scale across environments
The Decodo MCP Server gives your agents reliable, production-ready web access through this standard.
Key features
Web scraping for AI agents, no infrastructure required. Scrape any website, including JavaScript-hea
5b14b641187aOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp-server -- npx -y @decodo/[email protected]
Exposed tools (30)
28 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
amazon_bestsellers | read | |
amazon_pricing | read | |
amazon_product | read | |
amazon_search | read | |
amazon_sellers | read | |
bing_search | read | |
chatgpt | read | |
google_ads | read | |
google_ai_mode | read | |
google_lens | read | |
google_search | read | |
google_travel_hotels | read | |
perplexity | read | |
reddit_post | write | |
reddit_subreddit | read | |
reddit_user | read | |
scrape_as_markdown | read | |
screenshot | read | |
target_product | read | |
target_search | read | |
tiktok_post | write | |
tiktok_shop_product | read | |
tiktok_shop_search | read | |
tiktok_shop_url | read | |
walmart_product | read | |
walmart_search | read | |
youtube_channel | read | |
youtube_metadata | read | |
youtube_search | read | |
youtube_subtitles | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (14)
.releaserc.json
import { AUTH_TYPE } from '../../auth';import type { AuthCredential } from '../../auth';import { ScrapingMCPParams } from '../../types';import { AUTH_TYPE } from '../../auth';import type { AuthCredential } from '../../auth';expect(isAllowedOrigin('http://127.0.0.1:6274')).toBe(true);const response = await fetch(`http://127.0.0.1:${port}/mcp`, {const response = await fetch(`http://127.0.0.1:${port}/mcp`, {"/9j/4AAQSkZJRgABAQAAAQABAAD/2wCEAAkGBwgHBgkIBwgKCgkLDRYPDQwMDRsUFRAWIB0iIiAdHx8kKDQsJCYxJx8fLT0tMTU3Ojo6Iys/RD84QzQ5OjcBCgoKDQwNGg8PGjclHyU3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc
"/9j/4AAQSkZJRgABAQAAAQABAAD/2wCEAAkGBwgHBgkIBwgKCgkLDRYPDQwMDRsUFRAWIB0iIiAdHx8kKDQsJCYxJx8fLT0tMTU3Ojo6Iys/RD84QzQ5OjcBCgoKDQwNGg8PGjclHyU3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc
"/9j/4AAQSkZJRgABAQAAAQABAAD/2wCEAAkGBwgHBgkIBwgKCgkLDRYPDQwMDRsUFRAWIB0iIiAdHx8kKDQsJCYxJx8fLT0tMTU3Ojo6Iys/RD84QzQ5OjcBCgoKDQwNGg8PGjclHyU3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc
@decodo/sdk-ts, @modelcontextprotocol/sdk, cors, dotenv, express, node-html-markdown, tsx, @eslint/js
Gates applied: no_behavioural_pass, no_license.
5b14b641187afull audit observations/trust-audit/mcp-server/decodo__decodo-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 5b14b641187a | SAFE | B | 89 | first audit |
Questions
What is the Decodo MCP server?
The Decodo MCP server which enables MCP clients to interface with services.
What tools does Decodo expose?
30 in total: 28 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Decodo safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Decodo need?
No credential environment variables were found in its source, so it appears to need none.
How does Decodo run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @decodo/mcp-server at 1.2.5.
How current is this page?
The grade is for one exact copy of the source (5b14b641187a), read on 2026-10-08. The repository is watched and re-audited when it changes.