Search1APISAFE
Official Search1API MCP server for web search, news, crawling, sitemaps, and trends—hosted with OAuth 2.1 or local via npm.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://smithery.ai/servers/superagents-lab/search1api-mcp) [](https://glama.ai/mcp/servers/superagents-lab/search1api-mcp)
中文文档
The official MCP server for Search1API — web search, news, page retrieval, sitemap discovery, and trending topics in one API.
Authentication
- OAuth-aware clients can connect to the Remote MCP URL directly, then sign in and approve access in the browser.
- Existing integrations can continue to use an API key from the Search1API dashboard.
- Every MCP request — including tool discovery (
initialize,tools/list) — requires a credential. Unauthenticated requests draw the OAuth challenge, which is how clients trigger sign-in; pre-connect inspection is served by the static server card instead.
Quick Start (Remote MCP)
No installation required. Configure your MCP client with the remote URL. Use OAuth when the client supports it, or provide an API key.
Authentication
Three methods are supported — use whichever your client supports:
Prefer OAuth or the Authorization header. Query-parameter credentials can be exposed in URLs, logs, and shell history.
Claude Desktop
{
"mcpServers": {
"search1api": {
"url": "https://mcp.search1api.com/mcp",
"headers": {
"Authorization": "Bearer YOUR_SEARCH1API_KEY"
}
}
}
}Claude.ai (Web)
Settings > Connectors > Add custom connec
8fb93a097870OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add search1api-mcp --env SEARCH1API_KEY=${SEARCH1API_KEY} -- npx -y [email protected]Exposed tools (5)
5 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
crawl | read | Extract the readable title and full text from a public URL supplied by the user or returned by search. |
news | read | Search current news when the user asks about recent events, announcements, or coverage. Returns citable article results with title, URL, snippet, and optional extracted text. |
search | read | Search the live public web when the user needs current information, sources, or research. Returns citable results with id, title, URL, and text. Each result includes a URL that can be read in full. |
sitemap | read | Discover related public links from a page or domain when the user wants to explore a site |
trending | read | List currently trending repositories or stories from GitHub or Hacker News when the user asks what is popular now. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
.windsurfrules
url: new URL(`http://127.0.0.1:${address.port}/mcp`),@modelcontextprotocol/node, @modelcontextprotocol/server, dotenv, express, @modelcontextprotocol/client, @types/express, @types/node, typescript
Gates applied: no_behavioural_pass.
8fb93a097870full audit observations/trust-audit/mcp-server/fatwang2__search1api.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 8fb93a097870 | SAFE | B | 89 | first audit |
Questions
What is the Search1API MCP server?
Official Search1API MCP server for web search, news, crawling, sitemaps, and trends—hosted with OAuth 2.1 or local via npm.
What tools does Search1API expose?
5 in total: 5 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Search1API safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Search1API need?
It reads OAUTH_AUTHORIZATION_SERVER and SEARCH1API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Search1API run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as search1api-mcp at 0.6.1.
How current is this page?
The grade is for one exact copy of the source (8fb93a097870), read on 2026-10-06. The repository is watched and re-audited when it changes.