Openapi Mcp GeneratorBLOCK
A tool that converts OpenAPI specifications to MCP server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/openapi-mcp-generator) [](https://opensource.org/licenses/MIT) [](https://github.com/harsha-iiiv/openapi-mcp-generator) [](https://deepwiki.com/harsha-iiiv/openapi-mcp-generator)
Generate Model Context Protocol (MCP) servers from OpenAPI specifications.
This CLI tool automates the generation of MCP-compatible servers that proxy requests to existing REST APIs—enabling AI agents and other MCP clients to seamlessly interact with your APIs using your choice of transport methods.
✨ Features
- 🔧 OpenAPI 3.0 Support: Converts any OpenAPI 3.0+ spec into an MCP-compatible server.
- 🔁 Proxy Behavior: Proxies calls to your original REST API while validating request structure and security.
- 🔐 Authentication Support: API keys, Bearer tokens, Basic auth, and OAuth2 supported via environment variables.
- 🧪 Zod Validation: Automatically generates Zod schemas from OpenAPI definitions for runtime input validation.
- ⚙️ Typed Server: Fully typed, maintainable TypeScript code output.
- 🔌 Multiple Transports: Communicate over stdio, SSE via Hono, or StreamableHTTP.
- 🧰 Project Scaffold: Generates a complete Node.js project with
tsconfig.json,package.json, and entry point. - 🧪 Built-in HTML Test Clients: Test API interactions visually in your browser (for web-based transports).
🚀 Installation
npm install -g openapi-mcp-generator
You can also useyarn global add openapi-mcp-generatororpnpm add -g openapi-mcp-generator
🛠 Usage
# Generate an MCP server (stdio) openapi-mcp-generator --input pa
70d0168da385OBSERVED · 2026-09-28Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add openapi-mcp-generator --env MY_TOKEN=${MY_TOKEN} --env SECRET=${SECRET} -- npx -y [email protected]{
"mcpServers": {
"openapi-mcp-generator": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"MY_TOKEN": "${MY_TOKEN}",
"SECRET": "${SECRET}"
}
}
}
}Exposed tools (39)
29 read · 8 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
addPet | write | Add a new pet to the store. |
addpet | write | Add a new pet to the store. |
createUser | read | This can only be done by the logged in user. |
createUsersWithListInput | read | Creates list of users with given input array. |
createuser | read | This can only be done by the logged in user. |
createuserswithlistinput | read | Creates list of users with given input array. |
deleteOrder | read | For valid response try integer IDs with value < 1000. Anything above 1000 or non-integers will generate API errors. |
deletePet | destructive | Delete a pet. |
deleteUser | read | This can only be done by the logged in user. |
deleteorder | read | For valid response try integer IDs with value < 1000. Anything above 1000 or non-integers will generate API errors. |
deletepet | destructive | Delete a pet. |
deleteuser | read | This can only be done by the logged in user. |
findPetsByStatus | read | Multiple status values can be provided with comma separated strings. |
findPetsByTags | read | Multiple tags can be provided with comma separated strings. Use tag1, tag2, tag3 for testing. |
findpetsbystatus | read | Multiple status values can be provided with comma separated strings. |
findpetsbytags | read | Multiple tags can be provided with comma separated strings. Use tag1, tag2, tag3 for testing. |
getInventory | read | Returns a map of status codes to quantities. |
getOrderById | read | For valid response try integer IDs with value <= 5 or > 10. Other values will generate exceptions. |
getPetById | read | Returns a single pet. |
getUserByName | read | Get user detail based on username. |
getX | read | gets x |
getinventory | read | Returns a map of status codes to quantities. |
getorderbyid | read | For valid response try integer IDs with value <= 5 or > 10. Other values will generate exceptions. |
getpetbyid | read | Returns a single pet. |
getuserbyname | read | Get user detail based on username. |
loginUser | read | Log into the system. |
loginuser | read | Log into the system. |
logoutUser | read | Log user out of the system. |
logoutuser | read | Log user out of the system. |
placeOrder | write | Place a new order in the store. |
placeorder | write | Place a new order in the store. |
updatePet | write | Update an existing pet by Id. |
updatePetWithForm | read | Updates a pet resource based on the form data. |
updateUser | read | This can only be done by the logged in user. |
updatepet | write | Update an existing pet by Id. |
updatepetwithform | read | Updates a pet resource based on the form data. |
updateuser | read | This can only be done by the logged in user. |
uploadFile | write | Upload image of the pet. |
uploadfile | write | Upload image of the pet. |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (3 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (21)
const zodSchema = eval(zodSchemaString);
'-k, --insecure',
['--insecure', Boolean(options.insecure)],
const insecureHttpsAgent = new https.Agent({ rejectUnauthorized: false });deletePet, deletepet
.prettierignore
const zodSchema = eval(zodSchemaString);
const zodSchema = eval(zodSchemaString);
const zodSchema = eval(zodSchemaString);
const hash = createHash('sha1').update(name).digest('hex').slice(0, HASH_LEN);const disambiguator = createHash('sha1')responses: { '200': { $ref: 'http://169.254.169.254/latest' } },expect(isExternalHttpRef('http://169.254.169.254/')).toBe(true);responses: { '200': { $ref: 'http://169.254.169.254/latest' } },expect(isExternalHttpRef('http://169.254.169.254/')).toBe(true);'--insecure',
expect(code).toContain('rejectUnauthorized: false');@modelcontextprotocol/sdk, axios, dotenv, zod, json-schema-to-zod, hono, @hono/node-server, uuid
@modelcontextprotocol/sdk, axios, dotenv, zod, json-schema-to-zod, hono, @hono/node-server, uuid
@modelcontextprotocol/sdk, axios, json-schema-to-zod, zod, @types/node, typescript
@apidevtools/swagger-parser, commander, openapi-types, @types/node, @typescript-eslint/eslint-plugin, @typescript-eslint/parser, eslint, prettier
Gates applied: no_behavioural_pass.
70d0168da385full audit observations/trust-audit/mcp-server/harsha-iiiv__openapi-mcp-generator-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-28 | 70d0168da385 | BLOCK | D | 69 | first audit |
Questions
What is the Openapi Mcp Generator MCP server?
A tool that converts OpenAPI specifications to MCP server
What tools does Openapi Mcp Generator expose?
39 in total: 29 read-only, 8 that write, and 2 that can delete or overwrite (deletePet, deletepet). Every one is listed on this page with its risk.
Is Openapi Mcp Generator safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Openapi Mcp Generator need?
It reads MY_TOKEN and SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Openapi Mcp Generator run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as openapi-mcp-generator at 4.1.0.
How current is this page?
The grade is for one exact copy of the source (70d0168da385), read on 2026-09-28. The repository is watched and re-audited when it changes.