Live Tennis APIBLOCK
MCP server for the Live Tennis API — give Claude, Cursor and other LLM agents real-time tennis scores, odds and model win-probability
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
MCP server for the [Live Tennis API](https://livetennisapi.com).
Give Claude, Cursor, Zed or any MCP client live tennis scores, players and fixtures — for ATP, WTA, Challenger, ITF and juniors. Odds, rankings, match statistics, charting and model win-probability tools are included, and require the PRO and ULTRA plans.
[](https://github.com/livetennisapi/livetennisapi-mcp/actions/workflows/ci.yml) [](https://www.npmjs.com/package/livetennisapi-mcp) [](LICENSE)
**Documentation** · **Get a free API key**
Setup
Claude Code
claude mcp add livetennis -e LIVETENNISAPI_KEY=twjp_... -- npx -y livetennisapi-mcp
Claude Desktop — add to claude_desktop_config.json:
{
"mcpServers": {
"livetennis": {
"command": "npx",
"args": ["-y", "livetennisapi-mcp"],
"env": { "LIVETENNISAPI_KEY": "twjp_..." }
}
}
}Cursor / Zed / others — same command, same env var. No install step; npx fetches it on demand.
Get a free key (no card) at livetennisapi.com, or a paid plan at pricing.
Try it
"What tennis matches are live right now?" "Who's winning the Alcaraz match, and what does the model give him?" "Show me Sinner's ranking and recent results." "What are the current odds on match 18953?" "What's the all-time head-to-head between Borg and McEnroe?" "List Navratilova's Grand Slam finals from the archive." *"Who was ATP #1 the week Al
914b1cf2ace5OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add livetennisapi-mcp --env LIVETENNISAPI_KEY=${LIVETENNISAPI_KEY} -- npx -y [email protected]Exposed tools (24)
24 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
check_api_status | read | |
get_archive_career | read | |
get_archive_match | read | |
get_charting_match | read | |
get_charting_player | read | |
get_fixtures | read | |
get_h2h | read | |
get_live_matches | read | |
get_match | read | |
get_match_analysis | read | |
get_match_events | read | |
get_match_odds | read | |
get_match_score | read | |
get_match_statistics | read | |
get_player | read | |
get_player_rankings | read | |
get_rankings | read | |
get_recent_results | read | |
get_tournament | read | |
get_upcoming_matches | read | |
search_archive_matches | read | |
search_archive_players | read | |
search_players | read | |
search_tournaments | read |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | WARN |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (9 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (11)
[[ $EUID -eq 0 ]] || die "must be run as root (sudo)"
systemctl enable "$UNIT_NAME" >/dev/null
UNIT_DST="/etc/systemd/system/$UNIT_NAME"
if curl -fsS --max-time 2 "http://127.0.0.1:$PORT/health" >/dev/null 2>&1; then break; fi
health=$(curl -fsS --max-time 5 "http://127.0.0.1:$PORT/health" 2>/dev/null) \
anon=$(curl -fsS --max-time 10 -X POST "http://127.0.0.1:$PORT/mcp" \
tools=$(curl -fsS --max-time 10 -X POST "http://127.0.0.1:$PORT/mcp" \
system use found in code, not declared in the description
.mcpbignore
const URL = `http://127.0.0.1:${PORT}/mcp`;@modelcontextprotocol/sdk, express, express-rate-limit, livetennisapi, zod, @types/express, @types/node, esbuild
Gates applied: no_behavioural_pass.
914b1cf2ace5full audit observations/trust-audit/mcp-server/livetennisapi__live-tennis-api.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 914b1cf2ace5 | BLOCK | D | 69 | first audit |
Questions
What is the Live Tennis API MCP server?
MCP server for the Live Tennis API — give Claude, Cursor and other LLM agents real-time tennis scores, odds and model win-probability
What tools does Live Tennis API expose?
24 in total: 24 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Live Tennis API safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Live Tennis API need?
It reads LIVETENNISAPI_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Live Tennis API run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as livetennisapi-mcp at 1.5.0.
How current is this page?
The grade is for one exact copy of the source (914b1cf2ace5), read on 2026-10-06. The repository is watched and re-audited when it changes.