Wayback MachineCAUTION
MCP server and CLI tool for interacting with the Internet Archive's Wayback Machine
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/Mearman/mcp-wayback-machine) [](https://www.npmjs.com/package/mcp-wayback-machine) [](https://github.com/Mearman/mcp-wayback-machine/releases/latest) [](https://github.com/Mearman/mcp-wayback-machine/actions)
MCP server and CLI tool for interacting with the Internet Archive's Wayback Machine. Supports full CDX search, snapshot content retrieval, screenshot listing, snapshot comparison, and optional authentication for higher SPN2 rate limits.
[](https://www.npmjs.com/package/mcp-wayback-machine) [](https://github.com/Mearman/mcp-wayback-machine/stargazers)
Stack: TypeScript · Node.js 22+ · ES Modules · pnpm · Turbo · Zod
Getting started
Requires Node.js 22+ and pnpm.
pnpm install
Optional credentials (anonymous access works, but authenticated requests get higher SPN2 rate limits):
export WAYBACK_ACCESS_KEY="your-access-key" export WAYBACK_SECRET_KEY="your-secret-key"
Obtain credentials at archive.org/account/s3.php.
Build, test, and lint
pnpm validate # typecheck + lint + build + test + untested-files check (the full CI gate) pnpm check # typecheck + lint + build only pnpm build # compile TypeScript to dist/ pnpm test # run unit and integration tests pnpm test:coverage
f8409e61d168OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-wayback-machine --env WAYBACK_ACCESS_KEY=${WAYBACK_ACCESS_KEY} --env WAYBACK_SECRET_KEY=${WAYBACK_SECRET_KEY} -- npx -y [email protected]{
"mcpServers": {
"mcp-wayback-machine": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"WAYBACK_ACCESS_KEY": "${WAYBACK_ACCESS_KEY}",
"WAYBACK_SECRET_KEY": "${WAYBACK_SECRET_KEY}"
}
}
}
}Exposed tools (10)
8 read · 1 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
WAYBACK_ACCESS_KEY | read | Internet Archive S3 access key for higher SPN2 rate limits. Optional — anonymous mode works without it. |
WAYBACK_SECRET_KEY | read | Internet Archive S3 secret key for higher SPN2 rate limits. Optional — anonymous mode works without it. |
check_archive_status | read | |
clear_cache | destructive | |
compare_snapshots | read | |
get_archived_url | read | |
health | read | |
list_screenshots | read | |
save_url | write | |
search_archives | read |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- pinned
- Secrets in source
- found
Findings (7)
const TOKEN = "test-secret-token-abc123";
clear_cache
import pkg from "../../package.json" with { type: "json" };import { StaticTokenAuthProvider } from "../../src/auth/provider.ts";import { clearCache, getCacheStatus } from "../../src/tools/cache.ts";import { compareSnapshots } from "../../src/tools/compare.ts";import { getArchivedUrl } from "../../src/tools/retrieve.ts";Gates applied: no_behavioural_pass.
f8409e61d168full audit observations/trust-audit/mcp-server/mearman__wayback-machine.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | f8409e61d168 | CAUTION | B | 89 | first audit |
Questions
What is the Wayback Machine MCP server?
MCP server and CLI tool for interacting with the Internet Archive's Wayback Machine
What tools does Wayback Machine expose?
10 in total: 8 read-only, 1 that write, and 1 that can delete or overwrite (clear_cache). Every one is listed on this page with its risk.
Is Wayback Machine safe to connect to an agent?
With care. The audit graded it B (89/100) and found 7 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Wayback Machine need?
It reads WAYBACK_ACCESS_KEY and WAYBACK_SECRET_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Wayback Machine run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as mcp-wayback-machine at 3.7.1.
How current is this page?
The grade is for one exact copy of the source (f8409e61d168), read on 2026-10-08. The repository is watched and re-audited when it changes.