anyapi-server
A universal MCP server that connects any REST API to AI assistants (Claude, Cursor, etc.) via OpenAPI or Postman specs. Features GraphQL-style field selection, automatic schema inference, mutation support, and smart query suggestions.
Installation
npx anyapi-mcp-serverAsk AI about anyapi-server
Powered by Claude Β· Grounded in docs
I know everything about anyapi-server. Ask me about installation, configuration, usage, or troubleshooting.
0/500
Reviews
Documentation
anyapi-mcp-server
If it has an API, you can MCP it.
Traditional MCP servers hand-pick a handful of endpoints and call it a day β locking you into whatever subset someone decided was "enough." Why settle for a fraction of an API when you can have all of it?
anyapi-mcp-server is a universal MCP server that connects any REST API to AI assistants like Claude, Cursor, and other LLM-powered tools β just point it at an OpenAPI spec or Postman collection. Every endpoint the API provides becomes available instantly, with GraphQL-style field selection and automatic schema inference. No custom server code, no artificial limits.
Quick start
1. Install
npm install -g anyapi-mcp-server
2. Add to your MCP client (Cursor, Claude Desktop, etc.)
{
"mcpServers": {
"your-api": {
"command": "npx",
"args": [
"-y",
"anyapi-mcp-server",
"--name", "your-api",
"--spec", "path/to/openapi.json",
"--base-url", "https://api.example.com",
"--header", "Authorization: Bearer ${API_KEY}"
],
"env": {
"API_KEY": "your-api-key"
}
}
}
}
3. Use the tools β discover endpoints with list_api, inspect schemas with call_api, fetch data with query_api.
Provider examples
Ready-to-use configurations for popular APIs:
| Provider | Auth |
|---|---|
| Cloudflare | API Token or Key + Email |
| Datadog | API Key + App Key |
| GitHub | Personal Access Token |
| Google Workspace | OAuth 2.0 |
| Metabase | API Key |
| PostHog | Personal API Key |
| Slack | Bot/User Token |
These work with any API that has an OpenAPI or Postman spec β the above are just examples. Stripe, Twilio, Shopify, HubSpot, and anything else with a REST API will work the same way.
CLI reference
Required flags
| Flag | Description |
|---|---|
--name | Server name (e.g. cloudflare) |
--spec | Path or HTTPS URL to an OpenAPI spec (JSON/YAML) or Postman Collection. Remote URLs are cached locally. Supports ${ENV_VAR}. |
--base-url | API base URL (e.g. https://api.example.com). Supports ${ENV_VAR}. |
Optional flags
| Flag | Description |
|---|---|
--header | HTTP header as "Key: Value" (repeatable). Supports ${ENV_VAR} in values. |
--log | Path to NDJSON request/response log. Sensitive headers are masked automatically. |
OAuth flags
For APIs that use OAuth 2.0 instead of static tokens. If any of the three required flags is provided, all three are required. All flags support ${ENV_VAR}.
| Flag | Required | Description |
|---|---|---|
--oauth-client-id | Yes* | OAuth client ID |
--oauth-client-secret | Yes* | OAuth client secret |
--oauth-token-url | Yes* | Token endpoint URL |
--oauth-auth-url | No | Authorization endpoint (auto-detected from spec if available) |
--oauth-scopes | No | Comma-separated scopes |
--oauth-flow | No | authorization_code (default) or client_credentials |
--oauth-param | No | Extra token parameter as key=value (repeatable) |
See the Google Workspace guide for a complete OAuth example.
Tools
The server exposes four tools (plus auth when OAuth is configured):
list_api β Browse endpoints
Discover what the API offers. Call with no arguments to see all categories, provide category to list endpoints in a tag, or search to find endpoints by keyword.
call_api β Inspect an endpoint
Makes a real HTTP request and returns the inferred GraphQL schema (SDL) β not the data itself. Use this to discover the response shape and get suggestedQueries you can copy into query_api. Also returns per-field token costs (fieldTokenCosts) and a dataKey for cache reuse. For PUT/PATCH requests, automatically creates a pre-write backup (returns backupDataKey). Supports bodyFile for large payloads and blocks requests with detected placeholder values.
query_api β Fetch data
Fetches data and returns only the fields you select via a GraphQL query. Supports both reads and writes (mutations for POST/PUT/DELETE/PATCH). Pass a dataKey from call_api to reuse cached data with zero HTTP calls.
# Read
{ items { id name status } _count }
# Write
mutation { post_endpoint(input: { name: "example" }) { id } }
Key parameters:
maxTokensβ token budget for the response. Arrays are truncated to fit. Without this orunlimited, responses over ~10k tokens are rejected.unlimitedβ set totrueto return the full response with no token budget enforcement.dataKeyβ reuse cached data from a previouscall_apiorquery_apiresponse.jsonFilterβ dot-path to extract nested values after the GraphQL query (e.g."data[].attributes.name").bodyFileβ absolute path to a JSON file to use as request body (mutually exclusive withbody). Use for large payloads that can't be sent inline.skipBackupβ skip the automatic pre-write backup for PUT/PATCH requests (default:false).
explain_api β Read the docs
Returns spec documentation for an endpoint (parameters, request body schema, response codes) without making an HTTP request.
auth β OAuth authentication
Only available when --oauth-* flags are configured. Manages the OAuth flow:
action: "start"β returns an authorization URL (or exchanges credentials forclient_credentials)action: "exchange"β completes the authorization code flow (callback is captured automatically)action: "status"β shows current token status
Tokens are persisted and refreshed automatically.
Typical workflow
list_api β discover what's available
β
explain_api β read the docs for an endpoint
β
call_api β inspect the response schema (returns dataKey)
β
query_api β fetch exactly the fields you need (pass dataKey for zero HTTP calls)
β
query_api β re-query with different fields using the same dataKey
How it works
OpenAPI/Postman spec
β
βΌ
βββββββββββ βββββββββββββββ ββββββββββββ βββββββββββββ
βlist_api β β explain_api β β call_api β β query_api β
β(browse) β β (docs) β β (schema) β β (data) β
βββββββββββ βββββββββββββββ ββββββββββββ βββββββββββββ
β β no HTTP β β
βΌ βΌ request βΌ βΌ
Spec index Spec index REST API call dataKey cache
(tags, (params, (with retry) hit β no HTTP
paths) responses, β miss β fetch
body schema) βΌ β
Infer schema + βΌ
return dataKey Execute GraphQL
+ token budget
truncation
Features
- Any REST API β provide an OpenAPI (JSON/YAML) or Postman Collection v2.x spec as a file or URL
- Remote spec caching β HTTPS specs are fetched once and cached to
~/.cache/anyapi-mcp/ - GraphQL field selection β query only the fields you need from any response
- Schema inference β automatically builds GraphQL schemas from live API responses
- Multi-sample merging β samples up to 10 array elements for richer schemas
- Mutation support β write operations get typed GraphQL mutations from OpenAPI body schemas
- Smart suggestions β
call_apireturns ready-to-use queries based on the inferred schema - Response caching β filesystem-based cache with 5-min TTL;
dataKeytokens letquery_apireuse data with zero HTTP calls - Token budget β
query_apienforces a ~10k token safety limit by default; usemaxTokensto truncate the deepest largest array to fit, orunlimited: truefor full responses - Per-field token costs β
call_apireturns afieldTokenCoststree so the LLM can make informed field selections - Rate limit tracking β parses
X-RateLimit-*headers and warns when limits are nearly exhausted - Pagination detection β auto-detects cursor, next-page-token, and link-based pagination patterns in responses
- JSON filter β
query_apiaccepts ajsonFilterdot-path for post-query extraction (e.g."data[].name") - Retry with backoff β automatic retries for 429/5xx with exponential backoff and
Retry-Aftersupport - Multi-format β parses JSON, XML, CSV, and plain text responses
- Safe writes β PUT/PATCH requests automatically snapshot the resource before writing (
backupDataKey); placeholder values (e.g.PLACEHOLDER,TODO,file://) are detected and blocked before sending - File-based body β
bodyFileparameter accepts an absolute path to a JSON file, enabling large payloads that can't be sent inline - Rich errors β structured error messages with status-specific suggestions and spec context for self-correction
- OAuth 2.0 β Authorization Code (with PKCE) and Client Credentials flows with automatic token refresh
- Env var interpolation β
${ENV_VAR}in base URLs, headers, and spec paths - Request logging β optional NDJSON log with sensitive header masking
Supported spec formats
- OpenAPI 3.x (JSON or YAML)
- OpenAPI 2.0 / Swagger (JSON or YAML)
- Postman Collection v2.x (JSON)
License
Proprietary Non-Commercial. Free for personal and educational use. Commercial use requires written permission. See LICENSE for details.
