Apimesh
@mbeato
About Apimesh
APIMesh — 23 pay-per-call web analysis APIs + 16-tool MCP server with autonomous API generation. Security audits, SEO, tech stack detection. x402 + Stripe MPP payments.
Config
Add this server to your MCP-compatible client using the configuration below.
{
"mcpServers": {
"apimesh": {
"command": "npx",
"args": [
"@mbeato/apimesh-mcp-server"
]
}
}
}Tools
76Check if a brand name is available across 5 domain TLDs (.com, .io, .xyz, .dev, .ai), GitHub, npm, PyPI, and Reddit in one call. Free preview: GET https://check.apimesh.xyz/preview?name=... returns .com availability only
Check the live HTTP status of any URL, optionally verify against an expected code. Useful for uptime monitoring, redirect validation, and link checking
Check whether a website has a favicon and get its URL, format, and status. Useful for link previews and site branding validation
Check health and response times of up to 10 service URLs in parallel. Free preview: GET https://microservice-health-check.apimesh.xyz/preview?url=... checks 1 service for free
Fetch and parse a website's robots.txt into structured rules, sitemaps, and crawl directives
Get Core Web Vitals and Lighthouse performance scores for any URL. Returns LCP, CLS, INP field data plus performance, accessibility, best-practices, and SEO scores. Free preview: GET https://core-web-vitals.apimesh.xyz/preview?url=... returns performance score only
Audit HTTP security headers for any URL. Checks 10 headers (CSP, HSTS, X-Frame-Options, etc.) with weighted grading A+ through F and remediation suggestions. Free preview: GET https://security-headers.apimesh.xyz/preview?url=... checks 3 key headers for free
Trace the full redirect chain for any URL. Returns each hop with status code, location, and latency. Detects loops and extracts the final canonical URL. Free preview: GET https://redirect-chain.apimesh.xyz/preview?url=... traces up to 5 hops for free
Check email security configuration for any domain. Analyzes SPF, DMARC, DKIM (probes 10 common selectors), and MX records with provider detection. Free preview: GET https://email-security.apimesh.xyz/preview?domain=... checks SPF and DMARC for free
Run a comprehensive on-page SEO audit on any URL. Analyzes title, meta description, headings, images, links, content, canonical, OG tags, JSON-LD, and robots directives with a 0-100 score. Free preview: GET https://seo-audit.apimesh.xyz/preview?url=... returns title, meta, H1, and score for free
Check if a URL is indexable by search engines. Performs 5-layer analysis: robots.txt rules, HTTP status, meta robots, X-Robots-Tag, and canonical tag. Free preview: GET https://indexability.apimesh.xyz/preview?url=... checks HTTP status and meta robots for free
Extract brand assets from any domain. Returns logo URL, favicon, theme colors, OG image, and site name. Free preview: GET https://brand-assets.apimesh.xyz/preview?domain=... returns Google favicon URL for free
Verify an email address: syntax validation, MX record check, disposable domain detection, role-address detection, free provider detection, and deliverability assessment. Free preview: GET https://email-verify.apimesh.xyz/preview?email=... checks syntax and disposable status for free
Detect the technology stack of any website. Analyzes HTTP headers and HTML to identify CMS, frameworks, languages, analytics, CDN, hosting, JavaScript libraries, and CSS frameworks. Free preview: GET https://tech-stack.apimesh.xyz/preview?url=... detects technologies from HTTP headers only
Check your wallet's APIMesh spend and cap status. Returns daily/7d/30d spend totals, active spend cap with remaining budget, and recent requests. No authentication required.
Validate presence and correctness of common web resources (robots.txt, sitemap.xml, openapi.json, agent.json) for any domain. Returns availability status for the requested resource.
Analyze security-related HTTP headers for any website. Checks Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, X-XSS-Protection, Referrer-Policy, and Permissions-Policy with issue detection.
Comprehensive website security audit combining hostname analysis, SSL certificate validation, HTTP security headers, cookie security, and Content Security Policy analysis. Returns an overall security score (0-100) with actionable recommendations. Supports basic, detailed, and full scan levels.
Generate test JWTs with custom claims and expiry for local development. Returns a signed HS256 token. Useful for testing auth flows without a real identity provider.
Build and test regex patterns. POST /build creates a regex from a pattern string or components. POST /test validates a pattern against test strings. Useful for generating and debugging regular expressions.
Check the live HTTP status code of any URL. Returns the actual status code, reason phrase, and response headers. Simpler than http_status_checker — no expected-code validation.
Generate OpenAPI 3.0 documentation for an API endpoint. Provide the path, method, summary, and optionally parameters/requestBody/responses to get a complete OpenAPI spec fragment.
Parse a User-Agent string into structured data: browser name/version, OS name/version, device type, and bot detection. Useful for analytics and request filtering.
Validate YAML syntax and structure. Returns parsed result on success or detailed error with line/column on failure. Useful for CI pipelines and config file validation.
Set a spend cap on your wallet. Once the daily or monthly USDC limit is reached, further paid API calls return 429 before payment is attempted. Set limits to null to remove a cap.
Paid comprehensive subdomain enumeration and vulnerability ranking
Paid comprehensive audit with advanced heuristic analysis, web crawling, scoring, and detailed recommendations
Aggregates SSL/TLS configuration details from public scans, DNS records, and certificate transparency logs, then performs a risk assessment
Paid comprehensive subdomain enumeration and vulnerability ranking
Paid comprehensive full subdomain exposure scoring and audit report
Analyze an IP address for ASN, ISP, geolocation, and routing info; returns comprehensive report with scoring and recommendations
Comprehensive enumeration and exposure scoring of all detected subdomains for a domain
Comprehensive TLS security threat assessment for a domain
Fetch and analyze privacy policies across domains for GDPR/CCPA compliance and data sharing signals
Comprehensive DNS propagation audit across multiple global DNS resolvers with delay correlation, misconfiguration detection, scoring, grading, and recommendations
Comprehensive IP infrastructure analysis: ASN, ISP, geolocation, routing checks, scoring, recommendations
Enrich an IP address with detailed ASN, ISP, geolocation, and routing data
Comprehensive website authenticity assessment combining SSL cert validation, DNS records, redirect chain analysis, and server headers
Run full SSL, TLS, and HTTP security header comprehensive hardening score with actionable recommendations
Perform a comprehensive security headers audit with detailed scoring and remediation
Comprehensive paid scan: exhaustive subdomain enumeration from DNS, CT logs, plus HTTP endpoint probing, header analysis, TLS version checks, outdated service detection, with full scoring and rich recommendations
Analyze SSL/TLS info and forecast renewal and security outlook with detailed alerts and recommendations
Paid, comprehensive analysis of subdomain exposure and security ranking
Comprehensive SSL/TLS certificate and protocol expiry forecast for multiple domains
Paid comprehensive analysis of network routing paths including ASN hops, geolocation, latency, suspicion scoring, and remediation
Exhaustive subdomain enumeration from multiple sources, risk analysis, exposure scoring, recommendations and heatmap report
Simulate DNS record propagation across multiple DNS resolvers with delay estimation and misconfiguration detection
Perform a deep, comprehensive SSL/TLS configuration audit of a target site
Fetch and analyze a privacy policy URL, combining multiple signals for GDPR and CCPA compliance, data sharing practices, and privacy features
Comprehensive privacy risk analysis of a domain's publicly available privacy policies and disclosures
Full enumeration of HTTP methods supported by a target URL with scoring and analysis
Run a comprehensive security misconfiguration scan against the specified URL
Comprehensive license audit across multiple project manifests and license databases with risk scoring
Comprehensive paid SSL/TLS configuration forecast and security score for a domain
Perform a deep, comprehensive subdomain enumeration and risk ranking audit
Paid comprehensive audit with multiple fetches, deep NLP content variation analysis, content diffing, and scoring to detect content shuffling and obfuscation
Compare multiple API schema versions (REST or GraphQL) to highlight differences and score compatibility
Run a comprehensive linting and validation on provided OpenAPI spec and implementation URLs
Deep scan of a list of IP addresses or CIDR ranges with multi-source aggregation and vulnerability scoring
Comprehensive paid audit integrating DNS, HTTP headers, IP and regional info with detailed scoring and recommendations
Comprehensive paid audit with detailed scoring, grade, meta tags, and .env leak detection
Exhaustive subdomain enumeration, vulnerability inference, scoring, and recommendations
Comprehensive SSL/TLS certificate and protocol audit for the specified hostname or URL
Paid comprehensive DNS propagation audit across multiple resolver types, including scoring and actionable recommendations
Compare multiple API schemas from given URLs and return detailed diff and evolution analysis
Perform a deep port scan on a target IP or hostname
Get a comprehensive SSL/TLS and DNS record security assessment for a hostname
Comprehensively crawl and analyze API endpoints on the specified domain
Comprehensive API response heuristic analysis with scoring and recommendations
Perform a comprehensive API standard compliance analysis on the target API response URL
Perform a comprehensive security header and content security policy audit
Perform comprehensive CORS headers audit across multiple endpoints
Comprehensive DNS propagation audit across global resolvers with detailed result analysis
Comprehensive payable audit combining performance metrics, security headers, SSL cert and DNS analysis with scoring and prioritized fix suggestions
Comprehensive baseline audit with combined security headers, SSL, and configuration checks
Paid endpoint combining certificate transparency logs, DNS, SSL cert data to forecast expiry across multiple domains
Overview
What is Apimesh?
Apimesh is a pay-per-call web analysis API collection and MCP server for AI agents and developers. It provides 102 focused APIs (e.g., security audits, SEO analysis, email verification, tech stack detection) across individual subdomains, accessible via a 67-tool MCP server for use in Claude, Cursor, Windsurf, Cline, and other MCP-compatible clients. No signup is required; payment is made with USDC on Base, via card, or an API key.
How to use Apimesh?
Install the MCP server with one command: npx @mbeato/apimesh-mcp-server. For direct API usage, include the X-PAYMENT header with a signed USDC payment to the endpoint. Many APIs also offer free /preview endpoints for testing without payment.
Key features of Apimesh
- 102 pay-per-call web analysis APIs, each on its own subdomain.
- 67 MCP tools for direct use in AI coding assistants.
- Three payment methods: x402 crypto, Stripe MPP, and API keys.
- Autonomous build loop that creates, tests, and deploys new APIs daily.
- Free preview endpoints for most APIs; all have free health and info endpoints.
- Wallet and spend tracking endpoints (free, no auth).
Use cases of Apimesh
- AI agents performing real-time website security and performance audits.
- Developers integrating SEO analysis or email verification into automated workflows.
- DevOps teams monitoring uptime and redirect chains for multiple services.
- Builders needing instant tech stack detection or brand name availability checks.
- AI-powered compliance checks (e.g., robots.txt, security headers) without human signup.
FAQ from Apimesh
What payment methods does Apimesh support?
Three methods: x402 (crypto micropayments via USDC on Base), Stripe MPP (card/stablecoins), and traditional API keys purchased through Stripe checkout.
Does Apimesh require an account or API key?
No. With x402 (default), no accounts, API keys, or subscriptions are needed. The agent handles payment autonomously. API keys are an alternative for traditional developers.
What runtime and framework does Apimesh use?
The server runs on Bun with the Hono web framework, uses Caddy as a reverse proxy with automatic HTTPS, and stores analytics/usage in SQLite.
Are there any free endpoints?
Yes. Most APIs offer a free /preview endpoint, and every API has free /health and / info endpoints.
What data does the autonomous brain use?
The brain monitors API health, revenue, and error rates; gathers market signals; and uses an LLM (OpenAI gpt-4.1-mini) to generate, test, and deploy new APIs. It is hardened against prompt injection with sanitized external data and static code analysis.
Frequently asked questions
What payment methods does Apimesh support?
Three methods: x402 (crypto micropayments via USDC on Base), Stripe MPP (card/stablecoins), and traditional API keys purchased through Stripe checkout.
Does Apimesh require an account or API key?
No. With x402 (default), no accounts, API keys, or subscriptions are needed. The agent handles payment autonomously. API keys are an alternative for traditional developers.
What runtime and framework does Apimesh use?
The server runs on Bun with the Hono web framework, uses Caddy as a reverse proxy with automatic HTTPS, and stores analytics/usage in SQLite.
Are there any free endpoints?
Yes. Most APIs offer a free `/preview` endpoint, and every API has free `/health` and `/` info endpoints.
What data does the autonomous brain use?
The brain monitors API health, revenue, and error rates; gathers market signals; and uses an LLM (OpenAI gpt-4.1-mini) to generate, test, and deploy new APIs. It is hardened against prompt injection with sanitized external data and static code analysis.
Basic information
More Other MCP servers
Maestro
mobile-dev-incPainless E2E Automation for Mobile and Web
ICSS
chokcoco不止于 CSS

Sequential Thinking
modelcontextprotocolModel Context Protocol Servers
Production-ready MCP integrations for AI applications
Klavis-AIKlavis AI: MCP integration platforms that let AI agents use tools reliably at any scale
ghidraMCP
LaurieWiredMCP Server for Ghidra
Comments