MCP.so
Sign In

Apimesh

@mbeato

About Apimesh

APIMesh — 23 pay-per-call web analysis APIs + 16-tool MCP server with autonomous API generation. Security audits, SEO, tech stack detection. x402 + Stripe MPP payments.

Config

Add this server to your MCP-compatible client using the configuration below.

{
  "mcpServers": {
    "apimesh": {
      "command": "npx",
      "args": [
        "@mbeato/apimesh-mcp-server"
      ]
    }
  }
}

Tools

76

Check if a brand name is available across 5 domain TLDs (.com, .io, .xyz, .dev, .ai), GitHub, npm, PyPI, and Reddit in one call. Free preview: GET https://check.apimesh.xyz/preview?name=... returns .com availability only

Check the live HTTP status of any URL, optionally verify against an expected code. Useful for uptime monitoring, redirect validation, and link checking

Check whether a website has a favicon and get its URL, format, and status. Useful for link previews and site branding validation

Check health and response times of up to 10 service URLs in parallel. Free preview: GET https://microservice-health-check.apimesh.xyz/preview?url=... checks 1 service for free

Fetch and parse a website's robots.txt into structured rules, sitemaps, and crawl directives

Get Core Web Vitals and Lighthouse performance scores for any URL. Returns LCP, CLS, INP field data plus performance, accessibility, best-practices, and SEO scores. Free preview: GET https://core-web-vitals.apimesh.xyz/preview?url=... returns performance score only

Audit HTTP security headers for any URL. Checks 10 headers (CSP, HSTS, X-Frame-Options, etc.) with weighted grading A+ through F and remediation suggestions. Free preview: GET https://security-headers.apimesh.xyz/preview?url=... checks 3 key headers for free

Trace the full redirect chain for any URL. Returns each hop with status code, location, and latency. Detects loops and extracts the final canonical URL. Free preview: GET https://redirect-chain.apimesh.xyz/preview?url=... traces up to 5 hops for free

Check email security configuration for any domain. Analyzes SPF, DMARC, DKIM (probes 10 common selectors), and MX records with provider detection. Free preview: GET https://email-security.apimesh.xyz/preview?domain=... checks SPF and DMARC for free

Run a comprehensive on-page SEO audit on any URL. Analyzes title, meta description, headings, images, links, content, canonical, OG tags, JSON-LD, and robots directives with a 0-100 score. Free preview: GET https://seo-audit.apimesh.xyz/preview?url=... returns title, meta, H1, and score for free

Check if a URL is indexable by search engines. Performs 5-layer analysis: robots.txt rules, HTTP status, meta robots, X-Robots-Tag, and canonical tag. Free preview: GET https://indexability.apimesh.xyz/preview?url=... checks HTTP status and meta robots for free

Extract brand assets from any domain. Returns logo URL, favicon, theme colors, OG image, and site name. Free preview: GET https://brand-assets.apimesh.xyz/preview?domain=... returns Google favicon URL for free

Verify an email address: syntax validation, MX record check, disposable domain detection, role-address detection, free provider detection, and deliverability assessment. Free preview: GET https://email-verify.apimesh.xyz/preview?email=... checks syntax and disposable status for free

Detect the technology stack of any website. Analyzes HTTP headers and HTML to identify CMS, frameworks, languages, analytics, CDN, hosting, JavaScript libraries, and CSS frameworks. Free preview: GET https://tech-stack.apimesh.xyz/preview?url=... detects technologies from HTTP headers only

Check your wallet's APIMesh spend and cap status. Returns daily/7d/30d spend totals, active spend cap with remaining budget, and recent requests. No authentication required.

Validate presence and correctness of common web resources (robots.txt, sitemap.xml, openapi.json, agent.json) for any domain. Returns availability status for the requested resource.

Analyze security-related HTTP headers for any website. Checks Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, X-XSS-Protection, Referrer-Policy, and Permissions-Policy with issue detection.

Comprehensive website security audit combining hostname analysis, SSL certificate validation, HTTP security headers, cookie security, and Content Security Policy analysis. Returns an overall security score (0-100) with actionable recommendations. Supports basic, detailed, and full scan levels.

Generate test JWTs with custom claims and expiry for local development. Returns a signed HS256 token. Useful for testing auth flows without a real identity provider.

Build and test regex patterns. POST /build creates a regex from a pattern string or components. POST /test validates a pattern against test strings. Useful for generating and debugging regular expressions.

Check the live HTTP status code of any URL. Returns the actual status code, reason phrase, and response headers. Simpler than http_status_checker — no expected-code validation.

Generate OpenAPI 3.0 documentation for an API endpoint. Provide the path, method, summary, and optionally parameters/requestBody/responses to get a complete OpenAPI spec fragment.

Parse a User-Agent string into structured data: browser name/version, OS name/version, device type, and bot detection. Useful for analytics and request filtering.

Validate YAML syntax and structure. Returns parsed result on success or detailed error with line/column on failure. Useful for CI pipelines and config file validation.

Set a spend cap on your wallet. Once the daily or monthly USDC limit is reached, further paid API calls return 429 before payment is attempted. Set limits to null to remove a cap.

Paid comprehensive subdomain enumeration and vulnerability ranking

Paid comprehensive audit with advanced heuristic analysis, web crawling, scoring, and detailed recommendations

Aggregates SSL/TLS configuration details from public scans, DNS records, and certificate transparency logs, then performs a risk assessment

Paid comprehensive subdomain enumeration and vulnerability ranking

Paid comprehensive full subdomain exposure scoring and audit report

Analyze an IP address for ASN, ISP, geolocation, and routing info; returns comprehensive report with scoring and recommendations

Comprehensive enumeration and exposure scoring of all detected subdomains for a domain

Comprehensive TLS security threat assessment for a domain

Fetch and analyze privacy policies across domains for GDPR/CCPA compliance and data sharing signals

Comprehensive DNS propagation audit across multiple global DNS resolvers with delay correlation, misconfiguration detection, scoring, grading, and recommendations

Comprehensive IP infrastructure analysis: ASN, ISP, geolocation, routing checks, scoring, recommendations

Enrich an IP address with detailed ASN, ISP, geolocation, and routing data

Comprehensive website authenticity assessment combining SSL cert validation, DNS records, redirect chain analysis, and server headers

Run full SSL, TLS, and HTTP security header comprehensive hardening score with actionable recommendations

Perform a comprehensive security headers audit with detailed scoring and remediation

Comprehensive paid scan: exhaustive subdomain enumeration from DNS, CT logs, plus HTTP endpoint probing, header analysis, TLS version checks, outdated service detection, with full scoring and rich recommendations

Analyze SSL/TLS info and forecast renewal and security outlook with detailed alerts and recommendations

Paid, comprehensive analysis of subdomain exposure and security ranking

Comprehensive SSL/TLS certificate and protocol expiry forecast for multiple domains

Paid comprehensive analysis of network routing paths including ASN hops, geolocation, latency, suspicion scoring, and remediation

Exhaustive subdomain enumeration from multiple sources, risk analysis, exposure scoring, recommendations and heatmap report

Simulate DNS record propagation across multiple DNS resolvers with delay estimation and misconfiguration detection

Perform a deep, comprehensive SSL/TLS configuration audit of a target site

Fetch and analyze a privacy policy URL, combining multiple signals for GDPR and CCPA compliance, data sharing practices, and privacy features

Comprehensive privacy risk analysis of a domain's publicly available privacy policies and disclosures

Full enumeration of HTTP methods supported by a target URL with scoring and analysis

Run a comprehensive security misconfiguration scan against the specified URL

Comprehensive license audit across multiple project manifests and license databases with risk scoring

Comprehensive paid SSL/TLS configuration forecast and security score for a domain

Perform a deep, comprehensive subdomain enumeration and risk ranking audit

Paid comprehensive audit with multiple fetches, deep NLP content variation analysis, content diffing, and scoring to detect content shuffling and obfuscation

Compare multiple API schema versions (REST or GraphQL) to highlight differences and score compatibility

Run a comprehensive linting and validation on provided OpenAPI spec and implementation URLs

Deep scan of a list of IP addresses or CIDR ranges with multi-source aggregation and vulnerability scoring

Comprehensive paid audit integrating DNS, HTTP headers, IP and regional info with detailed scoring and recommendations

Comprehensive paid audit with detailed scoring, grade, meta tags, and .env leak detection

Exhaustive subdomain enumeration, vulnerability inference, scoring, and recommendations

Comprehensive SSL/TLS certificate and protocol audit for the specified hostname or URL

Paid comprehensive DNS propagation audit across multiple resolver types, including scoring and actionable recommendations

Compare multiple API schemas from given URLs and return detailed diff and evolution analysis

Perform a deep port scan on a target IP or hostname

Get a comprehensive SSL/TLS and DNS record security assessment for a hostname

Comprehensively crawl and analyze API endpoints on the specified domain

Comprehensive API response heuristic analysis with scoring and recommendations

Perform a comprehensive API standard compliance analysis on the target API response URL

Perform a comprehensive security header and content security policy audit

Perform comprehensive CORS headers audit across multiple endpoints

Comprehensive DNS propagation audit across global resolvers with detailed result analysis

Comprehensive payable audit combining performance metrics, security headers, SSL cert and DNS analysis with scoring and prioritized fix suggestions

Comprehensive baseline audit with combined security headers, SSL, and configuration checks

Paid endpoint combining certificate transparency logs, DNS, SSL cert data to forecast expiry across multiple domains

Overview

What is Apimesh?

Apimesh is a pay-per-call web analysis API collection and MCP server for AI agents and developers. It provides 102 focused APIs (e.g., security audits, SEO analysis, email verification, tech stack detection) across individual subdomains, accessible via a 67-tool MCP server for use in Claude, Cursor, Windsurf, Cline, and other MCP-compatible clients. No signup is required; payment is made with USDC on Base, via card, or an API key.

How to use Apimesh?

Install the MCP server with one command: npx @mbeato/apimesh-mcp-server. For direct API usage, include the X-PAYMENT header with a signed USDC payment to the endpoint. Many APIs also offer free /preview endpoints for testing without payment.

Key features of Apimesh

  • 102 pay-per-call web analysis APIs, each on its own subdomain.
  • 67 MCP tools for direct use in AI coding assistants.
  • Three payment methods: x402 crypto, Stripe MPP, and API keys.
  • Autonomous build loop that creates, tests, and deploys new APIs daily.
  • Free preview endpoints for most APIs; all have free health and info endpoints.
  • Wallet and spend tracking endpoints (free, no auth).

Use cases of Apimesh

  • AI agents performing real-time website security and performance audits.
  • Developers integrating SEO analysis or email verification into automated workflows.
  • DevOps teams monitoring uptime and redirect chains for multiple services.
  • Builders needing instant tech stack detection or brand name availability checks.
  • AI-powered compliance checks (e.g., robots.txt, security headers) without human signup.

FAQ from Apimesh

What payment methods does Apimesh support?

Three methods: x402 (crypto micropayments via USDC on Base), Stripe MPP (card/stablecoins), and traditional API keys purchased through Stripe checkout.

Does Apimesh require an account or API key?

No. With x402 (default), no accounts, API keys, or subscriptions are needed. The agent handles payment autonomously. API keys are an alternative for traditional developers.

What runtime and framework does Apimesh use?

The server runs on Bun with the Hono web framework, uses Caddy as a reverse proxy with automatic HTTPS, and stores analytics/usage in SQLite.

Are there any free endpoints?

Yes. Most APIs offer a free /preview endpoint, and every API has free /health and / info endpoints.

What data does the autonomous brain use?

The brain monitors API health, revenue, and error rates; gathers market signals; and uses an LLM (OpenAI gpt-4.1-mini) to generate, test, and deploy new APIs. It is hardened against prompt injection with sanitized external data and static code analysis.

Frequently asked questions

What payment methods does Apimesh support?

Three methods: x402 (crypto micropayments via USDC on Base), Stripe MPP (card/stablecoins), and traditional API keys purchased through Stripe checkout.

Does Apimesh require an account or API key?

No. With x402 (default), no accounts, API keys, or subscriptions are needed. The agent handles payment autonomously. API keys are an alternative for traditional developers.

What runtime and framework does Apimesh use?

The server runs on Bun with the Hono web framework, uses Caddy as a reverse proxy with automatic HTTPS, and stores analytics/usage in SQLite.

Are there any free endpoints?

Yes. Most APIs offer a free `/preview` endpoint, and every API has free `/health` and `/` info endpoints.

What data does the autonomous brain use?

The brain monitors API health, revenue, and error rates; gathers market signals; and uses an LLM (OpenAI gpt-4.1-mini) to generate, test, and deploy new APIs. It is hardened against prompt injection with sanitized external data and static code analysis.

Comments

More Other MCP servers