Developer Tools · Security

Toolkit MCP Server logo

Toolkit MCP Server

cyanheads/toolkit-mcp-server

Generate random IDs, QR codes, and hashes, encode and decode values, and geolocate IPs, plus gated network and system diagnostics, via MCP. STDIO or Streamable HTTP.

Install

bunx @cyanheads/toolkit-mcp-server@latest

Client configuration

{
  "mcpServers": {
    "toolkit-mcp-server": {
      "command": "bunx",
      "args": [
        "@cyanheads/toolkit-mcp-server@latest"
      ],
      "env": {
        "MCP_TRANSPORT_TYPE": "<MCP_TRANSPORT_TYPE>",
        "MCP_LOG_LEVEL": "<MCP_LOG_LEVEL>"
      }
    }
  }
}

Environment variables

MCP_TRANSPORT_TYPEMCP_LOG_LEVEL
GitHub stars
6
Category
Developer Tools, Security
License
Apache-2.0
Updated
Oct 6, 2026

Features

  • Local, pure-compute core — hashing, ID minting, QR encoding, and value encode/decode run entirely in-process via node:crypto and the qrcode library; no upstream calls

  • Fail-closed gating — the two host-probing tools (toolkit_check_network, toolkit_check_system) are absent from tools/list unless explicitly enabled, so a hosted instance exposes no SSRF or…

  • Two-tier network gate — even with diagnostics enabled, private/reserved/loopback/link-local targets (including the cloud-metadata endpoint) stay blocked until a second flag permits them

  • Bounded inputs — QR data capped at 2953 bytes, rendered PNGs capped at 2048 px per side, ID batches capped at 1000; CSPRNG-backed primitives with constant-time hash comparison via timingSafeEqual

  • Provenance — geolocation echoes resolvedIp (the IP actually located) and source (the answering provider); absent upstream fields are reported as unknown, never invented

  • Response shaping — provider-supplied strings (org, isp, as) are length-bounded and stripped of control characters before they reach the response, so untrusted registry text can't flood or format a…

  • Discriminated output contracts — operation, format, mode, and what fields echo back exactly what ran, with only the branch-relevant fields populated per call; an unreachable host in…

  • Typed failure reasons — decode, hashing, QR, geolocation, and network failures each carry a structured reason plus a next-step recovery hint (e.g. decode_not_utf8, expected_malformed,…

Tools (26)

  • toolkit_hash_value

    Generate a cryptographic digest (sha256/sha384/sha512/sha1/md5) as hex, base64, or SRI, or constant-time-compare a value against an expected digest.

  • toolkit_generate_id

    Mint cryptographically-random identifiers — UUIDv4, UUIDv7, or ULID — singly or in batches up to 1000.

  • toolkit_generate_qr

    Encode text or a URL into a QR code as SVG markup, base64 PNG, or a terminal-renderable string.

  • toolkit_encode_value

    Encode or decode a value across base64, base64url, hex, or URL percent-encoding, in either direction.

  • toolkit_geolocate_ip

    Resolve a public IP or hostname to geographic and network metadata — country, city, coordinates, ASN, timezone.

  • toolkit_check_network

    Gated, off by default.

  • toolkit_check_system

    Gated, off by default.

  • operation

    generate (a digest) or compare (timing-safe check via timingSafeEqual); omitted, it compares when expected is sent and generates otherwise. generate sent…

  • digestEncoding

    sets the generated digest's form: hex (lowercase, default), base64, or sri (sha512-<base64>, the npm lockfile integrity and Subresource Integrity form —…

  • expected

    is accepted as hex, base64, or SRI, recognized by its shape at the algorithm's digest length, so a published checksum is pasted as-is.

  • inputEncoding

    reads value as utf8 (default), hex, or base64, so binary blobs skip a decode round-trip

  • count

    mints a batch up to 1000 in one call; the returned ids array always holds exactly count values

  • uuid_v7

    and ulid batches are monotonic — strictly increasing even within the same millisecond — so ids stays in sorted creation order.

  • format

    svg (inline markup), png_base64 (raster bytes with mimeType and byteLength), or terminal (plain Unicode half-blocks with no escape codes, fenced in content[])

  • terminal

    is drawn for a dark background: light modules, quiet zone included, are blocks and dark modules are spaces

  • errorCorrection

    (L/M/Q/H) trades data capacity for damage tolerance; margin sets the quiet-zone width in modules for every format; scale sets pixels per module for svg (its…

  • png_base64

    also arrives as an MCP image content block, so a client reading content[] can render the code without decoding structuredContent

  • encoding

    base64, base64url (URL-safe alphabet), hex, or url (percent-encoding)

  • outputEncoding

    (decode only) returns the recovered bytes as utf8 text (when omitted), hex, or base64 — lossless for binary data, and a direct transcode between encodings (a…

  • proxy

    hosting, and mobile flag when the address is a proxy/VPN/Tor exit, a datacenter network, or a mobile carrier — a true on any of them means the coordinates…

  • Gated

    registered only when TOOLKIT_ENABLE_NET_DIAGNOSTICS=true; absent from tools/list otherwise

  • mode

    ping (ICMP round-trip), traceroute (hop path to the target), connectivity (raw TCP connect to target on port), or public_ip (the host's own egress IP)

  • ping

    reports sent, received, and packetLossPercent alongside the average rttMs; on macOS/BSD an IPv6 target runs ping6/traceroute6

  • connectivity

    reports an outcome — open, refused (nothing listening), timeout (traffic dropped), or unreachable (no route) — and the connect time as rttMs when open

  • what

    os, cpu, memory, load, or interfaces

  • memory

    reports availableBytes (headroom for new allocations) and, when the server runs under a container memory limit, limitBytes; totalBytes, freeBytes, and…

Details on this page are taken from the project's README. Open README

Supported clients

Clients mentioned in this server's README:

View all
Claude Desktop logo

Claude Desktop

Desktop · Freemium · Proprietary

Anthropic's official Claude AI desktop application. Supports MCP servers to extend functionality.

WindowsMacOS
Cursor logo

Cursor

Desktop · Freemium · Proprietary

The first agentic IDE. The Cursor editor truly merges how developers and AI work together, delivering a magical coding experience.

WindowsMacOSLinux
VS Code GitHub Copilot logo

VS Code GitHub Copilot

Desktop · Freemium · MIT

VS Code integrates MCP with GitHub Copilot through agent mode, allowing direct interaction with MCP-provided tools in your agentic coding workflow. Configure servers in Claude Desktop, workspace, or user settings, with guided MCP installation and secure handling of secrets in input variables to avoid leaking hardcoded keys.

WindowsMacOSLinuxWeb

Related MCP servers

More servers
Playwright logo

Playwright

microsoft/playwright

72.2k

Playwright is a framework for web automation and testing. It drives Chromium, Firefox, and WebKit with a single API — in your tests, in your scripts, and as a tool for AI agents.

Developer Tools
repomix logo

repomix

yamadashy/repomix

15.2k

Repomix is a tool that packs a codebase into an AI-friendly format, supporting local and remote repository processing and providing code compression, security checks and multiple output formats.

Developer Tools
UI-TARS-desktop logo

UI-TARS-desktop

bytedance/UI-TARS-desktop

12.9k

TARS is ByteDance's multimodal AI agent stack, shipping two projects: Agent TARS (a CLI and Web UI agent built on MCP) and UI-TARS-desktop (a desktop GUI agent).

Developer Tools
blender logo

blender

ahujasid/blender-mcp

10.6k

formerly blender-mcp — the PyPI package is now mcp-for-blender. Existing setups keep working; no config change is required. Read more.

Developer Tools
Playwright Browser Automation logo

Playwright Browser Automation

microsoft/playwright-mcp

9.2k

A Model Context Protocol (MCP) server that provides browser automation capabilities using Playwright. This server enables LLMs to interact with web pages through structured accessibility snapshots, bypassing the need for screenshots or visually-tuned models.

Developer Tools
2344 logo

2344

comet-ml/opik

7k

Opik is the open-source LLM observability and evaluation platform for AI agent tracing, LLM evaluation, prompt management, and production monitoring. Built by Comet. Apache-2.0 licensed, free to self-host the full platform, with 20,000+ GitHub stars.

Developer Tools