
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
allnewsapi-mcp
Advanced tools
Get access to real-time and historical news data including top headlines from global sources via AllNewsAPI. Supports multiple filter options including keyword search, category, language and more
Get access to real-time and historical news data including top headlines from global sources via AllNewsAPI. Supports multiple filter options including keyword search, category, language and more. This Model Context Protocol server lets MCP clients (Claude, Cursor, VS Code, Windsurf, and others) search news articles, fetch top headlines, and check your API usage.
You'll need an API key — get one at allnewsapi.com.
Pick one of the two ways to connect.
Point your client at the hosted server and pass your API key in the X-API-Key header:
{
"mcpServers": {
"allnewsapi": {
"type": "remote",
"url": "https://mcp.allnewsapi.com/mcp",
"headers": {
"X-API-Key": "YOUR_API_KEY_HERE"
}
}
}
}
Prefer a URL-only setup? Use https://mcp.allnewsapi.com/mcp?apikey=YOUR_API_KEY_HERE instead of the header.
The key can be supplied three ways, in this order of precedence: the X-API-Key header, the apikey query parameter, or an Authorization: Bearer YOUR_API_KEY_HERE header (a fallback for clients that only support bearer tokens).
Runs the server on your machine via npx — no clone or build needed:
{
"mcpServers": {
"allnewsapi": {
"command": "npx",
"args": ["allnewsapi-mcp@latest", "--apikey", "YOUR_API_KEY_HERE"]
}
}
}
You can also supply the key as an ALLNEWSAPI_KEY environment variable instead of --apikey.
Edit your config (Settings → Developer → Edit Config) and add the local or hosted snippet above. Full guide: modelcontextprotocol.io/quickstart/user.
Cursor Settings → MCP → Add new MCP Server. Name it "AllNewsAPI", choose the command type, and enter:
npx allnewsapi-mcp@latest --apikey YOUR_API_KEY_HERE
code --add-mcp '{"name":"allnewsapi","command":"npx","args":["allnewsapi-mcp@latest","--apikey","YOUR_API_KEY_HERE"]}'
The server is then available to your GitHub Copilot agent. Full guide: VS Code MCP docs.
Add the local or hosted snippet above to your MCP config. Full guide: Windsurf MCP docs.
Add it from the terminal — local:
claude mcp add allnewsapi -- npx allnewsapi-mcp@latest --apikey YOUR_API_KEY_HERE
Or the hosted server:
claude mcp add --transport http allnewsapi https://mcp.allnewsapi.com/mcp --header "X-API-Key: YOUR_API_KEY_HERE"
Cowork runs inside Claude Desktop. Add the hosted server as a custom connector — Customize → Connectors → + — and enter the URL with your key:
https://mcp.allnewsapi.com/mcp?apikey=YOUR_API_KEY_HERE
For a local setup, use the Claude Desktop config shown above.
OpenWork is an open-source Cowork alternative with MCP support. Add AllNewsAPI using either the local command (npx allnewsapi-mcp@latest --apikey YOUR_API_KEY_HERE) or the hosted URL above, following OpenWork's MCP configuration.
Any other MCP client: point it at the hosted URL (https://mcp.allnewsapi.com/mcp) or run the npx allnewsapi-mcp@latest command with your API key.
search-newsSearch articles by keyword, date, and filters.
| Parameter | Type | Description |
|---|---|---|
q | string | Keywords to search for |
startDate / endDate | string | Date range (YYYY-MM-DD) |
content | boolean | Include full article content (default: false) |
lang | string | Language code(s), e.g. en, fr |
country | string | Country code(s), e.g. us, gb |
region | string | Region(s), e.g. americas, europe |
category | string | Category/categories, e.g. business |
max | number | Number of articles, 1–100 (default: 5) |
page | number | Page number (default: 1) |
attributes | string | Where to match keywords: title, description, content |
sortby | string | publishedAt or relevance |
publisher | string | Filter by publisher(s) |
ai_sentiment | string | positive, negative, or neutral |
ai_entity_name | string | Named entity, e.g. Apple |
ai_entity_type | string | Entity type, e.g. person, organization, location |
headlinesGet top headlines, optionally filtered.
| Parameter | Type | Description |
|---|---|---|
country | string | Country code(s), e.g. us, gb |
category | string | Category, e.g. technology |
lang | string | Language code, e.g. en |
max | number | Number of articles, 1–100 (default: 5) |
ai_sentiment | string | positive, negative, or neutral |
ai_entity_name | string | Named entity, e.g. Apple |
ai_entity_type | string | Entity type, e.g. person, organization, location |
usageCheck your plan, request limits, and remaining quota. No parameters.
Plan note: Advanced filters —
country,region,category,publisher,lang,attributes, andsortby— require a paid plan. On the free plan, usesearch-newswithqandmax. See pricing.
search-news and headlines accept AI-analyzed filters:
ai_sentiment — overall article sentiment (positive, negative, neutral)ai_entity_name — a named entity in the article (e.g. United Nations)ai_entity_type — entity category (person, organization, location)Returned articles may also include AI sentiment scores, detected entities, and a short AI summary when available.
Full lists of accepted values live in the AllNewsAPI docs:
MIT © AllNewsAPI — see LICENSE for details.
FAQs
Get access to real-time and historical news data including top headlines from global sources via AllNewsAPI. Supports multiple filter options including keyword search, category, language and more
The npm package allnewsapi-mcp receives a total of 122 weekly downloads. As such, allnewsapi-mcp popularity was classified as not popular.
We found that allnewsapi-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.