
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
Local stdio MCP server for AnyAPI - hundreds of scraping and data APIs behind one key, priced per request in USD. Proxies to the hosted AnyAPI MCP server.
Hundreds of scraping and data APIs through one gateway: one key, USD pay-per-request, normalized schemas, automatic failover.
This package is a local stdio MCP server that proxies to the hosted AnyAPI
MCP server at https://api.getanyapi.com/mcp. Clients that speak remote
Streamable HTTP can point at that URL directly and skip this package entirely.
Use this one when your client only launches local MCP servers over stdio.
With npx, no clone and no build:
{
"mcpServers": {
"anyapi": {
"command": "npx",
"args": ["-y", "anyapi-mcp"],
"env": { "ANYAPI_API_KEY": "aa_live_..." }
}
}
}
With Docker, no clone and no build:
{
"mcpServers": {
"anyapi": {
"command": "docker",
"args": ["run", "-i", "--rm", "-e", "ANYAPI_API_KEY", "ghcr.io/getanyapi-com/mcp"],
"env": { "ANYAPI_API_KEY": "aa_live_..." }
}
}
}
Get a key at https://getanyapi.com/dashboard/keys. Agents can mint their own free-trial key with no dashboard and no email:
curl -s -X POST https://api.getanyapi.com/agent/signup
| Variable | Required | Default | Meaning |
|---|---|---|---|
ANYAPI_API_KEY | No | none | Your AnyAPI key. Discovery works without it; running an API needs it. |
ANYAPI_MCP_URL | No | https://api.getanyapi.com/mcp | The hosted endpoint to proxy to. |
The key is optional on purpose. The hosted server answers initialize and
tools/list without a credential, so you can browse the catalog, read schemas,
and price a call before you have an account. Only tools/call needs a key.
Ten tools, read live from the hosted server rather than declared in this package, so a catalog or schema change reaches you without a release here.
| Tool | What it does |
|---|---|
search_apis | Search APIs by meaning and keyword. Takes any combination of query, category and platform; a scope on its own is a complete search. |
list_apis | Browse the catalog as lightweight summaries (id, name, category, USD pricing), with an optional category. |
get_api | The full definition of one API: normalized input/output JSON Schemas, per-lane USD pricing, and trailing-30-day latency. |
quote_api | The exact USD price of a run_api call before running it. Nothing is charged or executed. |
run_api | Execute an API by SKU with normalized input. Returns the output, costUsd, and items. Supports fields, max_items, summary and jq. |
get_request | Inspect or resume a durable request. Reads stored state and never repeats the paid dispatch. |
read_result | Re-shape a prior run's output without re-running or paying again. |
get_balance | The remaining USD wallet balance for the key. |
report_bug | Report wrong, empty, or malformed data for input you believe is valid. Free. |
send_feedback | Report a missing API, a missing field, or anything confusing. Free. |
Failed calls are never charged.
npm install
npm run check # build, then unit tests
npm run check needs no network and no API key. To drive the built server
against production by hand:
npm run build
ANYAPI_API_KEY=aa_live_... node dist/index.js
Apache-2.0
FAQs
Local stdio MCP server for AnyAPI - hundreds of scraping and data APIs behind one key, priced per request in USD. Proxies to the hosted AnyAPI MCP server.
The npm package anyapi-mcp receives a total of 55 weekly downloads. As such, anyapi-mcp popularity was classified as not popular.
We found that anyapi-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.