
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
gstinapi-mcp
Advanced tools
MCP server for gstinapi.in — GSTIN verification, GST return/compliance/filing-preference history, and HSN/SAC code lookup, for use from Claude and other MCP clients.
An MCP server for gstinapi.in — GSTIN verification, GST return/compliance history and HSN/SAC code lookup, callable directly from Claude and other MCP clients.
This is a thin wrapper around the REST API at gstinapi.in/docs. It holds no logic of its own — every tool call is one authenticated HTTP request, and the response is returned as-is.
claude_desktop_config.json or .mcp.json):{
"mcpServers": {
"gstinapi": {
"command": "npx",
"args": ["-y", "gstinapi-mcp"],
"env": {
"GSTINAPI_API_KEY": "your-api-key-here"
}
}
}
}
No install step — npx fetches it on first use.
| Tool | What it does |
|---|---|
verify_gstin | Live registration lookup: legal name, status, taxpayer type, address |
get_gstin_returns | GSTR-1/3B filing history for a financial year |
get_gstin_compliance | Filing history summarised — counts, lag, last period |
get_gstin_filing_preference | Monthly vs quarterly (QRMP), quarter by quarter |
lookup_hsn_code | Official description for an HSN/SAC code |
search_hsn_codes | Find HSN/SAC codes from a description |
get_usage_stats | Today's call count for the key (free) |
Full field-level reference: https://www.gstinapi.in/docs
Pay-per-use credits on your gstinapi.in account, no separate charge for this MCP server. Pricing: https://www.gstinapi.in/pricing
MIT
FAQs
MCP server for gstinapi.in — GSTIN verification, GST return/compliance/filing-preference history, and HSN/SAC code lookup, for use from Claude and other MCP clients.
We found that gstinapi-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.