
Security News
Ruby's Bundler 4.0.18 Extends Cooldown to bundle lock and bundle cache
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.
Model Context Protocol server for opn.onl — the open-source, self-hostable URL shortener. Lets AI assistants shorten links, read analytics, and manage links.
An MCP server for opn.onl — the open-source, self-hostable URL shortener. It lets AI assistants (Claude Desktop, Cursor, etc.) shorten links, read analytics, generate QR codes, and manage links in natural language.
Works against the hosted service or your own self-hosted instance.
On your opn.onl instance, go to Settings → API Keys, create a key, and copy it (it starts with opn_ and is shown once).
Claude Desktop — edit claude_desktop_config.json (~/Library/Application Support/Claude/ on macOS, %APPDATA%\Claude\ on Windows):
{
"mcpServers": {
"opn": {
"command": "npx",
"args": ["-y", "opn-mcp"],
"env": {
"OPN_API_KEY": "opn_your_key_here"
}
}
}
}
Restart your client. That's it — it talks to the hosted API (https://l.opn.onl) by default.
Prefer to run from source? Swap the
argsfor the GitHub build — same config:"args": ["-y", "github:ysalitrynskyi/opn-mcp"](it builds on install).
Point OPN_BASE_URL at your own instance's API host:
{
"mcpServers": {
"opn": {
"command": "npx",
"args": ["-y", "opn-mcp"],
"env": {
"OPN_API_KEY": "opn_your_key_here",
"OPN_BASE_URL": "https://l.your-domain.com"
}
}
}
}
| Env var | Required | Default | Description |
|---|---|---|---|
OPN_API_KEY | ✅ | — | Your API key (opn_…), from Settings → API Keys |
OPN_BASE_URL | — | https://l.opn.onl | API base URL — set this for a self-hosted instance |
Links
| Tool | Description |
|---|---|
shorten_url | Create a short link — optional alias, title, notes, scheduling (starts_at/expires_at), max_clicks, password, burn-after-reading, folder and tags |
shorten_urls_bulk | Shorten many URLs at once, optionally into a folder |
list_links | List your links (limit, offset, search, folder or tag filter) |
update_link | Update destination, title, notes, scheduling, click limit, folder or protections; clear fields with remove_* flags |
delete_link | Delete a link |
clone_link | Duplicate a link under a fresh short code |
toggle_link_pin | Pin or unpin a link |
check_alias_available | Check whether a custom alias is free before using it |
Analytics
| Tool | Description |
|---|---|
get_link_stats | Per-link analytics (clicks, unique visitors, geo, cities, devices, browsers, OS, referrers); optional days window |
get_dashboard_stats | Account-wide analytics across all your links |
QR & URL helpers
| Tool | Description |
|---|---|
get_qr_code | Get a link's QR image — optional brand colour, centre logo, PNG/SVG |
check_url_health | Check a destination URL is reachable before shortening |
build_utm_url | Append UTM campaign parameters to a URL |
preview_url_metadata | Fetch Open Graph metadata (title, description, image) for a URL |
Tags & folders
| Tool | Description |
|---|---|
list_tags / create_tag | List or create tags |
add_tags_to_link / remove_tags_from_link | Attach or detach tags on a link |
list_folders / create_folder | List or create folders |
move_links_to_folder | Move links into a folder |
npm install
npm run build # tsc → dist/
npm test # vitest
OPN_API_KEY=opn_… npm run dev # run from source (stdio)
All three registries are owned by ysalitrynskyi (npm user, GitHub user, and
the io.github.ysalitrynskyi MCP-registry namespace), so publishing must be done
while signed in as that account.
package.json, server.json (top-level and the packages[0].version),
and SERVER_VERSION in src/server.ts.main and push. CI (.github/workflows/ci.yml) runs
build + test — it does not publish.ysalitrynskyi):
npm login
npm publish # prepublishOnly runs the build
ysalitrynskyi):
mcp-publisher validate # optional, offline check
mcp-publisher login github # interactive browser OAuth
mcp-publisher publish
Smithery (smithery.yaml) and Glama
(glama.json) track the npm/registry release automatically — no separate step.
MIT © ysalitrynskyi. Part of the opn.onl project.
FAQs
Model Context Protocol server for opn.onl — the open-source, self-hostable URL shortener. Lets AI assistants shorten links, read analytics, and manage links.
The npm package opn-mcp receives a total of 21 weekly downloads. As such, opn-mcp popularity was classified as not popular.
We found that opn-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.