
Security News
Ruby's Bundler 4.0.18 Extends Cooldown to bundle lock and bundle cache
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.
x402-codesearch-mcp
Advanced tools
Free MCP server: index a repo's files (free) into the live x402-codesearch Worker so it can be semantically searched. Open funnel twin of the paid x402-gated codesearch HTTP API.
A free MCP (Model Context Protocol) server that indexes a repo's files —
chunked and embedded — into the live semantic code search Worker, for free,
via one MCP tool: index_code.
This is the open funnel twin of a paid, x402-gated HTTP API:
x402-codesearch-poc.theliminalguy.workers.dev
— POST /search, $0.01 USDC on Base per query via the
x402 payment protocol, for the actual semantic search
step over an indexed repo.
Sibling packages like x402-repohealth-mcp
fully reimplement their paid Worker's logic locally (pure functions, no
external account-bound dependency) and expose the entire feature for
free via MCP.
This package cannot do that. The paid Worker's semantic search depends on two Cloudflare-account-bound bindings with no free, local, or portable equivalent:
@cf/baai/bge-base-en-v1.5) — generates the embeddingsBoth only exist inside the Worker's own Cloudflare account. There is no way to run them for free outside that account, so this MCP server does not try to fake or proxy them.
What genuinely is free is POST /index on the live Worker itself — the
step that chunks a file, embeds it, and upserts it into that Worker's own
Vectorize index. That's the one real, free, stateless capability this
package exposes as an MCP tool. The matching POST /search step stays
exactly where it already is: a real x402-gated HTTP call directly against
the live Worker.
One tool, index_code:
{ repoId: string, files: [{ path: string, content: string }] }POST https://x402-codesearch-poc.theliminalguy.workers.dev/index
(free, no payment) with that exact body.{ repoId, filesIndexed, chunksIndexed } plus a note field
reminding the caller that searching what was just indexed requires the
paid endpoint.It does not expose a search_code tool. Semantic search over data
indexed with this tool requires calling the x402-gated endpoint directly:
POST https://x402-codesearch-poc.theliminalguy.workers.dev/search
Body: { "repoId": "...", "query": "..." }
Price: $0.01 USDC on Base, via the x402 protocol (e.g. x402-fetch / x402-axios)
An unpaid request to /search returns 402 Payment Required with real
x402 payment instructions.
npx x402-codesearch-mcp
Or add it to an MCP client config (e.g. Claude Desktop's
claude_desktop_config.json):
{
"mcpServers": {
"codesearch": {
"command": "npx",
"args": ["-y", "x402-codesearch-mcp"]
}
}
}
index_codeInput:
{
"repoId": "my-repo",
"files": [
{ "path": "src/retry.py", "content": "def retry_with_backoff(...): ..." }
]
}
Output (MCP tool text content, JSON-stringified):
{
"repoId": "my-repo",
"filesIndexed": 1,
"chunksIndexed": 2,
"note": "Indexing succeeded (free). To semantically search this repoId, call the x402-gated POST https://x402-codesearch-poc.theliminalguy.workers.dev/search directly ($0.01 USDC on Base per query) — not available through this free MCP tool."
}
npm install
npm run dev # runs src/index.ts directly on stdio via tsx
npm run build # compiles to dist/ for the published npm package
npm run test:index # calls indexCode() directly against the real live Worker, no MCP transport
src/client.ts and src/types.ts hold the thin HTTP client against the
live Worker's /index endpoint — src/index.ts is a thin MCP wrapper
around indexCode().
POST /index call this tool makes goes to the actual live
Worker, which really chunks the given files, really calls Workers AI for
embeddings, and really upserts into Vectorize — nothing here is mocked or
hardcoded. Verified end-to-end against the live Worker (see below).POST /index requires no payment and no API key —
confirmed live, not just documented.POST /search on the same
Worker. That's a deliberate scope boundary, not an oversight — see "Why
this one is different" above.index_code call re-POSTs to the live
Worker; re-indexing the same file just re-chunks/re-embeds/re-upserts it.Use POST /search on the live Worker instead of (in addition to) this MCP
server when:
index_code and now want to actually search
it semantically.x402-fetch / x402-axios) and
can pay $0.01 USDC on Base per query.index_code
tool shares the same free /index endpoint as every other caller, but
/search is metered per call regardless of caller.MIT
FAQs
Free MCP server: index a repo's files (free) into the live x402-codesearch Worker so it can be semantically searched. Open funnel twin of the paid x402-gated codesearch HTTP API.
We found that x402-codesearch-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.