trackmcp
Back to directory
thisis-najeeb

api-test-mcp

View on GitHub

MCP server that calls your real API and checks the response against your OpenAPI spec — contract testing, auth presets, spec diffing, and health checks for Claude Code, Cursor, and Windsurf.

0 stars JavaScriptOthers Updated Aug 31, 2026
api-testingcontract-testingjson-schemamcpmcp-servermodel-context-protocolopenapirest-apischema-validationswaggerai-agentsapiclaudeclaude-codecursordeveloper-toolsdevtoolsllm-toolsnodejstesting

Documentation

api-test-mcp

CI
npm version
npm downloads
License: MIT

An MCP server that gives Claude Code, Cursor, Windsurf, or any MCP-compatible AI agent the ability to actually call your API and check the response against what your OpenAPI spec promises — not just read the docs and guess.

No API keys, no config, no cost. Works with any OpenAPI/Swagger 3.x spec (URL or local file).

Why this exists

AI agents are great at reading an OpenAPI spec and writing code against it — but they're guessing about whether the real API actually behaves the way the spec says. This gives an agent (or you, in a normal chat) a way to find out for real: call the live endpoint, and check whether the response actually matches the documented schema.

Install

bash
git clone 
cd api-test-mcp
npm install

Add it to your MCP client config, e.g. for Claude Code:

bash
claude mcp add api-test -- node /absolute/path/to/api-test-mcp/src/index.js

Or in `claude_desktop_config.json` / Cursor's MCP settings:

json
{
  "mcpServers": {
    "api-test": {
      "command": "node",
      "args": ["/absolute/path/to/api-test-mcp/src/index.js"]
    }
  }
}

Tools

ToolWhat it does
`load_api_spec`Load and dereference an OpenAPI/Swagger spec from a URL or local path. Returns the API title, servers, and every documented endpoint. Call this first.
`list_endpoints`List every endpoint currently loaded.
`call_endpoint`Make a real HTTP call to a documented endpoint. Returns the real status, headers, and body.
`validate_response`Check a response body against the JSON schema documented for a given method + path + status.
`test_endpoint``call_endpoint` + `validate_response` in one step. The main tool — "does this endpoint actually work as documented?"
`run_all_tests`Best-effort contract-test pass across every GET endpoint that needs no required parameters. Pass `includeMutating: true` to also auto-generate example params/bodies from the schema and attempt POST/PUT/PATCH (off by default — it can write real data). Endpoints still needing manual input are listed as skipped, with the reason.
`check_health`One-shot ping across a set of endpoints (or every parameter-free GET in the loaded spec): reports reachability and latency. Handy before a demo or as a CI step.
`diff_api_specs`Compare two versions of a spec (e.g. an old tag vs. `main`) and flag likely-breaking changes — removed endpoints, newly-required fields, type changes, removed enum values — versus safe additive changes.

All of the above accept an optional `auth` preset (`bearer`, `apiKey` in a header or query param, or `basic`) so authenticated APIs aren't limited to hand-building raw headers, and an optional `timeoutMs`.

Example (what an agent conversation looks like)

> You: Load my API spec at `https://api.example.com/openapi.json` and check whether `/users/{id}` actually returns what it documents.

>

> Agent: *(calls `load_api_spec`, then `test_endpoint` with a real user id)* → "Called it — got a 200, but the response is missing the `created_at` field your spec marks as required, and `role` is documented as an enum of 3 values but the API returned `"superadmin"`, which isn't one of them."

For an authenticated API:

> You: Run a full contract-test pass against my staging API using this bearer token, and include the write endpoints.

>

> Agent: *(calls `run_all_tests` with `{ auth: { type: "bearer", token: "..." }, includeMutating: true }`)* → "12 passed, 2 failed, 3 skipped. `POST /orders` failed schema validation — `total_cents` came back as a string, not the integer your spec documents."

Tested against real live traffic

`npm test` runs three real, unmocked checks, no canned fixtures pretending to be a server:

  • `test/smoke-test.js` — loads a spec, makes real HTTPS calls to a live public API, validates the real response, and deliberately feeds in a broken response to confirm validation actually catches mismatches (not just a happy-path check).
  • `test/new-features-test.js` — auth presets applied to a real outgoing request URL, a real network timeout/abort, a real health-check call, and deterministic offline tests for the spec-diff logic.
  • `test/mcp-protocol-test.js` — spawns the actual MCP server as a subprocess and talks to it over the real MCP protocol, the same way Claude Code or Cursor would.

CI runs the full suite on every push/PR against Node 18, 20, and 22.

Roadmap

v1.0 shipped contract testing, auth presets, auto-generated example data for mutating endpoints, spec diffing, and health checks. Ideas for what's next:

  • YAML output mode / a small CLI wrapper for non-MCP use
  • Configurable retry/backoff for flaky endpoints in `run_all_tests` and `check_health`
  • Pattern-aware example generation (respect JSON Schema `pattern` instead of a placeholder string)
  • Persisted health-check history (currently one-shot only)

Contributions welcome — see CONTRIBUTING.md. See an endpoint type or spec quirk this doesn't handle well? Open an issue.

License

MIT

Frequently asked questions

What is api-test-mcp?

api-test-mcp is MCP server that calls your real API and checks the response against your OpenAPI spec — contract testing, auth presets, spec diffing, and health checks for Claude Code, Cursor, and Windsurf.

How do I install api-test-mcp?

Open the GitHub repository and follow its README. Most MCP servers are added to your client's MCP config, then called by your agent.

Is api-test-mcp open source?

Yes — it is hosted on GitHub at https://github.com/thisis-najeeb/api-test-mcp.

Related MCP tools

atlassianatlassian-mcp-server

Official remote MCP server for Atlassian. Securely connect Jira, Confluence, Jira Service Management, Bitbucket, and Compass to Claude, ChatGPT, Cursor, VS Code, and other AI tools using OAuth 2.1 or API tokens.

1,015 JavaScript
aiai-agentsatlassian+17
riponcmprojectmem

Open-source coding agent memory. Records issues, attempts, fixes and decisions, then warns your agent before it repeats an approach that already failed. Native MCP server for Claude Code, Cursor, Antigravity and Codex. 100% local, no cloud, no telemetry. MIT.

796 Python
ai-agentsai-memoryai-tools+17
jgravellejcodemunch-mcp

Cut AI token costs 95%+ on code exploration. The leading MCP server for precise, symbol-level GitHub code retrieval via tree-sitter AST. Works with Claude Code, Cursor & any MCP client. 313B+ tokens saved.

2,651 Python
claudeclaude-codeai-coding+17
firecrawlfirecrawl-mcp-server

🔥 Official Firecrawl MCP Server - Adds powerful web scraping and search to Cursor, Claude and any other LLM clients.

7,393 JavaScript
batch-processingclaudecontent-extraction+11
KnockOutEZwigolo

The go-to web for your AI coding agent — local-first search, fetch, crawl & research over MCP. No API keys, no cloud, $0/query. Public beta.

4,906 TypeScript
mcpagentai+17
IvanMurzakUnity-MCP

AI Skills, MCP Tools, and CLI for Unity Engine. Full AI develop and test loop. Use cli for quick setup. Efficient token usage, advanced tools. Any C# method may be turned into a tool by a single line. Works with Claude Code, Gemini, Copilot, Cursor and any other absolutely for free.

4,137 C#
aiai-integrationgame-development+16

Run your own MCP server? See who uses it and what to fix.

Measure it with TrackMCP