
HackMyIP — no-key IP intelligence
io.github.0xviblyv1.0.0Updated Sep 28, 2026
Free no-key IP intelligence: geolocation, VPN detection, DNS, WHOIS, blacklists, breach checks
Installation
In SourceWeft
- Open HackMyIP — no-key IP intelligence in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.
Other MCP clients
Add this to your client's mcpServers config.
{
"mcpServers": {
"hackmyip-mcp": {
"type": "http",
"url": "https://hackmyip.com/mcp"
}
}
}README
hackmyip-mcp
The no-key IP intelligence MCP — paste one URL, no signup.
That's the whole setup. No API key. No account. No OAuth dance. No credit card. Point any MCP client at that URL and your agent can immediately look up IPs, geolocate addresses, classify VPN/datacenter traffic, query DNS, run WHOIS, check spam blacklists, audit security headers, scan ports and test email authentication.
It's a thin, stateless wrapper around the free HackMyIP public REST API (docs) running on Cloudflare Workers at the edge. Every tool passes the API's JSON straight back to your agent — nothing is cached, rewritten, or invented.
Install
Claude Code
Claude Desktop
Settings → Connectors → Add custom connector, then paste:
Or edit claude_desktop_config.json directly
mcp-remote is only needed on older Desktop builds that lack native remote-MCP support.
Cursor
~/.cursor/mcp.json (global) or .cursor/mcp.json (per project):
Codex CLI
~/.codex/config.toml:
Restart Codex. No codex mcp login step — this server is authless.
VS Code / GitHub Copilot
.vscode/mcp.json:
Anything else
Any client that speaks MCP Streamable HTTP works. Endpoint:
https://hackmyip.com/mcp (mirror: https://hackmyip-mcp.shitcoinape.workers.dev/mcp).
Both the 2025-06-18 and 2026-07-28 protocol revisions are served.
Tools
Things worth knowing
my_ipreports the IP the MCP request arrived from. If your client runs on your laptop, that's your real public IP — which is exactly what makes "is my VPN actually working?" answerable. If it runs on a remote host or behind a corporate proxy, you get that egress IP instead. The tool says so in its response.ip_blacklist_checknever fakes a clean result. Lists that refuse public queries come back asunavailable, so readtotal_checkednext tolisted_count.port_scanis a real scan from Cloudflare's network. Only point it at hosts you're authorized to test. Private and reserved ranges are rejected upstream.whois_domaindepends on third-party RDAP registries which occasionally 5xx. A failure there is upstream, not a malformed query — retry.
Fair use
The upstream API allows 60 requests/minute per client IP (20/min for port_scan and
security_headers_check), resetting every 60 seconds. There is no paid tier to upgrade
to and no key that lifts it — it exists so the service stays free for everyone. If you
hit it, tools return the upstream 429 message and you should back off.
Prefer bulk_ip_lookup over a loop of ip_lookup calls.
Privacy
This server stores nothing. It holds no session state, writes no logs of your queries,
and requires no identity. Each tool call is a stateless pass-through to
https://hackmyip.com/api/*.
Run it yourself
Built with @modelcontextprotocol/server
and Cloudflare's agents createMcpHandler —
stateless, no Durable Objects, no database.
Links
- Website — https://hackmyip.com
- API docs — https://hackmyip.com/api-docs
- 50+ browser tools (VPN leak tests, fingerprinting, breach checks) — https://hackmyip.com/tools
License
MIT
Source: README.md at commit 0e7270b
Tools
0Version history
1- v1.0.0LatestSep 16, 2026