
Wet
io.github.n24q02mv3.19.2Updated Oct 5, 2026
Open-source MCP server for AI agents: web search, content extraction, and library docs.
Overview
Gives an assistant web search, academic research, library documentation lookup, and URL or local file content extraction.
- What it does
- Exposes six MCP tools. search covers web and news search through an embedded SearXNG metasearch, academic sources such as Google Scholar, arXiv, PubMed and CrossRef, and version-aware library documentation search with project pinning. extract turns a URL into structured chunks (clean text, markdown, JSON-LD, code blocks, metadata) using an escalating fetch chain, and also handles batch URLs, crawling, site mapping and local file conversion from PDF, DOCX, XLSX, PPTX and EPUB. media lists and downloads images, video and audio; config and help manage settings and documentation.
- When to use it
- Useful when an assistant needs to look things up on the live web, gather academic references, pull current library documentation, or read pages and documents that are not already in context. It is a reasonable single addition for research and documentation-heavy coding work, especially since it runs without any API keys by default.
- Requirements
- Runs locally over stdio, typically via uvx wet-mcp, so Python tooling and network access are needed. It works zero-config with bundled local search and embedding models; optional cloud models and search backends require provider keys such as OPENAI_API_KEY, COHERE_API_KEY or TAVILY_API_KEY, and GITHUB_TOKEN raises rate limits for library discovery. An optional self-hosted HTTP mode uses a bearer token.
Installation
In SourceWeft
- Open Wet in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
WET - Web Extended Toolkit MCP Server
Renamed (2026-09-13): repo is now
wet— CLI-first (wetcommand). PyPI package stayswet(PyPI policy blocks new projectwet); MCP server is a secondary surface: runwetwith no subcommand.
mcp-name: io.github.n24q02m/wet
Renamed: the repo, CLI and Python module are now
wet. The PyPI distribution stayswet-mcp(installpip install wet-mcp/uvx wet-mcp). The MCP server remains available: runwetwith no subcommand (bare = MCP passthrough); the legacywet-mcpconsole alias still works.
Open-source MCP server for AI agents: web search, content extraction, and library docs.
Current release: v3.x.
media(action="analyze")was removed in the v2.0.0 BREAKING release. Useimagine-mcp'sunderstandaction for vision/audio/video analysis. Seedocs/migration.mdfor the upgrade recipe.
[Mode] [CI] [codecov] [PyPI] [License: Apache-2.0]
[Python] [SearXNG] [MCP] [semantic-release] [Renovate]
Sister projects from n24q02m (click to expand)
Table of contents
- Features
- Status
- Quick install
- Self-host usage
- Configuration
- Documentation
- Tools
- CLI
- Comparison
- Security
- Build from Source
- Deploy to Cloudflare
- Smithery
- Trust Model
- License
Features
- Web Search -- Embedded SearXNG metasearch (Google, Bing, DuckDuckGo, Brave) with query expansion, TTL cache (1 h general / 5 min time-sensitive), standardized citation format, and 200-token snippet cap. Optional cloud search backends (Tavily, Brave, Exa, OpenRouter) as a fallback chain via
SEARCH_BACKENDS, plus optional Cohere rerank (WET_SEARCH_RERANK) - Academic Research -- Search Google Scholar, Semantic Scholar, arXiv, PubMed, CrossRef, BASE
- Library Docs -- Auto-discover and index documentation with FTS5 hybrid search, HyDE-enhanced retrieval, and version-specific docs
- Content Extract -- 5-strategy escalation chain via
n24q02m-web-coreScrapingAgent(basic_http->tls_spoof-> render backends fromBROWSER_BACKENDS(native/browserless/cf-browser-rendering) -> optional key-gatedcaptcha), markitdown bridge for low-tier HTML/MD fallback, smart chunks structured output (clean text + markdown + JSON-LD + code blocks + metadata), batch processing (up to 50 URLs), deep crawling, site mapping - Local File Conversion -- Convert PDF, DOCX, XLSX, CSV, HTML, EPUB, PPTX to Markdown
- Media -- List + download images / videos / audio files.
analyzewas removed in v2.0.0 -- useimagine-mcp.understandfor vision/audio inference - Anti-bot -- Stealth strategies bypass Cloudflare, Medium, LinkedIn, Twitter
- Zero Config -- Built-in local reference embedding + reranking through fastretrieval, no API keys needed. Optional cloud providers (Jina AI, Gemini, OpenAI, Cohere, xAI, Anthropic) selected per task via the
EMBEDDING_MODELS/RERANK_MODELS/LLM_MODELSmodel chains for higher-quality vectors and LLM features - Sync -- Cross-machine sync of indexed docs via Google Drive (OAuth Device Code, no browser redirect)
Quick install
Install matrix (stdio unless noted; see the Setup page for full steps):
Public OCI image publication is discontinued. Existing historical registry tags remain untouched; new container deployments build from source or use the Cloudflare-managed registry.
The HTTP endpoint speaks Streamable HTTP and is OAuth-gated -- your client is prompted to authenticate in the browser on first connect (no API key to paste). Stand one up via Method 3 or the Deploy to Cloudflare section.
Full setup matrices live at the canonical docs site mcp.n24q02m.com/servers/wet/setup/ and the paste-to-agent snippets at claude-plugins/plugins/wet/setup-with-agent.md (per Spec F single source of truth).
Self-host usage
Two supported ways to run the always-listening HTTP server. In both, the MCP
endpoint is http://127.0.0.1:8000/mcp (Streamable HTTP) and the config root
is ~/.wet/ (config.toml, docs.db, subs/). Never run the server as a
spawned subprocess of a client — register the endpoint in your client instead.
Dev (uv, no-auth loopback)
no-auth refuses non-loopback binds — the server is localhost-only until you
switch to token auth.
Always-on (docker)
Compose publishes 127.0.0.1:${WET_PORT:-8000} → container 8000 (loopback
only) and mounts docker-config/config.toml read-only at
/home/appuser/.wet/config.toml. Persistent data (docs.db, subs/) lives in
the wet-home named volume; the download/cache dir in wet-data. Editing the
config takes effect on docker compose restart.
Consumers
Config: local vs cloud models
The [models.embed|rerank|chat|jev_score] cells in ~/.wet/config.toml are
per-task (each its own base_url + api_key + model, OpenAI-spec). The
example ships OpenRouter examples; any OpenAI-compatible endpoint works —
cloud, or a local server such as Ollama (base_url = "http://host.docker.internal:11434/v1" from the container). Keys in the file
are host-only material; alternatively leave api_key = "" and inject at start
via HULL_EMBED_API_KEY / HULL_RERANK_API_KEY / HULL_CHAT_API_KEY /
HULL_JEV_SCORE_API_KEY.
Configuration
wet runs zero-config out of the box: web search uses an embedded local SearXNG, and embedding/reranking fall back to the bundled local ONNX models through fastretrieval when no cloud keys are set. For higher-quality results, point each task at a cloud model chain. All settings are plain environment variables (no app prefix) -- in the HTTP self-host mode they are entered through the browser setup form instead.
Model chains (CSV provider/model,provider/model; order = fallback). Leave a
chain empty to use the local ONNX models (embedding/rerank) or to disable LLM
features (LLM):
Provider keys -- the provider is inferred from each model's prefix; supply the
matching key (litellm <PROVIDER>_API_KEY convention):
Any other litellm provider works via env passthrough -- see litellm provider docs for its key name.
FASTRETRIEVAL_CACHE_PATH controls the local model cache.
Search backends -- SEARCH_BACKENDS is an ordered runtime fallback chain:
searxng (default, local or external via SEARXNG_URL), keyed tavily / brave /
exa / kagi / openrouter, optional-key firecrawl, and credential-free duckduckgo /
startpage. Keyed providers use TAVILY_API_KEY, BRAVE_API_KEY, EXA_API_KEY,
KAGI_API_KEY, or OPENROUTER_API_KEY (comma-separate for rotation). The
openrouter backend runs the query through a chat completion with the
openrouter:web_search server tool and maps the returned url_citation
annotations onto the shared result shape; OPENROUTER_MODEL (default a
free-tier model), OPENROUTER_BASE_URL, and OPENROUTER_SEARCH_ENGINE
override its behavior. Firecrawl attempts a keyless request when FIRECRAWL_API_KEY
is absent; rejection or a DuckDuckGo/Startpage bot challenge advances the chain.
Cohere rerank (optional, paid) -- when WET_SEARCH_RERANK=1 AND
COHERE_API_KEY are both set, a successful chain result is re-ranked through
Cohere /v2/rerank (COHERE_RERANK_MODEL, default rerank-v4.0-fast;
COHERE_BASE_URL for gateway routes): results are reordered best-first and
tagged reranked_by: cohere with per-result rerank_score. Without either
variable the chain never calls Cohere; a rerank failure keeps the original
ordering. The same chain serves web search, research, similar-page search,
agent search,
and docs discovery/indexing fallbacks. SearXNG retains its science-category
filter for research; other providers use their own search capabilities.
Hosted users configure the chain and keys in their own relay record. An empty
hosted record never inherits an operator's provider key or local SearXNG URL;
single-user stdio still uses env/settings and preserves the public local path.
Browser render backends -- BROWSER_BACKENDS (CSV, escalation chain) picks
the headless render leg of extract: native (in-process chromium, the
zero-config default), browserless (self-host render service -- set
BROWSERLESS_URL + BROWSERLESS_TOKEN), and cf-browser-rendering (Cloudflare
Browser Rendering -- set CF_ACCOUNT_ID + CF_BROWSER_RENDERING_TOKEN). Empty
chain falls back to native. Set CAPSOLVER_API_KEY to append an optional,
key-gated CAPTCHA tier as the last escalation step.
Robots policy -- set RESPECT_ROBOTS_TXT=true to enforce robots.txt
across both the extract strategy chain and the Crawl4AI-backed crawl,
sitemap, and list_media actions. The default is false to preserve existing
deployment behaviour; configure this process-level policy explicitly when the
operator requires robots enforcement.
Invisible tier + seeded identity (opt-in) -- append invisible to
BROWSER_BACKENDS to add a stealth-Firefox engine tier as the last escalation
step (hull-core[invisible] extra: pip install "wet-mcp[invisible]"). One
coherent browser identity spans the whole chain: seed it with WET_IDENTITY_SEED
(or let wet derive once and persist it under ~/.wet/subs/<sub>/identity.json)
and install the wet[identity] extra. Without the extras the chain keeps
legacy behaviour (warn-once). STEALTHFOX_BINARY points at a patched Firefox
build to skip the engine download; IDENTITY_PROFILE_DIR (default
~/.wet/subs/<sub>/profiles) keeps persistent browser profiles per namespace.
Disable local fallbacks -- opt out of the heavy in-process local fallbacks
per capability (e.g. on a slim container that renders/searches/embeds via cloud
backends only): DISABLE_LOCAL_BROWSER, DISABLE_LOCAL_SEARCH,
DISABLE_LOCAL_EMBED, DISABLE_LOCAL_RERANK.
Docs sync -- SYNC_ENABLED (default true), GOOGLE_DRIVE_CLIENT_ID
(required for sync), SYNC_FOLDER (default wet), SYNC_INTERVAL (default
300s). Sync uses Google Drive over the OAuth Device Code flow (no browser
redirect).
DOCS_DB_BACKEND=cf-d1 disables GDrive/S3 file sync, including automatic
startup, relay wizard and device-code setup, even if legacy sync settings remain.
Non-CF SQLite deployments retain GDrive sync; SYNC_S3_BUCKET selects S3
instead, and SYNC_ENABLED=false disables both.
HTTP self-host -- MCP_TRANSPORT=http, PUBLIC_URL=<your-domain>. The setup
form is gated by MCP_RELAY_PASSWORD; multi-user deployments require
CREDENTIAL_SECRET (per-user vault key), MCP_JWT_SIGNING_SECRET (rotatable
OAuth JWT key), and MCP_DCR_SERVER_SECRET.
Example stdio config (cloud chains):
Status
Stable architecture with two transports: stdio (default, local) and
HTTP (self-host, OAuth-gated). No daemon-bridge layer and no auto-spawn
from stdio. The media.analyze action was removed in the v2.0.0 BREAKING
release -- see docs/migration.md for the upgrade
recipe. Current release line: v3.x.
Documentation
Full docs at mcp.n24q02m.com/servers/wet/setup/:
- Setup -- install methods for Claude Code, Codex, Gemini CLI, Cursor, Windsurf, mcp.json
- Modes overview -- stdio / local-relay / remote-relay / remote-oauth
- Multi-user setup -- per-JWT-sub credential model
In-repo references (Spec F single source of truth: setup docs live in claude-plugins/plugins/wet/):
docs/ARCHITECTURE.md-- web-core ScrapingAgent integration, strategy chain, storage layout, LLM provider dispatchdocs/BENCHMARKS.md-- v1.x baseline coverage / latency placeholders + tier-1 fixture metrics
Install with AI agent -- paste this to your AI coding agent:
Install MCP server
wetfollowing the steps at https://raw.githubusercontent.com/n24q02m/claude-plugins/main/plugins/wet/setup-with-agent.md
Tools
6 MCP tools (3 domain + config + help + config__open_relay). The legacy
setup tool merged into config action dispatch.
Media boundary: For vision / audio understanding (image captioning, OCR, audio transcription, video summarization), use imagine-mcp.
media.analyzewas removed in wet v2.0.0 -- useimagine-mcp.understandinstead.
CLI
The package installs two console scripts: wet (primary) and wet-mcp
(legacy alias kept so existing uvx wet-mcp configs keep working). A bare
invocation (or any leading-dash flag) starts the server; a leading positional
argument is dispatched as a subcommand.
auth google accepts an optional bring-your-own OAuth client via --client-id
and --client-secret (single-user / local machine only; the token is written to
the local store). Each subcommand prints a JSON result and exits.
Security
- SSRF prevention -- URL validation on crawl targets
- Graceful fallbacks -- Cloud → Local embedding, multi-tier crawling
- Error sanitization -- No credentials in error messages
- File conversion sandboxing -- Optional
CONVERT_ALLOWED_DIRSrestriction
Build from Source
Deploy to Cloudflare
Run your own single-user wet instance serverless on Cloudflare (Containers + D1 + Vectorize + KV).
Prerequisites: a Cloudflare account on the Workers Paid plan — required for Containers, D1, and Vectorize (the Cloudflare free tier does not include them) — and the wrangler CLI.
git clone https://github.com/n24q02m/wet && cd wetwrangler login- Provision resources and apply the D1 schema:
Paste the returned IDs into
wrangler.jsonc. - Build the slim HTTP image from this checkout and push it directly to Cloudflare's managed registry (CF Containers cannot pull from external registries):
- Set operator auth/storage and Browser Run secrets:
wrangler deployand complete setup in the browser relay form at your Worker domain.
Storage maps to Cloudflare via MCP_STORAGE_BACKEND=cf-kv (credentials/tokens, encrypted),
DOCS_DB_BACKEND=cf-d1 (docs + BM25 full-text), and Vectorize (embeddings). The
default headless renderer is BROWSER_BACKENDS=cf-browser-rendering. Local
ONNX fallbacks are disabled in the slim image; configure search and cloud
retrieval through each authenticated subject's relay record. Worker-wide
search/model chains and provider keys are not forwarded to the container.
For a Cloudflare AI Gateway route, enter the following values in that subject's
relay form (<CF_AIG_BASE> is the account/gateway base URL):
Store the matching OpenRouter/Cohere credentials and any keyed search-provider
credentials (such as TAVILY_API_KEY) in the same subject record.
All Wet synthesis and summaries use LLM_MODELS; there is no separate
SUMMARY_MODELS field. This completion chain has no paid or alternate-model
fallback. Cohere embedding/reranking and Browser Run may incur charges; obtain
the required budget authorization before exercising them. Provision Vectorize
and EMBEDDING_DIMS for a dimension supported by the selected embedding model.
The earlier 768-dimension example is not a Cohere v4 compatibility guarantee.
Deployment (maintained instance)
Every tagged release deploys automatically (only while the CF_DEPLOY_ENABLED
gate is on -- see the pause note below): the CD deploy-cf job checks out
the released tag, builds the http-slim image, pushes it to the Cloudflare-managed
registry as immutable :<release-tag>, deploys the Worker, and gates on a canary
health check -- a release is live at exactly its own version. A beta dispatch
redeploys the beta; a stable dispatch is maintainer-gated. Manual wrangler deploy
against the maintained instance is not permitted: it would break the
release-tag ↔ live-image correspondence. Self-hosting on your own Cloudflare
account (the button above) is unaffected.
Paused 2026-09-13: the CF deploy token was removed from the account as off-manifest (process violation), so
deploy-cfnow no-ops behind theCF_DEPLOY_ENABLEDrepo variable. The maintained instance stays frozen at its last deployed release until a token is re-established via the documented process and the variable is set totrue.
Smithery
wet ships a smithery.yaml so it can be installed and run
through Smithery. The manifest declares a stdio start
command (uvx --python 3.13 wet-mcp) with an empty config schema -- no config is
required to start, and providers and credentials are configured at runtime via
the server's own config flow (see Configuration).
Trust Model
This plugin implements TC-Local (machine-bound, single trust principal). See mcp-core trust model for full classification.
License
Apache-2.0 -- See LICENSE.
Source: README.md at commit 6b91569
Tools
0Version history
1- v3.19.2LatestOct 5, 2026
