
Toolkit Mcp Server
io.github.cyanheadsv2.3.2更新於 Oct 8, 2026
Generate IDs, QR codes, and hashes, encode values, geolocate IPs, plus gated host diagnostics.
概覽
一套開發者工具伺服器,可產生 ID、QR code 與雜湊值,進行編碼解碼,並查詢 IP 地理位置,另含選用的主機診斷功能。
- 功能
- 提供七個工具:toolkit_hash_value 產生 SHA-2/SHA-1/MD5 摘要並支援常數時間比對,toolkit_generate_id 批次產生 UUIDv4、UUIDv7 與 ULID,toolkit_generate_qr 輸出 SVG、PNG 或終端機 QR code,toolkit_encode_value 處理 base64、base64url、hex 與 URL 百分比編碼,toolkit_geolocate_ip 回傳公網 IP 或主機名稱的國家、城市、座標、ASN 與時區。另有 toolkit_check_network 與 toolkit_check_system 兩個工具回報伺服器主機狀況,僅在明確啟用後才會註冊。
- 適用情境
- 適合需要產生識別碼、計算校驗和或核對 npm integrity 值、產生 QR code、轉換編碼,或查詢某個公網 IP 歸屬的情境。主機診斷工具適用於本機或自架部署,此時探測執行伺服器的機器才有意義。
- 執行需求
- 可作為遠端 Streamable HTTP 端點使用,也可透過 npx、bunx 或 Docker 在本機執行;本機執行需要 Bun v1.4.0+ 或 Node.js v24+。預設不需要 API 金鑰,因為地理定位使用免金鑰的 ip-api 免費層;僅當所用服務商要求時才需設定 TOOLKIT_GEO_API_KEY。選用變數包括 TOOLKIT_ENABLE_NET_DIAGNOSTICS、TOOLKIT_ENABLE_SYSTEM_INFO、TOOLKIT_ALLOW_PRIVATE_NETWORK、TOOLKIT_GEO_BASE_URL 與 MCP_TRANSPORT_TYPE。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 Toolkit Mcp Server,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。
其他 MCP 客戶端
把它新增到你客戶端的 mcpServers 設定中。
{
"mcpServers": {
"toolkit-mcp-server": {
"type": "http",
"url": "https://toolkit.caseyjhand.com/mcp"
}
}
}README
@cyanheads/toolkit-mcp-server
Generate random IDs, QR codes, and hashes, encode and decode values, and geolocate IPs, plus gated network and system diagnostics, via MCP. STDIO or Streamable HTTP.
Public Hosted Server: https://toolkit.caseyjhand.com/mcp
Overview
Developer utilities that run in-process: generate identifiers, QR codes, and cryptographic digests, and encode or decode values. Geolocating a public IP or hostname is the one outbound call, and two host-diagnostic tools stay off unless enabled. Runs as a stdio process, a local Streamable HTTP server, or the public hosted endpoint above.
Tools
Capability reference
toolkit_hash_value tool
valueread perinputEncoding(utf8default,hex,base64);algorithmissha256(default),sha384, orsha512, withsha1andmd5for checksum compatibility only;operationisgenerateorcompare, and when omitted it compares ifexpectedis sentgeneratereturnsdigestindigestEncoding(hexdefault,base64, orsrifor the SHA-2 algorithms) pluslengthInBytes;comparereturnsmatchesagainstexpected, given as hex, base64, or SRI, including a multi-entry npmintegrityvalue- A bad
expectedfails asexpected_malformed,expected_length_mismatch(the hint names the algorithm that length fits), orexpected_algorithm_mismatch
toolkit_generate_id tool
typeisuuid_v4(default),uuid_v7, orulid;countis 1–1000 (default 1)idsalways holds exactlycountvalues;uuid_v7andulidbatches are strictly increasing even within one millisecond, with random gaps so no id is derivable from another
toolkit_generate_qr tool
dataup to 2953 UTF-8 bytes aterrorCorrectionL, less atM(default),Q, andH;formatissvg(default),png_base64, orterminal;margin0–20 modules (default 4),scale1–32 px per module (default 4)- Returns
content, the symbolversion(1–40),mimeTypefor image formats, andbyteLengthfor PNG;png_base64also arrives as an MCP image block, andterminalis plain Unicode half-blocks drawn for a dark background - Over-capacity input fails as
data_too_largewith its byte count; a PNG over 2048 px per side fails asraster_too_largewith a scale that fits, whilesvgandterminalhave no pixel cap
toolkit_encode_value tool
operation(encodeordecode) andencoding(base64,base64url,hex,url) are required; whitespace inhex,base64, andbase64urlinput is ignored, so wrapped MIME and PEM bodies decode as-is- Decode returns
resultasutf8text unlessoutputEncodingasks forhexorbase64, which returns the bytes losslessly and transcodes between encodings; malformed input fails asdecode_failed, and binary bytes asdecode_not_utf8rather than with replacement characters
toolkit_geolocate_ip tool
targetis an IPv4/IPv6 address or a dotted hostname, DNS-resolved first; private or reserved addresses fail asprivate_target, unresolvable hostnames asunresolvable_host- Returns
country,countryCode,region,city,latitude/longitude,asn,org, andtimezonewithresolvedIpandsource; atrueinproxy,hosting, ormobilemeans the location describes infrastructure, not a person - Keyless ip-api free tier over plaintext HTTP by default (
TOOLKIT_GEO_BASE_URL,TOOLKIT_GEO_API_KEY); results are cached per resolved IP and provider calls are rate-limited
toolkit_check_network tool
modeisping,traceroute,connectivity, orpublic_ip;targetis required except forpublic_ip, andport(1–65535) forconnectivity;count1–10 pings (default 3),timeoutMs100–30000 (default 3000)- A silent host is
reachable: false, not an error;pingaddsrttMs,sent,received, andpacketLossPercent,connectivityaddsoutcome(open,refused,timeout,unreachable), andtraceroutereturnshops; an unresolvable host or a ping/traceroute binary that can't run fails asunreachable - Registered only when
TOOLKIT_ENABLE_NET_DIAGNOSTICS=true; private and reserved targets fail asprivate_target_blockedunlessTOOLKIT_ALLOW_PRIVATE_NETWORK=true
toolkit_check_system tool
whatisos,cpu,memory,load, orinterfaces; exactly one matching facet object is populatedmemory.availableBytesis the allocation headroom andlimitBytesappears under a container memory limit;totalBytes,freeBytes, andusedBytesare raw OS figures that count reclaimable cache as used- Registered only when
TOOLKIT_ENABLE_SYSTEM_INFO=true, sinceosandinterfacesdisclose host topology and version details
Features
Built on @cyanheads/mcp-ts-core: stdio and Streamable HTTP transports, pluggable auth (none / jwt / oauth), swappable storage (in-memory, filesystem, Supabase, Cloudflare KV/R2/D1), structured logging with optional OpenTelemetry tracing.
Toolkit-specific:
- Hashing, ID minting, QR encoding, and encode/decode run in-process on
node:cryptoand theqrcodelibrary, with no upstream calls - Geolocation calls the provider, never the target, and checks the DNS-resolved IP against private ranges, so a hostname can't reach an internal address
- Fail-closed gating:
toolkit_check_networkandtoolkit_check_systemare absent fromtools/listunless enabled. Both report on the server's host, not the caller's, so they belong on local or self-hosted deployments - Two-tier network gate: with diagnostics on, private, loopback, link-local, and reserved targets (the cloud-metadata endpoint included) stay blocked until
TOOLKIT_ALLOW_PRIVATE_NETWORK=true
Agent-friendly output:
- Provenance: geolocation echoes
resolvedIpandsource, and omits fields the provider didn't report instead of inventing them - Response shaping: provider strings are capped at 256 characters and stripped of control characters, so registry-controlled text like
orgcan't flood or format a model's context - Discriminated outputs:
operation,format,mode, andwhatecho what ran, and only that branch's fields are populated - Typed failures: every declared failure carries a
reasonand a recovery hint, and conflicting inputs (expectedwithgenerate,outputEncodingwithencode) are rejected by name, not ignored
Getting started
Public Hosted Instance
A public instance is available at https://toolkit.caseyjhand.com/mcp — no installation required. Point any MCP client at it via Streamable HTTP:
Self-Hosted / Local
Add the following to your MCP client configuration file. No API key is required.
Or with npx (no Bun required):
Or with Docker:
To enable the gated host-probing tools, add their flags to env (or -e for Docker):
For Streamable HTTP, set the transport and start the server:
Prerequisites
- Bun v1.4.0 or higher (or Node.js v24+).
- No API key needed — geolocation uses the keyless ip-api free tier by default.
Installation
- Clone the repository:
- Navigate into the directory:
- Install dependencies:
Configuration
All variables are optional.
See .env.example for the full list of optional overrides.
Running the server
Local development
-
Build and run:
-
Run checks and tests:
Docker
The Dockerfile defaults to HTTP transport, stateless session mode, and logs to /var/log/toolkit-mcp-server. OpenTelemetry peer dependencies are installed by default — build with --build-arg OTEL_ENABLED=false to omit them.
Project structure
Development guide
See CLAUDE.md / AGENTS.md for development guidelines and architectural rules. The short version:
- Handlers throw, framework catches — no
try/catchin tool logic - Use
ctx.logfor request-scoped logging,ctx.statefor tenant-scoped storage - Register new tools in the
createApp()arrays insrc/index.ts; a host-probing tool registers only behind an enable flag - Wrap external API calls: validate raw → normalize to domain type → return output schema; never fabricate missing fields
Contributing
Issues are welcome. Run checks and tests before submitting:
License
Apache-2.0 — see LICENSE for details.
來源:README.md,提交 81bdf6c
工具
0版本歷史
4- v2.3.2最新Oct 7, 2026
- v2.3.1Sep 24, 2026
- v2.2.4Sep 19, 2026
- v2.2.3Sep 16, 2026

