Toolkit Mcp Server

io.github.cyanheadsv2.3.2更新於 Oct 8, 2026

Generate IDs, QR codes, and hashes, encode values, geolocate IPs, plus gated host diagnostics.

已驗證Streamable HTTP可網頁執行Developer ToolsSecurity & MonitoringLocation & Lifestyle

概覽

AI 產生的概覽

一套開發者工具伺服器,可產生 ID、QR code 與雜湊值,進行編碼解碼,並查詢 IP 地理位置,另含選用的主機診斷功能。

功能
提供七個工具:toolkit_hash_value 產生 SHA-2/SHA-1/MD5 摘要並支援常數時間比對,toolkit_generate_id 批次產生 UUIDv4、UUIDv7 與 ULID,toolkit_generate_qr 輸出 SVG、PNG 或終端機 QR code,toolkit_encode_value 處理 base64、base64url、hex 與 URL 百分比編碼,toolkit_geolocate_ip 回傳公網 IP 或主機名稱的國家、城市、座標、ASN 與時區。另有 toolkit_check_network 與 toolkit_check_system 兩個工具回報伺服器主機狀況,僅在明確啟用後才會註冊。
適用情境
適合需要產生識別碼、計算校驗和或核對 npm integrity 值、產生 QR code、轉換編碼,或查詢某個公網 IP 歸屬的情境。主機診斷工具適用於本機或自架部署,此時探測執行伺服器的機器才有意義。
執行需求
可作為遠端 Streamable HTTP 端點使用,也可透過 npx、bunx 或 Docker 在本機執行;本機執行需要 Bun v1.4.0+ 或 Node.js v24+。預設不需要 API 金鑰,因為地理定位使用免金鑰的 ip-api 免費層;僅當所用服務商要求時才需設定 TOOLKIT_GEO_API_KEY。選用變數包括 TOOLKIT_ENABLE_NET_DIAGNOSTICS、TOOLKIT_ENABLE_SYSTEM_INFO、TOOLKIT_ALLOW_PRIVATE_NETWORK、TOOLKIT_GEO_BASE_URL 與 MCP_TRANSPORT_TYPE。
安裝前請注意
兩個診斷工具預設關閉,會揭露作業系統、CPU、記憶體、負載與網路介面等主機資訊,因此在共用或代管部署中應保持關閉。TOOLKIT_ALLOW_PRIVATE_NETWORK 會解除對私有、回送、連結本地與保留位址(含雲端中介資料端點)的封鎖,只應刻意啟用。地理定位會把目標 IP 或主機名稱傳送給外部服務商;預設 ip-api 端點為明文 HTTP,HTTPS 需要付費金鑰。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Toolkit Mcp Server,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。

其他 MCP 客戶端

把它新增到你客戶端的 mcpServers 設定中。

{
  "mcpServers": {
    "toolkit-mcp-server": {
      "type": "http",
      "url": "https://toolkit.caseyjhand.com/mcp"
    }
  }
}

README

@cyanheads/toolkit-mcp-server

Generate random IDs, QR codes, and hashes, encode and decode values, and geolocate IPs, plus gated network and system diagnostics, via MCP. STDIO or Streamable HTTP.

7 Tools

Public Hosted Server: https://toolkit.caseyjhand.com/mcp


Overview

Developer utilities that run in-process: generate identifiers, QR codes, and cryptographic digests, and encode or decode values. Geolocating a public IP or hostname is the one outbound call, and two host-diagnostic tools stay off unless enabled. Runs as a stdio process, a local Streamable HTTP server, or the public hosted endpoint above.

Tools

ToolDescription
toolkit_hash_valueGenerate a digest (sha256/sha384/sha512/sha1/md5) as hex, base64, or SRI, or constant-time-compare a value against an expected digest
toolkit_generate_idMint cryptographically random UUIDv4, UUIDv7, or ULID identifiers, up to 1000 per call
toolkit_generate_qrEncode text or a URL as a QR code in SVG, base64 PNG, or terminal half-blocks
toolkit_encode_valueEncode or decode base64, base64url, hex, or URL percent-encoding
toolkit_geolocate_ipResolve a public IP or hostname to country, city, coordinates, ASN, and timezone
toolkit_check_networkGated, off by default. Ping, traceroute, TCP connectivity, or egress-IP check from the server host
toolkit_check_systemGated, off by default. OS, CPU, memory, load average, or network interfaces of the server host

Capability reference

toolkit_hash_value tool

  • value read per inputEncoding (utf8 default, hex, base64); algorithm is sha256 (default), sha384, or sha512, with sha1 and md5 for checksum compatibility only; operation is generate or compare, and when omitted it compares if expected is sent
  • generate returns digest in digestEncoding (hex default, base64, or sri for the SHA-2 algorithms) plus lengthInBytes; compare returns matches against expected, given as hex, base64, or SRI, including a multi-entry npm integrity value
  • A bad expected fails as expected_malformed, expected_length_mismatch (the hint names the algorithm that length fits), or expected_algorithm_mismatch

toolkit_generate_id tool

  • type is uuid_v4 (default), uuid_v7, or ulid; count is 1–1000 (default 1)
  • ids always holds exactly count values; uuid_v7 and ulid batches are strictly increasing even within one millisecond, with random gaps so no id is derivable from another

toolkit_generate_qr tool

  • data up to 2953 UTF-8 bytes at errorCorrection L, less at M (default), Q, and H; format is svg (default), png_base64, or terminal; margin 0–20 modules (default 4), scale 1–32 px per module (default 4)
  • Returns content, the symbol version (1–40), mimeType for image formats, and byteLength for PNG; png_base64 also arrives as an MCP image block, and terminal is plain Unicode half-blocks drawn for a dark background
  • Over-capacity input fails as data_too_large with its byte count; a PNG over 2048 px per side fails as raster_too_large with a scale that fits, while svg and terminal have no pixel cap

toolkit_encode_value tool

  • operation (encode or decode) and encoding (base64, base64url, hex, url) are required; whitespace in hex, base64, and base64url input is ignored, so wrapped MIME and PEM bodies decode as-is
  • Decode returns result as utf8 text unless outputEncoding asks for hex or base64, which returns the bytes losslessly and transcodes between encodings; malformed input fails as decode_failed, and binary bytes as decode_not_utf8 rather than with replacement characters

toolkit_geolocate_ip tool

  • target is an IPv4/IPv6 address or a dotted hostname, DNS-resolved first; private or reserved addresses fail as private_target, unresolvable hostnames as unresolvable_host
  • Returns country, countryCode, region, city, latitude/longitude, asn, org, and timezone with resolvedIp and source; a true in proxy, hosting, or mobile means the location describes infrastructure, not a person
  • Keyless ip-api free tier over plaintext HTTP by default (TOOLKIT_GEO_BASE_URL, TOOLKIT_GEO_API_KEY); results are cached per resolved IP and provider calls are rate-limited

toolkit_check_network tool

  • mode is ping, traceroute, connectivity, or public_ip; target is required except for public_ip, and port (1–65535) for connectivity; count 1–10 pings (default 3), timeoutMs 100–30000 (default 3000)
  • A silent host is reachable: false, not an error; ping adds rttMs, sent, received, and packetLossPercent, connectivity adds outcome (open, refused, timeout, unreachable), and traceroute returns hops; an unresolvable host or a ping/traceroute binary that can't run fails as unreachable
  • Registered only when TOOLKIT_ENABLE_NET_DIAGNOSTICS=true; private and reserved targets fail as private_target_blocked unless TOOLKIT_ALLOW_PRIVATE_NETWORK=true

toolkit_check_system tool

  • what is os, cpu, memory, load, or interfaces; exactly one matching facet object is populated
  • memory.availableBytes is the allocation headroom and limitBytes appears under a container memory limit; totalBytes, freeBytes, and usedBytes are raw OS figures that count reclaimable cache as used
  • Registered only when TOOLKIT_ENABLE_SYSTEM_INFO=true, since os and interfaces disclose host topology and version details

Features

Built on @cyanheads/mcp-ts-core: stdio and Streamable HTTP transports, pluggable auth (none / jwt / oauth), swappable storage (in-memory, filesystem, Supabase, Cloudflare KV/R2/D1), structured logging with optional OpenTelemetry tracing.

Toolkit-specific:

  • Hashing, ID minting, QR encoding, and encode/decode run in-process on node:crypto and the qrcode library, with no upstream calls
  • Geolocation calls the provider, never the target, and checks the DNS-resolved IP against private ranges, so a hostname can't reach an internal address
  • Fail-closed gating: toolkit_check_network and toolkit_check_system are absent from tools/list unless enabled. Both report on the server's host, not the caller's, so they belong on local or self-hosted deployments
  • Two-tier network gate: with diagnostics on, private, loopback, link-local, and reserved targets (the cloud-metadata endpoint included) stay blocked until TOOLKIT_ALLOW_PRIVATE_NETWORK=true

Agent-friendly output:

  • Provenance: geolocation echoes resolvedIp and source, and omits fields the provider didn't report instead of inventing them
  • Response shaping: provider strings are capped at 256 characters and stripped of control characters, so registry-controlled text like org can't flood or format a model's context
  • Discriminated outputs: operation, format, mode, and what echo what ran, and only that branch's fields are populated
  • Typed failures: every declared failure carries a reason and a recovery hint, and conflicting inputs (expected with generate, outputEncoding with encode) are rejected by name, not ignored

Getting started

Public Hosted Instance

A public instance is available at https://toolkit.caseyjhand.com/mcp — no installation required. Point any MCP client at it via Streamable HTTP:

json
{  "mcpServers": {    "toolkit-mcp-server": {      "type": "streamable-http",      "url": "https://toolkit.caseyjhand.com/mcp"    }  }}

Self-Hosted / Local

Add the following to your MCP client configuration file. No API key is required.

json
{  "mcpServers": {    "toolkit-mcp-server": {      "type": "stdio",      "command": "bunx",      "args": ["@cyanheads/toolkit-mcp-server@latest"],      "env": {        "MCP_TRANSPORT_TYPE": "stdio",        "MCP_LOG_LEVEL": "info"      }    }  }}

Or with npx (no Bun required):

json
{  "mcpServers": {    "toolkit-mcp-server": {      "type": "stdio",      "command": "npx",      "args": ["-y", "@cyanheads/toolkit-mcp-server@latest"],      "env": {        "MCP_TRANSPORT_TYPE": "stdio",        "MCP_LOG_LEVEL": "info"      }    }  }}

Or with Docker:

json
{  "mcpServers": {    "toolkit-mcp-server": {      "type": "stdio",      "command": "docker",      "args": ["run", "-i", "--rm", "-e", "MCP_TRANSPORT_TYPE=stdio", "ghcr.io/cyanheads/toolkit-mcp-server:latest"]    }  }}

To enable the gated host-probing tools, add their flags to env (or -e for Docker):

json
"env": {  "MCP_TRANSPORT_TYPE": "stdio",  "TOOLKIT_ENABLE_NET_DIAGNOSTICS": "true",  "TOOLKIT_ENABLE_SYSTEM_INFO": "true"}

For Streamable HTTP, set the transport and start the server:

sh
MCP_TRANSPORT_TYPE=http MCP_HTTP_PORT=3010 bun run start:http# Server listens at http://localhost:3010/mcp

Prerequisites

  • Bun v1.4.0 or higher (or Node.js v24+).
  • No API key needed — geolocation uses the keyless ip-api free tier by default.

Installation

  1. Clone the repository:
sh
git clone https://github.com/cyanheads/toolkit-mcp-server.git
  1. Navigate into the directory:
sh
cd toolkit-mcp-server
  1. Install dependencies:
sh
bun install

Configuration

All variables are optional.

VariableDescriptionDefault
TOOLKIT_ENABLE_NET_DIAGNOSTICSRegister the gated toolkit_check_network tool. Leave off for hosted or shared deployments.false
TOOLKIT_ENABLE_SYSTEM_INFORegister the gated toolkit_check_system tool.false
TOOLKIT_ALLOW_PRIVATE_NETWORKWith network diagnostics on, permit private, reserved, loopback, and link-local targets.false
TOOLKIT_GEO_API_KEYAPI key for the geolocation endpoint, if it requires one.none
TOOLKIT_GEO_BASE_URLBase URL for an ip-api-compatible endpoint. The keyless default is plaintext HTTP; ip-api's HTTPS endpoint needs a paid key.http://ip-api.com
TOOLKIT_GEO_CACHE_TTL_SECONDSIn-memory geolocation cache TTL in seconds.3600
TOOLKIT_GEO_RATE_LIMIT_PER_MINMax geolocation provider requests per minute; cache hits don't count, and excess requests fail with a retryable rate-limit error.45
MCP_TRANSPORT_TYPETransport: stdio or http.stdio
MCP_HTTP_PORTPort for the HTTP server.3010
MCP_SESSION_MODEHTTP session mode: stateless, stateful, or auto. The server declares stateless; an explicit value overrides it.stateless
MCP_AUTH_MODEAuth mode: none, jwt, or oauth.none
MCP_LOG_LEVELLog level (RFC 5424).info
OTEL_ENABLEDEnable OpenTelemetry.false

See .env.example for the full list of optional overrides.

Running the server

Local development

  • Build and run:

    sh
    # One-time buildbun run rebuild
    # Run the built serverbun run start:stdio# orbun run start:http
  • Run checks and tests:

    sh
    bun run devcheck   # Lint, format, typecheck, security, changelog syncbun run test       # Vitest test suitebun run lint:mcp   # Validate MCP definitions against spec

Docker

sh
docker build -t toolkit-mcp-server .docker run --rm -p 3010:3010 toolkit-mcp-server

The Dockerfile defaults to HTTP transport, stateless session mode, and logs to /var/log/toolkit-mcp-server. OpenTelemetry peer dependencies are installed by default — build with --build-arg OTEL_ENABLED=false to omit them.

Project structure

DirectoryPurpose
src/index.tscreateApp() entry point — registers the five always-on tools, and the two gated tools only behind their flags.
src/configServer-specific environment variable parsing and validation with Zod.
src/mcp-server/toolsTool definitions (*.tool.ts). Seven tools, five always-on and two gated.
src/services/geoGeolocation service — DNS resolution, provider call with retry, normalization, in-memory cache.
src/services/networkNetwork-diagnostic service plus the shared target schema and private-range classifier.
tests/Vitest suites for tools (tests/tools) and services (tests/services).

Development guide

See CLAUDE.md / AGENTS.md for development guidelines and architectural rules. The short version:

  • Handlers throw, framework catches — no try/catch in tool logic
  • Use ctx.log for request-scoped logging, ctx.state for tenant-scoped storage
  • Register new tools in the createApp() arrays in src/index.ts; a host-probing tool registers only behind an enable flag
  • Wrap external API calls: validate raw → normalize to domain type → return output schema; never fabricate missing fields

Contributing

Issues are welcome. Run checks and tests before submitting:

sh
bun run devcheckbun run test

License

Apache-2.0 — see LICENSE for details.

來源:README.md,提交 81bdf6c

工具

0
工具後設資料尚未被收錄。

版本歷史

4
  1. v2.3.2最新Oct 7, 2026
  2. v2.3.1Sep 24, 2026
  3. v2.2.4Sep 19, 2026
  4. v2.2.3Sep 16, 2026