mcp-openapi-proxy

MCP.Pizza Chef: matthewhand

Point it at the description file a service publishes and every operation listed inside becomes something you can ask for in chat. Notion, Asana, Slack, Box, WordPress, NetBox and Wolfram Alpha all have worked examples. That includes operations that create, change and delete records, with no confirmation step and no read-only mode, unless you narrow the list yourself using the allow-list setting. Most services also need their own access token, which you paste into the config file.

Data
Web/Research

Use This MCP server To

Search my Notion workspace from inside a chat Create a task in Asana without opening it Look up a document stored in Box by name Post a short message into a team channel Reach a service that has no ready-made connector yet

README

mcp-openapi-proxy

mcp-openapi-proxy is a Python package that implements a Model Context Protocol (MCP) server, designed to dynamically expose REST APIs—defined by OpenAPI specifications—as MCP tools. This facilitates seamless integration of OpenAPI-described APIs into MCP-based workflows.

What's New in 0.2.0

Works with every modern MCP-enabled client we tested. Strict MCP clients can now discover and call tools — the low-level server advertises correct capabilities and no longer crashes during resource/prompt discovery, and a slow spec download no longer crash-loops short-timeout clients. Verified live against the full list of mainstream agent CLIs:

  • ✅ Codex, Gemini, Qwen, Kilocode, opencode — native tool calls over stdio
  • ✅ Vibe — native discovery and read calls (writes were CLI-flaky, not a proxy issue)
  • ✅ Letta — Cloud (via a remote streamable-HTTP MCP URL) and self-hosted (via stdio)

See the client matrix for attach mechanisms, models, and exact results.

📄 Full write-up: Verification case study — what the proxy is, the API + client matrices, and every defect found & fixed.

Prompts and resources are real now — including custom resources. Both MCP surfaces are functional and tested: the summarize_spec / whimsical_blog prompts and the spec_file resource, plus a new ADDITIONAL_RESOURCES env var that serves your own use-case documents (e.g. a NetBox naming policy or an Asana project-layout guide) as MCP resources — see examples/resources/.

Bug fixes (every one live-verified):

  • MCP client discovery: empty capability set + a crash in resource discovery left strict clients seeing zero tools (#23) — fixed, with a full stdio-handshake test harness.
  • IGNORE_SSL_TOOLS was ignored by the low-level dispatcher (#14) — fixed (original patch by @robbycochran, #15).
  • Server crash-loop when a slow spec fetch outran a client's connect timeout (#28) — handshake now answers immediately, spec loads lazily, closed streams exit cleanly.
  • API_AUTH_TYPE custom schemes (e.g. NetBox Token) sent no auth header at all (#24) — fixed.
  • TOOL_WHITELIST never matched Slack-style dot paths like /users.list (#27) — fixed.
  • TOOL_NAME_MAX_LENGTH was not respected, and name-truncation collisions silently dropped tools (#11) — fixed.
  • Array parameters were emitted without items, which the OpenAI API rejects (#16) — fixed.
  • EXTRA_HEADERS now accepts a JSON array and literal \n separators, not just real newlines (#17).
  • Dead Render spec URL (#26) and incomplete ElevenLabs example (#29) — fixed; the GetZep example is documented for self-hosted Zep CE since the hosted endpoint now 401s (#38).
  • Added a Dockerfile + glama.json for the Glama listing (#13); collapsible README examples + a verified-client/API matrix (#35).

Full environment-variable reference is in Environment Variables.

Table of Contents

mcp-openapi-proxy FAQ

Do I need an access token?
Usually yes, one belonging to the service you are connecting, pasted into the config. A few open services need nothing at all, so this depends entirely on which service you point it at rather than on the connector itself.
Can it change or delete my data?
Yes, by default. Every operation the service publishes becomes a tool, deletions and edits included, and none of them ask for confirmation. If you want it safe, use the allow-list setting to expose only the read-only operations.
The sign-in style called basic is listed. Does it work?
No. Choosing it quietly writes a warning to the log and sends no sign-in details at all, so every call fails. Use the default bearer style or the custom-word option instead.
Are there settings I should leave alone?
Yes, the two ignore-certificate options. They switch off the check that you are really talking to the service you think you are, and your token is still sent regardless, so turning them on can expose it.
Which apps does it work in?
Claude Desktop plus a long list of command-line assistants the author tested live, including Codex, Gemini, Qwen, Kilocode, opencode and Letta. Installation is one small block pasted into a config file.
Can I use this to run a service that has no official connector?
Yes, that is the entire point. If the service publishes a machine-readable description of what it can do, this turns that description into usable tools without anyone writing code.
What is the catch for a non-technical user?
Finding the address of the service's description file. It is rarely advertised, and the readme's worked examples are the realistic starting point rather than something you can work out yourself.
Will it overwhelm my assistant with options?
It can. A large service can produce hundreds of tools at once, which some apps handle badly. The allow-list and name-prefix settings exist to trim that down.
Is it still maintained?
Yes. The code was last updated in June 2026, and the recent releases fixed a long list of real defects, each verified against live services.