Install
$ agentstack add mcp-kirkwat-openapi-to-mcp ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ● Environment & secrets Used
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
openapi-to-mcp
A minimal MCP server that auto-generates tools from your OpenAPI spec. Optimized for Vercel's serverless architecture.
[](https://vercel.com/new/clone?repository-url=https://github.com/kirkwat/openapi-to-mcp&env=OPENAPISPECURL&envDescription=URL%20to%20your%20OpenAPI%20spec&envLink=https://github.com/kirkwat/openapi-to-mcp%23configuration)
Quick Start
- Fork this repo
- Set
OPENAPI_SPEC_URLto your OpenAPI spec URL - Deploy to Vercel
Configuration
| Variable | Required | Description | | ------------------ | -------- | ---------------------------------------------------------------------- | | OPENAPI_SPEC_URL | Yes | URL or file path to your OpenAPI spec (YAML or JSON) | | API_BASE_URL | No | Override the API base URL (defaults to servers[0].url from the spec) | | MCP_SERVER_NAME | No | Override the MCP server name (defaults to info.title from the spec) | | PORT | No | Local dev server port (default: 3000) |
How It Works
- On cold start, the server fetches and parses your OpenAPI spec
- Each API endpoint becomes an MCP tool with a Zod-validated input schema
- When a tool is called, the request is forwarded to your API with the caller's headers (API key, Bearer token, etc.) passed through unchanged
- The spec and tools are cached in memory — warm invocations skip the fetch
Running Locally
1. Install dependencies
pnpm install
2. Configure environment variables
Create .env and set OPENAPI_SPEC_URL to your OpenAPI spec. For local dev, this can be a remote URL or an absolute file path:
# Remote URL
OPENAPI_SPEC_URL=https://api.example.com/openapi.yaml
# Or an absolute file path (local dev only)
OPENAPI_SPEC_URL=/path/to/your/openapi.yml
3. Start the dev server
pnpm dev
The server starts at http://localhost:3000/mcp.
4. Connect your MCP client to the local server
How you connect to the MCP server depends on your client (Claude Code, Cursor, VS Code, etc.) — check your client's docs for where to add MCP servers. Most clients use a similar JSON format. Here's an example for Claude Code (.mcp.json):
{
"mcpServers": {
"my-api": {
"type": "http",
"url": "http://localhost:3000/mcp",
"headers": {
"Authorization": "Bearer "
}
}
}
}
The headers block above shows a Bearer token, but you can use any header your API requires. The MCP server forwards all headers from your client config to the target API on every tool call without modification — it doesn't validate, store, or care which header is "the auth header". See [Auth](#auth) for examples (API key, Bearer token, multiple headers).
Deploying to Vercel
- Push this repo to GitHub
- Import it at vercel.com/new
- Add
OPENAPI_SPEC_URLunder Settings > Environment Variables.API_BASE_URLandMCP_SERVER_NAMEare optional overrides.
That's it. Your MCP server is live at https://your-project.vercel.app/mcp. Connect clients the same way as [local](#4-connect-your-mcp-client-to-the-local-server) — just swap the URL.
Auth
All headers from your MCP client config are forwarded to the target API on every tool call. The MCP server does not validate or store credentials — your API handles authentication.
Configure whatever headers your API expects in the client config:
// API key auth
"headers": { "X-Api-Key": "" }
// Bearer token
"headers": { "Authorization": "Bearer " }
// Multiple headers
"headers": { "Authorization": "Bearer ", "X-Org-Id": "org_123" }
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: kirkwat
- Source: kirkwat/openapi-to-mcp
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.