Install
$ agentstack add mcp-ventz-mcp-explorer ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
MCP Explorer
A web-based GUI for exploring and interacting with Model Context Protocol (MCP) servers. Connect to any MCP server, browse its capabilities, and execute tools, read resources, and test prompts — all from your browser.
Features
- Connect to any MCP server — supports both Streamable HTTP and SSE transports (auto-detects)
- Authentication — Bearer token, custom header, or no auth
- Browse Tools — list all tools, view schemas, fill in parameters, and execute them
- Browse Resources — list and read resources exposed by the server
- Browse Prompts — list prompts, fill in arguments, and retrieve rendered output
- Parameter Store — save and reuse frequently used parameter values across sessions
- URL History — remembers previously connected server URLs
- Clean UI — minimal, responsive interface with tabbed navigation
Quick Start
Prerequisites
- Python 3.13+
- uv (recommended) or pip
Install & Run
# Clone the repo
git clone https://github.com/ventz/mcp-explorer.git
cd mcp-explorer
# Install dependencies
uv sync
# Run the server
uv run python app.py
Open http://localhost:8000 in your browser.
Using pip
pip install fastapi 'uvicorn[standard]' jinja2 mcp
python app.py
Usage
- Enter an MCP server URL (e.g.,
http://localhost:3000/mcp) - Optionally configure authentication (Bearer token or custom header)
- Click Connect
- Use the tabs to explore Tools, Resources, and Prompts
- Select an item to view its details, fill in parameters, and execute
Project Structure
mcp-explorer/
├── app.py # FastAPI backend — MCP client + API routes
├── pyproject.toml # Python project metadata & dependencies
├── templates/
│ └── index.html # Main HTML template
└── static/
├── app.js # Frontend application logic
└── style.css # Styles
API Endpoints
| Method | Path | Description | |--------|---------------------|------------------------------| | GET | / | Web UI | | GET | /health | Health check | | POST | /api/connect | Connect to an MCP server | | POST | /api/disconnect | Disconnect | | GET | /api/status | Connection status | | GET | /api/tools | List available tools | | POST | /api/tools/call | Execute a tool | | GET | /api/resources | List available resources | | POST | /api/resources/read | Read a resource | | GET | /api/prompts | List available prompts | | POST | /api/prompts/get | Get a rendered prompt |
Security & Deployment Notes
This is a local developer tool. It connects to whatever URL you give it and has no authentication of its own, so keep the following in mind:
- Binds to
127.0.0.1by default. Only processes on your machine can reach
it. Override with MCP_EXPLORER_HOST only if you understand that exposing the proxy lets anyone who can reach it connect outward through your machine.
- SSRF guard. Requests to link-local (including the cloud metadata address
169.254.169.254), multicast, and reserved addresses are always refused. Loopback and private (RFC1918) addresses are allowed by default so you can reach local MCP servers; set MCP_EXPLORER_BLOCK_PRIVATE=1 to refuse those too (useful if you ever expose the server).
- Run as a single worker. Connection state is held in-process, so do not run
under multiple uvicorn workers — each worker would have its own state.
- Auth credentials are only saved to
localStoragewhen you tick
Remember; otherwise the token is used for the connection but not stored.
Protocol
Uses the official mcp Python SDK, which negotiates the latest MCP protocol version (2025-11-25) during initialization and terminates the session (DELETE /mcp) on disconnect. The negotiated version is reported by /api/status.
License
MIT
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: ventz
- Source: ventz/mcp-explorer
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.