# Kjopstad-IT/rqwstr [Health: Active]

**Category:** 🔒 Security  
**Repository:** https://github.com/Kjopstad-IT/rqwstr-mcp  
**GitHub Stars:** 0  
**Views:** 1  
**Installs:** 0  
**Upvotes:** 0  
**Directory Page:** https://allmcps.com/mcp/kjopstad-it-rqwstr

## Description
AI-native HTTP security testing toolkit: 17 tools (send, intruder, race, chain, oob) with low-level control over HTTP/1.1 + HTTP/2 (raw framing, connection pinning).

## Claude Desktop Quick Installation
Heuristic fallback — verify the package name and runner against the repository README before running it. Uses `npx` (confidence: low):

```json
"mcpServers": {
  "rqwstr": {
    "command": "npx",
    "args": ["-y","kjopstad-it-rqwstr"]
  }
}
```

## Documentation & README

# rqwstr

AI-native HTTP security testing toolkit, shipped as an MCP server. It gives an AI agent low-level control over HTTP/1.1 and HTTP/2 — raw framing, connection pinning, intruder-style fuzzing, request racing, OOB detection, and multi-step chains — on its own Go engine, rather than wrapping a high-level HTTP client.

This repository hosts the **release binaries and Claude Desktop `.mcpb` bundles**. The source is proprietary. Docs and sign-up: **[rqwstr.com](https://rqwstr.com)**.

![rqwstr localhost MCP demo](https://raw.githubusercontent.com/Kjopstad-IT/rqwstr-mcp/HEAD/demo/rqwstr-demo.gif)

Real v1.2.0 MCP session against a synthetic loopback fixture: one request, response-side
filtering, stored search, and named retrieval. The capture and renderer are reproducible
from [`demo/`](https://github.com/Kjopstad-IT/rqwstr-mcp/blob/HEAD/demo/README.md) with an activated free or Pro license; no live target is
involved.

## Install

### Claude Desktop (one-click)

Download the `.mcpb` for your platform from the [latest release](https://github.com/Kjopstad-IT/rqwstr-mcp/releases/latest) and double-click it to add rqwstr as a Claude Desktop extension.

- **macOS** — Apple silicon (`darwin_arm64`) or Intel (`darwin_amd64`)
- **Linux** — `linux_amd64` or `linux_arm64`
- **Windows** — `windows_amd64`

### Standalone MCP server

Download the binary for your platform from the [latest release](https://github.com/Kjopstad-IT/rqwstr-mcp/releases/latest), then point your MCP client at it:

```json
{
  "mcpServers": {
    "rqwstr": {
      "command": "rqwstr",
      "args": ["serve"]
    }
  }
}
```

`rqwstr serve` runs the MCP server on stdio.

## Tools

17 HTTP tools:

`send` · `send_h2` · `fetch` · `intruder` · `race` · `chain` · `oob` · `parallel` ·
`scope` · `session` · `encode` · `export` · `save` · `search` · `hunt` · `profile` ·
`import`

## Workflows

The HTTP tools cover:

- **Traffic** — `send` (HTTP/1.1), `send_h2` (HTTP/2), `fetch`, `import` (Burp / HAR), `export` (curl / python / requests)
- **Hunt lifecycle** — `hunt`, `scope`, `save`, `search`, `session`, `profile`
- **Attacks** — `intruder` (sniper, battering ram, pitchfork, cluster bomb), `race` (single-packet), `chain`, `parallel`
- **OOB** — `oob` with Interactsh integration
- **Encoding** — `encode` (URL, base64, JWT, and more)

Agents discover workflows through the `rqwstr_docs` tool. Per-hunt state lives in SQLite. The free tier is the core toolset; a Pro tier unlocks the heavier offensive tools.

## Verify a download

Each release includes `checksums.txt`. Verify before running:

```sh
# Linux
sha256sum -c checksums.txt

# macOS
shasum -a 256 -c checksums.txt
```

## Privacy Policy

rqwstr's data collection, usage, storage, sharing, retention, and contact practices are
documented in the [Privacy Policy](https://rqwstr.com/legal/privacy/).

## License

Proprietary. © Kjøpstad IT. See [rqwstr.com](https://rqwstr.com) for terms.

