Stateful OpenAPI sandbox for AI agents to validate API integrations end-to-end.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag β we're steadily working through the catalog.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Turn any OpenAPI spec into a working sandbox your AI agent can use, right from your IDE.
This is the Model Context Protocol (MCP) server for FetchSandbox. It exposes three tools that let any MCP-compatible agent ingest an OpenAPI spec, list its workflows, and run them β with realistic, schema-validated responses for every endpoint.
β If FetchSandbox saves you a debugging session, star this repo. It helps people find the project and helps us prioritize what to build next.
Agents read raw OpenAPI specs and hallucinate. They guess field names, invent IDs that won't exist, and produce broken curl commands. FetchSandbox turns the spec into a stateful, AJV-validated sandbox so the agent can actually call the API and see real-shaped responses.
Plug it into your IDE once, and any time you ask your agent "let me try the Stripe API" or "show me the GitHub issue lifecycle," it can do that β for real, end-to-end.
The MCP runs as a stdio process spawned by your IDE. There's nothing to install globally β npx runs the published version on demand. We recommend pinning to @latest so each session auto-upgrades to the current release; otherwise npm caches the first version it saw and silently drifts behind.
Pick your tool below, paste the snippet, restart.
File: ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)
Quit and reopen Claude Desktop (Cmd+Q, then reopen β not just close window).
User-level (all projects): ~/.claude/settings.json. Or project-level: .mcp.json in the repo root.
Restart the Claude Code session.
File: ~/.cursor/mcp.json (global) or .cursor/mcp.json (project)
Restart Cursor.
Open the Cline panel β settings cog β MCP Servers β add a new server with:
npx-y fetchsandbox-mcp@latestReload the VS Code window.
File: ~/.continue/config.yaml
Restart your IDE.
File: ~/.codex/config.toml
Restart Codex.
File: ~/.config/zed/settings.json
GitHub Copilot doesn't currently support the Model Context Protocol. Track github/copilot#feedback for updates. In the meantime, run any MCP-compatible chat (Claude Code, Cursor, Cline) alongside Copilot.
If your agent speaks MCP, it accepts a stdio command. Use:
npx["-y", "fetchsandbox-mcp@latest"]After restarting your agent, paste any of these prompts. Each hits a hand-curated workflow with realistic IDs and real state transitions.
Use fetchsandbox to import the Stripe spec from
https://raw.githubusercontent.com/stripe/openapi/master/openapi/spec3.jsonand run theaccept_paymentworkflow. Show me the trace.
The agent imports 587 endpoints, matches the bundled curated Stripe sandbox, and runs a 6-step workflow: create customer (cus_β¦) β create PaymentIntent (pi_β¦, $49.99 USD, requires_payment_method) β confirm (requires_capture) β capture (succeeded) β retrieve β verify webhooks (payment_intent.created, payment_intent.succeeded).
Use fetchsandbox to import the Twilio Messaging spec from
https://raw.githubusercontent.com/twilio/twilio-oai/main/spec/yaml/twilio_messaging_v1.yamland run thesend_smsworkflow.
The agent imports the messaging API and runs a curated send-and-verify flow with realistic Twilio-formatted message SIDs (SMβ¦).
Use fetchsandbox to import the GitHub REST API from
https://raw.githubusercontent.com/github/rest-api-description/main/descriptions/api.github.com/api.github.com.jsonand run theissue_lifecycleworkflow.
The agent walks the create β comment β close β reopen flow against a real-shaped GitHub sandbox.
If a vendor doesn't publish their spec at a stable URL (Paddle, Notion, Linear), paste the content directly:
Here's the Paddle Billing OpenAPI spec β
<paste JSON or YAML>. Use fetchsandbox to import it and run thesubscriptions_canceledworkflow.
Same engine path; same curated quality if the spec's info.title matches a bundled config.
Use fetchsandbox to import
<your OpenAPI URL>β list the workflows and tell me which is most interesting.
For specs we don't have curated configs for, the engine auto-enumerates create + verify workflows for every detected resource. Honest about what it shows: UUIDs instead of vendor-style IDs, generic enum values instead of API-specific ones β but the request/response shape and template substitution between steps still work.
import_specIngest an OpenAPI 3.x spec and get a sandbox you can call. Pass either a public URL or pasted content.
Returns spec_id, sandbox_id, base_url (proxy that serves real-shaped responses), workflows_preview (first 10), matched_bundled (true if we matched a curated config), and a dashboard_url to view everything in the browser.
list_workflowsList the named, runnable workflows the engine inferred or curated for an imported spec.
run_workflowExecute one workflow and return the step-by-step request/response trace. Template variables ({{step1.id}}) are resolved automatically between steps. The response now includes a share_url per run β a public receipt URL you can paste into a PR or share with a teammate.
| Env var | Default | Purpose |
|---|---|---|
FETCHSANDBOX_BASE_URL | https://fetchsandbox.com | Override for stage testing or self-hosted backends. |
FETCHSANDBOX_TELEMETRY | (on) | Set to 0 to disable anonymous usage telemetry. |
When telemetry is on, each tool call records: an opaque per-machine session id (random UUID stored at ~/.fetchsandbox/session.json), the tool name, latency, success/failure, and the spec URL or "pasted". We do not record spec content, request bodies, or credentials. We use this to count daily-active sessions and learn which APIs people are bringing to the platform.
To opt out:
Try the FetchSandbox Playground β five small brownfield apps with planted bugs in real API integrations (Stripe webhook dedup, Resend bounce drops, Clerk JWT verification, AgentMail attachment handling, Surge opt-out). Clone, run, point your agent at one, and see whether FetchSandbox catches the bug. PRs with your session findings welcome.
MIT β see LICENSE.
npx fetchsandbox-mcp@latestNo reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/mcp-292)<a href="https://allmcps.com/mcp/mcp-292"><img src="https://allmcps.com/api/badge/mcp-292?style=directory" alt="Fetchsandbox MCP on AllMCPs" /></a>