The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Picdefenseio MCP Server listing page.
A Model Context Protocol server for the PicDefense.io API — let AI agents run reverse-image risk analysis, EXIF extraction, image backlink discovery, and image content detection (face / landmark / logo / label / SafeSearch) on any image URL.
/mcp) and legacy SSE (/sse)/docs| Tool | Description |
|---|---|
picdefense_get_credits | Remaining account credit balance |
picdefense_check_image_risk | Reverse-image risk analysis + picrisk score (core tool) |
picdefense_extract_exif | Extract EXIF metadata (camera, timestamps, GPS) |
picdefense_detect_face | Detect a human face in an image |
picdefense_detect_landmark | Detect a recognizable landmark |
picdefense_detect_logo | Detect a brand logo |
picdefense_safesearch | Content-safety (adult/violence/racy/…) assessment |
picdefense_find_backlinks | Find pages where an image appears |
picdefense_detect_labels | Detect descriptive labels for image contents |
picdefense_extract_text | Extract text from an image via OCR |
picdefense_detect_watermark | Detect a visible stock/photographer watermark (source + confidence) |
All image tools take a single url (a public http/https image URL). Most tools
consume account credits per call — use picdefense_get_credits to check your balance.
Every request authenticates with your PicDefense API token, which is your user id and API key joined by a colon:
Find both in your PicDefense.io account settings: https://app.picdefense.io/?returnUrl=https://app.picdefense.io/dashboard/settings
The token is sent as the X-API-TOKEN header to the API (https://app.picdefense.io/api/v2).
The hosted server runs at https://mcp.picdefense.io. Add it to Claude Code:
Quick HTTP smoke test:
Claude Desktop launches MCP servers as local commands, so reach the hosted server
through the mcp-remote bridge (requires
Node.js installed). See claude_desktop_config.example.json:
Edit your claude_desktop_config.json (Settings → Developer → Edit Config), add the
mcpServers block above with your USERID:APIKEY, then fully quit and reopen Claude Desktop.
Testing against a plain-HTTP server (e.g.
http://<host>:6910) instead of HTTPS?mcp-remoteblocks non-HTTPS origins unless the host islocalhost— append"--allow-http"to theargsarray, or reach it over an SSH tunnel tolocalhost.
Run the published package directly. Requires Node.js installed.
You can also pass the token via the PICDEFENSE_API_TOKEN env var instead of --api-token.
Clone and build, then point Claude Desktop at the built entry point:
Then use "command": "node" with "args": ["/absolute/path/to/dist/index.js", "--api-token", "USERID:APIKEY"].
| Variable | Default | Description |
|---|---|---|
PICDEFENSE_API_TOKEN | — | USERID:APIKEY (stdio only; hosted server reads it per-connection) |
PICDEFENSE_API_BASE_URL | https://app.picdefense.io/api/v2 | API base URL |
PORT | 6910 | Hosted server listen port |
The container is named picdefenseio_mcp and listens on port 6910.
| Method | Path | Purpose |
|---|---|---|
| GET | /health | Health check (used by Docker + CI) |
| GET | /api/info | Server + transport info |
| GET | /tools | List available tools |
| GET | /docs | Swagger UI for the underlying API |
| GET | /sse?token=USERID:APIKEY | Open an SSE MCP session |
| POST | /messages?sessionId=<id> | SSE session message channel |
| POST | /mcp | Streamable HTTP MCP (header X-API-Token) |
There is no CI/CD in this repo — host it yourself. On your server:
The container is named picdefenseio_mcp and listens on 6910. To update,
git pull and re-run docker compose up --build -d.
Front it with nginx at https://mcp.picdefense.io → 127.0.0.1:6910
(proxy_buffering off and a long read timeout are recommended for the /sse path).
Each connection builds its own API client + MCP server bound to the caller's token, so the service is multi-tenant and stateless with respect to credentials.
MIT — see LICENSE.