The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Toolkit MCP Server listing page.
Generate random IDs, QR codes, and hashes, encode and decode values, and geolocate IPs, plus gated network and system diagnostics, via MCP. STDIO or Streamable HTTP.
Public Hosted Server: https://toolkit.caseyjhand.com/mcp
Seven tools. Five are always on and need no configuration — pure-compute utilities plus an SSRF-free IP lookup. Two probe the server host and stay absent from tools/list until you opt in, fail-closed.
| Tool | Description |
|---|---|
toolkit_hash_value | Generate a cryptographic digest (sha256/sha512/sha1/md5), or constant-time-compare a value against an expected digest. |
toolkit_generate_id | Mint cryptographically-random identifiers — UUIDv4, UUIDv7, or ULID — singly or in batches up to 1000. |
toolkit_generate_qr | Encode text or a URL into a QR code as SVG markup, base64 PNG, or a terminal-renderable string. |
toolkit_encode_value | Encode or decode a value across base64, base64url, hex, or URL percent-encoding, in either direction. |
toolkit_geolocate_ip | Resolve a public IP or hostname to geographic and network metadata — country, city, coordinates, ASN, timezone. |
toolkit_check_network | Gated, off by default. Read-only network diagnostics from the server host — ping, traceroute, TCP connectivity, or egress-IP detection. |
toolkit_check_system | Gated, off by default. Report a facet of the server host's system state — OS, CPU, memory, load average, or network interfaces. |
toolkit_hash_valueGenerate a digest, or constant-time-verify a value against an expected one.
operation: generate (lowercase-hex digest) or compare (timing-safe check via timingSafeEqual)sha256 (default) and sha512 for security; sha1 and md5 are exposed for checksum and file-integrity compatibility only — never for passwords or signaturesinputEncoding reads value as utf8 (default), hex, or base64, so binary blobs skip a decode round-triptoolkit_generate_idMint cryptographically-random identifiers from the platform CSPRNG — the correct source for IDs that must be unpredictable, unlike model-invented values.
type: uuid_v4 (random, default), uuid_v7 (time-ordered, sortable by creation), or ulid (26-char Crockford base32, lexicographically sortable)count mints a batch up to 1000 in one call; the returned ids array always holds exactly count valuesuuid_v7 and ulid batches are monotonic — strictly increasing even within the same millisecond — so ids stays in sorted creation ordertoolkit_generate_qrEncode text or a URL into a QR code.
format: svg (inline markup), png_base64 (raster bytes with mimeType and byteLength), or terminal (Unicode block string)errorCorrection (L/M/Q/H) trades data capacity for damage tolerance; margin sets the quiet-zone width; scale sets pixels per module for raster outputversion (1–40) reflects how dense the encoded data ispng_base64 also arrives as an MCP image content block, so a client reading content[] can render the code without decoding structuredContent(modules + 2 × margin) × scale — so a dense symbol at a high scale is rejected with a typed raster_too_large error naming a scale that fits; svg and terminal are unboundeddata is capped at 2953 bytes — the absolute ceiling (version 40, level L, byte mode); usable capacity is lower at higher errorCorrection levels, so over-capacity input is rejected with a typed data_too_large error rather than a generic failuretoolkit_encode_valueEncode or decode a value, in either direction.
encoding: base64, base64url (URL-safe alphabet), hex, or url (percent-encoding)operation: encode (raw UTF-8 → encoding) or decode (encoded value → text)decode_failed error with a recovery hint, not a silent best-efforttoolkit_geolocate_ipResolve a public IP or hostname to geographic and network metadata.
proxy, hosting, and mobile flag when the address is a proxy/VPN/Tor exit, a datacenter network, or a mobile carrier — a true on any of them means the coordinates describe infrastructure, not a person. Absent when the provider doesn't report themresolvedIp echoes the IP actually located, and source names the answering providerorg, isp, as) cannot flood or format a model's contextTOOLKIT_GEO_BASE_URL); results are cached in memory by resolved IP under a fixed entry captoolkit_check_networkGated — registered only when TOOLKIT_ENABLE_NET_DIAGNOSTICS=true. Read-only network diagnostics from the server host.
mode: ping (ICMP round-trip), traceroute (hop path to the target), connectivity (raw TCP connect to target on port), or public_ip (the host's own egress IP)reachable: false — a valid result, not an errorTOOLKIT_ALLOW_PRIVATE_NETWORK=true, which keeps the cloud-metadata endpoint blocked by defaulttoolkit_check_systemGated — registered only when TOOLKIT_ENABLE_SYSTEM_INFO=true. Report a facet of the server host's system state, read-only.
what: os, cpu, memory, load, or interfaceswhatos and interfaces disclose host topology and version detailsBuilt on @cyanheads/mcp-ts-core:
none, jwt, oauthToolkit-specific:
tools/list unless explicitly enabled, so a hosted instance exposes no SSRF or info-disclosure surfacetimingSafeEqualAgent-friendly output:
reachable: false instead of an error, so callers branch on data, not exception textA public instance is available at https://toolkit.caseyjhand.com/mcp — no installation required. Point any MCP client at it via Streamable HTTP:
Add the following to your MCP client configuration file. No API key is required — the five always-on tools and the default keyless geolocation tier work out of the box.
Or with npx (no Bun required):
Or with Docker:
To enable the gated host-probing tools, add their flags to env (or -e for Docker):
For Streamable HTTP, set the transport and start the server:
Every variable is optional. Server-specific options are validated at startup via the Zod schema in src/config/server-config.ts.
| Variable | Description | Default |
|---|---|---|
TOOLKIT_ENABLE_NET_DIAGNOSTICS | Register the gated toolkit_check_network tool. Leave off for hosted or shared deployments. | false |
TOOLKIT_ENABLE_SYSTEM_INFO | Register the gated toolkit_check_system tool. Meaningful only on a local or self-hosted deployment. | false |
TOOLKIT_ALLOW_PRIVATE_NETWORK | With network diagnostics on, permit private/reserved/loopback targets. The second explicit gate. | false |
TOOLKIT_GEO_API_KEY | API key for the geolocation endpoint, if it requires one. | none |
TOOLKIT_GEO_BASE_URL | Base URL for an ip-api-compatible geolocation endpoint. The default is plaintext HTTP — ip-api's HTTPS endpoint is not part of the keyless free tier and answers 403 SSL unavailable for this endpoint without a paid key. Point this at an HTTPS endpoint (with TOOLKIT_GEO_API_KEY) to encrypt the provider request. | http://ip-api.com |
TOOLKIT_GEO_CACHE_TTL_SECONDS | In-memory geolocation cache TTL in seconds. | 3600 |
TOOLKIT_GEO_RATE_LIMIT_PER_MIN | Max geolocation requests per minute. | 45 |
MCP_TRANSPORT_TYPE | Transport: stdio or http. | stdio |
MCP_HTTP_PORT | Port for the HTTP server. | 3010 |
MCP_AUTH_MODE | Auth mode: none, jwt, or oauth. | none |
MCP_LOG_LEVEL | Log level (RFC 5424). | info |
OTEL_ENABLED | Enable OpenTelemetry instrumentation (spans, metrics, completion logs). | false |
See .env.example for the full list of optional overrides.
Build and run:
Run checks and tests:
The Dockerfile defaults to HTTP transport, stateless session mode, and logs to /var/log/toolkit-mcp-server. OpenTelemetry peer dependencies are installed by default — build with --build-arg OTEL_ENABLED=false to omit them.
| Directory | Purpose |
|---|---|
src/index.ts | createApp() entry point — registers tools and inits services, with fail-closed gating for the two host-probing tools. |
src/config | Server-specific environment variable parsing and validation with Zod. |
src/mcp-server/tools | Tool definitions (*.tool.ts). Seven tools — five always-on, two gated. |
src/services/geo | Geolocation service — DNS resolution, provider call with retry/backoff, normalization, in-memory cache. |
src/services/network | Network-diagnostic service plus the shared target validator and private-range classifier. |
tests/ | Unit and integration tests mirroring the src/ structure. |
See CLAUDE.md / AGENTS.md for development guidelines and architectural rules. The short version:
try/catch in tool logicctx.log for request-scoped logging, ctx.state for tenant-scoped storagecreateApp() arrays in src/index.tsIssues and pull requests are welcome. Run checks and tests before submitting:
Apache-2.0 — see LICENSE for details.