APIShed
REMOTE · APISHED.COM · SCANNED OCT 4
Validates PESEL/NIP/REGON/IBAN/Luhn/ISBN/EAN/BIC/VAT; RPN, dates, hash, tokens, random, encode, time
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security60
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 52 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability77
- AI-judged instruction clarity (good).Pass
- Tool/resource definitions use about 3939 tokens (~75/item across 52 items; 52 tools + 0 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage88
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 59% of tool parameters carry a description.Partial
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety75
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 0 of 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "rpncalc_eval" implies "eval" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
- An AI judge read all 52 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the APIShed MCP server?
APIShed is a hosted endpoint at https://apished.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · apished.com
claude mcp add --transport http com-apished-apished 'https://apished.com/mcp'
{
"mcpServers": {
"com-apished-apished": {
"url": "https://apished.com/mcp"
}
}
} {
"servers": {
"com-apished-apished": {
"type": "http",
"url": "https://apished.com/mcp"
}
}
} [mcp_servers.com-apished-apished] url = "https://apished.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-apished-apished": {
"type": "remote",
"url": "https://apished.com/mcp",
"enabled": true
}
}
} openclaw mcp add com-apished-apished --url 'https://apished.com/mcp' --transport streamable-http
mcp_servers:
com-apished-apished:
url: "https://apished.com/mcp" {
"McpServers": {
"com-apished-apished": {
"Transport": "http",
"Url": "https://apished.com/mcp"
}
}
} assistant mcp add com-apished-apished -t streamable-http -u 'https://apished.com/mcp'
{
"mcpServers": {
"com-apished-apished": {
"type": "http",
"url": "https://apished.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 29 Sept 26 −1
- Tool “encode_decode” rewrote its description, which is the text the model reads security
- Tool “encode_encode” rewrote its description, which is the text the model reads security
- Schema quality: 2576 → 3939 ▼ functional
- Tool coverage: 74% → 59% ▼ functional
- Schema quality: excellent → good functional
- New tool “color_contrast” functional
- New tool “color_convert” functional
- New tool “csv_from_json” functional
- New tool “csv_parse” functional
- New tool “csv_stats” functional
- New tool “csv_to_json” functional
- New tool “csv_validate” functional
- New tool “hash_hmac” functional
- New tool “network_cidr_contains” functional
- New tool “network_cidr_info” functional
- New tool “network_cidr_overlaps” functional
- New tool “pipe_run” functional
- New tool “regex_extract” functional
- New tool “regex_replace” functional
- New tool “regex_split” functional
- New tool “units_convert_datasize” functional
- New tool “units_convert_temperature” functional
- New tool “uuid_generate” functional
- New tool “uuid_validate” functional
- “encode_decode” reworded the description of “format” cosmetic
- “encode_encode” reworded the description of “format” cosmetic
- 28 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Sept 26 0
- New tool “datetime_now” functional
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 23 Sept 26 0
- New tool “encode_decode” functional
- New tool “encode_encode” functional
- 18 Sept 26 0
- New tool “random_int” functional
- 17 Sept 26 0
- Stability: 0.97 → pass security
- 16 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 4 Oct 2026 · Probed https://apished.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=apished.com | CN=YR2,O=Let's Encrypt,C=US | 17 Aug 2026 | 15 Nov 2026 | RSA 4096 | SHA256-RSA | 5f4dfa5fcafb280b9204690908ddbca6b5c |
| SANs: apished.com | ||||||
| CN=YR2,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | 4ebd24947e24d394802d84a52fd5b319 |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
Background: What to check on a remote MCP endpoint →
DNSSEC secure
Validation of apished.com. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| apished.com. | present | 38629 | 8 | Verified |
| apished.com. | Verified address RRset verified with the apex keys |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://apished.com/mcp | Verified | 200 | |
| http (plaintext) | http://apished.com/mcp | HTTPS enforced | 301 | https://apished.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
color_contrast ~52
Computes the WCAG 2.1 contrast ratio between two hex colors. Alpha, if present, is composited over white first.
| Name | Type | Req | Description |
|---|---|---|---|
| colorA | string | yes | – |
| colorB | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| formula | string | yes | – |
| ratio | number | yes | – |
No examples provided.
color_convert ~113
Converts a color between hex, rgb, hsl, and hsv. value's shape depends on from/to: a string for hex, an object ({r,g,b,a?} etc.) otherwise.
| Name | Type | Req | Description |
|---|---|---|---|
| from | string | yes | hex, rgb, hsl, or hsv |
| to | string | yes | hex, rgb, hsl, or hsv |
| value | – | yes | a hex string, or an {r,g,b,a?}/{h,s,l,a?}/{h,s,v,a?} object per from |
Structured output declared, but exposes no named fields.
No examples provided.
csv_from_json ~61
Converts JSON records to CSV text. columns is the explicit, ordered header — JSON object key order can't be relied on to infer it.
| Name | Type | Req | Description |
|---|---|---|---|
| columns | null|array | yes | – |
| delimiter | string | – | – |
| records | null|array | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
csv_parse ~54
Parses CSV text into rows of string fields (no type guessing). Ragged rows are tolerated — use csv_validate to detect them.
| Name | Type | Req | Description |
|---|---|---|---|
| delimiter | string | – | a single character, default ',' |
| text | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| rows | null|array | yes | – |
No examples provided.
csv_stats ~49
Parses CSV text (header row required) and reports per-column non-empty/empty value counts across the data rows. No numeric aggregation.
| Name | Type | Req | Description |
|---|---|---|---|
| delimiter | string | – | – |
| text | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| columnCount | integer | yes | – |
| columns | null|array | yes | – |
| rowCount | integer | yes | – |
No examples provided.
csv_to_json ~67
Converts CSV text to JSON: header=true (default) returns one object per data row keyed by the header row; header=false returns raw rows. Every value is a string.
| Name | Type | Req | Description |
|---|---|---|---|
| delimiter | string | – | – |
| header | boolean | – | default true |
| text | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
csv_validate ~44
Reports whether CSV text is structurally well-formed: every row has the same field count as the first.
| Name | Type | Req | Description |
|---|---|---|---|
| delimiter | string | – | – |
| text | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| error | string | – | – |
| fieldCount | integer | – | – |
| rowCount | integer | – | – |
| valid | boolean | yes | – |
No examples provided.
datemath_add ~108
Adds years/months/days to date. years/months are applied together with end-of-month clamping — e.g. 2026-01-31 + 1 month = 2026-02-28, not an overflowed 2026-03-03. days is then applied as plain calendar-day arithmetic.
| Name | Type | Req | Description |
|---|---|---|---|
| date | string | yes | YYYY-MM-DD |
| days | integer | – | – |
| months | integer | – | – |
| years | integer | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
datemath_age ~77
Age in whole years as of asOf (optional, defaults to the current UTC date). A Feb-29 birthDate is treated as falling on March 1 in a non-leap asOf year.
| Name | Type | Req | Description |
|---|---|---|---|
| asOf | string | – | YYYY-MM-DD, defaults to today |
| birthDate | string | yes | YYYY-MM-DD |
Structured output declared, but exposes no named fields.
No examples provided.
datemath_businessdays ~104
Counts days in [from, to] (inclusive on both ends) whose weekday is in weekdays (default mon-fri) and which aren't in holidays.
| Name | Type | Req | Description |
|---|---|---|---|
| from | string | yes | YYYY-MM-DD |
| holidays | null|array | – | YYYY-MM-DD dates to exclude |
| to | string | yes | YYYY-MM-DD |
| weekdays | null|array | – | sun/mon/tue/wed/thu/fri/sat, default mon-fri |
Structured output declared, but exposes no named fields.
No examples provided.
datemath_dayofweek ~50
Day of the week for date: both the weekday name and its ISO 8601 weekday number (1=Monday..7=Sunday).
| Name | Type | Req | Description |
|---|---|---|---|
| date | string | yes | YYYY-MM-DD |
| Name | Type | Req | Description |
|---|---|---|---|
| dayOfWeek | string | yes | – |
| isoWeekday | integer | yes | – |
No examples provided.
datemath_diff ~54
Day difference between two YYYY-MM-DD dates: to minus from, in whole days. Negative if to is before from.
| Name | Type | Req | Description |
|---|---|---|---|
| from | string | yes | YYYY-MM-DD |
| to | string | yes | YYYY-MM-DD |
Structured output declared, but exposes no named fields.
No examples provided.
datemath_leapyear ~31
Checks whether year is a leap year in the Gregorian calendar.
| Name | Type | Req | Description |
|---|---|---|---|
| year | integer | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
datetime_now ~85
Returns the actual current date/time — an LLM has a training cutoff and no live clock, so it can't know what time it actually is right now.
| Name | Type | Req | Description |
|---|---|---|---|
| format | string | – | iso8601 (default), unix, unixmilli, or rfc1123 |
| timezone | string | – | IANA timezone name, e.g. Europe/Warsaw; default UTC |
| Name | Type | Req | Description |
|---|---|---|---|
| format | string | yes | – |
| timezone | string | yes | – |
| value | string | yes | – |
No examples provided.
ean_validate ~86
Validates an 8-digit (EAN-8), 12-digit (UPC-A), 13-digit (EAN-13), or 14-digit (GTIN-14) barcode checksum: alternating weights 1 3 applied right-to-left, check digit is (10 - sum mod 10) mod 10.
| Name | Type | Req | Description |
|---|---|---|---|
| value | string | yes | identifier or value to check |
| Name | Type | Req | Description |
|---|---|---|---|
| reason | string | – | – |
| valid | boolean | yes | – |
No examples provided.
email_validate ~64
Checks value is a single, bare RFC 5322 email address — syntax only, not a deliverability check. user@localhost is valid (no TLD required). "Name <email>" display syntax is rejected.
| Name | Type | Req | Description |
|---|---|---|---|
| value | string | yes | identifier or value to check |
| Name | Type | Req | Description |
|---|---|---|---|
| reason | string | – | – |
| valid | boolean | yes | – |
No examples provided.
encode_decode ~113
Decodes rot13, base64, base64url, base32, hex, uuencode, urlcomponent, urlform, or html text back to the original. encoding in the result is "text" if the decoded bytes are valid UTF-8, or "base64" if they're binary.
| Name | Type | Req | Description |
|---|---|---|---|
| format | string | yes | rot13, base64, base64url, base32, hex, uuencode, urlcomponent, urlform, or html |
| input | string | yes | encoded text to decode |
| Name | Type | Req | Description |
|---|---|---|---|
| encoding | string | yes | – |
| output | string | yes | – |
No examples provided.
encode_encode ~126
Encodes plain UTF-8 text into rot13, base64, base64url, base32, hex, uuencode, urlcomponent (RFC 3986 percent-encoding, space -> %20), urlform (application/x-www-form-urlencoded, space -> +), or html (entity-escapes < > & ' "). Returns plain ASCII.
| Name | Type | Req | Description |
|---|---|---|---|
| format | string | yes | rot13, base64, base64url, base32, hex, uuencode, urlcomponent, urlform, or html |
| input | string | yes | plain UTF-8 text to encode |
Structured output declared, but exposes no named fields.
No examples provided.
hash_digest ~110
Computes a hash digest of input (decoded per encoding: "text" default, "base64", or "hex") using algo: md5, sha1, sha256, sha512, or crc32. Returns the digest as lowercase hex.
| Name | Type | Req | Description |
|---|---|---|---|
| algo | string | yes | md5, sha1, sha256, sha512, or crc32 |
| encoding | string | – | text (default), base64, or hex |
| input | string | yes | data to hash, encoded per encoding |
Structured output declared, but exposes no named fields.
No examples provided.
hash_hmac ~145
Computes an HMAC of input (decoded per encoding) using algo: md5, sha1, sha256, or sha512 (crc32 isn't offered — it's a checksum, not a cryptographic primitive HMAC composes with). key is used as its raw UTF-8 bytes, not decoded per encoding. Returns the MAC as lowercase hex.
| Name | Type | Req | Description |
|---|---|---|---|
| algo | string | yes | md5, sha1, sha256, or sha512 |
| encoding | string | – | text (default), base64, or hex |
| input | string | yes | data to authenticate, encoded per encoding |
| key | string | yes | secret key, used as raw UTF-8 bytes |
Structured output declared, but exposes no named fields.
No examples provided.
iban_validate ~66
Validates an IBAN's length for its issuing country (per the SWIFT IBAN registry) and its mod-97 checksum. Does not decompose the BBAN into a bank code/account number or resolve a BIC.
| Name | Type | Req | Description |
|---|---|---|---|
| value | string | yes | identifier or value to check |
| Name | Type | Req | Description |
|---|---|---|---|
| reason | string | – | – |
| valid | boolean | yes | – |
No examples provided.
isbn_validate ~77
Validates a 10- or 13-character ISBN. ISBN-10 uses weights 10..1 over 10 characters (last may be X, worth 10), sum mod 11 must be 0. ISBN-13 uses the same GTIN checksum as barcodes.
| Name | Type | Req | Description |
|---|---|---|---|
| value | string | yes | identifier or value to check |
| Name | Type | Req | Description |
|---|---|---|---|
| reason | string | – | – |
| valid | boolean | yes | – |
No examples provided.
jsonschema_validate ~69
Validates document against schema (JSON Schema draft-07 or 2020-12). Reports one specific violation per call, not an aggregated list.
| Name | Type | Req | Description |
|---|---|---|---|
| document | – | yes | the JSON value to validate against schema |
| schema | – | yes | a JSON Schema (draft-07 or 2020-12) |
| Name | Type | Req | Description |
|---|---|---|---|
| reason | string | – | – |
| valid | boolean | yes | – |
No examples provided.
luhn_validate ~49
Validates a numeric string against the Luhn (mod-10) checksum — payment card numbers, IMEI numbers, and similar identifiers.
| Name | Type | Req | Description |
|---|---|---|---|
| value | string | yes | identifier or value to check |
| Name | Type | Req | Description |
|---|---|---|---|
| reason | string | – | – |
| valid | boolean | yes | – |
No examples provided.
network_cidr_contains ~48
Reports whether a CIDR block contains an address. Different address families (IPv4 vs IPv6) never match.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | – |
| cidr | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
network_cidr_info ~90
Parses a CIDR block and reports its network address, address range, and address count. An address with host bits set (e.g. 10.14.32.17/21) is normalized to its network address in the result.
| Name | Type | Req | Description |
|---|---|---|---|
| cidr | string | yes | an IPv4 or IPv6 CIDR block, e.g. 10.14.32.17/21 |
| Name | Type | Req | Description |
|---|---|---|---|
| addresses | string | yes | – |
| cidr | string | yes | – |
| firstAddress | string | yes | – |
| lastAddress | string | yes | – |
| network | string | yes | – |
| prefixLength | integer | yes | – |
| version | integer | yes | – |
No examples provided.
network_cidr_overlaps ~39
Reports whether two CIDR blocks share any address.
| Name | Type | Req | Description |
|---|---|---|---|
| cidrA | string | yes | – |
| cidrB | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
nip_validate ~96
Validates the checksum of a 10-digit Polish tax identification number (NIP). Checksum uses weights 6 5 7 2 3 4 5 6 7 over the first 9 digits; sum mod 11 must equal the 10th digit. A sum mod 11 of 10 is itself invalid.
| Name | Type | Req | Description |
|---|---|---|---|
| value | string | yes | digits-only identifier to validate (no spaces or dashes) |
| Name | Type | Req | Description |
|---|---|---|---|
| reason | string | – | – |
| valid | boolean | yes | – |
No examples provided.
pesel_validate ~128
Validates the checksum of an 11-digit Polish national identification number (PESEL). Checksum uses weights 1 3 7 9 1 3 7 9 1 3 over the first 10 digits; control digit is (10 - sum mod 10) mod 10. On success also decodes the date of birth and sex embedded in the number; a checksum-valid number with an impossible calendar date (e.g. Feb 30) is still reported invalid.
| Name | Type | Req | Description |
|---|---|---|---|
| value | string | yes | digits-only identifier to validate (no spaces or dashes) |
| Name | Type | Req | Description |
|---|---|---|---|
| birthDate | string | – | – |
| reason | string | – | – |
| sex | string | – | – |
| valid | boolean | yes | – |
No examples provided.
pipe_run ~64
Runs a short ordered chain of existing apished operations in one call (same as POST /v1/pipe/run), passing one named field of each step's result into the next step's args. Stops at the first failing step.
| Name | Type | Req | Description |
|---|---|---|---|
| steps | null|array | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
random_int ~96
Generates cryptographically random integers in [min, max] (inclusive), using crypto/rand — an actual random value, not a guess. count defaults to 1, max 1000.
| Name | Type | Req | Description |
|---|---|---|---|
| count | integer | – | how many numbers to generate, 1-1000, default 1 |
| max | integer | yes | upper bound, inclusive; must be >= min |
| min | integer | yes | lower bound, inclusive |
| Name | Type | Req | Description |
|---|---|---|---|
| numbers | null|array | yes | – |
No examples provided.
regex_extract ~94
Extracts up to maxMatches non-overlapping regex matches from input, using Go's RE2-based regexp engine (linear-time, no backreferences/lookaround). Named groups (?P<name>...) are reported in namedGroups.
| Name | Type | Req | Description |
|---|---|---|---|
| input | string | yes | – |
| maxMatches | integer | – | stop after this many matches; omitted/<=0 means no limit |
| pattern | string | yes | an RE2 regex pattern |
| Name | Type | Req | Description |
|---|---|---|---|
| matches | null|array | yes | – |
No examples provided.
regex_match ~71
Tests input against pattern (Go's regexp package: RE2 syntax, not PCRE — no backreferences or lookaround; use inline flags like (?i) for case-insensitive matching). Returns the full match and captured groups.
| Name | Type | Req | Description |
|---|---|---|---|
| input | string | yes | – |
| pattern | string | yes | RE2 syntax |
| Name | Type | Req | Description |
|---|---|---|---|
| groups | null|array | – | – |
| match | string | – | – |
| matches | boolean | yes | – |
No examples provided.
regex_replace ~64
Replaces every regex match of pattern in input with replacement, which may reference capture groups as $1, $name, etc. (Go's Regexp.Expand syntax).
| Name | Type | Req | Description |
|---|---|---|---|
| input | string | yes | – |
| pattern | string | yes | – |
| replacement | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
regex_split ~60
Splits input around regex matches of pattern, returning at most limit substrings (the last holds the unsplit remainder). limit<=0 means no limit.
| Name | Type | Req | Description |
|---|---|---|---|
| input | string | yes | – |
| limit | integer | – | – |
| pattern | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| parts | null|array | yes | – |
No examples provided.
regon_validate ~170
Validates the checksum of a 9- or 14-digit Polish business registry number (REGON). 9-digit: weights 8 9 2 3 4 5 6 7 over the first 8 digits, sum mod 11 (10 mapped to 0) must equal the 9th digit. 14-digit: the first 9 digits must themselves be a valid 9-digit REGON, and weights 2 4 8 5 0 9 7 3 6 1 2 4 8 over the first 13 digits (sum mod 11, 10 mapped to 0) must equal the 14th digit.
| Name | Type | Req | Description |
|---|---|---|---|
| value | string | yes | digits-only identifier to validate (no spaces or dashes) |
| Name | Type | Req | Description |
|---|---|---|---|
| reason | string | – | – |
| valid | boolean | yes | – |
No examples provided.
rpncalc_eval ~120
Evaluates a Reverse Polish Notation (postfix) expression: whitespace-separated tokens, each a number or an operator/function that pops its operands off a stack and pushes the result. Supports arithmetic, exponentiation/modulo, roots, trigonometry, logarithms, rounding, bitwise ops, and constants (pi, e, phi). Always returns the decimal result — for hex/bin/oct rendering, convert the returned number yourself.
| Name | Type | Req | Description |
|---|---|---|---|
| expr | string | yes | space-separated RPN expression, e.g. "3 4 + 2 *" |
Structured output declared, but exposes no named fields.
No examples provided.
swiftbic_validate ~82
Structural format validation only for a SWIFT/BIC code: 8 or 11 characters (4 letters bank code + 2 letters country code + 2 alphanumeric location code + optional 3 alphanumeric branch code). The country code is not cross-checked against ISO 3166-1.
| Name | Type | Req | Description |
|---|---|---|---|
| value | string | yes | identifier or value to check |
| Name | Type | Req | Description |
|---|---|---|---|
| reason | string | – | – |
| valid | boolean | yes | – |
No examples provided.
text_charat ~43
Returns the 0-indexed character (rune) at index in text.
| Name | Type | Req | Description |
|---|---|---|---|
| index | integer | yes | 0-indexed |
| text | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
text_count ~44
Counts non-overlapping occurrences of substring in text (rune-safe, not byte-based).
| Name | Type | Req | Description |
|---|---|---|---|
| substring | string | yes | must be non-empty |
| text | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
text_palindrome ~81
Checks whether text reads the same forwards and backwards. ignoreCase/ignoreNonAlnum default false (strict, literal comparison); set both true for phrase-style palindromes like "A man, a plan, a canal: Panama".
| Name | Type | Req | Description |
|---|---|---|---|
| ignoreCase | boolean | – | – |
| ignoreNonAlnum | boolean | – | – |
| text | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
text_reverse ~32
Reverses text by Unicode code point (rune), not grapheme cluster.
| Name | Type | Req | Description |
|---|---|---|---|
| text | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
text_sort ~70
Sorts text's characters or words alphabetically. by: "chars" (default, sorts runes, no separator) or "words" (splits on whitespace, rejoins with a single space).
| Name | Type | Req | Description |
|---|---|---|---|
| by | string | – | chars (default) or words |
| text | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
text_stats ~78
Descriptive statistics for text: rune/byte/word/line counts, a unique-rune count, a letters/digits/spaces/punctuation/other breakdown, an exact per-character frequency table, and word-length min/max/average plus the actual shortest/longest word (ties resolve to the first occurrence).
| Name | Type | Req | Description |
|---|---|---|---|
| text | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| bytes | integer | yes | – |
| charFrequency | object | yes | – |
| charTypes | object | yes | – |
| lines | integer | yes | – |
| runes | integer | yes | – |
| uniqueRunes | integer | yes | – |
| wordLengths | object | yes | – |
| words | integer | yes | – |
No examples provided.
text_wordcount ~24
Counts whitespace-delimited words in text.
| Name | Type | Req | Description |
|---|---|---|---|
| text | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
tokens_count ~112
Counts tokens under an OpenAI-compatible (tiktoken) encoding. Provide exactly one of model (e.g. "gpt-4o") or encoding ("o200k_base" or "cl100k_base"). No Claude/Anthropic tokenizer.
| Name | Type | Req | Description |
|---|---|---|---|
| encoding | string | – | o200k_base or cl100k_base; exactly one of model/encoding |
| model | string | – | e.g. gpt-4o; exactly one of model/encoding |
| text | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| encoding | string | – | – |
| tokens | integer | yes | – |
No examples provided.
units_convert_datasize ~97
Converts a data-size value (decimal string) between bit, Kbit, Mbit, Gbit, Tbit (SI bits), B, KB, MB, GB, TB, PB (SI bytes), and KiB, MiB, GiB, TiB, PiB (IEC bytes). Always exact.
| Name | Type | Req | Description |
|---|---|---|---|
| from | string | yes | – |
| to | string | yes | – |
| value | string | yes | decimal string |
Structured output declared, but exposes no named fields.
No examples provided.
units_convert_temperature ~68
Converts a temperature value (decimal string) between C, F, and K. Offset-aware, not a bare multiplier.
| Name | Type | Req | Description |
|---|---|---|---|
| from | string | yes | C, F, or K |
| to | string | yes | C, F, or K |
| value | string | yes | decimal string |
Structured output declared, but exposes no named fields.
No examples provided.
url_validate ~48
Checks value is a well-formed absolute URL (has both a scheme and a host) — syntax only, not a reachability check.
| Name | Type | Req | Description |
|---|---|---|---|
| value | string | yes | identifier or value to check |
| Name | Type | Req | Description |
|---|---|---|---|
| reason | string | – | – |
| valid | boolean | yes | – |
No examples provided.
uuid_generate ~48
Generates count (default 1, max 1000) random version-4 UUIDs from crypto/rand-backed entropy.
| Name | Type | Req | Description |
|---|---|---|---|
| count | integer | – | default 1, max 1000 |
| Name | Type | Req | Description |
|---|---|---|---|
| values | null|array | yes | – |
No examples provided.
What is the APIShed MCP server?
APIShed is an MCP server listed in the public MCP registry as com.apished/apished. Validates PESEL/NIP/REGON/IBAN/Luhn/ISBN/EAN/BIC/VAT; RPN, dates, hash, tokens, random, encode, time. This page covers its hosted endpoint (https://apished.com/mcp).
Is the APIShed MCP server safe to use?
APIShed scores 77 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the APIShed MCP server expose?
APIShed exposes 52 tools: color_contrast, color_convert, csv_from_json, csv_parse, csv_stats, and 47 more. Their descriptions and schemas cost roughly 3,939 tokens of context every time the server is loaded.
Does the APIShed MCP server require authentication?
No. We connected to APIShed without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the APIShed MCP server still maintained?
APIShed is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.