Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Musicboxmelodies

REMOTE · API.MUSICBOXMELODIES.COM · SCANNED SEP 30

Compose, save and print music box tunes for 15, 20 and 30-note music boxes.

61 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security46
Transport & Reachability100
Schema Quality & AI Usability81
  • 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 2732 tokens (~151/item across 18 items; 17 tools + 1 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management3
  • Stability observed for 1 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage95
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 81% of tool parameters carry a description.Partial
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • An AI judge read all 19 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a current MCP spec version (2026-07-28).Pass
Install

How do I install the Musicboxmelodies MCP server?

Musicboxmelodies is a hosted endpoint at https://api.musicboxmelodies.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · api.musicboxmelodies.com

# add to Claude Code
claude mcp add --transport http com-musicboxmelodies-music-box 'https://api.musicboxmelodies.com/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "com-musicboxmelodies-music-box": {
      "url": "https://api.musicboxmelodies.com/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "com-musicboxmelodies-music-box": {
      "type": "http",
      "url": "https://api.musicboxmelodies.com/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.com-musicboxmelodies-music-box]
url = "https://api.musicboxmelodies.com/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-musicboxmelodies-music-box": {
      "type": "remote",
      "url": "https://api.musicboxmelodies.com/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add com-musicboxmelodies-music-box --url 'https://api.musicboxmelodies.com/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  com-musicboxmelodies-music-box:
    url: "https://api.musicboxmelodies.com/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "com-musicboxmelodies-music-box": {
      "Transport": "http",
      "Url": "https://api.musicboxmelodies.com/mcp"
    }
  }
}
# add to Vellum
assistant mcp add com-musicboxmelodies-music-box -t streamable-http -u 'https://api.musicboxmelodies.com/mcp'
// mcp.json
{
  "mcpServers": {
    "com-musicboxmelodies-music-box": {
      "type": "http",
      "url": "https://api.musicboxmelodies.com/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 30 Sept 26 0
    • Stability: unverified → 0.03 ▲ functional
  • 29 Sept 26 61

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 30 Sept 2026 · Probed https://api.musicboxmelodies.com/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=api.musicboxmelodies.com CN=YR1,O=Let's Encrypt,C=US 29 Sept 2026 28 Dec 2026 RSA 2048 SHA256-RSA 59853bf64f353ada883f18a808c6e71b16b
SANs: api.musicboxmelodies.com
CN=YR1,O=Let's Encrypt,C=US (CA) CN=Root YR,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 RSA 2048 SHA256-RSA a20253f15f2691c05dc1ce13b9bcca4e
CN=Root YR,O=ISRG,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 RSA 4096 SHA256-RSA f24b6d17f9d9ad7cb1c9fea78782699f

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of api.musicboxmelodies.com. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
musicboxmelodies.com. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://api.musicboxmelodies.com/mcp Verified 200
http (plaintext) http://api.musicboxmelodies.com/mcp Inconclusive 405
MCP tools · 17 exposed · ~2,543 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
add_version ~213

Saves a melody as the version of an existing song for one box (a song can have one version per box: 15, 20, 30 notes or freestyle). Replaces that box's version if it exists. Works on the signed-in person's songs, or on a song saved without an account if you pass its claim_token. The melody must have no errors.

NameTypeReqDescription
boxstringyesMusic box type: "15", "20", "30" (notes) or "freestyle" (digital only). See list_music_boxes.
bpmnumberyesTempo in beats per minute (30-300).
claim_tokenstring–Only for songs saved without an account.
illegal_threshold_ticksinteger–Minimum gap between two identical notes, in ticks (default 384 = 2 beats).
notesarrayyesNotes in any order, at most 2000. Only onsets matter: music boxes have no note durations.
song_idstringyes–
NameTypeReqDescription
boxstringyes–
composer_urlstring––
replacedbooleanyes–
song_idstringyes–
validationobjectyes–

No examples provided.

create_song ~346

Saves a melody as a new private song. The melody must have no errors (run validate_melody or fit_melody_to_box first); warnings such as notes repeated too quickly are saved and marked, as in the composer. If the person is signed in, the song goes to their account and you get a link to open it in the composer. Without an account the song is saved anonymously and you get a claim link: give it to the person so they can keep it (valid 30 days). Set save_to_my_account to true to ask the person to sign in first (apps that cannot sign in mid-conversation should save without an account and give the claim link instead). Limits: 5 songs a day without an account, 15 a day with one.

NameTypeReqDescription
artiststringyesOriginal artist or composer ("Traditional" if unknown).
boxstringyesMusic box type: "15", "20", "30" (notes) or "freestyle" (digital only). See list_music_boxes.
bpmnumberyesTempo in beats per minute (30-300).
descriptionstring–Optional notes about the arrangement.
illegal_threshold_ticksinteger–Minimum gap between two identical notes, in ticks (default 384 = 2 beats).
namestringyesSong title.
notesarrayyesNotes in any order, at most 2000. Only onsets matter: music boxes have no note durations.
save_to_my_accountboolean–True to save it in the person's account; they will be asked to sign in if they are not.
tagsarray––
NameTypeReqDescription
boxstringyes–
claim_expires_atstring––
claim_tokenstring––
claim_urlstring––
composer_urlstring––
privatebooleanyes–
quotaobjectyes–
saved_to_accountbooleanyes–
song_idstringyes–
validationobjectyes–

No examples provided.

delete_song ~103

Permanently deletes one of the signed-in person's songs (all its box versions), or a song you saved without an account (pass its claim_token). This cannot be undone: tell the person which song will be deleted, ask them to confirm, then call again with confirmed: true.

NameTypeReqDescription
claim_tokenstring–Only for songs saved without an account.
confirmedboolean–true only after the person confirmed the deletion.
song_idstringyes–
NameTypeReqDescription
namestringyes–
song_idstringyes–
statusstringyes–

No examples provided.

export_song ~176

Creates a download link for one box version of a song: an MP3, a MIDI file or a printable strip PDF to cut and punch for a hand-crank music box ("pdf_long" is one continuous strip, "pdf_a4"/"pdf_letter" are sliced to fit the page). Works on the person's songs and on public tunes. Requires signing in, like exporting in the composer.

NameTypeReqDescription
boxstring–Which version. Defaults to the preferred one.
formatstringyes–
gridstring–Grid printed on the strip (PDF only). Default standard.
show_titleboolean–Print the song title on the strip (PDF only). Default true.
song_idstringyes–
strip_shapestring–Shape of the strip ends (PDF only). Default capped.
NameTypeReqDescription
boxstringyes–
download_urlstringyes–
formatstringyes–
song_idstringyes–

No examples provided.

fit_melody_to_box ~253

Adjusts a melody so it can be played on a music box and lists every change. Strategies: "transpose" (shift the whole melody to the key that fits best), "nearest_note" (move each unplayable note to the closest playable one), "transpose_then_nearest" (default: both). Optionally snaps notes to a grid. Returns the new melody and its validation.

NameTypeReqDescription
boxstringyesMusic box type: "15", "20", "30" (notes) or "freestyle" (digital only). See list_music_boxes.
bpmnumberyesTempo in beats per minute (30-300).
illegal_threshold_ticksinteger–Minimum gap between two identical notes, in ticks (default 384 = 2 beats).
notesarrayyesNotes in any order, at most 2000. Only onsets matter: music boxes have no note durations.
quantize_beatsnumber–Snap every note to this grid in beats (e.g. 0.5 = eighth notes).
strategystring––
target_boxstring–Box to fit into. Defaults to the melody's box.
NameTypeReqDescription
changesarrayyes–
melodyobjectyes–
semitonesintegeryes–
summarystringyes–
validationobjectyes–

No examples provided.

get_order_status ~60

Shows the signed-in person's orders (newest first) or one order: its status, items, price and, once delivered, the links to the finished files. Requires signing in.

NameTypeReqDescription
order_idstring–Omit to list recent orders.
NameTypeReqDescription
ordersarrayyes–

No examples provided.

get_product_options ~90

Lists the variations (with prices in US dollars) and the details needed to order a custom music box melody or a custom strip design. Call it before prepare_order.

NameTypeReqDescription
productstringyes"custom_melody" (a song arranged in music box style, delivered as audio) or "custom_strip_design" (printable strips for a 15 or 30-note hand-crank box).
NameTypeReqDescription
fieldsarrayyes–
namestringyes–
productstringyes–
variationsarrayyes–

No examples provided.

get_song ~141

Gets a music box tune with its notes in the melody format (the same one validate_melody accepts), for one box version. Works for public tunes, for the signed-in person's own songs, and for a song this agent saved anonymously (pass its claim_token). Use search_songs or list_my_songs to find song ids.

NameTypeReqDescription
boxstring–Which version to return. Defaults to the version the arranger marked as preferred.
claim_tokenstring–Only for songs saved without an account: the claim_token create_song returned.
song_idstringyesSong id from search_songs, list_my_songs or create_song.
NameTypeReqDescription
arranged_bystringyes–
artiststringyes–
available_boxesarrayyes–
composer_urlstring––
descriptionstring––
melodyobjectyes–
namestringyes–
privatebooleanyes–
song_idstringyes–
statsobjectyes–
tagsarrayyes–
urlstringyes–

No examples provided.

import_midi ~85

Converts a MIDI file (base64, up to 512 KB) into the melody format and validates it for a box, so you can fit, edit and save it. Drums are ignored. Saves nothing.

NameTypeReqDescription
boxstring–Box to validate against. Default "30".
midi_base64stringyesThe .mid file, base64-encoded.
NameTypeReqDescription
melodyobjectyes–
namestringyes–
notes_in_fileintegeryes–
skipped_percussion_tracksintegeryes–
validationobjectyes–

No examples provided.

list_music_boxes ~38

Lists the music box types a melody can be written for, with their exact playable notes and rules. Call this before composing or validating a melody.

Input schema present but exposes no named parameters.

NameTypeReqDescription
boxesarrayyes–
default_min_repeat_beatsnumberyes–
ticks_per_beatintegeryes–

No examples provided.

list_my_songs ~51

Lists the signed-in person's songs on Musicboxmelodies, newest first, including private ones. Requires signing in.

NameTypeReqDescription
pageinteger––
page_sizeinteger–Default 20.
NameTypeReqDescription
pageintegeryes–
pagesintegeryes–
songsarrayyes–
totalintegeryes–

No examples provided.

list_products ~52

Lists what Musicboxmelodies sells, with current prices in US dollars and delivery times: custom music box melodies, custom printable strip designs and PRO composer accounts. Orders are placed and paid by the person on the website.

Input schema present but exposes no named parameters.

NameTypeReqDescription
currencystringyes–
productsarrayyes–

No examples provided.

prepare_order ~268

Prepares a custom melody or strip design order with all its details and returns a link to the Musicboxmelodies cart, where the person reviews it, adds photos if needed, applies discount codes and pays with PayPal. Nothing is charged here. The link works for 7 days. Confirm the song, the variation and the price with the person before calling it. The price is calculated by the site.

NameTypeReqDescription
existing_tuneboolean–Strip designs only: the song is already on our YouTube channel (25% off).
note_count––Strip designs only: notes of the person's music box.
productstringyes"custom_melody" (a song arranged in music box style, delivered as audio) or "custom_strip_design" (printable strips for a 15 or 30-note hand-crank box).
reference_linkstring–YouTube or other link to the version the person wants.
song_artiststringyes–
song_namestringyes–
themestring–Strip designs only.
timestringyesPart of the song to convert, e.g. "0:00 - 1:30" or "whole song".
variation_idstringyesFrom get_product_options.
NameTypeReqDescription
cart_urlstringyes–
expires_atstringyes–
price_usdnumberyes–
summarystringyes–

No examples provided.

render_audio ~242

Creates an MP3 of a melody (before or without saving it) or of a saved song, so you and the person can hear it. Pass either song_id or a melody (box, bpm, notes). Sounds: "synth" (free, the site's default sound) or "music_box" (real music box recordings for the box; PRO accounts only). Saved songs use the sound their author chose unless you pass one. Up to 5 minutes; 20 new audios a day without an account and 60 with one (the same melody again is free).

NameTypeReqDescription
boxstring–With song_id: which version. Otherwise the melody's box.
bpmnumber–Melody tempo (required without song_id).
claim_tokenstring––
illegal_threshold_ticksinteger–Minimum gap between two identical notes, in ticks (default 384 = 2 beats).
notesarray–Melody notes (required without song_id).
song_idstring–A saved song (public, the person's own, or one you saved without an account with its claim_token).
soundstring––
NameTypeReqDescription
audio_urlstringyes–
duration_secondsnumberyes–
notestring––
soundstringyes–

No examples provided.

search_songs ~128

Searches the public catalog of music box tunes made by the Musicboxmelodies community. Search by song name, artist or arranger; optionally only tunes that have a version for one box type. Returns at most 20 per page.

NameTypeReqDescription
boxstring–Only tunes with a version for this box.
pageinteger–Page number, starting at 1.
page_sizeinteger–Results per page, 1-20 (default 10).
querystring–Words to search in the song name, artist or arranger. Omit to list tunes.
NameTypeReqDescription
pageintegeryes–
pagesintegeryes–
songsarrayyes–
totalintegeryes–

No examples provided.

set_song_visibility ~96

Makes one of the signed-in person's songs public (anyone can find and play it on musicboxmelodies.com) or private. Only make a song public when the person asked for it: ask them to confirm, then call again with confirmed: true.

NameTypeReqDescription
confirmedboolean–Required to make a song public: true only after the person confirmed.
song_idstringyes–
visibilitystringyes–
NameTypeReqDescription
song_idstringyes–
statusstringyes–
urlstringyes–
visibilitystringyes–

No examples provided.

validate_melody ~201

Checks whether a melody can be played on a music box: notes outside the box, same note repeated too fast, off-grid notes, tempo and length. Every issue names the note and how to fix it. Saves nothing. Call it before offering a melody to the person.

NameTypeReqDescription
boxstringyesMusic box type: "15", "20", "30" (notes) or "freestyle" (digital only). See list_music_boxes.
bpmnumberyesTempo in beats per minute (30-300).
illegal_threshold_ticksinteger–Minimum gap between two identical notes, in ticks (default 384 = 2 beats).
notesarrayyesNotes in any order, at most 2000. Only onsets matter: music boxes have no note durations.
snap_beatsnumber–Optional grid in beats (e.g. 0.5) to warn about notes off that grid.
NameTypeReqDescription
issuesarrayyes–
okbooleanyes–
statsobjectyes–

No examples provided.

Common questions

What is the Musicboxmelodies MCP server?

Musicboxmelodies is an MCP server listed in the public MCP registry as com.musicboxmelodies/music-box. Compose, save and print music box tunes for 15, 20 and 30-note music boxes. This page covers its hosted endpoint (https://api.musicboxmelodies.com/mcp).

Is the Musicboxmelodies MCP server safe to use?

Musicboxmelodies scores 61 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Musicboxmelodies MCP server expose?

Musicboxmelodies exposes 17 tools: list_music_boxes, search_songs, get_song, validate_melody, fit_melody_to_box, and 12 more. Their descriptions and schemas cost roughly 2,543 tokens of context every time the server is loaded.

Does the Musicboxmelodies MCP server require authentication?

No. We connected to Musicboxmelodies without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the Musicboxmelodies MCP server still maintained?

Musicboxmelodies is still listed as active in the MCP registry. We last reached this channel on 30 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.