Musicboxmelodies
REMOTE · API.MUSICBOXMELODIES.COM · SCANNED SEP 30
Compose, save and print music box tunes for 15, 20 and 30-note music boxes.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security46
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (add_version). See how to fix → View diagnostics → Fail
- HTTPS enforcement could not be verified: the plaintext port answered with HTTP 405, which proves neither a plaintext path nor enforcement. View diagnostics → Unverified
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability81
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2732 tokens (~151/item across 18 items; 17 tools + 1 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management3
- Stability observed for 1 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage95
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 81% of tool parameters carry a description.Partial
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 19 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the Musicboxmelodies MCP server?
Musicboxmelodies is a hosted endpoint at https://api.musicboxmelodies.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · api.musicboxmelodies.com
claude mcp add --transport http com-musicboxmelodies-music-box 'https://api.musicboxmelodies.com/mcp'
{
"mcpServers": {
"com-musicboxmelodies-music-box": {
"url": "https://api.musicboxmelodies.com/mcp"
}
}
} {
"servers": {
"com-musicboxmelodies-music-box": {
"type": "http",
"url": "https://api.musicboxmelodies.com/mcp"
}
}
} [mcp_servers.com-musicboxmelodies-music-box] url = "https://api.musicboxmelodies.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-musicboxmelodies-music-box": {
"type": "remote",
"url": "https://api.musicboxmelodies.com/mcp",
"enabled": true
}
}
} openclaw mcp add com-musicboxmelodies-music-box --url 'https://api.musicboxmelodies.com/mcp' --transport streamable-http
mcp_servers:
com-musicboxmelodies-music-box:
url: "https://api.musicboxmelodies.com/mcp" {
"McpServers": {
"com-musicboxmelodies-music-box": {
"Transport": "http",
"Url": "https://api.musicboxmelodies.com/mcp"
}
}
} assistant mcp add com-musicboxmelodies-music-box -t streamable-http -u 'https://api.musicboxmelodies.com/mcp'
{
"mcpServers": {
"com-musicboxmelodies-music-box": {
"type": "http",
"url": "https://api.musicboxmelodies.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 30 Sept 26 0
- Stability: unverified → 0.03 ▲ functional
- 29 Sept 26 61
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 30 Sept 2026 · Probed https://api.musicboxmelodies.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=api.musicboxmelodies.com | CN=YR1,O=Let's Encrypt,C=US | 29 Sept 2026 | 28 Dec 2026 | RSA 2048 | SHA256-RSA | 59853bf64f353ada883f18a808c6e71b16b |
| SANs: api.musicboxmelodies.com | ||||||
| CN=YR1,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | a20253f15f2691c05dc1ce13b9bcca4e |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of api.musicboxmelodies.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| musicboxmelodies.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://api.musicboxmelodies.com/mcp | Verified | 200 | |
| http (plaintext) | http://api.musicboxmelodies.com/mcp | Inconclusive | 405 |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
add_version Add or replace a box version of a song ~213
Saves a melody as the version of an existing song for one box (a song can have one version per box: 15, 20, 30 notes or freestyle). Replaces that box's version if it exists. Works on the signed-in person's songs, or on a song saved without an account if you pass its claim_token. The melody must have no errors.
| Name | Type | Req | Description |
|---|---|---|---|
| box | string | yes | Music box type: "15", "20", "30" (notes) or "freestyle" (digital only). See list_music_boxes. |
| bpm | number | yes | Tempo in beats per minute (30-300). |
| claim_token | string | – | Only for songs saved without an account. |
| illegal_threshold_ticks | integer | – | Minimum gap between two identical notes, in ticks (default 384 = 2 beats). |
| notes | array | yes | Notes in any order, at most 2000. Only onsets matter: music boxes have no note durations. |
| song_id | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| box | string | yes | – |
| composer_url | string | – | – |
| replaced | boolean | yes | – |
| song_id | string | yes | – |
| validation | object | yes | – |
No examples provided.
create_song Save a new music box song ~346
Saves a melody as a new private song. The melody must have no errors (run validate_melody or fit_melody_to_box first); warnings such as notes repeated too quickly are saved and marked, as in the composer. If the person is signed in, the song goes to their account and you get a link to open it in the composer. Without an account the song is saved anonymously and you get a claim link: give it to the person so they can keep it (valid 30 days). Set save_to_my_account to true to ask the person to sign in first (apps that cannot sign in mid-conversation should save without an account and give the claim link instead). Limits: 5 songs a day without an account, 15 a day with one.
| Name | Type | Req | Description |
|---|---|---|---|
| artist | string | yes | Original artist or composer ("Traditional" if unknown). |
| box | string | yes | Music box type: "15", "20", "30" (notes) or "freestyle" (digital only). See list_music_boxes. |
| bpm | number | yes | Tempo in beats per minute (30-300). |
| description | string | – | Optional notes about the arrangement. |
| illegal_threshold_ticks | integer | – | Minimum gap between two identical notes, in ticks (default 384 = 2 beats). |
| name | string | yes | Song title. |
| notes | array | yes | Notes in any order, at most 2000. Only onsets matter: music boxes have no note durations. |
| save_to_my_account | boolean | – | True to save it in the person's account; they will be asked to sign in if they are not. |
| tags | array | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| box | string | yes | – |
| claim_expires_at | string | – | – |
| claim_token | string | – | – |
| claim_url | string | – | – |
| composer_url | string | – | – |
| private | boolean | yes | – |
| quota | object | yes | – |
| saved_to_account | boolean | yes | – |
| song_id | string | yes | – |
| validation | object | yes | – |
No examples provided.
delete_song Delete a song ~103
Permanently deletes one of the signed-in person's songs (all its box versions), or a song you saved without an account (pass its claim_token). This cannot be undone: tell the person which song will be deleted, ask them to confirm, then call again with confirmed: true.
| Name | Type | Req | Description |
|---|---|---|---|
| claim_token | string | – | Only for songs saved without an account. |
| confirmed | boolean | – | true only after the person confirmed the deletion. |
| song_id | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | – |
| song_id | string | yes | – |
| status | string | yes | – |
No examples provided.
export_song Export a song as MIDI or a printable strip ~176
Creates a download link for one box version of a song: an MP3, a MIDI file or a printable strip PDF to cut and punch for a hand-crank music box ("pdf_long" is one continuous strip, "pdf_a4"/"pdf_letter" are sliced to fit the page). Works on the person's songs and on public tunes. Requires signing in, like exporting in the composer.
| Name | Type | Req | Description |
|---|---|---|---|
| box | string | – | Which version. Defaults to the preferred one. |
| format | string | yes | – |
| grid | string | – | Grid printed on the strip (PDF only). Default standard. |
| show_title | boolean | – | Print the song title on the strip (PDF only). Default true. |
| song_id | string | yes | – |
| strip_shape | string | – | Shape of the strip ends (PDF only). Default capped. |
| Name | Type | Req | Description |
|---|---|---|---|
| box | string | yes | – |
| download_url | string | yes | – |
| format | string | yes | – |
| song_id | string | yes | – |
No examples provided.
fit_melody_to_box Fit a melody to a music box ~253
Adjusts a melody so it can be played on a music box and lists every change. Strategies: "transpose" (shift the whole melody to the key that fits best), "nearest_note" (move each unplayable note to the closest playable one), "transpose_then_nearest" (default: both). Optionally snaps notes to a grid. Returns the new melody and its validation.
| Name | Type | Req | Description |
|---|---|---|---|
| box | string | yes | Music box type: "15", "20", "30" (notes) or "freestyle" (digital only). See list_music_boxes. |
| bpm | number | yes | Tempo in beats per minute (30-300). |
| illegal_threshold_ticks | integer | – | Minimum gap between two identical notes, in ticks (default 384 = 2 beats). |
| notes | array | yes | Notes in any order, at most 2000. Only onsets matter: music boxes have no note durations. |
| quantize_beats | number | – | Snap every note to this grid in beats (e.g. 0.5 = eighth notes). |
| strategy | string | – | – |
| target_box | string | – | Box to fit into. Defaults to the melody's box. |
| Name | Type | Req | Description |
|---|---|---|---|
| changes | array | yes | – |
| melody | object | yes | – |
| semitones | integer | yes | – |
| summary | string | yes | – |
| validation | object | yes | – |
No examples provided.
get_order_status Check my orders ~60
Shows the signed-in person's orders (newest first) or one order: its status, items, price and, once delivered, the links to the finished files. Requires signing in.
| Name | Type | Req | Description |
|---|---|---|---|
| order_id | string | – | Omit to list recent orders. |
| Name | Type | Req | Description |
|---|---|---|---|
| orders | array | yes | – |
No examples provided.
get_product_options Get the options of a product ~90
Lists the variations (with prices in US dollars) and the details needed to order a custom music box melody or a custom strip design. Call it before prepare_order.
| Name | Type | Req | Description |
|---|---|---|---|
| product | string | yes | "custom_melody" (a song arranged in music box style, delivered as audio) or "custom_strip_design" (printable strips for a 15 or 30-note hand-crank box). |
| Name | Type | Req | Description |
|---|---|---|---|
| fields | array | yes | – |
| name | string | yes | – |
| product | string | yes | – |
| variations | array | yes | – |
No examples provided.
get_song Get a music box tune ~141
Gets a music box tune with its notes in the melody format (the same one validate_melody accepts), for one box version. Works for public tunes, for the signed-in person's own songs, and for a song this agent saved anonymously (pass its claim_token). Use search_songs or list_my_songs to find song ids.
| Name | Type | Req | Description |
|---|---|---|---|
| box | string | – | Which version to return. Defaults to the version the arranger marked as preferred. |
| claim_token | string | – | Only for songs saved without an account: the claim_token create_song returned. |
| song_id | string | yes | Song id from search_songs, list_my_songs or create_song. |
| Name | Type | Req | Description |
|---|---|---|---|
| arranged_by | string | yes | – |
| artist | string | yes | – |
| available_boxes | array | yes | – |
| composer_url | string | – | – |
| description | string | – | – |
| melody | object | yes | – |
| name | string | yes | – |
| private | boolean | yes | – |
| song_id | string | yes | – |
| stats | object | yes | – |
| tags | array | yes | – |
| url | string | yes | – |
No examples provided.
import_midi Read a MIDI file as a melody ~85
Converts a MIDI file (base64, up to 512 KB) into the melody format and validates it for a box, so you can fit, edit and save it. Drums are ignored. Saves nothing.
| Name | Type | Req | Description |
|---|---|---|---|
| box | string | – | Box to validate against. Default "30". |
| midi_base64 | string | yes | The .mid file, base64-encoded. |
| Name | Type | Req | Description |
|---|---|---|---|
| melody | object | yes | – |
| name | string | yes | – |
| notes_in_file | integer | yes | – |
| skipped_percussion_tracks | integer | yes | – |
| validation | object | yes | – |
No examples provided.
list_music_boxes List music boxes ~38
Lists the music box types a melody can be written for, with their exact playable notes and rules. Call this before composing or validating a melody.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| boxes | array | yes | – |
| default_min_repeat_beats | number | yes | – |
| ticks_per_beat | integer | yes | – |
No examples provided.
list_my_songs List my songs ~51
Lists the signed-in person's songs on Musicboxmelodies, newest first, including private ones. Requires signing in.
| Name | Type | Req | Description |
|---|---|---|---|
| page | integer | – | – |
| page_size | integer | – | Default 20. |
| Name | Type | Req | Description |
|---|---|---|---|
| page | integer | yes | – |
| pages | integer | yes | – |
| songs | array | yes | – |
| total | integer | yes | – |
No examples provided.
list_products List products ~52
Lists what Musicboxmelodies sells, with current prices in US dollars and delivery times: custom music box melodies, custom printable strip designs and PRO composer accounts. Orders are placed and paid by the person on the website.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| currency | string | yes | – |
| products | array | yes | – |
No examples provided.
prepare_order Prepare an order for the person to pay ~268
Prepares a custom melody or strip design order with all its details and returns a link to the Musicboxmelodies cart, where the person reviews it, adds photos if needed, applies discount codes and pays with PayPal. Nothing is charged here. The link works for 7 days. Confirm the song, the variation and the price with the person before calling it. The price is calculated by the site.
| Name | Type | Req | Description |
|---|---|---|---|
| existing_tune | boolean | – | Strip designs only: the song is already on our YouTube channel (25% off). |
| note_count | – | – | Strip designs only: notes of the person's music box. |
| product | string | yes | "custom_melody" (a song arranged in music box style, delivered as audio) or "custom_strip_design" (printable strips for a 15 or 30-note hand-crank box). |
| reference_link | string | – | YouTube or other link to the version the person wants. |
| song_artist | string | yes | – |
| song_name | string | yes | – |
| theme | string | – | Strip designs only. |
| time | string | yes | Part of the song to convert, e.g. "0:00 - 1:30" or "whole song". |
| variation_id | string | yes | From get_product_options. |
| Name | Type | Req | Description |
|---|---|---|---|
| cart_url | string | yes | – |
| expires_at | string | yes | – |
| price_usd | number | yes | – |
| summary | string | yes | – |
No examples provided.
render_audio Listen to a melody or song ~242
Creates an MP3 of a melody (before or without saving it) or of a saved song, so you and the person can hear it. Pass either song_id or a melody (box, bpm, notes). Sounds: "synth" (free, the site's default sound) or "music_box" (real music box recordings for the box; PRO accounts only). Saved songs use the sound their author chose unless you pass one. Up to 5 minutes; 20 new audios a day without an account and 60 with one (the same melody again is free).
| Name | Type | Req | Description |
|---|---|---|---|
| box | string | – | With song_id: which version. Otherwise the melody's box. |
| bpm | number | – | Melody tempo (required without song_id). |
| claim_token | string | – | – |
| illegal_threshold_ticks | integer | – | Minimum gap between two identical notes, in ticks (default 384 = 2 beats). |
| notes | array | – | Melody notes (required without song_id). |
| song_id | string | – | A saved song (public, the person's own, or one you saved without an account with its claim_token). |
| sound | string | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| audio_url | string | yes | – |
| duration_seconds | number | yes | – |
| note | string | – | – |
| sound | string | yes | – |
No examples provided.
search_songs Search music box tunes ~128
Searches the public catalog of music box tunes made by the Musicboxmelodies community. Search by song name, artist or arranger; optionally only tunes that have a version for one box type. Returns at most 20 per page.
| Name | Type | Req | Description |
|---|---|---|---|
| box | string | – | Only tunes with a version for this box. |
| page | integer | – | Page number, starting at 1. |
| page_size | integer | – | Results per page, 1-20 (default 10). |
| query | string | – | Words to search in the song name, artist or arranger. Omit to list tunes. |
| Name | Type | Req | Description |
|---|---|---|---|
| page | integer | yes | – |
| pages | integer | yes | – |
| songs | array | yes | – |
| total | integer | yes | – |
No examples provided.
set_song_visibility Make a song public or private ~96
Makes one of the signed-in person's songs public (anyone can find and play it on musicboxmelodies.com) or private. Only make a song public when the person asked for it: ask them to confirm, then call again with confirmed: true.
| Name | Type | Req | Description |
|---|---|---|---|
| confirmed | boolean | – | Required to make a song public: true only after the person confirmed. |
| song_id | string | yes | – |
| visibility | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| song_id | string | yes | – |
| status | string | yes | – |
| url | string | yes | – |
| visibility | string | yes | – |
No examples provided.
validate_melody Validate a melody for a music box ~201
Checks whether a melody can be played on a music box: notes outside the box, same note repeated too fast, off-grid notes, tempo and length. Every issue names the note and how to fix it. Saves nothing. Call it before offering a melody to the person.
| Name | Type | Req | Description |
|---|---|---|---|
| box | string | yes | Music box type: "15", "20", "30" (notes) or "freestyle" (digital only). See list_music_boxes. |
| bpm | number | yes | Tempo in beats per minute (30-300). |
| illegal_threshold_ticks | integer | – | Minimum gap between two identical notes, in ticks (default 384 = 2 beats). |
| notes | array | yes | Notes in any order, at most 2000. Only onsets matter: music boxes have no note durations. |
| snap_beats | number | – | Optional grid in beats (e.g. 0.5) to warn about notes off that grid. |
| Name | Type | Req | Description |
|---|---|---|---|
| issues | array | yes | – |
| ok | boolean | yes | – |
| stats | object | yes | – |
No examples provided.
What is the Musicboxmelodies MCP server?
Musicboxmelodies is an MCP server listed in the public MCP registry as com.musicboxmelodies/music-box. Compose, save and print music box tunes for 15, 20 and 30-note music boxes. This page covers its hosted endpoint (https://api.musicboxmelodies.com/mcp).
Is the Musicboxmelodies MCP server safe to use?
Musicboxmelodies scores 61 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Musicboxmelodies MCP server expose?
Musicboxmelodies exposes 17 tools: list_music_boxes, search_songs, get_song, validate_melody, fit_melody_to_box, and 12 more. Their descriptions and schemas cost roughly 2,543 tokens of context every time the server is loaded.
Does the Musicboxmelodies MCP server require authentication?
No. We connected to Musicboxmelodies without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Musicboxmelodies MCP server still maintained?
Musicboxmelodies is still listed as active in the MCP registry. We last reached this channel on 30 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.