# Musicboxmelodies (remote · api.musicboxmelodies.com)

Compose, save and print music box tunes for 15, 20 and 30-note music boxes.

- Trust score: 61/100 (medium)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-30

## Components

- remote · `api.musicboxmelodies.com`: 61/100 (this document), [markdown](https://verifymcp.io/servers/com-musicboxmelodies-music-box/api.md), [page](https://verifymcp.io/servers/com-musicboxmelodies-music-box/api)

## Channel facts

- Endpoint: `https://api.musicboxmelodies.com/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.2.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-30.

- **Endpoint Security**: 46/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (add_version).
  - HTTPS enforcement could not be verified: the plaintext port answered with HTTP 405, which proves neither a plaintext path nor enforcement.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 81/100
  - 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 2732 tokens (~151/item across 18 items; 17 tools + 1 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 3/100
  - Stability observed for 1 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 95/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 81% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.
  - An AI judge read all 19 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a current MCP spec version (2026-07-28).

## Install

### How do I install the Musicboxmelodies MCP server?

Musicboxmelodies is a hosted endpoint at https://api.musicboxmelodies.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http com-musicboxmelodies-music-box 'https://api.musicboxmelodies.com/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "com-musicboxmelodies-music-box": {
      "url": "https://api.musicboxmelodies.com/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "com-musicboxmelodies-music-box": {
      "type": "http",
      "url": "https://api.musicboxmelodies.com/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.com-musicboxmelodies-music-box]
url = "https://api.musicboxmelodies.com/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-musicboxmelodies-music-box": {
      "type": "remote",
      "url": "https://api.musicboxmelodies.com/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add com-musicboxmelodies-music-box --url 'https://api.musicboxmelodies.com/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  com-musicboxmelodies-music-box:
    url: "https://api.musicboxmelodies.com/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "com-musicboxmelodies-music-box": {
      "Transport": "http",
      "Url": "https://api.musicboxmelodies.com/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add com-musicboxmelodies-music-box -t streamable-http -u 'https://api.musicboxmelodies.com/mcp'
```

### Other

```json
{
  "mcpServers": {
    "com-musicboxmelodies-music-box": {
      "type": "http",
      "url": "https://api.musicboxmelodies.com/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-30 (score 61, 0)

- [functional improvement] Stability: unverified → 0.03

### 2026-09-29 (score 61)

First indexed and scored.

## MCP tools (17)

### `list_music_boxes` (~38 tokens)

List music boxes

Lists the music box types a melody can be written for, with their exact playable notes and rules. Call this before composing or validating a melody.

Output parameters:

- `boxes` (array)
- `default_min_repeat_beats` (number)
- `ticks_per_beat` (integer)

### `search_songs` (~128 tokens)

Search music box tunes

Searches the public catalog of music box tunes made by the Musicboxmelodies community. Search by song name, artist or arranger; optionally only tunes that have a version for one box type. Returns at most 20 per page.

Input parameters:

- `box` (string): Only tunes with a version for this box.
- `page` (integer): Page number, starting at 1.
- `page_size` (integer): Results per page, 1-20 (default 10).
- `query` (string): Words to search in the song name, artist or arranger. Omit to list tunes.

Output parameters:

- `page` (integer)
- `pages` (integer)
- `songs` (array)
- `total` (integer)

### `get_song` (~141 tokens)

Get a music box tune

Gets a music box tune with its notes in the melody format (the same one validate_melody accepts), for one box version. Works for public tunes, for the signed-in person's own songs, and for a song this agent saved anonymously (pass its claim_token). Use search_songs or list_my_songs to find song ids.

Input parameters:

- `box` (string): Which version to return. Defaults to the version the arranger marked as preferred.
- `claim_token` (string): Only for songs saved without an account: the claim_token create_song returned.
- `song_id` (string, required): Song id from search_songs, list_my_songs or create_song.

Output parameters:

- `arranged_by` (string)
- `artist` (string)
- `available_boxes` (array)
- `composer_url` (string)
- `description` (string)
- `melody` (object)
- `name` (string)
- `private` (boolean)
- `song_id` (string)
- `stats` (object)
- `tags` (array)
- `url` (string)

### `validate_melody` (~201 tokens)

Validate a melody for a music box

Checks whether a melody can be played on a music box: notes outside the box, same note repeated too fast, off-grid notes, tempo and length. Every issue names the note and how to fix it. Saves nothing. Call it before offering a melody to the person.

Input parameters:

- `box` (string, required): Music box type: "15", "20", "30" (notes) or "freestyle" (digital only). See list_music_boxes.
- `bpm` (number, required): Tempo in beats per minute (30-300).
- `illegal_threshold_ticks` (integer): Minimum gap between two identical notes, in ticks (default 384 = 2 beats).
- `notes` (array, required): Notes in any order, at most 2000. Only onsets matter: music boxes have no note durations.
- `snap_beats` (number): Optional grid in beats (e.g. 0.5) to warn about notes off that grid.

Output parameters:

- `issues` (array)
- `ok` (boolean)
- `stats` (object)

### `fit_melody_to_box` (~253 tokens)

Fit a melody to a music box

Adjusts a melody so it can be played on a music box and lists every change. Strategies: "transpose" (shift the whole melody to the key that fits best), "nearest_note" (move each unplayable note to the closest playable one), "transpose_then_nearest" (default: both). Optionally snaps notes to a grid. Returns the new melody and its validation.

Input parameters:

- `box` (string, required): Music box type: "15", "20", "30" (notes) or "freestyle" (digital only). See list_music_boxes.
- `bpm` (number, required): Tempo in beats per minute (30-300).
- `illegal_threshold_ticks` (integer): Minimum gap between two identical notes, in ticks (default 384 = 2 beats).
- `notes` (array, required): Notes in any order, at most 2000. Only onsets matter: music boxes have no note durations.
- `quantize_beats` (number): Snap every note to this grid in beats (e.g. 0.5 = eighth notes).
- `strategy` (string)
- `target_box` (string): Box to fit into. Defaults to the melody's box.

Output parameters:

- `changes` (array)
- `melody` (object)
- `semitones` (integer)
- `summary` (string)
- `validation` (object)

### `list_products` (~52 tokens)

List products

Lists what Musicboxmelodies sells, with current prices in US dollars and delivery times: custom music box melodies, custom printable strip designs and PRO composer accounts. Orders are placed and paid by the person on the website.

Output parameters:

- `currency` (string)
- `products` (array)

### `create_song` (~346 tokens)

Save a new music box song

Saves a melody as a new private song. The melody must have no errors (run validate_melody or fit_melody_to_box first); warnings such as notes repeated too quickly are saved and marked, as in the composer. If the person is signed in, the song goes to their account and you get a link to open it in the composer. Without an account the song is saved anonymously and you get a claim link: give it to the person so they can keep it (valid 30 days). Set save_to_my_account to true to ask the person to sign in first (apps that cannot sign in mid-conversation should save without an account and give the claim link instead). Limits: 5 songs a day without an account, 15 a day with one.

Input parameters:

- `artist` (string, required): Original artist or composer ("Traditional" if unknown).
- `box` (string, required): Music box type: "15", "20", "30" (notes) or "freestyle" (digital only). See list_music_boxes.
- `bpm` (number, required): Tempo in beats per minute (30-300).
- `description` (string): Optional notes about the arrangement.
- `illegal_threshold_ticks` (integer): Minimum gap between two identical notes, in ticks (default 384 = 2 beats).
- `name` (string, required): Song title.
- `notes` (array, required): Notes in any order, at most 2000. Only onsets matter: music boxes have no note durations.
- `save_to_my_account` (boolean): True to save it in the person's account; they will be asked to sign in if they are not.
- `tags` (array)

Output parameters:

- `box` (string)
- `claim_expires_at` (string)
- `claim_token` (string)
- `claim_url` (string)
- `composer_url` (string)
- `private` (boolean)
- `quota` (object)
- `saved_to_account` (boolean)
- `song_id` (string)
- `validation` (object)

### `add_version` (~213 tokens)

Add or replace a box version of a song

Saves a melody as the version of an existing song for one box (a song can have one version per box: 15, 20, 30 notes or freestyle). Replaces that box's version if it exists. Works on the signed-in person's songs, or on a song saved without an account if you pass its claim_token. The melody must have no errors.

Input parameters:

- `box` (string, required): Music box type: "15", "20", "30" (notes) or "freestyle" (digital only). See list_music_boxes.
- `bpm` (number, required): Tempo in beats per minute (30-300).
- `claim_token` (string): Only for songs saved without an account.
- `illegal_threshold_ticks` (integer): Minimum gap between two identical notes, in ticks (default 384 = 2 beats).
- `notes` (array, required): Notes in any order, at most 2000. Only onsets matter: music boxes have no note durations.
- `song_id` (string, required)

Output parameters:

- `box` (string)
- `composer_url` (string)
- `replaced` (boolean)
- `song_id` (string)
- `validation` (object)

### `list_my_songs` (~51 tokens)

List my songs

Lists the signed-in person's songs on Musicboxmelodies, newest first, including private ones. Requires signing in.

Input parameters:

- `page` (integer)
- `page_size` (integer): Default 20.

Output parameters:

- `page` (integer)
- `pages` (integer)
- `songs` (array)
- `total` (integer)

### `set_song_visibility` (~96 tokens)

Make a song public or private

Makes one of the signed-in person's songs public (anyone can find and play it on musicboxmelodies.com) or private. Only make a song public when the person asked for it: ask them to confirm, then call again with confirmed: true.

Input parameters:

- `confirmed` (boolean): Required to make a song public: true only after the person confirmed.
- `song_id` (string, required)
- `visibility` (string, required)

Output parameters:

- `song_id` (string)
- `status` (string)
- `url` (string)
- `visibility` (string)

### `delete_song` (~103 tokens)

Delete a song

Permanently deletes one of the signed-in person's songs (all its box versions), or a song you saved without an account (pass its claim_token). This cannot be undone: tell the person which song will be deleted, ask them to confirm, then call again with confirmed: true.

Input parameters:

- `claim_token` (string): Only for songs saved without an account.
- `confirmed` (boolean): true only after the person confirmed the deletion.
- `song_id` (string, required)

Output parameters:

- `name` (string)
- `song_id` (string)
- `status` (string)

### `export_song` (~176 tokens)

Export a song as MIDI or a printable strip

Creates a download link for one box version of a song: an MP3, a MIDI file or a printable strip PDF to cut and punch for a hand-crank music box ("pdf_long" is one continuous strip, "pdf_a4"/"pdf_letter" are sliced to fit the page). Works on the person's songs and on public tunes. Requires signing in, like exporting in the composer.

Input parameters:

- `box` (string): Which version. Defaults to the preferred one.
- `format` (string, required)
- `grid` (string): Grid printed on the strip (PDF only). Default standard.
- `show_title` (boolean): Print the song title on the strip (PDF only). Default true.
- `song_id` (string, required)
- `strip_shape` (string): Shape of the strip ends (PDF only). Default capped.

Output parameters:

- `box` (string)
- `download_url` (string)
- `format` (string)
- `song_id` (string)

### `render_audio` (~242 tokens)

Listen to a melody or song

Creates an MP3 of a melody (before or without saving it) or of a saved song, so you and the person can hear it. Pass either song_id or a melody (box, bpm, notes). Sounds: "synth" (free, the site's default sound) or "music_box" (real music box recordings for the box; PRO accounts only). Saved songs use the sound their author chose unless you pass one. Up to 5 minutes; 20 new audios a day without an account and 60 with one (the same melody again is free).

Input parameters:

- `box` (string): With song_id: which version. Otherwise the melody's box.
- `bpm` (number): Melody tempo (required without song_id).
- `claim_token` (string)
- `illegal_threshold_ticks` (integer): Minimum gap between two identical notes, in ticks (default 384 = 2 beats).
- `notes` (array): Melody notes (required without song_id).
- `song_id` (string): A saved song (public, the person's own, or one you saved without an account with its claim_token).
- `sound` (string)

Output parameters:

- `audio_url` (string)
- `duration_seconds` (number)
- `note` (string)
- `sound` (string)

### `import_midi` (~85 tokens)

Read a MIDI file as a melody

Converts a MIDI file (base64, up to 512 KB) into the melody format and validates it for a box, so you can fit, edit and save it. Drums are ignored. Saves nothing.

Input parameters:

- `box` (string): Box to validate against. Default "30".
- `midi_base64` (string, required): The .mid file, base64-encoded.

Output parameters:

- `melody` (object)
- `name` (string)
- `notes_in_file` (integer)
- `skipped_percussion_tracks` (integer)
- `validation` (object)

### `get_product_options` (~90 tokens)

Get the options of a product

Lists the variations (with prices in US dollars) and the details needed to order a custom music box melody or a custom strip design. Call it before prepare_order.

Input parameters:

- `product` (string, required): "custom_melody" (a song arranged in music box style, delivered as audio) or "custom_strip_design" (printable strips for a 15 or 30-note hand-crank box).

Output parameters:

- `fields` (array)
- `name` (string)
- `product` (string)
- `variations` (array)

### `prepare_order` (~268 tokens)

Prepare an order for the person to pay

Prepares a custom melody or strip design order with all its details and returns a link to the Musicboxmelodies cart, where the person reviews it, adds photos if needed, applies discount codes and pays with PayPal. Nothing is charged here. The link works for 7 days. Confirm the song, the variation and the price with the person before calling it. The price is calculated by the site.

Input parameters:

- `existing_tune` (boolean): Strip designs only: the song is already on our YouTube channel (25% off).
- `note_count`: Strip designs only: notes of the person's music box.
- `product` (string, required): "custom_melody" (a song arranged in music box style, delivered as audio) or "custom_strip_design" (printable strips for a 15 or 30-note hand-crank box).
- `reference_link` (string): YouTube or other link to the version the person wants.
- `song_artist` (string, required)
- `song_name` (string, required)
- `theme` (string): Strip designs only.
- `time` (string, required): Part of the song to convert, e.g. "0:00 - 1:30" or "whole song".
- `variation_id` (string, required): From get_product_options.

Output parameters:

- `cart_url` (string)
- `expires_at` (string)
- `price_usd` (number)
- `summary` (string)

### `get_order_status` (~60 tokens)

Check my orders

Shows the signed-in person's orders (newest first) or one order: its status, items, price and, once delivered, the links to the finished files. Requires signing in.

Input parameters:

- `order_id` (string): Omit to list recent orders.

Output parameters:

- `orders` (array)

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/com-musicboxmelodies-music-box/api#diagnostics

## Score history

- 2026-09-30: 61
- 2026-09-29: 61

## Common questions

### What is the Musicboxmelodies MCP server?

Musicboxmelodies is an MCP server listed in the public MCP registry as com.musicboxmelodies/music-box. Compose, save and print music box tunes for 15, 20 and 30-note music boxes. This page covers its hosted endpoint (https://api.musicboxmelodies.com/mcp).

### Is the Musicboxmelodies MCP server safe to use?

Musicboxmelodies scores 61 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Musicboxmelodies MCP server expose?

Musicboxmelodies exposes 17 tools: list_music_boxes, search_songs, get_song, validate_melody, fit_melody_to_box, and 12 more. Their descriptions and schemas cost roughly 2,543 tokens of context every time the server is loaded.

### Does the Musicboxmelodies MCP server require authentication?

No. We connected to Musicboxmelodies without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the Musicboxmelodies MCP server still maintained?

Musicboxmelodies is still listed as active in the MCP registry. We last reached this channel on 30 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://api.musicboxmelodies.com/mcp
- Website: https://musicboxmelodies.com/ai
- Changelog RSS feed: https://verifymcp.io/servers/com-musicboxmelodies-music-box/api.xml
- Changelog JSON feed: https://verifymcp.io/servers/com-musicboxmelodies-music-box/api.json
- HTML version of this page: https://verifymcp.io/servers/com-musicboxmelodies-music-box/api
