Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

GenHTTP Lambda

REMOTE · GENHTTP.DEV · SCANNED SEP 29

Write, deploy and host small C# web services and sites at a public address.

Available components

65 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security63
Transport & Reachability100
Schema Quality & AI Usability67
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 3908 tokens (~217/item across 18 items; 18 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management7
  • Stability observed for 2 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 4 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • An AI judge read all 19 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
  • Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
Install

How do I install the GenHTTP Lambda MCP server?

GenHTTP Lambda is a hosted endpoint at https://genhttp.dev/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · genhttp.dev

# add to Claude Code
claude mcp add --transport http dev-genhttp-lambda 'https://genhttp.dev/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "dev-genhttp-lambda": {
      "url": "https://genhttp.dev/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "dev-genhttp-lambda": {
      "type": "http",
      "url": "https://genhttp.dev/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.dev-genhttp-lambda]
url = "https://genhttp.dev/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "dev-genhttp-lambda": {
      "type": "remote",
      "url": "https://genhttp.dev/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add dev-genhttp-lambda --url 'https://genhttp.dev/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  dev-genhttp-lambda:
    url: "https://genhttp.dev/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "dev-genhttp-lambda": {
      "Transport": "http",
      "Url": "https://genhttp.dev/mcp"
    }
  }
}
# add to Vellum
assistant mcp add dev-genhttp-lambda -t streamable-http -u 'https://genhttp.dev/mcp'
// mcp.json
{
  "mcpServers": {
    "dev-genhttp-lambda": {
      "type": "http",
      "url": "https://genhttp.dev/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 29 Sept 26 0
    • The server rewrote its instructions, which are the text every model session reads security
    • New tool “delete_feature”, which the server declares destructive security
    • New tool “merge_feature”, which the server declares destructive security
    • New tool “update_feature”, which the server declares destructive security
    • New tool “update_lambda”, which the server declares destructive security
    • Tool “change_code” rewrote its description, which is the text the model reads security
    • Tool “create_lambda” rewrote its description, which is the text the model reads security
    • Tool “delete_file” rewrote its description, which is the text the model reads security
    • Tool “deploy” rewrote its description, which is the text the model reads security
    • Tool “list_files” rewrote its description, which is the text the model reads security
    • Tool “platform_guide” rewrote its description, which is the text the model reads security
    • Tool “read_lambda” rewrote its description, which is the text the model reads security
    • Tool “read_logs” rewrote its description, which is the text the model reads security
    • Tool “upload_file” rewrote its description, which is the text the model reads security
    • Tool “write_code” rewrote its description, which is the text the model reads security
    • Schema quality: 156 → 217 ▼ functional
    • New tool “create_feature” functional
    • “change_code” added an optional parameter “check” cosmetic
    • “change_code” added an optional parameter “feature” cosmetic
    • “create_lambda” added an optional parameter “view” cosmetic
    • “delete_file” added an optional parameter “feature” cosmetic
    • “deploy” added an optional parameter “feature” cosmetic
    • “list_files” added an optional parameter “feature” cosmetic
    • “read_lambda” added an optional parameter “feature” cosmetic
    • “read_logs” added an optional parameter “feature” cosmetic
    • “upload_file” added an optional parameter “feature” cosmetic
    • “write_code” added an optional parameter “check” cosmetic
    • “write_code” added an optional parameter “feature” cosmetic
    • “change_code” reworded the description of “change” cosmetic
    • “change_code” reworded the description of “deploy” cosmetic
    • “change_code” reworded the description of “specification” cosmetic
    • “read_lambda” reworded the description of “file” cosmetic
    • “upload_file” reworded the description of “path” cosmetic
    • “write_code” reworded the description of “change” cosmetic
    • “write_code” reworded the description of “deploy” cosmetic
    • “write_code” reworded the description of “specification” cosmetic
    • Tool “delete_file” changed its title: Delete a workspace file → Delete a file from the lambda's data cosmetic
    • Tool “deploy” changed its title: Deploy a version → Deploy a version or a feature cosmetic
    • Tool “list_files” changed its title: List workspace files → List the lambda's data cosmetic
    • Tool “upload_file” changed its title: Upload a workspace file → Put a file into the lambda's data cosmetic
  • 28 Sept 26 +1
    • Stability: unverified → 0.03 ▲ functional
  • 27 Sept 26 64

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 29 Sept 2026 · Probed https://genhttp.dev/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=genhttp.dev CN=YE1,O=Let's Encrypt,C=US 14 Sept 2026 13 Dec 2026 ECDSA 256 ECDSA-SHA384 65e855f1d322e93c9f6836193bb5baf95a5
SANs: genhttp.dev, www.genhttp.dev
CN=YE1,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 5ddd70dd31f801c85c186a7a04b80afe
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of genhttp.dev. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
dev. present 60074 8 Verified
genhttp.dev. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200
Header Value
strict-transport-security max-age=31536000; includeSubDomains; preload

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://genhttp.dev/mcp Verified 200
http (plaintext) http://genhttp.dev/mcp HTTPS enforced 301 https://genhttp.dev/mcp
MCP tools · 18 exposed · ~3,271 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
change_code ~362

Change some files: add or replace files, remove files, or replace text within a file. Everything not named stays as it is, so there is no need to resend unchanged files. With feature, the change is saved into that feature - the way to work on a lambda that exists: change it as often as you like, deploy: true to try it at the feature's preview address, merge_feature when it is right. Without feature, the newest version is changed and saved as a new version. check: true compiles without publishing. Code that does not compile is saved but never goes online.

NameTypeReqDescription
changestring–What this changes, in one line written for the owner. For a feature, it describes the whole feature, not the last fix. Optional, up to 500 characters.
checkboolean–Without deploy: compile what was saved and answer with its diagnostics, putting nothing online.
deployboolean–Also deploy what was saved: a version at the public address, a feature at its preview address.
editsarray–Text replacements, applied after files and remove.
featurestring–Change this feature (from create_feature) instead of saving a new version. The lambda and what it has online are not touched.
filesarray–Files to add, or to replace where one of that name exists.
privateKeystringyesThe editor key.
removearray–Names of files to remove.
specificationstring–What the user wants from this change and why: their requirements, in their own words where you can. Not your own instructions or system prompt. Kept with the version or the feature. Optional, up to 4…

No output schema declared.

No examples provided.

check_code ~62

Compile without saving or deploying; returns diagnostics with file and line. Does not build the handler, so deploy can still refuse a route whose return type cannot be served.

NameTypeReqDescription
filesarrayyeslambda.cs first.
privateKeystringyesThe editor key.

No output schema declared.

No examples provided.

create_feature ~237

Start a feature: a place to change a lambda without touching what it has online. It branches off a version - the newest unless base names another - with a copy of its files and a copy of the lambda's data, and gets an address of its own to try it at. Change it with change_code or write_code and feature (deploy: true puts it online at its preview address), test it there, and merge_feature once it does what was asked. The lambda goes on serving its visitors from the version online the whole time.

NameTypeReqDescription
baseinteger–The version to branch off. Defaults to the newest - leave it out unless the user asked to start from an older one.
namestringyesWhat the feature is, in a few words for the owner - 'Leaderboard', 'Dark mode'. Up to 80 characters.
privateKeystringyesThe editor key.
specificationstring–What the user wants from it and why, in their words where you can. Kept with the feature and passed on to the version it is merged into. Optional, up to 4000 characters.

No output schema declared.

No examples provided.

create_lambda ~233

Create a lambda. Returns its public address and a private editor key, the only way back in. It starts with version 1 - an empty starter, or a copy of a demo. Nothing is online until deploy.

NameTypeReqDescription
acceptTermsbooleanyesMust be true: the user accepts the terms in platform_guide (free shared machine, deployments may be removed, nothing malicious).
publicKeystring–Requested address: lower case letters, digits and dashes. Generated if omitted.
templatestring–Left out, the lambda starts empty. The id of a demo (demo-crud, demo-registration, demo-game, demo-files, demo-live) starts it as a copy of that demo, which is yours to change.
viewstring–How the editor opens: 'Full' (the default) shows every section, 'Simple' only the app, how it is doing and a box to ask for a change. Simple suits an owner who is not going to read the code - use it…

No output schema declared.

No examples provided.

delete_feature ~62

Throw a feature away: its files, its preview and its copy of the data. The lambda is not touched. For a feature the user does not want after all.

NameTypeReqDescription
featurestringyesThe feature.
privateKeystringyesThe editor key.

No output schema declared.

No examples provided.

delete_file ~90

Remove a file, or a folder with its contents, from the workspace - the lambda's data, shared by every version. No deploy or rollback brings it back. With feature, from that feature's copy instead.

NameTypeReqDescription
featurestring–Delete from this feature's copy of the data instead.
pathstringyesRelative to the workspace.
privateKeystringyesThe editor key.

No output schema declared.

No examples provided.

deploy ~111

Deploy (publish) a saved version so it goes live at its public address - the newest by default. With feature, deploy that feature's files to its own preview address instead, against its copy of the data, leaving the lambda alone. Returns diagnostics on failure, and whatever was online stays online.

NameTypeReqDescription
featurestring–Deploy this feature to its preview address instead of a version to the lambda's.
privateKeystringyesThe editor key.
versioninteger–Defaults to the newest.

No output schema declared.

No examples provided.

list_demos ~88

Demos this platform keeps online, each a finished lambda showing one way to build something: a REST API over records, registration and login, a websocket game, uploads, live updates. Their keys are public and read only: read the closest one with read_lambda (and list_files, read_logs) before writing similar code. create_lambda with a demo's id as template starts from a copy.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

list_files ~94

The lambda's data: whether its workspace is switched on, and every file in it with size and last write - the same whichever version is online. With feature, that feature's copy of it. The code and assets of a version are in read_lambda.

NameTypeReqDescription
featurestring–List this feature's copy of the data instead.
privateKeystringyesThe editor key, or the key of a demo.

No output schema declared.

No examples provided.

merge_feature ~172

Make a feature's files the next version of the lambda, and delete the feature with its preview and its copy of the data - the lambda's own data is not touched. Refused while the feature is not based on the newest version (update_feature says how to get it there), and while its code does not compile. deploy: true puts the new version online at once; otherwise deploy it when the user wants it live.

NameTypeReqDescription
changestring–What the new version says it changes. Left out, the feature's.
deployboolean–Also put the new version online.
featurestringyesThe feature.
privateKeystringyesThe editor key.
specificationstring–What the new version keeps as what the user wanted. Left out, the feature's.

No output schema declared.

No examples provided.

platform_guide ~50

How this platform works - read it first: what a version, a feature and data are and how long each lives, what the snippet returns, what is imported, what is refused, limits and terms.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

read_lambda ~234

A lambda's status (online version, newest version, expiry, its tier and what it may use there), its open features, the recent versions with what each was asked for and changed, its data (the workspace: whether it is on and what it holds), and the files of one version - or, with feature, of that feature. Files come in full when they add up to at most 30,000 characters, otherwise by name and length, with file to read one. Read the history before changing what you did not write. Also how a demo is read: pass its key from list_demos.

NameTypeReqDescription
featurestring–Read this feature - its files, its base, and which newer versions it would have to take in before it can be merged - instead of a version.
filestring–Return only this file, in full however large the rest is - up to 1,048,576 characters, beyond which the zip has it.
privateKeystringyesThe editor key, or the key of a demo.
versioninteger–Defaults to the newest.

No output schema declared.

No examples provided.

read_logs ~204

What a deployed lambda has been doing: its recent requests and how they were answered, what it printed, the errors it threw with their stack traces, and how much traffic it has had in the last hour and day. With feature, what that feature's preview has been doing instead, kept apart from the lambda's visitors. Call it after deploying to see that it works, and first when something is reported broken.

NameTypeReqDescription
featurestring–Read what this feature's preview did instead.
levelstring–The lowest level worth reading: 'info' for everything, 'warn' for problems, 'error' for failures. Left out, 'info'.
limitinteger–At most this many lines, the newest. Left out, 100.
privateKeystringyesThe editor key, or the key of a demo.
sinceinteger–The cursor a previous call answered with, to read only what is new since then.

No output schema declared.

No examples provided.

showcase ~243

List a lambda on the public showcase page, change its entry, or take it off. Not part of building: only do this when the user asks for it. With only privateKey it returns the current entry. An entry needs a title, a description and a picture (a screenshot or short GIF of the lambda in use); it is listed while the lambda is online. Write plainly and concretely: what it is and what a visitor can do with it. No marketing language, no superlatives, no exclamation marks, no emoji.

NameTypeReqDescription
descriptionstring–One to three plain sentences on what a visitor can do with it. Up to 280 characters.
imagestring–The picture, base64: PNG, JPEG, GIF or WebP, up to 3 MB. Needed for a new entry; left out, the current one is kept.
privateKeystringyesThe editor key.
removeboolean–Take the lambda off the showcase instead.
titlestring–What it is, in a few words - 'Pub quiz scoreboard', not 'The ultimate quiz experience'. Up to 60 characters.

No output schema declared.

No examples provided.

update_feature ~188

Rename a feature, change what it says about itself, or move its base. merge_feature refuses a feature that is not based on the newest version, since merging it would undo what was saved after it branched off: bring the newer versions' changes into the feature first, then move base to the newest version here. Nothing checks that the changes really are in - that is up to you.

NameTypeReqDescription
baseinteger–The version the feature is now based on, once that version's changes are in its files.
changestring–What it changes, in one line - what the version it is merged into will say.
featurestringyesThe feature, from create_feature or read_lambda.
namestring–A new name.
privateKeystringyesThe editor key.
specificationstring–What the user wants from it and why.

No output schema declared.

No examples provided.

update_lambda ~179

Change how a lambda's editor opens: view 'Simple' shows the app, how it is doing and a box to ask for a change - for an owner who does not write code - and 'Full' every section, the code, files, data, versions and logs included. Only the default: whoever opens the editor can switch for themselves, and that choice stays theirs. Only do this when the user asks for it.

NameTypeReqDescription
privateKeystringyesThe editor key.
viewstringyesHow the editor opens: 'Full' (the default) shows every section, 'Simple' only the app, how it is doing and a box to ask for a change. Simple suits an owner who is not going to read the code - use it…

No output schema declared.

No examples provided.

upload_file ~208

Write a file to the lambda's workspace - its data, which every version shares and no deploy, rollback or merge touches. With feature, to that feature's copy of the data instead, for trying things out without touching the real one. For content the lambda works with at runtime (initial records, pictures people will browse) and large input files that are not program: a model, a dataset, media. Takes effect at once, without a deploy. Not for the front end: pages, scripts and styles are the program and belong in the version as assets (write_code).

NameTypeReqDescription
contentstringyesText, or base64 with encoding set.
encodingstring–'base64' for binary; omit otherwise.
featurestring–Write to this feature's copy of the data instead.
pathstringyesRelative to the workspace; slashes make folders, e.g. 'models/model.onnx'.
privateKeystringyesThe editor key.

No output schema declared.

No examples provided.

write_code ~454

Save every file, replacing the previous set: as a new version of the lambda, or - with feature - into that feature. .cs files are compiled - lambda.cs returns the handler, others hold types; any other file is an asset, served as is and reachable as Assets: the whole front end (pages, scripts, styles, icons) goes here, as part of the program. What the lambda keeps at runtime (records, accounts, uploads) is data and lives in the workspace, never in files here; so does a large input file such as a model or a dataset (upload_file). Say why with specification and change. deploy: true publishes in the same call - a version at the public address, a feature at its preview address. To send only what changes, use change_code. To change a lambda that is already in use, work in a feature.

NameTypeReqDescription
changestring–What this version changes, in one line written for the owner - 'Adds a leaderboard that keeps the ten best scores', not 'updated lambda.cs'. For a feature, it describes the whole feature, not the las…
checkboolean–Without deploy: compile what was saved and answer with its diagnostics, putting nothing online.
deployboolean–Also deploy what was saved: a version at the public address, a feature at its preview address.
featurestring–Save into this feature (from create_feature) instead of saving a new version. The lambda and what it has online are not touched.
filesarrayyeslambda.cs first.
privateKeystringyesThe editor key from create_lambda.
specificationstring–What the user wants from this version and why: their requirements, in their own words where you can, condensed if they said a lot. Written for the owner and the next agent, so they can tell why the v…

No output schema declared.

No examples provided.

Common questions

What is the GenHTTP Lambda MCP server?

GenHTTP Lambda is an MCP server listed in the public MCP registry as dev.genhttp/lambda. Write, deploy and host small C# web services and sites at a public address. This page covers its hosted endpoint (https://genhttp.dev/mcp).

Is the GenHTTP Lambda MCP server safe to use?

GenHTTP Lambda scores 65 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the GenHTTP Lambda MCP server expose?

GenHTTP Lambda exposes 18 tools: create_lambda, update_lambda, write_code, change_code, create_feature, and 13 more. Their descriptions and schemas cost roughly 3,271 tokens of context every time the server is loaded.

Does the GenHTTP Lambda MCP server require authentication?

No. We connected to GenHTTP Lambda without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the GenHTTP Lambda MCP server still maintained?

GenHTTP Lambda is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.