# GenHTTP Lambda (remote · genhttp.dev)

Write, deploy and host small C# web services and sites at a public address.

- Trust score: 65/100 (medium)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-29

## Components

- remote · `genhttp.dev`: 65/100 (this document), [markdown](https://verifymcp.io/servers/dev-genhttp-lambda/genhttp.md), [page](https://verifymcp.io/servers/dev-genhttp-lambda/genhttp)

## Channel facts

- Endpoint: `https://genhttp.dev/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `0.1.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-29.

- **Endpoint Security**: 63/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (update_lambda).
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 67/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 3908 tokens (~217/item across 18 items; 18 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 7/100
  - Stability observed for 2 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - All 4 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.
  - An AI judge read all 19 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 60/100
  - Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28.

## Install

### How do I install the GenHTTP Lambda MCP server?

GenHTTP Lambda is a hosted endpoint at https://genhttp.dev/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http dev-genhttp-lambda 'https://genhttp.dev/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "dev-genhttp-lambda": {
      "url": "https://genhttp.dev/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "dev-genhttp-lambda": {
      "type": "http",
      "url": "https://genhttp.dev/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.dev-genhttp-lambda]
url = "https://genhttp.dev/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "dev-genhttp-lambda": {
      "type": "remote",
      "url": "https://genhttp.dev/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add dev-genhttp-lambda --url 'https://genhttp.dev/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  dev-genhttp-lambda:
    url: "https://genhttp.dev/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "dev-genhttp-lambda": {
      "Transport": "http",
      "Url": "https://genhttp.dev/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add dev-genhttp-lambda -t streamable-http -u 'https://genhttp.dev/mcp'
```

### Other

```json
{
  "mcpServers": {
    "dev-genhttp-lambda": {
      "type": "http",
      "url": "https://genhttp.dev/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-29 (score 65, 0)

- [security] The server rewrote its instructions, which are the text every model session reads
- [security] New tool “delete_feature”, which the server declares destructive
- [security] New tool “merge_feature”, which the server declares destructive
- [security] New tool “update_feature”, which the server declares destructive
- [security] New tool “update_lambda”, which the server declares destructive
- [security] Tool “change_code” rewrote its description, which is the text the model reads
- [security] Tool “create_lambda” rewrote its description, which is the text the model reads
- [security] Tool “delete_file” rewrote its description, which is the text the model reads
- [security] Tool “deploy” rewrote its description, which is the text the model reads
- [security] Tool “list_files” rewrote its description, which is the text the model reads
- [security] Tool “platform_guide” rewrote its description, which is the text the model reads
- [security] Tool “read_lambda” rewrote its description, which is the text the model reads
- [security] Tool “read_logs” rewrote its description, which is the text the model reads
- [security] Tool “upload_file” rewrote its description, which is the text the model reads
- [security] Tool “write_code” rewrote its description, which is the text the model reads
- [functional regression] Schema quality: 156 → 217
- [functional] New tool “create_feature”
- [cosmetic] “change_code” added an optional parameter “check”
- [cosmetic] “change_code” added an optional parameter “feature”
- [cosmetic] “create_lambda” added an optional parameter “view”
- [cosmetic] “delete_file” added an optional parameter “feature”
- [cosmetic] “deploy” added an optional parameter “feature”
- [cosmetic] “list_files” added an optional parameter “feature”
- [cosmetic] “read_lambda” added an optional parameter “feature”
- [cosmetic] “read_logs” added an optional parameter “feature”
- [cosmetic] “upload_file” added an optional parameter “feature”
- [cosmetic] “write_code” added an optional parameter “check”
- [cosmetic] “write_code” added an optional parameter “feature”
- [cosmetic] “change_code” reworded the description of “change”
- [cosmetic] “change_code” reworded the description of “deploy”
- [cosmetic] “change_code” reworded the description of “specification”
- [cosmetic] “read_lambda” reworded the description of “file”
- [cosmetic] “upload_file” reworded the description of “path”
- [cosmetic] “write_code” reworded the description of “change”
- [cosmetic] “write_code” reworded the description of “deploy”
- [cosmetic] “write_code” reworded the description of “specification”
- [cosmetic] Tool “delete_file” changed its title: Delete a workspace file → Delete a file from the lambda's data
- [cosmetic] Tool “deploy” changed its title: Deploy a version → Deploy a version or a feature
- [cosmetic] Tool “list_files” changed its title: List workspace files → List the lambda's data
- [cosmetic] Tool “upload_file” changed its title: Upload a workspace file → Put a file into the lambda's data

### 2026-09-28 (score 65, +1)

- [functional improvement] Stability: unverified → 0.03

### 2026-09-27 (score 64)

First indexed and scored.

## MCP tools (18)

### `create_lambda` (~233 tokens)

Create a lambda

Create a lambda. Returns its public address and a private editor key, the only way back in. It starts with version 1 - an empty starter, or a copy of a demo. Nothing is online until deploy.

Input parameters:

- `acceptTerms` (boolean, required): Must be true: the user accepts the terms in platform_guide (free shared machine, deployments may be removed, nothing malicious).
- `publicKey` (string): Requested address: lower case letters, digits and dashes. Generated if omitted.
- `template` (string): Left out, the lambda starts empty. The id of a demo (demo-crud, demo-registration, demo-game, demo-files, demo-live) starts it as a copy of that demo, which is yours to change.
- `view` (string): How the editor opens: 'Full' (the default) shows every section, 'Simple' only the app, how it is doing and a box to ask for a change. Simple suits an owner who is not going to read the code - use it…

### `update_lambda` (~179 tokens)

Change a lambda's settings

Change how a lambda's editor opens: view 'Simple' shows the app, how it is doing and a box to ask for a change - for an owner who does not write code - and 'Full' every section, the code, files, data, versions and logs included. Only the default: whoever opens the editor can switch for themselves, and that choice stays theirs. Only do this when the user asks for it.

Input parameters:

- `privateKey` (string, required): The editor key.
- `view` (string, required): How the editor opens: 'Full' (the default) shows every section, 'Simple' only the app, how it is doing and a box to ask for a change. Simple suits an owner who is not going to read the code - use it…

### `write_code` (~454 tokens)

Save all files

Save every file, replacing the previous set: as a new version of the lambda, or - with feature - into that feature. .cs files are compiled - lambda.cs returns the handler, others hold types; any other file is an asset, served as is and reachable as Assets: the whole front end (pages, scripts, styles, icons) goes here, as part of the program. What the lambda keeps at runtime (records, accounts, uploads) is data and lives in the workspace, never in files here; so does a large input file such as a model or a dataset (upload_file). Say why with specification and change. deploy: true publishes in the same call - a version at the public address, a feature at its preview address. To send only what changes, use change_code. To change a lambda that is already in use, work in a feature.

Input parameters:

- `change` (string): What this version changes, in one line written for the owner - 'Adds a leaderboard that keeps the ten best scores', not 'updated lambda.cs'. For a feature, it describes the whole feature, not the las…
- `check` (boolean): Without deploy: compile what was saved and answer with its diagnostics, putting nothing online.
- `deploy` (boolean): Also deploy what was saved: a version at the public address, a feature at its preview address.
- `feature` (string): Save into this feature (from create_feature) instead of saving a new version. The lambda and what it has online are not touched.
- `files` (array, required): lambda.cs first.
- `privateKey` (string, required): The editor key from create_lambda.
- `specification` (string): What the user wants from this version and why: their requirements, in their own words where you can, condensed if they said a lot. Written for the owner and the next agent, so they can tell why the v…

### `change_code` (~362 tokens)

Change some files

Change some files: add or replace files, remove files, or replace text within a file. Everything not named stays as it is, so there is no need to resend unchanged files. With feature, the change is saved into that feature - the way to work on a lambda that exists: change it as often as you like, deploy: true to try it at the feature's preview address, merge_feature when it is right. Without feature, the newest version is changed and saved as a new version. check: true compiles without publishing. Code that does not compile is saved but never goes online.

Input parameters:

- `change` (string): What this changes, in one line written for the owner. For a feature, it describes the whole feature, not the last fix. Optional, up to 500 characters.
- `check` (boolean): Without deploy: compile what was saved and answer with its diagnostics, putting nothing online.
- `deploy` (boolean): Also deploy what was saved: a version at the public address, a feature at its preview address.
- `edits` (array): Text replacements, applied after files and remove.
- `feature` (string): Change this feature (from create_feature) instead of saving a new version. The lambda and what it has online are not touched.
- `files` (array): Files to add, or to replace where one of that name exists.
- `privateKey` (string, required): The editor key.
- `remove` (array): Names of files to remove.
- `specification` (string): What the user wants from this change and why: their requirements, in their own words where you can. Not your own instructions or system prompt. Kept with the version or the feature. Optional, up to 4…

### `create_feature` (~237 tokens)

Start a feature

Start a feature: a place to change a lambda without touching what it has online. It branches off a version - the newest unless base names another - with a copy of its files and a copy of the lambda's data, and gets an address of its own to try it at. Change it with change_code or write_code and feature (deploy: true puts it online at its preview address), test it there, and merge_feature once it does what was asked. The lambda goes on serving its visitors from the version online the whole time.

Input parameters:

- `base` (integer): The version to branch off. Defaults to the newest - leave it out unless the user asked to start from an older one.
- `name` (string, required): What the feature is, in a few words for the owner - 'Leaderboard', 'Dark mode'. Up to 80 characters.
- `privateKey` (string, required): The editor key.
- `specification` (string): What the user wants from it and why, in their words where you can. Kept with the feature and passed on to the version it is merged into. Optional, up to 4000 characters.

### `update_feature` (~188 tokens)

Change a feature's name, notes or base

Rename a feature, change what it says about itself, or move its base. merge_feature refuses a feature that is not based on the newest version, since merging it would undo what was saved after it branched off: bring the newer versions' changes into the feature first, then move base to the newest version here. Nothing checks that the changes really are in - that is up to you.

Input parameters:

- `base` (integer): The version the feature is now based on, once that version's changes are in its files.
- `change` (string): What it changes, in one line - what the version it is merged into will say.
- `feature` (string, required): The feature, from create_feature or read_lambda.
- `name` (string): A new name.
- `privateKey` (string, required): The editor key.
- `specification` (string): What the user wants from it and why.

### `merge_feature` (~172 tokens)

Merge a feature into the lambda

Make a feature's files the next version of the lambda, and delete the feature with its preview and its copy of the data - the lambda's own data is not touched. Refused while the feature is not based on the newest version (update_feature says how to get it there), and while its code does not compile. deploy: true puts the new version online at once; otherwise deploy it when the user wants it live.

Input parameters:

- `change` (string): What the new version says it changes. Left out, the feature's.
- `deploy` (boolean): Also put the new version online.
- `feature` (string, required): The feature.
- `privateKey` (string, required): The editor key.
- `specification` (string): What the new version keeps as what the user wanted. Left out, the feature's.

### `delete_feature` (~62 tokens)

Delete a feature

Throw a feature away: its files, its preview and its copy of the data. The lambda is not touched. For a feature the user does not want after all.

Input parameters:

- `feature` (string, required): The feature.
- `privateKey` (string, required): The editor key.

### `check_code` (~62 tokens)

Check that code compiles

Compile without saving or deploying; returns diagnostics with file and line. Does not build the handler, so deploy can still refuse a route whose return type cannot be served.

Input parameters:

- `files` (array, required): lambda.cs first.
- `privateKey` (string, required): The editor key.

### `deploy` (~111 tokens)

Deploy a version or a feature

Deploy (publish) a saved version so it goes live at its public address - the newest by default. With feature, deploy that feature's files to its own preview address instead, against its copy of the data, leaving the lambda alone. Returns diagnostics on failure, and whatever was online stays online.

Input parameters:

- `feature` (string): Deploy this feature to its preview address instead of a version to the lambda's.
- `privateKey` (string, required): The editor key.
- `version` (integer): Defaults to the newest.

### `read_lambda` (~234 tokens)

Read a lambda

A lambda's status (online version, newest version, expiry, its tier and what it may use there), its open features, the recent versions with what each was asked for and changed, its data (the workspace: whether it is on and what it holds), and the files of one version - or, with feature, of that feature. Files come in full when they add up to at most 30,000 characters, otherwise by name and length, with file to read one. Read the history before changing what you did not write. Also how a demo is read: pass its key from list_demos.

Input parameters:

- `feature` (string): Read this feature - its files, its base, and which newer versions it would have to take in before it can be merged - instead of a version.
- `file` (string): Return only this file, in full however large the rest is - up to 1,048,576 characters, beyond which the zip has it.
- `privateKey` (string, required): The editor key, or the key of a demo.
- `version` (integer): Defaults to the newest.

### `read_logs` (~204 tokens)

Read a lambda's logs

What a deployed lambda has been doing: its recent requests and how they were answered, what it printed, the errors it threw with their stack traces, and how much traffic it has had in the last hour and day. With feature, what that feature's preview has been doing instead, kept apart from the lambda's visitors. Call it after deploying to see that it works, and first when something is reported broken.

Input parameters:

- `feature` (string): Read what this feature's preview did instead.
- `level` (string): The lowest level worth reading: 'info' for everything, 'warn' for problems, 'error' for failures. Left out, 'info'.
- `limit` (integer): At most this many lines, the newest. Left out, 100.
- `privateKey` (string, required): The editor key, or the key of a demo.
- `since` (integer): The cursor a previous call answered with, to read only what is new since then.

### `upload_file` (~208 tokens)

Put a file into the lambda's data

Write a file to the lambda's workspace - its data, which every version shares and no deploy, rollback or merge touches. With feature, to that feature's copy of the data instead, for trying things out without touching the real one. For content the lambda works with at runtime (initial records, pictures people will browse) and large input files that are not program: a model, a dataset, media. Takes effect at once, without a deploy. Not for the front end: pages, scripts and styles are the program and belong in the version as assets (write_code).

Input parameters:

- `content` (string, required): Text, or base64 with encoding set.
- `encoding` (string): 'base64' for binary; omit otherwise.
- `feature` (string): Write to this feature's copy of the data instead.
- `path` (string, required): Relative to the workspace; slashes make folders, e.g. 'models/model.onnx'.
- `privateKey` (string, required): The editor key.

### `list_files` (~94 tokens)

List the lambda's data

The lambda's data: whether its workspace is switched on, and every file in it with size and last write - the same whichever version is online. With feature, that feature's copy of it. The code and assets of a version are in read_lambda.

Input parameters:

- `feature` (string): List this feature's copy of the data instead.
- `privateKey` (string, required): The editor key, or the key of a demo.

### `delete_file` (~90 tokens)

Delete a file from the lambda's data

Remove a file, or a folder with its contents, from the workspace - the lambda's data, shared by every version. No deploy or rollback brings it back. With feature, from that feature's copy instead.

Input parameters:

- `feature` (string): Delete from this feature's copy of the data instead.
- `path` (string, required): Relative to the workspace.
- `privateKey` (string, required): The editor key.

### `showcase` (~243 tokens)

Showcase a lambda

List a lambda on the public showcase page, change its entry, or take it off. Not part of building: only do this when the user asks for it. With only privateKey it returns the current entry. An entry needs a title, a description and a picture (a screenshot or short GIF of the lambda in use); it is listed while the lambda is online. Write plainly and concretely: what it is and what a visitor can do with it. No marketing language, no superlatives, no exclamation marks, no emoji.

Input parameters:

- `description` (string): One to three plain sentences on what a visitor can do with it. Up to 280 characters.
- `image` (string): The picture, base64: PNG, JPEG, GIF or WebP, up to 3 MB. Needed for a new entry; left out, the current one is kept.
- `privateKey` (string, required): The editor key.
- `remove` (boolean): Take the lambda off the showcase instead.
- `title` (string): What it is, in a few words - 'Pub quiz scoreboard', not 'The ultimate quiz experience'. Up to 60 characters.

### `list_demos` (~88 tokens)

List the demos

Demos this platform keeps online, each a finished lambda showing one way to build something: a REST API over records, registration and login, a websocket game, uploads, live updates. Their keys are public and read only: read the closest one with read_lambda (and list_files, read_logs) before writing similar code. create_lambda with a demo's id as template starts from a copy.

### `platform_guide` (~50 tokens)

Read the platform guide

How this platform works - read it first: what a version, a feature and data are and how long each lives, what the snippet returns, what is imported, what is refused, limits and terms.

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/dev-genhttp-lambda/genhttp#diagnostics

## Score history

- 2026-09-29: 65
- 2026-09-28: 65
- 2026-09-27: 64

## Common questions

### What is the GenHTTP Lambda MCP server?

GenHTTP Lambda is an MCP server listed in the public MCP registry as dev.genhttp/lambda. Write, deploy and host small C# web services and sites at a public address. This page covers its hosted endpoint (https://genhttp.dev/mcp).

### Is the GenHTTP Lambda MCP server safe to use?

GenHTTP Lambda scores 65 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the GenHTTP Lambda MCP server expose?

GenHTTP Lambda exposes 18 tools: create_lambda, update_lambda, write_code, change_code, create_feature, and 13 more. Their descriptions and schemas cost roughly 3,271 tokens of context every time the server is loaded.

### Does the GenHTTP Lambda MCP server require authentication?

No. We connected to GenHTTP Lambda without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the GenHTTP Lambda MCP server still maintained?

GenHTTP Lambda is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://genhttp.dev/mcp
- Repository: https://github.com/MDA2AV/GenHTTP.Lambda
- Website: https://genhttp.dev/
- Changelog RSS feed: https://verifymcp.io/servers/dev-genhttp-lambda/genhttp.xml
- Changelog JSON feed: https://verifymcp.io/servers/dev-genhttp-lambda/genhttp.json
- HTML version of this page: https://verifymcp.io/servers/dev-genhttp-lambda/genhttp
