URLpipe
REMOTE · URLPIPE.DEV · SCANNED OCT 2
Read any page with its JavaScript run: Markdown, screenshots, metadata, console errors, Lighthouse.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security91
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, but the challenge carries no valid RFC 9728 metadata, so a client cannot discover where to get a token. See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability76
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 5916 tokens (~394/item across 15 items; 14 tools + 1 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management23
- Stability observed for 7 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 14 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 16 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the URLpipe MCP server?
URLpipe is a hosted endpoint at https://urlpipe.dev/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · urlpipe.dev
claude mcp add --transport http dev-urlpipe-mcp 'https://urlpipe.dev/mcp'
{
"mcpServers": {
"dev-urlpipe-mcp": {
"url": "https://urlpipe.dev/mcp"
}
}
} {
"servers": {
"dev-urlpipe-mcp": {
"type": "http",
"url": "https://urlpipe.dev/mcp"
}
}
} [mcp_servers.dev-urlpipe-mcp] url = "https://urlpipe.dev/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"dev-urlpipe-mcp": {
"type": "remote",
"url": "https://urlpipe.dev/mcp",
"enabled": true
}
}
} openclaw mcp add dev-urlpipe-mcp --url 'https://urlpipe.dev/mcp' --transport streamable-http
mcp_servers:
dev-urlpipe-mcp:
url: "https://urlpipe.dev/mcp" {
"McpServers": {
"dev-urlpipe-mcp": {
"Transport": "http",
"Url": "https://urlpipe.dev/mcp"
}
}
} assistant mcp add dev-urlpipe-mcp -t streamable-http -u 'https://urlpipe.dev/mcp'
{
"mcpServers": {
"dev-urlpipe-mcp": {
"type": "http",
"url": "https://urlpipe.dev/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 1 Oct 26 +1
- The server rewrote its instructions, which are the text every model session reads security
- Tool “extract_metadata” rewrote its description, which is the text the model reads security
- Server version: 1.2.0 → 1.3.0 functional
- 29 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.
- 28 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Sept 26 +1
- Stability: unverified → 0.03 ▲ functional
- 25 Sept 26 78
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 2 Oct 2026 · Probed https://urlpipe.dev/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=urlpipe.dev | CN=YE2,O=Let's Encrypt,C=US | 19 Sept 2026 | 18 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 6f6ec9624da08fe159be034c9c8436c1aa6 |
| SANs: *.urlpipe.dev, urlpipe.dev | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC secure
Validation of urlpipe.dev. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| dev. | present | 60074 | 8 | Verified |
| urlpipe.dev. | present | 2371 | 13 | Verified |
| urlpipe.dev. | Verified address RRset verified with the apex keys |
Authentication Challenged, unverified
The endpoint asked for a token, but we could not retrieve and validate the RFC 9728 metadata that tells a client how to obtain one.
| Result | Challenged, unverified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer realm="urlpipe", error="invalid_token", error_description="A bearer token is required."
Bearer realm="urlpipe", error="invalid_token", error_description="A bearer token is required." | Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
| content-security-policy | default-src 'self'; font-src 'self' data:; img-src 'self' data:; object-src 'none'; script-src 'self' https://plausible.rogercampos.com https://challenges.cloudflare.com 'nonce-dc9b102e7b71966a516a6475789496e4'; style-src 'self' 'nonce-dc9b102e7b71966a516a6475789496e4'; connect-src 'self' https://plausible.rogercampos.com https://challenges.cloudflare.com ws://urlpipe.dev wss://urlpipe.dev; frame-src https://challenges.cloudflare.com |
| x-content-type-options | nosniff |
| x-frame-options | SAMEORIGIN |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), gyroscope=(), microphone=(), usb=(), fullscreen=(self), payment=(), geolocation=(), accelerometer=(), magnetometer=() |
Protected resource metadata
| Retrieved | No |
|---|---|
| Problem | no_resource_metadata |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://urlpipe.dev/mcp | Verified | 200 | |
| http (plaintext) | http://urlpipe.dev/mcp | HTTPS enforced | 301 | https://urlpipe.dev/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
capture_console_errors Capture console errors ~465
Exposes POST /console. Loads the page in headless Chrome and returns what it reported through console.error and console.warn during load, plus uncaught exceptions and unhandled promise rejections (not console.log). 1 credit. What you would open DevTools for: broken third-party scripts and client-side errors you cannot reproduce locally.
| Name | Type | Req | Description |
|---|---|---|---|
| idempotency_key | string | – | Makes the call safe to retry: sending it again with the same key within 24 hours returns the first call's token and result instead of starting (and charging for) new work, even with max_age "0". Up t… |
| labels | object | – | Your own keys to find this request by later, e.g. {"client": "acme"}: they come back with the result, in the webhook and in list_requests, which can filter by them. Up to 16 keys of up to 40 letters,… |
| max_age | string | – | How fresh a stored result must be to be reused, e.g. "2 hours" or "3 days". Default 7 days, maximum 30. A reused result is free. Pass "0" to force a fresh fetch. |
| page_options | object | – | What to do to the page before anything is read off it. Applies to the result itself: removed ads and banners are gone from html, markdown and summaries too. |
| project_id | integer | yes | Which project this request belongs to. From list_projects. |
| report_to | string | – | Async only: a webhook URL to deliver the result to. Defaults to the project's configured endpoint, if it has one. |
| residential | boolean | – | Fetch the page from a residential (home ISP) exit instead of a datacentre one. Costs a surcharge per page visit — see get_usage. Use it for sites that block datacentre traffic. |
| sync | boolean | – | Wait for the result and return it (default false). When false the call returns a token immediately and you collect the result with get_result. |
| url | string | yes | The page to fetch. Must be a public http(s) URL. |
Structured output declared, but exposes no named fields.
No examples provided.
capture_screenshot Take a screenshot ~560
Exposes POST /screenshot. Captures the whole rendered page as a PNG — JavaScript executed, web fonts and images included, exactly as a browser would draw it. 1 credit, whichever options you use. Use it to see a page rather than read it: layout, visual regressions, link previews, or checking what an anti-bot page actually showed us. screenshot_options size it (viewport, scale, one element, the fold only), encode it (png, jpeg or webp) and restyle it (dark mode, hidden elements, your own CSS); page_options wait for the page and take ads and cookie banners out of it.
| Name | Type | Req | Description |
|---|---|---|---|
| idempotency_key | string | – | Makes the call safe to retry: sending it again with the same key within 24 hours returns the first call's token and result instead of starting (and charging for) new work, even with max_age "0". Up t… |
| labels | object | – | Your own keys to find this request by later, e.g. {"client": "acme"}: they come back with the result, in the webhook and in list_requests, which can filter by them. Up to 16 keys of up to 40 letters,… |
| max_age | string | – | How fresh a stored result must be to be reused, e.g. "2 hours" or "3 days". Default 7 days, maximum 30. A reused result is free. Pass "0" to force a fresh fetch. |
| page_options | object | – | What to do to the page before anything is read off it. Applies to the result itself: removed ads and banners are gone from html, markdown and summaries too. |
| project_id | integer | yes | Which project this request belongs to. From list_projects. |
| report_to | string | – | Async only: a webhook URL to deliver the result to. Defaults to the project's configured endpoint, if it has one. |
| residential | boolean | – | Fetch the page from a residential (home ISP) exit instead of a datacentre one. Costs a surcharge per page visit — see get_usage. Use it for sites that block datacentre traffic. |
| screenshot_options | object | – | How to take the screenshot. Every key is optional; leave it out for a full-page PNG. |
| sync | boolean | – | Wait for the result and return it (default false). When false the call returns a token immediately and you collect the result with get_result. |
| url | string | yes | The page to fetch. Must be a public http(s) URL. |
Structured output declared, but exposes no named fields.
No examples provided.
extract_keywords Extract keywords ~465
Exposes POST /keywords. Returns the 5–15 terms and phrases that best represent the page, ordered by relevance — ranked by a language model, not by raw frequency. 15 credits. As with summarize_page: if you are going to reason over the result yourself, fetch_markdown costs 1 credit and gives you everything.
| Name | Type | Req | Description |
|---|---|---|---|
| idempotency_key | string | – | Makes the call safe to retry: sending it again with the same key within 24 hours returns the first call's token and result instead of starting (and charging for) new work, even with max_age "0". Up t… |
| labels | object | – | Your own keys to find this request by later, e.g. {"client": "acme"}: they come back with the result, in the webhook and in list_requests, which can filter by them. Up to 16 keys of up to 40 letters,… |
| max_age | string | – | How fresh a stored result must be to be reused, e.g. "2 hours" or "3 days". Default 7 days, maximum 30. A reused result is free. Pass "0" to force a fresh fetch. |
| page_options | object | – | What to do to the page before anything is read off it. Applies to the result itself: removed ads and banners are gone from html, markdown and summaries too. |
| project_id | integer | yes | Which project this request belongs to. From list_projects. |
| report_to | string | – | Async only: a webhook URL to deliver the result to. Defaults to the project's configured endpoint, if it has one. |
| residential | boolean | – | Fetch the page from a residential (home ISP) exit instead of a datacentre one. Costs a surcharge per page visit — see get_usage. Use it for sites that block datacentre traffic. |
| sync | boolean | – | Wait for the result and return it (default false). When false the call returns a token immediately and you collect the result with get_result. |
| url | string | yes | The page to fetch. Must be a public http(s) URL. |
Structured output declared, but exposes no named fields.
No examples provided.
extract_metadata Extract page metadata ~541
Exposes POST /meta. Reads everything a page declares about itself — Open Graph, Twitter cards, meta tags, JSON-LD, microdata and links — into one object with the same keys on every page: title, description, site name, kind of page, language, authors, publication and update dates, share image and video, favicon and icons, logo, feeds, keywords, canonical URL, robots directives, hreflang alternates, oEmbed endpoint and structured-data types, plus the raw og: and twitter: tags. A value the page does not declare is null or an empty list. Values injected by JavaScript are included, because the page is rendered first. 1 credit.
| Name | Type | Req | Description |
|---|---|---|---|
| idempotency_key | string | – | Makes the call safe to retry: sending it again with the same key within 24 hours returns the first call's token and result instead of starting (and charging for) new work, even with max_age "0". Up t… |
| labels | object | – | Your own keys to find this request by later, e.g. {"client": "acme"}: they come back with the result, in the webhook and in list_requests, which can filter by them. Up to 16 keys of up to 40 letters,… |
| max_age | string | – | How fresh a stored result must be to be reused, e.g. "2 hours" or "3 days". Default 7 days, maximum 30. A reused result is free. Pass "0" to force a fresh fetch. |
| page_options | object | – | What to do to the page before anything is read off it. Applies to the result itself: removed ads and banners are gone from html, markdown and summaries too. |
| project_id | integer | yes | Which project this request belongs to. From list_projects. |
| report_to | string | – | Async only: a webhook URL to deliver the result to. Defaults to the project's configured endpoint, if it has one. |
| residential | boolean | – | Fetch the page from a residential (home ISP) exit instead of a datacentre one. Costs a surcharge per page visit — see get_usage. Use it for sites that block datacentre traffic. |
| sync | boolean | – | Wait for the result and return it (default false). When false the call returns a token immediately and you collect the result with get_result. |
| url | string | yes | The page to fetch. Must be a public http(s) URL. |
Structured output declared, but exposes no named fields.
No examples provided.
fetch_html Get the rendered HTML ~484
Exposes POST /html. Returns the page's HTML after JavaScript has run and redirects have been followed — the DOM a real browser sees, not the empty shell curl returns. 1 credit. Use it when you need the markup itself: a specific attribute, a script tag, a structured-data block. If you want to read the page's content, fetch_markdown costs the same and returns a fraction of the text.
| Name | Type | Req | Description |
|---|---|---|---|
| idempotency_key | string | – | Makes the call safe to retry: sending it again with the same key within 24 hours returns the first call's token and result instead of starting (and charging for) new work, even with max_age "0". Up t… |
| labels | object | – | Your own keys to find this request by later, e.g. {"client": "acme"}: they come back with the result, in the webhook and in list_requests, which can filter by them. Up to 16 keys of up to 40 letters,… |
| max_age | string | – | How fresh a stored result must be to be reused, e.g. "2 hours" or "3 days". Default 7 days, maximum 30. A reused result is free. Pass "0" to force a fresh fetch. |
| page_options | object | – | What to do to the page before anything is read off it. Applies to the result itself: removed ads and banners are gone from html, markdown and summaries too. |
| project_id | integer | yes | Which project this request belongs to. From list_projects. |
| report_to | string | – | Async only: a webhook URL to deliver the result to. Defaults to the project's configured endpoint, if it has one. |
| residential | boolean | – | Fetch the page from a residential (home ISP) exit instead of a datacentre one. Costs a surcharge per page visit — see get_usage. Use it for sites that block datacentre traffic. |
| sync | boolean | – | Wait for the result and return it (default false). When false the call returns a token immediately and you collect the result with get_result. |
| url | string | yes | The page to fetch. Must be a public http(s) URL. |
Structured output declared, but exposes no named fields.
No examples provided.
fetch_markdown Read a page as Markdown ~502
Exposes POST /markdown. Renders the page in headless Chrome and converts its main content to clean Markdown — headings, lists, links and code kept, navigation, sidebars and cookie banners dropped. Start here when you want to READ a page. It is the cheapest operation we sell (1 credit) and by far the most compact thing to put in front of a model: fetch_html returns the whole DOM, which is usually many times larger and says nothing extra about what the page means.
| Name | Type | Req | Description |
|---|---|---|---|
| idempotency_key | string | – | Makes the call safe to retry: sending it again with the same key within 24 hours returns the first call's token and result instead of starting (and charging for) new work, even with max_age "0". Up t… |
| labels | object | – | Your own keys to find this request by later, e.g. {"client": "acme"}: they come back with the result, in the webhook and in list_requests, which can filter by them. Up to 16 keys of up to 40 letters,… |
| max_age | string | – | How fresh a stored result must be to be reused, e.g. "2 hours" or "3 days". Default 7 days, maximum 30. A reused result is free. Pass "0" to force a fresh fetch. |
| page_options | object | – | What to do to the page before anything is read off it. Applies to the result itself: removed ads and banners are gone from html, markdown and summaries too. |
| project_id | integer | yes | Which project this request belongs to. From list_projects. |
| report_to | string | – | Async only: a webhook URL to deliver the result to. Defaults to the project's configured endpoint, if it has one. |
| residential | boolean | – | Fetch the page from a residential (home ISP) exit instead of a datacentre one. Costs a surcharge per page visit — see get_usage. Use it for sites that block datacentre traffic. |
| sync | boolean | – | Wait for the result and return it (default false). When false the call returns a token immediately and you collect the result with get_result. |
| url | string | yes | The page to fetch. Must be a public http(s) URL. |
Structured output declared, but exposes no named fields.
No examples provided.
get_request Inspect a past request ~121
Everything about one past request except its result: what was asked for, how long each stage took, whether it came from the store, and how the webhook delivery went. This is the metadata; get_result returns the page itself. Reach for this one when a call did not do what you expected — it says whether the result was reused, why an analysis failed, and whether the delivery to the project's endpoint succeeded.
| Name | Type | Req | Description |
|---|---|---|---|
| project_id | integer | yes | From list_projects. |
| token | string | yes | The token the original call returned. |
| Name | Type | Req | Description |
|---|---|---|---|
| async | boolean|null | – | – |
| created_at | string | – | – |
| credits | integer | – | – |
| duration_ms | integer | – | – |
| final_url | string | – | Where the page ended up after its redirects. |
| finished_at | string | – | – |
| labels | object | – | – |
| max_age | integer|null | – | – |
| meta | object | – | What the HTTP response headers would say: cache, cost, quota, result_url, final_url. |
| operation | string|null | – | – |
| operations | array | – | – |
| outcome | object|null | – | – |
| report_to | string|null | – | – |
| request_options | object|null | – | – |
| served_from_cache | boolean|null | – | – |
| status | string | yes | – |
| success | boolean|null | – | – |
| token | string | yes | – |
| url | string | yes | – |
| webhook_delivered_at | string|null | – | – |
| webhook_error | string|null | – | – |
| webhook_status | string|null | – | – |
No examples provided.
get_result Get a result ~164
Exposes GET /result/:token. Returns the result of a past request, in the same form the call that made it would have returned — Markdown as Markdown, a structured operation as its object, a screenshot as an image, a scrape as its combined object. This is how an async call is collected: any tool called without sync: true answers with a token, and this turns that token into the result. It also re-reads a result somebody already paid for, which is free — results are kept for 30 days. A request that has not finished yet answers {"status": "processing"}; call again in a moment.
| Name | Type | Req | Description |
|---|---|---|---|
| project_id | integer | yes | From list_projects. |
| token | string | yes | The token the original call returned. |
Structured output declared, but exposes no named fields.
No examples provided.
get_usage Check usage and prices ~104
What the organization's plan allows, how much of it is left this period, and what each operation costs. Worth reading before a run of expensive calls: the operations differ by seventeen times in price, so the difference between fetch_markdown and summarize_page over a hundred pages is 100 credits against 1,700. It is also how to read a refusal — a call that comes back with quota_exceeded is telling you this number ran out.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| concurrency_limit | integer | – | – |
| cost_per_operation | object | yes | – |
| credits | object | yes | – |
| plan | string | yes | – |
| plan_name | string | – | – |
| residential_surcharge_per_page_visit | integer | – | – |
No examples provided.
list_projects List projects ~88
The projects this token can reach, each with how many requests it has made in the last 30 days and where its results are delivered. Start here: every other tool takes a project_id from this list. A project is the unit a request is billed and recorded against — credits themselves belong to the organization, so which project you pick does not change what a call costs.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| organization | string | yes | – |
| projects | array | yes | – |
No examples provided.
list_requests List past requests ~188
A project's recent requests, newest first, with each one's token. Look here before fetching a page: if somebody already pulled it, passing that token to get_result returns the same result for nothing. A /scrape appears as one entry — its per-operation children are internal, and the scrape's own token returns all of them. Pass labels to see only the requests made with them — every key given must match its value exactly.
| Name | Type | Req | Description |
|---|---|---|---|
| labels | object | – | Only requests made with all of these labels, each value matched exactly. |
| limit | integer | – | How many to return. Default 25, maximum 100. |
| offset | integer | – | Skip this many, for paging. |
| operation | string | – | Only requests running this operation. |
| project_id | integer | yes | From list_projects. |
| url | string | – | Only requests for this exact URL. |
| Name | Type | Req | Description |
|---|---|---|---|
| offset | integer | yes | – |
| project_id | integer | yes | – |
| requests | array | yes | – |
| total | integer | yes | – |
No examples provided.
run_lighthouse_audit Run a Lighthouse audit ~498
Exposes POST /lighthouse. Runs a real Google Lighthouse audit against the live page: performance, accessibility, best-practices and SEO scores plus Core Web Vitals. 2 credits — dearer than a page fetch because the audit runs in its own limited lane, so it also takes longer than anything else here. It fetches the page itself rather than sharing a visit, so asking for it inside scrape_url costs two page visits, not one.
| Name | Type | Req | Description |
|---|---|---|---|
| device | string | – | Which profile to audit under. Default mobile. |
| idempotency_key | string | – | Makes the call safe to retry: sending it again with the same key within 24 hours returns the first call's token and result instead of starting (and charging for) new work, even with max_age "0". Up t… |
| include_audits | boolean | – | Include the full per-audit detail, not just scores and metrics. Much larger; default false. |
| labels | object | – | Your own keys to find this request by later, e.g. {"client": "acme"}: they come back with the result, in the webhook and in list_requests, which can filter by them. Up to 16 keys of up to 40 letters,… |
| max_age | string | – | How fresh a stored result must be to be reused, e.g. "2 hours" or "3 days". Default 7 days, maximum 30. A reused result is free. Pass "0" to force a fresh fetch. |
| project_id | integer | yes | Which project this request belongs to. From list_projects. |
| report_to | string | – | Async only: a webhook URL to deliver the result to. Defaults to the project's configured endpoint, if it has one. |
| residential | boolean | – | Fetch the page from a residential (home ISP) exit instead of a datacentre one. Costs a surcharge per page visit — see get_usage. Use it for sites that block datacentre traffic. |
| sync | boolean | – | Wait for the result and return it (default false). When false the call returns a token immediately and you collect the result with get_result. |
| url | string | yes | The page to fetch. Must be a public http(s) URL. |
Structured output declared, but exposes no named fields.
No examples provided.
scrape_url Several results from one page visit ~680
Exposes POST /scrape. Runs any subset of the other operations in one request, served from a single page visit where possible. Each operation is billed and stored exactly as the individual call would be, so this is not a discount — with one exception, and it is the reason to use it: a residential exit is charged per page VISIT, so several results off one visit pay the surcharge once. Answers with one object keyed by operation, each entry carrying its own success and result, so a partial failure still returns everything that worked. lighthouse does not share the visit — it runs its own audit on its own engine — so including it means two page fetches, and two surcharges when residential is on. So does a screenshot whose screenshot_options set viewport_width, viewport_height, device_scale_factor, dark_mode or block_ads: those change how the page loads, so the screenshot gets a visit of its own.
| Name | Type | Req | Description |
|---|---|---|---|
| device | string | – | Lighthouse only, when it is among the operations. Default mobile. |
| idempotency_key | string | – | Makes the call safe to retry: sending it again with the same key within 24 hours returns the first call's token and result instead of starting (and charging for) new work, even with max_age "0". Up t… |
| include_audits | boolean | – | Lighthouse only: include the full per-audit detail. Default false. |
| labels | object | – | Your own keys to find this request by later, e.g. {"client": "acme"}: they come back with the result, in the webhook and in list_requests, which can filter by them. Up to 16 keys of up to 40 letters,… |
| max_age | string | – | How fresh a stored result must be to be reused, e.g. "2 hours" or "3 days". Default 7 days, maximum 30. A reused result is free. Pass "0" to force a fresh fetch. |
| operations | array | yes | Which operations to run off this page. |
| page_options | object | – | What to do to the page before anything is read off it. Applies to the result itself: removed ads and banners are gone from html, markdown and summaries too. |
| project_id | integer | yes | Which project this request belongs to. From list_projects. |
| report_to | string | – | Async only: a webhook URL to deliver the result to. Defaults to the project's configured endpoint, if it has one. |
| residential | boolean | – | Fetch the page from a residential (home ISP) exit instead of a datacentre one. Costs a surcharge per page visit — see get_usage. Use it for sites that block datacentre traffic. |
| screenshot_options | object | – | Screenshot only, when it is among the operations: how to take it, exactly as capture_screenshot takes it. |
| sync | boolean | – | Wait for the result and return it (default false). When false the call returns a token immediately and you collect the result with get_result. |
| url | string | yes | The page to fetch. Must be a public http(s) URL. |
Structured output declared, but exposes no named fields.
No examples provided.
summarize_page Summarize a page ~505
Exposes POST /summarize. Returns a concise Markdown summary of the page's main content, with the navigation, ads and boilerplate left out. The most expensive operation we sell, at 17 credits, because it runs a language model over the page. If YOU are the model that will read it, fetch_markdown gives you the whole page for 1 credit and you can summarize it yourself — this tool is for when the summary is the artefact being produced, not a step on the way to one.
| Name | Type | Req | Description |
|---|---|---|---|
| idempotency_key | string | – | Makes the call safe to retry: sending it again with the same key within 24 hours returns the first call's token and result instead of starting (and charging for) new work, even with max_age "0". Up t… |
| labels | object | – | Your own keys to find this request by later, e.g. {"client": "acme"}: they come back with the result, in the webhook and in list_requests, which can filter by them. Up to 16 keys of up to 40 letters,… |
| max_age | string | – | How fresh a stored result must be to be reused, e.g. "2 hours" or "3 days". Default 7 days, maximum 30. A reused result is free. Pass "0" to force a fresh fetch. |
| page_options | object | – | What to do to the page before anything is read off it. Applies to the result itself: removed ads and banners are gone from html, markdown and summaries too. |
| project_id | integer | yes | Which project this request belongs to. From list_projects. |
| report_to | string | – | Async only: a webhook URL to deliver the result to. Defaults to the project's configured endpoint, if it has one. |
| residential | boolean | – | Fetch the page from a residential (home ISP) exit instead of a datacentre one. Costs a surcharge per page visit — see get_usage. Use it for sites that block datacentre traffic. |
| sync | boolean | – | Wait for the result and return it (default false). When false the call returns a token immediately and you collect the result with get_result. |
| url | string | yes | The page to fetch. Must be a public http(s) URL. |
Structured output declared, but exposes no named fields.
No examples provided.
What is the URLpipe MCP server?
URLpipe is an MCP server listed in the public MCP registry as dev.urlpipe/mcp. Read any page with its JavaScript run: Markdown, screenshots, metadata, console errors, Lighthouse. This page covers its hosted endpoint (https://urlpipe.dev/mcp).
Is the URLpipe MCP server safe to use?
URLpipe scores 81 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the URLpipe MCP server expose?
URLpipe exposes 14 tools: list_projects, get_usage, fetch_markdown, fetch_html, capture_screenshot, and 9 more. Their descriptions and schemas cost roughly 5,365 tokens of context every time the server is loaded.
Does the URLpipe MCP server require authentication?
Yes. URLpipe asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the URLpipe MCP server still maintained?
URLpipe is still listed as active in the MCP registry. We last reached this channel on 2 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.