Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Mockbird

REMOTE · MOCKBIRD.MOCKBIRD.WORKERS.DEV · SCANNED SEP 28

Mock REST APIs, fake OAuth2/OIDC provider, uptime monitors + heartbeats, live badge/QR images.

0 this week 71 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security46
Transport & Reachability100
Schema Quality & AI Usability76
  • 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 6615 tokens (~315/item across 21 items; 19 tools + 2 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
  • No destabilizing schema changes in the last 30 days.Pass
Tool Coverage97
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 90% of tool parameters carry a description.Partial
Tool Safety75
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • 0 of 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "delete_project" implies "delete" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
  • An AI judge read all 21 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
  • Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
Install

How do I install the Mockbird MCP server?

Mockbird is a hosted endpoint at https://mockbird.mockbird.workers.dev/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · mockbird.mockbird.workers.dev

# add to Claude Code
claude mcp add --transport http dev-workers-mockbird-mockbird-mockbird 'https://mockbird.mockbird.workers.dev/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "dev-workers-mockbird-mockbird-mockbird": {
      "url": "https://mockbird.mockbird.workers.dev/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "dev-workers-mockbird-mockbird-mockbird": {
      "type": "http",
      "url": "https://mockbird.mockbird.workers.dev/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.dev-workers-mockbird-mockbird-mockbird]
url = "https://mockbird.mockbird.workers.dev/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "dev-workers-mockbird-mockbird-mockbird": {
      "type": "remote",
      "url": "https://mockbird.mockbird.workers.dev/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add dev-workers-mockbird-mockbird-mockbird --url 'https://mockbird.mockbird.workers.dev/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  dev-workers-mockbird-mockbird-mockbird:
    url: "https://mockbird.mockbird.workers.dev/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "dev-workers-mockbird-mockbird-mockbird": {
      "Transport": "http",
      "Url": "https://mockbird.mockbird.workers.dev/mcp"
    }
  }
}
# add to Vellum
assistant mcp add dev-workers-mockbird-mockbird-mockbird -t streamable-http -u 'https://mockbird.mockbird.workers.dev/mcp'
// mcp.json
{
  "mcpServers": {
    "dev-workers-mockbird-mockbird-mockbird": {
      "type": "http",
      "url": "https://mockbird.mockbird.workers.dev/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 28 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 25 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 20 Sept 26 0
    • The server rewrote its instructions, which are the text every model session reads security
  • 17 Sept 26 0
    • The server rewrote its instructions, which are the text every model session reads security
    • Tool “add_resource” rewrote its description, which is the text the model reads security
    • Tool “create_project” rewrote its description, which is the text the model reads security
    • Tool “uptime_monitor” rewrote its description, which is the text the model reads security
    • Server version: 1.5.1 → 1.6.0 functional
    • “add_resource” reworded the description of “adminKey” cosmetic
    • “add_resource” reworded the description of “project” cosmetic
    • “add_resource” made “adminKey” optional cosmetic
    • “add_resource” made “project” optional cosmetic
  • 16 Sept 26 0
    • Tool “image_url” rewrote its description, which is the text the model reads security
  • 13 Sept 26 0
    • Tool “image_url” rewrote its description, which is the text the model reads security
    • Server version: 1.5.0 → 1.5.1 functional
    • “image_url” reworded the description of “params” cosmetic
  • 12 Sept 26 0
    • Schema quality: 5640 → 6336 ▼ functional
    • Server version: 1.4.0 → 1.5.0 functional
    • New tool “image_url” functional
  • 11 Sept 26 0
    • Tool “verdict” rewrote its description, which is the text the model reads security
    • “verdict” added an optional parameter “name” cosmetic
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 28 Sept 2026 · Probed https://mockbird.mockbird.workers.dev/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=mockbird.workers.dev CN=WE1,O=Google Trust Services,C=US 22 Sept 2026 21 Dec 2026 ECDSA 256 ECDSA-SHA256 8e0f0309129826f90e1e64f3cefd16c4
SANs: mockbird.workers.dev, *.mockbird.workers.dev
CN=WE1,O=Google Trust Services,C=US (CA) CN=GTS Root R4,O=Google Trust Services LLC,C=US 13 Dec 2023 20 Feb 2029 ECDSA 256 ECDSA-SHA384 7ff31977972c224a76155d13b6d685e3
CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE 15 Nov 2023 28 Jan 2028 ECDSA 384 SHA256-RSA 7fe530bf331343bedd821610493d8a1b

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of mockbird.mockbird.workers.dev. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
dev. present 60074 8 Verified
workers.dev. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://mockbird.mockbird.workers.dev/mcp Verified 200
http (plaintext) http://mockbird.mockbird.workers.dev/mcp Inconclusive 405
MCP tools · 19 exposed · ~6,140 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
add_resource ~362

Add a resource (collection) to a project and seed it with realistic fake data. Either pass template (one of the built-ins, e.g. users, products, posts, comments, orders, todos, reviews, customers, events) or fields: an array of {name, type} where type ∈ uuid|firstName|lastName|fullName|username|email|avatar|image|word|words|title|sentence|paragraph|number|price|percent|boolean|date|pastDate|futureDate|url|domain|ip|phone|city|country|address|zipCode|company|jobTitle|color|latitude|longitude|rating|age|slug|status|category|refId, plus {name, type:"oneOf", values:[...]} for enums. seed = number of records to generate (default 20, max 100, 0 = empty). No project yet? Omit project AND adminKey and a fresh blank project is auto-created for this resource — the response then includes the new project id + adminKey (save both).

NameTypeReqDescription
adminKeystring–The project's adminKey. Omit (together with project) to auto-create.
fieldsarray–Array of {name, type} (or {name, type:'oneOf', values:[…]}). Optional.
namestringyesResource name, plural (e.g. products).
projectstring–Project id. Omit (together with adminKey) to auto-create a fresh project.
seednumber–Records to seed (default 20, max 100).
templatestring–Built-in template name. Optional (use this OR fields).

No output schema declared.

No examples provided.

check_api_status ~230

Live status of ~58 public mock/testing APIs — JSONPlaceholder, httpbin.org, ReqRes, FakeStoreAPI, DummyJSON, Postman Echo, httpstat.us, Mocky, Mockbin, CrudCrud, restcountries, and more — checked with a plain keyless GET every 30 minutes from Cloudflare's network (a service answering HTTP 200 error envelopes is probed by body and honestly reported as failing). No arguments → compact summary: up/down counts plus full detail for every failing service. Pass service (id, name, or hostname substring — e.g. "httpbin", "reqres.in") for one service's detail: latest check, last_success_at, down_since, 24h/7d uptime, note, recent check history. Use it before pointing tests or tutorials at a public API — and if it's down, the result links a Mockbird alternative guide plus the one-call hosted mock replacement.

NameTypeReqDescription
servicestring–Service id, name, or hostname substring (e.g. httpbin, reqres.in). Optional — omit for the summary.

No output schema declared.

No examples provided.

create_project ~398

Create a new mock REST API project. Returns {id, adminKey, baseUrl, resources[]}. SAVE the adminKey — it is required for admin operations (add_resource, custom_route, snapshots) and is shown only once. Presets seed a full backend: blog (posts/comments/authors), ecommerce (products/orders/customers/reviews), saas (users/teams/events), payments (Stripe-shaped sandbox: charges/refunds/subscriptions/customers + payment_intent create→confirm flow + /v1/balance — no keys), openai (ready OpenAI-compatible mock — chat completions incl. streaming SSE, embeddings with a real 1536-dim vector, models; point OPENAI_BASE_URL at {baseUrl}/v1). Omit preset for a starter project (one seeded "items" resource — live data immediately, reshape or delete it); use "blank" for a truly empty project you fill via add_resource or import_data. The mock API is then live at baseUrl: standard REST CRUD (GET/POST/PUT/PATCH/DELETE), CORS enabled, no auth needed. Every project also serves a mock OAuth2/OIDC provider at {baseUrl}/.well-known/openid-configuration (PKCE code flow, client_credentials, RS256 JWKS — any client_id works) for testing auth flows.

NameTypeReqDescription
namestring–Project name (max 60 chars). Optional.
presetstring–Seeded preset; 'blank' = truly empty. Omit for a starter project. Optional.
ttlnumber–Optional: self-expiring project — auto-deletes after this many seconds (60–604800, i.e. 1 min to 7 days). Perfect for CI/eval sandboxes that must not leak even when the run crashes. Extend or cancel…

No output schema declared.

No examples provided.

custom_route ~205

Define a custom endpoint on a project (like /health, /config/:key, or a catch-all /webhooks/* request bin). body is a response template: {{query.x}} {{params.x}} {{body.x}} {{headers.x}} {{method}} {{path}} {{now}} {{ts}} {{uuid}} {{rand}}; triple braces {{{body}}} insert raw JSON. Custom routes take precedence over resource routes; '*' catch-alls are a fallback. Max 20 routes/project.

NameTypeReqDescription
adminKeystringyes–
bodystring–Response body template (string; JSON works).
contentTypestring–Default application/json.
delayMsnumber–Artificial latency in ms.
methodstring–Default GET.
pathstringyese.g. /health, /config/:key, /webhooks/*
projectstringyes–
statusnumber–Response status (default 200).

No output schema declared.

No examples provided.

delete_project ~79

Permanently delete a project and ALL its data (records, resources, snapshots, custom routes, webhooks, request log). Irreversible. Good practice for short-lived test projects: clean up when your session is done. Requires the adminKey.

NameTypeReqDescription
adminKeystringyesThe project's adminKey.
projectstringyesProject id.

No output schema declared.

No examples provided.

fork_project ~258

Copy an entire project — resources + records verbatim, custom routes, behavior settings — into a brand-new project with its own id + adminKey. Built for parallel eval/CI runs: keep a template project, fork_project per run with a ttl (crashed runs can't leak sandboxes — the fork deletes itself), let the agent mutate the fork freely, then grade with snapshots action:"diff". withSnapshots:true also copies the template's snapshots, so a fork carries its expected/start answer keys for diff-based grading. Works on the shared playground with NO adminKey: {"project":"demo"} gives you the demo dataset as your own private project (writes persist, never resets).

NameTypeReqDescription
adminKeystring–Source project's adminKey. Not needed when forking "demo".
namestring–Name for the fork (default: <source name>-fork). Optional.
projectstringyesSource project id to fork (or "demo").
ttlnumber–Self-expiring fork: auto-deletes after this many seconds (60–604800), even if your run crashes. Optional.
withSnapshotsboolean–Also copy the source's snapshots into the fork (answer keys travel with it). Optional.

No output schema declared.

No examples provided.

generate_fake_data ~410

Generate realistic fake data instantly — stateless, nothing is created or stored, no project or adminKey needed. Ready-made resource shapes (FakerAPI-compatible): persons, users, addresses, companies, books, products, texts, images, places, credit_cards (credit cards are Luhn-valid; book EAN13/ISBN13 checksums are real; image URLs are live SVG placeholders served by Mockbird). Or pass fields for a custom shape: an object mapping output key → type, with type ∈ counter|uuid|number|boolean|word|text|longText|firstName|lastName|name|email|phone|date|dateTime|image|streetAddress|streetName|buildingNumber|city|postcode|state|country|countryCode|latitude|longitude|vat|website|company_name|card_type|card_number|card_expiration|ean|upc|pokemon|null. seed makes output deterministic — same seed + shape returns identical rows forever (reproducible fixtures). Need the data HOSTED instead? create_project / add_resource serve seeded collections at a live REST URL with full CRUD, filters, and persistence.

NameTypeReqDescription
fieldsobject–Custom shape: {outputKey: type}, e.g. {"id":"counter","name":"firstName","mail":"email","signup":"dateTime"}. Optional.
paramsobject–Extra FakerAPI-compatible query params, e.g. {"_gender":"female"}, {"_price_min":10,"_price_max":500}, {"_characters":500}, {"_width":640}. Optional.
quantitynumber–Rows to generate (1-100, default 5).
resourcestring–One of persons|users|addresses|companies|books|products|texts|images|places|credit_cards. Default persons. Ignored when fields is set.
seednumber–Deterministic seed — same seed returns the same rows. Optional.

No output schema declared.

No examples provided.

heartbeat ~552

Dead man's switch for cron jobs, scheduled tasks, and recurring agent runs — the INVERSE of uptime_monitor: the JOB pings Mockbird, and if the ping stops arriving the alert fires once (plus one recovery message when pings resume). action:"create" {name?, period_minutes, grace_minutes?, notify?}: period_minutes = how often the job runs (30–10080); grace defaults to half the period. With notify, missed check-ins hit that webhook; WITHOUT notify you get a pollable heartbeat instead — poll for missed-check-in transitions, no webhook needed. Returns a ping URL (curl -fsS -m 10 <ping_url> at the end of the job — or call this tool with action:"ping"), a public status page /status/:id, badge.svg, Atom feed, and {id, secret} — STORE id, secret AND ping_url; they cannot be recovered. Creation counts as the first ping. action:"ping" {ping_url}: check in (use this to arm a heartbeat for YOUR OWN recurring runs — ping each run, and a missed run alerts your human via the webhook or your next poll). action:"poll" {id, secret}: (webhook-less heartbeats) missed-check-in / checked-in-again transitions since your last poll plus the current ping age. action:"info" {id, secret}: last ping, ping URL, recent evaluations. action:"delete" {id, secret}: disarm. notify formats are the same as uptime_monitor (Slack/Discord native, HMAC-signed JSON otherwise). Limits: 5 live heartbeats per IP — deleting one frees the slot immediately; evaluation granularity 30 min; pollable heartbeats with no polls and no pings for 30 days are removed.

NameTypeReqDescription
actionstringyesWhat to do.
grace_minutesnumber–create: extra slack before alerting (5–1440). Default: half the period.
idstring–poll/info/delete: the heartbeat id (hb-…) returned by create.
namestring–create: a label for the job (shown on the status page), e.g. "nightly backup".
notifystring–create (optional): the webhook URL to alert when the ping stops. Omit it to get a pollable heartbeat instead.
period_minutesnumber–create: how often the job is supposed to run, in minutes (30–10080).
ping_urlstring–ping: the ping URL returned by create (https://…/ping/p-…).
secretstring–poll/info/delete: the secret returned by create.

No output schema declared.

No examples provided.

image_url ~745

Mint a permanent, keyless image URL rendered by Mockbird — README badges (including LIVE record-count badges), chart images, QR codes, Open Graph cards, placeholder images, initials avatars. Deterministic: the same URL renders the same image forever (no account, no expiry, no watermark). Params are validated against the real endpoint before the URL is returned, so a returned URL is guaranteed to render. Returns {url, markdown} ready to paste into READMEs, PR comments, issues, chat, dashboards, or HTML <img> tags. Kinds and their params: badge (SVG): {label, value, color (shields-style names like brightgreen/red/blue or hex), labelColor, style: flat|flat-square|plastic|for-the-badge|social}; label ALONE renders a message-only badge (single colored segment) — OR live mode: {resource:"products"} renders the CURRENT record count of that resource in the project (extra field:value entries filter exact-match, e.g. {resource:"orders", status:"shipped"}); re-counted on every render (~60s cache) — a README badge that tracks live mock data. chart (PNG; format:"svg" for vector): {data:"1,4,2,8" — comma-separated numbers, up to 6 pipe-separated series "1,4,2|3,5,8", type: line|area|bar|spark|pie|donut, labels:"mon,tue,wed", title, theme: light|dark}; size like "800x400". qr (PNG or svg): {data:"https://…"} — any text up to 1000 chars: URLs, WIFI:T:WPA;S:net;P:pw;; strings, mailto:, plain text; optional {ecc: L|M|Q|H, margin, fg, bg (hex, no #)}; size like "512". og (PNG at the og:image-standard 1200x630 — paste straight into <meta property="og:image">): {title (≤120 chars, wrapped), subtitle (≤200), site (footer text), logo: <seed> (deterministic identicon), theme: dark|light}. placeholder: size "300x200" (WxH, default) plus {text, bg, fg (hex, no #), seed (deterministic palette), round:1 (circle)}. avatar: {name:"Ada Lovelace"} — deterministic initials avatar. By default images render under the shared demo project; pass project:<your id> to point live badge counts at YOUR mock…

NameTypeReqDescription
formatstring–Optional. badge is always SVG; chart/qr/og/placeholder default to PNG (og/chart/qr) or SVG (placeholder/avatar) — svg forces the vector twin.
kindstringyesWhich image to mint.
paramsobject–Query params for the endpoint (see the per-kind lists in the tool description). Values are strings or numbers (arrays of numbers join with commas). Passing these directly as top-level properties (e.g…
projectstring–Optional project id (default "demo", the shared public playground). Use your own project id so live badge counts track your data.
sizestring–Optional size path: "WxH" for chart/og/placeholder (e.g. "800x400"), a single number for qr (e.g. "512") or a square placeholder.

No output schema declared.

No examples provided.

import_data ~305

Create a live mock API from existing artifacts. Auto-detects: OpenAPI 3.x / Swagger 2.0 spec (JSON or YAML) → resources with realistic seeded data, and non-CRUD paths (login, /search, RPC verbs like POST /invoices/{id}/send) become custom routes serving the spec's own examples verbatim; json-server db.json → hosts your exact records; Postman Collection v2.x → resources from requests, saved example responses become records verbatim; HAR (DevTools network export) or VCR/vcrpy cassette YAML → replayable mock of the recorded JSON APIs (these two up to 8 MB); bare JSON array of objects → one hosted collection; CSV/TSV → one typed collection (numbers/booleans inferred per column). Max 512 KB (HAR/cassette 8 MB). Returns {id, adminKey, baseUrl, warnings[], routes[]}.

NameTypeReqDescription
contentstringyesThe raw spec / db.json / collection / CSV text.
namestring–Project name override. Optional.
resourcestring–CSV only: collection name (default items).
seednumber–Records to seed per resource for OpenAPI specs (default 20, max 100).
ttlnumber–Optional: self-expiring project — auto-deletes after this many seconds (60–604800). Sandboxes for CI/eval runs clean themselves up.

No output schema declared.

No examples provided.

inspect_requests ~415

Read the project's request inspector: the most recent requests that hit the mock API (method, path, query, status, origin, captured headers incl. x-* — authorization redacted to its scheme — and a body snippet for writes). Use it to VERIFY what your app / tests / webhook sender actually sent: point code at the mock, run it, then inspect. Pairs with custom_route catch-all bins (e.g. /webhooks/*) for webhook payload + signature debugging. TRAJECTORY ASSERTIONS: filters (method / path / status / status_gte / status_lte / since) return {count} of matches in the retained window, so a grader can assert the agent never called DELETE (method:"DELETE" → count 0), stayed inside /tasks, or produced no 4xx/5xx (status_gte:400 → count 0). Fork per run and the log is exactly one episode's trace. Requires the adminKey, except project "demo" whose inspector is public.

NameTypeReqDescription
adminKeystring–Project adminKey (not needed for demo).
limitnumber–Newest N entries to return (default 20, max 50).
methodstring–Filter: HTTP method, comma-list ok (e.g. "DELETE" or "PUT,PATCH,DELETE").
pathstring–Filter: segment-aware path prefix ("/tasks" matches /tasks and /tasks/5, not /tasksomething).
projectstringyesProject id.
sincestring–Filter: only requests at/after this time (epoch ms or ISO-8601) — record the episode start, assert about only that episode.
statusnumber–Filter: exact response status (comma-list ok as a string via status_gte/lte for ranges).
status_gtenumber–Filter: status >= this (400 = any error).
status_ltenumber–Filter: status <= this.

No output schema declared.

No examples provided.

project_info ~80

Get a project's public root index: every resource with record counts and URLs, custom routes, auth mode, and export links (openapi.json, types.ts, postman.json, db.json, GraphQL). No adminKey needed. Try project "demo" for the shared public playground.

NameTypeReqDescription
projectstringyesProject id (e.g. demo).

No output schema declared.

No examples provided.

query_records ~247

GET records from a mock resource. params is an object of query parameters, all optional: exact filters (field=value), operator suffixes (price_gte, date_lte, name_like, status_ne), full-text q, _sort/_order (or _page/_limit for pagination), select (field projection, e.g. "name,price"), _expand=<parent>/_embed=<children> relations. Failure simulation for testing: mock_status=503 forces that status, mock_delay=2000 adds latency (ms), mock_chaos=0.3 fails that fraction of requests randomly, mock_seq=503,503,200 serves a deterministic status sequence (fail twice then succeed — best for retry tests), mock_jitter=500 adds random latency, mock_envelope=data wraps the response. Pass id to fetch a single record. Defaults to _limit=25 — pass _limit explicitly for more (max 100 per page).

NameTypeReqDescription
idstring–Single record id. Optional.
paramsobject–Query params as key→value. Optional.
projectstringyes–
resourcestringyesResource name (e.g. products).

No output schema declared.

No examples provided.

share_project ~169

Mint (or manage) a READ-ONLY share link for a project: a browser URL you can hand to a human reviewer — they can browse the data, endpoints, snapshots and the live request inspector, but can't write and never see the adminKey. Agent workflow: build or mutate a sandbox, then share_project and give your human the shareUrl to review your work — no key handover. Works even when the project is in protected mode. action "create" returns the existing link if one exists; "rotate" invalidates the old link and mints a new one; "revoke" kills it; "status" just reports.

NameTypeReqDescription
actionstring–Default: create.
adminKeystringyesThe project's adminKey.
projectstringyesProject id.

No output schema declared.

No examples provided.

snapshots ~313

Deterministic test fixtures + eval grading: save the project's entire dataset under a name, restore it exactly later, or DIFF it against live data (list/delete too). action:"diff" is machine-checkable grading — compares the named snapshot (expected) against live data (actual, or another snapshot via against) and returns {identical, summary, resources[] with per-record added/removed/changed field detail}: author an answer-key snapshot, let the agent work the fork, then assert .identical. Any GET can also be served read-only FROM a snapshot without touching live data via query param mock_snapshot=<name> in query_records params — parallel test scenarios on one project.

NameTypeReqDescription
actionstringyes–
adminKeystringyes–
againststring–diff only, optional: compare the named snapshot against THIS other snapshot instead of live data.
dataobject–save only, optional: AUTHOR the snapshot inline instead of capturing live state — {"tasks":[{...records...}],"labels":[]} (records verbatim, ids preserved, [] = expected-empty, new resource names all…
ignorestring–diff only, optional: comma-separated field names excluded from comparison (volatile timestamps etc.), e.g. "updatedAt,id".
namestring–Snapshot name (required for restore/delete/diff; default for save: snapshot-<n>).
projectstringyes–

No output schema declared.

No examples provided.

uptime_monitor ~481

Free downtime alerts for any public URL — no account, armed in one call. action:"create" {url, notify?}: Mockbird GETs the url every 30 minutes from Cloudflare's network (8s timeout, 2xx/3xx = up; a timeout/TLS/DNS blip on an otherwise-up url is confirmed with a same-run retry before it counts); with notify, that webhook gets ONE message when it goes down and ONE when it recovers — debounced (two consecutive checks must agree), so single blips never fire. WITHOUT notify you get a pollable monitor instead — no webhook infrastructure needed. notify formats: hooks.slack.com URLs get {"text"}, discord.com/api/webhooks get {"content"}, anything else gets JSON signed with the returned secret (x-mockbird-signature: sha256=hex(hmac-sha256(secret, body))). The result includes the CURRENT up/down state (checked immediately), a public hostname-only status page /status/:id, an embeddable badge.svg, an Atom feed, and {id, secret} — STORE BOTH; they manage the monitor and cannot be recovered. action:"poll" {id, secret}: (webhook-less monitors) the down/recovered transitions since your last poll plus the latest check — empty events = nothing changed. action:"info" {id, secret}: latest check, 24h ok-rate, recent up/down transitions, alert delivery state. action:"delete" {id, secret}: stop monitoring. Limits: 3 live monitors per IP — deleting one frees the slot immediately (the 429 states the limit); pollable monitors not polled for 30 days are removed. For cron jobs / scheduled tasks use the inverse tool: heartbeat.

NameTypeReqDescription
actionstringyesWhat to do.
idstring–poll/info/delete: the monitor id (mon-…) returned by create.
notifystring–create (optional): the webhook URL to alert (Slack/Discord webhook, or any HTTPS endpoint — gets HMAC-signed JSON). Omit it to get a pollable monitor instead.
secretstring–poll/info/delete: the secret returned by create.
urlstring–create: the public https URL to watch (e.g. https://api.example.com/health).

No output schema declared.

No examples provided.

verdict ~401

One call = the whole eval grade. Composes the state check (snapshot diff vs live data) with trajectory constraints on the request log into a single {pass, checks[]} verdict. Pass snapshot:"expected" to require live data to match that snapshot (author it as the answer key first via snapshots action:"save" with data), and/or trajectory constraints like [{method:"DELETE", count:0}, {method:"POST", path:"/orders", count:1}, {status_gte:400, count:0}] — each needs an expectation: count (exact), min and/or max. Typical harness: fork_project per run → agent works the fork → verdict {snapshot:"expected", trajectory:[...]} → assert .pass → delete_project. Trajectory counts see the retained request window (last 50) — fork per run so the log is exactly one episode's trace. Or pass name to run a SAVED spec (authored via PUT /api/projects/:id/verdicts/:name; forks copy them) — graders without the admin key can run saved specs keylessly via the share link: GET /api/share/:token/verdict/:name.

NameTypeReqDescription
adminKeystringyesThe project's adminKey.
ignorestring–Optional (with snapshot): comma-separated field names excluded from the state comparison, e.g. "updatedAt,createdAt".
namestring–Optional: run a saved verdict spec by name instead of an inline spec (mutually exclusive with snapshot/ignore/trajectory).
projectstringyesProject id.
snapshotstring–Optional: snapshot name to diff live data against — pass means identical.
trajectoryarray–Optional: constraint objects — filters (method comma-list, path segment-prefix, status, status_gte, status_lte, since) + expectation (count exact, min, max). Example: [{"method":"DELETE","count":0}].

No output schema declared.

No examples provided.

watch_service_status ~383

Subscribe to down/recovered alerts for any of the public mock/testing APIs tracked by check_api_status (httpbin, JSONPlaceholder, ReqRes, FakeStoreAPI, DummyJSON …). action:"subscribe" {service, notify?}: service is an id from check_api_status (or "*" for all tracked services). With notify, that webhook gets one message when the service goes down and one when it recovers (debounced across two consecutive hourly checks — blips never fire; a confirmation message is delivered immediately so you can see the wiring works). WITHOUT notify you get a pollable subscription instead — no webhook needed. Returns {id, secret} — store both. action:"poll" {id, secret}: (webhook-less watches) returns the down/recovered transitions since your last poll — empty events = nothing changed; checks run hourly so polling more often sees nothing new. action:"info" {id, secret}: subscription state. action:"unsubscribe" {id, secret}: stop alerts. notify formats: Slack/Discord webhooks get native payloads; anything else gets HMAC-signed JSON. Limits: 5 live watches per IP — deleting one frees the slot immediately. To watch YOUR OWN URL instead, use uptime_monitor.

NameTypeReqDescription
actionstringyesWhat to do.
idstring–poll/info/unsubscribe: the watch id (w…) returned by subscribe.
notifystring–subscribe (optional): webhook URL to alert (Slack/Discord webhook, or any HTTPS endpoint — gets HMAC-signed JSON). Omit it to get a pollable subscription instead.
secretstring–poll/info/unsubscribe: the secret returned by subscribe.
servicestring–subscribe: service id from check_api_status (e.g. "reqres", "httpbin"), or "*" for all tracked services.

No output schema declared.

No examples provided.

write_record ~107

Create, update, or delete records in a mock resource. Writes persist (unlike JSONPlaceholder/FakeStoreAPI). POST creates (auto-id), PUT replaces, PATCH merges, DELETE removes. id required for PUT/PATCH/DELETE.

NameTypeReqDescription
bodyobject–Record fields (POST/PUT/PATCH).
idstring–Record id (PUT/PATCH/DELETE).
methodstringyes–
projectstringyes–
resourcestringyes–

No output schema declared.

No examples provided.

Common questions

What is the Mockbird MCP server?

Mockbird is an MCP server listed in the public MCP registry as dev.workers.mockbird.mockbird/mockbird. Mock REST APIs, fake OAuth2/OIDC provider, uptime monitors + heartbeats, live badge/QR images. This page covers its hosted endpoint (https://mockbird.mockbird.workers.dev/mcp).

Is the Mockbird MCP server safe to use?

Mockbird scores 71 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Mockbird MCP server expose?

Mockbird exposes 19 tools: create_project, import_data, fork_project, add_resource, project_info, and 14 more. Their descriptions and schemas cost roughly 6,140 tokens of context every time the server is loaded.

Does the Mockbird MCP server require authentication?

No. We connected to Mockbird without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the Mockbird MCP server still maintained?

Mockbird is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.