ToolRouter
REMOTE · API.TOOLROUTER.COM · SCANNED SEP 21
The OpenRouter for tools. One MCP connection gives any AI agent 254 hosted tools, pay per call.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security94
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents. View diagnostics → Partial
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability71
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 6181 tokens (~128/item across 48 items; 48 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management57
- Stability observed for 17 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 6 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 49 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the ToolRouter MCP server?
ToolRouter is a hosted endpoint at https://api.toolrouter.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · api.toolrouter.com
claude mcp add --transport http humanleap-toolrouter 'https://api.toolrouter.com/mcp'
{
"mcpServers": {
"humanleap-toolrouter": {
"url": "https://api.toolrouter.com/mcp"
}
}
} {
"servers": {
"humanleap-toolrouter": {
"type": "http",
"url": "https://api.toolrouter.com/mcp"
}
}
} [mcp_servers.humanleap-toolrouter] url = "https://api.toolrouter.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"humanleap-toolrouter": {
"type": "remote",
"url": "https://api.toolrouter.com/mcp",
"enabled": true
}
}
} openclaw mcp add humanleap-toolrouter --url 'https://api.toolrouter.com/mcp' --transport streamable-http
mcp_servers:
humanleap-toolrouter:
url: "https://api.toolrouter.com/mcp" {
"McpServers": {
"humanleap-toolrouter": {
"Transport": "http",
"Url": "https://api.toolrouter.com/mcp"
}
}
} assistant mcp add humanleap-toolrouter -t streamable-http -u 'https://api.toolrouter.com/mcp'
{
"mcpServers": {
"humanleap-toolrouter": {
"type": "http",
"url": "https://api.toolrouter.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 50 to 53. That category is still filling its 30-day observation window: 15 days of observed history at the previous scan, 16 at this one. The score rises as the window fills, whether or not the server changes.
- 19 Sept 26 0
- Tool “discover” rewrote its description, which is the text the model reads security
- Tool “use_tool” rewrote its description, which is the text the model reads security
- New tool “route” functional
- 18 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 43 to 47. That category is still filling its 30-day observation window: 13 days of observed history at the previous scan, 14 at this one. The score rises as the window fills, whether or not the server changes.
- 15 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 33 to 37. That category is still filling its 30-day observation window: 10 days of observed history at the previous scan, 11 at this one. The score rises as the window fills, whether or not the server changes.
- 13 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 27 to 30. That category is still filling its 30-day observation window: 8 days of observed history at the previous scan, 9 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.
- 9 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 13 to 17. That category is still filling its 30-day observation window: 4 days of observed history at the previous scan, 5 at this one. The score rises as the window fills, whether or not the server changes.
- 7 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 21 Sept 2026 · Probed https://api.toolrouter.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=api.toolrouter.com | CN=YR1,O=Let's Encrypt,C=US | 11 Sept 2026 | 10 Dec 2026 | RSA 2048 | SHA256-RSA | 52b4609be36503738ad28d042bfe188155c |
| SANs: api.toolrouter.com | ||||||
| CN=YR1,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | a20253f15f2691c05dc1ce13b9bcca4e |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of api.toolrouter.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| toolrouter.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer resource_metadata="https://api.toolrouter.com/.well-known/oauth-protected-resource/mcp"
Bearer resource_metadata="https://api.toolrouter.com/.well-known/oauth-protected-resource/mcp" | Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(), geolocation=() |
Protected resource metadata
| Document | https://api.toolrouter.com/.well-known/oauth-protected-resource/mcp |
|---|---|
| Retrieved | Yes |
| Resource | https://api.toolrouter.com/mcp |
| Authorisation server | https://api.toolrouter.com/ |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://api.toolrouter.com/mcp | Verified | 200 | |
| http (plaintext) | http://api.toolrouter.com/mcp | HTTPS enforced | 301 | https://api.toolrouter.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
account_list List Accounts & Teams ~75
List all billing contexts (personal + teams) or get detail on one. No slug → summary list. With slug → full detail including team members, role, subscription status, and pointers to the team's connectors, credentials, keys, and files.
| Name | Type | Req | Description |
|---|---|---|---|
| slug | string | – | Account slug for detail view. Omit to list all. |
No output schema declared.
No examples provided.
account_preferences Account Preferences ~175
Read or write billing preferences (auto-reload, budget cap, default context). Pass action: "get" to read, action: "set" with fields to write.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | "get" to read preferences, "set" to update them. |
| auto_reload_amount | number | – | Amount (USD) to reload when triggered (set only, max 500). |
| auto_reload_enabled | boolean | – | Enable or disable auto-reload (set only). |
| auto_reload_threshold | number | – | Balance threshold (USD) that triggers a reload (set only). |
| budget_limit | number|null | – | Monthly spending cap in USD, or null to remove (set only). |
| default_billing_context | string | – | Default account to bill (set only). "personal" or "team:<id>". |
No output schema declared.
No examples provided.
account_setup Set Up Account ~54
Initialize or re-check your account, provision it when needed, and return your user ID and plan. CALL THIS FIRST when the user asks to set up ToolRouter, connect their account, check their account status, or get started.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
account_switch Switch Account ~66
Set the active billing context. Accepts a slug (e.g. "personal", "team:nd7fx…") or team ID.
| Name | Type | Req | Description |
|---|---|---|---|
| context | string | yes | Account slug or team ID to switch to (e.g. "personal", "team:nd7fx…"). |
No output schema declared.
No examples provided.
brain_add Add to brain ~231
Create a new brain page. Knowledge you add here will be available to all future tool calls. Optional wing/room/hall organise the page in the MemPalace hierarchy for sharper retrieval.
| Name | Type | Req | Description |
|---|---|---|---|
| content | string | yes | Page content (markdown) |
| hall | string | – | Optional. One of "fact", "event", "discovery", "preference", "advice". Defaults to "fact". |
| load_tier | string | – | Optional. L0 = operator identity (rare), L1 = always-loaded critical fact, L2 = default on-demand, L3 = cold archive. Omit to default to L2. |
| room | string | – | Optional. Sub-area within the wing (e.g. "databases", "deploy"). Defaults to "untagged". |
| scope | string | – | Visibility scope. Defaults to personal. |
| tags | array | – | Tags for categorisation |
| title | string | yes | Page title |
| wing | string | – | Optional. Top-level area (e.g. "engineering", "family", "general"). Auto-classified if omitted. |
No output schema declared.
No examples provided.
brain_admin Brain Admin ~269
Brain admin operations. Pass action: "lint" | "link" | "promote" | "rebuild_index" | "team_sleep". team_sleep enables/disables/runs the nightly team consolidation cycle — pass sub_action "enable" (with optional timezone), "disable", "status", or "run_now". Team admin role required for team_sleep actions.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | Admin operation to perform. |
| label | string | – | Human-readable relationship label (for link). |
| page_id | string | – | Source brain page ID (for link/promote). |
| relationship | string | – | Relationship type (for link, e.g. relates_to, derived_from). |
| sub_action | string | – | Required for action="team_sleep". "enable" turns on nightly sleep for the team; "disable" turns it off; "status" shows last run and schedule; "run_now" triggers an immediate sleep cycle. |
| team_id | string | – | Team to promote to (for promote). Auto-resolved if on one team. |
| timezone | string | – | IANA timezone for team_sleep enable (e.g. "Europe/London"). Defaults to UTC. Sleep fires at 3 AM local time. |
| to_page_id | string | – | Target page ID (for link). |
No output schema declared.
No examples provided.
brain_delete Delete brain page ~41
Archive a brain page. It will no longer appear in searches or tool consultations.
| Name | Type | Req | Description |
|---|---|---|---|
| page_id | string | yes | Brain page ID (bp_...) to archive |
No output schema declared.
No examples provided.
brain_expand Expand brain page (reveal raw source) ~95
Retrieve the verbatim source text (a "drawer") linked from a brain page. Use this when a summary lacks specifics you need — drawers contain the original tool output, redacted for credentials. Returns 404 if the page has no linked drawer (not all pages do — drawers are a Step 4 feature for allowlisted tools only).
| Name | Type | Req | Description |
|---|---|---|---|
| page_id | string | yes | Brain page ID (bp_...) whose drawer to expand. |
No output schema declared.
No examples provided.
brain_lint Brain lint ~28
Run maintenance checks on your brain: find stale pages, orphaned knowledge, and other issues.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
brain_query Search brain ~259
Search your knowledge brain for relevant information. Returns pages ranked by relevance. Optional wing/hall narrow the search to a slice of the brain (e.g. wing="engineering", hall="preference").
| Name | Type | Req | Description |
|---|---|---|---|
| as_of | string | – | Optional. ISO-date string (e.g. "2026-01-15"). When set, returns pages that were valid at that point in time — including superseded versions. Useful for "what did we know in January?" queries. |
| hall | string | – | Optional. Restrict to a hall: "fact", "event", "discovery", "preference", or "advice". |
| include_drawer_previews | boolean | – | Optional. When true, each result includes the first ~400 chars of its linked drawer (raw source text) if one exists. Useful to decide whether to call brain_expand for the full text. |
| limit | number | – | Max results. Defaults to 10. |
| query | string | – | Search query. Omit to list all pages by recency. |
| scope | string | – | Which brain scope to search. Defaults to all. |
| wing | string | – | Optional. Restrict to a specific wing (top-level area like "engineering", "family"). |
No output schema declared.
No examples provided.
brain_settings Brain settings ~88
View and toggle your brain settings. Currently supports: drawers_enabled (store raw tool output alongside summaries for richer recall).
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | "get" lists current settings; "set" toggles a named setting. |
| setting | string | – | Setting name (required for "set"). Currently: "drawers_enabled". |
| value | boolean | – | New value (required for "set"). |
No output schema declared.
No examples provided.
brain_status Brain status ~22
View brain page counts and recent pages for your personal and team brain.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
brain_update Update brain page ~298
Edit an existing brain page's content or metadata. wing/room/hall can be patched to re-file a page. scope can be changed to move a page between your personal and team brain — useful when an auto-ingested page landed in the wrong place. Moving a page to team scope requires team admin role.
| Name | Type | Req | Description |
|---|---|---|---|
| content | string | – | New content (replaces existing) |
| hall | string | – | Optional. Change hall: fact / event / discovery / preference / advice. |
| load_tier | string | – | Optional. Change load tier. L1 promotes a page to always-loaded; L3 sends it to cold archive. |
| material_change | boolean | – | Optional. When true, creates a new version of the page — the old version is preserved with a timestamp and a "supersedes" link. Use for corrections or significant changes; skip for minor edits. Defau… |
| page_id | string | yes | Brain page ID (bp_...) |
| room | string | – | Optional. Re-file under a different room. |
| scope | string | – | Optional. Move the page between your personal and team brain. Moving TO team requires team admin role and a team billing context. Moving FROM team to personal is allowed if you own the page or are an… |
| tags | array | – | New tags |
| title | string | – | New title |
| wing | string | – | Optional. Re-file under a different wing. |
No output schema declared.
No examples provided.
brain_wings List brain wings ~92
List the wings of your brain — the top-level areas your knowledge is organised under (e.g. "engineering", "family"). For each wing returns the rooms and halls inside, page count, and last-updated time. Use this to discover the right wing/hall to pass to brain_query.
| Name | Type | Req | Description |
|---|---|---|---|
| include_team | boolean | – | If true, also count team-scope pages. Default false (personal only). |
No output schema declared.
No examples provided.
connector_add Add Connector ~224
Connect a new OAuth account or MCP server. For OAuth: pass type: "oauth", kind: "slack". For MCP catalog: pass catalog_slug. For custom MCP: pass url + auth_type.
| Name | Type | Req | Description |
|---|---|---|---|
| auth_token | string | – | Auth token or API key. |
| auth_type | string | – | Auth type (custom MCP). Default: none. |
| billing | string | – | Scope: "personal" (default), "team" (auto-resolves), a team slug, or "team:<id>". |
| catalog_slug | string | – | MCP catalog slug for one-click connect. |
| display_name | string | – | Human-readable name (custom MCP). |
| header_name | string | – | Custom header name (for header_key auth). |
| kind | string | – | OAuth connector kind (e.g. "slack", "notion"). Required for type: "oauth". |
| slug | string | – | Short identifier for the connection. |
| type | string | – | Type of connector to add. |
| url | string | – | MCP server endpoint URL (custom MCP). |
No output schema declared.
No examples provided.
connector_list List Connectors ~137
List connected accounts and MCP servers (summary) or detail on one connector. Pass slug for detail including every tool the connector exposes. Optional type: "oauth" | "mcp" filter. Pass include_available: true to also see available catalog MCPs you can connect.
| Name | Type | Req | Description |
|---|---|---|---|
| context | string | – | Scope: "personal" (default) or "team:<id>" for a team. |
| include_available | boolean | – | When true, also include catalog MCPs you have not connected yet. |
| slug | string | – | Connector slug for detail view. Omit to list all. |
| type | string | – | Filter by connector type. |
No output schema declared.
No examples provided.
connector_permissions Connector Permissions ~423
View or set permissions for tools on a connected MCP server — which tools are allowed, rate limits, budget caps, argument restrictions. Pass the connector slug (from connector_list) and action: "list" to see current rules, or action: "set" with tool_name + rules to update one. Team scope requires admin role.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | – | Omit to list permissions for all tools. Pass "set" with tool_name + rules to update one. |
| allowed | boolean | – | Whether the tool is allowed (for set). |
| arg_natural_language_rules | string | – | Plain English rules for argument filtering (for set). Example: "Only allow queries for the last 90 days." |
| arg_schema_rules | string | – | JSON Schema validating tool arguments (for set). Example: {"properties":{"channel":{"enum":["#general"]}}} |
| billing | string | – | Scope: "personal", "team" (auto-resolves if on one team), a team slug, or "team:<id>". |
| budget_per_day | number | – | Max daily spend per user, in millicents (for set). |
| cost_per_call | number | – | Cost in millicents per call (for set). |
| nl_filter_mode | string | – | How to enforce NL rules: strict (block on violation) or advisory (log only). Default: strict. |
| rate_limit_per_day | number | – | Max calls per day, per user (for set). |
| rate_limit_per_hour | number | – | Max calls per hour, per user (for set). |
| slug | string | yes | Connector slug. |
| team_budget_per_day | number | – | Max daily spend team-wide, in millicents (for set). |
| team_rate_limit_per_day | number | – | Max calls per day, team-wide (for set). |
| team_rate_limit_per_hour | number | – | Max calls per hour, team-wide (for set). |
| tool_name | string | – | Tool name (for set). Use "*" for all tools on this connector. |
No output schema declared.
No examples provided.
connector_remove Remove Connector ~79
Disconnect a connector. Pass slug.
| Name | Type | Req | Description |
|---|---|---|---|
| billing | string | – | Scope: "personal" (default), "team" (auto-resolves), a team slug, or "team:<id>". |
| slug | string | yes | Connector slug to disconnect. |
| type | string | – | Type of connector (mcp or oauth). Default: mcp. |
No output schema declared.
No examples provided.
credential_default Set Default Credential ~74
Set the default value for a multi-value credential.
| Name | Type | Req | Description |
|---|---|---|---|
| context | string | – | "personal" or "team:<id>". Defaults to personal. |
| label | string | yes | Label of the entry to make default (e.g. "Production"). |
| name | string | yes | Credential name (e.g. "ios_app_id"). |
No output schema declared.
No examples provided.
credential_delete Delete Credential ~99
Remove a saved credential. If label is provided, removes only that specific entry. If no label, removes ALL entries for that credential name.
| Name | Type | Req | Description |
|---|---|---|---|
| context | string | – | "personal" or "team:<id>". Defaults to personal. |
| label | string | – | Label of the specific entry to delete. Omit to remove all entries for this credential name. |
| name | string | yes | Credential name to delete (e.g. "ios_app_id"). |
No output schema declared.
No examples provided.
credential_guide Credential Setup Guide ~43
Get setup instructions for a specific credential.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Credential name (e.g. "ios_app_id", "play_store_app_id", "domain"). |
No output schema declared.
No examples provided.
credential_list List Credentials ~95
List saved credentials (summary) or detail on one. Pass name for detail view. Pass show_available: true to include the full credential catalog.
| Name | Type | Req | Description |
|---|---|---|---|
| context | string | – | "personal" or "team:<id>". Defaults to personal. |
| name | string | – | Credential name for detail view. Omit to list all saved. |
| show_available | boolean | – | Include the full catalogue of available BYOK options. Default false. |
No output schema declared.
No examples provided.
credential_save Save Credential ~136
Save a credential (BYOK provider API key). Saved keys persist across sessions and are used automatically.
| Name | Type | Req | Description |
|---|---|---|---|
| context | string | – | "personal" or "team:<id>". Defaults to personal. |
| is_default | boolean | – | Set this value as the default for this credential. |
| label | string | – | Human-readable label to identify this value (e.g. "MyApp", "Staging"). Required when saving multiple values for the same credential. |
| name | string | yes | Credential name from the tool requirements (e.g. "ios_app_id", "openai"). |
| value | string | yes | The credential value to save. |
No output schema declared.
No examples provided.
credits_balance Credits Balance ~28
Current balance, plan tier, rate limits, and any negative-balance warnings for the active context.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
credits_usage Credits Usage ~161
Usage summary or history. Pass scope: "me" | "team" and detail: "tool" | "skill". Sorted by cost with _others rollup.
| Name | Type | Req | Description |
|---|---|---|---|
| detail | string | – | Detail level. "tool" groups by tool, "skill" adds per-skill breakdown. |
| limit | number | – | Number of top tools/skills to return. Remaining rolled into "_others". Default 10. |
| offset | number | – | Records to skip for pagination (history mode). Default 0. |
| period | string | – | Time period to summarize. 'all' covers the last 30 days (the maximum window). |
| scope | string | – | Whose usage to show. "me" for personal, "team" for team-wide. |
No output schema declared.
No examples provided.
discover Discover Tools ~235
Find the right ToolRouter tool for your task. Describe what you need in plain language. Examples: "analyze a website", "research competitors", "find prospect companies", "check DNS records". Exact tool name (e.g. "seo") returns full schemas and examples. Flow: prefer route({ intent }) to pick and run a tool. Use discover when you need schemas or a listing, then call use_tool(tool, skill, input). Every discover response also includes a top-level `connectors` array listing SaaS accounts the user has already connected (LinkedIn, Google, Notion, etc.). Use that to pick the right tool and account without asking — e.g. if `connectors` shows LinkedIn, the linkedin-post tool is ready to use. Categories: data, media, search, marketing, development, communication, analytics, productivity, ai, finance, security, infrastructure
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | – | Filter by category |
| query | string | yes | What you want to do (e.g. "scrape a webpage"), a category (e.g. "security"), or "*" to list everything. |
No output schema declared.
No examples provided.
feedback_debug Report a Bug ~409
Report a ToolRouter platform bug that blocks you from completing the user's task. Use this when you suspect the issue is on our side — a tool crashed, returned malformed data, timed out unexpectedly, or behaved inconsistently. Include the relevant ToolRouter errors, call IDs, non-sensitive input shape, retries, and expected behavior. Do not include chat history, unrelated conversation text, uploaded file contents, personal data, API keys, or secrets. Reports are stored and reviewed within hours. Skip this for expected errors like invalid input, missing credentials, insufficient balance, rate limits, or genuine "not found" results — those aren't bugs. Limit: 5 reports per hour.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_context | string | – | MCP client name and version, if known. |
| call_ids | string | – | ALL call IDs from this interaction (successful and failed), one per line or comma-separated. |
| error_messages | string | yes | ALL error messages received during this interaction — not just the last one. Include the full text of every error response from ToolRouter, separated by newlines. |
| expected_behavior | string | – | What you expected to happen vs what actually happened. |
| input_summary | string | – | Summary of what you sent to the failing tool (do NOT include API keys or secrets — describe the shape and intent). |
| interaction_log | string | – | Chronological log limited to the relevant ToolRouter calls: tool/skill names, non-sensitive input shape, response status, errors, retries, and job polling. Do not include chat history, unrelated conv… |
| job_id | string | – | Job ID for async jobs that failed, if applicable. |
| severity | string | yes | "blocking" = cannot complete task. "degraded" = partial results or workaround exists. |
| skill | string | – | Skill name that failed (e.g. "search"). |
| tool | string | – | Tool name that failed (e.g. "web-search"). |
No output schema declared.
No examples provided.
feedback_request_tool Request a Tool ~152
Ask ToolRouter to build a tool that does not exist yet. Use this when discover returned nothing useful for what the user needs. Describe the capability in plain terms — do not include personal data, API keys, or secrets. Requests go straight to the team. Limit: 5 per hour.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_context | string | – | MCP client name and version, if known. |
| searched | string | – | The discover query you tried that came back empty. |
| what | string | yes | What the tool should do, in one or two sentences (e.g. "Look up UK company filings by company number"). |
| why | string | – | What the user was trying to accomplish and why existing tools did not fit. |
No output schema declared.
No examples provided.
feedback_review Submit Review ~84
Submit a review or star rating.
| Name | Type | Req | Description |
|---|---|---|---|
| rating | number | yes | Star rating 1-5 (1=poor, 3=okay, 5=excellent). |
| review | string | – | Constructive feedback — what worked well and any specific suggestions to improve. |
| tool | string | yes | Tool name to review (e.g. "web-search" or "seo"). |
No output schema declared.
No examples provided.
file_delete Delete File ~38
Delete a file. Cannot be undone. For team files: requires owner/admin role.
| Name | Type | Req | Description |
|---|---|---|---|
| file_id | string | yes | The file ID to delete. |
No output schema declared.
No examples provided.
file_list List Files ~163
List or search files. Optional query triggers semantic search. Supports section, tags, plan_status, limit, cursor filters.
| Name | Type | Req | Description |
|---|---|---|---|
| context | string | – | "personal" (default) or "team:<id>". |
| cursor | string | – | Pagination cursor from a previous file_list response. |
| limit | number | – | Max results (default 20, max 50). |
| plan_status | string | – | Filter plans by status. |
| prompt_type | string | – | Filter prompts by type (only valid when section is "prompts"). |
| query | string | – | Natural language search query. Omit to browse. |
| section | string | – | Filter by section. Omit to list all. |
| tags | array | – | Filter to files matching ALL of these tags. |
No output schema declared.
No examples provided.
file_read Read File ~63
Read a file's full content. Text files return content inline. Binary files (images, video) return a download URL.
| Name | Type | Req | Description |
|---|---|---|---|
| file_id | string | yes | The file ID (e.g. "ast_a1b2c3d4e5f67890"). |
No output schema declared.
No examples provided.
file_write Write File ~341
Create or update a file. Pass mode: "create" | "update". Binary uploads: call with binary: true to get an upload_url, then PUT bytes, then call with mode: "finalize".
| Name | Type | Req | Description |
|---|---|---|---|
| asset_id | string | – | Existing asset ID to retrieve URL without re-uploading. |
| content | string | – | Text content (for .md files). |
| content_type | string | – | MIME type. Defaults to "text/markdown" for content, "image/png" for file_data. |
| context | string | – | "personal" (default) or "team:<id>". |
| description | string | – | Optional summary (max 500 chars). |
| file_data | string | – | Base64-encoded binary data (for images, video). |
| file_id | string | – | File ID to update (required for update/finalize). |
| filename | string | – | Optional filename for the asset. |
| image_data | string | – | Base64-encoded image. Alternative to image_url when the bytes are already local. |
| image_url | string | – | Public URL to download and host permanently. |
| mode | string | yes | "create" for new files, "update" to edit existing, "finalize" to complete a binary upload. |
| name | string | – | File name (required for create, max 200 chars). |
| plan_status | string | – | Plan status (only for plans section). |
| prompt_meta | object | – | Prompt metadata (only for prompts section). |
| section | string | – | Which section to file under (required for create). |
| tags | array | – | Tags for organization (max 10). |
No output schema declared.
No examples provided.
invoice_list List Invoices ~36
List invoices for the active billing context.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | Number of invoices to return (default 10, max 20). |
No output schema declared.
No examples provided.
job_cancel Cancel Job ~26
Cancel a running job.
| Name | Type | Req | Description |
|---|---|---|---|
| job_id | string | yes | The job ID to cancel. |
No output schema declared.
No examples provided.
job_get Get Job ~55
Get job status and result. Returns status: running | completed | failed and result when terminal. Keep polling until you get a terminal status.
| Name | Type | Req | Description |
|---|---|---|---|
| job_id | string | yes | The job ID returned when a long-running tool was called. |
No output schema declared.
No examples provided.
job_list List Jobs ~49
List your active and recent jobs. Optional status filter.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | Max jobs to return (default 20, max 100). |
| status | string | – | Filter by job status. |
No output schema declared.
No examples provided.
key_create Create API Key ~47
Create a new API key. Returns the secret once — save it immediately.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | A name to identify this key (e.g. "Claude Desktop", "Production Bot"). |
No output schema declared.
No examples provided.
key_delete Delete API Key ~42
Revoke an API key. Refuses to revoke the currently-authenticating key.
| Name | Type | Req | Description |
|---|---|---|---|
| key_id | string | yes | The key ID to revoke (from key_list). |
No output schema declared.
No examples provided.
key_list List API Keys ~47
List API keys (summary) or get detail on one key. Pass key_id for detail view.
| Name | Type | Req | Description |
|---|---|---|---|
| key_id | string | – | Key ID for detail view. Omit to list all. |
No output schema declared.
No examples provided.
outfit_list List Outfits ~31
List your outfits.
| Name | Type | Req | Description |
|---|---|---|---|
| context | string | – | "personal" (default) or "team:<id>". |
No output schema declared.
No examples provided.
persona_list List Personas ~31
List your personas.
| Name | Type | Req | Description |
|---|---|---|---|
| context | string | – | "personal" (default) or "team:<id>". |
No output schema declared.
No examples provided.
product_list List Products ~31
List your products.
| Name | Type | Req | Description |
|---|---|---|---|
| context | string | – | "personal" (default) or "team:<id>". |
No output schema declared.
No examples provided.
route Route Intent ~203
Send a natural-language intent and optionally any dimensions you already know (tool, skill, model, input fields). Fills only the blanks via Jev, then either executes the call or returns a ready-to-run use_tool payload. Explicit values are never overridden. Returns candidates when confidence is low or no tool fits. Flow: route → if confident and complete, result is returned; otherwise use the pre-filled call with use_tool.
| Name | Type | Req | Description |
|---|---|---|---|
| input | object | – | Optional. Partial skill input — explicit fields are never overridden. |
| intent | string | yes | What you want to do, in plain language. |
| max_cost | number | – | Optional. Max USD to spend; above this returns a pre-filled call instead of executing. |
| model | string | – | Optional. Model override — honoured verbatim when set. |
| skill | string | – | Optional. Skill name — honoured verbatim when set. |
| tool | string | – | Optional. Tool name — honoured verbatim when set. |
No output schema declared.
No examples provided.
scene_list List Scenes ~31
List your scenes.
| Name | Type | Req | Description |
|---|---|---|---|
| context | string | – | "personal" (default) or "team:<id>". |
No output schema declared.
No examples provided.
subscription_manage Manage Subscription ~78
Get a Stripe management URL (portal, upgrade, or cancel). Also covers billing portal — returns the URL for the user to open.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | "subscribe" to start a subscription, "manage" to view/cancel existing subscription. |
| tier | string | – | Which plan to subscribe to (required for "subscribe" action). |
No output schema declared.
No examples provided.
top_up_credits Top Up Credits ~65
Add credits to your account. Returns a Stripe checkout URL — share it with the user to complete payment. Minimum $1.
| Name | Type | Req | Description |
|---|---|---|---|
| amount_usd | number | yes | Amount in USD to add (e.g. 10, 25, 50). Minimum $1. |
No output schema declared.
No examples provided.
use_tool Use Tool ~594
Call a ToolRouter catalogue tool. Prefer `route` with a natural-language intent when you do not already know the tool and skill — it picks them, fills arguments, and runs the call. Use discover when you need schemas or a catalogue listing, then pass the exact tool name and skill here. IMPORTANT: "discover", "route", "credits_balance", and other built-in tools are NOT catalogue tools — call them directly, never through use_tool. Long-running tools return a job_id — poll with job_get. If a skill needs an image_url or file URL and you have a local file or base64 image, use file_write first to get a hosted URL, then pass that URL to the skill. BRAIN: Some tools require you to consult brain_query first. If use_tool returns an error about brain_context, call brain_query with a relevant query, then pass the result text as brain_context in your use_tool input.
| Name | Type | Req | Description |
|---|---|---|---|
| backend | object | – | Route the same model through interchangeable providers. order prioritises providers; only restricts; ignore excludes; allow_fallbacks defaults true. |
| billing | string | – | Which account to bill. "personal", "team" (auto-resolves if on one team), a team slug ("humanleap"), or a team ID ("team:m57df8c..."). Omit to use your default. |
| brain_context | string | – | Brain knowledge from brain_query. Pass at the top level of use_tool (alongside "tool", "skill", "input") — NOT inside input. Call brain_query first, then paste the result text here to clear the brain… |
| input | object | yes | Skill input parameters (see discover for schema). For persona-using tools, include persona_file_id from discover or persona_list. For scene-using tools, include scene_file_id from discover or scene_l… |
| response_format | string | – | Response verbosity. "concise" (default) strips noise, returns essential data only. "detailed" returns everything including raw metadata. |
| skill | string | yes | Skill name from discover results, e.g. "search" |
| tool | string | yes | Tool reference from discover results, e.g. "web-search" |
No output schema declared.
No examples provided.
What is the ToolRouter MCP server?
ToolRouter is an MCP server listed in the public MCP registry as io.github.Humanleap/toolrouter. The OpenRouter for tools. One MCP connection gives any AI agent 254 hosted tools, pay per call. This page covers its hosted endpoint (https://api.toolrouter.com/mcp).
Is the ToolRouter MCP server safe to use?
ToolRouter scores 86 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the ToolRouter MCP server expose?
ToolRouter exposes 48 tools: account_setup, account_list, account_switch, account_preferences, credits_balance, and 43 more. Their descriptions and schemas cost roughly 6,143 tokens of context every time the server is loaded.
Does the ToolRouter MCP server require authentication?
Yes. ToolRouter asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the ToolRouter MCP server still maintained?
ToolRouter is still listed as active in the MCP registry. We last reached this channel on 21 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.