Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

ToolRouter

REMOTE · API.TOOLROUTER.COM · SCANNED SEP 21

The OpenRouter for tools. One MCP connection gives any AI agent 254 hosted tools, pay per call.

+3 this week 86 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security94
Transport & Reachability100
Schema Quality & AI Usability71
  • AI-judged instruction clarity (good).Pass
  • Context-footprint check failed: tool/resource definitions use about 6181 tokens (~128/item across 48 items; 48 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management57
  • Stability observed for 17 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 6 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • An AI judge read all 49 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

How do I install the ToolRouter MCP server?

ToolRouter is a hosted endpoint at https://api.toolrouter.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · api.toolrouter.com

# add to Claude Code
claude mcp add --transport http humanleap-toolrouter 'https://api.toolrouter.com/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "humanleap-toolrouter": {
      "url": "https://api.toolrouter.com/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "humanleap-toolrouter": {
      "type": "http",
      "url": "https://api.toolrouter.com/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.humanleap-toolrouter]
url = "https://api.toolrouter.com/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "humanleap-toolrouter": {
      "type": "remote",
      "url": "https://api.toolrouter.com/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add humanleap-toolrouter --url 'https://api.toolrouter.com/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  humanleap-toolrouter:
    url: "https://api.toolrouter.com/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "humanleap-toolrouter": {
      "Transport": "http",
      "Url": "https://api.toolrouter.com/mcp"
    }
  }
}
# add to Vellum
assistant mcp add humanleap-toolrouter -t streamable-http -u 'https://api.toolrouter.com/mcp'
// mcp.json
{
  "mcpServers": {
    "humanleap-toolrouter": {
      "type": "http",
      "url": "https://api.toolrouter.com/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 20 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 50 to 53. That category is still filling its 30-day observation window: 15 days of observed history at the previous scan, 16 at this one. The score rises as the window fills, whether or not the server changes.

  • 19 Sept 26 0
    • Tool “discover” rewrote its description, which is the text the model reads security
    • Tool “use_tool” rewrote its description, which is the text the model reads security
    • New tool “route” functional
  • 18 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 43 to 47. That category is still filling its 30-day observation window: 13 days of observed history at the previous scan, 14 at this one. The score rises as the window fills, whether or not the server changes.

  • 15 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 33 to 37. That category is still filling its 30-day observation window: 10 days of observed history at the previous scan, 11 at this one. The score rises as the window fills, whether or not the server changes.

  • 13 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 27 to 30. That category is still filling its 30-day observation window: 8 days of observed history at the previous scan, 9 at this one. The score rises as the window fills, whether or not the server changes.

  • 11 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.

  • 9 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 13 to 17. That category is still filling its 30-day observation window: 4 days of observed history at the previous scan, 5 at this one. The score rises as the window fills, whether or not the server changes.

  • 7 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 21 Sept 2026 · Probed https://api.toolrouter.com/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=api.toolrouter.com CN=YR1,O=Let's Encrypt,C=US 11 Sept 2026 10 Dec 2026 RSA 2048 SHA256-RSA 52b4609be36503738ad28d042bfe188155c
SANs: api.toolrouter.com
CN=YR1,O=Let's Encrypt,C=US (CA) CN=Root YR,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 RSA 2048 SHA256-RSA a20253f15f2691c05dc1ce13b9bcca4e
CN=Root YR,O=ISRG,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 RSA 4096 SHA256-RSA f24b6d17f9d9ad7cb1c9fea78782699f

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of api.toolrouter.com. Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
toolrouter.com. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication Enforced and verified

The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.

Result Enforced and verified
Enforced On tool calls
HTTP status 200

WWW-Authenticate challenge Bearer resource_metadata="https://api.toolrouter.com/.well-known/oauth-protected-resource/mcp"

Bearer resource_metadata="https://api.toolrouter.com/.well-known/oauth-protected-resource/mcp"
Header Value
strict-transport-security max-age=63072000; includeSubDomains; preload
x-content-type-options nosniff
x-frame-options DENY
referrer-policy strict-origin-when-cross-origin
permissions-policy camera=(), microphone=(), geolocation=()

Protected resource metadata

Document https://api.toolrouter.com/.well-known/oauth-protected-resource/mcp
Retrieved Yes
Resource https://api.toolrouter.com/mcp
Authorisation server https://api.toolrouter.com/

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://api.toolrouter.com/mcp Verified 200
http (plaintext) http://api.toolrouter.com/mcp HTTPS enforced 301 https://api.toolrouter.com/mcp
MCP tools · 48 exposed · ~6,143 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
account_list ~75

List all billing contexts (personal + teams) or get detail on one. No slug → summary list. With slug → full detail including team members, role, subscription status, and pointers to the team's connectors, credentials, keys, and files.

NameTypeReqDescription
slugstringAccount slug for detail view. Omit to list all.

No output schema declared.

No examples provided.

account_preferences ~175

Read or write billing preferences (auto-reload, budget cap, default context). Pass action: "get" to read, action: "set" with fields to write.

NameTypeReqDescription
actionstringyes"get" to read preferences, "set" to update them.
auto_reload_amountnumberAmount (USD) to reload when triggered (set only, max 500).
auto_reload_enabledbooleanEnable or disable auto-reload (set only).
auto_reload_thresholdnumberBalance threshold (USD) that triggers a reload (set only).
budget_limitnumber|nullMonthly spending cap in USD, or null to remove (set only).
default_billing_contextstringDefault account to bill (set only). "personal" or "team:<id>".

No output schema declared.

No examples provided.

account_setup ~54

Initialize or re-check your account, provision it when needed, and return your user ID and plan. CALL THIS FIRST when the user asks to set up ToolRouter, connect their account, check their account status, or get started.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

account_switch ~66

Set the active billing context. Accepts a slug (e.g. "personal", "team:nd7fx…") or team ID.

NameTypeReqDescription
contextstringyesAccount slug or team ID to switch to (e.g. "personal", "team:nd7fx…").

No output schema declared.

No examples provided.

brain_add ~231

Create a new brain page. Knowledge you add here will be available to all future tool calls. Optional wing/room/hall organise the page in the MemPalace hierarchy for sharper retrieval.

NameTypeReqDescription
contentstringyesPage content (markdown)
hallstringOptional. One of "fact", "event", "discovery", "preference", "advice". Defaults to "fact".
load_tierstringOptional. L0 = operator identity (rare), L1 = always-loaded critical fact, L2 = default on-demand, L3 = cold archive. Omit to default to L2.
roomstringOptional. Sub-area within the wing (e.g. "databases", "deploy"). Defaults to "untagged".
scopestringVisibility scope. Defaults to personal.
tagsarrayTags for categorisation
titlestringyesPage title
wingstringOptional. Top-level area (e.g. "engineering", "family", "general"). Auto-classified if omitted.

No output schema declared.

No examples provided.

brain_admin ~269

Brain admin operations. Pass action: "lint" | "link" | "promote" | "rebuild_index" | "team_sleep". team_sleep enables/disables/runs the nightly team consolidation cycle — pass sub_action "enable" (with optional timezone), "disable", "status", or "run_now". Team admin role required for team_sleep actions.

NameTypeReqDescription
actionstringyesAdmin operation to perform.
labelstringHuman-readable relationship label (for link).
page_idstringSource brain page ID (for link/promote).
relationshipstringRelationship type (for link, e.g. relates_to, derived_from).
sub_actionstringRequired for action="team_sleep". "enable" turns on nightly sleep for the team; "disable" turns it off; "status" shows last run and schedule; "run_now" triggers an immediate sleep cycle.
team_idstringTeam to promote to (for promote). Auto-resolved if on one team.
timezonestringIANA timezone for team_sleep enable (e.g. "Europe/London"). Defaults to UTC. Sleep fires at 3 AM local time.
to_page_idstringTarget page ID (for link).

No output schema declared.

No examples provided.

brain_delete ~41

Archive a brain page. It will no longer appear in searches or tool consultations.

NameTypeReqDescription
page_idstringyesBrain page ID (bp_...) to archive

No output schema declared.

No examples provided.

brain_expand ~95

Retrieve the verbatim source text (a "drawer") linked from a brain page. Use this when a summary lacks specifics you need — drawers contain the original tool output, redacted for credentials. Returns 404 if the page has no linked drawer (not all pages do — drawers are a Step 4 feature for allowlisted tools only).

NameTypeReqDescription
page_idstringyesBrain page ID (bp_...) whose drawer to expand.

No output schema declared.

No examples provided.

brain_lint ~28

Run maintenance checks on your brain: find stale pages, orphaned knowledge, and other issues.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

brain_query ~259

Search your knowledge brain for relevant information. Returns pages ranked by relevance. Optional wing/hall narrow the search to a slice of the brain (e.g. wing="engineering", hall="preference").

NameTypeReqDescription
as_ofstringOptional. ISO-date string (e.g. "2026-01-15"). When set, returns pages that were valid at that point in time — including superseded versions. Useful for "what did we know in January?" queries.
hallstringOptional. Restrict to a hall: "fact", "event", "discovery", "preference", or "advice".
include_drawer_previewsbooleanOptional. When true, each result includes the first ~400 chars of its linked drawer (raw source text) if one exists. Useful to decide whether to call brain_expand for the full text.
limitnumberMax results. Defaults to 10.
querystringSearch query. Omit to list all pages by recency.
scopestringWhich brain scope to search. Defaults to all.
wingstringOptional. Restrict to a specific wing (top-level area like "engineering", "family").

No output schema declared.

No examples provided.

brain_settings ~88

View and toggle your brain settings. Currently supports: drawers_enabled (store raw tool output alongside summaries for richer recall).

NameTypeReqDescription
actionstringyes"get" lists current settings; "set" toggles a named setting.
settingstringSetting name (required for "set"). Currently: "drawers_enabled".
valuebooleanNew value (required for "set").

No output schema declared.

No examples provided.

brain_status ~22

View brain page counts and recent pages for your personal and team brain.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

brain_update ~298

Edit an existing brain page's content or metadata. wing/room/hall can be patched to re-file a page. scope can be changed to move a page between your personal and team brain — useful when an auto-ingested page landed in the wrong place. Moving a page to team scope requires team admin role.

NameTypeReqDescription
contentstringNew content (replaces existing)
hallstringOptional. Change hall: fact / event / discovery / preference / advice.
load_tierstringOptional. Change load tier. L1 promotes a page to always-loaded; L3 sends it to cold archive.
material_changebooleanOptional. When true, creates a new version of the page — the old version is preserved with a timestamp and a "supersedes" link. Use for corrections or significant changes; skip for minor edits. Defau…
page_idstringyesBrain page ID (bp_...)
roomstringOptional. Re-file under a different room.
scopestringOptional. Move the page between your personal and team brain. Moving TO team requires team admin role and a team billing context. Moving FROM team to personal is allowed if you own the page or are an…
tagsarrayNew tags
titlestringNew title
wingstringOptional. Re-file under a different wing.

No output schema declared.

No examples provided.

brain_wings ~92

List the wings of your brain — the top-level areas your knowledge is organised under (e.g. "engineering", "family"). For each wing returns the rooms and halls inside, page count, and last-updated time. Use this to discover the right wing/hall to pass to brain_query.

NameTypeReqDescription
include_teambooleanIf true, also count team-scope pages. Default false (personal only).

No output schema declared.

No examples provided.

connector_add ~224

Connect a new OAuth account or MCP server. For OAuth: pass type: "oauth", kind: "slack". For MCP catalog: pass catalog_slug. For custom MCP: pass url + auth_type.

NameTypeReqDescription
auth_tokenstringAuth token or API key.
auth_typestringAuth type (custom MCP). Default: none.
billingstringScope: "personal" (default), "team" (auto-resolves), a team slug, or "team:<id>".
catalog_slugstringMCP catalog slug for one-click connect.
display_namestringHuman-readable name (custom MCP).
header_namestringCustom header name (for header_key auth).
kindstringOAuth connector kind (e.g. "slack", "notion"). Required for type: "oauth".
slugstringShort identifier for the connection.
typestringType of connector to add.
urlstringMCP server endpoint URL (custom MCP).

No output schema declared.

No examples provided.

connector_list ~137

List connected accounts and MCP servers (summary) or detail on one connector. Pass slug for detail including every tool the connector exposes. Optional type: "oauth" | "mcp" filter. Pass include_available: true to also see available catalog MCPs you can connect.

NameTypeReqDescription
contextstringScope: "personal" (default) or "team:<id>" for a team.
include_availablebooleanWhen true, also include catalog MCPs you have not connected yet.
slugstringConnector slug for detail view. Omit to list all.
typestringFilter by connector type.

No output schema declared.

No examples provided.

connector_permissions ~423

View or set permissions for tools on a connected MCP server — which tools are allowed, rate limits, budget caps, argument restrictions. Pass the connector slug (from connector_list) and action: "list" to see current rules, or action: "set" with tool_name + rules to update one. Team scope requires admin role.

NameTypeReqDescription
actionstringOmit to list permissions for all tools. Pass "set" with tool_name + rules to update one.
allowedbooleanWhether the tool is allowed (for set).
arg_natural_language_rulesstringPlain English rules for argument filtering (for set). Example: "Only allow queries for the last 90 days."
arg_schema_rulesstringJSON Schema validating tool arguments (for set). Example: {"properties":{"channel":{"enum":["#general"]}}}
billingstringScope: "personal", "team" (auto-resolves if on one team), a team slug, or "team:<id>".
budget_per_daynumberMax daily spend per user, in millicents (for set).
cost_per_callnumberCost in millicents per call (for set).
nl_filter_modestringHow to enforce NL rules: strict (block on violation) or advisory (log only). Default: strict.
rate_limit_per_daynumberMax calls per day, per user (for set).
rate_limit_per_hournumberMax calls per hour, per user (for set).
slugstringyesConnector slug.
team_budget_per_daynumberMax daily spend team-wide, in millicents (for set).
team_rate_limit_per_daynumberMax calls per day, team-wide (for set).
team_rate_limit_per_hournumberMax calls per hour, team-wide (for set).
tool_namestringTool name (for set). Use "*" for all tools on this connector.

No output schema declared.

No examples provided.

connector_remove ~79

Disconnect a connector. Pass slug.

NameTypeReqDescription
billingstringScope: "personal" (default), "team" (auto-resolves), a team slug, or "team:<id>".
slugstringyesConnector slug to disconnect.
typestringType of connector (mcp or oauth). Default: mcp.

No output schema declared.

No examples provided.

credential_default ~74

Set the default value for a multi-value credential.

NameTypeReqDescription
contextstring"personal" or "team:<id>". Defaults to personal.
labelstringyesLabel of the entry to make default (e.g. "Production").
namestringyesCredential name (e.g. "ios_app_id").

No output schema declared.

No examples provided.

credential_delete ~99

Remove a saved credential. If label is provided, removes only that specific entry. If no label, removes ALL entries for that credential name.

NameTypeReqDescription
contextstring"personal" or "team:<id>". Defaults to personal.
labelstringLabel of the specific entry to delete. Omit to remove all entries for this credential name.
namestringyesCredential name to delete (e.g. "ios_app_id").

No output schema declared.

No examples provided.

credential_guide ~43

Get setup instructions for a specific credential.

NameTypeReqDescription
namestringyesCredential name (e.g. "ios_app_id", "play_store_app_id", "domain").

No output schema declared.

No examples provided.

credential_list ~95

List saved credentials (summary) or detail on one. Pass name for detail view. Pass show_available: true to include the full credential catalog.

NameTypeReqDescription
contextstring"personal" or "team:<id>". Defaults to personal.
namestringCredential name for detail view. Omit to list all saved.
show_availablebooleanInclude the full catalogue of available BYOK options. Default false.

No output schema declared.

No examples provided.

credential_save ~136

Save a credential (BYOK provider API key). Saved keys persist across sessions and are used automatically.

NameTypeReqDescription
contextstring"personal" or "team:<id>". Defaults to personal.
is_defaultbooleanSet this value as the default for this credential.
labelstringHuman-readable label to identify this value (e.g. "MyApp", "Staging"). Required when saving multiple values for the same credential.
namestringyesCredential name from the tool requirements (e.g. "ios_app_id", "openai").
valuestringyesThe credential value to save.

No output schema declared.

No examples provided.

credits_balance ~28

Current balance, plan tier, rate limits, and any negative-balance warnings for the active context.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

credits_usage ~161

Usage summary or history. Pass scope: "me" | "team" and detail: "tool" | "skill". Sorted by cost with _others rollup.

NameTypeReqDescription
detailstringDetail level. "tool" groups by tool, "skill" adds per-skill breakdown.
limitnumberNumber of top tools/skills to return. Remaining rolled into "_others". Default 10.
offsetnumberRecords to skip for pagination (history mode). Default 0.
periodstringTime period to summarize. 'all' covers the last 30 days (the maximum window).
scopestringWhose usage to show. "me" for personal, "team" for team-wide.

No output schema declared.

No examples provided.

discover ~235

Find the right ToolRouter tool for your task. Describe what you need in plain language. Examples: "analyze a website", "research competitors", "find prospect companies", "check DNS records". Exact tool name (e.g. "seo") returns full schemas and examples. Flow: prefer route({ intent }) to pick and run a tool. Use discover when you need schemas or a listing, then call use_tool(tool, skill, input). Every discover response also includes a top-level `connectors` array listing SaaS accounts the user has already connected (LinkedIn, Google, Notion, etc.). Use that to pick the right tool and account without asking — e.g. if `connectors` shows LinkedIn, the linkedin-post tool is ready to use. Categories: data, media, search, marketing, development, communication, analytics, productivity, ai, finance, security, infrastructure

NameTypeReqDescription
categorystringFilter by category
querystringyesWhat you want to do (e.g. "scrape a webpage"), a category (e.g. "security"), or "*" to list everything.

No output schema declared.

No examples provided.

feedback_debug ~409

Report a ToolRouter platform bug that blocks you from completing the user's task. Use this when you suspect the issue is on our side — a tool crashed, returned malformed data, timed out unexpectedly, or behaved inconsistently. Include the relevant ToolRouter errors, call IDs, non-sensitive input shape, retries, and expected behavior. Do not include chat history, unrelated conversation text, uploaded file contents, personal data, API keys, or secrets. Reports are stored and reviewed within hours. Skip this for expected errors like invalid input, missing credentials, insufficient balance, rate limits, or genuine "not found" results — those aren't bugs. Limit: 5 reports per hour.

NameTypeReqDescription
agent_contextstringMCP client name and version, if known.
call_idsstringALL call IDs from this interaction (successful and failed), one per line or comma-separated.
error_messagesstringyesALL error messages received during this interaction — not just the last one. Include the full text of every error response from ToolRouter, separated by newlines.
expected_behaviorstringWhat you expected to happen vs what actually happened.
input_summarystringSummary of what you sent to the failing tool (do NOT include API keys or secrets — describe the shape and intent).
interaction_logstringChronological log limited to the relevant ToolRouter calls: tool/skill names, non-sensitive input shape, response status, errors, retries, and job polling. Do not include chat history, unrelated conv…
job_idstringJob ID for async jobs that failed, if applicable.
severitystringyes"blocking" = cannot complete task. "degraded" = partial results or workaround exists.
skillstringSkill name that failed (e.g. "search").
toolstringTool name that failed (e.g. "web-search").

No output schema declared.

No examples provided.

feedback_request_tool ~152

Ask ToolRouter to build a tool that does not exist yet. Use this when discover returned nothing useful for what the user needs. Describe the capability in plain terms — do not include personal data, API keys, or secrets. Requests go straight to the team. Limit: 5 per hour.

NameTypeReqDescription
agent_contextstringMCP client name and version, if known.
searchedstringThe discover query you tried that came back empty.
whatstringyesWhat the tool should do, in one or two sentences (e.g. "Look up UK company filings by company number").
whystringWhat the user was trying to accomplish and why existing tools did not fit.

No output schema declared.

No examples provided.

feedback_review ~84

Submit a review or star rating.

NameTypeReqDescription
ratingnumberyesStar rating 1-5 (1=poor, 3=okay, 5=excellent).
reviewstringConstructive feedback — what worked well and any specific suggestions to improve.
toolstringyesTool name to review (e.g. "web-search" or "seo").

No output schema declared.

No examples provided.

file_delete ~38

Delete a file. Cannot be undone. For team files: requires owner/admin role.

NameTypeReqDescription
file_idstringyesThe file ID to delete.

No output schema declared.

No examples provided.

file_list ~163

List or search files. Optional query triggers semantic search. Supports section, tags, plan_status, limit, cursor filters.

NameTypeReqDescription
contextstring"personal" (default) or "team:<id>".
cursorstringPagination cursor from a previous file_list response.
limitnumberMax results (default 20, max 50).
plan_statusstringFilter plans by status.
prompt_typestringFilter prompts by type (only valid when section is "prompts").
querystringNatural language search query. Omit to browse.
sectionstringFilter by section. Omit to list all.
tagsarrayFilter to files matching ALL of these tags.

No output schema declared.

No examples provided.

file_read ~63

Read a file's full content. Text files return content inline. Binary files (images, video) return a download URL.

NameTypeReqDescription
file_idstringyesThe file ID (e.g. "ast_a1b2c3d4e5f67890").

No output schema declared.

No examples provided.

file_write ~341

Create or update a file. Pass mode: "create" | "update". Binary uploads: call with binary: true to get an upload_url, then PUT bytes, then call with mode: "finalize".

NameTypeReqDescription
asset_idstringExisting asset ID to retrieve URL without re-uploading.
contentstringText content (for .md files).
content_typestringMIME type. Defaults to "text/markdown" for content, "image/png" for file_data.
contextstring"personal" (default) or "team:<id>".
descriptionstringOptional summary (max 500 chars).
file_datastringBase64-encoded binary data (for images, video).
file_idstringFile ID to update (required for update/finalize).
filenamestringOptional filename for the asset.
image_datastringBase64-encoded image. Alternative to image_url when the bytes are already local.
image_urlstringPublic URL to download and host permanently.
modestringyes"create" for new files, "update" to edit existing, "finalize" to complete a binary upload.
namestringFile name (required for create, max 200 chars).
plan_statusstringPlan status (only for plans section).
prompt_metaobjectPrompt metadata (only for prompts section).
sectionstringWhich section to file under (required for create).
tagsarrayTags for organization (max 10).

No output schema declared.

No examples provided.

invoice_list ~36

List invoices for the active billing context.

NameTypeReqDescription
limitnumberNumber of invoices to return (default 10, max 20).

No output schema declared.

No examples provided.

job_cancel ~26

Cancel a running job.

NameTypeReqDescription
job_idstringyesThe job ID to cancel.

No output schema declared.

No examples provided.

job_get ~55

Get job status and result. Returns status: running | completed | failed and result when terminal. Keep polling until you get a terminal status.

NameTypeReqDescription
job_idstringyesThe job ID returned when a long-running tool was called.

No output schema declared.

No examples provided.

job_list ~49

List your active and recent jobs. Optional status filter.

NameTypeReqDescription
limitnumberMax jobs to return (default 20, max 100).
statusstringFilter by job status.

No output schema declared.

No examples provided.

key_create ~47

Create a new API key. Returns the secret once — save it immediately.

NameTypeReqDescription
namestringyesA name to identify this key (e.g. "Claude Desktop", "Production Bot").

No output schema declared.

No examples provided.

key_delete ~42

Revoke an API key. Refuses to revoke the currently-authenticating key.

NameTypeReqDescription
key_idstringyesThe key ID to revoke (from key_list).

No output schema declared.

No examples provided.

key_list ~47

List API keys (summary) or get detail on one key. Pass key_id for detail view.

NameTypeReqDescription
key_idstringKey ID for detail view. Omit to list all.

No output schema declared.

No examples provided.

outfit_list ~31

List your outfits.

NameTypeReqDescription
contextstring"personal" (default) or "team:<id>".

No output schema declared.

No examples provided.

persona_list ~31

List your personas.

NameTypeReqDescription
contextstring"personal" (default) or "team:<id>".

No output schema declared.

No examples provided.

product_list ~31

List your products.

NameTypeReqDescription
contextstring"personal" (default) or "team:<id>".

No output schema declared.

No examples provided.

route ~203

Send a natural-language intent and optionally any dimensions you already know (tool, skill, model, input fields). Fills only the blanks via Jev, then either executes the call or returns a ready-to-run use_tool payload. Explicit values are never overridden. Returns candidates when confidence is low or no tool fits. Flow: route → if confident and complete, result is returned; otherwise use the pre-filled call with use_tool.

NameTypeReqDescription
inputobjectOptional. Partial skill input — explicit fields are never overridden.
intentstringyesWhat you want to do, in plain language.
max_costnumberOptional. Max USD to spend; above this returns a pre-filled call instead of executing.
modelstringOptional. Model override — honoured verbatim when set.
skillstringOptional. Skill name — honoured verbatim when set.
toolstringOptional. Tool name — honoured verbatim when set.

No output schema declared.

No examples provided.

scene_list ~31

List your scenes.

NameTypeReqDescription
contextstring"personal" (default) or "team:<id>".

No output schema declared.

No examples provided.

subscription_manage ~78

Get a Stripe management URL (portal, upgrade, or cancel). Also covers billing portal — returns the URL for the user to open.

NameTypeReqDescription
actionstringyes"subscribe" to start a subscription, "manage" to view/cancel existing subscription.
tierstringWhich plan to subscribe to (required for "subscribe" action).

No output schema declared.

No examples provided.

top_up_credits ~65

Add credits to your account. Returns a Stripe checkout URL — share it with the user to complete payment. Minimum $1.

NameTypeReqDescription
amount_usdnumberyesAmount in USD to add (e.g. 10, 25, 50). Minimum $1.

No output schema declared.

No examples provided.

use_tool ~594

Call a ToolRouter catalogue tool. Prefer `route` with a natural-language intent when you do not already know the tool and skill — it picks them, fills arguments, and runs the call. Use discover when you need schemas or a catalogue listing, then pass the exact tool name and skill here. IMPORTANT: "discover", "route", "credits_balance", and other built-in tools are NOT catalogue tools — call them directly, never through use_tool. Long-running tools return a job_id — poll with job_get. If a skill needs an image_url or file URL and you have a local file or base64 image, use file_write first to get a hosted URL, then pass that URL to the skill. BRAIN: Some tools require you to consult brain_query first. If use_tool returns an error about brain_context, call brain_query with a relevant query, then pass the result text as brain_context in your use_tool input.

NameTypeReqDescription
backendobjectRoute the same model through interchangeable providers. order prioritises providers; only restricts; ignore excludes; allow_fallbacks defaults true.
billingstringWhich account to bill. "personal", "team" (auto-resolves if on one team), a team slug ("humanleap"), or a team ID ("team:m57df8c..."). Omit to use your default.
brain_contextstringBrain knowledge from brain_query. Pass at the top level of use_tool (alongside "tool", "skill", "input") — NOT inside input. Call brain_query first, then paste the result text here to clear the brain…
inputobjectyesSkill input parameters (see discover for schema). For persona-using tools, include persona_file_id from discover or persona_list. For scene-using tools, include scene_file_id from discover or scene_l…
response_formatstringResponse verbosity. "concise" (default) strips noise, returns essential data only. "detailed" returns everything including raw metadata.
skillstringyesSkill name from discover results, e.g. "search"
toolstringyesTool reference from discover results, e.g. "web-search"

No output schema declared.

No examples provided.

Common questions

What is the ToolRouter MCP server?

ToolRouter is an MCP server listed in the public MCP registry as io.github.Humanleap/toolrouter. The OpenRouter for tools. One MCP connection gives any AI agent 254 hosted tools, pay per call. This page covers its hosted endpoint (https://api.toolrouter.com/mcp).

Is the ToolRouter MCP server safe to use?

ToolRouter scores 86 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the ToolRouter MCP server expose?

ToolRouter exposes 48 tools: account_setup, account_list, account_switch, account_preferences, credits_balance, and 43 more. Their descriptions and schemas cost roughly 6,143 tokens of context every time the server is loaded.

Does the ToolRouter MCP server require authentication?

Yes. ToolRouter asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

Is the ToolRouter MCP server still maintained?

ToolRouter is still listed as active in the MCP registry. We last reached this channel on 21 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.