io.github.maginaryai/maginary-mcp
REMOTE · MCP.MAGINARY.AI · 2 COMPONENTS · SCANNED SEP 20
AI image + video generation for agents: --flag prompt DSL, async generate/poll, x402 pay-per-use.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security46
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (create_wallet_account). See how to fix → View diagnostics → Fail
- HTTPS enforcement could not be verified: the plaintext port answered with HTTP 406, which proves neither a plaintext path nor enforcement. View diagnostics → Unverified
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability65
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 5954 tokens (~372/item across 16 items; 16 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management17
- Stability observed for 5 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 17 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the io.github.maginaryai/maginary-mcp server?
io.github.maginaryai/maginary-mcp is a hosted endpoint at https://mcp.maginary.ai/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.maginary.ai
claude mcp add --transport http maginaryai-maginary-mcp 'https://mcp.maginary.ai/mcp'
{
"mcpServers": {
"maginaryai-maginary-mcp": {
"url": "https://mcp.maginary.ai/mcp"
}
}
} {
"servers": {
"maginaryai-maginary-mcp": {
"type": "http",
"url": "https://mcp.maginary.ai/mcp"
}
}
} [mcp_servers.maginaryai-maginary-mcp] url = "https://mcp.maginary.ai/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"maginaryai-maginary-mcp": {
"type": "remote",
"url": "https://mcp.maginary.ai/mcp",
"enabled": true
}
}
} openclaw mcp add maginaryai-maginary-mcp --url 'https://mcp.maginary.ai/mcp' --transport streamable-http
mcp_servers:
maginaryai-maginary-mcp:
url: "https://mcp.maginary.ai/mcp" {
"McpServers": {
"maginaryai-maginary-mcp": {
"Transport": "http",
"Url": "https://mcp.maginary.ai/mcp"
}
}
} assistant mcp add maginaryai-maginary-mcp -t streamable-http -u 'https://mcp.maginary.ai/mcp'
{
"mcpServers": {
"maginaryai-maginary-mcp": {
"type": "http",
"url": "https://mcp.maginary.ai/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 18 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.
- 16 Sept 26 +1
- Stability: unverified → 0.03 ▲ functional
- 15 Sept 26 58
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://mcp.maginary.ai/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=mcp.maginary.ai | CN=YR2,O=Let's Encrypt,C=US | 3 Sept 2026 | 2 Dec 2026 | RSA 4096 | SHA256-RSA | 5e17ffcd8575b4df8d4ee095880b4887bc4 |
| SANs: mcp.maginary.ai | ||||||
| CN=YR2,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | 4ebd24947e24d394802d84a52fd5b319 |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.maginary.ai. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| ai. | present | 3799 | 8 | Verified |
| maginary.ai. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| x-content-type-options | nosniff |
| x-frame-options | SAMEORIGIN |
| referrer-policy | same-origin |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.maginary.ai/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.maginary.ai/mcp | Inconclusive | 406 |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
check_account_status Check account status ~159
Check account verification status, credit balance, and API key count. Use this after ``create_account`` to poll whether the user has clicked the verification link. Pass ``email`` + ``password`` (from ``create_account``) for Basic auth, or omit both to use the configured API key. Args: email: Account email (for Basic auth). password: Account password (for Basic auth). Returns: Dict with ``verified`` (bool), ``email``, ``api_key_count``, ``credits_remaining``, ``uploads_remaining``.
| Name | Type | Req | Description |
|---|---|---|---|
| – | – | Account email (for Basic auth). Omit to use API key. | |
| password | – | – | Account password (for Basic auth). |
Structured output declared, but exposes no named fields.
No examples provided.
checkout Create checkout link ~249
Create a Stripe checkout session for purchasing a product. Returns a ``checkout_url`` — the user must open it in a browser to complete payment. After payment, credits are provisioned automatically via webhook. **Present the URL exactly as returned, including the ``#fragment`` — do not truncate, reformat, or strip any part of it.** If the agent has a USDC wallet, skip this entirely — just call ``generate`` and the x402 protocol handles payment on-chain. Args: product_id: Product ID from ``get_products``. email: Account email (for Basic auth during onboarding). password: Account password (for Basic auth during onboarding). Returns: Dict with ``checkout_url``. On failure, an ``isError`` result — e.g. ``error: "email_not_verified"`` until the user clicks the verification link, or ``"auth"`` / ``"failed"``.
| Name | Type | Req | Description |
|---|---|---|---|
| – | – | Account email (for Basic auth during onboarding). | |
| password | – | – | Account password (for Basic auth). |
| product_id | integer | yes | Product ID from get_products. |
Structured output declared, but exposes no named fields.
No examples provided.
configure_api_key Configure API key ~191
Activate an API key. Local (stdio) servers persist it; hosted does not. Call this after ``manage_api_key(action='create')`` returns a ``raw_key``. On a local server the key is saved to ``~/.config/maginary/api_key`` (chmod 600) and survives restarts. On the hosted server (mcp.maginary.ai) nothing can be stored — auth is per-request: the response will say ``persisted: false`` and the key must be sent as an ``Authorization: Bearer <key>`` header on every request (set it in the MCP client's connection config). Args: api_key: The full API key string returned by ``manage_api_key``. Returns: Confirmation dict.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | yes | Full API key string from manage_api_key. |
Structured output declared, but exposes no named fields.
No examples provided.
create_account Create account ~203
Create a new Maginary account for the given email address. Returns the auto-generated password — display it to the user ONCE so they can save it. A verification email is sent; the user must click the link before the account can generate images. After verification, use ``manage_api_key(action='create')`` with ``email`` + ``password`` to get an API key, then ``configure_api_key`` to activate it. Args: email: The user's email address. Returns: Dict with ``email``, ``password``, and ``message``. On failure, an ``isError`` result — e.g. ``error: "already_exists"`` (email taken: ask the user for their password or a different email), ``"rate_limited"``, or ``"failed"``.
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | Email address for the new account. |
Structured output declared, but exposes no named fields.
No examples provided.
create_wallet_account Create wallet account ~354
Create (or access) a Maginary account using a wallet signature. Sign the message ``Maginary: authenticate <address> at <timestamp>. This does not move funds.`` with EIP-191 ``personal_sign`` and pass all three values. On success, an API key is returned immediately — no email verification needed. Use this when you have a wallet but no email. The returned ``api_key`` should be passed as ``Authorization: Bearer <key>`` in the MCP client config, or via ``configure_api_key`` (stdio) / ``_meta["maginary/api_key"]`` (hosted, per-call). If the wallet already has an account, returns the existing account with a fresh API key. Args: address: EVM wallet address (0x..., 42 chars). signature: Hex-encoded EIP-191 personal_sign of the auth message. timestamp: Unix epoch seconds used in the signed message (must be within the last 5 minutes). Returns: Dict with ``address``, ``api_key`` (full key — show once), ``key_prefix``, ``created`` (bool), ``message``. On failure: ``isError`` with ``error`` = ``"validation"``, ``"signature_failed"``, or ``"rate_limited"``.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | EVM wallet address (0x..., 42 chars). |
| signature | string | yes | Hex EIP-191 personal_sign of the auth message. |
| timestamp | integer | yes | Unix epoch seconds used in the signed message. |
Structured output declared, but exposes no named fields.
No examples provided.
execute_action Run action on image ~475
Run a follow-up action on a completed generation's image. After ``generate`` → ``wait_for_generation``, the response's ``processing_result.available_actions`` lists what's possible per slot. Call this tool with one of those action types. Args: generation_uuid: UUID of the parent generation (from ``generate``). action_type: One of the values from ``available_actions`` — e.g. ``"upscale_2x"``, ``"upscale_1_5x"``, ``"vary_strong"``, ``"vary_subtle"``, ``"pan_left"``, ``"pan_right"``, ``"pan_up"``, ``"pan_down"``, ``"zoom_out_2x"``, ``"zoom_out_1_5x"``, ``"img2vid_basic"``, ``"reroll"``. parent_image_index: The slot index of the image to act on (0, 1, 2, or 3 for a 4-image grid). Required for per-slot actions; omit for ``"reroll"`` (global action). prompt: Optional replacement prompt. For ``vary_*`` you can steer the variation with a new prompt; for ``img2vid_basic`` you can describe the desired motion. callback_url: Optional webhook URL (same as ``generate``). Returns: The newly created child generation record (same shape as ``generate``'s return — poll it with ``wait_for_generation``). On failure, same ``isError`` contract as ``generate``: ``"auth"``, ``"payment_required"`` (with x402 challenge), or ``"failed"``.
| Name | Type | Req | Description |
|---|---|---|---|
| action_type | string | yes | Action from available_actions, e.g. upscale_2x, vary_strong, img2vid_basic, reroll. |
| callback_url | – | – | HTTPS webhook URL for done/failed notifications. |
| generation_uuid | string | yes | UUID of the parent generation. |
| parent_image_index | – | – | Slot index (0-3) of the image to act on. Omit for global actions like reroll. |
| prompt | – | – | Optional replacement prompt for vary/img2vid actions. |
Structured output declared, but exposes no named fields.
No examples provided.
generate Generate image or video ~1,367
Kick off a generation via POST /api/gens/. Args: prompt: The user's words, passed through as-is. Do NOT add flags the user did not ask for — no ``--ar``, no ``--flagship``, no model flags. Every extra flag costs credits; adding them unrequested is wrong. Standard quality is the default and is cheap; ``--flagship`` is ~4× more expensive and must only be used when the user explicitly asks for best quality. If the user asks about quality or aspect ratio: ask them first (standard vs flagship, landscape vs portrait) before generating. Flags go at the END, only when the user asked: ``--1``/``--2``/``--3``/``--4`` = image count (default 4), ``--ar 16:9`` = aspect ratio, ``--flagship`` = best quality. Unknown flag: call ``get_parameter(name)`` first — never guess. Examples — user says "a fox": prompt is ``"a fox"``. User says "a fox, landscape, best quality": prompt is ``"a fox --ar 16:9 --flagship"``. **Image-to-image (img2img):** Place one or more public image URLs in the prompt, followed by editing instructions: ``"https://cdn.example.com/photo.webp reimagine as oil painting --ar 16:9"`` The engine extracts URLs automatically and switches to img2img mode. Multiple URLs trigger multi-input mode (compositing/combining). Use ``upload_image`` first if images aren't already hosted. **Image-to-video:** Place an image URL in the prompt AND add ``--mp4`` plus video flags (``--5sec``, ``--1080p``). Or use ``execute_action`` with ``action_type="img2vid_basic"`` on a completed generation's image. **Style reference (--sref) is NOT img2img:** ``--sref <url>`` copies the visual *style* of a reference image (colors, mood, composition) without using…
| Name | Type | Req | Description |
|---|---|---|---|
| callback_url | – | – | HTTPS webhook URL for done/failed notifications. |
| prompt | string | yes | The user's words as-is, flags at the end. Do NOT add flags the user did not ask for. |
Structured output declared, but exposes no named fields.
No examples provided.
get_balance Get balance ~80
Check remaining credits and uploads for the authenticated account. Args: email: Account email (for Basic auth). password: Account password (for Basic auth). Returns: Dict with ``credits_remaining`` and ``uploads_remaining``.
| Name | Type | Req | Description |
|---|---|---|---|
| – | – | Account email (for Basic auth). | |
| password | – | – | Account password (for Basic auth). |
Structured output declared, but exposes no named fields.
No examples provided.
get_generation Get generation ~256
Fetch a generation by UUID (GET /api/gens/{uuid}/). Args: uuid: The UUID returned by ``generate``. Returns: The full generation record. If terminal, ``image_urls[]`` holds the finished outputs and ``processing_result.slots[]`` the per-slot detail. NOTE: a generation that failed server-side is a SUCCESSFUL tool call returning ``processing_state: "failed"`` — always check the state, never infer success from the absence of a tool error. **Follow-up actions:** A completed generation's ``processing_result.available_actions`` maps slot indices to valid action types. E.g. ``{"0": ["upscale_2x", "vary_strong", ...], "global": ["reroll"]}``. Use ``execute_action`` with the ``uuid``, a chosen ``action_type``, and the ``parent_image_index`` (the slot key as an int) to run an action. Hosted: a key obtained mid-session may be passed as ``_meta["maginary/api_key"]``.
| Name | Type | Req | Description |
|---|---|---|---|
| uuid | string | yes | Generation UUID from generate or execute_action. |
Structured output declared, but exposes no named fields.
No examples provided.
get_parameter Get parameter ~112
Return the full record for a single parameter (canonical name or alias). Args: name: Parameter name with or without leading ``--`` (e.g. ``ar``, ``--ar``, ``aspect``). Case-insensitive. Returns: The parameter dict. Not-found is an ``isError`` result — surface it rather than fabricating a param.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Parameter name with or without --, e.g. ar, --ar, aspect. |
Structured output declared, but exposes no named fields.
No examples provided.
get_products Get products ~146
List available Maginary products/plans with pricing. No authentication required. Use this to present purchase options to the user. The ``novice_pack`` ($10, 150 credits) is the recommended starting point. Returns: Dict with ``count`` and ``products`` — each product carries ``id``, ``short_name``, ``title``, ``description``, ``price_cents``, ``credits``, ``uploads``, ``is_subscription``. (The backend sends a bare array; it is wrapped here because FastMCP validates tool output against the dict annotation and rejects a top-level list.)
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
list_parameters List parameters ~232
List Maginary prompt-DSL parameters. Args: category: Restrict to one category (e.g. ``composition``, ``video``, ``model``, ``outpaint``). Call with no filters once — the response's ``categories`` / ``statuses`` maps are the full taxonomy. status: Restrict to one status (``live``, ``mostly-dead``, ``unimplemented``). include_reserved: When False (default) drop ``unimplemented`` (recognized-but-blocked) parameters from the result. Returns: A dict with ``count``, ``source`` (``live`` vs. ``bundled-snapshot``), ``categories`` / ``statuses`` (the filter taxonomy), and ``parameters`` (the array of matching entries).
| Name | Type | Req | Description |
|---|---|---|---|
| category | – | – | Filter by category, e.g. composition, video, model, outpaint. |
| include_reserved | boolean | – | Include unimplemented (blocked) parameters. |
| status | – | – | Filter by status: live, mostly-dead, or unimplemented. |
Structured output declared, but exposes no named fields.
No examples provided.
manage_api_key Manage API key ~270
Create, list, or revoke Maginary API keys (up to 10 per account). Auth: pass ``email`` + ``password`` for Basic auth (onboarding), or omit both to use the configured API key (normal operation). Args: action: One of ``create``, ``list``, ``revoke``. name: Key name (required for ``create``). key_prefix: 8-char prefix of the key to revoke (required for ``revoke``). email: Account email (for Basic auth). password: Account password (for Basic auth). Returns: For ``create``: dict with ``raw_key`` (the full key — show once, then use ``configure_api_key`` to activate it), ``key_prefix``, ``name``. For ``list``: dict with ``keys`` array. For ``revoke``: success/error message.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | One of: create, list, revoke. |
| – | – | Account email (for Basic auth). | |
| key_prefix | – | – | 8-char prefix of key to revoke (required for revoke). |
| name | – | – | Key name (required for create). |
| password | – | – | Account password (for Basic auth). |
Structured output declared, but exposes no named fields.
No examples provided.
search_parameters Search parameters ~145
Text-search over parameter names, aliases, descriptions, values, examples. Args: query: Substring match, case-insensitive. category: Optional single-category restriction. include_reserved: Whether to include ``unimplemented`` parameters. Returns: Dict with ``count``, ``source`` (``live`` vs. ``bundled-snapshot``), and ``parameters`` (ordered as they appear in the catalog).
| Name | Type | Req | Description |
|---|---|---|---|
| category | – | – | Filter by category, e.g. composition, video, model. |
| include_reserved | boolean | – | Include unimplemented (blocked) parameters. |
| query | string | yes | Search term (case-insensitive substring match). |
Structured output declared, but exposes no named fields.
No examples provided.
upload_image Upload image ~211
Upload a local image and get a CDN URL for img2img or ``--sref``. Only available on local (stdio) connections. On hosted/remote connections, place an existing image URL directly in the prompt. Place the returned ``url`` in a ``generate`` prompt: ``generate("https://cdn.maginary.ai/…/photo.webp reimagine as oil painting")`` Args: file_path: Path to an image file on disk (JPEG, PNG, WebP, HEIC). filename: Original filename. Inferred from ``file_path`` if omitted. Returns: Dict with ``url`` (the public CDN URL), ``exists`` (deduplicated), ``credits_deducted``, and ``message``.
| Name | Type | Req | Description |
|---|---|---|---|
| file_path | string | yes | Path to a local image (JPEG, PNG, WebP, HEIC). |
| filename | – | – | Override filename. Inferred from file_path if omitted. |
Structured output declared, but exposes no named fields.
No examples provided.
wait_for_generation Wait for generation ~380
Poll ``get_generation`` on a backoff until it reaches done / failed. Args: uuid: The UUID returned by ``generate``. timeout_s: Return after this many seconds even if still running. Default 45 stays under the 60 s per-call limit most MCP clients enforce; a ``timeout`` result just means "call again". Only raise it (e.g. for video) on clients you know allow long tool calls. Returns: The terminal generation record — which includes generations that failed server-side: those are SUCCESSFUL tool calls returning ``processing_state: "failed"`` with empty ``image_urls``, so always check the state. On tool failure, an ``isError`` result whose ``error`` field is ``"timeout"`` (``message`` names the last observed state — the generation keeps running server-side and can be re-fetched with ``get_generation`` later), ``"auth"``, or ``"failed"``. **Follow-up actions:** A ``done`` generation's ``processing_result.available_actions`` maps slot indices to valid action types — e.g. ``{"0": ["upscale_2x", "vary_strong", "pan_left", "zoom_out_2x", "img2vid_basic", ...], "global": ["reroll"]}``. Use ``execute_action`` with the ``uuid``, a chosen ``action_type``, and the ``parent_image_index`` (the slot key as an int) to run an action on a specific output image.
| Name | Type | Req | Description |
|---|---|---|---|
| timeout_s | number | – | Max seconds to wait before returning a timeout result. |
| uuid | string | yes | Generation UUID to poll. |
Structured output declared, but exposes no named fields.
No examples provided.
What is the io.github.maginaryai/maginary-mcp server?
io.github.maginaryai/maginary-mcp is listed in the public MCP registry as io.github.maginaryai/maginary-mcp. AI image + video generation for agents: --flag prompt DSL, async generate/poll, x402 pay-per-use. This page covers its hosted endpoint (https://mcp.maginary.ai/mcp).
Is the io.github.maginaryai/maginary-mcp server safe to use?
io.github.maginaryai/maginary-mcp scores 60 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.maginaryai/maginary-mcp server expose?
io.github.maginaryai/maginary-mcp exposes 16 tools: list_parameters, search_parameters, get_parameter, generate, get_generation, and 11 more. Their descriptions and schemas cost roughly 4,830 tokens of context every time the server is loaded.
Does the io.github.maginaryai/maginary-mcp server require authentication?
No. We connected to io.github.maginaryai/maginary-mcp without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the io.github.maginaryai/maginary-mcp server still maintained?
io.github.maginaryai/maginary-mcp is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.