Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Razi Tools

REMOTE · WWW.RAZI.PRO · 2 COMPONENTS · SCANNED SEP 21

PDF, image, video, OCR, screenshot, SQL, QR and text tools for agents. No API key, no signup.

0 this week 36 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security89
Transport & Reachability0
Schema Quality & AI Usability0
  • Schema blocked by authentication: the endpoint requires auth we don't have to read it. See how to fix → Unverified
Stability & Change Management0
  • Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage0
  • Tool coverage blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Tool Safety0
  • Tool safety blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Capabilities0
  • Capabilities blocked by authentication: the endpoint requires auth we don't have to read them. See how to fix → Unverified

Unverified: 6 categories

Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm. Claim this server and supply a read-only token to verify it and lift the score.

Install

How do I install the Razi Tools MCP server?

Razi Tools is a hosted endpoint at https://www.razi.pro/api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · www.razi.pro

# add to Claude Code
claude mcp add --transport http razikallayi-razi-tools 'https://www.razi.pro/api/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "razikallayi-razi-tools": {
      "url": "https://www.razi.pro/api/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "razikallayi-razi-tools": {
      "type": "http",
      "url": "https://www.razi.pro/api/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.razikallayi-razi-tools]
url = "https://www.razi.pro/api/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "razikallayi-razi-tools": {
      "type": "remote",
      "url": "https://www.razi.pro/api/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add razikallayi-razi-tools --url 'https://www.razi.pro/api/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  razikallayi-razi-tools:
    url: "https://www.razi.pro/api/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "razikallayi-razi-tools": {
      "Transport": "http",
      "Url": "https://www.razi.pro/api/mcp"
    }
  }
}
# add to Vellum
assistant mcp add razikallayi-razi-tools -t streamable-http -u 'https://www.razi.pro/api/mcp'
// mcp.json
{
  "mcpServers": {
    "razikallayi-razi-tools": {
      "type": "http",
      "url": "https://www.razi.pro/api/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 9 Sept 26 −27
    • Endpoint reachability: reachable → behind authorisation security
    • Authorization: unverified → fail security
    • Tool safety: pass → unverified security
    • Transport: pass → unverified security
    • Capabilities: fail → unverified functional
    • Tool coverage: 100 → unverified functional
    • First check of Schema quality: unverified functional
  • 8 Sept 26 63

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 20 Sept 2026 · Probed https://www.razi.pro/api/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=www.razi.pro CN=YR2,O=Let's Encrypt,C=US 12 Sept 2026 11 Dec 2026 RSA 2048 SHA256-RSA 5b5cb6701996625e48e7d57e8c436c9e7b8
SANs: www.razi.pro
CN=YR2,O=Let's Encrypt,C=US (CA) CN=Root YR,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 RSA 2048 SHA256-RSA 4ebd24947e24d394802d84a52fd5b319
CN=Root YR,O=ISRG,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 RSA 4096 SHA256-RSA f24b6d17f9d9ad7cb1c9fea78782699f

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of www.razi.pro. Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
pro. present 42154 8 Verified
razi.pro. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication Challenged, unverified

The endpoint asked for a token, but we could not retrieve and validate the RFC 9728 metadata that tells a client how to obtain one.

Result Challenged, unverified
Enforced On connection
HTTP status 403
Header Value
strict-transport-security max-age=63072000; includeSubDomains; preload
content-security-policy default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://www.youtube.com https://www.googletagmanager.com https://www.clarity.ms https://scripts.clarity.ms https://vercel.live https://va.vercel-scripts.com; worker-src 'self' blob:; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https:; font-src 'self' data:; connect-src 'self' data: blob: https://*.supabase.co wss://*.supabase.co https://*.posthog.com https://us.i.posthog.com https://us-assets.i.posthog.com https://*.clarity.ms https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com https://www.googletagmanager.com https://*.googletagmanager.com https://vitals.vercel-insights.com https://va.vercel-scripts.com https://vercel.live wss://vercel.live https://*.public.blob.vercel-storage.com https://*.upstash.io https://api.dicebear.com wss://worker.razi.pro https://worker.razi.pro/api/peerdrop/files/; frame-src https://www.youtube.com https://youtube.com https://www.youtube-nocookie.com
x-content-type-options nosniff
x-frame-options DENY
referrer-policy origin-when-cross-origin
permissions-policy camera=(), microphone=(), geolocation=()

Protected resource metadata

Retrieved No
Problem no_resource_metadata

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://www.razi.pro/api/mcp Auth required 403
http (plaintext) http://www.razi.pro/api/mcp HTTPS enforced 308 https://www.razi.pro/api/mcp
MCP tools · 29 exposed · ~2,224 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
calculate_percentage ~48

Calculate percentages, percentage increase/decrease, and ratios.

NameTypeReqDescription
operationstringyesCalculation type
value1numberyesFirst value
value2numberyesSecond value

No output schema declared.

No examples provided.

compare_text ~42

Compare two text strings and highlight differences with detailed line-by-line analysis.

NameTypeReqDescription
text1stringyesFirst text
text2stringyesSecond text

No output schema declared.

No examples provided.

compress_image ~131

Compress and convert images to different formats (webp, jpeg, png, avif). Supports HEIC/HEIF input for conversion. Can also resize images.

NameTypeReqDescription
formatstringOutput format
grayscalebooleanConvert image to grayscale
heightnumberTarget height in pixels (optional)
keepAspectRatiobooleanMaintain aspect ratio when resizing. Set false for square crop.
qualitynumberQuality from 0.1 to 1.0, default 0.9
widthnumberTarget width in pixels (optional)

No output schema declared.

No examples provided.

compress_pdf ~23

Compress a PDF file to reduce its size. Requires an uploaded PDF file.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

compress_video ~151

Compress and convert videos to different formats. Can adjust quality, resolution, codec, and remove audio.

NameTypeReqDescription
audioBitratestringAudio bitrate like '128k'
audioCodecstringAudio codec
crfnumberQuality 0-51, lower is better, 23 is default
formatstringOutput format
fpsstringFrame rate like '30' or '24'
presetstringCompression speed
removeAudiobooleanRemove audio track
scalestringResolution like '1920:1080' or '-1:720'
videoCodecstringVideo codec

No output schema declared.

No examples provided.

decode_base64 ~40

Recover the original plain text from a Base64 string, rejecting input that is not valid Base64.

NameTypeReqDescription
encodedstringyesBase64 encoded text

No output schema declared.

No examples provided.

decode_jwt ~41

Decode and inspect JWT tokens, extracting user details from payload and presenting them in a clean markdown table format.

NameTypeReqDescription
tokenstringyesJWT token to decode

No output schema declared.

No examples provided.

decode_url ~37

Reverse percent-encoding, turning %20-style escape sequences back into the literal characters they represent.

NameTypeReqDescription
encodedstringyesURL encoded string

No output schema declared.

No examples provided.

draft_email ~39

Draft professional business emails with configurable tone and style.

NameTypeReqDescription
promptstringyesEmail purpose or content description
tonestringEmail tone

No output schema declared.

No examples provided.

encode_base64 ~44

Convert plain text into a Base64 string, for embedding binary-unsafe content in JSON, data URIs or HTTP headers.

NameTypeReqDescription
textstringyesText to encode

No output schema declared.

No examples provided.

encode_url ~40

Percent-encode a URL or query-string value so reserved characters such as & = ? and spaces survive transport.

NameTypeReqDescription
urlstringyesURL to encode

No output schema declared.

No examples provided.

extract_text_ocr ~44

Extract text from images and PDF files using OCR (Optical Character Recognition). Supports multiple languages.

NameTypeReqDescription
languagestringLanguage of the text (default: eng)

No output schema declared.

No examples provided.

fetch_page_metadata ~153

Read a web page's metadata without downloading any images: title, description, siteName, canonical URL, language, theme colour, generator, RSS/Atom feeds, and the full OpenGraph and Twitter card tag sets. Also returns `finalUrl`, the address after redirects, which is how you resolve where a domain actually points. This is the fast, cheap counterpart to fetch_site_logo: it does one page fetch and no image work. Use fetch_site_logo instead when the caller wants a logo, favicon or icon. Results are cached for 24 hours.

NameTypeReqDescription
urlstringyesThe page to read, e.g. https://stripe.com/pricing. A bare domain is accepted and assumed to be https.

No output schema declared.

No examples provided.

fetch_site_logo ~342

Get a company's logo from its website URL. Reads the web app manifest, apple-touch-icons, declared favicons, OpenGraph/Twitter images and /favicon.ico, then downloads every candidate and measures its real dimensions — declared `sizes` attributes are frequently wrong, so ranking uses the measurement rather than the claim. Returns `logo` (the best candidate) and `icons` (all candidates, best first; real icon assets deliberately outrank social share images, which are usually a wide marketing banner rather than a logo). Each candidate is { url, source, width, height, format, bytes, rehostedUrl? }. Candidates the site declares but that cannot be fetched are still returned, carrying an `error` field — that is what makes this useful for auditing your own site's icons. SVG logos carry no width/height because they are not rasterised. Page metadata (title, description, OpenGraph, ...) is included too, so there is no need to also call fetch_page_metadata. Use that one instead if you do NOT need the logo: it skips the image downloads entirely and is much faster. Results are cached for 24 hours.

NameTypeReqDescription
rehostbooleanCopy the top candidates to razi.pro's CDN and expose them as `rehostedUrl` (default true). Prefer these for downloading or embedding: many origins block hotlinking or omit CORS headers, so the origin…
urlstringyesThe website to inspect, e.g. https://stripe.com. A bare domain is accepted and assumed to be https.

No output schema declared.

No examples provided.

format_json ~45

Format, validate, and beautify JSON with syntax highlighting.

NameTypeReqDescription
indentnumberIndentation spaces (default 2)
jsonstringyesJSON string to format

No output schema declared.

No examples provided.

generate_blog_outline ~46

Generate SEO-optimized blog post outlines from keywords or topics.

NameTypeReqDescription
sectionsnumberNumber of sections (default 5)
topicstringyesBlog topic or keywords

No output schema declared.

No examples provided.

generate_fake_data ~47

Generate realistic mock data for testing. Automatically formats multiple user records as tables.

NameTypeReqDescription
countnumberNumber of records (default 1)
typestringyesData type

No output schema declared.

No examples provided.

generate_image ~57

Generate AI images from text descriptions using Stable Diffusion. Creates high-quality images based on prompts.

NameTypeReqDescription
negativePromptstringWhat to avoid in the image (optional)
promptstringyesText description of the image to generate

No output schema declared.

No examples provided.

generate_qr_code ~60

Generate QR codes from text or URLs with customization options.

NameTypeReqDescription
errorCorrectionstringError correction level
sizenumberQR code size in pixels (default 256)
textstringyesText or URL to encode

No output schema declared.

No examples provided.

generate_sql ~41

Generate SQL queries from natural language with validation warnings and complexity analysis.

NameTypeReqDescription
descriptionstringyesNatural language query description
dialectstringSQL dialect

No output schema declared.

No examples provided.

generate_text ~68

Generate lorem ipsum, random text, or sentences for testing and placeholder content.

NameTypeReqDescription
countnumberNumber of text blocks to generate (default 1)
lengthnumberLength of text in characters (default 100)
typestringyesType of text to generate

No output schema declared.

No examples provided.

humanize_text ~42

Rewrite AI-generated text to sound more natural and human-like.

NameTypeReqDescription
levelstringHumanization level
textstringyesText to humanize

No output schema declared.

No examples provided.

merge_pdf ~38

Merge multiple PDF files into one. Use this ONLY when all files are already PDFs. For a mix of images and PDFs, use images_to_pdf.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

parse_document ~21

Extract text from uploaded PDF, DOCX, or TXT documents.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

screenshot_url ~356

Capture a screenshot of any public web page, rendered in a real headless browser so JavaScript, web fonts and lazy-loaded images all appear. Returns JSON with a hosted image URL on razi.pro's CDN — not image bytes: { url, width, height, format, bytes, cached, source }. Public pages only: every capture runs in a fresh browser with no cookies or credentials, so anything behind a login is unreachable. Identical requests are cached for 7 days and return the same image (cached: true), so this cannot be used to poll a page for changes. If source is "thumbio" the renderer was unavailable and a fallback provider produced the image, which ignores the fullPage, format, darkMode and delayMs options.

NameTypeReqDescription
darkModebooleanRender with prefers-color-scheme: dark. Has no effect on sites that do not implement a dark theme.
delayMsnumberExtra wait after load, in milliseconds (max 5000). Use for pages with entrance animations or slow client-side rendering.
formatstringImage format (default webp)
fullPagebooleanCapture the entire scrollable page rather than just the viewport. Pages taller than 12000px are truncated at 12000px, which is a browser encoding limit, so a very long article returns only its top po…
heightnumberViewport height in pixels (200-4320, default 800). Ignored when fullPage is true.
urlstringyesThe page to capture. Must be publicly reachable over http(s).
widthnumberViewport width in pixels (200-3840, default 1280)

No output schema declared.

No examples provided.

shorten_url ~48

Create a shortened URL from a long URL. Returns a short razi.pro link.

NameTypeReqDescription
customCodestringOptional custom short code
urlstringyesThe URL to shorten

No output schema declared.

No examples provided.

split_image ~96

Split a storyboard, collage, or grid image into individual images. Uses AI vision to automatically detect panel boundaries, borders, and gaps. Returns a ZIP file of all extracted panels.

NameTypeReqDescription
colsnumberNumber of columns (optional, auto-detected if not provided)
formatstringOutput image format (default: png)
rowsnumberNumber of rows (optional, auto-detected if not provided)

No output schema declared.

No examples provided.

split_pdf ~50

Split a PDF file into multiple files based on page ranges. Requires an uploaded PDF file.

NameTypeReqDescription
rangesarrayyesArray of page ranges (e.g., '1-2', '3-5')

No output schema declared.

No examples provided.

upload_file ~34

Upload a file to cloud storage and get a public URL. Supports images, videos, PDFs, documents up to 50MB.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

Common questions

What is the Razi Tools MCP server?

Razi Tools is an MCP server listed in the public MCP registry as io.github.razikallayi/razi-tools. PDF, image, video, OCR, screenshot, SQL, QR and text tools for agents. No API key, no signup. This page covers its hosted endpoint (https://www.razi.pro/api/mcp).

Is the Razi Tools MCP server safe to use?

Razi Tools scores 36 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Razi Tools MCP server expose?

Razi Tools exposes 29 tools: merge_pdf, split_pdf, compress_pdf, compress_image, compress_video, and 24 more. Their descriptions and schemas cost roughly 2,224 tokens of context every time the server is loaded.

Does the Razi Tools MCP server require authentication?

Yes. Razi Tools asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

Is the Razi Tools MCP server still maintained?

Razi Tools is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.