Razi Tools
REMOTE · WWW.RAZI.PRO · 2 COMPONENTS · SCANNED SEP 21
PDF, image, video, OCR, screenshot, SQL, QR and text tools for agents. No API key, no signup.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security89
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- The endpoint enforces authorisation, but returns a challenge with no valid RFC 9728 metadata, so a client cannot discover where to get a token. See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability0
- Transport blocked by authentication: the endpoint requires auth we don't have to verify streamable-http. See how to fix → View diagnostics → Unverified
Schema Quality & AI Usability0
- Schema blocked by authentication: the endpoint requires auth we don't have to read it. See how to fix → Unverified
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage0
- Tool coverage blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Tool Safety0
- Tool safety blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Capabilities0
- Capabilities blocked by authentication: the endpoint requires auth we don't have to read them. See how to fix → Unverified
Unverified: 6 categories
Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm. Claim this server and supply a read-only token to verify it and lift the score.
How do I install the Razi Tools MCP server?
Razi Tools is a hosted endpoint at https://www.razi.pro/api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · www.razi.pro
claude mcp add --transport http razikallayi-razi-tools 'https://www.razi.pro/api/mcp'
{
"mcpServers": {
"razikallayi-razi-tools": {
"url": "https://www.razi.pro/api/mcp"
}
}
} {
"servers": {
"razikallayi-razi-tools": {
"type": "http",
"url": "https://www.razi.pro/api/mcp"
}
}
} [mcp_servers.razikallayi-razi-tools] url = "https://www.razi.pro/api/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"razikallayi-razi-tools": {
"type": "remote",
"url": "https://www.razi.pro/api/mcp",
"enabled": true
}
}
} openclaw mcp add razikallayi-razi-tools --url 'https://www.razi.pro/api/mcp' --transport streamable-http
mcp_servers:
razikallayi-razi-tools:
url: "https://www.razi.pro/api/mcp" {
"McpServers": {
"razikallayi-razi-tools": {
"Transport": "http",
"Url": "https://www.razi.pro/api/mcp"
}
}
} assistant mcp add razikallayi-razi-tools -t streamable-http -u 'https://www.razi.pro/api/mcp'
{
"mcpServers": {
"razikallayi-razi-tools": {
"type": "http",
"url": "https://www.razi.pro/api/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 9 Sept 26 −27
- Endpoint reachability: reachable → behind authorisation ▼ security
- Authorization: unverified → fail ▼ security
- Tool safety: pass → unverified ▼ security
- Transport: pass → unverified ▼ security
- Capabilities: fail → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- First check of Schema quality: unverified functional
- 8 Sept 26 63
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://www.razi.pro/api/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=www.razi.pro | CN=YR2,O=Let's Encrypt,C=US | 12 Sept 2026 | 11 Dec 2026 | RSA 2048 | SHA256-RSA | 5b5cb6701996625e48e7d57e8c436c9e7b8 |
| SANs: www.razi.pro | ||||||
| CN=YR2,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | 4ebd24947e24d394802d84a52fd5b319 |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of www.razi.pro. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| pro. | present | 42154 | 8 | Verified |
| razi.pro. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Challenged, unverified
The endpoint asked for a token, but we could not retrieve and validate the RFC 9728 metadata that tells a client how to obtain one.
| Result | Challenged, unverified |
|---|---|
| Enforced | On connection |
| HTTP status | 403 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
| content-security-policy | default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://www.youtube.com https://www.googletagmanager.com https://www.clarity.ms https://scripts.clarity.ms https://vercel.live https://va.vercel-scripts.com; worker-src 'self' blob:; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https:; font-src 'self' data:; connect-src 'self' data: blob: https://*.supabase.co wss://*.supabase.co https://*.posthog.com https://us.i.posthog.com https://us-assets.i.posthog.com https://*.clarity.ms https://www.google-analytics.com https://*.google-analytics.com https://*.analytics.google.com https://www.googletagmanager.com https://*.googletagmanager.com https://vitals.vercel-insights.com https://va.vercel-scripts.com https://vercel.live wss://vercel.live https://*.public.blob.vercel-storage.com https://*.upstash.io https://api.dicebear.com wss://worker.razi.pro https://worker.razi.pro/api/peerdrop/files/; frame-src https://www.youtube.com https://youtube.com https://www.youtube-nocookie.com |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(), geolocation=() |
Protected resource metadata
| Retrieved | No |
|---|---|
| Problem | no_resource_metadata |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://www.razi.pro/api/mcp | Auth required | 403 | |
| http (plaintext) | http://www.razi.pro/api/mcp | HTTPS enforced | 308 | https://www.razi.pro/api/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
calculate_percentage ~48
Calculate percentages, percentage increase/decrease, and ratios.
| Name | Type | Req | Description |
|---|---|---|---|
| operation | string | yes | Calculation type |
| value1 | number | yes | First value |
| value2 | number | yes | Second value |
No output schema declared.
No examples provided.
compare_text ~42
Compare two text strings and highlight differences with detailed line-by-line analysis.
| Name | Type | Req | Description |
|---|---|---|---|
| text1 | string | yes | First text |
| text2 | string | yes | Second text |
No output schema declared.
No examples provided.
compress_image ~131
Compress and convert images to different formats (webp, jpeg, png, avif). Supports HEIC/HEIF input for conversion. Can also resize images.
| Name | Type | Req | Description |
|---|---|---|---|
| format | string | – | Output format |
| grayscale | boolean | – | Convert image to grayscale |
| height | number | – | Target height in pixels (optional) |
| keepAspectRatio | boolean | – | Maintain aspect ratio when resizing. Set false for square crop. |
| quality | number | – | Quality from 0.1 to 1.0, default 0.9 |
| width | number | – | Target width in pixels (optional) |
No output schema declared.
No examples provided.
compress_pdf ~23
Compress a PDF file to reduce its size. Requires an uploaded PDF file.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
compress_video ~151
Compress and convert videos to different formats. Can adjust quality, resolution, codec, and remove audio.
| Name | Type | Req | Description |
|---|---|---|---|
| audioBitrate | string | – | Audio bitrate like '128k' |
| audioCodec | string | – | Audio codec |
| crf | number | – | Quality 0-51, lower is better, 23 is default |
| format | string | – | Output format |
| fps | string | – | Frame rate like '30' or '24' |
| preset | string | – | Compression speed |
| removeAudio | boolean | – | Remove audio track |
| scale | string | – | Resolution like '1920:1080' or '-1:720' |
| videoCodec | string | – | Video codec |
No output schema declared.
No examples provided.
decode_base64 ~40
Recover the original plain text from a Base64 string, rejecting input that is not valid Base64.
| Name | Type | Req | Description |
|---|---|---|---|
| encoded | string | yes | Base64 encoded text |
No output schema declared.
No examples provided.
decode_jwt ~41
Decode and inspect JWT tokens, extracting user details from payload and presenting them in a clean markdown table format.
| Name | Type | Req | Description |
|---|---|---|---|
| token | string | yes | JWT token to decode |
No output schema declared.
No examples provided.
decode_url ~37
Reverse percent-encoding, turning %20-style escape sequences back into the literal characters they represent.
| Name | Type | Req | Description |
|---|---|---|---|
| encoded | string | yes | URL encoded string |
No output schema declared.
No examples provided.
draft_email ~39
Draft professional business emails with configurable tone and style.
| Name | Type | Req | Description |
|---|---|---|---|
| prompt | string | yes | Email purpose or content description |
| tone | string | – | Email tone |
No output schema declared.
No examples provided.
encode_base64 ~44
Convert plain text into a Base64 string, for embedding binary-unsafe content in JSON, data URIs or HTTP headers.
| Name | Type | Req | Description |
|---|---|---|---|
| text | string | yes | Text to encode |
No output schema declared.
No examples provided.
encode_url ~40
Percent-encode a URL or query-string value so reserved characters such as & = ? and spaces survive transport.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | URL to encode |
No output schema declared.
No examples provided.
extract_text_ocr ~44
Extract text from images and PDF files using OCR (Optical Character Recognition). Supports multiple languages.
| Name | Type | Req | Description |
|---|---|---|---|
| language | string | – | Language of the text (default: eng) |
No output schema declared.
No examples provided.
fetch_page_metadata ~153
Read a web page's metadata without downloading any images: title, description, siteName, canonical URL, language, theme colour, generator, RSS/Atom feeds, and the full OpenGraph and Twitter card tag sets. Also returns `finalUrl`, the address after redirects, which is how you resolve where a domain actually points. This is the fast, cheap counterpart to fetch_site_logo: it does one page fetch and no image work. Use fetch_site_logo instead when the caller wants a logo, favicon or icon. Results are cached for 24 hours.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | The page to read, e.g. https://stripe.com/pricing. A bare domain is accepted and assumed to be https. |
No output schema declared.
No examples provided.
fetch_site_logo ~342
Get a company's logo from its website URL. Reads the web app manifest, apple-touch-icons, declared favicons, OpenGraph/Twitter images and /favicon.ico, then downloads every candidate and measures its real dimensions — declared `sizes` attributes are frequently wrong, so ranking uses the measurement rather than the claim. Returns `logo` (the best candidate) and `icons` (all candidates, best first; real icon assets deliberately outrank social share images, which are usually a wide marketing banner rather than a logo). Each candidate is { url, source, width, height, format, bytes, rehostedUrl? }. Candidates the site declares but that cannot be fetched are still returned, carrying an `error` field — that is what makes this useful for auditing your own site's icons. SVG logos carry no width/height because they are not rasterised. Page metadata (title, description, OpenGraph, ...) is included too, so there is no need to also call fetch_page_metadata. Use that one instead if you do NOT need the logo: it skips the image downloads entirely and is much faster. Results are cached for 24 hours.
| Name | Type | Req | Description |
|---|---|---|---|
| rehost | boolean | – | Copy the top candidates to razi.pro's CDN and expose them as `rehostedUrl` (default true). Prefer these for downloading or embedding: many origins block hotlinking or omit CORS headers, so the origin… |
| url | string | yes | The website to inspect, e.g. https://stripe.com. A bare domain is accepted and assumed to be https. |
No output schema declared.
No examples provided.
format_json ~45
Format, validate, and beautify JSON with syntax highlighting.
| Name | Type | Req | Description |
|---|---|---|---|
| indent | number | – | Indentation spaces (default 2) |
| json | string | yes | JSON string to format |
No output schema declared.
No examples provided.
generate_blog_outline ~46
Generate SEO-optimized blog post outlines from keywords or topics.
| Name | Type | Req | Description |
|---|---|---|---|
| sections | number | – | Number of sections (default 5) |
| topic | string | yes | Blog topic or keywords |
No output schema declared.
No examples provided.
generate_fake_data ~47
Generate realistic mock data for testing. Automatically formats multiple user records as tables.
| Name | Type | Req | Description |
|---|---|---|---|
| count | number | – | Number of records (default 1) |
| type | string | yes | Data type |
No output schema declared.
No examples provided.
generate_image ~57
Generate AI images from text descriptions using Stable Diffusion. Creates high-quality images based on prompts.
| Name | Type | Req | Description |
|---|---|---|---|
| negativePrompt | string | – | What to avoid in the image (optional) |
| prompt | string | yes | Text description of the image to generate |
No output schema declared.
No examples provided.
generate_qr_code ~60
Generate QR codes from text or URLs with customization options.
| Name | Type | Req | Description |
|---|---|---|---|
| errorCorrection | string | – | Error correction level |
| size | number | – | QR code size in pixels (default 256) |
| text | string | yes | Text or URL to encode |
No output schema declared.
No examples provided.
generate_sql ~41
Generate SQL queries from natural language with validation warnings and complexity analysis.
| Name | Type | Req | Description |
|---|---|---|---|
| description | string | yes | Natural language query description |
| dialect | string | – | SQL dialect |
No output schema declared.
No examples provided.
generate_text ~68
Generate lorem ipsum, random text, or sentences for testing and placeholder content.
| Name | Type | Req | Description |
|---|---|---|---|
| count | number | – | Number of text blocks to generate (default 1) |
| length | number | – | Length of text in characters (default 100) |
| type | string | yes | Type of text to generate |
No output schema declared.
No examples provided.
humanize_text ~42
Rewrite AI-generated text to sound more natural and human-like.
| Name | Type | Req | Description |
|---|---|---|---|
| level | string | – | Humanization level |
| text | string | yes | Text to humanize |
No output schema declared.
No examples provided.
merge_pdf ~38
Merge multiple PDF files into one. Use this ONLY when all files are already PDFs. For a mix of images and PDFs, use images_to_pdf.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
parse_document ~21
Extract text from uploaded PDF, DOCX, or TXT documents.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
screenshot_url ~356
Capture a screenshot of any public web page, rendered in a real headless browser so JavaScript, web fonts and lazy-loaded images all appear. Returns JSON with a hosted image URL on razi.pro's CDN — not image bytes: { url, width, height, format, bytes, cached, source }. Public pages only: every capture runs in a fresh browser with no cookies or credentials, so anything behind a login is unreachable. Identical requests are cached for 7 days and return the same image (cached: true), so this cannot be used to poll a page for changes. If source is "thumbio" the renderer was unavailable and a fallback provider produced the image, which ignores the fullPage, format, darkMode and delayMs options.
| Name | Type | Req | Description |
|---|---|---|---|
| darkMode | boolean | – | Render with prefers-color-scheme: dark. Has no effect on sites that do not implement a dark theme. |
| delayMs | number | – | Extra wait after load, in milliseconds (max 5000). Use for pages with entrance animations or slow client-side rendering. |
| format | string | – | Image format (default webp) |
| fullPage | boolean | – | Capture the entire scrollable page rather than just the viewport. Pages taller than 12000px are truncated at 12000px, which is a browser encoding limit, so a very long article returns only its top po… |
| height | number | – | Viewport height in pixels (200-4320, default 800). Ignored when fullPage is true. |
| url | string | yes | The page to capture. Must be publicly reachable over http(s). |
| width | number | – | Viewport width in pixels (200-3840, default 1280) |
No output schema declared.
No examples provided.
shorten_url ~48
Create a shortened URL from a long URL. Returns a short razi.pro link.
| Name | Type | Req | Description |
|---|---|---|---|
| customCode | string | – | Optional custom short code |
| url | string | yes | The URL to shorten |
No output schema declared.
No examples provided.
split_image ~96
Split a storyboard, collage, or grid image into individual images. Uses AI vision to automatically detect panel boundaries, borders, and gaps. Returns a ZIP file of all extracted panels.
| Name | Type | Req | Description |
|---|---|---|---|
| cols | number | – | Number of columns (optional, auto-detected if not provided) |
| format | string | – | Output image format (default: png) |
| rows | number | – | Number of rows (optional, auto-detected if not provided) |
No output schema declared.
No examples provided.
split_pdf ~50
Split a PDF file into multiple files based on page ranges. Requires an uploaded PDF file.
| Name | Type | Req | Description |
|---|---|---|---|
| ranges | array | yes | Array of page ranges (e.g., '1-2', '3-5') |
No output schema declared.
No examples provided.
upload_file ~34
Upload a file to cloud storage and get a public URL. Supports images, videos, PDFs, documents up to 50MB.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
What is the Razi Tools MCP server?
Razi Tools is an MCP server listed in the public MCP registry as io.github.razikallayi/razi-tools. PDF, image, video, OCR, screenshot, SQL, QR and text tools for agents. No API key, no signup. This page covers its hosted endpoint (https://www.razi.pro/api/mcp).
Is the Razi Tools MCP server safe to use?
Razi Tools scores 36 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Razi Tools MCP server expose?
Razi Tools exposes 29 tools: merge_pdf, split_pdf, compress_pdf, compress_image, compress_video, and 24 more. Their descriptions and schemas cost roughly 2,224 tokens of context every time the server is loaded.
Does the Razi Tools MCP server require authentication?
Yes. Razi Tools asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the Razi Tools MCP server still maintained?
Razi Tools is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.