Mmcp.market

SandboxAPIs MCP server

by sandboxapis.dev·dev.sandboxapis/mcp·v0.3.13

Drop-in read-only replicas of GitHub, Jira, Slack and 18 more, preloaded with one fake company.

C68/100grade C
What users say
No reviews yet
Be the first
Safety scan
C68/100

full report

Adoption
New

878 downloads/wk

Reviews

Write one

Nobody has reviewed SandboxAPIs yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

SandboxAPIs tools (10)

write = sends, deletes, buys or posts

Read from the package source without running it. The installed server may list more.

  • check_budget

    Costs nothing \u2014 call it before any loop of more than a handful of requests. Returns this server's real hourly window (limit, remaining, when it resets) read from the provider's own budget endpoint, which is exempt from the budget it reports, plus whether a key is set and where to raise the limit. The window is ONE bucket per caller shared across every provider host, so the numbers apply to al

  • get_pull_request

    Fetch one PR (GitHub) / MR (GitLab) plus its reviews (GitHub) / approvals (GitLab). Returns both in one result; each carries provider-form ids for cross-referencing.

  • get_repository

    Fetch one repository by name (default: the flagship repo). Provider-shaped, with provider-form ids.

  • get_snapshot

    Return the pinned, reproducible hostname for a provider \u2014 point your client's base URL at it for drift-free CI. A snapshot regenerates byte-identically on every request.

  • get_user

    Fetch a user by login/username. Provider-shaped, with provider-form ids.

  • list_issues

    List a repo's issues. Optional state filter (open/closed/all).

  • list_pull_requests

    List a repo's pull requests (GitHub) or merge requests (GitLab). Optional state filter.

  • list_repositories

    List repositories for the universe's org. Results are identical to the provider's REST API and carry provider-form ids (node_id / numeric id).

  • orient

    START HERE. Returns everything needed to use SandboxAPIs with no docs: the universe/theme, every API surface and its base URL (git hosts and issue trackers), live-vs-snapshot modes and how to pin, the org and its teams/repos, notable entry points (each with a ready-to-run REST path), where the coverage manifest lives, and this server's access block \u2014 whether a key is set and how many requests

  • search_commits_by_author

    Find commits authored by a given login in a repo. Returns SHAs (identical across GitHub and GitLab, invariant #5) with a REST path to fetch each \u2014 so you can cross-reference against either provider.

Public scan report

scanner v0.1.9 · 2026-09-20 · same rubric, same numbers if you re-run it

1 low
  • Code scan3 source files scanned25/25
  • Live reliabilityno gateway calls yet and no remote to proben/a
  • Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitylocal package, no credentials required12/15
  • Maintenanceno repository listed3/15
  • Maintainer identityverified namespace with website, no repo4/10

Findings (1)

  • lowNo source repository listedmaint.no-repo
Overall 68/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install directly

Runs npx -y @sandboxapis/mcp on your machine. Read the scan report first; the gateway never runs local packages.

claude mcp add mcp -- npx -y @sandboxapis/mcp
Add to Cursor

SandboxAPIs: common questions

Is SandboxAPIs MCP server safe?
With care: it is graded C, so read the findings first (68/100). Read the SandboxAPIs safety report
How do I install SandboxAPIs?
It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
Does SandboxAPIs need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is SandboxAPIs maintained?
The latest release is v0.3.13.
What can I use instead of SandboxAPIs?
Servers from other publishers that do the same job: GitHub MCP server, Atlassian Rovo MCP Server and uploads.sh MCP server. Compare all SandboxAPIs alternatives.

Alternatives to SandboxAPIs

Same job from other publishers: the closest match first, then the best rated.

All SandboxAPIs alternatives →
  • GitHub
    Connect AI assistants to GitHub - manage repos, issues, PRs, and workflows through natural language.
    A
  • Atlassian Rovo MCP Server
    Connect to Atlassian Jira, Confluence, Loom, and more to search, create, and manage your work.
    A
  • uploads.sh
    Host files from coding agents; stage on a branch and attach to GitHub PRs.
    A
  • Agent Harnesses
    Agent-harness picks and decision guides; pick_infrastructure adds live GitHub/HN discovery.
    A
  • Jira Alerts (JSM Operations)
    MCP server for Jira Service Management Operations — alerts, on-call schedules and responders
    B

More from sandboxapis.dev