MCP-Server

castle

io.usefulapi/castle
Daten & Analytik Sicherheit Öffentlich und erreichbar MCP 2026-07-28

Was dieses MCP kann

Queries and aggregates security events and manages live allow and deny lists for IPs, emails, devices, and other event fields.

castle_archive_list_item
Archive a list item
Archive a list entry so it stops matching. Reversible with castle_unarchive_list_item. Castle: DELETE /v1/lists/{list_id}/items/{id}/archive.
Destruktiv
Eingabeschema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['list_id', 'item_id'], 'properties': {'item_id': {'type': 'string', 'description': 'The item to archive.'}, 'list_id': {'type': 'string', 'description': 'The list holding the item.'}}}
castle_count_list_items
Count items in a list
Count the entries in one list, with the same optional filters as the search. Read-only despite being a POST. Castle: POST /v1/lists/{list_id}/items/count.
Nur Lesen
Eingabeschema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['list_id'], 'properties': {'filters': {'type': 'array', 'items': {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'description': 'Optional {field, op, value} filters over the items.'}, 'list_id': {'type': 'string', 'description': 'The list to count.'}}}
castle_create_list
Create a list
Create a new allow or deny list. primary_field is the event field its entries match on, e.g. ip or user.email. Castle: POST /v1/lists.
Destruktiv
Eingabeschema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['name', 'color', 'primary_field'], 'properties': {'name': {'type': 'string', 'description': 'The list name.'}, 'color': {'type': 'string', 'description': 'Dashboard colour label, e.g. $red, $green, $blue — Castle requires one.'}, 'description': {'type': 'string', 'description': 'What this list is for.'}, 'primary_field': {'type': 'string', 'description': 'The event field entries match on, e.g. ip or user.email.'}, 'secondary_field': {'type': 'string', 'description': 'An optional second field entries also carry.'}}}
castle_create_list_item
Add an item to a list
Add an entry to a list — for example block an IP or an email. This changes live policy behaviour. Castle: POST /v1/lists/{list_id}/items.
Destruktiv
Eingabeschema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['list_id', 'primary_value', 'author_type', 'author_identifier'], 'properties': {'comment': {'type': 'string', 'description': 'Why this entry was added.'}, 'list_id': {'type': 'string', 'description': 'The list to add to.'}, 'author_type': {'enum': ['$analyst_email', '$castle_dashboard_user', '$castle_policy', '$user', '$user_email', '$other'], 'type': 'string', 'description': 'What kind of actor is adding this entry.'}, 'primary_value': {'type': 'string', 'description': "The value to add, matching the list's primary_field."}, 'secondary_value': {'type': 'string', 'description': "Value for the list's secondary_field."}, 'auto_archives_at': {'type': 'string', 'description': 'ISO-8601 time to archive the entry automatically.'}, 'author_identifier': {'type': 'string', 'description': "Who is adding it, e.g. the analyst's email address."}}}
castle_get_events_schema
Get the event schema
List the event fields you can filter and group on, with their types. Read this first — the other query tools need real field names. Castle: GET /v1/events/schema.
Nur Lesen
Eingabeschema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {}}
castle_get_list
Get one list
Fetch a single list with its primary and secondary field definitions. Castle: GET /v1/lists/{id}.
Nur Lesen
Eingabeschema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['list_id'], 'properties': {'list_id': {'type': 'string', 'description': "The list's id."}}}
castle_get_list_item
Get one list item
Fetch a single list entry — its value, who added it, the comment and its archive time. Castle: GET /v1/lists/{list_id}/items/{id}.
Nur Lesen
Eingabeschema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['list_id', 'item_id'], 'properties': {'item_id': {'type': 'string', 'description': "The item's id."}, 'list_id': {'type': 'string', 'description': 'The list holding the item.'}}}
castle_group_events
Group security events
Aggregate matching events by one or more fields — the fast way to see which IPs, devices or countries dominate a spike. Read-only despite being a POST. Castle: POST /v1/events/group.
Nur Lesen
Eingabeschema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['filters', 'group_by_fields'], 'properties': {'page': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 1, 'description': '1-based page number.'}, 'filters': {'type': 'array', 'items': {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'description': 'Castle query filters, ANDed together. Each is {field, op, value} — e.g. {"field":"user.email","op":"$eq","value":"a@example.com"}. Operators: $eq, $neq, $in, $nin, $like, $nlike, $contains, $ncontains, $starts_with, $nstarts_with, $ends_with, $nends_with, $matches, $nmatches, $ip_range, $nip_range, $relative_range (value {gt,gteq,lt,lteq} in seconds ago), $range, $exists. Call castle_get_events_schema first to see the available field names.'}, 'results_size': {'type': 'integer', 'maximum': 100, 'minimum': 1, 'description': 'Results per page, 1-100.'}, 'group_by_fields': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Fields to group by, e.g. ["ip", "user.email"]. Names come from the event schema.'}}}
castle_search_events
Search security events
Query the security event stream — logins, registrations, transactions and their risk verdicts. Read-only despite being a POST: Castle takes the query in the body. Castle: POST /v1/events/query.
Nur Lesen
Eingabeschema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['filters'], 'properties': {'page': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 1, 'description': '1-based page number.'}, 'columns': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Only return these event fields.'}, 'filters': {'type': 'array', 'items': {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'description': 'Castle query filters, ANDed together. Each is {field, op, value} — e.g. {"field":"user.email","op":"$eq","value":"a@example.com"}. Operators: $eq, $neq, $in, $nin, $like, $nlike, $contains, $ncontains, $starts_with, $nstarts_with, $ends_with, $nends_with, $matches, $nmatches, $ip_range, $nip_range, $relative_range (value {gt,gteq,lt,lteq} in seconds ago), $range, $exists. Call castle_get_events_schema first to see the available field names.'}, 'query_type': {'enum': ['$records', '$count', '$records_with_count'], 'type': 'string', 'description': 'Return matching records, just a count, or both. Defaults to records.'}, 'results_size': {'type': 'integer', 'maximum': 100, 'minimum': 1, 'description': 'Results per page, 1-100.'}}}
castle_search_list_items
Search items in a list
Search the entries of one list — the blocked IPs, emails or device ids it holds. Read-only despite being a POST. Castle: POST /v1/lists/{list_id}/items/query.
Nur Lesen
Eingabeschema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['list_id'], 'properties': {'page': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 1, 'description': '1-based page number.'}, 'filters': {'type': 'array', 'items': {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'description': 'Optional {field, op, value} filters over the items.'}, 'list_id': {'type': 'string', 'description': 'The list to search.'}, 'results_size': {'type': 'integer', 'maximum': 100, 'minimum': 1, 'description': 'Results per page, 1-100.'}}}
castle_search_lists
Search lists
Find the allow/deny lists defined in the environment. Read-only despite being a POST. Castle: POST /v1/lists/query.
Nur Lesen
Eingabeschema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {'page': {'type': 'integer', 'maximum': 9007199254740991, 'minimum': 1, 'description': '1-based page number.'}, 'filters': {'type': 'array', 'items': {'type': 'object', 'propertyNames': {'type': 'string'}, 'additionalProperties': {}}, 'description': 'Optional {field, op, value} filters over the lists themselves.'}, 'results_size': {'type': 'integer', 'maximum': 100, 'minimum': 1, 'description': 'Results per page, 1-100.'}}}
castle_unarchive_list_item
Unarchive a list item
Restore a previously archived list entry so it matches again. Castle: PUT /v1/lists/{list_id}/items/{id}/unarchive.
Destruktiv
Eingabeschema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['list_id', 'item_id'], 'properties': {'item_id': {'type': 'string', 'description': 'The item to restore.'}, 'list_id': {'type': 'string', 'description': 'The list holding the item.'}}}
castle_update_list
Update a list
Rename a list or change its colour or description. Castle: PUT /v1/lists/{id}.
Destruktiv
Eingabeschema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['list_id'], 'properties': {'name': {'type': 'string', 'description': 'New name.'}, 'color': {'type': 'string', 'description': 'New colour label.'}, 'list_id': {'type': 'string', 'description': 'The list to update.'}, 'description': {'type': 'string', 'description': 'New description.'}}}
castle_update_list_item
Update a list item's comment
Change the comment on a list entry. Castle: PUT /v1/lists/{list_id}/items/{id}.
Destruktiv
Eingabeschema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['list_id', 'item_id', 'comment'], 'properties': {'comment': {'type': 'string', 'description': 'The new comment.'}, 'item_id': {'type': 'string', 'description': 'The item to update.'}, 'list_id': {'type': 'string', 'description': 'The list holding the item.'}}}
Geändert
castle_unarchive_list_item
2. October 2026 02:40
Geändert
castle_archive_list_item
2. October 2026 02:40
Geändert
castle_update_list_item
2. October 2026 02:40
Geändert
castle_create_list_item
2. October 2026 02:40
Geändert
castle_update_list
2. October 2026 02:40
Geändert
castle_create_list
2. October 2026 02:40
Geändert
castle_get_list_item
2. October 2026 02:40
Geändert
castle_count_list_items
2. October 2026 02:40
Geändert
castle_search_list_items
2. October 2026 02:40
Geändert
castle_get_list
2. October 2026 02:40
Geändert
castle_search_lists
2. October 2026 02:40
Geändert
castle_group_events
2. October 2026 02:40
Geändert
castle_search_events
2. October 2026 02:40
Geändert
castle_get_events_schema
2. October 2026 02:40
Hinzugefügt
castle_unarchive_list_item
30. September 2026 02:40
Hinzugefügt
castle_archive_list_item
30. September 2026 02:40
Hinzugefügt
castle_update_list_item
30. September 2026 02:40
Hinzugefügt
castle_create_list_item
30. September 2026 02:40
Hinzugefügt
castle_update_list
30. September 2026 02:40
Hinzugefügt
castle_create_list
30. September 2026 02:40
Hinzugefügt
castle_get_list_item
30. September 2026 02:40
Hinzugefügt
castle_count_list_items
30. September 2026 02:40
Hinzugefügt
castle_search_list_items
30. September 2026 02:40
Hinzugefügt
castle_get_list
30. September 2026 02:40
Hinzugefügt
castle_search_lists
30. September 2026 02:40
Hinzugefügt
castle_group_events
30. September 2026 02:40
Hinzugefügt
castle_search_events
30. September 2026 02:40
Hinzugefügt
castle_get_events_schema
30. September 2026 02:40

Crypto Bot Audit + Market Data (x402 paid)

io.github.kaminariouji/x402-audit-agent

Audits crypto bot source code and provides paid crypto market, token, gas, stablecoin, and DeFi TVL data.

TunnelMind Data API

ai.tunnelmind/data

Aggregates web, routing, supply-chain, tracker, threat, and agent-registry intelligence into risk verdicts, evidence, receipts, a…

Polyform

org.polyform/polyform

Offers pay-per-call APIs for economic, financial, geographic, healthcare, domain, email, sanctions, blockchain, and business risk…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

Qiniso

io.github.qinisolabs/qiniso

Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…

SYNTHORA x402 Intelligence Mesh

com.hergertsynthora/synthora-x402

Delivers paid intelligence on markets, crypto, prediction markets, maritime and space risks, domain and wallet exposure, sanction…

Satoshidata Wallet Intel

io.github.wrbtc/wallet-intelligence

Provides Bitcoin wallet intelligence, address labels, trust and risk signals, transaction verification, entity activity, fees, me…

Cloudflare Radar

io.github.pipeworx-io/cloudflare-radar

Provides Cloudflare Radar internet observatory data on DDoS attacks, BGP leaks, domain popularity, internet quality, and traffic …