MCP Server

pipehero

io.github.pipehero/pipehero
Developer Tools Public & reachable MCP 2026-07-28

What this MCP does

Captures, inspects, replays, tests, monitors, and documents webhooks and API endpoints through local tunnels.

add_api_example
Save a response example on an endpoint (for instance the 402 your handler returns for a declined card). Replaces the example with the same name, so it is safe to repeat.
Idempotent
Input schema
{'type': 'object', 'required': ['collection_id', 'name', 'status'], 'properties': {'body': {'description': 'Example response body (any JSON).'}, 'name': {'type': 'string', 'description': 'e.g. Card declined.'}, 'path': {'type': 'string', 'description': 'Route path as written in the code, e.g. /v1/charges/:id or /v1/charges/{id}.'}, 'method': {'type': 'string', 'description': 'HTTP method of the route, e.g. POST. Use with path instead of endpoint_id.'}, 'status': {'type': 'integer'}, 'headers': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'value'], 'properties': {'name': {'type': 'string'}, 'value': {'type': 'string'}}}}, 'endpoint_id': {'type': 'string', 'description': 'Id of the endpoint. Alternative to method + path.'}, 'status_text': {'type': 'string'}, 'collection_id': {'type': 'string', 'description': 'Id from list_api_collections.'}}}
check_api_drift
Compare a collection's docs with the real traffic a tunnel captured (Pro/Team). Returns routes nobody documented, status codes with no example, response or request fields missing from every example (or with another type), undocumented query parameters, and documented fields that never appear. Each finding includes `request_id` of the newest request that shows it: pass it to save_captured_request to add it to the docs, or fix the docs with upsert_api_endpoint and add_api_example. Use it to find out what drifted after a code change.
Read only
Input schema
{'type': 'object', 'required': ['collection_id', 'tunnel'], 'properties': {'limit': {'type': 'integer', 'description': 'How many recent requests to compare (default 200, max 500).'}, 'tunnel': {'type': 'string', 'description': 'Subdomain of the tunnel whose traffic to compare.'}, 'collection_id': {'type': 'string'}}}
create_api_collection
Create an empty API collection. Prefer import_api_spec when there is an OpenAPI file, and upsert_api_endpoint to fill it from the code.
Input schema
{'type': 'object', 'required': ['name'], 'properties': {'name': {'type': 'string'}, 'description': {'type': 'string'}}}
delete_api_endpoint
Delete an endpoint and its examples. Use when the route no longer exists in the code. Cannot be undone.
Destructive Idempotent
Input schema
{'type': 'object', 'required': ['collection_id'], 'properties': {'path': {'type': 'string', 'description': 'Route path as written in the code, e.g. /v1/charges/:id or /v1/charges/{id}.'}, 'method': {'type': 'string', 'description': 'HTTP method of the route, e.g. POST. Use with path instead of endpoint_id.'}, 'endpoint_id': {'type': 'string', 'description': 'Id of the endpoint. Alternative to method + path.'}, 'collection_id': {'type': 'string', 'description': 'Id from list_api_collections.'}}}
export_api_collection
Export a collection as an OpenAPI 3.1 or Postman 2.1 document. Handy to read the whole API at once.
Read only
Input schema
{'type': 'object', 'required': ['collection_id'], 'properties': {'format': {'enum': ['openapi', 'postman'], 'type': 'string'}, 'collection_id': {'type': 'string'}}}
get_api_collection
Get one collection's folders, endpoints (id, method, path, name, version, example count) and environments (with their variables).
Read only
Input schema
{'type': 'object', 'required': ['collection_id'], 'properties': {'collection_id': {'type': 'string'}}}
get_api_endpoint
Get one endpoint in full: description, parameters, headers, request body, saved response examples and its current `version`. Identify it by endpoint_id or by method + path.
Read only
Input schema
{'type': 'object', 'required': ['collection_id'], 'properties': {'path': {'type': 'string', 'description': 'Route path as written in the code, e.g. /v1/charges/:id or /v1/charges/{id}.'}, 'method': {'type': 'string', 'description': 'HTTP method of the route, e.g. POST. Use with path instead of endpoint_id.'}, 'endpoint_id': {'type': 'string', 'description': 'Id of the endpoint. Alternative to method + path.'}, 'collection_id': {'type': 'string', 'description': 'Id from list_api_collections.'}}}
get_request
Get the full request and response (headers + body) of one captured webhook by id.
Read only
Input schema
{'type': 'object', 'required': ['subdomain', 'id'], 'properties': {'id': {'type': 'string'}, 'subdomain': {'type': 'string'}}}
import_api_spec
Import an OpenAPI 3.x document (as JSON), a Postman v2.x collection (JSON) or a curl command into a new collection, or into `collection_id`. All or nothing, and plan limits are checked first. Credentials are never imported (they become variables). Convert YAML to JSON before sending.
Input schema
{'type': 'object', 'required': ['format', 'content'], 'properties': {'name': {'type': 'string', 'description': 'Name for the new collection.'}, 'format': {'enum': ['openapi', 'postman', 'har', 'curl'], 'type': 'string'}, 'content': {'description': 'The document (object or JSON string), or the curl command.'}, 'collection_id': {'type': 'string', 'description': 'Add to this collection instead of creating one.'}}}
list_api_collections
List the workspace's API collections (saved endpoints with examples and environments). Start here to find a collection_id.
Read only
Input schema
{'type': 'object', 'properties': {}}
list_api_monitors
See which endpoints of a collection are checked on a schedule (Pro/Team monitors) and how they are doing: state (healthy, failing, blip, paused, waiting), the last check with its status, latency and error, and since when it has been failing. Use it to find out what is broken in staging or production, then read the endpoint and its code. Read-only: people decide what to monitor.
Read only
Input schema
{'type': 'object', 'required': ['collection_id'], 'properties': {'collection_id': {'type': 'string'}}}
list_api_proposals
See what happened to the changes you proposed. Some workspaces review AI changes: your write tools then answer `pending_review` and change nothing until a teammate approves. This lists the latest proposals with their status (pending, approved, rejected with the reviewer's reason, or failed with why) so you can tell whether a change went through.
Read only
Input schema
{'type': 'object', 'properties': {}}
list_api_runs
Recent runs of an endpoint (newest first, default 5): who/what was sent and what came back. Use to see what happened the last time it was run.
Read only
Input schema
{'type': 'object', 'required': ['collection_id'], 'properties': {'path': {'type': 'string', 'description': 'Route path as written in the code, e.g. /v1/charges/:id or /v1/charges/{id}.'}, 'limit': {'type': 'integer', 'description': '1 to 20.'}, 'method': {'type': 'string', 'description': 'HTTP method of the route, e.g. POST. Use with path instead of endpoint_id.'}, 'endpoint_id': {'type': 'string', 'description': 'Id of the endpoint. Alternative to method + path.'}, 'collection_id': {'type': 'string', 'description': 'Id from list_api_collections.'}}}
list_requests
List recent webhooks/requests captured for a tunnel. Returns id, method, path, status and bodies.
Read only
Input schema
{'type': 'object', 'required': ['subdomain'], 'properties': {'subdomain': {'type': 'string'}}}
list_tunnels
List the user's Pipehero tunnels and whether each is currently online.
Read only
Input schema
{'type': 'object', 'properties': {}}
replay_request
Replay a captured webhook to the user's localhost (the tunnel CLI must be running).
Destructive Open world
Input schema
{'type': 'object', 'required': ['subdomain', 'id'], 'properties': {'id': {'type': 'string'}, 'subdomain': {'type': 'string'}}}
run_api_endpoint
Send an endpoint against an environment and return the real response (status, headers, body up to 20 KB). A `local` environment goes through the user's tunnel to their localhost (the CLI must be running); staging/prod are sent from Pipehero's cloud (Pro/Team) to public addresses only. Sending to a `prod` environment with a write method needs confirm_write_to_prod: true, which you should only pass after the user agrees. Use it to check that the code you wrote behaves as documented.
Destructive Open world
Input schema
{'type': 'object', 'required': ['collection_id', 'environment'], 'properties': {'path': {'type': 'string', 'description': 'Route path as written in the code, e.g. /v1/charges/:id or /v1/charges/{id}.'}, 'method': {'type': 'string', 'description': 'HTTP method of the route, e.g. POST. Use with path instead of endpoint_id.'}, 'variables': {'type': 'object', 'description': 'Values for {{variables}} the environment doesn\'t define, e.g. {"id": "ch_123"}.', 'additionalProperties': {'type': 'string'}}, 'endpoint_id': {'type': 'string', 'description': 'Id of the endpoint. Alternative to method + path.'}, 'environment': {'type': 'string', 'description': 'Environment name or id, e.g. local.'}, 'collection_id': {'type': 'string', 'description': 'Id from list_api_collections.'}, 'confirm_write_to_prod': {'type': 'boolean'}}}
save_captured_request
Document a real request captured by a tunnel (get its id from list_requests). If an endpoint already covers the route, the response is added to it as an example; otherwise an endpoint is created from the request. Credentials, cookies and signatures are replaced by {{variables}} and only JSON bodies are kept. A response already saved as an example is not duplicated. Use it to document webhooks and calls you have only seen in traffic.
Idempotent
Input schema
{'type': 'object', 'required': ['collection_id', 'tunnel', 'request_id'], 'properties': {'path': {'type': 'string'}, 'folder': {'type': 'string', 'description': 'Folder for a newly created endpoint, created by name if missing.'}, 'method': {'type': 'string', 'description': 'With path: the endpoint that should receive the example.'}, 'tunnel': {'type': 'string', 'description': 'Subdomain of the tunnel that captured the request.'}, 'request_id': {'type': 'string', 'description': 'Id of the captured request, from list_requests.'}, 'endpoint_id': {'type': 'string', 'description': 'Add the example to this endpoint instead of matching by route. Alternative to method + path.'}, 'collection_id': {'type': 'string'}}}
send_test_webhook
Send a generated test webhook to the user's localhost (the tunnel CLI must be running). Provide a `provider` (stripe, github, shopify, clerk, slack, resend, paddle, polar, lemonsqueezy) and optional `event` for a realistic sample payload, or pass a custom JSON `body`. Pro plan required.
Destructive Open world
Input schema
{'type': 'object', 'required': ['subdomain', 'provider'], 'properties': {'body': {'type': 'string', 'description': 'Custom JSON body (overrides the template)'}, 'event': {'type': 'string'}, 'provider': {'type': 'string'}, 'subdomain': {'type': 'string'}}}
set_long_requests
Opt a tunnel into a 120-second ingress timeout instead of the 30-second default — for tool calls that legitimately run long, e.g. an MCP server exposed through the tunnel. Persists on the tunnel; pass enabled: false to revert to the 30-second default.
Idempotent
Input schema
{'type': 'object', 'required': ['subdomain', 'enabled'], 'properties': {'enabled': {'type': 'boolean'}, 'subdomain': {'type': 'string'}}}
set_ws_passthrough
Opt a tunnel into WebSocket passthrough, so an application-level WebSocket connection (e.g. a mobile/web app's own realtime feature) can be relayed to your localhost. Pro/Team plan required to enable; pass enabled: false to disable on any plan.
Idempotent
Input schema
{'type': 'object', 'required': ['subdomain', 'enabled'], 'properties': {'enabled': {'type': 'boolean'}, 'subdomain': {'type': 'string'}}}
upsert_api_endpoint
Document an endpoint: creates it, or updates the existing one for the same method + path. Use it whenever you add or change a route in the code, so the docs stay true. Only the fields you send change. `path` may use :id, {id} or {{id}} for variables. `folder` is created by name if missing. Send `version` (from get_api_endpoint) to avoid overwriting a teammate's edit; a stale version is rejected.
Idempotent
Input schema
{'type': 'object', 'required': ['collection_id', 'method', 'path'], 'properties': {'body': {'description': 'Example request body (any JSON). null clears it.'}, 'kind': {'enum': ['http', 'event'], 'type': 'string', 'description': '`event` for a webhook your app sends.'}, 'name': {'type': 'string', 'description': 'Short title, e.g. Create a charge. Defaults to METHOD /path.'}, 'path': {'type': 'string'}, 'folder': {'type': 'string', 'description': 'Folder name, e.g. Charges.'}, 'method': {'type': 'string'}, 'params': {'type': 'array', 'items': {'type': 'object', 'required': ['name'], 'properties': {'in': {'enum': ['path', 'query', 'header', 'body'], 'type': 'string'}, 'name': {'type': 'string'}, 'type': {'type': 'string'}, 'required': {'type': 'boolean'}, 'description': {'type': 'string'}}}, 'description': 'Documented fields.'}, 'headers': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'value'], 'properties': {'name': {'type': 'string'}, 'value': {'type': 'string'}}}}, 'version': {'type': 'integer'}, 'description': {'type': 'string'}, 'collection_id': {'type': 'string'}}}
Added
list_api_runs
Sept. 23, 2026, 2:47 a.m.
Added
check_api_drift
Sept. 23, 2026, 2:47 a.m.
Added
list_api_proposals
Sept. 23, 2026, 2:47 a.m.
Added
list_api_monitors
Sept. 23, 2026, 2:47 a.m.
Added
save_captured_request
Sept. 23, 2026, 2:47 a.m.
Added
run_api_endpoint
Sept. 23, 2026, 2:47 a.m.
Added
export_api_collection
Sept. 23, 2026, 2:47 a.m.
Added
import_api_spec
Sept. 23, 2026, 2:47 a.m.
Added
delete_api_endpoint
Sept. 23, 2026, 2:47 a.m.
Added
add_api_example
Sept. 23, 2026, 2:47 a.m.
Added
upsert_api_endpoint
Sept. 23, 2026, 2:47 a.m.
Added
create_api_collection
Sept. 23, 2026, 2:47 a.m.
Added
get_api_endpoint
Sept. 23, 2026, 2:47 a.m.
Added
get_api_collection
Sept. 23, 2026, 2:47 a.m.
Added
list_api_collections
Sept. 23, 2026, 2:47 a.m.
Added
set_ws_passthrough
Sept. 17, 2026, 12:45 p.m.
Added
set_long_requests
Sept. 17, 2026, 12:45 p.m.
Added
send_test_webhook
Sept. 17, 2026, 12:45 p.m.
Added
replay_request
Sept. 17, 2026, 12:45 p.m.
Added
get_request
Sept. 17, 2026, 12:45 p.m.
Added
list_requests
Sept. 17, 2026, 12:45 p.m.
Added
list_tunnels
Sept. 17, 2026, 12:45 p.m.