mrkeyoor.com_
Mon 28 Sept 15:17 UTC
Self-Hostedevaluationupdated 28 Sept 2026

anythingmcp review

AnythingMCP turns existing REST, SOAP, GraphQL, OData, database, and MCP services into tools behind one Model Context Protocol endpoint. It is a self-hosted gateway for teams whose business systems do not already speak MCP, with a visual tool editor, access controls, audit logs, and a catalog of ready-made adapters.

Verdict

Our AnythingMCP install pulled 2,046 packages and used 1,443 MB, then its build stopped after 3 seconds because DATABASE_URL was absent. Use the published Docker quickstart for evaluation, and consider the platform when several non-MCP systems need one governed agent endpoint. Do not mistake the 265-adapter catalog for zero-configuration infrastructure: production still requires database operations, secret custody, tool-level data review, and careful handling of mappings that fail open by default.

We ran it

Lab card: what happened when we ran anythingmcpScreenshot of anythingmcp (anythingmcp.com)
Install✓ · 56s2046 packages · 1443 MB
Build✗ · 3s
Tests✗ · 36s4860 passed · 0 failed · 78 skipped of 4938 (jest)
Known vulns00 critical · 0 high · 0 moderate · 0 low (npm audit)
Repo1593 files~125,754 lines of source · 12.3 MB · 17 CI workflows · Dockerfile

Answers from our run

Does anythingmcp build from source?

Dependencies installed in 56 seconds (2046 packages), and the build failed. We cloned commit c69d517 into a clean Debian container with 3 CPUs and no project-specific setup.

Do anythingmcp's tests pass?

Yes: 4860 of 4938 passed when we ran the project's own test command (jest). Some failures need services or credentials a bare container does not have.

Does anythingmcp have known vulnerabilities in its dependencies?

npm audit found none in the dependency tree at the time of our run.

Who should not use anythingmcp?

Developers expecting a source checkout to build without service configuration: our build stopped because Prisma could not resolve DATABASE_URL.

What are the alternatives to anythingmcp?

ContextForge, Docker MCP Gateway, MetaMCP. Our AnythingMCP install pulled 2,046 packages and used 1,443 MB, then its build stopped after 3 seconds because DATABASE_URL was absent.

Setup2/52,046 packages installed, but source build and test commands failed
Docs5/5Detailed quickstart, deployment, connector, auth, and privacy docs
Community4/5536 stars, 27 issues and PRs, and a same-day release
Maturity3/5v0.15.0 is active, but source checks and connectors have gaps

Who it’s for

Teams connecting Claude, ChatGPT, Copilot, or another MCP client to several internal APIs and databases.
Companies with ERP, e-commerce, SOAP, or SQL systems that would otherwise need separate custom MCP servers.
Operators who need credentials, tool permissions, response shaping, and call logs kept on their own infrastructure.
TypeScript teams prepared to run PostgreSQL, manage encryption keys, and review each generated tool before exposing it to an agent.

Who it’s NOT for

Developers expecting a source checkout to build without service configuration: our build stopped because Prisma could not resolve DATABASE_URL.
Workflows that require file uploads through the custom tool builder: open issue 645 says multipart values are sent as text and real file parts are unsupported.
SOAP estates that depend on WS-Security UsernameToken today: the README says those headers are not implemented, and issue 735 confirms the UI option is not used by the engine.
Teams that assume response shaping always blocks sensitive fields: mappings return the raw upstream response on error unless fallbackToRaw is explicitly set to false.
ARM-only operators who cannot accept emulation: the published image is amd64-only and the quickstart pins linux/amd64.
SaaS vendors unwilling to meet AGPL source-offer duties for modified network deployments or buy a commercial license.

Setup reality

Our sandbox installed 2,046 npm packages in 56 seconds and used 1,443 MB on disk. The build failed after 3 seconds because Prisma could not resolve DATABASE_URL. Tests exited 1 after 36 seconds: Jest reported 4,860 passed, 0 failed, and 78 skipped, while 112 suites failed to run. Npm audit found 0 known vulnerabilities.

The published-image quickstart needs Docker 24+, OpenSSL, PostgreSQL, a JWT secret, and an encryption key. Lose the encryption key and stored connector credentials must be entered again. A reachable production instance also needs TLS, MCP authentication, backups, and a deliberate first-admin registration.

The 12.3 MB checkout had 1,593 files and about 125,754 lines of source at commit c69d517. It is an npm-workspace monorepo with a Dockerfile, Compose configuration, and 17 CI workflow files, but no root tests directory. Local development requires Node 22.12 or newer, npm 9+, PostgreSQL, environment links in both packages, Prisma generation, and migrations.

Six connector types sit behind one MCP endpoint

AnythingMCP converts 6 connector types into tools: REST, SOAP, GraphQL, OData, databases, and other MCP servers. A workspace can assign selected connectors to one MCP endpoint, then restrict which roles see which tools. That starts earlier in the integration chain than most MCP gateways. It is meant for the ERP, internal API, or database that has no MCP server yet, rather than only combining servers someone else already built.

The README lists 265 adapters and more than 2,400 tools, including ERP and e-commerce systems that are awkward to connect by hand. Users can also import OpenAPI, Postman, cURL, or WSDL definitions. The visual editor can rename tools and map parameters before an agent sees them.

The source checkout uses 1,443 MB before any database data

Our sandbox installed 2,046 npm packages in 56 seconds and occupied 1,443 MB on disk. The checkout itself was 12.3 MB, with 1,593 files and roughly 125,754 lines of source at commit c69d517. This is a full platform built as backend and frontend workspaces, not a small MCP executable. PostgreSQL is required, Redis is optional, and production normally adds a reverse proxy and TLS.

What happened when we ran it

Our install succeeded, but the build exited 1 after 3 seconds. The backend first regenerated a catalog containing 265 adapters across 15 regions. Prisma then tried to generate its client and stopped because it could not resolve the DATABASE_URL environment variable. The log establishes that missing configuration and nothing beyond it. We did not supply a database URL after the failure, so this run does not show whether a configured source build would pass.

The test command also exited 1 after 36 seconds. Jest counted 4,860 passed, 0 failed, and 78 skipped out of 4,938 individual tests, yet 112 test suites failed to run. The tail named ConvertKit and Loops live specs, a Prisma service spec, an MCP usage spec, and an email-detection spec, but did not include their underlying error messages. Npm audit found 0 known vulnerabilities in the installed packages.

A build-time database requirement changes the quickstart choice

AnythingMCP's source build invokes prisma generate before Nest compiles, so DATABASE_URL is needed even for that build command. The deployment guide's manual development path creates .env, links it into both workspaces, exports the variables, starts PostgreSQL, generates Prisma files, and runs migrations. Our clean container intentionally had no secrets or services, and the 3-second failure shows that the root build is not isolated from runtime configuration.

The prebuilt Compose route avoids compiling the monorepo locally, but it is not maintenance-free. ENCRYPTION_KEY protects stored connector credentials, and losing it forces every connector to be credentialed again. The first registered account becomes admin. Production exposure also needs HTTPS and MCP authentication; the local quickstart binds ports 3000 and 4000 to loopback because it has no TLS terminator.

Response shaping returns raw data unless you close the fallback

Per-tool response mapping can drop or rename fields before they reach an AI client. That is useful for removing an IBAN, tax identifier, or oversized payload while keeping the full upstream result in the local audit log. The documented default has a sharp edge: if the mapping fails at runtime, AnythingMCP returns the raw response and logs a warning. Set fallbackToRaw to false wherever disclosure must fail closed.

Tool permissions deserve the same treatment. Database queries are read-only by default, and MCP annotations can distinguish read and destructive calls, but imported systems can still expose create or update operations. AnythingMCP supplies role-based whitelists and recommends a read-only database user. Those controls are ingredients, not proof. A production review should test each role, response map, and failure path against the exact connector credentials it receives.

The 265-adapter catalog includes documented limits

AnythingMCP says 21 of its 265 adapters need no API key. Others require user credentials, and some catalog entries are explicitly marked as built from vendor documentation without a live seller account. That label is useful honesty. It also means catalog count is not a compatibility guarantee. Test authentication, pagination, destructive actions, and error responses against your own vendor account before giving the tools to an agent.

Current gaps are concrete. Open issue 645 says the custom builder cannot send a real multipart file, even when multipart/form-data is selected. Issue 735 says the SOAP engine does not emit WS-Security UsernameToken headers despite the auth type appearing in the schema and UI. Issue 788 reports a cURL and Postman placeholder regex that can stall the Node event loop on long unmatched brace input, with a fix proposed in pull request 789.

Version 0.15.0 is active, while licensing needs a close read

Release v0.15.0 and the last repository push both landed on September 28, 2026. GitHub showed 536 stars and 27 combined issues and pull requests. The same-day release adds self-hosted editions and license reporting. Community allows up to 3 active users, while paid editions cover work teams and Business adds more users, SSO, and SCIM. That current model is more specific than older statements that every self-hosted feature is included.

The core is AGPL-3.0-only, while code under ee/ has a separate commercial license. Internal use and modification are allowed. If you offer a modified AnythingMCP as a network service, the license FAQ says users must be offered the source of that modified version. Teams building a proprietary hosted product should settle that obligation or commercial licensing before making this gateway central to their architecture.

Pick it when your systems do not speak MCP yet

AnythingMCP's strongest case combines several non-MCP systems, 6 supported connector types, and a need to keep credentials and audit records in-house. In that setting, one governed endpoint can replace several bespoke adapters. Our 2,046-package install and failed default build show the cost: this is infrastructure with a database, secrets, migrations, auth, and a large connector surface.

Alternatives

ProjectWhat it isPick it when
ContextForgeA gateway and registry for federating MCP servers that already exist.pick this instead when your tools already speak MCP and federation, virtual servers, and registry management are the main job.
Docker MCP GatewayA gateway that runs catalog MCP servers in containers with Docker-managed isolation and secrets.pick this instead when published MCP servers cover your systems and container isolation matters more than converting arbitrary APIs.
MetaMCPA middleware layer for grouping existing MCP servers into namespaced endpoints.pick this instead when you mainly need to combine and re-scope MCP servers per client rather than generate tools from REST, SOAP, or SQL.

What people are saying

  1. [github-trending] HelpCode-ai/anythingmcp

Sources

  1. AnythingMCP repository and README
  2. AnythingMCP deployment guide
  3. AnythingMCP v0.15.0 release notes
  4. AnythingMCP license FAQ
  5. Multipart file-upload issue 645
  6. SOAP WS-Security issue 735
  7. cURL and Postman import ReDoS issue 788

More self-hosted reviews

Calibre-Web-Automated · CF-Server-Monitor · niubigeo · kuboard-press · taskview-community · dae · the whole board →