Six connector types sit behind one MCP endpoint
AnythingMCP converts 6 connector types into tools: REST, SOAP, GraphQL, OData, databases, and other MCP servers. A workspace can assign selected connectors to one MCP endpoint, then restrict which roles see which tools. That starts earlier in the integration chain than most MCP gateways. It is meant for the ERP, internal API, or database that has no MCP server yet, rather than only combining servers someone else already built.
The README lists 265 adapters and more than 2,400 tools, including ERP and e-commerce systems that are awkward to connect by hand. Users can also import OpenAPI, Postman, cURL, or WSDL definitions. The visual editor can rename tools and map parameters before an agent sees them.
The source checkout uses 1,443 MB before any database data
Our sandbox installed 2,046 npm packages in 56 seconds and occupied 1,443 MB on disk. The checkout itself was 12.3 MB, with 1,593 files and roughly 125,754 lines of source at commit c69d517. This is a full platform built as backend and frontend workspaces, not a small MCP executable. PostgreSQL is required, Redis is optional, and production normally adds a reverse proxy and TLS.
What happened when we ran it
Our install succeeded, but the build exited 1 after 3 seconds. The backend first regenerated a catalog containing 265 adapters across 15 regions. Prisma then tried to generate its client and stopped because it could not resolve the DATABASE_URL environment variable. The log establishes that missing configuration and nothing beyond it. We did not supply a database URL after the failure, so this run does not show whether a configured source build would pass.
The test command also exited 1 after 36 seconds. Jest counted 4,860 passed, 0 failed, and 78 skipped out of 4,938 individual tests, yet 112 test suites failed to run. The tail named ConvertKit and Loops live specs, a Prisma service spec, an MCP usage spec, and an email-detection spec, but did not include their underlying error messages. Npm audit found 0 known vulnerabilities in the installed packages.
A build-time database requirement changes the quickstart choice
AnythingMCP's source build invokes prisma generate before Nest compiles, so DATABASE_URL is needed even for that build command. The deployment guide's manual development path creates .env, links it into both workspaces, exports the variables, starts PostgreSQL, generates Prisma files, and runs migrations. Our clean container intentionally had no secrets or services, and the 3-second failure shows that the root build is not isolated from runtime configuration.
The prebuilt Compose route avoids compiling the monorepo locally, but it is not maintenance-free. ENCRYPTION_KEY protects stored connector credentials, and losing it forces every connector to be credentialed again. The first registered account becomes admin. Production exposure also needs HTTPS and MCP authentication; the local quickstart binds ports 3000 and 4000 to loopback because it has no TLS terminator.
Response shaping returns raw data unless you close the fallback
Per-tool response mapping can drop or rename fields before they reach an AI client. That is useful for removing an IBAN, tax identifier, or oversized payload while keeping the full upstream result in the local audit log. The documented default has a sharp edge: if the mapping fails at runtime, AnythingMCP returns the raw response and logs a warning. Set fallbackToRaw to false wherever disclosure must fail closed.
Tool permissions deserve the same treatment. Database queries are read-only by default, and MCP annotations can distinguish read and destructive calls, but imported systems can still expose create or update operations. AnythingMCP supplies role-based whitelists and recommends a read-only database user. Those controls are ingredients, not proof. A production review should test each role, response map, and failure path against the exact connector credentials it receives.
The 265-adapter catalog includes documented limits
AnythingMCP says 21 of its 265 adapters need no API key. Others require user credentials, and some catalog entries are explicitly marked as built from vendor documentation without a live seller account. That label is useful honesty. It also means catalog count is not a compatibility guarantee. Test authentication, pagination, destructive actions, and error responses against your own vendor account before giving the tools to an agent.
Current gaps are concrete. Open issue 645 says the custom builder cannot send a real multipart file, even when multipart/form-data is selected. Issue 735 says the SOAP engine does not emit WS-Security UsernameToken headers despite the auth type appearing in the schema and UI. Issue 788 reports a cURL and Postman placeholder regex that can stall the Node event loop on long unmatched brace input, with a fix proposed in pull request 789.
Version 0.15.0 is active, while licensing needs a close read
Release v0.15.0 and the last repository push both landed on September 28, 2026. GitHub showed 536 stars and 27 combined issues and pull requests. The same-day release adds self-hosted editions and license reporting. Community allows up to 3 active users, while paid editions cover work teams and Business adds more users, SSO, and SCIM. That current model is more specific than older statements that every self-hosted feature is included.
The core is AGPL-3.0-only, while code under ee/ has a separate commercial license. Internal use and modification are allowed. If you offer a modified AnythingMCP as a network service, the license FAQ says users must be offered the source of that modified version. Teams building a proprietary hosted product should settle that obligation or commercial licensing before making this gateway central to their architecture.
Pick it when your systems do not speak MCP yet
AnythingMCP's strongest case combines several non-MCP systems, 6 supported connector types, and a need to keep credentials and audit records in-house. In that setting, one governed endpoint can replace several bespoke adapters. Our 2,046-package install and failed default build show the cost: this is infrastructure with a database, secrets, migrations, auth, and a large connector surface.

