SandboxAPIs MCP server
Drop-in read-only replicas of GitHub, Jira, Slack and 18 more, preloaded with one fake company.
878 downloads/wk
Reviews
Write oneNobody has reviewed SandboxAPIs yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
SandboxAPIs tools (10)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
check_budgetCosts nothing \u2014 call it before any loop of more than a handful of requests. Returns this server's real hourly window (limit, remaining, when it resets) read from the provider's own budget endpoint, which is exempt from the budget it reports, plus whether a key is set and where to raise the limit. The window is ONE bucket per caller shared across every provider host, so the numbers apply to al
get_pull_requestFetch one PR (GitHub) / MR (GitLab) plus its reviews (GitHub) / approvals (GitLab). Returns both in one result; each carries provider-form ids for cross-referencing.
get_repositoryFetch one repository by name (default: the flagship repo). Provider-shaped, with provider-form ids.
get_snapshotReturn the pinned, reproducible hostname for a provider \u2014 point your client's base URL at it for drift-free CI. A snapshot regenerates byte-identically on every request.
get_userFetch a user by login/username. Provider-shaped, with provider-form ids.
list_issuesList a repo's issues. Optional state filter (open/closed/all).
list_pull_requestsList a repo's pull requests (GitHub) or merge requests (GitLab). Optional state filter.
list_repositoriesList repositories for the universe's org. Results are identical to the provider's REST API and carry provider-form ids (node_id / numeric id).
orientSTART HERE. Returns everything needed to use SandboxAPIs with no docs: the universe/theme, every API surface and its base URL (git hosts and issue trackers), live-vs-snapshot modes and how to pin, the org and its teams/repos, notable entry points (each with a ready-to-run REST path), where the coverage manifest lives, and this server's access block \u2014 whether a key is set and how many requests
search_commits_by_authorFind commits authored by a given login in a repo. Returns SHAs (identical across GitHub and GitLab, invariant #5) with a REST path to fetch each \u2014 so you can cross-reference against either provider.
Public scan report
scanner v0.1.9 · 2026-09-20 · same rubric, same numbers if you re-run it
- Code scan3 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenanceno repository listed3/15
- Maintainer identityverified namespace with website, no repo4/10
Findings (1)
- lowNo source repository listed
maint.no-repo
Install directly
Runs npx -y @sandboxapis/mcp on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add mcp -- npx -y @sandboxapis/mcp
SandboxAPIs: common questions
- Is SandboxAPIs MCP server safe?
- With care: it is graded C, so read the findings first (68/100). Read the SandboxAPIs safety report
- How do I install SandboxAPIs?
- It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
- Does SandboxAPIs need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is SandboxAPIs maintained?
- The latest release is v0.3.13.
- What can I use instead of SandboxAPIs?
- Servers from other publishers that do the same job: GitHub MCP server, Atlassian Rovo MCP Server and uploads.sh MCP server. Compare all SandboxAPIs alternatives.
Alternatives to SandboxAPIs
Same job from other publishers: the closest match first, then the best rated.
- GitHubConnect AI assistants to GitHub - manage repos, issues, PRs, and workflows through natural language.not reviewedEstablishedA
- Atlassian Rovo MCP ServerConnect to Atlassian Jira, Confluence, Loom, and more to search, create, and manage your work.not reviewedEstablishedA
uploads.shHost files from coding agents; stage on a branch and attach to GitHub PRs.not reviewedEstablishedA- Agent HarnessesAgent-harness picks and decision guides; pick_infrastructure adds live GitHub/HN discovery.not reviewedGrowingA
Jira Alerts (JSM Operations)MCP server for Jira Service Management Operations — alerts, on-call schedules and respondersnot reviewedGrowingB