{
  "server": "skuuy-mcp",
  "version": "1.0.0",
  "transport": "Streamable HTTP (JSON-RPC 2.0)",
  "endpoint": "POST https://mcp.skuuy.com/mcp",
  "toolsCount": 13,
  "tools": [
    {
      "name": "skuuy_get_egress_ip",
      "description": "Returns the caller's public egress IP address with geolocation, ASN/ISP, and datacenter/proxy detection. Use to verify which IP and country your traffic exits from, or to confirm a VPN/proxy is active. No parameters needed."
    },
    {
      "name": "skuuy_list_proxies",
      "description": "Lists tested-live public proxies (HTTP/HTTPS/SOCKS4/SOCKS5) across 150+ countries, refreshed every 30 minutes. Filter by protocol, country, anonymity tier (L1 Elite = no forwarding headers, L2 Anonymous, L3 Transparent), and max latency. Each entry includes last_checked so you can judge freshness. Free public proxies are inherently unreliable — always implement retry/fallback."
    },
    {
      "name": "skuuy_generate_totp",
      "description": "Generates a time-based one-time password (RFC 6238 TOTP) from a base32 secret. PRIVACY: the secret is processed ephemerally in memory, never logged or stored. By sending the secret you opt in to server-side generation (the browser vault at 2fa.skuuy.com remains the zero-knowledge alternative). Compatible with Google Authenticator / Authy / Microsoft Authenticator secrets."
    },
    {
      "name": "skuuy_create_temp_inbox",
      "description": "Creates a disposable email inbox for sign-ups and verifications. Inbox self-destructs after TTL (default 30 minutes). Pair with skuuy_read_inbox to poll incoming mail and auto-extracted OTP codes."
    },
    {
      "name": "skuuy_read_inbox",
      "description": "Reads messages in a temp inbox created by skuuy_create_temp_inbox. Each message includes plain-text body and auto-extracted 4-8 digit OTP codes and action links (e.g. password-reset URLs) when detected. Poll this after triggering a verification email."
    },
    {
      "name": "skuuy_resolve_dns",
      "description": "Resolves DNS records for a domain. Without 'locations', performs a single edge-resolver lookup. With 'locations', returns a propagation matrix across global edge PoPs (useful to verify DNS changes propagated worldwide). Supports A, AAAA, CNAME, MX, TXT, NS, SOA with DNSSEC validation status."
    },
    {
      "name": "skuuy_check_ports",
      "description": "Checks whether common service ports are open (TCP connect) on a host. ABUSE GUARD: only a fixed allowlist of common ports may be tested (22 SSH, 80 HTTP, 443 HTTPS, 3306 MySQL, 5432 Postgres, 6379 Redis, 51820 WireGuard). Arbitrary port ranges are rejected. Strictly rate-limited. Intended for diagnosing your own deployments and firewall/NAT traversal — not for scanning third parties."
    },
    {
      "name": "skuuy_check_security_headers",
      "description": "Audits a URL's security posture: security headers (HSTS, CSP, X-Frame-Options, Permissions-Policy, etc.), full redirect chain, and TLS certificate health (issuer, expiry, days remaining). Use for pre-deploy checks or auditing any site's hardening."
    },
    {
      "name": "skuuy_read_url",
      "description": "Fetches any public URL and returns clean markdown (ads, cookie banners, nav chrome, and script tags stripped; JS-rendered pages rendered best-effort). Privacy: zero-log, the fetch is not associated with you. Honest scope: soft paywalls and JS pages handled best-effort; hard anti-bot challenges (interactive CAPTCHA) are not bypassed."
    },
    {
      "name": "skuuy_create_webhook_bin",
      "description": "Creates an ephemeral webhook-catcher URL (bin.skuuy.com/w/<id>) that records incoming HTTP requests with full headers and body. Point a third-party callback (Stripe, GitHub, your own API) at it while debugging, then inspect with skuuy_get_bin_requests. Auto-deleted after TTL."
    },
    {
      "name": "skuuy_get_bin_requests",
      "description": "Lists HTTP requests captured by a webhook bin created with skuuy_create_webhook_bin: method, headers, query params, and body (truncated at 1 MB). Poll this after triggering the callback you are debugging (allow ~3-5 seconds for edge KV propagation)."
    },
    {
      "name": "skuuy_hash_encode",
      "description": "One-shot hashing/encoding utilities: SHA-256, SHA-512, Base64 encode/decode, UUID v4, and cryptographically random password generation. (MD5 included for legacy checksum verification only — do not use for security.)"
    },
    {
      "name": "skuuy_search_public_apis",
      "description": "Searches the Skuuy public API catalog. Call this FIRST when you are unsure which Skuuy tool fits your task — it returns matching tools with their MCP tool name, HTTP endpoint, and parameter summary."
    }
  ],
  "documentation": "https://skuuy.com/llms.txt",
  "help": "Send JSON-RPC 2.0 request (initialize, tools/list, tools/call) via POST /mcp"
}