gateway

Find and call the right MCP server for any task - pay per use, no install.

Should I use this

Quality & Safety

A
Description quality
60%
Schema completeness
100%
Naming quality
100%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Findings (2)

  • LOWTool 'find_mcp_server' has short descriptionin find_mcp_server
  • LOWTool 'find_mcp_server' description lacks action verbin find_mcp_server

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~508Tokens (tool definitions)
~2.2 KBTypical response size
Minimal attention impact (0.40% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "gateway": {
      "url": "https://mcp.toolhail.com/mcp"
    }
  }
}

Remote endpoints

https://mcp.toolhail.com/mcpstreamable-http

What it can do

Tool inventory

Tools (2)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
🟢find_mcp_server(query, maxResults, requireRemote)

Input Schema

{
  "type": "object",
  "properties": {
    "query": {
      "type": "string",
      "description": "Plain-language description of the capability you need, e.g. 'query a Postgres database'."
    },
    "maxResults": {
      "description": "How many ranked matches to return (default 5).",
      "type": "integer",
      "minimum": 1,
      "maximum": 25
    },
    "requireRemote": {
      "description": "Only return servers with a hosted remote endpoint (usable immediately).",
      "type": "boolean"
    }
  },
  "required": [
    "query"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟡call_tool(url, toolName, args, maxSpendUsd, allowWrite)

Proxy one tool call to a discovered remote MCP server (paid). Every call passes pre-execution guards before anything runs: tools on TOOLHAIL_BLOCKED_TOOLS are always refused; when TOOLHAIL_ALLOWED_TOOLS is set (non-empty, no "*") only listed tools may fire; write/mutating-looking tool names are refused unless allowWrite:true is passed or the tool is allowlisted; and TOOLHAIL_ARG_LIMITS can cap specific argument values per tool (e.g. daily_budget<=500) so an allowlisted broad tool still cannot push a value past its ceiling. Any refusal executes nothing and bills nothing, and every receipt records the gate decision.

Input Schema

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "Remote MCP server URL (the \"remotes[].url\" from a find_mcp_server result)."
    },
    "toolName": {
      "type": "string",
      "description": "Name of the tool to call on that server."
    },
    "args": {
      "description": "Arguments object to pass to the tool.",
      "type": "object",
      "properties": {},
      "additionalProperties": {}
    },
    "maxSpendUsd": {
      "description": "Spend cap. Refuse the call — nothing executed, nothing billed — if the gateway fee would exceed this many USD.",
      "type": "number",
      "minimum": 0
    },
    "allowWrite": {
      "description": "Explicit acknowledgement that a write/mutating call is intended. Tool names that look like writes (create/update/delete/send/pay/deploy/...) are refused by default — nothing executed, nothing billed — unless this is true or the tool is on TOOLHAIL_ALLOWED_TOOLS. Set it only when the mutation is deliberate and vetted; never set it reflexively to get past a refusal.",
      "type": "boolean"
    }
  },
  "required": [
    "url",
    "toolName"
  ],
  "$schema": "http://json-schema.org/draft-07/schema#"
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded2 tools
verifiedversion not recorded2 tools