Start free. Upgrade when your API reaches production.
Try it out
For solo builders
For production teams
For AI agencies
See what your API looks like before exposing it to AI agents.
Production MCP adoption often requires approval from security, IAM, and platform teams. MCPForge provides the controls they expect before AI agents can access production APIs.
Control exactly which API operations AI agents can access.
Require human approval before sensitive actions execute.
Keep API credentials encrypted and isolated from Claude, Cursor, and other AI clients.
Track every tool call, approval, denial, failure, and execution.
DELETE, billing, auth, admin, and refund operations are detected and disabled automatically.
Generate a Security Score, risk analysis, side-effect classification, and actionable recommendations before deployment.
| Feature | Free | Starter | Pro | Agency |
|---|---|---|---|---|
| MCP Servers | 1 | 3 | 10 | Unlimited |
| Requests/month | 1k | 100k | 1M | Unlimited |
| MCP Verify | 100/month | 1,000/month | 5,000/month | Unlimited |
| Security Report | ✓ | ✓ | ✓ | ✓ |
| Security Score | ✓ | ✓ | ✓ | ✓ |
| Side Effect Detection | ✓ | ✓ | ✓ | ✓ |
| Tool Quality Score | ✓ | ✓ | ✓ | ✓ |
| Tool Permissions | ✓ | ✓ | ✓ | ✓ |
| Approval Workflows | 5/month | 100/month | Unlimited | Unlimited |
| Audit Logs | Last 50 | 30 days | 90 days | 1 year |
| Credentials Vault | 1 credential | 3 credentials | Unlimited | Unlimited |
| White Label | ✕ | ✕ | ✕ | soon |
What is an MCP server?
An MCP server exposes API functionality as AI-accessible tools that can be used by Claude, Cursor, OpenAI agents, and other MCP-compatible clients.
Do I need to write any code?
No. Paste your OpenAPI spec URL or Postman collection — we handle everything. Your MCP server is live in under 60 seconds.
How does MCPForge help with security reviews?
MCPForge generates Security Reports, Security Scores, Side Effect Detection, Tool Permissions, Approval Workflows, Audit Logs, and Credentials Vault controls that help teams evaluate MCP deployments before production use.
Can I block dangerous API operations?
Yes. MCPForge automatically detects DELETE endpoints, billing operations, authentication endpoints, refund actions, and administrative APIs. These operations can be disabled or protected with approval workflows.
Do AI agents ever see my API credentials?
No. API credentials are stored encrypted and injected server-side. Claude, Cursor, and other AI clients never receive raw credentials.
What is auto-sync?
Paid plans automatically check your OpenAPI spec URL for changes and update your MCP server — so it stays in sync with your API without any manual work.
Can I cancel anytime?
Yes. Cancel from the billing portal anytime. Your servers stay active until the end of the billing period. No questions asked.
What formats do you support?
OpenAPI 3.x (JSON & YAML), Swagger 2.x, and Postman collections (v2.1).
Why are core governance features available on Free?
MCPForge is designed so teams can experience the full governance workflow before upgrading. Free includes limited Tool Permissions, Approval Workflows, Audit Logs, Credentials Vault, Security Reports, Security Score, Tool Quality Score, and Side Effect Detection. Paid plans increase limits, retention, scale, and production usage.
Import an OpenAPI specification and receive an instant security assessment, risk classification, and actionable recommendations.
SECURITY SCORE
Why 85/100?
48 TOOLS ANALYZED
HIGH PRIORITY
MEDIUM PRIORITY
LOW PRIORITY
getCustomerRead-onlylistOrdersRead-onlysearchInvoicesRead-onlycreateCustomerSide EffectupdateCustomerSide EffectcreateInvoiceSide EffectdeleteCustomerCritical 🔒refundPaymentCritical 🔒cancelSubscriptionCritical 🔒Why this matters
Security and IAM teams often need visibility into tool permissions, high-risk operations, side effects, and approval requirements before MCP servers can be approved for production use.
Security Score
85/100
Good
Is it safe to deploy?
Tool Quality Score
81/100
Good
Is it Agent-Ready?
Used by teams preparing for
MCPForge focuses on helping teams understand and govern MCP deployments before exposing production APIs to AI agents.
Most MCP tools focus on generating servers. MCPForge focuses on operating MCP securely in production through permissions, approvals, audit logs, credentials management, side-effect detection, and security reporting.