Zactonz MCP Server

v0.1.0

A Model Context Protocol server that gives AI assistants the Zactonz APIs as tools: screenshots, page to Markdown, link previews, DNS, SSL, WHOIS, email checks, QR codes, barcodes, social images, image conversion and translation.

Node.js 18+An MCP client over stdioZactonz API keys Updated 6 Oct 2026

Security & limits

What is sent and kept#

  • Tool arguments go to api.zactonz.com and nowhere else. The server keeps no logs and stores nothing on disk. The API's own handling of data is covered by the privacy policy.
  • Keys stay in the server process. They are sent only in the Authorization header to the API and are never included in anything returned to the assistant.
  • Arguments are validated against each tool's schema before any request is made, and arguments outside the schema are refused.
  • Images are fetched for inline display only from the API's own host, over HTTPS, without following redirects, and capped in size while streaming.
  • Tools that fetch a URL do so from Zactonz's servers, which refuse private and internal addresses.

Untrusted content#

read_webpage, preview_link and read_qr_code return text written by whoever controls the page or the code. That text can contain instructions aimed at the assistant. The server labels it as third-party data, but the label is advice to the model, not a guarantee. Review what an assistant does after reading pages you do not control.

Screenshots, PDFs, QR codes, barcodes and converted images are stored on api.zactonz.com at unguessable URLs that anyone holding the link can open, for the period given on each endpoint's reference page. Do not render documents that must stay private.

Timing and quota#

Calls spend units from your plan's quota, the same as direct API calls. See rate limits and quotas.

A tool call is given 55 seconds in total, because MCP clients stop waiting after 60. Within that time the server retries once, and only where a retry cannot repeat work: after a 429 with a short Retry-After, after a gateway error on a read, or ten seconds after the API host's request burst guard rejects a call. If the client cancels a call, the server stops.

Reporting a problem#

Bugs and feature requests go to the issue tracker. Report a vulnerability privately by email as described in the repository's security policy; do not open a public issue for it.