Model Context Protocol gateway

One MCP URL for your whole toolset.

Omniio sits between your agent and every MCP server you use. Connect once; switch servers on and off without touching a config file. Your agent searches for tools instead of loading all of them.

Livehttps://mcp.omniio.dev

145 servers in the library · 6 on by default · 25,000 calls a month on Free

Every mark above is a server in the library today.

See all 145 servers →
How it works

Connect once. Change anything after.

The endpoint never changes, so the client config you write today keeps working as your toolset grows.

01

Add one URL

Paste the Omniio endpoint into Claude, Cursor, Windsurf or any MCP client. Your client authorizes once, against Omniio.

02

Switch servers on

Turn servers on in your library. Open servers work immediately; the rest take an API token or an OAuth grant, held per user.

03

Let the agent search

Instead of hundreds of preloaded tools, your agent gets three: search for a tool, read its schema, run it.

claude code
claude mcp add --transport http omniio https://mcp.omniio.dev
Try it here

Ask for a capability. Watch the catalog answer.

This box runs the ranker the endpoint runs, over the servers the library lists. Type what you need the agent to do — the ordering you get is the ordering it gets.

search_tools3 of 145
describe_toolsupabase

Supabase

Data & AI

Manage your Supabase projects — query the database, inspect schema, run migrations, and read logs. Sign in with Supabase to connect.

auth
oauth
default
off
namespace
supabase__*

Takes an OAuth grant, held per person and refreshed on demand.

run_tool

Runs against your account, so it needs your connection — not this page.

Why it stays fast

Your agent is good. Its toolbox should be too.

Four things sit between the request and the upstream server, and none of them ask your agent to carry more context than the job needs.

your connectionsper person
  • Airtableoauth 2.1
  • AWS Knowledgeopen
at restAES-256-GCM
02

Per-person authorization

Your grant is yours. Omniio never serves one account’s call with another account’s credential, and a token you paste is sealed before it reaches the database.

  • OAuth grants held per user and refreshed on demand
  • API tokens encrypted with their own IV and auth tag, opened in memory for one call
  • Disconnecting deletes the credential — not a flag
How credentials are held →
tool policyper tool
  • allowruns straight through
  • askwaits for a person, up to 60s
  • blocknever reaches upstream
no rule setallow
03

A gate before the write

Reading a repository and closing an invoice are not the same risk. Put the ones that matter behind a person, and leave the rest alone.

  • Allow, ask or block, set per tool
  • An asked call holds while you decide, then answers your agent either way
  • No rule means allow, so nothing breaks the day you add the first one
How tool policy works →
each run recordsyours to export
  • server
  • tool
  • arguments
  • result
  • outcome
  • duration
  • client
kept7 days – 1 year
04

Everything on the record

A record you can read, filter and take away — not telemetry kept for us. Push it as it happens, or pull it on your own schedule.

  • Arguments, result, outcome and duration for every run
  • Signed webhooks as each call finishes
  • OTLP spans into the collector you already run
What is recorded →
The library

145 servers, one authorization.

The twelve with the most tools indexed so far. Turn one on and its tools join your endpoint on the next call.

Postman203 tools
Resend128 tools
Make121 tools
Close113 tools
Neon113 tools
Bitrise86 tools
MailerLite80 tools
Contentful70 tools
Cloudflare Radar66 tools
ClickUp61 tools
Buildkite58 tools
Miro58 tools
The skill library

74 skills, read over the same endpoint.

A tool is something your agent calls. A skill is something it reads first — how to drive test-first development, how to review a diff, how to plan before writing code. They are 5 authors’ published work, carried at a pinned commit under the licence each one ships with, not rewritten and not passed off as ours.

Browse the skill library
Safety

Written down, including what we don’t claim.

The security page says what is true today rather than what sounds reassuring. These are its headlines.

Where your credentials live

Encrypted with AES-256-GCM before the database sees them, with the key in the deployment’s environment rather than beside the data it opens. Each record carries its own IV and auth tag, so a tampered row fails to open instead of opening into something else.

How a client gets in

OAuth 2.1 with PKCE required, and the token a client receives is bound to this endpoint. Teams can put their own Okta or Entra in front of it and provision people over SCIM.

What is recorded, and for how long

Server, tool, arguments, result, outcome, duration and client, for every run. Kept 7 days on Free and up to 1 year on Enterprise, then deleted rather than archived somewhere else.

What we don’t claim

No certification we have not been through, and no compliance badge we have not earned. The security page names the gaps as plainly as the controls.

AES-256-GCMOAuth 2.1 + PKCESSO & SCIMAudit trail
Read the security page →

Add the URL. Keep your context for the work.

Free covers 25,000 MCP calls a month — enough to run a personal agent all month. No card needed to start, and no contract to sign.