Orcarouter Mcp Server — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Orcarouter Mcp Server (MCP Server) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<p align="center"> <a href="https://www.orcarouter.ai"> <img src="https://raw.githubusercontent.com/Continuum-AI-Corp/orcarouter-mcp-server/main/assets/logo.gif" alt="OrcaRouter" width="180" /> </a> </p>
<h1 align="center">OrcaRouter MCP Server</h1>
<p align="center"> Official MCP server for the <a href="https://www.orcarouter.ai">OrcaRouter</a> LLM gateway. </p>
<p align="center"> <a href="https://discord.com/invite/943Zqp9bs"><img src="https://img.shields.io/discord/1501106943178309662?logo=discord&label=discord&color=5865F2" alt="Discord" /></a> <a href="https://x.com/OrcaRouter"><img src="https://img.shields.io/badge/X-Follow-000000?logo=x&logoColor=white" alt="X" /></a> <a href="https://www.npmjs.com/package/@orcarouter/mcp"><img src="https://img.shields.io/npm/v/@orcarouter/mcp" alt="npm version" /></a> <a href="https://github.com/Continuum-AI-Corp/orcarouter-mcp-server/actions/workflows/test.yml"><img src="https://github.com/Continuum-AI-Corp/orcarouter-mcp-server/actions/workflows/test.yml/badge.svg" alt="CI" /></a> <a href="https://smithery.ai/servers/continuum-ai-corp/orcarouter-mcp"><img src="https://smithery.ai/badge/continuum-ai-corp/orcarouter-mcp" alt="Smithery" /></a> </p>
<p align="center"> <a href="README.md">English</a> | <a href="README.ja.md">日本語</a> | <a href="README.zh-CN.md">中文</a> | <a href="README.ko.md">한국어</a> | <a href="README.de.md">Deutsch</a> | <a href="README.fr.md">Français</a> | <a href="README.es.md">Español</a> | <a href="README.it.md">Italiano</a> | <a href="README.ru.md">Русский</a> | <a href="README.pt.md">Português</a> | <a href="README.vi.md">Tiếng Việt</a> | <a href="README.hi.md">हिन्दी</a> </p>
<br/>
Browse OrcaRouter's model catalog and run chat completions from inside any Model Context Protocol client — Claude Desktop, Claude Code, Cursor, Windsurf, Zed, or anything else that speaks the protocol.
Catalog browsing works without an API key — compare pricing and capabilities before signing up.
orcarouter/auto router (cost / quality / balanced / LinUCB / gated-adaptive strategies)Try saying things like:
claude mcp add orcarouter -s user \
-e ORCAROUTER_API_KEY=sk-orca-your-key \
-- npx -y @orcarouter/mcp| Client | Example | Action |
|---|---|---|
| Claude Desktop | claude-desktop.json | Replace |
| Claude Code | claude-code.json | Merge |
| Cursor | cursor.json | Replace |
| Windsurf | windsurf.json | Replace |
See examples/README.md for the config-file paths and notes on Zed and other clients.
sk-or-... in the copied file with your OrcaRouter API key.The root .mcp.json is the same config in the Open Plugins standard location, so registry/discovery tools that scan for it (e.g. cursor.directory) can pick this server up automatically.
Requires Node.js 18 or later. The ORCAROUTER_API_KEY env var is only required for orcarouter_chat; catalog tools work without it.
orcarouter_chat — run a chat completion (with optional fallback chain)orcarouter_models_list — browse the catalog (pricing, context, capabilities)orcarouter_model_card — detailed info for one modelorcarouter_providers_list — list providers with model countsFull input schemas are exposed at runtime via the MCP tools/list method — your MCP client (Claude Desktop, Cursor, etc.) reads them automatically.
| Name | Required | Description |
|---|---|---|
ORCAROUTER_API_KEY | optional | OrcaRouter API key. Required only for orcarouter_chat. |
ORCAROUTER_BASE_URL | optional | API base URL. Defaults to https://api.orcarouter.ai. |
ORCAROUTER_REQUEST_TIMEOUT | optional | Per-request HTTP timeout in seconds. Defaults to 300. |
API keys are read from environment variables, never logged, and only sent to the OrcaRouter API. See SECURITY.md for the vulnerability disclosure policy.
# bun (preferred)
bun install
bun run test
bun run typecheck
bun run build
# or with npm
npm install
npm test
npm run typecheck
npm run buildThe build produces an ESM bundle at dist/index.js with a #!/usr/bin/env node shebang, runnable as the orcarouter-mcp binary.
See CONTRIBUTING.md. For newcomer-friendly tasks, browse the good first issue label.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.