Back to the catalog

io.github.Kjopstad-IT/rqwstr

AI-native HTTP security testing MCP server — 17 tools with raw HTTP/1.1 + HTTP/2 control

Open source Open in the app JSON README (API)

About

AI-native HTTP security testing MCP server — 17 tools with raw HTTP/1.1 + HTTP/2 control

Details

Kind
MCP servers
Topic
Developer tools
Publisher
kjopstad-it
Origin
official
Category
ferramentas
Transport
local
Version
1.1.0
Last push
2026-08-22T13:31:16Z
Repository state
ativo
Language
Dockerfile
License
NOASSERTION
Added
2026-08-29 03:02:01
Updated
2026-08-29 03:02:01
Origin id
io.github.Kjopstad-IT/rqwstr

README

# rqwstr

AI-native HTTP security testing toolkit, shipped as an MCP server. It gives an AI agent low-level control over HTTP/1.1 and HTTP/2 — raw framing, connection pinning, intruder-style fuzzing, request racing, OOB detection, and multi-step chains — on its own Go engine, rather than wrapping a high-level HTTP client.

This repository hosts the **release binaries and Claude Desktop `.mcpb` bundles**. The source is proprietary. Docs and sign-up: **[rqwstr.com](https://rqwstr.com)**.

![rqwstr localhost MCP demo](demo/rqwstr-demo.gif)

Real v1.2.0 MCP session against a synthetic loopback fixture: one request, response-side
filtering, stored search, and named retrieval. The capture and renderer are reproducible
from [`demo/`](demo/README.md) with an activated free or Pro license; no live target is
involved.

## Install

### Claude Desktop (one-click)

Download the `.mcpb` for your platform from the [latest release](https://github.com/Kjopstad-IT/rqwstr-mcp/releases/latest) and double-click it to add rqwstr as a Claude Desktop extension.

- **macOS** — Apple silicon (`darwin_arm64`) or Intel (`darwin_amd64`)
- **Linux** — `linux_amd64` or `linux_arm64`
- **Windows** — `windows_amd64`

### Standalone MCP server

Download the binary for your platform from the [latest release](https://github.com/Kjopstad-IT/rqwstr-mcp/releases/latest), then point your MCP client at it:

```json
{
  "mcpServers": {
    "rqwstr": {
      "command": "rqwstr",
      "args": ["serve"]
    }
  }
}
```

`rqwstr serve` runs the MCP server on stdio.

## Tools

17 HTTP tools:

`send` · `send_h2` · `fetch` · `intruder` · `race` · `chain` · `oob` · `parallel` ·
`scope` · `session` · `encode` · `export` · `save` · `search` · `hunt` · `profile` ·
`import`

## Workflows

The HTTP tools cover:

- **Traffic** — `send` (HTTP/1.1), `send_h2` (HTTP/2), `fetch`, `import` (Burp / HAR), `export` (curl / python / requests)
- **Hunt lifecycle** — `hunt`, `scope`, `save`, `search`, `session`, `profile`
- **Attacks** — `intruder` (sniper, battering ram, pitchfork, cluster bomb), `race` (single-packet), `chain`, `parallel`
- **OOB** — `oob` with Interactsh integration
- **Encoding** — `encode` (URL, base64, JWT, and more)

Agents discover workflows through the `rqwstr_docs` tool. Per-hunt state lives in SQLite. The free tier is the core toolset; a Pro tier unlocks the heavier offensive tools.

## Verify a download

Each release includes `checksums.txt`. Verify before running:

```sh
# Linux
sha256sum -c checksums.txt

# macOS
shasum -a 256 -c checksums.txt
```

## Privacy Policy

rqwstr's data collection, usage, storage, sharing, retention, and contact practices are
documented in the [Privacy Policy](https://rqwstr.com/legal/privacy/).

## License

Proprietary. © Kjøpstad IT. See [rqwstr.com](https://rqwstr.com) for terms.

More