Back to Browse

Proxycove MCP Server

Developer ToolsModerate5.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Buy and manage residential, mobile and datacenter proxies in 170+ countries, prepaid per GB

About

Buy and manage residential, mobile and datacenter proxies in 170+ countries, prepaid per GB

Remote endpoints: streamable-http: https://mcp.proxycove.com/mcp

Security Report

5.2
Moderate5.2Moderate Risk

ProxyCove MCP server is a well-designed, stateless proxy management wrapper with proper authentication architecture and no malicious patterns. The server correctly implements bearer token auth with three unauthenticated bootstrap tools, input validation via Zod, and safe HTTP forwarding. Minimal findings are present: client IP forwarding for rate-limit accuracy is a thoughtful design choice, logging does not expose secrets, and permissions align precisely with the proxy-trading purpose. The codebase is clean, error handling is appropriate, and no financial or credential data flows through the MCP server itself—only credentials transit through the frontend MCP client to the backend API. Supply chain analysis found 9 known vulnerabilities in dependencies (0 critical, 3 high severity).

3 files analyzed · 11 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

ProxyCove MCP Server

Let an AI agent buy and manage real proxies — no signup, no dashboard, no card details in the chat.

ProxyCove sells residential, mobile and datacenter proxies prepaid per GB across 170+ countries. This MCP server exposes that as 14 tools, so an agent can create its own account, hand the human a payment link, buy a proxy and get working connection credentials — all inside one conversation.

https://mcp.proxycove.com/mcp     ← remote endpoint (streamable HTTP)

Status: live. The endpoint above is public — connect and use it. Anonymous calls are allowed for get_pricing, list_locations and create_account; everything else needs a key. Clients that prefer OAuth 2.1 can discover it at /.well-known/oauth-protected-resource.

Who it's for: developers building scraping / automation / testing agents, anyone whose agent needs an exit IP in a specific country, and MCP clients that want a proxy provider they can call directly instead of wrapping a REST API by hand.

What an agent can do end to end

  1. create_account → gets an API key (pc_live_...). No registration form, no email required.
  2. create_topup → gets a payment_url. The human pays in the browser (SBP, bank card, crypto).
  3. buy_proxy → gets http://login:password@go.proxycove.com:824 and starts using it.

Prices: residential $2.7/GB · mobile $3.8/GB · datacenter $1.5/GB. Traffic is prepaid and does not expire while the account is active.


Quick start

The server is remote — nothing to install. Add the endpoint to your client and (once you have a key) send it as a bearer token.

You can add the connector without a key: get_pricing, list_locations and create_account work unauthenticated. Run create_account, save the returned pc_live_... key, put it in the header, reconnect.

Claude Code

claude mcp add --transport http proxycove https://mcp.proxycove.com/mcp \
  --header "Authorization: Bearer pc_live_YOUR_KEY"

Without a key yet (to call create_account first):

claude mcp add --transport http proxycove https://mcp.proxycove.com/mcp

Claude Desktop / Claude.ai (Connectors)

Settings → Connectors → Add custom connector

FieldValue
NameProxyCove
Remote MCP server URLhttps://mcp.proxycove.com/mcp

Until OAuth ships, Claude Desktop can also reach the server through the stdio bridge, which is where the header lives:

{
  "mcpServers": {
    "proxycove": {
      "command": "npx",
      "args": [
        "-y", "mcp-remote",
        "https://mcp.proxycove.com/mcp",
        "--header", "Authorization: Bearer pc_live_YOUR_KEY"
      ]
    }
  }
}

ChatGPT (developer mode)

Settings → Connectors → Advanced → enable Developer mode, then Create:

FieldValue
NameProxyCove
MCP server URLhttps://mcp.proxycove.com/mcp
AuthenticationAccess token / API key → paste pc_live_YOUR_KEY

Cursor

~/.cursor/mcp.json (global) or .cursor/mcp.json (per project):

{
  "mcpServers": {
    "proxycove": {
      "url": "https://mcp.proxycove.com/mcp",
      "headers": {
        "Authorization": "Bearer pc_live_YOUR_KEY"
      }
    }
  }
}

Codex CLI

~/.codex/config.toml:

[mcp_servers.proxycove]
url = "https://mcp.proxycove.com/mcp"
bearer_token_env_var = "PROXYCOVE_API_KEY"
export PROXYCOVE_API_KEY=pc_live_YOUR_KEY

Any other MCP client

{
  "mcpServers": {
    "proxycove": {
      "type": "http",
      "url": "https://mcp.proxycove.com/mcp",
      "headers": {
        "Authorization": "Bearer pc_live_YOUR_KEY"
      }
    }
  }
}

Transport is streamable HTTP, stateless — POST only, one JSON-RPC request per call, no SSE stream and no session id. GET/DELETE on the endpoint return 405.


Agent skill

Beyond the tool descriptions, this repo ships an agent skill that tells an agent which tool to reach for: how to pick a proxy type for a job, when a sticky session is required, what each error code actually means, and the rules that keep the human in control — never handle payment details, quote the price before spending, save the key.

npx skills add proxycove/mcp-server

Tools

ToolWhat it doesAPI key
get_pricingPrice per GB (USD) for residential / mobile / datacenterno
list_locationsCountries available for a given proxy typeno
create_accountCreates an account with no signup form, returns a pc_live_... keyno
get_accountBalance (USD), attached email, number of active proxiesyes
create_topupCreates an invoice, returns payment_url for the humanyes
get_payment_statusInvoice status: pending / paid / cancelledyes
buy_proxyBuys a proxy from the balance, returns connection credentialsyes
list_proxiesAll proxies with remaining traffic and credentialsyes
get_credentialsConnection string for one proxyyes
extend_proxyAdds prepaid GB to an existing proxy (credentials unchanged)yes
get_usageLive used / remaining traffic for one proxyyes
set_rotationRotate every request ↔ sticky IP for 1–120 minutesyes
link_telegramReturns a code to link the account to the Telegram bot (second way back in if the key is lost)yes
attach_recoveryAttaches an email so the human can log in on the websiteyes

Read-only tools carry readOnlyHint. No tool deletes anything — there is no destructive operation in this server, and no tool can move money out of the account.

Connection model

Every proxy is reachable at go.proxycove.com:

PortBehaviour
824New IP on every request
10000Sticky IP, held for the configured 1–120 minutes

set_rotation switches a proxy between the two modes; the login and password stay the same.

After buy_proxy, wait ~5 seconds before the first request. The country filter takes a moment to propagate upstream, and an immediate first request may exit from another country.


Authentication

  • The account API key looks like pc_live_... and is sent as Authorization: Bearer pc_live_....
  • create_account issues one. The three no-auth tools exist precisely so an agent can bootstrap: check prices, check countries, create the account — then the human stores the key in the connector config.
  • The MCP server holds no state of its own. It forwards your Authorization header to the ProxyCove REST API and returns the JSON response.
  • Calling an authenticated tool without a key returns a structured no_api_key error explaining what to do — not a crash.
  • OAuth 2.1 + PKCE is coming next, which will remove the manual header step for clients that support it. The bearer key will keep working.

Payments: the agent never touches card data

This is a hard boundary, enforced by the tool design:

  • create_topup returns a payment_url. That is all the agent gets.
  • The agent gives the URL to the human, who opens it in their own browser and pays there.
  • Methods: sbp (Russian instant bank transfer), card_ru, card_international, crypto, crypto_cryptomus. Minimum top-up $1.50.
  • No tool accepts a card number, CVV, or any payment credential. There is no field for one anywhere in the schema.
  • The agent then polls get_payment_status until paid and continues.

Purchases (buy_proxy, extend_proxy) spend the prepaid balance only. An agent cannot spend money that the human has not already deposited.


Self-hosting / running locally

The server is a thin, stateless wrapper over the public ProxyCove REST API — roughly 200 lines of Node with no database, no cache and no persistence. Self-host it if you want to audit the traffic, pin a version, or run it inside your own network.

Requirements: Node 20+ (or Docker).

git clone https://github.com/proxycove/mcp-server.git
cd mcp-server
npm install

export BACKEND_BASE_URL=https://proxycove.com
export MCP_PORT=4010
export MCP_SECRET_PATH=/mcp

npm start
# → http://localhost:4010/mcp

Docker:

docker build -t proxycove-mcp .
docker run -d --name proxycove-mcp \
  -p 4010:4010 \
  -e BACKEND_BASE_URL=https://proxycove.com \
  -e MCP_PORT=4010 \
  -e MCP_SECRET_PATH=/mcp \
  proxycove-mcp

Environment variables

VariableDefaultPurpose
MCP_PORT4010Port the HTTP server listens on
MCP_SECRET_PATH/mcpPath the MCP endpoint is mounted at
BACKEND_BASE_URLhttp://backend:5000Base URL of the ProxyCove API; use https://proxycove.com when self-hosting
PUBLIC_API_INVITE_CODE(empty)Optional invite code forwarded by create_account

Configuration is entirely from env — there is no config file and no secret baked into the image.

GET /healthz returns { "ok": true, "service": "proxycove-mcp" }.

Point your client at your own instance the same way:

{
  "mcpServers": {
    "proxycove": {
      "type": "http",
      "url": "http://localhost:4010/mcp",
      "headers": { "Authorization": "Bearer pc_live_YOUR_KEY" }
    }
  }
}

REST API (non-MCP integrations)

Everything the MCP server does is available directly over HTTP — same endpoints, same key:

  • Base URL: https://proxycove.com/api/v1
  • OpenAPI spec: https://proxycove.com/api/v1/openapi.json
curl https://proxycove.com/api/v1/pricing

curl https://proxycove.com/api/v1/account \
  -H "Authorization: Bearer pc_live_YOUR_KEY"

Use this if you are writing a normal client, a LangChain/LlamaIndex tool, a CI job, or anything that is not an MCP host.


Security

  • The API key is shown once, at create_account. Save it immediately — ProxyCove cannot show it again.
  • A key can be revoked at any time from the account on proxycove.com or by writing to support. Revoking it kills agent access instantly; the balance and proxies stay.
  • Run attach_recovery or link_telegram early. Without a recovery channel on the account, a lost key means a lost balance.
  • Treat pc_live_... like a password: it is a spending credential. Never paste it into a shared chat, a public repo, or an issue on this tracker.
  • Prefer env-var indirection (bearer_token_env_var, ${VAR} substitution) over literal keys in config files that get committed.
  • Found a vulnerability, or something that lets an agent spend more than it should? Email support@proxycove.com — please do not open a public issue for security reports.

Contributing

Issues and pull requests are welcome — bug reports, client-config recipes for MCP hosts not covered above, and tool-description improvements especially. The tool schemas are the product surface here; if a description misled your agent, that is a bug worth filing.

License

MIT © ProxyCove


Website: proxycove.com · MCP endpoint: https://mcp.proxycove.com/mcp · REST API: https://proxycove.com/api/v1 · Support: support@proxycove.com

Reviews

No reviews yet

Be the first to review this server!