← All servers

Grabblist

warnings

mcp.grabbitapp.com

Save and organize web finds in persistent, user-controlled collections for AI assistants.

https://mcp.grabbitapp.com/api/mcpWebsiteOAuthMCP 2025-03-26v2.1.0last checked 24 Aug 2026spoke MCP on 3 of 3 checks (30 days)initialize in 805 ms

How to authenticate

Checked against the endpoint by our probe on 24 Aug 2026. These are the capabilities the server advertises, not a prediction about any particular client.

Scheme
OAuth
Issuer
https://grabbitapp.com
Dynamic client registration
Advertised (RFC 7591)
Client ID Metadata Document
Not advertised
PKCE
S256
Grant types
authorization_code, refresh_token
Scopes
grabblist:read, grabblist:write
Protected-resource metadata
Published (RFC 9728)
Anonymous access
Handshake succeeds; 23 tools listable
Credentials demanded in prose
ask_agent

These tools are listed anonymously and their own descriptions ask for an account or key, but no challenge is issued — so a client has nothing to act on and the refusal arrives as a tool error.

What the probe found

warningTools needing credentials are listed without a challenge

1 of the 23 tools listed anonymously say in their own descriptions that they need an account or a key (ask_agent), but the endpoint issued no WWW-Authenticate challenge. The requirement is stated only in prose, so a call reaches the tool and comes back as a tool error instead of an authorization step.

No CORS headers for browser-based clients

A cross-origin preflight came back without Access-Control-Allow-Origin, so the endpoint is reachable from native clients only — code running in a web page is stopped by the browser before a request is ever sent.

23 tools usable without signing in

The server exposes a public surface before authorization: ping, get_wishlist, get_item, add_item, delete_item, restore_item, search_saved, update_price, update_item, list_collections, create_collection, add_to_collection, remove_from_collection, delete_collection, update_collection, link_items, get_item_graph, unlink_items, get_item_history, get_collection_activity, set_pinned_items, send_feedback, ask_agent.

Tools

add_itemadd_to_collectionask_agentcreate_collectiondelete_collectiondelete_itemget_collection_activityget_itemget_item_graphget_item_historyget_wishlistlink_itemslist_collectionspingremove_from_collectionrestore_itemsearch_savedsend_feedbackset_pinned_itemsunlink_itemsupdate_collectionupdate_itemupdate_price

Contract history

24 Aug 2026v2.1.0first recorded contract

Get alerted when this contract changes

Depend on this server? Leave an email and get a message when a probe records a change — a tool removed, an argument newly required, an enum narrowed. Alerts are being built; signing up is what tells us to hurry.

Prefer a feed reader? This page's contract changes are also an Atom feed.

Status badge

Status for a README, from the last probe — cached an hour, so up to seven hours behind the endpoint. Links back to this page.

MCP status badge for Grabblist
[![MCP status](https://mcpi.app/servers/grabblist/badge.svg)](https://mcpi.app/servers/grabblist)

Own this server?

Sign in to claim this listing by proving control of the endpoint.