Versioned profiles
Every profile identifies an exact r2mcp artifact, radare2 build, plugin inventory, decompilers, startup policy, limits, and selectable tools.
RADARE2 · MCP · CONTROLLED EXECUTION
mcp.radare.org gives MCP clients a stable way to use radare2 through versioned analysis profiles, isolated runners, explicit tool policies, and revocable API keys.
/sseStreamable HTTPWHAT IT IS
The gateway separates public HTTP, account policy, and disposable analysis processes so an analyzer can be upgraded or replaced without taking the service down.
Every profile identifies an exact r2mcp artifact, radare2 build, plugin inventory, decompilers, startup policy, limits, and selectable tools.
Each API key is pinned to one profile and exposes only the tool subset you choose. Keys can expire or be revoked independently.
Wasm and native r2mcp backends run behind the gateway. They can live locally, in containers, or on remote workers with separate QoS.
WHAT YOU CAN DO
Connect an MCP-capable assistant or development environment and expose only the analysis operations appropriate for the job.
HOW IT WORKS
Review the exact build, capabilities, tools, plugins, and decompilers available to your account.
Select only the tools your client needs and set a deliberate expiration date.
Use the generated bearer secret with /sse. Revoke it without disrupting your other clients.
ACCOUNT ACCESS
API keys, profiles, quotas, and usage are private to your account.
YOUR ACCOUNT
01 · STORAGE
Projects are flat folders containing regular files only. Upload limits and total storage are enforced from your account tier.
02 · CATALOG
Each profile pins one artifact, build, plugin inventory, runtime policy, and public tool ceiling.
03 · POLICY
Every API key created here belongs to your account and can only use profiles enabled for your subscription tier.
04 · CREDENTIALS
ONE-TIME SECRET
MCP client JSON
List tools with curl