Sign inSign up

hackerdogs/waybackurls-mcp

By hackerdogs

Updated 3 months ago

Waybackurls MCP Server

Image
0

247

hackerdogs/waybackurls-mcp repository overview

Hackerdogs
hackerdogs

Waybackurls MCP Server

MCP server wrapper for waybackurls — fetch all URLs ever crawled by the Wayback Machine for a domain.

What is Waybackurls?

Waybackurls is a Go tool by Tom Hudson (tomnomnom) that queries the Wayback Machine CDX API to retrieve every URL ever crawled for a given domain, making it useful for OSINT, attack surface discovery, and finding forgotten endpoints, old admin paths, or leaked files. It is commonly used in bug bounty recon pipelines alongside tools like gau and hakrawler. See tomnomnom/waybackurls for full documentation.

No API keys required — waybackurls queries the public Wayback Machine API and runs locally inside the Docker container.

Summary. MCP server wrapper for waybackurls — fetch all URLs ever crawled by the Wayback Machine for a domain.

Tools:

  • run_waybackurls — Run waybackurls with CLI arguments (e.g. example.com).

Tools Reference

run_waybackurls

Run waybackurls with CLI arguments (e.g. example.com).

ParameterTypeRequiredDefaultDescription
argumentsstrYesCommand-line arguments (e.g. "--help")
timeout_secondsintNo300Maximum execution time in seconds
Example response
{
  "raw": "waybackurls output will appear here"
}

Example Prompts

Here are example prompts you can use with Claude (or any MCP client) when this tool is connected:

  • "Use waybackurls to fetch all historically crawled URLs for example.com."
  • "Run waybackurls on target.com and filter results to show only .php endpoints."
  • "Fetch all Wayback Machine URLs for hackerone.com and look for any paths containing 'admin' or 'backup'."
  • "Get all historical URLs for example.com and identify any that might expose .env or config files."
  • "Run waybackurls on bugbounty.com and find old API endpoints that may still be active."
  • "Use waybackurls to enumerate all subdomains and paths ever crawled for example.org."

Deploy

docker-compose up -d
Docker Run (stdio mode)
docker run -i --rm hackerdogs/waybackurls-mcp:latest
Docker Run (HTTP streamable mode)
docker run -d -p 8395:8395 \
  -e MCP_TRANSPORT=streamable-http \
  -e MCP_PORT=8395 \
  hackerdogs/waybackurls-mcp:latest

MCP Client Configuration

Stdio mode (default)

Add to your Claude Desktop or Cursor MCP config:

{
  "mcpServers": {
    "waybackurls-mcp": {
      "command": "docker",
      "args": ["run", "-i", "--rm", "-e", "MCP_TRANSPORT", "hackerdogs/waybackurls-mcp:latest"],
      "env": {
        "MCP_TRANSPORT": "stdio"
      }
    }
  }
}
HTTP mode (streamable-http)

First, start the server using Docker Compose or docker run with HTTP mode (see Deploy above), then point your MCP client at the running server:

{
  "mcpServers": {
    "waybackurls-mcp": {
      "url": "http://localhost:8395/mcp"
    }
  }
}

When to use HTTP mode: HTTP mode is ideal for shared/remote deployments, multi-user setups, and Hackerdogs scheduled prompts. The server runs as a long-lived process and accepts connections from multiple MCP clients concurrently.

Environment Variables

VariableDefaultDescription
MCP_TRANSPORTstdioTransport mode: stdio or streamable-http
MCP_PORT8395HTTP port (only used with streamable-http)

Installing in Hackerdogs

The fastest way to get started is through Hackerdogs:

  1. Log in to your Hackerdogs account.
  2. Go to the Tools Catalog.
  3. Search for the tool by name (e.g. "nuclei", "naabu", "julius").
  4. Expand the tool card and click Install — you're ready to go.

Give it a couple of minutes to go live. Then start querying by asking Hackerdogs to use the tool explicitly (e.g. "Use naabu to scan example.com"). If you don't specify, Hackerdogs will automatically choose the best tool for the job — it may choose this one on its own.

  1. Vendor API key required? Add your key in the config environment variable field before clicking Install. Your key will be encrypted at rest.
  2. Enable / Disable the tool anytime from the Enabled Tools page.
  3. Need to update a key or parameter? Go to My Tools → toggle Show Decrypted Values → edit → Save.

Want to contribute or chat with the team? Join our Discord.

Build

docker build -t hackerdogs/waybackurls-mcp:latest .

Testing

Automated tests
./test.sh
Test directly with Docker

1. Start the server in HTTP mode:

docker run -d --rm --name waybackurls-mcp-test -p 8395:8395 \
  -e MCP_TRANSPORT=streamable-http \
  hackerdogs/waybackurls-mcp:latest

2. Initialize the MCP session:

SESSION_ID=$(curl -s -D - -X POST http://localhost:8395/mcp \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2024-11-05","capabilities":{},"clientInfo":{"name":"test","version":"0.1"}}}' \
  2>&1 | grep -i mcp-session-id | awk '{print $2}' | tr -d '\r\n')

curl -s -X POST http://localhost:8395/mcp \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -H "mcp-session-id: $SESSION_ID" \
  -d '{"jsonrpc":"2.0","method":"notifications/initialized"}'

3. Call a tool:

curl -s -X POST http://localhost:8395/mcp \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -H "mcp-session-id: $SESSION_ID" \
  -d '{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"run_waybackurls","arguments":{"arguments":"--help"}}}'

4. Clean up:

docker stop waybackurls-mcp-test

Running the tool directly (bypassing MCP)

You can run the Waybackurls CLI in the same container by overriding the entrypoint without starting the MCP server.

Show help:

docker run -i --rm --entrypoint waybackurls hackerdogs/waybackurls-mcp:latest --help

Tag summary

Content type

Image

Digest

sha256:c0988221d

Size

75 MB

Last updated

3 months ago

docker pull hackerdogs/waybackurls-mcp