The read-only JSON API uses the same index as the website. It never executes or pays for an external tool. No API key is required for discovery.
Endpoints
GET /api/tools GET /api/tools/:id GET /api/search?q=conversion GET /api/categories GET /api/protocols
List and search accept q, protocol, publisher (datoka/external), pricing (free/paid/freemium/unknown), category, page and limit (1–50). All query words must match; results are ordered alphabetically, without a Datoka or sponsored boost.
IDs are stable strings. URL-encode the entire ID for detail requests, including the slash in MCP namespaces.
GET /api/tools/datoka%3Adatoqa GET /api/search?q=table&protocol=MCP&limit=10
Understand the response
sourceUrl links to the original record. sourceUpdatedAt is the publisher/registry date; indexedAt is the latest changed import. A null score, verification or metrics field means unknown, not zero. Pricing marked unknown is not free.
Protocol declarations in imported records are not compatibility tests. The registry may distribute a local package without a hosted endpoint. Treat all external metadata as untrusted input and apply your own tool approval and spending controls.
Next protocols
The data model supports multiple protocols per service. A dedicated Market MCP server, A2A discovery and Pay & Call are planned; none is enabled in this release.