mzizi-mcp Cloudflare
Worker, published as @nyuchi/mzizi-mcp
(0.11.2, read from npm on 30 September 2026; the hosted server answered initialize with
the same version, and the MCP Registry lists it). In the
MCP Registry it is
io.github.mzizi-dev/mzizi-mcp, listing both the hosted endpoint and the npm package. The
earlier entry under the nyuchi namespace is deleted.
Connecting
mzizi.dev/mcp answers 308 to this endpoint, so old clients keep
working, but point new ones here directly.
To run it locally over stdio, with no network for anything but the docs tools:
Who can use it
The MCP server is free, with no gate, as the owner decided on 29 September 2026. Every tool except the Fundi tools is served without sign-in. On 30 September 2026 an anonymousinitialize and tools/list on https://mcp.mzizi.dev/mcp returned all fourteen tools, and
an anonymous call to mzizi_search returned results.
The Fundi tools stay gated because they tie into the console at
app.mzizi.dev:
mzizi_report_issue files into the Fundi issue desk, and mzizi_fundi delegates work to
Fundi on a user’s behalf. Both need to know who the user is. The server advertises its OAuth
metadata at
/.well-known/oauth-protected-resource,
so MCP clients can run the sign-in flow for those tools themselves. Called without sign-in,
a Fundi tool answers with how to sign in rather than failing silently. A client that cannot
run the flow can connect to https://mcp.mzizi.dev/mcp/signin instead, which asks you to sign
in and then serves every tool.
Anonymous requests are rate-limited to 120 per 60 seconds per IP address, according to the
server’s catalogue.json. Signed-in requests are not.
Discovering the tools
Ask the server, not a page. A list written down anywhere, this one included, is only as fresh as its last edit.tools/listover MCP is the live answer.https://mcp.mzizi.dev/catalogue.jsonis the same list over plain HTTP, with no sign-in, including which older tools each one replaces.- The
mzizi_mcp_describetool, and themzizi://toolsresource, describe the tools and the data sources.
catalogue.json and an anonymous tools/list both listed fourteen
tools:
Start with
mzizi_search when you do not know the name of the thing you want, and
mzizi_get_component when you do.
Components, Rust first
From0.11.0 the component tools lead with Mzizi Roots, the Rust
implementation, wherever one exists. The React (TSX) components are the React build: they
keep working, but they are deprioritised and come second.
mzizi_get_component takes name (a former nyuchi-* name resolves to its mzizi-*
successor) and an optional include of "docs", "versions" or both. It answers with these
fields, in this order:
rust is the registry’s GET /v1/rs/{name} answer, with the install before the source:
crate:{ name, registry, git }, the crate the component ships in, such asmzizi-brand;install.cargo:cargo add <crate>, the crates.io release;install.pinned: the samecargo addwith--gitand--revat the server’s registry pin, which builds exactly the source shown;module: the crate’s Rust path, such asmzizi_brand;contract: the component’scontract … endblock, ornullwhen its source declares none;files: the.rssource, inline.
react.install is npx shadcn@latest add https://api.mzizi.dev/v1/ui/<name>. If the registry
refuses the React build but Rust exists, react is { build, error } and the Rust still leads.
mzizi_list_components rows carry rustCrate when the component has Rust, the response
carries withRust (how many of total have it), and rust: true or rust: false filters on
it. On 30 September 2026, rust: true listed 55 of the registry’s 577 components.
mzizi_search component hits carry rustCrate the same way, and at an equal score a
component with Rust ranks first; a better word match still wins.
Where its data comes from
Nothing is read from a database, and no registry data is fetched at request time.
Because the generator runs the registry’s API handlers rather than re-deriving their output,
a tool answers with the payload
api.mzizi.dev/v1 would give at the same commit. The registry
no longer carries those handlers: it removed its Next.js app, app/api/v1/** included, on
2 October 2026 (mzizi-registry #389 and #391). mzizi-mcp keeps the eleven it calls in
mzizi-mcp/scripts/registry-handlers/, ported unchanged from registry commit 270af9f, the
last with them (agent-tools #172). They run at build time only and are not part of the
Worker’s bundle. They still read through the registry’s own lib/ modules, which resolve into
the checkout at the pinned commit, so the data is that commit’s. The generator replaces every
npm import those handlers make with a module that throws when used (next/server gets a small
response shim instead), so a handler that reaches for a database or a service fails the build
rather than shipping an empty answer.
catalogue.json names the pinned registry commit in source.registry, and
mzizi_mcp_describe reports it. Read the live pin there rather than from this page, and
compare it with the pin api.mzizi.dev reports in its
X-Mzizi-Source header. The two are meant to be the same commit, but they move separately, so
they can differ for a while after one of them moves. For example, 0.11.2 moved the pin by
hand on 30 September 2026 to registry commit e1c1c89, which was then also the API’s; that is
an example, not the current value. Moving to newer registry content is a change to that pin,
made in a pull request that CI checks.
The pin, ref in mzizi-mcp/registry.pin.json, has the same bot as
the API gateway’s. Every hour it compares the pin
with registry main and keeps one pull request, from the branch bot/registry-pin, that
moves it. That pull request merges itself (rebase) only when every check on it is green, and
otherwise waits for review. The bot is live on the RELEASE_BUMP_TOKEN secret (it opened
agent-tools #169 on 2 October 2026), and a bump by hand still works.
The server holds no database credential. Former nyuchi-* component names resolve to their
mzizi-* names through the registry’s rename map, bundled with the rest.
The skills
mzizi_get_skills serves the five skills of @nyuchi/mzizi-skills,
bundled from the skills’ source when the server is built, so it answers with the same version
as npm. From 0.11.1, each skill’s source names where it is authored,
mzizi-dev/agent-tools/mzizi-skills/skills/<name>. The skills renamed or removed in 0.8.0
have no aliases; see renamed and removed skills.
The docs tools
These docs run their own MCP server, which Mintlify hosts athttps://docs.mzizi.dev/mcp.
It is public and needs no sign-in. The Mzizi MCP server lists its tools under a docs_
prefix and forwards each call unchanged:
- it caches the upstream tool list for five minutes;
- if a refresh fails it reuses the last good list, and with nothing cached it falls back to a built-in snapshot of the upstream definitions;
- a failed call comes back as a tool error naming the docs server and the reason.
docs_* names mirror whatever docs.mzizi.dev/mcp lists, so they can change when these
docs change. You can also connect to https://docs.mzizi.dev/mcp directly.
The Fundi tools
Fundi is the self-healing agent behind the console, run under Nyuchi. Two tools reach it.mzizi_report_issue reproduces and drafts an issue, then logs it to Fundi’s issue desk.
Fundi files the GitHub issue with its healing plan, and records the issue’s lifecycle, which
is how the desk and the console can tell you whether your report was picked up.
mzizi_fundi delegates long runs, such as a security, chaos or accessibility run, to
Fundi over the Agent2Agent (A2A) protocol. A run is a task with a lifecycle, not a
blocking tool call: you submit it and get a task id back at once, then poll its status or
cancel it. It replaces the older fundi_status, fundi_submit_test, fundi_task_status
and fundi_cancel_task tools.
The A2A bridge is built through its second stage: the agent card, task submission, status
and cancellation. The runs behind it, streaming updates and push notifications are still
design. A submitted task can come back parked as accepted but not executed.
Use cases
Building against the registry
mzizi_list_components, filtered to the node you are building at.mzizi_get_componentfor the full document of anything that looks right. Where a Rust implementation exists, it leads: depend on the crate inrust.install(see Mzizi Roots).mzizi_list_componentswithrust: truelists only those.- Install it (see consuming the registry).
Reviewing a change
mzizi_get_tokensto check a component uses published tokens, not raw values.mzizi_get_architectureto check it sits where its imports say it does.mzizi_check_accessibilityfor contrast on any new colour pairing.
Answering a question about Mzizi
docs_search_mzizi, then docs_query_docs_filesystem_mzizi to read the page it found.