OpenAPI in. Governed MCP tools out. Turn documented APIs into explicitly approved AI tools with credential protection, least privilege, and auditability.
Category: AI Developer Tools
Tech Stack: TypeScript, Node.js, Express 5, PostgreSQL, Drizzle ORM, OpenAPI, Model Context Protocol (MCP)
SpecRelay is an early, MIT-licensed open-source project for turning documented APIs into governed MCP tools. Import an OpenAPI document, review its operations, explicitly approve what AI can use, and expose eligible operations with credential protection, least privilege, and auditability.
The current milestone deliberately supports only HTTPS GET operations without request bodies. It supports declared API-key and HTTP Bearer credentials, not upstream OAuth flows or arbitrary proxying. It is a foundation to build on, not a claim of production readiness.
I built this as a sales engineer who builds with AI, not a traditional software engineer. That is part of the point. AI is giving more people who understand customers, workflows, APIs, and business problems the ability to build.
Connecting those tools to real systems safely is still harder than it should be. I wanted to make those connections safer: start with a documented API, require explicit approval, and keep credentials and execution behind a clear policy boundary. I open-sourced SpecRelay so other builders can inspect the approach and contribute.