How to integrate URLhaus using MCP
Retrieve recent malicious URLs from URLhaus. This guide creates an MCP server from Arthur's URLhaus template — tools preconfigured against https://urlhaus-api.abuse.ch/v1 — and finishes by sharing the server's MCP swagger documentation.
Steps
Open the Secrets vault and create a secret named
URLHAUS_API_KEYholding your API key. Obtain a free abuse.ch Auth-Key and send it in the Auth-Key header.


Go to the REST API Templates gallery and search for URLhaus.


Click Use template on the URLhaus card to open the server-creation dialog.


Review the server name and select
URLHAUS_API_KEYin the credential field — the dialog only accepts vault secrets, and it lists every tool that will be created.


Click Create server. Arthur creates the server, applies the authentication, and generates all the tools.





Open the server's Tools tab to review the generated tools.

Open the server's Connect section and click Share the MCP swagger documentation — Arthur generates the public documentation link and QR code for this server.



Confirm it worked
The server appears with 1 preconfigured tool(s): list_recent_malicious_urls. The Connect section offers the MCP swagger documentation — a shareable page with setup instructions for any AI client.
Good to know
- List recently reported malware-distribution URLs from the URLhaus community feed.
- This integration requires a credential (api-key). Get one at https://auth.abuse.ch/.
- Official API documentation: https://urlhaus-api.abuse.ch/
- Editing a tool later never changes the template — templates are starting points, and the server is fully yours after creation.
Related
Tutorial video