Official MCP server for Linkly — create and manage short links, custom domains, click analytics and webhooks from any MCP client. Powers the hosted server at https://mcp.linklyhq.com
This MCP server has serious definitional gaps that prevent confident production deployment. Of 7 tools, 5 have adequate schemas and descriptions, but 2 (list_links and create_link from index.js) lack visibility into their actual implementations. The server shows some quality characteristics: tool annotations (destructiveHint/readOnlyHint) are present, risk levels are declared, and most descriptions exist. However, critical issues undermine overall quality: (1) descriptions are sparse and often vague (averaging 60-100 chars when best practice is 150-250), (2) parameter descriptions are missing or trivial for many tools, (3) no output schemas are documented anywhere, (4) error handling is not evident from the code, (5) the 'ping' tool is a deprecated MCP pattern (removed in 2024-11 spec) and should not be present, (6) tool composition is poor, update_link and update_workspace lack crucial detail about field merging behavior, and (7) the create_link tool's schema (visible in index.js) shows 23 optional parameters with minimal guidance on dependencies (e.g., 'domain required with slug' mentioned only in description, not enforced). The server is deprecated (noted in index.js header) and directs users to a hosted alternative, which undermines confidence in maintenance. The codebase quality is further damaged by incomplete source visibility, we see tool definitions scattered across src/index.ts and index.js without clear registration patterns.
Batch delete multiple links
Create short links and URL shorteners. Use this when the user asks to shorten a URL, create a short link, or make a link shorter.
List links with sorting and search
Return details of authenticated workspace
Health check
Test API Authentication
Update workspace settings. Only the fields provided are changed; omitted fields keep their current values.
No output schemas documented for any tool. Tools return results but LLMs cannot know the structure of returned fields, forcing agents to guess at response shape and breaking composition chains.
The 'ping' tool implements a deprecated MCP pattern (health check via tool invocation). Removed in current spec. Should be replaced with proper server health reporting or removed entirely.
Tool names lack consistent verb_noun convention: 'batchDeleteLinks' uses camelCase and compound action (batch + delete). Should be 'batch_delete_links' or split into separate tools. Naming ambiguity confuses LLM tool selection.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 60 | 2025-06-18+ | v2 |
| 2026-03-09 | F | 0 | - | v1 |
create_link parameter 'domain' has description 'Custom domain for the short link (without trailing /)' but critical constraint 'Must be a domain that already belongs to this workspace, call list_domains to get valid values' is buried. No mention of list_domains tool existing. Parameter lacks enum constraint or reference to discovery tool. Agents cannot know valid domains without trial-and-error.
Parameter descriptions extremely sparse. 'list_links' sort_by parameter has no description of valid values (e.g., which fields can be sorted?). 'update_workspace' webhooks parameter description warns about replacement behavior but lacks examples or validation rules for webhook URLs. Agents cannot validate inputs.
No error handling documentation visible. apiRequest() function throws generic 'API request failed' errors with no guidance for LLM recovery. Agents cannot distinguish retryable failures from permanent ones or learn what to do next.
No pagination limits documented. 'list_links' accepts page and page_size but no guidance on max page_size or default. Agents could request huge batches, blowing context windows. Baseline pattern requires result caps and pagination hints.
create_link has 23 optional parameters with minimal type constraints. Parameter 'enabled' is boolean but defaulting behavior not explicit in schema (says 'default: true' in description, not JSON Schema default). Parameter 'expiry_datetime' expects ISO 8601 but no format constraint. Validation relies entirely on API-side behavior.
API key and workspace ID exposed as environment variables injected into every request body (see apiRequest: '...body, workspace_id: WORKSPACE_ID, api_key: API_KEY'). Best practice is header-only injection. Request bodies logged in traces risk exposing credentials.
Tool 'batchDeleteLinks' performs destructive operations (batch delete) but lacks confirmation or dry-run support. No audit trail documented. Agents could accidentally delete all links with one malformed call.