“I need my agent to use the Stripe, Jupiter, whatever-is-next API.”
One line adds it. No client to hand-write.
Open source · Built in public
Open-source and on-device. Correct calls. Keys safe.
One command, and Gecko translates the docs to your agent's language. We bring a clear path, so your agent stops guessing. It starts getting things right.
TRY IT NOW
$ npx @geckovision/gecko add <your-api>SEE IT WORK
THE JOURNEY
“I need my agent to use the Stripe, Jupiter, whatever-is-next API.”
One line adds it. No client to hand-write.
“Do I paste my API key into mcp.json? Into an env var?”
Neither. Your key stays hidden on your machine and is used only at the moment of the call. Never in a file, never inside the agent.
“The agent called it and got a 400. Then a 401. Then another 400.”
Gecko read the API first. Your agent calls it right the first time: right params, right auth.
“I don't want to burn rate limits or real money just to test.”
Recorded mode proves every call offline, for $0.
“It worked yesterday. Now it's a 401 at 3am. Who wrote a refresh loop?”
Sessions auto-refresh. The agent never sees the expiry.
“Fifth API, same pain, times five.”
One layer for every API. Keys out of reach, calls correct, no per-API glue.
For agent builders
For API providers
WHY NOW
HOW IT WORKS
CONNECT
An OpenAPI spec or a docs URL. Even messy, undocumented, or paywalled. Gecko reads the API first and turns it into tools your agent picks by what you ask.
npx @geckovision/gecko add \ https://api.example.com/openapi.json
SECURE
Sealed in the OS keychain, never in a file. The agent never sees it: nothing to paste, nothing to steal.
# sealed in your OS keychain gecko auth set stripe
EXECUTE
The call is right the first time. The key joins only at the moment of the call, sent only to the API's own host. Log-ins refresh on their own; you stop babysitting.
✓ call correct · key joined at call time → ask: "charge $10 to customer_123"
Gecko never sees your data. The key never enters the agent, the model, your files, or Gecko's servers.
FAQ
In your OS keychain, the same vault your machine already uses for passwords. Gecko reads it on your machine at the moment of the call and sends it only to the API's own domain. It never enters the agent, your files, or Gecko's servers.
The API's shape — endpoints, parameters, schemas — and the tools it generates from that. Not your responses, not your data, not your keys. The call goes from your machine to the API's own host. Gecko routes the intent, not the payload.
It happens: a manipulated description or example crafted to steer an agent into a dangerous move. Gecko screens everything an API says before your agent sees it, and quarantines anything suspicious. Running today, on every API it reads.
We read the docs. For Mintlify, Redoc, and Scalar we discover the spec behind the page. If we can't find one, we tell you what to paste.
The engine is open source and free. Providers pay a flat per-API fee, never a take-rate.
Yes. Any MCP client — Cursor, Windsurf, Claude Desktop — connects via the hosted endpoint in one line. Python library if you prefer to call it directly. Recorded mode ($0, fully offline) works everywhere.
MCP is the pipe. A wrapper just opens it — every endpoint becomes a tool, auth is still your problem, and when your agent needs to pick the right call across five APIs, the wrapper has nothing to say. Gecko adds the layer that makes the pipe worth using: it reads the API first, builds a graph of what to call and when, seals your key, and answers when the agent has to choose. We are not replacing MCP. We run on top of it.
This page has a twin your agent can read. For agents →