Kimi K3 MCP
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Kimi K3 MCPreview the binary search algorithm for edge cases"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Kimi K3 MCP
A small, read-only Model Context Protocol server that gives Codex and other MCP clients a Kimi K3 second opinion through OpenRouter.
It exposes three tools:
review_algorithm: challenge correctness, invariants, edge cases, counterexamples, and complexity.review_code: find concrete correctness, security, reliability, and performance defects.plan_project: produce an implementation-ready plan with dependencies, verification, risks, and rollback.
The server cannot read or modify local files. The MCP client chooses what code and context to send. Submitted content is treated as untrusted data, and Kimi's private reasoning is excluded from tool results. Responses include token usage, cost, latency, provider, and retry metadata.
The tools are strictly opt-in. Server instructions tell the MCP client not to call them for routine reviews or planning; explicitly mention Kimi, K3, the Kimi MCP, or a tool name when you want a call.
Requirements
Python 3.11 or newer
An
OPENROUTER_API_KEYwith access tomoonshotai/kimi-k3
Related MCP server: codex-fusion-mcp
Install
git clone git@github.com:catid/k3mcp.git
cd k3mcp
uv sync --frozenDo not put the OpenRouter key in this repository or in config.toml. Export it in the environment
that starts Codex:
export OPENROUTER_API_KEY=sk-or-v1-...Configure Codex
Add the server to ~/.codex/config.toml. Adjust the absolute path to the clone:
[mcp_servers.kimi_k3]
command = "/absolute/path/to/k3mcp/.venv/bin/k3mcp"
env_vars = ["OPENROUTER_API_KEY"]
enabled = true
required = false
startup_timeout_sec = 20
tool_timeout_sec = 15600
default_tools_approval_mode = "approve"Restart Codex after changing its MCP configuration. In the TUI, /mcp shows whether the server
and its tools loaded successfully.
Other MCP clients
The server uses stdio transport:
OPENROUTER_API_KEY=... uv run k3mcpThe process writes MCP protocol messages to stdout. Application logs must go to stderr.
Configuration
Variable | Default | Purpose |
| required | OpenRouter credential |
|
| Model slug |
|
| API root |
|
| Maximum completion tokens per call |
|
| Combined system and user prompt limit |
|
| Per-attempt response-read timeout |
|
| Total call deadline including retries |
|
| Total attempts for retryable failures |
|
| OpenRouter reasoning effort |
|
| OpenRouter attribution title |
| repository URL | OpenRouter attribution referrer |
Kimi K3 reasoning is mandatory on OpenRouter. The server requests maximum effort and excludes the reasoning trace while retaining its token count in usage metadata.
Development
uv sync --all-groups
uv run ruff check .
uv run ruff format --check .
uv run pytestTests use a mocked OpenRouter transport and a real MCP stdio handshake; they do not spend API
credits. Retry tests cover network failures, rate limits, every 5xx status, malformed or empty
successful responses, and OpenRouter's occasional transient invalid model ID response for an
otherwise live model slug. OpenRouter can report provider failures inside HTTP 200 responses;
those are classified by their embedded status so billing, authentication, guardrail, and token-cap
errors are not retried. Explicit transient provider responses and connection-establishment failures
use the full retry budget. Ambiguous failures that may already have incurred usage are retried at
most once, and read timeouts are not retried. Backoff is bounded; Retry-After supports both
delta-seconds and HTTP dates up to five minutes, while longer cooldowns fail without retrying early.
Connection and pool waits are capped at 30 seconds and request writes at 60 seconds, independently
of the longer response-read timeout needed for high-effort K3 completions. The server's total call
deadline is deliberately 10 minutes shorter than the sample MCP client timeout, leaving time to
return a structured error instead of being cancelled by the client.
GitHub Actions runs linting, formatting, tests, the stdio protocol handshake, and package builds on Python 3.11, 3.12, and 3.13. Workflow actions are pinned to immutable commit SHAs.
Security and cost
Tool calls send the supplied code and project context to OpenRouter and its selected provider.
The server is read-only but calls a metered external API (
openWorldHint=true).The 256,000-token completion setting is a ceiling, not a reservation, but long reasoning calls can still consume substantial metered output tokens.
Inputs and outputs are bounded by environment-configurable limits.
Errors never include request headers or the API key.
Model output is advisory. Verify findings and plans before applying changes.
Available Tools
3 toolsplan_projectPlan a project with Kimi K3ARead-only
Only when explicitly requested, ask Kimi K3 to create a project plan.
| Name | Required | Description | Default |
|---|---|---|---|
| decisions | No | Optional decisions already made that the plan should preserve or explicitly challenge. | |
| objective | Yes | Concrete outcome the project must achieve. | |
| constraints | No | Optional technical, compatibility, operational, budget, or scope constraints. | |
| project_context | Yes | Current system, repository evidence, relevant components, and known state. |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The annotations already declare readOnlyHint=true and destructiveHint=false, covering the safety profile. The description adds no further behavioral context, such as that this invokes an external AI model or the nature of the plan output. It is not misleading, but it provides minimal additional transparency beyond the annotations.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single sentence, front-loaded with the usage condition and action. It is concise and easy to parse. However, it is also under-specified, lacking useful context about the planning process, but it avoids verbosity.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The tool has a rich schema and an output schema, but the description is very sparse. It does not explain what kind of project plan is produced or how the parameters are used. Given the richness of the structured fields, the description is minimally acceptable but could do more to aid selection.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema has 100% description coverage for all 4 parameters, so the structured fields fully document them. The description does not add any parameter-specific semantics, relying entirely on the schema. Baseline 3 is appropriate since the schema carries the information.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states the action 'ask Kimi K3 to create a project plan' and the title says 'Plan a project', clearly indicating the tool's purpose. It is distinct from sibling tools 'review_algorithm' and 'review_code', which are for code review. However, the description is conditional and does not add detail beyond the title.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly says 'Only when explicitly requested', providing a clear when-to-use condition and implying not to use it proactively. It does not name alternatives, but the siblings are clearly review tools, so there is no ambiguity. This meets the 'when' criterion but lacks explicit when-not and alternative references.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
review_algorithmReview an algorithm with Kimi K3ARead-only
Only when explicitly requested, ask Kimi K3 to challenge an algorithm.
| Name | Required | Description | Default |
|---|---|---|---|
| focus | No | Optional specific concern such as proof, complexity, numerical stability, or concurrency. | |
| context | No | Optional surrounding architecture, data assumptions, or known tradeoffs. | |
| algorithm | Yes | Algorithm description, pseudocode, or implementation to review. Include all relevant details. | |
| requirements | Yes | Required behavior, constraints, and correctness criteria. |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint=true and destructiveHint=false, covering the safety profile. The description adds the conditional trigger ('only when explicitly requested') but does not disclose further behavioral details such as external calls, latency, or result handling. This is acceptable given annotation coverage but not generous.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single sentence that front-loads the key constraint and action. There is no wasted text, and the essential usage condition is immediately visible.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The description is brief, but the rich schema and annotations cover parameters and safety, and an output schema exists so return values are documented elsewhere. The main missing element is explicit connection to sibling tools, but the core trigger and action are sufficient for a simple review tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%: all four parameters have meaningful descriptions in the schema (algorithm, requirements, focus, context). The tool description itself adds no parameter-specific semantics, so the schema carries the full burden and the baseline score of 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the specific action 'challenge' applied to 'an algorithm' and names the target 'Kimi K3'. This distinguishes it from sibling tools like review_code and plan_project, which target different resources.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The phrase 'Only when explicitly requested' provides a clear condition for invocation, effectively excluding proactive use. However, it does not explicitly mention alternatives or contrast with sibling tools, so it stops short of a 5.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
review_codeReview code with Kimi K3ARead-only
Only when explicitly requested, ask Kimi K3 to review code or a diff.
| Name | Required | Description | Default |
|---|---|---|---|
| code | Yes | Relevant code, patch, or diff. Include enough surrounding code to validate findings. | |
| focus | No | Optional review focus such as correctness, security, performance, or concurrency. | |
| context | No | Optional language, runtime, architecture, tests, and surrounding behavior. | |
| requirements | Yes | Intended behavior and review acceptance criteria. |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description adds valuable behavioral context beyond the annotations: it requires an explicit request and reveals that the tool delegates to an external AI (Kimi K3). The annotations already provide readOnlyHint=true and destructiveHint=false, so the safety profile is well covered, and the description is consistent with them.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, front-loaded sentence that states the key usage condition and the core purpose. There is no filler or redundant information.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The description, combined with complete schema coverage, output schema, and annotations, provides enough information to invoke the tool correctly. It could mention alternative tools or process details, but the essential rule (explicit request) is covered.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
All four parameters have descriptive schema entries (100% coverage), so the schema handles parameter semantics. The description itself adds no additional parameter-level detail, warranting the baseline score of 3.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly identifies the action ('review code or a diff') and the resource (code/diff with Kimi K3), making the purpose specific. It does not explicitly differentiate from sibling tools like review_algorithm, but the name and target resource provide enough distinction.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
'Only when explicitly requested' is a strong, explicit usage condition, telling the agent not to invoke this tool proactively. It doesn't mention alternative tools or exclusions, but this condition alone gives clear guidance on when to use it.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
3 tool updates
v0.1.0- First observed
plan_project - First observed
review_algorithm - First observed
review_code
TDQS
Each tool targets a distinct task: algorithmic review, code review, and project planning. There is no overlap or ambiguity between them.
All tools follow the same verb_noun pattern (review_algorithm, review_code, plan_project), making the set predictable and easy to understand.
With three tools, the server is well-scoped for its purpose of invoking specific Kimi K3 actions. Each tool serves a clear function, and the count is within the ideal range.
The set covers key developer workflows (review and planning), but it lacks additional common tasks like code generation or debugging, which are minor gaps for the apparent scope.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
An MCP server that gives your AI access to the source code and docs of all public github repos
Augments MCP Server - A comprehensive framework documentation provider for Claude Code
Hosted MCP server connecting claude.ai, ChatGPT and other AI apps to your own computer
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceA read-only MCP server for AI coding agents to inspect repositories, audit code quality, route engineering skills, and plan safe issue/PR workflows.1MIT
- AlicenseNot gradedqualityBmaintenanceMCP server enabling Claude to consult Codex (GPT-5.x) mid-task for second opinions, plan/diff review, brainstorming, and codebase exploration via structured debates and permission-controlled interactions.2MIT
- AlicenseAqualityDmaintenanceAn MCP server that provides technical consultation, code review, and code explanation by integrating with OpenAI's Codex CLI, enabling AI-powered coding assistance in a sandboxed, read-only environment.3641MIT
- AlicenseBqualityAmaintenanceAn unofficial MCP server that lets Codex ask a read-only OpenCode advisor for a second review pass on Git changes.3MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/catid/k3mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server