# dev.echorelay/management

A managed runtime for custom API integrations. Manage lines, endpoints, keys, logs and DLQ via MCP.

- **Type:** MCP server
- **Trust:** 30/100 (D), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 0.13.0
- **Author:** dev.echorelay
- **License:** Unknown
- **Endpoints:** streamable-http https://mcp.echorelay.dev
- **Source:** https://mcp.echorelay.dev
- **Endpoint health:** reachable (last checked 2026-10-03T06:28:45.715Z, 6 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

30/100 (D), scored on the content rubric
- Publisher verified: no
- Install scripts: suspicious script found
- Prompt-injection scan: findings present
- Obfuscation scan: clean
- Evidence age: 38 days

## Security scan

- **Status:** warnings
- **Scanned:** 2026-08-29T21:15:08.080Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.
**Findings**
- injection-shaped content (warning) in the `generate_line_draft` tool: Exfiltration-shaped instruction

## Tools

79 declared. Observed from a live `tools/list` probe.
- `get_project` — Get the EchoRelay project this token is scoped to: id, slug, name, caller-facing API base URL, whether the token has edit access, and the request-log hot-tier r
- `list_lines` — List the project's versioned API lines (e.g. v1, v2), each with its endpoint count.
- `list_endpoints` — List the endpoints under one line of the project.
- `get_endpoint` — Get the full JSON of one endpoint, including its targets, auth keys and attributes.
- `get_config` — Get the project's published relay configuration — the exact JSON the EchoRelay Framework consumes. Includes pendingPublish with its frozen, redacted config when
- `config_diff` — Preview what Save & Publish (or the pending scheduled publish, if one exists) would change: added/removed/changed lines, and within each changed line the added/
- `list_config_revisions` — List retained revisions for one line so a prior revision can be selected for rollback.
- `get_line_draft` — Read one line draft, its optimistic revision, preview, and schedule.
- `preview_line_draft` — Preview one line draft without publishing it.
- `publish_line_draft` — Publish one line draft now and clear only its schedule.
- `discard_line_draft` — Discard every unpublished change and schedule for one line.
- `discard_draft_endpoint` — Discard one endpoint change from a line draft.
- `schedule_line_publish` — Schedule one non-empty line draft. Active subscribers required.
- `cancel_line_publish` — Cancel one line schedule before its two-minute lock.
- `rollback_config` — Publish a retained line revision immediately and clear any pending schedule.
- `get_billing` — Get the project's credit balances (paid + testing) and which ledger it settles on. `billingModel` is `prepaid` (metered against the credit balance) or `invoicea
- `set_burst_opt_in` — Enable or disable the auto-decaying burst window for live traffic and publish the change immediately. When enabled, brief spikes a little above your steady RPM 
- `set_rpm_ceiling` — Set or clear a self-set ceiling on this project's own effective live-traffic RPM (Traffic shaping) — for when your origin can't take the throughput your plan gr
- `set_outbound_allowlist` — Narrow the project's outbound host allowlist — the hosts a target may point at. The current list is on get_project as `outboundHostAllowlist` (empty means any p
- `create_line` — Create a new versioned line. A new line has no endpoints, so creating one publishes nothing and serves no traffic yet — add an endpoint, which publishes the lin
- `delete_line` — Delete a line and every endpoint under it, publishing the removal immediately. Requires edit access.
- `activate_line` — Activate and immediately publish an inactive line so it serves traffic again. Blocked at the active-line cap — deactivate another line first. Requires edit acce
- `deactivate_line` — Take a line off the data plane immediately (callers get 404) without deleting it — endpoints/targets/config are preserved and it can be reactivated later. A del
- `duplicate_line` — Copy a line and all its endpoints/targets/rules into a new line key — build v2 from v1. The copy is saved inactive and remains off the data plane; edit it, then
- `set_docs_shared` — Turn the line's public OpenAPI docs on or off. When enabled, the line's spec is published at docs.{baseDomain}/{slug}/{lineKey} (and …/openapi.json); when disab
- `create_endpoint` — Create an endpoint under a line. Defaults to immediate publish; draft mode requires draftRevision. scheduledAt stages the line draft then schedules it. Requires
- `generate_line_draft` — Generate a draft endpoint under a line from a sample inbound request and a description of the target: infers the inbound body schema from the sample, reads the 
- `update_endpoint` — Update an endpoint immediately or in its line draft. The patch is merged field-by-field. Requires edit access.
- `delete_endpoint` — Delete an endpoint and its targets, publishing the removal immediately. Requires edit access.
- `default_endpoint_template` — Return a canonical minimal-valid endpoint JSON for a fresh line. POST it verbatim to create_endpoint to land an immediately-working endpoint, then customise. It
- `dry_run_endpoint` — Validate an endpoint document without writing it. Returns either {ok: true, resolved: <Framework config slice>} or {ok: false, errors: {...}}. Pass endpointId t
- `list_members` — List accepted and pending members of this project. Shows name/email, role, and whether the invite has been accepted. Owner only.
- `invite_member` — Invite a person by email to collaborate on this project. Returns the new invitation record; the invitee receives an email with an accept link. Enforces the seat
- `remove_member` — Remove a member (accepted or pending) from this project by their member ID or email. Owner only.
- `set_member_role` — Change a member's role between editor, viewer, and billing. Identify the member by their member ID or email (from list_members); the project owner's own role ca
- `resend_invite` — Re-send the invitation email for a still-pending invite, by member ID or email (from list_members). The original accept link is reused. Already-accepted members
- `list_api_keys` — List the project's inbound API keys (metadata only — the secret plaintext is never returned).
- `create_api_key` — Mint an inbound relay (data-plane) API key for callers to send traffic to this project. Its `er_live_` or `er_test_` secret authenticates relay requests; it can
- `rotate_api_key` — Mint a linked successor for an existing key. Returns the successor plaintext exactly once — store it now. The predecessor stays valid through its overlap window
- `reveal_rotation_successor` — One-shot retrieval of the plaintext for a successor minted by the auto-rotation scheduler (not by rotate_api_key — that returns its own plaintext directly). Dec
- …and 39 more

## Install

**Verdict: do-not-install** — Do not install: 1 injection-shaped pattern found in this entry's own text — it may try to steer the model that loads it.
**Blocking**
- 1 injection-shaped pattern found in this entry's own text — it may try to steer the model that loads it. — tool:generate_line_draft#sample: Exfiltration-shaped instruction
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Client configuration withheld.** Client configs are withheld because this entry has a blocking finding. Show the warnings below to the person installing it.
If they have seen the findings and still want to proceed, request the plan again with acknowledge_warnings=true.

## Blast radius

Extensive to critical — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: deletes data; runs on someone else's infrastructure.
- Floor 36, ceiling 60 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/dev.echorelay%2Fmanagement
- Install plan: https://forgeregistry.com/api/v1/packages/dev.echorelay%2Fmanagement/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/dev.echorelay%2Fmanagement
- HTML page: https://forgeregistry.com/registry/dev.echorelay%2Fmanagement
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
