APISIX MCP
MCP server bridging LLMs with the Apache APISIX Admin API to query and manage gateway resources.
🛡️ AgentReady threat assessment
MAESTRO 7-layer threat model + OWASP AIVSS risk score for APISIX MCP, derived from its capabilities.
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.
Overview
Connects LLMs to the Apache APISIX Admin API, letting agents query and manage all gateway resources - routes, upstreams, plugins, consumers. Admin access to an API gateway is powerful: an agent could reconfigure routing or auth plugins, so the admin key scope is a critical surface.
Key features and capabilities
- APISIX Admin API access
- Manage routes and plugins
- Gateway resource control
Use cases
- Managing an API gateway via AI
- Automating APISIX configuration