@pipeworx/hackertarget
Connect: https://pipeworx.io/mcp — every tool in the catalog, including @pipeworx/hackertarget’s. Install: one-click buttons
Connect to just the @pipeworx/hackertarget pack
https://gateway.pipeworx.io/hackertarget/mcp — only @pipeworx/hackertarget’s own tools, nothing else in the catalog.
No MCP client? Skip the connection: POST https://gateway.pipeworx.io/v1/tools/search_packs {"query":"..."} to find a tool below, GET /v1/tools/<name> for its schema, POST the same URL with arguments for the data — see For AI agents.
Tools: 14
HackerTarget MCP — DNS and network-recon
utilities. Eleven of the fourteen tools need no credential; three
(whois, mtr, traceroute) require the caller’s own HackerTarget key.
Responses are line-oriented plain text from upstream; this pack parses them into
structured JSON when reasonable (lines[] plus the verbatim raw).
Tools
Keyless — call with just target:
dns_lookup(target)— A/AAAA/MX/NS/SOA records for a hostnamereverse_dns(target)— reverse DNS (PTR) for an IPnping(target)— ICMP ping from HackerTarget’s probe hostdns_host_search(target)— passive DNS subdomain searchfind_shared_dns(target)— domains sharing the same nameservergeoip(target)— IP geolocation (country / region / city / coords)reverse_ip(target)— hostnames resolving to the same IPas_lookup(target)— ASN, announced prefix and network namehttp_headers(target)— HTTP response headers for a host or URLsubnet_lookup(target)— subnet arithmetic for a CIDR blockpage_links(target)— links extracted from one page (full URL)
Require a caller-supplied key — call with target and _apiKey:
whois(target, _apiKey)— WHOIS record for a domain or IPmtr(target, _apiKey)— per-hop loss/latency reporttraceroute(target, _apiKey)— routers between HackerTarget and the target
Auth
Pipeworx fronts no platform key for HackerTarget. The eleven keyless tools
work with no credential at all; whois, mtr and traceroute are gated behind
a HackerTarget membership and are bring-your-own-key (Bruce’s ruling, fleet
#2132, 2026-09-16).
Get a key from the HackerTarget member dashboard
(https://hackertarget.com/ip-tools/) and pass it as _apiKey. It is forwarded
as the apikey= query parameter HackerTarget documents.
A keyless call to one of the three gated tools is refused before any request
leaves the gateway, with error: auth_required and a message saying the tool
requires an API key and where to get one. It is not an outage and does not
count as a tool failure. A key that is supplied and then rejected by HackerTarget
gets a different auth_required message — “the key you supplied was refused” —
so a caller who already holds a key is not sent to fetch it again.
Passing _apiKey to the eleven keyless tools is allowed and useful: it bills the
call against the caller’s own member quota instead of the shared free tier.
Rate limits
HackerTarget’s free tier is 50 calls/day per source IP at up to 2 requests/s
(their FAQ, re-read 2026-09-16 — older copies of this file said 100). That source
IP is the gateway’s shared egress, so an exhausted quota surfaces as an
API count exceeded body rather than an HTTP 429. Pipeworx’s own rate limit is
the outer envelope. Callers who bring _apiKey draw on their own quota.
Data sources
https://api.hackertarget.com— every tool in this pack- https://hackertarget.com/ip-tools/ — endpoint, auth and quota documentation
Tools
- dns_lookup — “Resolve [domain]” / “what IP does [site] point at” / “A records for [X]” — forward DNS lookup via HackerTarget, returning the A/AAAA/MX/NS/SOA records the resolver holds for a hostname. Use to check
- reverse_dns — “What hostname is [IP]” / “reverse DNS for [address]” / “PTR record lookup” — reverse DNS (PTR) lookup via HackerTarget, mapping an IP address back to the hostname its owner published. Use to identify
- mtr — “Network path to [host]” / “where does traffic to [X] slow down” / “per-hop latency” — mtr report via HackerTarget, combining traceroute and ping into a per-hop table of loss and latency measured FROM
- nping — “Is [host] up” / “ping [X]” / “round-trip time to [address]” — ICMP ping via HackerTarget, reporting reachability and round-trip time from HackerTarget’s probe host. Use for a liveness check when you
- dns_host_search — “Subdomains of [domain]” / “what hosts exist under [X]” / “find an admin or staging subdomain” — passive DNS host search via HackerTarget, listing known subdomains of a domain with their IPs, drawn fr
- find_shared_dns — “What else uses this nameserver” / “domains sharing DNS with [X]” — shared-nameserver search via HackerTarget, listing other domains served by the same DNS server. Use to map the infrastructure footpr
- geoip — “Where is [IP] located” / “what country is this address in” / “geolocate an IP” — IP geolocation via HackerTarget, returning country, state/region, city and coordinates for an address. City-level accu
- reverse_ip — “What else is hosted on [IP]” / “other sites on the same server” / “reverse IP lookup” — reverse IP lookup via HackerTarget, listing hostnames known to resolve to one address. Use to spot shared hosti
- as_lookup — “Which ASN owns [IP]” / “what network is this address on” / “who is the upstream provider” — autonomous system lookup via HackerTarget, returning the ASN, the announced prefix and the network’s name f
- whois — “Who owns [domain]” / “when does [X] expire” / “whois lookup” / “registrar for [site]” — WHOIS record via HackerTarget for a domain or IP: registrar, creation and expiry dates, nameservers, and whatev
- http_headers — “What headers does [site] return” / “what server runs [X]” / “check the security headers” / “does [site] redirect” — HTTP response headers fetched by HackerTarget, including status line, Server, redir
- traceroute — “Traceroute to [host]” / “what route does traffic take to [X]” / “how many hops to [address]” — traceroute via HackerTarget, listing the routers between HackerTarget’s probe host and the target. The p
- subnet_lookup — “What is the range of [CIDR]” / “how many hosts in a /24” / “network and broadcast address for [X]” / “subnet calculator” — subnet arithmetic via HackerTarget, returning network address, broadcast add
- page_links — “What does [page] link to” / “extract every link from [URL]” / “outbound links on a page” — link extraction via HackerTarget, fetching one web page and returning the URLs it links to. Use to map a sit
Tools
as_lookup— Which ASN owns [IP] / what network is this address on / who is the upstream provider — autonomous system lookup via HackerTarget, returning the ASN, the announced prefix and the network's name for andns_host_search— Subdomains of [domain] / what hosts exist under [X] / find an admin or staging subdomain — passive DNS host search via HackerTarget, listing known subdomains of a domain with their IPs, drawn from predns_lookup— Resolve [domain] / what IP does [site] point at / A records for [X] — forward DNS lookup via HackerTarget, returning the A/AAAA/MX/NS/SOA records the resolver holds for a hostname. Use to check wherefind_shared_dns— What else uses this nameserver / domains sharing DNS with [X] — shared-nameserver search via HackerTarget, listing other domains served by the same DNS server. Use to map the infrastructure footprintgeoip— Where is [IP] located / what country is this address in / geolocate an IP — IP geolocation via HackerTarget, returning country, state/region, city and coordinates for an address. City-level accuracy ihttp_headers— What headers does [site] return / what server runs [X] / check the security headers / does [site] redirect — HTTP response headers fetched by HackerTarget, including status line, Server, redirect Locamtr— Network path to [host] / where does traffic to [X] slow down / per-hop latency — mtr report via HackerTarget, combining traceroute and ping into a per-hop table of loss and latency measured FROM Hackenping— Is [host] up / ping [X] / round-trip time to [address] — ICMP ping via HackerTarget, reporting reachability and round-trip time from HackerTarget's probe host. Use for a liveness check when you cannotpage_links— What does [page] link to / extract every link from [URL] / outbound links on a page — link extraction via HackerTarget, fetching one web page and returning the URLs it links to. Use to map a site sectreverse_dns— What hostname is [IP] / reverse DNS for [address] / PTR record lookup — reverse DNS (PTR) lookup via HackerTarget, mapping an IP address back to the hostname its owner published. Use to identify the oreverse_ip— What else is hosted on [IP] / other sites on the same server / reverse IP lookup — reverse IP lookup via HackerTarget, listing hostnames known to resolve to one address. Use to spot shared hosting orsubnet_lookup— What is the range of [CIDR] / how many hosts in a /24 / network and broadcast address for [X] / subnet calculator — subnet arithmetic via HackerTarget, returning network address, broadcast address, ustraceroute— Traceroute to [host] / what route does traffic take to [X] / how many hops to [address] — traceroute via HackerTarget, listing the routers between HackerTarget's probe host and the target. The path iswhois— Who owns [domain] / when does [X] expire / whois lookup / registrar for [site] — WHOIS record via HackerTarget for a domain or IP: registrar, creation and expiry dates, nameservers, and whatever conta