AmunCore website screenshot

AmunCore

AmunCore turns a database into a secure REST API without writing a backend. You connect a database, pick tables, and endpoints go live with routing, authentication, validation, pagination, joins, errors, logs and docs already handled — the layer between a database and HTTP that would otherwise be a two-to-six-week project. It supports SQL Server, MySQL, MariaDB, PostgreSQL, Oracle and SQLite, with a visual builder that is the same regardless of the engine underneath. It is MCP-native by design: the endpoints you build become tools an AI assistant can call under the same keys, permissions and audit trail, and the MCP endpoint is live, token-gated and now fronted by RFC 8414/9728 OAuth discovery. A public OpenAPI 3.0.1 describes the five generated CRUD operations; REST auth is an X-Api-Key header. Built and operated by HYNOWorld, with a self-hosted option for regulated deployments. Full CRUD, a free plan forever, and paid tiers from $29/mo.

AmunCore publishes 1 API on the APIs.io network: Dynamic API. Tagged areas include Database, API Management, Backend, No-Code, and SQL.

The AmunCore catalog on APIs.io includes 1 event-driven AsyncAPI specification.

AmunCore’s developer surface includes documentation, code examples, authentication, sandbox, pricing, signup flow, support, and 28 more developer resources.

54.2/100 developing ▬ flat Agent 42/100 agent ready saas Full breakdown ↓
scored 2026-09-14 · rubric v0.22.0
AccessFreemiumSelf serve⚡ Free to try
2 APIs 1 MCP Servers
DatabaseAPI ManagementBackendNo-CodeSQLPostgreSQLMySQLOracleMCPAgentsDataSQL ServerWebhookOpenAPILow-CodeEgypt

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-09-14 · rubric v0.22.0
Create-or-Update Ergonomics applies to this provider. This API accepts writes, so it carries 10 points of the composite. It is scored from the published contracts themselves: whether a caller can create-or-update in one call, whether the write accepts a key the caller already holds, and whether the response says which branch ran. Without that, every write needs a search-and-branch in front of it, and the first time that check is skipped a duplicate record is created. Scored against the observed mean rather than raw — a provider at the catalog average is unchanged by this facet, not penalised by it.
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. Every facet and dimension name above is a link: it opens that measurement's own page — what it means, the exact checks that feed it, how the whole catalog distributes on it, and the providers at the top of it. This rating is computed from github.com/api-evangelist/amuncore: open an issue to ask a question, or submit a pull request to add artifacts. Submit an artifact on GitHub — free → Manage your own listing — the Influence plan, $499/mo →

APIs 1

Individual APIs this provider publishes, each with its own machine-readable definition.

AmunCore Dynamic API

Generated CRUD over a table or view exposed as an endpoint on a registered AmunCore application.

Open Collections 1

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

MCP Servers 1

Model Context Protocol servers that expose these APIs to AI agents.

AmunCore MCP Server

AmunCore is MCP-native by design: the REST endpoints a user builds over their own database become tools an AI assistant can call, under the same keys, permissions and audit trai...

MCP SERVER

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Amuncore Rate Limits

4 limits

RATE LIMITS

Event Specifications 1

AsyncAPI definitions for this provider's event-driven and streaming APIs.

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Amuncore Authentication

apiKey/oauth2 · 3 schemes

SECURITY

Amuncore Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Amuncore Trust Center

trust center published

SECURITY

Scopes 1

OAuth scopes governing access to this provider's APIs.

Amuncore Scopes

1 scope · authorizationCode

1 scopes

SCOPES

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Amuncore Agentic Access

5 operations · 3 acting

5 operations · 3 acting

AGENTIC

Resources

Get Started 3

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 7

MCP servers, agent skills, and machine-readable catalogs

Scroll for all 7

Design & Contract 6

Pagination, idempotency, versioning, errors, and events

Build 3

SDKs, sample code, and the tooling you integrate with

Access & Security 4

Authentication, authorization, and security posture

Operate 2

Status, limits, changes, and where to get help

Commercial 4

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Other 2

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: amuncore
url: https://raw.githubusercontent.com/api-evangelist/amuncore/refs/heads/main/apis.yml
name: AmunCore
description: 'AmunCore turns a database into a secure REST API without writing a backend. You connect a database, pick tables,
  and endpoints go live with routing, authentication, validation, pagination, joins, errors, logs and docs already handled
  — the layer between a database and HTTP that would otherwise be a two-to-six-week project. It supports SQL Server, MySQL,
  MariaDB, PostgreSQL, Oracle and SQLite, with a visual builder that is the same regardless of the engine underneath. It is
  MCP-native by design: the endpoints you build become tools an AI assistant can call under the same keys, permissions and
  audit trail, and the MCP endpoint is live, token-gated and now fronted by RFC 8414/9728 OAuth discovery. A public OpenAPI
  3.0.1 describes the five generated CRUD operations; REST auth is an X-Api-Key header. Built and operated by HYNOWorld, with
  a self-hosted option for regulated deployments. Full CRUD, a free plan forever, and paid tiers from $29/mo.'
deliveryModel:
  model: saas
  open_source: false
  commercial: true
  callable_host: true
  label: Hosted service · you call their endpoint
  confidence: high
  source:
  - openapi
  - pricing
  generated: '2026-08-28'
  method: derived
accessModel:
  pricing: freemium
  onboarding: self-serve
  trial: false
  try_now: true
  public: false
  label: Freemium · Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  - scopes
  - rate-limits
  - security
  - sandbox
  generated: '2026-09-02'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/amuncore.png
created: '2026-08-03'
modified: '2026-08-10'
specificationVersion: '0.23'
type: Index
position: Producing
access: 3rd-Party
kind: contract
tags:
- Database
- API Management
- Backend
- No-Code
- SQL
- PostgreSQL
- MySQL
- Oracle
- MCP
- Agents
- Data
- SQL Server
- Webhook
- OpenAPI
- Low-Code
- Egypt
tags_raw:
- Database
- API Management
- Backend
- No Code
- SQL
- PostgreSQL
- MySQL
- Oracle
- MCP
- Agents
- Data
- SQL Server
- Webhooks
- OpenAPI
- Low Code
- Egypt
apis:
- aid: amuncore:amuncore-dynamic-api-api
  name: AmunCore Dynamic API
  description: Generated CRUD over a table or view exposed as an endpoint on a registered AmunCore application.
  humanURL: https://amuncore.com
  baseURL: https://amuncore.com
  tags:
  - Dynamic API
  properties:
  - type: OpenAPI
    url: openapi/amuncore-dynamic-api-api-openapi.yml
  - type: Website
    url: https://amuncore.com
  - type: Documentation
    url: https://amuncore.com/swagger
  - type: Examples
    url: examples/amuncore-dynamic-api-examples.yml
  - type: Authentication
    url: authentication/amuncore-authentication.yml
  - type: OAuthScopes
    url: scopes/amuncore-scopes.yml
  - type: Conventions
    url: conventions/amuncore-conventions.yml
  - type: ErrorCatalog
    url: errors/amuncore-problem-types.yml
  - type: RateLimits
    url: rate-limits/amuncore-rate-limits.yml
  - type: DataModel
    url: data-model/amuncore-data-model.yml
  - type: ToolCrosswalk
    url: mcp/amuncore-tool-crosswalk.yml
  - type: Webhooks
    url: asyncapi/amuncore-webhooks.yml
  - type: Plans
    url: plans/amuncore-plans-pricing.yml
common:
- type: Overlay
  url: overlays/amuncore-dynamic-api-overlay.yaml
- type: MCPServer
  url: mcp/amuncore-mcp.yml
- type: AgenticAccess
  url: agentic-access/amuncore-agentic-access.yml
- type: DomainSecurity
  url: security/amuncore-domain-security.yml
- url: https://amuncore.com
  type: Website
- url: https://amuncore.com/swagger
  type: Documentation
- url: https://amuncore.com/llms.txt
  type: LLMsTxt
- url: openapi/amuncore-dynamic-api-openapi.yml
  type: OpenAPI
- url: examples/amuncore-dynamic-api-examples.yml
  type: Examples
- url: overlays/amuncore-dynamic-api-overlay.yaml
  type: Overlay
- url: llms/amuncore-llms.txt
  type: LLMsTxt
- url: well-known/amuncore-well-known.yml
  type: WellKnown
- url: mcp/amuncore-mcp.yml
  type: MCPServer
- url: mcp/amuncore-tool-crosswalk.yml
  type: ToolCrosswalk
- url: skills/_index.yml
  type: AgentSkill
- url: authentication/amuncore-authentication.yml
  type: Authentication
- url: scopes/amuncore-scopes.yml
  type: OAuthScopes
- url: conventions/amuncore-conventions.yml
  type: Conventions
- url: errors/amuncore-problem-types.yml
  type: ErrorCatalog
- url: rate-limits/amuncore-rate-limits.yml
  type: RateLimits
- url: lifecycle/amuncore-lifecycle.yml
  type: Lifecycle
- url: data-model/amuncore-data-model.yml
  type: DataModel
- url: conformance/amuncore-conformance.yml
  type: Conformance
- url: security/amuncore-trust-center.yml
  type: TrustCenter
- url: sandbox/amuncore-sandbox.yml
  type: Sandbox
- url: asyncapi/amuncore-webhooks.yml
  type: Webhooks
- url: packages/amuncore-packages.yml
  type: Packages
- url: plans/amuncore-plans-pricing.yml
  type: Plans
- url: https://amuncore.com/#pricing
  type: Pricing
- url: https://amuncore.com/Register
  type: SignUp
- url: https://amuncore.com/Auth/Login
  type: Login
- url: https://amuncore.com/terms.html
  type: TermsOfService
- url: https://amuncore.com/privacy.html
  type: PrivacyPolicy
- url: https://amuncore.com/#contact
  type: Support
- url: https://amuncore.com/about.html
  type: About
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
X-Discovery:
  date: '2026-08-03'
  method: probed
  note: Found while researching a separate company and profiled on its own merits. Everything below was fetched.
  findings:
  - surface: Website
    url: https://amuncore.com
    http_status: 200
    real: true
  - surface: MCPServer
    url: https://amuncore.com/mcp
    http_status: 401
    real: true
    note: 'Real and well built. GET returns 405; POST jsonrpc returns a correct JSON-RPC error -32001 "Unauthorized: missing
      MCP-Token header" rather than an HTML page.'
  - surface: OpenAPI
    url: https://amuncore.com/openapi.json
    http_status: 404
    real: false
    note: SUPERSEDED — see the 2026-08-10 re-probe below. On 2026-08-03 none was published for the platform itself. Note the
      product GENERATES APIs per tenant, so a platform-level spec is a different thing from the specs it produces.
  - surface: LlmsTxt
    url: https://amuncore.com/llms.txt
    http_status: 404
    real: false
    note: SUPERSEDED — see the 2026-08-10 re-probe below.
  - surface: Control
    url: https://amuncore.com/zzz-control-nonsense
    http_status: 404
    real: false
    note: Control path correctly 404s — no SPA catch-all, so the probes above are trustworthy.
X-Reprobe:
  date: '2026-08-10'
  method: probed
  note: 'Re-probed on the second enrichment pass. AmunCore shipped a machine-readable contract surface in the seven days after
    first profiling: the OpenAPI, llms.txt and both OAuth discovery documents were all 404 on 2026-08-03 and are all 200 now.
    The 2026-08-03 findings above are kept for the record and marked SUPERSEDED rather than rewritten. Note this also means
    the provider changed its public contract with no changelog and no status page to announce it.'
  findings:
  - surface: OpenAPI
    url: https://amuncore.com/openapi.json
    http_status: 200
    real: true
    note: OpenAPI 3.0.1, 5 operations over 2 paths, X-Api-Key security scheme, examples on all 30 responses. Byte-identical
      mirror at https://amuncore.com/swagger/v1/swagger.json.
  - surface: APIReference
    url: https://amuncore.com/swagger
    http_status: 200
    real: true
    note: Public Swagger UI, no sign-in required.
  - surface: LlmsTxt
    url: https://amuncore.com/llms.txt
    http_status: 200
    real: true
    note: 6.2KB, well-formed, and it publishes the twelve MCP tool names — the only anonymous route to the tool list, since
      tools/list itself is gated.
  - surface: WellKnown
    url: https://amuncore.com/.well-known/oauth-authorization-server
    http_status: 200
    real: true
    note: RFC 8414 metadata — authorization_code + refresh_token, PKCE S256 only, RFC 7591 dynamic client registration, single
      scope "mcp".
  - surface: WellKnown
    url: https://amuncore.com/.well-known/oauth-protected-resource
    http_status: 200
    real: true
    note: RFC 9728 metadata naming https://amuncore.com/mcp as the protected resource; the MCP 401 now carries the matching
      WWW-Authenticate Bearer challenge.
  - surface: AgentCard
    url: https://amuncore.com/.well-known/agent-card.json
    http_status: 404
    real: false
    note: Legacy /.well-known/agent.json also 404. No A2A agent card, so nothing was written to a2a/.
  - surface: SecurityTxt
    url: https://amuncore.com/.well-known/security.txt
    http_status: 404
    real: false
  - surface: GraphQL
    url: https://amuncore.com/graphql
    http_status: 404
    real: false
    note: security.html documents a GraphQL channel, but /graphql, /api/graphql and /api/v1/graphql all 404 — the GraphQL
      surface is generated per tenant, not served at the platform root.
  - surface: StatusPage
    url: https://status.amuncore.com/
    http_status: 0
    real: false
    note: DNS does not resolve. /changelog and /pricing also 404 — no status page, no changelog, and no standalone pricing
      route.
x-enrichment:
  date: '2026-08-10'
  status: enriched
  artifacts_added: 27
  artifacts_updated: 3
  pass: local-v1

Work with this as data

Every provider here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for providers

9 MCP tools reach this
  • find_providersBrowse and filter every provider in the catalog.
  • get_provider_artifactsEvery artifact this provider publishes, grouped by type.
  • get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
  • get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
  • get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
  • get_provider_ratingPRO — composite, band, trend and facet scores.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This provider
curl "https://apis.io/api/v1/providers/amuncore"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/amuncore/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/amuncore/evidence"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.