Pipeworx Gateway

Remote MCP gateway for current, citable data from SEC, FDA, economics, real estate, research, and other sources.

Description

Pipeworx Gateway is a standalone, durable remote MCP service operated by Pipeworx. The official product site at https://pipeworx.io presents Pipeworx as a data gateway rather than a directory. The official documentation at https://pipeworx.io/docs/ explains connection through https://gateway.pipeworx.io/mcp. The official repository at https://github.com/pipeworx-io/pipeworx contains the public project description, configuration examples, and guides. Smithery contains the exact pipeworx/gateway entry with the candidate description unchanged, remote=true, and isDeployed=true. Smithery reports the deployment endpoint https://gateway--pipeworx.run.tools; its lastSuccessfulDeployment maps the upstreamUrl to https://gateway.pipeworx.io/pipeworx-catalog/mcp. This mapping connects the registry deployment to the provider domain, but it does not replace checking the provider documentation for current conditions. The provider repository also publishes the current general connection URL https://gateway.pipeworx.io/mcp. GitHub identifies the repository as MIT licensed. On 2026-09-09, GitHub reported exactly six stars; that point-in-time number is a popularity signal, not evidence of quality, security, or availability.

Purpose and data scope

According to the provider, the gateway connects an MCP-capable AI client to many live data sources through one connection. Sources include SEC and other financial information, FDA and health data, FRED and BLS economic series, trade data, real estate information, clinical trials, patents, weather, public procurement, environmental information, news, and developer data. The exact number of sources and tools changes. The Smithery description says 250+ data sources and 900+ tools for this entry, while the repository and website publish later, larger snapshots. These numbers are therefore provider and registry snapshots, not timeless guarantees. According to the provider, ask_pipeworx accepts a plain-language question, selects a suitable tool, fills arguments, and returns structured results with citations. discover_tools can find tools for a domain. Compound tools combine several queries, but they must not manufacture unsupported conclusions.

Operation and source quality

The product value comes from aggregating heterogeneous, preferably primary data sources. SEC EDGAR, FDA, FRED, BLS, Census, ClinicalTrials.gov, and government registers each have their own update schedules, correction processes, definitions, and geographic limits. A citation makes an answer more traceable but guarantees neither completeness nor correct interpretation. Users must check period, unit, region, reference date, and the primary source before a business, medical, financial, or legal decision. A cache may be returned with freshness metadata according to the provider; current therefore does not necessarily mean published moments ago. Results are data, not binding advice. Expert review is required especially for health, finance, and compliance questions.

Authorization, privacy, and roles

The documentation describes a public starting path without an API key for many queries; current limits, account terms, and optional authentication must be checked directly with the provider before use. The absence of credentials does not make an operation safe without access controls. Network access to a remote service is itself a trust decision. The MCP client sends questions, parameters, and potentially pasted business data to Pipeworx. Pipeworx may pass them to connected data sources and return results to the client. A local MCP client does not automatically keep this information local, and an attached hosted model may process the context as well. Organizations should clarify purpose limitation, legal basis, retention, region, logging, subprocessors, and deletion. Roles should distinguish the requester, approving operator, and system owner. Access restrictions, DLP rules, network allowlisting, and minimal context are required for enterprise data. Catalog examples contain no personal data, secrets, tokens, or API keys.

Write access and security boundaries

The gateway is primarily documented for research and data retrieval. Nevertheless, tool calls can reach external systems, save results, or make information available across sessions through remember and recall. Any possible write access requires explicit authorization, the correct role, a confirmed target, idempotency, and an audit trail. Prompt injection can appear in documents, search results, company fields, or error messages. It must not change permissions, network rules, roles, or follow-up actions. Clients should allowlist the provider endpoint, enforce TLS, inspect tool schemas, confirm sensitive actions, and bound timeouts and retries. The provider claims source quality and citations; according to the provider, this is not independent certification. The E-E-A-T basis of this entry is the Pipeworx product site, Pipeworx documentation, Pipeworx repository, and the exact Smithery deployment data. Before production use, re-check endpoint identity, data flow, access model, terms, and security posture.

Requirements

An MCP client with Streamable HTTP support and network access to the official Pipeworx endpoint. Enterprise data additionally requires role controls, DLP, allowlisting, and a reviewed privacy basis.

Installation instructions

Add the official endpoint https://gateway.pipeworx.io/mcp to the MCP client. Use the Smithery endpoint only after confirming its current mapping and access conditions. Start with read-only tools and minimal data.

https://gateway.pipeworx.io/mcp

Authentication

According to the provider, many entry queries need no API key. Check current authentication, account, and usage conditions in official Pipeworx documentation. Do not store credentials in the catalog.

Required access permissions

The client receives access to data tools exposed by the remote gateway. Organizations must define roles, data classes, endpoint allowlisting, and confirmations; possible storage or follow-up actions require separate authorization.

Transmitted or stored data

Questions, parameters, and potentially business data are sent to Pipeworx and may be shared with connected sources and the attached model. Minimize data and review retention, logging, region, and deletion.

Security risks

Remote trust boundaries, prompt injection in sources, incorrect citations, PII in logs, unclear roles, and possible storage or follow-up actions are risks. Mitigate with TLS, allowlisting, least privilege, DLP, confirmations, and auditing.

License and costs

License
MIT
Cost
paid

Pipeworx describes the gateway as a metered service. Check current availability, limits, and provider terms directly; concrete prices are not stored in the catalog.

Alternatives

Not recorded yet.

At a glance

Provider
Pipeworx
Status
Official server
Deployment
Remote
Current version
Not recorded yet.
GitHub stars
6
Last reviewed
09.09.2026

Repository and documentation

Categories

Supported clients

Not recorded yet.