Docs

whichlib answers three questions for coding agents: which library fits a need, which of several is better, and what is new or rising.

On this page: Tools · Remote MCP · Web API · Score and tiers · Limits and your own token · Privacy

Tools

ToolInputsReturns
recommend_reposneed in plain words (2-200 characters), optional language (GitHub language name), limit 1-10 (default 5)The best repositories for the need, ranked by fit = score × relevance. On whichlib.com, relevance uses a TypeSafe Jev judgment of whether each candidate is an installable library whose main purpose is the need (returned as signals.jevFit, with a weak-fit flag below 0.5) in place of the word-match factors; the npm package and own-token calls use the word-match rules.
compare_reposrepos: 2-10 names as owner/repoSide by side, best score first; names that do not exist are listed under notFound.
trending_reposperiod day, week, month or rising (default week), optional language, limit 1-100 (default 20), withDownloads (default false)Most-starred repositories created in the period, or with rising repositories of any age by stars gained this week; returned sorted by score (starsRank keeps the stars order).

Every result has readable text and the same data as JSON: score, tier, verdict, the four parts of the score, flags, npm/PyPI packages and weekly downloads.

Remote MCP

Streamable HTTP, stateless. Claude Code:

claude mcp add --transport http whichlib https://whichlib.com/mcp

With your own GitHub token (unlimited use):

claude mcp add --transport http whichlib https://whichlib.com/mcp --header "X-GitHub-Token: YOUR_TOKEN"

Cursor (.cursor/mcp.json):

{ "mcpServers": { "whichlib": { "url": "https://whichlib.com/mcp" } } }

Own token: add "headers": { "X-GitHub-Token": "YOUR_TOKEN" } next to url.

VS Code (.vscode/mcp.json):

{ "servers": { "whichlib": { "type": "http", "url": "https://whichlib.com/mcp" } } }

Own token: add "headers": { "X-GitHub-Token": "YOUR_TOKEN" } next to url.

Writing your own client: POST one JSON-RPC message per request with the header Accept: application/json, text/event-stream. Batches are not supported; GET returns 405 (there is no server-to-client stream).

Web API

The same three tools as JSON over GET. Parameters have the tools' names, ranges and defaults (repos is comma-separated); the response is the tool's JSON result.

curl "https://whichlib.com/api/recommend?need=python+http+client&language=Python&limit=3"
curl "https://whichlib.com/api/compare?repos=colinhacks/zod,fabian-hiller/valibot"
curl "https://whichlib.com/api/trending?period=rising&language=Rust&limit=10"
StatusMeaning
200The result.
400Bad input, including unknown parameters.
401Your X-GitHub-Token was rejected by GitHub.
404None of the repositories to compare exist.
405Only GET is allowed.
429Daily free limit, the per-minute limit, or the rate limit of your own GitHub token reached; see Retry-After.
500Internal error.
502 / 503GitHub failed (or the rising list could not be downloaded), or the shared GitHub limit is used up; try again shortly or use your own token.

Errors are JSON: { "error": "..." }. CORS is open (read-only, no cookies).

Score and tiers

Each repository gets a score from 0 to 100:

PartWeightMeasures
Momentum40%Stars gained per week from daily star counts; for repositories not tracked, lifetime stars per week scaled by the npm/PyPI download trend.
Maintenance25%Full marks for a push within the last 30 days, falling to zero at a year; a penalty when open issues exceed 10% of the stars. Widely used repositories (10,000+ stars or 100,000+ weekly downloads) pushed within the last year never score below half.
Adoption25%Stars, forks and, when known, npm/PyPI weekly downloads, each on a log scale.
License10%Permissive licenses (MIT, Apache-2.0, BSD, ISC and similar) score highest, weak copyleft (MPL, LGPL) a little less, strong copyleft (GPL, AGPL) and unrecognised licenses half, no license zero.

Tiers: Strong 75 and up, Solid 50-74, Watch 25-49, Avoid below 25. Repositories younger than 30 days show New instead of a tier: too new to judge. Archived repositories are capped at 20. The full definition is in the README and score.js.

Limits and your own token

Privacy

Your search text goes to GitHub as a search query, as with the npm package. For recommend_repos without your own token, the need and the public name, description and topics of each candidate also go to TypeSafe (hosted in the US), which judges each candidate's fit; TypeSafe does not train on it, and your token and IP address are never sent there. whichlib stores hashed cache keys and cached results (public GitHub, npm and PyPI data, plus the question asked, kept for up to a day), and a per-day call counter per hashed IP address (the raw address is never stored, and the hash changes every day). Each tool call also adds one anonymous row to the call counter (tool name, version and time; no IP, token or query); only aggregate counts are public. Your own GitHub token is used for your request only and never stored; results fetched with it are not shared with other callers. The website's pages load their fonts from Google Fonts, so your browser sends its IP address to Google when you open them. Details: PRIVACY.md.