An MCP server for OpenStreetMap travel planning: geocoding, walking/driving/cycling routes, multi-stop optimization, isochrones and POI search — over free public services, with no API key.
The public OSRM demo servers ignore the profile inside the OSRM URL and always answer with car routes unless the FOSSGIS routed-foot/bike/car path prefixes are used. Most OSM MCP servers get this wrong; this one uses the prefixes, and its live smoke test asserts that foot routes come out much slower than car routes.
Policy-compliant by construction
Per-service client-side rate limiting, a mandatory identifying User-Agent, response caching, capped Overpass concurrency and automatic failover to an Overpass mirror on 429/5xx — the published usage policies of the shared community services are enforced in code.
Eleven tools, or the three you need
OSM_ALLOW_TOOLS cuts finer — essential for a curated six, your own comma-separated list, or a whole family with list_* — and OSM_DENY_TOOLS subtracts. Whatever is filtered out does not exist on the protocol rather than failing when called, and a name that matches no tool stops the server at startup instead of quietly going missing.
No API key, read-only by design
Every backend is a free public OpenStreetMap service and all 11 tools are read-only. The only optional secret is an OpenRouteService key, which is scrubbed from the environment after loading and redacted from error messages.
The server speaks stdio, holds no credentials by default, and throttles itself below the published limits of every public OSM service it calls.
No URL, no token — the public OpenStreetMap services are the default configuration. Then ask things like "how long is the walk from the Louvre to Notre-Dame?", "plan the best order to visit these five places", "what can I reach in 15 minutes on foot from my hotel?" or "find a fair cafe for the three of us to meet".
By design: no writes to OpenStreetMap (the API for that is not even wired up), no map image rendering, no GPS tracking, no traffic data, and no bulk geocoding — the client-side throttles that keep it inside the public services' usage policies make it deliberately unsuitable for hammering. For heavy or commercial use, self-host the backends and point the *_BASE_URL variables at them. See Security.
A client that cannot spawn a local process — ChatGPT connectors, Claude on the web, Cursor, LibreChat — cannot start osm-mcp the way Claude Code does. mcp-hub is the bridge: one container serves many stdio MCP servers over Streamable HTTP, with an OAuth 2.1 login behind a single password and long-lived tokens for the clients that cannot do OAuth. Its /hub endpoint puts every server behind six meta-tools, so one connector reaches all of them without N×tool schemas in the model's context, and it speaks both protocol revisions — a question this server asks travels through it to the person at the far end instead of ending at the gateway.
Its configuration is Claude Code's mcpServers format, so the entry you already have is the entry it takes: Through mcp-hub.