treg: a credential-injecting registry that gives agents one token for 3,000+ tools
OpenRouter for agent tools. Join community here: https://discord.gg/6mQYYfFMAn
At a glance
- What is it?
- treg is an OpenRouter-style catalog and proxy for agent tools, not models. It solves the subscription problem by carrying provider accounts server-side and metering calls against a prepaid balance, while letting teams register their own keys, CLIs and skills behind the same token.
- Who is it for?
- treg fits teams whose agents need occasional access to paid data sources (backlinks, enrichment, ads, scraping) without buying a subscription per provider, and teams that want to share internal CLIs and SKILL.md recipes without handing out credentials. It is the wrong tool when you need one provider at high volume, when you want the proxy to choose or fail over between vendors for you, or when you cannot accept that the registry holds upstream secrets server-side.
- Can I use it commercially?
- Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
- Is it still maintained?
- Yes. The repository received new commits within the last day.
- What is it written in?
- Mainly Python, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.
Editorial analysis
The problem treg solves: agent tools sit behind subscriptions nobody buys for one run
The README is blunt about the motivation. The tools an agent needs for real work sit behind subscriptions nobody buys for a single run, and it names the numbers: Semrush at $139/mo, Moz at $99/mo, Crunchbase at $99/mo, Apollo at $59/seat. Others sit behind signup walls or have no public API at all. The stated audience is the Superdesign team, with treg.to as the live instance, but the README says anyone can self-host.
The pitch is that you ask for the task, not the tool. You do not need to know which vendor sells backlink data, or hold an account with them. You search for what you want to do, read the price, and call it. That is the whole value proposition, and it is a real one for agents that need a backlink lookup once a week rather than a seat on a platform.
How the proxy works: relay, never model, and inject auth server-side
The repository describes one governing rule: the proxy relays, never models the upstream, and injects auth server-side. That means it survives upstream API changes and callers never hold keys. It is a proxy in the narrow sense, not an abstraction layer that reshapes responses.
The vocabulary matters because the README uses it precisely. A tool is something the registry calls for you with the org's credential, and it comes in two kinds. An endpoint is an upstream base_url plus credential bindings, where each binding injects one secret into the request; a single request can carry several, such as an OAuth bearer and a developer-token header together. A CLI is a vendor binary (stripe, gh, vercel) run with the credential injected. A skill or bundle is a recipe (SKILL.md) plus its secrets plus its tool(s), registered together.
Catalogued calls resolve through a credential ladder, in order: your team registered its own tool for that provider, so that tool and that key are used; your team stored a secret for the provider, injected through a virtual tool; or neither, in which case treg's own key is used and billed to the team's prepaid balance. Your own credential always beats treg's, so connecting a key you already pay for makes those calls free of the balance rather than duplicating them. One consequence is stated plainly: an endpoint treg has no published price for is refused, not served free, and you are told to connect your own key instead.
Installing the treg CLI and making a first catalogued call
The README's quickstart mirrors the dashboard's Getting started guide. The install script both installs the CLI and points it at the registry:
curl -fsSL https://treg.to/install.sh | shSign-in supports three paths. GitHub is the default, --email requests a one-time code, and --token is intended for agents and CI:
treg loginYou can do something useful immediately, with no key and nothing registered. Search by what a tool does rather than by vendor, then call it and check what it cost:
treg catalog search "backlinks for a domain"
treg call tikhub.tiktok.user.profile --query uniqueId=tiktok
treg balanceYour token identifies you on every call through the X-Treg-Token header and is the same for all tools. To see what your team has shared, run treg tool ls, and to check credential health, run treg health. The README also mentions treg onboard as a guided walkthrough.
There is a second install path if you use Claude Code. The plugin marketplace commands install with no token and no configuration, and the skill loads as treg:treg:
/plugin marketplace add superdesigndev/treg
/plugin install treg@tregOn its first run the skill walks your agent through the CLI, sign-in, then treg mcp install. For other agents the README gives npx skills add superdesigndev/treg -s treg, and notes that the -s matters because without it you also get the repository's internal dev skills.
Sharing your own tools, and the scan-first path
The second half of treg is about your own credentials. The README calls the zero-thought path treg scan, which points treg at a project and figures out what is shareable; the excerpt describes it as a read-only preview. Anything a teammate registered, whether a paid API account, an OAuth connection, a vendor CLI or a SKILL.md, becomes callable by every teammate's agent without the credential leaving the server.
The important asymmetry is billing. Catalog calls on treg's key are metered against the team's prepaid balance, but calls made with your own key are never metered. That gives teams a clear decision: bring the accounts you already pay for, and use the catalog for the long tail you would never buy.
There is also an Enrich Arena at /enrich-arena, outside the dashboard, for comparing enrichment answers with each vendor's cost and speed. Browsing is public; submitting requires login, and billable attempts use your team's credits.
Where treg stops: no failover, unpriced endpoints refused, secrets on the server
The README is unusually candid about a design boundary. Where several providers serve one capability, treg catalog search shows them side by side with prices, and choosing is yours. The registry does not silently pick or fail over between providers for you. If you want that behaviour, it is opt-in: treg.<capability> routed endpoints let treg pick the provider and name it. For anyone expecting an OpenRouter-like router that balances across vendors, this is a meaningful difference.
Two other constraints follow from the same design. First, an endpoint with no published price is refused rather than served free, so the catalog is not a blanket fallback for every provider you might want. Second, the proxy injects auth server-side, which is the source of its convenience and also its trust requirement: upstream credentials live in the registry, so self-hosting or trusting the hosted instance is a real decision, not a formality.
The README notes one more behaviour worth knowing: when treg's own account for a provider is out, it may serve the same endpoint through a treg-owned relay account, disclosed on the response, and a team can opt out.
treg compared with wiring provider SDKs directly
The obvious alternative is what most teams do today: create an account with each provider, store the key in your own secret manager, and call the provider's SDK or REST API from the agent. The difference in approach is where the credential lives and who pays. Direct wiring gives you the provider's full API surface, its rate limits under your own account, and no intermediary that can change or refuse a call. It also means a signup, a billing relationship and a key rotation for every provider, which is exactly the cost treg is built to remove.
treg trades that control for a single token and per-call pricing from a cent. The trade is visible in the credential ladder: your key wins when you have one, and treg's key covers the rest at a metered price. If you already pay for Semrush or Apollo and use it heavily, direct wiring is cheaper and simpler. If your agent needs twenty providers occasionally, the registry is the smaller commitment.
Licence, maintenance and what upgrading costs
The licence situation needs care. The repository's LICENSE file is flagged as NOASSERTION by the hosting platform, while package.json declares Apache-2.0 and pyproject.toml carries the classifier License :: Other/Proprietary License. Those three signals do not agree, and the README does not resolve them. Anyone planning to embed treg in a product should read the LICENSE file itself rather than rely on the metadata. This is not legal advice.
On maintenance, the last push to the default branch was on 2026-09-10, and the repository is not archived. The Python package is versioned 0.19.1 and classified Development Status :: 4 - Beta, so the API surface should be treated as pre-1.0. The npm package treg-dsh carries the same version.
Upgrade cost is shaped by the packaging split. The base install is just the CLI, kept light and pure-Python so pip install tools-registry and Homebrew are fast. Everything needed to run a registry server lives in the server extra, installed with pip install "tools-registry[server]", which pulls FastAPI, uvicorn, SQLModel, SQLAlchemy, alembic, asyncpg, cryptography and pyyaml. Self-hosters therefore carry a database and migration surface that CLI-only users never touch. Python is pinned to >=3.12,<3.14, and pyproject.toml notes that this must stay in sync with PYREQ in src/treg/web/install.sh, so version bumps touch more than one file.
What the MCP surfaces expose, and why there are two
treg exposes MCP in more than one place, and the split is deliberate. The Claude Connectors Directory surface is https://treg.to/mcp/v2/. According to the README it exposes only curated catalog endpoints and separates read calls from write calls so Claude receives accurate safety signals. The existing /mcp/ surface remains available for catalog endpoints, team-owned tools and imported skills.
If you are wiring treg into Claude through the connectors directory, the /mcp/v2/ boundary is narrower by design, and that is the point. If you need your team's own tools or imported skills, you are on the older surface. The README points to docs/context/architecture/mcp-oauth.md for the boundary and implementation, and to docs/CLAUDE-CONNECTOR-SUBMISSION.md for release gates.
Editorial conclusion
treg fits teams whose agents need occasional access to paid data sources (backlinks, enrichment, ads, scraping) without buying a subscription per provider, and teams that want to share internal CLIs and SKILL.md recipes without handing out credentials. It is the wrong tool when you need one provider at high volume, when you want the proxy to choose or fail over between vendors for you, or when you cannot accept that the registry holds upstream secrets server-side. Before adopting, verify the licence terms for your use case, confirm whether the hosted treg.to instance or a self-hosted server is the right deployment for your data, and check that the specific endpoints you need carry a published price, since unpriced endpoints are refused rather than served free.
Frequently asked questions
What is treg used for?
treg is a registry and proxy that lets an agent call catalogued third-party tools, such as backlink, enrichment, ads and scraping endpoints, through one base URL and one token, with calls metered against a prepaid balance. It also lets a team register its own APIs, CLIs and SKILL.md recipes so teammates' agents can call them without holding the credential.
How do I install the treg CLI?
The README's quickstart installs it with curl -fsSL https://treg.to/install.sh | sh, which also points the CLI at the registry, followed by treg login. Sign-in defaults to GitHub, with --email for a one-time code and --token for agents and CI.
Does treg work without an account with each provider?
For catalogued endpoints, yes: the registry can serve them on treg's own key, billed to your team's prepaid balance, with no provider account needed. The exception is an endpoint treg has no published price for, which is refused rather than served free and requires you to connect your own key.
Can I self-host treg?
The README states that anyone can self-host, and pyproject.toml defines a server extra installed with pip install "tools-registry[server]" that carries the FastAPI app, database drivers and encryption. The base install is only the CLI and is not enough to run a registry server.
What happens when my team's treg balance runs out?
The README states that being out of balance is an HTTP 402 carrying balance_micro, estimated_cost_micro and a topup_url, so an agent can act on it without reading prose. Funds are added with treg topup, which also supports automatic top-ups.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/superdesigndev-treg)