Every request your agent makes carries every tool definition this server exposes — context your code, documents and conversation can't use, mostly for tools the agent never calls. You don't need them all in the window, and you don't have to pay for them.
QUICK ANSWER The ReplyNodes MCP server's 66 tool definitions consume 432,983 tokens — 216% of a 200k context window, and 227× the median MCP server (1,908 tokens). A scoped grant exposing only the tools you use cuts that roughly in proportion.
Tool definitions are overhead: they occupy context on every request and compete with your code, documents and conversation history for the same window.
Corpus context: ReplyNodes ranks #1 of 9,700 measured MCP servers by definition cost. The median is 1,908 tokens, p90 is 17,396, and the heaviest (ReplyNodes) is 432,983 — 216% of a 200k window on its own. New to this? See MCP token cost and context window in the glossary.
Token cost is one axis. See the risk picture across your whole stack →
Each row is one tool definition as a tools/list entry — name, description and
input schema — counted with o200k_base. Average: 6,560 tokens per tool.
| Tool | Category | Tokens | % of server |
|---|---|---|---|
| read_document | Read | 6,686 | 1.5% |
| googleplay_reviews | Read | 6,669 | 1.5% |
| get_company_events | Read | 6,648 | 1.5% |
| webcontext_scrape | Read | 6,632 | 1.5% |
| webcontext_crawl | Read | 6,629 | 1.5% |
| web_search | Read | 6,628 | 1.5% |
| get_recent_company_events | Read | 6,625 | 1.5% |
| search | Read | 6,622 | 1.5% |
| googleplay_similar_apps | Read | 6,613 | 1.5% |
| googleplay_category_apps | Read | 6,608 | 1.5% |
| list | Read | 6,608 | 1.5% |
| hackernews_search | Read | 6,607 | 1.5% |
| reviews | Read | 6,607 | 1.5% |
| monitor_update | Read | 6,600 | 1.5% |
| googleplay_developer | Read | 6,598 | 1.5% |
| googleplay_availability | Read | 6,595 | 1.5% |
| app | Read | 6,588 | 1.5% |
| googleplay_search | Read | 6,588 | 1.5% |
| googleplay_suggest | Read | 6,588 | 1.5% |
| get_company_history | Read | 6,587 | 1.5% |
| googleplay_data_safety | Read | 6,585 | 1.5% |
| googleplay_app_details | Read | 6,581 | 1.5% |
| brand_retrieve | Read | 6,579 | 1.5% |
| hackernews_item | Read | 6,578 | 1.5% |
| googleplay_permissions | Read | 6,576 | 1.5% |
| webcontext_brand | Read | 6,575 | 1.5% |
| hackernews_stories_ask | Read | 6,567 | 1.5% |
| hackernews_stories_new | Read | 6,565 | 1.5% |
| hackernews_stories_best | Read | 6,565 | 1.5% |
| hackernews_stories_job | Read | 6,565 | 1.5% |
| hackernews_stories_show | Read | 6,565 | 1.5% |
| hackernews_stories_top | Read | 6,565 | 1.5% |
| brand_styleguide | Read | 6,564 | 1.5% |
| ratings | Read | 6,558 | 1.5% |
| brand_search | Read | 6,557 | 1.5% |
| developer | Read | 6,553 | 1.5% |
| brand_fonts | Read | 6,552 | 1.5% |
| webcontext_map | Read | 6,551 | 1.5% |
| similar | Read | 6,549 | 1.5% |
| brand_logo | Read | 6,543 | 1.5% |
| subreddit_posts | Read | 6,542 | 1.5% |
| googleplay_categories | Read | 6,538 | 1.5% |
| hackernews_user | Read | 6,538 | 1.5% |
| monitor_changes | Read | 6,537 | 1.5% |
| monitor_runs | Read | 6,537 | 1.5% |
| user_posts | Read | 6,537 | 1.5% |
| privacy | Read | 6,528 | 1.5% |
| suggest | Read | 6,528 | 1.5% |
| get_company_intelligence | Read | 6,521 | 1.5% |
| monitor_create | Read | 6,521 | 1.5% |
| search_posts | Read | 6,521 | 1.5% |
| youtube_search | Read | 6,520 | 1.5% |
| monitor_list | Read | 6,515 | 1.5% |
| user_activity | Read | 6,512 | 1.5% |
| youtube_comments | Read | 6,511 | 1.5% |
| youtube_transcript | Read | 6,505 | 1.5% |
| youtube_playlist | Read | 6,504 | 1.5% |
| youtube_related | Read | 6,504 | 1.5% |
| youtube_channel | Read | 6,503 | 1.5% |
| youtube_video | Read | 6,503 | 1.5% |
| monitor_get | Read | 6,500 | 1.5% |
| post_by_id | Write | 6,494 | 1.5% |
| post_by_permalink | Write | 6,493 | 1.5% |
| get_v1_hackernews_capabilities | Read | 6,487 | 1.5% |
| get_fetcher_readyz | Read | 6,485 | 1.5% |
| get_fetcher_healthz | Read | 6,480 | 1.5% |
You don't need all 66 of those definitions in the window. PolicyLayer is an MCP gateway that sits in front of ReplyNodes: only the tools you grant are exposed to the agent, the rest never load. A smaller window means a sharper agent — less noise when it picks a tool — and every request costs less:
| Grant scope | Definition cost | Reduction |
|---|---|---|
| All 66 tools (no gateway) | 432,983 tokens | — |
| 3 granted tools | ~19,681 tokens | −95% |
| 5 granted tools | ~32,802 tokens | −92% |
| 10 granted tools | ~65,603 tokens | −85% |
Instant setup, no code required.
Model your own stack in the token-cost calculator, or see the ReplyNodes policy for what a sensible grant looks like.
Its 66 tool definitions total 432,983 tokens — 216% of a 200k context window — measured with tiktoken o200k_base over the serialised tools/list payload. Exact counts vary slightly by client and model.
MCP clients load every connected server's tool definitions — name, description, and input schema — into the model's context so it knows what it can call. That payload is charged against your context window on every request, whether or not a tool is used.
Expose fewer tools. A PolicyLayer grant scopes ReplyNodes to only the tools you allow — ungranted definitions are filtered out of the tool list, so they never enter the context window. A grant of 3 typical tools costs roughly 19,681 tokens, a 95% reduction.
Partially, in some clients. Claude Code defers MCP tool schemas behind a tool-search step by default, and VS Code has experimental grouping — but you still pay tokens per search and reload, and Cursor, Windsurf and Gemini CLI load definitions upfront. Reducing the exposed tool set cuts the cost in every client.
Each tool is serialised as a tools/list entry — name, description, input schema — from the schemas in the PolicyLayer scan database. Clients differ slightly in framing, so treat counts as close estimates.
tiktoken o200k_base (GPT-4o/o-series). Anthropic's current tokeniser isn't published, so Claude's exact counts will differ; for English text and JSON schemas the totals are close enough to treat these as estimates.
Some clients now defer schema loading (Claude Code's tool search; VS Code experimental grouping). You still pay per search and reload — and Cursor, Windsurf and Gemini CLI load everything upfront.
Computed 07-10-2026 from the PolicyLayer scan database over all 66 catalogued ReplyNodes tools. Counts refresh with every site build.
A PolicyLayer grant scopes ReplyNodes to the tools you actually allow. Ungranted definitions never load, and every call that does run is checked against policy first.
Instant setup, no code required.
46,500+ MCP servers and 515,000+ tools scanned and risk-classified.