# ai.duvera/gateway (remote · app.duvera.ai)

Governed AI actions with signed, verifiable receipts: free keyless reads, human-approved writes.

- Trust score: 63/100 (medium)
- Change this week: +2
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- remote · `app.duvera.ai`: 63/100 (this document), [markdown](https://verifymcp.io/servers/ai-duvera-gateway/app.md), [page](https://verifymcp.io/servers/ai-duvera-gateway/app)

## Channel facts

- Endpoint: `https://app.duvera.ai/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.0.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Endpoint Security**: 57/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation not fully verified: no authorisation is required to call this server, and 52 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe.
  - HTTPS is enforced; there's no plaintext access path.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 73/100
  - AI-judged instruction clarity (good).
  - Tool/resource definitions use about 3630 tokens (~69/item across 52 items; 52 tools + 0 resources), lean.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 27/100
  - Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Capabilities**: 40/100
  - Spec-recency check failed: implements MCP spec 2025-03-26; the latest is 2026-07-28.

## Install

### Claude

```bash
claude mcp add --transport http ai-duvera-gateway https://app.duvera.ai/mcp
```

### Codex

```toml
[mcp_servers.ai-duvera-gateway]
url = "https://app.duvera.ai/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "ai-duvera-gateway": {
      "type": "remote",
      "url": "https://app.duvera.ai/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add ai-duvera-gateway --url https://app.duvera.ai/mcp --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  ai-duvera-gateway:
    url: "https://app.duvera.ai/mcp"
```

### Other

```json
{
  "mcpServers": {
    "ai-duvera-gateway": {
      "type": "http",
      "url": "https://app.duvera.ai/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-02 (score 63, +1)

No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-07-31 (score 62, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-30 (score 62, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-29 (score 62, +1)

No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-07-27 (score 61, +1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-26 (score 60)

First indexed and scored.

## MCP tools (52)

### `amazon__package_track` (~51 tokens)

[amazon · risk:low] Look up the delivery status of an Amazon order (read-only)

Input parameters:

- `order_id` (string): The order or tracking id to look up (defaults to most recent)

### `applehealth__heart_rate_read` (~68 tokens)

[applehealth · risk:medium] Read heart-rate data from Apple Health

Input parameters:

- `end` (string): ISO-8601 end of the query window (defaults to now)
- `start` (string): ISO-8601 start of the query window (defaults to today)

### `applehealth__sleep_read` (~68 tokens)

[applehealth · risk:medium] Read sleep-analysis data from Apple Health

Input parameters:

- `end` (string): ISO-8601 end of the query window (defaults to now)
- `start` (string): ISO-8601 start of the query window (defaults to last night)

### `applehealth__steps_read` (~67 tokens)

[applehealth · risk:medium] Read step-count data from Apple Health

Input parameters:

- `end` (string): ISO-8601 end of the query window (defaults to now)
- `start` (string): ISO-8601 start of the query window (defaults to today)

### `bluesky__trending_get` (~51 tokens)

[bluesky · risk:low] Fetch the current trending topics on Bluesky. Returns topic names, display labels, and links to the topic feed. No account or API key required.

### `chase__balance_check` (~46 tokens)

[chase · risk:low] Read the current balance of a Chase account (read-only)

Input parameters:

- `account` (string): The Chase account to check (defaults to primary)

### `datadog__logs_view` (~85 tokens)

[datadog · risk:low] Search and read logs from Datadog over a time range

Input parameters:

- `from` (string): Start of the time range (ISO 8601 or relative)
- `query` (string, required): Datadog log search query
- `to` (string): End of the time range (ISO 8601 or relative)

### `delta__boardingpass_show` (~49 tokens)

[delta · risk:low] Pull up the boarding pass for a Delta flight

Input parameters:

- `confirmation_code` (string, required): Booking confirmation code
- `passenger` (string): Passenger last name

### `duvera__dev_npm_package` (~76 tokens)

[duvera · risk:low] Look up the latest version, description, license, and dependencies of an npm package. Works for scoped packages too (e.g. "@types/node"). No account required.

Input parameters:

- `package` (string, required): npm package name, e.g. "express" or "@types/node".

### `duvera__dev_pypi_package` (~68 tokens)

[duvera · risk:low] Look up the current version, summary, license, and homepage of a Python package on PyPI. No account required.

Input parameters:

- `package` (string, required): PyPI package name, e.g. "requests" or "fastapi".

### `duvera__dev_stackoverflow_search` (~75 tokens)

[duvera · risk:low] Search Stack Overflow questions by keyword. Returns top 5 by relevance with title, link, score, and answer status. No account required.

Input parameters:

- `query` (string, required): Search terms, e.g. "goroutine leak detection" or "pandas merge on index".

### `duvera__finance_crypto_price` (~117 tokens)

[duvera · risk:low] Current spot price for one or more cryptocurrencies (CoinGecko ids like "bitcoin,ethereum,solana") in a fiat currency (default USD). Read-only market data. No account required.

Input parameters:

- `ids` (string, required): Comma-separated CoinGecko coin ids, e.g. "bitcoin" or "bitcoin,ethereum,solana".
- `vs_currencies` (string): Comma-separated fiat/quote currencies (default "usd"), e.g. "usd,eur".

### `duvera__finance_exchange_rates` (~35 tokens)

[duvera · risk:low] Live USD exchange rates against major currencies. Read-only, no account required.

### `duvera__food_recipe_search` (~71 tokens)

[duvera · risk:low] Search recipes by dish name (e.g. "arrabiata", "pad thai"). Returns ingredients, instructions, category, and cuisine. No account required.

Input parameters:

- `query` (string, required): Dish name to search for, e.g. "carbonara".

### `duvera__food_restaurant_search` (~68 tokens)

[duvera · risk:low] Search for restaurants and food places by name or location using OpenStreetMap. Read-only, no account required.

Input parameters:

- `query` (string, required): Search query, e.g. "pizza in San Francisco" or "sushi near me".

### `duvera__geo_geocode` (~95 tokens)

[duvera · risk:low] Convert a city or place name (e.g. "Berlin", "San Francisco") to latitude/longitude, country, timezone, and population. Use this before weather.current or weather.air-quality when you only have a place name. No account required.

Input parameters:

- `query` (string, required): Place name to look up, e.g. "Berlin" or "Springfield, Illinois".

### `duvera__github_latest_release` (~86 tokens)

[duvera · risk:low] Get the latest published release (tag, name, notes, date) of a public GitHub repository. Returns 404 for repos that publish no releases. No auth required.

Input parameters:

- `owner` (string, required): Repository owner, e.g. "expressjs".
- `repo` (string, required): Repository name, e.g. "express".

### `duvera__github_read_file` (~94 tokens)

[duvera · risk:low] Read a file from a public GitHub repository. Read-only.

Input parameters:

- `owner` (string, required): Repository owner (username or org), e.g. "octocat".
- `path` (string): File path within the repository, e.g. "README.md". Defaults to README.md.
- `repo` (string, required): Repository name, e.g. "Hello-World".

### `duvera__github_search_repos` (~63 tokens)

[duvera · risk:low] Search public GitHub repositories by keyword. Returns top 5 results by stars. No auth required.

Input parameters:

- `query` (string, required): Search query (e.g. "machine learning python", "react component library").

### `duvera__news_search` (~69 tokens)

[duvera · risk:low] Search Hacker News stories by keyword, ranked by relevance. Returns title, URL, points, author, and comment count. No account required.

Input parameters:

- `query` (string, required): Search terms, e.g. "model context protocol" or "postgres performance".

### `duvera__news_top_stories` (~34 tokens)

[duvera · risk:low] Top stories from Hacker News. Read-only, no account required.

### `duvera__reference_dictionary` (~58 tokens)

[duvera · risk:low] Definitions, phonetics, part of speech, and examples for an English word. No account required.

Input parameters:

- `word` (string, required): English word to define, e.g. "governance".

### `duvera__reference_public_holidays` (~102 tokens)

[duvera · risk:low] Public holidays for a given year and ISO country code (e.g. 2026 + "US"). Includes national and regional holidays with dates and names. No account required.

Input parameters:

- `country` (string, required): ISO 3166-1 alpha-2 country code, e.g. "US", "DE", "JP".
- `year` (number, required): Calendar year, e.g. 2026.

### `duvera__time_now` (~88 tokens)

[duvera · risk:low] Current date and time in an IANA timezone (e.g. "America/New_York", "Asia/Tokyo"). Includes day of week and DST status. No account required.

Input parameters:

- `timezone` (string, required): IANA timezone name, e.g. "America/New_York", "Europe/Berlin", "Asia/Tokyo".

### `duvera__travel_flight_search` (~133 tokens)

[duvera · risk:low] List aircraft currently airborne within a radius of a point (adsb.lol ADS-B data). Use geo.geocode to get a city's coordinates first. Returns callsign, altitude, speed, and position. No account required.

Input parameters:

- `latitude` (number, required): Latitude of the search center (e.g. 40.64 for JFK).
- `longitude` (number, required): Longitude of the search center (e.g. -73.78 for JFK).
- `radius_nm` (number, required): Search radius in nautical miles (1-250), e.g. 50.

### `duvera__weather_air_quality` (~105 tokens)

[duvera · risk:low] Current air quality (US AQI, PM2.5, PM10, ozone) for a latitude/longitude. Use geo.geocode first if you only have a place name. No account required.

Input parameters:

- `latitude` (number, required): Latitude of the location (e.g. 37.77 for San Francisco).
- `longitude` (number, required): Longitude of the location (e.g. -122.42 for San Francisco).

### `duvera__weather_current` (~102 tokens)

[duvera · risk:low] Current temperature, conditions, wind, and humidity for a latitude/longitude (Open-Meteo). Use geo.geocode first if you only have a city or place name. No account required.

Input parameters:

- `latitude` (number, required): Latitude of the location (e.g. 37.77 for San Francisco).
- `longitude` (number, required): Longitude of the location (e.g. -122.42 for San Francisco).

### `duvera__wiki_search` (~76 tokens)

[duvera · risk:low] Search Wikipedia articles by keyword. Returns matching page titles, keys, and excerpts. Pass a result's key to wiki.summary for the article summary. No account required.

Input parameters:

- `query` (string, required): Search terms, e.g. "zero trust architecture" or "Ada Lovelace".

### `duvera__wiki_summary` (~90 tokens)

[duvera · risk:low] Get the lead summary of a Wikipedia article by title (e.g. "Zero_trust_architecture"). Use wiki.search first to find the exact page key. No account required.

Input parameters:

- `title` (string, required): Article title or page key, e.g. "Ada Lovelace" or "Zero_trust_architecture" (from wiki.search results).

### `gmail__mail_read` (~44 tokens)

[gmail · risk:low] Read recent emails from the Gmail inbox

Input parameters:

- `label` (string): Optional label/folder to read from (defaults to INBOX)

### `google_workspace__mail_search` (~51 tokens)

[google-workspace · risk:low] Search Mail via Gmail, governed by Duvera.

Input parameters:

- `query` (string, required): Search query, e.g. 'invoices from Acme last month'.

### `googlecalendar__availability_find` (~80 tokens)

[googlecalendar · risk:low] Find open time slots within a date range in Google Calendar

Input parameters:

- `duration_minutes` (number): Desired slot length in minutes
- `end` (string, required): End of the search window in ISO 8601 format
- `start` (string, required): Start of the search window in ISO 8601 format

### `grubhub__order_track` (~47 tokens)

[grubhub · risk:low] Check the live status and ETA of a Grubhub order

Input parameters:

- `order_id` (string, required): Identifier of the order to track

### `hackernews__stories_top` (~66 tokens)

[hackernews · risk:low] Fetch the current list of top-story ids on Hacker News. Returns an array of item ids (resolve details via the item endpoint). No account or API key required; the hacker-news.firebaseio.com endpoint is open and unmetered.

### `instacart__menu_search` (~65 tokens)

[instacart · risk:low] Search for grocery items and stores in the Instacart app

Input parameters:

- `query` (string, required): Search terms, e.g. "organic bananas"
- `store` (string): Store name or id to scope the search

### `maps__eta_share` (~61 tokens)

[maps · risk:low] Share your estimated time of arrival with a contact from Apple Maps

Input parameters:

- `contact` (string, required): Contact name or number to share ETA with
- `destination` (string): Destination address or place name for the active trip

### `microsoft365__calendar_list` (~47 tokens)

[microsoft365 · risk:low] List Calendar via Outlook Calendar, governed by Duvera.

Input parameters:

- `range` (string): Date range, e.g. 'this week'.

### `microsoft365__mail_search` (~53 tokens)

[microsoft365 · risk:low] Search Mail via Outlook / Exchange, governed by Duvera.

Input parameters:

- `query` (string, required): Search query, e.g. 'invoices from Acme last month'.

### `notion__notes_search` (~38 tokens)

[notion · risk:low] Search pages and notes in Notion by query

Input parameters:

- `query` (string, required): Search query string

### `obsidian__notes_search` (~40 tokens)

[obsidian · risk:low] Search notes in an Obsidian vault by query

Input parameters:

- `query` (string, required): Search query string

### `open_meteo__weather_forecast` (~89 tokens)

[open-meteo · risk:low] Current temperature, conditions, humidity, and wind for a latitude/longitude, from Open-Meteo.

Input parameters:

- `latitude` (number, required): Latitude of the place (e.g. 37.77 for San Francisco).
- `longitude` (number, required): Longitude of the place (e.g. -122.42 for San Francisco).

### `opensky__flights_live` (~143 tokens)

[opensky · risk:low] List aircraft currently airborne within a latitude/longitude box, from OpenSky's live ADS-B feed.

Input parameters:

- `lamax` (number, required): North edge of the box — maximum latitude (e.g. 40.9 for NYC).
- `lamin` (number, required): South edge of the box — minimum latitude (e.g. 40.6 for NYC).
- `lomax` (number, required): East edge of the box — maximum longitude (e.g. -73.7 for NYC).
- `lomin` (number, required): West edge of the box — minimum longitude (e.g. -74.1 for NYC).

### `postgres__sql_read` (~55 tokens)

[postgres · risk:low] Execute a read-only SQL query against a Postgres database

Input parameters:

- `database` (string, required): Target database name
- `query` (string, required): Read-only SQL query (SELECT) to execute

### `shazam__audio_identify` (~46 tokens)

[shazam · risk:low] Identify the song currently playing using Shazam

Input parameters:

- `duration_ms` (number): How long to listen before identifying, in milliseconds

### `slack__message_search` (~35 tokens)

[slack · risk:low] Search recent messages across Slack channels

Input parameters:

- `query` (string, required): Search query string

### `southwest__flight_status` (~57 tokens)

[southwest · risk:low] Check the status of a Southwest flight

Input parameters:

- `date` (string): Flight date (YYYY-MM-DD)
- `flight_number` (string, required): Flight number, e.g. WN1234

### `telegram__message_read` (~40 tokens)

[telegram · risk:low] Read recent messages from a Telegram chat

Input parameters:

- `chat` (string, required): Chat id or @username to read from

### `twitter__tweets_search` (~114 tokens)

[twitter · risk:low] Search for recent tweets matching a keyword, hashtag, or phrase using the Twitter v2 API. Pass your Twitter Bearer Token via X-Duvera-Service-Token header — Duvera never stores it. Get a free Bearer Token at developer.twitter.com.

Input parameters:

- `max_results` (number): Number of tweets to return (10-100, default 10).
- `query` (string, required): Twitter search query. Supports operators like "from:user", "#hashtag", "-word".

### `uber__fare_estimate` (~75 tokens)

[uber · risk:low] Estimate the fare for a trip in the Uber app

Input parameters:

- `destination` (string, required): Drop-off address or place name
- `pickup` (string): Pickup address (defaults to current location)
- `product` (string): Ride product, e.g. UberX, Comfort, Black

### `united__flight_status` (~55 tokens)

[united · risk:low] Check the status of a United flight

Input parameters:

- `date` (string): Flight date (YYYY-MM-DD)
- `flight_number` (string, required): Flight number, e.g. UA123

### `venmo__payment_request` (~81 tokens)

[venmo · risk:low] Request a payment from a contact via Venmo (no money leaves your account)

Input parameters:

- `amount_cents` (number, required): Amount being requested, in cents
- `note` (string): Optional note explaining the request
- `recipient` (string, required): The Venmo handle, phone, or contact to request from

### `wallet__boardingpass_show` (~58 tokens)

[wallet · risk:low] Pull up a boarding pass stored in Apple Wallet

Input parameters:

- `flight_number` (string): Flight number associated with the pass
- `pass_name` (string): Name or description of the pass to display

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/ai-duvera-gateway/app#diagnostics

## Score history

- 2026-08-03: 63
- 2026-08-02: 63
- 2026-08-01: 62
- 2026-07-31: 62
- 2026-07-30: 62
- 2026-07-29: 62
- 2026-07-28: 61
- 2026-07-27: 61
- 2026-07-26: 60

## Links

- Remote endpoint: https://app.duvera.ai/mcp
- Website: https://duvera.ai/
- Changelog RSS feed: https://verifymcp.io/servers/ai-duvera-gateway/app/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/ai-duvera-gateway/app/changelog.json
- HTML version of this page: https://verifymcp.io/servers/ai-duvera-gateway/app
