ai.kontato/kontato
REMOTE · API.KONTATO.AI · SCANNED AUG 3
Give your AI agents a real WhatsApp number to send and receive messages.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (cancel_schedule). See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability57
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 1450 tokens (~161/item across 9 items; 9 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
- Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · api.kontato.ai
claude mcp add --transport http ai-kontato-kontato https://api.kontato.ai/mcp
[mcp_servers.ai-kontato-kontato] url = "https://api.kontato.ai/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"ai-kontato-kontato": {
"type": "remote",
"url": "https://api.kontato.ai/mcp",
"enabled": true
}
}
} openclaw mcp add ai-kontato-kontato --url https://api.kontato.ai/mcp --transport streamable-http
mcp_servers:
ai-kontato-kontato:
url: "https://api.kontato.ai/mcp" {
"mcpServers": {
"ai-kontato-kontato": {
"type": "http",
"url": "https://api.kontato.ai/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 2 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.
- 31 Jul 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 29 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.
- 28 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 59
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://api.kontato.ai/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=api.kontato.ai | CN=YE1,O=Let's Encrypt,C=US | 14 Jun 2026 | 12 Sept 2026 | ECDSA 256 | ECDSA-SHA384 | 564a538025e71c008f1537e96992001f675 |
| SANs: api.kontato.ai | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
DNSSEC insecure
Validation of api.kontato.ai. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| ai. | present | 3799 | 8 | Verified |
| kontato.ai. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://api.kontato.ai/mcp | Verified | 200 | |
| http (plaintext) | http://api.kontato.ai/mcp | HTTPS enforced | 308 | https://api.kontato.ai/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
cancel_schedule Cancel a schedule ~84
Cancela uma entrega agendada pelo seu schedule_id (obtido em `list_schedules` ou `schedule`).
| Name | Type | Req | Description |
|---|---|---|---|
| owner_phone | string | — | Numero do dono (so digitos, como texto ou numero). Passe para reativar a conta se a sessao MCP for nova (clientes stateless). |
| schedule_id | string | yes | ID do schedule a cancelar. |
No output schema declared.
No examples provided.
list_messages List message history ~113
Lista o historico de mensagens do numero-ponte (recebidas e enviadas), mais recentes primeiro. Use para decidir a quem responder com `reply`.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | — | Maximo de mensagens (1 a 100). |
| owner_phone | string | — | Numero do dono (so digitos, como texto ou numero). Passe para reativar a conta se a sessao MCP for nova (clientes stateless). |
| since | string | — | Timestamp ISO 8601; retorna apenas mensagens posteriores. |
No output schema declared.
No examples provided.
list_schedules List schedules ~71
Lista as entregas agendadas (recorrentes/unicas) desta conta, com proximo disparo.
| Name | Type | Req | Description |
|---|---|---|---|
| owner_phone | string | — | Numero do dono (so digitos, como texto ou numero). Passe para reativar a conta se a sessao MCP for nova (clientes stateless). |
No output schema declared.
No examples provided.
provision Activate Kontato account (create or reuse) ~246
ATIVA a conta Kontato do telefone informado — cria apenas se ainda nao existir; se ja existe, reutiliza a MESMA conta (e normal e esperado chamar com conta existente: funciona como login). IDEMPOTENTE POR TELEFONE: se ja existe conta para o owner_phone, devolve a MESMA conta — entao e seguro chamar de novo em qualquer sessao ou depois de um restart (o usuario nunca precisa lidar com api_key). Se a resposta vier com verification_required=false (numero ja verificado antes), NAO peca OTP: chame `send` direto. Informe owner_phone (formato internacional so digitos, ex: 5511999998888) para habilitar o caso seguro de self-notification: o agente entrega no WhatsApp do proprio dono. Retorna o whatsapp_bridge_number (numero generico do Kontato que envia, nunca o numero pessoal do dono).
| Name | Type | Req | Description |
|---|---|---|---|
| string | — | E-mail do dono (opcional). | |
| owner_phone | string | — | Numero WhatsApp do dono, so digitos, como texto ou numero (ex: 5511999998888). Vira o destino default das self-notifications. |
No output schema declared.
No examples provided.
reply Reply to a WhatsApp contact ~136
Responde a um numero especifico que mandou mensagem para o numero-ponte. Igual a `send`, mas "to" e OBRIGATORIO. Responder a quem te escreveu (reply-ratio alto) e mais seguro que cold outbound.
| Name | Type | Req | Description |
|---|---|---|---|
| message | string | yes | Texto da resposta. |
| owner_phone | string | — | Numero do dono (so digitos, como texto ou numero). Passe para reativar a conta se a sessao MCP for nova (clientes stateless). |
| to | string | yes | Destino so com digitos, como texto ou numero (ex: 5511999998888). |
No output schema declared.
No examples provided.
schedule Schedule a recurring delivery ~253
Registra uma entrega recorrente ou unica no scheduler do Kontato. No horario, o Kontato roda o `prompt` como um agente completo (com web/Exa) e entrega no WhatsApp do dono. USE ISTO para "todo dia me manda X": voce nao precisa ficar online nem prometer trabalho futuro — o scheduler dispara sozinho. O `prompt` deve ser autossuficiente (ex: "Busque as principais noticias do mercado financeiro de hoje e entregue um resumo curto").
| Name | Type | Req | Description |
|---|---|---|---|
| owner_phone | string | — | Numero do dono (so digitos, como texto ou numero). Passe para reativar a conta se a sessao MCP for nova (clientes stateless). |
| prompt | string | yes | O que entregar quando disparar. Autossuficiente. |
| schedule_type | string | yes | cron=recorrente em horarios; interval=a cada N ms; once=uma vez. |
| schedule_value | string | yes | cron: "0 8 * * *" (todo dia 8h, fuso BRT) | interval: ms como "3600000" | once: horario local "2026-06-20T15:30:00" (sem Z). |
No output schema declared.
No examples provided.
send Send WhatsApp message ~290
Envia uma mensagem de WhatsApp pelo numero-ponte do Kontato. CASO SEGURO: se OMITIR "to", entrega no WhatsApp do PROPRIO DONO (self-notification). REGRA TURN-BASED: voce nao executa trabalho no futuro; se pedirem algo recorrente ("todo dia me manda X"), faca a entrega de HOJE agora e oriente a registrar um schedule, nunca prometa entrega futura.
| Name | Type | Req | Description |
|---|---|---|---|
| message | string | — | Texto da mensagem (obrigatorio quando NAO usar template). |
| owner_phone | string | — | Numero do DONO da conta (so digitos, como texto ou numero). Passe SEMPRE que souber: reativa a conta automaticamente quando a sessao MCP e nova (clientes stateless como o conector do claude.ai). |
| template_name | string | — | Nome de template APROVADO da Meta (ex: kontato_ativacao). Use APENAS para partida fria pontual ou janela de 24h fechada — o padrao do produto e o destinatario iniciar a conversa. Template atravessa a… |
| template_variables | array | — | Variaveis posicionais do template ({{1}}, {{2}}...), em ordem. |
| to | string | — | Destino so com digitos, como texto ou numero. OMITA para enviar ao proprio dono (recomendado). |
No output schema declared.
No examples provided.
status Account status & schedules ~102
Mostra o estado da conta Kontato: ativa ou nao, numero-ponte, e os schedules (rotinas) ja registrados. Use para honrar a regra turn-based: antes de dizer que algo sera entregue "todo dia", confirme aqui se existe um schedule ativo.
| Name | Type | Req | Description |
|---|---|---|---|
| owner_phone | string | — | Numero do dono (so digitos, como texto ou numero). Passe para reativar a conta se a sessao MCP for nova (clientes stateless). |
No output schema declared.
No examples provided.
verify_number Verify owner number (OTP) ~155
Confirma o numero do dono com o codigo OTP de 6 digitos que chegou no WhatsApp dele apos o `provision`. OBRIGATORIO antes de enviar/agendar: ate verificar, `send`/`reply`/`schedule` retornam 403 owner_not_verified. Se o codigo expirou ou errou demais, chame de novo apos pedir um novo (resend) ao operador.
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | yes | Codigo de 6 digitos recebido no WhatsApp do dono (texto ou numero). |
| owner_phone | string | — | Numero do dono (so digitos, como texto ou numero). Passe para reativar a conta se a sessao MCP for nova (clientes stateless). |
No output schema declared.
No examples provided.