OpenMandate
REMOTE · MCP.OPENMANDATE.AI · SCANNED AUG 3
MCP server for OpenMandate — find cofounders and early teammates beyond your network. 15 tools.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security83
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, but the challenge carries no valid RFC 9728 metadata, so a client cannot discover where to get a token. See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability75
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1711 tokens (~114/item across 15 items; 15 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
- Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Capabilities40
- Spec-recency check failed: implements MCP spec 2025-03-26; the latest is 2026-07-28. See how to fix → Fail
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · mcp.openmandate.ai
claude mcp add --transport http ai-openmandate-mcp https://mcp.openmandate.ai/mcp
[mcp_servers.ai-openmandate-mcp] url = "https://mcp.openmandate.ai/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"ai-openmandate-mcp": {
"type": "remote",
"url": "https://mcp.openmandate.ai/mcp",
"enabled": true
}
}
} openclaw mcp add ai-openmandate-mcp --url https://mcp.openmandate.ai/mcp --transport streamable-http
mcp_servers:
ai-openmandate-mcp:
url: "https://mcp.openmandate.ai/mcp" {
"mcpServers": {
"ai-openmandate-mcp": {
"type": "http",
"url": "https://mcp.openmandate.ai/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 2 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.
- 31 Jul 26 +3
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.
- 29 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.
- 27 Jul 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 67
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://mcp.openmandate.ai/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=mcp.openmandate.ai | CN=Amazon RSA 2048 M04,O=Amazon,C=US | 3 Mar 2026 | 16 Sept 2026 | RSA 2048 | SHA256-RSA | a8f875ef2cdf92f65f25801995141ce |
| SANs: mcp.openmandate.ai | ||||||
| CN=Amazon RSA 2048 M04,O=Amazon,C=US (CA) | CN=Amazon Root CA 1,O=Amazon,C=US | 23 Aug 2022 | 23 Aug 2030 | RSA 2048 | SHA256-RSA | 773124f2a952e3ed18a58bdb85d1bc0ce5f27 |
| CN=Amazon Root CA 1,O=Amazon,C=US (CA) | CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies\, Inc.,L=Scottsdale,ST=Arizona,C=US | 25 May 2015 | 31 Dec 2037 | RSA 2048 | SHA256-RSA | 67f944a2a27cdf3fac2ae2b01f908eeb9c4c6 |
DNSSEC insecure
Validation of mcp.openmandate.ai. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| ai. | present | 3799 | 8 | Verified |
| openmandate.ai. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Challenged, unverified
The endpoint asked for a token, but we could not retrieve and validate the RFC 9728 metadata that tells a client how to obtain one.
| Result | Challenged, unverified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
Protected resource metadata
| Retrieved | No |
|---|---|
| Problem | no_resource_metadata |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.openmandate.ai/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.openmandate.ai/mcp | HTTPS enforced |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
openmandate_add_contact ~117
Add a new contact for the user. A verification code (OTP) will be sent to the contact address. The user must verify the contact using openmandate_verify_contact before it can be used on mandates. The first contact added becomes the primary contact automatically.
| Name | Type | Req | Description |
|---|---|---|---|
| contact_type | string | yes | Contact type. |
| contact_value | string | yes | The contact address to add (e.g. email address). |
| display_label | string | — | Optional human-readable label (e.g. 'Work email'). Defaults to the contact type. |
No output schema declared.
No examples provided.
openmandate_close_mandate ~57
Close (withdraw) a mandate. This is permanent — the mandate will stop matching and cannot be reopened. Only close if the user explicitly wants to withdraw.
| Name | Type | Req | Description |
|---|---|---|---|
| mandate_id | string | yes | The mandate ID to close. |
No output schema declared.
No examples provided.
openmandate_create_mandate ~175
Create a new mandate on OpenMandate. Provide what the user is looking for (want) and what they bring to the table (offer). The user's verified contacts are automatically attached. Returns the mandate with follow-up questions. You MUST relay these questions to the user and collect their actual answers before calling openmandate_submit_answers. Do not answer questions on the user's behalf. If the user has no verified contacts, they must add one first at https://openmandate.ai/settings or use openmandate_list_contacts to check.
| Name | Type | Req | Description |
|---|---|---|---|
| offer | string | yes | What the user brings to the table (skills, experience, resources, etc.). Minimum 20 characters. |
| want | string | yes | What the user is looking for (cofounder, service provider, investor, etc.). Minimum 20 characters. |
No output schema declared.
No examples provided.
openmandate_delete_contact ~47
Delete a contact. If the deleted contact was primary, the next verified contact is automatically promoted. This is permanent.
| Name | Type | Req | Description |
|---|---|---|---|
| contact_id | string | yes | The contact ID to delete. |
No output schema declared.
No examples provided.
openmandate_get_mandate ~62
Get a mandate by ID. Returns the mandate's current status, any pending intake questions, and summary once active. Use this to check progress or retrieve questions after creating a mandate.
| Name | Type | Req | Description |
|---|---|---|---|
| mandate_id | string | yes | The mandate ID to retrieve. |
No output schema declared.
No examples provided.
openmandate_get_match ~54
Get detailed information about a specific match, including compatibility grade, strengths, concerns, and — if both parties accepted — the counterparty's contact information.
| Name | Type | Req | Description |
|---|---|---|---|
| match_id | string | yes | The match ID to retrieve. |
No output schema declared.
No examples provided.
openmandate_list_contacts ~45
List the user's verified contacts. These are the contacts revealed to the other party on match confirmation. Each contact has an ID, type, display label, and verification status.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
openmandate_list_mandates ~84
List the user's open mandates. Returns non-closed mandates by default. Pass status to filter (e.g. status='closed' for history).
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | — | Maximum number of mandates to return (default 20, max 100). |
| status | string | — | Filter by status: intake, active, matched, pending_input, closed. |
No output schema declared.
No examples provided.
openmandate_list_matches ~59
List matches for the authenticated user. Returns matches with compatibility grade, strengths, and concerns. Check this periodically after a mandate becomes active.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | — | Maximum number of matches to return (default 20, max 100). |
No output schema declared.
No examples provided.
openmandate_resend_otp ~68
Resend the verification code for a pending contact. Use this if the user didn't receive the code or it expired (codes expire after 10 minutes). Rate limited to 3 per contact per hour.
| Name | Type | Req | Description |
|---|---|---|---|
| contact_id | string | yes | The contact ID to resend verification for. |
No output schema declared.
No examples provided.
openmandate_respond_to_match ~114
Accept or decline a match. If you accept and the other party also accepts, contact info is revealed to both sides. Declining is permanent for this match.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | Either 'accept' or 'decline'. |
| decline_reason | string | — | Why the user is declining. Only used when action is 'decline'. |
| decline_reason_text | string | — | Free-text detail when decline_reason is 'other'. |
| match_id | string | yes | The match ID to respond to. |
No output schema declared.
No examples provided.
openmandate_submit_answers ~109
Submit the user's answers to pending intake questions. The mandate must be in 'intake' status with pending questions. IMPORTANT: Before calling this, you must show each pending question to the user and collect their real answer. Never fabricate or infer answers. OpenMandate may return additional questions. Relay each round to the user until the mandate becomes active.
| Name | Type | Req | Description |
|---|---|---|---|
| answers | array | yes | Array of answers to pending questions. |
| mandate_id | string | yes | The mandate ID to submit answers for. |
No output schema declared.
No examples provided.
openmandate_submit_outcome ~124
Report how a confirmed match went. Available after both parties accepted and contact info was revealed. Outcomes: - 'succeeded': Found the right person. Mandate closes. - 'failed': Didn't work out. Mandate reactivates for new matches. - 'ongoing': Still in conversation. OpenMandate checks back later. IMPORTANT: Always confirm the outcome with the user before submitting. This affects their mandate and matching status.
| Name | Type | Req | Description |
|---|---|---|---|
| match_id | string | yes | The match ID to report outcome for. |
| outcome | string | yes | Match outcome. |
No output schema declared.
No examples provided.
openmandate_update_contact ~81
Update a contact's display label or set it as the primary contact. Setting a contact as primary will unset any other primary contact.
| Name | Type | Req | Description |
|---|---|---|---|
| contact_id | string | yes | The contact ID to update. |
| display_label | string | — | New display label for the contact. |
| is_primary | boolean | — | Set to true to make this the primary contact. |
No output schema declared.
No examples provided.
openmandate_verify_contact ~76
Verify a contact by submitting the OTP code sent to it. The user must check their email for the 8-digit code. After verification, the contact can be used on mandates.
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | yes | The 8-digit verification code from the email. |
| contact_id | string | yes | The contact ID to verify. |
No output schema declared.
No examples provided.