APICK Business
REMOTE · APICK.APP · SCANNED SEP 23
Korean business registry, corporate info, parcel tracking, validation APIs
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 13 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability77
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1930 tokens (~128/item across 15 items; 15 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management87
- Stability check failed: schema churn in the 30 days we've observed: 1 tool removals, 2 breaking changes, 0 auth/transport breaks, 0 additions. See how to fix → Fail
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 15 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 15 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the APICK Business MCP server?
APICK Business is a hosted endpoint at https://apick.app/mcp/business, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · apick.app
claude mcp add --transport http app-apick-business 'https://apick.app/mcp/business'
{
"mcpServers": {
"app-apick-business": {
"url": "https://apick.app/mcp/business"
}
}
} {
"servers": {
"app-apick-business": {
"type": "http",
"url": "https://apick.app/mcp/business"
}
}
} [mcp_servers.app-apick-business] url = "https://apick.app/mcp/business"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"app-apick-business": {
"type": "remote",
"url": "https://apick.app/mcp/business",
"enabled": true
}
}
} openclaw mcp add app-apick-business --url 'https://apick.app/mcp/business' --transport streamable-http
mcp_servers:
app-apick-business:
url: "https://apick.app/mcp/business" {
"McpServers": {
"app-apick-business": {
"Transport": "http",
"Url": "https://apick.app/mcp/business"
}
}
} assistant mcp add app-apick-business -t streamable-http -u 'https://apick.app/mcp/business'
{
"mcpServers": {
"app-apick-business": {
"type": "http",
"url": "https://apick.app/mcp/business"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Sept 26 0
- Tool “check_phone_valid” rewrote its description, which is the text the model reads security
- “check_phone_valid” dropped the optional parameter “search_hlr” cosmetic
- 19 Sept 26 −2
- Stability: pass → fail ▼ security
- A breaking change shipped without a version bump: still 0.0.1 ▼ security
- Tool “check_pccc” was removed ▼ security
- Tool “get_pccc” rewrote its description, which is the text the model reads security
- Tool “req_pccc” rewrote its description, which is the text the model reads security
- “get_pccc” added a required parameter “tx_id”, so existing callers break ▼ functional
- “req_pccc” added a required parameter “birthday”, so existing callers break ▼ functional
- “req_pccc” added a required parameter “provider”, so existing callers break ▼ functional
- “get_pccc” dropped the required parameter “answer” ▼ functional
- “get_pccc” dropped the required parameter “auth_key” ▼ functional
- “req_pccc” dropped the required parameter “rrn1” ▼ functional
- “req_pccc” dropped the required parameter “rrn2” ▼ functional
- 9 Sept 26 +1
- Stability: 0.97 → pass security
- 7 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 90 to 93. That category is still filling its 30-day observation window: 27 days of observed history at the previous scan, 28 at this one. The score rises as the window fills, whether or not the server changes.
- 5 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.
- 4 Sept 26 0
- Tool “check_phone_valid” rewrote its description, which is the text the model reads security
- “check_phone_valid” added an optional parameter “search_hlr” cosmetic
- 2 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 73 to 77. That category is still filling its 30-day observation window: 22 days of observed history at the previous scan, 23 at this one. The score rises as the window fills, whether or not the server changes.
- 31 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 67 to 70. That category is still filling its 30-day observation window: 20 days of observed history at the previous scan, 21 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 23 Sept 2026 · Probed https://apick.app/mcp/business
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=apick.app | CN=YE2,O=Let's Encrypt,C=US | 21 Sept 2026 | 20 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 6df569e0949f856521f576f0e936f1ae953 |
| SANs: apick.app | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of apick.app. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| app. | present | 23684 | 8 | Verified |
| apick.app. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://apick.app/mcp/business | Verified | 200 | |
| http (plaintext) | http://apick.app/mcp/business | HTTPS enforced | 308 | https://apick.app/mcp/business |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
biz_detail 사업자 정보 조회 ~118
Look up general status information of a Korean business by its 10-digit business registration number. 사업자등록번호로 해당 사업자의 일반 현황 정보(대표자, 주소, 직원수, 설립일, 업종, 업태, 종목, 연락처, 사업자상태, 과세유형 등)를 조회합니다. [호출당 50포인트]
| Name | Type | Req | Description |
|---|---|---|---|
| biz_no | string | yes | 사업자등록번호 (숫자 10자리, 하이픈 제외, 예: 4398700761) |
No output schema declared.
No examples provided.
check_email_valid 이메일 유효성 검사 ~70
Validate email syntax, MX availability, and free or disposable domain status. 이메일 형식, MX 수신 가능 여부, 무료·일회용 메일 여부를 검사합니다. [호출당 10포인트]
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | 이메일 주소 (예: sample.user@gmail.com) |
No output schema declared.
No examples provided.
check_phone_valid 전화번호 유효성 검사 ~84
Validate and format a phone number and check the carrier and line type. 전화번호 형식 검사와 통신사·회선유형 확인을 함께 제공합니다. 건당 40P. [호출당 40포인트]
| Name | Type | Req | Description |
|---|---|---|---|
| number | string | yes | 전화번호 (예: 01012341234, 해외는 +국가코드 형식) |
No output schema declared.
No examples provided.
check_spam_number 스팸/광고/범죄 전화번호 조회 ~88
Check whether a phone number has been reported for spam, advertising, or criminal use in Korea. 스팸/광고/범죄에 사용된 전화번호인지 조회합니다. 수신 전화 필터링, 이상 거래 탐지 등에 사용합니다. [호출당 10포인트]
| Name | Type | Req | Description |
|---|---|---|---|
| number | string | yes | 전화번호 (예: 01012341234) |
No output schema declared.
No examples provided.
get_car_flooding 차량 침수차 여부 조회 ~117
Check whether a Korean vehicle has a flood damage record, by VIN or license plate number. 차대번호(VIN) 또는 차량번호로 자동차의 침수 이력 여부를 조회합니다. 중고차 구매 전 확인 등에 사용합니다. [호출당 10포인트]
| Name | Type | Req | Description |
|---|---|---|---|
| type | string | yes | 조회 종류. 1: 차대번호(VIN), 2: 차량번호 |
| value | string | yes | 차대번호(type=1, 17자리) 또는 차량번호(type=2) |
No output schema declared.
No examples provided.
get_car_scrap 차량 폐차사고처리 여부 조회 ~119
Check whether a Korean vehicle has a scrap/total-loss accident record, by VIN or license plate number. 차대번호(VIN) 또는 차량번호로 폐차사고처리 여부를 조회합니다. 중고차 구매 전 확인 등에 사용합니다. [호출당 10포인트]
| Name | Type | Req | Description |
|---|---|---|---|
| type | string | yes | 조회 종류. 1: 차대번호(VIN), 2: 차량번호 |
| value | string | yes | 차대번호(type=1, 17자리) 또는 차량번호(type=2) |
No output schema declared.
No examples provided.
get_pccc 개인통관고유부호 조회 ~192
Retrieve a Korean Personal Customs Clearance Code (PCCC) by transaction ID. req_pccc 로 받은 tx_id 를 입력하면 처리 상태를 확인합니다. 아직 승인 전이면 status 는 pending, message 는 "인증 대기중입니다." 이며 과금되지 않습니다. 승인이 끝나면 서버가 최종 정보를 조회해 DB에 저장하고 개인통관고유부호·주소와 함께 수집 시각 checked_at 을 반환하며 이때 과금됩니다. 조회는 정상 처리됐지만 발급된 부호가 없으면 message 는 "조회된 개인통관고유부호가 없습니다." 이고 과금되지 않습니다. 결과는 24시간 동안 재조회할 수 있고 재조회할 때마다 과금됩니다. [호출당 30포인트]
| Name | Type | Req | Description |
|---|---|---|---|
| tx_id | string | yes | req_pccc 응답의 트랜잭션 ID |
No output schema declared.
No examples provided.
holiday_info 공휴일 조회 ~94
Look up Korean public holidays for a given year and month. 해당 년월의 대한민국 공휴일 정보를 조회합니다. 영업일 계산, 일정 관리 등에 사용합니다. [호출당 3포인트]
| Name | Type | Req | Description |
|---|---|---|---|
| month | string | yes | 조회 월 (1 ~ 12, 예: 02) |
| year | string | yes | 조회 년도 (1900 ~ 2200, 예: 2024) |
No output schema declared.
No examples provided.
info 계정 정보 조회 ~46
Check your APICK account balance and status. 현재 인증 키에 연결된 APICK 계정의 잔여 포인트와 계정 상태 정보를 조회합니다. 무료입니다. [무료]
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
land_rt_price 부동산 실거래가 조회 ~242
Look up real estate transaction price records in Korea by region, property type, and year. 시/도·시/군/구, 부동산 유형, 년도를 지정해 부동산 실거래 이력을 조회합니다. addr1 값이 잘못되면 응답의 options 필드로 선택 가능한 지역 목록을 안내합니다. [호출당 100포인트]
| Name | Type | Req | Description |
|---|---|---|---|
| addr1 | string | yes | 도/광역시/특별시 정식 명칭 (예: 서울특별시, 경기도, 부산광역시) |
| addr2 | string | yes | 시/군/구 (예: 금천구) |
| type | string | yes | 유형 코드 A~H 중 하나. A:아파트, B:연립/다세대, C:단독/다가구, D:오피스텔, E:분양/입주권, F:상업/업무용, G:토지, H:공장/창고등 |
| year | string | yes | 조회 년도 (1950 ~ 현재 년도, 예: 2025) |
No output schema declared.
No examples provided.
parcel_tracking 택배 배송조회 ~192
Track a Korean parcel in real time by carrier code and tracking number. 택배사 코드와 운송장번호를 지정해 실시간 배송현황을 조회합니다. 결과는 저장하지 않고 매 호출마다 즉시 조회합니다. carrier 코드 예: cj(CJ대한통운), hanjin(한진택배), lotte(롯데택배), logen(로젠택배), epost-domestic(우체국택배) 등 — 전체 목록은 /rest/parcel_tracking_carriers(무료)에서 확인할 수 있고, 택배사를 모르면 parcel_tracking_auto Tool로 자동판별 조회하세요. [호출당 5포인트]
| Name | Type | Req | Description |
|---|---|---|---|
| carrier | string | yes | 택배사 코드 (예: cj, hanjin, lotte, logen, epost-domestic) |
| trackingNumber | string | yes | 운송장번호 |
No output schema declared.
No examples provided.
parcel_tracking_auto 택배 배송조회(자동) ~106
Track a Korean parcel in real time with automatic carrier detection from the tracking number alone. 택배사 지정 없이 운송장번호만으로 택배사를 자동 판별해 실시간 배송현황을 조회합니다. 택배사를 이미 아는 경우에는 parcel_tracking Tool이 더 정확합니다. [호출당 10포인트]
| Name | Type | Req | Description |
|---|---|---|---|
| trackingNumber | string | yes | 운송장번호 (택배사 지정 없이 형식만으로 자동 판별) |
No output schema declared.
No examples provided.
req_pccc 개인통관고유부호 인증 요청 ~247
Request simple authentication (KakaoTalk, Toss, PASS, etc.) to retrieve a Korean Personal Customs Clearance Code (PCCC). 이름, 생년월일, 휴대전화번호와 간편인증 방식을 입력하면 해당 휴대폰으로 인증 요청이 발송되고, 응답을 기다리지 않고 tx_id 를 즉시 반환합니다. 인증 요청이 실제 발송된 접수 시점에 과금되며, 이미 대기 중인 요청을 다시 보내면 재발송 없이 기존 tx_id 를 반환하고 과금되지 않습니다. 사용자가 휴대폰에서 승인한 뒤 get_pccc 에 tx_id 를 넣어 결과를 확인하세요. [호출당 30포인트]
| Name | Type | Req | Description |
|---|---|---|---|
| birthday | string | yes | 생년월일 8자리 (YYYYMMDD) |
| name | string | yes | 이름 |
| phone | string | yes | 휴대전화 번호 (본인 명의, 숫자만) |
| provider | string | yes | 간편인증 방식 (kakao, naver, toss, pass, samsung, kb, shinhan, hana, woori, ibk, nh, kakaobank, banksalad) |
No output schema declared.
No examples provided.
search_juso 도로명주소 조회 ~119
Search Korean road-name addresses by keyword. 지번 또는 도로명 키워드로 도로명 주소를 검색합니다. 페이지당 10건씩 반환되며 total_count 필드로 전체 검색결과 개수를 확인할 수 있습니다. [호출당 2포인트]
| Name | Type | Req | Description |
|---|---|---|---|
| juso | string | yes | 검색할 주소 키워드 (지번, 도로명. 예: 디지털로) |
| page | string | – | 검색 결과 조회 페이지 (기본값 1, 페이지당 10건) |
No output schema declared.
No examples provided.
venture_biz_info 벤처기업 정보조회 ~96
Look up venture company information of a Korean business, including financial statements and investment data. 벤처기업을 대상으로 사업자 정보, 대차대조표, 손익계산서, 투자정보, 벤처기업확인정보를 조회합니다. [호출당 40포인트]
| Name | Type | Req | Description |
|---|---|---|---|
| biz_no | string | yes | 사업자등록번호 (숫자 10자리, 하이픈 제외) |
No output schema declared.
No examples provided.
What is the APICK Business MCP server?
APICK Business is an MCP server listed in the public MCP registry as app.apick/business. Korean business registry, corporate info, parcel tracking, validation APIs. This page covers its hosted endpoint (https://apick.app/mcp/business).
Is the APICK Business MCP server safe to use?
APICK Business scores 77 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the APICK Business MCP server expose?
APICK Business exposes 15 tools: biz_detail, venture_biz_info, land_rt_price, req_pccc, get_pccc, and 10 more. Their descriptions and schemas cost roughly 1,930 tokens of context every time the server is loaded.
Does the APICK Business MCP server require authentication?
No. We connected to APICK Business without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the APICK Business MCP server still maintained?
APICK Business is still listed as active in the MCP registry. We last reached this channel on 23 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.