FrankKi
REMOTE · MCP.FRANKKI.APP · SCANNED SEP 29
The agentic layer of letters. Agents send real printed mail worldwide, German compliance built in.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security89
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents. View diagnostics → Partial
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability49
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 1894 tokens (~473/item across 4 items; 4 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage77
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 32% of tool parameters carry a description.Partial
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 4 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 5 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the FrankKi MCP server?
FrankKi is a hosted endpoint at https://mcp.frankki.app/, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.frankki.app
claude mcp add --transport http app-frankki-letters 'https://mcp.frankki.app/'
{
"mcpServers": {
"app-frankki-letters": {
"url": "https://mcp.frankki.app/"
}
}
} {
"servers": {
"app-frankki-letters": {
"type": "http",
"url": "https://mcp.frankki.app/"
}
}
} [mcp_servers.app-frankki-letters] url = "https://mcp.frankki.app/"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"app-frankki-letters": {
"type": "remote",
"url": "https://mcp.frankki.app/",
"enabled": true
}
}
} openclaw mcp add app-frankki-letters --url 'https://mcp.frankki.app/' --transport streamable-http
mcp_servers:
app-frankki-letters:
url: "https://mcp.frankki.app/" {
"McpServers": {
"app-frankki-letters": {
"Transport": "http",
"Url": "https://mcp.frankki.app/"
}
}
} assistant mcp add app-frankki-letters -t streamable-http -u 'https://mcp.frankki.app/'
{
"mcpServers": {
"app-frankki-letters": {
"type": "http",
"url": "https://mcp.frankki.app/"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 29 Sept 26 0
- This server's schema is too large to store in full, so we cannot compare its tools day to day functional
- 28 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Sept 26 0
- This server's schema is too large to store in full, so we cannot compare its tools day to day functional
- 26 Sept 26 0
- This server's schema is too large to store in full, so we cannot compare its tools day to day functional
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 24 Sept 26 0
- This server's schema is too large to store in full, so we cannot compare its tools day to day functional
- 23 Sept 26 0
- This server's schema is too large to store in full, so we cannot compare its tools day to day functional
- 22 Sept 26 0
- This server's schema is too large to store in full, so we cannot compare its tools day to day functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 29 Sept 2026 · Probed https://mcp.frankki.app
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=mcp.frankki.app | CN=YE1,O=Let's Encrypt,C=US | 5 Sept 2026 | 4 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 6b8d2b87fb760a0904e3d5d79732245768b |
| SANs: mcp.frankki.app | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.frankki.app. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| app. | present | 23684 | 8 | Verified |
| frankki.app. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer resource_metadata="https://mcp.frankki.app/.well-known/oauth-protected-resource/api/mcp/v1"
Bearer resource_metadata="https://mcp.frankki.app/.well-known/oauth-protected-resource/api/mcp/v1" | Header | Value |
|---|---|
| x-content-type-options | nosniff |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(), geolocation=(), payment=() |
| www-authenticate | Bearer resource_metadata="https://mcp.frankki.app/.well-known/oauth-protected-resource/api/mcp/v1" |
Protected resource metadata
| Document | https://mcp.frankki.app/.well-known/oauth-protected-resource/api/mcp/v1 |
|---|---|
| Retrieved | Yes |
| Resource | https://mcp.frankki.app/api/mcp/v1 |
| Authorisation server | https://mcp.frankki.app |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.frankki.app | Verified | 200 | |
| http (plaintext) | http://mcp.frankki.app | HTTPS enforced | 308 | https://mcp.frankki.app/ |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
address_validate Adresse prüfen ~212
Prüft eine Adresse anhand landesspezifischer Regeln und meldet harte Fehler als ADDRESS_INVALID. Nur eine Prüfung, das Adressbuch bleibt unverändert; zum Anlegen oder Ändern einer Adresse nimm address_upsert. EN: Validates an address using country-specific rules and reports hard failures as ADDRESS_INVALID. A check only, the address book is left untouched; to create or change an address use address_upsert.
| Name | Type | Req | Description |
|---|---|---|---|
| addressType | string | – | – |
| city | string | yes | – |
| company | string | – | – |
| country | string | – | ISO-3166-alpha-2, default DE. EN: ISO 3166-1 alpha-2, defaults to DE. |
| houseNumber | string | – | – |
| isDefault | boolean | – | – |
| mandantennummer | string | – | – |
| name | string | yes | – |
| pobox | string | – | – |
| reasoning | string | – | – |
| street | string | yes | – |
| zip | string | – | – |
No output schema declared.
No examples provided.
mcp_health Verbindung prüfen ~243
Health-/Echo-Probe - prüft das Partner-Token und die Verarbeitungskette von Anfang bis Ende und sagt dir unter setup, welche Voraussetzungen für einen echten Versand schon erfüllt sind (Absender-Profil, AVV, Guthaben, Sandbox, Freigabe) und was der nächste Schritt ist. Mit checkRender: true wird zusätzlich geprüft, ob gerade überhaupt gerendert werden kann (Vorschau, Thumbnail). Rufe das auf, bevor du eine Vorlage baust, die du danach ansehen musst. EN: Health/echo probe - verifies the partner token and the chain end to end, and reports under setup which prerequisites for a real send are already met (sender profile, data processing agreement, balance, sandbox, approval) and what the next step is. With checkRender: true it additionally checks whether rendering currently works at all (preview, thumbnail). Call it before building a template you will need to look at.
| Name | Type | Req | Description |
|---|---|---|---|
| checkRender | boolean | – | Prüft zusätzlich den Render-Pfad (Composer + Rasterizer). Default false. EN: Additionally probes the render path (composer + rasterizer). Defaults to false. |
| reasoning | string | – | – |
No output schema declared.
No examples provided.
pricing_tiers Staffelpreise abrufen ~188
Liefert die Staffelpreise (Mengenrabatte) von FrankKi: ab welcher Monatsmenge welcher Beispielpreis pro Brief gilt. Nutze das, wenn jemand nach Mengenrabatt, Volumenpreis, Staffelpreis oder Großkundenpreis fragt. Die Beispielpreise gelten für einen einseitigen Standardbrief in Schwarzweiß innerhalb Deutschlands, der echte Preis pro Brief hängt zusätzlich von Seitenzahl, Farbe, Versandart und Zielland ab (dafür shipping_quote). EN: Returns FrankKi's volume tiers (bulk discounts): from which monthly quantity which example price per letter applies. Use this when someone asks about bulk discounts, volume pricing or enterprise pricing. The example prices are for a one-page black and white standard letter within Germany; the real per-letter price also depends on page count, color, delivery type and destination country (use shipping_quote for that).
| Name | Type | Req | Description |
|---|---|---|---|
| reasoning | string | – | – |
No output schema declared.
No examples provided.
shipping_quote Versandpreis ermitteln ~952
Registered-mail availability depends on the destination and its current catalog, not a Germany-only rule. The codes einschreiben_einwurf and einschreiben_uebergabe are German products; Switzerland uses ch_einschreiben. For other destinations, use only methods returned in availableDeliveryTypes by a standard shipping_quote for that country, then quote the chosen code. A rejected country/method pair does not establish availability in other countries. A catalog snapshot with no registered method does not prove that the postal service never offers one. Tracked mail is not registered mail. Never substitute standard or tracked delivery when registered mail was requested without the user's agreement. A carrier-issued proof-of-posting PDF is not promised. Reply in the user's conversation language, regardless of recipient country, letter language, German tool titles or bilingual tool results. Translate shipping methods, letter formats, delivery estimates and explanations for the user. In English: Standardbrief = standard letter; Kompaktbrief = compact letter; Großbrief = large letter; Maxibrief = maxi letter; Einschreiben = registered mail; Einwurf-Einschreiben = registered mail with recorded mailbox delivery; Übergabe-Einschreiben = registered mail with signature on delivery; Einlieferungsbeleg = proof of posting. Use localized money and number formatting. Keep tool names, parameter names, deliveryType values and error codes unchanged in tool calls; show codes to users only when needed for troubleshooting. This presentation rule does not translate the letter's contents. Ermittelt den Preis, das Briefformat, die Versandart und die voraussichtliche Laufzeit für einen geplanten Brief, bevor er versendet wird. Das ist die Schätzung für den Fall, dass der Brief erst geplant ist: du gibst nur Seitenzahl, Land und Versandart an. Steht der Brief schon fest, versendest du ihn mit order_send (order_send mit dryRun:true liefert dann den genaueren Preis für genau diesen Brief). Der Pr…
| Name | Type | Req | Description |
|---|---|---|---|
| color | boolean | yes | Farbannahme fuer eine allgemeine Schaetzung. Mit letterId erkennt FrankKi die Farbe aus der gespeicherten Vorschau und ignoriert diesen Wert. EN: Colour assumption for a general estimate. With letter… |
| country | string | – | ISO 3166-1 alpha-2, Standard DE. EN: ISO 3166-1 alpha-2, defaults to DE. |
| deliveryType | string | yes | Registered-mail availability depends on the destination and its current catalog, not a Germany-only rule. The codes einschreiben_einwurf and einschreiben_uebergabe are German products; Switzerland us… |
| express | boolean | – | – |
| letterId | string | – | Optional: die letterId eines bestehenden Entwurfs. Dann kommen Seitenzahl und Farbe aus der gespeicherten Vorschau; fuer den endgueltigen Preis inklusive Anhaengen nutze order_send mit dryRun:true. E… |
| pageCount | integer | yes | Seitenzahl fuer eine allgemeine Schaetzung. Mit letterId verwendet FrankKi die gespeicherte Seitenzahl und ignoriert diesen Wert. EN: Page count for a general estimate. With letterId, FrankKi uses th… |
| reasoning | string | – | – |
No output schema declared.
No examples provided.
What is the FrankKi MCP server?
FrankKi is an MCP server listed in the public MCP registry as app.frankki/letters. The agentic layer of letters. Agents send real printed mail worldwide, German compliance built in. This page covers its hosted endpoint (https://mcp.frankki.app).
Is the FrankKi MCP server safe to use?
FrankKi scores 85 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the FrankKi MCP server expose?
FrankKi exposes 4 tools: mcp_health, address_validate, shipping_quote, pricing_tiers. Their descriptions and schemas cost roughly 1,595 tokens of context every time the server is loaded.
Does the FrankKi MCP server require authentication?
Yes. FrankKi asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the FrankKi MCP server still maintained?
FrankKi is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.