ca.myoutfitters/mcp
REMOTE · MYOUTFITTERS.CA · SCANNED SEP 20
Search Canadian hunting and fishing outfitters, check availability, and send price requests.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 7 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability58
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 2119 tokens (~264/item across 8 items; 8 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management90
- Stability observed for 27 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage84
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 53% of tool parameters carry a description.Partial
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 9 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the ca.myoutfitters/mcp server?
ca.myoutfitters/mcp is a hosted endpoint at https://myoutfitters.ca/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · myoutfitters.ca
claude mcp add --transport http ca-myoutfitters-mcp 'https://myoutfitters.ca/mcp'
{
"mcpServers": {
"ca-myoutfitters-mcp": {
"url": "https://myoutfitters.ca/mcp"
}
}
} {
"servers": {
"ca-myoutfitters-mcp": {
"type": "http",
"url": "https://myoutfitters.ca/mcp"
}
}
} [mcp_servers.ca-myoutfitters-mcp] url = "https://myoutfitters.ca/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"ca-myoutfitters-mcp": {
"type": "remote",
"url": "https://myoutfitters.ca/mcp",
"enabled": true
}
}
} openclaw mcp add ca-myoutfitters-mcp --url 'https://myoutfitters.ca/mcp' --transport streamable-http
mcp_servers:
ca-myoutfitters-mcp:
url: "https://myoutfitters.ca/mcp" {
"McpServers": {
"ca-myoutfitters-mcp": {
"Transport": "http",
"Url": "https://myoutfitters.ca/mcp"
}
}
} assistant mcp add ca-myoutfitters-mcp -t streamable-http -u 'https://myoutfitters.ca/mcp'
{
"mcpServers": {
"ca-myoutfitters-mcp": {
"type": "http",
"url": "https://myoutfitters.ca/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 19 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 77 to 80. That category is still filling its 30-day observation window: 23 days of observed history at the previous scan, 24 at this one. The score rises as the window fills, whether or not the server changes.
- 15 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 70 to 73. That category is still filling its 30-day observation window: 21 days of observed history at the previous scan, 22 at this one. The score rises as the window fills, whether or not the server changes.
- 13 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 63 to 67. That category is still filling its 30-day observation window: 19 days of observed history at the previous scan, 20 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.
- 9 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 50 to 53. That category is still filling its 30-day observation window: 15 days of observed history at the previous scan, 16 at this one. The score rises as the window fills, whether or not the server changes.
- 7 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 43 to 47. That category is still filling its 30-day observation window: 13 days of observed history at the previous scan, 14 at this one. The score rises as the window fills, whether or not the server changes.
- 4 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 33 to 37. That category is still filling its 30-day observation window: 10 days of observed history at the previous scan, 11 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://myoutfitters.ca/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=myoutfitters.ca | CN=WE1,O=Google Trust Services,C=US | 24 Aug 2026 | 22 Nov 2026 | ECDSA 256 | ECDSA-SHA256 | dc5c07873e818cba0e37bc289b8c8a9e |
| SANs: myoutfitters.ca | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of myoutfitters.ca. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| ca. | present | 26384 | 13 | Verified |
| myoutfitters.ca. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains |
| x-content-type-options | nosniff |
| referrer-policy | strict-origin-when-cross-origin |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://myoutfitters.ca/mcp | Verified | 200 | |
| http (plaintext) | http://myoutfitters.ca/mcp | HTTPS enforced | 301 | https://myoutfitters.ca/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
check_availability Check availability ~100
For up to 10 named outfitters, tell whether the requested dates fall in season and which packages fit the party. Returns a verdict per outfitter, never raw inventory.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | – | – |
| arrival | string | yes | – |
| departure | string | yes | – |
| locale | string | – | – |
| outfitter_ids | array | yes | Outfitter ids obtained from search_outfitters. |
| party_size | integer | – | – |
No output schema declared.
No examples provided.
create_price_request Request a price or dates ~143
Send a traveller's enquiry to one outfitter through MyOutfitters' anonymised relay. Requires the traveller's own name and e-mail, given with their consent. The outfitter replies by e-mail; neither side sees the other's raw contact details.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | – | – |
| arrival | string | – | – |
| departure | string | – | – |
| string | yes | – | |
| full_name | string | yes | – |
| locale | string | – | – |
| message | string | yes | – |
| outfitter_id | string | yes | – |
| package_id | string | – | – |
| party_size | integer | – | – |
| phone | string | – | – |
No output schema declared.
No examples provided.
fetch Fetch a MyOutfitters document ~114
Retrieve one MyOutfitters outfitter document by the id returned by `search` (e.g. 'PV-0009') or by its MyOutfitters URL. Returns id, title, url, readable text and metadata. No phone, e-mail or website is ever returned.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | – | – |
| id | string | yes | Document id from `search` (e.g. 'PV-0009') or the outfitter's MyOutfitters URL. |
| locale | string | – | – |
No output schema declared.
No examples provided.
get_booking_options Get booking options ~180
For one outfitter, return how a stay can be booked: booking mode (online payment on MyOutfitters, or a price request through MyOutfitters' anonymised relay), the packages that fit the party and the requested dates, indicative per-person rates when the listing is confirmed, the season window and the exact next step. Optionally pass dates and party size to filter the packages and get a season/availability verdict.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | – | – |
| arrival | string | – | Requested arrival date (YYYY-MM-DD). |
| departure | string | – | Requested departure date (YYYY-MM-DD). |
| locale | string | – | – |
| outfitter_id | string | yes | Outfitter id (e.g. 'PV-0009') or the id-bearing MyOutfitters URL segment. |
| party_size | integer | – | – |
No output schema declared.
No examples provided.
get_outfitter Get outfitter profile ~99
Public profile of one outfitter: territory, species, season, and up to 8 summarised packages. Rates appear only when the outfitter has confirmed its listing. No phone, e-mail or website is ever returned.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | – | – |
| locale | string | – | – |
| outfitter_id | string | yes | Outfitter id (e.g. 'PV-0009') or the id-bearing URL segment. |
No output schema declared.
No examples provided.
list_reference_data List search vocabulary ~102
List the values MyOutfitters understands for each search filter: provinces, regions, species, activity types, meal plan types, lodging types, access types, amenities, ZECs, major cities used as driving origins, and seasons. Contains no outfitter data.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | – | – |
| kind | string | yes | – |
| locale | string | – | – |
| province | string | – | Filter regions, ZECs or cities by province. |
No output schema declared.
No examples provided.
search Search MyOutfitters ~142
Free-text search over MyOutfitters' Canadian hunting and fishing outfitters (pourvoiries). Returns up to 10 documents with id, title and URL; pass an id to `fetch` for the full profile. For precise multi-criteria filtering (species, region, budget, lodging, dates) prefer search_outfitters. No phone, e-mail or website is ever returned.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | – | – |
| limit | integer | – | – |
| locale | string | – | – |
| query | string | yes | Natural-language query, e.g. 'walleye fishing in Mauricie' or 'pourvoirie chasse orignal Abitibi'. |
No output schema declared.
No examples provided.
search_outfitters Search outfitters ~857
Find up to 10 Canadian hunting and fishing outfitters (pourvoiries) matching a traveller's criteria, using the same advanced filters as the website: activities, several species at once, province, region, ZEC, access type, driving distance from a major city, Collection Prestige, per-person nightly budget, lodging type, single-lodging capacity, bedrooms, two-person and one-person bed counts, meal plan, season and equipment/amenities. Lodging criteria (capacity, bedrooms, beds, amenities) must all be met by the SAME cabin. At least one criterion is required — the full directory is never returned. Results carry no phone number, e-mail or website: enquiries go through create_price_request. Call list_reference_data to learn the valid values for any filter.
| Name | Type | Req | Description |
|---|---|---|---|
| access | array | – | Access types by code or name (road, boat, floatplane…). |
| activities | array | – | Exact activity-type codes an outfitter must offer: chasse (hunting), peche (fishing), big_game_hunting, ice_fishing (pêche sur glace), bird_hunting (chasse aux oiseaux), nature_lodging, family_experi… |
| activity | string | – | Shorthand for the two main activities. |
| amenities | array | – | Amenity names an outfitter must offer in one of its lodgings (all of them must match). |
| api_key | string | – | Optional MyOutfitters partner key. |
| budget_max_per_person_night | number | – | Cap on the per-person, per-night rate (package price divided by nights). |
| budget_min_per_person_night | number | – | – |
| hunt_or_fish_keyword | string | – | Deprecated alias of keyword. |
| keyword | string | – | Free text matched against the outfitter name, town, street address and the lakes, reservoirs and rivers it operates on; water-body and address matches rank first. |
| limit | integer | – | Max results (hard cap 10). |
| locale | string | – | – |
| lodging_types | array | – | Lodging types by code or name (chalet, camp, pavillon…). |
| max_drive_hours | number | – | Maximum driving hours from near_city (requires near_city). |
| max_price_per_person | number | – | Cap on the starting package price per person. |
| min_bedrooms | integer | – | Minimum bedrooms in a single lodging ('minimum 4 chambres' / '4 rooms'). |
| min_double_beds | integer | – | Minimum number of two-person beds in that SAME lodging (double, queen, king; a double bunk bed counts as 2). |
| min_lodging_capacity | integer | – | Minimum number of people a SINGLE cabin/lodging must sleep (e.g. 'a cabin for 10 people' → 10). Different from party_size, which is how many travellers are coming. |
| min_single_beds | integer | – | Minimum number of one-person beds in that SAME lodging (single beds; a bunk bed counts as 2). |
| near_city | string | – | Major city used as the driving origin, e.g. 'Montréal', 'Toronto'. |
| party_size | integer | – | Number of guests to accommodate. |
| plan_types | array | – | Meal plan types by code or name (américain / american, européen, MAP…). |
| prestige_only | boolean | – | Only Collection Prestige outfitters. |
| province | string | – | Province code or name, e.g. 'QC', 'Ontario'. |
| region | string | – | A single tourist region, e.g. 'Mauricie'. |
| regions | array | – | Several tourist regions; an outfitter matches any of them. |
| seasons | array | – | Seasons the outfitter must be open in. |
| species | – | – | One species or several, e.g. ['doré','brochet'] / ['walleye','pike']. |
| species_match | string | – | 'all' (default) requires every species; 'any' matches at least one. |
| zecs | array | – | ZEC names (Quebec controlled-exploitation zones). |
No output schema declared.
No examples provided.
What is the ca.myoutfitters/mcp server?
ca.myoutfitters/mcp is listed in the public MCP registry as ca.myoutfitters/mcp. Search Canadian hunting and fishing outfitters, check availability, and send price requests. This page covers its hosted endpoint (https://myoutfitters.ca/mcp).
Is the ca.myoutfitters/mcp server safe to use?
ca.myoutfitters/mcp scores 75 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the ca.myoutfitters/mcp server expose?
ca.myoutfitters/mcp exposes 8 tools: list_reference_data, search, fetch, search_outfitters, get_outfitter, and 3 more. Their descriptions and schemas cost roughly 1,737 tokens of context every time the server is loaded.
Does the ca.myoutfitters/mcp server require authentication?
No. We connected to ca.myoutfitters/mcp without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the ca.myoutfitters/mcp server still maintained?
ca.myoutfitters/mcp is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.