Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

redm-mcp

REMOTE · REDM-MCP.FIVEM.NO · SCANNED OCT 4

RedM / RDR3 docs MCP server: native lookups, semantic search, VORP, RSGCore, oxmysql.

0 this week 36 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security91
Transport & Reachability0
Schema Quality & AI Usability0
  • Schema blocked by authentication: the endpoint requires auth we don't have to read it. See how to fix → Unverified
Stability & Change Management0
  • Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage0
  • Tool coverage blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Tool Safety0
  • Tool safety blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Capabilities0
  • Capabilities blocked by authentication: the endpoint requires auth we don't have to read them. See how to fix → Unverified

Unverified: 6 categories

Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm. Claim this server and supply a read-only token to verify it and lift the score.

Install

How do I install the redm-mcp server?

redm-mcp is a hosted endpoint at https://redm-mcp.fivem.no/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · redm-mcp.fivem.no

# add to Claude Code
claude mcp add --transport http cmoen11-redm-mcp 'https://redm-mcp.fivem.no/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "cmoen11-redm-mcp": {
      "url": "https://redm-mcp.fivem.no/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "cmoen11-redm-mcp": {
      "type": "http",
      "url": "https://redm-mcp.fivem.no/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.cmoen11-redm-mcp]
url = "https://redm-mcp.fivem.no/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "cmoen11-redm-mcp": {
      "type": "remote",
      "url": "https://redm-mcp.fivem.no/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add cmoen11-redm-mcp --url 'https://redm-mcp.fivem.no/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  cmoen11-redm-mcp:
    url: "https://redm-mcp.fivem.no/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "cmoen11-redm-mcp": {
      "Transport": "http",
      "Url": "https://redm-mcp.fivem.no/mcp"
    }
  }
}
# add to Vellum
assistant mcp add cmoen11-redm-mcp -t streamable-http -u 'https://redm-mcp.fivem.no/mcp'
// mcp.json
{
  "mcpServers": {
    "cmoen11-redm-mcp": {
      "type": "http",
      "url": "https://redm-mcp.fivem.no/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 28 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 25 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 15 Sept 26 −41
    • Endpoint reachability: reachable → behind authorisation ▼ security
    • Stability: pass → unverified ▼ security
    • Tool safety: pass → unverified ▼ security
    • Transport: pass → unverified ▼ security
    • Authorization: unverified → pass ▲ security
    • First check of Authorization: partial security
    • Capabilities: pass → unverified ▼ functional
    • Tool coverage: 100 → unverified ▼ functional
    • First check of Schema quality: unverified functional
  • 13 Sept 26 0
    • The server rewrote its instructions, which are the text every model session reads security
  • 26 Aug 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 25 Aug 26 0
    • Stability: 0.97 → pass security
  • 11 Aug 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 10 Aug 26 0
    • Tool “asset_lookup” now declares an output schema ▲ functional
    • Tool “list_namespaces” now declares an output schema ▲ functional
    • Tool “lookup_native” now declares an output schema ▲ functional
    • First check of Tool coverage: 30 functional
    • MCP protocol: Implements a current MCP spec version (2026-07-28). functional
    • MCP protocol version: 2025-11-25 → 2026-07-28 functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 6 Oct 2026 · Probed https://redm-mcp.fivem.no/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=redm-mcp.fivem.no CN=YE2,O=Let's Encrypt,C=US 23 Aug 2026 21 Nov 2026 ECDSA 256 ECDSA-SHA384 62e394e7e4f11ceba1ca047c9f92bec62b4
SANs: redm-mcp.fivem.no
CN=YE2,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 4df3b15dd6c0784c507cd37b58e6f115
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd

Background: What to check on a remote MCP endpoint →

DNSSEC secure

Validation of redm-mcp.fivem.no. — Secure

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
no. present 38032 13 Verified
fivem.no. present 3368, 3368 15, 15 Verified
redm-mcp.fivem.no. Verified address RRset verified with the apex keys
Authentication Enforced and verified

The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.

Result Enforced and verified
Enforced On connection
HTTP status 401

WWW-Authenticate challenge Bearer resource_metadata="https://redm-mcp.fivem.no/.well-known/oauth-protected-resource/mcp"

Bearer resource_metadata="https://redm-mcp.fivem.no/.well-known/oauth-protected-resource/mcp"
Header Value
www-authenticate Bearer resource_metadata="https://redm-mcp.fivem.no/.well-known/oauth-protected-resource/mcp"

Protected resource metadata

Document https://redm-mcp.fivem.no/.well-known/oauth-protected-resource/mcp
Retrieved Yes
Resource https://redm-mcp.fivem.no/mcp
Authorisation server https://redm-mcp.fivem.no

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://redm-mcp.fivem.no/mcp Auth required 401
http (plaintext) http://redm-mcp.fivem.no/mcp HTTPS enforced 301 https://redm-mcp.fivem.no/mcp
MCP tools · 10 exposed · ~3,950 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
asset_lookup ~1,039

Resolve a RedM game-data asset (ped model, weapon, object, door, vehicle) by exact name, 32-bit hash, or partial-name search. O(1) structured lookup against pre-parsed discoveries tables — replaces the common workflow of grepping `a_c_bear_01` in peds_list.lua, then cross-referencing RELATIONSHIP/README.md for its relationship group. Returns: type, name, normalized hash (`0x` + 8 uppercase hex), source file + line, plus type-specific metadata (peds get `variants` + `relationship`, weapons get `group`, doors get `coords` + `model_hash`, objects get `category`/`subcategory`). Catalog ~22,500 entries (mostly objects). Typical latency p50 ~15ms, p95 ~65ms. NOT for: - **Script natives** like `SET_ENTITY_COORDS`, `GetPedHealth`, or hashes from `Citizen.InvokeNative(0x...)` — use `lookup_native`. Native hashes are 64-bit (`0x06843DA7060A026B`); asset hashes are 32-bit (`0xBCFD0E7F`). Different namespaces, never collide. - **Flag enums, settings, clipsets, scenario keys** like `CPED_CONFIG_FLAGS`, `MP_Style_Casual`, `mech_loco_m@`, `MAGGIE_SEAT_CHAIR_DESK_WRITING`. Those live as tokens in lua source but not in this catalog. Use `grep_docs`. - **Behavior queries** ("which animal is the bear", "weapons in the lemat family") — use `semantic_search`. Pass exactly ONE of `name` / `hash` / `search`. Optional `type` narrows to a category (useful when a fragment like "horse" hits both peds and vehicles). Note: `type` reflects the SOURCE FILE — the same asset name can exist under multiple `type`s. e.g. `mp006_p_mshine_int_door01x` appears as `type=object` (1 row from object_list.lua) AND `type=door` (2 rows from doorhashes.lua, different door hashes for distinct in-world instances with `coords`). Pick `type=door` when you want lockable in-world doors with positions; `type=object` for the model itself. Examples: - `{name: "a_c_bear_01"}` → exact ped lookup, returns variants=11 + relationship=REL_WILD_ANIMAL_PREDATOR. - `{hash: "0xBCFD0E7F"}` → resolves to ped `a_c_bear_01` (omit…

NameTypeReqDescription
hashstring–Asset hash (32-bit jenkins) in HEX format, case-insensitive, `0x` prefix optional. Examples: `0xBCFD0E7F`, `bcfd0e7f`. Use when you have a hash from decompiled code or another table and need the cano…
limitinteger–Max matches to return. Default 5, max 50. Only applies to `search` — exact `name`/`hash` always return 0 or 1.
namestring–Exact asset name, case-insensitive. Examples: `a_c_bear_01`, `weapon_pistol_volcanic`, `p_safe01`, `armysupplywagon`. Use when you know the precise name.
searchstring–Substring fragment within asset name, case-insensitive. Examples: `lemat`, `norfolk`, `volcanic`. Use when you remember part of the name. Algorithm: exact substring (ILIKE) first; if zero hits, falls…
typestring–Filter results to one category. Useful when a name fragment matches multiple types (e.g. `horse` hits peds + vehicles).
NameTypeReqDescription
assetsarrayyes–
hashFormat–yes–
hint–yes–
statusstringyes–
suggestionsarrayyes–

No examples provided.

browse ~85

Enumerate doc paths in a category/namespace. Use to discover what exists before calling `get_document` or a targeted `grep_docs`. NOT a content search — use `semantic_search` for behavior/concept lookups or `grep_docs` for token lookups. Returns `{path, title, chunks}[]`.

NameTypeReqDescription
categorystring––
namespacestring––

No output schema declared.

No examples provided.

get_document ~357

Fetch full markdown of a doc by `path` (as returned by `browse`, `semantic_search`, or `grep_docs`). Use to retrieve full content after a search snippet looks promising. Pass `heading` (full breadcrumb like `Character Management > Inventory Management`, or just the leaf — case-insensitive, fuzzy) to fetch only that section. Deep-heading matches auto-prepend the H2 parent's intro for context. For individual script natives prefer `lookup_native`. The largest rdr3_discoveries lua data tables are keyed catalogs: call with no `heading` to list their top-level keys, then pass a key as `heading` to fetch that one entry; use `grep_docs` to search values inside. For code symbols (`addItem`) use `grep_docs`. Community findings use `learning:N` paths, not `learnings/<slug>.md`. On 404 returns available headings + cross-file hints.

NameTypeReqDescription
headingstring–Optional prose heading from the doc, e.g. `Add Item to User` or `Character Management > Inventory Management`. Case-insensitive, fuzzy match on the leaf (text after the final `>`). NOT for code symbo…
pathstringyesDoc path. Two valid shapes: (a) `<category>/<file>.md` for docs, e.g. `vorp/vorp_core_docs.md`; (b) `learning:<id>` for community findings, e.g. `learning:11`. Use the path returned by `browse`/`sema…

No output schema declared.

No examples provided.

get_invoke_guide ~124

Load the calling-convention reference for RedM/RDR3 natives in `js` or `lua`. Call ONCE per session before writing native-calling code — every native doc page only shows Lua examples, so JS/TS authors need this to translate correctly. Covers result modifiers (`Citizen.resultAsInteger/Float/String/Vector`), `Citizen.invokeNative` vs `invokeNativeByHash`, type mapping, pointer-arg gotchas, worked examples. Cheap, no embedding.

NameTypeReqDescription
languagestringyesTarget language: 'js' or 'lua'

No output schema declared.

No examples provided.

grep_docs ~666

Find an EXACT literal token in raw doc files (markdown + lua). Use for specific weapon/ped/animation/prop/interior/zone names (`weapon_pistol_volcanic`, `a_c_bear_01`, `p_campfire01x`), known hashes (`0x020D13FF`), walkstyles/clipsets (`MP_Style_Casual`, `mech_loco_m@`), or any string you'd `grep` for. NOT for behavior/concept queries (use `semantic_search`) or script-native hash/name lookup (use `lookup_native`). REQUIRED for tokens inside the largest rdr3_discoveries data tables (audio_banks, ingameanims_list, cloth_drawable, cloth_hash_names, object_list, megadictanims, entity_extensions, imaps_with_coords, propsets_list, vehicle_bones) — only preview-indexed for embeddings, so `semantic_search` will NOT find tokens in them. Optional: `contextBefore`/`contextAfter` for ±N surrounding lines (saves a follow-up `get_document` call); `filesOnly: true` to get paths only (cheap exploration); `multiline: true` for cross-line patterns (`(?s)foo.*bar`). Pattern uses Rust regex syntax (rg engine). PREFER one targeted call over giant `a|b|c|d|e` alternations — split into separate calls; alternations rarely improve recall and bloat the regex automaton. Returns matched lines with path + line number. Long matched lines are windowed ±60 chars around the match (…); to read around a hit, use `read_lines({path, start})` for the preview-only mega-tables listed above (get_document holds only their ~80-line head), or `get_document({path})` for ordinary docs. If you are retrying after a previous pattern returned no matches, populate `prior_attempt` so the server can record what didn't work and steer alternative spellings.

NameTypeReqDescription
caseInsensitiveboolean–Default true. Set false for case-sensitive match.
categorystring–Limit to a doc category (e.g. discoveries, natives).
contextAfterinteger–Include N lines after each match (rg -A).
contextBeforeinteger–Include N lines before each match (rg -B). Saves follow-up get_document calls when you need surrounding context.
filesOnlyboolean–Return only the list of matching paths (no per-line matches). Cheap for exploration before zoom-in.
limitinteger––
multilineboolean–Allow `.` to match newlines and patterns to span lines (rg -U --multiline-dotall). Use for `(?s)foo.*bar` style.
pathSubstringstring–Substring filter on relative doc path, e.g. 'weapons' or 'clothes/cloth_hash_names'.
patternstringyesRust regex pattern (ripgrep engine). Case-insensitive by default. Prefer narrow, single-token patterns over kitchen-sink alternations.
prior_attemptobject–Populate ONLY when retrying after a previous grep_docs call returned no matches. Skip on first attempts.

No output schema declared.

No examples provided.

list_namespaces ~144

Orient yourself: list available doc categories and their namespaces. Use once at session start (or when unsure) before applying a `category=` / `namespace=` filter to `browse` / `semantic_search`. NOT a content search. Categories: `natives` (PLAYER, ENTITY, VEHICLE, …), `vorp`, `rsgcore`, `oxmysql`, `discoveries` (AI, weapons, peds, animations, clothes, objects, …), `jo_libs` (menu, notification, callback, framework-bridge, …, dev_resources, redm_scripts), `guides`, `learnings`.

NameTypeReqDescription
categorystring––
NameTypeReqDescription
categoriesarrayyes–

No examples provided.

lookup_native ~415

Resolve a RedM/RDR3 SCRIPT native by hash or name — O(1), exact. Use whenever you see `Citizen.InvokeNative(0x...)`, `Citizen.invokeNative('0x...')`, `GetHashKey('NAME')`, or a SCREAMING_SNAKE_CASE native name (e.g. `SET_ENTITY_COORDS`, `GetPedHealth`) in Lua/JS/TS. NOT for game-data hashes (weapon/ped/animation names) — use `grep_docs`. Pass `hash` (0x… optional, case-insensitive) or `name` (exact first, ILIKE substring fallback). Returns name, hash, namespace, return type, params, description, full content, plus `findings[]` — community gotchas linked to that native. Inspect `findings[].id` and call `get_document({path: 'learning:<id>'})` for full body. Also returns `refDocs[]` — enum/flag value tables for that native (the constants to pass for params like flagId/attributeIndex/eventType). When `refDocs[].content` is set, it's the inline enum table — use those values directly. When `content` is null but `refDocs[].fetch` is present, the table was too large to inline — run that exact call (e.g. `get_document({ path: "refdoc:eEventType" })`) to get the full table; `refDocs[].preview` shows the first lines. github entries (no `fetch`) are url-only.

NameTypeReqDescription
hashstring–Native hash, e.g. 0x09C28F828EE674FA (case-insensitive, 0x optional)
limitinteger––
namestring–Native name, e.g. CAN_PLAYER_START_MISSION. Substring match if no exact hit.
namespacestring–Restrict to a namespace, e.g. PLAYER, ENTITY. Only used with `name`.
NameTypeReqDescription
hint–yes–
nativesarrayyes–
statusstringyes–
suggestionsarrayyes–

No examples provided.

read_lines ~352

Read an exact line range from a raw doc file by absolute line number — the windowed-read companion to `grep_docs`. When `grep_docs` returns a hit at `path:line` inside a large file, call `read_lines({ path, start, end })` to pull the surrounding block. This is the ONLY way to read around a hit in the largest rdr3_discoveries data tables (audio_banks, ingameanims_list, ptfx, soundsets, imaps_with_coords, megadictanims, etc.): their full bodies are NOT in the vector/heading index (only an ~80-line preview is), so `semantic_search` can't reach them and `get_document` resolves real section headings only — NOT synthetic `lines N-M` offsets. `start`/`end` are 1-based and inclusive; omit `end` for a 50-line window; one call returns at most 400 lines (narrow the range for more). For prose `.md` docs prefer `get_document` with a `heading`; to search values use `grep_docs`; for individual script natives use `lookup_native`.

NameTypeReqDescription
endinteger–Last line to return (1-based, inclusive). Omit for a 50-line window from `start`. Spans over 400 lines are capped.
pathstringyesDoc path exactly as returned by `grep_docs` / `browse` / `semantic_search`, e.g. `discoveries/audio/audio_banks/audio_banks.lua`. Do not invent paths.
startintegeryesFirst line to return (1-based, inclusive). Use the line number from a `grep_docs` hit.

No output schema declared.

No examples provided.

semantic_search ~431

Search RedM/RDR3 docs by behavior, concept, OR exact token. Use when you don't have a specific native hash/name (use `lookup_native`) and the term isn't a known asset name in a large data table (use `grep_docs`). Hybrid mode (default) handles 'how do I X' queries ('teleport player', 'spawn vehicle', 'inventory add item') AND tokens ('addItem', 'weapon_pistol_volcanic', 'CPED_CONFIG_FLAG_') — fused via RRF over vector + BM25. Returns ranked snippets (path, breadcrumb, heading, snippet, score). Call `get_document({path, heading})` for full chunk content. `mode=semantic` for pure vector; `mode=lexical` for pure BM25. Filter via `category=vorp|rsgcore|oxmysql|natives|discoveries|jo_libs|learnings` or `namespace`. Community findings merged by default; `category=learnings` returns only findings. If you are retrying after a previous call returned no useful results, populate `prior_attempt` so the server can surface alternative wordings and learn what's missing from the docs.

NameTypeReqDescription
categorystring–Limit to one doc category
limitinteger–How many ranked snippets to return. Default 20 (Anthropic contextual-retrieval research: top-20 outperforms top-5/10 before reranking).
modestring–Retrieval mode. Default hybrid (recommended).
namespacestring–Limit to a native namespace, e.g. PLAYER, ENTITY
prior_attemptobject–Populate ONLY when retrying after a previous semantic_search call returned no useful results. Skip on first attempts.
querystringyesNatural language or token query
responseFormatstring–`concise` (default): 400-char snippet per hit — cheap, browse-style. `detailed`: full chunk content — use when you need an answer in one round-trip and want to skip the `get_document` follow-up.

No output schema declared.

No examples provided.

share_finding ~337

Share a verified finding back to the docs corpus so the next agent can find it. Use AFTER solving a non-trivial problem to record what would have saved you time: a gotcha, a working parameter combo, an undocumented constraint, a relationship between two natives that isn't obvious. Other agents will find this via `semantic_search` (findings are merged into default results; `category: 'learnings'` returns only findings). WHEN to use: - You burned multiple iterations on something not in the docs. - You discovered an undocumented quirk (param order, hash collision, framework export that isn't in `vorp`/`rsgcore`). - You verified that a specific combination works (e.g. native A + flag B for behavior C). WHEN NOT to use: - The information is already in the docs (verify with `semantic_search`/`grep_docs` first). - You're guessing — only contribute verified findings. - It's project-specific (your repo's auth flow, your DB schema). Keep it general to RedM/RDR3. Keep `title` short and searchable. `body` should explain WHY, not just WHAT — context, the trap, the fix.

NameTypeReqDescription
bodystringyesMarkdown explaining WHY: context, the trap, the fix, verified behavior.
categorystring–Optional doc category this relates to.
sourcestring–Optional short identifier of the contributing agent.
tagsarray–Up to 8 lowercase tags, e.g. ['weapons', 'damage'].
titlestringyesShort, searchable summary of the finding.

No output schema declared.

No examples provided.

Common questions

What is the redm-mcp server?

redm-mcp is listed in the public MCP registry as io.github.Cmoen11/redm-mcp. RedM / RDR3 docs MCP server: native lookups, semantic search, VORP, RSGCore, oxmysql. This page covers its hosted endpoint (https://redm-mcp.fivem.no/mcp).

Is the redm-mcp server safe to use?

redm-mcp scores 36 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the redm-mcp server expose?

redm-mcp exposes 10 tools: semantic_search, list_namespaces, browse, get_document, read_lines, and 5 more. Their descriptions and schemas cost roughly 3,950 tokens of context every time the server is loaded.

Does the redm-mcp server require authentication?

Yes. redm-mcp asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

Is the redm-mcp server still maintained?

redm-mcp is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.