Almirall MCP
REMOTE · MCP.ALMIRALL.COM · SCANNED SEP 24
Official Almirall company, product and brand info: Almax, Hidroxil, Calmatel, Cicopoli and more.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security74
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability70
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2051 tokens (~186/item across 11 items; 11 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management53
- Stability observed for 16 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 11 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 11 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the Almirall MCP server?
Almirall MCP is a hosted endpoint at https://mcp.almirall.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.almirall.com
claude mcp add --transport http com-almirall-mcp 'https://mcp.almirall.com/mcp'
{
"mcpServers": {
"com-almirall-mcp": {
"url": "https://mcp.almirall.com/mcp"
}
}
} {
"servers": {
"com-almirall-mcp": {
"type": "http",
"url": "https://mcp.almirall.com/mcp"
}
}
} [mcp_servers.com-almirall-mcp] url = "https://mcp.almirall.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-almirall-mcp": {
"type": "remote",
"url": "https://mcp.almirall.com/mcp",
"enabled": true
}
}
} openclaw mcp add com-almirall-mcp --url 'https://mcp.almirall.com/mcp' --transport streamable-http
mcp_servers:
com-almirall-mcp:
url: "https://mcp.almirall.com/mcp" {
"McpServers": {
"com-almirall-mcp": {
"Transport": "http",
"Url": "https://mcp.almirall.com/mcp"
}
}
} assistant mcp add com-almirall-mcp -t streamable-http -u 'https://mcp.almirall.com/mcp'
{
"mcpServers": {
"com-almirall-mcp": {
"type": "http",
"url": "https://mcp.almirall.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 24 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 50 to 53. That category is still filling its 30-day observation window: 15 days of observed history at the previous scan, 16 at this one. The score rises as the window fills, whether or not the server changes.
- 22 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 43 to 47. That category is still filling its 30-day observation window: 13 days of observed history at the previous scan, 14 at this one. The score rises as the window fills, whether or not the server changes.
- 20 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 37 to 40. That category is still filling its 30-day observation window: 11 days of observed history at the previous scan, 12 at this one. The score rises as the window fills, whether or not the server changes.
- 18 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 30 to 33. That category is still filling its 30-day observation window: 9 days of observed history at the previous scan, 10 at this one. The score rises as the window fills, whether or not the server changes.
- 16 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.
- 13 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 13 to 17. That category is still filling its 30-day observation window: 4 days of observed history at the previous scan, 5 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Sept 26 +8
- Authorization: unverified → partial ▲ security
- 9 Sept 26 +1
- Stability: unverified → 0.03 ▲ functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 24 Sept 2026 · Probed https://mcp.almirall.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_256_GCM_SHA384 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=mcp.almirall.com | CN=Sectigo Public Server Authentication CA DV R36,O=Sectigo Limited,C=GB | 20 Jul 2026 | 3 Feb 2027 | RSA 2048 | SHA256-RSA | 8f52a7dbb20a364785911e1139af3c78 |
| SANs: mcp.almirall.com, www.mcp.almirall.com | ||||||
| CN=Sectigo Public Server Authentication CA DV R36,O=Sectigo Limited,C=GB (CA) | CN=Sectigo Public Server Authentication Root R46,O=Sectigo Limited,C=GB | 22 Mar 2021 | 21 Mar 2036 | RSA 3072 | SHA384-RSA | 397a66cc2756362e0daa87ca6eabe3b1 |
| CN=Sectigo Public Server Authentication Root R46,O=Sectigo Limited,C=GB (CA) | CN=USERTrust RSA Certification Authority,O=The USERTRUST Network,L=Jersey City,ST=New Jersey,C=US | 22 Mar 2021 | 18 Jan 2038 | RSA 4096 | SHA384-RSA | d27fbbc1de359e5216ad6149586099c4 |
| CN=USERTrust RSA Certification Authority,O=The USERTRUST Network,L=Jersey City,ST=New Jersey,C=US (CA) | CN=USERTrust RSA Certification Authority,O=The USERTRUST Network,L=Jersey City,ST=New Jersey,C=US | 1 Feb 2010 | 18 Jan 2038 | RSA 4096 | SHA384-RSA | 1fd6d30fca3ca51a81bbc640e35032d |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.almirall.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| almirall.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.almirall.com/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.almirall.com/mcp | HTTPS enforced | 301 | https://mcp.almirall.com |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
compare_content Compare Content ~219
Compare two or more named items, product formats, ranges, topics, or alternatives using indexed website content. Use this when the user asks for differences, similarities, pros/cons, or when to choose one option versus another, for example comparing Almax formats or Physiorelax ranges. Returns grouped evidence for each item so the client can build a grounded comparison.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | – | Optional domain filter, for example physio-relax.de. |
| items | array | yes | Names of the items or topics to compare. |
| query | string | – | Optional comparison context, such as ingredients, benefits, usage, format, contraindications, or when to choose each option. |
| sourceId | string | – | Optional crawler source id, for example physio-relax-de. |
| topPerItem | integer | – | Maximum number of search results to keep per item. Defaults to 3. |
| userLocation | object | – | Optional approximate user location. Include only if the client or user has explicitly made it available; do not infer or guess it. |
No output schema declared.
No examples provided.
find_content_assets Find Content Assets ~207
Extract image/media asset URLs from indexed markdown text. Use only when the user asks for product images, media files, visual assets, screenshots, WordPress uploads, or image evidence. For textual questions about extracted page content, use search_content instead. Returns asset URLs plus the real page URL where each asset appeared.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | – | Optional exact domain filter, for example physio-relax.de. |
| query | string | – | Optional topic, product, filename, or asset context to search before extracting assets. Defaults to image/product-oriented search. |
| sourceId | string | – | Optional crawler source id, for example physio-relax-de. |
| top | integer | – | Maximum number of chunks to inspect for assets. Defaults to at least 10. |
| url | string | – | Optional exact crawled page URL filter. |
| userLocation | object | – | Optional approximate user location. Include only if the client or user has explicitly made it available; do not infer or guess it. |
No output schema declared.
No examples provided.
find_pages_by_title Find Pages by Title ~170
Resolve the most relevant indexed pages by approximate title match before doing a narrower content search. Use this when the user mentions a brand, product family, or page-like concept but not a domain or URL, and you want to identify the right page first without requiring an exact title match.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | – | Optional domain filter to narrow title matching. |
| sourceId | string | – | Optional crawler source id to narrow title matching. |
| titleQuery | string | yes | Brand, product, or page title hint to match approximately against indexed page titles. |
| top | integer | – | Maximum number of candidate pages to return. Defaults to 10. |
| userLocation | object | – | Optional approximate user location. Include only if the client or user has explicitly made it available; do not infer or guess it. |
No output schema declared.
No examples provided.
find_product_mentions Find Product Mentions ~245
Specialized product extraction tool. Use when the user specifically asks what products a crawled brand/site offers, asks for catalog items, variants, product ranges, formulations, product benefits, ingredients by product, or where product claims appear. If the user is asking a general content question rather than enumerating products, use search_content instead. sourceId and domain are optional filters; if you need to discover the right indexed source before narrowing, use list_sources. Returns grouped product mentions with evidence snippets and real page URLs.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | – | Optional domain filter, for example physio-relax.de. |
| productHint | string | – | Optional known product or brand name to bias extraction and grouping. |
| query | string | yes | Natural-language query describing the product, brand, category, or benefit to detect. |
| sourceId | string | – | Optional crawler source id, for example physio-relax-de. |
| top | integer | – | Maximum number of search results to inspect for product mentions. Defaults to at least 8. |
| userLocation | object | – | Optional approximate user location. Include only if the client or user has explicitly made it available; do not infer or guess it. |
No output schema declared.
No examples provided.
get_chunk Get Chunk ~151
Retrieve one concrete indexed chunk by uid, or by documentId plus chunkIndex. Optionally returns adjacent chunks from the same document for context.
| Name | Type | Req | Description |
|---|---|---|---|
| chunkIndex | integer | – | Chunk index inside the document. |
| contextAfter | integer | – | Number of following chunks to include. Defaults to 0. |
| contextBefore | integer | – | Number of previous chunks to include. Defaults to 0. |
| documentId | string | – | Document id. Required when looking up by chunkIndex. |
| uid | string | – | Exact Azure Search uid for the chunk. |
| userLocation | object | – | Optional approximate user location. Include only if the client or user has explicitly made it available; do not infer or guess it. |
No output schema declared.
No examples provided.
get_page Get Page ~143
Reconstruct a page by documentId or url. Returns chunks ordered by chunkIndex plus a compact heading structure.
| Name | Type | Req | Description |
|---|---|---|---|
| documentId | string | – | Document id to reconstruct. |
| domain | string | – | Optional exact domain filter, for example physio-relax.de. |
| sourceId | string | – | Optional source id filter, for example physio-relax-de. |
| top | integer | – | Maximum chunks to return. Defaults to 30. |
| url | string | – | Exact crawled page URL to reconstruct. |
| userLocation | object | – | Optional approximate user location. Include only if the client or user has explicitly made it available; do not infer or guess it. |
No output schema declared.
No examples provided.
get_source_map Get Source Map ~145
Build a navigable map of an indexed source or domain with pages, documents, headings, and chunk ranges.
| Name | Type | Req | Description |
|---|---|---|---|
| documentId | string | – | Optional document id filter. |
| domain | string | – | Optional exact domain filter, for example physio-relax.de. |
| sourceId | string | – | Optional crawler source id, for example physio-relax-de. |
| top | integer | – | Maximum chunks to inspect for the map. Defaults to 30. |
| url | string | – | Optional exact page URL filter. |
| userLocation | object | – | Optional approximate user location. Include only if the client or user has explicitly made it available; do not infer or guess it. |
No output schema declared.
No examples provided.
list_pages List Pages ~147
List indexed pages available within a sourceId or domain. Use this to discover which page URLs/documents exist before requesting a full page.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | – | Optional exact domain filter, for example physio-relax.de. |
| query | string | – | Optional search query to narrow page discovery. Use * or omit for broad discovery. |
| sourceId | string | – | Optional crawler source id, for example physio-relax-de. |
| top | integer | – | Maximum chunks to inspect for page discovery. Defaults to 30. |
| userLocation | object | – | Optional approximate user location. Include only if the client or user has explicitly made it available; do not infer or guess it. |
No output schema declared.
No examples provided.
list_sources List Sources ~244
Discovery tool for indexed brands, sites, and domains. Use this when you need to discover or disambiguate which indexed domain/sourceId corresponds to a brand or product name, especially if an initial broad search needs narrowing. search_content does not require domain or sourceId, so prefer calling list_sources as an optional discovery step rather than as a mandatory prerequisite. It helps determine whether this MCP has a relevant indexed source and which domain or sourceId to pass into search_content or other tools.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | – | Optional domain filter, for example physio-relax.de. |
| query | string | – | Optional query to list sources related to a topic. Use * or omit for broad source discovery. |
| skip | integer | – | Number of matching chunks to skip before collecting the next page of sources. Defaults to 0. |
| sourceId | string | – | Optional crawler source id, for example physio-relax-de. |
| top | integer | – | Maximum chunks to inspect for source discovery. Defaults to 30. |
| userLocation | object | – | Optional approximate user location. Include only if the client or user has explicitly made it available; do not infer or guess it. |
No output schema declared.
No examples provided.
match_almax_prompt Match Almax Prompt ~71
Classify a Spanish prompt or phrase related to Almax into the closest editorial intent from the corpus. Use this when the client needs to detect which predefined Almax topic a user sentence matches before routing to another tool or template.
| Name | Type | Req | Description |
|---|---|---|---|
| text | string | yes | Phrase, prompt, or user text to classify. |
No output schema declared.
No examples provided.
search_content Search Content ~309
Primary tool for answering natural-language questions over indexed website and landing-page content. Use this whenever the user asks what a brand, product, or site says about ingredients, plant extracts, composition, contraindications, usage, benefits, claims, FAQs, or evidence. This includes questions that only mention a brand or product name, for example 'What ingredients or plant extracts does Physio Relax mention?'. Call this tool directly with the question even if domain or sourceId are unknown; those fields are optional narrowing filters, not required inputs. If you need to discover or disambiguate the indexed domain or sourceId for a second narrowed call, use list_sources. Searches content with keyword, semantic, and vector search, and can filter by domain, url, sourceId, or documentId.
| Name | Type | Req | Description |
|---|---|---|---|
| documentId | string | – | Optional crawler document id to restrict results to one indexed page/document. |
| domain | string | – | Optional exact domain filter, for example physio-relax.de. |
| query | string | yes | Natural-language question or keywords to search in crawled website content. |
| sourceId | string | – | Optional crawler source id, for example physio-relax-de. |
| top | integer | – | Maximum number of search results to return. Defaults to the server setting. |
| url | string | – | Optional exact crawled page URL filter. |
| userLocation | object | – | Optional approximate user location. Include only if the client or user has explicitly made it available; do not infer or guess it. |
No output schema declared.
No examples provided.
What is the Almirall MCP server?
Almirall MCP is listed in the public MCP registry as com.almirall/mcp. Official Almirall company, product and brand info: Almax, Hidroxil, Calmatel, Cicopoli and more. This page covers its hosted endpoint (https://mcp.almirall.com/mcp).
Is the Almirall MCP server safe to use?
Almirall MCP scores 78 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Almirall MCP server expose?
Almirall MCP exposes 11 tools: search_content, get_chunk, get_page, get_source_map, list_pages, and 6 more. Their descriptions and schemas cost roughly 2,051 tokens of context every time the server is loaded.
Does the Almirall MCP server require authentication?
No. We connected to Almirall MCP without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Almirall MCP server still maintained?
Almirall MCP is still listed as active in the MCP registry. We last reached this channel on 24 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.