com.buyukesim/mcp
REMOTE · BUYUKESIM.COM · SCANNED SEP 22
No-logs VPN, real UK +44 number eSIMs and travel-data eSIMs, bought with crypto. No KYC, no account.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 21 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability75
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2973 tokens (~141/item across 21 items; 21 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 21 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 22 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the com.buyukesim/mcp server?
com.buyukesim/mcp is a hosted endpoint at https://buyukesim.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · buyukesim.com
claude mcp add --transport http com-buyukesim-mcp 'https://buyukesim.com/mcp'
{
"mcpServers": {
"com-buyukesim-mcp": {
"url": "https://buyukesim.com/mcp"
}
}
} {
"servers": {
"com-buyukesim-mcp": {
"type": "http",
"url": "https://buyukesim.com/mcp"
}
}
} [mcp_servers.com-buyukesim-mcp] url = "https://buyukesim.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-buyukesim-mcp": {
"type": "remote",
"url": "https://buyukesim.com/mcp",
"enabled": true
}
}
} openclaw mcp add com-buyukesim-mcp --url 'https://buyukesim.com/mcp' --transport streamable-http
mcp_servers:
com-buyukesim-mcp:
url: "https://buyukesim.com/mcp" {
"McpServers": {
"com-buyukesim-mcp": {
"Transport": "http",
"Url": "https://buyukesim.com/mcp"
}
}
} assistant mcp add com-buyukesim-mcp -t streamable-http -u 'https://buyukesim.com/mcp'
{
"mcpServers": {
"com-buyukesim-mcp": {
"type": "http",
"url": "https://buyukesim.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 16 Sept 26 0
- The server rewrote its instructions, which are the text every model session reads security
- Schema quality: 2527 → 2973 ▼ functional
- New tool “list_esim_topups” functional
- New tool “purchase_esim_topup” functional
- 12 Sept 26 0
- Tool “create_deposit” rewrote its description, which is the text the model reads security
- Tool “list_reviews” rewrote its description, which is the text the model reads security
- 4 Sept 26 0
- New tool “get_esim_exit_countries” functional
- 3 Sept 26 0
- New tool “get_payment_and_delivery_times” functional
- 2 Sept 26 0
- The server rewrote its instructions, which are the text every model session reads security
- 30 Aug 26 −1
- The server rewrote its instructions, which are the text every model session reads security
- Schema quality: 117 → 129 ▼ functional
- Schema quality: 117 → 134 ▼ functional
- New tool “check_uk_coverage” functional
- New tool “get_bundle_info” functional
- New tool “list_reviews” functional
- New tool “get_vpn_config” functional
- New tool “list_vpn_plans” functional
- New tool “purchase_vpn” functional
- 26 Aug 26 +3
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 80 to 84.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 22 Sept 2026 · Probed https://buyukesim.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=buyukesim.com | CN=WE1,O=Google Trust Services,C=US | 8 Aug 2026 | 6 Nov 2026 | ECDSA 256 | ECDSA-SHA256 | 9244e6852fde1eaf13832a7e0549f95e |
| SANs: buyukesim.com, mcp.buyukesim.com, *.mcp.buyukesim.com | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of buyukesim.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| buyukesim.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
| content-security-policy | default-src 'self'; script-src 'self' 'unsafe-inline' https://challenges.cloudflare.com; style-src 'self' 'unsafe-inline' https://challenges.cloudflare.com; img-src 'self' data: https:; font-src 'self' data:; frame-src 'self' https://challenges.cloudflare.com https://www.youtube-nocookie.com https://www.youtube.com; connect-src 'self' https://buyukesim.com https://api.telegram.org https://challenges.cloudflare.com; |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(), geolocation=() |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://buyukesim.com/mcp | Verified | 200 | |
| http (plaintext) | http://buyukesim.com/mcp | HTTPS enforced | 301 | https://buyukesim.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
check_balance ~62
Check the balance of the agent wallet (pass the ak_live_ api key from create_wallet). Returns available USD balance.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | – | The ak_live_ key returned by create_wallet. Pass it here, or as an Authorization: Bearer header. |
No output schema declared.
No examples provided.
check_order_status ~72
Look up the status of a BuyUKeSIM order using its short lookup/magic code (the code the customer received). Returns only the order status - no personal data, no QR.
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | yes | The order lookup / magic code, e.g. 8U6D-ANCM. |
No output schema declared.
No examples provided.
check_uk_coverage ~118
Check whether the UK +44 number has been reported working in a country, from buyers who told us after using it there. Pass a 2-letter ISO country code. Returns how many reports exist and how many said it worked, and says plainly when there are none - an absent country means no evidence either way, not a failure. This is evidence, not a promise: roaming depends on the local network. Read-only.
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | yes | 2-letter ISO country code, e.g. NG, DE, RU. |
No output schema declared.
No examples provided.
create_deposit ~136
Top up the agent wallet with crypto (pass the ak_live_ api key from create_wallet). Returns a crypto payment address and amount; the balance is credited automatically once the payment confirms on-chain. Minimum $100.
| Name | Type | Req | Description |
|---|---|---|---|
| amount_usd | number | yes | USD amount to add, minimum 10. |
| api_key | string | – | The ak_live_ key returned by create_wallet. Pass it here, or as an Authorization: Bearer header. |
| coin | string | – | Payment method id, e.g. usdttrc20 (default), btc, eth, trx. See payment options on buyukesim.com. |
No output schema declared.
No examples provided.
create_wallet ~107
Create a new BuyUKeSIM agent wallet - a prepaid, no-KYC balance an AI agent funds with crypto and spends on eSIMs. Returns an api_key (ak_live_...) and a wallet_code. Save both: pass the api_key as the api_key argument on the wallet tools; the wallet_code lets a human sign back in. Balance can only be spent on eSIMs, never withdrawn.
| Name | Type | Req | Description |
|---|---|---|---|
| label | string | – | Optional short label to recognise this wallet later. |
No output schema declared.
No examples provided.
get_bundle_info ~79
Describe the UK Number + Travel eSIM bundle: both products in ONE crypto checkout, delivered as TWO QR codes and opened with one order code. Use it when someone wants a +44 number for verification codes AND mobile data for a trip, so they are not told to make two separate purchases. Read-only; the bundle is bought on the website.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_esim_exit_countries ~179
Where a BuyUKeSIM travel data eSIM reaches the public internet, per destination. A travel eSIM roams, so the data session is usually tunnelled to the sponsoring operator gateway and a website sees THAT country, not the country the plan is named after (a Germany plan can break out in France, the Netherlands or the UK). Returns the exit country and plan count for every destination, regenerated from the live catalogue on each site build. Use this for "what IP country will my eSIM show", "will my bank app see me in X", and geo-blocking questions. An exit country changes what a site sees, not who the user is. Read-only.
| Name | Type | Req | Description |
|---|---|---|---|
| destination | string | – | Optional destination to return instead of the whole table: an ISO country code (DE) or the English name (Germany). |
No output schema declared.
No examples provided.
get_one_time_code ~136
One-Time Codes are PAUSED and cannot be bought; this only works for orders placed before the pause. Poll a purchased One-Time Code order for its SMS code. Returns the phone number and, once it arrives, the verification code. Call repeatedly (every few seconds) until phase is code_ready or failed. Pass the ak_live_ api key and the order_id from purchase_one_time_code.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | – | The ak_live_ key returned by create_wallet. Pass it here, or as an Authorization: Bearer header. |
| order_id | integer | yes | The order_id returned by purchase_one_time_code. |
No output schema declared.
No examples provided.
get_payment_and_delivery_times ~120
How long a crypto payment actually takes at BuyUKeSIM and what happens after it confirms. Returns measured confirmation times per coin (median, worst case, share confirmed within two minutes) taken from real orders against public blockchain block timestamps, plus the send delay buyers themselves add, plus how delivery works: it is automatic, triggered by the confirmation, with no human approval step. Use this for "how long does it take", "which coin is fastest", "is delivery instant" and "does someone have to approve my order". Read-only.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_uk_number_info ~71
Get details of the BuyUKeSIM UK Number (+44) eSIM: a real UK mobile line for unlimited incoming SMS and calls (app and service verification codes, WhatsApp, Telegram), no KYC, paid in crypto, instant QR. This is distinct from the travel data eSIM.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_vpn_config ~193
Fetch a VPN client configuration for one server on a VPN order. Needs the order_id and its short lookup/magic code (both returned by purchase_vpn), a protocol (wireguard, openvpn or vless) and a server_id from list_vpn_plans. Returns the config file text, ready to import into any standard client. No wallet key needed - the order code is the credential. Call it again for another server or protocol; there is no limit.
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | yes | The order lookup / magic code, e.g. 8U6D-ANCM. |
| order_id | integer | yes | The order_id from purchase_vpn. |
| protocol | string | yes | wireguard, openvpn or vless. WireGuard servers also serve OpenVPN; VLESS servers only serve VLESS. |
| server_id | integer | yes | A server id from list_vpn_plans. |
No output schema declared.
No examples provided.
list_covered_countries ~40
List the countries/regions BuyUKeSIM travel eSIM data plans currently cover, with how many plans each has (2-letter ISO codes).
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_esim_topups ~151
List the extra data packages that can be loaded onto a travel eSIM this wallet already bought, so it keeps working instead of being replaced. Pass the order_id from purchase_esim and the ak_live_ key. The offer is per eSIM and live, so call this rather than reusing codes from search_esim_plans - those are for NEW eSIMs and will not work here. Read-only: it spends nothing.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | – | The ak_live_ key returned by create_wallet. Pass it here, or as an Authorization: Bearer header. |
| order_id | integer | yes | The order_id of the travel eSIM to reload, from purchase_esim. |
No output schema declared.
No examples provided.
list_reviews ~135
Read real customer reviews of BuyUKeSIM, newest first, with the overall rating and how many there are. Reviews are published unmoderated: nothing approves one before it appears, and the buyer country shown on each card comes from the sale, so a low rating is as likely to appear as a high one. Where the shop has answered a review in public, that answer is included under it. Use this when you are deciding whether to recommend the shop, or when a user asks what buyers say. Read-only.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | How many reviews to return, 1 to 25. Default 10. |
No output schema declared.
No examples provided.
list_transactions ~66
List the most recent transactions (deposits and purchases) on the agent wallet. Pass the ak_live_ api key from create_wallet.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | – | The ak_live_ key returned by create_wallet. Pass it here, or as an Authorization: Bearer header. |
No output schema declared.
No examples provided.
list_vpn_plans ~77
List the BuyUKeSIM VPN access plans (7/15/30/90/180/365 days, USD price) and the server countries currently available, with protocols (WireGuard, OpenVPN, VLESS). VPN access, no account, paid in crypto. Read-only; buy a plan with purchase_vpn.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
purchase_esim ~174
Buy a travel/data eSIM using the agent wallet balance (pass the ak_live_ api key from create_wallet). Deducts the plan price from the balance and returns the eSIM QR code instantly. Get a package_code from search_esim_plans first. Pass a stable request_id to make retries safe (no double charge). This provisions a real eSIM - only call it when the user has confirmed the purchase.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | – | The ak_live_ key returned by create_wallet. Pass it here, or as an Authorization: Bearer header. |
| package_code | string | yes | The plan code from search_esim_plans, e.g. CKH253. |
| request_id | string | – | Optional idempotency key - reuse the same value on a retry to avoid a double charge. |
No output schema declared.
No examples provided.
purchase_esim_topup ~247
Add more data to a travel eSIM this wallet already bought, paid from the balance. The data lands on the profile the user already installed: same QR, same ICCID, nothing to install again, so there is no new eSIM and nothing to scan. Use this when someone runs out of data mid-trip or needs longer than one plan - buying a second eSIM instead means a second profile to install. Get package_code from list_esim_topups. An eSIM takes 10 top-ups in total. Pass request_id for safe retries. This spends real balance - only call it once the user has confirmed.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | – | The ak_live_ key returned by create_wallet. Pass it here, or as an Authorization: Bearer header. |
| order_id | integer | yes | The order_id of the travel eSIM to reload, from purchase_esim. |
| package_code | string | yes | A top-up package code from list_esim_topups for THIS eSIM. Codes from search_esim_plans do not work here. |
| request_id | string | – | Optional idempotency key - reuse on a retry to avoid a double charge. |
No output schema declared.
No examples provided.
purchase_uk_number ~138
Buy a UK +44 Number eSIM (a real UK mobile line for incoming verification SMS and calls) using the agent wallet balance. Deducts about $25 and delivers a QR from stock instantly. Pass the ak_live_ api key from create_wallet. Pass request_id for safe retries. This delivers a real eSIM - only call it once the user has confirmed.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | – | The ak_live_ key returned by create_wallet. Pass it here, or as an Authorization: Bearer header. |
| request_id | string | – | Optional idempotency key - reuse on a retry to avoid a double charge. |
No output schema declared.
No examples provided.
purchase_vpn ~210
Buy VPN access using the agent wallet balance. Deducts the plan price and returns the username, password and expiry instantly. plan is one of 7d, 15d, 30d, 90d, 180d, 365d - call list_vpn_plans first for the current prices and server countries. One payment, no auto-renewal, no account. Configs are fetched afterwards with get_vpn_config, or from the order page. Pass request_id for safe retries. This spends real balance - only call it once the user has confirmed. Not an eSIM: it carries no phone number and no mobile data.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | – | The ak_live_ key returned by create_wallet. Pass it here, or as an Authorization: Bearer header. |
| plan | string | yes | Plan key from list_vpn_plans. |
| request_id | string | – | Optional idempotency key - reuse on a retry to avoid a double charge. |
No output schema declared.
No examples provided.
search_esim_plans ~117
Search BuyUKeSIM travel/data eSIM plans for a country. Returns plan name, data amount, validity days, USD price, and package code. Pass a 2-letter ISO country code (e.g. GB, US, TR, JP). Omit country to get popular/featured plans.
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | – | 2-letter ISO country code, e.g. GB, US, TR, JP. Optional. |
| limit | integer | – | Max plans to return (1-50). Default 20. |
No output schema declared.
No examples provided.
What is the com.buyukesim/mcp server?
com.buyukesim/mcp is listed in the public MCP registry as com.buyukesim/mcp. No-logs VPN, real UK +44 number eSIMs and travel-data eSIMs, bought with crypto. No KYC, no account. This page covers its hosted endpoint (https://buyukesim.com/mcp).
Is the com.buyukesim/mcp server safe to use?
com.buyukesim/mcp scores 81 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the com.buyukesim/mcp server expose?
com.buyukesim/mcp exposes 21 tools: search_esim_plans, list_covered_countries, get_uk_number_info, list_vpn_plans, get_payment_and_delivery_times, and 16 more. Their descriptions and schemas cost roughly 2,628 tokens of context every time the server is loaded.
Does the com.buyukesim/mcp server require authentication?
No. We connected to com.buyukesim/mcp without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the com.buyukesim/mcp server still maintained?
com.buyukesim/mcp is still listed as active in the MCP registry. We last reached this channel on 22 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.