com.candidcost/mcp
REMOTE · CANDIDCOST.COM · SCANNED AUG 3
Cited, receipt-backed US home-buying data & calculators — education-only, every number sourced.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security80
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability68
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2004 tokens (~200/item across 10 items; 10 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
- Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · candidcost.com
claude mcp add --transport http com-candidcost-mcp https://candidcost.com/api/mcp
[mcp_servers.com-candidcost-mcp] url = "https://candidcost.com/api/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-candidcost-mcp": {
"type": "remote",
"url": "https://candidcost.com/api/mcp",
"enabled": true
}
}
} openclaw mcp add com-candidcost-mcp --url https://candidcost.com/api/mcp --transport streamable-http
mcp_servers:
com-candidcost-mcp:
url: "https://candidcost.com/api/mcp" {
"mcpServers": {
"com-candidcost-mcp": {
"type": "http",
"url": "https://candidcost.com/api/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.
- 1 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.
- 31 Jul 26 +3
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.
- 29 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.
- 27 Jul 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 67
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://candidcost.com/api/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=*.candidcost.com | CN=YR1,O=Let's Encrypt,C=US | 6 Jul 2026 | 4 Oct 2026 | RSA 2048 | SHA256-RSA | 58ed967ab4c622c8dd7733a88213993dc9b |
| SANs: *.candidcost.com, candidcost.com | ||||||
| CN=YR1,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | a20253f15f2691c05dc1ce13b9bcca4e |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
DNSSEC insecure
Validation of candidcost.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| candidcost.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000 |
| content-security-policy | frame-ancestors 'self' |
| x-frame-options | SAMEORIGIN |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://candidcost.com/api/mcp | Verified | 200 | |
| http (plaintext) | http://candidcost.com/api/mcp | HTTPS enforced | 308 | https://candidcost.com/api/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
affordability_estimate ~226
Compute front-end (housing) and back-end (total debt) DTI budgets from income and debts, and the home price implied by the binding limit. Reports the standard 28/36 thresholds without ever telling the user what they "can afford". Dollar inputs are US dollars; money in the response is integer cents.
| Name | Type | Req | Description |
|---|---|---|---|
| backEndLimitPct | number | — | Total DTI ceiling percent (default 36) |
| downPayment | number | — | Down payment available, US dollars |
| frontEndLimitPct | number | — | Housing DTI ceiling percent (default 28) |
| grossMonthlyIncome | number | yes | Gross monthly income, US dollars |
| insuranceAnnual | number | — | Annual homeowners insurance premium, US dollars |
| monthlyDebts | number | — | Recurring monthly debt payments (cards, autos, student loans), US dollars |
| propertyTaxRatePct | number | — | Annual property tax rate, % of value |
| rateAnnualPct | number | — | Annual interest rate percent |
| termYears | integer | — | Loan term in years (default 30) |
No output schema declared.
No examples provided.
benchmark_rates ~52
Return the latest benchmark mortgage rates (e.g. 30-year and 15-year fixed) from the Federal Reserve (FRED), each with its observation date and ledger receipt. Rates are fixed-precision percent strings.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
decode_loan_estimate_fee ~88
Classify a mortgage Loan Estimate fee by CFPB section and control class (set by lender, shoppable, third-party, government, or prepaid), with a plain-language explanation and an educational question a buyer could ask. Omit "fee" to list the full catalog.
| Name | Type | Req | Description |
|---|---|---|---|
| fee | string | — | Fee name or keyword, e.g. "origination", "title" |
No output schema declared.
No examples provided.
fee_benchmarks ~150
Return closing-cost and rate-spread percentile distributions (p25/p50/p75 + mean) for a US state, computed from the row-level CFPB HMDA LAR for originated, first-lien, home-purchase loans. Cells with fewer than 25 records are suppressed. Dollar metrics are integer cents (…Cents); percent metrics are fixed-precision strings (…Pct). Each distribution carries a ledger receipt hash for verification.
| Name | Type | Req | Description |
|---|---|---|---|
| metric | string | — | One of: total_loan_costs, origination_charges, rate_spread, interest_rate. Omit to return all metrics. |
| state | string | yes | Two-letter US state code, e.g. "MA" |
No output schema declared.
No examples provided.
payment_shock_estimate ~250
Estimate why a mortgage payment often jumps in year two: escrow at closing is sized from the seller's current tax bill, but the county reassesses at your purchase price, and RESPA spreads the resulting escrow shortage over 12 months. Given the purchase price, the seller's current annual tax (from the listing), a state (or county FIPS) for the reassessment rate, and insurance, returns the year-1 escrow, the year-2 ongoing escrow, the temporary catch-up peak, and the jump. Money is integer cents. This decomposes the mechanics; it is not a prediction of your specific bill.
| Name | Type | Req | Description |
|---|---|---|---|
| county | string | — | 5-digit county FIPS; its Census effective rate takes priority over the state rate |
| insuranceAnnual | number | — | Annual homeowners insurance, US dollars |
| purchasePrice | number | yes | Purchase price in US dollars |
| reassessRatePct | number | — | Effective annual property-tax rate at reassessment, %. Overrides county/state. |
| sellersCurrentAnnualTax | number | yes | Seller's current annual property tax in US dollars (from the listing) |
| state | string | — | Two-letter US state code for the reassessment rate |
No output schema declared.
No examples provided.
pressure_check ~249
Decompose the tradeoff a rushed buyer faces: the earnest money at risk by walking away versus what overpaying to "win" costs over the life of the loan. Given the earnest money at risk, the overpay amount over your walk-away price, down-payment percent, rate, and term, returns the cash and financed shares of the overpay, the extra monthly P&I, the lifetime cost of overpaying, and its ratio to the earnest money. Money is integer cents. Educational decomposition — it names the two numbers so they can be compared; it never tells the user to walk or stay.
| Name | Type | Req | Description |
|---|---|---|---|
| downPaymentPct | number | — | Down payment as a percent of price (0–100); splits the overpay into cash-at-close vs. financed |
| earnestMoney | number | yes | Earnest money at risk if you walk away after removing contingencies, US dollars |
| overpay | number | yes | How much over your walk-away price the pressure would push you to pay, US dollars |
| rateAnnualPct | number | — | Annual interest rate percent, e.g. 6.5 |
| termYears | integer | — | Loan term in years (default 30) |
No output schema declared.
No examples provided.
rent_vs_buy_estimate ~368
Compare the net cost of owning against renting over a holding period and find the break-even year. Owning nets upfront cash and recurring carrying costs against sale proceeds (appreciated value − selling costs − remaining loan); renting nets rent paid against the investment gain on the cash a buyer would tie up. Dollar inputs are US dollars; money in the response is integer cents. Appreciation, rent growth, and investment return are user-set assumptions. Tax deductions are excluded (documented simplification). Educational decomposition — it reports both net costs and the break-even year; it never says rent or buy.
| Name | Type | Req | Description |
|---|---|---|---|
| annualAppreciationPct | number | — | Assumed annual home-price appreciation percent |
| annualRentIncreasePct | number | — | Assumed annual rent increase percent |
| closingCostPct | number | — | Upfront buy-side closing costs, % of price |
| downPaymentPct | number | — | Down payment as a percent of price |
| hoaMonthly | number | — | Monthly HOA dues, US dollars |
| holdingYears | integer | — | How many years you plan to stay before selling |
| homePrice | number | yes | Home price in US dollars |
| insuranceAnnual | number | — | Annual homeowners insurance, US dollars |
| investmentReturnPct | number | — | Assumed annual return a renter earns on invested cash percent |
| maintenanceRatePct | number | — | Annual maintenance reserve, % of home value |
| monthlyRent | number | yes | Comparable monthly rent in US dollars |
| propertyTaxRatePct | number | — | Annual property tax rate, % of value |
| rateAnnualPct | number | — | Annual interest rate percent |
| sellingCostPct | number | — | Selling costs at exit, % of future value |
| termYears | integer | — | Loan term in years |
No output schema declared.
No examples provided.
search_dpa_programs ~95
Find down payment assistance (DPA) programs by US state and/or buyer type. Includes national programs. Each result links to its official government source and carries a ledger receipt and last-verified date.
| Name | Type | Req | Description |
|---|---|---|---|
| buyer | string | — | Buyer type filter, e.g. "first-time", "veteran", "rural", "teacher" |
| state | string | — | Two-letter US state code to filter by |
No output schema declared.
No examples provided.
true_cost_estimate ~384
Estimate the full monthly cost of owning a home — principal & interest, property tax, insurance, PMI, HOA, and maintenance — and contrast it with the lender "approval" payment (PITI+PMI) to reveal the hidden monthly gap. Dollar inputs are US dollars; all money in the response is integer cents; rates are fixed-precision percent strings.
| Name | Type | Req | Description |
|---|---|---|---|
| county | string | — | 5-digit county FIPS code. When provided and its Census county rate is available, it takes priority over the state rate (more accurate). |
| downPaymentPct | number | — | Down payment as a percent of price (0–100) |
| hoaMonthly | number | — | Monthly HOA dues, US dollars |
| homePrice | number | yes | Home price in US dollars |
| homeYearBuilt | integer | — | Year the home was built. Scales the maintenance reserve by age band: ×1.5 pre-1980, ×1.2 1980–2005, ×1.0 2006+. |
| insuranceAnnual | number | — | Annual homeowners insurance premium, US dollars |
| maintenanceRatePct | number | — | Annual maintenance reserve, % of home value (baseline before age adjustment) |
| pmiAnnualRatePct | number | — | Annual PMI rate, % of loan, applied while LTV > 80% |
| propertyTaxRatePct | number | — | Annual property tax rate, % of value. Overrides county/state-derived rates when supplied. |
| rateAnnualPct | number | — | Annual interest rate percent, e.g. 6.5 |
| state | string | — | Two-letter US state code (e.g. "NJ"). When provided and propertyTaxRatePct is omitted, the Census ACS effective property-tax rate for that state is used. |
| termYears | integer | — | Loan term in years (default 30) |
No output schema declared.
No examples provided.
verify_receipt ~73
Verify a CandidCost ledger receipt hash (full sha256 or short "3f9a…c21e" form). Confirms the receipt exists and that its dataset hash chain is intact, proving the underlying data has not been altered since ingestion.
| Name | Type | Req | Description |
|---|---|---|---|
| hash | string | yes | The receipt content hash to verify |
No output schema declared.
No examples provided.