# Duck Tax (remote · ducktax.com)

Check micro-entity company accounts: raw figures in, validated balance sheet and deadlines out.

- Trust score: 69/100 (medium)
- Change this week: +3
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-28

## Components

- remote · `ducktax.com`: 69/100 (this document), [markdown](https://verifymcp.io/servers/com-ducktax-ducktax/api-mcp.md), [page](https://verifymcp.io/servers/com-ducktax-ducktax/api-mcp)

## Channel facts

- Endpoint: `https://ducktax.com/api/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.0.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-28.

- **Endpoint Security**: 63/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation not fully verified: no authorisation is required to call this server, and 20 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe.
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 74/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 3012 tokens (~150/item across 20 items; 20 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 40/100
  - Stability observed for 12 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 99/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 98% of tool parameters carry a description.
- **Tool Safety**: 75/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - 0 of 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "delete_filing" implies "delete" and declares no destructiveHint at all, which the MCP spec reads as destructive by default.
  - An AI judge read all 21 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 60/100
  - Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28.

## Install

### How do I install the Duck Tax MCP server?

Duck Tax is a hosted endpoint at https://ducktax.com/api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http com-ducktax-ducktax 'https://ducktax.com/api/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "com-ducktax-ducktax": {
      "url": "https://ducktax.com/api/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "com-ducktax-ducktax": {
      "type": "http",
      "url": "https://ducktax.com/api/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.com-ducktax-ducktax]
url = "https://ducktax.com/api/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-ducktax-ducktax": {
      "type": "remote",
      "url": "https://ducktax.com/api/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add com-ducktax-ducktax --url 'https://ducktax.com/api/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  com-ducktax-ducktax:
    url: "https://ducktax.com/api/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "com-ducktax-ducktax": {
      "Transport": "http",
      "Url": "https://ducktax.com/api/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add com-ducktax-ducktax -t streamable-http -u 'https://ducktax.com/api/mcp'
```

### Other

```json
{
  "mcpServers": {
    "com-ducktax-ducktax": {
      "type": "http",
      "url": "https://ducktax.com/api/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-28 (score 69, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-27 (score 69, +1)

No change was recorded against any check on this day. Stability & Change Management went from 33 to 37. That category is still filling its 30-day observation window: 10 days of observed history at the previous scan, 11 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-25 (score 68, +1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-23 (score 67, +1)

No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-21 (score 66, +1)

No change was recorded against any check on this day. Stability & Change Management went from 13 to 17. That category is still filling its 30-day observation window: 4 days of observed history at the previous scan, 5 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-19 (score 65, +1)

No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-17 (score 64, +1)

- [functional improvement] Stability: unverified → 0.03

### 2026-09-16 (score 63)

First indexed and scored.

## MCP tools (20)

### `check_accounts` (~241 tokens)

Derive a small-company balance sheet (micro-entity, in UK terms) from raw figures and validate it. Returns the derived sheet for the current and prior year, the figures the authority would reject (negatives where it wants a positive, share capital left at nil), and whether they are complete enough to hand to a filing product. It does NOT check that the sheet balances and cannot: retained earnings is derived as the balancing figure, so both sides always agree. Do not tell anybody their sheet was checked for internal consistency. Free and instant: call it after every change to the figures. All money in major units (pounds not pence, dollars not cents). Pass lastFiledAs from lookup_company and it also warns when figures showing activity are about to be filed dormant again.

Input parameters:

- `figures` (object, required): The figures behind a small-company balance sheet. ALL amounts in major units.
- `jurisdiction` (string, required): ISO country code. GB is the only jurisdiction with full support.
- `lastFiledAs` (string): What the last accounts were filed as, straight from lookup_company's company.lastAccountsType. Pass it through; do not guess it.

### `dormant_figures` (~85 tokens)

The complete set of figures for a dormant company: share capital, the matching cash, and zeros everywhere else. The register says when the last accounts were filed dormant, and for those companies this collapses the whole form to one call. Amounts in major units.

Input parameters:

- `shareCapital` (number, required): Issued share capital in major units. 1 is the overwhelmingly common figure.

### `totals_to_figures` (~104 tokens)

Turn categorised bank-statement totals into balance sheet figures, applying the rules that stop an import lying: only income categories reach turnover, only expense categories reach operating costs, and the owner topping up the account is never sales. Totals are signed major units per category code; get codes from categorise_transactions.

Input parameters:

- `totals` (object, required): Signed totals per category code, major units, e.g. {"sales": 60000, "software": -1200}.

### `late_filing_penalty` (~78 tokens)

What missing a Companies House accounts deadline costs. Given the due date, returns days remaining or overdue, the penalty band already incurred, and what the next band costs, the number that makes someone act today. UK private companies only.

Input parameters:

- `accountsDue` (string, required): The accounts due date, from lookup_company or a Companies House letter.

### `list_jurisdictions` (~59 tokens)

The countries this server knows about and what it can actually do in each: which have a real accounts engine, which registers can be searched or looked up, the currency, and the identifiers each jurisdiction files under. Call this first when unsure.

### `sample_accounts` (~56 tokens)

A real worked example: nil turnover, a director loan, a near-empty bank account, the simplest accounts the UK regime permits. Use it to demonstrate check_accounts or as a template for a first-year company. Amounts in major units.

### `lookup_company` (~140 tokens)

Look a company up on its public register (Companies House for GB, ABN Lookup for AU) by its registered number. Returns the full public record: name, status, registered office, officers, SIC codes, accounting period, plus both filing deadlines with days remaining and the late-filing penalty already incurred if overdue. Rate limited and quota-charged; cached results are free. Find the number first with search_companies.

Input parameters:

- `companyNumber` (string, required): The register identifier: GB company number (e.g. 15379140) or AU ABN.
- `jurisdiction` (string, required): ISO country code. Register access exists for GB and AU.

### `search_companies` (~88 tokens)

Find a company by name on its public register and get back its registered number, status and address. This is how you reach lookup_company when the person only knows the name. Free of the daily quota; lightly rate limited.

Input parameters:

- `jurisdiction` (string, required): ISO country code. Register access exists for GB and AU.
- `query` (string, required): The company name, as someone would say it.

### `get_prior_year_figures` (~94 tokens)

Read last year's figures out of the company's last filed accounts at Companies House, ready to drop into the *Prior fields of check_accounts or save_filing. Saves typing seven numbers from a PDF and gets the comparatives exactly as filed. GB only, and only when the last accounts were filed digitally. Quota-charged; cached results are free.

Input parameters:

- `companyNumber` (string, required): The GB company number.

### `explain_accounts` (~114 tokens)

A plain-English reading of a set of figures, written for a director who is not an accountant: what the derived balance sheet says about the company and anything that needs attention before filing. Only the derived sheet is sent to the model, no company name or number. Quota-charged; identical figures are answered from cache free.

Input parameters:

- `figures` (object, required): The figures behind a small-company balance sheet. ALL amounts in major units.
- `jurisdiction` (string, required): ISO country code. Register access exists for GB and AU.

### `categorise_transactions` (~141 tokens)

Categorise bank-statement transaction descriptions into the fixed vocabulary this product maps to balance sheet lines (sales, software, owner-in, …). Send description strings only, never amounts or dates. Sum the amounts per returned category yourself, then call totals_to_figures. One statement import is one quota unit; previously seen descriptions are answered from a shared cache free.

Input parameters:

- `descriptions` (array, required): The raw description strings, one per transaction.
- `tradingType` (string, required): What the company does, to resolve ambiguous merchants. One of: software, consulting, creative, retail, construction, property, hospitality, other. lookup_company suggests one from the SIC codes.

### `check_filing_extension` (~324 tokens)

Whether a company can still apply to its registrar for more time to file, how many days are left to apply, and what being late costs if that window is missed. This is usually the most useful thing to tell somebody who has just found a deadline: applying is free, takes about 15 minutes, and has to be done BEFORE the deadline it extends, so the option expires on the same day the penalty starts. Returns nextAction first. It PREPARES an application and can never submit one: the application is made by a director on the registrar’s own service, which this tool links to. It does not file accounts. Give a company number to read the deadline off the register (quota-charged, cached results free), or give the dates yourself and it costs nothing.

Input parameters:

- `alreadyExtended` (boolean, required): True if this deadline has been extended once already. Do not guess it, ask.
- `companyNumber` (string): Read the deadline and period end off the register. Omit if you supply the dates.
- `filing` (string, required): Which deadline. Only accounts can be extended; ask about the other and it says so.
- `filingDeadline` (string): The normal filing deadline, if you already have it. Skips the register request.
- `jurisdiction` (string, required): ISO country code. Register access exists for GB and AU.
- `periodEnd` (string): The accounting reference date. Bounds how much extra time could be granted.
- `today` (string): Defaults to the server's date. Supply it to test a boundary.

### `draft_extension_reason` (~240 tokens)

Turn a short factual account of what went wrong into the reason text for an application for more time to file accounts, framed in the terms the registrar actually applies. It uses only the facts you give it: it will not invent circumstances, and where something is missing it leaves a bracketed placeholder rather than filling it in. The person must check every sentence before using it, because they are certifying it to the registrar. Ask them what happened, do not supply it yourself. This tool does not submit the application and does not file accounts. Quota-charged as an explanation; identical input is answered from cache free.

Input parameters:

- `circumstances` (string, required): What actually happened, in the person's own words, with dates. Facts only. If you do not have this, ask them for it rather than writing it.
- `expectedReadyBy` (string): When they expect the accounts to be ready, if they have said. Never estimate it.
- `jurisdiction` (string, required): ISO country code. Register access exists for GB and AU.
- `whyItStoppedTheAccounts` (string): How the event stopped the accounts being prepared, if they have said.

### `list_saved_filings` (~51 tokens)

The user's saved filings, most recently touched first, with every figure in major units. This is the same list the website dashboard shows. Start here when asked about "my accounts" or "my company".

### `save_filing` (~224 tokens)

Save a set of figures to the user's account, or update a saved one by passing its id from list_saved_filings. Figures in major units. The filing is saved even when validation finds problems, because a work in progress is worth keeping, and the problems come back in the response so you can raise them.

Input parameters:

- `categoryTotals` (object): Where the figures came from, when a bank statement fed them: signed major-unit totals per category code from categorise_transactions.
- `figures` (object, required): The figures behind a small-company balance sheet. ALL amounts in major units.
- `id` (integer): Omit to create. Pass an id from list_saved_filings to update that filing.
- `identifiers` (object): Register identifiers, e.g. {"companyNumber": "15379140"}. Tax references (UTR, EIN, TFN) are never stored and are silently dropped.
- `jurisdiction` (string, required)
- `label` (string): A name for the filing, e.g. "SparkGames year to 31 Dec 2025".

### `delete_filing` (~48 tokens)

Delete one saved filing by id, permanently. Confirm with the person before calling this; there is no undo and no trash.

Input parameters:

- `id` (integer, required): The id from list_saved_filings.

### `track_company_deadlines` (~289 tokens)

Watch a company by its register number and get reminded before its filing deadlines. Which channels are actually available depends on the server: the reply reports what will really be sent, and it can be nothing at all, so read it rather than assuming. No saved filing is needed: this is for the deadline itself, which matters months before any figures exist. Reminders go out on a ladder of days before the deadline (default 90, 60, 30, 14, 7, 1), and each one states the company, the deadline, the date, the days remaining and the penalty for missing it. Calling this again updates the settings and un-mutes a company that was untracked.

Input parameters:

- `companyNumber` (string, required): The register identifier: GB company number (e.g. 15379140) or AU ABN.
- `email` (boolean, required): Send reminders to the account email address.
- `jurisdiction` (string, required): ISO country code. Deadline reminders exist where the register publishes deadlines.
- `push` (boolean, required): Send reminders as web push to signed-in browsers.
- `remindDaysBefore` (array): Days before the deadline to warn, e.g. [60, 14, 1]. Omit to use this server’s default ladder. Only the tightest rung that applies is ever sent, so a long ladder does not mean a burst of messages.

### `list_tracked_companies` (~53 tokens)

Every company this user gets deadline reminders about, including the ones implied by their saved filings. Shows the next accounts deadline and days remaining where a register record is already cached. Free: this never contacts a register.

### `untrack_company_deadlines` (~99 tokens)

Stop sending deadline reminders about a company. This mutes rather than forgets, which is the only thing that holds: a company implied by a saved filing would otherwise be re-added by the next scan. track_company_deadlines un-mutes it again.

Input parameters:

- `companyNumber` (string, required): The register identifier, as in track_company_deadlines.
- `jurisdiction` (string, required): ISO country code. Deadline reminders exist where the register publishes deadlines.

### `server_status` (~59 tokens)

What this deployment can actually do right now: which integrations are configured, whether your token is valid, and how much of each daily quota you have left. Call it when a tool refuses and you want to know whether the feature is off or used up.

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/com-ducktax-ducktax/api-mcp#diagnostics

## Score history

- 2026-09-28: 69
- 2026-09-27: 69
- 2026-09-26: 68
- 2026-09-25: 68
- 2026-09-24: 67
- 2026-09-23: 67
- 2026-09-22: 66
- 2026-09-21: 66
- 2026-09-20: 65
- 2026-09-19: 65
- 2026-09-18: 64
- 2026-09-17: 64
- 2026-09-16: 63

## Common questions

### What is the Duck Tax MCP server?

Duck Tax is an MCP server listed in the public MCP registry as com.ducktax/ducktax. Check micro-entity company accounts: raw figures in, validated balance sheet and deadlines out. This page covers its hosted endpoint (https://ducktax.com/api/mcp).

### Is the Duck Tax MCP server safe to use?

Duck Tax scores 69 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Duck Tax MCP server expose?

Duck Tax exposes 20 tools: check_accounts, dormant_figures, totals_to_figures, late_filing_penalty, list_jurisdictions, and 15 more. Their descriptions and schemas cost roughly 2,587 tokens of context every time the server is loaded.

### Does the Duck Tax MCP server require authentication?

No. We connected to Duck Tax without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the Duck Tax MCP server still maintained?

Duck Tax is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://ducktax.com/api/mcp
- Website: https://ducktax.com/
- Changelog RSS feed: https://verifymcp.io/servers/com-ducktax-ducktax/api-mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/com-ducktax-ducktax/api-mcp.json
- HTML version of this page: https://verifymcp.io/servers/com-ducktax-ducktax/api-mcp
