Duo Data Utilities
REMOTE · API.DUOLEADS.COM · SCANNED SEP 29
31 pay-per-call data utilities (IDs, time, text, codes, geo, chain, ref, numbers) via x402.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS enforcement could not be verified: the plaintext port answered with HTTP 405, which proves neither a plaintext path nor enforcement. View diagnostics → Unverified
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability66
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 8100 tokens (~261/item across 31 items; 31 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 31 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 31 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Unverified: 1 category
A category scored 0 because we could not verify it: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.
How do I install the Duo Data Utilities MCP server?
Duo Data Utilities is a hosted endpoint at https://api.duoleads.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · api.duoleads.com
claude mcp add --transport http com-duoleads-api-data-utilities 'https://api.duoleads.com/mcp'
{
"mcpServers": {
"com-duoleads-api-data-utilities": {
"url": "https://api.duoleads.com/mcp"
}
}
} {
"servers": {
"com-duoleads-api-data-utilities": {
"type": "http",
"url": "https://api.duoleads.com/mcp"
}
}
} [mcp_servers.com-duoleads-api-data-utilities] url = "https://api.duoleads.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-duoleads-api-data-utilities": {
"type": "remote",
"url": "https://api.duoleads.com/mcp",
"enabled": true
}
}
} openclaw mcp add com-duoleads-api-data-utilities --url 'https://api.duoleads.com/mcp' --transport streamable-http
mcp_servers:
com-duoleads-api-data-utilities:
url: "https://api.duoleads.com/mcp" {
"McpServers": {
"com-duoleads-api-data-utilities": {
"Transport": "http",
"Url": "https://api.duoleads.com/mcp"
}
}
} assistant mcp add com-duoleads-api-data-utilities -t streamable-http -u 'https://api.duoleads.com/mcp'
{
"mcpServers": {
"com-duoleads-api-data-utilities": {
"type": "http",
"url": "https://api.duoleads.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 29 Sept 26 65
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 29 Sept 2026 · Probed https://api.duoleads.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=duoleads.com | CN=WE1,O=Google Trust Services,C=US | 28 Sept 2026 | 27 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | 3b18e748c305c1fe0ecc93b3b78dec72 |
| SANs: duoleads.com, api.duoleads.com, *.api.duoleads.com | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of api.duoleads.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| duoleads.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://api.duoleads.com/mcp | Verified | 200 | |
| http (plaintext) | http://api.duoleads.com/mcp | Inconclusive | 405 |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
chain_address Blockchain address format detection and checksum validation ~232
Identify which blockchain an address belongs to and validate its encoding: EVM EIP-55 checksum, Bitcoin base58check and bech32/bech32m with witness version, Solana base58 and on-curve check, Cosmos bech32 with its HRP, Tron, XRP, Litecoin, Dogecoin, Cardano, Polkadot SS58 and Algorand. Returns the detected chains with a confidence note, the checksummed form for EVM addresses, and the exact reason an address failed. Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | Address to identify and validate. Accepted: at most 128 characters. |
| chain_id | string | – | EVM chain id; enables EIP-1191 chain-salted checksum validation. Accepted: a positive integer chain id. |
| expect | string | – | Restrict the check to one chain id. Accepted: evm, bitcoin, solana, cosmos, tron, xrp, cardano, polkadot, algorand, litecoin, dogecoin. |
No output schema declared.
No examples provided.
chain_selector Keccak-256 hash, 4-byte function selector and 32-byte event topic from a Solidity signature ~220
Compute the Keccak-256 hash of a Solidity function or event signature and derive the 4-byte function selector and the 32-byte event topic. Normalises the signature first — strips parameter names, expands uint to uint256 and the other aliases, flattens tuples — so a signature copied from source code produces the same selector as the canonical form. Also hashes arbitrary text or hex bytes with Keccak-256. Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| data | string | – | Alternative to signature: raw data to Keccak-256 hash. Accepted: at most 8192 characters. |
| encoding | string | – | Encoding of data: utf8 (default) or hex. Accepted: utf8, hex. |
| kind | string | – | function (default), event or error. Accepted: function, event, error. |
| signature | string | – | Solidity function, event or error signature, e.g. transfer(address to, uint amount). Accepted: at most 1024 characters. |
No output schema declared.
No examples provided.
code_hash SHA-2, SHA-3, BLAKE2 and HMAC digests of supplied text or base64 bytes ~359
Compute a cryptographic digest of supplied data: SHA-256, SHA-384, SHA-512, SHA-1, SHA3-256, SHA3-512, Keccak-256, BLAKE2b-256 and BLAKE2b-512, plus HMAC with any of them. Input is UTF-8 text, base64 or hex bytes; output is hex, base64, base64url or base32. Returns the digest, the byte length of the input, and the exact algorithm identifier used. Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| algo | string | yes | Digest algorithm. Accepted: sha256, sha384, sha512, sha1, sha3-256, sha3-512, keccak256, blake2b-256, blake2b-512. |
| data | string | yes | Input data, interpreted per encoding. At most 8192 characters. An empty value hashes the empty string. Accepted: at most 8192 characters. |
| encoding | string | – | Encoding of data: utf8 (default), base64, base64url or hex. Accepted: utf8, base64, base64url, hex. |
| hmac_key | string | – | If present, computes HMAC with this key. Accepted: at most 512 characters. |
| hmac_key_encoding | string | – | Encoding of hmac_key, as encoding. Accepted: utf8, base64, base64url, hex. |
| out | string | – | Digest output encoding: hex (default), base64, base64url or base32. Accepted: hex, base64, base64url, base32. |
No output schema declared.
No examples provided.
code_idn IDNA2008 / punycode conversion and domain-label validation ~250
Convert internationalised domain names between Unicode and ASCII punycode in either direction, label by label, and validate each label against IDNA2008: length, leading and trailing hyphens, the hyphen-hyphen rule at positions 3 and 4, disallowed code points and bidirectional rules. Returns both forms, the per-label breakdown and the first rule violated. Strict mode is IDNA2008 (UTS 46 non-transitional); it may reject names /v1/code/url displays. Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain name in Unicode or punycode form. Accepted: at most 512 characters. |
| strict | string | – | true (default) applies IDNA2008 strictly; false uses UTS 46 transitional (IDNA2003-compatible) processing, which maps e.g. ß to ss; current browsers and /v1/code/url use non-transitional processing,… |
| to | string | – | ascii, unicode or both (default). Accepted: ascii, unicode, both. |
No output schema declared.
No examples provided.
code_jwt JWT structural decode: header, claims, expiry state — no signature verification ~189
Decode a JSON Web Token without verifying it: returns the header, the claims, the signature length and algorithm, and a computed view of the time claims — whether exp has passed, whether nbf is in the future, and the remaining lifetime in seconds against a supplied or current instant. Reports structural problems such as a missing part, invalid base64url or an alg of none. It does not and cannot verify the signature; do not use it to decide trust. Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| at | string | – | Instant to evaluate exp/nbf against: RFC 3339 or epoch seconds. Default now. Accepted: RFC 3339 timestamp or integer epoch. |
| token | string | yes | The JWT to decode (not verified). At most 8192 characters. Accepted: at most 8192 characters. |
No output schema declared.
No examples provided.
code_semver Semantic-version parse, compare, and range satisfaction ~255
Parse a semantic version into major, minor, patch, prerelease and build parts; compare two versions by precedence including prerelease ordering; or test whether a version satisfies a range expression using caret, tilde, hyphen, x-ranges and comparator sets. Returns the parsed structure, the comparison result and the reason a range did not match. Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| a | string | – | First version for op=compare. Accepted: at most 256 characters. |
| b | string | – | Second version for op=compare. Accepted: at most 256 characters. |
| op | string | – | parse (default), compare, satisfies or sort. Accepted: parse, compare, satisfies, sort. |
| range | string | – | Range expression for op=satisfies, e.g. ^1.2.0. Accepted: at most 256 characters. |
| version | string | – | Version to parse (op=parse) or test (op=satisfies). Accepted: at most 256 characters. |
| versions | string | – | Comma-separated versions for op=sort, at most 100. Accepted: at most 100 versions. |
No output schema declared.
No examples provided.
code_url URL parse, canonicalise, and registrable-domain (eTLD+1) extraction ~194
Parse and canonicalise a URL, and extract its registrable domain using the Public Suffix List — the part an agent needs to decide whether two URLs belong to the same owner. Returns scheme, host, port, path, decoded query parameters and fragment, the public suffix, the registrable domain (eTLD+1), the subdomain, whether the suffix is an ICANN or a private entry, plus a canonical form with default port, dot-segments and percent-encoding normalised. unicode_host uses WHATWG/UTS 46 (non-strict). Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| base | string | – | Base URL to resolve url against as a relative reference. Accepted: an absolute URL. |
| url | string | yes | Absolute URL, or a bare hostname (https:// assumed). Accepted: an absolute URL, or a hostname. |
No output schema declared.
No examples provided.
geo_distance Geodesic distance, initial bearing and destination point on WGS-84 ~325
Distance and direction between WGS-84 coordinates: geodesic distance by Vincenty with a haversine fallback, initial and final bearing, the midpoint, and the destination point reached from a start point on a given bearing and distance. Also computes the cumulative length of a supplied coordinate path. Results in metres, kilometres, nautical miles and miles. Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| bearing | string | – | Initial bearing in degrees for op=destination. Accepted: number 0-360. |
| distance_m | string | – | Distance in metres for op=destination. Accepted: a number >= 0. |
| lat1 | string | – | Start latitude. Accepted: a number between -90 and 90. |
| lat2 | string | – | End latitude. Accepted: a number between -90 and 90. |
| lon1 | string | – | Start longitude. Accepted: a number between -180 and 180. |
| lon2 | string | – | End longitude. Accepted: a number between -180 and 180. |
| method | string | – | vincenty (default, WGS-84) or haversine. Accepted: vincenty, haversine. |
| op | string | – | distance (default), destination, midpoint or path. Accepted: distance, destination, midpoint, path. |
| path | string | – | Comma-separated lat,lon pairs for op=path, at most 200 points. Accepted: comma-separated lat,lon pairs, at most 200 points. |
No output schema declared.
No examples provided.
geo_geohash Geohash encode and decode with neighbour cells ~281
Encode a WGS-84 latitude and longitude to a geohash at a chosen precision, or decode a geohash back to its bounding box, centre point and error bounds in metres. Encoding also returns the eight neighbouring cells, which is what a caller needs to do proximity search over a geohash-indexed store without a spatial database. Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| geohash | string | – | Geohash to decode, 1-12 characters. Required when op=decode. Accepted: base32 geohash alphabet, excluding a, i, l and o. |
| lat | string | – | WGS-84 latitude, -90 to 90. Required when op=encode. Accepted: a number between -90 and 90. |
| lon | string | – | WGS-84 longitude, -180 to 180. Required when op=encode. Accepted: a number between -180 and 180. |
| op | string | – | encode (default): lat/lon to geohash. decode: geohash to bounding box. Accepted: encode, decode. |
| precision | string | – | Geohash length 1-12, default 9 (about 4.8 m). Accepted: integer 1-12. |
No output schema declared.
No examples provided.
geo_pluscode Open Location Code (plus code) encode and decode ~311
Encode coordinates as an Open Location Code (plus code) at a chosen length, or decode a full code back to its bounding box and centre. Also shortens a full code against a reference coordinate and recovers a shortened code given a reference, which is how plus codes are normally exchanged in text. Returns code length, precision in metres and validity. Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | Plus code for decode, shorten or recover. Accepted: at most 20 characters. |
| lat | string | – | Latitude for op=encode. Accepted: a number between -90 and 90. |
| length | string | – | Code length for op=encode: 2,4,6,8,10 (default),11,12,13,14,15. Accepted: one of 2,4,6,8,10,11,12,13,14,15. |
| lon | string | – | Longitude for op=encode. Accepted: a number between -180 and 180. |
| op | string | – | encode (default), decode, shorten or recover. Accepted: encode, decode, shorten, recover. |
| ref_lat | string | – | Reference latitude for op=shorten/recover. Accepted: a number between -90 and 90. |
| ref_lon | string | – | Reference longitude for op=shorten/recover. Accepted: a number between -180 and 180. |
No output schema declared.
No examples provided.
geo_polygon Point-in-polygon, bounding box, centroid and area on supplied GeoJSON ~255
Geometric predicates on a GeoJSON geometry supplied in the request: point-in-polygon with correct hole handling, bounding box, centroid, signed area in square metres, perimeter length, and ring winding order. Accepts Polygon and MultiPolygon, and a GeoJSON Feature wrapping either. Area and length are geodesic on the WGS-84 ellipsoid, correct at any latitude; containment is planar in lon/lat. Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| geometry | string | yes | URL-encoded GeoJSON Polygon, MultiPolygon or a Feature wrapping one. At most 3072 characters and 2000 coordinate pairs. Accepted: valid GeoJSON. |
| lat | string | – | Point latitude; with lon, runs the containment test. Accepted: a number between -90 and 90. |
| lon | string | – | Point longitude; with lat, runs the containment test. Accepted: a number between -180 and 180. |
| ops | string | – | Comma-separated subset of contains,bbox,centroid,area,perimeter,winding. Default all. Accepted: comma-separated subset of contains, bbox, centroid, area, perimeter, winding. |
No output schema declared.
No examples provided.
id_gs1 GS1 identifier validation: GTIN-8/12/13/14, GLN, SSCC ~232
Validate and convert GS1 identifiers: GTIN-8, GTIN-12 (UPC-A), GTIN-13 (EAN-13), GTIN-14, GLN and SSCC. Returns the check-digit verdict, the computed correct check digit, the GS1 company-prefix boundary where it is derivable, and conversion to GTIN-14. Also computes a missing check digit from a partial code. Structure only, no product database. Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| op | string | – | validate (default), checkdigit (compute the missing final digit) or convert. Accepted: validate, checkdigit, convert. |
| to | string | – | Target format. Required when op=convert. Accepted: gtin8, gtin12, gtin13, gtin14. |
| value | string | yes | GS1 code, digits with optional spaces or hyphens. For op=checkdigit, omit the final digit. Accepted: 8, 12, 13, 14 or 18 digits. |
No output schema declared.
No examples provided.
id_national National identity- and company-number validation, 23 countries ~251
Validate a national identity, tax or company registration number against its country's official checksum rule. Covers 23 countries including NL BSN, ES NIF/NIE/CIF, IT codice fiscale, FR SIREN/SIRET, DE Steuer-ID, BE/PL/CZ national numbers, SE/NO/DK/FI personal numbers, BR CPF/CNPJ, AU ABN/TFN, UK NINo, IE PPS, US NPI/EIN. Structure and check digit only — no registry lookup, no personal data stored. Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | yes | ISO 3166-1 alpha-2 country code, case-insensitive. One of the 23 supported countries. Accepted: one of the 23 supported ISO 3166-1 alpha-2 codes. |
| kind | string | yes | Identifier type for that country, e.g. bsn, nif, cf, cpf. Accepted: an identifier kind supported for the country. |
| value | string | yes | The identifier. Separators (space . - /) are stripped before checking. Accepted: at most 64 characters. |
No output schema declared.
No examples provided.
id_security ISIN, CUSIP, SEDOL and FIGI check-digit validation ~240
Validate the check digit of a financial security identifier: ISIN (ISO 6166), CUSIP, SEDOL and FIGI. Returns the verdict, the computed correct check character, and for an ISIN the issuing country prefix and the embedded NSIN. Also builds an ISIN from a country code plus a 9-character NSIN. Format and checksum only, no security master lookup. Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | – | ISO 3166-1 alpha-2 code or XS. Required when op=build-isin. Accepted: at most 16 characters. |
| nsin | string | – | Exactly 9 alphanumeric characters. Required when op=build-isin. Accepted: exactly 9 alphanumeric characters. |
| op | string | – | validate (default) or build-isin. Accepted: validate, build-isin. |
| value | string | – | ISIN, CUSIP, SEDOL or FIGI to validate. Required when op=validate. Accepted: an alphanumeric security identifier of at most 24 characters. |
No output schema declared.
No examples provided.
num_allocate Split a money amount into shares with no rounding loss ~319
Split a money amount into shares without losing or inventing a cent. Divide evenly into N parts, or by a list of ratios, and the remainder is distributed one minor unit at a time by a named, deterministic rule — largest-remainder, first-wins or last-wins — so the parts always sum exactly to the original. Uses Unicode CLDR minor-unit digits, so zero- and three-decimal currencies work (CLDR differs from ISO 4217 for a few, e.g. IDR, HUF: 0). Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| amount | string | yes | Decimal amount, absolute value below 1e12. Accepted: a decimal amount with absolute value below 1e12. |
| currency | string | yes | ISO 4217 alpha-3 code. Accepted: an ISO 4217 alpha-3 code. |
| parts | string | – | Number of equal parts, 1-1000. One of parts or ratios. Accepted: integer 1-1000. |
| ratios | string | – | Comma-separated non-negative ratios, at most 1000, each with at most 15 integer digits and 15 decimal places. One of parts or ratios. Accepted: comma-separated non-negative numbers, at most 1000. |
| rule | string | – | Remainder rule: largest-remainder (default), first, last or round-robin. Accepted: largest-remainder, first, last, round-robin. |
No output schema declared.
No examples provided.
num_radix Integer conversion between arbitrary numeric bases 2–36 ~264
Convert an integer between any two numeric bases from 2 to 36, with arbitrary precision so values far beyond 2^53 are exact. Accepts an optional sign and common prefixes (0x, 0b, 0o), validates every digit against the source base, and returns the value in the target base, in decimal, and as its bit length and digit count. Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| case | string | – | Digit case for bases above 10: lower (default) or upper. Accepted: lower, upper. |
| from | string | – | Source base 2-36, or auto (default) to read a 0x/0b/0o prefix. Accepted: integer 2-36, or 'auto'. |
| prefix | string | – | Emit 0x/0b/0o where conventional. Default false. Accepted: true or false. |
| to | string | – | Target base 2-36, default 10. Accepted: integer 2-36. |
| value | string | yes | Integer to convert; optional sign and 0x/0b/0o prefix. Accepted: at most 1024 characters. |
No output schema declared.
No examples provided.
num_stats Descriptive statistics and percentiles for a supplied numeric array ~287
Descriptive statistics for a supplied numeric array in one call: count, sum, mean, median, mode, variance and standard deviation with variance and standard deviation honouring ddof (default 1, the sample form; 0 gives the population form) and always-population *_population fields, min, max, range, the quartiles and interquartile range, skewness, kurtosis, and any requested percentiles. Percentiles use a named interpolation method so the result is reproducible rather than implementation-defined. Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| ddof | string | – | Delta degrees of freedom for variance/stdev: 1 (default, sample, n-1) or 0 (population, n). The *_population fields are always population. Accepted: integer 0-1. |
| method | string | – | Percentile interpolation (NumPy/R names): linear (default), nearest, lower, higher, midpoint. Accepted: linear, nearest, lower, higher, midpoint. |
| percentiles | string | – | Comma-separated percentiles 0-100, at most 20. Default 25,50,75. Accepted: numbers between 0 and 100. |
| values | string | yes | Comma-separated finite numbers, at most 500 values. Accepted: comma-separated finite numbers. |
No output schema declared.
No examples provided.
num_words Number spelled out in words, 12 locales, with ordinal and currency forms ~263
Spell a number out in words in English, Dutch, German, French, Spanish, Italian, Portuguese, Polish, Russian, Turkish, Swedish or Japanese, in cardinal, currency or year form, and ordinal form in English, Dutch, German and French. Currency form applies the correct grammatical agreement and the right minor-unit name and count for the supplied ISO 4217 code. Handles negatives and values up to 10^15. Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| case | string | – | lower (default), sentence or title. Accepted: lower, sentence, title. |
| currency | string | – | ISO 4217 code. Required when form=currency. Accepted: an ISO 4217 alpha-3 code. |
| form | string | – | cardinal (default), ordinal, currency or year. Accepted: cardinal, ordinal, currency, year. |
| lang | string | – | Language, ISO 639-1. Default en. Accepted: en, nl, de, fr, es, it, pt, pl, ru, tr, sv, ja. |
| value | string | yes | Integer or decimal, absolute value below 1e15. Accepted: absolute value below 1e15. |
No output schema declared.
No examples provided.
ref_airport Airport lookup by IATA or ICAO code with coordinates and elevation ~269
Look up an airport by IATA or ICAO code and get its name, city, country, ISO 3166-2 region code, WGS-84 coordinates and elevation, or find the nearest airports to a coordinate within a radius. Covers every airport worldwide that holds a three-letter IATA code and scheduled service. Returns the code type that matched and the distance in kilometres for proximity results. Time zones are not included. Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | 3-letter IATA or 4-letter ICAO code, case-insensitive. Accepted: a 3-letter IATA or 4-letter ICAO code. |
| country | string | – | ISO 3166-1 alpha-2 filter. Accepted: an ISO 3166-1 alpha-2 code. |
| limit | string | – | Maximum results 1-25, default 5. Only with near. Accepted: integer 1-25. |
| near | string | – | lat,lon to search around. Accepted: lat,lon. |
| radius_km | string | – | Search radius in km, 1-1000, default 100. Only with near. Accepted: number 1-1000. |
No output schema declared.
No examples provided.
ref_country ISO 3166-1 country record: codes, currency, TLD, UN M49 region ~221
Look up a country or territory by ISO 3166-1 alpha-2, alpha-3 or numeric code, or by name, and get the other codes, the English name, the UN M49 region and sub-region, the currencies in use, and the country-code top-level domain. Names are matched case- and accent-insensitively. Country level only: ISO 3166-2 subdivisions are not included. Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | ISO 3166-1 alpha-2, alpha-3 or numeric code. Accepted: ISO 3166-1 alpha-2, alpha-3 or numeric code. |
| include | string | – | Comma-separated: m49, currency, tld. Default all three. Accepted: comma-separated subset of m49, currency, tld. |
| name | string | – | Substring search on country names, case- and accent-insensitive. Accepted: at most 128 characters. |
No output schema declared.
No examples provided.
ref_currency Currency record (ISO 4217 codes, CLDR minor units and cash rounding) ~209
Look up a currency by ISO 4217 code: its alphabetic and numeric codes, English name, minor-unit exponent, the smallest cash denomination where it differs from the minor unit, and the territories that use it. Returns the correct rounding increment for cash amounts, which is what a caller needs to render or settle a price. This route returns currency facts only and never an exchange rate. Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | ISO 4217 alpha-3 or 3-digit numeric code. Accepted: a 3-letter alphabetic or 3-digit numeric ISO 4217 code. |
| country | string | – | ISO 3166-1 alpha-2; returns the currencies in use there. Accepted: an ISO 3166-1 alpha-2 code. |
| include | string | – | Comma-separated: territories, historic. Default none. Accepted: comma-separated subset of territories, historic. |
No output schema declared.
No examples provided.
ref_nuts NUTS statistical region code lookup for the EU ~334
Look up a NUTS statistical region of the European Union: resolve a NUTS code to its name, country and level, walk up to its parents or down to its children, or search regions by name. Covers all four levels (country, major region, basic region, small region) for the 27 member states and 12 further reporting countries, from the NUTS 2024 classification. Returns the Latin-script and local-language names plus the urbanisation, coastal and mountain typologies. Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | – | NUTS code, 2-5 characters, case-insensitive (level-3 codes may contain letters, e.g. NL32B). Accepted: 2 to 5 characters matching ^[A-Z]{2}[0-9A-Z]{0,3}$. |
| country | string | – | ISO 3166-1 alpha-2 country filter (UK/GB and EL/GR both accepted). Accepted: an ISO 3166-1 alpha-2 code. |
| include | string | – | Comma-separated: parents, children, typology. Default parents,typology. Accepted: comma-separated subset of parents, children, typology. |
| level | string | – | Restrict a name search to one level, 0-3. Accepted: integer 0-3. |
| name | string | – | Substring search on region names, case- and accent-insensitive. Up to 25 matches. Accepted: at most 128 characters. |
No output schema declared.
No examples provided.
text_similarity String distance and phonetic keys: Levenshtein, Jaro-Winkler, Soundex, Metaphone ~221
Compare two strings and return every standard similarity measure in one call: Levenshtein and Damerau-Levenshtein edit distance, normalised similarity, Jaro and Jaro-Winkler, longest common subsequence, Dice coefficient on character bigrams, and the Soundex, Metaphone and NYSIIS phonetic keys of each string. Optional case folding, accent folding and whitespace normalisation before comparison. Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| a | string | yes | First string, at most 512 characters. Accepted: at most 512 characters. |
| b | string | yes | Second string, at most 512 characters. Accepted: at most 512 characters. |
| fold | string | – | Comma-separated folds before comparing: case, accents, space, punct. Default case. Accepted: comma-separated subset of case, accents, space, punct. |
| only | string | – | Comma-separated measure names to compute. Default all. Accepted: comma-separated measure names. |
No output schema declared.
No examples provided.
text_slug Unicode-aware URL slug with transliteration ~253
Turn arbitrary text into a URL-safe slug. Decomposes accents, transliterates German umlauts, Scandinavian and Turkish letters, and the ligatures that lose meaning under plain NFD, lowercases, collapses separators, and truncates on a word boundary. Options for separator character, maximum length and case preservation. Returns the slug plus what was removed. Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| case | string | – | lower (default), preserve or upper. Accepted: lower, preserve, upper. |
| lang | string | – | ISO 639-1 code for locale-sensitive folding (de: ü->ue, tr: dotless i). Default locale-neutral. Accepted: an ISO 639-1 language code. |
| max | string | – | Maximum slug length 1-512, default 96. Truncates at the last complete word. Accepted: integer 1-512. |
| separator | string | – | Separator: - (default), _, . or empty. Accepted: -, _, . or empty. |
| text | string | yes | Text to slugify, at most 2048 characters. Accepted: at most 2048 characters. |
No output schema declared.
No examples provided.
text_transliterate Cyrillic-to-Latin transliteration (ISO 9, BGN/PCGN) ~238
Transliterate Cyrillic text into Latin using a named standard: ISO 9:1995 (one-to-one, with diacritics) or the BGN/PCGN Russian system. Returns the transliteration, the detected source script, the standard actually applied, the fraction of non-ASCII characters that were mapped, and any characters passed through untouched. Other scripts are not supported yet and are rejected with UNSUPPORTED_VALUE. Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| case | string | – | preserve (default), lower or upper. Accepted: preserve, lower, upper. |
| from | string | – | Source script name (cyrillic), or auto (default). Accepted: cyrillic or auto. |
| standard | string | – | Romanisation standard, e.g. iso-9, bgn-pcgn. Default: the first listed for the detected script. Accepted: a romanisation standard supported for the script. |
| text | string | yes | Text to transliterate, at most 2048 characters. Accepted: at most 2048 characters. |
No output schema declared.
No examples provided.
text_unicode Unicode normalisation, script detection and confusable/homoglyph analysis ~204
Analyse a string at the Unicode level: apply NFC, NFD, NFKC or NFKD normalisation, report which normalisation forms it is already in, list the scripts present, and flag confusable and homoglyph characters — Cyrillic а in a Latin word, zero-width joiners, bidirectional overrides, invisible characters. Returns per-character detail for anything suspicious, with code points, names and the ASCII character each one imitates. Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| detail | string | – | summary (default) or full per-code-point detail (capped at 256 entries). Accepted: summary, full. |
| form | string | – | Normalisation form to apply, default nfc. Accepted: nfc, nfd, nfkc or nfkd. |
| text | string | yes | Text to analyse, at most 1024 characters. Accepted: at most 1024 characters. |
No output schema declared.
No examples provided.
time_business-days Business-day arithmetic with a caller-supplied weekend mask and holiday list ~359
Business-day arithmetic with a caller-supplied calendar: add or subtract N working days from a date, or count the working days between two dates. The weekend is specified as a weekday mask so Friday-Saturday and Sunday-only weeks work, and holidays are passed in as an explicit date list, so the answer never depends on a holiday table that can go stale. Returns the result date, the day count, and the first 1,000 skipped dates with the reason each was skipped. Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| days | string | – | Business days to add, -3650 to 3650. Required when op=add. Accepted: integer between -3650 and 3650. |
| from | string | yes | Start date, YYYY-MM-DD. Accepted: a calendar date as YYYY-MM-DD. |
| holidays | string | – | Comma-separated YYYY-MM-DD holiday dates. Accepted: comma-separated YYYY-MM-DD dates, at most 2048 characters. |
| inclusive | string | – | For op=count: start (default, half-open [from, to)), both or neither. Accepted: start, both, neither. |
| op | string | – | add (default) N business days to from, or count business days between from and to. Accepted: add, count. |
| to | string | – | End date YYYY-MM-DD, may precede from. Required when op=count. Accepted: a calendar date as YYYY-MM-DD. |
| weekend | string | – | Comma-separated weekday names or ISO numbers. Default sat,sun. Empty string = no weekend. Accepted: comma-separated weekday names (mon..sun) or ISO numbers 1-7. |
No output schema declared.
No examples provided.
time_calendar Gregorian conversion to Hijri, Hebrew and Japanese-era dates, plus Easter ~271
Convert a Gregorian date to other calendar systems and back: Islamic (both the tabular civil calendar and the Umm al-Qura variant), Hebrew, Japanese imperial era, Republic of China, Buddhist and Persian. Also computes Easter Sunday for a year in both the Gregorian and Julian reckonings. Uses the calendar support built into the runtime, with the algorithm named in every response. Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| date | string | – | Gregorian date YYYY-MM-DD. Required when op=convert. Accepted: a calendar date as YYYY-MM-DD. |
| op | string | – | convert (default) a Gregorian date, or easter for a year. Accepted: convert, easter. |
| rite | string | – | Easter reckoning: western (default) or eastern. Accepted: western, eastern. |
| to | string | – | Comma-separated calendar ids: islamic, islamic-umalqura, hebrew, japanese, roc, buddhist, persian. Default all. Accepted: islamic, islamic-umalqura, hebrew, japanese, roc, buddhist, persian. |
| year | string | – | Year for op=easter, 326-9999. Accepted: integer 326-9999. |
No output schema declared.
No examples provided.
time_dst Next daylight-saving transitions for an IANA time zone ~189
List the daylight-saving transitions for an IANA time zone over a date range: the exact instant of each shift, the offset before and after, and whether local clocks jump forward or back. Returns the current offset and DST state, and the next transition from a given instant. Zones without DST return an empty transition list rather than an error. Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| from | string | – | Start of the range: RFC 3339 or YYYY-MM-DD. Default now. Accepted: RFC 3339 timestamp or YYYY-MM-DD. |
| years | string | – | Length of the range in years, 1-10. Default 2. Accepted: integer 1-10. |
| zone | string | yes | IANA time zone id. Accepted: an IANA time zone id, e.g. Europe/Amsterdam. |
No output schema declared.
No examples provided.
time_rrule RFC 5545 RRULE expansion into concrete occurrence timestamps ~345
Expand an RFC 5545 recurrence rule into concrete occurrence timestamps. Accepts an RRULE string with DTSTART, an IANA time zone, and optional EXDATE and RDATE lists, and returns up to 200 occurrences as both local wall-clock times and UTC instants. Supports FREQ, INTERVAL, COUNT, UNTIL, BYDAY, BYMONTHDAY, BYMONTH, BYSETPOS and WKST. Occurrences moved by a DST gap carry gap: true. Rules needing over 50,000 candidate evaluations are rejected. Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| after | string | – | RFC 3339 instant; skip occurrences before it. Accepted: RFC 3339 timestamp. |
| count | string | – | Maximum occurrences to return, 1-200. Default 20. Accepted: integer 1-200. |
| dtstart | string | yes | First occurrence, YYYY-MM-DDTHH:MM:SS local to zone. Accepted: YYYY-MM-DDTHH:MM:SS. |
| exdate | string | – | Comma-separated local datetimes to exclude. Accepted: at most 1024 characters. |
| rdate | string | – | Comma-separated local datetimes to add. Accepted: at most 1024 characters. |
| rrule | string | yes | RFC 5545 RRULE, e.g. FREQ=MONTHLY;BYDAY=-1FR;COUNT=6. Accepted: at most 512 characters. |
| zone | string | yes | IANA time zone id. Accepted: an IANA time zone id, e.g. Europe/Amsterdam. |
No output schema declared.
No examples provided.
time_zone Instant to wall-clock time in an IANA zone, with offset and DST state ~260
Convert an instant to wall-clock time in a named IANA time zone, or a wall-clock time in a zone back to an instant. Returns the local date and time, the UTC offset in ±HH:MM and seconds, the zone abbreviation, whether DST is in effect, the ISO week date, and the day of year. Handles the ambiguous and skipped local times at DST boundaries explicitly rather than guessing. Price: $0.05 per successful call, paid over x402 (USDC on Base).
| Name | Type | Req | Description |
|---|---|---|---|
| ambiguous | string | – | Only with local: which instant a repeated local time maps to. Default earlier. Accepted: earlier, later, reject. |
| instant | string | – | RFC 3339 timestamp or integer Unix seconds/milliseconds. Defaults to now. Mutually exclusive with local. Accepted: RFC 3339 timestamp or integer epoch. |
| local | string | – | Wall-clock time YYYY-MM-DDTHH:MM[:SS] in zone, converted back to an instant. Mutually exclusive with instant. Accepted: YYYY-MM-DDTHH:MM[:SS]. |
| zone | string | yes | IANA time zone id, e.g. Europe/Amsterdam. Accepted: an IANA time zone id, e.g. Europe/Amsterdam. |
No output schema declared.
No examples provided.
What is the Duo Data Utilities MCP server?
Duo Data Utilities is an MCP server listed in the public MCP registry as com.duoleads.api/data-utilities. 31 pay-per-call data utilities (IDs, time, text, codes, geo, chain, ref, numbers) via x402. This page covers its hosted endpoint (https://api.duoleads.com/mcp).
Is the Duo Data Utilities MCP server safe to use?
Duo Data Utilities scores 65 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Duo Data Utilities MCP server expose?
Duo Data Utilities exposes 31 tools: id_national, id_gs1, id_security, time_zone, time_dst, and 26 more. Their descriptions and schemas cost roughly 8,100 tokens of context every time the server is loaded.
Does the Duo Data Utilities MCP server require authentication?
No. We connected to Duo Data Utilities without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Duo Data Utilities MCP server still maintained?
Duo Data Utilities is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.