# Duo Data Utilities (remote · api.duoleads.com)

33 pay-per-call data utilities (IDs, time, text, codes, geo, chain, ref, numbers) via x402.

- Trust score: 65/100 (medium)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-29

## Components

- remote · `api.duoleads.com`: 65/100 (this document), [markdown](https://verifymcp.io/servers/com-duoleads-api-data-utilities/api.md), [page](https://verifymcp.io/servers/com-duoleads-api-data-utilities/api)

## Channel facts

- Endpoint: `https://api.duoleads.com/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.0.1`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-29.

- **Endpoint Security**: 63/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one.
  - HTTPS enforcement could not be verified: the plaintext port answered with HTTP 405, which proves neither a plaintext path nor enforcement.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 66/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 8100 tokens (~261/item across 31 items; 31 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 31 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 31 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

**Unverified: 1 category.** A category scored 0 because we could not verify it: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.

## Install

### How do I install the Duo Data Utilities MCP server?

Duo Data Utilities is a hosted endpoint at https://api.duoleads.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http com-duoleads-api-data-utilities 'https://api.duoleads.com/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "com-duoleads-api-data-utilities": {
      "url": "https://api.duoleads.com/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "com-duoleads-api-data-utilities": {
      "type": "http",
      "url": "https://api.duoleads.com/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.com-duoleads-api-data-utilities]
url = "https://api.duoleads.com/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-duoleads-api-data-utilities": {
      "type": "remote",
      "url": "https://api.duoleads.com/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add com-duoleads-api-data-utilities --url 'https://api.duoleads.com/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  com-duoleads-api-data-utilities:
    url: "https://api.duoleads.com/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "com-duoleads-api-data-utilities": {
      "Transport": "http",
      "Url": "https://api.duoleads.com/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add com-duoleads-api-data-utilities -t streamable-http -u 'https://api.duoleads.com/mcp'
```

### Other

```json
{
  "mcpServers": {
    "com-duoleads-api-data-utilities": {
      "type": "http",
      "url": "https://api.duoleads.com/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-29 (score 65)

First indexed and scored.

## MCP tools (31)

### `id_national` (~251 tokens)

National identity- and company-number validation, 23 countries

Validate a national identity, tax or company registration number against its country's official checksum rule. Covers 23 countries including NL BSN, ES NIF/NIE/CIF, IT codice fiscale, FR SIREN/SIRET, DE Steuer-ID, BE/PL/CZ national numbers, SE/NO/DK/FI personal numbers, BR CPF/CNPJ, AU ABN/TFN, UK NINo, IE PPS, US NPI/EIN. Structure and check digit only — no registry lookup, no personal data stored. Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `country` (string, required): ISO 3166-1 alpha-2 country code, case-insensitive. One of the 23 supported countries. Accepted: one of the 23 supported ISO 3166-1 alpha-2 codes.
- `kind` (string, required): Identifier type for that country, e.g. bsn, nif, cf, cpf. Accepted: an identifier kind supported for the country.
- `value` (string, required): The identifier. Separators (space . - /) are stripped before checking. Accepted: at most 64 characters.

### `id_gs1` (~232 tokens)

GS1 identifier validation: GTIN-8/12/13/14, GLN, SSCC

Validate and convert GS1 identifiers: GTIN-8, GTIN-12 (UPC-A), GTIN-13 (EAN-13), GTIN-14, GLN and SSCC. Returns the check-digit verdict, the computed correct check digit, the GS1 company-prefix boundary where it is derivable, and conversion to GTIN-14. Also computes a missing check digit from a partial code. Structure only, no product database. Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `op` (string): validate (default), checkdigit (compute the missing final digit) or convert. Accepted: validate, checkdigit, convert.
- `to` (string): Target format. Required when op=convert. Accepted: gtin8, gtin12, gtin13, gtin14.
- `value` (string, required): GS1 code, digits with optional spaces or hyphens. For op=checkdigit, omit the final digit. Accepted: 8, 12, 13, 14 or 18 digits.

### `id_security` (~240 tokens)

ISIN, CUSIP, SEDOL and FIGI check-digit validation

Validate the check digit of a financial security identifier: ISIN (ISO 6166), CUSIP, SEDOL and FIGI. Returns the verdict, the computed correct check character, and for an ISIN the issuing country prefix and the embedded NSIN. Also builds an ISIN from a country code plus a 9-character NSIN. Format and checksum only, no security master lookup. Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `country` (string): ISO 3166-1 alpha-2 code or XS. Required when op=build-isin. Accepted: at most 16 characters.
- `nsin` (string): Exactly 9 alphanumeric characters. Required when op=build-isin. Accepted: exactly 9 alphanumeric characters.
- `op` (string): validate (default) or build-isin. Accepted: validate, build-isin.
- `value` (string): ISIN, CUSIP, SEDOL or FIGI to validate. Required when op=validate. Accepted: an alphanumeric security identifier of at most 24 characters.

### `time_zone` (~260 tokens)

Instant to wall-clock time in an IANA zone, with offset and DST state

Convert an instant to wall-clock time in a named IANA time zone, or a wall-clock time in a zone back to an instant. Returns the local date and time, the UTC offset in ±HH:MM and seconds, the zone abbreviation, whether DST is in effect, the ISO week date, and the day of year. Handles the ambiguous and skipped local times at DST boundaries explicitly rather than guessing. Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `ambiguous` (string): Only with local: which instant a repeated local time maps to. Default earlier. Accepted: earlier, later, reject.
- `instant` (string): RFC 3339 timestamp or integer Unix seconds/milliseconds. Defaults to now. Mutually exclusive with local. Accepted: RFC 3339 timestamp or integer epoch.
- `local` (string): Wall-clock time YYYY-MM-DDTHH:MM[:SS] in zone, converted back to an instant. Mutually exclusive with instant. Accepted: YYYY-MM-DDTHH:MM[:SS].
- `zone` (string, required): IANA time zone id, e.g. Europe/Amsterdam. Accepted: an IANA time zone id, e.g. Europe/Amsterdam.

### `time_dst` (~189 tokens)

Next daylight-saving transitions for an IANA time zone

List the daylight-saving transitions for an IANA time zone over a date range: the exact instant of each shift, the offset before and after, and whether local clocks jump forward or back. Returns the current offset and DST state, and the next transition from a given instant. Zones without DST return an empty transition list rather than an error. Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `from` (string): Start of the range: RFC 3339 or YYYY-MM-DD. Default now. Accepted: RFC 3339 timestamp or YYYY-MM-DD.
- `years` (string): Length of the range in years, 1-10. Default 2. Accepted: integer 1-10.
- `zone` (string, required): IANA time zone id. Accepted: an IANA time zone id, e.g. Europe/Amsterdam.

### `time_business-days` (~359 tokens)

Business-day arithmetic with a caller-supplied weekend mask and holiday list

Business-day arithmetic with a caller-supplied calendar: add or subtract N working days from a date, or count the working days between two dates. The weekend is specified as a weekday mask so Friday-Saturday and Sunday-only weeks work, and holidays are passed in as an explicit date list, so the answer never depends on a holiday table that can go stale. Returns the result date, the day count, and the first 1,000 skipped dates with the reason each was skipped. Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `days` (string): Business days to add, -3650 to 3650. Required when op=add. Accepted: integer between -3650 and 3650.
- `from` (string, required): Start date, YYYY-MM-DD. Accepted: a calendar date as YYYY-MM-DD.
- `holidays` (string): Comma-separated YYYY-MM-DD holiday dates. Accepted: comma-separated YYYY-MM-DD dates, at most 2048 characters.
- `inclusive` (string): For op=count: start (default, half-open [from, to)), both or neither. Accepted: start, both, neither.
- `op` (string): add (default) N business days to from, or count business days between from and to. Accepted: add, count.
- `to` (string): End date YYYY-MM-DD, may precede from. Required when op=count. Accepted: a calendar date as YYYY-MM-DD.
- `weekend` (string): Comma-separated weekday names or ISO numbers. Default sat,sun. Empty string = no weekend. Accepted: comma-separated weekday names (mon..sun) or ISO numbers 1-7.

### `time_rrule` (~345 tokens)

RFC 5545 RRULE expansion into concrete occurrence timestamps

Expand an RFC 5545 recurrence rule into concrete occurrence timestamps. Accepts an RRULE string with DTSTART, an IANA time zone, and optional EXDATE and RDATE lists, and returns up to 200 occurrences as both local wall-clock times and UTC instants. Supports FREQ, INTERVAL, COUNT, UNTIL, BYDAY, BYMONTHDAY, BYMONTH, BYSETPOS and WKST. Occurrences moved by a DST gap carry gap: true. Rules needing over 50,000 candidate evaluations are rejected. Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `after` (string): RFC 3339 instant; skip occurrences before it. Accepted: RFC 3339 timestamp.
- `count` (string): Maximum occurrences to return, 1-200. Default 20. Accepted: integer 1-200.
- `dtstart` (string, required): First occurrence, YYYY-MM-DDTHH:MM:SS local to zone. Accepted: YYYY-MM-DDTHH:MM:SS.
- `exdate` (string): Comma-separated local datetimes to exclude. Accepted: at most 1024 characters.
- `rdate` (string): Comma-separated local datetimes to add. Accepted: at most 1024 characters.
- `rrule` (string, required): RFC 5545 RRULE, e.g. FREQ=MONTHLY;BYDAY=-1FR;COUNT=6. Accepted: at most 512 characters.
- `zone` (string, required): IANA time zone id. Accepted: an IANA time zone id, e.g. Europe/Amsterdam.

### `time_calendar` (~271 tokens)

Gregorian conversion to Hijri, Hebrew and Japanese-era dates, plus Easter

Convert a Gregorian date to other calendar systems and back: Islamic (both the tabular civil calendar and the Umm al-Qura variant), Hebrew, Japanese imperial era, Republic of China, Buddhist and Persian. Also computes Easter Sunday for a year in both the Gregorian and Julian reckonings. Uses the calendar support built into the runtime, with the algorithm named in every response. Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `date` (string): Gregorian date YYYY-MM-DD. Required when op=convert. Accepted: a calendar date as YYYY-MM-DD.
- `op` (string): convert (default) a Gregorian date, or easter for a year. Accepted: convert, easter.
- `rite` (string): Easter reckoning: western (default) or eastern. Accepted: western, eastern.
- `to` (string): Comma-separated calendar ids: islamic, islamic-umalqura, hebrew, japanese, roc, buddhist, persian. Default all. Accepted: islamic, islamic-umalqura, hebrew, japanese, roc, buddhist, persian.
- `year` (string): Year for op=easter, 326-9999. Accepted: integer 326-9999.

### `text_slug` (~253 tokens)

Unicode-aware URL slug with transliteration

Turn arbitrary text into a URL-safe slug. Decomposes accents, transliterates German umlauts, Scandinavian and Turkish letters, and the ligatures that lose meaning under plain NFD, lowercases, collapses separators, and truncates on a word boundary. Options for separator character, maximum length and case preservation. Returns the slug plus what was removed. Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `case` (string): lower (default), preserve or upper. Accepted: lower, preserve, upper.
- `lang` (string): ISO 639-1 code for locale-sensitive folding (de: ü->ue, tr: dotless i). Default locale-neutral. Accepted: an ISO 639-1 language code.
- `max` (string): Maximum slug length 1-512, default 96. Truncates at the last complete word. Accepted: integer 1-512.
- `separator` (string): Separator: - (default), _, . or empty. Accepted: -, _, . or empty.
- `text` (string, required): Text to slugify, at most 2048 characters. Accepted: at most 2048 characters.

### `text_transliterate` (~238 tokens)

Cyrillic-to-Latin transliteration (ISO 9, BGN/PCGN)

Transliterate Cyrillic text into Latin using a named standard: ISO 9:1995 (one-to-one, with diacritics) or the BGN/PCGN Russian system. Returns the transliteration, the detected source script, the standard actually applied, the fraction of non-ASCII characters that were mapped, and any characters passed through untouched. Other scripts are not supported yet and are rejected with UNSUPPORTED_VALUE. Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `case` (string): preserve (default), lower or upper. Accepted: preserve, lower, upper.
- `from` (string): Source script name (cyrillic), or auto (default). Accepted: cyrillic or auto.
- `standard` (string): Romanisation standard, e.g. iso-9, bgn-pcgn. Default: the first listed for the detected script. Accepted: a romanisation standard supported for the script.
- `text` (string, required): Text to transliterate, at most 2048 characters. Accepted: at most 2048 characters.

### `text_unicode` (~204 tokens)

Unicode normalisation, script detection and confusable/homoglyph analysis

Analyse a string at the Unicode level: apply NFC, NFD, NFKC or NFKD normalisation, report which normalisation forms it is already in, list the scripts present, and flag confusable and homoglyph characters — Cyrillic а in a Latin word, zero-width joiners, bidirectional overrides, invisible characters. Returns per-character detail for anything suspicious, with code points, names and the ASCII character each one imitates. Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `detail` (string): summary (default) or full per-code-point detail (capped at 256 entries). Accepted: summary, full.
- `form` (string): Normalisation form to apply, default nfc. Accepted: nfc, nfd, nfkc or nfkd.
- `text` (string, required): Text to analyse, at most 1024 characters. Accepted: at most 1024 characters.

### `text_similarity` (~221 tokens)

String distance and phonetic keys: Levenshtein, Jaro-Winkler, Soundex, Metaphone

Compare two strings and return every standard similarity measure in one call: Levenshtein and Damerau-Levenshtein edit distance, normalised similarity, Jaro and Jaro-Winkler, longest common subsequence, Dice coefficient on character bigrams, and the Soundex, Metaphone and NYSIIS phonetic keys of each string. Optional case folding, accent folding and whitespace normalisation before comparison. Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `a` (string, required): First string, at most 512 characters. Accepted: at most 512 characters.
- `b` (string, required): Second string, at most 512 characters. Accepted: at most 512 characters.
- `fold` (string): Comma-separated folds before comparing: case, accents, space, punct. Default case. Accepted: comma-separated subset of case, accents, space, punct.
- `only` (string): Comma-separated measure names to compute. Default all. Accepted: comma-separated measure names.

### `code_url` (~194 tokens)

URL parse, canonicalise, and registrable-domain (eTLD+1) extraction

Parse and canonicalise a URL, and extract its registrable domain using the Public Suffix List — the part an agent needs to decide whether two URLs belong to the same owner. Returns scheme, host, port, path, decoded query parameters and fragment, the public suffix, the registrable domain (eTLD+1), the subdomain, whether the suffix is an ICANN or a private entry, plus a canonical form with default port, dot-segments and percent-encoding normalised. unicode_host uses WHATWG/UTS 46 (non-strict). Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `base` (string): Base URL to resolve url against as a relative reference. Accepted: an absolute URL.
- `url` (string, required): Absolute URL, or a bare hostname (https:// assumed). Accepted: an absolute URL, or a hostname.

### `code_idn` (~250 tokens)

IDNA2008 / punycode conversion and domain-label validation

Convert internationalised domain names between Unicode and ASCII punycode in either direction, label by label, and validate each label against IDNA2008: length, leading and trailing hyphens, the hyphen-hyphen rule at positions 3 and 4, disallowed code points and bidirectional rules. Returns both forms, the per-label breakdown and the first rule violated. Strict mode is IDNA2008 (UTS 46 non-transitional); it may reject names /v1/code/url displays. Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `domain` (string, required): Domain name in Unicode or punycode form. Accepted: at most 512 characters.
- `strict` (string): true (default) applies IDNA2008 strictly; false uses UTS 46 transitional (IDNA2003-compatible) processing, which maps e.g. ß to ss; current browsers and /v1/code/url use non-transitional processing,…
- `to` (string): ascii, unicode or both (default). Accepted: ascii, unicode, both.

### `code_semver` (~255 tokens)

Semantic-version parse, compare, and range satisfaction

Parse a semantic version into major, minor, patch, prerelease and build parts; compare two versions by precedence including prerelease ordering; or test whether a version satisfies a range expression using caret, tilde, hyphen, x-ranges and comparator sets. Returns the parsed structure, the comparison result and the reason a range did not match. Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `a` (string): First version for op=compare. Accepted: at most 256 characters.
- `b` (string): Second version for op=compare. Accepted: at most 256 characters.
- `op` (string): parse (default), compare, satisfies or sort. Accepted: parse, compare, satisfies, sort.
- `range` (string): Range expression for op=satisfies, e.g. ^1.2.0. Accepted: at most 256 characters.
- `version` (string): Version to parse (op=parse) or test (op=satisfies). Accepted: at most 256 characters.
- `versions` (string): Comma-separated versions for op=sort, at most 100. Accepted: at most 100 versions.

### `code_hash` (~359 tokens)

SHA-2, SHA-3, BLAKE2 and HMAC digests of supplied text or base64 bytes

Compute a cryptographic digest of supplied data: SHA-256, SHA-384, SHA-512, SHA-1, SHA3-256, SHA3-512, Keccak-256, BLAKE2b-256 and BLAKE2b-512, plus HMAC with any of them. Input is UTF-8 text, base64 or hex bytes; output is hex, base64, base64url or base32. Returns the digest, the byte length of the input, and the exact algorithm identifier used. Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `algo` (string, required): Digest algorithm. Accepted: sha256, sha384, sha512, sha1, sha3-256, sha3-512, keccak256, blake2b-256, blake2b-512.
- `data` (string, required): Input data, interpreted per encoding. At most 8192 characters. An empty value hashes the empty string. Accepted: at most 8192 characters.
- `encoding` (string): Encoding of data: utf8 (default), base64, base64url or hex. Accepted: utf8, base64, base64url, hex.
- `hmac_key` (string): If present, computes HMAC with this key. Accepted: at most 512 characters.
- `hmac_key_encoding` (string): Encoding of hmac_key, as encoding. Accepted: utf8, base64, base64url, hex.
- `out` (string): Digest output encoding: hex (default), base64, base64url or base32. Accepted: hex, base64, base64url, base32.

### `code_jwt` (~189 tokens)

JWT structural decode: header, claims, expiry state — no signature verification

Decode a JSON Web Token without verifying it: returns the header, the claims, the signature length and algorithm, and a computed view of the time claims — whether exp has passed, whether nbf is in the future, and the remaining lifetime in seconds against a supplied or current instant. Reports structural problems such as a missing part, invalid base64url or an alg of none. It does not and cannot verify the signature; do not use it to decide trust. Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `at` (string): Instant to evaluate exp/nbf against: RFC 3339 or epoch seconds. Default now. Accepted: RFC 3339 timestamp or integer epoch.
- `token` (string, required): The JWT to decode (not verified). At most 8192 characters. Accepted: at most 8192 characters.

### `geo_geohash` (~281 tokens)

Geohash encode and decode with neighbour cells

Encode a WGS-84 latitude and longitude to a geohash at a chosen precision, or decode a geohash back to its bounding box, centre point and error bounds in metres. Encoding also returns the eight neighbouring cells, which is what a caller needs to do proximity search over a geohash-indexed store without a spatial database. Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `geohash` (string): Geohash to decode, 1-12 characters. Required when op=decode. Accepted: base32 geohash alphabet, excluding a, i, l and o.
- `lat` (string): WGS-84 latitude, -90 to 90. Required when op=encode. Accepted: a number between -90 and 90.
- `lon` (string): WGS-84 longitude, -180 to 180. Required when op=encode. Accepted: a number between -180 and 180.
- `op` (string): encode (default): lat/lon to geohash. decode: geohash to bounding box. Accepted: encode, decode.
- `precision` (string): Geohash length 1-12, default 9 (about 4.8 m). Accepted: integer 1-12.

### `geo_pluscode` (~311 tokens)

Open Location Code (plus code) encode and decode

Encode coordinates as an Open Location Code (plus code) at a chosen length, or decode a full code back to its bounding box and centre. Also shortens a full code against a reference coordinate and recovers a shortened code given a reference, which is how plus codes are normally exchanged in text. Returns code length, precision in metres and validity. Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `code` (string): Plus code for decode, shorten or recover. Accepted: at most 20 characters.
- `lat` (string): Latitude for op=encode. Accepted: a number between -90 and 90.
- `length` (string): Code length for op=encode: 2,4,6,8,10 (default),11,12,13,14,15. Accepted: one of 2,4,6,8,10,11,12,13,14,15.
- `lon` (string): Longitude for op=encode. Accepted: a number between -180 and 180.
- `op` (string): encode (default), decode, shorten or recover. Accepted: encode, decode, shorten, recover.
- `ref_lat` (string): Reference latitude for op=shorten/recover. Accepted: a number between -90 and 90.
- `ref_lon` (string): Reference longitude for op=shorten/recover. Accepted: a number between -180 and 180.

### `geo_polygon` (~255 tokens)

Point-in-polygon, bounding box, centroid and area on supplied GeoJSON

Geometric predicates on a GeoJSON geometry supplied in the request: point-in-polygon with correct hole handling, bounding box, centroid, signed area in square metres, perimeter length, and ring winding order. Accepts Polygon and MultiPolygon, and a GeoJSON Feature wrapping either. Area and length are geodesic on the WGS-84 ellipsoid, correct at any latitude; containment is planar in lon/lat. Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `geometry` (string, required): URL-encoded GeoJSON Polygon, MultiPolygon or a Feature wrapping one. At most 3072 characters and 2000 coordinate pairs. Accepted: valid GeoJSON.
- `lat` (string): Point latitude; with lon, runs the containment test. Accepted: a number between -90 and 90.
- `lon` (string): Point longitude; with lat, runs the containment test. Accepted: a number between -180 and 180.
- `ops` (string): Comma-separated subset of contains,bbox,centroid,area,perimeter,winding. Default all. Accepted: comma-separated subset of contains, bbox, centroid, area, perimeter, winding.

### `geo_distance` (~325 tokens)

Geodesic distance, initial bearing and destination point on WGS-84

Distance and direction between WGS-84 coordinates: geodesic distance by Vincenty with a haversine fallback, initial and final bearing, the midpoint, and the destination point reached from a start point on a given bearing and distance. Also computes the cumulative length of a supplied coordinate path. Results in metres, kilometres, nautical miles and miles. Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `bearing` (string): Initial bearing in degrees for op=destination. Accepted: number 0-360.
- `distance_m` (string): Distance in metres for op=destination. Accepted: a number >= 0.
- `lat1` (string): Start latitude. Accepted: a number between -90 and 90.
- `lat2` (string): End latitude. Accepted: a number between -90 and 90.
- `lon1` (string): Start longitude. Accepted: a number between -180 and 180.
- `lon2` (string): End longitude. Accepted: a number between -180 and 180.
- `method` (string): vincenty (default, WGS-84) or haversine. Accepted: vincenty, haversine.
- `op` (string): distance (default), destination, midpoint or path. Accepted: distance, destination, midpoint, path.
- `path` (string): Comma-separated lat,lon pairs for op=path, at most 200 points. Accepted: comma-separated lat,lon pairs, at most 200 points.

### `chain_address` (~232 tokens)

Blockchain address format detection and checksum validation

Identify which blockchain an address belongs to and validate its encoding: EVM EIP-55 checksum, Bitcoin base58check and bech32/bech32m with witness version, Solana base58 and on-curve check, Cosmos bech32 with its HRP, Tron, XRP, Litecoin, Dogecoin, Cardano, Polkadot SS58 and Algorand. Returns the detected chains with a confidence note, the checksummed form for EVM addresses, and the exact reason an address failed. Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `address` (string, required): Address to identify and validate. Accepted: at most 128 characters.
- `chain_id` (string): EVM chain id; enables EIP-1191 chain-salted checksum validation. Accepted: a positive integer chain id.
- `expect` (string): Restrict the check to one chain id. Accepted: evm, bitcoin, solana, cosmos, tron, xrp, cardano, polkadot, algorand, litecoin, dogecoin.

### `chain_selector` (~220 tokens)

Keccak-256 hash, 4-byte function selector and 32-byte event topic from a Solidity signature

Compute the Keccak-256 hash of a Solidity function or event signature and derive the 4-byte function selector and the 32-byte event topic. Normalises the signature first — strips parameter names, expands uint to uint256 and the other aliases, flattens tuples — so a signature copied from source code produces the same selector as the canonical form. Also hashes arbitrary text or hex bytes with Keccak-256. Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `data` (string): Alternative to signature: raw data to Keccak-256 hash. Accepted: at most 8192 characters.
- `encoding` (string): Encoding of data: utf8 (default) or hex. Accepted: utf8, hex.
- `kind` (string): function (default), event or error. Accepted: function, event, error.
- `signature` (string): Solidity function, event or error signature, e.g. transfer(address to, uint amount). Accepted: at most 1024 characters.

### `ref_nuts` (~334 tokens)

NUTS statistical region code lookup for the EU

Look up a NUTS statistical region of the European Union: resolve a NUTS code to its name, country and level, walk up to its parents or down to its children, or search regions by name. Covers all four levels (country, major region, basic region, small region) for the 27 member states and 12 further reporting countries, from the NUTS 2024 classification. Returns the Latin-script and local-language names plus the urbanisation, coastal and mountain typologies. Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `code` (string): NUTS code, 2-5 characters, case-insensitive (level-3 codes may contain letters, e.g. NL32B). Accepted: 2 to 5 characters matching ^[A-Z]{2}[0-9A-Z]{0,3}$.
- `country` (string): ISO 3166-1 alpha-2 country filter (UK/GB and EL/GR both accepted). Accepted: an ISO 3166-1 alpha-2 code.
- `include` (string): Comma-separated: parents, children, typology. Default parents,typology. Accepted: comma-separated subset of parents, children, typology.
- `level` (string): Restrict a name search to one level, 0-3. Accepted: integer 0-3.
- `name` (string): Substring search on region names, case- and accent-insensitive. Up to 25 matches. Accepted: at most 128 characters.

### `ref_airport` (~269 tokens)

Airport lookup by IATA or ICAO code with coordinates and elevation

Look up an airport by IATA or ICAO code and get its name, city, country, ISO 3166-2 region code, WGS-84 coordinates and elevation, or find the nearest airports to a coordinate within a radius. Covers every airport worldwide that holds a three-letter IATA code and scheduled service. Returns the code type that matched and the distance in kilometres for proximity results. Time zones are not included. Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `code` (string): 3-letter IATA or 4-letter ICAO code, case-insensitive. Accepted: a 3-letter IATA or 4-letter ICAO code.
- `country` (string): ISO 3166-1 alpha-2 filter. Accepted: an ISO 3166-1 alpha-2 code.
- `limit` (string): Maximum results 1-25, default 5. Only with near. Accepted: integer 1-25.
- `near` (string): lat,lon to search around. Accepted: lat,lon.
- `radius_km` (string): Search radius in km, 1-1000, default 100. Only with near. Accepted: number 1-1000.

### `ref_currency` (~209 tokens)

Currency record (ISO 4217 codes, CLDR minor units and cash rounding)

Look up a currency by ISO 4217 code: its alphabetic and numeric codes, English name, minor-unit exponent, the smallest cash denomination where it differs from the minor unit, and the territories that use it. Returns the correct rounding increment for cash amounts, which is what a caller needs to render or settle a price. This route returns currency facts only and never an exchange rate. Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `code` (string): ISO 4217 alpha-3 or 3-digit numeric code. Accepted: a 3-letter alphabetic or 3-digit numeric ISO 4217 code.
- `country` (string): ISO 3166-1 alpha-2; returns the currencies in use there. Accepted: an ISO 3166-1 alpha-2 code.
- `include` (string): Comma-separated: territories, historic. Default none. Accepted: comma-separated subset of territories, historic.

### `ref_country` (~221 tokens)

ISO 3166-1 country record: codes, currency, TLD, UN M49 region

Look up a country or territory by ISO 3166-1 alpha-2, alpha-3 or numeric code, or by name, and get the other codes, the English name, the UN M49 region and sub-region, the currencies in use, and the country-code top-level domain. Names are matched case- and accent-insensitively. Country level only: ISO 3166-2 subdivisions are not included. Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `code` (string): ISO 3166-1 alpha-2, alpha-3 or numeric code. Accepted: ISO 3166-1 alpha-2, alpha-3 or numeric code.
- `include` (string): Comma-separated: m49, currency, tld. Default all three. Accepted: comma-separated subset of m49, currency, tld.
- `name` (string): Substring search on country names, case- and accent-insensitive. Accepted: at most 128 characters.

### `num_radix` (~264 tokens)

Integer conversion between arbitrary numeric bases 2–36

Convert an integer between any two numeric bases from 2 to 36, with arbitrary precision so values far beyond 2^53 are exact. Accepts an optional sign and common prefixes (0x, 0b, 0o), validates every digit against the source base, and returns the value in the target base, in decimal, and as its bit length and digit count. Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `case` (string): Digit case for bases above 10: lower (default) or upper. Accepted: lower, upper.
- `from` (string): Source base 2-36, or auto (default) to read a 0x/0b/0o prefix. Accepted: integer 2-36, or 'auto'.
- `prefix` (string): Emit 0x/0b/0o where conventional. Default false. Accepted: true or false.
- `to` (string): Target base 2-36, default 10. Accepted: integer 2-36.
- `value` (string, required): Integer to convert; optional sign and 0x/0b/0o prefix. Accepted: at most 1024 characters.

### `num_words` (~263 tokens)

Number spelled out in words, 12 locales, with ordinal and currency forms

Spell a number out in words in English, Dutch, German, French, Spanish, Italian, Portuguese, Polish, Russian, Turkish, Swedish or Japanese, in cardinal, currency or year form, and ordinal form in English, Dutch, German and French. Currency form applies the correct grammatical agreement and the right minor-unit name and count for the supplied ISO 4217 code. Handles negatives and values up to 10^15. Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `case` (string): lower (default), sentence or title. Accepted: lower, sentence, title.
- `currency` (string): ISO 4217 code. Required when form=currency. Accepted: an ISO 4217 alpha-3 code.
- `form` (string): cardinal (default), ordinal, currency or year. Accepted: cardinal, ordinal, currency, year.
- `lang` (string): Language, ISO 639-1. Default en. Accepted: en, nl, de, fr, es, it, pt, pl, ru, tr, sv, ja.
- `value` (string, required): Integer or decimal, absolute value below 1e15. Accepted: absolute value below 1e15.

### `num_stats` (~287 tokens)

Descriptive statistics and percentiles for a supplied numeric array

Descriptive statistics for a supplied numeric array in one call: count, sum, mean, median, mode, variance and standard deviation with variance and standard deviation honouring ddof (default 1, the sample form; 0 gives the population form) and always-population *_population fields, min, max, range, the quartiles and interquartile range, skewness, kurtosis, and any requested percentiles. Percentiles use a named interpolation method so the result is reproducible rather than implementation-defined. Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `ddof` (string): Delta degrees of freedom for variance/stdev: 1 (default, sample, n-1) or 0 (population, n). The *_population fields are always population. Accepted: integer 0-1.
- `method` (string): Percentile interpolation (NumPy/R names): linear (default), nearest, lower, higher, midpoint. Accepted: linear, nearest, lower, higher, midpoint.
- `percentiles` (string): Comma-separated percentiles 0-100, at most 20. Default 25,50,75. Accepted: numbers between 0 and 100.
- `values` (string, required): Comma-separated finite numbers, at most 500 values. Accepted: comma-separated finite numbers.

### `num_allocate` (~319 tokens)

Split a money amount into shares with no rounding loss

Split a money amount into shares without losing or inventing a cent. Divide evenly into N parts, or by a list of ratios, and the remainder is distributed one minor unit at a time by a named, deterministic rule — largest-remainder, first-wins or last-wins — so the parts always sum exactly to the original. Uses Unicode CLDR minor-unit digits, so zero- and three-decimal currencies work (CLDR differs from ISO 4217 for a few, e.g. IDR, HUF: 0). Price: $0.05 per successful call, paid over x402 (USDC on Base).

Input parameters:

- `amount` (string, required): Decimal amount, absolute value below 1e12. Accepted: a decimal amount with absolute value below 1e12.
- `currency` (string, required): ISO 4217 alpha-3 code. Accepted: an ISO 4217 alpha-3 code.
- `parts` (string): Number of equal parts, 1-1000. One of parts or ratios. Accepted: integer 1-1000.
- `ratios` (string): Comma-separated non-negative ratios, at most 1000, each with at most 15 integer digits and 15 decimal places. One of parts or ratios. Accepted: comma-separated non-negative numbers, at most 1000.
- `rule` (string): Remainder rule: largest-remainder (default), first, last or round-robin. Accepted: largest-remainder, first, last, round-robin.

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/com-duoleads-api-data-utilities/api#diagnostics

## Score history

- 2026-09-29: 65

## Common questions

### What is the Duo Data Utilities MCP server?

Duo Data Utilities is an MCP server listed in the public MCP registry as com.duoleads.api/data-utilities. 33 pay-per-call data utilities (IDs, time, text, codes, geo, chain, ref, numbers) via x402. This page covers its hosted endpoint (https://api.duoleads.com/mcp).

### Is the Duo Data Utilities MCP server safe to use?

Duo Data Utilities scores 65 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Duo Data Utilities MCP server expose?

Duo Data Utilities exposes 31 tools: id_national, id_gs1, id_security, time_zone, time_dst, and 26 more. Their descriptions and schemas cost roughly 8,100 tokens of context every time the server is loaded.

### Does the Duo Data Utilities MCP server require authentication?

No. We connected to Duo Data Utilities without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the Duo Data Utilities MCP server still maintained?

Duo Data Utilities is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://api.duoleads.com/mcp
- Website: https://api.duoleads.com/
- Changelog RSS feed: https://verifymcp.io/servers/com-duoleads-api-data-utilities/api.xml
- Changelog JSON feed: https://verifymcp.io/servers/com-duoleads-api-data-utilities/api.json
- HTML version of this page: https://verifymcp.io/servers/com-duoleads-api-data-utilities/api
