Epovest
REMOTE · MCP.EPOVEST.COM · SCANNED AUG 3
With Epovest, businesses make AIs recommend them.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security97
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server supports Client ID Metadata Documents, the current MCP client-registration mechanism. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability54
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 15125 tokens (~252/item across 60 items; 60 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management24
- Stability check failed: schema churn in the 8 days we've observed: 1 tool removals, 0 breaking changes, 0 auth/transport breaks, 11 additions. See how to fix → Fail
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 99% of tool parameters carry a description.Partial
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · mcp.epovest.com
claude mcp add --transport http com-epovest-ai-visibility https://mcp.epovest.com/mcp
[mcp_servers.com-epovest-ai-visibility] url = "https://mcp.epovest.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-epovest-ai-visibility": {
"type": "remote",
"url": "https://mcp.epovest.com/mcp",
"enabled": true
}
}
} openclaw mcp add com-epovest-ai-visibility --url https://mcp.epovest.com/mcp --transport streamable-http
mcp_servers:
com-epovest-ai-visibility:
url: "https://mcp.epovest.com/mcp" {
"mcpServers": {
"com-epovest-ai-visibility": {
"type": "http",
"url": "https://mcp.epovest.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Aug 26 −2
- Schema quality: excellent → good functional
- New tool “rename_project” functional
- 2 Aug 26 +5
- Authorization: partial → pass ▲ security
- Schema quality: excellent → unverified ▼ functional
- MCP protocol: fail → pass ▲ functional
- 31 Jul 26 +6
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 −1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 29 Jul 26 −1
- Stability: 0.07 → fail ▼ security
- A breaking change shipped without a version bump: still 1.0.0 ▼ security
- Tool “mark_surface_aligned” was removed ▼ security
- Tool “update_surface” rewrote its description, which is the text the model reads security
- Tool “create_surface” rewrote its description, which is the text the model reads security
- Tool “list_quests” rewrote its description, which is the text the model reads security
- Tool “list_surfaces” rewrote its description, which is the text the model reads security
- Tool “tick_surface_checklist” rewrote its description, which is the text the model reads security
- Schema quality: excellent → good functional
- “get_responses” added an optional parameter “tone” cosmetic
- “tick_surface_checklist” reworded the description of “ticks” cosmetic
- Tool “tick_surface_checklist” changed its title: Tick the checklist of a surface → Verify or set aside checklist cells of a surface cosmetic
- 28 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 70
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://mcp.epovest.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=mcp.epovest.com | CN=WE1,O=Google Trust Services,C=US | 9 Jul 2026 | 7 Oct 2026 | ECDSA 256 | ECDSA-SHA256 | 2606a4c039a3b8590ed64acb61c41253 |
| SANs: mcp.epovest.com | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
DNSSEC insecure
Validation of mcp.epovest.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| epovest.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 400 |
WWW-Authenticate challenge Bearer realm="epovest-api", resource_metadata="https://mcp.epovest.com/.well-known/oauth-protected-resource"
Bearer realm="epovest-api", resource_metadata="https://mcp.epovest.com/.well-known/oauth-protected-resource" | Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains |
| content-security-policy | frame-ancestors 'none' |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
Protected resource metadata
| Document | https://mcp.epovest.com/.well-known/oauth-protected-resource |
|---|---|
| Retrieved | Yes |
| Resource | https://mcp.epovest.com/mcp |
| Authorisation server | https://app.epovest.com |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.epovest.com/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.epovest.com/mcp | HTTPS enforced | 301 | https://mcp.epovest.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
topup_credits Buy credits ~354
Prepare a top-up of the prepaid credit balance and return the hosted payment link. Nothing is charged by this call: hand payment_url to the user, the payment happens there, and they approve the amount on that page. When the user names an amount, that amount wins: pass it as `amount`, exactly the number they said. Amounts are always in the wallet currency of the account, which get_credits gives: if they name another currency, tell them, never convert one currency into another yourself. When they leave it to you, take one of the amounts get_credits already suggests in `suggested_topups[]` and pass its `amount_minor`: they are derived from what this account consumes, they clear the floor, and each says the runway it buys in `covers_months`. Name the one you picked and what it covers. Nothing to compute, and nothing to convert. Send one of the two, never both. The minimum top-up is 10.00 (1000 minor units). Once paid, the balance updates on its own, paused trackers resume and the data-access window reopens.
| Name | Type | Req | Description |
|---|---|---|---|
| amount | number | — | Credits to buy, in MAJOR units of the wallet currency: what a person says. 50 means 50.00, and 12.5 means 12.50. Use this one when the user names the amount, exactly as they said it. Minimum 10.00. |
| amount_minor | integer | — | Credits to buy, in MINOR units of the wallet currency: 5000 means 50.00. Use this one when you compute the amount from the cost grid, which is in minor units too. Minimum 1000. |
No output schema declared.
No examples provided.
update_account_settings Update the account settings ~387
Change the settings of the account. Send only what the user is changing: every setting you leave out keeps its value. `billing_country`, `billing_address` and `intra_eu_vat_number` clear when you send null; `name`, `language` and `timezone` keep their value on null, so name the language or the time zone you want. A postal address and a VAT number travel with `billing_country`: send the country in the same call. What you write here goes on the next invoices of the account, and the invoices already issued keep the details they carry.
| Name | Type | Req | Description |
|---|---|---|---|
| billing_address | array | — | Postal address of the account, one string per line, like ["12 Example Street", "75001 Paris"]. The list replaces the previous address; [] or null clears it. Three lines at most, so the address block… |
| billing_country | string | — | Billing country, as an ISO 3166-1 alpha-2 code: "FR", "US", "BR". It decides the tax treatment of the next invoices, so it is the country of the entity being billed, not where the user happens to be. |
| intra_eu_vat_number | string | — | Intra-EU VAT number, for an account billed in an EU member state: the two-letter country code followed by the national number, like "FR12345678901". It goes on the invoices of the account. |
| language | string | — | The language we write to this account in: emails, and the hosted payment page of a top-up. |
| name | string | — | Legal name of the account, the one printed on its invoices. |
| timezone | string | — | The time zone the hours of the account are shown in, as an IANA identifier: "Europe/Paris", "America/New_York", "UTC". |
No output schema declared.
No examples provided.
update_corroboration Update a corroboration ~488
Update the sheet of a corroboration: only the fields you send change (an empty label goes back to the derived one, an empty notes or published_on clears it). Correcting the url ALWAYS recomputes the source: the two never drift apart. It also carries monitoring, the cadence at which the page is read again on its own, which is why watching a page needs no tool of its own. To say a page is gone, use archive_corroboration instead: editing never takes anything down.
| Name | Type | Req | Description |
|---|---|---|---|
| corroboration_id | string | yes | The UUID of the corroboration: call list_corroborations to find it. |
| label | string | — | Display name of the page. OMIT IT: it is derived from the address (domain and path). Send an empty string to go back to the derived one. |
| monitoring | string | — | How often the page is read again on its own: "off" (the default), "daily", "weekly" or "monthly". Each executed check costs 0.02 USD from the prepaid balance and returns the same two findings as veri… |
| notes | string | — | Free notes: the passage that mentions the brand, the contact, how the page came about. |
| published_on | string | — | The day the page was PUBLISHED, as YYYY-MM-DD. Distinct from the recording day, and the one that means something against the citation curves. Omit it when unknown: it is never guessed. |
| request_channel | string | — | Whether someone can be asked to change the page: "available" (a contact or a process exists), "none" (nobody to ask), "unknown" (not filled in, the default). It gates the refresh suggestions of the q… |
| url | string | — | Absolute http(s) address of the EXACT page where the third party talks about the brand, never the home page of the site. |
No output schema declared.
No examples provided.
update_logbook_entry Edit a logbook entry ~237
Edit a manual logbook entry: only the fields you send change (empty notes clear them). It is the customer's own logbook: a typo or a wrong date is simply corrected. Tool events cannot be edited: they are derived from the canon and surface registries.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | — | What kind of action this is; it files the entry for filtering. "other" covers anything else. |
| entry_id | string | yes | The UUID of the logbook entry: call get_logbook to find it (only manual entries carry an id). |
| label | string | — | Short wording of the action, e.g. "Site translated into Spanish": it is what the annotation shows next to the citation curves. |
| notes | string | — | Free notes: context, links, details of the action. |
| occurred_at | string | — | When the action HAPPENED, ISO 8601 date or datetime, read as UTC without an offset. Distinct from the recording time: when the user says "yesterday" or "last week", compute and pass that date. Omitte… |
No output schema declared.
No examples provided.
update_project_canon Update the canon of a project ~586
Revise the brand canon of a project. Field by field: a provided field replaces the current wording (an empty string clears it), an omitted field is kept as is. Any actual change records the NEXT canon version (numbered, immutable; version_created true in the answer); sending identical wording records nothing. The canon lives in ONE language, its canonical language (canon_language): it is never translated, changing the language is a revision like any other. The canon is meant to be STABLE: revising it is a rare and deliberate move, and every surface that reuses the wording will need to be brought back in phase with the new version. Confirm with the user before revising.
| Name | Type | Req | Description |
|---|---|---|---|
| canon_address | string | — | Postal address, as written on a listing. Language-neutral: the same string everywhere, like the other facts. |
| canon_category | string | — | Category label for listings and structured data. |
| canon_email | string | — | Public email address of the brand. |
| canon_language | string | — | Short code of the ONE language the canon is written in, like "en" or "pt-br". On a project whose canon is not posted yet, send it with at least one wording: the canon is the wording, and the language… |
| canon_legal_name | string | — | Registered name of the company that operates the brand, with its jurisdiction when the user states it ("Acme Holdings, LLC, Delaware, United States"). Language-neutral, like the other facts: the AIs… |
| canon_long | string | — | The two-sentence version, when the surface allows it. |
| canon_one_liner | string | — | One-sentence signature of the brand. |
| canon_perks | array | — | The distinctive claims of the brand, in the order they should be hammered, written in the canonical language. Facts that hold and can be corroborated ("works without a subscription"), never superlati… |
| canon_phone | string | — | Phone number, international prefix included. |
| canon_short | string | — | THE one-sentence description third-party pages reuse as is. |
| canon_website | string | — | The canonical address of the brand website, the one that identifies the entity. A bare domain is enough ("example.com" completes to "https://example.com"). ONE URL only: the other addresses of the br… |
| canon_whatsapp | string | — | WhatsApp number, international prefix included. |
| project_id | string | yes | UUID of the project: call list_projects to find it. |
No output schema declared.
No examples provided.
update_quest Edit a quest ~136
Edit a quest: only the fields you send change (empty notes clear them). It is the customer's own file: a typo or a sharpened wording is simply corrected. The status changes through its own moves, complete_quest, dismiss_quest and reopen_quest.
| Name | Type | Req | Description |
|---|---|---|---|
| notes | string | — | Free notes: context, links, what done looks like. |
| quest_id | string | yes | The UUID of the quest: call list_quests to find it. |
| title | string | — | Short wording of the move, e.g. "Get our MCP server listed on the AI tool directories": it is what the file shows. |
No output schema declared.
No examples provided.
update_surface Update a surface ~368
Update the registry sheet of a surface: only the fields you send change (a sent languages list replaces the previous one; an empty label or notes clears it). No journal line is ever written here: an alignment is earned with tick_surface_checklist, cell by cell. Languages ARE the columns of the checklist, so declaring the language of a single-language page renames its column and carries its verified cells along. When the change leaves no single destination (a language dropped from a page that keeps others, one column split into several), the columns that leave the model come back in dropped_checklist_columns with what they held; their cells stay stored, and declaring the language again brings them back. The status of the answer is derived from the cells that read NOW, so read it back rather than assuming it held.
| Name | Type | Req | Description |
|---|---|---|---|
| label | string | — | Display name of the surface. OMIT IT on creation: it is derived from the url (the handle on a known place, the host and path on a website). |
| languages | array | — | Languages of the surface, as short codes like "en" or "pt-br". A sent list replaces the previous one. |
| notes | string | — | Free registry notes: who owns the account, access, context. |
| surface_id | string | yes | The UUID of the surface: call list_surfaces to find it. |
| type | string | — | What kind of surface this is; it picks the checklist to come. OMIT IT on creation: the type is derived from the url by the catalogue of places (github.com is GitHub, an unknown host is the brand webs… |
| url | string | — | Absolute http(s) address of the surface. |
No output schema declared.
No examples provided.
update_surface_check Correct a check of your own ~195
Correct a check of your own on a surface: its label, and whether it restates the canon. Only what you send changes. The key never moves, being the coordinate of the cells already recorded, so renaming a check keeps every tick it carries. Turning restates_canon on makes a tick recorded without a canon stamp perish, which is the honest reading: the page was never checked against a wording.
| Name | Type | Req | Description |
|---|---|---|---|
| check | string | yes | The key of the check of your own, exactly as listed by list_surfaces in checklist.custom (add_surface_check returns it too). |
| label | string | — | The new wording of the check, up to 120 characters. |
| restates_canon | boolean | — | true when the check restates the WORDING of the canon, false when it constates something else. |
| surface_id | string | yes | The UUID of the surface: call list_surfaces to find it. |
No output schema declared.
No examples provided.
update_tracker Update a tracker ~455
Update the configuration of a tracker: only the fields you send change. Keywords, analysts and the title apply in place. Changing the prompts, engines, frequency or resolution of a tracker that has measured creates a new version: the score series continues across versions, and the response carries the new tracker id (version_created says when). A sent list replaces the previous one entirely.
| Name | Type | Req | Description |
|---|---|---|---|
| analysts | array | — | The lenses that score every survey. keyword_presence and share_of_voice are deterministic; sentiment and custom_prompt are AI analysts billed per analyzed response. |
| custom_prompt | string | — | The instruction of the custom_prompt analyst. Required when that analyst is selected. |
| discovery | boolean | — | Suggest new keywords spotted in the answers. |
| engines | array | — | The AI engines surveyed. |
| frequency | string | — | How often a survey runs. |
| keywords | array | — | Names to detect in the answers: your brand and the names you compare against. Flag yours as favorite. |
| next_survey_at | string | — | When the next survey runs, ISO 8601, strictly in the future; read as UTC without an offset. Later surveys keep that day and time at the pace of the frequency. |
| notify_on_survey | boolean | — | Email the account owner and managers each time a survey closes with fresh data, so the results reach them on their own. Off by default. |
| project_id | string | — | The project the tracker is filed under: the UUID of a project of the account (call list_projects), or "default" for none. Pure organization, editable at any time. Omitted on creation the tracker file… |
| prompts | array | — | The questions asked to the AI engines at every survey, phrased exactly as a customer would ask them. |
| resolution | string | — | Repetitions of every question per engine and survey: hd=1, full_hd=3, 4k=6, 8k=9. Answers are stochastic; more repetitions sharpen the rates. |
| title | string | — | Display name of the tracker. |
| tracker_id | string | yes | The UUID of the tracker: call list_trackers to find it. |
No output schema declared.
No examples provided.
verify_corroboration Check a corroboration against its page, now ~497
Read the page again and report what it says today. One pass returns two findings, dated, and included at no cost. On the MENTION: the passage around the brand is archived on the line (the sentence that names it, one before, one after), and the finding says unchanged, changed (the passage moved, worth re-reading), figures (the passage moved on NUMBERS only, such as a rank or a counter: a fact to read, and changed_at stays where it was) or gone (the page did not answer). When a change was found, excerpt_before carries the passage as it stood BEFORE changed_at: compare it with excerpt to state what moved, in words, without reading the whole page. On the LINK: every link of the page towards an address of the brand, derived from the canon website and from the surface registry of the project, with its rel tokens (nofollow, sponsored, ugc, or none), its target and title attributes, its anchor text, its exact destination with the resolved redirect chain and the HTTP code of that destination, whether it sits in the main content or outside it, and its dates; the finding says unchanged, changed (changes lists what moved: rel, anchor, target, placement, appeared), gone, or none, which means the page carries no such link and is a normal state. The reply also carries how the page reads (readability: "html" when it reads, "blocked" when an anti-bot stands in front of it, "unreachable" when it did not answer, "no_page" when the address answers with something that is not a page, "unreadable" when it answers HTML with no text in it, "pending" while no reading has completed yet), the number of outbound links of the page, and what the page declares about itself (noindex, page_nofollow, canonical_elsewhere). Read readability before deciding a move: an anti-bot is a fact of the world, while a page that did not answer is worth reading again. Everything here is a FACT: the third party has the final say, so nothing closes, nothing counts, and nothing is taken down on its own. Use it to dec…
| Name | Type | Req | Description |
|---|---|---|---|
| corroboration_id | string | yes | The UUID of the corroboration: call list_corroborations to find it. |
No output schema declared.
No examples provided.