FPL Copilot
REMOTE · API.FPLCOPILOT.COM · SCANNED OCT 4
Fantasy Premier League expected points, team ratings, captaincy and mini-league win chances.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security80
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability84
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2565 tokens (~116/item across 22 items; 21 tools + 1 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management13
- Stability observed for 4 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 21 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 23 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
- Supports UI / widget rendering.Pass
How do I install the FPL Copilot MCP server?
FPL Copilot is a hosted endpoint at https://api.fplcopilot.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · api.fplcopilot.com
claude mcp add --transport http com-fplcopilot-fpl-copilot 'https://api.fplcopilot.com/mcp'
{
"mcpServers": {
"com-fplcopilot-fpl-copilot": {
"url": "https://api.fplcopilot.com/mcp"
}
}
} {
"servers": {
"com-fplcopilot-fpl-copilot": {
"type": "http",
"url": "https://api.fplcopilot.com/mcp"
}
}
} [mcp_servers.com-fplcopilot-fpl-copilot] url = "https://api.fplcopilot.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-fplcopilot-fpl-copilot": {
"type": "remote",
"url": "https://api.fplcopilot.com/mcp",
"enabled": true
}
}
} openclaw mcp add com-fplcopilot-fpl-copilot --url 'https://api.fplcopilot.com/mcp' --transport streamable-http
mcp_servers:
com-fplcopilot-fpl-copilot:
url: "https://api.fplcopilot.com/mcp" {
"McpServers": {
"com-fplcopilot-fpl-copilot": {
"Transport": "http",
"Url": "https://api.fplcopilot.com/mcp"
}
}
} assistant mcp add com-fplcopilot-fpl-copilot -t streamable-http -u 'https://api.fplcopilot.com/mcp'
{
"mcpServers": {
"com-fplcopilot-fpl-copilot": {
"type": "http",
"url": "https://api.fplcopilot.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Oct 26 +1
- The server rewrote its instructions, which are the text every model session reads security
- Tool “compare_players” rewrote its description, which is the text the model reads security
- Tool “find_players” rewrote its description, which is the text the model reads security
- Tool “get_best_chip_squad” rewrote its description, which is the text the model reads security
- Tool “get_captain_picks” rewrote its description, which is the text the model reads security
- Tool “get_fixture_ticker” rewrote its description, which is the text the model reads security
- Tool “get_mini_league” rewrote its description, which is the text the model reads security
- Tool “get_penalty_takers” rewrote its description, which is the text the model reads security
- Tool “get_player” rewrote its description, which is the text the model reads security
- Tool “get_predicted_lineups” rewrote its description, which is the text the model reads security
- Tool “rate_my_team” rewrote its description, which is the text the model reads security
- Tool “search_guides” rewrote its description, which is the text the model reads security
- Schema quality: 2224 → 2565 ▼ functional
- New tool “get_manager_squad” functional
- New tool “get_player_breakdowns” functional
- “get_captain_picks” added an optional parameter “scope” cosmetic
- “find_players” reworded the description of “limit” cosmetic
- “find_players” reworded the description of “position” cosmetic
- “get_best_chip_squad” reworded the description of “chip” cosmetic
- 1 Oct 26 +1
- Tool “get_my_team” rewrote its description, which is the text the model reads security
- Tool “read_guide” rewrote its description, which is the text the model reads security
- Stability: unverified → 0.03 ▲ functional
- 30 Sept 26 75
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 4 Oct 2026 · Probed https://api.fplcopilot.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=api.fplcopilot.com | CN=YE2,O=Let's Encrypt,C=US | 19 Sept 2026 | 18 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 59ea40f4d351abdc87927814d8fe230a958 |
| SANs: api.fplcopilot.com | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of api.fplcopilot.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| fplcopilot.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains |
| content-security-policy | default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.vercel-insights.com https://us.i.posthog.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https://lh3.googleusercontent.com https://resources.premierleague.com; connect-src 'self' http://localhost:8000 https://api.fplcopilot.com https://us.i.posthog.com https://fantasy.premierleague.com; font-src 'self'; frame-ancestors 'none' |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://api.fplcopilot.com/mcp | Verified | 200 | |
| http (plaintext) | http://api.fplcopilot.com/mcp | HTTPS enforced | 307 | https://api.fplcopilot.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
compare_players Compare FPL players ~92
Use this when choosing between two or three FPL players (e.g. 'Saka or Palmer?', one transfer for another, or whether a -4 hit is worth it): expected points over the coming gameweeks, form, price and ownership side by side.
| Name | Type | Req | Description |
|---|---|---|---|
| horizon | integer | – | How many gameweeks ahead to count (1-8). |
| names | array | yes | 2-3 player names |
No output schema declared.
No examples provided.
create_share_link Share this card ~77
Creates a public fplcopilot.com page for an FPL Copilot card so it can be shared.
| Name | Type | Req | Description |
|---|---|---|---|
| component | string | yes | The card's component, e.g. rating_card |
| data | object | yes | The card's data object |
| token | – | – | The card's share token (from the result's _meta) |
No output schema declared.
No examples provided.
find_players Find FPL players by expected points ~216
Use this to find the best Fantasy Premier League (fantasy football) players to pick or buy, by FPL Copilot expected points (xPts, also called predicted or projected points), filtered by position, price, club or ownership, and sorted by points, value per £m, or as low-owned differentials. Classic FPL, not FPL Draft.
| Name | Type | Req | Description |
|---|---|---|---|
| horizon | integer | – | How many gameweeks ahead to count (1-8). |
| limit | integer | – | How many players (1-15) |
| max_ownership | – | – | Max ownership %, e.g. 10 for differentials |
| max_price | – | – | Max price in £m, e.g. 8.0 |
| min_price | – | – | Min price in £m |
| position | – | – | Position: GK, DEF, MID or FWD |
| sort | string | – | xpts (default), value (xPts per £m) or differential (low-owned) |
| team | – | – | Club, e.g. ARS or Arsenal |
No output schema declared.
No examples provided.
get_best_chip_squad Best FPL Wildcard or Free Hit team ~129
Use this when someone wants the best FPL Wildcard or Free Hit squad for any gameweek, or the best FPL team right now, built by FPL Copilot's optimiser within £100m and FPL squad rules. Not for a Bench Boost team or when to play a chip: the result links FPL Copilot's Chip Strategies for that.
| Name | Type | Req | Description |
|---|---|---|---|
| chip | string | – | wildcard or free_hit (bench_boost and triple_captain, played on the manager's own team, return where to plan them) |
| gw | – | – | Gameweek (default: next) |
No output schema declared.
No examples provided.
get_captain_picks FPL captain picks ~142
Use this when someone asks who to captain (or Triple Captain) in Fantasy Premier League (fantasy football) this gameweek. Call it even without their team: it then lists the best captain options in the game. With a team ID (or their team from an earlier chat) it ranks their own players; scope "all" ranks the game.
| Name | Type | Req | Description |
|---|---|---|---|
| scope | – | – | all: the best captains in the game, for general asks; squad: from the user's own team |
| team_id | – | – | The manager's FPL team ID (entry ID), or any FPL link containing /entry/<id>/. Leave empty if unknown. |
No output schema declared.
No examples provided.
get_deadline FPL deadline ~23
Use this for the next Fantasy Premier League deadline time and gameweek.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_fixture_ticker FPL fixture difficulty ~109
Use this for Fantasy Premier League fixture difficulty (FDR) and which teams have the easiest or hardest fixtures: each club's coming fixtures and their average difficulty, easiest runs first.
| Name | Type | Req | Description |
|---|---|---|---|
| gw_from | – | – | First gameweek. Leave empty for the next gameweek; set only if the user names one |
| gw_to | – | – | Last gameweek. Leave empty for a 6-gameweek view (max 8 ahead) |
| teams | – | – | Clubs to include (default: all 20) |
No output schema declared.
No examples provided.
get_gameweek_review FPL gameweek review ~97
Use this to review an FPL manager's gameweek: points vs the average, captain result, bench points and transfers, plus how lucky their season has been against FPL Copilot's expected points.
| Name | Type | Req | Description |
|---|---|---|---|
| gw | – | – | Gameweek (default: the last finished) |
| team_id | – | – | The manager's FPL team ID (entry ID), or any FPL link containing /entry/<id>/. Leave empty if unknown. |
No output schema declared.
No examples provided.
get_manager_squad Rival squad ~59
An FPL mini-league rival's squad for the league card's own view.
| Name | Type | Req | Description |
|---|---|---|---|
| entry_id | integer | yes | The rival's FPL team (entry) id |
| gw | – | – | A played gameweek (default: the last) |
No output schema declared.
No examples provided.
get_mini_league FPL mini-league standings ~119
Use this for an FPL mini-league or a manager's rivals in it: standings, the gap to the leader, and rivals' captains and differential picks. Without a league ID it lists the manager's leagues to choose from.
| Name | Type | Req | Description |
|---|---|---|---|
| league_id | – | – | Mini-league ID, or the FPL league standings link. Leave empty to list the manager's leagues. |
| team_id | – | – | The manager's FPL team ID (entry ID), or any FPL link containing /entry/<id>/. Leave empty if unknown. |
No output schema declared.
No examples provided.
get_mini_league_odds FPL mini-league win chances ~116
Use this when an FPL manager asks their chances (or odds) of winning their mini-league: each manager's win and top-3 probability from 5,000 simulations of the rest of the season.
| Name | Type | Req | Description |
|---|---|---|---|
| league_id | – | – | Mini-league ID, or the FPL league standings link. Leave empty to list the manager's leagues. |
| team_id | – | – | The manager's FPL team ID (entry ID), or any FPL link containing /entry/<id>/. Leave empty if unknown. |
No output schema declared.
No examples provided.
get_my_team Show my FPL team ~157
Use this for start, bench and captain questions about an FPL manager's own squad: each player's FPL Copilot expected points for the next gameweek with fixtures, and the best XI and captain. It shows the squad and does not score it. Needs their team ID or FPL link, or player names from a screenshot.
| Name | Type | Req | Description |
|---|---|---|---|
| players | – | – | 11-15 FPL player names (e.g. read from a screenshot of their team), used when there is no team ID. Add the club to disambiguate, e.g. 'Palmer CHE'. |
| team_id | – | – | The manager's FPL team ID (entry ID), or any FPL link containing /entry/<id>/. Leave empty if unknown. |
No output schema declared.
No examples provided.
get_penalty_takers FPL penalty takers ~66
Use this to find who takes penalties, corners and free kicks for Premier League clubs in FPL, with each penalty taker's chance of being his club's main taker.
| Name | Type | Req | Description |
|---|---|---|---|
| teams | – | – | Clubs, e.g. ['BHA'] (default: all 20) |
No output schema declared.
No examples provided.
get_player FPL player card ~105
Use this for one to five FPL players, e.g. whether to buy, sell or start them: expected points for each coming gameweek with fixtures, injury news, price and price-change progress, ownership, xG/xA and his chance of being the main penalty taker.
| Name | Type | Req | Description |
|---|---|---|---|
| horizon | integer | – | How many gameweeks ahead to count (1-8). |
| names | array | yes | 1-5 player names, e.g. ['Haaland'] |
No output schema declared.
No examples provided.
get_player_breakdown Player card ~46
The FPL Copilot player card's data for one player (for the card's own view).
| Name | Type | Req | Description |
|---|---|---|---|
| player_id | integer | yes | The FPL player (element) id |
No output schema declared.
No examples provided.
get_player_breakdowns Player cards ~48
The FPL Copilot player cards' data for the players on a card (for the card's own view).
| Name | Type | Req | Description |
|---|---|---|---|
| player_ids | array | yes | FPL player (element) ids |
No output schema declared.
No examples provided.
get_predicted_lineups FPL predicted lineups ~71
Use this for predicted Premier League starting XIs and team news for the next FPL gameweek (who starts, who is injured or rotated), from FPL Copilot's expected minutes.
| Name | Type | Req | Description |
|---|---|---|---|
| teams | – | – | Clubs, e.g. ['ARS', 'Chelsea'] (default: all 20) |
No output schema declared.
No examples provided.
get_price_changes FPL price changes ~65
Use this for FPL price rises and falls: players likely to change price tonight, or changes already made this gameweek.
| Name | Type | Req | Description |
|---|---|---|---|
| names | – | – | Specific players to check |
| view | string | – | tonight (default): likely changes tonight; recent: changes made this gameweek |
No output schema declared.
No examples provided.
rate_my_team Rate my FPL team ~186
Use this when a Fantasy Premier League (FPL, fantasy football) manager wants their team rated or reviewed, or shares their team ID or FPL link without saying more. Scores the squad 0-100 against the best possible squad over the next 5 gameweeks and lists the biggest fixes, naming the players; pass their team ID or FPL link, or the player names read from a screenshot of their team.
| Name | Type | Req | Description |
|---|---|---|---|
| captain | – | – | Captain's name, if known |
| players | – | – | 11-15 FPL player names (e.g. read from a screenshot of their team), used when there is no team ID. Add the club to disambiguate, e.g. 'Palmer CHE'. |
| team_id | – | – | The manager's FPL team ID (entry ID), or any FPL link containing /entry/<id>/. Leave empty if unknown. |
No output schema declared.
No examples provided.
read_guide Read an FPL Copilot guide ~61
Use this to read one FPL Copilot Fantasy Premier League guide in full, by its slug or its fplcopilot.com/blog/ link.
| Name | Type | Req | Description |
|---|---|---|---|
| slug | string | yes | The guide's slug, or its fplcopilot.com/blog/ link |
No output schema declared.
No examples provided.
search_guides Search FPL Copilot guides ~119
Use this for Fantasy Premier League rules and how-to questions (scoring, free transfers, chips and when to play them, DefCon, FDR) and FPL Copilot's guides: gameweek tips, chip guides, penalty takers, fixtures. FPL's rules change each season (free transfers now roll over up to 5), so use these, not memory.
| Name | Type | Req | Description |
|---|---|---|---|
| gw | – | – | Prefer guides for this gameweek |
| query | – | – | What to look for, e.g. 'bench boost' or 'GW7 tips' |
No output schema declared.
No examples provided.
What is the FPL Copilot MCP server?
FPL Copilot is an MCP server listed in the public MCP registry as com.fplcopilot/fpl-copilot. Fantasy Premier League expected points, team ratings, captaincy and mini-league win chances. This page covers its hosted endpoint (https://api.fplcopilot.com/mcp).
Is the FPL Copilot MCP server safe to use?
FPL Copilot scores 77 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the FPL Copilot MCP server expose?
FPL Copilot exposes 21 tools: rate_my_team, get_my_team, get_captain_picks, find_players, get_player, and 16 more. Their descriptions and schemas cost roughly 2,103 tokens of context every time the server is loaded.
Does the FPL Copilot MCP server require authentication?
No. We connected to FPL Copilot without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the FPL Copilot MCP server still maintained?
FPL Copilot is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.