Roomproof
REMOTE · GETROOMPROOF.COM · SCANNED SEP 26
Room planning to scale from your AI: it places furniture, Roomproof checks walkways and door swings.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security77
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability69
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2325 tokens (~258/item across 9 items; 9 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management20
- Stability observed for 6 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 9 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 10 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the Roomproof MCP server?
Roomproof is a hosted endpoint at https://getroomproof.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · getroomproof.com
claude mcp add --transport http com-getroomproof-roomproof 'https://getroomproof.com/mcp'
{
"mcpServers": {
"com-getroomproof-roomproof": {
"url": "https://getroomproof.com/mcp"
}
}
} {
"servers": {
"com-getroomproof-roomproof": {
"type": "http",
"url": "https://getroomproof.com/mcp"
}
}
} [mcp_servers.com-getroomproof-roomproof] url = "https://getroomproof.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-getroomproof-roomproof": {
"type": "remote",
"url": "https://getroomproof.com/mcp",
"enabled": true
}
}
} openclaw mcp add com-getroomproof-roomproof --url 'https://getroomproof.com/mcp' --transport streamable-http
mcp_servers:
com-getroomproof-roomproof:
url: "https://getroomproof.com/mcp" {
"McpServers": {
"com-getroomproof-roomproof": {
"Transport": "http",
"Url": "https://getroomproof.com/mcp"
}
}
} assistant mcp add com-getroomproof-roomproof -t streamable-http -u 'https://getroomproof.com/mcp'
{
"mcpServers": {
"com-getroomproof-roomproof": {
"type": "http",
"url": "https://getroomproof.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 25 Sept 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 23 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.
- 21 Sept 26 +7
- Authorization: unverified → partial ▲ security
- The server rewrote its instructions, which are the text every model session reads security
- Stability: unverified → 0.03 ▲ functional
- 20 Sept 26 65
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 26 Sept 2026 · Probed https://getroomproof.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=getroomproof.com | CN=YE2,O=Let's Encrypt,C=US | 15 Sept 2026 | 14 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 607ca5bf3660ef1c632aaa1bec60a81f6e9 |
| SANs: getroomproof.com, www.getroomproof.com | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC secure
Validation of getroomproof.com. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| getroomproof.com. | present | 31654 | 13 | Verified |
| getroomproof.com. | Verified address RRset verified with the apex keys |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://getroomproof.com/mcp | Verified | 200 | |
| http (plaintext) | http://getroomproof.com/mcp | HTTPS enforced | 301 | https://getroomproof.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
check_plan Check plan ~166
Re-checks the saved layout only: pieces sticking out, overlaps, blocked areas including door swings, and a 0.9 m path to every piece. Does not place, move or spend a wish. Call it after move_furniture or when issues are unclear; ok true with an empty issues list is the condition for open_plan. Needs key on your own project, free on beispiel-wohnzimmer.
| Name | Type | Req | Description |
|---|---|---|---|
| key | string | – | Purchase token rp_ plus 20 characters, from the purchase confirmation. Required on projects you created, not on beispiel-wohnzimmer. Not the project id. |
| project | string | yes | Plan id from create_room, or beispiel-wohnzimmer. |
| variant | string | – | Variant id from a previous response; default the newest. |
No output schema declared.
No examples provided.
create_room Create room ~305
Free, no key. Creates a new plan at scale 1:50 and returns its project id plus purchase_url. Send name, plus either width_m and depth_m (rectangle) or rectangles (L-shape, alcove, bay), never both. Always send openings in this same call; without openings the checker treats the room as having no doors and skips the door-swing check. Each side 0.3 to 200 m. Coordinates: x to the right, y down, origin at the room's top-left corner.
| Name | Type | Req | Description |
|---|---|---|---|
| depth_m | number | – | Depth in meters (top to bottom), 0.3 to 200. |
| key | string | – | Purchase token rp_ plus 20 characters, from the purchase confirmation. Required on projects you created, not on beispiel-wohnzimmer. Not the project id. |
| name | string | – | Name of the plan, e.g. Living room. Default My room. |
| openings | array | – | All doors and windows of the room. The swing area of every door becomes a blocked area that furniture must keep clear. |
| rectangles | array | – | Instead of width_m and depth_m: 1 to 12 partial areas in meters. kind add joins the area, kind cut removes it. x, y is the rectangle's top-left corner, w, h its size. |
| width_m | number | – | Width in meters (left to right), 0.3 to 200. |
No output schema declared.
No examples provided.
move_furniture Move furniture ~299
Moves, rotates or removes one piece in the saved layout and returns the re-checked plan as an image with issues. Send x and y together (piece center, meters), rot, or remove true. The result is saved even with issues, so read them and move again if needed. Needs key on your own project, free on beispiel-wohnzimmer (not saved).
| Name | Type | Req | Description |
|---|---|---|---|
| index | integer | – | If several pieces share the name: which one, counted from 1 in list order. Default 1. |
| key | string | – | Purchase token rp_ plus 20 characters, from the purchase confirmation. Required on projects you created, not on beispiel-wohnzimmer. Not the project id. |
| piece | string | yes | Display name from placed, furniture or issues in the last place_furniture, show_plan or check_plan response, e.g. 3-seat sofa. Not the catalog id. |
| project | string | yes | Plan id from create_room, or beispiel-wohnzimmer. |
| remove | boolean | – | true removes the piece; x, y and rot are then ignored. |
| rot | number | – | New rotation in degrees clockwise. |
| variant | string | – | Variant id from a previous response; default the newest. |
| x | number | – | New piece center, horizontal, in meters. Send with y. |
| y | number | – | New piece center, vertical, in meters. Send with x. |
No output schema declared.
No examples provided.
open_plan Open plan ~133
Call only after the last check_plan returned no issues. Returns view_url (read-only, to share) and edit_url (for the owner, with the scaled PDF download). Needs key; not available on beispiel-wohnzimmer.
| Name | Type | Req | Description |
|---|---|---|---|
| key | string | – | Purchase token rp_ plus 20 characters, from the purchase confirmation. Required on projects you created, not on beispiel-wohnzimmer. Not the project id. |
| new | boolean | – | true creates a new view_url and invalidates the previous share link. Only if the user wants that. |
| project | string | yes | Plan id from create_room. |
No output schema declared.
No examples provided.
place_furniture Place furniture ~500
Places furniture and returns the checked plan as an image plus placed, rejected, issues and image_prompt. Send exactly one of spots, placement, or wish. Prefer spots: you name each piece and a rough position (at), the server finds the exact spot, snaps to a 5 cm grid and avoids walls, doors and other pieces. Use placement only when the user gives exact positions; never invent x, y or rot. Use wish only when the user describes the room without naming pieces; it calls Roomproof's own model, is slower and less predictable. Every way is checked against the floor area, overlaps, blocked areas and a 0.9 m path; what does not fit comes back in rejected with a reason. Dimensions in millimeters; x and y in meters to the CENTER of the piece, from the room's top-left corner. Needs key on your own project, free on beispiel-wohnzimmer (nothing is saved there).
| Name | Type | Req | Description |
|---|---|---|---|
| blocked | array | – | Rectangles that must stay free (radiator, wall cupboard, walkway): x, y, w, h in meters from the room's top-left corner, not piece centers. Door swings are added automatically. |
| keep | boolean | – | Default false: the new pieces replace everything in the plan. true adds them to the pieces already there. |
| key | string | – | Purchase token rp_ plus 20 characters, from the purchase confirmation. Required on projects you created, not on beispiel-wohnzimmer. Not the project id. |
| name | string | – | Name of the saved variant, default Draft. |
| outdoor | boolean | – | With wish only: limit the model to outdoor furniture, for terraces and balconies. |
| placement | array | – | Exact positions from the user, 1 to 60 pieces. Each with catalog or with name plus width_mm and depth_mm, plus x, y (meters to the piece center) and rot. Nothing is nudged: a piece that sticks out or… |
| project | string | yes | Plan id from create_room, or beispiel-wohnzimmer. |
| spots | array | – | Preferred. 1 to 40 pieces, each with catalog or with name plus width_mm and depth_mm, plus at. Larger pieces are placed first. |
| wish | string | – | One sentence describing the room, e.g. a living room for four with a reading corner. Only without spots and placement. |
No output schema declared.
No examples provided.
read_product Read product ~148
Free, no key. Turns a product link (IKEA, any furniture shop) or the pasted text of a product page into real dimensions: name, width_mm, depth_mm, height_mm, price, link. Call it as soon as the user gives a furniture link. On success pass name, width_mm, depth_mm, height_mm, price and link unchanged into a custom piece in place_furniture. If blocked is true, ask the user to paste the product page text and call read_product again with that text as input. Never guess millimeters; a missing dimension is listed in missing.
| Name | Type | Req | Description |
|---|---|---|---|
| input | string | yes | A product URL, or the pasted text of the product page. |
No output schema declared.
No examples provided.
set_door Set doors and windows ~146
Replaces the full openings list of a project you created (an empty list removes all). Windows have no hinge. Until openings exist, door-swing clearance is not checked. Saved layouts may get new issues afterwards; run check_plan. Needs key; not available on beispiel-wohnzimmer.
| Name | Type | Req | Description |
|---|---|---|---|
| key | string | – | Purchase token rp_ plus 20 characters, from the purchase confirmation. Required on projects you created, not on beispiel-wohnzimmer. Not the project id. |
| openings | array | yes | All doors and windows of the room, 0 to 20. Replaces the existing list completely. |
| project | string | yes | Plan id from create_room. |
No output schema declared.
No examples provided.
show_catalog Show catalog ~103
Free, no key. Lists every piece Roomproof knows: catalog id (ASCII slug, copy it exactly), display name, width_mm, depth_mm, group. Call it with no group first. Custom pieces (name plus width_mm and depth_mm, e.g. from read_product) do not need the catalog.
| Name | Type | Req | Description |
|---|---|---|---|
| group | string | – | Optional filter. Must be one of the strings in groups from a previous show_catalog response, e.g. Living or Outdoor. |
No output schema declared.
No examples provided.
show_plan Show plan ~140
Returns the saved plan as an image drawn to scale, plus image_prompt and image_positions. For a photo of the room copy image_prompt verbatim into your own image generator; Roomproof does not render photos. Needs key on your own project, free on beispiel-wohnzimmer.
| Name | Type | Req | Description |
|---|---|---|---|
| key | string | – | Purchase token rp_ plus 20 characters, from the purchase confirmation. Required on projects you created, not on beispiel-wohnzimmer. Not the project id. |
| project | string | yes | Plan id from create_room, or beispiel-wohnzimmer. |
| variant | string | – | Variant id from a previous response; default the newest. |
No output schema declared.
No examples provided.
What is the Roomproof MCP server?
Roomproof is an MCP server listed in the public MCP registry as com.getroomproof/roomproof. Room planning to scale from your AI: it places furniture, Roomproof checks walkways and door swings. This page covers its hosted endpoint (https://getroomproof.com/mcp).
Is the Roomproof MCP server safe to use?
Roomproof scores 74 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Roomproof MCP server expose?
Roomproof exposes 9 tools: read_product, create_room, place_furniture, set_door, show_catalog, and 4 more. Their descriptions and schemas cost roughly 1,940 tokens of context every time the server is loaded.
Does the Roomproof MCP server require authentication?
No. We connected to Roomproof without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Roomproof MCP server still maintained?
Roomproof is still listed as active in the MCP registry. We last reached this channel on 26 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.