Grabblist
REMOTE · MCP.GRABBITAPP.COM · SCANNED AUG 14
Save and organize web finds in persistent, user-controlled collections for AI assistants.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security94
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents. View diagnostics → Partial
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability75
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 3111 tokens (~135/item across 23 items; 23 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management3
- Stability observed for 1 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Capabilities40
- Spec-recency check failed: implements MCP spec 2025-03-26; the latest is 2026-07-28. See how to fix → Fail
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · mcp.grabbitapp.com
claude mcp add --transport http com-grabbitapp-grabblist https://mcp.grabbitapp.com/api/mcp
[mcp_servers.com-grabbitapp-grabblist] url = "https://mcp.grabbitapp.com/api/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-grabbitapp-grabblist": {
"type": "remote",
"url": "https://mcp.grabbitapp.com/api/mcp",
"enabled": true
}
}
} openclaw mcp add com-grabbitapp-grabblist --url https://mcp.grabbitapp.com/api/mcp --transport streamable-http
mcp_servers:
com-grabbitapp-grabblist:
url: "https://mcp.grabbitapp.com/api/mcp" {
"mcpServers": {
"com-grabbitapp-grabblist": {
"type": "http",
"url": "https://mcp.grabbitapp.com/api/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 14 Aug 26 0
- Stability: unverified → 0.03 ▲ functional
- 13 Aug 26 75
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 14 Aug 2026 · Probed https://mcp.grabbitapp.com/api/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=grabbitapp.com | CN=WE1,O=Google Trust Services,C=US | 3 Aug 2026 | 1 Nov 2026 | ECDSA 256 | ECDSA-SHA256 | 65a731a9bdbe50d60e04fa403916479a |
| SANs: grabbitapp.com, *.grabbitapp.com | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
DNSSEC insecure
Validation of mcp.grabbitapp.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| grabbitapp.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer resource_metadata="https://mcp.grabbitapp.com/.well-known/oauth-protected-resource"
Bearer resource_metadata="https://mcp.grabbitapp.com/.well-known/oauth-protected-resource" | Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains; preload |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(), geolocation=() |
Protected resource metadata
| Document | https://mcp.grabbitapp.com/.well-known/oauth-protected-resource |
|---|---|
| Retrieved | Yes |
| Resource | https://mcp.grabbitapp.com/api/mcp |
| Authorisation server | https://grabbitapp.com |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.grabbitapp.com/api/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.grabbitapp.com/api/mcp | HTTPS enforced | 301 | https://mcp.grabbitapp.com/api/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
add_item ~450
Save an item to the user's Grabblist. Creates a static snapshot — Grabblist does not monitor prices or auto-update data. Only include fields with values available from the source. If no image is provided, the server attempts to fetch og:image automatically.
| Name | Type | Req | Description |
|---|---|---|---|
| attributes | object | – | Specs/details as key-value pairs |
| category | string | – | Category — pick the best match |
| condition | string | – | Condition if applicable: New, Used, Refurbished, Used - Like New, Used - Good, Used - Fair |
| currency | string | yes | Currency code: USD, NZD, AUD, EUR, GBP, etc. |
| description | string | – | Description from the page (max 2000 chars) |
| image | object | – | Main image URL. Server auto-fetches og:image if not provided. |
| images | array | – | All image URLs found on the page |
| item_type | string | – | What kind of item: product (buy), rental (Airbnb), service (cleaning), course (Udemy), listing (classified), event (ticket). Default: product. |
| location | string | – | Seller location or pickup location |
| original_price | number | – | Original price before discount (if on sale) |
| platform | string | yes | Site domain name without TLD: amazon.com→"amazon", ebay.co.nz→"ebay", kiwiquads.co.nz→"kiwiquads" |
| posted_at | string | – | When the listing was originally posted (ISO 8601) |
| price | number | yes | Price as number (e.g. 99.99) — REQUIRED, extract from page |
| quantity | integer | – | How many of this item |
| reason | string | – | Why this change was made (shown to user in change history) |
| seller_name | string | – | Seller or store name |
| seller_rating | number | – | Seller rating 0-5 |
| seller_reviews | integer | – | Number of seller reviews |
| tags | array | – | Tags for categorization |
| title | string | yes | Exact title from the page |
| url | object | yes | Direct public HTTP(S) page URL. |
No output schema declared.
No examples provided.
add_to_collection ~69
Add a saved item to a collection. Both the item and collection must already exist.
| Name | Type | Req | Description |
|---|---|---|---|
| collection_id | string | yes | The collection ID |
| item_id | string | yes | The item ID to add |
| reason | string | – | Why this change was made (shown to user in change history) |
No output schema declared.
No examples provided.
ask_agent ~125
Delegate a task to Grabblist's built-in AI assistant. The agent knows the user's Grabblist and can answer questions, compare items, give shopping advice, or analyze saved products. Use this when you want a second opinion or a specialized shopping assistant perspective. Requires the user to have an Anthropic API key configured in Settings.
| Name | Type | Req | Description |
|---|---|---|---|
| message | string | yes | The question or task for the Grabblist assistant |
| model | string | – | AI model to use (default: sonnet). haiku=fast/cheap, sonnet=balanced, opus=most capable |
No output schema declared.
No examples provided.
create_collection ~229
Create a new collection (folder) in the user's Grabblist to organize saved items.
| Name | Type | Req | Description |
|---|---|---|---|
| budget | number | – | Total spending target for this collection (e.g. 1500 for "Build PC under $1500") |
| budget_currency | string | – | Currency for the budget (default: NZD) |
| color | string | – | Hex color for the collection (e.g. "#3B82F6", "#22C55E", "#A855F7", "#EC4899", "#F59E0B", "#EF4444"). Default: #3B82F6 |
| description | string | – | Short description of what this collection is for |
| icon | string | – | Material Symbols icon name (e.g. "devices", "home", "shopping_bag", "checkroom", "directions_car", "favorite"). Default: inventory_2 |
| name | string | yes | Collection name, e.g. "Gaming Setup" or "Gift Ideas" |
| reason | string | – | Why this change was made (shown to user in change history) |
No output schema declared.
No examples provided.
delete_collection ~59
Permanently delete a collection. Items inside are not deleted — they stay in the Grabblist.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | The collection ID to delete |
| reason | string | – | Why this change was made (shown to user in change history) |
No output schema declared.
No examples provided.
delete_item ~69
Remove one or more items from the user's Grabblist (soft-delete). Pass a single id or an array of ids for batch operations.
| Name | Type | Req | Description |
|---|---|---|---|
| id | – | yes | Item ID or array of item IDs to delete |
| reason | string | – | Why this change was made (shown to user in change history) |
No output schema declared.
No examples provided.
get_collection_activity ~50
Get recent activity on a collection — additions, removals, edits.
| Name | Type | Req | Description |
|---|---|---|---|
| collection_id | string | yes | The collection ID |
| limit | number | – | Max events to return (default: 20) |
No output schema declared.
No examples provided.
get_item ~39
Get full details of a saved item by ID. Returns a static snapshot from the user's Grabblist.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | The item ID |
No output schema declared.
No examples provided.
get_item_graph ~50
Get all relations for an item — alternatives, complements, upgrades, duplicates. Returns the item and all connected items with their relation types.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | The item ID to get relations for |
No output schema declared.
No examples provided.
get_item_history ~51
Get the change history for a saved item — who changed what and when.
| Name | Type | Req | Description |
|---|---|---|---|
| item_id | string | yes | The item ID |
| limit | number | – | Max events to return (default: 20) |
No output schema declared.
No examples provided.
get_wishlist ~82
Get all saved items from the user's Grabblist. Each item is a static snapshot — data reflects the moment it was saved, not current prices.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | Max items to return (default: 50) |
| platform | string | – | Filter by platform (domain name, e.g. "amazon", "ebay", "trademe") |
No output schema declared.
No examples provided.
link_items ~144
Create typed relations between items: alternative (A or B), complement (A and B together), upgrade (B replaces A), duplicate (same item different site), same_seller. Supports single pair (from_id, to_id, relation) or bulk (pairs array).
| Name | Type | Req | Description |
|---|---|---|---|
| from_id | string | – | First item ID (for single pair mode) |
| pairs | array | – | Array of pairs to link (for bulk mode) |
| reason | string | – | Why this change was made (shown to user in change history) |
| relation | string | – | Type of relationship (for single pair mode) |
| to_id | string | – | Second item ID (for single pair mode) |
No output schema declared.
No examples provided.
list_collections ~221
List all collections OR get a specific collection with its items. Without id: returns all collections with counts/values. With id: returns that collection's metadata and all items inside (with optional filters).
| Name | Type | Req | Description |
|---|---|---|---|
| created_by | string | – | Filter by who added: "ai" for AI-added items (only when id is provided) |
| id | string | – | Collection ID — if provided, returns that collection with all its items. If omitted, lists all collections. |
| max_price | number | – | Maximum price filter (only when id is provided) |
| min_price | number | – | Minimum price filter (only when id is provided) |
| platform | string | – | Filter by platform domain name, e.g. "amazon", "ebay" (only when id is provided) |
| sort | string | – | Sort order (only when id is provided, default: newest) |
| status | string | – | Filter by decision status (only when id is provided) |
| tags | array | – | Filter items that have ALL these tags (only when id is provided) |
No output schema declared.
No examples provided.
ping ~18
Test connectivity to Grabblist and return service version.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
remove_from_collection ~91
Remove one or more items from a collection. Pass a single item_id or an array of item_ids for batch removal. Items are NOT deleted — they stay in the Grabblist.
| Name | Type | Req | Description |
|---|---|---|---|
| collection_id | string | yes | The collection ID |
| item_ids | – | yes | Item ID or array of item IDs to remove |
| reason | string | – | Why this change was made (shown to user in change history) |
No output schema declared.
No examples provided.
restore_item ~71
Restore one or more deleted (archived) items back to the Grabblist. Pass a single id or an array of ids for batch restore.
| Name | Type | Req | Description |
|---|---|---|---|
| id | – | yes | Item ID or array of item IDs to restore |
| reason | string | – | Why this change was made (shown to user in change history) |
No output schema declared.
No examples provided.
search_saved ~40
Search within the user's saved items by keyword
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | Max results (default: 20) |
| query | string | yes | Search query |
No output schema declared.
No examples provided.
send_feedback ~165
Send feedback, bug report, or feature request to the Grabbit team. Use this when you encounter parsing failures, missing features, broken URLs, or have improvement suggestions. The team reads these to improve the product. Be specific about what went wrong and where.
| Name | Type | Req | Description |
|---|---|---|---|
| error | string | – | Error message you received, if any |
| message | string | yes | What happened or what you propose. Be specific — the team reads this. |
| tool | string | – | The tool you were using when the issue occurred (e.g. add_item, search_saved) |
| type | string | yes | Type: bug (something broken), parsing_failure (price/title/image not extracted), feature_request (wishlist), feedback (general feedback) |
| url | string | – | The URL where the issue occurred |
No output schema declared.
No examples provided.
set_pinned_items ~86
Set the pinned "Top Picks" items for a collection (max 3). Pinned items are highlighted on the share page.
| Name | Type | Req | Description |
|---|---|---|---|
| collection_id | string | yes | The collection ID |
| item_ids | array | yes | Items to pin, in display order (1st = top) |
| reason | string | – | Why this change was made (shown to user in change history) |
No output schema declared.
No examples provided.
unlink_items ~68
Remove a relation between two items.
| Name | Type | Req | Description |
|---|---|---|---|
| from_id | string | yes | First item ID |
| reason | string | – | Why this change was made (shown to user in change history) |
| relation | string | yes | The relation type to remove |
| to_id | string | yes | Second item ID |
No output schema declared.
No examples provided.
update_collection ~204
Update a collection's name, icon, description, budget, or sharing status. Only provide the fields you want to change — omitted fields stay unchanged. Set is_public=true to share (returns public URL), is_public=false to unshare.
| Name | Type | Req | Description |
|---|---|---|---|
| budget | number | – | New budget amount |
| budget_currency | string | – | New budget currency |
| color | string | – | Hex color (e.g. "#3B82F6", "#22C55E", "#EF4444") |
| description | string | – | New description |
| icon | string | – | Material Symbols icon name (e.g. "devices", "home", "shopping_bag") |
| id | string | yes | The collection ID to update |
| is_public | boolean | – | Set true to share (generates public URL), false to unshare |
| name | string | – | New collection name |
| reason | string | – | Why this change was made (shown to user in change history) |
No output schema declared.
No examples provided.
update_item ~275
Edit fields on one or more saved items. Pass a single id or an array of ids for batch updates (same fields applied to all). For batch: attributes are REPLACED not merged, og:image fallback is skipped.
| Name | Type | Req | Description |
|---|---|---|---|
| attributes | object | – | Merge into existing attributes |
| category | string | – | Item category |
| description | string | – | Item description (max 2000 chars) |
| id | – | yes | Item ID or array of item IDs to update |
| image_url | object | – | Main image URL |
| images | array | – | All image URLs — replaces the entire images array |
| is_favorite | boolean | – | Set true to favorite, false to unfavorite |
| item_type | string | – | What kind of item this is |
| notes | string | – | User or AI notes — personal comments, thoughts, comparisons |
| quantity | integer | – | How many of this item |
| reason | string | – | Why this change was made (shown to user in change history) |
| status | string | – | Decision status: considering, shortlisted, decided, bought, rejected |
| tags | array | – | Replace all tags with this list |
| target_price | number | – | What the user wants to pay — not the actual price, but the goal price |
| title | string | – | Item title |
No output schema declared.
No examples provided.
update_price ~86
Manually update the price on a saved item. Records old and new price for comparison. This is a manual correction, not automatic price tracking.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | The item ID |
| price | number | yes | New current price |
| reason | string | – | Why this change was made (shown to user in change history) |
| source | string | – | Price update source |
No output schema declared.
No examples provided.