HojinCheck — Japanese corporate verification API (hojin = 法人/corporate entity)
REMOTE · HOJINCHECK.COM · SCANNED SEP 21
Verify Japanese companies, invoice-issuer registrations and addresses against government open data.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security71
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, but the challenge carries no valid RFC 9728 metadata, so a client cannot discover where to get a token. See how to fix → View diagnostics → Fail
- HTTPS enforcement could not be verified: the plaintext port answered with HTTP 500, which proves neither a plaintext path nor enforcement. View diagnostics → Unverified
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability69
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1191 tokens (~198/item across 6 items; 6 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 6 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 6 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the HojinCheck — Japanese corporate verification API (hojin… MCP server?
HojinCheck — Japanese corporate verification API (hojin… is a hosted endpoint at https://hojincheck.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · hojincheck.com
claude mcp add --transport http com-hojincheck-hojincheck 'https://hojincheck.com/mcp'
{
"mcpServers": {
"com-hojincheck-hojincheck": {
"url": "https://hojincheck.com/mcp"
}
}
} {
"servers": {
"com-hojincheck-hojincheck": {
"type": "http",
"url": "https://hojincheck.com/mcp"
}
}
} [mcp_servers.com-hojincheck-hojincheck] url = "https://hojincheck.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-hojincheck-hojincheck": {
"type": "remote",
"url": "https://hojincheck.com/mcp",
"enabled": true
}
}
} openclaw mcp add com-hojincheck-hojincheck --url 'https://hojincheck.com/mcp' --transport streamable-http
mcp_servers:
com-hojincheck-hojincheck:
url: "https://hojincheck.com/mcp" {
"McpServers": {
"com-hojincheck-hojincheck": {
"Transport": "http",
"Url": "https://hojincheck.com/mcp"
}
}
} assistant mcp add com-hojincheck-hojincheck -t streamable-http -u 'https://hojincheck.com/mcp'
{
"mcpServers": {
"com-hojincheck-hojincheck": {
"type": "http",
"url": "https://hojincheck.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 26 Aug 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 0
- Stability: 0.97 → pass security
- 24 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 31 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 0
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 21 Sept 2026 · Probed https://hojincheck.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=hojincheck.com | CN=WE1,O=Google Trust Services,C=US | 11 Sept 2026 | 10 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | 65b2e302131af1f13bad7393ca75fd4 |
| SANs: hojincheck.com, *.hojincheck.com | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of hojincheck.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| hojincheck.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Challenged, unverified
The endpoint asked for a token, but we could not retrieve and validate the RFC 9728 metadata that tells a client how to obtain one.
| Result | Challenged, unverified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
Protected resource metadata
| Retrieved | No |
|---|---|
| Problem | no_resource_metadata |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://hojincheck.com/mcp | Verified | 200 | |
| http (plaintext) | http://hojincheck.com/mcp | Inconclusive | 500 |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
get_company_profile 法人プロファイル取得(gBizINFO) ~129
法人番号(13桁・チェックディジット検証つき)からgBizINFOの法人プロファイル(所在地・代表者・資本金・従業員数等)を、項目別の出典・最終取得日メタとあわせて返します。データ源: Gビズインフォ REST API v2(経済産業省)。
| Name | Type | Req | Description |
|---|---|---|---|
| corporate_number | string | yes | 法人番号13桁(全角・ハイフン・空白は吸収。チェックディジット検証あり) |
No output schema declared.
No examples provided.
jp_calendar 日本の祝日・営業日計算 ~227
日本の祝日判定と営業日計算(内閣府「国民の祝日」CSV準拠)。営業日=土日・祝日以外。year_end_as_holiday=trueで12/29〜1/3も非営業日扱い。
| Name | Type | Req | Description |
|---|---|---|---|
| date | string | – | 基準日 YYYY-MM-DD(list_holidays以外で必須) |
| days | integer | – | 加算する営業日数(add_business_daysで必須。負数=遡り、0=基準日をそのまま返す) |
| from | string | – | 期間開始日(list_holidaysで必須) |
| op | string | yes | 操作種別 |
| to | string | – | 期間終了日(list_holidaysで必須) |
| year_end_as_holiday | boolean | – | 12/29〜1/3を非営業日として扱う(官公庁・銀行休業の慣行。既定false=祝日法と土日のみ) |
No output schema declared.
No examples provided.
normalize_address 日本住所の正規化・要素分解・郵便番号照合 ~279
日本の住所を正規化し、都道府県/市区町村/町字(大字・町名+丁目)に分解して町字ID(アドレス・ベース・レジストリ)を解決し、郵便番号と照合します(不一致は不一致として明示)。【v1の粒度と限界】分解は町字(大字・丁目)まで。街区符号・住居番号・地番・小字・京都の通り名は解析対象外で、未解析部分は残余文字列としてそのまま返します(推測補完なし)。データ源: アドレス・ベース・レジストリ町字マスター(デジタル庁)+日本郵便郵便番号データ(ローカルマスター駆動・政府API停止の影響なし)。
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | 日本の住所文字列(郵便番号含み可。全半角・漢数字/算用数字・旧字体の表記ゆれ可) |
| postal_code | string | – | 郵便番号を別引数で渡す場合に指定(住所文字列内の記載より優先して照合) |
No output schema declared.
No examples provided.
resolve_company 法人名から法人番号を解決 ~193
法人名(表記ゆれ・かな/カナ対応)から法人番号の候補と確度(0〜1+根拠ラベル)を返します。データ源: 国税庁法人番号システムWeb-API。
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | – | 所在地で絞り込み: 都道府県コード2桁(JIS X 0401)または+市区町村コード3桁の計5桁 |
| include_closed | boolean | – | 閉鎖法人を候補に含める(既定true) |
| limit | integer | – | 返却する候補数の上限(既定10) |
| name | string | yes | 法人名((株)等の略記・全半角・かな/カナ・旧字体の表記ゆれ可) |
No output schema declared.
No examples provided.
verify_company 法人番号の実在検証 ~133
法人番号(13桁・チェックディジット検証つき)から実在・商号・本店所在地・法人種別・閉鎖ステータスを返します。include_history=trueで商号変更等の履歴も返します。データ源: 国税庁法人番号システムWeb-API。
| Name | Type | Req | Description |
|---|---|---|---|
| corporate_number | string | yes | 法人番号13桁(全角・ハイフン・空白は吸収) |
| include_history | boolean | – | 商号変更等の履歴を含める(既定false) |
No output schema declared.
No examples provided.
verify_invoice_number 適格請求書発行事業者登録番号の検証 ~230
適格請求書発行事業者の登録番号(T+13桁)から登録有無・登録年月日・取消/失効を返します。on_dateで基準日時点の有効性判定、include_history=trueで公表履歴も返します。入力は登録番号のみ(氏名等による検索は提供しません)。データ源: 国税庁適格請求書発行事業者公表システムWeb-API。
| Name | Type | Req | Description |
|---|---|---|---|
| include_history | boolean | – | 公表履歴(新規登録・変更・取消・失効)を含める(既定false) |
| on_date | string | – | 基準日 YYYY-MM-DD(指定時はその日時点で登録が有効だったかを as_of で返す) |
| registration_number | string | yes | 適格請求書発行事業者登録番号(T+13桁。Tなし13桁・全角・ハイフン空白は吸収) |
No output schema declared.
No examples provided.
What is the HojinCheck — Japanese corporate verification API (hojin… MCP server?
HojinCheck — Japanese corporate verification API (hojin… is an MCP server listed in the public MCP registry as com.hojincheck/hojincheck. Verify Japanese companies, invoice-issuer registrations and addresses against government open data. This page covers its hosted endpoint (https://hojincheck.com/mcp).
Is the HojinCheck — Japanese corporate verification API (hojin… MCP server safe to use?
HojinCheck — Japanese corporate verification API (hojin… scores 83 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the HojinCheck — Japanese corporate verification API (hojin… MCP server expose?
HojinCheck — Japanese corporate verification API (hojin… exposes 6 tools: resolve_company, verify_company, verify_invoice_number, get_company_profile, normalize_address, jp_calendar. Their descriptions and schemas cost roughly 1,191 tokens of context every time the server is loaded.
Does the HojinCheck — Japanese corporate verification API (hojin… MCP server require authentication?
Yes. HojinCheck — Japanese corporate verification API (hojin… asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the HojinCheck — Japanese corporate verification API (hojin… MCP server still maintained?
HojinCheck — Japanese corporate verification API (hojin… is still listed as active in the MCP registry. We last reached this channel on 21 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.