Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Jithox Commerce Preflight

REMOTE · COMMERCE.MCP.JITHOX.COM · SCANNED AUG 15

Provider-neutral, read-only commerce preflight with UCP/ACP checkout evidence. Never orders.

+4 this week 74 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →

Endpoint Security80
Transport & Reachability100
Schema Quality & AI Usability66
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 1244 tokens (~248/item across 5 items; 5 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
  • Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Capabilities100
  • Implements a current MCP spec version (2026-07-28).Pass
Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

remote · commerce.mcp.jithox.com

# add to Claude Code
claude mcp add --transport http com-jithox-be-commerce-preflight https://commerce.mcp.jithox.com/mcp
# ~/.codex/config.toml
[mcp_servers.com-jithox-be-commerce-preflight]
url = "https://commerce.mcp.jithox.com/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-jithox-be-commerce-preflight": {
      "type": "remote",
      "url": "https://commerce.mcp.jithox.com/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add com-jithox-be-commerce-preflight --url https://commerce.mcp.jithox.com/mcp --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  com-jithox-be-commerce-preflight:
    url: "https://commerce.mcp.jithox.com/mcp"
// mcp.json
{
  "mcpServers": {
    "com-jithox-be-commerce-preflight": {
      "type": "http",
      "url": "https://commerce.mcp.jithox.com/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 14 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.

  • 12 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 13 to 17. That category is still filling its 30-day observation window: 4 days of observed history at the previous scan, 5 at this one. The score rises as the window fills, whether or not the server changes.

  • 11 Aug 26 +1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 10 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

  • 8 Aug 26 −2
    • The server rewrote its instructions, which are the text every model session reads security
    • Tool “get_commerce_readiness” rewrote its description, which is the text the model reads security
    • Tool “get_product_offer” rewrote its description, which is the text the model reads security
    • Tool “search_retail_products” rewrote its description, which is the text the model reads security
    • Tool “build_affiliate_buy_link” rewrote its description, which is the text the model reads security
    • Tool “compare_product_offers” rewrote its description, which is the text the model reads security
    • Schema quality: 171 → 248 functional
    • Stability: unverified → 0.03 functional
    • Server version: 0.1.1 → 0.2.0 functional
    • “get_product_offer” added an optional parameter “itemId” cosmetic
    • “get_product_offer” added an optional parameter “priorEvidence” cosmetic
    • “get_product_offer” added an optional parameter “quantity” cosmetic
    • “get_product_offer” added an optional parameter “merchant” cosmetic
    • Tool “get_product_offer” changed its title: Get one product's current offer → Get one product's current offer or checkout evidence cosmetic
    • Tool “search_retail_products” changed its title: Search Belgian retail products → Search retail products cosmetic
  • 7 Aug 26 72

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 15 Aug 2026 · Probed https://commerce.mcp.jithox.com/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=commerce.mcp.jithox.com CN=YE2,O=Let's Encrypt,C=US 7 Aug 2026 5 Nov 2026 ECDSA 256 ECDSA-SHA384 51baa361be3034e5d3876120130b7a9f724
SANs: commerce.mcp.jithox.com
CN=YE2,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 4df3b15dd6c0784c507cd37b58e6f115
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd
DNSSEC insecure

Validation of commerce.mcp.jithox.com. Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
jithox.com. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200
Header Value
strict-transport-security max-age=31536000; includeSubDomains
x-content-type-options nosniff
x-frame-options DENY
referrer-policy no-referrer
Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://commerce.mcp.jithox.com/mcp Verified 200
http (plaintext) http://commerce.mcp.jithox.com/mcp HTTPS enforced 308 https://commerce.mcp.jithox.com/mcp
MCP tools · 5 exposed · ~1,031 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
build_affiliate_buy_link ~137

Return the provider's OFFICIAL product link for a record — no network call, nothing ordered, never a checkout-completion URL. A HUMAN clicks it; any commission accrues at the provider's own partner programme, never through this server. 'ready' when the provider publishes a link; 'unsupported' when it does not; truthful 'not_configured' (costs nothing) without a provider. Preflight evidence only — this server never places, modifies or cancels an order and never touches a payment; the merchant stays merchant of record.

NameTypeReqDescription
publicRecordIdstringyesThe public record id to link to.
NameTypeReqDescription
billingobjectyes
capabilityyes
dataobjectyes
decisionstringyes
decisionCategorystringyes
generatedAtstringyes
limitationsarrayyes
productyes
provenanceobjectyes
receiptyes
receiptEnvelopeobject
retryablebooleanyes
schemaVersionyes

No examples provided.

compare_product_offers ~181

Compare current offers for 2–5 EANs as a VALUE TABLE ordered by a stated criterion (price ascending). One unreadable offer makes the whole table 'unavailable' — no partial table is sold as a comparison. A table, never a ranking sold as advice, never a 'best product'. Answers come from the queried source at the stated retrieval time — a UCP or ACP merchant, a partner catalog source, or a clearly-labelled synthetic fixture in dev/test; provenance.sourceAuthority names which, and every answer carries the markets that source declares. Preflight evidence only — this server never places, modifies or cancels an order and never touches a payment; the merchant stays merchant of record.

NameTypeReqDescription
eansarrayyesEANs to compare; a comparison needs at least 2 (fewer returns 'insufficient_identifiers').
NameTypeReqDescription
billingobjectyes
capabilityyes
dataobjectyes
decisionstringyes
decisionCategorystringyes
generatedAtstringyes
limitationsarrayyes
productyes
provenanceobjectyes
receiptyes
receiptEnvelopeobject
retryablebooleanyes
schemaVersionyes

No examples provided.

get_commerce_readiness ~108

One plain state of THIS server: which commerce provider is configured, which protocols this deployment speaks (UCP profile discovery + negotiation; the ACP REST checkout format), what each protocol still needs before live evidence exists, and the affiliate state. 'ready' / 'not_configured'. Truthful self-description, never a claim about any merchant. Preflight evidence only — this server never places, modifies or cancels an order and never touches a payment; the merchant stays merchant of record.

Input schema present but exposes no named parameters.

NameTypeReqDescription
billingobjectyes
capabilityyes
dataobjectyes
decisionstringyes
decisionCategorystringyes
generatedAtstringyes
limitationsarrayyes
productyes
provenanceobjectyes
receiptyes
receiptEnvelopeobject
retryablebooleanyes
schemaVersionyes

No examples provided.

get_product_offer ~384

Report one product's current offer from the queried source (price in integer minor units, availability, provenance) — or, given a merchant host plus the merchant's own itemId, prepare/re-check NORMALIZED CHECKOUT EVIDENCE over the merchant's declared UCP/ACP checkout data: items, currency, subtotal, discount, tax, fees, shipping, total, fulfillment, policy links, expiry and an evidence hash, with bounded truth states 'verified' / 'changed' / 'unsupported' / 'unavailable' / 'unverified'. Pass priorEvidence (component hashes from an earlier answer) to detect price/stock/shipping/terms changes between preparation and re-check. 'verified' means fetched, parsed and internally consistent — never 'safe', never 'approved', never a guarantee the merchant honors the quote. A price is never guessed. Answers come from the queried source at the stated retrieval time — a UCP or ACP merchant, a partner catalog source, or a clearly-labelled synthetic fixture in dev/test; provenance.sourceAuthority names which, and every answer carries the markets that source declares. Preflight evidence only — this server never places, modifies or cancels an order and never touches a payment; the merchant stays merchant of record.

NameTypeReqDescription
eanstringEAN/GTIN of the product.
itemIdstringThe merchant's own item id (required with merchant).
merchantstringA merchant hostname for checkout evidence (must be on this deployment's allowlist or served by a configured provider).
priorEvidenceobjectcomponentHashes from a prior evidence answer — presence turns this call into a re-check with per-component change detection.
publicRecordIdstringA public record id from a prior search.
quantityintegerQuantity for the checkout evidence quote (default 1).
NameTypeReqDescription
billingobjectyes
capabilityyes
dataobjectyes
decisionstringyes
decisionCategorystringyes
generatedAtstringyes
limitationsarrayyes
productyes
provenanceobjectyes
receiptyes
receiptEnvelopeobject
retryablebooleanyes
schemaVersionyes

No examples provided.

search_retail_products ~221

Search the queried retail source by free text or EAN. Returns CANDIDATE public records with deterministic match kinds and visible ambiguity: 'exact_public_record' / 'possible_match' / 'multiple_matches' / 'no_match_in_queried_source' — a no-match is never 'not sold', only 'not in the source we queried'. A provider without a search surface → 'unsupported'; outage → 'unavailable'; unconfigured source → 'not_configured' (costs nothing). Answers come from the queried source at the stated retrieval time — a UCP or ACP merchant, a partner catalog source, or a clearly-labelled synthetic fixture in dev/test; provenance.sourceAuthority names which, and every answer carries the markets that source declares. Preflight evidence only — this server never places, modifies or cancels an order and never touches a payment; the merchant stays merchant of record.

NameTypeReqDescription
eanstringEAN/GTIN for an exact lookup.
querystringFree-text search (title/brand).
NameTypeReqDescription
billingobjectyes
capabilityyes
dataobjectyes
decisionstringyes
decisionCategorystringyes
generatedAtstringyes
limitationsarrayyes
productyes
provenanceobjectyes
receiptyes
receiptEnvelopeobject
retryablebooleanyes
schemaVersionyes

No examples provided.