KaiCalls
REMOTE · WWW.KAICALLS.COM · SCANNED AUG 4
AI phone secretary: place calls, read transcripts, list calls, agents, and stats.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security97
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- The endpoint enforces authorisation, advertised via RFC 9728 protected-resource metadata. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server supports Client ID Metadata Documents, the current MCP client-registration mechanism. View diagnostics → Pass
Transport & Reachability0
- Transport blocked by authentication: the endpoint requires auth we don't have to verify streamable-http. See how to fix → View diagnostics → Unverified
Schema Quality & AI Usability0
- Schema blocked by authentication: the endpoint requires auth we don't have to read it. See how to fix → Unverified
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage0
- Tool coverage blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Capabilities0
- Capabilities blocked by authentication: the endpoint requires auth we don't have to read them. See how to fix → Unverified
Unverified: 5 categories
Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · www.kaicalls.com
claude mcp add --transport http com-kaicalls-kaicalls https://www.kaicalls.com/api/mcp
[mcp_servers.com-kaicalls-kaicalls] url = "https://www.kaicalls.com/api/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-kaicalls-kaicalls": {
"type": "remote",
"url": "https://www.kaicalls.com/api/mcp",
"enabled": true
}
}
} openclaw mcp add com-kaicalls-kaicalls --url https://www.kaicalls.com/api/mcp --transport streamable-http
mcp_servers:
com-kaicalls-kaicalls:
url: "https://www.kaicalls.com/api/mcp" {
"mcpServers": {
"com-kaicalls-kaicalls": {
"type": "http",
"url": "https://www.kaicalls.com/api/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 1 Aug 26 −36
- Endpoint reachability: reachable → behind authorisation ▼ security
- Transport: pass → unverified ▼ security
- Stability: 0.17 → unverified ▼ security
- Authorization: The endpoint enforces authorisation, advertised via RFC 9728 protected-resource metadata. security
- Capabilities: fail → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- First check of Schema quality: unverified functional
- 31 Jul 26 +7
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 29 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.
- 27 Jul 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 66
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 4 Aug 2026 · Probed https://www.kaicalls.com/api/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=www.kaicalls.com | CN=YR2,O=Let's Encrypt,C=US | 20 Jun 2026 | 18 Sept 2026 | RSA 2048 | SHA256-RSA | 50bdac0ddc08bc0eedac503838df7e99aa4 |
| SANs: www.kaicalls.com | ||||||
| CN=YR2,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | 4ebd24947e24d394802d84a52fd5b319 |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
DNSSEC insecure
Validation of www.kaicalls.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| kaicalls.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On connection |
| HTTP status | 401 |
WWW-Authenticate challenge Bearer resource_metadata="https://www.kaicalls.com/.well-known/oauth-protected-resource", scope="agents:read calls:read calls:write"
Bearer resource_metadata="https://www.kaicalls.com/.well-known/oauth-protected-resource", scope="agents:read calls:read calls:write" | Header | Value |
|---|---|
| strict-transport-security | max-age=63072000 |
| www-authenticate | Bearer resource_metadata="https://www.kaicalls.com/.well-known/oauth-protected-resource", scope="agents:read calls:read calls:write" |
Protected resource metadata
| Document | https://www.kaicalls.com/.well-known/oauth-protected-resource |
|---|---|
| Retrieved | Yes |
| Resource | https://www.kaicalls.com/api/mcp |
| Authorisation server | https://www.kaicalls.com |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://www.kaicalls.com/api/mcp | Auth required | 401 | |
| http (plaintext) | http://www.kaicalls.com/api/mcp | HTTPS enforced | 308 | https://www.kaicalls.com/api/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
rollback_config Rollback Agent Configuration ~490
Roll an agent's deployed voice configuration back to a prior assistant_config_versions snapshot — restoring greeting, voice, prompt, and scalar model params (never secrets/credentials) onto the live agent. This OVERWRITES the live deployed config, so it is APPROVAL-GATED: without human-grade authority (an authority envelope with mode human_confirmed, or a dashboard approval) the tool executes nothing and returns a pending_approval record the business owner approves or denies from the dashboard — relay the returned confirmation text to them. Agent-initiated rollbacks never run unattended. Wraps the same version-restore logic as POST /api/v1/agents/rollback and the admin_rollback_change voice tool, via the agent.config.rollback update intent. Discover a target with list_config_versions or get_change_history. Every executed rollback records a new config version; to repeat a rollback that already executed, pass a fresh idempotency_key.
| Name | Type | Req | Description |
|---|---|---|---|
| actor | object | — | Who is asking: { type: agent|human|system|integration, id, display_name }. |
| agent_id | string | yes | Agent ID to roll back. |
| authority | object | — | How the rollback was authorized: { mode, confirmed_by, confirmed_at, confirmation_ref }. human_confirmed requires all three confirmation fields; anything weaker returns pending_approval. |
| business_id | string | — | Business ID (optional only when the token can access exactly one business). |
| dry_run | boolean | — | Validate tenant, scope, and policy without touching the live config. |
| idempotency_key | string | — | Stable key for the rollback request; repeating it returns the original outcome. Defaults to a key derived from agent + version — pass a fresh key to repeat a rollback that already executed. |
| queue_for_approval | boolean | — | When authority is insufficient, create a durable dashboard approval (default true). Set false to get needs_approval and retry yourself with the same idempotency_key once a human confirms. |
| reason | string | — | Optional human-readable reason recorded in the audit trail. |
| source_ref | string | — | External source reference, such as a ticket or automation run ID. |
| version_id | string | — | Target assistant_config_versions row id to restore. One of version_number/version_id is required. |
| version_number | integer | — | Target assistant_config_versions.version_number to restore. One of version_number/version_id is required. |
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | — | — |
| approval | object|null | — | — |
| business_id | string|null | — | — |
| code | string|null | — | — |
| error | string | — | Present when success is false |
| message | string|null | — | — |
| request_id | string|null | — | — |
| result | object|null | — | On executed: { agent_id, restored_from_version, restored_fields, skipped_fields, new_version_number, warning? }. |
| risk_level | string|null | — | — |
| status | string | — | — |
| success | boolean | yes | Whether the tool completed successfully |
| summary | object|null | — | — |
No examples provided.
run_eval Run Agent Eval ~127
Run a single eval scenario (eval_id) or every scenario for an agent (agent_id) against its live Vapi assistant and grade the result. Bills Vapi compute. Mirrors POST /api/v1/evals/run.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | — | Run every eval scenario for this agent. |
| eval_id | string | — | Run a single eval scenario by ID. |
| max_wait_ms | integer | — | Per-run wait cap in ms when wait is true (default 60000, max 110000). |
| wait | boolean | — | Block until the run completes (default true). |
| Name | Type | Req | Description |
|---|---|---|---|
| completed | integer|null | — | — |
| error | string | — | Present when success is false |
| failed | integer|null | — | — |
| passed | boolean|null | — | — |
| results | array|object|null | — | — |
| run_id | string|null | — | — |
| status | string|null | — | — |
| success | boolean | yes | Whether the tool completed successfully |
| total | integer|null | — | — |
| vapi_run_id | string|null | — | — |
No examples provided.
search_available_numbers Search Available Numbers ~84
Search the carrier for phone numbers available to purchase (real-time Twilio inventory lookup). Mirrors GET /api/v1/phone-numbers/search.
| Name | Type | Req | Description |
|---|---|---|---|
| area_code | string | — | Preferred area code (optional). |
| country | string | — | Two-letter country code (default US). |
| limit | integer | — | Max results to return (default 10, max 20). |
| Name | Type | Req | Description |
|---|---|---|---|
| available_numbers | array | — | — |
| error | string | — | Present when success is false |
| success | boolean | yes | Whether the tool completed successfully |
No examples provided.
send_sms Send SMS ~213
Send an outbound text message from one of your agents' phone lines to a recipient, routed through the governed messaging API. Compliance gates (opt-out / Do-Not-Call / quiet-hours), rate limits, and message logging all apply. Provide from_agent_id (the sending agent), to (recipient phone in E.164), and message. Optionally link lead_id to attribute the text and respect that lead's automation-pause state.
| Name | Type | Req | Description |
|---|---|---|---|
| from_agent_id | string | yes | Agent ID whose phone line the text is sent from. |
| idempotency_key | string | — | Optional caller-supplied key. A replay with the same key returns the original send outcome instead of sending again — use it when retrying after an uncertain response. |
| lead_id | string | — | Optional lead ID to link and honor the lead's automation-pause state. |
| message | string | yes | Text message body. |
| to | string | yes | Recipient phone number in E.164 format (e.g. +18135551234). |
| Name | Type | Req | Description |
|---|---|---|---|
| error | string | — | Present when success is false |
| from | string|null | — | — |
| message_sid | string|null | — | — |
| success | boolean | yes | Whether the tool completed successfully |
| to | string|null | — | — |
No examples provided.
set_webhook Set Webhook ~139
Create or update a business outbound webhook (URL + subscribed events). Returns a webhook secret on first creation only. Mirrors POST /api/v1/webhooks.
| Name | Type | Req | Description |
|---|---|---|---|
| business_id | string | — | Business ID (optional only when the token can access exactly one business). |
| description | string | — | Human label for this webhook. |
| events | array | — | Event types to subscribe to (see get_webhook for the supported list). |
| id | string | — | Existing webhook ID to update (omit to create new). |
| is_active | boolean | — | Enable or disable delivery. |
| webhook_url | string | yes | HTTPS/HTTP destination URL for event delivery. |
| Name | Type | Req | Description |
|---|---|---|---|
| business_id | string | — | — |
| error | string | — | Present when success is false |
| events | array | — | — |
| message | string | — | — |
| success | boolean | yes | Whether the tool completed successfully |
| webhook | object | — | — |
| webhook_secret | string|null | — | — |
No examples provided.
update_agent_config Update Agent Configuration ~464
Edit an agent's live runtime configuration — greeting/first message, inbound or SMS prompt, voice, language model, max call duration, and call-transfer settings — routed through the governed update broker so every change keeps the consent + audit trail (a versioned config snapshot and change history). Every write here is reversible: inspect what changed with get_change_history or list_config_versions, then undo it with rollback_config. Mutating changes need an idempotency_key; high-impact live changes need human authority (an authority envelope) or queue_for_approval for dashboard sign-off. For just a single named operational-rules section, prefer configure_agent_business_rules.
| Name | Type | Req | Description |
|---|---|---|---|
| actor | object | — | Who is asking: { type: agent|human|system|integration, id, display_name }. |
| agent_id | string | yes | KaiCalls agent ID to update. |
| authority | object | — | Human-grade authority for live changes: { mode: human_confirmed|dashboard_session|system_policy, confirmed_by, confirmed_at, confirmation_ref }. |
| business_id | string | — | Business ID. Required when the agent has multiple accessible assignments. |
| dry_run | boolean | — | Validate and summarize the change without writing. |
| first_message | string | — | Spoken greeting / first message callers hear. |
| idempotency_key | string | — | Required for writes. Reuse the same key when retrying the same change. |
| inbound_prompt | string | — | Full inbound system prompt that drives the agent. |
| max_duration | integer | — | Maximum call duration in seconds. |
| model | object | — | Language model selection: { provider, model, temperature }. |
| name | string | — | Agent display name. |
| outbound_prompt | string | — | Outbound (campaign) system prompt. |
| queue_for_approval | boolean | — | When authority is missing, create a pending dashboard approval instead of returning needs_approval. |
| sms_prompt | string | — | SMS reply prompt. |
| source_ref | string | — | External source reference, such as a support ticket or conversation ID. |
| transfer_enabled | boolean | — | Enable/disable live call transfer. |
| transfer_phone_number | string | — | Number to transfer qualified calls to. |
| voice | object | — | Voice selection: { provider, voiceId }. |
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string|null | — | — |
| approval | object|null | — | — |
| business_id | string|null | — | — |
| code | string|null | — | — |
| error | string | — | Present when success is false |
| message | string|null | — | — |
| request_id | string|null | — | — |
| result | object|null | — | — |
| risk_level | string|null | — | — |
| status | string | — | — |
| success | boolean | yes | Whether the tool completed successfully |
| summary | object|null | — | — |
No examples provided.
upsert_knowledge Create or Update Agent Knowledge ~120
Create a new agent knowledge base entry, or update one when `id` is provided. Mirrors POST /api/v1/knowledge. Creating requires title, content, and content_type.
| Name | Type | Req | Description |
|---|---|---|---|
| business_id | string | — | Business ID. Required for create when the token can access multiple businesses. |
| category | string | — | — |
| content | string | — | — |
| content_type | string | — | — |
| id | string | — | Knowledge item ID to update (omit to create). |
| tags | array | — | — |
| title | string | — | — |
| Name | Type | Req | Description |
|---|---|---|---|
| error | string | — | Present when success is false |
| knowledge | object|null | — | — |
| success | boolean | yes | Whether the tool completed successfully |
No examples provided.
upsert_lead Create or Update Lead ~256
Create a new lead or update existing leads for the authenticated business, routed through the governed leads API (business access-checked, usage-logged, and audited). To create one, pass `lead` with at least one of name/phone/email plus optional status/source/notes/agent_id/etc. To update, pass `updates`: an array of { id, ...fields } for one or many existing leads (status, name, phone, email, notes, address, city, state, zip). Updates are access-checked per row and report partial success.
| Name | Type | Req | Description |
|---|---|---|---|
| business_id | string | — | Business ID. Required for create when the API key can access multiple businesses. |
| lead | object | — | Fields for a NEW lead: name, first_name, last_name, phone, email, status, source, notes, address, city, state, zip, agent_id, message. At least one of name/phone/email is required. |
| updates | array | — | Update existing leads. Each item is { id, ...fields } where fields are a subset of name, first_name, last_name, email, phone, status, source, notes, address, city, state, zip. Max 100 per call. |
| Name | Type | Req | Description |
|---|---|---|---|
| error | string | — | Present when success is false |
| failed | integer|null | — | — |
| lead | object|null | — | — |
| operation | string | — | create or update |
| results | array|null | — | — |
| success | boolean | yes | Whether the tool completed successfully |
| updated | integer|null | — | — |
No examples provided.
upsert_product Create or Update Agent Product ~140
Create a new product row, or update one when `id` is provided. Mirrors POST /api/v1/products. Creating requires name and business_id. Pass `quantity` to set/update inventory.
| Name | Type | Req | Description |
|---|---|---|---|
| attributes | object | — | — |
| business_id | string | — | Business ID. Required for create when the token can access multiple businesses. |
| category | string | — | — |
| description | string | — | — |
| id | string | — | Product ID to update (omit to create). |
| name | string | — | — |
| price | number | — | — |
| quantity | number | — | Inventory quantity to set (optional). |
| sku | string | — | — |
| Name | Type | Req | Description |
|---|---|---|---|
| error | string | — | Present when success is false |
| product | object|null | — | — |
| success | boolean | yes | Whether the tool completed successfully |
No examples provided.