# Loppee (remote · loppee.com)

Agent-first US business trust registry with neutral Trust Cards and local search.

- Trust score: 63/100 (medium)
- Change this week: +5
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- remote · `loppee.com`: 63/100 (this document), [markdown](https://verifymcp.io/servers/com-loppee-loppee/loppee.md), [page](https://verifymcp.io/servers/com-loppee-loppee/loppee)

## Channel facts

- Endpoint: `https://loppee.com/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `0.1.1`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Endpoint Security**: 63/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (set_admin_business_lifecycle).
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 53/100
  - 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).
  - AI-judged instruction clarity (poor).
  - Context-footprint check failed: tool/resource definitions use about 14083 tokens (~234/item across 60 items; 58 tools + 2 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 26/100
  - Stability check failed: schema churn in the 8 days we've observed: 0 tool removals, 1 breaking changes, 0 auth/transport breaks, 1 additions.
- **Tool Coverage**: 87/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 53% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### Claude

```bash
claude mcp add --transport http com-loppee-loppee https://loppee.com/mcp
```

### Codex

```toml
[mcp_servers.com-loppee-loppee]
url = "https://loppee.com/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-loppee-loppee": {
      "type": "remote",
      "url": "https://loppee.com/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add com-loppee-loppee --url https://loppee.com/mcp --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  com-loppee-loppee:
    url: "https://loppee.com/mcp"
```

### Other

```json
{
  "mcpServers": {
    "com-loppee-loppee": {
      "type": "http",
      "url": "https://loppee.com/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-02 (score 63, +1)

- [security] The server rewrote its instructions, which are the text every model session reads
- [security] Tool “lookup_business” rewrote its description, which is the text the model reads
- [security] Tool “recommend_businesses” rewrote its description, which is the text the model reads
- [security] Tool “submit_review_for_moderation” rewrote its description, which is the text the model reads
- [security] Tool “compare_businesses” rewrote its description, which is the text the model reads
- [security] Tool “decide_admin_manual_verification_submission” rewrote its description, which is the text the model reads
- [security] Tool “explain_recommendation” rewrote its description, which is the text the model reads
- [security] Tool “get_business_reviews” rewrote its description, which is the text the model reads
- [security] Tool “get_trust_card” rewrote its description, which is the text the model reads
- [cosmetic] “submit_review_for_moderation” added an optional parameter “customer_confirmed”
- [cosmetic] “decide_admin_manual_verification_submission” added an optional parameter “owner_reason_code”
- [cosmetic] “decide_admin_manual_verification_submission” reworded the description of “source_authority”
- [cosmetic] “decide_admin_manual_verification_submission” reworded the description of “source_url”

### 2026-07-31 (score 62, +3)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-29 (score 59, +1)

- [security regression] Stability: 0.03 → fail

### 2026-07-27 (score 58, +1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-26 (score 57)

First indexed and scored.

## MCP tools (58)

### `get_agent_capabilities` (~27 tokens)

Get Agent Capabilities

Return the Loppee agent contract, endpoints, policy rules, and available MCP tools.

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `get_pricing_plans` (~147 tokens)

Get Loppee Pricing Plans

Return Loppee's published exposure plans, feature bullets, branch add-ons, and promotions. Editing exposure-plan prices or promotions cannot change publication, verification class, review authority, reputation, moderation, or class ordering. Loppee Jobs is billed separately and affects job-posting activation only. Exposure-plan payment changes discovery reach and, when Sponsored ordering is active, labeled position-weighted exposure only within the same verification class and verified-review reputation band. It never changes business-profile publication, verification, review authority, reputation, moderation, class ordering, or reputation band. Loppee Jobs is a separate optional paid product; its billing affects job-posting activation only and never business verification or directory ranking.

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `search_businesses` (~856 tokens)

Search Businesses

Search Loppee's closed taxonomy or use universal business-name lookup. A customer personal agent first calls get_location_options and asks exactly: "Where should I search? For local categories, share your current location or use Home only when it is marked exact. Another city/ZIP is for area context or business-name lookup only." Use current, or saved only when the returned kind is saved_exact, for local category discovery. Provided city/ZIP and coarse Home are name-disambiguation context only. Other personas cannot access customer location authority and therefore cannot run local category discovery. Never infer a choice or expose coordinates. Local category discovery and recommendations require a current precise location proof or handoff, or a saved_exact Home location. City/state, ZIP, provider IP, saved_coarse locations, and caller-supplied coordinates are neutral area context for business-name disambiguation only: they return no local category or recommendation results, cannot activate Sponsored placement, and record no impressions. Exact and genuine-prefix business-name lookup remains universal; without precise location it is commercially neutral. Exposure-plan payment changes discovery reach and, when Sponsored ordering is active, labeled position-weighted exposure only within the same verification class and verified-review reputation band. It never changes business-profile publication, verification, review authority, reputation, moderation, class ordering, or reputation band. Loppee Jobs is a separate optional paid product; its billing affects job-posting activation only and never business verification or directory ranking.

Input parameters:

- `category` (string): Taxonomy category alias or category term. Resolved categories require current precise-location authority or saved_exact; coarse context returns no local results.
- `city` (string): City context. With state, it can disambiguate a business name but cannot enable local category/recommendation reach, Sponsored placement, or impressions.
- `cursor` (string): Opaque cursor returned in next_cursor by the previous v3 search page. Omit for the first page.
- `include_directory_listings` (boolean): Include honestly labeled, unverified directory listings for discovery.
- `intent` (string): Routing hint: auto resolves taxonomy first; category and name force their respective lanes.
- `limit` (integer): Maximum result count from 1 to 50.
- `location_handoff_id` (string): Opaque current precise-location handoff approved by the consumer. It can authorize local category/recommendation reach and Sponsored exposure. Requires the same active scoped consumer-agent key that…
- `location_selection` (string): The customer's explicit location choice. Current, or Home when reach_precision=exact, can authorize local category/recommendation discovery. Provided city/ZIP and coarse Home are neutral area context…
- `q` (string): Free-text search. Category terms auto-route to precise-location-gated discovery; otherwise exact and genuine-prefix business-name lookup is universal and commercially neutral without precise location.
- `radius_miles` (number): Requested area radius. It never substitutes for a current precise location proof/handoff or saved_exact authority. Universal name lookup may use it only as neutral context.
- `saved_location_ref` (string): Opaque saved-location reference returned by get_location_options. Required with location_selection=saved. Only kind=saved_exact authorizes local category/recommendation reach; coarse saved kinds rema…
- `state` (string): Two-letter US state or territory code. With city, this is neutral area context for business-name disambiguation; it is not precise local-discovery authority.
- `zip` (string): 5-digit US ZIP (ZIP+4 accepted). Its ZCTA centroid is neutral area context for business-name disambiguation only; it cannot enable local category/recommendation reach, Sponsored placement, or impress…

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `search_category` (~705 tokens)

Search Category

Local category discovery requires current or Home with kind=saved_exact. Provided city/ZIP, coarse Home, and provider IP return no results with commercial_influence=none and record no impressions. Other agent personas cannot access customer location authority and therefore cannot run this local category lane. Local category discovery and recommendations require a current precise location proof or handoff, or a saved_exact Home location. City/state, ZIP, provider IP, saved_coarse locations, and caller-supplied coordinates are neutral area context for business-name disambiguation only: they return no local category or recommendation results, cannot activate Sponsored placement, and record no impressions. Exact and genuine-prefix business-name lookup remains universal; without precise location it is commercially neutral. Exposure-plan payment changes discovery reach and, when Sponsored ordering is active, labeled position-weighted exposure only within the same verification class and verified-review reputation band. It never changes business-profile publication, verification, review authority, reputation, moderation, class ordering, or reputation band. Loppee Jobs is a separate optional paid product; its billing affects job-posting activation only and never business verification or directory ranking.

Input parameters:

- `category` (string, required): Taxonomy category alias or natural category term. Local results require a current precise proof/handoff or saved_exact authority.
- `city` (string): City context. With state, it can disambiguate a business name but cannot enable local category/recommendation reach, Sponsored placement, or impressions.
- `cursor` (string): Opaque cursor returned in next_cursor by the previous v3 search page. Omit for the first page.
- `limit` (integer): Maximum result count from 1 to 50.
- `location_handoff_id` (string): Opaque current precise-location handoff approved by the consumer. It can authorize local category/recommendation reach and Sponsored exposure. Requires the same active scoped consumer-agent key that…
- `location_selection` (string): The customer's explicit location choice. Current, or Home when reach_precision=exact, can authorize local category/recommendation discovery. Provided city/ZIP and coarse Home are neutral area context…
- `radius_miles` (number): Requested area radius. It never substitutes for a current precise location proof/handoff or saved_exact authority. Universal name lookup may use it only as neutral context.
- `saved_location_ref` (string): Opaque saved-location reference returned by get_location_options. Required with location_selection=saved. Only kind=saved_exact authorizes local category/recommendation reach; coarse saved kinds rema…
- `state` (string): Two-letter US state or territory code. With city, this is neutral area context for business-name disambiguation; it is not precise local-discovery authority.
- `zip` (string): 5-digit US ZIP (ZIP+4 accepted). Its ZCTA centroid is neutral area context for business-name disambiguation only; it cannot enable local category/recommendation reach, Sponsored placement, or impress…

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `lookup_business` (~216 tokens)

Lookup Business

Universal, pay-independent business-name lookup. Exact and genuine-prefix matches remain relevance-authoritative and return the requested entity with its truthful Verified, Listed, or claim-state-accurate Registry classification. Coarse location may disambiguate names only; without precise authority results are commercially neutral, sponsored=false, and record no impressions. Exposure-plan payment changes discovery reach and, when Sponsored ordering is active, labeled position-weighted exposure only within the same verification class and verified-review reputation band. It never changes business-profile publication, verification, review authority, reputation, moderation, class ordering, or reputation band. Loppee Jobs is a separate optional paid product; its billing affects job-posting activation only and never business verification or directory ranking.

Input parameters:

- `cursor` (string): Opaque cursor returned in next_cursor by the previous v3 search page. Omit for the first page.
- `limit` (integer): Maximum result count from 1 to 50.
- `name` (string, required): Business name to look up through the universal, pay-independent name lane.

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `recommend_businesses` (~893 tokens)

Recommend Businesses

Return category recommendations in explicit Verified, Listed, reviewed_registry, and fallback_registry sections. Published Verified and Listed businesses come first; identity-reviewed Registry rows may fill only within the one-mile Free reach. fallback_registry may contain at most one unrated unclaimed Registry row and only when every higher-authority pool is empty. Owner-submitted and claimed-but-unpublished Registry records are never fallback results. Registry rows retain claim status and remain outside published Verified/Listed classes; the recommendation rationale is carried on the returned recommend row. Exact fallback warning: This unclaimed business has no identity-verified reviewer ratings. Loppee has not verified it; the customer should independently check the business before making contact or booking service. Local category recommendations require current precise authority or Home with kind=saved_exact; coarse context returns no local results or commercial exposure. Local category discovery and recommendations require a current precise location proof or handoff, or a saved_exact Home location. City/state, ZIP, provider IP, saved_coarse locations, and caller-supplied coordinates are neutral area context for business-name disambiguation only: they return no local category or recommendation results, cannot activate Sponsored placement, and record no impressions. Exact and genuine-prefix business-name lookup remains universal; without precise location it is commercially neutral. Sponsored share-of-voice ordering is active only within one verification class and one verified-review half-star band. Paid tier entitlement is position-weighted, every paid placement is labeled with sponsored=true, eligible Free businesses retain a 25% exposure floor, and direct entity/name lookup is exempt from rotation. Exposure-plan payment changes discovery reach and, when Sponsored ordering is active, labeled position-weighted exposure only within the same verification class and…

Input parameters:

- `allowed_action` (string): Require a published allowed action such as recommend or call_business.
- `category` (string): Business category or taxonomy term. Local recommendations require a current precise proof/handoff or saved_exact authority.
- `city` (string): City context. With state, it can disambiguate a business name but cannot enable local category/recommendation reach, Sponsored placement, or impressions.
- `limit` (integer): Maximum result count from 1 to 50.
- `location_handoff_id` (string): Opaque current precise-location handoff approved by the consumer. It can authorize local category/recommendation reach and Sponsored exposure. Requires the same active scoped consumer-agent key that…
- `location_selection` (string): The customer's explicit location choice. Current, or Home when reach_precision=exact, can authorize local category/recommendation discovery. Provided city/ZIP and coarse Home are neutral area context…
- `q` (string): Free-text search across the published pool. Exact and genuine-prefix name lookup remains universal; category recommendations require precise location authority.
- `radius_miles` (number): Requested area radius. It never substitutes for a current precise location proof/handoff or saved_exact authority. Universal name lookup may use it only as neutral context.
- `saved_location_ref` (string): Opaque saved-location reference returned by get_location_options. Required with location_selection=saved. Only kind=saved_exact authorizes local category/recommendation reach; coarse saved kinds rema…
- `state` (string): Two-letter US state or territory code. With city, this is neutral area context for business-name disambiguation; it is not precise local-discovery authority.
- `zip` (string): 5-digit US ZIP (ZIP+4 accepted). Its ZCTA centroid is neutral area context for business-name disambiguation only; it cannot enable local category/recommendation reach, Sponsored placement, or impress…

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `search_jobs` (~523 tokens)

Search Jobs

Discover active schema.org-aligned Loppee jobs from currently Verified, published employers. Every employer carries the exact v3 Verified class disclosure and no numeric verification metric. Location and job filters remain commercially neutral. Exposure-plan payment changes discovery reach and, when Sponsored ordering is active, labeled position-weighted exposure only within the same verification class and verified-review reputation band. It never changes business-profile publication, verification, review authority, reputation, moderation, class ordering, or reputation band. Loppee Jobs is a separate optional paid product; its billing affects job-posting activation only and never business verification or directory ranking.

Input parameters:

- `category` (string): Field/domain filter resolved against the same closed category taxonomy as businesses (aliases + synonyms, e.g. 'hvac' or 'ac repair'); unresolvable terms fall back to free-text category matching.
- `city` (string): City filter.
- `employment_type` (string): Employment type.
- `experience_level` (string): Experience-level filter (substring match, e.g. 'entry', 'senior').
- `include_remote` (boolean): Default true: remote roles bypass ZIP/radius location filters. Set false to exclude remote roles from located searches.
- `job_id` (string): Exact posting lookup — the id behind the /jobs/{job_id} page.
- `lat` (number): Latitude for radius search (use with lng and radius_miles).
- `limit` (integer): Maximum result count.
- `lng` (number): Longitude for radius search.
- `offset` (integer): Pagination offset into the ranked result set.
- `posted_within_days` (integer): Only roles published within the last N days.
- `q` (string): Role/keyword search across job title, description, category, skills, experience, and location. Typo-tolerant (trigram word similarity).
- `radius_miles` (number): Radius in miles around lat/lng. Remote roles are included regardless of distance unless include_remote=false.
- `salary_max` (number): Annualized USD salary ceiling.
- `salary_min` (number): Annualized USD salary floor (hourly salaries compare at x2080, monthly at x12). Jobs without a disclosed salary are excluded when set.
- `sort` (string): Result ordering; both are commercially neutral. Default relevance (text/location fit + recency).
- `state` (string): Two-letter US state filter.
- `workplace_type` (string): Workplace type.
- `zip` (string): 5-digit US ZIP filter, matched against the posting's postal code.

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `get_trust_card` (~99 tokens)

Get Trust Card

Fetch the public v3 Trust Card for one published business or visible Registry-page business by business_id; domain_key remains published-only. Both use the same Trust Card contract. A Registry card retains its exact claim status and disclosure, remains outside the published Verified/Listed classes, and never fabricates missing facts.

Input parameters:

- `business_id` (string): Loppee business id.
- `domain_key` (string): Normalized domain key such as example-com.

Output parameters:

- `contract_version` (string)
- `data`
- `error` (object)
- `ok` (boolean)

### `get_business_reviews` (~177 tokens)

Get Business Reviews (paginated)

Read public reviews for a published business or visible Registry-page business. Every review stays visible. reviewer_verification_label and quality_ranking_weight expose Passkey-or-verified-phone quality authority separately from verification_label and ranking_weight interaction evidence. Unqualified legacy reviews remain visible with quality_ranking_weight=0. Verified reviewer means the registered account completed Passkey or phone verification. It does not prove a transaction or government identity.

Input parameters:

- `business_id` (string, required): Loppee business id of a published business.
- `limit` (integer): Reviews per page (default 5, max 50).
- `page` (integer): 1-based page number (default 1).
- `ratings` (array): Star-rating filter: return only reviews with these ratings, e.g. [1] or [4,5]. Omit for all ratings.

Output parameters:

- `contract_version` (string)
- `data`
- `error` (object)
- `ok` (boolean)

### `explain_recommendation` (~73 tokens)

Explain Recommendation

Explain one published business's v3 class and exact disclosure. Registry recommendation rationale remains on the category recommend row; explain_recommendation stays published-only because a business_id alone cannot prove the prior category, location, and fallback context.

Input parameters:

- `business_id` (string, required): Loppee business id of a published Trust Card.

Output parameters:

- `contract_version` (string)
- `data`
- `error` (object)
- `ok` (boolean)

### `compare_businesses` (~159 tokens)

Compare Businesses

Compare published businesses only, in request order, by explicit v3 class and identity-verified-reviewer quality context. Registry rows remain unavailable on this tool. Every row retains its exact disclosure; payment never affects reviewer quality. Exposure-plan payment changes discovery reach and, when Sponsored ordering is active, labeled position-weighted exposure only within the same verification class and verified-review reputation band. It never changes business-profile publication, verification, review authority, reputation, moderation, class ordering, or reputation band. Loppee Jobs is a separate optional paid product; its billing affects job-posting activation only and never business verification or directory ranking.

Input parameters:

- `business_ids` (array, required): Two to twenty Loppee business ids to compare. Duplicates are de-duplicated.

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `get_agent_identity` (~119 tokens)

Get Agent Identity

Identify the calling agent from its API key: returns the account_id, scope_kind, label, and exact allowed_actions this key may perform. It also states explicitly that the connecting principal supplies and operates the external agent while Loppee issues only scoped API/MCP access. Call this first to confirm a key is wired correctly and to discover this agent's permissions before attempting any write tool. Requires a valid agent API key (X-LOPPEE-API-Key or Authorization: Bearer); returns an auth error when the key is missing or revoked.

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `get_admin_overview` (~51 tokens)

Get Back-office Overview

Read the Loppee back-office queue totals and launch checks. Requires a team/admin-agent key whose exact allowed_actions include view. This is a Back-office tool; consumer and business-owner keys cannot call it.

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `get_admin_analytics` (~66 tokens)

Get Back-office Analytics

Read bounded Back-office operational and projected-revenue analytics. Requires a team/admin-agent key whose exact allowed_actions include view_financial; a view-only key cannot call it. This tool is read-only and never changes billing, placement, verification, or publication.

Input parameters:

- `days`

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `list_admin_businesses` (~123 tokens)

List Back-office Businesses

Search and page the Loppee business-operations pipeline. Requires a team/admin-agent key with view. V3 results expose only the current Verified or Listed class and private operational completion, never a public numeric grade. This tool never edits a business.

Input parameters:

- `category` (string)
- `claim_status` (string)
- `cursor` (string)
- `limit` (integer)
- `search` (string)
- `sort` (string)
- `source` (string)
- `state` (string)
- `status` (string)

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `set_admin_business_lifecycle` (~111 tokens)

Suspend or Restore a Business

Suspend an active business from public surfaces or restore a suspended business without changing its pipeline status. Requires a team/admin-agent key with the exact publish action; suspend requires an enumerated reason and other requires detail. Archive, unarchive, and deletion are mechanically unavailable to this tool and remain human-only. Every successful transition uses the existing transactional audit path.

Input parameters:

- `action` (string, required)
- `business_id` (string, required)
- `reason_code` (string)
- `reason_detail` (string)

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `list_admin_verification_cases` (~71 tokens)

List Back-office Verification Cases

List the server-owned verification work queue. Requires a team/admin-agent key with view. Reading a case never changes its class, evidence, publication, or assignment.

Input parameters:

- `cursor` (string)
- `filter` (string)
- `limit` (integer)
- `search` (string)

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `get_admin_verification_case` (~62 tokens)

Get Back-office Verification Case

Open one audited verification case file by business_id. Requires a team/admin-agent key with view. The response is the same minimized v3 projection used by the Back-office and never grants authority to change the business class.

Input parameters:

- `business_id` (string, required)

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `list_admin_manual_verification_submissions` (~89 tokens)

List Manual Verification Submissions

Read the private entity/license manual-review queue. Requires a team/admin-agent key whose exact allowed_actions include complete_manual_verification. Signed document links are short lived; raw storage references are never returned. Merely reading a document cannot mint Verified.

Input parameters:

- `limit` (integer)
- `offset` (integer)
- `q` (string)
- `status` (string)

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `decide_admin_manual_verification_submission` (~378 tokens)

Decide Manual Verification Submission

Approve or reject one current entity/license submission through Loppee's audited manual authority. Rejection should include a controlled owner_reason_code plus a separate internal reason; omission maps to the controlled generic other copy only for legacy compatibility, and approval forbids owner_reason_code. Every official_source_manual decision requires the exact nonempty authority name and valid HTTPS source URL; document_review cannot carry an external source. official_record_not_found is additionally limited to a rejected official_source_manual review. Requires a team/admin-agent key with the separately granted complete_manual_verification action, all method-specific checks, a validity window for approval, and the exact type-to-confirm phrase. The database reauthorizes the exact key and derives the class; the agent cannot set a class or approve its own evidence. Insurance is not accepted by this tool.

Input parameters:

- `active_or_good_standing` (boolean)
- `confirmation` (string, required)
- `holder_name_match` (boolean)
- `identifier_match` (boolean)
- `observed_at` (string)
- `outcome` (string, required)
- `owner_reason_code` (string): Controlled owner-visible rejection reason. New clients should always send it for rejection; omission maps to other only for legacy compatibility. official_record_not_found is valid only for a rejecte…
- `reason` (string, required)
- `source_authority` (string): Exact official authority name. Required for every official_source_manual decision; document_review cannot carry an external authority.
- `source_url` (string): Exact HTTPS official source URL. Required for every official_source_manual decision and forbidden for document_review.
- `submission_id` (string, required)
- `valid_until` (string)
- `verification_method` (string, required)
- `verified_service_scope` (array)

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `list_admin_review_anomalies` (~72 tokens)

List Review Anomaly Flags

Read the private flag-only review-anomaly queue. Requires a team/admin-agent key with moderate_reviews. Flags never auto-hide, remove, or reweight a review and never change a business class.

Input parameters:

- `limit` (integer)
- `offset` (integer)
- `status` (string)

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `resolve_admin_review_anomaly` (~88 tokens)

Resolve Review Anomaly Flag

Resolve or ignore one anomaly flag with a recorded reason and exact confirmation. Requires a team/admin-agent key with moderate_reviews. This changes only the flag; it cannot hide/remove the review, change review weight, or change a business class.

Input parameters:

- `confirm` (string, required)
- `flag_id` (string, required)
- `resolution_note` (string, required)
- `status` (string, required)

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `list_admin_business_claims` (~62 tokens)

List Business Claims

Page the full business-ownership claim queue. Requires a team/admin-agent key with review_intake. This read never grants ownership or changes a claim.

Input parameters:

- `filter` (string)
- `limit` (integer)
- `offset` (integer)

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `triage_admin_business_claim` (~107 tokens)

Triage Business Claim

Reject a business claim or request more evidence. Requires a team/admin-agent key with review_intake, a non-empty reason, and the exact decision-matched confirmation phrase; it retains the existing audit and notification flow. Ownership approval is intentionally absent: only a freshly stepped-up human admin with verify_evidence can approve and grant ownership.

Input parameters:

- `claim_id` (string, required)
- `confirmation` (string, required)
- `decision` (string, required)
- `review_notes` (string, required)

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `revoke_my_key` (~211 tokens)

Revoke My Key

Immediately and irreversibly revoke the API key THIS call authenticates with — the agent-side 'delete my key' for connection hygiene (e.g. the key may be exposed, the integration is being retired, or the user asked to disconnect). Possession of the key is the authorization: it can only ever revoke itself, never another key or account, and it removes access rather than granting any. Takes effect on the next request (key validation is a live database check, so there is no cache window). The revocation is written to the audit log before the key is disabled. Requires confirm:true — without it the tool returns confirm_required and changes nothing. A new key can only be issued by the account's human owner from their Loppee dashboard (or by an admin); this tool cannot mint keys. Operator keys configured in the server environment return env_key_not_revocable. Call get_agent_identity first if you need to confirm which account and label this key belongs to.

Input parameters:

- `confirm` (boolean, required)

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `save_business` (~204 tokens)

Save Business

Attach a published business or directory listing to a customer/service-agent account workflow (a shortlist — it does not contact the business). The shortlist round-trips: read it back with list_saved_businesses and prune entries with unsave_business. Requires a valid scoped agent API key whose account_id matches the account_id argument and whose allowed_actions include save_business; call get_agent_identity first to confirm scope. Idempotent: saving the same business twice is a no-op. Saving never affects the business's verification class, review authority, review reputation, or recommendation eligibility. Returns a machine-readable auth error (missing_api_key / forbidden_account) when the key is absent or out of scope.

Input parameters:

- `account_id` (string, required)
- `business_id` (string, required)
- `business_name` (string, required)
- `business_source` (string, required)
- `category` (string)
- `city` (string)
- `notes` (string)
- `state` (string)

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `list_saved_businesses` (~199 tokens)

List Saved Businesses

List the calling account's OWN saved-business shortlist, newest first — the read half of save_business, so an agent can review and report the shortlist it has built. Returns business_id, business_name, business_source, category, city, state, notes, and saved_at for up to 100 entries (default 20, newest-first, no cursor). Requires a valid scoped agent API key whose account_id matches the account_id argument (call get_agent_identity first); keys scoped to save_business may also read. Read-only: never modifies the shortlist and never affects any business's verification class or recommendation order. Returns a machine-readable auth error (invalid_agent_api_key / agent_account_scope_violation) when the key is absent or out of scope.

Input parameters:

- `account_id` (string, required): The customer/service-agent account id this key belongs to (confirm with get_agent_identity).
- `limit` (integer): Max shortlist entries to return (default 20).

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `unsave_business` (~198 tokens)

Unsave Business

Remove one business from the calling account's OWN saved-business shortlist — the prune half of save_business. Idempotent: unsaving a business that is not on the shortlist is a no-op that returns removed=false, never an error. This only edits the account's own shortlist; it does not contact the business and never affects the business's verification class, review authority, review reputation, or recommendation eligibility. Requires a valid scoped agent API key whose account_id matches the account_id argument and whose allowed_actions include unsave_business (keys scoped to save_business may also unsave; call get_agent_identity first). Returns a machine-readable auth error (invalid_agent_api_key / agent_account_scope_violation) when the key is absent or out of scope.

Input parameters:

- `account_id` (string, required): The customer/service-agent account id this key belongs to (confirm with get_agent_identity).
- `business_id` (string, required): The saved business to remove from the shortlist.

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `get_location_options` (~154 tokens)

Get Safe Location Choices

Return only the calling customer's safe Home metadata plus opaque saved_location_ref, current-location handoff availability, and provided city/ZIP context. Never returns ZIP, address, latitude, or longitude. Ask exactly: "Where should I search? For local categories, share your current location or use Home only when it is marked exact. Another city/ZIP is for area context or business-name lookup only." Only current or Home with kind=saved_exact authorizes local category/recommendation discovery; provided city/ZIP and coarse Home are neutral name-disambiguation context. Requires an active scoped consumer personal-agent key.

Input parameters:

- `account_id` (string, required): The customer account id this personal-agent key belongs to (confirm with get_agent_identity).

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `get_my_location` (~144 tokens)

Get Safe Location Choices (Compatibility Alias)

Backward-compatible safe alias for get_location_options. Returns only availability, safe labels, precision metadata, and opaque references; it never returns ZIP, address, latitude, or longitude. Ask exactly: "Where should I search? For local categories, share your current location or use Home only when it is marked exact. Another city/ZIP is for area context or business-name lookup only." Only current or saved_exact authorizes local category/recommendation reach. Discovery location never affects any business's verification class, review authority, review reputation, or recommendation eligibility.

Input parameters:

- `account_id` (string, required): The customer account id this personal-agent key belongs to (confirm with get_agent_identity).

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `create_location_handoff` (~77 tokens)

Ask User for Precise Location

Create a short-lived consent link for current precise-location authority. Once approved, it can authorize local category/recommendation reach and Sponsored exposure. Send the location_url to the user, then poll get_location_handoff. The assistant receives readiness and normal business results, never latitude or longitude. Requires an active database-backed customer personal-agent key.

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `get_location_handoff` (~77 tokens)

Check Location Request

Check whether the customer approved current precise-location authority. This returns only status and expiry; it never returns coordinates. Once ready, pass handoff_id as location_handoff_id to search_businesses, search_category, or recommend_businesses.

Input parameters:

- `handoff_id` (string, required): Opaque handoff id returned by create_location_handoff.

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `set_my_location` (~190 tokens)

Set My Saved Location

Save or replace the calling customer's coarse service ZIP, optionally with a safe label such as Home. This coarse Home is neutral context only and cannot return local category/recommendation results, activate Sponsored placement, or record impressions. An agent cannot save raw coordinates or silently choose this location. A signed-in customer may save current precise location through Loppee's private proof flow. Confirm before saving; this never affects verification or reviews.

Input parameters:

- `account_id` (string, required): The customer account id this personal-agent key belongs to (confirm with get_agent_identity).
- `label` (string): Optional safe label, e.g. 'Home' or 'Office'.
- `zip` (string, required): Coarse US ZIP to save as neutral Home area context. It cannot enable local category/recommendation reach, Sponsored placement, or impressions. An agent cannot save raw coordinates; the signed-in cust…

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `clear_my_location` (~122 tokens)

Clear My Saved Location

Remove the calling customer's saved service location. Idempotent: clearing when nothing is saved returns available=false. Provider IP remains neutral context only and cannot activate local category/recommendation results, Sponsored placement, or impressions. On the next local search ask exactly: "Where should I search? For local categories, share your current location or use Home only when it is marked exact. Another city/ZIP is for area context or business-name lookup only."

Input parameters:

- `account_id` (string, required): The customer account id this personal-agent key belongs to (confirm with get_agent_identity).

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `send_message_request` (~259 tokens)

Send Message Request

Send a message to a published business on behalf of the calling customer account. Messaging is available on every v3 exposure plan; the exposure plan does not change messaging access. The message is delivered DIRECTLY to the business owner's Loppee inbox with no human pre-moderation. The stored business name is resolved from the registry, never from target_business_name. Repeat sends to the same business append to the one ongoing conversation thread; read replies with list_my_conversations. client_message_id is required and makes an exact retry idempotent; reuse with different content is rejected. Subject is capped at 160 characters and the message at 4000. Requires a valid scoped agent API key whose account_id matches the account_id argument and whose allowed_actions include send_message_request (call get_agent_identity first). Returns a machine-readable auth error when the key is absent or out of scope. Sending a message never affects the business's verification class, ranking, or review weighting.

Input parameters:

- `account_id` (string, required)
- `client_message_id` (string, required)
- `message` (string, required)
- `subject` (string, required)
- `target_business_id` (string, required)
- `target_business_name` (string, required)
- `target_business_source` (string, required)

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `list_my_conversations` (~192 tokens)

List My Conversations

List the calling customer account's OWN message conversations with businesses, newest first, each including the business's replies — the read half of send_message_request, so an agent can report answers back to its user. Follow pagination.next_cursor until pagination.has_more=false to traverse older history. Pass conversation_id from a webhook resource for one exact scoped lookup; conversation_id and cursor are mutually exclusive. Requires a valid scoped agent API key whose account_id matches the account_id argument (call get_agent_identity first); keys scoped to send_message_request may also read. Read-only: never modifies anything.

Input parameters:

- `account_id` (string, required)
- `conversation_id` (string): Exact conversation referenced by a webhook; returns zero or one scoped thread.
- `cursor` (string): Opaque pagination cursor returned by the previous page. Do not combine with conversation_id.
- `limit` (integer): Max conversations to return (default 20).

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `submit_review_for_moderation` (~200 tokens)

Submit Review

Submit or edit one first-party review for a published business or visible Registry-page business. Registry targets require customer_confirmed=true. The registered consumer account must have an active Passkey or OTP-verified phone; callers cannot choose either reviewer authority or interaction evidence. The review publishes immediately, with human policy moderation only. Verified reviewer means the registered account completed Passkey or phone verification. It does not prove a transaction or government identity.

Input parameters:

- `account_id` (string, required)
- `attestation_accepted` (boolean, required)
- `customer_confirmed` (boolean): Set true to confirm you were a customer of this business. Required when the target business has not claimed its page.
- `message` (string, required)
- `rating` (integer, required)
- `service_date`: Optional real, non-future service date in YYYY-MM-DD format; empty means not provided.
- `subject` (string, required)
- `target_business_id` (string, required)

Output parameters:

- `contract_version` (string)
- `data`
- `error` (object)
- `ok` (boolean)

### `apply_to_job` (~121 tokens)

Apply To Job

Apply to an active Loppee job on behalf of the calling customer account. Requires a customer personal agent key whose account_id matches the account_id argument and whose allowed_actions include apply_to_job. The seeker is never charged. The resume must be a base64 PDF, DOC, or DOCX file and is stored in a private bucket; employers and the applicant retrieve it only through scoped short-lived signed URLs.

Input parameters:

- `account_id` (string, required)
- `cover_note` (string)
- `job_id` (string, required)
- `resume` (object, required)

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `list_my_job_applications` (~262 tokens)

List My Job Applications

List the calling customer account's OWN job applications, newest first — the read half of apply_to_job, so an agent can report what happened to each application. Each entry carries the employer-set status (submitted, viewed, shortlisted, rejected, hired, or withdrawn), a job + employer summary, the cover note, and — when a resume is attached — a short-lived signed resume_url (about 5 minutes; re-list to refresh, resume_url is null if signing fails). Optional status filter and offset pagination (limit up to 50, default 20). Requires a customer personal agent key whose account_id matches the account_id argument (call get_agent_identity first); keys minted before this tool existed may read with apply_to_job scope. Read-only: listing never changes an application's status and never affects any employer's verification class or recommendation order — application status is set by the employer, never by this tool.

Input parameters:

- `account_id` (string, required): The customer account id this personal-agent key belongs to (confirm with get_agent_identity).
- `limit` (integer): Max applications to return (default 20).
- `offset` (integer): Pagination offset into the newest-first list.
- `status` (string): Only return applications currently in this employer-set status.

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `withdraw_job_application` (~207 tokens)

Withdraw Job Application

Withdraw one of the calling customer account's OWN job applications. The application row is kept and flipped to status=withdrawn (the employer sees an honest withdrawn status; nothing is deleted), and the seeker can re-apply later, which reactivates the same application. Idempotent: withdrawing an already-withdrawn application succeeds and reports already_withdrawn=true — never an error. Only the applicant's own application changes; withdrawing never affects the employer's verification class, review authority, review reputation, or recommendation eligibility. Requires a customer personal agent key whose account_id matches the account_id argument (apply_to_job-scoped keys may also withdraw; call get_agent_identity first). Returns job_application_not_found when the application does not belong to this account.

Input parameters:

- `account_id` (string, required): The customer account id this personal-agent key belongs to (confirm with get_agent_identity).
- `application_id` (string, required): The application to withdraw (from list_my_job_applications or apply_to_job).

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `manage_business_deal` (~347 tokens)

Manage Business Deal

Create, edit, publish, unpublish, or delete a deal/coupon for a business you manage. This mutates deal records: operation=create makes a draft, operation=publish takes a draft live, operation=unpublish cancels public display, operation=update overwrites supplied deal fields, and operation=delete removes the deal. Not idempotent for create/delete/publish transitions. Requires allowed_actions include manage_deals. Requires an owner-scoped management key, explicit business scope, and the tool's permission; exposure tier does not grant or remove access. Under v3, a business owner connects an external agent they already use. Loppee provides scoped API and MCP access only; it does not provide or host that customer-connected agent. Access is available at no charge for now. Deals are included plan-neutrally; the exposure plan does not change deal access. Call get_agent_identity first. Never affects the verification class or recommendation order.

Input parameters:

- `account_id` (string, required): The managing agent's account id (from get_agent_identity).
- `business_id` (string, required): The business this deal belongs to (must be in the key's allowed_business_ids).
- `deal_id` (string): Required for update/publish/unpublish/delete.
- `description` (string)
- `discount_label` (string): Human-readable discount, e.g. "20% off" or "$10 off".
- `ends_at`: ISO date; null/absent = no expiry.
- `operation` (string, required)
- `promo_code`
- `starts_at`: ISO date; null/absent = live immediately.
- `terms`
- `title` (string)

Output parameters:

- `contract_version` (string)
- `data`
- `error` (object)
- `ok` (boolean)

### `update_business_profile` (~410 tokens)

Update Business Profile

Update editable profile fields for a business you manage: display_name, category, website, phone, city, state, zip. Provide only the fields you want to change; any supplied field replaces/overwrites the current stored value, and repeating the same payload is idempotent. Changing category REQUIRES category_aliases: 1-3 exact taxonomy leaf aliases (discover them via GET /v1/taxonomy/suggest?q=...) — they set the business's authoritative category placement in search. IMPORTANT: an agent may ESTABLISH a business's category (when it has none) and CORRECT it (prune/reorder/replace within the same number of lines), but it may NOT GROW an existing set by adding a brand-new line of business — that is a regulated action requiring an owner license + admin approval (403 category_addition_requires_approval), and the owner must submit it from the owner portal (Lines of business → Request to add a line of business). Requires allowed_actions include update_business_profile. Requires an owner-scoped management key, explicit business scope, and the tool's permission; exposure tier does not grant or remove access. Under v3, a business owner connects an external agent they already use. Loppee provides scoped API and MCP access only; it does not provide or host that customer-connected agent. Access is available at no charge for now. Cannot edit legal name, verification evidence, billing, publish state, or the verification class.

Input parameters:

- `account_id` (string, required)
- `business_id` (string, required)
- `category` (string)
- `category_aliases` (array): Exact taxonomy leaf aliases (1-3) for the business, e.g. home_property.trades.hvac_services. Required when category is supplied.
- `city` (string)
- `display_name` (string)
- `phone` (string)
- `state` (string)
- `website` (string)
- `zip` (string)

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `set_business_hours` (~299 tokens)

Set Business Hours

Set (or clear) the structured operating hours for a business you manage — the same validated write the owner's dashboard hours editor performs. Supply the WHOLE document each time (idempotent replace): hours.weekly maps every weekday mon..sun to { status, ranges } where status is one of open (1-4 time ranges, split hours like a lunch break supported), closed, open_24 (open 24 hours), or appointment (by appointment only); ranges use business-local 24h "HH:MM" times with open < close (close may be "24:00" = midnight). hours.overrides is an optional list of date-specific SPECIAL/HOLIDAY schedules ({ date: "YYYY-MM-DD", label e.g. "Independence Day", status, ranges }) that REPLACE the weekly schedule on that date. Pass hours=null to clear the schedule (profile shows no hours again). The business's IANA time_zone is derived server-side from its location; the public payloads expose the schedule plus a live computed open_now status in that zone. Hours are informational display data ONLY — they never change verification class, review reputation, ranking, reach, share-of-voice, or eligibility. Requires a scoped management key (allowed_actions include update_business_profile).

Input parameters:

- `account_id` (string, required)
- `business_id` (string, required)
- `hours` (required): The full hours document, or null to clear the stored schedule.

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `update_business_photos` (~374 tokens)

Update Business Photos

Add or remove branding media for a business you manage — all three kinds: kind=business_photo (default) is the plan-neutral GALLERY: operation=add uploads one image (JPEG/PNG/WebP base64, up to 8MB) that enters the media review queue before appearing publicly. kind=logo and kind=cover_photo are REPLACE-IN-PLACE SINGLETONS that follow the owner-dashboard path exactly: JPEG/PNG/WebP/SVG up to 5MB, SVG is sanitized on upload, the new file replaces the prior one and is published immediately (moderation is reactive, same as owner uploads). operation=remove deletes any branding photo by asset_id (verification evidence files are never reachable here). Photos never change verification class, review authority, or recommendation order. Requires allowed_actions include update_business_photos. Requires an owner-scoped management key, explicit business scope, and the tool's permission; exposure tier does not grant or remove access. Under v3, a business owner connects an external agent they already use. Loppee provides scoped API and MCP access only; it does not provide or host that customer-connected agent. Access is available at no charge for now.

Input parameters:

- `account_id` (string, required)
- `asset_id` (string): Required for remove.
- `business_id` (string, required)
- `content_type` (string): Image MIME type, required for add.
- `data_base64` (string): Base64-encoded image bytes, required for add.
- `file_name` (string): Required for add.
- `kind` (string): Branding kind for add (default business_photo = gallery). logo/cover_photo replace the current one in place.
- `operation` (string, required)
- `size_bytes` (integer): Byte length of the decoded image, required for add.

Output parameters:

- `contract_version` (string)
- `data`
- `error` (object)
- `ok` (boolean)

### `list_customer_messages` (~232 tokens)

List Customer Messages

List inbound customer messages for a business you manage, newest first, each with any replies already sent. Follow pagination.next_cursor until pagination.has_more=false to traverse older history. Pass conversation_id from a webhook resource for one exact business-scoped lookup; conversation_id and cursor are mutually exclusive. Requires allowed_actions include list_customer_messages. Requires an owner-scoped management key, explicit business scope, and the tool's permission; exposure tier does not grant or remove access. Under v3, a business owner connects an external agent they already use. Loppee provides scoped API and MCP access only; it does not provide or host that customer-connected agent. Access is available at no charge for now. Use the returned interaction_id with reply_to_customer_message.

Input parameters:

- `account_id` (string, required)
- `business_id` (string, required)
- `conversation_id` (string): Exact conversation referenced by a webhook; returns zero or one scoped thread.
- `cursor` (string): Opaque pagination cursor returned by the previous page. Do not combine with conversation_id.
- `limit` (integer): Max messages to return (default 20).

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `reply_to_customer_message` (~212 tokens)

Reply To Customer Message

Post a reply to an inbound customer message on behalf of a business you manage. Pass the interaction_id from list_customer_messages and the reply body. client_message_id is required and makes an exact retry idempotent; reuse with different content is rejected. Requires allowed_actions include reply_to_customer_message. Requires an owner-scoped management key, explicit business scope, and the tool's permission; exposure tier does not grant or remove access. Under v3, a business owner connects an external agent they already use. Loppee provides scoped API and MCP access only; it does not provide or host that customer-connected agent. Access is available at no charge for now. The reply is stored and attributed to this agent; it does not change the verification class or review reputation.

Input parameters:

- `account_id` (string, required)
- `body` (string, required)
- `business_id` (string, required)
- `client_message_id` (string, required)
- `interaction_id` (string, required): The customer message being answered (from list_customer_messages).

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `list_support_messages` (~195 tokens)

List Support Messages

Read the Loppee support conversation(s) for a business you manage — the owner↔Loppee-support thread, newest first, each with its full message log and status (open/pending/resolved/closed). SCOPED to THIS business only: it never returns the owner's support tickets about their other businesses. Requires allowed_actions include list_support_messages. Requires an owner-scoped management key, explicit business scope, and the tool's permission; exposure tier does not grant or remove access. Under v3, a business owner connects an external agent they already use. Loppee provides scoped API and MCP access only; it does not provide or host that customer-connected agent. Access is available at no charge for now. Read-only; pair with send_support_message to reply.

Input parameters:

- `account_id` (string, required)
- `business_id` (string, required)
- `limit` (integer): Max conversations to return (default 20).

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `send_support_message` (~264 tokens)

Send Support Message

Post a message to Loppee support on behalf of a business you manage. It appends to the business's one open support thread (reopening a resolved one), or opens a fresh ticket if none is active — the same behavior as the owner sending from the support widget. A closed ticket is never reused; a new one opens instead. The turn is stored as an owner-side message and attributed to this agent in the audit log. SCOPED to THIS business only. Requires allowed_actions include send_support_message. Requires an owner-scoped management key, explicit business scope, and the tool's permission; exposure tier does not grant or remove access. Under v3, a business owner connects an external agent they already use. Loppee provides scoped API and MCP access only; it does not provide or host that customer-connected agent. Access is available at no charge for now. Optional subject (≤160 chars) names a new ticket; body ≤4000 chars. Support chat never affects verification class, review reputation, ranking, reach, or review weighting.

Input parameters:

- `account_id` (string, required)
- `body` (string, required)
- `business_id` (string, required)
- `subject` (string): Subject for a NEW ticket (ignored when appending to an open one).

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `list_notifications` (~99 tokens)

List Owner Notifications

List owner notifications for the business this management agent is scoped to. Returns event metadata, summaries, and resource links only; it never includes raw CVs, full message bodies, or applicant PII. Requires allowed_actions include list_notifications.

Input parameters:

- `account_id` (string, required)
- `business_id` (string, required)
- `limit` (integer)
- `offset` (integer)
- `type` (string)
- `unread` (boolean)

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `list_missed_contacts` (~110 tokens)

List Missed Contacts

List captured MISSED CONTACTS for the business this management agent is scoped to. The v3 exposure plan does not lock identity, message content, or access to this owner workflow. Rows remain restricted to the exact owner-authorized business, and the key must include list_missed_contacts. Reading missed contacts never affects verification class, ranking, or reviews.

Input parameters:

- `account_id` (string, required)
- `business_id` (string, required)
- `limit` (integer)
- `offset` (integer)

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `mark_notification_read` (~57 tokens)

Mark Owner Notification Read

Mark one owner notification as read for the business this management agent is scoped to. Requires allowed_actions include mark_notification_read.

Input parameters:

- `account_id` (string, required)
- `business_id` (string, required)
- `notification_id` (string, required)

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `respond_to_review` (~297 tokens)

Respond To Review

Publish the business's ONE public response to a customer review of a business you manage. Repeating the call EDITS the existing response in place (idempotent per review — a business never gets a second response slot). The response is public and attributed to this agent. Responding NEVER changes the verification class, review authority, the review, its rating, or its weighting — it only adds the business's side of the story under the review. Requires allowed_actions include respond_to_review. Requires an owner-scoped management key, explicit business scope, and the tool's permission; exposure tier does not grant or remove access. Under v3, a business owner connects an external agent they already use. Loppee provides scoped API and MCP access only; it does not provide or host that customer-connected agent. Access is available at no charge for now. Call get_agent_identity first. Returns review_not_found when the review does not belong to this business, and missing_response_body when body is empty.

Input parameters:

- `account_id` (string, required): The managing agent's account id (from get_agent_identity).
- `body` (string, required): The public response text (up to 2000 characters, same cap as the owner dashboard).
- `business_id` (string, required): The reviewed business (must be in the key's allowed_business_ids).
- `review_id` (string, required): The review being answered (review ids appear in the business's review notifications and dashboard payload).

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `manage_job_posting` (~676 tokens)

Manage Job Posting

Create, edit, publish, pause, close, or delete a job posting for a business you manage (mirrors manage_business_deal). operation=create makes a DRAFT posting (never live directly). operation=publish takes a draft/paused posting live: when this environment has live billing and payment is required, it returns status=checkout_required with a Stripe Checkout url that the HUMAN business owner must open and pay — this tool NEVER completes payment itself; when billing is off, publish activates the posting directly at no charge. operation=update overwrites only the supplied fields (status changes go through publish/pause/close). operation=delete removes the posting (idempotent: deleting a missing posting reports deleted). Separate Loppee Jobs billing controls posting activation ONLY — it never ranks jobs, never changes the business's verification class, and never changes recommendation order. Employers must be claimed, verified, and published (jobs_verified_business_required otherwise). Seekers are never charged. Requires allowed_actions include manage_job_posting. Requires an owner-scoped management key, explicit business scope, and the tool's permission; exposure tier does not grant or remove access. Under v3, a business owner connects an external agent they already use. Loppee provides scoped API and MCP access only; it does not provide or host that customer-connected agent. Access is available at no charge for now. Call get_agent_identity first. Not idempotent for create/publish/delete transitions.

Input parameters:

- `account_id` (string, required): The managing agent's account id (from get_agent_identity).
- `apply_url`
- `benefits` (string)
- `business_id` (string, required): The employer business (must be in the key's allowed_business_ids).
- `category` (string): Free-text category label; defaults to the employer's category.
- `category_alias` (string): Exact taxonomy LEAF alias for field/domain search (discover via GET /v1/taxonomy/suggest); defaults to the employer's primary alias.
- `city` (string): Defaults to the employer's city for create.
- `compensation_text` (string): Human-readable pay line, e.g. "$25-$30/hr + commission".
- `contact_email`
- `description` (string)
- `direct_apply` (boolean): true = seekers apply on Loppee (free for them); false = external apply_url.
- `employment_type` (string)
- `experience_level` (string)
- `job_id` (string): Required for update/publish/pause/close/delete.
- `operation` (string, required): create makes a DRAFT; publish takes it live (returns checkout_required with a Stripe url for the HUMAN owner when payment is required); pause/close change visibility; delete removes the posting.
- `postal_code` (string)
- `salary_currency` (string)
- `salary_max`
- `salary_min`
- `salary_period` (string): hour, year, or month.
- `schedule` (string)
- `skills` (array)
- `state` (string): Two-letter US state; defaults to the employer's state for create.
- `street_address` (string)
- `title` (string): Job title (required for create).
- `total_job_openings`
- `workplace_type` (string)

Output parameters:

- `contract_version` (string)
- `data`
- `error` (object)
- `ok` (boolean)

### `report_review` (~419 tokens)

Report Review

Report a customer review of a business you manage into Loppee's moderation queue for a claimed policy violation (spam, harassment, off_topic, fake, or other). IMPORTANT: reporting NEVER removes the review — the review stays published, moderation is HUMAN and REACTIVE, and a moderator removes a review only for a recorded policy violation, never for being negative. Do not use this tool to suppress honest criticism; use respond_to_review to answer it publicly. Filing a report never changes the verification class, review authority, the review's weighting, or recommendation order. Requires allowed_actions include report_review. Requires an owner-scoped management key, explicit business scope, and the tool's permission; exposure tier does not grant or remove access. Under v3, a business owner connects an external agent they already use. Loppee provides scoped API and MCP access only; it does not provide or host that customer-connected agent. Access is available at no charge for now. Call get_agent_identity first. Reportability rules: only a NEGATIVE review (rating 3 stars and below) can be reported at all — a 4-5 star review returns review_report_not_negative; only ONE report may be open at a time — while a prior report is being reviewed a new one returns review_report_already_open; and a review accepts at most 3 reports in its LIFETIME — past that the call returns review_report_limit_reached. Returns review_not_found when the review does not belong to this business and invalid_report_reason for an unknown category.

Input parameters:

- `account_id` (string, required): The managing agent's account id (from get_agent_identity).
- `business_id` (string, required): The reviewed business (must be in the key's allowed_business_ids).
- `reason_category` (string, required): Policy-violation category. 'The review is negative' is not a category — negative reviews are never removed for being negative.
- `reason_detail` (string): What specifically violates policy (up to 2000 characters).
- `review_id` (string, required): The review being reported.

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `list_job_applications` (~346 tokens)

List Job Applications (Employer)

List applications to the job postings of a business you manage, newest first — the employer side of the hiring pipeline. PII NOTICE: rows include the applicant's name, email, cover note, and (when attached) a SHORT-LIVED signed resume_url (about 5 minutes; re-list to refresh, null if signing fails). This is an explicit owner grant: the business owner must have checked this action when connecting this key (it is never granted by default), and access stays attributable to that scoped key. Handle applicant data only for this business's hiring workflow — never republish it or use it beyond hiring. Optional job_id/status filters and offset pagination (limit up to 100, default 25). Requires allowed_actions include list_job_applications. Requires an owner-scoped management key, explicit business scope, and the tool's permission; exposure tier does not grant or remove access. Under v3, a business owner connects an external agent they already use. Loppee provides scoped API and MCP access only; it does not provide or host that customer-connected agent. Access is available at no charge for now. Read-only: listing never changes application statuses and never affects verification class or recommendation order.

Input parameters:

- `account_id` (string, required): The managing agent's account id (from get_agent_identity).
- `business_id` (string, required): The employer business (must be in the key's allowed_business_ids).
- `job_id` (string): Only applications to this posting.
- `limit` (integer): Max applications to return (default 25).
- `offset` (integer): Pagination offset into the newest-first list.
- `status` (string): Only applications currently in this status.

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `update_job_application_status` (~305 tokens)

Update Job Application Status (Employer)

Set the employer-side status of one application to a job posting of a business you manage: submitted, viewed, shortlisted, rejected, or hired. Applicants alone may withdraw — passing 'withdrawn' is rejected (invalid_job_application_status). Idempotent per (application, status): re-setting the same status is a no-op overwrite. The change is visible to the seeker in their applications view and is audit-logged with this agent's attribution. Status changes never affect the business's verification class, recommendation order, or the applicant's account. Requires allowed_actions include update_job_application_status — an explicit owner grant, never default. Requires an owner-scoped management key, explicit business scope, and the tool's permission; exposure tier does not grant or remove access. Under v3, a business owner connects an external agent they already use. Loppee provides scoped API and MCP access only; it does not provide or host that customer-connected agent. Access is available at no charge for now. Returns job_application_not_found when the application does not belong to this business's postings.

Input parameters:

- `account_id` (string, required): The managing agent's account id (from get_agent_identity).
- `application_id` (string, required): The application to update (from list_job_applications).
- `business_id` (string, required): The employer business (must be in the key's allowed_business_ids).
- `status` (string, required): Employer-set status. Applicants alone may withdraw — 'withdrawn' is rejected here.

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `validate_coupon` (~388 tokens)

Validate Coupon

Check a Loppee-issued subscription coupon code against a business you manage and a chosen paid exposure plan, and return the priced result: original_cents, discount_cents, final_cents, plan_name, and whether the discount repeats (duration: once = first payment, forever = every renewal). Read-only — nothing is redeemed, reserved, or counted against the code's limits. Requires a scoped management key whose account_id + business_id match and whose allowed_actions include validate_coupon; call get_agent_identity first. Coupons are issued by Loppee admins to discount the plan PRICE (this is NOT the business's own customer-facing deals — see manage_deal for those). Machine-readable failures match the owner UI exactly: coupon_not_found (invalid code), coupon_inactive, coupon_expired, coupon_wrong_plan (code is scoped to a different plan), coupon_exhausted (total redemption cap reached), coupon_customer_limit (this business already used it), coupon_requires_paid_plan, plus the standard management auth errors (missing_api_key / forbidden_account / management_rate_limited), billing_already_active, billing_checkout_in_progress, and billing_not_configured. A coupon changes the subscription PRICE only. It never changes verification class, review reputation, plan entitlement, eligibility, or quality band; completed payment grants exactly the chosen plan.

Input parameters:

- `account_id` (string, required): The agent account id this API key belongs to (confirm with get_agent_identity).
- `business_id` (string, required): The managed business to apply the coupon for. Must be within this key's allowed_business_ids.
- `code` (string, required): The coupon code exactly as issued by the Loppee team. Case- and whitespace-insensitive.
- `period` (string): Billing period to price the plan at.
- `tier` (string, required): Paid exposure plan to price: nearby=Silver, local=Gold, regional=Platinum, metro=Diamond.

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

### `redeem_coupon` (~493 tokens)

Redeem Coupon

Redeem a Loppee-issued subscription coupon for a business you manage: runs the exact same validation as validate_coupon, then creates a Stripe Checkout session for the chosen paid plan WITH the discount already applied, and returns its url plus the priced breakdown (original_cents, discount_cents, final_cents) and a redemption_id. IMPORTANT: this tool never charges anyone — the business owner must open the returned url and complete payment on Stripe's hosted page; until then the redemption is 'pending' and is released automatically if the checkout expires. Redeeming counts against the code's redemption limits while pending, so do not call this speculatively — use validate_coupon to check a code. Retry-safe/idempotent for an identical pending business + code + tier + period: it returns the same redemption and live Checkout session instead of creating another. A different plan, period, or coupon is refused with billing_checkout_in_progress while the existing business Checkout remains open; no competing session is created. Requires a scoped management key whose account_id + business_id match and whose allowed_actions include redeem_coupon (owner opt-in), plus enabled online billing (billing_not_configured otherwise); call get_agent_identity first. Machine-readable failures match the owner UI exactly: coupon_not_found (invalid code), coupon_inactive, coupon_expired, coupon_wrong_plan (code is scoped to a different plan), coupon_exhausted (total redemption cap reached), coupon_customer_limit (this business already used it), coupon_requires_paid_plan, plus the standard management auth errors (missing_api_key / forbidden_account / management_rate_limited), billing_already_active, billing_checkout_in_progress, and billing_not_configured. A coupon changes the subscription PRICE only. It never changes verification class, review reputation, plan entitlement, eligibility, or quality band; completed payment grants exactly the chosen plan.

Input parameters:

- `account_id` (string, required): The agent account id this API key belongs to (confirm with get_agent_identity).
- `business_id` (string, required): The managed business to apply the coupon for. Must be within this key's allowed_business_ids.
- `code` (string, required): The coupon code exactly as issued by the Loppee team. Case- and whitespace-insensitive.
- `period` (string): Billing period to price the plan at.
- `tier` (string, required): Paid exposure plan to price: nearby=Silver, local=Gold, regional=Platinum, metro=Diamond.

Output parameters:

- `contract_version` (string)
- `data` (object)
- `error` (object)
- `ok` (boolean)

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/com-loppee-loppee/loppee#diagnostics

## Score history

- 2026-08-03: 63
- 2026-08-02: 63
- 2026-08-01: 62
- 2026-07-31: 62
- 2026-07-30: 59
- 2026-07-29: 59
- 2026-07-27: 58
- 2026-07-26: 57

## Links

- Remote endpoint: https://loppee.com/mcp
- Repository: https://github.com/4dwebspro-cell/ylai-platform
- Website: https://loppee.com/agents
- Changelog RSS feed: https://verifymcp.io/servers/com-loppee-loppee/loppee/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/com-loppee-loppee/loppee/changelog.json
- HTML version of this page: https://verifymcp.io/servers/com-loppee-loppee/loppee
