Tempi
REMOTE · MEETTEMPI.COM · SCANNED SEP 29
Find open times and book, reschedule or cancel meetings on anyone's Tempi link. No account needed.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (cancel_booking_as_invitee). See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability64
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 1516 tokens (~189/item across 8 items; 8 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management10
- Stability observed for 3 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage90
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 71% of tool parameters carry a description.Partial
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 8 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 9 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
- Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
How do I install the Tempi MCP server?
Tempi is a hosted endpoint at https://meettempi.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · meettempi.com
claude mcp add --transport http com-meettempi-tempi 'https://meettempi.com/mcp'
{
"mcpServers": {
"com-meettempi-tempi": {
"url": "https://meettempi.com/mcp"
}
}
} {
"servers": {
"com-meettempi-tempi": {
"type": "http",
"url": "https://meettempi.com/mcp"
}
}
} [mcp_servers.com-meettempi-tempi] url = "https://meettempi.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-meettempi-tempi": {
"type": "remote",
"url": "https://meettempi.com/mcp",
"enabled": true
}
}
} openclaw mcp add com-meettempi-tempi --url 'https://meettempi.com/mcp' --transport streamable-http
mcp_servers:
com-meettempi-tempi:
url: "https://meettempi.com/mcp" {
"McpServers": {
"com-meettempi-tempi": {
"Transport": "http",
"Url": "https://meettempi.com/mcp"
}
}
} assistant mcp add com-meettempi-tempi -t streamable-http -u 'https://meettempi.com/mcp'
{
"mcpServers": {
"com-meettempi-tempi": {
"type": "http",
"url": "https://meettempi.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 29 Sept 26 +7
- HTTPS: unverified → pass ▲ security
- HSTS header: fail → pass ▲ security
- Tool “create_booking” rewrote its description, which is the text the model reads security
- 28 Sept 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Sept 26 0
- Stability: unverified → 0.03 ▲ functional
- “join_waitlist” added an optional parameter “ref” cosmetic
- 26 Sept 26 56
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 29 Sept 2026 · Probed https://meettempi.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=meettempi.com | CN=WE1,O=Google Trust Services,C=US | 25 Sept 2026 | 24 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | 1cfc72b09b88c69e0e7f9cd5543aeb25 |
| SANs: meettempi.com, staging.meettempi.com, *.staging.meettempi.com | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of meettempi.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| meettempi.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://meettempi.com/mcp | Verified | 200 | |
| http (plaintext) | http://meettempi.com/mcp | HTTPS enforced | 301 | https://meettempi.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
cancel_booking_as_invitee Cancel a booking (invitee) ~183
Cancels a booking by its id and token. The event is removed from the host's calendar. Paid bookings cancelled before `refundableUntil` are refunded in full. Later cancellations get no refund. The event type sets the rules, which get_booking shows: no changes after `changeableUntil` (409 change_too_late), no cancelling when `canCancel` is false (409 cancel_not_allowed, reschedule instead), and a `reason` when `cancelReasonRequired` is true (422 reason_required).
| Name | Type | Req | Description |
|---|---|---|---|
| following | boolean | – | for a series: also cancel every later meeting |
| id | string | yes | a string at least 1 character(s) long |
| reason | string | – | a string at most 500 character(s) long |
| token | string | yes | a string at least 10 character(s) long |
No output schema declared.
No examples provided.
check_series Check a repeating series before booking it ~175
For event types with `repeatMax` (from get_public_profile): lists each meeting of a series that starts at `start` (one of the slots) and repeats `every` 1, 2 or 4 weeks at the same local time, and whether each is free. Book it with create_booking and `repeat` when `bookable` is true. A series is booked whole or not at all, and round robin gives every meeting to the same host.
| Name | Type | Req | Description |
|---|---|---|---|
| count | – | yes | – |
| every | – | yes | – |
| handle | string | yes | 1-40 lowercase letters, digits or dashes, starting and ending with a letter or digit |
| slug | string | yes | 1-40 lowercase letters, digits or dashes, starting and ending with a letter or digit |
| start | string | yes | – |
No output schema declared.
No examples provided.
create_booking Book a meeting ~346
Books `start`, which must be one of the `slots` from get_available_slots. Free events are confirmed at once, unless the event type has `requiresApproval`: then it's a request (status=pending_approval) that holds the time until a host approves or declines it, and the invitee hears either way by email. Tell the human it isn't confirmed yet. Paid events return status=pending_payment and a `paymentUrl`. Give it to the human to pay before `holdExpiresAt`, or the slot is released. Once confirmed, the event is added to the host's calendar if they connected one, and the invitee gets its invitation. Keep `manageUrl` and `token`: they are the only way to view, reschedule or cancel later. 409 slot_unavailable means the time was just taken: fetch slots again.
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | – | |
| handle | string | yes | 1-40 lowercase letters, digits or dashes, starting and ending with a letter or digit |
| name | – | yes | the invitee's full name |
| notes | string | – | a string at most 2000 character(s) long |
| repeat | object | – | book a series instead: `count` meetings, `every` 1, 2 or 4 weeks at the same local time, when the event type's repeatMax allows. All or nothing: check_series first |
| slug | string | yes | 1-40 lowercase letters, digits or dashes, starting and ending with a letter or digit |
| start | string | yes | – |
| timezone | string | – | an IANA time zone such as "America/New_York" |
No output schema declared.
No examples provided.
get_available_slots Find open times ~261
Returns the start times that can be booked, with the hosts' calendars, buffers and limits already applied. Pass `date` (YYYY-MM-DD in `timezone`) or `from` and `to` (ISO, at most 62 days apart). With neither, it covers the next 7 days. `days` groups the slots by date in `timezone` (default UTC). For new times for an existing booking, also pass its `bookingId` and `token`. Next: call create_booking (or reschedule_booking_as_invitee) with one of the `slots` values as `start`.
| Name | Type | Req | Description |
|---|---|---|---|
| bookingId | string | – | a string at least 1 character(s) long |
| date | string | – | – |
| from | string | – | – |
| handle | string | yes | 1-40 lowercase letters, digits or dashes, starting and ending with a letter or digit |
| slug | string | yes | 1-40 lowercase letters, digits or dashes, starting and ending with a letter or digit |
| timezone | string | – | an IANA time zone such as "America/New_York" |
| to | string | – | – |
| token | string | – | a string at least 10 character(s) long |
No output schema declared.
No examples provided.
get_booking View a booking (invitee) ~96
Returns a booking by its id and token (from create_booking or its manageUrl), with `changeableUntil`, `refundableUntil`, `canCancel` and `cancelReasonRequired`. For a series, `series` lists every meeting with its own manageUrl.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | a string at least 1 character(s) long |
| token | string | yes | a string at least 10 character(s) long |
No output schema declared.
No examples provided.
get_public_profile List a person's or team's event types ~103
Takes a handle, the first path segment of a booking link (https://host/acme/demo → "acme"). Returns the person or team and their bookable event types, with duration, price and hosts. A handle from before a rename also works. Next: call get_available_slots with one of the event type slugs.
| Name | Type | Req | Description |
|---|---|---|---|
| handle | string | yes | 1-40 lowercase letters, digits or dashes, starting and ending with a letter or digit |
No output schema declared.
No examples provided.
join_waitlist Join the private beta waitlist ~148
Requests access to host on Tempi (create event types, share a booking page). Not needed to book meetings, since booking pages are public. Returns the status: pending, approved (sign in at APP_URL/login), rejected, or open (no waitlist, sign in directly). Joining again with the same email returns the current status.
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | – | |
| name | string | – | a string at most 100 character(s) long |
| note | string | – | anything the admins should know, e.g. what you want to use Tempi for |
| ref | string | – | a short source tag of lowercase letters, digits, - or _, like "embed" |
No output schema declared.
No examples provided.
reschedule_booking_as_invitee Reschedule a booking (invitee) ~115
Moves a confirmed booking to `start` with the same hosts. Get valid times from get_available_slots with this `bookingId` and `token`. The calendar event is updated and its provider notifies attendees. Payment carries over. Not possible after `changeableUntil` (409 change_too_late).
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | a string at least 1 character(s) long |
| start | string | yes | – |
| token | string | yes | a string at least 10 character(s) long |
No output schema declared.
No examples provided.
What is the Tempi MCP server?
Tempi is an MCP server listed in the public MCP registry as com.meettempi/tempi. Find open times and book, reschedule or cancel meetings on anyone's Tempi link. No account needed. This page covers its hosted endpoint (https://meettempi.com/mcp).
Is the Tempi MCP server safe to use?
Tempi scores 64 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Tempi MCP server expose?
Tempi exposes 8 tools: get_public_profile, get_available_slots, check_series, create_booking, get_booking, and 3 more. Their descriptions and schemas cost roughly 1,427 tokens of context every time the server is loaded.
Does the Tempi MCP server require authentication?
No. We connected to Tempi without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Tempi MCP server still maintained?
Tempi is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.