# Ontonym (remote · mcp.ontonym.com)

Give your agents your team's real data — read the shared graph, propose actions your team approves.

- Trust score: 38/100 (low)
- Change this week: 0
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-03

## Components

- remote · `mcp.ontonym.com`: 38/100 (this document), [markdown](https://verifymcp.io/servers/com-ontonym-memory/mcp.md), [page](https://verifymcp.io/servers/com-ontonym-memory/mcp)

## Channel facts

- Endpoint: `https://mcp.ontonym.com/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.1.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-03.

- **Endpoint Security**: 94/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - The endpoint enforces authorisation, advertised via RFC 9728 protected-resource metadata.
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
  - The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents.
- **Transport & Reachability**: 0/100
  - Transport blocked by authentication: the endpoint requires auth we don't have to verify streamable-http.
- **Schema Quality & AI Usability**: 0/100
  - Schema blocked by authentication: the endpoint requires auth we don't have to read it.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 0/100
  - Tool coverage blocked by authentication: the endpoint requires auth we don't have to read its tools.
- **Tool Safety**: 0/100
  - Tool safety blocked by authentication: the endpoint requires auth we don't have to read its tools.
- **Capabilities**: 0/100
  - Capabilities blocked by authentication: the endpoint requires auth we don't have to read them.

**Unverified: 6 categories.** Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.

## Install

### How do I install the Ontonym MCP server?

Ontonym is a hosted endpoint at https://mcp.ontonym.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http com-ontonym-memory 'https://mcp.ontonym.com/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "com-ontonym-memory": {
      "url": "https://mcp.ontonym.com/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "com-ontonym-memory": {
      "type": "http",
      "url": "https://mcp.ontonym.com/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.com-ontonym-memory]
url = "https://mcp.ontonym.com/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-ontonym-memory": {
      "type": "remote",
      "url": "https://mcp.ontonym.com/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add com-ontonym-memory --url 'https://mcp.ontonym.com/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  com-ontonym-memory:
    url: "https://mcp.ontonym.com/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "com-ontonym-memory": {
      "Transport": "http",
      "Url": "https://mcp.ontonym.com/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add com-ontonym-memory -t streamable-http -u 'https://mcp.ontonym.com/mcp'
```

### Other

```json
{
  "mcpServers": {
    "com-ontonym-memory": {
      "type": "http",
      "url": "https://mcp.ontonym.com/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-28 (score 38, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-25 (score 38, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-11 (score 38, 0)

- [security regression] Endpoint reachability: reachable → behind authorisation
- [security improvement] Transport: unverified → pass
- [security improvement] Injection markers: unverified → pass
- [security] First check of Judged manipulation: pass
- [security] Authorization: Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token.
- [functional improvement] MCP protocol: unverified → pass
- [functional improvement] Tool coverage: unverified → 100
- [functional] First check of Tool coverage: 0
- [functional] First check of Schema quality: fail
- [functional] First check of Schema quality: excellent
- [functional] First check of Destructive annotations: 100
- [functional] First check of Schema quality: pass
- [functional] First check of Tool coverage: 100

### 2026-09-09 (score 38)

First indexed and scored.

## MCP tools (22)

### `list_my_memories` (~44 tokens)

List my memories

List the memories YOU can read and ingest into. Call this first, then
    pass the chosen `slug` as the `memory` argument to every other tool.

### `semantic_search` (~172 tokens)

Semantic search

Semantic search over a memory's classes and objects. `memory` is the
    slug from list_my_memories. `kind` = 'class' | 'object' | omit. Check
    `status` and defer on 'unapproved'.

    `expand=1` inlines each top object hit's FIRST RING — properties plus
    relationship groups with counts and member previews — so you learn what a
    hit is and what it touches without a get_object per hit. Prefer expand=1
    whenever you intend to follow relationships; for reach beyond one ring,
    use get_paths instead of hopping get_object calls.

Input parameters:

- `expand` (integer)
- `kind`
- `memory` (string, required)
- `query` (string, required)
- `top_k` (integer)

### `get_paths` (~161 tokens)

Find paths between two objects

Shortest relationship paths between two objects in a memory — the
    one-call answer to "how are A and B connected?". `start` and `target`
    accept an object id or an exact name/display name. Each returned path is a
    list of steps {from, rel, direction, to}; paths are all of minimal length.
    `found: false` with `frontier_truncated: true` means the search hit its
    breadth cap, NOT proof the objects are disconnected. Use this instead of
    chaining get_object calls hop by hop.

Input parameters:

- `limit` (integer)
- `max_depth` (integer)
- `memory` (string, required)
- `start` (string, required)
- `target` (string, required)

### `resolve_names` (~162 tokens)

Resolve names in batch

Ask which of your candidate names already exist in the memory — call
    ONCE per document during extraction, after drafting candidate entities
    and before emitting the final JSON.

    `items` = [{"kind": "object"|"class", "name": "...", "class_name": "..."?},
    ...] (max 200). Each result carries `exact` (case-insensitive name hits)
    and `matches` (spelling/semantic look-alikes with scores). REUSE a
    returned canonical `name` + its class instead of creating a duplicate;
    only names with no hits should be created new. Read-only.

Input parameters:

- `items` (array, required)
- `memory` (string, required)
- `top_k` (integer)

### `list_classes` (~32 tokens)

List classes

List the classes (schema) in a memory (slug from list_my_memories).

Input parameters:

- `memory` (string, required)

### `list_class_objects` (~39 tokens)

List objects in a class

List objects of one class in a memory (class_id from list_classes).

Input parameters:

- `class_id` (integer, required)
- `memory` (string, required)

### `get_object` (~39 tokens)

Get object

Full detail/subgraph for one object in a memory (id from search/list).

Input parameters:

- `memory` (string, required)
- `object_id` (integer, required)

### `get_graph` (~28 tokens)

Get memory graph

The class-level graph (classes + relationships) of a memory.

Input parameters:

- `memory` (string, required)

### `get_feed` (~33 tokens)

Get activity feed

Recent ingestions in a memory — what changed lately.

Input parameters:

- `limit` (integer)
- `memory` (string, required)

### `get_extraction_prompt` (~209 tokens)

Get extraction prompt

Add a document to the knowledge graph by extracting it YOURSELF, in this chat.

    STEP 1 of 4. Use whenever the user shares a document/notes/transcript and
    wants it captured in the graph, and you (this assistant) should do the
    extraction. `memory` is the slug from list_my_memories.

    Returns a `passes` list. The flow: (1) run the `classes` pass prompt over
    the document you already have; (2) run the `objects` pass prompt and draft
    candidate objects/events; (3) call resolve_names ONCE with every candidate
    name and reuse each returned canonical name + class; (4) call
    submit_extraction_from_llm(memory, results). The document is NOT sent to
    the server, and no object list is embedded in the prompts — resolve_names
    is how you see what already exists.

Input parameters:

- `memory` (string, required)

### `submit_extraction_from_llm` (~179 tokens)

Submit extraction

Save the extraction you produced — the LAST step after get_extraction_prompt
    and your single resolve_names call.

    `memory` is the slug. `results` maps each pass `key` to that pass's JSON,
    e.g. {"classes": {...}, "objects": {...}}. `source_doc` is an optional label
    (filename/title) for provenance. New rows land status='unapproved'.

    The response may carry `validation_errors` (rows the server could not
    place — report them to the user instead of ignoring them) and
    `near_duplicates` (new objects that look like an existing one — review
    with the user and fold confirmed pairs with merge_objects).

Input parameters:

- `memory` (string, required)
- `results` (object, required)
- `source_doc`

### `list_objects` (~75 tokens)

List objects

List objects in a memory, optionally filtered to one exact class (by
    canonical snake_case name; descendants NOT included). Each row carries
    `status` — defer on 'unapproved'. `memory` is the slug.

Input parameters:

- `class_name`
- `limit` (integer)
- `memory` (string, required)

### `get_change_impact` (~72 tokens)

Get change impact

"What should I watch out for if I change this object?" — event-class
    neighbours, actions touching it, property conflicts, top related objects, and
    provenance. One composite call. `memory` is the slug.

Input parameters:

- `memory` (string, required)
- `object_id` (integer, required)

### `list_unapproved` (~88 tokens)

List unapproved items

The review queue — rows still status='unapproved', which an
    agent should defer on. `kind` filters to one of class/property/action/
    relationship/rule/flow/flow_step/object/object_property/object_action/
    object_relationship/object_flow/object_flow_step; omit to scan all.

Input parameters:

- `kind`
- `limit` (integer)
- `memory` (string, required)

### `list_unapproved_owners` (~36 tokens)

List unapproved ownerships

Pending-review ownership suggestions in a memory, newest first.

Input parameters:

- `limit` (integer)
- `memory` (string, required)

### `list_owned_objects` (~53 tokens)

List owned objects

Reverse ownership lookup — what objects does this person (object_id) own?
    Approved ownerships only. `memory` is the slug.

Input parameters:

- `memory` (string, required)
- `person_object_id` (integer, required)

### `set_owner` (~74 tokens)

Set object owner

Set ownership directly (status='approved'). `role` is 'primary' (demotes any
    existing approved primary to secondary) or 'secondary'. Requires write scope.

Input parameters:

- `memory` (string, required)
- `object_id` (integer, required)
- `owner_object_id` (integer, required)
- `role` (string)

### `suggest_owner` (~80 tokens)

Suggest object owner

File an ownership SUGGESTION (status='unapproved') for review instead
    of writing it directly. Idempotent and sticky. Requires write scope.

Input parameters:

- `memory` (string, required)
- `object_id` (integer, required)
- `owner_object_id` (integer, required)
- `role` (string)
- `suggestion_source` (string)

### `remove_owner` (~62 tokens)

Remove object owner

Drop an ownership row by (object, owner). Idempotent — `removed=false` when
    the pair wasn't linked. Requires write scope.

Input parameters:

- `memory` (string, required)
- `object_id` (integer, required)
- `owner_object_id` (integer, required)

### `merge_objects` (~229 tokens)

Merge duplicate objects

Fold a DUPLICATE object into the object it duplicates, then delete it.

    Extraction coins near-duplicates (`turkey` beside `country_tur`) because the
    known-objects hint it sees is capped at the newest rows. Use this when two
    objects of the SAME class denote one real thing: `winner_id` is the one to
    keep, and the loser's properties, edges, mentions and ownership move onto it
    before it goes. Edges the move turns into self-loops or exact duplicates are
    dropped. Identify the loser by `loser_id` or by `loser_name` (its canonical
    snake_case name, resolved within the winner's class).

    Irreversible, and the loser id stops resolving afterwards — confirm the two
    really are one thing (get_object on both) before calling. Refuses a
    cross-class pair. Requires write access to the memory.

Input parameters:

- `loser_id`
- `loser_name`
- `memory` (string, required)
- `winner_id` (integer, required)

### `embed_memory` (~156 tokens)

Build semantic search index

Build (or top up) the vector index a memory's semantic_search reads.

    `semantic_search` matches against stored embeddings, so a memory that has
    never been embedded answers every query with ZERO results — indistinguishable
    from "nothing matches". Run this once per memory, and again after a large
    ingestion, to make newly added objects findable by meaning.

    Idempotent: entities already embedded for the current model are skipped
    unless `force`. `kinds` defaults to ['object', 'class']. Requires write
    scope. Large memories take a while — this can run for minutes.

Input parameters:

- `force` (boolean)
- `kinds`
- `memory` (string, required)

### `propose_action` (~213 tokens)

Propose an action for approval

Queue ONE action for HUMAN APPROVAL — nothing is sent or written
    until a memory owner approves it in the Agents tab.

    The kind that makes this powerful from an AI client: `workspace_write`
    creates a record in the memory's own apps once approved — an issue on
    the Agile board, a support ticket, a CRM deal, a note. Fields:
    target=record title, body=record body, extra.class_name=the app class
    (issue/ticket/deal/note/…), extra.properties=a {property: value}
    object, extra.relationships=[{type, target_name}].

    Outbound kinds (jira_comment, slack_message, gmail_send, …) address
    connected external tools; see the API's action registry for their
    fields. `memory` is the slug. Requires write scope.

Input parameters:

- `body`
- `extra`
- `kind` (string, required)
- `memory` (string, required)
- `target`

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/com-ontonym-memory/mcp#diagnostics

## Score history

- 2026-10-03: 38
- 2026-10-02: 38
- 2026-10-01: 38
- 2026-09-30: 38
- 2026-09-29: 38
- 2026-09-28: 38
- 2026-09-27: 38
- 2026-09-26: 38
- 2026-09-25: 38
- 2026-09-24: 38
- 2026-09-23: 38
- 2026-09-22: 38
- 2026-09-21: 38
- 2026-09-20: 38
- 2026-09-19: 38
- 2026-09-18: 38
- 2026-09-17: 38
- 2026-09-16: 38
- 2026-09-15: 38
- 2026-09-14: 38
- 2026-09-13: 38
- 2026-09-12: 38
- 2026-09-11: 38
- 2026-09-10: 38
- 2026-09-09: 38

## Common questions

### What is the Ontonym MCP server?

Ontonym is an MCP server listed in the public MCP registry as com.ontonym/memory. Give your agents your team's real data, read the shared graph, propose actions your team approves. This page covers its hosted endpoint (https://mcp.ontonym.com/mcp).

### Is the Ontonym MCP server safe to use?

Ontonym scores 38 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Ontonym MCP server expose?

Ontonym exposes 22 tools: list_my_memories, semantic_search, get_paths, resolve_names, list_classes, and 17 more. Their descriptions and schemas cost roughly 2,236 tokens of context every time the server is loaded.

### Does the Ontonym MCP server require authentication?

Yes. Ontonym asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

### Is the Ontonym MCP server still maintained?

Ontonym is still listed as active in the MCP registry. We last reached this channel on 3 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://mcp.ontonym.com/mcp
- Website: https://www.ontonym.com/
- Changelog RSS feed: https://verifymcp.io/servers/com-ontonym-memory/mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/com-ontonym-memory/mcp.json
- HTML version of this page: https://verifymcp.io/servers/com-ontonym-memory/mcp
