PeppolStatus
REMOTE · MCP.PEPPOLSTATUS.COM · SCANNED SEP 24
Peppol market intelligence and network monitoring: migrations, provider churn, leads, and uptime.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 62 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability65
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 12933 tokens (~208/item across 62 items; 62 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 62 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 63 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the PeppolStatus MCP server?
PeppolStatus is a hosted endpoint at https://mcp.peppolstatus.com/, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.peppolstatus.com
claude mcp add --transport http com-peppolstatus-api 'https://mcp.peppolstatus.com/'
{
"mcpServers": {
"com-peppolstatus-api": {
"url": "https://mcp.peppolstatus.com/"
}
}
} {
"servers": {
"com-peppolstatus-api": {
"type": "http",
"url": "https://mcp.peppolstatus.com/"
}
}
} [mcp_servers.com-peppolstatus-api] url = "https://mcp.peppolstatus.com/"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-peppolstatus-api": {
"type": "remote",
"url": "https://mcp.peppolstatus.com/",
"enabled": true
}
}
} openclaw mcp add com-peppolstatus-api --url 'https://mcp.peppolstatus.com/' --transport streamable-http
mcp_servers:
com-peppolstatus-api:
url: "https://mcp.peppolstatus.com/" {
"McpServers": {
"com-peppolstatus-api": {
"Transport": "http",
"Url": "https://mcp.peppolstatus.com/"
}
}
} assistant mcp add com-peppolstatus-api -t streamable-http -u 'https://mcp.peppolstatus.com/'
{
"mcpServers": {
"com-peppolstatus-api": {
"type": "http",
"url": "https://mcp.peppolstatus.com/"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Sept 26 0
- New tool “get_participants_mix” functional
- 19 Sept 26 0
- Schema quality: 176 → 195 ▼ functional
- New tool “get_access_point_roster_mix” functional
- “list_participants” added an optional parameter “not_country” cosmetic
- “list_participants” added an optional parameter “not_entity_type” cosmetic
- “list_participants” added an optional parameter “not_region” cosmetic
- “list_participants” added an optional parameter “not_sector” cosmetic
- “list_participants” added an optional parameter “not_size” cosmetic
- “list_participants” added an optional parameter “not_smp” cosmetic
- “get_adoption” reworded the description of “country” cosmetic
- 18 Sept 26 −1
- Tool “get_host_software” rewrote its description, which is the text the model reads security
- Tool “get_participant_stats” rewrote its description, which is the text the model reads security
- Tool “get_software” rewrote its description, which is the text the model reads security
- Tool “list_host_software” rewrote its description, which is the text the model reads security
- Tool “list_smps” rewrote its description, which is the text the model reads security
- Tool “list_software” rewrote its description, which is the text the model reads security
- “get_adoption” reworded the description of “country” cosmetic
- 16 Sept 26 0
- New tool “get_software” functional
- New tool “list_software” functional
- “list_compliance_findings” reworded the description of “since” cosmetic
- 15 Sept 26 0
- Tool “get_access_point” rewrote its description, which is the text the model reads security
- Tool “get_host” rewrote its description, which is the text the model reads security
- 11 Sept 26 0
- Tool “list_access_points” rewrote its description, which is the text the model reads security
- Schema quality: 8488 → 9429 ▼ functional
- New tool “list_cohort_move_participants” functional
- New tool “list_cohort_moves” functional
- “list_access_points” added an optional parameter “country” cosmetic
- 10 Sept 26 0
- Tool “get_compliance_stats” rewrote its description, which is the text the model reads security
- Tool “get_compliance_stats_history” rewrote its description, which is the text the model reads security
- “get_compliance_stats” added an optional parameter “country” cosmetic
- “get_compliance_stats_history” added an optional parameter “country” cosmetic
- 9 Sept 26 0
- Tool “list_participants” rewrote its description, which is the text the model reads security
- Schema quality: 7018 → 8225 ▼ functional
- New tool “get_compliance_stats” functional
- New tool “get_compliance_stats_history” functional
- New tool “get_seat_compliance” functional
- New tool “list_compliance_findings” functional
- New tool “list_compliance_rules” functional
- “list_participants” added an optional parameter “sub_provider” cosmetic
- “list_participants” reworded the description of “sort” cosmetic
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 24 Sept 2026 · Probed https://mcp.peppolstatus.com
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=peppolstatus.com | CN=WE1,O=Google Trust Services,C=US | 5 Aug 2026 | 3 Nov 2026 | ECDSA 256 | ECDSA-SHA256 | 151ba528f0866ef0133293c5497cc634 |
| SANs: peppolstatus.com, mcp.peppolstatus.com, *.mcp.peppolstatus.com | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.peppolstatus.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| peppolstatus.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=0; includeSubDomains |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.peppolstatus.com | Verified | 200 | |
| http (plaintext) | http://mcp.peppolstatus.com | HTTPS enforced | 301 | https://mcp.peppolstatus.com/ |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
get_access_point ~186
Get an access point One Provider's detail: display name, verified flag, member seats (each with its embedded provider or unverified cert-CN), roster size, and the country + document-scheme composition of its roster. A request for a STALE key (a seat since curated, so its old unverified key left the directory) resolves to the current Provider; the returned `key` is always the canonical current one. `software` groups the Provider's sighted hosts by registrable domain with the crawled identity of each, and `hostname_count` / `smp_hostname_count` give the true totals behind the capped `hostnames` / `smp_hostnames` samples.
| Name | Type | Req | Description |
|---|---|---|---|
| key | string | yes | The provider key (e.g. `c-tickstar`, `o-teamleader-nv-1f3a2b9c`). |
No output schema declared.
No examples provided.
get_access_point_churn ~178
Get an access point's churn An Access Point's joiner / mover / leaver activity over a period: a daily category series with derived net growth, period totals, and the 'won from / lost to' counterpart breakdown. Joiners are first-ever serving seats (from 2026-08-02 onward, first-full-deep-sweep completion); movers change Provider (both sides resolved to the current identity); leavers deregister while served. Defaults to the trailing 30 days.
| Name | Type | Req | Description |
|---|---|---|---|
| from | string | – | Inclusive period start, `YYYY-MM-DD` UTC. Defaults to 29 days before `to`. |
| key | string | yes | The Provider key (e.g. `c-tickstar`). |
| to | string | – | Inclusive period end, `YYYY-MM-DD` UTC. Defaults to today. |
No output schema declared.
No examples provided.
get_access_point_roster_mix ~907
Get a filtered access point roster breakdown The five roster breakdowns of `GET /v1/aps/{key}` (country, entity type, NACE sector, size class, region) recomputed over a FILTERED slice of the roster, so a breakdown stays true while the roster is cut down. The filters are the same names and shapes as `GET /v1/participants`, scoped to this provider's seats. BOUNDED BY DESIGN. The breakdowns are computed only when the filtered slice is narrow (under an internal cap of 10,000 participants). A request that narrows on nothing, that carries a filter this endpoint cannot express (`doctype`, `transport_profile`, `q`, `host`, `sub_provider`, `postcode`, `provenance`, `vat_liable`), or whose slice is too wide answers `degraded: true` with every mix null — never a wrong number and never an error. Callers fall back to the stored whole-roster mixes on `GET /v1/aps/{key}`. Counts are sparse the same way the stored mixes are: company enrichment covers a handful of registers, so every mix except `country_mix` sums BELOW `participant_count` and the un-enriched remainder is derived from the total rather than served as a bucket.
| Name | Type | Req | Description |
|---|---|---|---|
| country | array | – | Comma-array of ISO-3166-1 alpha-2 country codes. Matched on the participant's card country, falling back to the country its ICD prefix implies — the same rule the stored `country_mix` buckets on. |
| entity_type | array | – | Comma-array of company legal-form families (`company`, `natural_person`, `association`, `public`). |
| key | string | yes | The provider key (e.g. `c-tickstar`, `o-teamleader-nv-1f3a2b9c`). |
| not_country | array | – | Comma-array of country codes (`NO,SE`) to EXCLUDE. Rows with no value are KEPT — excluding a value never drops the un-enriched remainder. Combines with its include twin: `?region=NO-03¬_region=NO-… |
| not_entity_type | array | – | Comma-array of company legal-form families (`company`,`natural_person`,`association`,`public`) to EXCLUDE. Rows with no value are KEPT — excluding a value never drops the un-enriched remainder. Combi… |
| not_region | array | – | Comma-array of company seat region codes (`NO-32,BE-BRU`) to EXCLUDE. Rows with no value are KEPT — excluding a value never drops the un-enriched remainder. Combines with its include twin: `?region=N… |
| not_sector | array | – | Comma-array of 2-digit NACE divisions (`47,62`) to EXCLUDE. Rows with no value are KEPT — excluding a value never drops the un-enriched remainder. Combines with its include twin: `?region=NO-03¬_r… |
| not_size | array | – | Comma-array of company size classes (as stored; SIRENE only) to EXCLUDE. Rows with no value are KEPT — excluding a value never drops the un-enriched remainder. Combines with its include twin: `?regio… |
| region | array | – | Comma-array of company seat region codes (`NO-32,BE-BRU`). |
| registered | boolean | – | Restrict to participants present (`true`) or absent (`false`) in the Peppol Directory. |
| scheme | array | – | Comma-array of Peppol identifier schemes. |
| seat | string | – | Scope the slice to ONE member seat of this provider. A seat that is not a member answers an empty (not degraded) slice. Single-valued. |
| sector | array | – | Comma-array of 2-digit NACE divisions (`47,62`). |
| size | array | – | Comma-array of company size classes (as stored). |
| smp | array | – | Comma-array of SMP hostnames serving the participant. |
No output schema declared.
No examples provided.
get_adoption ~225
Get a country's adoption aggregates Peppol adoption for one country as one bare object: headline totals (universe, on_peppol, penetration), the single-dimension cuts (sector with a NACE section rollup, region, FR-only département + size class, BE-only province + postcode + mandate scope, legal-form family, and company age), the same categorical cuts cross-tabbed by company-age band (`cuts_by_age`), and the trend (monthly new adopters plus per-run penetration history). Region cells carry ISO 3166-2 (BE) / INSEE région (FR) codes and sector cells the NACE division code, so the choropleth joins geometry with no string matching. Numerator cells below 10 matched companies are suppressed (`on_peppol`/`penetration` null, `suppressed` true); denominators are never suppressed. Cached for a day (data moves monthly).
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | yes | Country code — `be`, `fr`, `sk`, `no`, `se` or `fi`. |
No output schema declared.
No examples provided.
get_anomaly ~33
Get an anomaly One anomaly by its stable content-derived key.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | The stable anomaly key. |
No output schema declared.
No examples provided.
get_compliance_stats ~275
Network compliance landscape The free compliance landscape (issue #692): per-country error rates — the share of a country's registered participants that break at least one published Peppol rule — and the per-rule breakdown of every open finding. Counts ONLY: no participant, seat or hostname appears here; the participant-level records are `GET /v1/compliance/findings` (Network tier). Read from the pre-computed compliance rollup tables and edge-cached. Keyless-cacheable. Pass `country` to scope the whole body to one country (issue #716): the same shape, with `countries` holding that one cell, `rules` its own breakdown, each rule's `share` a share of THAT country's open findings, and the code echoed back in `country`. A country scope is how a structural national pattern is told apart from a real problem — AU and NZ, for example, break `not_in_peppol_directory` almost everywhere because A-NZ PINT participants are absent from the European Peppol Directory by design.
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | – | Scope the landscape to one ISO 3166-1 alpha-2 country (or `ZZ`, the bucket for findings whose subject resolves to no country). A country the rollup has not seen returns an empty landscape, not an err… |
No output schema declared.
No examples provided.
get_compliance_stats_history ~201
Network compliance trend The network compliance picture over time: one point per UTC day the rollup ran, carrying that day's participant denominator, affected participants, error rate and open findings by grade. The series starts the day the rollup first ran. Keyless-cacheable. Pass `country` for one country's trend (issue #716) — the same series shape, restricted to that country and echoed back in `country`. The per-country series starts the day the country rollup first ran, which is later than the network one.
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | – | Scope the trend to one ISO 3166-1 alpha-2 country (or `ZZ`). A country the rollup has not seen returns an empty series, not an error. |
| from | string | – | Inclusive lower bound (YYYY-MM-DD UTC). Defaults to 90 days ago. |
| to | string | – | Inclusive upper bound (YYYY-MM-DD UTC). Defaults to today. |
No output schema declared.
No examples provided.
get_country_churn ~138
Per-country participant churn New (joiner) vs departed (leaver) participants for one country, as a daily series and an all-time monthly rollup, from the hourly churn rollup. A valid but unknown country returns empty arrays. Keyless-cacheable.
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | yes | Two-letter country code (ISO 3166-1 alpha-2), case-insensitive. |
| from | string | – | Inclusive lower bound of the daily series (YYYY-MM-DD UTC). Defaults to 30 days ago. |
| to | string | – | Inclusive upper bound of the daily series (YYYY-MM-DD UTC). Defaults to today. |
No output schema declared.
No examples provided.
get_country_providers ~190
Providers serving a country The Access Points serving one country, ranked two ways from the hourly rollup: `providers` by participant (Peppol-ID) count, and `providers_by_company` by the number of DISTINCT organizations (real businesses) each serves (issue #467). Each row's `key` is the `/v1/aps/{key}` handle and `share` is that provider's fraction of the country's AP-served total for its metric. `company_coverage` (0..1) is how much ID→organization dedup the market shows — ~0 (and `providers_by_company` empty) for markets without register enrichment, meaningfully positive for BE/FR. A valid but unknown country returns empty lists. Keyless-cacheable.
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | yes | Two-letter country code (ISO 3166-1 alpha-2), case-insensitive. |
No output schema declared.
No examples provided.
get_doctype_family ~91
Doctypes within a family The concrete document types within one family (issue #647): each doctype's local name, version, participant count, and share of the family. An unknown family returns an empty `doctypes` array. Keyless-cacheable.
| Name | Type | Req | Description |
|---|---|---|---|
| family | string | yes | The doctype family name (e.g. `Invoice`, `Order`, `Credit Note`). |
No output schema declared.
No examples provided.
get_doctype_family_countries ~107
A family's receivers by country One document family's receiving participants sliced by ISO-3166 alpha-2 country (issue #652), each with its share of the family total. The country is derived from the participant identifier's ICD; unresolved identifiers bucket as `ZZ`. An unknown family returns an empty `countries` array. Keyless-cacheable.
| Name | Type | Req | Description |
|---|---|---|---|
| family | string | yes | The doctype family name (e.g. `Invoice`, `Order`, `Credit Note`). |
No output schema declared.
No examples provided.
get_doctype_family_providers ~114
A family's receivers by provider One document family's receiving participants sliced by hosting provider (issue #652), attributed via the SMP-hosted footprint (the participant's current SMP host mapped to a provider), each with its share of the family total. Participants whose SMP host maps to no known provider are omitted. An unknown family returns an empty `providers` array. Keyless-cacheable.
| Name | Type | Req | Description |
|---|---|---|---|
| family | string | yes | The doctype family name (e.g. `Invoice`, `Order`, `Credit Note`). |
No output schema declared.
No examples provided.
get_doctype_stats ~70
Document-type landscape The free document-type landscape (issue #647): per-family participant share (Invoice, Order, Credit Note, …), the wildcard-doctype bucket, and the participant denominator. Read from the pre-computed doctype rollup tables and edge-cached. Keyless-cacheable.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_doctype_stats_history ~88
Document-type landscape history The document-type landscape over time: per UTC day, the participant count for each family, from the doctype history rollup. Keyless-cacheable.
| Name | Type | Req | Description |
|---|---|---|---|
| from | string | – | Inclusive lower bound (YYYY-MM-DD UTC). Defaults to 90 days ago. |
| to | string | – | Inclusive upper bound (YYYY-MM-DD UTC). Defaults to today. |
No output schema declared.
No examples provided.
get_host ~117
Get a host's current state Current role, verdict, network attribution (IPs/PTR), TLS certificate and operating provider for a host. `?at=` returns point-in-time state. `profile` carries the crawled software identity of the host's registrable domain when one is publishable (curated, or extraction confidence 0.8+ — then unverified).
| Name | Type | Req | Description |
|---|---|---|---|
| at | string | – | Point-in-time ISO 8601 instant; omitted returns current state. |
| hostname | string | yes | The host's fully-qualified hostname. |
No output schema declared.
No examples provided.
get_host_software ~271
Get a host's software fingerprint The detected software of a host across ALL its roles: vendor, version and hosting per role, each with its confidence tier, first-seen timestamp and the structured evidence that fired. `?at=` returns point-in-time state. The version axis adds release staleness (issue #798): `latest_release` (the newest stable upstream release of the product LANE — `oxalis` has three independent lanes, so the comparison is never one "latest Oxalis"), `lag` (`releases_behind`, `days_behind`, and an `exactness` of `exact` / `at_least` for a floor reading such as `>=8.1.0`, measured against the floor version / `unknown` for a snapshot or a version no lane claims) and `advisories` (CVSS severity counts plus the matching advisory ids). All three are NULL when the engine tracks no upstream lane; `advisories` alone is NULL when the lane publishes no advisory feed, and all-zero counts mean tracked and clean, which is a different statement. Market tier.
| Name | Type | Req | Description |
|---|---|---|---|
| at | string | – | Point-in-time ISO 8601 instant; omitted returns current state. |
| hostname | string | yes | The host's fully-qualified hostname. |
No output schema declared.
No examples provided.
get_host_uptime ~186
Get a host's uptime aggregates The aggregate ladder for a host at a chosen resolution, per-location plus the `__all__` rollup, optionally windowed by `[from, to)`, cursor-paginated.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | Opaque pagination cursor returned as `next_cursor` by the previous page. |
| from | string | – | Inclusive lower bound (ISO 8601). Must not be after `to`. |
| hostname | string | yes | The host's fully-qualified hostname. |
| limit | integer | – | Page size, clamped to [1, 200]. Defaults to 50. |
| location | string | – | Restrict to one probe location, or `__all__` for the rollup. |
| resolution | string | – | Aggregate tier. Defaults to hourly. |
| to | string | – | Exclusive upper bound (ISO 8601). |
No output schema declared.
No examples provided.
get_id_quality ~58
Peppol ID quality summary Per-scheme (ICD) summary of the structural identifier checks: how many participants were checked, how many failed their scheme's rule, and the resulting violation rate. Ordered by violation count, busiest first.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_id_quality_hosting ~142
Hosting rollup for malformed identifiers Which Access Points and SMPs serve the malformed identifiers, honouring the same `scheme`/`reason`/`q` filters as the malformed list. Access points and SMPs are ranked by malformed-id count; `totals` covers the filtered set.
| Name | Type | Req | Description |
|---|---|---|---|
| q | string | – | Case-insensitive substring match on the identifier value. |
| reason | string | – | Filter by the kind of structural failure. |
| scheme | string | – | Filter to one Peppol ICD scheme (e.g. `0208`). |
| smp | string | – | Filter to malformed ids homed on one SMP hostname. |
No output schema declared.
No examples provided.
get_network_history ~203
Get the network verdict history The host verdict mix over time, derived from the temporal verdict table in one windowed pass: per UTC day, the rows open at 00:00 that day, counted by verdict. Two caveats. Counts are (hostname, role) pairs — a host serving two roles counts twice, the same grain as `/v1/network`. And before 2026-08-15 an unresolvable host was recorded as `down`, so `unresolvable` reads 0 over the earlier stretch. The series starts 2026-07-21, the first day the table covers; an earlier `from` is clamped to it. Keyless-cacheable.
| Name | Type | Req | Description |
|---|---|---|---|
| from | string | – | Inclusive lower bound (YYYY-MM-DD UTC). Defaults to 90 days ago; clamped to 2026-07-21. |
| to | string | – | Inclusive upper bound (YYYY-MM-DD UTC). Defaults to today. |
No output schema declared.
No examples provided.
get_network_summary ~45
Get the network summary Current host verdict counts, open incidents and anomalies in the last 24h, plus how fresh the Peppol Directory export behind every other endpoint is.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_participant ~91
Get a participant's current state Directory presence, SML registration + current SMP, business card, the company-register enrichment block, endpoints and serving seats for a Peppol participant. Discovered participants carry no card; unmatched participants carry company: null.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Canonical `scheme::value` Peppol identifier (e.g. `0208::0762747721`). |
No output schema declared.
No examples provided.
get_participant_availability ~319
Get a participant's measured availability The real, probe-measured reachability of one Peppol ID over time. Two lanes — the participant's SMP host (discovery) and its Access Point host(s) (delivery) — are read from the uptime ladder and merged per bucket into one verdict (available | degraded | unreachable | no_data): an AP with any down check is unreachable; an AP up/degraded with the SMP down is degraded (discovery impaired, still deliverable); both lanes up is available. Returns per-lane `UptimeBucket` ladders, the worst-of combined lane, 30/90-day + full headline uptime (degraded counts as available), a monthly 99.5% Peppol AP service-level TARGET (never a contractual claim), host-change markers and window-overlapping incidents. `daily` spans the full history; `hourly` covers the last 90 days. Buckets before the 2026-08-02 AP epoch carry partial AP attribution (`pre_epoch`).
| Name | Type | Req | Description |
|---|---|---|---|
| from | string | – | Inclusive lower bound (ISO 8601). Must not be after `to`. |
| id | string | yes | Canonical `scheme::value` Peppol identifier (e.g. `0208::0762747721`). |
| resolution | string | – | Aggregate tier. `daily` spans the full history; `hourly` the last 90 days. |
| to | string | – | Exclusive upper bound (ISO 8601). Defaults to now. |
No output schema declared.
No examples provided.
get_participant_history ~103
List a participant's temporal history The participant's temporal rows across the directory/card/registration/SMP fact families, newest-first, cursor-paginated.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | Opaque pagination cursor returned as `next_cursor` by the previous page. |
| id | string | yes | Canonical `scheme::value` Peppol identifier. |
| limit | integer | – | Page size, clamped to [1, 200]. Defaults to 50. |
No output schema declared.
No examples provided.
get_participant_joiners ~101
Network joiners curve The real onboarding curve (issue #222): joiner counts bucketed by derived network join date (business-card RegistrationDate, else genuine first-seen), with a whole-network coverage split (registration_date / first_seen / unknown). The unknown/seed tail is reported in `coverage` only, never folded into a bucket. Keyless-cacheable.
| Name | Type | Req | Description |
|---|---|---|---|
| bucket | string | – | Bucket granularity. Defaults to `year`. |
No output schema declared.
No examples provided.
get_participant_stats ~100
Participant facet stats Global participant facet counts (per country/scheme/smp/ap/doctype/transport_profile, registered share, provenance split) plus an estimated total, from the hourly rollup. `total_count` counts every ID ever registered; `registered_count` and the `country_registered` facet scope the same data to the LIVE (registered) IDs (issue #818). Keyless-cacheable — safe for the marketing site to hit directly.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_participant_stats_history ~185
Participant facet history A daily time series over one participant facet dimension (adoption curves / QoQ trends), from daily snapshots of the rollup. History accrues from the day the feature shipped. Keyless-cacheable.
| Name | Type | Req | Description |
|---|---|---|---|
| dimension | string | yes | Which series to return: `total` (whole-network count) or a facet dimension. |
| from | string | – | Inclusive lower bound (YYYY-MM-DD UTC). Defaults to 90 days ago. |
| key | array | – | Comma-separated facet keys to filter to (e.g. `BE,NL` for `dimension=country`). Omit for every key in the dimension. |
| limit | integer | – | Max points returned, clamped to [1, 10000]. Defaults to 10000. |
| to | string | – | Inclusive upper bound (YYYY-MM-DD UTC). Defaults to today. |
No output schema declared.
No examples provided.
get_participants_mix ~1,024
Get a filtered participant breakdown The participant set broken down by country, entity type, NACE sector, size class, region and serving Access Point, over a FILTERED slice — so a breakdown stays true while the list is cut down. The filters are the same names and shapes as `GET /v1/participants`. TWO SOURCES, one shape, named by `source`. A request that narrows on NOTHING is answered from the hourly rollup (`source: "rollup"`, with `refreshed_at`) — the whole-network breakdown, no scan. A request that narrows is computed live (`source: "slice"`). BOUNDED BY DESIGN. A live slice is computed only while it is narrow (under an internal cap of 10,000 participants). A slice wider than the cap, or a request carrying a filter this endpoint cannot express (`doctype`, `transport_profile`, `q`, `host`, `sub_provider`), answers `degraded: true` with every mix null — never a wrong number and never an error. Callers fall back to the whole-network breakdown on `GET /v1/stats/participants`. Counts are sparse the same way the rollup facets are: company enrichment covers a handful of registers, so every mix except `country_mix` sums BELOW `participant_count` and the un-enriched remainder is derived from the total rather than served as a bucket. `ap_mix` names the busiest Access Point Seats and folds the rest into one `__other__` bucket.
| Name | Type | Req | Description |
|---|---|---|---|
| ap | array | – | Comma-array of serving Access Point SeatIDs (`PBE000123,PNO000456`). |
| country | array | – | Comma-array of ISO-3166-1 alpha-2 country codes. Matched on the participant's card country, falling back to the country its ICD prefix implies — the same rule `country_mix` buckets on. |
| entity_type | array | – | Comma-array of company legal-form families (`company`,`natural_person`,`association`,`public`), from the company-register enrichment denormalized onto the participant. |
| not_country | array | – | Comma-array of country codes (`NO,SE`) to EXCLUDE. Rows with no value are KEPT — excluding a value never drops the un-enriched remainder. Combines with its include twin: `?region=NO-03¬_region=NO-… |
| not_entity_type | array | – | Comma-array of company legal-form families (`company`,`natural_person`,`association`,`public`) to EXCLUDE. Rows with no value are KEPT — excluding a value never drops the un-enriched remainder. Combi… |
| not_region | array | – | Comma-array of company seat region codes (`NO-32,BE-BRU`) to EXCLUDE. Rows with no value are KEPT — excluding a value never drops the un-enriched remainder. Combines with its include twin: `?region=N… |
| not_sector | array | – | Comma-array of 2-digit NACE divisions (`47,62`) to EXCLUDE. Rows with no value are KEPT — excluding a value never drops the un-enriched remainder. Combines with its include twin: `?region=NO-03¬_r… |
| not_size | array | – | Comma-array of company size classes (as stored; SIRENE only) to EXCLUDE. Rows with no value are KEPT — excluding a value never drops the un-enriched remainder. Combines with its include twin: `?regio… |
| not_smp | array | – | Comma-array of SMP hostnames to EXCLUDE. Rows with no value are KEPT — excluding a value never drops the un-enriched remainder. Combines with its include twin: `?region=NO-03¬_region=NO-32` applie… |
| postcode | array | – | Comma-array of company seat postcodes. |
| provenance | array | – | Comma-array of provenance values. |
| region | array | – | Comma-array of company seat region codes (`BE-BRU,BE-VLG`). |
| registered | boolean | – | Filter by current SML registration state. |
| scheme | array | – | Comma-array of Peppol identifier schemes. |
| sector | array | – | Comma-array of 2-digit NACE divisions (`47,62`). |
| size | array | – | Comma-array of company size classes (as stored; SIRENE only). |
| smp | array | – | Comma-array of current SMP hostnames (`smp1.example,smp2.example`). |
| vat_liable | boolean | – | Filter by company VAT-liable / mandate-scope flag. |
No output schema declared.
No examples provided.
get_provider ~39
Get a curated provider A curated provider navigable to its seats and each seat's observed hosts.
| Name | Type | Req | Description |
|---|---|---|---|
| slug | string | yes | The curated provider slug. |
No output schema declared.
No examples provided.
get_provider_sla ~108
List provider SLA scorecards Per-provider SLA scorecards for one trailing period: checks-weighted uptime across each provider's mapped hosts, incident count, total downtime minutes and the single worst host. Ordered worst uptime first (providers with no checks in the window last). Materialized hourly by the batch runner. Not paginated (the envelope's `next_cursor` is always null).
| Name | Type | Req | Description |
|---|---|---|---|
| period | string | – | Trailing window: `30d` (default) or `90d`. |
No output schema declared.
No examples provided.
get_provider_sla_by_key ~83
Get a provider's SLA scorecards One provider's SLA scorecards, one per trailing period (30d and 90d). `key` is the provider's natural key (as reported by `GET /v1/providers`). Empty `items` when the provider has no SLA data yet.
| Name | Type | Req | Description |
|---|---|---|---|
| key | string | yes | The provider natural key. |
No output schema declared.
No examples provided.
get_public_provider ~59
Get a public provider profile The FREE, crawlable public subset for one curated provider (same shape as a `GET /v1/providers/public` item). Reachable with no API key.
| Name | Type | Req | Description |
|---|---|---|---|
| slug | string | yes | The curated provider slug. |
No output schema declared.
No examples provided.
get_seat ~62
Get a seat A Peppol certificate seat: its embedded provider (verified mapping or unverified cert-CN fallback) and the hosts it was observed operating.
| Name | Type | Req | Description |
|---|---|---|---|
| seatId | string | yes | The seat identifier (e.g. `POP000748`). |
No output schema declared.
No examples provided.
get_seat_compliance ~230
Get a seat's compliance scorecard One seat's compliance posture: the registrations under it, its OPEN findings broken down by rule, the daily trend, and where the seat sits against the network. This is what a Peppol Authority's periodic scan reports, from the same published rules (`GET /v1/compliance/rules`), before the letter arrives. Rates are open findings per 1,000 registrations, and `null` when the seat hosts no registrations. The network median and 90th percentile are taken over every seat that hosts registrations — a seat with no finding of a rule counts as 0 — so they describe the whole network, not only the seats that break the rule. Read from a daily rollup: `snapshot_date` is the day it describes, and is `null` (with zero counts and empty lists) for a seat no scan has covered yet.
| Name | Type | Req | Description |
|---|---|---|---|
| days | integer | – | How many daily snapshots the trend covers (default 90). |
| seatId | string | yes | The seat identifier (e.g. `POP000748`). |
No output schema declared.
No examples provided.
get_seat_sla ~101
Get a seat's SLA scorecards One seat's SLA scorecards, one per trailing period (30d and 90d). `seatId` is the seat identifier (as reported by `GET /v1/aps/{key}` on `seats[].seat_id`). Empty `items` when the seat has no SLA data yet.
| Name | Type | Req | Description |
|---|---|---|---|
| seatId | string | yes | The seat identifier (e.g. `POP000748`). |
No output schema declared.
No examples provided.
get_sml_status ~48
Get SML/SMK zone status One entry per monitored zone: quorum verdict, per-location canary breakdown, DNAME cutover state, management-host TLS snapshot and zone incidents.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_software ~203
Get one software product (Market) One engine of the software library: the same row the list returns (product metadata, host count per observed role, first/last seen, the compliance signal and the host-count trend) plus the catalogue version and generation stamp. `engine` is a catalogue engine slug as published in `engine` on the list; an unknown slug is a 404. Beyond the list row it also returns `advisory_list[]` (issue #798): every live advisory of the engine's lanes with its id, normalized severity, CVSS score, summary, url and publication stamp, newest first. Null when no lane of the engine has an advisory feed; `[]` when it has one and upstream has published nothing. Market tier.
| Name | Type | Req | Description |
|---|---|---|---|
| days | integer | – | Trend window in trailing UTC days, 1..90 (default 90). |
| engine | string | yes | The catalogue engine slug, e.g. `phoss`. |
No output schema declared.
No examples provided.
get_software_stats ~107
Software landscape The free host-software landscape (issue #490): k-anonymised vendor share (k=5, the sub-k tail folded into `other`), version distribution within each named vendor, ASN hosting share, and a two-denominator coverage block (host-weighted ~90% and participant-weighted ~50%, each named, no bare coverage scalar). Computed live from the temporal software table and edge-cached. Names no operator. Keyless-cacheable.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_software_stats_history ~100
Software landscape history The software landscape over time, derived from the temporal software table in one windowed pass: per UTC day, the host-weighted identified/total targets and the k-anonymised vendor shares. Keyless-cacheable.
| Name | Type | Req | Description |
|---|---|---|---|
| from | string | – | Inclusive lower bound (YYYY-MM-DD UTC). Defaults to 90 days ago. |
| to | string | – | Inclusive upper bound (YYYY-MM-DD UTC). Defaults to today. |
No output schema declared.
No examples provided.
get_summary ~81
Get the public dashboard summary The free marketing-dashboard rollup: the network-wide host rollup (fleet count + mean uptime/latency), the hourly fleet-average p50 latency trend over the last 24h, and the top-10 providers by market share (0..1 fraction). No host list, full registry or arbitrary per-host uptime is exposed.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_access_point_churn_participants ~110
List participants behind a churn category The drill-down: the participant IDs behind one churn category count for this Provider over the period. Bounded to 500 rows (never paginated; next_cursor null).
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | The churn category to expand. |
| from | string | – | Inclusive period start, `YYYY-MM-DD` UTC. |
| key | string | yes | The Provider key. |
| to | string | – | Inclusive period end, `YYYY-MM-DD` UTC. |
No output schema declared.
No examples provided.
list_access_points ~192
List access points The Access Point directory: every Provider in its serving role, with its member seats and roster size (current participant count), busiest first. A Provider is resolved from each seat with the precedence curated mapping (verified) → exact signing-cert `O=` string (unverified) → bare SeatID. Not paginated (the envelope's `next_cursor` is always null). Pass `?country=CC` to compare providers within one market instead of network-wide.
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | – | Scope the returned figures to one market: an ISO 3166-1 alpha-2 code (e.g. `BE`), case-insensitive. Anything that is not exactly two letters is a 400. When set, every item additionally carries `count… |
No output schema declared.
No examples provided.
list_anomalies ~145
List anomalies The anomaly feed, newest-first, cursor-paginated.
| Name | Type | Req | Description |
|---|---|---|---|
| acknowledged | boolean | – | Filter by acknowledgement state. |
| cursor | string | – | Opaque pagination cursor returned as `next_cursor` by the previous page. |
| detector | string | – | Filter by detector. |
| grade | string | – | Filter by grade. |
| host | string | – | Filter to anomalies targeting one host. |
| limit | integer | – | Page size, clamped to [1, 200]. Defaults to 50. |
| seat | string | – | Filter to anomalies targeting one seat. |
| since | string | – | Only include items at or after this ISO 8601 instant. |
No output schema declared.
No examples provided.
list_cohort_move_participants ~200
List participants in a bulk AP migration The drill-down: the participant IDs behind one cohort, oldest observation day first. A cohort's membership is DEFINED as the mover events its provider pair and day range select, so this list is always in step with the cohort's counts. Cursor-paginated on (day, value). `id` is the request-lifetime handle from `GET /v1/stats/cohort-moves`. The detector re-clusters the trailing window on every run, so a handle whose cohort boundaries have since shifted answers 404 rather than a stale list — re-read the feed instead of persisting ids.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | Opaque pagination cursor returned as `next_cursor` by the previous page. |
| id | string | yes | The cohort handle: 16 lowercase hex characters. |
| limit | integer | – | Page size, clamped to [1, 200]. Defaults to 50. |
No output schema declared.
No examples provided.
list_cohort_moves ~636
List bulk AP migrations Detected bulk migrations between Access Points, largest first. A cohort is a gap-≤3-day island of (from_provider, to_provider) mover days that clears three thresholds: at least 25 participants, at least 40 % of them on the busiest day (which rejects a steady drip), and at most 20 active days for the pair over the trailing 40 days (which rejects a recurring partnership). Every day is the PROBE-OBSERVATION day — the day the change scan saw the SMP record change, not the day the migration was executed — so a cohort is always a `[first_day, last_day]` range and `peak_day` is the busiest observation day. Render the range, never a single date. `top_country` is derived from the ICD prefix of the participant identifiers, not from business-card country fields. `merge_suspect` marks a cohort large enough (or whose source provider no longer resolves in the directory) to be a provider merge or a renamed provider rather than that many independent customer decisions — the canonical case is Sovos → Sage, 10,574 participants. Such rows are data events, not customer decisions; verify one before quoting it. The flag is a CURRENT judgment, re-evaluated on every recompute, not frozen at detection. `from`/`to` are OVERLAP bounds (a cohort counts when its range intersects the window), defaulting to the trailing 90 days the detector re-clusters. Mover history begins 2026-07-24, so no cohort predates it. `id` is a request-lifetime handle for the participant drill-down — never persist one.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | Opaque pagination cursor returned as `next_cursor` by the previous page. |
| direction | string | – | Which side of the `provider` filter to take: `in` = cohorts the provider received, `out` = cohorts it lost, `both` = either. Only meaningful together with `provider`. |
| from | string | – | Inclusive lower bound of the observation window (`YYYY-MM-DD` UTC); a cohort matches when its `last_day` is at or after it. Defaults to 90 days ago. |
| limit | integer | – | Page size, clamped to [1, 200]. Defaults to 50. |
| merge_suspect | string | – | How to treat probable provider merges / slug changes: `include` (default), `exclude` for real customer migrations only, or `only` to review the flagged rows. |
| min_participants | integer | – | Only cohorts with at least this many participants. The detector's own floor is 25, so a lower value cannot surface smaller groups. |
| provider | string | – | Only cohorts involving this Provider key (`/v1/aps/{key}`). Matches EITHER side unless `direction` narrows it. |
| to | string | – | Inclusive upper bound of the observation window (`YYYY-MM-DD` UTC); a cohort matches when its `first_day` is at or before it. Defaults to today. |
No output schema declared.
No examples provided.
list_compliance_findings ~351
List compliance findings Deterministic verdicts against the published rules, newest first and keyset-paginated on (`first_detected_at`, `finding_id`). A finding stays `open` until the registration is corrected, at which point the next scan stamps `resolved_at`; `first_detected_at` survives every re-scan. Distinct from `/v1/anomalies`, which reports observed behaviour rather than rule breaches. The first page's `meta.facets` gives rule and grade counts over the filtered set.
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | – | Filter to one ISO 3166-1 alpha-2 country. |
| cursor | string | – | Opaque pagination cursor returned as `next_cursor` by the previous page. |
| grade | string | – | Filter by severity. |
| limit | integer | – | Page size, clamped to [1, 200]. Defaults to 50. |
| rule | string | – | Filter to one rule code (from `GET /v1/compliance/rules`). |
| scheme | string | – | Filter to one participant scheme id, for participant-grain rules. |
| seat | string | – | Filter to one operating seat id (e.g. `PBE000123`). |
| since | string | – | Only findings whose `last_seen_at` or `resolved_at` is at or after this ISO 8601 instant: everything the latest scans still confirm, plus everything opened, changed or resolved since. A finding whose… |
| status | string | – | Lifecycle slice; defaults to the open findings. |
No output schema declared.
No examples provided.
list_compliance_rules ~82
List the compliance rule catalogue The published rules registrations are judged against: what each rule requires, what it applies to, how severe a breach is, and how many findings requires, what it applies to, and how severe a breach is. Free — the rules themselves are public; the findings against them are on `GET /v1/compliance/findings`.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_events ~310
List global change events Every typed change event, newest-first, cursor-paginated. Any anomaly an event triggered is embedded on it. `cursor` walks older events; `prev_cursor` walks the newer edge (for live polling). The first page carries a `meta` block with exact type facets + filter count and an auto-bucketed timeline chart.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | Opaque pagination cursor returned as `next_cursor` by the previous page. |
| doctype | string | – | Filter to events touching one document-type URN. Matches both payload shapes: the merged `endpoint_changed` `doctypes` array and the legacy singular `doctype` on pre-merge rows. |
| host | string | – | Filter to events for one host. |
| limit | integer | – | Page size, clamped to [1, 200]. Defaults to 50. |
| participant | string | – | Filter to one participant (`scheme::value`). |
| prev_cursor | string | – | Opaque newer-direction cursor (from a page's `prev_cursor`): returns events newer than it, newest-first. Mutually exclusive with `cursor`. |
| seat | string | – | Filter to events referencing one seat. |
| since | string | – | Only include items at or after this ISO 8601 instant. |
| type | array | – | Comma-array of change-event types (a single value is valid). |
| until | string | – | Only include events at or before this ISO 8601 instant. |
No output schema declared.
No examples provided.
list_host_incidents ~118
List a host's incidents Incidents for one host, newest-first, cursor-paginated.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | Opaque pagination cursor returned as `next_cursor` by the previous page. |
| hostname | string | yes | The host's fully-qualified hostname. |
| limit | integer | – | Page size, clamped to [1, 200]. Defaults to 50. |
| since | string | – | Only include items at or after this ISO 8601 instant. |
| status | string | – | Filter by incident lifecycle state. |
No output schema declared.
No examples provided.
list_host_software ~303
List all hosts' software (Market) Every host with open software fingerprint rows, one row per (hostname, role) with the vendor / version / hosting axes folded in (value, tier, first-seen; plus vendor `variant` and version `kind`). The evidence blob is omitted to keep the list lean — it stays on the per-host resource. Cursor-paginated on the stable (hostname, role) order; optional `vendor=` filter. The version axis also carries release staleness (issue #798): `latest_release` (the newest stable upstream release of the product lane), `lag` (`releases_behind`, `days_behind`, `exactness`) and `advisories` (CVSS severity counts plus ids). All three are NULL when the engine tracks no upstream lane at all, and `advisories` alone is NULL when the lane publishes no advisory feed — null is not zero. A TRACKED engine whose detected version matches none of its lanes keeps `lag` with `exactness: "unknown"` and null counts, so it stays distinguishable from an untracked one. Market tier.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | Opaque pagination cursor returned as `next_cursor` by the previous page. |
| limit | integer | – | Page size, clamped to [1, 200]. Defaults to 50. |
| vendor | string | – | Keep only rows whose open vendor axis exactly equals this value. |
No output schema declared.
No examples provided.
What is the PeppolStatus MCP server?
PeppolStatus is an MCP server listed in the public MCP registry as com.peppolstatus/api. Peppol market intelligence and network monitoring: migrations, provider churn, leads, and uptime. This page covers its hosted endpoint (https://mcp.peppolstatus.com).
Is the PeppolStatus MCP server safe to use?
PeppolStatus scores 79 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the PeppolStatus MCP server expose?
PeppolStatus exposes 62 tools: list_hosts, get_host, list_host_incidents, get_host_uptime, list_host_software, and 57 more. Their descriptions and schemas cost roughly 12,776 tokens of context every time the server is loaded.
Does the PeppolStatus MCP server require authentication?
No. We connected to PeppolStatus without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the PeppolStatus MCP server still maintained?
PeppolStatus is still listed as active in the MCP registry. We last reached this channel on 24 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.