# Rekvira: EU regulation pinpoints for compliance AI (remote · mcp.rekvira.com)

Official EU regulation text with article and recital pinpoints over MCP. Keyless trial.

- Trust score: 69/100 (medium)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-28

## Components

- remote · `mcp.rekvira.com`: 69/100 (this document), [markdown](https://verifymcp.io/servers/com-rekvira-rekvira/mcp.md), [page](https://verifymcp.io/servers/com-rekvira-rekvira/mcp)

## Channel facts

- Endpoint: `https://mcp.rekvira.com/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `0.1.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-28.

- **Endpoint Security**: 63/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (rekvira_account).
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 77/100
  - 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 5424 tokens (~285/item across 19 items; 19 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 13/100
  - Stability observed for 4 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - All 3 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.
  - An AI judge read all 20 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a current MCP spec version (2026-07-28).

## Install

### How do I install the Rekvira: EU regulation pinpoints for compliance AI MCP server?

Rekvira: EU regulation pinpoints for compliance AI is a hosted endpoint at https://mcp.rekvira.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http com-rekvira-rekvira 'https://mcp.rekvira.com/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "com-rekvira-rekvira": {
      "url": "https://mcp.rekvira.com/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "com-rekvira-rekvira": {
      "type": "http",
      "url": "https://mcp.rekvira.com/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.com-rekvira-rekvira]
url = "https://mcp.rekvira.com/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-rekvira-rekvira": {
      "type": "remote",
      "url": "https://mcp.rekvira.com/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add com-rekvira-rekvira --url 'https://mcp.rekvira.com/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  com-rekvira-rekvira:
    url: "https://mcp.rekvira.com/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "com-rekvira-rekvira": {
      "Transport": "http",
      "Url": "https://mcp.rekvira.com/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add com-rekvira-rekvira -t streamable-http -u 'https://mcp.rekvira.com/mcp'
```

### Other

```json
{
  "mcpServers": {
    "com-rekvira-rekvira": {
      "type": "http",
      "url": "https://mcp.rekvira.com/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-28 (score 69, +1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-26 (score 68, +1)

- [security] Tool “submit_feedback” rewrote its description, which is the text the model reads
- [cosmetic] “submit_feedback” added an optional parameter “contact_email”
- [cosmetic] “submit_feedback” added an optional parameter “expected”
- [cosmetic] “submit_feedback” added an optional parameter “got”
- [cosmetic] “submit_feedback” added an optional parameter “query”
- [cosmetic] “submit_feedback” added an optional parameter “severity”
- [cosmetic] “submit_feedback” added an optional parameter “tool”
- [cosmetic] “submit_feedback” added an optional parameter “what”
- [cosmetic] “submit_feedback” reworded the description of “authored_by”
- [cosmetic] “submit_feedback” reworded the description of “confirmed”
- [cosmetic] “submit_feedback” reworded the description of “kind”
- [cosmetic] “submit_feedback” reworded the description of “message”
- [cosmetic] Tool “submit_feedback” changed its title: Send feedback to the operator → Send feedback to the team

### 2026-09-25 (score 67, +3)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-24 (score 64, +31)

- [security regression] Authorization: fail → unverified
- [security improvement] Transport: unverified → pass
- [security improvement] Injection markers: unverified → pass
- [security improvement] HSTS header: fail → pass
- [security] First check of Judged manipulation: pass
- [functional improvement] MCP protocol: unverified → pass
- [functional improvement] Tool coverage: unverified → 100
- [functional] First check of Schema quality: fail
- [functional] First check of Schema quality: excellent
- [functional] First check of Schema quality: fail
- [functional] First check of Destructive annotations: 0
- [functional] First check of Tool coverage: 100

### 2026-09-23 (score 33)

First indexed and scored.

## MCP tools (19)

### `connect` (~201 tokens)

Connect, or sign in (step 1 of 2)

Connect. With no arguments: the keyless trial — no email, no key; returns trial_id for record_assessment / list_assessments and the private playbook tools. Call start_here next. With the user's email and the language you speak with them (e.g. 'en', 'de', 'lt'): sign in to a free account that keeps their assessments and playbooks across chats. Rekvira sends ONE email in that language with a Confirm link and a six-digit code, valid 15 minutes, and returns request_id. Tell the user to click Confirm; then IMMEDIATELY call connect_verify(request_id) — it waits for the click. Nothing is charged and no card is needed.

Input parameters:

- `email`: Only to sign in: the user's email. Omit for the keyless trial
- `language`: The language you speak with the user (en, de, lt, fr, es, pl); the email uses it

### `connect_verify` (~174 tokens)

Sign in (step 2 of 2)

Finish signing in. Call it RIGHT AFTER connect(email) with the request_id and no code: it waits up to 45 s for the user to click Confirm in the email and returns as soon as they do (if it returns waiting, call it again — do not ask the user to report the click). If the user reads you the six-digit code, pass it as code. Pass the trial_id you already have and the keyless work moves into the account. Returns a rek_ key (shown once) and a `session` value to pass on later calls.

Input parameters:

- `code`: Only if the user reads you the six-digit code from the email
- `request_id`: request_id returned by connect(email)
- `trial_id`: Optional trial_id from the keyless connect(): its work moves into the account

### `rekvira_account` (~273 tokens)

Your account and plan

The signed-in account: action='status' (default: email, what is kept, keys), 'plan' (what the free beta includes: the keyless trial and the free account; nothing is charged), 'usage', 'keys' (list; never the key itself), 'revoke_key' with key_prefix, 'export' (everything held), 'delete' with confirm_email=<the account email> (mails a confirmation link; deletion happens on the click). Not signed in: says how to sign in, and 'plan' still shows what the free beta includes.

Input parameters:

- `action`: status | plan | usage | keys | revoke_key | export | delete
- `confirm_email`: With action='delete': the account's email, typed back by the user
- `key_prefix`: With action='revoke_key': the key's prefix as action='keys' lists it (rek_xxxxxx)
- `session`: The `session` value the sign-in returned. Pass it on every call in this conversation, so the sign-in survives however this client handles connections; omit it when the user connected with Sign in (OA…
- `tier`: With action='plan': not needed during the beta — everything is free and there is no paid plan to choose

### `start_here` (~70 tokens)

Start here

Orientation for this corpus right now — which regulations are loaded, unit counts, data_as_of, what is not held, and first-call hints per module. Built from the loaded corpus at call time. Cheap: one call, no quota. Then list_regulations, search_regulation, or list_workflows.

### `whoami` (~115 tokens)

Who am I

Who is calling: tier, trial state, corpus load count. Pass trial_id from connect() to confirm the handle used for assessments and private workflows. After connect, call start_here or list_regulations.

Input parameters:

- `session`: The `session` value the sign-in returned. Pass it on every call in this conversation, so the sign-in survives however this client handles connections; omit it when the user connected with Sign in (OA…
- `trial_id`: Optional trial_id from connect() — echoed when present

### `record_assessment` (~224 tokens)

Record an assessment

Record one structured applicability verdict on a regulation pinpoint for this keyless trial_id (from connect). Verdicts: applicable | not_applicable | needs_review | deferred. Optional reason codes only — never free-text notes. Re-recording the same regulation+pinpoint overwrites. Assessments annotate; they never hide search or read results. Call after the officer states applicability.

Input parameters:

- `pinpoint`: Pinpoint string, e.g. Article 6(1)
- `reason`: Optional structured reason: wrong_entity_type | below_threshold | already_covered_elsewhere | awaiting_vendor_answer | confirmed_obligation | revisit_after_guidance
- `regulation`: Regulation id, e.g. eu-ai-act
- `session`: The `session` value the sign-in returned. Pass it on every call in this conversation, so the sign-in survives however this client handles connections; omit it when the user connected with Sign in (OA…
- `trial_id`: trial_id returned by connect()
- `verdict`: applicable | not_applicable | needs_review | deferred

### `list_assessments` (~142 tokens)

List my assessments

List this trial_id's recorded assessments, newest first. Pass the trial_id from connect(). Use when resuming a multi-week DPIA or applicability review. Never invent rows for another trial.

Input parameters:

- `limit`: Max rows (1–100, default 50)
- `max_chars`: Cap on the response size in characters (default 8000)
- `session`: The `session` value the sign-in returned. Pass it on every call in this conversation, so the sign-in survives however this client handles connections; omit it when the user connected with Sign in (OA…
- `trial_id`: trial_id returned by connect()

### `submit_feedback` (~586 tokens)

Send feedback to the team

Send feedback about Rekvira to the team that builds it: a bug, a wrong answer, missing data, a missing feature, a workflow idea, or praise. Every item is read by a person.
When to offer it: an answer came back empty or wrong; the user corrected you or the result; a workflow was missing a step the user needed; the user repeats a manual step the service could do for them; the user says they need something the service does not do. Offer once, in one sentence; the user's task comes first.
Ask first. Show the user what you will send and send it only after they agree. Their own words, and any client, case, company or personal detail, go only with their explicit OK; then set confirmed=true. With authored_by='agent' you may report your own observation of the service (the tool, what you expected, what came back) without asking, as long as it holds none of the user's words or confidential content.
Fill kind and what (the task, and what went wrong or what is needed). For a wrong answer add expected and got. Add tool and query for context (the query only with the user's OK), severity, and contact_email only when the user wants a reply.
The reply carries a reference id. Tell the user it reached the team; do not promise a reply or a date.

Input parameters:

- `authored_by`: user (their words) | agent_drafted (you wrote it, they approved) | agent (your own observation)
- `confirmed` (boolean): true once the user approved sending this; required for authored_by user or agent_drafted
- `contact_email`: Only if the user wants a reply: the address to reply to
- `expected`: For a wrong answer: what the right answer or result would have been
- `got`: For a wrong answer: what came back instead
- `kind`: One of: bug (something failed or errored), wrong_answer (an answer was returned but it was wrong or misleading), missing_data (a document, record or source the user expected is not covered), missing_…
- `message`: Older name for `what`, kept so earlier callers still work; prefer `what`
- `query`: The query or arguments that produced it; only with the user's OK
- `severity`: low | normal | high | blocking (blocking: the user cannot do their work)
- `tool`: The tool the feedback is about, if one (e.g. the tool that answered wrongly)
- `what`: The task and what went wrong or what is needed (3-2000 characters)

### `list_regulations` (~76 tokens)

List regulations

List regulations in the registry and whether corpus JSON is loaded. Then search_regulation, search_regulations, or list_workflows for a named process.

Input parameters:

- `limit`: Most rows to return (default 10 on searches, max 50)
- `max_chars`: Cap on the response size in characters (default 8000)

### `search_regulation` (~207 tokens)

Search one regulation

Search held regulation text. Returns pinpoints and excerpts, not summaries. Requires regulation id (e.g. eu-ai-act) and query string. limit, detail (compact|full) and max_chars bound the response. Then read_unit on the best pinpoints; verify_citation if checking someone else's cite.

Input parameters:

- `as_of`: Optional date YYYY-MM-DD: answer with the wording in force on that date (default today). Amended provisions say which act gave them their wording
- `detail`: compact (default: ~400-char excerpt around the match) | full (whole unit text)
- `kinds`: Optional filter: recital, article, paragraph, annex, section
- `limit`: Most rows to return (default 10 on searches, max 50)
- `max_chars`: Cap on the response size in characters (default 8000)
- `query`: Search terms in English (required)
- `regulation`: Regulation id from list_regulations (required)

### `search_regulations` (~244 tokens)

Search all regulations

Search all loaded regulation modules in one call, ranked by relevance across them. Use when the question names more than one act or you do not know which act holds the answer. limit, detail (compact|full) and max_chars bound the response; per_regulation_min gives each act a share of the page. Each hit carries its regulation id — then read_unit per regulation.

Input parameters:

- `as_of`: Optional date YYYY-MM-DD: answer with the wording in force on that date (default today). Amended provisions say which act gave them their wording
- `detail`: compact (default: ~400-char excerpt around the match) | full (whole unit text)
- `kinds`: Optional filter: recital, article, paragraph, annex, section
- `limit`: Most rows to return (default 10 on searches, max 50)
- `max_chars`: Cap on the response size in characters (default 8000)
- `per_regulation_min`: Optional: at least this many rows from each act with matches
- `query`: Search terms in English (required)
- `regulations`: Optional subset of regulation ids; default = all loaded corpus

### `lookup_obligations` (~552 tokens)

Look up obligations by role

Articles whose official title names a role as an obligation addressee (e.g. role='deployer', optional system_class='high-risk'). Heading index, not annotated metadata — then read_unit the article. role accepts the word a title uses (deployer, provider, importer, operator, authorised representative, controller, processor, joint controller, data subject, or supervisory authority on gdpr). notified body on eu-ai-act returns Arts 34/45. Read also_named (Arts 31 through 38) for related titles without 'obligation'. When result_count is 0, read also_named before concluding none match (e.g. Arts 22/54 on eu-ai-act authorised representative; Arts 63/94 on eu-ai-act operator; Arts 29/39 on eu-ai-act conformity assessment body; Arts 76/77/85 on eu-ai-act market surveillance authority; Art 100 on eu-ai-act union institution; Arts 53/55/88 on eu-ai-act GPAI provider / general-purpose AI provider / provider of general-purpose AI models; Arts 13/14/21/22 on cra manufacturer / manufacturer of products with digital elements; when also_named is empty read heading_note and use search_regulation; Arts 24/26/27/29/79 on gdpr controller; Arts 27/28/29/79 on gdpr processor; Art 26 on gdpr joint controller; Arts 12/13/14/15/34/80 on gdpr data subject; Arts 31/33/51/53/54/56/60/62/77/78 on gdpr supervisory authority; Art 32 on nis2 essential entity; Arts 3/33/34 on nis2 important entity; Arts 23/31 on dora provider; Art 31 on dora ict third-party service provider; on dora financial entity or operator also_named is empty — read heading_note and use search_regulation for body mentions (Arts 28/30 for ICT third-party context); Art 18 on cra authorised representative). Then read_unit each article — the index is not a complete duty set.

Input parameters:

- `limit`: Most rows to return (default 10 on searches, max 50)
- `max_chars`: Cap on the response size in characters (default 8000)
- `query`: Alias for role when agents pass search-style query= instead of role=
- `regulation`: Regulation id from list_regulations (required)
- `role`: Addressee in the article title, e.g. deployer
- `system_class`: Optional class in the same title, e.g. high-risk

### `verify_citation` (~191 tokens)

Verify a citation

Verify a citation someone else produced — does the pinpoint exist in held text, and optionally does the quote appear. Pass the cite as written (e.g. 'Article 6(1) EU AI Act') plus optional quote=. Then read_unit for full text. regulation= disambiguates when the cite omits the act name; returns regulation_mismatch when the cite embeds YYYY/NNNN for a different act.

Input parameters:

- `as_of`: Optional date YYYY-MM-DD: answer with the wording in force on that date (default today). Amended provisions say which act gave them their wording
- `citation`: Citation as written, e.g. Article 6(1) EU AI Act
- `cite`: Alias for citation when agents pass cite= instead of citation=
- `quote`: Optional sentence to check against held text
- `regulation`: Regulation id when the cite string alone is ambiguous

### `read_unit` (~259 tokens)

Read a provision

Read one citable unit by kind and number or label. Articles return aggregated paragraph text. Paragraphs repeat across articles — pass article= (e.g. 6 or '6') to disambiguate. number, label and article accept JSON numbers or strings. read_unit also takes a result row's pinpoint verbatim: pinpoint='Article 6(1)' resolves kind and number for you. Then verify_citation if checking someone else's pinpoint.

Input parameters:

- `article`: Required for paragraphs: parent article number (e.g. 6 or '6')
- `as_of`: Optional date YYYY-MM-DD: answer with the wording in force on that date (default today). Amended provisions say which act gave them their wording
- `citation`: Alias for pinpoint
- `cite`: Alias for pinpoint
- `kind`: recital | article | paragraph | annex | section
- `label`: Exact label e.g. (47) or 1. (string or JSON number)
- `number`: Unit number within kind (string or JSON number)
- `pinpoint`: A pinpoint string from a result row, e.g. 'Article 6(1)' — read instead of kind/number
- `regulation`: Regulation id (required)

### `list_workflows` (~176 tokens)

List playbooks and jobs

Playbook library for compliance-officer workflows — high-risk triage, DORA ICT review, cross-reg scans, vendor questionnaires. Read a playbook before improvising a process. Pass trial_id from connect to list your own private drafts beside the shipped library. Then call get_workflow with workflow_id from this list.

Input parameters:

- `limit`: Most rows to return (default 10 on searches, max 50)
- `max_chars`: Cap on the response size in characters (default 8000)
- `session`: The `session` value the sign-in returned. Pass it on every call in this conversation, so the sign-in survives however this client handles connections; omit it when the user connected with Sign in (OA…
- `trial_id`: Optional trial_id from connect for this client private drafts

### `get_workflow` (~154 tokens)

Open a playbook or job

Full step-by-step playbook for one workflow id from list_workflows. Follow the named tools (search_regulation, read_unit, verify_citation, …) rather than summarising the playbook.

Input parameters:

- `id`: Alias for workflow_id
- `name`: Alias for workflow_id
- `session`: The `session` value the sign-in returned. Pass it on every call in this conversation, so the sign-in survives however this client handles connections; omit it when the user connected with Sign in (OA…
- `trial_id`: Optional trial_id from connect to read your private draft
- `workflow_id`: Id from list_workflows, e.g. high-risk-triage

### `save_workflow` (~172 tokens)

Save a private playbook

Save or update one private compliance playbook for this keyless trial. It stays inside this trial_id; call publish_workflow only to mark it ready here, never to share it with another user.

Input parameters:

- `body`: The steps and tool calls for this private playbook
- `session`: The `session` value the sign-in returned. Pass it on every call in this conversation, so the sign-in survives however this client handles connections; omit it when the user connected with Sign in (OA…
- `summary`: One sentence saying when this private playbook is useful
- `title`: Plain title for this private playbook
- `trial_id`: trial_id returned by connect()
- `workflow_id`: Lowercase id for this private workflow, e.g. vendor-ai-review

### `publish_workflow` (~132 tokens)

Publish a private playbook

Mark one of this trial_id private playbooks ready or draft. Publishing is private state only; it never adds content to the shipped library or another trial.

Input parameters:

- `published` (boolean): true marks it ready in this trial; false returns it to draft
- `session`: The `session` value the sign-in returned. Pass it on every call in this conversation, so the sign-in survives however this client handles connections; omit it when the user connected with Sign in (OA…
- `trial_id`: trial_id returned by connect()
- `workflow_id`: Id of your private workflow

### `delete_workflow` (~107 tokens)

Delete a private playbook

Delete one private workflow for this trial_id. It cannot delete a shipped playbook or a draft owned by another trial.

Input parameters:

- `session`: The `session` value the sign-in returned. Pass it on every call in this conversation, so the sign-in survives however this client handles connections; omit it when the user connected with Sign in (OA…
- `trial_id`: trial_id returned by connect()
- `workflow_id`: Id of your private workflow to delete

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/com-rekvira-rekvira/mcp#diagnostics

## Score history

- 2026-09-28: 69
- 2026-09-27: 68
- 2026-09-26: 68
- 2026-09-25: 67
- 2026-09-24: 64
- 2026-09-23: 33

## Common questions

### What is the Rekvira: EU regulation pinpoints for compliance AI MCP server?

Rekvira: EU regulation pinpoints for compliance AI is an MCP server listed in the public MCP registry as com.rekvira/rekvira. Official EU regulation text with article and recital pinpoints over MCP. Keyless trial. This page covers its hosted endpoint (https://mcp.rekvira.com/mcp).

### Is the Rekvira: EU regulation pinpoints for compliance AI MCP server safe to use?

Rekvira: EU regulation pinpoints for compliance AI scores 69 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Rekvira: EU regulation pinpoints for compliance AI MCP server expose?

Rekvira: EU regulation pinpoints for compliance AI exposes 19 tools: connect, connect_verify, rekvira_account, start_here, whoami, and 14 more. Their descriptions and schemas cost roughly 4,055 tokens of context every time the server is loaded.

### Does the Rekvira: EU regulation pinpoints for compliance AI MCP server require authentication?

No. We connected to Rekvira: EU regulation pinpoints for compliance AI without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the Rekvira: EU regulation pinpoints for compliance AI MCP server still maintained?

Rekvira: EU regulation pinpoints for compliance AI is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://mcp.rekvira.com/mcp
- Website: https://rekvira.com/
- Changelog RSS feed: https://verifymcp.io/servers/com-rekvira-rekvira/mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/com-rekvira-rekvira/mcp.json
- HTML version of this page: https://verifymcp.io/servers/com-rekvira-rekvira/mcp
