Ship24 Tracking
REMOTE · API.SHIP24.COM · SCANNED SEP 22
Track parcels across 2,500+ carriers and 3PLs: live delivery status, event history, carrier lookup.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security71
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, but the challenge carries no valid RFC 9728 metadata, so a client cannot discover where to get a token. See how to fix → View diagnostics → Fail
- HTTPS enforcement could not be verified: the plaintext port answered with HTTP 400, which proves neither a plaintext path nor enforcement. View diagnostics → Unverified
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability69
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1996 tokens (~166/item across 12 items; 12 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage92
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 73% of tool parameters carry a description.Partial
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 12 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 13 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the Ship24 Tracking MCP server?
Ship24 Tracking is a hosted endpoint at https://api.ship24.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · api.ship24.com
claude mcp add --transport http com-ship24-tracking-mcp 'https://api.ship24.com/mcp'
{
"mcpServers": {
"com-ship24-tracking-mcp": {
"url": "https://api.ship24.com/mcp"
}
}
} {
"servers": {
"com-ship24-tracking-mcp": {
"type": "http",
"url": "https://api.ship24.com/mcp"
}
}
} [mcp_servers.com-ship24-tracking-mcp] url = "https://api.ship24.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-ship24-tracking-mcp": {
"type": "remote",
"url": "https://api.ship24.com/mcp",
"enabled": true
}
}
} openclaw mcp add com-ship24-tracking-mcp --url 'https://api.ship24.com/mcp' --transport streamable-http
mcp_servers:
com-ship24-tracking-mcp:
url: "https://api.ship24.com/mcp" {
"McpServers": {
"com-ship24-tracking-mcp": {
"Transport": "http",
"Url": "https://api.ship24.com/mcp"
}
}
} assistant mcp add com-ship24-tracking-mcp -t streamable-http -u 'https://api.ship24.com/mcp'
{
"mcpServers": {
"com-ship24-tracking-mcp": {
"type": "http",
"url": "https://api.ship24.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 18 Sept 26 0
- Stability: 0.97 → pass security
- 17 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 15 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.
- 13 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 73 to 77. That category is still filling its 30-day observation window: 22 days of observed history at the previous scan, 23 at this one. The score rises as the window fills, whether or not the server changes.
- 8 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 63 to 67. That category is still filling its 30-day observation window: 19 days of observed history at the previous scan, 20 at this one. The score rises as the window fills, whether or not the server changes.
- 6 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.
- 4 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 50 to 53. That category is still filling its 30-day observation window: 15 days of observed history at the previous scan, 16 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 22 Sept 2026 · Probed https://api.ship24.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=*.ship24.com | CN=Amazon RSA 2048 M01,O=Amazon,C=US | 12 Sept 2026 | 28 Mar 2027 | RSA 2048 | SHA256-RSA | 6b02ed676c4422d30f36ec14267aecf |
| SANs: *.ship24.com | ||||||
| CN=Amazon RSA 2048 M01,O=Amazon,C=US (CA) | CN=Amazon Root CA 1,O=Amazon,C=US | 23 Aug 2022 | 23 Aug 2030 | RSA 2048 | SHA256-RSA | 77312380b9d6688a33b1ed9bf9ccda68e0e0f |
| CN=Amazon Root CA 1,O=Amazon,C=US (CA) | CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies\, Inc.,L=Scottsdale,ST=Arizona,C=US | 25 May 2015 | 31 Dec 2037 | RSA 2048 | SHA256-RSA | 67f944a2a27cdf3fac2ae2b01f908eeb9c4c6 |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of api.ship24.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| ship24.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Challenged, unverified
The endpoint asked for a token, but we could not retrieve and validate the RFC 9728 metadata that tells a client how to obtain one.
| Result | Challenged, unverified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
Protected resource metadata
| Retrieved | No |
|---|---|
| Problem | no_resource_metadata |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://api.ship24.com/mcp | Verified | 200 | |
| http (plaintext) | http://api.ship24.com/mcp | Inconclusive | 400 |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
bulk_create_trackers Bulk Create Trackers ~93
Creates up to 100 trackers in one request. Each tracker object accepts the same fields as create_tracker — see that tool for field details. Not fully idempotent: retrying a failed bulk request may partially create trackers. Returns counts of created, ignored (duplicate), and failed trackers plus per-item details.
| Name | Type | Req | Description |
|---|---|---|---|
| trackers | array | yes | Array of tracker objects to create (minimum 1, maximum 100). |
| Name | Type | Req | Description |
|---|---|---|---|
| data | – | – | Per-item outcome, in submission order. Null when status is error. |
| error | – | – | Request-level error. Null unless the whole request failed. |
| status | – | – | success (all created or already existing) | partial (successes and errors) | error (all failed, or a request-level error). |
| summary | – | – | Per-request counts. Null when status is error. |
No examples provided.
create_tracker Create Tracker ~301
Creates a new tracker for a tracking number. Use when the user explicitly wants ongoing monitoring or webhook updates; results arrive asynchronously — for immediate results use track or search_tracking. Idempotent: same parameters reuse the existing tracker; any field change creates a new one. Subscribes to webhook updates if configured. Returns the created tracker including its Ship24 trackerId.
| Name | Type | Req | Description |
|---|---|---|---|
| clientTrackerId | string | – | Your unique identifier for this tracker, for lookup via searchBy=clientTrackerId. |
| courierCode | array | – | Courier codes for this tracker (max 3). Use get_couriers for valid codes. IMPORTANT: Check each courier's requiredFields array — any listed fields should be provided, otherwise the courier may not re… |
| courierName | string | – | Courier name (informational). |
| destinationCountryCode | string | – | Destination country code (ISO alpha-2). |
| destinationPostCode | string | – | Destination postal/ZIP code. |
| orderNumber | string | – | Associated order number. |
| originCountryCode | string | – | Origin country code (ISO alpha-2, e.g. US). |
| settings | object | – | – |
| shipmentReference | string | – | Internal reference for the shipment. |
| shippingDate | string | – | Date the package was shipped (YYYY-MM-DD or ISO 8601). |
| trackingNumber | string | yes | Tracking number to monitor. |
| trackingUrl | string | – | Courier tracking URL. |
| Name | Type | Req | Description |
|---|---|---|---|
| tracker | – | yes | The tracker. |
No examples provided.
download_webhook_history Download Webhook History ~158
Retrieves the full webhook push history for a tracker. Returns metadata (trackingNumber, trackerId, clientTrackerId, webhookUrl, lastSuccessfulPushAt, lastFailedPushAt) and a list of all sent or failed pushes with status, pushTimestamp, requestBody, responseBody, responseHeaders, and responseStatusCode. Pending (unsent) webhooks are excluded. Results are sorted newest first. Rate-limited to 1 request/second per tracker.
| Name | Type | Req | Description |
|---|---|---|---|
| searchBy | string | – | How to interpret trackerId: default is Ship24 trackerId, use "clientTrackerId" for your own reference. |
| trackerId | string | yes | Ship24 trackerId, or clientTrackerId when searchBy="clientTrackerId". |
| Name | Type | Req | Description |
|---|---|---|---|
| metadata | – | – | Tracker and webhook endpoint context. |
| webhooks | – | yes | Sent and failed pushes, newest first. Pending webhooks are excluded. |
No examples provided.
get_couriers Get Couriers ~86
Returns the list of all couriers supported by Ship24, including their unique courier codes, human-readable names, and any special tracking requirements. Use this tool to discover valid courierCode values before creating or updating trackers, or to help identify which courier handles a particular tracking number format. Note: this endpoint has a rate limit of 1 request/second; cache results when possible.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| couriers | – | yes | All couriers supported by Ship24. |
No examples provided.
get_tracker Get Tracker ~95
Retrieves a single tracker by trackerId (or clientTrackerId when searchBy is set). Returns tracker metadata only — use get_tracking_results for events and status.
| Name | Type | Req | Description |
|---|---|---|---|
| searchBy | string | – | How to interpret trackerId: default is Ship24 trackerId, use "clientTrackerId" for your own reference. |
| trackerId | string | yes | Ship24 trackerId, or clientTrackerId when searchBy="clientTrackerId". |
| Name | Type | Req | Description |
|---|---|---|---|
| tracker | – | yes | The tracker. |
No examples provided.
get_tracking_results Get Tracking Results ~133
Returns full tracking results for an existing tracker: metadata, shipment status, all events in order, and delivery statistics. Primary tool for "where is my package?" when you have a trackerId. statusMilestone values: pending | info_received | in_transit | out_for_delivery | failed_attempt | available_for_pickup | delivered | exception.
| Name | Type | Req | Description |
|---|---|---|---|
| searchBy | string | – | How to interpret trackerId: default is Ship24 trackerId, use "clientTrackerId" for your own reference. |
| trackerId | string | yes | Ship24 trackerId, or clientTrackerId when searchBy="clientTrackerId". |
| Name | Type | Req | Description |
|---|---|---|---|
| trackings | – | yes | One entry per matched tracker or shipment. |
No examples provided.
list_trackers List Trackers ~95
Returns a paginated list of all trackers. Supports offset (page/limit) or cursor-based pagination. Filter by subscription status with isSubscribed.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Results per page (max 500). |
| page | integer | – | Page number (1-indexed). |
| sort | – | – | Sort order by createdAt. 1 = ascending (oldest first, default), -1 = descending (newest first). |
| Name | Type | Req | Description |
|---|---|---|---|
| trackers | – | yes | Trackers on the requested page. |
No examples provided.
resend_webhooks Resend Webhooks ~131
Replays all webhook events for a tracker. Use when your endpoint missed or failed to process previous notifications. Terminates any in-flight webhook delivery for this tracker and invalidates its existing webhook payload records before regenerating and resending them — do not call repeatedly in quick succession. Rate-limited to 1 request/second per tracker.
| Name | Type | Req | Description |
|---|---|---|---|
| searchBy | string | – | How to interpret trackerId: default is Ship24 trackerId, use "clientTrackerId" for your own reference. |
| trackerId | string | yes | Ship24 trackerId, or clientTrackerId when searchBy="clientTrackerId". |
| Name | Type | Req | Description |
|---|---|---|---|
| summary | – | yes | Outcome of the webhook replay. |
No examples provided.
search_tracking Search Tracking ~234
Default tool for one-off tracking lookups ('track X', 'where is my package'). Synchronous per-call plan endpoint: returns full results (status, events, statistics) immediately and creates NO tracker on the account. Billed per call. Requires an active per-call plan — if it fails with no_active_subscription, use the track tool instead.
| Name | Type | Req | Description |
|---|---|---|---|
| courierCode | array | – | Courier codes for this tracker (max 3). Use get_couriers for valid codes. IMPORTANT: Check each courier's requiredFields array — any listed fields should be provided, otherwise the courier may not re… |
| destinationCountryCode | string | – | Destination country code (ISO alpha-2). |
| destinationPostCode | string | – | Destination postal/ZIP code. |
| originCountryCode | string | – | Origin country code (ISO alpha-2). |
| shippingDate | string | – | Date the package was shipped (YYYY-MM-DD or ISO 8601). |
| trackingNumber | string | yes | Tracking number to look up. 5-50 alphanumeric characters, hyphens, underscores, dots, or slashes. |
| Name | Type | Req | Description |
|---|---|---|---|
| trackings | – | yes | One entry per matched tracker or shipment. |
No examples provided.
search_tracking_by_number Search by Tracking Number ~117
Returns existing tracking results for a raw tracking number across trackers already on the account, without needing a trackerId. Free read: never creates a tracker and never triggers a new crawl. Responds 404 tracker_not_found if no tracker exists for that number — in that case use search_tracking (per-call) or track (per-shipment). Use this first when a tracker may already exist.
| Name | Type | Req | Description |
|---|---|---|---|
| trackingNumber | string | yes | The raw shipment tracking number to search for (e.g. 1Z999AA10123456784). |
| Name | Type | Req | Description |
|---|---|---|---|
| trackings | – | yes | One entry per matched tracker or shipment. |
No examples provided.
track Track Shipment ~242
Creates a persistent tracker on the account AND returns full tracking results synchronously in one call (per-shipment plan). Idempotent: same payload reuses the existing tracker. Prefer search_tracking for one-off lookups when the per-call plan is available. If the returned shipment is still pending with no events, call get_tracking_results once with the returned trackerId before answering. Accepts the same fields as create_tracker — see that tool for field details.
| Name | Type | Req | Description |
|---|---|---|---|
| clientTrackerId | string | – | – |
| courierCode | array | – | Courier codes for this tracker (max 3). Use get_couriers for valid codes. IMPORTANT: Check each courier's requiredFields array — any listed fields should be provided, otherwise the courier may not re… |
| courierName | string | – | – |
| destinationCountryCode | string | – | – |
| destinationPostCode | string | – | – |
| orderNumber | string | – | – |
| originCountryCode | string | – | – |
| settings | object | – | – |
| shipmentReference | string | – | – |
| shippingDate | string | – | – |
| trackingNumber | string | yes | – |
| trackingUrl | string | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| trackings | – | yes | One entry per matched tracker or shipment. |
No examples provided.
update_tracker Update Tracker ~251
Partially updates a tracker (PATCH). Only provided fields are changed. Common uses: toggling isSubscribed, correcting destination details, or setting a clientTrackerId.
| Name | Type | Req | Description |
|---|---|---|---|
| courierCode | array | – | Courier codes for this tracker (max 3). Use get_couriers for valid codes. IMPORTANT: Check each courier's requiredFields array — any listed fields should be provided, otherwise the courier may not re… |
| destinationCountryCode | string | – | Destination country code (ISO alpha-2). Immutable once tracking data exists. |
| destinationPostCode | string | – | – |
| isSubscribed | boolean | – | true to subscribe to webhooks, false to unsubscribe. |
| originCountryCode | string | – | Origin country code (ISO alpha-2). Immutable once tracking data exists. |
| searchBy | string | – | How to interpret trackerId: default is Ship24 trackerId, use "clientTrackerId" for your own reference. |
| settings | object | – | – |
| shippingDate | string | – | Ship date (YYYY-MM-DD or ISO 8601). Immutable once tracking data exists. |
| trackerId | string | yes | The tracker to update (Ship24 trackerId or clientTrackerId). |
| Name | Type | Req | Description |
|---|---|---|---|
| tracker | – | yes | The tracker. |
No examples provided.
What is the Ship24 Tracking MCP server?
Ship24 Tracking is an MCP server listed in the public MCP registry as com.ship24/tracking-mcp. Track parcels across 2,500+ carriers and 3PLs: live delivery status, event history, carrier lookup. This page covers its hosted endpoint (https://api.ship24.com/mcp).
Is the Ship24 Tracking MCP server safe to use?
Ship24 Tracking scores 82 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Ship24 Tracking MCP server expose?
Ship24 Tracking exposes 12 tools: create_tracker, list_trackers, bulk_create_trackers, track, get_tracker, and 7 more. Their descriptions and schemas cost roughly 1,936 tokens of context every time the server is loaded.
Does the Ship24 Tracking MCP server require authentication?
Yes. Ship24 Tracking asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the Ship24 Tracking MCP server still maintained?
Ship24 Tracking is still listed as active in the MCP registry. We last reached this channel on 22 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.