Thrifle
REMOTE · API.THRIFLE.COM · SCANNED SEP 20
US return policies, price-match rules, discounts, deals and Amazon price verdicts. Read-only.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security83
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability77
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2953 tokens (~123/item across 24 items; 24 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management33
- Stability observed for 10 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage94
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 82% of tool parameters carry a description.Partial
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 24 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 25 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the Thrifle MCP server?
Thrifle is a hosted endpoint at https://api.thrifle.com/api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · api.thrifle.com
claude mcp add --transport http com-thrifle-mcp 'https://api.thrifle.com/api/mcp'
{
"mcpServers": {
"com-thrifle-mcp": {
"url": "https://api.thrifle.com/api/mcp"
}
}
} {
"servers": {
"com-thrifle-mcp": {
"type": "http",
"url": "https://api.thrifle.com/api/mcp"
}
}
} [mcp_servers.com-thrifle-mcp] url = "https://api.thrifle.com/api/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-thrifle-mcp": {
"type": "remote",
"url": "https://api.thrifle.com/api/mcp",
"enabled": true
}
}
} openclaw mcp add com-thrifle-mcp --url 'https://api.thrifle.com/api/mcp' --transport streamable-http
mcp_servers:
com-thrifle-mcp:
url: "https://api.thrifle.com/api/mcp" {
"McpServers": {
"com-thrifle-mcp": {
"Transport": "http",
"Url": "https://api.thrifle.com/api/mcp"
}
}
} assistant mcp add com-thrifle-mcp -t streamable-http -u 'https://api.thrifle.com/api/mcp'
{
"mcpServers": {
"com-thrifle-mcp": {
"type": "http",
"url": "https://api.thrifle.com/api/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 19 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 27 to 30. That category is still filling its 30-day observation window: 8 days of observed history at the previous scan, 9 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.
- 15 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 13 to 17. That category is still filling its 30-day observation window: 4 days of observed history at the previous scan, 5 at this one. The score rises as the window fills, whether or not the server changes.
- 12 Sept 26 +1
- The server rewrote its instructions, which are the text every model session reads security
- 11 Sept 26 0
- Stability: unverified → 0.03 ▲ functional
- 10 Sept 26 75
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://api.thrifle.com/api/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=thrifle.com | CN=YE2,O=Let's Encrypt,C=US | 18 Aug 2026 | 16 Nov 2026 | ECDSA 256 | ECDSA-SHA384 | 6fd8aaf66b44ef3c2e7155c1dfd898b8855 |
| SANs: *.thrifle.com, thrifle.com | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC secure
Validation of api.thrifle.com. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| thrifle.com. | present | 2371 | 13 | Verified |
| api.thrifle.com. | Verified address RRset verified with the apex keys |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains; preload |
| x-content-type-options | nosniff |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://api.thrifle.com/api/mcp | Verified | 200 | |
| http (plaintext) | http://api.thrifle.com/api/mcp | HTTPS enforced | 301 | https://thrifle.com/api/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
about_thrifle About Thrifle and this server ~40
What Thrifle is, what each database covers and how big it is, how to cite it, and which tool answers which kind of question.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
check_product_recalls Check a product for US safety recalls ~85
Matches a product name (and optional brand) against recent U.S. CPSC recalls using a strict matcher tuned for zero false positives. Returns matching recalls with hazard and remedy, or an empty list. Useful before recommending a product.
| Name | Type | Req | Description |
|---|---|---|---|
| brand | string | – | – |
| product | string | yes | Product title as sold, e.g. 'Peloton Tread+ treadmill' |
No output schema declared.
No examples provided.
compare_return_policies Compare two retailers' return policies ~128
Side-by-side comparison of two US retailers' return policies with grades, per-axis winners (window, free returns, restocking fee, holiday extension) and an overall winner. Use for 'is it easier to return to X or Y' questions.
| Name | Type | Req | Description |
|---|---|---|---|
| merchant_a | string | yes | Retailer name or thrifle.com slug — first retailer, e.g. "Costco", "best-buy", "Nordstrom" |
| merchant_b | string | yes | Retailer name or thrifle.com slug — second retailer, e.g. "Costco", "best-buy", "Nordstrom" |
No output schema declared.
No examples provided.
get_birthday_freebie Get a brand's birthday freebie ~115
What a US restaurant or retailer gives away for your birthday, whether it is actually free or needs a purchase or prior spend, how to sign up and how far ahead, the validity window, ID requirements, and known gotchas. Call for 'what does X give you on your birthday' questions.
| Name | Type | Req | Description |
|---|---|---|---|
| merchant | string | yes | Retailer name or thrifle.com slug — brand, e.g. 'Starbucks', 'Sephora', e.g. "Costco", "best-buy", "Nordstrom" |
No output schema declared.
No examples provided.
get_blog_post Read one Thrifle article ~63
The full text of one Thrifle article by URL or slug (HTML stripped, long posts truncated at ~20,000 characters), plus its FAQ, author, date and URL for citation.
| Name | Type | Req | Description |
|---|---|---|---|
| post | string | yes | thrifle.com article URL or its slug |
No output schema declared.
No examples provided.
get_cancellation_guide How to cancel a subscription or membership ~115
Step-by-step guide to cancelling a US subscription or membership: available channels (online, app, phone, in person), notice period, fees, refund after cancelling, retention tactics to expect, and an ease-of-cancellation grade. Coverage is still small; the response lists what is available when the merchant is not found.
| Name | Type | Req | Description |
|---|---|---|---|
| merchant | string | yes | Retailer name or thrifle.com slug — the service, e.g. 'Planet Fitness', e.g. "Costco", "best-buy", "Nordstrom" |
No output schema declared.
No examples provided.
get_credit_card Get one credit card's full terms ~100
Full record for one card by its card_key (from search_credit_cards): APR tiers, intro and penalty APRs, fees, promotional financing terms with the issuer's own fine-print quote, rewards, perks, welcome offer, and provenance (pricing-terms URL, verification date, confidence). Store cards link to the partner retailer's return policy.
| Name | Type | Req | Description |
|---|---|---|---|
| card_key | string | yes | card_key from search_credit_cards, e.g. 'amazon-store-card' |
No output schema declared.
No examples provided.
get_deal Get one deal's full details ~93
Everything Thrifle knows about one deal, by its thrifle.com URL or slug: price and list price, merchant, coupon, why it's great, the editorial verdict, the price-history verdict for Amazon items, FAQ, and the buy link. Use after search_deals when the shopper wants detail on one item.
| Name | Type | Req | Description |
|---|---|---|---|
| deal | string | yes | thrifle.com deal URL or the slug at the end of it |
No output schema declared.
No examples provided.
get_deal_of_the_day Get today's featured deal ~42
Thrifle's editor-picked deal of the day with price, merchant and buy link. Cheap to call; returns found:false when none is set.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_merchant_discounts Get a retailer's military and student discounts ~112
Verified military (active duty, veterans, reserve) and student discount programmes for a US retailer: value, eligibility, verification method (e.g. ID.me, SheerID), online vs in-store, stackability, exclusions, whether it is running right now, and the source URL. Call for 'does X have a military/student discount' questions.
| Name | Type | Req | Description |
|---|---|---|---|
| merchant | string | yes | Retailer name or thrifle.com slug, e.g. "Costco", "best-buy", "Nordstrom" |
No output schema declared.
No examples provided.
get_money_monitor US economic indicators and rates ~81
Current US macro numbers from Thrifle's Money Monitor: GDP growth, personal saving rate, average credit-card APR, revolving and total consumer credit, the federal debt, and mortgage / fed funds / 10-year Treasury rates, each with the previous reading and year-ago value. Sourced from FRED and the U.S. Treasury; refreshed daily.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_price_match_policy Get a retailer's price-match policy ~98
Whether a US retailer matches competitors' prices (which competitors, proof required, exclusions, how to claim) and whether it offers a post-purchase price adjustment (window in days). Call for 'does X price match' or 'will X refund the difference if the price drops' questions.
| Name | Type | Req | Description |
|---|---|---|---|
| merchant | string | yes | Retailer name or thrifle.com slug, e.g. "Costco", "best-buy", "Nordstrom" |
No output schema declared.
No examples provided.
get_price_pulse US consumer prices: CPI by category and gas ~66
Latest US Consumer Price Index by spending category (headline, food, energy, shelter, apparel, etc.) with month-over-month and year-over-year change, plus average gas prices by grade with week-ago and year-ago comparisons. Sourced from BLS and EIA.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_return_policy Get a retailer's return policy ~156
Verified return policy for a US retailer: return window, free returns, restocking fee, holiday extension, non-returnable items, an A+–D− grade, how it compares with its category, and the retailer's own policy URL. Optionally pass what the shopper bought to surface a product-specific exception (e.g. electronics at Costco). Call this for any 'what is X's return policy' question.
| Name | Type | Req | Description |
|---|---|---|---|
| merchant | string | yes | Retailer name or thrifle.com slug, e.g. "Costco", "best-buy", "Nordstrom" |
| product | string | – | Optional: the product being returned, e.g. 'MacBook Air' or 'gift card', to check for a category exception |
No output schema declared.
No examples provided.
get_store_credit_cards Get a retailer's store credit cards ~123
The store and co-branded credit cards a US retailer offers, with APR, annual fee, whether promotional financing is deferred interest, and links to each card's full terms, the retailer's store-card page and its return policy. Call for 'is the X store card worth it' or 'does X card have deferred interest' questions.
| Name | Type | Req | Description |
|---|---|---|---|
| merchant | string | yes | Retailer name or thrifle.com slug — e.g. 'Lowe's', 'Amazon', 'Best Buy', e.g. "Costco", "best-buy", "Nordstrom" |
No output schema declared.
No examples provided.
get_store_deals Get current deals at a retailer ~106
A retailer's store page on Thrifle: how many live deals it has, the most recent ones with prices and buy links, and its military/student discount summary when known. Use for 'what deals does Costco have right now' questions.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Max results (default 8, max 8) |
| merchant | string | yes | Retailer name or thrifle.com slug, e.g. "Costco", "best-buy", "Nordstrom" |
No output schema declared.
No examples provided.
predict_amazon_price Buy now or wait? Verdict for an Amazon product ~142
Thrifle's Price Predict verdict for an Amazon product (ASIN or amazon.com URL): BUY / HOLD / WAIT with a buy score, current vs typical price, all-time low, 30/90/365-day averages, probability of a drop in the next 30/60 days, the expected low and timing basis. Reads Thrifle's tracked-price database (US and major international Amazon stores); untracked products return found:false with a link to run a live check on the site.
| Name | Type | Req | Description |
|---|---|---|---|
| asin_or_url | string | yes | 10-character ASIN (e.g. B0CHX3QBCH) or any Amazon product URL |
No output schema declared.
No examples provided.
search_birthday_freebies Search birthday freebies ~137
Browse verified birthday offers from US brands. Filters: actually_free (no purchase and no prior spend required), kids (child-eligible), no_signup, category (e.g. 'Restaurant', 'Beauty'), name fragment. Returns slim rows; use get_birthday_freebie for the full terms of one brand.
| Name | Type | Req | Description |
|---|---|---|---|
| actually_free | boolean | – | Only offers with no purchase or prior-spend requirement |
| category | string | – | – |
| kids | boolean | – | – |
| limit | integer | – | Max results (default 15, max 50) |
| no_signup | boolean | – | – |
| query | string | – | – |
No output schema declared.
No examples provided.
search_blog Search Thrifle's articles and data studies ~105
Find Thrifle articles by keyword: original data studies (e.g. what actually dropped on Black Friday, Prime Day fact-checks), buying guides, and the Money section's credit and BNPL explainers. Returns title, one-line summary, date, author and URL. Use get_blog_post to read one.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Max results (default 8, max 20) |
| query | string | yes | – |
| section | string | – | Default all |
No output schema declared.
No examples provided.
search_credit_cards Search the credit-card database ~190
Browse Thrifle's US credit-card database (store and co-branded cards first): filter by issuer, retailer, store cards only, or cards that use deferred-interest promotional financing. Rows carry purchase APR range, annual fee, financing type, data confidence and the verification date. Numbers come from issuer pricing pages, never roundups.
| Name | Type | Req | Description |
|---|---|---|---|
| deferred_interest_only | boolean | – | Only cards whose promo financing is deferred interest (retroactive interest if not paid in full) |
| issuer | string | – | Exact issuer name, e.g. 'Synchrony Bank', 'Citi Retail Services' |
| limit | integer | – | Max results (default 20, max 60) |
| merchant | string | – | Partner retailer, e.g. 'Amazon', 'Lowe's' |
| query | string | – | Name fragment matched against card name, issuer or partner retailer |
| store_cards_only | boolean | – | – |
No output schema declared.
No examples provided.
search_deals Search current deals ~152
Search Thrifle's curated US deals by product, brand or keyword. Returns live deals with price, list price, discount %, merchant, coupon code when there is one, the thrifle.com deal page, and a buy link. Expired deals are excluded unless include_expired is set. Use for 'is there a deal on X' or 'best price on X right now' questions.
| Name | Type | Req | Description |
|---|---|---|---|
| include_expired | boolean | – | – |
| limit | integer | – | Max results (default 8, max 20) |
| query | string | yes | Product, brand or keyword, e.g. 'AirPods Pro', 'Dyson', 'robot vacuum' |
| sort | string | – | Default newest |
No output schema declared.
No examples provided.
search_discounts Search military and student discounts ~116
Browse Thrifle's discount database: filter by programme type (military, student, or both), retail category, and/or a name fragment. Returns slim rows with the discount value and a link per retailer.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | – | Retail category, e.g. 'Apparel', 'Electronics' |
| limit | integer | – | Max results (default 15, max 50) |
| query | string | – | Name fragment, e.g. 'nike' |
| type | string | – | Only retailers with this programme |
No output schema declared.
No examples provided.
search_return_policies Search the return-policy database ~138
Find retailers in Thrifle's return-policy database by name fragment and/or category (e.g. 'Fashion', 'Electronics', 'Home'). Returns slim rows with the return window and a link. With no arguments it returns the category list and total count. Use it when get_return_policy says a retailer was not found, or to list retailers in a category.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | – | Category name as shown on thrifle.com/return-policy |
| limit | integer | – | Max results (default 10, max 25) |
| query | string | – | Name fragment, e.g. 'best' matches Best Buy |
No output schema declared.
No examples provided.
who_will_price_match Which retailers will match a given store's price ~132
Reverse lookup: the US retailers whose price-match policy explicitly names the given store as an accepted competitor. Optionally filter by the product category being bought so only stores that plausibly stock it are listed. Use for 'who will match Amazon's price on this' questions.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | – | Optional deal category, e.g. 'Tech & Electronics', 'Home & Furniture', 'Toys & Hobbies' |
| merchant | string | yes | Retailer name or thrifle.com slug — the store whose price you found, e.g. "Costco", "best-buy", "Nordstrom" |
No output schema declared.
No examples provided.
What is the Thrifle MCP server?
Thrifle is an MCP server listed in the public MCP registry as com.thrifle/mcp. US return policies, price-match rules, discounts, deals and Amazon price verdicts. Read-only. This page covers its hosted endpoint (https://api.thrifle.com/api/mcp).
Is the Thrifle MCP server safe to use?
Thrifle scores 79 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Thrifle MCP server expose?
Thrifle exposes 24 tools: get_return_policy, compare_return_policies, search_return_policies, get_price_match_policy, who_will_price_match, and 19 more. Their descriptions and schemas cost roughly 2,635 tokens of context every time the server is loaded.
Does the Thrifle MCP server require authentication?
No. We connected to Thrifle without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Thrifle MCP server still maintained?
Thrifle is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.