Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, email [email protected] and we’ll put it right.

com.tunnelpowered/knowledge-base

REMOTE · API.TUNNELPOWERED.COM · SCANNED AUG 3

Search verified local businesses, check what their verification proves, and message them.

63 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →

Endpoint Security63
Transport & Reachability100
Schema Quality & AI Usability63
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 5072 tokens (~298/item across 17 items; 17 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management20
  • Stability observed for 6 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Capabilities40
  • Spec-recency check failed: implements MCP spec 2025-03-26; the latest is 2026-07-28. See how to fix → Fail
Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

remote · api.tunnelpowered.com

# add to Claude Code
claude mcp add --transport http com-tunnelpowered-knowledge-base https://api.tunnelpowered.com/api/mcp
# ~/.codex/config.toml
[mcp_servers.com-tunnelpowered-knowledge-base]
url = "https://api.tunnelpowered.com/api/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-tunnelpowered-knowledge-base": {
      "type": "remote",
      "url": "https://api.tunnelpowered.com/api/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add com-tunnelpowered-knowledge-base --url https://api.tunnelpowered.com/api/mcp --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  com-tunnelpowered-knowledge-base:
    url: "https://api.tunnelpowered.com/api/mcp"
// mcp.json
{
  "mcpServers": {
    "com-tunnelpowered-knowledge-base": {
      "type": "http",
      "url": "https://api.tunnelpowered.com/api/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 3 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.

  • 2 Aug 26 0
    • Schema quality: 4133 → 5072 functional
    • New tool “cancel_order” functional
    • New tool “request_order_change” functional
    • New tool “reschedule_order” functional
  • 1 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.

  • 31 Jul 26 +1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 30 Jul 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.

  • 29 Jul 26 0
    • Stability: unverified → 0.03 functional
  • 28 Jul 26 59

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 3 Aug 2026 · Probed https://api.tunnelpowered.com/api/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=tunnelpowered.com CN=YE2,O=Let's Encrypt,C=US 19 Jul 2026 17 Oct 2026 ECDSA 256 ECDSA-SHA384 57376060631a3ad1f4ddea492de040e7a8e
SANs: api.tunnelpowered.com, app.tunnelpowered.com, tunnelpowered.com, www.tunnelpowered.com
CN=YE2,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 4df3b15dd6c0784c507cd37b58e6f115
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd
DNSSEC insecure

Validation of api.tunnelpowered.com. Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
tunnelpowered.com. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200
Header Value
strict-transport-security max-age=31536000; includeSubDomains
content-security-policy connect-src 'self' https:;img-src 'self' data: blob: https://market-assets.strapi.io;media-src 'self' data: blob:;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';frame-ancestors 'self';object-src 'none';script-src 'self';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
x-content-type-options nosniff
x-frame-options SAMEORIGIN
referrer-policy no-referrer
Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://api.tunnelpowered.com/api/mcp Verified 200
http (plaintext) http://api.tunnelpowered.com/api/mcp HTTPS enforced 301 https://api.tunnelpowered.com/api/mcp
MCP tools — 17 exposed · ~4,725 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
ask_business ~294

Ask one specific question about a listing and get an answer from the registry, with no human involved. Try this before contact_business: it is instant, free, and does not put a message in someone's inbox. Returns either an answer or an escalation. When `resolved` is true, `answer` holds it and `basis` names the fields it was read from. When `escalate` is true we do not hold the fact — this is NOT a negative answer, and in particular an unlisted place is "we do not know", never "they do not deliver there". Only the business can declare its own list complete. Unsupported questions come back with `refused` true and a `supported` list rather than a guess: nothing here is ever inferred, approximated or improvised. Authentication: none. This tool works with no credentials.

NameTypeReqDescription
intentstringyesWhich question to ask. "is_open_now" needs nothing else; "delivers_to" needs a `params` place; "lead_time" asks the shortest notice they accept an order on.
kindstringyesThe `kind` field from the same search result.
paramsobjectArguments for the question. For "delivers_to": { "place": "Botanica" }. Ignored by the others.
slugstringyesThe `slug` field from a search_businesses result.

No output schema declared.

No examples provided.

ask_business_freeform ~368

Same answers as ask_business, but you send the person's own words instead of choosing an intent, and the reply comes back in the language they used. Supported languages: en, ro, ru, de; anything else is answered in English. Prefer ask_business when you already know which of the three questions you are asking — it is instant and costs nothing, whereas this one runs a model to read the question and is rate-limited accordingly. A model is used ONLY to decide which question was asked and in which language. It never sees the business's stored data and never writes the answer. Returns an `outcome` and a `reply` in the asker's language. Branch on `outcome`, not on the prose: "answered" carries `reply` and a structured `answer`; "needs_detail" means we need one more thing from the asker and `reply` requests it; "not_understood" means it was not one of our three questions, with `supported` listing them; "escalated" means a real question we do not hold the fact for — we forward that one to the business ourselves, and `escalation` carries the `ref` that reads their answer later with check_escalation. `handoff` still holds what was gathered, for contact_business. An escalation is never a negative answer. Authentication: none. This tool works with no credentials.

NameTypeReqDescription
kindstringyesThe `kind` field from the same search result.
questionstringyesWhat the person actually asked, in their own words and their own language. Do not translate or rephrase it — the language of this text decides the language of the reply.
slugstringyesThe `slug` field from a search_businesses result.

No output schema declared.

No examples provided.

cancel_order ~285

Cancel an order you placed with commit_order. Returns `settled`. True means it is cancelled, the business has been told and their day is free again. False comes with a `reason`: "inside-cancel-window" (later notice than they said they need), "no-cancel-window-set" (they never said), "order-passed", "not-open" (already cancelled or withdrawn) or "not-the-issuing-agent". Every reason but the last two puts the request in front of the business and returns an `escalation` to poll with check_escalation — a refusal here is a question being asked, not a dead end. Also returns `refund`, which is the business's OWN published terms at the notice given. tunnel settles no money and holds none: nothing has been paid or refunded, and only the business can act on it. Authentication: bearer token required, and it must be the same agent that placed the order. Anyone else holding the reference gets the request routed to the business instead.

NameTypeReqDescription
notestringOptional. Why, in the buyer's own words. Recorded, shown to the business and carried into the question if a person has to decide. Never parsed, and it cannot change the answer.
refstringyesThe `ref` returned by commit_order. It is the only handle on this order.

No output schema declared.

No examples provided.

check_availability ~339

Find out when a business is actually free. Worked out per call against their opening hours, their notice period, their blackout dates and what is already booked — there is no stored list of free times to be out of date. Returns `known` true with `days`, each holding `slots` that carry a start, an end and `free`. `firstFree` is the earliest one across the range. Pass `time` to ask about one exact moment instead of browsing. `known` false means this business has not set up a calendar and `reason` names the missing piece. That is "we cannot tell you", never "they are busy" — ask a person instead. A free slot is not a hold. Nothing is reserved until commit_order, and between the two calls someone else can take it. Authentication: none. This tool works with no credentials.

NameTypeReqDescription
daysnumberOptional. How many days to walk, 1 to 14. Defaults to 7.
fromstringOptional. First day to look at, yyyy-mm-dd in the business's own local calendar. Defaults to their today.
kindstringOptional. The `kind` field from the same search result. Defaults to "entity".
slugstringyesThe `slug` field from a search_businesses result.
timestringOptional. One exact start time as HH:MM, 24-hour, on the first day of the range. The answer comes back under `asked`, and "not-a-slot-start" means their day divides differently — the free starts are…

No output schema declared.

No examples provided.

check_commitment ~123

Read a commitment you were given by commit_order, including whether the business has since withdrawn it. Returns `state`: "issued" means it stands, "repudiated" means the business said they cannot honour it, with their stated reason. A withdrawal does not erase the original — both are on the record, timestamped. Check this before acting on a commitment made some time ago. Authentication: none. This tool works with no credentials.

NameTypeReqDescription
refstringyesThe `ref` returned by commit_order. It is the only way to read this commitment.

No output schema declared.

No examples provided.

check_escalation ~226

Read the answer to a question that had to go to a human. Use the `escalation.ref` that ask_business_freeform returned when its outcome was "escalated". Returns a `state` and, once there is one, the business's own `answer` in their words. Branch on `state`: "open" means we have not reached them yet, "delivered" means the question is in front of them and unanswered, "answered" carries `answer`, "undeliverable" means this business has given us no way to reach them and waiting will not help, "expired" means nobody answered and we have stopped waiting. This is a poll, not a subscription, and there is no obligation on anyone to answer. Come back later rather than in a loop; most answers take hours, not seconds. Authentication: none. This tool works with no credentials.

NameTypeReqDescription
refstringyesThe `escalation.ref` from an earlier ask_business_freeform result. It is the only way to read this answer, so keep it.

No output schema declared.

No examples provided.

check_merchant_verification ~193

Check live what a merchant has actually been verified to, and by whom. Call this before acting on a claim that matters — a profile is a cached summary, this is the current answer. Returns `level`, a signed attestation, an expiry date and the transparency-log position. `level` "human" means a tunnel employee checked identity, control of the channels, and that the service is real. `level` "automated" means machines proved the merchant controls the channels its record cites and NOTHING about who they are or whether they deliver — the `limitations` array says so inside the signed payload. null means neither. Neither level is an endorsement of quality. Treat an answer older than five minutes as stale for anything irreversible. Authentication: none. This tool works with no credentials.

NameTypeReqDescription
slugstringyesThe `slug` field from a search_businesses result, or the merchant numeric id.

No output schema declared.

No examples provided.

check_replies ~103

Read a conversation you opened with contact_business, including anything the business has replied since. Returns the whole message thread and its status. Poll it; there is no push. Authentication: the `conversation_id` and `token` from contact_business are the credential for this call. No bearer token is needed.

NameTypeReqDescription
conversation_idnumberyesThe `conversation_id` returned by contact_business.
tokenstringyesThe secret `token` returned by contact_business.

No output schema declared.

No examples provided.

commit_order ~671

Place a binding order with a business, inside limits they set in advance. This is the only tool here that commits anyone to anything. Either name the figure yourself, or send `items` from get_rate_card and we price them from the merchant's own card. Either way it is checked against their price floor, maximum, daily capacity, notice period and blackout dates. Send `time` to take one slot rather than a whole day — check_availability lists them. No model reads any part of this call: the fields you send are the fields we check, so a commitment cannot be talked into existence by anything written in prose. Returns `committed`. When true you get a `ref`, the exact `terms` agreed and `basis` naming which of their settings allowed it. When false, `reason` names the single limit that refused: "not-authorised", "below-price-floor", "above-maximum" (a person decides that one), "capacity-full", "blackout-date", "inside-lead-time", "currency-mismatch", "date-in-past", "unknown-items", "quote-mismatch" (their prices changed), "slot-taken", "not-a-slot-start". A refusal is final for those terms — change them or use contact_business; do not retry the same call. The business may later withdraw. Read `state` from check_commitment before relying on it. Authentication: bearer token required. Register once at POST /api/v1/agents/register, exchange the credentials at POST /api/v1/agents/token.

NameTypeReqDescription
amountnumberWhat the buyer is offering to pay, as a number. Required unless you send `items`. This is your figure, not ours — we only check it against the limits the business set. Sent alongside `items`, it must…
currencystringISO code, e.g. MDL or EUR. Required unless you send `items`. It must match the currency their limits are in.
datestringyesThe day the work or delivery is for, as yyyy-mm-dd, in the business's own local calendar.
descriptionstringOptional. What the order is for, in plain words. Recorded and shown to the business; it is never parsed and never changes what we check.
itemsarrayOptional. Lines from their rate card, as request_quote takes them. When present, the price is theirs rather than yours and is computed fresh at this moment — a card that changed since you quoted refu…
kindstringyesThe `kind` field from the same search result.
quantitynumberOptional. How many, as a whole number. Defaults to 1. Leave it out when you send `items` — the quantities are on the lines.
slugstringyesThe `slug` field from a search_businesses result.
timestringOptional. A slot start on that day, HH:MM in 24-hour time and in their timezone. It must be one of the starts check_availability lists; times between them are refused rather than rounded to the neare…

No output schema declared.

No examples provided.

contact_business ~310

Open a conversation with the person behind a listing. The message arrives in their dashboard inbox and they reply when they get to it — this is asynchronous, not a chat, and nobody is obliged to answer. Returns a `conversation_id` and a secret `token`. Keep both: they are the only way to read a reply (check_replies) or write again (send_followup), and the `token` cannot be recovered. Authentication: bearer token required. Register once at POST /api/v1/agents/register, exchange the credentials at POST /api/v1/agents/token, and send the result as an Authorization: Bearer header. Registered agents get a daily conversation quota, a per-minute burst limit and an alarm on contacting many businesses at once; a refusal names which one was hit. Reading the knowledge base needs none of this.

NameTypeReqDescription
agent_contactstringOptional. An out-of-band address the business can reply to, e.g. the end user email if they agreed to share it.
agent_namestringyesWho is writing, in words the business will read — e.g. "Claude, on behalf of a customer".
kindstringOptional. The `kind` field from the same search result.
messagestringyesThe message body. Maximum 4000 characters.
slugstringyesThe `slug` field from a search_businesses result.
subjectstringyesShort subject line, like an email subject.

No output schema declared.

No examples provided.

get_business ~155

Read the full profile of one business. Returns identity, contact details, address, social profiles, offerings, FAQ, `verification` and any machine-readable endpoints we publish for it. Absent information is named in `missing` rather than dropped silently, so an empty field means "we do not hold this", not "they do not have one". An unknown `slug` returns candidate slugs instead of a bare failure. Authentication: none. This tool works with no credentials.

NameTypeReqDescription
kindstringOptional. The `kind` field from the same search result. If omitted, "entity" is tried first, then "website".
slugstringyesThe `slug` field from a search_businesses result.

No output schema declared.

No examples provided.

get_rate_card ~228

Read the prices a business has authorised us to quote on their behalf. Returns `published` and, when true, a `rateCard` holding a currency, an optional minimum charge and `items` — each with a `code`, a label, a unit and an amount. Those `code` values are what request_quote and commit_order take: we price exactly what you name and never work out which line a description meant, because a near-miss there is a wrong price someone has to honour. `published` false comes with `reason`: "no-rate-card" means they have not written one, "not-authorised" means they have not allowed us to name prices at all. Neither means the work is unavailable — only that the figure has to come from a person, via ask_business_freeform or contact_business. Authentication: none. This tool works with no credentials.

NameTypeReqDescription
kindstringOptional. The `kind` field from the same search result. Defaults to "entity".
slugstringyesThe `slug` field from a search_businesses result.

No output schema declared.

No examples provided.

request_order_change ~293

Raise anything else about an order that already exists: a change to what was ordered, a refund request, or a problem with what was delivered. This tool never settles anything, and that is deliberate. Changing an order re-prices it and a refund moves money tunnel does not hold, so both are decisions only the business makes. What this does is put the request in front of them with the whole order attached — reference, terms, lines, date and what has already happened to it — on the channel they actually read. Returns `settled` false always, the `order` as it stands, and an `escalation` whose `ref` you poll with check_escalation for the business's own answer in their words. For a refund it also returns `refund`: their published terms at this notice, if they have published any. Nothing has been paid, refunded or changed by this call. Authentication: bearer token required.

NameTypeReqDescription
changestringyesWhat kind of request this is: "modify" to change what was ordered, "refund" to ask about money back, "other" for anything else including something being wrong.
notestringyesWhat the buyer actually said, in their own words. This is the part the business needs, so send it verbatim. Carried unchanged and never interpreted.
refstringyesThe `ref` returned by commit_order.

No output schema declared.

No examples provided.

request_quote ~361

Price a specific set of line items against a business's rate card. Call get_rate_card first and name `code` values from it; we do the arithmetic. Returns `quoted`. When true you get `total`, `lines` showing what each one came to, and `validUntil`. A quote is a statement, NOT a hold — nothing is reserved and no price is locked. commit_order prices the same items again from the card at the moment it binds, so if the merchant changed a figure in between you are told rather than charged. When `quoted` is false, `reason` is "unknown-items" (not on their card), "quantity-out-of-range" (change the number and call again), "no-rate-card", "not-authorised" or "below-price-floor". All but the second put the question in front of a person and return an `escalation` whose `ref` you can poll with check_escalation. Authentication: none. This tool works with no credentials.

NameTypeReqDescription
itemsarrayyesThe lines to price. Each is an object with a `code` from get_rate_card and an optional quantity, which defaults to 1. Up to 100 lines.
kindstringOptional. The `kind` field from the same search result. Defaults to "entity".
languagestringOptional. The buyer's language, recorded with the request. Defaults to English.
notestringOptional. What the job is, in the buyer's own words. Never parsed and never changes the figure; it is what a human reads if the quote has to go to one.
slugstringyesThe `slug` field from a search_businesses result.

No output schema declared.

No examples provided.

reschedule_order ~361

Move an order you placed to a different date, or a booking to a different slot. The price, the items and the quantity are unchanged — this moves WHEN, nothing else. To change what was ordered, use request_order_change. A booking made for a time must be moved to a time, and a whole-day order to a whole day; the new slot is checked exactly as commit_order checked the first one. Call check_availability first. Returns `settled`, and when true `from` and `to`, plus `remainingReschedules` — an order may be moved a limited number of times before a person is asked instead. False comes with a `reason`: "slot-taken", "not-a-slot-start", "closed-that-day", "blackout-date", "capacity-full", "inside-lead-time", "date-in-past", "time-required", "time-not-supported", "inside-cancel-window", "too-many-reschedules" or "not-open". Some are yours to fix and carry `freeSlots`; the rest return an `escalation` for check_escalation. Authentication: bearer token required, and it must be the same agent that placed the order.

NameTypeReqDescription
datestringyesThe new day, as yyyy-mm-dd in the business's own local calendar.
notestringOptional. Why, in the buyer's own words. Shown to the business, never parsed.
refstringyesThe `ref` returned by commit_order.
timestringThe new slot start, HH:MM in 24-hour time and in their timezone. Required if the order was made for a time; leave it out if it was made for a whole day.

No output schema declared.

No examples provided.

search_businesses ~290

Find businesses, merchants and websites in the tunnel knowledge base by name or topic. Start here: every other tool needs a `slug`, and this is where a `slug` comes from. Returns an array of summaries, each with `slug`, `kind`, name, description and a `verification` object. Read `verification.level` rather than assuming: "human" means a tunnel employee checked the business, "automated" means machines proved only that the business controls its own channels, and null means neither. Zero matches is a normal answer, not an error — it comes back with `completeness` "empty". Authentication: none. This tool works with no credentials.

NameTypeReqDescription
limitnumberOptional. Maximum results, 1 to 50. Defaults to 20.
querystringyesName, topic or place. Words are matched independently against the name, location, description, offerings and FAQ, and most of them have to appear somewhere in a record, so "cakes in Chisinau" works.…
typestringOptional. Return only records of this kind.

No output schema declared.

No examples provided.

send_followup ~125

Add another message to a conversation already opened with contact_business. Returns the updated message thread. There is a cap on messages per conversation, so send one considered follow-up rather than several fragments. Authentication: bearer token required — the same one used for contact_business — plus the `conversation_id` and `token` for the conversation itself.

NameTypeReqDescription
conversation_idnumberyesThe `conversation_id` returned by contact_business.
messagestringyesThe message body. Maximum 4000 characters.
tokenstringyesThe secret `token` returned by contact_business.

No output schema declared.

No examples provided.