Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Xona Dental Gateway

REMOTE · BOOK.XONARK.COM · SCANNED SEP 29

Find Canadian dentists; send an appointment request or book with a connected practice.

Available components

−3 this week 67 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security77
Transport & Reachability100
Schema Quality & AI Usability42
  • 0% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Fail
  • AI-judged instruction clarity (good).Pass
  • Context-footprint check failed: tool/resource definitions use about 2559 tokens (~127/item across 20 items; 19 tools + 1 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management26
  • Stability check failed: schema churn in the 10 days we've observed: 0 tool removals, 2 breaking changes, 0 auth/transport breaks, 4 additions. See how to fix → Fail
Tool Coverage82
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 36% of tool parameters carry a description.Partial
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • An AI judge read all 21 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities73
  • Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
  • Supports UI / widget rendering.Pass
Install

How do I install the Xona Dental Gateway MCP server?

Xona Dental Gateway is a hosted endpoint at https://book.xonark.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · book.xonark.com

# add to Claude Code
claude mcp add --transport http com-xonark-dental-gateway 'https://book.xonark.com/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "com-xonark-dental-gateway": {
      "url": "https://book.xonark.com/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "com-xonark-dental-gateway": {
      "type": "http",
      "url": "https://book.xonark.com/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.com-xonark-dental-gateway]
url = "https://book.xonark.com/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-xonark-dental-gateway": {
      "type": "remote",
      "url": "https://book.xonark.com/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add com-xonark-dental-gateway --url 'https://book.xonark.com/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  com-xonark-dental-gateway:
    url: "https://book.xonark.com/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "com-xonark-dental-gateway": {
      "Transport": "http",
      "Url": "https://book.xonark.com/mcp"
    }
  }
}
# add to Vellum
assistant mcp add com-xonark-dental-gateway -t streamable-http -u 'https://book.xonark.com/mcp'
// mcp.json
{
  "mcpServers": {
    "com-xonark-dental-gateway": {
      "type": "http",
      "url": "https://book.xonark.com/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 28 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 27 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 16 to 19.

  • 25 Sept 26 −4
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 24 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 6 to 9.

  • 23 Sept 26 −1
    • Stability: 0.10 → fail ▼ security
    • A breaking change shipped without a version bump: still 0.1.0 ▼ security
    • The server rewrote its instructions, which are the text every model session reads security
    • Tool “confirm_xona_booking” rewrote its description, which is the text the model reads security
    • Tool “hold_xona_booking_slot” rewrote its description, which is the text the model reads security
    • “confirm_xona_booking” dropped the required parameter “consent_version” ▼ functional
    • “hold_xona_booking_slot” dropped the required parameter “patient_email” ▼ functional
    • “hold_xona_booking_slot” reworded the description of “patient_phone” cosmetic
    • Tool “confirm_xona_booking” changed its title: Book the held time → Get the booking's result cosmetic
    • Tool “hold_xona_booking_slot” changed its title: Hold an open time → Hold an open time and text the patient a link cosmetic
  • 21 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.

  • 20 Sept 26 0
    • Stability: unverified → 0.03 ▲ functional
  • 19 Sept 26 69

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 29 Sept 2026 · Probed https://book.xonark.com/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=xonark.com CN=WE1,O=Google Trust Services,C=US 27 Aug 2026 25 Nov 2026 ECDSA 256 ECDSA-SHA256 4e00c42e4e84ee440ec5d39dca564905
SANs: xonark.com, *.xonark.com
CN=WE1,O=Google Trust Services,C=US (CA) CN=GTS Root R4,O=Google Trust Services LLC,C=US 13 Dec 2023 20 Feb 2029 ECDSA 256 ECDSA-SHA384 7ff31977972c224a76155d13b6d685e3
CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE 15 Nov 2023 28 Jan 2028 ECDSA 384 SHA256-RSA 7fe530bf331343bedd821610493d8a1b

Background: What to check on a remote MCP endpoint →

DNSSEC secure

Validation of book.xonark.com. — Secure

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
xonark.com. present 2371 13 Verified
book.xonark.com. Verified address RRset verified with the apex keys
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://book.xonark.com/mcp Verified 200
http (plaintext) http://book.xonark.com/mcp HTTPS enforced 301 https://book.xonark.com/mcp
MCP tools · 19 exposed · ~2,126 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
abandon_xona_booking ~58

Release the held time and drop the patient's details when the patient no longer wants it, at any step before it is booked. It never cancels a booked appointment. Calling again returns the same result.

NameTypeReqDescription
action_idstringyes–
NameTypeReqDescription
action_idstringyes–
appointment_startstring––
appointment_start_localstring––
booking_stepsarray––
booking_urlstring––
confirmation_smsstring––
consent_versionstring––
continue_urlstring––
link_expires_atstring––
next_stepstringyes–
outcomestringyes–
practiceobjectyes–
reasonstring––

No examples provided.

answer_dental_practice_question ~53

Answer a bounded factual question from the selected practices' evidence. Unknown is returned explicitly; missing data is never inferred as no.

NameTypeReqDescription
practice_slugsarrayyes–
topicstringyes–
NameTypeReqDescription
answersarrayyes–

No examples provided.

change_xona_appointment ~175

Move or cancel one of the patient's appointments. Xona texts the patient a link to a page that shows the exact change. When they press its button (or type the code from the text on book.xonark.com/code) the practice's schedule changes, or, at a practice that confirms changes itself, the practice receives the request. Calling again with the same arguments returns the result, read live from the practice's schedule.

NameTypeReqDescription
action_idstringyes–
appointment_refstringyes–
datestring–For a reschedule: the new time's date exactly as list_xona_reschedule_times returned it
kindstringyes–
slot_fingerprintstring–For a reschedule: the new time's slot_fingerprint from list_xona_reschedule_times
NameTypeReqDescription
action_idstringyes–
appointment_refstringyes–
appointment_start_localstring––
kindstring––
link_expires_atstring––
next_stepstringyes–
practiceobjectyes–
requested_start_localstring––
statestringyes–

No examples provided.

confirm_dental_request ~127

Send the started request to the clinic. It takes the 6-digit code Xona emailed the patient and the consent_version of the consent_text the patient agreed to. The outcome is a delivered, held or failed request, never a confirmed booking. Calling again with the same action_id returns the same outcome.

NameTypeReqDescription
action_idstringyes–
consent_versionstringyes–
notestring––
preferred_windowstringyesWhen the patient is free, in their words
service_categorystringyes–
verification_codestringyes–
NameTypeReqDescription
actionobjectyes–
next_stepstringyes–
outcomestringyes–
receipt_urlstring––

No examples provided.

confirm_xona_booking ~91

Get the result once the patient has tapped the text link and pressed Book this appointment. Until then it returns waiting_for_patient. Xona finds an existing patient itself; when it cannot tell, it returns the practice's booking page instead of guessing. If the booking stopped before it was written, the first call tries it once more. Calling again returns the same outcome.

NameTypeReqDescription
action_idstringyes–
NameTypeReqDescription
action_idstringyes–
appointment_startstring––
appointment_start_localstring––
booking_stepsarray––
booking_urlstring––
confirmation_smsstring––
consent_versionstring––
continue_urlstring––
link_expires_atstring––
next_stepstringyes–
outcomestringyes–
practiceobjectyes–
reasonstring––

No examples provided.

get_canadian_dental_practice ~38

Get one public dental practice profile, fact evidence, citations, and current public actions.

NameTypeReqDescription
practice_slugstringyes–
NameTypeReqDescription
actionsarrayyes–
practiceobjectyes–

No examples provided.

get_dental_action_status ~42

Read the exact outcome of an expiring dental action. Handoff, request, and confirmed booking outcomes remain distinct.

NameTypeReqDescription
action_idstringyes–
NameTypeReqDescription
actionobjectyes–

No examples provided.

hold_xona_booking_slot ~237

Hold one open time and text the patient a link to it. The page the link opens shows the time and the details above a Book this appointment button. When the patient presses it the appointment is booked, or, at a practice that confirms bookings itself, sent to the practice as a request.

NameTypeReqDescription
datestringyesThe chosen slot's date exactly as list_xona_booking_slots returned it
date_of_birthstringyesThe patient's date of birth, as the patient gave it in this conversation
first_namestringyesThe patient's first name, as the patient gave it in this conversation
guardian_namestring–Required when the patient is under 16
last_namestringyesThe patient's last name, as the patient gave it in this conversation
notestring––
patient_phonestringyesThe patient's own Canadian or US mobile number, as the patient gave it in this conversation; the booking link is texted there
practice_slugstringyes–
service_idstringyes–
slot_fingerprintstringyes–
NameTypeReqDescription
action_idstringyes–
booking_stepsarray––
booking_urlstring––
continue_urlstring––
hold_expires_atstring––
link_expires_atstring––
next_stepstringyes–
outcomestring––
practiceobjectyes–
reasonstring––
verificationstring––

No examples provided.

list_dental_practice_actions ~42

List current public booking, request, form, call, and website actions for a dental practice in preference order.

NameTypeReqDescription
practice_slugstringyes–
NameTypeReqDescription
actionsarrayyes–
practice_slugstringyes–

No examples provided.

list_public_booking_services ~39

Read services from a clinic's already-prepared supported public booking widget. Provider locators remain server-owned.

NameTypeReqDescription
action_idstringyes–
NameTypeReqDescription
servicesarrayyes–

No examples provided.

list_public_booking_slots ~55

Read public availability from a supported clinic widget for one service and UTC window.

NameTypeReqDescription
action_idstringyes–
endstringyes–
service_idstringyes–
startstringyes–
NameTypeReqDescription
action_idstring––
practice_slugstring––
slotsarrayyes–
use_toolstring––

No examples provided.

list_xona_appointments ~90

Read the named patient's upcoming appointments at the practice, live from its schedule, after the patient tapped the text link. Works with the action_id of a booking made in this conversation (for 30 minutes after the tap, and for that appointment until its day) or of start_xona_appointment_access. Before the tap it says it is still waiting.

NameTypeReqDescription
action_idstringyes–
NameTypeReqDescription
access_expires_atstring––
action_idstringyes–
appointmentsarray––
booked_untilstring––
changesarray––
next_stepstringyes–
pending_requestsarray––
practiceobjectyes–
statusstringyes–
time_zonestring––

No examples provided.

list_xona_booking_services ~55

List the services a practice that connected its schedule to Xona books online. Use it where list_dental_practice_actions marks the Xona booking route as completes_in_conversation.

NameTypeReqDescription
practice_slugstringyes–
NameTypeReqDescription
next_stepstringyes–
practiceobjectyes–
servicesarrayyes–

No examples provided.

list_xona_booking_slots ~193

List open times at a connected practice for one service between date_from and date_to (inclusive, at most 8 weeks out). Returns the closest ten to preferred_time (else a balanced spread) plus the earliest open time, with a reason when empty. Each slot has a slot_fingerprint and date for hold_xona_booking_slot.

NameTypeReqDescription
date_fromstringyesFirst day to search, in the practice's time zone
date_tostringyesLast day to search (inclusive); at most 56 days after date_from and 8 weeks from today
doctor_idstring–Restrict to one provider, using a doctor_id a previous slot listing returned
practice_slugstringyes–
preferred_timestring–The patient's preferred local start time, 24-hour HH:MM; slots closest to it come first
service_idstringyes–
NameTypeReqDescription
booking_urlstring––
date_correctionobject––
earliestobject––
effective_fromstringyes–
effective_tostringyes–
instructionsstring––
next_stepstringyes–
practiceobjectyes–
reasonstring––
service_idstringyes–
slotsarrayyes–
time_zonestringyes–

No examples provided.

list_xona_reschedule_times ~112

List open times one of the patient's appointments can move to, for its own service and provider, between date_from and date_to. appointment_ref comes from list_xona_appointments.

NameTypeReqDescription
action_idstringyes–
appointment_refstringyes–
date_fromstringyesFirst day to search, in the practice's time zone
date_tostringyesLast day to search (inclusive); at most 56 days after date_from and 8 weeks from today
NameTypeReqDescription
action_idstringyes–
appointment_refstringyes–
next_stepstringyes–
practiceobjectyes–
slotsarrayyes–
time_zonestringyes–

No examples provided.

prepare_dental_practice_action ~50

Prepare an expiring, attributed dental action and return the patient review URL where the patient sees the action and continues.

NameTypeReqDescription
capabilitystringyes–
practice_slugstringyes–
NameTypeReqDescription
actionobjectyes–
conversational_next_toolstring––
manual_review_requiredbooleanyes–
next_stepstringyes–

No examples provided.

search_canadian_dentists ~400

Search evidence-backed public profiles in the Canadian dental directory by name or place, and filter by a service, a language, published weekend or evening hours, a booking route you can use now, and a payment plan the clinic says it accepts (the Canadian Dental Care Plan). Each row says which published fact matched and when it was read. No login or clinic membership is required.

NameTypeReqDescription
bookingstring–A route the agent can use now: the clinic's online booking page, its request form, an appointment request Xona delivers, a phone number, or any of these
coveragestring–A payment plan the clinic says it accepts, on its own website or in a correction its owner made: cdcp is the Canadian Dental Care Plan. Each row quotes the clinic's own words and the day they were re…
languagestring–A language the clinic's own site lists
limitinteger––
localitystring––
openstring–Published hours: open that day, or closing at/after 18:00 on some day
orderstring–route (default) orders by booking route; soonest orders one place's practices by when they can be seen, and needs that place's locality and province: practices whose live schedule Xona reads first, t…
postal_codestring––
provincestring––
querystring––
servicestring–A service the clinic's own site lists: cleaning, implants, invisalign, emergency, kids, root canal, whitening …
NameTypeReqDescription
countintegeryes–
projectionstring––
resultsarrayyes–

No examples provided.

start_dental_request ~111

Start an appointment request that Xona emails to the selected clinic, without leaving the conversation. Xona first emails the patient a code that confirms their address; confirm_dental_request then sends the request. Use it where list_dental_practice_actions marks xona_email_appointment_request as completes_in_conversation.

NameTypeReqDescription
patient_emailstringyesThe patient's own email; the code goes there
patient_namestringyesThe patient's name as they typed it
practice_slugstringyes–
NameTypeReqDescription
actionobjectyes–
consent_textstringyes–
consent_versionstringyes–
next_stepstringyes–
practiceobjectyes–
verificationstringyes–

No examples provided.

start_xona_appointment_access ~158

Text a patient one link to see, move or cancel the appointments they already have at a practice connected to Xona, for a conversation with no booking action_id that still works. If the mobile number, name and date of birth match a patient there, Xona texts them the link; after they tap it and press Show my appointments, list_xona_appointments reads their appointments. The answer is the same whether or not the details match.

NameTypeReqDescription
date_of_birthstringyes–
first_namestringyes–
last_namestringyes–
patient_phonestringyesThe patient's own Canadian or US mobile number, as the practice has it on file
practice_slugstringyes–
NameTypeReqDescription
action_idstringyes–
link_expires_atstringyes–
next_stepstringyes–
practiceobjectyes–
statusstringyes–

No examples provided.

Common questions

What is the Xona Dental Gateway MCP server?

Xona Dental Gateway is an MCP server listed in the public MCP registry as com.xonark/dental-gateway. Find Canadian dentists; send an appointment request or book with a connected practice. This page covers its hosted endpoint (https://book.xonark.com/mcp).

Is the Xona Dental Gateway MCP server safe to use?

Xona Dental Gateway scores 67 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Xona Dental Gateway MCP server expose?

Xona Dental Gateway exposes 19 tools: search_canadian_dentists, get_canadian_dental_practice, answer_dental_practice_question, list_dental_practice_actions, prepare_dental_practice_action, and 14 more. Their descriptions and schemas cost roughly 2,126 tokens of context every time the server is loaded.

Does the Xona Dental Gateway MCP server require authentication?

No. We connected to Xona Dental Gateway without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the Xona Dental Gateway MCP server still maintained?

Xona Dental Gateway is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.