Xona Dental Gateway
REMOTE · BOOK.XONARK.COM · SCANNED SEP 29
Find Canadian dentists; send an appointment request or book with a connected practice.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security77
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability42
- 0% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Fail
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 2559 tokens (~127/item across 20 items; 19 tools + 1 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management26
- Stability check failed: schema churn in the 10 days we've observed: 0 tool removals, 2 breaking changes, 0 auth/transport breaks, 4 additions. See how to fix → Fail
Tool Coverage82
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 36% of tool parameters carry a description.Partial
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 21 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities73
- Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
- Supports UI / widget rendering.Pass
How do I install the Xona Dental Gateway MCP server?
Xona Dental Gateway is a hosted endpoint at https://book.xonark.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · book.xonark.com
claude mcp add --transport http com-xonark-dental-gateway 'https://book.xonark.com/mcp'
{
"mcpServers": {
"com-xonark-dental-gateway": {
"url": "https://book.xonark.com/mcp"
}
}
} {
"servers": {
"com-xonark-dental-gateway": {
"type": "http",
"url": "https://book.xonark.com/mcp"
}
}
} [mcp_servers.com-xonark-dental-gateway] url = "https://book.xonark.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-xonark-dental-gateway": {
"type": "remote",
"url": "https://book.xonark.com/mcp",
"enabled": true
}
}
} openclaw mcp add com-xonark-dental-gateway --url 'https://book.xonark.com/mcp' --transport streamable-http
mcp_servers:
com-xonark-dental-gateway:
url: "https://book.xonark.com/mcp" {
"McpServers": {
"com-xonark-dental-gateway": {
"Transport": "http",
"Url": "https://book.xonark.com/mcp"
}
}
} assistant mcp add com-xonark-dental-gateway -t streamable-http -u 'https://book.xonark.com/mcp'
{
"mcpServers": {
"com-xonark-dental-gateway": {
"type": "http",
"url": "https://book.xonark.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 28 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 16 to 19.
- 25 Sept 26 −4
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 24 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 6 to 9.
- 23 Sept 26 −1
- Stability: 0.10 → fail ▼ security
- A breaking change shipped without a version bump: still 0.1.0 ▼ security
- The server rewrote its instructions, which are the text every model session reads security
- Tool “confirm_xona_booking” rewrote its description, which is the text the model reads security
- Tool “hold_xona_booking_slot” rewrote its description, which is the text the model reads security
- “confirm_xona_booking” dropped the required parameter “consent_version” ▼ functional
- “hold_xona_booking_slot” dropped the required parameter “patient_email” ▼ functional
- “hold_xona_booking_slot” reworded the description of “patient_phone” cosmetic
- Tool “confirm_xona_booking” changed its title: Book the held time → Get the booking's result cosmetic
- Tool “hold_xona_booking_slot” changed its title: Hold an open time → Hold an open time and text the patient a link cosmetic
- 21 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 20 Sept 26 0
- Stability: unverified → 0.03 ▲ functional
- 19 Sept 26 69
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 29 Sept 2026 · Probed https://book.xonark.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=xonark.com | CN=WE1,O=Google Trust Services,C=US | 27 Aug 2026 | 25 Nov 2026 | ECDSA 256 | ECDSA-SHA256 | 4e00c42e4e84ee440ec5d39dca564905 |
| SANs: xonark.com, *.xonark.com | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC secure
Validation of book.xonark.com. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| xonark.com. | present | 2371 | 13 | Verified |
| book.xonark.com. | Verified address RRset verified with the apex keys |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://book.xonark.com/mcp | Verified | 200 | |
| http (plaintext) | http://book.xonark.com/mcp | HTTPS enforced | 301 | https://book.xonark.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
abandon_xona_booking Give up a booking that is not booked yet ~58
Release the held time and drop the patient's details when the patient no longer wants it, at any step before it is booked. It never cancels a booked appointment. Calling again returns the same result.
| Name | Type | Req | Description |
|---|---|---|---|
| action_id | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| action_id | string | yes | – |
| appointment_start | string | – | – |
| appointment_start_local | string | – | – |
| booking_steps | array | – | – |
| booking_url | string | – | – |
| confirmation_sms | string | – | – |
| consent_version | string | – | – |
| continue_url | string | – | – |
| link_expires_at | string | – | – |
| next_step | string | yes | – |
| outcome | string | yes | – |
| practice | object | yes | – |
| reason | string | – | – |
No examples provided.
answer_dental_practice_question Answer from dental practice evidence ~53
Answer a bounded factual question from the selected practices' evidence. Unknown is returned explicitly; missing data is never inferred as no.
| Name | Type | Req | Description |
|---|---|---|---|
| practice_slugs | array | yes | – |
| topic | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| answers | array | yes | – |
No examples provided.
change_xona_appointment Ask to move or cancel an appointment ~175
Move or cancel one of the patient's appointments. Xona texts the patient a link to a page that shows the exact change. When they press its button (or type the code from the text on book.xonark.com/code) the practice's schedule changes, or, at a practice that confirms changes itself, the practice receives the request. Calling again with the same arguments returns the result, read live from the practice's schedule.
| Name | Type | Req | Description |
|---|---|---|---|
| action_id | string | yes | – |
| appointment_ref | string | yes | – |
| date | string | – | For a reschedule: the new time's date exactly as list_xona_reschedule_times returned it |
| kind | string | yes | – |
| slot_fingerprint | string | – | For a reschedule: the new time's slot_fingerprint from list_xona_reschedule_times |
| Name | Type | Req | Description |
|---|---|---|---|
| action_id | string | yes | – |
| appointment_ref | string | yes | – |
| appointment_start_local | string | – | – |
| kind | string | – | – |
| link_expires_at | string | – | – |
| next_step | string | yes | – |
| practice | object | yes | – |
| requested_start_local | string | – | – |
| state | string | yes | – |
No examples provided.
confirm_dental_request Send a dental appointment request ~127
Send the started request to the clinic. It takes the 6-digit code Xona emailed the patient and the consent_version of the consent_text the patient agreed to. The outcome is a delivered, held or failed request, never a confirmed booking. Calling again with the same action_id returns the same outcome.
| Name | Type | Req | Description |
|---|---|---|---|
| action_id | string | yes | – |
| consent_version | string | yes | – |
| note | string | – | – |
| preferred_window | string | yes | When the patient is free, in their words |
| service_category | string | yes | – |
| verification_code | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| action | object | yes | – |
| next_step | string | yes | – |
| outcome | string | yes | – |
| receipt_url | string | – | – |
No examples provided.
confirm_xona_booking Get the booking's result ~91
Get the result once the patient has tapped the text link and pressed Book this appointment. Until then it returns waiting_for_patient. Xona finds an existing patient itself; when it cannot tell, it returns the practice's booking page instead of guessing. If the booking stopped before it was written, the first call tries it once more. Calling again returns the same outcome.
| Name | Type | Req | Description |
|---|---|---|---|
| action_id | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| action_id | string | yes | – |
| appointment_start | string | – | – |
| appointment_start_local | string | – | – |
| booking_steps | array | – | – |
| booking_url | string | – | – |
| confirmation_sms | string | – | – |
| consent_version | string | – | – |
| continue_url | string | – | – |
| link_expires_at | string | – | – |
| next_step | string | yes | – |
| outcome | string | yes | – |
| practice | object | yes | – |
| reason | string | – | – |
No examples provided.
get_canadian_dental_practice Get a Canadian dental practice ~38
Get one public dental practice profile, fact evidence, citations, and current public actions.
| Name | Type | Req | Description |
|---|---|---|---|
| practice_slug | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| actions | array | yes | – |
| practice | object | yes | – |
No examples provided.
get_dental_action_status Get dental action status ~42
Read the exact outcome of an expiring dental action. Handoff, request, and confirmed booking outcomes remain distinct.
| Name | Type | Req | Description |
|---|---|---|---|
| action_id | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| action | object | yes | – |
No examples provided.
hold_xona_booking_slot Hold an open time and text the patient a link ~237
Hold one open time and text the patient a link to it. The page the link opens shows the time and the details above a Book this appointment button. When the patient presses it the appointment is booked, or, at a practice that confirms bookings itself, sent to the practice as a request.
| Name | Type | Req | Description |
|---|---|---|---|
| date | string | yes | The chosen slot's date exactly as list_xona_booking_slots returned it |
| date_of_birth | string | yes | The patient's date of birth, as the patient gave it in this conversation |
| first_name | string | yes | The patient's first name, as the patient gave it in this conversation |
| guardian_name | string | – | Required when the patient is under 16 |
| last_name | string | yes | The patient's last name, as the patient gave it in this conversation |
| note | string | – | – |
| patient_phone | string | yes | The patient's own Canadian or US mobile number, as the patient gave it in this conversation; the booking link is texted there |
| practice_slug | string | yes | – |
| service_id | string | yes | – |
| slot_fingerprint | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| action_id | string | yes | – |
| booking_steps | array | – | – |
| booking_url | string | – | – |
| continue_url | string | – | – |
| hold_expires_at | string | – | – |
| link_expires_at | string | – | – |
| next_step | string | yes | – |
| outcome | string | – | – |
| practice | object | yes | – |
| reason | string | – | – |
| verification | string | – | – |
No examples provided.
list_dental_practice_actions List dental practice actions ~42
List current public booking, request, form, call, and website actions for a dental practice in preference order.
| Name | Type | Req | Description |
|---|---|---|---|
| practice_slug | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| actions | array | yes | – |
| practice_slug | string | yes | – |
No examples provided.
list_public_booking_services List a clinic's public booking services ~39
Read services from a clinic's already-prepared supported public booking widget. Provider locators remain server-owned.
| Name | Type | Req | Description |
|---|---|---|---|
| action_id | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| services | array | yes | – |
No examples provided.
list_public_booking_slots List a clinic's public booking slots ~55
Read public availability from a supported clinic widget for one service and UTC window.
| Name | Type | Req | Description |
|---|---|---|---|
| action_id | string | yes | – |
| end | string | yes | – |
| service_id | string | yes | – |
| start | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| action_id | string | – | – |
| practice_slug | string | – | – |
| slots | array | yes | – |
| use_tool | string | – | – |
No examples provided.
list_xona_appointments List the patient's upcoming appointments ~90
Read the named patient's upcoming appointments at the practice, live from its schedule, after the patient tapped the text link. Works with the action_id of a booking made in this conversation (for 30 minutes after the tap, and for that appointment until its day) or of start_xona_appointment_access. Before the tap it says it is still waiting.
| Name | Type | Req | Description |
|---|---|---|---|
| action_id | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| access_expires_at | string | – | – |
| action_id | string | yes | – |
| appointments | array | – | – |
| booked_until | string | – | – |
| changes | array | – | – |
| next_step | string | yes | – |
| pending_requests | array | – | – |
| practice | object | yes | – |
| status | string | yes | – |
| time_zone | string | – | – |
No examples provided.
list_xona_booking_services List a connected practice's booking services ~55
List the services a practice that connected its schedule to Xona books online. Use it where list_dental_practice_actions marks the Xona booking route as completes_in_conversation.
| Name | Type | Req | Description |
|---|---|---|---|
| practice_slug | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| next_step | string | yes | – |
| practice | object | yes | – |
| services | array | yes | – |
No examples provided.
list_xona_booking_slots List a connected practice's open times ~193
List open times at a connected practice for one service between date_from and date_to (inclusive, at most 8 weeks out). Returns the closest ten to preferred_time (else a balanced spread) plus the earliest open time, with a reason when empty. Each slot has a slot_fingerprint and date for hold_xona_booking_slot.
| Name | Type | Req | Description |
|---|---|---|---|
| date_from | string | yes | First day to search, in the practice's time zone |
| date_to | string | yes | Last day to search (inclusive); at most 56 days after date_from and 8 weeks from today |
| doctor_id | string | – | Restrict to one provider, using a doctor_id a previous slot listing returned |
| practice_slug | string | yes | – |
| preferred_time | string | – | The patient's preferred local start time, 24-hour HH:MM; slots closest to it come first |
| service_id | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| booking_url | string | – | – |
| date_correction | object | – | – |
| earliest | object | – | – |
| effective_from | string | yes | – |
| effective_to | string | yes | – |
| instructions | string | – | – |
| next_step | string | yes | – |
| practice | object | yes | – |
| reason | string | – | – |
| service_id | string | yes | – |
| slots | array | yes | – |
| time_zone | string | yes | – |
No examples provided.
list_xona_reschedule_times List times an appointment can move to ~112
List open times one of the patient's appointments can move to, for its own service and provider, between date_from and date_to. appointment_ref comes from list_xona_appointments.
| Name | Type | Req | Description |
|---|---|---|---|
| action_id | string | yes | – |
| appointment_ref | string | yes | – |
| date_from | string | yes | First day to search, in the practice's time zone |
| date_to | string | yes | Last day to search (inclusive); at most 56 days after date_from and 8 weeks from today |
| Name | Type | Req | Description |
|---|---|---|---|
| action_id | string | yes | – |
| appointment_ref | string | yes | – |
| next_step | string | yes | – |
| practice | object | yes | – |
| slots | array | yes | – |
| time_zone | string | yes | – |
No examples provided.
prepare_dental_practice_action Open a dental action for review ~50
Prepare an expiring, attributed dental action and return the patient review URL where the patient sees the action and continues.
| Name | Type | Req | Description |
|---|---|---|---|
| capability | string | yes | – |
| practice_slug | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| action | object | yes | – |
| conversational_next_tool | string | – | – |
| manual_review_required | boolean | yes | – |
| next_step | string | yes | – |
No examples provided.
search_canadian_dentists Search Canadian dentists ~400
Search evidence-backed public profiles in the Canadian dental directory by name or place, and filter by a service, a language, published weekend or evening hours, a booking route you can use now, and a payment plan the clinic says it accepts (the Canadian Dental Care Plan). Each row says which published fact matched and when it was read. No login or clinic membership is required.
| Name | Type | Req | Description |
|---|---|---|---|
| booking | string | – | A route the agent can use now: the clinic's online booking page, its request form, an appointment request Xona delivers, a phone number, or any of these |
| coverage | string | – | A payment plan the clinic says it accepts, on its own website or in a correction its owner made: cdcp is the Canadian Dental Care Plan. Each row quotes the clinic's own words and the day they were re… |
| language | string | – | A language the clinic's own site lists |
| limit | integer | – | – |
| locality | string | – | – |
| open | string | – | Published hours: open that day, or closing at/after 18:00 on some day |
| order | string | – | route (default) orders by booking route; soonest orders one place's practices by when they can be seen, and needs that place's locality and province: practices whose live schedule Xona reads first, t… |
| postal_code | string | – | – |
| province | string | – | – |
| query | string | – | – |
| service | string | – | A service the clinic's own site lists: cleaning, implants, invisalign, emergency, kids, root canal, whitening … |
| Name | Type | Req | Description |
|---|---|---|---|
| count | integer | yes | – |
| projection | string | – | – |
| results | array | yes | – |
No examples provided.
start_dental_request Start a dental appointment request ~111
Start an appointment request that Xona emails to the selected clinic, without leaving the conversation. Xona first emails the patient a code that confirms their address; confirm_dental_request then sends the request. Use it where list_dental_practice_actions marks xona_email_appointment_request as completes_in_conversation.
| Name | Type | Req | Description |
|---|---|---|---|
| patient_email | string | yes | The patient's own email; the code goes there |
| patient_name | string | yes | The patient's name as they typed it |
| practice_slug | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| action | object | yes | – |
| consent_text | string | yes | – |
| consent_version | string | yes | – |
| next_step | string | yes | – |
| practice | object | yes | – |
| verification | string | yes | – |
No examples provided.
start_xona_appointment_access Text the patient a link to show their appointments ~158
Text a patient one link to see, move or cancel the appointments they already have at a practice connected to Xona, for a conversation with no booking action_id that still works. If the mobile number, name and date of birth match a patient there, Xona texts them the link; after they tap it and press Show my appointments, list_xona_appointments reads their appointments. The answer is the same whether or not the details match.
| Name | Type | Req | Description |
|---|---|---|---|
| date_of_birth | string | yes | – |
| first_name | string | yes | – |
| last_name | string | yes | – |
| patient_phone | string | yes | The patient's own Canadian or US mobile number, as the practice has it on file |
| practice_slug | string | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| action_id | string | yes | – |
| link_expires_at | string | yes | – |
| next_step | string | yes | – |
| practice | object | yes | – |
| status | string | yes | – |
No examples provided.
What is the Xona Dental Gateway MCP server?
Xona Dental Gateway is an MCP server listed in the public MCP registry as com.xonark/dental-gateway. Find Canadian dentists; send an appointment request or book with a connected practice. This page covers its hosted endpoint (https://book.xonark.com/mcp).
Is the Xona Dental Gateway MCP server safe to use?
Xona Dental Gateway scores 67 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Xona Dental Gateway MCP server expose?
Xona Dental Gateway exposes 19 tools: search_canadian_dentists, get_canadian_dental_practice, answer_dental_practice_question, list_dental_practice_actions, prepare_dental_practice_action, and 14 more. Their descriptions and schemas cost roughly 2,126 tokens of context every time the server is loaded.
Does the Xona Dental Gateway MCP server require authentication?
No. We connected to Xona Dental Gateway without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Xona Dental Gateway MCP server still maintained?
Xona Dental Gateway is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.