# Xona Dental Gateway (remote · book.xonark.com)

Find Canadian dentists; send an appointment request or book with a connected practice.

- Trust score: 67/100 (medium)
- Change this week: −3
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-29

## Components

- remote · `book.xonark.com`: 67/100 (this document), [markdown](https://verifymcp.io/servers/com-xonark-dental-gateway/book.md), [page](https://verifymcp.io/servers/com-xonark-dental-gateway/book)

## Channel facts

- Endpoint: `https://book.xonark.com/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.1.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-29.

- **Endpoint Security**: 77/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one.
  - HTTPS is enforced; there's no plaintext access path.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC is configured correctly; the domain's records validate against the full chain to the root.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 42/100
  - 0% of prompts and resources have a non-trivial description (not blank, and not just the item's name).
  - AI-judged instruction clarity (good).
  - Context-footprint check failed: tool/resource definitions use about 2559 tokens (~127/item across 20 items; 19 tools + 1 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 26/100
  - Stability check failed: schema churn in the 10 days we've observed: 0 tool removals, 2 breaking changes, 0 auth/transport breaks, 4 additions.
- **Tool Coverage**: 82/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 36% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.
  - An AI judge read all 21 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 73/100
  - Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28.
  - Supports UI / widget rendering.

## Install

### How do I install the Xona Dental Gateway MCP server?

Xona Dental Gateway is a hosted endpoint at https://book.xonark.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http com-xonark-dental-gateway 'https://book.xonark.com/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "com-xonark-dental-gateway": {
      "url": "https://book.xonark.com/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "com-xonark-dental-gateway": {
      "type": "http",
      "url": "https://book.xonark.com/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.com-xonark-dental-gateway]
url = "https://book.xonark.com/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-xonark-dental-gateway": {
      "type": "remote",
      "url": "https://book.xonark.com/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add com-xonark-dental-gateway --url 'https://book.xonark.com/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  com-xonark-dental-gateway:
    url: "https://book.xonark.com/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "com-xonark-dental-gateway": {
      "Transport": "http",
      "Url": "https://book.xonark.com/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add com-xonark-dental-gateway -t streamable-http -u 'https://book.xonark.com/mcp'
```

### Other

```json
{
  "mcpServers": {
    "com-xonark-dental-gateway": {
      "type": "http",
      "url": "https://book.xonark.com/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-28 (score 67, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-27 (score 67, +1)

No change was recorded against any check on this day. Stability & Change Management went from 16 to 19.

### 2026-09-25 (score 66, −4)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-24 (score 70, +1)

No change was recorded against any check on this day. Stability & Change Management went from 6 to 9.

### 2026-09-23 (score 69, −1)

- [security regression] Stability: 0.10 → fail
- [security regression] A breaking change shipped without a version bump: still 0.1.0
- [security] The server rewrote its instructions, which are the text every model session reads
- [security] Tool “confirm_xona_booking” rewrote its description, which is the text the model reads
- [security] Tool “hold_xona_booking_slot” rewrote its description, which is the text the model reads
- [functional regression] “confirm_xona_booking” dropped the required parameter “consent_version”
- [functional regression] “hold_xona_booking_slot” dropped the required parameter “patient_email”
- [cosmetic] “hold_xona_booking_slot” reworded the description of “patient_phone”
- [cosmetic] Tool “confirm_xona_booking” changed its title: Book the held time → Get the booking's result
- [cosmetic] Tool “hold_xona_booking_slot” changed its title: Hold an open time → Hold an open time and text the patient a link

### 2026-09-21 (score 70, +1)

No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-20 (score 69, 0)

- [functional improvement] Stability: unverified → 0.03

### 2026-09-19 (score 69)

First indexed and scored.

## MCP tools (19)

### `search_canadian_dentists` (~400 tokens)

Search Canadian dentists

Search evidence-backed public profiles in the Canadian dental directory by name or place, and filter by a service, a language, published weekend or evening hours, a booking route you can use now, and a payment plan the clinic says it accepts (the Canadian Dental Care Plan). Each row says which published fact matched and when it was read. No login or clinic membership is required.

Input parameters:

- `booking` (string): A route the agent can use now: the clinic's online booking page, its request form, an appointment request Xona delivers, a phone number, or any of these
- `coverage` (string): A payment plan the clinic says it accepts, on its own website or in a correction its owner made: cdcp is the Canadian Dental Care Plan. Each row quotes the clinic's own words and the day they were re…
- `language` (string): A language the clinic's own site lists
- `limit` (integer)
- `locality` (string)
- `open` (string): Published hours: open that day, or closing at/after 18:00 on some day
- `order` (string): route (default) orders by booking route; soonest orders one place's practices by when they can be seen, and needs that place's locality and province: practices whose live schedule Xona reads first, t…
- `postal_code` (string)
- `province` (string)
- `query` (string)
- `service` (string): A service the clinic's own site lists: cleaning, implants, invisalign, emergency, kids, root canal, whitening …

Output parameters:

- `count` (integer)
- `projection` (string)
- `results` (array)

### `get_canadian_dental_practice` (~38 tokens)

Get a Canadian dental practice

Get one public dental practice profile, fact evidence, citations, and current public actions.

Input parameters:

- `practice_slug` (string, required)

Output parameters:

- `actions` (array)
- `practice` (object)

### `answer_dental_practice_question` (~53 tokens)

Answer from dental practice evidence

Answer a bounded factual question from the selected practices' evidence. Unknown is returned explicitly; missing data is never inferred as no.

Input parameters:

- `practice_slugs` (array, required)
- `topic` (string, required)

Output parameters:

- `answers` (array)

### `list_dental_practice_actions` (~42 tokens)

List dental practice actions

List current public booking, request, form, call, and website actions for a dental practice in preference order.

Input parameters:

- `practice_slug` (string, required)

Output parameters:

- `actions` (array)
- `practice_slug` (string)

### `prepare_dental_practice_action` (~50 tokens)

Open a dental action for review

Prepare an expiring, attributed dental action and return the patient review URL where the patient sees the action and continues.

Input parameters:

- `capability` (string, required)
- `practice_slug` (string, required)

Output parameters:

- `action` (object)
- `conversational_next_tool` (string)
- `manual_review_required` (boolean)
- `next_step` (string)

### `get_dental_action_status` (~42 tokens)

Get dental action status

Read the exact outcome of an expiring dental action. Handoff, request, and confirmed booking outcomes remain distinct.

Input parameters:

- `action_id` (string, required)

Output parameters:

- `action` (object)

### `list_public_booking_services` (~39 tokens)

List a clinic's public booking services

Read services from a clinic's already-prepared supported public booking widget. Provider locators remain server-owned.

Input parameters:

- `action_id` (string, required)

Output parameters:

- `services` (array)

### `list_public_booking_slots` (~55 tokens)

List a clinic's public booking slots

Read public availability from a supported clinic widget for one service and UTC window.

Input parameters:

- `action_id` (string, required)
- `end` (string, required)
- `service_id` (string, required)
- `start` (string, required)

Output parameters:

- `action_id` (string)
- `practice_slug` (string)
- `slots` (array)
- `use_tool` (string)

### `start_dental_request` (~111 tokens)

Start a dental appointment request

Start an appointment request that Xona emails to the selected clinic, without leaving the conversation. Xona first emails the patient a code that confirms their address; confirm_dental_request then sends the request. Use it where list_dental_practice_actions marks xona_email_appointment_request as completes_in_conversation.

Input parameters:

- `patient_email` (string, required): The patient's own email; the code goes there
- `patient_name` (string, required): The patient's name as they typed it
- `practice_slug` (string, required)

Output parameters:

- `action` (object)
- `consent_text` (string)
- `consent_version` (string)
- `next_step` (string)
- `practice` (object)
- `verification` (string)

### `confirm_dental_request` (~127 tokens)

Send a dental appointment request

Send the started request to the clinic. It takes the 6-digit code Xona emailed the patient and the consent_version of the consent_text the patient agreed to. The outcome is a delivered, held or failed request, never a confirmed booking. Calling again with the same action_id returns the same outcome.

Input parameters:

- `action_id` (string, required)
- `consent_version` (string, required)
- `note` (string)
- `preferred_window` (string, required): When the patient is free, in their words
- `service_category` (string, required)
- `verification_code` (string, required)

Output parameters:

- `action` (object)
- `next_step` (string)
- `outcome` (string)
- `receipt_url` (string)

### `list_xona_booking_services` (~55 tokens)

List a connected practice's booking services

List the services a practice that connected its schedule to Xona books online. Use it where list_dental_practice_actions marks the Xona booking route as completes_in_conversation.

Input parameters:

- `practice_slug` (string, required)

Output parameters:

- `next_step` (string)
- `practice` (object)
- `services` (array)

### `list_xona_booking_slots` (~193 tokens)

List a connected practice's open times

List open times at a connected practice for one service between date_from and date_to (inclusive, at most 8 weeks out). Returns the closest ten to preferred_time (else a balanced spread) plus the earliest open time, with a reason when empty. Each slot has a slot_fingerprint and date for hold_xona_booking_slot.

Input parameters:

- `date_from` (string, required): First day to search, in the practice's time zone
- `date_to` (string, required): Last day to search (inclusive); at most 56 days after date_from and 8 weeks from today
- `doctor_id` (string): Restrict to one provider, using a doctor_id a previous slot listing returned
- `practice_slug` (string, required)
- `preferred_time` (string): The patient's preferred local start time, 24-hour HH:MM; slots closest to it come first
- `service_id` (string, required)

Output parameters:

- `booking_url` (string)
- `date_correction` (object)
- `earliest` (object)
- `effective_from` (string)
- `effective_to` (string)
- `instructions` (string)
- `next_step` (string)
- `practice` (object)
- `reason` (string)
- `service_id` (string)
- `slots` (array)
- `time_zone` (string)

### `hold_xona_booking_slot` (~237 tokens)

Hold an open time and text the patient a link

Hold one open time and text the patient a link to it. The page the link opens shows the time and the details above a Book this appointment button. When the patient presses it the appointment is booked, or, at a practice that confirms bookings itself, sent to the practice as a request.

Input parameters:

- `date` (string, required): The chosen slot's date exactly as list_xona_booking_slots returned it
- `date_of_birth` (string, required): The patient's date of birth, as the patient gave it in this conversation
- `first_name` (string, required): The patient's first name, as the patient gave it in this conversation
- `guardian_name` (string): Required when the patient is under 16
- `last_name` (string, required): The patient's last name, as the patient gave it in this conversation
- `note` (string)
- `patient_phone` (string, required): The patient's own Canadian or US mobile number, as the patient gave it in this conversation; the booking link is texted there
- `practice_slug` (string, required)
- `service_id` (string, required)
- `slot_fingerprint` (string, required)

Output parameters:

- `action_id` (string)
- `booking_steps` (array)
- `booking_url` (string)
- `continue_url` (string)
- `hold_expires_at` (string)
- `link_expires_at` (string)
- `next_step` (string)
- `outcome` (string)
- `practice` (object)
- `reason` (string)
- `verification` (string)

### `confirm_xona_booking` (~91 tokens)

Get the booking's result

Get the result once the patient has tapped the text link and pressed Book this appointment. Until then it returns waiting_for_patient. Xona finds an existing patient itself; when it cannot tell, it returns the practice's booking page instead of guessing. If the booking stopped before it was written, the first call tries it once more. Calling again returns the same outcome.

Input parameters:

- `action_id` (string, required)

Output parameters:

- `action_id` (string)
- `appointment_start` (string)
- `appointment_start_local` (string)
- `booking_steps` (array)
- `booking_url` (string)
- `confirmation_sms` (string)
- `consent_version` (string)
- `continue_url` (string)
- `link_expires_at` (string)
- `next_step` (string)
- `outcome` (string)
- `practice` (object)
- `reason` (string)

### `abandon_xona_booking` (~58 tokens)

Give up a booking that is not booked yet

Release the held time and drop the patient's details when the patient no longer wants it, at any step before it is booked. It never cancels a booked appointment. Calling again returns the same result.

Input parameters:

- `action_id` (string, required)

Output parameters:

- `action_id` (string)
- `appointment_start` (string)
- `appointment_start_local` (string)
- `booking_steps` (array)
- `booking_url` (string)
- `confirmation_sms` (string)
- `consent_version` (string)
- `continue_url` (string)
- `link_expires_at` (string)
- `next_step` (string)
- `outcome` (string)
- `practice` (object)
- `reason` (string)

### `start_xona_appointment_access` (~158 tokens)

Text the patient a link to show their appointments

Text a patient one link to see, move or cancel the appointments they already have at a practice connected to Xona, for a conversation with no booking action_id that still works. If the mobile number, name and date of birth match a patient there, Xona texts them the link; after they tap it and press Show my appointments, list_xona_appointments reads their appointments. The answer is the same whether or not the details match.

Input parameters:

- `date_of_birth` (string, required)
- `first_name` (string, required)
- `last_name` (string, required)
- `patient_phone` (string, required): The patient's own Canadian or US mobile number, as the practice has it on file
- `practice_slug` (string, required)

Output parameters:

- `action_id` (string)
- `link_expires_at` (string)
- `next_step` (string)
- `practice` (object)
- `status` (string)

### `list_xona_appointments` (~90 tokens)

List the patient's upcoming appointments

Read the named patient's upcoming appointments at the practice, live from its schedule, after the patient tapped the text link. Works with the action_id of a booking made in this conversation (for 30 minutes after the tap, and for that appointment until its day) or of start_xona_appointment_access. Before the tap it says it is still waiting.

Input parameters:

- `action_id` (string, required)

Output parameters:

- `access_expires_at` (string)
- `action_id` (string)
- `appointments` (array)
- `booked_until` (string)
- `changes` (array)
- `next_step` (string)
- `pending_requests` (array)
- `practice` (object)
- `status` (string)
- `time_zone` (string)

### `list_xona_reschedule_times` (~112 tokens)

List times an appointment can move to

List open times one of the patient's appointments can move to, for its own service and provider, between date_from and date_to. appointment_ref comes from list_xona_appointments.

Input parameters:

- `action_id` (string, required)
- `appointment_ref` (string, required)
- `date_from` (string, required): First day to search, in the practice's time zone
- `date_to` (string, required): Last day to search (inclusive); at most 56 days after date_from and 8 weeks from today

Output parameters:

- `action_id` (string)
- `appointment_ref` (string)
- `next_step` (string)
- `practice` (object)
- `slots` (array)
- `time_zone` (string)

### `change_xona_appointment` (~175 tokens)

Ask to move or cancel an appointment

Move or cancel one of the patient's appointments. Xona texts the patient a link to a page that shows the exact change. When they press its button (or type the code from the text on book.xonark.com/code) the practice's schedule changes, or, at a practice that confirms changes itself, the practice receives the request. Calling again with the same arguments returns the result, read live from the practice's schedule.

Input parameters:

- `action_id` (string, required)
- `appointment_ref` (string, required)
- `date` (string): For a reschedule: the new time's date exactly as list_xona_reschedule_times returned it
- `kind` (string, required)
- `slot_fingerprint` (string): For a reschedule: the new time's slot_fingerprint from list_xona_reschedule_times

Output parameters:

- `action_id` (string)
- `appointment_ref` (string)
- `appointment_start_local` (string)
- `kind` (string)
- `link_expires_at` (string)
- `next_step` (string)
- `practice` (object)
- `requested_start_local` (string)
- `state` (string)

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/com-xonark-dental-gateway/book#diagnostics

## Score history

- 2026-09-29: 67
- 2026-09-28: 67
- 2026-09-27: 67
- 2026-09-26: 66
- 2026-09-25: 66
- 2026-09-24: 70
- 2026-09-23: 69
- 2026-09-22: 70
- 2026-09-21: 70
- 2026-09-20: 69
- 2026-09-19: 69

## Common questions

### What is the Xona Dental Gateway MCP server?

Xona Dental Gateway is an MCP server listed in the public MCP registry as com.xonark/dental-gateway. Find Canadian dentists; send an appointment request or book with a connected practice. This page covers its hosted endpoint (https://book.xonark.com/mcp).

### Is the Xona Dental Gateway MCP server safe to use?

Xona Dental Gateway scores 67 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Xona Dental Gateway MCP server expose?

Xona Dental Gateway exposes 19 tools: search_canadian_dentists, get_canadian_dental_practice, answer_dental_practice_question, list_dental_practice_actions, prepare_dental_practice_action, and 14 more. Their descriptions and schemas cost roughly 2,126 tokens of context every time the server is loaded.

### Does the Xona Dental Gateway MCP server require authentication?

No. We connected to Xona Dental Gateway without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the Xona Dental Gateway MCP server still maintained?

Xona Dental Gateway is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://book.xonark.com/mcp
- Website: https://book.xonark.com/use-with-ai
- Changelog RSS feed: https://verifymcp.io/servers/com-xonark-dental-gateway/book.xml
- Changelog JSON feed: https://verifymcp.io/servers/com-xonark-dental-gateway/book.json
- HTML version of this page: https://verifymcp.io/servers/com-xonark-dental-gateway/book
