Corply — Start and run your company
REMOTE · CORPLY.DEV · SCANNED OCT 5
Form and manage a Delaware C-Corp from your agent. Setup: https://corply.dev/skills.md
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security91
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- The endpoint enforces authorisation, advertised via RFC 9728 protected-resource metadata. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
- The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents. View diagnostics → Partial
Transport & Reachability0
- Transport blocked by authentication: the endpoint requires auth we don't have to verify streamable-http. See how to fix → View diagnostics → Unverified
Schema Quality & AI Usability0
- Schema blocked by authentication: the endpoint requires auth we don't have to read it. See how to fix → Unverified
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage0
- Tool coverage blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Tool Safety0
- Tool safety blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Capabilities0
- Capabilities blocked by authentication: the endpoint requires auth we don't have to read them. See how to fix → Unverified
Unverified: 6 categories
Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm. Claim this server and supply a read-only token to verify it and lift the score.
How do I install the Corply — Start and run your company MCP server?
Corply — Start and run your company is a hosted endpoint at https://corply.dev/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · corply.dev
claude mcp add --transport http corply-dev-corply 'https://corply.dev/mcp'
{
"mcpServers": {
"corply-dev-corply": {
"url": "https://corply.dev/mcp"
}
}
} {
"servers": {
"corply-dev-corply": {
"type": "http",
"url": "https://corply.dev/mcp"
}
}
} [mcp_servers.corply-dev-corply] url = "https://corply.dev/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"corply-dev-corply": {
"type": "remote",
"url": "https://corply.dev/mcp",
"enabled": true
}
}
} openclaw mcp add corply-dev-corply --url 'https://corply.dev/mcp' --transport streamable-http
mcp_servers:
corply-dev-corply:
url: "https://corply.dev/mcp" {
"McpServers": {
"corply-dev-corply": {
"Transport": "http",
"Url": "https://corply.dev/mcp"
}
}
} assistant mcp add corply-dev-corply -t streamable-http -u 'https://corply.dev/mcp'
{
"mcpServers": {
"corply-dev-corply": {
"type": "http",
"url": "https://corply.dev/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 28 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 8 Sept 26 −48
- Endpoint reachability: reachable → behind authorisation ▼ security
- Stability: fail → unverified ▼ security
- Tool safety: pass → unverified ▼ security
- Transport: pass → unverified ▼ security
- Authorization: The endpoint enforces authorisation, advertised via RFC 9728 protected-resource metadata. security
- Capabilities: fail → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- Schema quality: 100 → unverified ▼ functional
- 7 Sept 26 0
- Tool “get_status” rewrote its description, which is the text the model reads security
- 5 Sept 26 0
- Schema quality: excellent → good functional
- New tool “advance_corporate_action_case” functional
- New tool “attach_corporate_action_evidence” functional
- New tool “create_corporate_action_case” functional
- New tool “get_corporate_action_case” functional
- New tool “list_corporate_action_cases” functional
- 2 Sept 26 0
- Tool “amend_frozen_application” rewrote its description, which is the text the model reads security
- Tool “save_application” rewrote its description, which is the text the model reads security
- Tool “validate_application” rewrote its description, which is the text the model reads security
- 31 Aug 26 0
- Tool “request_payment” rewrote its description, which is the text the model reads security
- Server version: 0.9.0 → 0.10.0 functional
- “request_payment” added an optional parameter “corplyMail” cosmetic
- 27 Aug 26 0
- Tool “save_application” rewrote its description, which is the text the model reads security
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 5 Oct 2026 · Probed https://corply.dev/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=corply.dev | CN=WR3,O=Google Trust Services,C=US | 3 Oct 2026 | 1 Jan 2027 | RSA 2048 | SHA256-RSA | 55bd310a8528de4a12c8079028fea896 |
| SANs: corply.dev | ||||||
| CN=WR3,O=Google Trust Services,C=US (CA) | CN=GTS Root R1,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | RSA 2048 | SHA256-RSA | 7ff005a91568d63abc22861684aa4b5a |
| CN=GTS Root R1,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 19 Jun 2020 | 28 Jan 2028 | RSA 4096 | SHA256-RSA | 77bd0d6cdb36f91aea210fc4f058d30d |
Background: What to check on a remote MCP endpoint →
DNSSEC secure
Validation of corply.dev. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| dev. | present | 60074 | 8 | Verified |
| corply.dev. | present | 359 | 8 | Verified |
| corply.dev. | Verified address RRset verified with the apex keys |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On connection |
| HTTP status | 401 |
WWW-Authenticate challenge Bearer resource_metadata="https://corply.dev/.well-known/oauth-protected-resource"
Bearer resource_metadata="https://corply.dev/.well-known/oauth-protected-resource" | Header | Value |
|---|---|
| www-authenticate | Bearer resource_metadata="https://corply.dev/.well-known/oauth-protected-resource" |
Protected resource metadata
| Document | https://corply.dev/.well-known/oauth-protected-resource |
|---|---|
| Retrieved | Yes |
| Resource | https://corply.dev |
| Authorisation server | https://corply.dev |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://corply.dev/mcp | Auth required | 401 | |
| http (plaintext) | http://corply.dev/mcp | HTTPS enforced | 302 | https://corply.dev/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
start_payment_route_onboarding ~283
Create or recover the secure hosted Moov sandbox onboarding link for one existing Corply payment route. This makes an idempotent provider call after a durable local claim, pre-fills only the canonical legal business name, and asks the founder to complete identity, ownership, underwriting, pricing disclosure, capability, and payout-bank setup directly with Moov. It never receives identity documents, bank/card data, provider credentials, or terms acceptance in chat, activates no route, and moves no money. Return the onboardingLink to the founder, then call get_payment_pipeline_status after they complete it. Prerequisite: authenticated active organization access plus every prerequisite stated above. Canonicality: invokes the shared backend action; trust the returned actual_tool_output and context_engineering instead of adding a state-recovery call. Idempotency: obey the tool-specific retry key or guarantee; if none is stated, inspect refreshed state before retrying. Confirmation boundary: no additional confirmation is needed for this read, reversible save, explicit fact/evidence record, link preparation, plan refresh, or action pre-authorized by a standing founder-configured policy.
| Name | Type | Req | Description |
|---|---|---|---|
| _corply_context | object | – | Echo context_engineering.context_session from the prior Corply result. |
| companyId | string | – | – |
| idempotencyKey | string | yes | – |
| routeId | string | yes | – |
No output schema declared.
No examples provided.
submit_for_formation ~171
Requires the incorporation fee to be PAID first (request_payment → await_payment). Hand the fully-signed formation to the human filing pipeline, then best-effort notify the organization and email the signed incorporation documents to each founder. Does NOT file with Delaware. Prerequisite: authenticated active organization access plus every prerequisite stated above. Canonicality: invokes the shared backend action; trust the returned actual_tool_output and context_engineering instead of adding a state-recovery call. Idempotency: obey the tool-specific retry key or guarantee; if none is stated, inspect refreshed state before retrying. Confirmation boundary: obtain fresh, explicit user confirmation before calling.
| Name | Type | Req | Description |
|---|---|---|---|
| _corply_context | object | – | Echo context_engineering.context_session from the prior Corply result. |
| formationId | string | yes | – |
No output schema declared.
No examples provided.
submit_operating_fact_evidence ~292
Submit one founder-provided document for an evidence-confirmed operating fact. This stages the exact typed assertion, binds the server-verified immutable artifact, and creates a durable operator-review claim. Submission never makes the fact canonical and the resolver will continue to ask for it until an operator approves the exact claim. filePath/fileHash must come from upload_operating_evidence. Prerequisite: authenticated active organization access plus every prerequisite stated above. Canonicality: invokes the shared backend action; trust the returned actual_tool_output and context_engineering instead of adding a state-recovery call. Idempotency: obey the tool-specific retry key or guarantee; if none is stated, inspect refreshed state before retrying. Confirmation boundary: no additional confirmation is needed for this read, reversible save, explicit fact/evidence record, link preparation, plan refresh, or action pre-authorized by a standing founder-configured policy.
| Name | Type | Req | Description |
|---|---|---|---|
| _corply_context | object | – | Echo context_engineering.context_session from the prior Corply result. |
| companyId | string | yes | – |
| factKey | string | yes | – |
| fileHash | string | yes | – |
| filePath | string | yes | – |
| idempotencyKey | string | yes | – |
| sourceObservedAt | string | yes | – |
| sourceReference | string | yes | – |
| subjectId | – | yes | – |
| title | string | yes | – |
| value | – | yes | – |
No output schema declared.
No examples provided.
transition_operating_work_item ~292
Transition one materialized work occurrence by workItemId, then freshly resolve the company plan. Completion is rejected until attached company evidence covers every requirement and required human/professional boundaries. Legal, tax, regulatory, provider, and contractual requirements cannot be waived; change facts only with truthful evidence. Prerequisite: authenticated active organization access plus every prerequisite stated above. Canonicality: invokes the shared backend action; trust the returned actual_tool_output and context_engineering instead of adding a state-recovery call. Idempotency: obey the tool-specific retry key or guarantee; if none is stated, inspect refreshed state before retrying. Confirmation boundary: obtain fresh, explicit user confirmation before calling.
| Name | Type | Req | Description |
|---|---|---|---|
| _corply_context | object | – | Echo context_engineering.context_session from the prior Corply result. |
| companyId | string | – | corply_companies.id. May be omitted only when the active organization has exactly one company. |
| evidenceEventIds | array | – | – |
| expectedFromStatus | string | – | Optimistic-concurrency guard from the latest plan. |
| idempotencyKey | string | – | – |
| itemLimit | integer | yes | Maximum items returned per actionable/blocked/waiting section. |
| questionLimit | integer | yes | Maximum targeted missing-fact questions returned. |
| reason | string | – | – |
| toStatus | string | yes | – |
| workItemId | string | yes | – |
No output schema declared.
No examples provided.
upload_operating_evidence ~287
Store exact caller-supplied evidence bytes in the active company's private canonical evidence prefix and return the server-computed SHA-256 needed by record_operating_evidence. Use only when the client has supplied the actual base64 file bytes; never invent bytes from a description. Browser/desktop clients should use POST /operating/evidence/upload for files larger than the MCP limit. Prerequisite: authenticated active organization access plus every prerequisite stated above. Canonicality: invokes the shared backend action; trust the returned actual_tool_output and context_engineering instead of adding a state-recovery call. Idempotency: obey the tool-specific retry key or guarantee; if none is stated, inspect refreshed state before retrying. Confirmation boundary: no additional confirmation is needed for this read, reversible save, explicit fact/evidence record, link preparation, plan refresh, or action pre-authorized by a standing founder-configured policy.
| Name | Type | Req | Description |
|---|---|---|---|
| _corply_context | object | – | Echo context_engineering.context_session from the prior Corply result. |
| companyId | string | – | corply_companies.id. May be omitted only when the active organization has exactly one company. |
| contentType | string | – | – |
| dataBase64 | string | yes | Canonical RFC 4648 base64 for the exact file bytes, without a data-URL prefix. |
| fileName | string | yes | – |
No output schema declared.
No examples provided.
upsert_operating_subject ~386
Create or update one durable company-owned subject, including a person, location, product, offering, customer, vendor, contract, equity award, account, or obligation, then freshly resolve the plan. Use a stable externalKey; store decision facts through record_operating_fact, not opaque attributes. Never fabricate personal, immigration, or credential data. Prerequisite: authenticated active organization access plus every prerequisite stated above. Canonicality: invokes the shared backend action; trust the returned actual_tool_output and context_engineering instead of adding a state-recovery call. Idempotency: obey the tool-specific retry key or guarantee; if none is stated, inspect refreshed state before retrying. Confirmation boundary: no additional confirmation is needed for this read, reversible save, explicit fact/evidence record, link preparation, plan refresh, or action pre-authorized by a standing founder-configured policy.
| Name | Type | Req | Description |
|---|---|---|---|
| _corply_context | object | – | Echo context_engineering.context_session from the prior Corply result. |
| attributes | object | – | Allowlisted integration linkage only. Citizenship, visa, tax, ID, health, credential, compensation, and other decision data must be typed facts. |
| companyId | string | – | corply_companies.id. May be omitted only when the active organization has exactly one company. |
| displayName | string | yes | – |
| externalKey | string | yes | Stable caller-controlled identity, e.g. founder:<uuid> or product:billing. |
| itemLimit | integer | yes | Maximum items returned per actionable/blocked/waiting section. |
| linkedUserId | – | – | Owner/operator-only account link for subject-self private access. Omit to preserve; null to unlink. The target must be an active org member. |
| questionLimit | integer | yes | Maximum targeted missing-fact questions returned. |
| status | string | yes | – |
| subjectType | string | yes | – |
No output schema declared.
No examples provided.
validate_application ~190
Validate the formation application and return structured validationIssues whose kind distinguishes absent inputs from saved-but-invalid values. Promotes the formation to 'ready' when complete and returns the server-authoritative standardConfiguration with the canonical nextStep. Prerequisite: authenticated active organization access plus every prerequisite stated above. Canonicality: invokes the shared backend action; trust the returned actual_tool_output and context_engineering instead of adding a state-recovery call. Idempotency: obey the tool-specific retry key or guarantee; if none is stated, inspect refreshed state before retrying. Confirmation boundary: no additional confirmation is needed for this read, reversible save, explicit fact/evidence record, link preparation, plan refresh, or action pre-authorized by a standing founder-configured policy.
| Name | Type | Req | Description |
|---|---|---|---|
| _corply_context | object | – | Echo context_engineering.context_session from the prior Corply result. |
| formationId | string | yes | – |
No output schema declared.
No examples provided.
verify_payment_integration ~281
Inventory caller-reported local/sandbox evidence references against every required Corply Pay control: build/type tests, webhook authenticity/idempotency/out-of-order delivery, subscription lifecycle, deny-by-default entitlements, tenant isolation, return-URL validation, secret scan, and sandbox checkout. This tool reports only whether that caller-supplied inventory is complete; it does not execute or independently attest commands, establish sandbox or production readiness, or make provider calls. Passed/failed results require the exact command and a SHA-256 evidence reference. Evidence inventory completeness NEVER completes KYB/KYC, terms, payout-bank, provider approval, refunds, money movement, migrations, deployment, or production go-live; report those as explicit unverified human/external actions and require fresh founder confirmation for any later live action. Prerequisite: authenticated active organization access plus every prerequisite stated above. Canonicality: reads current server state and does not manufacture company facts. Idempotency: safe to repeat. Confirmation boundary: no additional confirmation is needed for this read, reversible save, explicit fact/evidence record, link preparation, plan refresh, or action pre-authorized by a standing founder-configured policy.
| Name | Type | Req | Description |
|---|---|---|---|
| _corply_context | object | – | Echo context_engineering.context_session from the prior Corply result. |
| checks | array | yes | – |
| manifest | object | yes | – |
No output schema declared.
No examples provided.
whoami ~139
Return the resolved caller identity (user + org). If pendingInvites is non-empty, tell the user and OFFER to join (confirm before redeem_invite). Prerequisite: authenticated active organization access plus every prerequisite stated above. Canonicality: reads current server state and does not manufacture company facts. Idempotency: safe to repeat. Confirmation boundary: no additional confirmation is needed for this read, reversible save, explicit fact/evidence record, link preparation, plan refresh, or action pre-authorized by a standing founder-configured policy.
| Name | Type | Req | Description |
|---|---|---|---|
| _corply_context | object | – | Echo context_engineering.context_session from the prior Corply result. |
No output schema declared.
No examples provided.
What is the Corply — Start and run your company MCP server?
Corply — Start and run your company is an MCP server listed in the public MCP registry as io.github.corply-dev/corply. Form and manage a Delaware C-Corp from your agent. Setup: https://corply.dev/skills.md. This page covers its hosted endpoint (https://corply.dev/mcp).
Is the Corply — Start and run your company MCP server safe to use?
Corply — Start and run your company scores 36 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Corply — Start and run your company MCP server expose?
Corply — Start and run your company exposes 57 tools: get_company_briefing, adopt_existing_company, whoami, get_org, get_status, and 52 more. Their descriptions and schemas cost roughly 15,141 tokens of context every time the server is loaded.
Does the Corply — Start and run your company MCP server require authentication?
Yes. Corply — Start and run your company asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the Corply — Start and run your company MCP server still maintained?
Corply — Start and run your company is still listed as active in the MCP registry. We last reached this channel on 5 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.