io.github.cyanheads/faa-aircraft-registry-mcp-server
REMOTE · FAA-AIRCRAFT-REGISTRY.CASEYJHAND.COM · 2 COMPONENTS · SCANNED SEP 28
Offline, keyless lookup of the US civil aircraft registry — decode N-numbers, search records.
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security83
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability69
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1146 tokens (~229/item across 5 items; 5 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 5 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 6 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the io.github.cyanheads/faa-aircraft-registry-mcp-server server?
io.github.cyanheads/faa-aircraft-registry-mcp-server is a hosted endpoint at https://faa-aircraft-registry.caseyjhand.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · faa-aircraft-registry.caseyjhand.com
claude mcp add --transport http cyanheads-faa-aircraft-registry-mcp-server 'https://faa-aircraft-registry.caseyjhand.com/mcp'
{
"mcpServers": {
"cyanheads-faa-aircraft-registry-mcp-server": {
"url": "https://faa-aircraft-registry.caseyjhand.com/mcp"
}
}
} {
"servers": {
"cyanheads-faa-aircraft-registry-mcp-server": {
"type": "http",
"url": "https://faa-aircraft-registry.caseyjhand.com/mcp"
}
}
} [mcp_servers.cyanheads-faa-aircraft-registry-mcp-server] url = "https://faa-aircraft-registry.caseyjhand.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"cyanheads-faa-aircraft-registry-mcp-server": {
"type": "remote",
"url": "https://faa-aircraft-registry.caseyjhand.com/mcp",
"enabled": true
}
}
} openclaw mcp add cyanheads-faa-aircraft-registry-mcp-server --url 'https://faa-aircraft-registry.caseyjhand.com/mcp' --transport streamable-http
mcp_servers:
cyanheads-faa-aircraft-registry-mcp-server:
url: "https://faa-aircraft-registry.caseyjhand.com/mcp" {
"McpServers": {
"cyanheads-faa-aircraft-registry-mcp-server": {
"Transport": "http",
"Url": "https://faa-aircraft-registry.caseyjhand.com/mcp"
}
}
} assistant mcp add cyanheads-faa-aircraft-registry-mcp-server -t streamable-http -u 'https://faa-aircraft-registry.caseyjhand.com/mcp'
{
"mcpServers": {
"cyanheads-faa-aircraft-registry-mcp-server": {
"type": "http",
"url": "https://faa-aircraft-registry.caseyjhand.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 28 Sept 26 +7
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 20 Sept 26 0
- Server version: 0.1.8 → 0.1.9 functional
- 9 Sept 26 +1
- Stability: 0.97 → pass security
- 7 Sept 26 −1
- Stability: pass → 0.93 functional
- 26 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 0
- Stability: 0.97 → pass security
- Tool “faa_get_registration_status” rewrote its description, which is the text the model reads security
- Tool “faa_search_registrations” rewrote its description, which is the text the model reads security
- Tool “faa_search_aircraft_types” rewrote its description, which is the text the model reads security
- Tool “faa_lookup_registration” rewrote its description, which is the text the model reads security
- Tool “faa_get_aircraft_type” rewrote its description, which is the text the model reads security
- MCP protocol: Implements a current MCP spec version (2026-07-28). functional
- MCP protocol version: 2025-11-25 → 2026-07-28 functional
- Server version: 0.1.7 → 0.1.8 functional
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 28 Sept 2026 · Probed https://faa-aircraft-registry.caseyjhand.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=caseyjhand.com | CN=WE1,O=Google Trust Services,C=US | 4 Sept 2026 | 3 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | a6985204ed51ae050e7738aa6be668e9 |
| SANs: caseyjhand.com, *.caseyjhand.com | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC secure
Validation of faa-aircraft-registry.caseyjhand.com. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| caseyjhand.com. | present | 2371 | 13 | Verified |
| faa-aircraft-registry.caseyjhand.com. | Verified address RRset verified with the apex keys |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
| x-content-type-options | nosniff |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://faa-aircraft-registry.caseyjhand.com/mcp | Verified | 200 | |
| http (plaintext) | http://faa-aircraft-registry.caseyjhand.com/mcp | HTTPS enforced | 301 | https://faa-aircraft-registry.caseyjhand.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
faa_get_aircraft_type faa-aircraft-registry-mcp-server: get aircraft type ~122
Decode a 7-character FAA manufacturer/model/series code to aircraft specifications — manufacturer, model, aircraft category, aircraft type, engine type, number of engines, number of seats, weight class, cruise speed, and type-certificate data sheet/holder. Use faa_search_aircraft_types first to discover a code by manufacturer or model name.
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | yes | Manufacturer/model/series code (e.g. "2072714") — 6–7 uppercase alphanumeric characters, usually 7. Discover codes via faa_search_aircraft_types. |
| Name | Type | Req | Description |
|---|---|---|---|
| aircraftType | object | – | Aircraft type as code + label. |
| builderCertification | object | – | Builder certification (Type Certificated, Not Type Certificated, Light Sport) as code + label. |
| category | object | – | Aircraft category (Land, Sea, Amphibian) as code + label. |
| code | string | – | The 7-char manufacturer/model/series code. |
| cruiseSpeedMph | number | – | Cruise speed in mph; often blank (permissible field). |
| engineType | object | – | Engine type as code + label. |
| error | object | – | Present when the call failed. Absent on success. |
| manufacturer | string | – | Aircraft manufacturer name. |
| model | string | – | Aircraft model name. |
| numberOfEngines | number | – | Number of engines; may be blank on the reference record. |
| numberOfSeats | number | – | Number of seats; may be blank on the reference record. |
| typeCertificateDataHolder | string | – | Type-certificate data holder. |
| typeCertificateDataSheet | string | – | Type-certificate data sheet identifier. |
| weightClass | string | – | Weight class as the literal FAA string (e.g. "CLASS 1"). |
No examples provided.
faa_get_registration_status faa-aircraft-registry-mcp-server: get registration status ~153
Resolve whether a US civil aircraft N-number is active, deregistered, reserved, or unknown, including the available registration and airworthiness status. Use this rather than faa_lookup_registration when a number may be inactive. A number that was never issued returns recordType "unknown" — a valid, informative answer, not an error. Accepts "N12345" or "12345".
| Name | Type | Req | Description |
|---|---|---|---|
| nNumber | string | yes | US registration N-number to resolve. Accepts "N12345" or "12345" (leading N optional). Shape: 1–5 characters — a leading digit 1–9, then digits, optionally ending in 1–2 letters (I and O are unused). |
| Name | Type | Req | Description |
|---|---|---|---|
| airworthinessClass | object | – | Airworthiness classification as code + label (active records). |
| airworthinessDate | string | – | Airworthiness certificate date, YYYY-MM-DD (active records). |
| cancelDate | string | – | Cancellation date, YYYY-MM-DD (deregistered records). |
| certIssueDate | string | – | Certificate issue date, YYYY-MM-DD (active records). |
| error | object | – | Present when the call failed. Absent on success. |
| expirationDate | string | – | Registration expiration date, YYYY-MM-DD (active records). |
| expirationNoticeDate | string | – | Date an expiration notice was sent, YYYY-MM-DD (reserved records). |
| manufacturerModelCode | string | – | 7-char manufacturer/model/series code (deregistered records). |
| modeSCodeHex | string | – | Mode S code in hex / ICAO 24-bit address (deregistered records). |
| nNumber | string | – | Normalized N-number without the leading "N". |
| nNumberDisplay | string | – | N-number with the leading "N" for display. |
| nNumberForChange | string | – | The N-number this reservation changes to/from (reserved records). |
| purgeDate | string | – | Scheduled purge date, YYYY-MM-DD (reserved records). |
| recordType | string | – | Resolved registration state: active, deregistered, reserved, or unknown. |
| reserveDate | string | – | Date the number was reserved, YYYY-MM-DD (reserved records). |
| serialNumber | string | – | Manufacturer serial number (deregistered records). |
| status | object | – | Registration/cancellation status as code + label (active and deregistered records). |
| typeReservation | object | – | Type of reservation as code + label (reserved records). |
No examples provided.
faa_lookup_registration faa-aircraft-registry-mcp-server: lookup registration ~187
Decode one US civil aircraft N-number to its full registration record — aircraft make/model, engine, year manufactured, airworthiness, registration status, Mode S (ICAO 24-bit) code, and registered owner (when owner-PII redaction is off). Accepts "N12345" or "12345" (the leading N is optional). Returns ownerRedacted: true when owner details were withheld. A number that is known but inactive (deregistered or reserved) is not found here — use faa_get_registration_status for its current state.
| Name | Type | Req | Description |
|---|---|---|---|
| nNumber | string | yes | US registration N-number to decode. Accepts "N12345" or "12345" (leading N optional). Shape: 1–5 characters — a leading digit 1–9, then digits, optionally ending in 1–2 letters (I and O are unused). |
| Name | Type | Req | Description |
|---|---|---|---|
| aircraftType | object | – | Aircraft type (e.g. Fixed-wing single-engine) as code + label. |
| airworthinessClass | object | – | Airworthiness classification (Standard, Experimental, …) from CERTIFICATION char 1, as code + label. |
| airworthinessDate | string | – | Airworthiness certificate date (YYYY-MM-DD). |
| approvedOperationsRaw | string | – | Raw FAA approved-operations sub-code string; interpretation varies by airworthiness class. |
| certIssueDate | string | – | Certificate issue date (YYYY-MM-DD). |
| engineMake | string | – | Engine manufacturer name. |
| engineManufacturerModelCode | string | – | 5-char engine manufacturer/model code. |
| engineModel | string | – | Engine model name. |
| engineType | object | – | Engine type (e.g. Reciprocating, Turbo-fan) as code + label. |
| error | object | – | Present when the call failed. Absent on success. |
| expirationDate | string | – | Registration expiration date (YYYY-MM-DD). |
| fractionalOwner | boolean | – | True when the aircraft is under fractional ownership. |
| kitManufacturer | string | – | Kit manufacturer (amateur-built aircraft); often blank. |
| kitModel | string | – | Kit model (amateur-built aircraft); often blank. |
| lastActionDate | string | – | Date of the last registration action (YYYY-MM-DD). |
| make | string | – | Aircraft manufacturer name. |
| manufacturerModelCode | string | – | 7-char manufacturer/model/series code. |
| modeSCodeHex | string | – | Mode S code in hex — the ICAO 24-bit address used to key live flight-tracking data. |
| modeSCodeOctal | string | – | Mode S transponder code in octal. |
| model | string | – | Aircraft model name. |
| nNumber | string | – | Normalized N-number without the leading "N" (the registry storage form). |
| nNumberDisplay | string | – | N-number in conventional display form, with the leading "N". |
| owner | object | – | Registrant name/address; present only when redaction is off. |
| ownerRedacted | boolean | – | True when owner name/address were withheld from this payload by the redaction gate. |
| region | object | – | Registrant's FAA region as code + label. |
| serialNumber | string | – | Manufacturer serial number. |
| status | object | – | Registration status (e.g. Valid registration) as code + label. |
| uniqueId | string | – | FAA unique aircraft identifier. |
| yearManufactured | number | – | Year the aircraft was manufactured; often blank (permissible field). |
No examples provided.
faa_search_aircraft_types faa-aircraft-registry-mcp-server: search aircraft types ~220
Search FAA aircraft types by manufacturer/model name, aircraft type code, or category code to discover 7-character manufacturer/model/series codes and browse specifications. Use this before faa_get_aircraft_type to find a code by name. At least one filter is required. Every response reports totalCount (all matches, not just this page); when more remain, it returns nextOffset — pass it back as offset to page forward.
| Name | Type | Req | Description |
|---|---|---|---|
| aircraftType | string | – | Aircraft type code to match exactly (e.g. "6" for rotorcraft). |
| category | string | – | Aircraft category code to match exactly (1 Land, 2 Sea, 3 Amphibian). |
| limit | integer | – | Maximum number of results to return (1–200, default 25). |
| offset | integer | – | Zero-based index of the first result to return — pass the nextOffset from a previous response, with identical filters, to page forward (default 0). |
| query | string | – | Manufacturer and/or model name to match (full-text). |
| Name | Type | Req | Description |
|---|---|---|---|
| aircraftTypes | array | – | Matching aircraft-reference summaries for this page (up to limit). |
| cap | number | – | The limit that was applied (present only when truncated is set). |
| error | object | – | Present when the call failed. Absent on success. |
| nextOffset | number | – | Offset to request the next page; absent when this page reached the end of the matches. |
| notice | string | – | Guidance when no aircraft types matched, or when more matches remain. |
| shown | number | – | Number of results on this page (present only when truncated is set). |
| totalCount | number | – | Total aircraft types matching the filters, across all pages. Always present. |
| truncated | boolean | – | Present and true only when matches remain beyond this page. |
No examples provided.
faa_search_registrations faa-aircraft-registry-mcp-server: search registrations ~292
Search active US civil aircraft registrations by owner name, make/model, state, aircraft type, or Mode S (hex) code. Returns decoded summaries with N-numbers to drill into via faa_lookup_registration. At least one filter is required. Owner-name search is unavailable when this deployment redacts owner PII — search by make/model, state, aircraft type, or Mode S code instead. Every response reports totalCount (all matches, not just this page); when more remain, it returns nextOffset — pass it back as offset to page forward.
| Name | Type | Req | Description |
|---|---|---|---|
| aircraftType | string | – | Aircraft type code to match exactly (e.g. "4" for fixed-wing single-engine). |
| limit | integer | – | Maximum number of results to return (1–200, default 25). |
| makeModel | string | – | Aircraft make and/or model to match (full-text). |
| modeSCode | string | – | Mode S code in hex to match exactly (ICAO 24-bit address). |
| offset | integer | – | Zero-based index of the first result to return — pass the nextOffset from a previous response, with identical filters, to page forward (default 0). |
| ownerName | string | – | Registrant name to match (full-text). Rejected when owner-PII redaction is on. |
| state | string | – | Two-letter state/territory abbreviation (exact match). |
| Name | Type | Req | Description |
|---|---|---|---|
| cap | number | – | The limit that was applied (present only when truncated is set). |
| error | object | – | Present when the call failed. Absent on success. |
| nextOffset | number | – | Offset to request the next page; absent when this page reached the end of the matches. |
| notice | string | – | Guidance when no registrations matched, or when more matches remain. |
| registrations | array | – | Matching registration summaries for this page (up to limit). |
| shown | number | – | Number of results on this page (present only when truncated is set). |
| totalCount | number | – | Total registrations matching the filters, across all pages. Always present. |
| truncated | boolean | – | Present and true only when matches remain beyond this page. |
No examples provided.
What is the io.github.cyanheads/faa-aircraft-registry-mcp-server server?
io.github.cyanheads/faa-aircraft-registry-mcp-server is listed in the public MCP registry as io.github.cyanheads/faa-aircraft-registry-mcp-server. Offline, keyless lookup of the US civil aircraft registry, decode N-numbers, search records. This page covers its hosted endpoint (https://faa-aircraft-registry.caseyjhand.com/mcp).
Is the io.github.cyanheads/faa-aircraft-registry-mcp-server server safe to use?
io.github.cyanheads/faa-aircraft-registry-mcp-server scores 88 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.cyanheads/faa-aircraft-registry-mcp-server server expose?
io.github.cyanheads/faa-aircraft-registry-mcp-server exposes 5 tools: faa_lookup_registration, faa_get_aircraft_type, faa_search_registrations, faa_search_aircraft_types, faa_get_registration_status. Their descriptions and schemas cost roughly 974 tokens of context every time the server is loaded.
Does the io.github.cyanheads/faa-aircraft-registry-mcp-server server require authentication?
No. We connected to io.github.cyanheads/faa-aircraft-registry-mcp-server without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the io.github.cyanheads/faa-aircraft-registry-mcp-server server still maintained?
io.github.cyanheads/faa-aircraft-registry-mcp-server is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.