io.github.cyanheads/oecd-mcp-server
REMOTE · OECD.CASEYJHAND.COM · 2 COMPONENTS · SCANNED SEP 28
Search and query 1,500+ OECD statistical datasets via SDMX. Keyless.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security83
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability71
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1467 tokens (~209/item across 7 items; 7 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 7 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 8 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the io.github.cyanheads/oecd-mcp-server server?
io.github.cyanheads/oecd-mcp-server is a hosted endpoint at https://oecd.caseyjhand.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · oecd.caseyjhand.com
claude mcp add --transport http cyanheads-oecd-mcp-server 'https://oecd.caseyjhand.com/mcp'
{
"mcpServers": {
"cyanheads-oecd-mcp-server": {
"url": "https://oecd.caseyjhand.com/mcp"
}
}
} {
"servers": {
"cyanheads-oecd-mcp-server": {
"type": "http",
"url": "https://oecd.caseyjhand.com/mcp"
}
}
} [mcp_servers.cyanheads-oecd-mcp-server] url = "https://oecd.caseyjhand.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"cyanheads-oecd-mcp-server": {
"type": "remote",
"url": "https://oecd.caseyjhand.com/mcp",
"enabled": true
}
}
} openclaw mcp add cyanheads-oecd-mcp-server --url 'https://oecd.caseyjhand.com/mcp' --transport streamable-http
mcp_servers:
cyanheads-oecd-mcp-server:
url: "https://oecd.caseyjhand.com/mcp" {
"McpServers": {
"cyanheads-oecd-mcp-server": {
"Transport": "http",
"Url": "https://oecd.caseyjhand.com/mcp"
}
}
} assistant mcp add cyanheads-oecd-mcp-server -t streamable-http -u 'https://oecd.caseyjhand.com/mcp'
{
"mcpServers": {
"cyanheads-oecd-mcp-server": {
"type": "http",
"url": "https://oecd.caseyjhand.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 28 Sept 26 +7
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 24 Sept 26 0
- Stability: 0.97 → pass security
- 23 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 21 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.
- 20 Sept 26 0
- Server version: 0.3.1 → 0.3.2 functional
- “oecd_dataframe_query” reworded the description of “canvas_id” cosmetic
- “oecd_query_dataset” reworded the description of “canvas_id” cosmetic
- “oecd_dataframe_describe” reworded the description of “canvas_id” cosmetic
- 19 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 73 to 77. That category is still filling its 30-day observation window: 22 days of observed history at the previous scan, 23 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 28 Sept 2026 · Probed https://oecd.caseyjhand.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=caseyjhand.com | CN=WE1,O=Google Trust Services,C=US | 4 Sept 2026 | 3 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | a6985204ed51ae050e7738aa6be668e9 |
| SANs: caseyjhand.com, *.caseyjhand.com | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC secure
Validation of oecd.caseyjhand.com. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| caseyjhand.com. | present | 2371 | 13 | Verified |
| oecd.caseyjhand.com. | Verified address RRset verified with the apex keys |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
| x-content-type-options | nosniff |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://oecd.caseyjhand.com/mcp | Verified | 200 | |
| http (plaintext) | http://oecd.caseyjhand.com/mcp | HTTPS enforced | 301 | https://oecd.caseyjhand.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
oecd_dataframe_describe Oecd Dataframe Describe ~103
List tables and columns staged on a DataCanvas by a prior oecd_query_dataset spill. Call this before oecd_dataframe_query to discover exact table and column names for SQL. Only available when CANVAS_PROVIDER_TYPE=duckdb is set.
| Name | Type | Req | Description |
|---|---|---|---|
| canvas_id | string | yes | Canvas ID returned by oecd_query_dataset — exactly 10 characters of letters, digits, hyphens, and underscores. Identifies the DataCanvas session holding the staged observation tables. |
| Name | Type | Req | Description |
|---|---|---|---|
| canvas_id | string | – | The canvas ID whose tables are listed. |
| error | object | – | Present when the call failed. Absent on success. |
| table_count | number | – | Total number of tables and views. |
| tables | array | – | Tables and views staged on this canvas. |
No examples provided.
oecd_dataframe_query Oecd Dataframe Query ~163
Run a read-only SQL SELECT against OECD observation tables staged on a DataCanvas by oecd_query_dataset. Call oecd_dataframe_describe first to discover exact table and column names, then use this tool for aggregation, filtering, GROUP BY, JOIN, and window functions. Only available when CANVAS_PROVIDER_TYPE=duckdb is set.
| Name | Type | Req | Description |
|---|---|---|---|
| canvas_id | string | yes | Canvas ID returned by oecd_query_dataset — exactly 10 characters of letters, digits, hyphens, and underscores. Identifies the DataCanvas session holding the observation tables. |
| sql | string | yes | Read-only SELECT statement. Reference tables by the names returned by oecd_dataframe_describe. Only SELECT statements are allowed — DDL, DML, and file-reading functions are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| column_names | array | – | Column names in the result, in order. |
| error | object | – | Present when the call failed. Absent on success. |
| row_count | number | – | Full result count before any row cap. |
| rows | array | – | Result rows from the SQL query (capped at the canvas row limit). |
No examples provided.
oecd_get_dataset_info Oecd Get Dataset Info ~143
Fetch a dataflow's dimensions, their order, and how to construct a query key. Returns per-dimension names, codelist references, and position in the dot-delimited key. Required before calling oecd_query_dataset to understand key structure.
| Name | Type | Req | Description |
|---|---|---|---|
| flow_ref | string | yes | Full flow reference, either {agencyID},{dsd_id}@{df_id} — e.g. "OECD.SDD.NAD,DSD_NAAG@DF_NAAG_I" — or the bare {agencyID},{df_id} form OECD uses for the few dataflows published without a datastructur… |
| Name | Type | Req | Description |
|---|---|---|---|
| dimensions | array | – | Dimensions in ascending position order. |
| error | object | – | Present when the call failed. Absent on success. |
| flow_ref | string | – | The resolved flow reference. |
| key_example | string | – | Example dot-delimited key with wildcards — each dot corresponds to one dimension in position order. Empty segments are wildcards. Replace with actual codes from oecd_get_dimension_values. |
| non_production | boolean | – | True if OECD flagged this dataflow as experimental or deprecated. |
| source | string | – | Data source attribution — always "OECD". |
| time_dimension | object | – | Time dimension — used for startPeriod/endPeriod filtering in oecd_query_dataset. |
No examples provided.
oecd_get_dimension_values Oecd Get Dimension Values ~303
Fetch the valid codes and labels for one dimension of a dataflow. Use to resolve human-readable names (countries, measures) to SDMX codes before querying with oecd_query_dataset. Pass query to match a code or label by substring — codelists run to a thousand-plus entries, and the response is a page of at most limit codes either way.
| Name | Type | Req | Description |
|---|---|---|---|
| dimension_id | string | yes | Dimension identifier to fetch codes for — e.g. "REF_AREA" or "MEASURE". Obtain valid dimension IDs from oecd_get_dataset_info. |
| flow_ref | string | yes | Full flow reference — e.g. "OECD.SDD.NAD,DSD_NAAG@DF_NAAG_I", or the bare "OECD.TAD.ARP,DF_AEI2024_DASHBOARD" form for a dataflow published without a datastructure prefix. Obtain from oecd_search_dat… |
| limit | integer | – | Maximum codes to return (1–500, default 50). |
| offset | integer | – | Zero-based index of the first code to return within the matching list, applied before limit. Advance it to page; an offset past the last match returns an empty page. |
| query | string | – | Case-insensitive substring matched against both the code and its label, so "PA" and "percent" each reach the code "PA" / "Percent per annum". Omit to page the whole codelist. |
| Name | Type | Req | Description |
|---|---|---|---|
| code_count | number | – | Number of codes in this page — not the size of the dimension's codelist. |
| codes | array | – | The requested page of codes, after query, offset, and limit are applied. |
| dimension_id | string | – | The dimension whose codes are listed. |
| effectiveQuery | string | – | The substring filter as applied. Absent when the whole codelist was paged. |
| error | object | – | Present when the call failed. Absent on success. |
| flow_ref | string | – | The flow reference this dimension belongs to. |
| notice | string | – | Present when the page needs explaining — the dimension has no codelist, the query matched nothing, or codes remain beyond the page. States how to reach the rest. |
| source | string | – | Data source attribution — always "OECD". |
| totalCount | number | – | Codes matching before offset and limit, disclosed when the page does not cover them all. |
No examples provided.
oecd_list_agencies Oecd List Agencies ~48
List OECD SDMX agencies, the directorate each belongs to, and the number of dataflows each publishes. Use to discover agency IDs before filtering oecd_search_datasets by department.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| agencies | array | – | Agencies and their dataflow counts, sorted descending by count. |
| error | object | – | Present when the call failed. Absent on success. |
| source | string | – | Data source attribution — always "OECD". |
| total_agencies | number | – | Total number of distinct agencies. |
| total_dataflows | number | – | Total number of dataflows across all agencies. |
No examples provided.
oecd_query_dataset Oecd Query Dataset ~416
Fetch observations from an OECD dataflow filtered by a dimension key and optional time range. Returns decoded rows (one per observation) with dimension and attribute labels, and values already scaled by the observation unit multiplier. Large multi-country time-series spill to a DataCanvas table — follow up with oecd_dataframe_query; without DataCanvas every row still comes back, but the rendered table stops at a preview slice. Call oecd_get_dataset_info first to learn the dimension order for constructing the key.
| Name | Type | Req | Description |
|---|---|---|---|
| canvas_id | string | – | Canvas ID from a prior oecd_query_dataset call — exactly 10 characters of letters, digits, hyphens, and underscores — to stage this result alongside that one. Omit to let the server mint a canvas if… |
| end_period | string | – | End of the time range — ISO period code such as "2023" or "2023-Q4". Omit to include up to the latest available period. |
| flow_ref | string | yes | Full flow reference — e.g. "OECD.SDD.NAD,DSD_NAAG@DF_NAAG_I", or the bare "OECD.TAD.ARP,DF_AEI2024_DASHBOARD" form for a dataflow published without a datastructure prefix. Obtain from oecd_search_dat… |
| key | string | yes | Dot-delimited dimension key matching the dimension order from oecd_get_dataset_info. Empty segments are wildcards; "+" separates multiple values per segment. Example: "A.USA+DEU.B1GQ.." — Annual, USA… |
| start_period | string | – | Start of the time range — ISO period code such as "2010", "2010-Q1", or "2010-01". Omit to include all history (may produce very large results). |
| Name | Type | Req | Description |
|---|---|---|---|
| canvas_id | string | – | Canvas handle for the staged result. Present only when DataCanvas is configured and the result exceeded the inline budget; absent when DataCanvas is off, and absent when it is on but the result fit i… |
| content_table_capped | boolean | – | True when the rendered table shows only the leading rows of the result. Distinct from truncated: nothing was staged anywhere, and structuredContent.rows still holds every row. To shrink the result it… |
| content_table_rows | number | – | Rows the rendered table shows when content_table_capped is true. |
| error | object | – | Present when the call failed. Absent on success. |
| query_end_period | string | – | End period filter applied in this query, if any. |
| query_flow_ref | string | – | Flow reference used in this query. |
| query_key | string | – | Dimension key used in this query. |
| query_start_period | string | – | Start period filter applied in this query, if any. |
| row_count | number | – | Total rows in the result (or on the canvas when truncated). |
| rows | array | – | Observation rows. Every row of the result when truncated is absent; the leading preview slice when truncated is true — query the canvas table for the rest. |
| source | string | – | Data source attribution — always "OECD". |
| table_name | string | – | Canvas table name holding the full result — present when canvas_id is set. |
| truncated | boolean | – | True when rows is a preview slice and the full result was staged on DataCanvas; omitted entirely (never false) when rows holds the complete result. Use oecd_dataframe_query with the canvas_id for ana… |
No examples provided.
oecd_search_datasets Oecd Search Datasets ~192
Search OECD dataflows by keyword or theme, matching against dataflow names and descriptions. Returns flow_ref identifiers, names, and agency IDs for use with oecd_get_dataset_info.
| Name | Type | Req | Description |
|---|---|---|---|
| agency_id | string | – | Optional agency identifier to restrict the search scope — e.g. "OECD.SDD.NAD". Obtain valid agency IDs from oecd_list_agencies. |
| limit | integer | – | Maximum number of results to return (1–100, default 20). |
| offset | integer | – | Zero-based index of the first match to return, applied before limit. Page through results past the limit by advancing it; an offset at or past total_matches returns an empty list. |
| query | string | yes | Keyword or phrase to search for in dataflow names and descriptions — e.g. "GDP", "employment", "education". Every whitespace-separated token must appear somewhere in the name or description. |
| Name | Type | Req | Description |
|---|---|---|---|
| dataflows | array | – | Matching dataflows for the requested page, up to the requested limit. |
| error | object | – | Present when the call failed. Absent on success. |
| offset | number | – | Zero-based index of the first returned result within the full match list. |
| result_count | number | – | Number of results returned (may be less than total_matches). |
| source | string | – | Data source attribution — always "OECD". |
| totalCount | number | – | Total dataflows matching the query, disclosed when matches remain beyond the returned page. |
| total_matches | number | – | Total dataflows matching the query before applying offset and limit. |
No examples provided.
What is the io.github.cyanheads/oecd-mcp-server server?
io.github.cyanheads/oecd-mcp-server is listed in the public MCP registry as io.github.cyanheads/oecd-mcp-server. Search and query 1,500+ OECD statistical datasets via SDMX. Keyless. This page covers its hosted endpoint (https://oecd.caseyjhand.com/mcp).
Is the io.github.cyanheads/oecd-mcp-server server safe to use?
io.github.cyanheads/oecd-mcp-server scores 88 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.cyanheads/oecd-mcp-server server expose?
io.github.cyanheads/oecd-mcp-server exposes 7 tools: oecd_list_agencies, oecd_search_datasets, oecd_get_dataset_info, oecd_get_dimension_values, oecd_query_dataset, and 2 more. Their descriptions and schemas cost roughly 1,368 tokens of context every time the server is loaded.
Does the io.github.cyanheads/oecd-mcp-server server require authentication?
No. We connected to io.github.cyanheads/oecd-mcp-server without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the io.github.cyanheads/oecd-mcp-server server still maintained?
io.github.cyanheads/oecd-mcp-server is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.