agentView
REMOTE · AGENTVIEW.DE · SCANNED AUG 3
Display delivery platform for AI agents. Push HTML, dashboards and live data to screens.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (assign_display_categories). See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability72
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 10067 tokens (~141/item across 71 items; 57 tools + 14 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
- Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage99
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 97% of tool parameters carry a description.Partial
- Structured output schemas are declared (54% of tools); any adoption earns full credit.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
- Supports UI / widget rendering.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · agentview.de
claude mcp add --transport http de-agentview-agentview-mcp https://agentview.de/mcp
[mcp_servers.de-agentview-agentview-mcp] url = "https://agentview.de/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"de-agentview-agentview-mcp": {
"type": "remote",
"url": "https://agentview.de/mcp",
"enabled": true
}
}
} openclaw mcp add de-agentview-agentview-mcp --url https://agentview.de/mcp --transport streamable-http
mcp_servers:
de-agentview-agentview-mcp:
url: "https://agentview.de/mcp" {
"mcpServers": {
"de-agentview-agentview-mcp": {
"type": "http",
"url": "https://agentview.de/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.
- 1 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.
- 31 Jul 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 29 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.
- 28 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 64
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://agentview.de/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=agentview.de | CN=YE1,O=Let's Encrypt,C=US | 11 Jul 2026 | 9 Oct 2026 | ECDSA 256 | ECDSA-SHA384 | 552531b588214398b86c25b313d8e7a515d |
| SANs: agentview.de | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
DNSSEC insecure
Validation of agentview.de. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| de. | present | 26755 | 8 | Verified |
| agentview.de. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains; preload |
| content-security-policy | default-src 'self'; script-src 'self' 'unsafe-inline' https://www.googletagmanager.com https://cdn.paddle.com; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https:; connect-src 'self' https://www.google-analytics.com https://region1.google-analytics.com https://www.googletagmanager.com https://*.paddle.com; font-src 'self' data:; frame-src 'self' https://display.agentview.de https://content.agentview.de https://*.paddle.com; base-uri 'self'; frame-ancestors 'none'; object-src 'none'; |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(), geolocation=() |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://agentview.de/mcp | Verified | 200 | |
| http (plaintext) | http://agentview.de/mcp | HTTPS enforced | 308 | https://agentview.de/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
search Search Resources ~173
Searches agentView resources by keyword: documentation, server status, your account, your displays and the API catalog. Returns ranked resource URIs with snippets to read via fetch. Unauthenticated searches cover public docs only. Skip when you already know the URI — call fetch directly.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | — | Maximum number of results to return. Integer between 1 and 20 inclusive. Defaults to 5. |
| query | string | — | Free-text search terms. Examples: a display name, 'account', 'OAuth', 'status'. At least one of query or resource_type should be provided. |
| resource_type | string | — | Restricts results to a specific resource category. Must be one of: 'all', 'documentation', 'status', 'account', 'display', 'api'. Defaults to 'all' when omitted. |
| Name | Type | Req | Description |
|---|---|---|---|
| count | integer|null | — | — |
| query | string|null | — | — |
| resourceType | string|null | — | — |
| results | array|null | — | — |
No examples provided.
search_public_apis Search Public APIs ~207
Searches a curated catalog of 600+ free public APIs (no key, HTTPS) for embedding live data in display HTML via fetch(): weather, news, finance, sports, images, food and 40+ more categories. Use when generating HTML that needs live internet data. Set list_categories=true to get the category menu with counts instead of search results. Returns docs links, CORS status and fetch() hints. No authentication required.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | — | Category ID filter, e.g. 'weather', 'finance', 'news'. Omit for all. |
| cors_only | boolean | — | true returns only APIs with confirmed browser CORS support. Default false. |
| limit | integer | — | Maximum results, 1-20. Default 10. |
| list_categories | boolean | — | true returns all categories with API counts instead of search results. |
| query | string | — | Free-text search, e.g. 'weather forecast', 'bitcoin price', 'jokes'. |
| Name | Type | Req | Description |
|---|---|---|---|
| categories | array|null | — | — |
| category | string|null | — | — |
| corsOnly | boolean|null | — | — |
| count | integer|null | — | — |
| query | string|null | — | — |
| results | array|null | — | — |
| totalCatalogApis | integer|null | — | — |
No examples provided.
search_store_templates Search Store Templates ~233
Searches the agentView template store for ready-made display designs ('Zahnarzt-Wartezimmer', 'Bistro', 'reception', ...). Use when the user wants a polished pre-built design instead of generated HTML; results render as a gallery widget. Filter by category, suite and language; paginate with limit/offset. Follow up with get_store_template_details. No authentication required.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | — | Optional category slug to restrict the search (English kebab-case, e.g. 'gastronomie', 'waiting-room'). |
| language | string | — | Preferred content language. Defaults to 'en'. |
| limit | integer | — | Maximum number of templates to return. Defaults to 10. |
| offset | integer | — | Offset into the filtered result set for pagination. Defaults to 0. |
| query | string | — | Free-text search over template title, description and tags. Examples: 'Zahnarzt', 'italienisches Bistro', 'conference room'. |
| suite | string | — | Optional design-family suite slug (e.g. 'bistro-warm', 'sushi-minimal'). |
| Name | Type | Req | Description |
|---|---|---|---|
| language | string|null | — | — |
| limit | integer|null | — | — |
| offset | integer|null | — | — |
| templates | array|null | — | — |
| total | integer|null | — | — |
No examples provided.
send_html Send HTML ~347
Shows HTML content on a display: menus, dashboards, welcome pages, schedules or any custom design. slot 'live' (default) replaces the current content; slot 'idle' stores the default/fallback content shown when nothing live is active (idle requires admin scope). Always pass a short description so later content reads stay meaningful. Exactly one of html or base64_html. For external web pages use send_url; to edit current content call read_display_html first. For polished results load prompt render_premium_display_html or resource agentview://public/design-system. Requires content scope.
| Name | Type | Req | Description |
|---|---|---|---|
| access_token | string | — | Optional bearer token; prefer session_request_id. Distinct from the display-specific 'token'. |
| base64_html | string | — | Base64-encoded HTML (standard base64). Use only when raw HTML cannot survive JSON transport. Mutually exclusive with html. |
| description | string | yes | Short human-readable summary of the content, e.g. 'Weekly KPI dashboard'. |
| display_id | string | yes | 8-character display profile ID, e.g. 'ABCD1234'. |
| duration | integer | — | Seconds the content stays; 0 = indefinite (default). Live slot only. |
| html | string | — | Complete HTML document to render. Mutually exclusive with base64_html. |
| session_request_id | string | — | Session handle from create_auth_session; pass it on every authenticated call. |
| slot | string | — | Target slot: 'live' (default) replaces current content; 'idle' sets the default shown when idle (admin scope). |
| token | string | — | Display-specific demo/preview token for unauthenticated access. NOT the OAuth token. |
No output schema declared.
No examples provided.
send_store_template_to_display Send Store Template to Display ~386
Installs a published store template onto a display: materializes the HTML, auto-creates required data slots (reusing prior installs) and publishes within seconds. Call get_store_template_install_options first for valid targets and slots; customize per-slot JSON inline via data_slot_overrides (raw JSON string or inline object per key, max 64 KiB each). Requires content scope and control access to the display.
| Name | Type | Req | Description |
|---|---|---|---|
| access_token | string | — | Optional bearer token; prefer session_request_id. |
| data_slot_overrides | object | — | Optional { key: value } map keyed by data-slot key (see requiredDataSlots). Each value is JSON payload to install into that slot — either a string of raw JSON or an inline object/array. Unknown keys… |
| display_id | string | yes | Display profile ID (8-char alphanumeric) from list_displays or get_store_template_install_options. |
| idempotency_key | string | — | Optional opaque key (max 128 chars) to make this install retry-safe. If a previous successful install for the same (user, display, idempotency_key) tuple exists within 24 hours, the cached result is… |
| session_request_id | string | — | Session handle from create_auth_session; pass it on every authenticated call. |
| slug | string | yes | Template slug to install, e.g. 'bistro-warm-door'. Must be a currently published template. |
| Name | Type | Req | Description |
|---|---|---|---|
| contentVersionId | string|null | — | — |
| displayId | string|null | — | — |
| fileName | string|null | — | — |
| installedSlots | array|null | — | — |
| overrideCount | integer|null | — | — |
| templateSlug | string|null | — | — |
| versionId | string|null | — | — |
No examples provided.
send_url Send URL ~250
Shows an external web page on a display via full-page iframe: dashboards, websites or web apps. slot 'live' (default) replaces current content; slot 'idle' stores it as default/fallback content (admin scope). The URL must be absolute HTTP(S). Check get_display (response_format 'detailed') first when unsure about connectivity or embedding limits. If the page design is not display-ready, prefer send_html with generated content. Requires content scope.
| Name | Type | Req | Description |
|---|---|---|---|
| access_token | string | — | Optional bearer token; prefer session_request_id. |
| content_description | string | — | Short summary of what the page shows (recommended). |
| display_id | string | yes | 8-character display profile ID, e.g. 'ABCD1234'. |
| duration | integer | — | Seconds the content stays; 0 = indefinite (default). Live slot only. |
| session_request_id | string | — | Session handle from create_auth_session; pass it on every authenticated call. |
| slot | string | — | 'live' (default) or 'idle' for default/fallback content (admin scope). |
| url | string | yes | Absolute HTTP or HTTPS URL to load, e.g. 'https://example.com/dashboard'. |
No output schema declared.
No examples provided.
set_data_slot Set Data Slot ~336
Creates or updates a mutable JSON data slot (max 2 MB) that display HTML fetches via its readUrl — the live-data backbone for store templates. The slug is stable; reusing it updates in place. type 'value' stores JSON verbatim; 'aggregate' composes up to 32 sources ({slot:'name'} or one {prefixMatch:'agent-'}) within the same personal/group scope. Requires content scope. Returns slug, readUrl and size.
| Name | Type | Req | Description |
|---|---|---|---|
| access_token | string | — | Optional bearer token; prefer session_request_id. |
| content | — | yes | JSON content to store. For value slots: any valid JSON value up to 2 MB. For aggregate slots: a definition object { sources: [{slot,as?} | {prefixMatch}], onMissing?, onInvalidJson?, includeMeta?, st… |
| group_id | string | — | Group/organization ID for shared group slots. Omit for personal slots. |
| label | string | — | Human-readable label (max 200 chars). Required when creating a new slot; optional on update. |
| slug | string | yes | Stable slug for the data slot. Must match ^[A-Za-z0-9_-]{8,64}$. Same slug on a later call updates the existing slot. Slug stays exactly as supplied; the public URL uses a separate server-generated P… |
| type | string | — | Slot kind. 'value' (default) stores 'content' verbatim. 'aggregate' stores 'content' as a composite-slot definition. Immutable after creation. |
| Name | Type | Req | Description |
|---|---|---|---|
| groupId | string|null | — | — |
| label | string|null | — | — |
| readUrl | string|null | — | — |
| sizeBytes | integer|null | — | — |
| slug | string|null | — | — |
| type | string|null | — | — |
| updatedAt | string|null | — | — |
No examples provided.
set_display_grant Set Display Grant ~187
Grants or revokes a member's access to one display inside an organization. action 'set' (default) creates/updates the grant with access_level 'view' (see status) or 'control' (send content); action 'remove' revokes it. The target user must be an organization member. Requires admin scope.
| Name | Type | Req | Description |
|---|---|---|---|
| access_level | string | — | Required for action 'set'. |
| access_token | string | — | Optional bearer token; prefer session_request_id. |
| action | string | — | 'set' (default) creates/updates the grant; 'remove' revokes it. |
| display_id | string | yes | Display profile ID. |
| org_id | string | yes | Organization ID. |
| session_request_id | string | — | Session handle from create_auth_session; pass it on every authenticated call. |
| target_user_id | string | yes | User to grant or revoke. |
No output schema declared.
No examples provided.
submit_feedback Submit Feedback ~154
Sends the user's feedback, feature request or bug report about agentView itself (not display content) for later review. Confirm the exact wording with the user before sending; optional sentiment. There is no automatic reply. Requires content scope.
| Name | Type | Req | Description |
|---|---|---|---|
| access_token | string | — | Optional bearer token; prefer session_request_id. |
| message | string | yes | The user's verbatim feedback text (max 2000 characters). Pass what the user actually said; do not paraphrase or add your own commentary. |
| sentiment | string | — | Optional overall sentiment of the feedback. Set only when the user's tone is clear; omit if unsure. |
| session_request_id | string | — | Session handle from create_auth_session; pass it on every authenticated call. |
No output schema declared.
No examples provided.
test_display_content Test Display Content ~176
Dry-run validator for generated HTML: runs agentView's size and description checks WITHOUT touching a real display. Use after composing complex HTML and before send_html or broadcast_content. No display_id needed; the response carries simulated=true. Capped at 1 MB. Requires authentication.
| Name | Type | Req | Description |
|---|---|---|---|
| access_token | string | — | Optional bearer token; prefer session_request_id. |
| base64_html | string | — | Base64-encoded HTML payload. Mutually exclusive with html. |
| description | string | yes | Short human-readable description of what the HTML represents (1-1000 chars). Same validation rules as send_html. |
| html | string | — | Complete HTML document to validate. Mutually exclusive with base64_html — provide exactly one. |
| session_request_id | string | — | Session handle from create_auth_session; pass it on every authenticated call. |
No output schema declared.
No examples provided.
update_asset Update Asset ~98
Updates the name and/or description of an existing asset. The URL does not change. At least one of name or description must be provided. Requires authentication with at least content_only scope.
| Name | Type | Req | Description |
|---|---|---|---|
| access_token | string | — | Optional bearer token; prefer session_request_id. |
| asset_id | string | yes | The asset ID to update. |
| description | string | — | New description for the asset. |
| name | string | — | New filename for the asset. |
No output schema declared.
No examples provided.
upload_asset Upload Asset ~152
Upload one or more files (images, fonts, CSS, video, etc.) as assets and receive stable URLs. Use these URLs in your HTML with <img src> or @font-face. Assets are cached on displays. Pass files as base64-encoded data. Requires authentication with at least content_only scope.
| Name | Type | Req | Description |
|---|---|---|---|
| access_token | string | — | Optional bearer token; prefer session_request_id. |
| descriptions | object | yes | JSON object mapping each filename to a human-readable description. |
| files | array | yes | Array of file objects, each with 'name' (filename with extension) and 'data' (base64-encoded content). |
| group_id | string | — | Optional group ID to associate the assets with. |
| Name | Type | Req | Description |
|---|---|---|---|
| assets | array|null | — | — |
| count | integer|null | — | — |
No examples provided.