Voxcars (Portugal)
REMOTE · WWW.VOXCARS.PT · SCANNED OCT 2
Used-car listings in Portugal: search, price statistics, comparables and articles.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security80
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability52
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 1621 tokens (~270/item across 6 items; 6 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 6 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 6 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities20
- Spec-recency check failed: implements MCP spec 2024-11-05; the latest is 2026-07-28. See how to fix → Fail
How do I install the Voxcars (Portugal) MCP server?
Voxcars (Portugal) is a hosted endpoint at https://www.voxcars.pt/api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · www.voxcars.pt
claude mcp add --transport http eu-voxs-voxcars-pt 'https://www.voxcars.pt/api/mcp'
{
"mcpServers": {
"eu-voxs-voxcars-pt": {
"url": "https://www.voxcars.pt/api/mcp"
}
}
} {
"servers": {
"eu-voxs-voxcars-pt": {
"type": "http",
"url": "https://www.voxcars.pt/api/mcp"
}
}
} [mcp_servers.eu-voxs-voxcars-pt] url = "https://www.voxcars.pt/api/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"eu-voxs-voxcars-pt": {
"type": "remote",
"url": "https://www.voxcars.pt/api/mcp",
"enabled": true
}
}
} openclaw mcp add eu-voxs-voxcars-pt --url 'https://www.voxcars.pt/api/mcp' --transport streamable-http
mcp_servers:
eu-voxs-voxcars-pt:
url: "https://www.voxcars.pt/api/mcp" {
"McpServers": {
"eu-voxs-voxcars-pt": {
"Transport": "http",
"Url": "https://www.voxcars.pt/api/mcp"
}
}
} assistant mcp add eu-voxs-voxcars-pt -t streamable-http -u 'https://www.voxcars.pt/api/mcp'
{
"mcpServers": {
"eu-voxs-voxcars-pt": {
"type": "http",
"url": "https://www.voxcars.pt/api/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 1 Oct 26 0
- Stability: 0.97 → pass security
- 30 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 28 Sept 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 24 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 73 to 77. That category is still filling its 30-day observation window: 22 days of observed history at the previous scan, 23 at this one. The score rises as the window fills, whether or not the server changes.
- 21 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 63 to 67. That category is still filling its 30-day observation window: 19 days of observed history at the previous scan, 20 at this one. The score rises as the window fills, whether or not the server changes.
- 19 Sept 26 +1
- Authorization: unverified → partial ▲ security
- Injection markers: unverified → pass ▲ security
- HSTS header: unverified → pass ▲ security
- Transport: fail → pass ▲ security
- MCP protocol: unverified → fail ▼ functional
- Endpoint reachability: unreachable → reachable ▲ functional
- Tool coverage: unverified → 100 ▲ functional
- Stability: unverified → 0.60 ▲ functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 2 Oct 2026 · Probed https://www.voxcars.pt/api/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=voxcars.pt | CN=WE1,O=Google Trust Services,C=US | 23 Aug 2026 | 21 Nov 2026 | ECDSA 256 | ECDSA-SHA256 | c931d48d7398c0d6136cbdbc029f8fc6 |
| SANs: voxcars.pt, *.voxcars.pt | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of www.voxcars.pt. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| pt. | present | 40155 | 13 | Verified |
| voxcars.pt. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(), geolocation=(), interest-cohort=() |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://www.voxcars.pt/api/mcp | Verified | 200 | |
| http (plaintext) | http://www.voxcars.pt/api/mcp | HTTPS enforced | 302 | https://www.voxcars.pt/api/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
find_similar_cars ~199
Given one listing, find comparable ones: same make, similar year, mileage and price band. Use this when the user likes a car but wants alternatives — 'find me something similar', 'the same but cheaper', 'what else is around this price'. Pass `maxPrice` for the cheaper case; without it, comparables are drawn from a band around the reference price. Comparability is by structure (make/model/year/km/price), not by text similarity: it answers 'is this well priced for what it is', which a keyword search cannot.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | Maximum number of comparables (default 6, max 20). |
| maxPrice | number | – | Optional budget ceiling, in EUR. Use it for 'similar but cheaper'; it overrides the default band around the reference price. |
| slug | string | yes | Slug of the reference listing, as returned by search_cars or get_car_detail. |
| Name | Type | Req | Description |
|---|---|---|---|
| cars | array | yes | – |
| currency | string | – | – |
| market | string | yes | – |
| reference | object | yes | The listing the comparables are measured against, echoed back for the comparison. |
| total | number | yes | Comparables returned. |
No examples provided.
get_car_detail ~73
Get the complete record of one used-car listing in Portugal by its slug. Use this after search_cars when the user asks about a specific car: full description, features, photos, seller, and the original source URL to cite.
| Name | Type | Req | Description |
|---|---|---|---|
| slug | string | yes | Unique listing slug, as returned by search_cars. |
| Name | Type | Req | Description |
|---|---|---|---|
| body | string|null | – | – |
| color | string|null | – | – |
| condition | string|null | – | – |
| currency | string | yes | ISO 4217 code of this market. |
| description | string|null | – | – |
| district | string|null | – | – |
| doors | number|null | – | – |
| engineCc | number|null | – | – |
| features | array | – | – |
| fuel | string|null | – | – |
| km | number|null | – | – |
| make | string | yes | – |
| model | string | yes | – |
| origin | string|null | – | NACIONAL = domestic; IMPORTADO = imported. |
| photos | array | – | Up to 5 image URLs. |
| power_cv | number|null | – | Engine power in metric horsepower (CV/PS). |
| price | number|null | – | null means the source does not publish a price (on request). |
| publishedAt | string | yes | ISO 8601 date the listing was first seen at the source. |
| seats | number|null | – | – |
| sellerType | string|null | – | – |
| slug | string | yes | Stable identifier; pass to get_car_detail or find_similar_cars. |
| source | string|null | – | Aggregator platform the listing came from; null when published directly with us. |
| sourceUrl | string|null | – | Original listing URL at the source. Cite this alongside url. |
| title | string | yes | – |
| transmission | string|null | – | – |
| url | string | yes | Canonical listing page on this market's domain. |
| variant | string|null | – | – |
| year | number|null | – | – |
No examples provided.
get_price_stats ~420
Get price statistics for a slice of the Portugal used-car market: how many listings match, the median price, the p25–p75 range, the median price per kilometre and a breakdown by body type. Use this when the user asks what something costs, whether an asking price is fair, or how two makes compare — instead of listing individual cars. Takes the same filters as search_cars and describes exactly the set that tool would return, so the two never disagree. Reports medians and quartiles rather than averages, because car prices have a long right tail and a single luxury listing moves an average.
| Name | Type | Req | Description |
|---|---|---|---|
| bodyType | string | – | Body style. SEDAN = berlina, HATCHBACK = citadino, COMBI = carrinha, CABRIO = descapotável, MINIVAN = monovolume. |
| condition | string | – | Vehicle condition. new = 0 km / registered this year; semi_new = <2 years and <20 000 km; used = everything else. |
| district | string | – | District or region inside the market (e.g. Lisboa, Porto, Berlin, Madrid). Matched exactly. |
| fuel | string | – | Fuel type. GASOLINE = gasolina, ELECTRIC = eléctrico, HYBRID = full hybrid, PLUG_IN_HYBRID = PHEV. |
| kmMax | number | – | Maximum kilometres on the odometer. |
| make | string | – | Make slug (e.g. toyota, bmw, volkswagen). Not free text — the slug is the same in every market. |
| model | string | – | Model slug (e.g. corolla, serie-3, golf). Requires `make` to disambiguate. |
| priceMax | number | – | Maximum price in the market currency. Listings with no published price are excluded by either bound. |
| priceMin | number | – | Minimum price in the market currency. |
| yearMax | number | – | Maximum registration year. |
| yearMin | number | – | Minimum registration year. |
| Name | Type | Req | Description |
|---|---|---|---|
| byBodyType | array | yes | Up to 6 most represented body types, each with its own median. |
| count | number | yes | Listings matching the filters, with or without a published price. |
| currency | string | yes | – |
| market | string | yes | – |
| price | object|null | – | Price distribution, in percentiles. null when no matching listing publishes a price. There is deliberately no min or max: listings come from third-party sources and the extremes are set by data error… |
| pricePerKmMedian | number|null | – | Median price per kilometre on the odometer, in the listing currency (order of magnitude 0.05–3). Small = the car has done a lot for its price. |
| priced | number | yes | Subset with a published price — the base of every figure below. A large gap to `count` means many listings in this slice are 'price on request'. |
No examples provided.
search_articles ~89
Search editorial articles about the used-car market in Portugal: buying guides, reviews, comparisons and market analysis. Use this when the user asks how something works — financing, warranty, IUC, IPO/ITV, the buying process — rather than asking for listings.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | – | Article category. |
| limit | number | – | Maximum number of results (default 5, max 10). |
| Name | Type | Req | Description |
|---|---|---|---|
| articles | array | yes | – |
No examples provided.
search_cars ~476
Search current used-car listings for sale in Portugal. Use this whenever the user wants to find, compare or explore cars — by make, model, budget, mileage, fuel or district. Returns price, mileage, fuel, body and a citable listing URL, plus `total`: the exact number of listings matching the filters, which makes this tool usable to answer 'how many' questions. Listings are aggregated from stands and portals and refreshed daily; each result carries `publishedAt`. Prefer the broadest filters that answer the question and report `total` as a floor, not a census.
| Name | Type | Req | Description |
|---|---|---|---|
| bodyType | string | – | Body style. SEDAN = berlina, HATCHBACK = citadino, COMBI = carrinha, CABRIO = descapotável, MINIVAN = monovolume. |
| condition | string | – | Vehicle condition. new = 0 km / registered this year; semi_new = <2 years and <20 000 km; used = everything else. |
| district | string | – | District or region inside the market (e.g. Lisboa, Porto, Berlin, Madrid). Matched exactly. |
| fuel | string | – | Fuel type. GASOLINE = gasolina, ELECTRIC = eléctrico, HYBRID = full hybrid, PLUG_IN_HYBRID = PHEV. |
| kmMax | number | – | Maximum kilometres on the odometer. |
| limit | number | – | Results per page (default 10, max 20). |
| make | string | – | Make slug (e.g. toyota, bmw, volkswagen). Not free text — the slug is the same in every market. |
| model | string | – | Model slug (e.g. corolla, serie-3, golf). Requires `make` to disambiguate. |
| page | number | – | 1-based page number. Use with `total` to walk a large result set. |
| priceMax | number | – | Maximum price in the market currency. Listings with no published price are excluded by either bound. |
| priceMin | number | – | Minimum price in the market currency. |
| sort | string | – | Result order. Default `recent` (most recently seen first). |
| yearMax | number | – | Maximum registration year. |
| yearMin | number | – | Minimum registration year. |
| Name | Type | Req | Description |
|---|---|---|---|
| cars | array | yes | – |
| currency | string | yes | – |
| hasMore | boolean | yes | – |
| market | string | yes | ISO country code of this market. |
| page | number | yes | – |
| pageSize | number | – | – |
| shown | number | – | – |
| total | number | yes | Exact number of listings in this market matching the filters, across all pages. |
No examples provided.
search_cars_by_description ~364
Search Portugal listings by describing the car in plain language, matched against listing text by meaning rather than keywords. Use this for wants that are not filter fields — 'a family SUV good in the snow', 'a low-mileage hybrid for the city', 'a used 4x4 to restore'. Prefer search_cars for entirely structural queries (make/model/budget); use this when the request is descriptive. Combine both by passing structural filters here too — they act as hard constraints while the description only ranks. Results are ordered by relevance, so `total` is the number matching the structural filters, not the number that fit the description.
| Name | Type | Req | Description |
|---|---|---|---|
| bodyType | string | – | Body style. SEDAN = berlina, HATCHBACK = citadino, COMBI = carrinha, CABRIO = descapotável, MINIVAN = monovolume. |
| description | string | yes | What the user is looking for, in their own words. Full phrases work better than keywords. Pass the qualities here and the hard limits in the other arguments. |
| fuel | string | – | Fuel type. GASOLINE = gasolina, ELECTRIC = eléctrico, HYBRID = full hybrid, PLUG_IN_HYBRID = PHEV. |
| kmMax | number | – | Maximum kilometres on the odometer. |
| limit | number | – | Maximum number of results (default 10, max 20). |
| make | string | – | Make slug (e.g. toyota, bmw, volkswagen). Not free text — the slug is the same in every market. |
| priceMax | number | – | Maximum price in the market currency. Listings with no published price are excluded by either bound. |
| yearMin | number | – | Minimum registration year. |
| Name | Type | Req | Description |
|---|---|---|---|
| cars | array | yes | Ordered by relevance to the description, most relevant first. |
| currency | string | – | – |
| market | string | yes | – |
| shown | number | yes | – |
| total | number | yes | Listings matching the structural filters. The description narrows the ranking, not this count. |
No examples provided.
What is the Voxcars (Portugal) MCP server?
Voxcars (Portugal) is an MCP server listed in the public MCP registry as eu.voxs/voxcars-pt. Used-car listings in Portugal: search, price statistics, comparables and articles. This page covers its hosted endpoint (https://www.voxcars.pt/api/mcp).
Is the Voxcars (Portugal) MCP server safe to use?
Voxcars (Portugal) scores 80 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Voxcars (Portugal) MCP server expose?
Voxcars (Portugal) exposes 6 tools: search_cars, search_cars_by_description, get_price_stats, find_similar_cars, get_car_detail, search_articles. Their descriptions and schemas cost roughly 1,621 tokens of context every time the server is loaded.
Does the Voxcars (Portugal) MCP server require authentication?
No. We connected to Voxcars (Portugal) without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Voxcars (Portugal) MCP server still maintained?
Voxcars (Portugal) is still listed as active in the MCP registry. We last reached this channel on 2 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.