global.rootz.cars/marketplace
REMOTE · CARS.ROOTZ.GLOBAL · SCANNED SEP 27
AI-native used car marketplace. 145K+ vehicles, 4300+ dealers, 13 US states, 20 MCP tools.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security60
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not yet verified: we couldn't confirm whether this endpoint requires it. View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS not yet verified: we couldn't read the response headers to check for it. View diagnostics → Unverified
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability0
- Transport check failed: declared streamable-http, but we couldn't connect to verify it. See how to fix → View diagnostics → Fail
Schema Quality & AI Usability0
- Schema not yet verified: we couldn't read the endpoint's schema, or could read only part of its tool list.Unverified
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage0
- Tool coverage not yet verified: we couldn't read the endpoint's tools, or could read only part of the list.Unverified
Tool Safety0
- Tool safety not yet verified: we couldn't read the endpoint's tools, or could read only part of the list.Unverified
Capabilities0
- Capabilities not yet verified: we couldn't read the endpoint's capabilities.Unverified
Unverified: 5 categories
Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.
How do I install the global.rootz.cars/marketplace MCP server?
global.rootz.cars/marketplace is a hosted endpoint at https://cars.rootz.global/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · cars.rootz.global
claude mcp add --transport http global-rootz-cars-marketplace 'https://cars.rootz.global/mcp'
{
"mcpServers": {
"global-rootz-cars-marketplace": {
"url": "https://cars.rootz.global/mcp"
}
}
} {
"servers": {
"global-rootz-cars-marketplace": {
"type": "http",
"url": "https://cars.rootz.global/mcp"
}
}
} [mcp_servers.global-rootz-cars-marketplace] url = "https://cars.rootz.global/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"global-rootz-cars-marketplace": {
"type": "remote",
"url": "https://cars.rootz.global/mcp",
"enabled": true
}
}
} openclaw mcp add global-rootz-cars-marketplace --url 'https://cars.rootz.global/mcp' --transport streamable-http
mcp_servers:
global-rootz-cars-marketplace:
url: "https://cars.rootz.global/mcp" {
"McpServers": {
"global-rootz-cars-marketplace": {
"Transport": "http",
"Url": "https://cars.rootz.global/mcp"
}
}
} assistant mcp add global-rootz-cars-marketplace -t streamable-http -u 'https://cars.rootz.global/mcp'
{
"mcpServers": {
"global-rootz-cars-marketplace": {
"type": "http",
"url": "https://cars.rootz.global/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 27 Sept 26 0
- Endpoint reachability: reachable → unreachable ▼ security
- HSTS header: fail → unverified ▼ security
- Stability: 0.93 → unverified ▼ security
- Tool safety: pass → unverified ▼ security
- Transport: pass → fail ▼ security
- Authorization: Authorisation not yet verified: we couldn't confirm whether this endpoint requires it. security
- Capabilities: fail → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- 26 Sept 26 +14
- HSTS header: unverified → fail ▼ security
- Injection markers: unverified → pass ▲ security
- Transport: fail → pass ▲ security
- Authorization: Authorisation not fully verified: no authorisation is required to call this server, and 19 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. security
- MCP protocol: unverified → fail ▼ functional
- Endpoint reachability: unreachable → reachable ▲ functional
- Tool coverage: unverified → 100 ▲ functional
- Stability: unverified → 0.93 ▲ functional
- 25 Sept 26 −15
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 23 Sept 26 0
- Endpoint reachability: reachable → unreachable ▼ security
- Stability: pass → unverified ▼ security
- Tool safety: pass → unverified ▼ security
- Transport: pass → fail ▼ security
- Capabilities: fail → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- 22 Sept 26 0
- HSTS header: fail → unverified ▼ security
- Authorization: Authorisation not yet verified: we couldn't confirm whether this endpoint requires it. security
- 17 Sept 26 0
- HSTS header: unverified → fail ▼ security
- Injection markers: unverified → pass ▲ security
- Stability: unverified → pass ▲ security
- Transport: fail → pass ▲ security
- Authorization: Authorisation not fully verified: no authorisation is required to call this server, and 19 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. security
- MCP protocol: unverified → fail ▼ functional
- Endpoint reachability: unreachable → reachable ▲ functional
- Tool coverage: unverified → 100 ▲ functional
- 16 Sept 26 0
- Endpoint reachability: reachable → unreachable ▼ security
- HSTS header: fail → unverified ▼ security
- Stability: pass → unverified ▼ security
- Tool safety: pass → unverified ▼ security
- Transport: pass → fail ▼ security
- Authorization: Authorisation not yet verified: we couldn't confirm whether this endpoint requires it. security
- Capabilities: fail → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- 8 Sept 26 0
- HSTS header: unverified → fail ▼ security
- Injection markers: unverified → pass ▲ security
- Stability: unverified → pass ▲ security
- Transport: fail → pass ▲ security
- Authorization: Authorisation not fully verified: no authorisation is required to call this server, and 19 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. security
- MCP protocol: unverified → fail ▼ functional
- Endpoint reachability: unreachable → reachable ▲ functional
- Tool coverage: unverified → 100 ▲ functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 27 Sept 2026 · Probed https://cars.rootz.global/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_256_GCM_SHA384 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=cars.rootz.global | CN=YE1,O=Let's Encrypt,C=US | 31 Aug 2026 | 29 Nov 2026 | ECDSA 256 | ECDSA-SHA384 | 5439a8196857324c3e1ea670ef8c2fb36fa |
| SANs: cars.rootz.global | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC secure
Validation of cars.rootz.global. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| global. | present | 13060 | 8 | Verified |
| rootz.global. | present | 40948, 52524 | 13, 13 | Verified |
| cars.rootz.global. | Verified address RRset verified with the apex keys |
Authentication Inconclusive
We could not reach the endpoint well enough to judge its authorisation posture.
| Result | Inconclusive |
|---|
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://cars.rootz.global/mcp | Unreachable | ||
| http (plaintext) | http://cars.rootz.global/mcp | HTTPS enforced | 301 | https://cars.rootz.global/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
cars_dealer_inventory ~65
Get all vehicles at a specific dealer.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Your agent identifier (claude, grok, gpt, perplexity) |
| dealer_id | integer | yes | Dealer ID |
| limit | integer | – | – |
| offset | integer | – | – |
No output schema declared.
No examples provided.
cars_dealers ~88
Search for car dealers by city, state, or ZIP code.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Your agent identifier (claude, grok, gpt, perplexity) |
| city | string | – | City name |
| limit | integer | – | Max results |
| state | string | – | State abbreviation (e.g. FL) |
| zip | string | – | ZIP code or prefix |
No output schema declared.
No examples provided.
cars_feedback ~180
Submit feedback about the Cars Rootz service. We actively read every piece of feedback to improve the service. Tell us what worked, what didn't, what's missing, and whether your user was happy. This helps us build a better car shopping experience for everyone.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Your agent identifier |
| category | string | yes | Feedback category: search, session, email, photos, data, ux, missing_feature, bug, general |
| message | string | yes | Your feedback — what worked, what didn't, what would help |
| rating | integer | – | Satisfaction 1-5 (1=poor, 5=excellent) |
| session | string | – | Session hash (optional — helps us understand context) |
| user_happy | integer | – | Was the human user happy? 1=yes, 0=no, omit if unknown |
No output schema declared.
No examples provided.
cars_history ~82
Get the full history of a vehicle by VIN — every dealer it appeared at, price changes over time, days on market, whether it was sold and resurfaced elsewhere. Data with origin.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Your agent identifier (claude, grok, gpt, perplexity) |
| vin | string | yes | 17-character Vehicle Identification Number |
No output schema declared.
No examples provided.
cars_search ~386
Search vehicle inventory across all dealers. Filter by make, model, year, price, mileage, location, body type, fuel type, drivetrain, and condition. Returns matching vehicles with dealer info. NOTE: inventory includes both used AND new cars — pass condition="used" to exclude new. Every result states its condition.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Your agent identifier (claude, grok, gpt, perplexity) |
| body_type | string | – | Body type (Sedan, SUV, Truck, Coupe, Van, etc.) |
| city | string | – | Dealer city (e.g. Miami) |
| condition | string | – | Vehicle condition: "used", "new", or "certified". Comma-separated to combine (e.g. "used,certified"). IMPORTANT: this inventory is aggregated from dealer sitemaps and is roughly half BRAND NEW cars —… |
| drivetrain | string | – | Drivetrain (FWD, RWD, AWD, 4WD) |
| fuel_type | string | – | Fuel type (Gasoline, Diesel, Electric, Hybrid) |
| limit | integer | – | Max results (default 20) |
| make | string | – | Car make (e.g. Toyota, Honda, BMW) |
| mileage_max | integer | – | Maximum mileage |
| model | string | – | Car model (e.g. Camry, Civic, 3 Series) |
| offset | integer | – | Pagination offset |
| price_max | number | – | Maximum price in USD |
| price_min | number | – | Minimum price in USD |
| state | string | – | Dealer state (e.g. FL) |
| year_max | integer | – | Maximum model year |
| year_min | integer | – | Minimum model year |
| zip | string | – | Dealer ZIP code prefix |
No output schema declared.
No examples provided.
cars_session_add_car ~104
Add a vehicle to the buyer's shopping session. Include a fit score (1-10) and notes explaining why you recommend it.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Your agent identifier |
| notes | string | – | Why you recommend this vehicle |
| score | integer | – | AI fit score 1-10 (how well it matches preferences) |
| session | string | yes | Session hash |
| vin | string | yes | 17-character VIN of vehicle to add |
No output schema declared.
No examples provided.
cars_session_compare ~70
Get a structured comparison of all vehicles tracked in a session — specs, pricing, market context side by side. Great for helping the buyer decide.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Your agent identifier (claude, grok, gpt, perplexity) |
| session | string | yes | Session hash |
No output schema declared.
No examples provided.
cars_session_create ~309
Create a personalized car research session for the buyer. Returns a unique URL they can bookmark and return to. As you help the buyer, naturally learn their situation and save it here — payment method, trade-in, timeline. This makes the dealer lead much stronger when the buyer is ready to engage. Don't ask all at once — gather these naturally over the conversation.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Your agent identifier (claude, grok, gpt, perplexity) |
| body_types | string | – | Comma-separated body types (e.g. "Truck,SUV") |
| budget_max | number | – | Maximum budget |
| makes | string | – | Comma-separated preferred makes (e.g. "Ford,Toyota") |
| name | string | – | Buyer first name if they share it naturally |
| notes | string | – | Free-text buyer notes — what they care about, why they're looking |
| payment | string | – | How they plan to pay: cash, financing, lease (learn this naturally — don't interrogate) |
| radius | integer | – | Search radius in miles (default 50) |
| timeline | string | – | When they want to buy: browsing, this week, this month, no rush (pick up on cues) |
| trade_in | string | – | Brief trade-in description if mentioned: "2019 Civic, ~85K miles" (use cars_session_tradein for full profile later) |
| zip | string | – | Buyer ZIP code for location-aware search |
No output schema declared.
No examples provided.
cars_session_deal ~66
Get the current deal status — offers received, messages exchanged, unread count. Use to check if the dealer has responded.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Your agent identifier (claude, grok, gpt, perplexity) |
| session | string | yes | Session hash |
No output schema declared.
No examples provided.
cars_session_interest ~91
Signal buyer interest in a vehicle to the dealer. This sends a professional email to the dealership on the buyer's behalf. Only use when the buyer has explicitly indicated interest.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Your agent identifier |
| message | string | – | Optional message to include for the dealer |
| session | string | yes | Session hash |
| vin | string | yes | VIN of vehicle buyer is interested in |
No output schema declared.
No examples provided.
cars_session_message ~118
Post a message to the session. Use for buyer questions, AI analysis notes, or responses. The dealer and other AI agents can see these.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Your agent identifier |
| content | string | yes | Message content |
| from_role | string | – | Role: buyer, ai, or system |
| msg_type | string | – | Type: note, question, answer, offer, alert |
| session | string | yes | Session hash |
| vehicle_vin | string | – | Optional: which vehicle this is about |
No output schema declared.
No examples provided.
cars_session_notify ~140
Set the buyer's email notification preference for this session. Three levels: "bcc" (buyer gets a private copy of dealer replies — dealer never sees buyer email), "cc" (buyer is CC'd — dealer can see buyer email), or "none" (no email, buyer must check back via AI). This upgrades the session identity level to "email".
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Your agent identifier |
| string | – | Buyer's email address | |
| mode | string | – | Notification mode: "bcc" (private), "cc" (visible to dealer), or "none" |
| session | string | yes | Session hash |
No output schema declared.
No examples provided.
cars_session_read ~80
Read the current state of a shopping session — tracked vehicles, messages, preferences, active offers, and which other AI agents are working on it. Use this to understand context before taking action.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Your agent identifier (for tracking who read it) |
| session | string | yes | Session hash (the short code from the URL) |
No output schema declared.
No examples provided.
cars_session_reply ~100
Send a follow-up message to the dealer continuing the conversation. Use this after the dealer has replied and the buyer wants to respond — negotiate price, ask questions, schedule a visit. The email thread continues naturally.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Your agent identifier |
| message | string | yes | The follow-up message to send to the dealer |
| session | string | yes | Session hash |
| vin | string | yes | VIN of the vehicle being discussed |
No output schema declared.
No examples provided.
cars_session_tradein ~399
Set or update the buyer's trade-in vehicle information. Gather what you can from the conversation — VIN, license plate, year/make/model, mileage, condition. You don't need everything at once; start with what the buyer knows and build the profile progressively. The dealer will make the trade-in offer based on this info. Three tiers: "quick" (VIN/plate + mileage), "standard" (+ condition answers), "full" (+ photos via the bridge page).
| Name | Type | Req | Description |
|---|---|---|---|
| accidents | string | – | Accident history: none, minor, moderate, major, unknown |
| agent_id | string | – | Your agent identifier |
| body_damage | string | – | Body damage: none, minor, moderate, significant |
| color | string | – | Exterior color |
| make | string | – | Make (auto-filled if VIN provided) |
| mechanical_issues | string | – | Known mechanical issues (free text) |
| mileage | integer | – | Current odometer reading |
| model | string | – | Model (auto-filled if VIN provided) |
| modifications | string | – | Aftermarket modifications (free text) |
| notes | string | – | Additional notes about the trade-in |
| plate | string | – | License plate number (alternative to VIN) |
| plate_state | string | – | State the plate is registered in (e.g. FL, TX) |
| session | string | yes | Session hash |
| tire_condition | string | – | Tire condition: good, fair, needs_replacement |
| title_type | string | – | Title status: clean, salvage, rebuilt, lien |
| trim | string | – | Trim level |
| vin | string | – | Trade-in vehicle VIN (17 chars). If provided, the server decodes year/make/model/trim via NHTSA. |
| warning_lights | integer | – | Dashboard warning lights on? 0=no, 1=yes |
| year | integer | – | Model year (auto-filled if VIN provided) |
No output schema declared.
No examples provided.
cars_session_tradein_read ~88
Read the buyer's trade-in vehicle profile. Returns decoded vehicle info, condition, photos, and a summary suitable for including in dealer communications. Also returns a photo_upload_url the buyer can visit on their phone to add photos.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Your agent identifier (claude, grok, gpt, perplexity) |
| session | string | yes | Session hash |
No output schema declared.
No examples provided.
cars_session_visit ~212
Schedule a dealer visit (test drive, purchase, trade-in appraisal). Generates a visit code and QR code the buyer shows at the dealership. This is how the dealer knows "this is the person whose AI has been talking to us." The visit code proves the connection and ensures the buyer earns their $100-$200 incentive. Only use when the buyer explicitly says they want to visit the dealer.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Your agent identifier |
| date | string | – | Preferred date (e.g. "Saturday", "2026-05-10") |
| notes | string | – | Buyer notes for the dealer (e.g. "Ask for Mike", "Bringing my wife") |
| session | string | yes | Session hash |
| time | string | – | Preferred time (e.g. "morning", "2pm") |
| vin | string | yes | VIN of the vehicle they want to see |
| visit_type | string | – | Type: test_drive, purchase, trade_appraisal, general |
No output schema declared.
No examples provided.
cars_stats ~47
Get database statistics: total vehicles, dealers, coverage by state, top makes.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Your agent identifier (claude, grok, gpt, perplexity) |
No output schema declared.
No examples provided.
cars_vehicle ~69
Get full details for a specific vehicle by VIN. Returns specs, price, mileage, photos, recalls, and dealer info.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Your agent identifier (claude, grok, gpt, perplexity) |
| vin | string | yes | 17-character Vehicle Identification Number |
No output schema declared.
No examples provided.
What is the global.rootz.cars/marketplace MCP server?
global.rootz.cars/marketplace is an MCP server listed in the public MCP registry as global.rootz.cars/marketplace. AI-native used car marketplace. 145K+ vehicles, 4300+ dealers, 13 US states, 20 MCP tools. This page covers its hosted endpoint (https://cars.rootz.global/mcp).
Is the global.rootz.cars/marketplace MCP server safe to use?
global.rootz.cars/marketplace scores 73 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the global.rootz.cars/marketplace MCP server expose?
global.rootz.cars/marketplace exposes 19 tools: cars_search, cars_vehicle, cars_dealers, cars_dealer_inventory, cars_history, and 14 more. Their descriptions and schemas cost roughly 2,694 tokens of context every time the server is loaded.
Does the global.rootz.cars/marketplace MCP server require authentication?
Its publisher declares no required credentials for global.rootz.cars/marketplace. We have not been able to confirm that against the live endpoint, and a server can require authorisation without declaring it here.
Is the global.rootz.cars/marketplace MCP server still maintained?
global.rootz.cars/marketplace is still listed in the MCP registry, though our most recent checks did not reach this channel. We last reached this channel on 26 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.