# io.github.hellosverre/brreg (npm · brreg-mcp)

MCP server for Norway's Brønnøysund business registry — lookup, search, roles.

- Trust score: 69/100 (medium)
- Change this week: +25
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- npm · `brreg-mcp`: 69/100 (this document), [markdown](https://verifymcp.io/servers/hellosverre-brreg/brreg-mcp.md), [page](https://verifymcp.io/servers/hellosverre-brreg/brreg-mcp)

## Channel facts

- Registry: `npm`
- Package: `brreg-mcp`
- Version: `0.1.1`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Supply Chain Security**: 86/100
  - No malware found by supply-chain analysis.
  - Only part of the dependency tree could be resolved (94 of 98), so this covers what we could see, not the whole tree.
  - No install/post-install scripts declared.
  - Only part of the dependency tree could be resolved (94 of 98), so this covers what we could see, not the whole tree.
- **Provenance & Transparency**: 45/100
  - Source repository is publicly reachable at the declared URL.
  - Provenance check failed: no build-provenance attestation is published.
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 101 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 76/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 742 tokens (~148/item across 5 items; 5 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 27/100
  - Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 95/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 85% of tool parameters carry a description.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### Claude

```bash
claude mcp add hellosverre-brreg -- npx -y brreg-mcp
```

### Codex

```bash
codex mcp add hellosverre-brreg -- npx -y brreg-mcp
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "hellosverre-brreg": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "brreg-mcp"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add hellosverre-brreg --command npx --arg -y --arg brreg-mcp
```

### Hermes

```yaml
mcp_servers:
  hellosverre-brreg:
    command: "npx"
    args: ["-y", "brreg-mcp"]
```

### Other

```json
{
  "mcpServers": {
    "hellosverre-brreg": {
      "command": "npx",
      "args": [
        "-y",
        "brreg-mcp"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-03 (score 69, +1)

No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-08-02 (score 68, +63)

- [security regression] Provenance: unverified → fail
- [security improvement] Malware scan: unverified → pass
- [security improvement] Install scripts: unverified → pass
- [security improvement] Known CVEs: unverified → partial
- [functional improvement] Stability: unverified → 0.23
- [functional improvement] MCP protocol: unverified → pass
- [functional improvement] Schema quality: unverified → excellent
- [functional improvement] Tool coverage: unverified → 100
- [functional improvement] Dependency health: unverified → partial
- [functional improvement] Maintenance: unverified → pass
- [functional improvement] License: unverified → pass
- [functional] Licence: MIT

### 2026-08-01 (score 5, −21)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-31 (score 26, −18)

- [security regression] Malware scan: pass → unverified

### 2026-07-27 (score 44)

First indexed and scored.

## MCP tools (5)

### `lookup_company` (~113 tokens)

Look up Norwegian company by organization number

Retrieves full details of a Norwegian business entity from the Brønnøysund Register Centre (Enhetsregisteret) by its 9-digit organization number. Returns name, address, industry (NACE) codes, organization form, employee count, VAT registration status, bankruptcy status, foundation date, and more. Use this when the user provides or asks about a specific Norwegian orgnr.

Input parameters:

- `orgnr` (string, required): 9-digit Norwegian organization number (organisasjonsnummer), e.g. '923609016'

### `search_companies` (~266 tokens)

Search Norwegian companies

Searches the Norwegian business registry (Enhetsregisteret) by name and optional filters. Returns a paginated list of matching entities. Use this when the user wants to find a company by name, or filter by municipality, industry code, organization form, or registration status.

Input parameters:

- `kommunenummer` (string): 4-digit municipality number (kommunenummer) to filter by location
- `konkurs` (boolean): Filter by bankruptcy status (true = only bankrupt, false = only non-bankrupt)
- `naeringskode` (string): NACE industry code filter (e.g. '62.010' for computer programming)
- `navn` (string): Company name or substring (case-insensitive)
- `organisasjonsform` (string): Filter by organization form code, e.g. 'AS' (aksjeselskap), 'ENK' (enkeltpersonforetak), 'ASA', 'DA', 'NUF'
- `page` (integer): Page number (0-indexed, default 0)
- `postnummer` (string): 4-digit postal code filter
- `registrertIMvaregisteret` (boolean): Filter to only VAT-registered companies
- `size` (integer): Results per page (1-100, default 20)

### `get_company_roles` (~93 tokens)

Get roles (board, directors, auditor) of a company

Retrieves all registered roles — board members (styre), CEO (daglig leder), chair (styreleder), auditor (revisor), sole proprietor (innehaver), etc. — for a Norwegian company. Returns structured role groups with person or entity role-holders. Does NOT include personal identification numbers (that requires Maskinporten auth).

Input parameters:

- `orgnr` (string, required): 9-digit Norwegian organization number

### `search_subunits` (~146 tokens)

Search subunits (branch offices) of Norwegian companies

Searches subunits (underenheter — branch offices, departments, production sites) in the Norwegian business registry. Typically used to find all branches of a parent company, or to locate subunits in a specific municipality. A subunit shares the parent's organization but has its own orgnr for reporting purposes.

Input parameters:

- `kommunenummer` (string): 4-digit municipality number
- `naeringskode` (string): NACE industry code
- `navn` (string): Subunit name or substring
- `overordnetEnhet` (string): 9-digit orgnr of the parent entity to list all its subunits
- `page` (integer)
- `size` (integer)

### `get_recent_updates` (~124 tokens)

Get recently updated companies

Fetches a feed of entities (companies) that were recently updated in the Norwegian business registry. Useful for monitoring changes to specific companies or watching for new registrations / status changes. Each update references the changed entity by orgnr along with the change type and timestamp.

Input parameters:

- `dato` (string): ISO-8601 timestamp — return updates from this point onward (e.g. '2026-04-20T00:00:00Z')
- `oppdateringsid` (integer): Continue from a specific update id (pagination cursor)
- `size` (integer)

## Diagnostics

Captured diagnostic sections: Provenance, Dependencies. The full working is on the page: https://verifymcp.io/servers/hellosverre-brreg/brreg-mcp#diagnostics

## Score history

- 2026-08-03: 69
- 2026-08-02: 68
- 2026-08-01: 5
- 2026-07-31: 26
- 2026-07-30: 44
- 2026-07-28: 44
- 2026-07-27: 44

## Links

- npm package: https://www.npmjs.com/package/brreg-mcp
- Socket report: https://socket.dev/npm/package/brreg-mcp
- Repository: https://github.com/hellosverre/brreg-mcp
- Changelog RSS feed: https://verifymcp.io/servers/hellosverre-brreg/brreg-mcp/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/hellosverre-brreg/brreg-mcp/changelog.json
- HTML version of this page: https://verifymcp.io/servers/hellosverre-brreg/brreg-mcp
