# DataQuoll (remote · dataquoll.io)

Australian public data as MCP tools: incidents, gauges, declarations, industry calendars, archive.

- Trust score: 39/100 (low)
- Change this week: 0
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-02

## Components

- remote · `dataquoll.io`: 39/100 (this document), [markdown](https://verifymcp.io/servers/io-dataquoll-data-api/api-mcp.md), [page](https://verifymcp.io/servers/io-dataquoll-data-api/api-mcp)

## Channel facts

- Endpoint: `https://dataquoll.io/api/mcp`
- Transports: `streamable-http`
- Auth: `required`
- Version: `1.3.1`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-02.

- **Endpoint Security**: 97/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - The endpoint enforces authorisation, advertised via RFC 9728 protected-resource metadata.
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC is configured correctly; the domain's records validate against the full chain to the root.
  - The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents.
- **Transport & Reachability**: 0/100
  - Transport blocked by authentication: the endpoint requires auth we don't have to verify streamable-http.
- **Schema Quality & AI Usability**: 0/100
  - Schema blocked by authentication: the endpoint requires auth we don't have to read it.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 0/100
  - Tool coverage blocked by authentication: the endpoint requires auth we don't have to read its tools.
- **Tool Safety**: 0/100
  - Tool safety blocked by authentication: the endpoint requires auth we don't have to read its tools.
- **Capabilities**: 0/100
  - Capabilities blocked by authentication: the endpoint requires auth we don't have to read them.

**Unverified: 6 categories.** Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.

## Install

### How do I install the DataQuoll MCP server?

DataQuoll is a hosted endpoint at https://dataquoll.io/api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http io-dataquoll-data-api 'https://dataquoll.io/api/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "io-dataquoll-data-api": {
      "url": "https://dataquoll.io/api/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "io-dataquoll-data-api": {
      "type": "http",
      "url": "https://dataquoll.io/api/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.io-dataquoll-data-api]
url = "https://dataquoll.io/api/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "io-dataquoll-data-api": {
      "type": "remote",
      "url": "https://dataquoll.io/api/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add io-dataquoll-data-api --url 'https://dataquoll.io/api/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  io-dataquoll-data-api:
    url: "https://dataquoll.io/api/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "io-dataquoll-data-api": {
      "Transport": "http",
      "Url": "https://dataquoll.io/api/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add io-dataquoll-data-api -t streamable-http -u 'https://dataquoll.io/api/mcp'
```

### Other

```json
{
  "mcpServers": {
    "io-dataquoll-data-api": {
      "type": "http",
      "url": "https://dataquoll.io/api/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-28 (score 39, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-25 (score 39, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-08 (score 39, −27)

- [security regression] Endpoint reachability: reachable → behind authorisation
- [security regression] Tool safety: pass → unverified
- [security regression] Transport: pass → unverified
- [security regression] Stability: 0.03 → unverified
- [security improvement] Authorization: unverified → pass
- [security] First check of Authorization: partial
- [functional regression] Capabilities: pass → unverified
- [functional regression] Tool coverage: 100 → unverified
- [functional] First check of Schema quality: unverified

### 2026-09-07 (score 66, +1)

- [functional improvement] Stability: unverified → 0.03
- [functional] Server version: 1.1.0 → 1.2.0
- [functional] New tool “get_calendar_day”
- [functional] New tool “get_calendar_days”
- [functional] New tool “list_calendars”

### 2026-09-06 (score 65)

First indexed and scored.

## MCP tools (22)

### `list_incidents` (~814 tokens)

List all current incidents

Returns a GeoJSON FeatureCollection of all current emergency incidents, with support for filtering, pagination, and bounding box queries.

Example response:
{
  "type": "FeatureCollection",
  "features": [
    {
      "type": "Feature",
      "id": "nsw-rfs-1234567",
      "geometry": {
        "type": "Point",
        "coordinates": [
          150.604,
          -33.883
        ]
      },
      "properties": {
        "source": {
          "state": "nsw",
          "agency": "RFS",
          "feedId": "1234567"
        },
        "title": "Bush Fire - Warragamba",
        "eventType": "bushfire",
        "status": "active",
        "warningLevel": "watch_and_act",
        "severity": "Severe",
        "urgency": "Expected",
        "certainty": "Observed",
        "location": {
          "address": "Warragamba Dam Rd, Warragamba NSW",
          "suburb": "Warragamba",
          "state": "NSW",
          "latitude": -33.883,
          "longitude": 150.604
        },
        "details": {
          "description": "Bush fire burning in a south-easterly direction"
        },
        "timestamps": {
          "reported": "2026-04-07T14:30:00+10:00",
          "updated": "2026-04-07T16:45:00+10:00",
          "fetched": "2026-04-07T16:46:12+10:00"
        },
        "retraction": {
          "retracted": true,
          "retractedAt": "2026
... (truncated)

Input parameters:

- `after` (string): Alias for cursor. This is the parameter name emitted in links.next, and is accepted for backward compatibility. If both are supplied, after wins.
- `agency` (string): Source agency filter
- `bbox` (string): Bounding box: minLon,minLat,maxLon,maxLat
- `category` (string): Comma-separated event categories. Groups related event types (e.g. fire includes bushfire, structure_fire, grass_fire, vehicle_fire). burn_off is its own category (planned). See /api/v1/schema for th…
- `certainty` (string): CAP-AU certainty levels (Observed, Likely, Possible, Unlikely, Unknown)
- `cursor` (string): Opaque pagination cursor, taken from meta.next_cursor of the previous response. Absent next_cursor means there are no further pages.
- `eventType` (string): Comma-separated event types (bushfire, burn_off, fire_ban, structure_fire, vehicle_fire, grass_fire, hazmat, rescue, flood, storm, tree_down, cyclone, earthquake, extreme_heat, vehicle_accident, medi…
- `featureType` (string): Comma-separated feature types. Defaults to 'incident' (point incidents only), so boundary polygons never appear unless requested. Request them explicitly: incident_area, warning_area, fire_ban_area.…
- `include_retracted` (boolean): Include retracted incidents (default false). Retracted incidents are marked when upstream feeds stop publishing them.
- `limit` (integer): Results per page (default 100, max 500)
- `severity` (string): CAP-AU severity levels (Extreme, Severe, Moderate, Minor, Unknown)
- `state` (string): Comma-separated state codes (e.g. nsw,vic,qld)
- `status` (string): Incident status filter
- `urgency` (string): CAP-AU urgency levels (Immediate, Expected, Future, Past, Unknown)
- `warningLevel` (string): Australian Warning System levels

### `get_incident` (~40 tokens)

Get a single incident

Returns a single incident as a GeoJSON Feature.

Input parameters:

- `id` (string, required): Incident ID (e.g. nsw-rfs-1234567)

### `nearby_incidents` (~181 tokens)

Find incidents near a location

Returns incidents within a radius (km) of a given lat/lng coordinate, sorted by distance.

Input parameters:

- `agency` (string)
- `certainty` (string)
- `eventCategory` (string)
- `eventType` (string)
- `include_retracted` (boolean): Set true to include retracted incidents. Default false; retracted incidents are hidden, matching /incidents.
- `lat` (number, required): Latitude
- `limit` (integer)
- `lng` (number, required): Longitude
- `radius` (number, required): Radius in kilometres (max 500)
- `severity` (string)
- `state` (string)
- `status` (string): Comma-separated incident statuses (active, contained, controlled, safe, completed). Defaults to all.
- `urgency` (string)
- `warningLevel` (string)

### `incident_snapshot` (~198 tokens)

Audit trail snapshot

Returns the incidents that were active at a specific point in time. Recent datetimes are reconstructed from live and lifecycle data. Datetimes before 2026-04-08 are reconstructed from the historical archive (4.8M+ records) and are gated by the same tier lookback as /incidents/history (free has no archive access; Starter 1 year, Developer and Business 5 years, Pro and Enterprise unlimited). Archive (pre-2026-04-08) snapshots require a state filter, and meta.source indicates whether the result came from "live" or "archive".

Input parameters:

- `datetime` (string, required): ISO 8601 datetime to query (cannot be in the future)
- `event_type` (string): Filter by event type
- `limit` (integer): Max results (default 500)
- `state` (string): Filter by state code. Required for archive (pre-2026-04-08) snapshots.

### `list_historical_incidents` (~148 tokens)

Historical incident data (paid tier)

Returns historical emergency incidents from the 4.8M+ record archive (1840-2026). Free tier is blocked. Starter tier limited to 1 year lookback, Developer and Business to 5 years, Pro and Enterprise unlimited.

Input parameters:

- `after` (string): Start of date range (ISO 8601, inclusive). Tier-limited.
- `before` (string): End of date range (ISO 8601, exclusive). Defaults to now.
- `eventType` (string): Comma-separated event types
- `limit` (integer): Max results per page (1-500, default 100)
- `state` (string): Comma-separated state codes

### `list_states` (~27 tokens)

Feed health by state

Returns the status of each state feed, including last poll time, health, and incident count.

### `declarations_by_postcode` (~308 tokens)

Disaster declaration status for a postcode

Returns the declaration STATUS for a postcode: declared, partial, activation_only, not_declared, uncertain, or unknown_postcode, with per-LGA detail and official source links. Reports declared-area status only; the billing/eligibility decision rests with the practitioner. Built for Medicare disaster telehealth checks.

Requires the "declarations" entitlement on the API key. Accounts without it get a clear error rather than an empty result, so an empty response never means "not entitled".

Input parameters:

- `as_at` (string): Point-in-time check (YYYY-MM-DD). Defaults to today.
- `include_expired` (boolean): Include expired records in the per-LGA lists. Never changes matchStatus.
- `instrument_type` (string): Trim the returned record lists to one instrument type. Never changes matchStatus.
- `postcode` (string, required)
- `suburb` (string): Optional suburb/locality name (ABS SAL) to narrow the result to the local government areas that suburb falls in, within this postcode only. Matching is exact after normalisation; there is no fuzzy ma…

### `declarations_by_point` (~285 tokens)

Disaster declaration status for an exact point

Returns the declaration STATUS for the local government area containing a lat/lng point, resolved against ABS LGA 2022 (ASGS Edition 3) boundary polygons at full resolution. POST with a JSON body is used deliberately so coordinates never appear in URLs or request logs; the request is read-only and safe to retry. Coordinates are never stored, logged, or echoed back, and the response is Cache-Control: no-store. Reports declared-area status only; the billing decision rests with the practitioner. A point outside every Australian LGA returns unknown_location. A point exactly on a shared LGA boundary returns every covering area with onBoundary=true. LGA matching is at ABS code level; some ABS codes aggregate multiple administrative areas (for example Unincorporated NSW covers both Far West and Lord Howe Island).

Requires the "declarations" entitlement on the API key. Accounts without it get a clear error rather than an empty result, so an empty response never means "not entitled".

Input parameters:

- `as_at` (string): Point-in-time check (YYYY-MM-DD). Defaults to today.
- `include_expired` (boolean): Include expired records in the per-LGA lists. Never changes matchStatus.
- `instrument_type` (string): Trim the returned record lists to one instrument type. Never changes matchStatus.
- `lat` (number, required)
- `lng` (number, required)

### `hazard_history_by_point` (~373 tokens)

Observed record and declared status for an exact point

What official sources recorded near a location, unioned with the disaster declarations that covered its local government area. Two lanes are returned because both are required: the observed lane (historical archive plus live-era incident history within a radius) and the declared lane (declarations for the covering ABS LGA, counted once per AGRN even when several authorities recorded the same event). Measured example: a Lismore address returns the February 2022 flood only through the declared lane, because the spatial lane holds no record for it at address precision. POST with a JSON body is used deliberately so coordinates never appear in URLs or request logs; the request is read-only and safe to retry. Coordinates are never stored, logged, or echoed back, and the response is Cache-Control: no-store. This reports a RECORD and a declared STATUS. It is not an assessment of risk, insurability, or any obligation, and absence of a record is not evidence that nothing happened. Precision is reported per record: a record at postcode precision sits at a postcode centroid, which can be kilometres from the event.

Requires the "hazard-history" entitlement on the API key. Accounts without it get a clear error rather than an empty result, so an empty response never means "not entitled".

Input parameters:

- `lat` (number, required): Latitude in decimal degrees, -90 to 90. Never logged or echoed.
- `lng` (number, required): Longitude in decimal degrees, -180 to 180. Never logged or echoed.
- `radiusKm` (number): Search radius for the observed lane, greater than 0 and no more than 5. Defaults to 1.
- `records` (integer): Maximum observed records returned in the list. Aggregates always cover everything in radius. 1 to 100, defaults to 25.

### `list_declarations` (~128 tokens)

List/filter declarations

Browse and historically report on declaration records. Filters and keyset (cursor) pagination. Record status is derived at query time.

Requires the "declarations" entitlement on the API key. Accounts without it get a clear error rather than an empty result, so an empty response never means "not entitled".

Input parameters:

- `active_on` (string)
- `cursor` (string): Opaque pagination cursor from links.next.
- `disaster_type` (string)
- `instrument_type` (string)
- `jurisdiction` (string)
- `limit` (integer)
- `status` (string)

### `declaration_by_agrn` (~76 tokens)

One disaster event by AGRN (across sources)

The declaration/activation for an Australian Government Reference Number, merged across sources with the full affected-LGA list.

Requires the "declarations" entitlement on the API key. Accounts without it get a clear error rather than an empty result, so an empty response never means "not entitled".

Input parameters:

- `agrn` (string, required)

### `get_attribution` (~27 tokens)

Data source attributions

Returns attribution information for all data sources, including licence details. Required for CC BY compliance.

### `list_events` (~161 tokens)

List clustered events (incident intelligence)

Returns spatially clustered emergency events as a GeoJSON FeatureCollection.
Events group related incidents using PostGIS ST_ClusterDBSCAN spatial clustering.
Each event has a boundary polygon, centroid, affected suburbs, contributing agencies,
and auto-generated title and summary. Only active events are returned by default.

Input parameters:

- `eventType` (string): Comma-separated event types (e.g. bushfire,flood)
- `limit` (integer): Maximum events to return (default 50, max 200)
- `severity` (string): Comma-separated max severity levels
- `state` (string): Comma-separated state codes to filter by (e.g. nsw,vic). Uses array overlap matching.
- `warningLevel` (string): Comma-separated max warning levels

### `get_event` (~60 tokens)

Get a single event with optional linked incidents

Returns a single clustered event by ID. Use `include_incidents=true` to also
retrieve all incidents that belong to this event cluster.

Input parameters:

- `id` (string, required): Event UUID
- `include_incidents` (boolean): Include linked incidents in the response

### `get_schema` (~46 tokens)

API schema and valid enum values

Returns all valid enum values for event types, categories, states, warning levels, and other filterable fields. Use this to discover what values are accepted by filter parameters. No authentication required.

### `list_gauges` (~401 tokens)

River gauge stations with live flood status

Returns river gauge stations with their latest water level, the Bureau of Meteorology flood classification thresholds for each gauge, and a derived floodClass (below_minor, minor, moderate, major, or unclassified) computed from the latest reading against the published thresholds. Water-level readings are in metres relative to each gauge's local datum (each gauge carries its own unit, since some report in AHD). readingStatus flags stale data (bom-kiwis sourced stations are a 1-2 day archive, stale horizon 72 hours; bcc-telemetry are event-driven council ALERT loggers, stale horizon 48 hours; telemetry sources 24 hours). Defaults to water-level gauges; pass variable=rainfall for observed rainfall gauges, which report incremental millimetres and carry no flood classification. Status reporting, not flood prediction.

Input parameters:

- `bbox` (string): Bounding box minLng,minLat,maxLng,maxLat (within Australia)
- `cursor` (string): Pagination cursor from meta.nextCursor
- `floodClass` (string): Filter to gauges at or above this class (>= semantics: minor matches moderate and major too). Water-level only; cannot combine with variable=rainfall.
- `lga` (string): ABS LGA code (the same LGA_2022 vocabulary as the declarations API)
- `limit` (integer): Max results per page (1-500, default 100)
- `source` (string): Polling source (hydstra-nsw, hydstra-vic, hydstra-qld, aquarius-sa, aquarius-tas, aquarius-nt, bom-kiwis, bcc-telemetry)
- `state` (string): Lowercase state code (nsw, vic, qld, sa, wa, tas, nt, act)
- `variable` (string): Measured variable. Defaults to water_level; rainfall returns observed rain gauges (millimetres, incremental, no flood class).

### `get_gauge` (~74 tokens)

One gauge with a 6-hour recent window

Returns a single gauge station plus its trailing 6 hours of raw readings (enough to see the current trend). Deeper history is the tier-gated /gauges/{id}/readings endpoint.

Input parameters:

- `id` (string, required): Gauge id from /gauges (e.g. hydstra-nsw-410001)

### `list_gauge_readings` (~224 tokens)

Gauge reading history (paid tier)

Historical water level readings for one gauge. Free tier is blocked (the free surface is current readings on /gauges and the 6-hour window on /gauges/{id}). Starter tier limited to 1 year lookback, Developer and Business to 5 years, Pro and Enterprise unlimited. Retention ladder: raw 30 days, hourly rollups 90 days, daily forever — plus full-resolution raw inside flood-event windows kept forever. interval=auto picks the finest granularity available for the requested window.

Input parameters:

- `above` (string): Only readings at/above this published flood classification for the gauge
- `after` (string): Start of range (ISO 8601, inclusive). Tier-limited.
- `before` (string): End of range (ISO 8601, exclusive). Defaults to now.
- `cursor` (string): Pagination cursor from meta.nextCursor (ISO timestamp keyset)
- `id` (string, required)
- `interval` (string): raw, hourly, daily, or auto (default)
- `limit` (integer)

### `get_gauge_summary` (~145 tokens)

Flood status counts by state or LGA

Counts of gauges at or above minor/moderate/major flood classification, grouped by state or LGA, plus the full list of at-or-above-minor stations (capped at 500). STALE GUARD: only readings within the staleness horizon enter class counts — a days-old reading above minor is counted as stale, never as a current flood signal.

Input parameters:

- `groupBy` (string): state (default) or lga (requires the state parameter)
- `state` (string)
- `variable` (string): Measured variable. Defaults to water_level (rain gauges carry no flood class, so they are excluded from the counts by default).

### `list_calendars` (~93 tokens)

Industry calendar editions

Every industry-calendar edition on the platform, one per jurisdiction and year (NSW, VIC, QLD, WA, SA, TAS, ACT and NT for 2026), with its publisher, cover range and per-category counts. RDOs, public holidays, school holidays and industry shutdowns, read from each branch calendar and verified against the Fair Work Ombudsman list and the education departments' term dates.

### `get_calendar_days` (~140 tokens)

Calendar days for a jurisdiction

The day rows for one jurisdiction across a date range, each date answered by exactly one edition. Defaults to the current calendar year in the jurisdiction's own time zone; a lone from or to extends to the edge of its own year. Every place the calendar disagrees with the official list is returned under discrepancies. Rows can be CSV with format=csv.

Input parameters:

- `category` (string): Comma-separated categories to include (default all). Values are the CalendarDay category enum.
- `from` (string): First date, YYYY-MM-DD
- `jurisdiction` (string, required): Jurisdiction code
- `to` (string): Last date, YYYY-MM-DD

### `get_calendar_day` (~115 tokens)

Is this a working day

The answer for one date in one jurisdiction. A jurisdiction-wide public holiday wins, then the weekend, then the calendar's own entries in order (industry shutdown, RDO, part-day holiday, annual leave, industry event); otherwise working. Restricted holidays (a show day for one region, a public-service-only day) never decide it and are returned under restricted for the caller to apply to the employer's area.

Input parameters:

- `date` (string, required): The date, YYYY-MM-DD
- `jurisdiction` (string, required): Jurisdiction code

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/io-dataquoll-data-api/api-mcp#diagnostics

## Score history

- 2026-10-02: 39
- 2026-10-01: 39
- 2026-09-30: 39
- 2026-09-29: 39
- 2026-09-28: 39
- 2026-09-27: 39
- 2026-09-26: 39
- 2026-09-25: 39
- 2026-09-24: 39
- 2026-09-23: 39
- 2026-09-22: 39
- 2026-09-21: 39
- 2026-09-20: 39
- 2026-09-19: 39
- 2026-09-18: 39
- 2026-09-17: 39
- 2026-09-16: 39
- 2026-09-15: 39
- 2026-09-14: 39
- 2026-09-13: 39
- 2026-09-12: 39
- 2026-09-11: 39
- 2026-09-10: 39
- 2026-09-09: 39
- 2026-09-08: 39
- 2026-09-07: 66
- 2026-09-06: 65

## Common questions

### What is the DataQuoll MCP server?

DataQuoll is an MCP server listed in the public MCP registry as io.dataquoll/data-api. Australian public data as MCP tools: incidents, gauges, declarations, industry calendars, archive. This page covers its hosted endpoint (https://dataquoll.io/api/mcp).

### Is the DataQuoll MCP server safe to use?

DataQuoll scores 39 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the DataQuoll MCP server expose?

DataQuoll exposes 22 tools: list_incidents, get_incident, nearby_incidents, incident_snapshot, list_historical_incidents, and 17 more. Their descriptions and schemas cost roughly 4,064 tokens of context every time the server is loaded.

### Does the DataQuoll MCP server require authentication?

Yes. DataQuoll asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

### Is the DataQuoll MCP server still maintained?

DataQuoll is still listed as active in the MCP registry. We last reached this channel on 2 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://dataquoll.io/api/mcp
- Authorisation metadata: https://dataquoll.io/.well-known/oauth-protected-resource/api/mcp
- Website: https://dataquoll.io/mcp
- Changelog RSS feed: https://verifymcp.io/servers/io-dataquoll-data-api/api-mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/io-dataquoll-data-api/api-mcp.json
- HTML version of this page: https://verifymcp.io/servers/io-dataquoll-data-api/api-mcp
