hovhannes.io
REMOTE · HOVHANNES.IO · SCANNED SEP 21
Yerevan Product Coffee: table dates, remaining seats, seat requests, and the field notes behind it.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security66
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 5 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability89
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Tool/resource definitions use about 2042 tokens (~88/item across 23 items; 6 tools + 17 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management87
- Stability observed for 26 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 6 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 7 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the hovhannes.io MCP server?
hovhannes.io is a hosted endpoint at https://hovhannes.io/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · hovhannes.io
claude mcp add --transport http io-hovhannes-site 'https://hovhannes.io/mcp'
{
"mcpServers": {
"io-hovhannes-site": {
"url": "https://hovhannes.io/mcp"
}
}
} {
"servers": {
"io-hovhannes-site": {
"type": "http",
"url": "https://hovhannes.io/mcp"
}
}
} [mcp_servers.io-hovhannes-site] url = "https://hovhannes.io/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"io-hovhannes-site": {
"type": "remote",
"url": "https://hovhannes.io/mcp",
"enabled": true
}
}
} openclaw mcp add io-hovhannes-site --url 'https://hovhannes.io/mcp' --transport streamable-http
mcp_servers:
io-hovhannes-site:
url: "https://hovhannes.io/mcp" {
"McpServers": {
"io-hovhannes-site": {
"Transport": "http",
"Url": "https://hovhannes.io/mcp"
}
}
} assistant mcp add io-hovhannes-site -t streamable-http -u 'https://hovhannes.io/mcp'
{
"mcpServers": {
"io-hovhannes-site": {
"type": "http",
"url": "https://hovhannes.io/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 21 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.
- 19 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 77 to 80. That category is still filling its 30-day observation window: 23 days of observed history at the previous scan, 24 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 70 to 73. That category is still filling its 30-day observation window: 21 days of observed history at the previous scan, 22 at this one. The score rises as the window fills, whether or not the server changes.
- 15 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 63 to 67. That category is still filling its 30-day observation window: 19 days of observed history at the previous scan, 20 at this one. The score rises as the window fills, whether or not the server changes.
- 13 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 50 to 53. That category is still filling its 30-day observation window: 15 days of observed history at the previous scan, 16 at this one. The score rises as the window fills, whether or not the server changes.
- 9 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 43 to 47. That category is still filling its 30-day observation window: 13 days of observed history at the previous scan, 14 at this one. The score rises as the window fills, whether or not the server changes. Other categories moved too: Schema Quality & AI Usability rose 1.
- 7 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 37 to 40. That category is still filling its 30-day observation window: 11 days of observed history at the previous scan, 12 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 21 Sept 2026 · Probed https://hovhannes.io/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=hovhannes.io | CN=WE1,O=Google Trust Services,C=US | 17 Sept 2026 | 16 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | 7e0edae97b7998d90ef2bf4f531268de |
| SANs: hovhannes.io, www.hovhannes.io, *.www.hovhannes.io | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC secure
Validation of hovhannes.io. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| io. | present | 57355 | 8 | Verified |
| hovhannes.io. | present | 2371 | 13 | Verified |
| hovhannes.io. | Verified address RRset verified with the apex keys |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains; preload |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | geolocation=(), microphone=(), camera=(), payment=() |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://hovhannes.io/mcp | Verified | 200 | |
| http (plaintext) | http://hovhannes.io/mcp | HTTPS enforced | 301 | https://hovhannes.io/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
get_field_note Read one field note in full ~114
The complete text of a single field note. Use this after search_field_notes or list_field_notes, which return only an excerpt. Accepts the slug, the path, or the full URL — 'what-30-days-of-crawler-logs-showed', '/what-30-days-of-crawler-logs-showed' and 'https://hovhannes.io/what-30-days-of-crawler-logs-showed' all work.
| Name | Type | Req | Description |
|---|---|---|---|
| note | string | yes | The note's slug, path, or URL |
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | – |
| publishedAt | string | yes | – |
| readTime | string | – | – |
| text | string | yes | The note in full, as plain text |
| title | string | yes | – |
| url | string | yes | – |
No examples provided.
get_sprint_details Clarity Sprint details ~52
What a Clarity Sprint is, what it produces, how long it takes, what it costs, and where to apply. Use this when asked how to work with Hovhannes or what he offers.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| applyAt | string | yes | – |
| deliverable | string | yes | – |
| duration | string | yes | – |
| guarantee | string | yes | – |
| name | string | yes | – |
| price | string | yes | – |
| summary | string | yes | – |
| url | string | yes | – |
No examples provided.
list_field_notes List every field note ~51
Every published field note with its title, category and date, newest first. Use this to see the full range of what has been written before searching within it, then get_field_note to read one in full.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| count | number | yes | – |
| notes | array | yes | – |
No examples provided.
list_upcoming_tables Upcoming Yerevan Product Coffee tables ~70
The scheduled dates for the private six-person product roundtable in Yerevan, with how many guest seats remain on each. Use this to answer when the next table is or whether a given date still has room, and to get the exact `startsAt` value that request_table_seat needs.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| tables | array | yes | – |
No examples provided.
request_table_seat Request a seat at a Yerevan Product Coffee table ~535
Ask for one of the five guest seats at a Yerevan Product Coffee table. Call list_upcoming_tables first and pass one of its exact `startsAt` values. This sends a real request to a real person, so it takes two calls: call it once to see exactly what would be sent, show that to the person it is about, then call it again with the same values and confirm: true. A request is not a booking — Hovhannes reads each one himself and replies within 3–5 days, and no seat is held until he does.
| Name | Type | Req | Description |
|---|---|---|---|
| building | string | – | What they are building, in their own words. Optional but read |
| confirm | boolean | – | Leave unset or false to validate and preview without sending anything. Set to true only after the person has seen the preview and agreed to it |
| contribution | string | – | What they can offer the other five people. Optional |
| discussionQuestion | string | – | The one real decision or trade-off they are stuck on and want the table's help with. Optional, and the single most useful thing to include |
| string | yes | Their email address. The reply and the confirmation both go here, so it has to be one they read | |
| eventStart | string | yes | Which table. The exact `startsAt` from list_upcoming_tables is best, but the calendar day on its own ("2026-09-10") or the word "next" also resolve against the real schedule |
| fullName | string | yes | The applicant's full name, as they would write it |
| linkedinUrl | string | yes | Their personal LinkedIn profile URL (linkedin.com/in/…). Required: seats are chosen on who sits together, which cannot be judged from a name. Company pages, posts and shortened links are refused |
| motivation | string | – | Why this table, now. Optional |
| perspective | string | yes | The perspective they bring: founder (Building or validating a product of your own.); product (Deciding scope, priority, discovery, and delivery.); design-research (Bringing users, flows, and evidence… |
| phone | string | yes | Their phone number with its country code, like +374 11 22 33 44. Used only on the evening itself and deleted if the request is closed |
| Name | Type | Req | Description |
|---|---|---|---|
| alreadyRequested | boolean | – | – |
| confirmationEmailStatus | string | – | – |
| confirmationEmailedTo | string | – | – |
| dailyLimit | string | – | – |
| duplicate | boolean | – | – |
| instruction | string | – | – |
| message | string | – | – |
| needsConfirmation | boolean | – | – |
| privacyNote | string | – | – |
| status | string | – | – |
| submitted | boolean | yes | – |
| table | string | – | – |
| whatHappensOnConfirm | array | – | – |
| willSubmit | object | – | – |
No examples provided.
search_field_notes Search the field notes ~87
Search Hovhannes Hovhannisyan's written field notes on product planning, MVP scope, and building with AI agents. Returns the closest notes with a short excerpt and a link. Use this when asked what he has written or thinks about a product topic, then get_field_note to read one in full.
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | yes | What to look for, in words |
| Name | Type | Req | Description |
|---|---|---|---|
| matchCount | number | yes | – |
| notes | array | yes | – |
| query | string | yes | – |
No examples provided.
What is the hovhannes.io MCP server?
hovhannes.io is an MCP server listed in the public MCP registry as io.hovhannes/site. Yerevan Product Coffee: table dates, remaining seats, seat requests, and the field notes behind it. This page covers its hosted endpoint (https://hovhannes.io/mcp).
Is the hovhannes.io MCP server safe to use?
hovhannes.io scores 83 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the hovhannes.io MCP server expose?
hovhannes.io exposes 6 tools: list_upcoming_tables, search_field_notes, get_sprint_details, list_field_notes, request_table_seat, get_field_note. Their descriptions and schemas cost roughly 909 tokens of context every time the server is loaded.
Does the hovhannes.io MCP server require authentication?
No. We connected to hovhannes.io without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the hovhannes.io MCP server still maintained?
hovhannes.io is still listed as active in the MCP registry. We last reached this channel on 21 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.