JSONPad documentation
NPM · @BASEMENTUNIVERSE/JSONPAD-DOCS-MCP · 2 COMPONENTS · SCANNED OCT 4
JSONPad docs, API, SDK and CLI references, and offline checkers for write rules and flows.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security98
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- No install/post-install scripts declared.Pass
- 31 of 96 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency19
- Repository check failed: no source repository is declared. See how to fix → View diagnostics → Fail
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 3 days ago).Pass
- Security-disclosure policy not yet verified: we couldn't inspect the source repository.Unverified
Schema Quality & AI Usability87
- 97% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Partial
- AI-judged instruction clarity (excellent).Pass
- Tool/resource definitions use about 6407 tokens (~46/item across 138 items; 14 tools + 124 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety75
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 0 of 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "eval_write_rule" implies "eval" and declares readOnlyHint instead, contradicting what its own name says it does. See how to fix → Fail
- An AI judge read all 16 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Unverified: 1 category
A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.
How do I install the JSONPad documentation MCP server?
JSONPad documentation runs locally as an npm package, launched with npx -y @basementuniverse/jsonpad-docs-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · @basementuniverse/jsonpad-docs-mcp
claude mcp add io-jsonpad-docs -- npx -y @basementuniverse/jsonpad-docs-mcp
{
"mcpServers": {
"io-jsonpad-docs": {
"command": "npx",
"args": [
"-y",
"@basementuniverse/jsonpad-docs-mcp"
]
}
}
} {
"servers": {
"io-jsonpad-docs": {
"command": "npx",
"args": [
"-y",
"@basementuniverse/jsonpad-docs-mcp"
]
}
}
} codex mcp add io-jsonpad-docs -- npx -y @basementuniverse/jsonpad-docs-mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"io-jsonpad-docs": {
"type": "local",
"command": [
"npx",
"-y",
"@basementuniverse/jsonpad-docs-mcp"
],
"enabled": true
}
}
} openclaw mcp add io-jsonpad-docs --command npx --arg -y --arg @basementuniverse/jsonpad-docs-mcp
mcp_servers:
io-jsonpad-docs:
command: "npx"
args: ["-y", "@basementuniverse/jsonpad-docs-mcp"] {
"McpServers": {
"io-jsonpad-docs": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"@basementuniverse/jsonpad-docs-mcp"
]
}
}
} assistant mcp add io-jsonpad-docs -t stdio -c npx -a -y @basementuniverse/jsonpad-docs-mcp
{
"mcpServers": {
"io-jsonpad-docs": {
"command": "npx",
"args": [
"-y",
"@basementuniverse/jsonpad-docs-mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 1 Oct 26 +15
- Malware scan: unverified → pass ▲ security
- 30 Sept 26 50
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 4 Oct 2026 · Analysed npm/@basementuniverse/jsonpad-docs-mcp@0.1.0
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | npm |
Background: How many MCP packages publish verified provenance →
Dependencies 96 packages
| Packages resolved | 96 |
|---|---|
| Stale | 31 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
check_flow Check a flow ~121
Compile a flow document (flows-v1) with the same engine the API uses, and run its tests (flow-tests-v1) against in-memory data. Returns diagnostics (with JSON pointers into the document), what the flow reads and writes, and why each failing test failed. Costs nothing and sees no data.
| Name | Type | Req | Description |
|---|---|---|---|
| flow | – | yes | The flow document |
| knownLists | array | – | Path names of lists that exist, so the flow using any other list is warned about |
| tests | – | – | The flow tests: a flow-tests-v1 document, optional |
| Name | Type | Req | Description |
|---|---|---|---|
| diagnostics | array | yes | – |
| ok | boolean | yes | – |
No examples provided.
check_write_rules Check write rules ~163
Compile a list's write rules with the same engine the API uses, and run their tests (a rules-tests-v1 document). Returns every diagnostic with its line and column, and for each failing test what it expected, what happened, and how each rule came out. Costs nothing and sees no data: lookups find the test document's items. Use it before saving rules.
| Name | Type | Req | Description |
|---|---|---|---|
| knownLists | array | – | Path names of lists that exist, so lookups into any other list are warned about, as the API does when rules are saved |
| rules | – | yes | The rule text, or its lines as an array (as in a schema sync document) |
| tests | – | – | The rule tests: a rules-tests-v1 document ({ "tests": [...] }), optional |
| Name | Type | Req | Description |
|---|---|---|---|
| diagnostics | array | yes | – |
| ok | boolean | yes | – |
No examples provided.
eval_write_rule Try a write against write rules ~182
Check one write against a rule set, as the API would, and say whether it would be allowed, denied (403) or failed (400), which statement decided it, and (with trace) what every expression evaluated to. The write is shaped like a rule test case: action, identity, token, old, new, patch, merge, now. Costs nothing and sees no data.
| Name | Type | Req | Description |
|---|---|---|---|
| identities | object | – | Named identities the write can refer to |
| items | object | – | Items for lookups to find: { "<list>": { "<item id or alias>": { "data": ... } } } |
| rules | – | yes | The rule text, or its lines as an array (as in a schema sync document) |
| trace | boolean | – | Include the value of every expression |
| write | object | yes | The write to check |
| Name | Type | Req | Description |
|---|---|---|---|
| ok | boolean | yes | – |
No examples provided.
get_api_endpoint Get a JSONPad API endpoint contract ~148
The full contract of one REST API endpoint: parameters, headers, request body, responses and examples, and the JavaScript SDK method that calls it. Find it by id (the docs page slug, e.g. "item-restore"), by method and path (templates or concrete paths both work: "/lists/my-list/items/abc"), or by a description.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | – | The endpoint id, from list_api_endpoints |
| method | string | – | The HTTP method |
| path | string | – | The path, e.g. /lists/{listId}/items |
| query | string | – | What the endpoint does, e.g. "restore a deleted item" |
| Name | Type | Req | Description |
|---|---|---|---|
| endpoint | object | yes | – |
No examples provided.
get_cli_command Get a JSONPad CLI command ~106
The usage, arguments and options of a jsonpad command line tool (@basementuniverse/jsonpad-cli) command, and whether it works offline. Find it by name ("rules test", "jsonpad sync-schema --dry-run") or by what it does.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | – | The command, e.g. "sync-schema" or "jsonpad rules test" |
| query | string | – | What the command does, e.g. "export items to a file" |
| Name | Type | Req | Description |
|---|---|---|---|
| command | object | yes | – |
No examples provided.
get_plan_limits Get JSONPad plan limits ~110
The limits of each public plan (Free, Indie, Pro, Scale): requests per month and minute, the minimum gap between requests, storage, item size, versions kept, tokens, identities, realtime connections, webhooks and flows. null means unlimited. Sizes are in bytes, rateLimit in milliseconds, prices in GBP.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | string | – | One limit, e.g. maxItemSize |
| plan | string | – | One plan, by id or name, e.g. "free" |
| Name | Type | Req | Description |
|---|---|---|---|
| plans | array | yes | – |
No examples provided.
get_sdk_method Get a JSONPad SDK method ~106
The signature, description and example of a method in the JavaScript SDK (@basementuniverse/jsonpad-sdk) or the realtime SDK, and the REST endpoint it calls. Find it by name ("restoreItem") or by what it does.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | – | The method name, e.g. restoreItem |
| package | string | – | Only one package |
| query | string | – | What the method does, e.g. "wait for an index to build" |
| Name | Type | Req | Description |
|---|---|---|---|
| method | object | yes | – |
No examples provided.
list_api_endpoints List the JSONPad API endpoints ~47
List the REST API endpoints an API token can use, as method, path and title. Get one in full with get_api_endpoint.
| Name | Type | Req | Description |
|---|---|---|---|
| resource | string | – | Only one resource |
| Name | Type | Req | Description |
|---|---|---|---|
| endpoints | array | yes | – |
No examples provided.
list_docs List the JSONPad docs pages ~37
List the documentation pages by section, with a description of each: the table of contents.
| Name | Type | Req | Description |
|---|---|---|---|
| section | string | – | Only list one section |
| Name | Type | Req | Description |
|---|---|---|---|
| sections | array | yes | – |
No examples provided.
lookup_error Look up a JSONPad error ~95
What a JSONPad API error code means, its HTTP status, and the guides that explain it. Give the numeric code (10013) or the name (QUOTA_EXCEEDED), as found in an error response's "code" and "name".
| Name | Type | Req | Description |
|---|---|---|---|
| code | integer | – | The numeric code, e.g. 10013 |
| name | string | – | The name, e.g. QUOTA_EXCEEDED |
| Name | Type | Req | Description |
|---|---|---|---|
| error | object | yes | – |
No examples provided.
read_doc Read a JSONPad docs page ~150
Read a documentation page as markdown, or one section of it. Give a page slug ("indexing"), a /docs path, a jsonpad.io URL (with or without .md, and with an optional #anchor), "sdk/jsonpad-sdk", "sdk/jsonpad-realtime-sdk", "cli/reference" or "cli/readme". Long pages are cut at a section boundary; read on with the returned nextSection.
| Name | Type | Req | Description |
|---|---|---|---|
| maxChars | integer | – | The most characters of markdown to return |
| page | string | yes | The page: a slug, path or URL |
| section | string | – | A heading anchor ("filtering-items") or heading text; overrides a #anchor in page |
| Name | Type | Req | Description |
|---|---|---|---|
| markdown | string | yes | – |
| title | string | yes | – |
| truncated | boolean | yes | – |
| url | string | yes | – |
No examples provided.
search_docs Search the JSONPad docs ~147
Search the JSONPad documentation, the JavaScript SDK references and the command line tool reference. Returns the best-matching sections with a snippet and their jsonpad.io URL; read one with read_doc. Exact identifiers work well: error codes and names, headers, SDK methods, CLI commands, $jsonpad-var variables, "POST /lists/{listId}/items".
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | How many results (1-10) |
| query | string | yes | What to look for |
| section | string | – | Only search one section: guides, api-reference (every API reference section), lists, items, indexes, identities, tokens, flows, schema-sync, sdk or cli |
| Name | Type | Req | Description |
|---|---|---|---|
| results | array | yes | – |
No examples provided.
validate_sync_document Validate a schema sync document ~155
Check a schema sync document (sync-v1) as far as possible without an account: against the JSON schema the API uses, the API's rules for keys and indexes, and every rule set and flow in it with their tests. Documents that reference files (rulesFile, flowFile and their tests) are checked too if the files' contents are given in files. What a sync would change needs the account: the API server's plan_schema_sync, or jsonpad sync-schema --dry-run.
| Name | Type | Req | Description |
|---|---|---|---|
| document | – | yes | The schema sync document |
| files | object | – | The contents of files the document references, keyed by the path written in the document, e.g. { "rules/games.rules": "allow ..." } |
| Name | Type | Req | Description |
|---|---|---|---|
| ok | boolean | yes | – |
| problems | array | yes | – |
No examples provided.
validate_token_permissions Validate token permissions ~108
Check an API token's permission rules against the schema the API uses, say which rule shape a broken one was meant to be, and warn about valid rules that probably don't do what was meant (rule order, restore without view, sync-schema alone, allow "*").
| Name | Type | Req | Description |
|---|---|---|---|
| permissions | – | yes | The permission rules, e.g. [{ "mode": "allow", "action": "view", "resourceType": "item", "listIds": ["*"], "itemIds": ["*"] }] |
| Name | Type | Req | Description |
|---|---|---|---|
| ok | boolean | yes | – |
No examples provided.
What is the JSONPad documentation MCP server?
JSONPad documentation is an MCP server listed in the public MCP registry as io.jsonpad/docs. JSONPad docs, API, SDK and CLI references, and offline checkers for write rules and flows. This page covers its npm package (@basementuniverse/jsonpad-docs-mcp).
Is the JSONPad documentation MCP server safe to use?
JSONPad documentation scores 65 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 4 October 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the JSONPad documentation MCP server expose?
JSONPad documentation exposes 14 tools: search_docs, read_doc, list_docs, list_api_endpoints, get_api_endpoint, and 9 more. Their descriptions and schemas cost roughly 1,675 tokens of context every time the server is loaded.
Is the JSONPad documentation MCP server still maintained?
JSONPad documentation is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the JSONPad documentation MCP server under?
JSONPad documentation declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.