Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

JSONPad documentation

REMOTE · MCP.JSONPAD.IO · 2 COMPONENTS · SCANNED OCT 4

JSONPad docs, API, SDK and CLI references, and offline checkers for write rules and flows.

74 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security74
Transport & Reachability100
Schema Quality & AI Usability87
  • 97% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Partial
  • AI-judged instruction clarity (excellent).Pass
  • Tool/resource definitions use about 6365 tokens (~46/item across 138 items; 14 tools + 124 resources), lean.Pass
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management13
  • Stability observed for 4 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety75
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • 0 of 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "eval_write_rule" implies "eval" and declares readOnlyHint instead, contradicting what its own name says it does. See how to fix → Fail
  • An AI judge read all 16 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

How do I install the JSONPad documentation MCP server?

JSONPad documentation is a hosted endpoint at https://mcp.jsonpad.io/docs, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · mcp.jsonpad.io

# add to Claude Code
claude mcp add --transport http io-jsonpad-docs 'https://mcp.jsonpad.io/docs'
// .cursor/mcp.json
{
  "mcpServers": {
    "io-jsonpad-docs": {
      "url": "https://mcp.jsonpad.io/docs"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "io-jsonpad-docs": {
      "type": "http",
      "url": "https://mcp.jsonpad.io/docs"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.io-jsonpad-docs]
url = "https://mcp.jsonpad.io/docs"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "io-jsonpad-docs": {
      "type": "remote",
      "url": "https://mcp.jsonpad.io/docs",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add io-jsonpad-docs --url 'https://mcp.jsonpad.io/docs' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  io-jsonpad-docs:
    url: "https://mcp.jsonpad.io/docs"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "io-jsonpad-docs": {
      "Transport": "http",
      "Url": "https://mcp.jsonpad.io/docs"
    }
  }
}
# add to Vellum
assistant mcp add io-jsonpad-docs -t streamable-http -u 'https://mcp.jsonpad.io/docs'
// mcp.json
{
  "mcpServers": {
    "io-jsonpad-docs": {
      "type": "http",
      "url": "https://mcp.jsonpad.io/docs"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 4 Oct 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.

  • 3 Oct 26 +8
    • Judged manipulation: unverified → pass ▲ security
    • Schema quality: unverified → excellent ▲ functional
  • 2 Oct 26 −7
    • Judged manipulation: pass → unverified ▼ security
    • Schema quality: excellent → unverified ▼ functional
  • 1 Oct 26 0
    • Stability: unverified → 0.03 ▲ functional
  • 30 Sept 26 72

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 4 Oct 2026 · Probed https://mcp.jsonpad.io/docs

TLS valid

Negotiated TLS 1.3 with TLS_AES_256_GCM_SHA384 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=mcp.jsonpad.io CN=YE2,O=Let's Encrypt,C=US 30 Sept 2026 29 Dec 2026 ECDSA 256 ECDSA-SHA384 537c4bf179ea0005f5d8f2d1f109b6e4e95
SANs: mcp.jsonpad.io
CN=YE2,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 4df3b15dd6c0784c507cd37b58e6f115
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of mcp.jsonpad.io. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
io. present 57355 8 Verified
jsonpad.io. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://mcp.jsonpad.io/docs Verified 200
http (plaintext) http://mcp.jsonpad.io/docs HTTPS enforced 301 https://mcp.jsonpad.io/docs
MCP tools · 14 exposed · ~1,675 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
check_flow ~121

Compile a flow document (flows-v1) with the same engine the API uses, and run its tests (flow-tests-v1) against in-memory data. Returns diagnostics (with JSON pointers into the document), what the flow reads and writes, and why each failing test failed. Costs nothing and sees no data.

NameTypeReqDescription
flow–yesThe flow document
knownListsarray–Path names of lists that exist, so the flow using any other list is warned about
tests––The flow tests: a flow-tests-v1 document, optional
NameTypeReqDescription
diagnosticsarrayyes–
okbooleanyes–

No examples provided.

check_write_rules ~163

Compile a list's write rules with the same engine the API uses, and run their tests (a rules-tests-v1 document). Returns every diagnostic with its line and column, and for each failing test what it expected, what happened, and how each rule came out. Costs nothing and sees no data: lookups find the test document's items. Use it before saving rules.

NameTypeReqDescription
knownListsarray–Path names of lists that exist, so lookups into any other list are warned about, as the API does when rules are saved
rules–yesThe rule text, or its lines as an array (as in a schema sync document)
tests––The rule tests: a rules-tests-v1 document ({ "tests": [...] }), optional
NameTypeReqDescription
diagnosticsarrayyes–
okbooleanyes–

No examples provided.

eval_write_rule ~182

Check one write against a rule set, as the API would, and say whether it would be allowed, denied (403) or failed (400), which statement decided it, and (with trace) what every expression evaluated to. The write is shaped like a rule test case: action, identity, token, old, new, patch, merge, now. Costs nothing and sees no data.

NameTypeReqDescription
identitiesobject–Named identities the write can refer to
itemsobject–Items for lookups to find: { "<list>": { "<item id or alias>": { "data": ... } } }
rules–yesThe rule text, or its lines as an array (as in a schema sync document)
traceboolean–Include the value of every expression
writeobjectyesThe write to check
NameTypeReqDescription
okbooleanyes–

No examples provided.

get_api_endpoint ~148

The full contract of one REST API endpoint: parameters, headers, request body, responses and examples, and the JavaScript SDK method that calls it. Find it by id (the docs page slug, e.g. "item-restore"), by method and path (templates or concrete paths both work: "/lists/my-list/items/abc"), or by a description.

NameTypeReqDescription
idstring–The endpoint id, from list_api_endpoints
methodstring–The HTTP method
pathstring–The path, e.g. /lists/{listId}/items
querystring–What the endpoint does, e.g. "restore a deleted item"
NameTypeReqDescription
endpointobjectyes–

No examples provided.

get_cli_command ~106

The usage, arguments and options of a jsonpad command line tool (@basementuniverse/jsonpad-cli) command, and whether it works offline. Find it by name ("rules test", "jsonpad sync-schema --dry-run") or by what it does.

NameTypeReqDescription
namestring–The command, e.g. "sync-schema" or "jsonpad rules test"
querystring–What the command does, e.g. "export items to a file"
NameTypeReqDescription
commandobjectyes–

No examples provided.

get_plan_limits ~110

The limits of each public plan (Free, Indie, Pro, Scale): requests per month and minute, the minimum gap between requests, storage, item size, versions kept, tokens, identities, realtime connections, webhooks and flows. null means unlimited. Sizes are in bytes, rateLimit in milliseconds, prices in GBP.

NameTypeReqDescription
limitstring–One limit, e.g. maxItemSize
planstring–One plan, by id or name, e.g. "free"
NameTypeReqDescription
plansarrayyes–

No examples provided.

get_sdk_method ~106

The signature, description and example of a method in the JavaScript SDK (@basementuniverse/jsonpad-sdk) or the realtime SDK, and the REST endpoint it calls. Find it by name ("restoreItem") or by what it does.

NameTypeReqDescription
namestring–The method name, e.g. restoreItem
packagestring–Only one package
querystring–What the method does, e.g. "wait for an index to build"
NameTypeReqDescription
methodobjectyes–

No examples provided.

list_api_endpoints ~47

List the REST API endpoints an API token can use, as method, path and title. Get one in full with get_api_endpoint.

NameTypeReqDescription
resourcestring–Only one resource
NameTypeReqDescription
endpointsarrayyes–

No examples provided.

list_docs ~37

List the documentation pages by section, with a description of each: the table of contents.

NameTypeReqDescription
sectionstring–Only list one section
NameTypeReqDescription
sectionsarrayyes–

No examples provided.

lookup_error ~95

What a JSONPad API error code means, its HTTP status, and the guides that explain it. Give the numeric code (10013) or the name (QUOTA_EXCEEDED), as found in an error response's "code" and "name".

NameTypeReqDescription
codeinteger–The numeric code, e.g. 10013
namestring–The name, e.g. QUOTA_EXCEEDED
NameTypeReqDescription
errorobjectyes–

No examples provided.

read_doc ~150

Read a documentation page as markdown, or one section of it. Give a page slug ("indexing"), a /docs path, a jsonpad.io URL (with or without .md, and with an optional #anchor), "sdk/jsonpad-sdk", "sdk/jsonpad-realtime-sdk", "cli/reference" or "cli/readme". Long pages are cut at a section boundary; read on with the returned nextSection.

NameTypeReqDescription
maxCharsinteger–The most characters of markdown to return
pagestringyesThe page: a slug, path or URL
sectionstring–A heading anchor ("filtering-items") or heading text; overrides a #anchor in page
NameTypeReqDescription
markdownstringyes–
titlestringyes–
truncatedbooleanyes–
urlstringyes–

No examples provided.

search_docs ~147

Search the JSONPad documentation, the JavaScript SDK references and the command line tool reference. Returns the best-matching sections with a snippet and their jsonpad.io URL; read one with read_doc. Exact identifiers work well: error codes and names, headers, SDK methods, CLI commands, $jsonpad-var variables, "POST /lists/{listId}/items".

NameTypeReqDescription
limitinteger–How many results (1-10)
querystringyesWhat to look for
sectionstring–Only search one section: guides, api-reference (every API reference section), lists, items, indexes, identities, tokens, flows, schema-sync, sdk or cli
NameTypeReqDescription
resultsarrayyes–

No examples provided.

validate_sync_document ~155

Check a schema sync document (sync-v1) as far as possible without an account: against the JSON schema the API uses, the API's rules for keys and indexes, and every rule set and flow in it with their tests. Documents that reference files (rulesFile, flowFile and their tests) are checked too if the files' contents are given in files. What a sync would change needs the account: the API server's plan_schema_sync, or jsonpad sync-schema --dry-run.

NameTypeReqDescription
document–yesThe schema sync document
filesobject–The contents of files the document references, keyed by the path written in the document, e.g. { "rules/games.rules": "allow ..." }
NameTypeReqDescription
okbooleanyes–
problemsarrayyes–

No examples provided.

validate_token_permissions ~108

Check an API token's permission rules against the schema the API uses, say which rule shape a broken one was meant to be, and warn about valid rules that probably don't do what was meant (rule order, restore without view, sync-schema alone, allow "*").

NameTypeReqDescription
permissions–yesThe permission rules, e.g. [{ "mode": "allow", "action": "view", "resourceType": "item", "listIds": ["*"], "itemIds": ["*"] }]
NameTypeReqDescription
okbooleanyes–

No examples provided.

Common questions

What is the JSONPad documentation MCP server?

JSONPad documentation is an MCP server listed in the public MCP registry as io.jsonpad/docs. JSONPad docs, API, SDK and CLI references, and offline checkers for write rules and flows. This page covers its hosted endpoint (https://mcp.jsonpad.io/docs).

Is the JSONPad documentation MCP server safe to use?

JSONPad documentation scores 74 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the JSONPad documentation MCP server expose?

JSONPad documentation exposes 14 tools: search_docs, read_doc, list_docs, list_api_endpoints, get_api_endpoint, and 9 more. Their descriptions and schemas cost roughly 1,675 tokens of context every time the server is loaded.

Does the JSONPad documentation MCP server require authentication?

No. We connected to JSONPad documentation without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the JSONPad documentation MCP server still maintained?

JSONPad documentation is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.