TGGET Niche Research
REMOTE · TGGET.IO · SCANNED OCT 4
Validate app and SaaS ideas: search demand, competitors, app store data and a verdict.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security86
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, but the challenge carries no valid RFC 9728 metadata, so a client cannot discover where to get a token. See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability80
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2253 tokens (~187/item across 12 items; 10 tools + 2 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management17
- Stability observed for 5 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 10 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 12 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the TGGET Niche Research MCP server?
TGGET Niche Research is a hosted endpoint at https://tgget.io/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · tgget.io
claude mcp add --transport http io-tgget-niche-research 'https://tgget.io/mcp'
{
"mcpServers": {
"io-tgget-niche-research": {
"url": "https://tgget.io/mcp"
}
}
} {
"servers": {
"io-tgget-niche-research": {
"type": "http",
"url": "https://tgget.io/mcp"
}
}
} [mcp_servers.io-tgget-niche-research] url = "https://tgget.io/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"io-tgget-niche-research": {
"type": "remote",
"url": "https://tgget.io/mcp",
"enabled": true
}
}
} openclaw mcp add io-tgget-niche-research --url 'https://tgget.io/mcp' --transport streamable-http
mcp_servers:
io-tgget-niche-research:
url: "https://tgget.io/mcp" {
"McpServers": {
"io-tgget-niche-research": {
"Transport": "http",
"Url": "https://tgget.io/mcp"
}
}
} assistant mcp add io-tgget-niche-research -t streamable-http -u 'https://tgget.io/mcp'
{
"mcpServers": {
"io-tgget-niche-research": {
"type": "http",
"url": "https://tgget.io/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Oct 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.
- 1 Oct 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 30 Sept 26 0
- Stability: unverified → 0.03 ▲ functional
- 29 Sept 26 77
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 4 Oct 2026 · Probed https://tgget.io/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=tgget.io | CN=YE1,O=Let's Encrypt,C=US | 24 Sept 2026 | 23 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 5d545cb07158da56bc69949e92f9326aef1 |
| SANs: tgget.io, www.tgget.io | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC secure
Validation of tgget.io. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| io. | present | 57355 | 8 | Verified |
| tgget.io. | present | 40880 | 13 | Verified |
| tgget.io. | Verified address RRset verified with the apex keys |
Authentication Challenged, unverified
The endpoint asked for a token, but we could not retrieve and validate the RFC 9728 metadata that tells a client how to obtain one.
| Result | Challenged, unverified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer realm="mcp", error="invalid_token"
Bearer realm="mcp", error="invalid_token" | Header | Value |
|---|---|
| x-content-type-options | nosniff |
| x-frame-options | SAMEORIGIN |
| referrer-policy | strict-origin-when-cross-origin |
Protected resource metadata
| Retrieved | No |
|---|---|
| Problem | no_resource_metadata |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://tgget.io/mcp | Verified | 200 | |
| http (plaintext) | http://tgget.io/mcp | HTTPS enforced | 301 | https://tgget.io/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
compare_research Compare Research ~249
Puts two to five finished niche scans side by side to help choose between ideas. `items` are the niches with their numbers, the report's positioning and napkin economics, and `wins`: in how many rows the niche holds the better value. `rows` are the ranked measures (verdict, demand, trend, cost per click, weak search results, competitor sites, App Store apps, fresh community signals) with the value of every niche and `best`, the indexes of the items that hold the better value; `better` says which way is better (max or min), null when the row is shown but not ranked. Demand and cost per click are not ranked across different markets (`mixed_markets`). The marks are computed from numbers, not written by a language model. Every scan needs a finished report. `share_url` is a read-only link to this comparison that works without signing in: give it to the person only when they want to share the comparison, it shows the numbers and the conclusions of their researches to whoever holds it.
| Name | Type | Req | Description |
|---|---|---|---|
| ids | array | yes | Two to five ids of finished niche scans (or of their reports), as listed by list_research. |
No output schema declared.
No examples provided.
follow_niche Follow Niche ~106
Starts following the niche of a finished scan that has a report: the scan becomes the first measurement and the niche is scanned anew every month, with a digest of what changed sent to the account. Monthly checks do not spend researches; the plan limits how many niches are followed (FREE 1, Starter 2, Pro 10). Following a niche that is already followed returns its project.
| Name | Type | Req | Description |
|---|---|---|---|
| research_id | string | yes | Id of a finished niche scan, or of its report. |
No output schema declared.
No examples provided.
get_project Get Project ~100
Returns a followed niche with the history of its checks, newest first: the first measurement (`baseline`) and the monthly checks, each with its numbers, what changed since the previous check and the id of the research it came from. Pass that `research_id` to get_report to read the fresh report of a check. Changes are computed from numbers and lists, not written by a language model.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Project id listed by list_projects. |
No output schema declared.
No examples provided.
get_report Get Report ~223
Returns the final niche report of a finished scan (or the report research itself) as Markdown: verdict, what product to build (customer pains with evidence and severity, positioning, MVP with the pain each feature relieves, platform, monetization, competitor matrix), napkin economics (price hypothesis, acquisition cost from the cost per click in paid search, revenue per customer, whether it adds up, assumptions), SEO plan for the site (clusters, pages with title/H1/description, content plan, FAQ), ASO for App Store and Google Play, name options with domain and App Store availability, landing page draft, distribution channels by type with a first step, effort and priority, validation steps and risks. Pass format "json" for structured data (keys: verdict, product, economics, seo, aso, names, landing, channels, validation, risks).
| Name | Type | Req | Description |
|---|---|---|---|
| format | string | – | markdown (default) for reading, json for structured fields. |
| id | string | yes | Id of the scan research (its latest report is returned) or of the report itself. |
No output schema declared.
No examples provided.
get_research Get Research ~85
Returns the current state and findings of a research by id: status, headline numbers, ranked candidate phrases, competitor overview, child researches (sub-topics, competitor checks, signals) with their ids, and skipped stages. Call repeatedly until status is completed and pending is 0.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Research id returned by start_research or listed by list_research. |
No output schema declared.
No examples provided.
list_projects List Projects ~129
Lists the niches the account follows. A followed niche (a project) is scanned anew once a month and compared with its previous check. For each project: status, whether the plan serves it, the date of the next check, the latest numbers (verdict, demand, cost per click, competitor sites, App Store, community signals) and what changed at the latest monthly check, as structured `changes` and as `digest` lines of text. Also returns how many niches the plan follows.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | How many projects to return, 1-50 (default 20). |
No output schema declared.
No examples provided.
list_research List Research ~165
Lists the researches the account started itself, newest first: niche scans of a phrase and descriptions of an idea, without the checks they spawned. Use it to find the id of an earlier research before get_research, get_report, compare_research or follow_niche, or to see what is still running. Each item has `id`, `kind`, `phrase`, `status` (queued, running, completed, failed), `mode`, `created_at`, `url` of its page and `total_count`: monthly searches of the phrase, null for a description. `quota` tells how many researches the plan has left. Reads only; spends nothing.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | How many researches to return, from 1 to 50. Default 10. |
No output schema declared.
No examples provided.
run_signal Run Signal ~516
Adds one check to a finished research and returns the id of the new child research. Use it when the scan skipped a stage, when a person asks about one phrase in particular, or to rebuild the report after new checks. A niche scan already runs the usual checks by itself, so this tool is for what is missing. Checks added this way are free: they do not spend researches of the plan. Checks of a demand research (`kind`): - `competitors`: who holds the search results for a phrase of the research; pass the phrase in `phrase`. - `dynamics`: two years of demand history. - `appstore`: App Store apps for the phrase with ratings and freshness. - `wiki`, `radar`, `youtube`: public interest and community signals. - `paid`: paid search for the phrase and its strongest candidates: volume, advertiser competition, cost per click. - `insight`: a summary of the findings written by the language model. - `report`: the final niche report, written anew from the current data; needs a finished niche scan. Checks of a child research: - `fingerprint`: product sites found by a competitors check, with pricing and app links; the parent is that competitors check. - `reviews`: recent App Store reviews of the leaders; the parent is an App Store research. - `insight` also accepts a competitors check as the parent. The parent must be completed and belong to the account. The check runs in the background: poll get_research with the returned `id` every 20-30 seconds until `status` is `completed`. `insight` and `report` are rebuilt at most once an hour.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Id of the completed research the check is added to, as returned by start_research, get_research or list_research. |
| kind | string | yes | Which check to add. competitors, dynamics, appstore, wiki, radar, youtube, paid and report need a demand research as the parent; fingerprint a competitors check; reviews an App Store research; insigh… |
| locale | string | – | Only for insight and report: language of the text. Defaults to the language the research was started with, then to the language of the account. |
| phrase | string | – | Only for competitors: the phrase whose search results are checked, usually one of the candidate phrases of the parent. Defaults to the phrase of the parent. Ignored by the other checks. |
No output schema declared.
No examples provided.
start_research Start Research ~210
Starts a niche research from a short search phrase or a plain-language description of an app or service idea. A phrase is scanned directly (demand, sub-topics, competitors, signals); a description is first turned into real search queries, the best one is then scanned automatically. Returns the research id to poll with get_research. Counts as one research of the plan allowance, whether the data comes from the sources or from the shared cache.
| Name | Type | Req | Description |
|---|---|---|---|
| deep | boolean | – | Deeper scan with more sub-topics and competitor checks. Available on plans that include it (Pro) and to administrators; counted as two researches. |
| locale | string | – | Language of the conclusions and the final report. Defaults to the interface language of the account. Texts meant for the site and the stores are always written in the language of the market. |
| text | string | yes | Search phrase (e.g. "expense tracker") or a description of the idea in your own words, up to 400 characters. |
No output schema declared.
No examples provided.
update_project Update Project ~100
Pauses a followed niche (`paused`: no monthly checks, its place in the plan is freed), follows it again (`active`, needs a free place in the plan) or stops following it (`deleted`: the project with its checks and digests is removed for good, the researches stay in the history). Ask the person before deleting.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Project id listed by list_projects. |
| status | string | yes | active, paused or deleted. |
No output schema declared.
No examples provided.
What is the TGGET Niche Research MCP server?
TGGET Niche Research is an MCP server listed in the public MCP registry as io.tgget/niche-research. Validate app and SaaS ideas: search demand, competitors, app store data and a verdict. This page covers its hosted endpoint (https://tgget.io/mcp).
Is the TGGET Niche Research MCP server safe to use?
TGGET Niche Research scores 79 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the TGGET Niche Research MCP server expose?
TGGET Niche Research exposes 10 tools: start_research, get_research, get_report, list_research, run_signal, and 5 more. Their descriptions and schemas cost roughly 1,883 tokens of context every time the server is loaded.
Does the TGGET Niche Research MCP server require authentication?
Yes. TGGET Niche Research asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the TGGET Niche Research MCP server still maintained?
TGGET Niche Research is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.