# io.usefulapi/deputy (remote · deputy.usefulapi.io)

See rosters, timesheets, leave and staff in Deputy, and create shifts, leave and memos.

- Trust score: 77/100 (medium)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-03

## Components

- remote · `deputy.usefulapi.io`: 77/100 (this document), [markdown](https://verifymcp.io/servers/io-usefulapi-deputy/deputy.md), [page](https://verifymcp.io/servers/io-usefulapi-deputy/deputy)

## Channel facts

- Endpoint: `https://deputy.usefulapi.io/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.0.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-03.

- **Endpoint Security**: 89/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token.
  - HTTPS is enforced; there's no plaintext access path.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
  - The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 73/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 3270 tokens (~155/item across 21 items; 21 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 10/100
  - Stability observed for 3 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.
  - An AI judge read all 21 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 60/100
  - Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28.

## Install

### How do I install the io.usefulapi/deputy MCP server?

io.usefulapi/deputy is a hosted endpoint at https://deputy.usefulapi.io/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http io-usefulapi-deputy 'https://deputy.usefulapi.io/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "io-usefulapi-deputy": {
      "url": "https://deputy.usefulapi.io/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "io-usefulapi-deputy": {
      "type": "http",
      "url": "https://deputy.usefulapi.io/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.io-usefulapi-deputy]
url = "https://deputy.usefulapi.io/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "io-usefulapi-deputy": {
      "type": "remote",
      "url": "https://deputy.usefulapi.io/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add io-usefulapi-deputy --url 'https://deputy.usefulapi.io/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  io-usefulapi-deputy:
    url: "https://deputy.usefulapi.io/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "io-usefulapi-deputy": {
      "Transport": "http",
      "Url": "https://deputy.usefulapi.io/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add io-usefulapi-deputy -t streamable-http -u 'https://deputy.usefulapi.io/mcp'
```

### Other

```json
{
  "mcpServers": {
    "io-usefulapi-deputy": {
      "type": "http",
      "url": "https://deputy.usefulapi.io/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-10-03 (score 77, +1)

No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-10-02 (score 76, 0)

- [functional] Server version: 1.3.0 → 1.5.1

### 2026-10-01 (score 76, +5)

- [security improvement] HTTPS: unverified → pass
- [functional improvement] Stability: unverified → 0.03
- [functional] Server version: 1.0.0 → 1.3.0

### 2026-09-30 (score 71, +53)

- [security improvement] Authorization: unverified → pass
- [security improvement] Injection markers: unverified → pass
- [security improvement] Transport: fail → pass
- [security] First check of Judged manipulation: pass
- [security] First check of Authorization: partial
- [functional regression] MCP protocol: unverified → fail
- [functional improvement] Tool coverage: unverified → 100
- [functional] First check of Schema quality: fail
- [functional] First check of Schema quality: excellent
- [functional] First check of Schema quality: fail
- [functional] First check of Destructive annotations: 100
- [functional] First check of Tool coverage: 100

### 2026-09-29 (score 18)

First indexed and scored.

## MCP tools (21)

### `deputy_whoami` (~52 tokens)

Who am I

Return the Deputy user the token belongs to — name, employee id, company and permissions. A cheap way to confirm DEPUTY_INSTALL and the token are right. Deputy: GET /api/v1/me.

### `deputy_list_locations` (~47 tokens)

List locations

List the install's locations (workplaces). Deputy calls a location a Company; its Id is what other tools take as location_id. Deputy: GET /api/v1/resource/Company.

### `deputy_list_areas` (~152 tokens)

List areas

List areas (Deputy OperationalUnits — the rosterable sections of a location, e.g. Kitchen, Front of house). Shifts and timesheets belong to an area. Optionally only one location's areas. Deputy: GET /api/v1/resource/OperationalUnit, or POST .../OperationalUnit/QUERY when filtered.

Input parameters:

- `active` (boolean): Only active (true) or inactive (false) areas.
- `location_id` (integer): Only areas of this location (Company id).
- `max` (integer): Page size, 1-500 (Deputy's cap). Default 100.
- `start` (integer): Pagination offset (0-based). Pass the previous page's next_start.

### `deputy_list_employees` (~147 tokens)

List employees

Search employees by name, location or active status. Returns Id, DisplayName, Company (main location), Active, StartDate, Role and more. Deputy: POST /api/v1/resource/Employee/QUERY.

Input parameters:

- `active` (boolean): true = current staff only; false = terminated/inactive only.
- `location_id` (integer): Only employees whose main location is this Company id.
- `max` (integer): Page size, 1-500 (Deputy's cap). Default 100.
- `name_contains` (string): Only employees whose DisplayName contains this text.
- `start` (integer): Pagination offset (0-based). Pass the previous page's next_start.

### `deputy_get_employee` (~54 tokens)

Get one employee

Fetch one employee's details as a supervisor sees them — contact, locations, role and employment. Deputy: GET /api/v1/supervise/employee/{id}.

Input parameters:

- `employee_id` (integer, required): The employee id.

### `deputy_list_shifts` (~261 tokens)

List shifts

Search the roster (scheduled shifts) by time window, employee, area, and published/open state. Each record has StartTime/EndTime (unix), StartTimeLocalized, Employee (0 or null when open), OperationalUnit (area), Published, Open, Cost and _DPMetaData with names. Deputy: POST /api/v1/resource/Roster/QUERY.

Input parameters:

- `area_id` (integer): Only shifts in this area (OperationalUnit id).
- `employee_id` (integer): Only this employee's shifts.
- `from`: Only shifts starting at or after this time: a unix timestamp in seconds, or an ISO 8601 date/datetime (include an offset for local times).
- `max` (integer): Page size, 1-500 (Deputy's cap). Default 100.
- `open` (boolean): true = open (unfilled) shifts only.
- `published` (boolean): true = published only; false = drafts only.
- `start` (integer): Pagination offset (0-based). Pass the previous page's next_start.
- `to`: Only shifts starting at or before this time: a unix timestamp in seconds, or an ISO 8601 date/datetime (include an offset for local times).

### `deputy_get_shift` (~46 tokens)

Get one shift

Fetch one shift (Roster record) by id. Deputy: GET /api/v1/resource/Roster/{id}.

Input parameters:

- `shift_id` (integer, required): The shift (Roster) id.

### `deputy_list_timesheets` (~294 tokens)

List timesheets

Search timesheets (actual worked time) by time window, employee, area and approval state. Each record has StartTime/EndTime (unix; EndTime null while in progress), TotalTime (hours), Cost, TimeApproved, PayRuleApproved, IsInProgress, IsLeave, Roster (linked shift) and Exported. Deputy: POST /api/v1/resource/Timesheet/QUERY.

Input parameters:

- `area_id` (integer): Only timesheets in this area (OperationalUnit id).
- `employee_id` (integer): Only this employee's timesheets.
- `from`: Only timesheets starting at or after this time: a unix timestamp in seconds, or an ISO 8601 date/datetime (include an offset for local times).
- `in_progress` (boolean): true = only people currently on the clock.
- `max` (integer): Page size, 1-500 (Deputy's cap). Default 100.
- `pay_approved` (boolean): Filter on PayRuleApproved (approved for payroll export).
- `start` (integer): Pagination offset (0-based). Pass the previous page's next_start.
- `time_approved` (boolean): Filter on TimeApproved (supervisor approved the times).
- `to`: Only timesheets starting at or before this time: a unix timestamp in seconds, or an ISO 8601 date/datetime (include an offset for local times).

### `deputy_get_timesheet` (~55 tokens)

Get one timesheet

Fetch one timesheet's full details, including breaks and approval state. Deputy: GET /api/v1/supervise/timesheet/{id}/details.

Input parameters:

- `timesheet_id` (integer, required): The timesheet id.

### `deputy_list_leave` (~242 tokens)

List leave requests

Search leave requests by employee, location, status and time window. Status: 0 awaiting approval, 1 approved, 2 declined, 3 cancelled, 4 date approved without pay, 5 pay approved without date. Start/End are unix; LeaveRule is the leave type id. Deputy: POST /api/v1/resource/Leave/QUERY.

Input parameters:

- `employee_id` (integer): Only this employee's leave.
- `from`: Only leave starting at or after this time: a unix timestamp in seconds, or an ISO 8601 date/datetime (include an offset for local times).
- `location_id` (integer): Only leave against this location (Company id).
- `max` (integer): Page size, 1-500 (Deputy's cap). Default 100.
- `start` (integer): Pagination offset (0-based). Pass the previous page's next_start.
- `status` (integer): Only this status (0-5, see description).
- `to`: Only leave starting at or before this time: a unix timestamp in seconds, or an ISO 8601 date/datetime (include an offset for local times).

### `deputy_get_employee_unavailability` (~61 tokens)

Get an employee's unavailability

List the times one employee has marked themselves (or been marked) unavailable to work — check before rostering them. Deputy: GET /api/v1/supervise/unavail/{employeeId}.

Input parameters:

- `employee_id` (integer, required): The employee id.

### `deputy_query_resource` (~281 tokens)

Query any Deputy resource

Run a Resource API search on any business object (leave types, pay rules, public holidays, memos, events, shift templates, pay lines, availability, sales data, …). `search` is Deputy's clause map, e.g. {"s1":{"field":"Employee","data":12,"type":"eq"}}; operators: eq ne gt lt ge le is 'is not' in 'not in' starts contains. Use deputy_describe_resource to see an object's fields and joins. Read-only. Deputy: POST /api/v1/resource/{Object}/QUERY.

Input parameters:

- `join` (array): Related objects to expand inline, e.g. ["TimesheetObject"] on TimesheetPayReturn.
- `max` (integer): Page size, 1-500 (Deputy's cap). Default 100.
- `object` (string, required): Resource API object. Deputy names: Company = location, OperationalUnit = area, Roster = shift, LeaveRules = leave types, TimesheetPayReturn = approved pay lines.
- `search` (object): Clauses keyed by any id (s1, s2, …). All must match.
- `sort` (object): Field → asc/desc, e.g. {"Id":"desc"}.
- `start` (integer): Pagination offset (0-based). Pass the previous page's next_start.

### `deputy_describe_resource` (~92 tokens)

Describe a Deputy resource

Return a Resource API object's field list, field types and joinable associations — what deputy_query_resource can filter, sort and join on. Deputy: GET /api/v1/resource/{Object}/INFO.

Input parameters:

- `object` (string, required): Resource API object. Deputy names: Company = location, OperationalUnit = area, Roster = shift, LeaveRules = leave types, TimesheetPayReturn = approved pay lines.

### `deputy_create_shift` (~280 tokens)

Create a shift

Add a shift to the roster, assigned to an employee or left open. Created as a DRAFT unless publish is true (publishing can notify the employee). Deputy returns an empty 200 on success — use deputy_list_shifts to find the new shift's id. Deputy: POST /api/v1/supervise/roster.

Input parameters:

- `area_id` (integer, required): Area (OperationalUnit id) the shift is for.
- `comment` (string): Comment shown on the shift.
- `confirmed` (boolean): Mark the shift as confirmed.
- `employee_id` (integer): Employee to put on the shift. Omit (and set open: true) for an unfilled shift.
- `end_time` (required): Shift end: a unix timestamp in seconds, or an ISO 8601 datetime (include an offset for local times).
- `force_overwrite` (boolean): Overwrite a clashing shift for the same employee. Default false.
- `mealbreak_minutes` (integer): Unpaid meal break length in minutes.
- `open` (boolean): Show the shift as open for employees to claim.
- `publish` (boolean): Publish now. Publishing can notify the employee. Default false (draft).
- `start_time` (required): Shift start: a unix timestamp in seconds, or an ISO 8601 datetime (include an offset for local times).

### `deputy_update_shift` (~283 tokens)

Update a shift

Change an existing shift's times, area, employee, break or comment. Send the full intended shift (same fields as create) — Deputy's update is the add call with the shift id. Deputy: POST /api/v1/supervise/roster with intRosterId.

Input parameters:

- `area_id` (integer, required): Area (OperationalUnit id) the shift is for.
- `comment` (string): Comment shown on the shift.
- `confirmed` (boolean): Mark the shift as confirmed.
- `employee_id` (integer): Employee to put on the shift. Omit (and set open: true) for an unfilled shift.
- `end_time` (required): Shift end: a unix timestamp in seconds, or an ISO 8601 datetime (include an offset for local times).
- `force_overwrite` (boolean): Overwrite a clashing shift for the same employee. Default false.
- `mealbreak_minutes` (integer): Unpaid meal break length in minutes.
- `open` (boolean): Show the shift as open for employees to claim.
- `publish` (boolean): Publish now. Publishing can notify the employee. Default false (draft).
- `shift_id` (integer, required): The shift (Roster) id.
- `start_time` (required): Shift start: a unix timestamp in seconds, or an ISO 8601 datetime (include an offset for local times).

### `deputy_publish_shifts` (~115 tokens)

Publish shifts

Publish draft shifts so employees see them, choosing how they are notified: 1 SMS and email, 2 SMS, 3 email, 4 no notification, 5 confirmation required. Only the listed shift ids are published. Deputy: POST /api/v1/supervise/roster/publish.

Input parameters:

- `notify_mode` (integer, required): 1 SMS+email, 2 SMS, 3 email, 4 none, 5 confirmation required.
- `shift_ids` (array, required): Roster ids to publish.

### `deputy_create_leave_request` (~270 tokens)

Create a leave request

Add a leave request for an employee. By default it waits for manager approval (status 0); pass status 1 only when your system is the source of truth and the leave is already approved. Deputy tracks leave in hours, so give exact start and end times. Find leave type ids with deputy_query_resource on LeaveRules. Deputy: POST /api/v1/resource/Leave.

Input parameters:

- `approval_comment` (string): Manager's comment, when status is 1.
- `comment` (string, required): The employee's note to the manager.
- `employee_id` (integer, required): The employee id.
- `end_date` (string, required): Last day, YYYY-MM-DD.
- `end_time` (required): Leave end: a unix timestamp in seconds, or an ISO 8601 datetime (include an offset for local times).
- `leave_rule_id` (integer, required): Leave type (LeaveRules id), e.g. annual leave.
- `location_id` (integer, required): Location (Company id) the leave is recorded against.
- `start_date` (string, required): First day, YYYY-MM-DD.
- `start_time` (required): Leave start: a unix timestamp in seconds, or an ISO 8601 datetime (include an offset for local times).
- `status`: 0 awaiting approval (default), 1 already approved.

### `deputy_add_unavailability` (~166 tokens)

Add unavailability for an employee

Record a time an employee cannot work (one-off, or recurring with an RFC 5545-style rule such as FREQ WEEKLY, INTERVAL 1, BYDAY MO). Auto-scheduling then skips them. Deputy: POST /api/v1/supervise/unavail.

Input parameters:

- `comment` (string): Note the manager sees. Default empty.
- `employee_id` (integer, required): The employee id.
- `end_time` (required): Unavailability end: a unix timestamp in seconds, or an ISO 8601 datetime (include an offset for local times).
- `recurrence` (object): Omit for a one-off block.
- `start_time` (required): Unavailability start: a unix timestamp in seconds, or an ISO 8601 datetime (include an offset for local times).

### `deputy_create_memo` (~132 tokens)

Post a memo

Post a memo to a location's news feed, optionally requiring staff to confirm they read it, or targeted to specific locations or users. Visible to staff immediately. Deputy: PUT /api/v1/supervise/memo.

Input parameters:

- `content` (string, required): The memo text.
- `location_id` (integer, required): Location (Company id) to post to.
- `location_ids` (array): Also show at these locations.
- `require_confirm` (boolean): Ask staff to confirm they have read it. Default false.
- `user_ids` (array): Only these USER ids (not employee ids) receive it.

### `deputy_update_timesheet` (~171 tokens)

Update a timesheet

Correct an existing timesheet's start/end time, area, meal break or supervisor comment. Times cannot be in the future. Deputy: POST /api/v1/supervise/timesheet/update.

Input parameters:

- `area_id` (integer, required): Area (OperationalUnit id) the time was worked in.
- `comment` (string): Comment attached to the timesheet.
- `end_time` (required): Timesheet end: a unix timestamp in seconds, or an ISO 8601 datetime (include an offset for local times).
- `mealbreak_minutes` (integer): Total unscheduled meal break, minutes.
- `start_time` (required): Timesheet start: a unix timestamp in seconds, or an ISO 8601 datetime (include an offset for local times).
- `timesheet_id` (integer, required): The timesheet id.

### `deputy_approve_timesheet` (~69 tokens)

Approve a timesheet

Approve one timesheet's times as a supervisor. Approved timesheets flow toward payroll export, so check it first with deputy_get_timesheet. Deputy: POST /api/v1/supervise/timesheet/approve.

Input parameters:

- `timesheet_id` (integer, required): The timesheet id.

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/io-usefulapi-deputy/deputy#diagnostics

## Score history

- 2026-10-03: 77
- 2026-10-02: 76
- 2026-10-01: 76
- 2026-09-30: 71
- 2026-09-29: 18

## Common questions

### What is the io.usefulapi/deputy MCP server?

io.usefulapi/deputy is an MCP server listed in the public MCP registry as io.usefulapi/deputy. See rosters, timesheets, leave and staff in Deputy, and create shifts, leave and memos. This page covers its hosted endpoint (https://deputy.usefulapi.io/mcp).

### Is the io.usefulapi/deputy MCP server safe to use?

io.usefulapi/deputy scores 77 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the io.usefulapi/deputy MCP server expose?

io.usefulapi/deputy exposes 21 tools: deputy_whoami, deputy_list_locations, deputy_list_areas, deputy_list_employees, deputy_get_employee, and 16 more. Their descriptions and schemas cost roughly 3,270 tokens of context every time the server is loaded.

### Does the io.usefulapi/deputy MCP server require authentication?

Yes. io.usefulapi/deputy asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

### Is the io.usefulapi/deputy MCP server still maintained?

io.usefulapi/deputy is still listed as active in the MCP registry. We last reached this channel on 3 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://deputy.usefulapi.io/mcp
- Repository: https://github.com/m190/usefulapi-mcp
- Changelog RSS feed: https://verifymcp.io/servers/io-usefulapi-deputy/deputy.xml
- Changelog JSON feed: https://verifymcp.io/servers/io-usefulapi-deputy/deputy.json
- HTML version of this page: https://verifymcp.io/servers/io-usefulapi-deputy/deputy
