# io.usefulapi/loyverse (remote · loyverse.usefulapi.io)

Query Loyverse POS receipts, shifts, items, inventory and customers, and update stock and customers.

- Trust score: 76/100 (medium)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-03

## Components

- remote · `loyverse.usefulapi.io`: 76/100 (this document), [markdown](https://verifymcp.io/servers/io-usefulapi-loyverse/loyverse.md), [page](https://verifymcp.io/servers/io-usefulapi-loyverse/loyverse)

## Channel facts

- Endpoint: `https://loyverse.usefulapi.io/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.0.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-03.

- **Endpoint Security**: 89/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token.
  - HTTPS is enforced; there's no plaintext access path.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
  - The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 69/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 4009 tokens (~190/item across 21 items; 21 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 10/100
  - Stability observed for 3 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 21 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 21 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 60/100
  - Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28.

## Install

### How do I install the io.usefulapi/loyverse MCP server?

io.usefulapi/loyverse is a hosted endpoint at https://loyverse.usefulapi.io/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http io-usefulapi-loyverse 'https://loyverse.usefulapi.io/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "io-usefulapi-loyverse": {
      "url": "https://loyverse.usefulapi.io/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "io-usefulapi-loyverse": {
      "type": "http",
      "url": "https://loyverse.usefulapi.io/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.io-usefulapi-loyverse]
url = "https://loyverse.usefulapi.io/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "io-usefulapi-loyverse": {
      "type": "remote",
      "url": "https://loyverse.usefulapi.io/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add io-usefulapi-loyverse --url 'https://loyverse.usefulapi.io/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  io-usefulapi-loyverse:
    url: "https://loyverse.usefulapi.io/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "io-usefulapi-loyverse": {
      "Transport": "http",
      "Url": "https://loyverse.usefulapi.io/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add io-usefulapi-loyverse -t streamable-http -u 'https://loyverse.usefulapi.io/mcp'
```

### Other

```json
{
  "mcpServers": {
    "io-usefulapi-loyverse": {
      "type": "http",
      "url": "https://loyverse.usefulapi.io/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-10-03 (score 76, +1)

No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-10-02 (score 75, 0)

- [functional] Server version: 1.3.0 → 1.5.1

### 2026-10-01 (score 75, +5)

- [security improvement] HTTPS: unverified → pass
- [functional improvement] Stability: unverified → 0.03
- [functional] Server version: 1.0.0 → 1.3.0

### 2026-09-30 (score 70, +42)

- [security improvement] Authorization: unverified → pass
- [security improvement] Injection markers: unverified → pass
- [security] First check of Judged manipulation: pass
- [security] First check of Authorization: partial
- [functional regression] MCP protocol: unverified → fail
- [functional improvement] Tool coverage: unverified → 100
- [functional] First check of Schema quality: fail
- [functional] First check of Schema quality: excellent
- [functional] First check of Destructive annotations: pass
- [functional] First check of Schema quality: fail
- [functional] First check of Tool coverage: 100

### 2026-09-29 (score 28)

First indexed and scored.

## MCP tools (21)

### `loyverse_get_merchant` (~45 tokens)

Get the merchant

Fetch the merchant account this token belongs to — business name, email, country and currency. A cheap way to confirm the token works. Loyverse: GET /merchant/.

### `loyverse_list_stores` (~251 tokens)

List stores

List the merchant's stores (locations) with their addresses. Store ids are what the receipt, shift and inventory filters take. Loyverse: GET /stores.

Input parameters:

- `created_at_max` (string): Only records created at or before this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `created_at_min` (string): Only records created at or after this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `show_deleted` (boolean): Also return soft-deleted records (they carry deleted_at).
- `store_ids` (string): Comma-separated list of store ids to return.
- `updated_at_max` (string): Only records updated at or before this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `updated_at_min` (string): Only records updated at or after this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).

### `loyverse_list_employees` (~287 tokens)

List employees

List employees, with the stores each can access and whether they are the owner. Loyverse: GET /employees.

Input parameters:

- `created_at_max` (string): Only records created at or before this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `created_at_min` (string): Only records created at or after this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `cursor` (string): The `cursor` from the previous page's response. Omit for the first page.
- `employee_ids` (string): Comma-separated list of employee ids to return.
- `limit` (integer): Page size, 1-250 (Loyverse default 50).
- `show_deleted` (boolean): Also return soft-deleted records (they carry deleted_at).
- `updated_at_max` (string): Only records updated at or before this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `updated_at_min` (string): Only records updated at or after this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).

### `loyverse_list_receipts` (~389 tokens)

List receipts

List sales and refund receipts, newest first, with line items, payments, discounts and taxes. Filter by store, time range or receipt numbers — the core of any sales question. Loyverse: GET /receipts.

Input parameters:

- `before_receipt_number` (string): Only receipts created up to the receipt with this number.
- `created_at_max` (string): Only records created at or before this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `created_at_min` (string): Only records created at or after this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `cursor` (string): The `cursor` from the previous page's response. Omit for the first page.
- `limit` (integer): Page size, 1-250 (Loyverse default 50).
- `order` (string): Only receipts with this order name/number.
- `receipt_numbers` (string): Comma-separated receipt numbers to return, e.g. 2-1008,2-1009.
- `since_receipt_number` (string): Only receipts created at or after the receipt with this number.
- `source` (string): Only receipts from this source (e.g. an app name).
- `store_id` (string): Only receipts from this store.
- `updated_at_max` (string): Only records updated at or before this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `updated_at_min` (string): Only records updated at or after this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).

### `loyverse_get_receipt` (~72 tokens)

Get one receipt

Fetch a single receipt by its receipt number (e.g. 2-1008), with line items, modifiers, discounts, taxes and payments. Loyverse: GET /receipts/{receipt_number}.

Input parameters:

- `receipt_number` (string, required): The receipt number, e.g. 2-1008.

### `loyverse_list_shifts` (~202 tokens)

List shifts

List cash-register shifts with their cash, gross/net sales, refunds, discounts, taxes, per-payment-type totals and pay-in/pay-out movements — the end-of-day view. Loyverse: GET /shifts.

Input parameters:

- `created_at_max` (string): Only shifts opened at or before this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `created_at_min` (string): Only shifts opened at or after this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `cursor` (string): The `cursor` from the previous page's response. Omit for the first page.
- `limit` (integer): Page size, 1-250 (Loyverse default 50).
- `store_ids` (string): Comma-separated list of store ids to return.

### `loyverse_list_items` (~295 tokens)

List items

List catalog items with their variants (SKU, barcode, price, cost, per-store pricing), category, taxes and modifiers. Loyverse: GET /items.

Input parameters:

- `created_at_max` (string): Only records created at or before this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `created_at_min` (string): Only records created at or after this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `cursor` (string): The `cursor` from the previous page's response. Omit for the first page.
- `items_ids` (string): Comma-separated list of item ids to return.
- `limit` (integer): Page size, 1-250 (Loyverse default 50).
- `show_deleted` (boolean): Also return soft-deleted records (they carry deleted_at).
- `updated_at_max` (string): Only records updated at or before this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `updated_at_min` (string): Only records updated at or after this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).

### `loyverse_get_item` (~45 tokens)

Get one item

Fetch a single catalog item by id, with its variants. Loyverse: GET /items/{item_id}.

Input parameters:

- `item_id` (string, required): The item id (UUID).

### `loyverse_list_variants` (~329 tokens)

List item variants

List item variants — the sellable SKUs — optionally for given items or one SKU. Variant ids are what inventory levels are keyed on. Loyverse: GET /variants.

Input parameters:

- `created_at_max` (string): Only records created at or before this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `created_at_min` (string): Only records created at or after this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `cursor` (string): The `cursor` from the previous page's response. Omit for the first page.
- `items_ids` (string): Comma-separated item ids whose variants to return.
- `limit` (integer): Page size, 1-250 (Loyverse default 50).
- `show_deleted` (boolean): Also return soft-deleted records (they carry deleted_at).
- `sku` (string): Only the variant with this SKU.
- `updated_at_max` (string): Only records updated at or before this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `updated_at_min` (string): Only records updated at or after this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `variants_ids` (string): Comma-separated list of variant ids to return.

### `loyverse_list_categories` (~102 tokens)

List categories

List item categories. Loyverse: GET /categories.

Input parameters:

- `categories_ids` (string): Comma-separated list of category ids to return.
- `cursor` (string): The `cursor` from the previous page's response. Omit for the first page.
- `limit` (integer): Page size, 1-250 (Loyverse default 50).
- `show_deleted` (boolean): Also return soft-deleted records (they carry deleted_at).

### `loyverse_list_inventory` (~203 tokens)

List inventory levels

List current stock (`in_stock`) per variant per store. Filter by stores and/or variants — the answer to 'what is running low?'. Loyverse: GET /inventory.

Input parameters:

- `cursor` (string): The `cursor` from the previous page's response. Omit for the first page.
- `limit` (integer): Page size, 1-250 (Loyverse default 50).
- `store_ids` (string): Comma-separated store ids.
- `updated_at_max` (string): Only levels updated at or before this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `updated_at_min` (string): Only levels updated at or after this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `variant_ids` (string): Comma-separated variant ids.

### `loyverse_list_customers` (~287 tokens)

List customers

List loyalty customers, newest first, with visits, total spent and points balance. Filter by email or ids. Loyverse: GET /customers.

Input parameters:

- `created_at_max` (string): Only records created at or before this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `created_at_min` (string): Only records created at or after this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `cursor` (string): The `cursor` from the previous page's response. Omit for the first page.
- `customer_ids` (string): Comma-separated list of customer ids to return.
- `email` (string): Only the customer with this email.
- `limit` (integer): Page size, 1-250 (Loyverse default 50).
- `updated_at_max` (string): Only records updated at or before this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `updated_at_min` (string): Only records updated at or after this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).

### `loyverse_get_customer` (~49 tokens)

Get one customer

Fetch a single customer by id, with visits, total spent and points balance. Loyverse: GET /customers/{customer_id}.

Input parameters:

- `customer_id` (string, required): The customer id (UUID).

### `loyverse_list_payment_types` (~255 tokens)

List payment types

List the payment types (cash, card, integrated terminals…) and the stores where each is available. Receipt payments reference these ids. Loyverse: GET /payment_types.

Input parameters:

- `created_at_max` (string): Only records created at or before this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `created_at_min` (string): Only records created at or after this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `payment_type_ids` (string): Comma-separated list of payment type ids to return.
- `show_deleted` (boolean): Also return soft-deleted records (they carry deleted_at).
- `updated_at_max` (string): Only records updated at or before this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `updated_at_min` (string): Only records updated at or after this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).

### `loyverse_list_discounts` (~248 tokens)

List discounts

List configured discounts (fixed/variable percent or amount, discount-by-points) and where they apply. Loyverse: GET /discounts.

Input parameters:

- `created_at_max` (string): Only records created at or before this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `created_at_min` (string): Only records created at or after this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `discount_ids` (string): Comma-separated list of discount ids to return.
- `show_deleted` (boolean): Also return soft-deleted records (they carry deleted_at).
- `updated_at_max` (string): Only records updated at or before this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `updated_at_min` (string): Only records updated at or after this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).

### `loyverse_list_taxes` (~252 tokens)

List taxes

List taxes with their rate, whether they are INCLUDED in or ADDED to the price, and the stores they apply in. Loyverse: GET /taxes.

Input parameters:

- `created_at_max` (string): Only records created at or before this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `created_at_min` (string): Only records created at or after this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `show_deleted` (boolean): Also return soft-deleted records (they carry deleted_at).
- `tax_ids` (string): Comma-separated list of tax ids to return.
- `updated_at_max` (string): Only records updated at or before this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).
- `updated_at_min` (string): Only records updated at or after this time (ISO 8601 UTC, e.g. 2026-03-30T18:30:00.000Z).

### `loyverse_list_suppliers` (~107 tokens)

List suppliers

List suppliers with their contact details. Loyverse: GET /suppliers/.

Input parameters:

- `cursor` (string): The `cursor` from the previous page's response. Omit for the first page.
- `limit` (integer): Page size, 1-250 (Loyverse default 50).
- `show_deleted` (boolean): Also return soft-deleted records (they carry deleted_at).
- `suppliers_ids` (string): Comma-separated list of supplier ids to return.

### `loyverse_upsert_customer` (~209 tokens)

Create or update a customer

Create a loyalty customer, or update one by passing its `id`. Loyverse does not document whether omitted fields survive an update, so on update fetch the customer first and send the full record. Loyverse: POST /customers.

Input parameters:

- `address` (string): Street address.
- `city` (string): City, town or village.
- `country_code` (string): Two-letter ISO 3166-1 alpha-2 country code, e.g. US.
- `customer_code` (string): Your own customer code (e.g. a loyalty card number).
- `email` (string): Email address.
- `id` (string): Existing customer id to update. Omit to create.
- `name` (string, required): The customer's name (required).
- `note` (string): A note about the customer.
- `phone_number` (string): Phone number.
- `postal_code` (string): Postal / ZIP code.
- `region` (string): Province, state or prefecture.

### `loyverse_upsert_category` (~75 tokens)

Create or update a category

Create an item category, or rename/recolor one by passing its `id`. Loyverse: POST /categories.

Input parameters:

- `color` (string): Display color on the POS.
- `id` (string): Existing category id to update. Omit to create.
- `name` (string, required): The category name (required).

### `loyverse_upsert_supplier` (~221 tokens)

Create or update a supplier

Create a supplier, or update one by passing its `id`. Loyverse does not document whether omitted fields survive an update, so on update send the full record. Loyverse: POST /suppliers/.

Input parameters:

- `address_1` (string): Address line 1.
- `address_2` (string): Address line 2.
- `city` (string): City, town or village.
- `contact` (string): Contact person's name.
- `country_code` (string): Two-letter ISO 3166-1 alpha-2 country code, e.g. US.
- `email` (string): Email address.
- `id` (string): Existing supplier id to update. Omit to create.
- `name` (string, required): The supplier company name (required).
- `note` (string): A note about the supplier.
- `phone_number` (string): Phone number.
- `postal_code` (string): Postal / ZIP code.
- `region` (string): Province, state or prefecture.
- `website` (string): Website URL.

### `loyverse_set_inventory_levels` (~86 tokens)

Set inventory levels

Set the ABSOLUTE stock (`stock_after`) of one or more variants at given stores — e.g. after a stock count. This overwrites the current level rather than adding to it; read the current levels with loyverse_list_inventory first so they can be restored. Loyverse: POST /inventory.

Input parameters:

- `inventory_levels` (array, required): The stock levels to set.

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/io-usefulapi-loyverse/loyverse#diagnostics

## Score history

- 2026-10-03: 76
- 2026-10-02: 75
- 2026-10-01: 75
- 2026-09-30: 70
- 2026-09-29: 28

## Common questions

### What is the io.usefulapi/loyverse MCP server?

io.usefulapi/loyverse is an MCP server listed in the public MCP registry as io.usefulapi/loyverse. Query Loyverse POS receipts, shifts, items, inventory and customers, and update stock and customers. This page covers its hosted endpoint (https://loyverse.usefulapi.io/mcp).

### Is the io.usefulapi/loyverse MCP server safe to use?

io.usefulapi/loyverse scores 76 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the io.usefulapi/loyverse MCP server expose?

io.usefulapi/loyverse exposes 21 tools: loyverse_get_merchant, loyverse_list_stores, loyverse_list_employees, loyverse_list_receipts, loyverse_get_receipt, and 16 more. Their descriptions and schemas cost roughly 4,009 tokens of context every time the server is loaded.

### Does the io.usefulapi/loyverse MCP server require authentication?

Yes. io.usefulapi/loyverse asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

### Is the io.usefulapi/loyverse MCP server still maintained?

io.usefulapi/loyverse is still listed as active in the MCP registry. We last reached this channel on 3 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://loyverse.usefulapi.io/mcp
- Repository: https://github.com/m190/usefulapi-mcp
- Changelog RSS feed: https://verifymcp.io/servers/io-usefulapi-loyverse/loyverse.xml
- Changelog JSON feed: https://verifymcp.io/servers/io-usefulapi-loyverse/loyverse.json
- HTML version of this page: https://verifymcp.io/servers/io-usefulapi-loyverse/loyverse
