# Thermo Orbitrap (Instrument API) (pypi · labmcp-thermo-iapi)

MCP server adapter for Thermo Fisher Orbitrap mass spectrometers via the licensed Instrument API.

- Trust score: 83/100 (high trust)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-30

## Components

- pypi · `labmcp-thermo-iapi`: 83/100 (this document), [markdown](https://verifymcp.io/servers/k-dense-ai-labmcp-thermo-iapi/labmcp-thermo-iapi.md), [page](https://verifymcp.io/servers/k-dense-ai-labmcp-thermo-iapi/labmcp-thermo-iapi)

## Channel facts

- Registry: `pypi`
- Package: `labmcp-thermo-iapi`
- Version: `0.1.1`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-30.

- **Supply Chain Security**: 99/100
  - No malware found by supply-chain analysis.
  - No known CVEs affecting this package version or its production dependencies.
  - Runs hatchling.build at install time, a recognised build step with no custom scripting around it.
  - 2 of 17 dependencies flagged as unhealthy.
- **Provenance & Transparency**: 100/100
  - Source repository is publicly reachable at the declared URL.
  - Cryptographically verified build provenance (signed, bound to K-Dense-AI/lab-instrument-mcps).
  - Clear OSI-approved license (Apache-2.0).
  - Actively maintained (last published 3 days ago).
  - Publishes a security disclosure policy (SECURITY.md).
- **Schema Quality & AI Usability**: 74/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 2116 tokens (~141/item across 15 items; 15 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 13/100
  - Stability observed for 4 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 97/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 91% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 15 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 16 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a current MCP spec version (2026-07-28).

## Install

### How do I install the Thermo Orbitrap (Instrument API) MCP server?

Thermo Orbitrap (Instrument API) runs locally as a PyPI package, launched with uvx labmcp-thermo-iapi. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add k-dense-ai-labmcp-thermo-iapi -- uvx labmcp-thermo-iapi
```

### Cursor

```json
{
  "mcpServers": {
    "k-dense-ai-labmcp-thermo-iapi": {
      "command": "uvx",
      "args": [
        "labmcp-thermo-iapi"
      ]
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "k-dense-ai-labmcp-thermo-iapi": {
      "command": "uvx",
      "args": [
        "labmcp-thermo-iapi"
      ]
    }
  }
}
```

### Codex

```bash
codex mcp add k-dense-ai-labmcp-thermo-iapi -- uvx labmcp-thermo-iapi
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "k-dense-ai-labmcp-thermo-iapi": {
      "type": "local",
      "command": [
        "uvx",
        "labmcp-thermo-iapi"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add k-dense-ai-labmcp-thermo-iapi --command uvx --arg labmcp-thermo-iapi
```

### Hermes

```yaml
mcp_servers:
  k-dense-ai-labmcp-thermo-iapi:
    command: "uvx"
    args: ["labmcp-thermo-iapi"]
```

### Netclaw

```json
{
  "McpServers": {
    "k-dense-ai-labmcp-thermo-iapi": {
      "Transport": "stdio",
      "Command": "uvx",
      "Arguments": [
        "labmcp-thermo-iapi"
      ]
    }
  }
}
```

### Vellum

```bash
assistant mcp add k-dense-ai-labmcp-thermo-iapi -t stdio -c uvx -a labmcp-thermo-iapi
```

### Other

```json
{
  "mcpServers": {
    "k-dense-ai-labmcp-thermo-iapi": {
      "command": "uvx",
      "args": [
        "labmcp-thermo-iapi"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-30 (score 83, +16)

- [security improvement] Malware scan: unverified → pass

### 2026-09-29 (score 67, −15)

- [security regression] Malware scan: pass → unverified

### 2026-09-28 (score 82, +43)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-27 (score 39, −31)

- [security regression] Tool safety: pass → unverified
- [security] Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.
- [functional regression] Capabilities: pass → unverified
- [functional regression] Tool coverage: 100 → unverified
- [functional] First check of Schema quality: unverified
- [functional] Package version: 0.1.0 → 0.1.1

### 2026-09-26 (score 70)

First indexed and scored.

## MCP tools (15)

### `get_connection_info` (~40 tokens)

Get Connection Info

Report which instrument is connected (identity, address, simulated or real),
whether the server is read-only, and the active safety limits. Call this first.

### `get_command_log` (~46 tokens)

Get Command Log

Return the most recent raw commands sent to / replies received from the
instrument (newest last). Useful for debugging and for recording what was done.

Input parameters:

- `limit` (integer)

Output parameters:

- `result` (array)

### `reconnect` (~35 tokens)

Reconnect

Close and re-open the connection to the instrument (e.g. after it was power
cycled or a cable was re-plugged).

### `get_instrument_status` (~85 tokens)

Get Instrument Status

Report the instrument model, IAPI service/instrument connection, system mode and state
(On/Standby/Off; Running/ReadyToDownload/...), whether an acquisition can be paused or
resumed, the IAPI licence where the API exposes it, requested readbacks, the latest scan
status log (vacuum, source) and how many scans have arrived.

Output parameters:

- `acquiring` (boolean)
- `acquisition`
- `api_license`: IAPI licence found (Exploris only; None = not queryable)
- `backend` (string)
- `can_pause` (boolean)
- `can_resume` (boolean)
- `custom_scans_last_minute` (integer)
- `family`
- `instrument_connected` (boolean)
- `last_scan_at`
- `last_status_log` (object): Latest scan status log (vacuum, source, ...)
- `model` (string)
- `readback_names` (array): Instrument value names the API exposes
- `readbacks` (object): Requested instrument values (IInstrumentValues)
- `scans_received` (integer)
- `service_connected` (boolean)
- `system_mode`: IState.SystemMode, e.g. On, Standby, Off, Disconnected
- `system_state`: IState.SystemState, e.g. Running, ReadyToDownload, Error
- `timestamp` (string)

### `get_possible_scan_parameters` (~82 tokens)

Get Possible Scan Parameters

List the scan parameters this instrument accepts for custom and repeating scans
(IScans.PossibleParameters): name, allowed range or choices, default and help. The set
depends on the model, licence and Tune version.

Input parameters:

- `name_contains`: Case-insensitive name filter
- `refresh` (boolean): Re-read from the instrument instead of the cache

Output parameters:

- `result` (array)

### `get_recent_scans` (~174 tokens)

Get Recent Scans

Return the most recent scans received from the instrument (oldest first), optionally
only one MS order or one custom scan's access id: scan number, MS order, precursor m/z,
AGC target, injection time and the most intense centroids. Scans only arrive in On mode.

Input parameters:

- `access_id`: Only scans with this access id (-1 = system scans)
- `count` (integer): Number of most recent matching scans
- `include_header_trailer` (boolean): Include the raw header and trailer
- `max_centroids` (integer): Most intense centroids to return per scan
- `ms_order`: Only scans of this MS order (1 = MS1)
- `save_path`: Optional .csv path (must not exist yet): write all kept centroids of the returned scans

Output parameters:

- `buffered_total` (integer)
- `returned` (integer)
- `saved_to`
- `scans` (array)
- `timestamp` (string)

### `wait_for_scan` (~170 tokens)

Wait For Scan

Wait for the next scan that arrives after this call (optionally of one MS order, or the
result of a custom scan by its access id) and return it. For a custom scan placed with
submit_custom_scan, a result that arrived since it was placed is returned at once. Returns
found=false after timeout_s if nothing matching arrived (e.g. the instrument is in Standby).

Input parameters:

- `access_id`: Only scans with this access id (-1 = system scans)
- `include_header_trailer` (boolean): Include the raw header and trailer
- `max_centroids` (integer): Most intense centroids to return per scan
- `ms_order`: Only scans of this MS order (1 = MS1)
- `timeout_s` (number): Longest time to wait

Output parameters:

- `found` (boolean)
- `message` (string)
- `scan`
- `waited_s` (number)

### `start_acquisition` (~157 tokens)

Start Acquisition

Start an acquisition with the instrument's current settings (IAPI StartAcquisition),
recording to a raw file. This consumes sample. The instrument must be On; an acquisition
must not already be running. Stop it with stop_acquisition. scan_count and until_stopped
acquisitions are cancelled automatically after max_acquisition_duration_s.

Input parameters:

- `comment`
- `duration_s`: For mode=duration
- `mode` (string, required): Stop after duration_s, after scan_count scans, or only when stopped
- `raw_file_path`: Raw file to write on the instrument PC, e.g. D:\Data\run1.raw
- `sample_name`
- `scan_count`: For mode=scan_count

Output parameters:

- `result` (string)

### `pause_acquisition` (~28 tokens)

Pause Acquisition

Pause the running acquisition (IAPI Pause). Fails if the instrument reports it cannot pause.

Output parameters:

- `result` (string)

### `resume_acquisition` (~22 tokens)

Resume Acquisition

Resume a paused acquisition (IAPI Resume). Sample consumption continues.

Output parameters:

- `result` (string)

### `stop_acquisition` (~94 tokens)

Stop Acquisition

Stop the running acquisition (IAPI CancelAcquisition), by default also cancelling custom
and repeating scans, and optionally switch the instrument to Standby (switch back to On in
Tune). Every step is attempted even if an earlier one fails; failures are reported.

Input parameters:

- `cancel_scans` (boolean): Also cancel pending custom scans and the repeating scan
- `standby` (boolean): Then put the instrument in Standby

Output parameters:

- `result` (string)

### `cancel_custom_scans` (~26 tokens)

Cancel Custom Scans

Cancel any pending custom scan and its processing delay (IAPI CancelCustomScan).

Output parameters:

- `result` (string)

### `cancel_repeating_scan` (~27 tokens)

Cancel Repeating Scan

Cancel the repeating scan set with set_repeating_scan (IAPI CancelRepetition).

Output parameters:

- `result` (string)

### `submit_custom_scan` (~348 tokens)

Submit Custom Scan

Place one custom scan to run next (IAPI CreateCustomScan/SetCustomScan); unset values
fall back to the instrument's defaults. Every value is checked against
PossibleParameters and the safety limits, and calls are rate-limited, before anything is
sent. Fetch the result with wait_for_scan(access_id=running_number).

Input parameters:

- `activation_type`: ActivationType, e.g. HCD or CID
- `agc_target`: AGCTarget (charges)
- `analyzer`: Mass analyzer, e.g. Orbitrap or IonTrap (Tribrid)
- `collision_energy`: CollisionEnergy (normalized, %)
- `extra_parameters`: Other IAPI scan values by exact name (see get_possible_scan_parameters)
- `first_mass_mz`: FirstMass: scan range start (m/z)
- `isolation_width_mz`: IsolationWidth (m/z)
- `last_mass_mz`: LastMass: scan range end (m/z)
- `max_injection_time_ms`: MaxIT: maximum injection time (ms)
- `microscans`
- `orbitrap_resolution`: OrbitrapResolution at m/z 200; must be an allowed value
- `polarity`: Polarity as the instrument lists it
- `precursor_mz`: PrecursorMass (m/z) for MSn/SIM
- `running_number`: Reported back as access_id (default: auto)
- `scan_description`: ScanDescription stored with the scan
- `scan_type`: ScanType, e.g. Full, SIM or MSn
- `single_processing_delay_s` (number): Hold further custom scans this long (ICustomScan.SingleProcessingDelay)

Output parameters:

- `custom_scans_last_minute`
- `message` (string)
- `running_number` (integer)
- `sent` (boolean): True if IAPI reports the command was sent to the instrument
- `values` (object): The exact IAPI scan values sent

### `set_repeating_scan` (~304 tokens)

Set Repeating Scan

Define or replace the scan the instrument repeats when no method or custom scan is
running (IAPI CreateRepeatingScan/SetRepetitionScan). Values are validated like
submit_custom_scan. Cancel with cancel_repeating_scan.

Input parameters:

- `activation_type`: ActivationType, e.g. HCD or CID
- `agc_target`: AGCTarget (charges)
- `analyzer`: Mass analyzer, e.g. Orbitrap or IonTrap (Tribrid)
- `collision_energy`: CollisionEnergy (normalized, %)
- `extra_parameters`: Other IAPI scan values by exact name (see get_possible_scan_parameters)
- `first_mass_mz`: FirstMass: scan range start (m/z)
- `isolation_width_mz`: IsolationWidth (m/z)
- `last_mass_mz`: LastMass: scan range end (m/z)
- `max_injection_time_ms`: MaxIT: maximum injection time (ms)
- `microscans`
- `orbitrap_resolution`: OrbitrapResolution at m/z 200; must be an allowed value
- `polarity`: Polarity as the instrument lists it
- `precursor_mz`: PrecursorMass (m/z) for MSn/SIM
- `running_number`: Reported back as access_id (default: auto)
- `scan_description`: ScanDescription stored with the scan
- `scan_type`: ScanType, e.g. Full, SIM or MSn

Output parameters:

- `custom_scans_last_minute`
- `message` (string)
- `running_number` (integer)
- `sent` (boolean): True if IAPI reports the command was sent to the instrument
- `values` (object): The exact IAPI scan values sent

## Diagnostics

Captured diagnostic sections: Provenance, Install scripts, Dependencies. The full working is on the page: https://verifymcp.io/servers/k-dense-ai-labmcp-thermo-iapi/labmcp-thermo-iapi#diagnostics

## Score history

- 2026-09-30: 83
- 2026-09-29: 67
- 2026-09-28: 82
- 2026-09-27: 39
- 2026-09-26: 70

## Common questions

### What is the Thermo Orbitrap (Instrument API) MCP server?

Thermo Orbitrap (Instrument API) is an MCP server listed in the public MCP registry as io.github.K-Dense-AI/labmcp-thermo-iapi. MCP server adapter for Thermo Fisher Orbitrap mass spectrometers via the licensed Instrument API. This page covers its PyPI package (labmcp-thermo-iapi).

### Is the Thermo Orbitrap (Instrument API) MCP server safe to use?

Thermo Orbitrap (Instrument API) scores 83 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 30 September 2026. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Thermo Orbitrap (Instrument API) MCP server expose?

Thermo Orbitrap (Instrument API) exposes 15 tools: get_connection_info, get_command_log, reconnect, get_instrument_status, get_possible_scan_parameters, and 10 more. Their descriptions and schemas cost roughly 1,638 tokens of context every time the server is loaded.

### Is the Thermo Orbitrap (Instrument API) MCP server still maintained?

Thermo Orbitrap (Instrument API) is still listed as active in the MCP registry. We last reached this channel on 30 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

### What licence is the Thermo Orbitrap (Instrument API) MCP server under?

Thermo Orbitrap (Instrument API) declares the Apache-2.0 licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.

## Links

- PyPI project: https://pypi.org/project/labmcp-thermo-iapi/
- Socket report: https://socket.dev/pypi/package/labmcp-thermo-iapi
- Repository: https://github.com/K-Dense-AI/lab-instrument-mcps
- Website: https://github.com/K-Dense-AI/lab-instrument-mcps/tree/main/servers/chemistry/thermo-iapi
- Changelog RSS feed: https://verifymcp.io/servers/k-dense-ai-labmcp-thermo-iapi/labmcp-thermo-iapi.xml
- Changelog JSON feed: https://verifymcp.io/servers/k-dense-ai-labmcp-thermo-iapi/labmcp-thermo-iapi.json
- HTML version of this page: https://verifymcp.io/servers/k-dense-ai-labmcp-thermo-iapi/labmcp-thermo-iapi
