xupersplit
REMOTE · SPLIT.XUPER.FUN · SCANNED SEP 20
Split shared expenses in a group — no account needed. See who owes whom and settle up.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security66
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (delete_entry). See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability71
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1778 tokens (~161/item across 11 items; 11 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage97
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 88% of tool parameters carry a description.Partial
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 12 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the xupersplit MCP server?
xupersplit is a hosted endpoint at https://split.xuper.fun/api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · split.xuper.fun
claude mcp add --transport http kanylbullen-xupersplit 'https://split.xuper.fun/api/mcp'
{
"mcpServers": {
"kanylbullen-xupersplit": {
"url": "https://split.xuper.fun/api/mcp"
}
}
} {
"servers": {
"kanylbullen-xupersplit": {
"type": "http",
"url": "https://split.xuper.fun/api/mcp"
}
}
} [mcp_servers.kanylbullen-xupersplit] url = "https://split.xuper.fun/api/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"kanylbullen-xupersplit": {
"type": "remote",
"url": "https://split.xuper.fun/api/mcp",
"enabled": true
}
}
} openclaw mcp add kanylbullen-xupersplit --url 'https://split.xuper.fun/api/mcp' --transport streamable-http
mcp_servers:
kanylbullen-xupersplit:
url: "https://split.xuper.fun/api/mcp" {
"McpServers": {
"kanylbullen-xupersplit": {
"Transport": "http",
"Url": "https://split.xuper.fun/api/mcp"
}
}
} assistant mcp add kanylbullen-xupersplit -t streamable-http -u 'https://split.xuper.fun/api/mcp'
{
"mcpServers": {
"kanylbullen-xupersplit": {
"type": "http",
"url": "https://split.xuper.fun/api/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 2 Sept 26 0
- Stability: 0.97 → pass security
- 1 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 30 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.
- 28 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.
- 26 Aug 26 +2
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 24 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 67 to 70. That category is still filling its 30-day observation window: 20 days of observed history at the previous scan, 21 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 10 Aug 26 0
- Server version: 1.0.0 → 1.0.1 functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://split.xuper.fun/api/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=split.xuper.fun | CN=YR2,O=Let's Encrypt,C=US | 16 Aug 2026 | 14 Nov 2026 | RSA 2048 | SHA256-RSA | 6638b00f7a6cf7656529b42e3ba262c3914 |
| SANs: split.xuper.fun | ||||||
| CN=YR2,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | 4ebd24947e24d394802d84a52fd5b319 |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
Background: What to check on a remote MCP endpoint →
DNSSEC secure
Validation of split.xuper.fun. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| fun. | present | 47728 | 13 | Verified |
| xuper.fun. | present | 2371 | 13 | Verified |
| split.xuper.fun. | Verified address RRset verified with the apex keys |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000 |
| content-security-policy | default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https:; font-src 'self'; connect-src 'self' https://auth.farcaster.xyz https://*.supabase.co https://*.vercel-insights.com https://vitals.vercel-insights.com https://*.walletconnect.org https://*.walletconnect.com wss://*.walletconnect.org wss://*.walletconnect.com https://*.reown.com https://api.web3modal.org https://*.solana.com https://solana-rpc.publicnode.com https://uvlgfszbmzdurjlbqovu.supabase.co; frame-src 'self' https://verify.walletconnect.org https://secure.walletconnect.org; form-action 'self'; frame-ancestors 'self' https://farcaster.xyz https://*.farcaster.xyz https://warpcast.com https://*.warpcast.com https://base.org https://*.base.org https://wallet.coinbase.com https://*.coinbase.com; base-uri 'self'; object-src 'none' |
| x-content-type-options | nosniff |
| referrer-policy | no-referrer |
| permissions-policy | camera=(), microphone=(), geolocation=(), interest-cohort=() |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://split.xuper.fun/api/mcp | Verified | 200 | |
| http (plaintext) | http://split.xuper.fun/api/mcp | HTTPS enforced | 308 | https://split.xuper.fun/api/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
add_expense Add an expense ~342
Record something one person paid for the group. Split equally by default; pass split_between for a subset, or shares for an uneven split. One expense covers one set of people — a receipt whose items aren't all shared by everyone is several expenses, so call this once per group of items that the same people share, rather than splitting the total equally. Works on simple, accountless splits. Secure splits (created by a signed-in user) are read-only here and must be opened in a browser.
| Name | Type | Req | Description |
|---|---|---|---|
| amount | number | yes | Amount in the split's currency, as a decimal (e.g. 249.50). |
| date | string | – | Date as YYYY-MM-DD. Defaults to today. |
| description | string | – | What it was, e.g. "Groceries". |
| paid_by | string | yes | Who paid — a participant's name (or id) in this split. A card receipt rarely names the payer, so ask unless you know: guess wrong and every balance points the wrong way. If the user counts themselves… |
| shares | array | – | Uneven split. Either an exact `amount` per person (must add up to the total) or a relative `weight` per person (e.g. weight 2 for a couple). Don't combine with split_between. |
| split | string | yes | The split key, or the whole https://split.xuper.fun/k/<key> link. |
| split_between | array | – | Names of the people sharing this cost, split equally. Defaults to everyone. |
| Name | Type | Req | Description |
|---|---|---|---|
| created_at | string | yes | – |
| currency | string | yes | – |
| entries | array | yes | – |
| key | string | yes | – |
| participants | array | yes | – |
| secure | boolean | yes | – |
| settled | boolean | yes | – |
| settlement | array | yes | – |
| title | string | yes | – |
| total_spent | number | yes | – |
| url | string | yes | – |
No examples provided.
add_participant Add a participant ~78
Add someone to an existing split. Works on simple, accountless splits. Secure splits (created by a signed-in user) are read-only here and must be opened in a browser.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | – |
| split | string | yes | The split key, or the whole https://split.xuper.fun/k/<key> link. |
| Name | Type | Req | Description |
|---|---|---|---|
| created_at | string | yes | – |
| currency | string | yes | – |
| entries | array | yes | – |
| key | string | yes | – |
| participants | array | yes | – |
| secure | boolean | yes | – |
| settled | boolean | yes | – |
| settlement | array | yes | – |
| title | string | yes | – |
| total_spent | number | yes | – |
| url | string | yes | – |
No examples provided.
create_split Create a split ~106
Create a new xupersplit for sharing expenses in a group. No account needed. Returns a secret link — give it to the user and tell them to share it with the group, since anyone holding the link can see and edit the split.
| Name | Type | Req | Description |
|---|---|---|---|
| currency | string | – | Currency code. Defaults to SEK. |
| participants | array | yes | Names of everyone splitting, at least two. |
| title | string | yes | What the split is for, e.g. "Ski trip". |
| Name | Type | Req | Description |
|---|---|---|---|
| created_at | string | yes | – |
| currency | string | yes | – |
| entries | array | yes | – |
| key | string | yes | – |
| participants | array | yes | – |
| secure | boolean | yes | – |
| settled | boolean | yes | – |
| settlement | array | yes | – |
| title | string | yes | – |
| total_spent | number | yes | – |
| url | string | yes | – |
No examples provided.
delete_entry Delete an entry ~87
Remove an expense or payment for good. Works on simple, accountless splits. Secure splits (created by a signed-in user) are read-only here and must be opened in a browser.
| Name | Type | Req | Description |
|---|---|---|---|
| entry_id | string | yes | The entry's id, from get_split. |
| split | string | yes | The split key, or the whole https://split.xuper.fun/k/<key> link. |
| Name | Type | Req | Description |
|---|---|---|---|
| created_at | string | yes | – |
| currency | string | yes | – |
| entries | array | yes | – |
| key | string | yes | – |
| participants | array | yes | – |
| secure | boolean | yes | – |
| settled | boolean | yes | – |
| settlement | array | yes | – |
| title | string | yes | – |
| total_spent | number | yes | – |
| url | string | yes | – |
No examples provided.
get_split Read a split ~55
Read a split: participants, expenses, per-person balances and the shortest set of payments that settles everyone up.
| Name | Type | Req | Description |
|---|---|---|---|
| split | string | yes | The split key, or the whole https://split.xuper.fun/k/<key> link. |
| Name | Type | Req | Description |
|---|---|---|---|
| created_at | string | yes | – |
| currency | string | yes | – |
| entries | array | yes | – |
| key | string | yes | – |
| participants | array | yes | – |
| secure | boolean | yes | – |
| settled | boolean | yes | – |
| settlement | array | yes | – |
| title | string | yes | – |
| total_spent | number | yes | – |
| url | string | yes | – |
No examples provided.
record_payment Record a payment ~204
Record that one person paid another back, settling part or all of a debt. Use get_split first to see who should pay whom. Works on simple, accountless splits. Secure splits (created by a signed-in user) are read-only here and must be opened in a browser.
| Name | Type | Req | Description |
|---|---|---|---|
| amount | number | yes | Amount in the split's currency, as a decimal (e.g. 249.50). |
| date | string | – | Date as YYYY-MM-DD. Defaults to today. |
| description | string | – | How it was paid, e.g. "Swish, 3 March". Shown in the history. |
| from | string | yes | Who sent the money — a participant's name (or id) in this split. |
| split | string | yes | The split key, or the whole https://split.xuper.fun/k/<key> link. |
| to | string | yes | Who received it — a participant's name (or id) in this split. |
| Name | Type | Req | Description |
|---|---|---|---|
| created_at | string | yes | – |
| currency | string | yes | – |
| entries | array | yes | – |
| key | string | yes | – |
| participants | array | yes | – |
| secure | boolean | yes | – |
| settled | boolean | yes | – |
| settlement | array | yes | – |
| title | string | yes | – |
| total_spent | number | yes | – |
| url | string | yes | – |
No examples provided.
remove_participant Remove a participant ~102
Remove someone from a split. Only works if they aren't on any expense yet. Works on simple, accountless splits. Secure splits (created by a signed-in user) are read-only here and must be opened in a browser.
| Name | Type | Req | Description |
|---|---|---|---|
| participant | string | yes | Who to remove — a participant's name (or id) in this split. |
| split | string | yes | The split key, or the whole https://split.xuper.fun/k/<key> link. |
| Name | Type | Req | Description |
|---|---|---|---|
| created_at | string | yes | – |
| currency | string | yes | – |
| entries | array | yes | – |
| key | string | yes | – |
| participants | array | yes | – |
| secure | boolean | yes | – |
| settled | boolean | yes | – |
| settlement | array | yes | – |
| title | string | yes | – |
| total_spent | number | yes | – |
| url | string | yes | – |
No examples provided.
rename_participant Rename a participant ~102
Change a participant's name. Works on simple, accountless splits. Secure splits (created by a signed-in user) are read-only here and must be opened in a browser.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | The new name. |
| participant | string | yes | Who to rename — a participant's name (or id) in this split. |
| split | string | yes | The split key, or the whole https://split.xuper.fun/k/<key> link. |
| Name | Type | Req | Description |
|---|---|---|---|
| created_at | string | yes | – |
| currency | string | yes | – |
| entries | array | yes | – |
| key | string | yes | – |
| participants | array | yes | – |
| secure | boolean | yes | – |
| settled | boolean | yes | – |
| settlement | array | yes | – |
| title | string | yes | – |
| total_spent | number | yes | – |
| url | string | yes | – |
No examples provided.
set_payment_methods Set payment details ~131
Set how a participant wants to be paid back, so the split can show a QR code or pay link. Replaces their current list (pass an empty array to clear it). Works on simple, accountless splits. Secure splits (created by a signed-in user) are read-only here and must be opened in a browser.
| Name | Type | Req | Description |
|---|---|---|---|
| methods | array | yes | – |
| participant | string | yes | Whose details these are — a participant's name (or id) in this split. |
| split | string | yes | The split key, or the whole https://split.xuper.fun/k/<key> link. |
| Name | Type | Req | Description |
|---|---|---|---|
| created_at | string | yes | – |
| currency | string | yes | – |
| entries | array | yes | – |
| key | string | yes | – |
| participants | array | yes | – |
| secure | boolean | yes | – |
| settled | boolean | yes | – |
| settlement | array | yes | – |
| title | string | yes | – |
| total_spent | number | yes | – |
| url | string | yes | – |
No examples provided.
update_entry Update an entry ~249
Change an existing expense or payment. Only the fields you pass are changed. Entry ids come from get_split. Works on simple, accountless splits. Secure splits (created by a signed-in user) are read-only here and must be opened in a browser.
| Name | Type | Req | Description |
|---|---|---|---|
| amount | number | – | Amount in the split's currency, as a decimal (e.g. 249.50). |
| date | string | – | Date as YYYY-MM-DD. Defaults to today. |
| description | string | – | – |
| entry_id | string | yes | The entry's id, from get_split. |
| paid_by | string | – | Move the entry to a different payer. |
| shares | array | – | Uneven split. Either an exact `amount` per person (must add up to the total) or a relative `weight` per person (e.g. weight 2 for a couple). Don't combine with split_between. |
| split | string | yes | The split key, or the whole https://split.xuper.fun/k/<key> link. |
| split_between | array | – | Names of the people sharing this cost, split equally. Defaults to everyone. |
| to | string | – | New recipient — payments only. |
| Name | Type | Req | Description |
|---|---|---|---|
| created_at | string | yes | – |
| currency | string | yes | – |
| entries | array | yes | – |
| key | string | yes | – |
| participants | array | yes | – |
| secure | boolean | yes | – |
| settled | boolean | yes | – |
| settlement | array | yes | – |
| title | string | yes | – |
| total_spent | number | yes | – |
| url | string | yes | – |
No examples provided.
update_split Rename a split ~95
Change a split's title or currency. The currency is locked once the split has expenses. Works on simple, accountless splits. Secure splits (created by a signed-in user) are read-only here and must be opened in a browser.
| Name | Type | Req | Description |
|---|---|---|---|
| currency | string | – | – |
| split | string | yes | The split key, or the whole https://split.xuper.fun/k/<key> link. |
| title | string | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| created_at | string | yes | – |
| currency | string | yes | – |
| entries | array | yes | – |
| key | string | yes | – |
| participants | array | yes | – |
| secure | boolean | yes | – |
| settled | boolean | yes | – |
| settlement | array | yes | – |
| title | string | yes | – |
| total_spent | number | yes | – |
| url | string | yes | – |
No examples provided.
What is the xupersplit MCP server?
xupersplit is an MCP server listed in the public MCP registry as io.github.kanylbullen/xupersplit. Split shared expenses in a group, no account needed. See who owes whom and settle up. This page covers its hosted endpoint (https://split.xuper.fun/api/mcp).
Is the xupersplit MCP server safe to use?
xupersplit scores 81 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the xupersplit MCP server expose?
xupersplit exposes 11 tools: create_split, get_split, add_expense, record_payment, update_entry, and 6 more. Their descriptions and schemas cost roughly 1,551 tokens of context every time the server is loaded.
Does the xupersplit MCP server require authentication?
No. We connected to xupersplit without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the xupersplit MCP server still maintained?
xupersplit is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.