OpenJob
REMOTE · OPENJOBS-3168F222.ALPIC.LIVE · SCANNED SEP 20
Find jobs in your own words and apply on the company website — no detours.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to connect, but we couldn't read the tool list to see what that exposes. View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability0
- Transport check failed: declared streamable-http, but the endpoint returned HTTP 402. See how to fix → View diagnostics → Fail
Schema Quality & AI Usability0
- Schema not yet verified: we couldn't read the endpoint's schema.Unverified
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage0
- Tool coverage not yet verified: we couldn't read the endpoint's tools.Unverified
Tool Safety0
- Tool safety not yet verified: we couldn't read the endpoint's tools.Unverified
Capabilities0
- Capabilities not yet verified: we couldn't read the endpoint's capabilities.Unverified
Unverified: 5 categories
Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.
How do I install the OpenJob MCP server?
OpenJob is a hosted endpoint at https://openjobs-3168f222.alpic.live/, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · openjobs-3168f222.alpic.live
claude mcp add --transport http live-alpic-openjobs-3168f222-openjobs 'https://openjobs-3168f222.alpic.live/'
{
"mcpServers": {
"live-alpic-openjobs-3168f222-openjobs": {
"url": "https://openjobs-3168f222.alpic.live/"
}
}
} {
"servers": {
"live-alpic-openjobs-3168f222-openjobs": {
"type": "http",
"url": "https://openjobs-3168f222.alpic.live/"
}
}
} [mcp_servers.live-alpic-openjobs-3168f222-openjobs] url = "https://openjobs-3168f222.alpic.live/"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"live-alpic-openjobs-3168f222-openjobs": {
"type": "remote",
"url": "https://openjobs-3168f222.alpic.live/",
"enabled": true
}
}
} openclaw mcp add live-alpic-openjobs-3168f222-openjobs --url 'https://openjobs-3168f222.alpic.live/' --transport streamable-http
mcp_servers:
live-alpic-openjobs-3168f222-openjobs:
url: "https://openjobs-3168f222.alpic.live/" {
"McpServers": {
"live-alpic-openjobs-3168f222-openjobs": {
"Transport": "http",
"Url": "https://openjobs-3168f222.alpic.live/"
}
}
} assistant mcp add live-alpic-openjobs-3168f222-openjobs -t streamable-http -u 'https://openjobs-3168f222.alpic.live/'
{
"mcpServers": {
"live-alpic-openjobs-3168f222-openjobs": {
"type": "http",
"url": "https://openjobs-3168f222.alpic.live/"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 12 Sept 26 −62
- Endpoint reachability: reachable → not serving MCP ▼ security
- Stability: pass → unverified ▼ security
- Tool safety: pass → unverified ▼ security
- Authorization: partial → unverified ▼ security
- Transport: pass → fail ▼ security
- Schema quality: 100 → unverified ▼ functional
- Capabilities: pass → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- 11 Sept 26 0
- Resource “get_job_details” now points somewhere else: ui://views/apps-sdk/job-details.html?v=d67f2d6f → ui://views/ext-apps/job-details.html?v=d67f2d6f security
- Resource “search_jobs” now points somewhere else: ui://views/apps-sdk/jobs.html?v=97de5338 → ui://views/ext-apps/jobs.html?v=97de5338 security
- 10 Sept 26 0
- Resource “get_job_details” now points somewhere else: ui://views/apps-sdk/job-details.html?v=d67f2d6f → ui://views/ext-apps/job-details.html?v=d67f2d6f security
- Resource “search_jobs” now points somewhere else: ui://views/apps-sdk/jobs.html?v=97de5338 → ui://views/ext-apps/jobs.html?v=97de5338 security
- 9 Sept 26 0
- Resource “get_job_details” now points somewhere else: ui://views/apps-sdk/job-details.html?v=d67f2d6f → ui://views/ext-apps/job-details.html?v=d67f2d6f security
- Resource “search_jobs” now points somewhere else: ui://views/apps-sdk/jobs.html?v=97de5338 → ui://views/ext-apps/jobs.html?v=97de5338 security
- 8 Sept 26 0
- Resource “get_job_details” now points somewhere else: ui://views/apps-sdk/job-details.html?v=d67f2d6f → ui://views/ext-apps/job-details.html?v=d67f2d6f security
- Resource “search_jobs” now points somewhere else: ui://views/apps-sdk/jobs.html?v=97de5338 → ui://views/ext-apps/jobs.html?v=97de5338 security
- 7 Sept 26 0
- Resource “get_job_details” now points somewhere else: ui://views/apps-sdk/job-details.html?v=d67f2d6f → ui://views/ext-apps/job-details.html?v=d67f2d6f security
- Resource “search_jobs” now points somewhere else: ui://views/apps-sdk/jobs.html?v=97de5338 → ui://views/ext-apps/jobs.html?v=97de5338 security
- 6 Sept 26 0
- Resource “get_job_details” now points somewhere else: ui://views/apps-sdk/job-details.html?v=d67f2d6f → ui://views/ext-apps/job-details.html?v=d67f2d6f security
- Resource “search_jobs” now points somewhere else: ui://views/apps-sdk/jobs.html?v=97de5338 → ui://views/ext-apps/jobs.html?v=97de5338 security
- 5 Sept 26 0
- Resource “get_job_details” now points somewhere else: ui://views/apps-sdk/job-details.html?v=d67f2d6f → ui://views/ext-apps/job-details.html?v=d67f2d6f security
- Resource “search_jobs” now points somewhere else: ui://views/apps-sdk/jobs.html?v=97de5338 → ui://views/ext-apps/jobs.html?v=97de5338 security
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://openjobs-3168f222.alpic.live
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=*.alpic.live | CN=Amazon RSA 2048 M01,O=Amazon,C=US | 23 Oct 2025 | 21 Nov 2026 | RSA 2048 | SHA256-RSA | 2f102c87e3a6a1adcfbddc95579fdc1 |
| SANs: *.alpic.live | ||||||
| CN=Amazon RSA 2048 M01,O=Amazon,C=US (CA) | CN=Amazon Root CA 1,O=Amazon,C=US | 23 Aug 2022 | 23 Aug 2030 | RSA 2048 | SHA256-RSA | 77312380b9d6688a33b1ed9bf9ccda68e0e0f |
| CN=Amazon Root CA 1,O=Amazon,C=US (CA) | CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies\, Inc.,L=Scottsdale,ST=Arizona,C=US | 25 May 2015 | 31 Dec 2037 | RSA 2048 | SHA256-RSA | 67f944a2a27cdf3fac2ae2b01f908eeb9c4c6 |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of openjobs-3168f222.alpic.live. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| live. | present | 36322 | 8 | Verified |
| alpic.live. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 402 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 3 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://openjobs-3168f222.alpic.live | HTTP error | 402 | |
| sse | https://openjobs-3168f222.alpic.live | HTTP error | 402 | |
| http (plaintext) | http://openjobs-3168f222.alpic.live | HTTPS enforced | 301 | https://openjobs-3168f222.alpic.live/ |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
explain_data_source ~49
Where job listings come from, licensing, and links to the data provider. Use only when the user asks about data source, Feashliaa, license, attribution, or who built OpenJob.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| affiliation | string | yes | – |
| github | string | yes | – |
| license | string | yes | – |
| license_url | string | yes | – |
| maintainer | string | yes | – |
| openjob_repo | string | yes | – |
| provider | string | yes | – |
| summary | string | yes | – |
| update_cadence | string | yes | – |
| website | string | yes | – |
| what_we_show | string | yes | – |
No examples provided.
explain_filters ~37
Plain-language search tips for job seekers. Use when the user asks how to search or what they can filter. No technical jargon in the reply.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| filters | array | yes | – |
| if_no_results | array | yes | – |
| intro | string | yes | – |
| limitations | array | yes | – |
| role_presets | array | yes | – |
| title | string | yes | – |
| verified_examples | array | yes | – |
No examples provided.
get_app_intro ~35
Friendly introduction to OpenJob for job seekers. Use when the user is new or asks how this works. Return plain language only.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| cv_note | string | yes | – |
| example_prompts | array | yes | – |
| name | string | yes | – |
| seniority_note | string | yes | – |
| tagline | string | yes | – |
| tips | array | yes | – |
| welcome | string | yes | – |
| what_it_does | string | yes | – |
| who_its_for | string | yes | – |
No examples provided.
get_index_status ~36
How much of the job board is loaded and whether search is ready. Explain to the user in simple terms, not technical sync jargon.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| baked_index | boolean | yes | – |
| coverage_percent | – | yes | – |
| jobs_loaded | number | yes | – |
| message | string | yes | – |
| ready | boolean | yes | – |
| still_loading | boolean | yes | – |
| total_jobs_about | – | yes | – |
No examples provided.
get_job_details ~583
Fetch full posting text for job urls from search_jobs. Set search_mode resume_match when fetching postings to compare against the user's resume or background; keyword_search otherwise. Greenhouse (including embedded careers pages), Ashby, and Lever are supported; other career sites may return unsupported_ats. Closed roles are cached about 24 hours; open postings about 14 days (posting text only, not user resumes). Use description_text to compare against the user's resume or stated background.
| Name | Type | Req | Description |
|---|---|---|---|
| search_mode | string | – | keyword_search = role/location/filters only; resume_match = user uploaded a resume (CV) or asked to match jobs to their background or ChatGPT memory. |
| url | string | – | Single job url from search_jobs results. |
| urls | array | – | Up to 10 job urls — preferred after resume match. |
| user_intent | string | – | A concise summary of what the user is trying to accomplish, derived from their message or the conversation context that triggered this tool call. This is used to understand the user's intent and cont… |
| Name | Type | Req | Description |
|---|---|---|---|
| count | number | yes | – |
| from_cache_count | number | – | – |
| jobs | array | yes | – |
| loaded_ok | number | yes | – |
| requested | number | yes | – |
No examples provided.
search_jobs ~1,295
Search open company job listings. Map the user's natural language to filters. Always set search_mode on search_jobs and get_job_details: keyword_search when the user only describes a role, place, or filters; resume_match when they upload a resume/CV or ask to match jobs to their background or memory. Never show parameter names (role_cluster, skill_level, search_mode, etc.) to the user — speak like a career coach. Do not mention data sources or licenses unless the user asks — use explain_data_source for that. Every job has url and apply_url (company careers page). When you list jobs in a table, bullets, or prose, each row must include at least one clickable markdown link to that url — e.g. linked title [Title](url), linked company name, or a separate Apply / View posting link. Never list a job with no way to click through. After search_jobs, add a structured follow-up in the user's language — the widget shows cards; your text adds coaching. Include: (1) a markdown table Role | Company | Fit (use resume/memory when available; otherwise one-line highlight per row); (2) a numbered priority list for applying (top 3–5 with brief rationale); (3) if the user shared background, one CV positioning sentence they can reuse; (4) related title search variants as inline tags (e.g. Entrepreneur in Residence, Venture Development, GTM Associate, Chief of Staff). When the user has a resume or detailed background, call get_job_details on the best 5–8 urls before ranking. Do not invent match percentages. search_jobs live-checks up to 8 Greenhouse/Ashby/Lever listings per search and drops roles confirmed closed on the company site. For deeper advice on a shortlist, call get_job_details on the best urls (batch up to 10) to load full posting text. Use verifiable_only=true when the user wants only listings we can double-check live (~30% of the board). When the user uploads a resume (curriculum vitae) or asks to match jobs to their background (or ChatGPT memory): (1) extract target titles,…
| Name | Type | Req | Description |
|---|---|---|---|
| ats | string | – | Career-site type if user asks, e.g. greenhouse, lever, ashby |
| company | string | – | Company name. |
| exclude_keywords | string | – | Comma-separated words to exclude from title |
| hide_recruiters | boolean | – | Exclude recruiting-agency posts; default true |
| include_keywords | string | – | Comma-separated words that must appear in title |
| limit | integer | – | – |
| location | string | – | City, region, or country. |
| min_salary | number | – | – |
| remote_only | boolean | – | – |
| role_cluster | string | – | Internal preset when user wants a role family: founder_associate | chief_of_staff | product_manager |
| search_mode | string | yes | keyword_search = role/location/filters only; resume_match = user uploaded a resume (CV) or asked to match jobs to their background or ChatGPT memory. |
| skill_level | string | – | Seniority if user says junior, senior, etc. |
| title | string | – | Job title keywords from the user's words. |
| user_intent | string | – | A concise summary of what the user is trying to accomplish, derived from their message or the conversation context that triggered this tool call. This is used to understand the user's intent and cont… |
| verifiable_only | boolean | – | Only Greenhouse, Ashby, and Lever (~30% of board) — listings we can live-verify |
| verify_live | boolean | – | Live-check Greenhouse/Ashby/Lever and drop listings confirmed closed; default true |
| Name | Type | Req | Description |
|---|---|---|---|
| apply_note | string | yes | – |
| count | number | yes | – |
| hints | array | yes | – |
| jobs | array | yes | – |
| listings_removed | number | – | – |
| live_checks_run | number | – | – |
| locale | string | yes | – |
| model_followup_hint | string | yes | – |
No examples provided.
What is the OpenJob MCP server?
OpenJob is an MCP server listed in the public MCP registry as live.alpic.openjobs-3168f222/openjobs. Find jobs in your own words and apply on the company website, no detours. This page covers its hosted endpoint (https://openjobs-3168f222.alpic.live).
Is the OpenJob MCP server safe to use?
OpenJob scores 23 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the OpenJob MCP server expose?
OpenJob exposes 6 tools: get_app_intro, explain_filters, explain_data_source, get_index_status, search_jobs, get_job_details. Their descriptions and schemas cost roughly 2,035 tokens of context every time the server is loaded.
Does the OpenJob MCP server require authentication?
No. We connected to OpenJob without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the OpenJob MCP server still maintained?
OpenJob is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.