WozApi
REMOTE · WOZ-API.NL · SCANNED OCT 4
WOZ values (official Dutch property valuations) for Dutch addresses, one lookup or a whole list.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security83
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability73
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1712 tokens (~190/item across 9 items; 9 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management23
- Stability observed for 7 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 9 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 10 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the WozApi MCP server?
WozApi is a hosted endpoint at https://woz-api.nl/Api/Mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · woz-api.nl
claude mcp add --transport http nl-woz-api-wozapi 'https://woz-api.nl/Api/Mcp'
{
"mcpServers": {
"nl-woz-api-wozapi": {
"url": "https://woz-api.nl/Api/Mcp"
}
}
} {
"servers": {
"nl-woz-api-wozapi": {
"type": "http",
"url": "https://woz-api.nl/Api/Mcp"
}
}
} [mcp_servers.nl-woz-api-wozapi] url = "https://woz-api.nl/Api/Mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"nl-woz-api-wozapi": {
"type": "remote",
"url": "https://woz-api.nl/Api/Mcp",
"enabled": true
}
}
} openclaw mcp add nl-woz-api-wozapi --url 'https://woz-api.nl/Api/Mcp' --transport streamable-http
mcp_servers:
nl-woz-api-wozapi:
url: "https://woz-api.nl/Api/Mcp" {
"McpServers": {
"nl-woz-api-wozapi": {
"Transport": "http",
"Url": "https://woz-api.nl/Api/Mcp"
}
}
} assistant mcp add nl-woz-api-wozapi -t streamable-http -u 'https://woz-api.nl/Api/Mcp'
{
"mcpServers": {
"nl-woz-api-wozapi": {
"type": "http",
"url": "https://woz-api.nl/Api/Mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 4 Oct 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.
- 2 Oct 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 13 to 17. That category is still filling its 30-day observation window: 4 days of observed history at the previous scan, 5 at this one. The score rises as the window fills, whether or not the server changes.
- 30 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.
- 28 Sept 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Sept 26 74
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 4 Oct 2026 · Probed https://woz-api.nl/Api/Mcp
TLS valid
Negotiated TLS 1.2 with TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=woz-api.nl | CN=YR1,O=Let's Encrypt,C=US | 20 Aug 2026 | 18 Nov 2026 | RSA 3072 | SHA256-RSA | 5ce3363a92460293d9b770b62fad7ca2431 |
| SANs: woz-api.nl, www.woz-api.nl | ||||||
| CN=YR1,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | a20253f15f2691c05dc1ce13b9bcca4e |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
Background: What to check on a remote MCP endpoint →
DNSSEC secure
Validation of woz-api.nl. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| nl. | present | 17153 | 13 | Verified |
| woz-api.nl. | present | 12521 | 13 | Verified |
| woz-api.nl. | Verified address RRset verified with the apex keys |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000 |
| x-content-type-options | nosniff |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | geolocation=(), microphone=(), camera=(), payment=(), interest-cohort=() |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://woz-api.nl/Api/Mcp | Verified | 200 | |
| http (plaintext) | http://woz-api.nl/Api/Mcp | HTTPS enforced | 308 | https://woz-api.nl/Api/Mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
add_trial_email E-mailadres aan de proef toevoegen ~124
Adds the user's own e-mail address to a trial. The trial grows to 10 addresses in total and the user gets a WozApi account without a password (they log in with a code sent by e-mail). Only use an address the user typed.
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | Optional. The user's own e-mail address, only if the user typed it. Never invent one. | |
| trial_code | string | yes | The trial_code from start_trial. Leave empty when the user is signed in to WozApi or the connection has a WozApi API key. |
No output schema declared.
No examples provided.
create_credit_payment_link Betaallink voor credits ~127
Returns a page where the user buys WozApi credits for single lookups and pays with iDEAL. This tool moves no money. Works when the user is signed in to WozApi, with the connected API key, or with a trial_code that has the user's e-mail address.
| Name | Type | Req | Description |
|---|---|---|---|
| credits | integer|null | – | Optional. Number of credits; leave empty for the suggested amount. |
| trial_code | string|null | – | The trial_code from start_trial. Leave empty when the user is signed in to WozApi or the connection has a WozApi API key. |
No output schema declared.
No examples provided.
create_list_payment_link Betaallink voor de lijst ~113
Returns the page where the user reviews the trial and the price of the list and pays with iDEAL. This tool moves no money: payment only happens when the user pays on that page. Optionally stores the user's own e-mail address for delivery of the file and the invoice.
| Name | Type | Req | Description |
|---|---|---|---|
| string|null | – | Optional. The user's own e-mail address for delivery of the file and the invoice, only if the user typed it. | |
| list_token | string | yes | The list_token from start_address_list. |
No output schema declared.
No examples provided.
get_account_balance Saldo bekijken ~65
Returns the remaining credits of the user's own WozApi account. Needs the user to be signed in to WozApi, or a WozApi API key on the connection; when neither is there, the client asks the user to sign in first. Read-only and free.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_address_list Adreslijst bekijken ~141
Returns the status of an address list: trial rows, number of addresses found, price, payment link, progress, and after payment the result rows (at most 50 per call; use offset for more) and a download link for the Excel file. Can wait up to 20 seconds for the trial or the processing to finish.
| Name | Type | Req | Description |
|---|---|---|---|
| list_token | string | yes | The list_token from start_address_list. |
| offset | integer | – | Optional. First result row to return after delivery, starting at 0. |
| wait_seconds | integer | – | Optional. Seconds to wait for a change while the trial or the processing runs, 0 to 20. |
No output schema declared.
No examples provided.
get_prices Prijzen bekijken ~41
Returns WozApi prices: credits for single lookups by quantity, the price of an address list by size, and the trial terms. Read-only and free.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
lookup_woz_value WOZ-waarde opvragen ~173
Returns the WOZ values of one Dutch address for all available years, with the address as matched. Costs one trial address or one credit per unique address; the same address again within 7 days, an answer without WOZ values and an error cost nothing. For questions about properties, not to assess or profile people. Needs a trial_code unless the user is signed in to WozApi or the connection has a WozApi API key.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | A full Dutch address with house number and postcode or city, for example 'Spuistraat 36C, 1012 TT Amsterdam'. |
| trial_code | string|null | – | The trial_code from start_trial. Leave empty when the user is signed in to WozApi or the connection has a WozApi API key. |
No output schema declared.
No examples provided.
start_address_list Adreslijst starten ~195
Starts WOZ lookups for a whole list of Dutch addresses, for example from a spreadsheet the user shared. Runs a free trial on 5 addresses, then gives the price of the full list and a payment page for the user. Returns a list_token for get_address_list. Sending the same list again within an hour returns the same list.
| Name | Type | Req | Description |
|---|---|---|---|
| addresses | array | yes | The addresses, one string per row in the original order, each with house number and postcode or city. |
| string|null | – | Optional. The user's own e-mail address for delivery of the file and the invoice, only if the user typed it. | |
| place | string|null | – | Optional. The city for all addresses that have no postcode or city. |
| trial_code | string|null | – | The trial_code from start_trial. Leave empty when the user is signed in to WozApi or the connection has a WozApi API key. |
No output schema declared.
No examples provided.
start_trial Gratis proef starten ~124
Starts a free WozApi trial without an account and returns a trial_code. The trial covers WOZ value lookups for 5 unique Dutch addresses, or 10 when the user's own e-mail address is given. Pass the trial_code to lookup_woz_value and start_address_list. Call it once per conversation, and not when the user is signed in to WozApi or the connection already has a WozApi API key.
| Name | Type | Req | Description |
|---|---|---|---|
| string|null | – | Optional. The user's own e-mail address, only if the user typed it. Never invent one. |
No output schema declared.
No examples provided.
What is the WozApi MCP server?
WozApi is an MCP server listed in the public MCP registry as nl.woz-api/wozapi. WOZ values (official Dutch property valuations) for Dutch addresses, one lookup or a whole list. This page covers its hosted endpoint (https://woz-api.nl/Api/Mcp).
Is the WozApi MCP server safe to use?
WozApi scores 78 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the WozApi MCP server expose?
WozApi exposes 9 tools: create_credit_payment_link, add_trial_email, get_account_balance, get_address_list, start_address_list, and 4 more. Their descriptions and schemas cost roughly 1,103 tokens of context every time the server is loaded.
Does the WozApi MCP server require authentication?
No. We connected to WozApi without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the WozApi MCP server still maintained?
WozApi is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.