OpenWeather for agents
REMOTE · MCP.OPENWEATHERMAP.ORG · SCANNED SEP 22
OpenWeather data for AI agents: list feeds, sign up, check balance, get a top-up link, fetch data.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security80
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability69
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1323 tokens (~220/item across 6 items; 6 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management60
- Stability observed for 18 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 6 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 7 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the OpenWeather for agents MCP server?
OpenWeather for agents is a hosted endpoint at https://mcp.openweathermap.org/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.openweathermap.org
claude mcp add --transport http org-openweathermap-agents 'https://mcp.openweathermap.org/mcp'
{
"mcpServers": {
"org-openweathermap-agents": {
"url": "https://mcp.openweathermap.org/mcp"
}
}
} {
"servers": {
"org-openweathermap-agents": {
"type": "http",
"url": "https://mcp.openweathermap.org/mcp"
}
}
} [mcp_servers.org-openweathermap-agents] url = "https://mcp.openweathermap.org/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"org-openweathermap-agents": {
"type": "remote",
"url": "https://mcp.openweathermap.org/mcp",
"enabled": true
}
}
} openclaw mcp add org-openweathermap-agents --url 'https://mcp.openweathermap.org/mcp' --transport streamable-http
mcp_servers:
org-openweathermap-agents:
url: "https://mcp.openweathermap.org/mcp" {
"McpServers": {
"org-openweathermap-agents": {
"Transport": "http",
"Url": "https://mcp.openweathermap.org/mcp"
}
}
} assistant mcp add org-openweathermap-agents -t streamable-http -u 'https://mcp.openweathermap.org/mcp'
{
"mcpServers": {
"org-openweathermap-agents": {
"type": "http",
"url": "https://mcp.openweathermap.org/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 22 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.
- 20 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 50 to 53. That category is still filling its 30-day observation window: 15 days of observed history at the previous scan, 16 at this one. The score rises as the window fills, whether or not the server changes.
- 18 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 43 to 47. That category is still filling its 30-day observation window: 13 days of observed history at the previous scan, 14 at this one. The score rises as the window fills, whether or not the server changes.
- 15 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 33 to 37. That category is still filling its 30-day observation window: 10 days of observed history at the previous scan, 11 at this one. The score rises as the window fills, whether or not the server changes.
- 13 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 27 to 30. That category is still filling its 30-day observation window: 8 days of observed history at the previous scan, 9 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.
- 10 Sept 26 0
- The server rewrote its instructions, which are the text every model session reads security
- Tool “account_status” rewrote its description, which is the text the model reads security
- Tool “fetch_data” rewrote its description, which is the text the model reads security
- Tool “sign_up” rewrote its description, which is the text the model reads security
- 9 Sept 26 0
- The server rewrote its instructions, which are the text every model session reads security
- Tool “fetch_data” rewrote its description, which is the text the model reads security
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 22 Sept 2026 · Probed https://mcp.openweathermap.org/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=mcp.forum.bot | CN=YR1,O=Let's Encrypt,C=US | 4 Sept 2026 | 3 Dec 2026 | RSA 4096 | SHA256-RSA | 504868cd933ce01fee8440b363910b9bf3e |
| SANs: mcp.forum.bot, mcp.openweathermap.org | ||||||
| CN=YR1,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | a20253f15f2691c05dc1ce13b9bcca4e |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.openweathermap.org. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| org. | present | 26974 | 8 | Verified |
| openweathermap.org. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.openweathermap.org/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.openweathermap.org/mcp | HTTPS enforced | 301 | https://mcp.openweathermap.org/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
account_status Account status ~188
Reads the account behind the secret: tier, accepted Terms version, the products it may call, the balance in credits the account bought minus the spend those credits funded, the last 30 days of usage per day, product and key, and the 50 latest balance movements. A product's own daily credits are spent before that balance and are no part of it, so a call can be served while it reads zero; list_products carries each product's credit account. Pass the secret sign_up returned as the secret argument; the data key your client configuration sends cannot read the account and answers 403 wrong_credential. Charges nothing; without a string the platform answers 401 invalid_key.
| Name | Type | Req | Description |
|---|---|---|---|
| secret | string | – | the account's secret — the string sign_up returned as secret; the client configuration's header holds the data key, which this tool cannot use; when both are present the argument wins |
| Name | Type | Req | Description |
|---|---|---|---|
| account | – | – | – |
| body | – | – | – |
| body_text | string | – | – |
| configure | object | – | – |
| fault | object | – | – |
| headers | object | – | – |
| key_source | string | – | – |
| record | object | – | – |
| request_id | string | yes | – |
| status | integer|null | – | – |
| transport | object | – | – |
| upstream | string|null | – | – |
| usage | object | – | – |
No examples provided.
fetch_data Fetch data ~312
Fetches one data response: GET data.openweathermap.org/{product}/{route} with the query parameters you pass, using the data key from your client configuration's Authorization header or the data_key argument — never the secret, which fetches nothing. A successful call is billed the product's price per call; a refused call costs nothing. The result carries the payload with the platform's meta block (licence and attribution) and the rate-limit headers; the balance is read with account_status, never from a data response. Every refusal is the platform's error envelope unchanged — a code from https://agents.openweathermap.org/errors.json; 402 payment_required means the key is known but cannot pay for this product now, and 401 invalid_key means it is authorized for no product at all, most often because every credit is spent. Both carry an action_url: a human tops up there (get_topup_link returns the page) and the same key serves again within the engine's build interval plus the region's poll interval.
| Name | Type | Req | Description |
|---|---|---|---|
| data_key | string | – | only when the client cannot send an Authorization header — the data_key.key sign_up returned in this session; when both are present the argument wins |
| params | object | – | query parameters, sent as given; the parameters a route requires are in get_product |
| product | string | yes | a product slug from list_products |
| route | string | yes | a route from get_product, without the product prefix — e.g. current or timeline/1h |
| Name | Type | Req | Description |
|---|---|---|---|
| account | – | – | – |
| body | – | – | – |
| body_text | string | – | – |
| configure | object | – | – |
| fault | object | – | – |
| headers | object | – | – |
| key_source | string | – | – |
| record | object | – | – |
| request_id | string | yes | – |
| status | integer|null | – | – |
| transport | object | – | – |
| upstream | string|null | – | – |
| usage | object | – | – |
No examples provided.
get_product Get product ~99
Returns one product by slug: its live catalogue entry (price, licence, lifecycle state, the specification address) together with the routes fetch_data can call and the parameters each route requires, taken from the platform's published product record. Needs no key and charges nothing. Use it before fetch_data — the route names come from here; an unknown slug answers with the slugs the catalogue serves.
| Name | Type | Req | Description |
|---|---|---|---|
| product | string | yes | a product slug from list_products |
| Name | Type | Req | Description |
|---|---|---|---|
| account | – | – | – |
| body | – | – | – |
| body_text | string | – | – |
| configure | object | – | – |
| fault | object | – | – |
| headers | object | – | – |
| key_source | string | – | – |
| record | object | – | – |
| request_id | string | yes | – |
| status | integer|null | – | – |
| transport | object | – | – |
| upstream | string|null | – | – |
| usage | object | – | – |
No examples provided.
get_topup_link Get top-up link ~212
Opens a top-up for the account and returns the payment intent with hosted_url, the payment provider's short-lived page where a human completes the payment — no tool pays, and card details never touch the Forum. amount_minor is in cents; the platform accepts USD only and a minimum of 1000 (= $10). Pass the secret sign_up returned as the secret argument; the data key cannot open a payment. Asking again while a page is open returns the same page. Bought credits appear in account_status once the payment completes.
| Name | Type | Req | Description |
|---|---|---|---|
| amount_minor | integer | yes | the amount in the currency's minor unit (cents); the platform's minimum is 1000 = $10 and the platform checks it |
| currency | string | – | USD is the only currency the platform accepts; the platform refuses any other |
| secret | string | – | the account's secret — the string sign_up returned as secret; the data key in the client configuration cannot open a payment; when both are present the argument wins |
| Name | Type | Req | Description |
|---|---|---|---|
| account | – | – | – |
| body | – | – | – |
| body_text | string | – | – |
| configure | object | – | – |
| fault | object | – | – |
| headers | object | – | – |
| key_source | string | – | – |
| record | object | – | – |
| request_id | string | yes | – |
| status | integer|null | – | – |
| transport | object | – | – |
| upstream | string|null | – | – |
| usage | object | – | – |
No examples provided.
list_products List products ~88
Lists every data product the Forum serves, as the platform's own catalogue answer: slug, title, lifecycle state, price in credits per call (1 credit = $0.001; the quoted price is the charged price), licence and attribution text, and the address of the product's route specification. Needs no key and charges nothing. Call get_product next for a product's routes and required parameters.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| account | – | – | – |
| body | – | – | – |
| body_text | string | – | – |
| configure | object | – | – |
| fault | object | – | – |
| headers | object | – | – |
| key_source | string | – | – |
| record | object | – | – |
| request_id | string | yes | – |
| status | integer|null | – | – |
| transport | object | – | – |
| upstream | string|null | – | – |
| usage | object | – | – |
No examples provided.
sign_up Sign up ~200
Creates a Forum account for an email address under the Terms version currently served, and returns the account, its secret — the one string that runs the account, shown exactly once — and its first data key, shown exactly once. It grants the account no credits of its own: a new account's free calls are the daily credit account of each product that gives one, spendable on that product alone and replaced every night, and list_products states which products give one and how much. The result's configure block is the client configuration entry that sends the data key from then on; until the client reconnects, pass data_key.key as data_key on fetch_data. Keep the secret with the owner and pass it as secret on account_status and get_topup_link. An address that already has an account answers 409 email_exists with next_action login_to_link.
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | the owner's email address — the account's identity; one account per address |
| Name | Type | Req | Description |
|---|---|---|---|
| account | – | – | – |
| body | – | – | – |
| body_text | string | – | – |
| configure | object | – | – |
| fault | object | – | – |
| headers | object | – | – |
| key_source | string | – | – |
| record | object | – | – |
| request_id | string | yes | – |
| status | integer|null | – | – |
| transport | object | – | – |
| upstream | string|null | – | – |
| usage | object | – | – |
No examples provided.
What is the OpenWeather for agents MCP server?
OpenWeather for agents is an MCP server listed in the public MCP registry as org.openweathermap/agents. OpenWeather data for AI agents: list feeds, sign up, check balance, get a top-up link, fetch data. This page covers its hosted endpoint (https://mcp.openweathermap.org/mcp).
Is the OpenWeather for agents MCP server safe to use?
OpenWeather for agents scores 81 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the OpenWeather for agents MCP server expose?
OpenWeather for agents exposes 6 tools: list_products, get_product, sign_up, account_status, get_topup_link, fetch_data. Their descriptions and schemas cost roughly 1,099 tokens of context every time the server is loaded.
Does the OpenWeather for agents MCP server require authentication?
No. We connected to OpenWeather for agents without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the OpenWeather for agents MCP server still maintained?
OpenWeather for agents is still listed as active in the MCP registry. We last reached this channel on 22 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.