SingChat
REMOTE · MCP.SINGCHAT.ORG · SCANNED SEP 24
Free live chat and AI support agent. Auto-create a workspace and embed from your AI editor.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 17 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability85
- AI-judged instruction clarity (excellent).Pass
- Tool/resource definitions use about 1587 tokens (~93/item across 17 items; 17 tools + 0 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (12% of tools); any adoption earns full credit.Pass
Tool Safety75
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 0 of 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "reply_to_conversation" implies "send" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
- An AI judge read all 17 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the SingChat MCP server?
SingChat is a hosted endpoint at https://mcp.singchat.org/, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.singchat.org
claude mcp add --transport http org-singchat-singchat 'https://mcp.singchat.org/'
{
"mcpServers": {
"org-singchat-singchat": {
"url": "https://mcp.singchat.org/"
}
}
} {
"servers": {
"org-singchat-singchat": {
"type": "http",
"url": "https://mcp.singchat.org/"
}
}
} [mcp_servers.org-singchat-singchat] url = "https://mcp.singchat.org/"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"org-singchat-singchat": {
"type": "remote",
"url": "https://mcp.singchat.org/",
"enabled": true
}
}
} openclaw mcp add org-singchat-singchat --url 'https://mcp.singchat.org/' --transport streamable-http
mcp_servers:
org-singchat-singchat:
url: "https://mcp.singchat.org/" {
"McpServers": {
"org-singchat-singchat": {
"Transport": "http",
"Url": "https://mcp.singchat.org/"
}
}
} assistant mcp add org-singchat-singchat -t streamable-http -u 'https://mcp.singchat.org/'
{
"mcpServers": {
"org-singchat-singchat": {
"type": "http",
"url": "https://mcp.singchat.org/"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 21 Sept 26 0
- Tool “add_knowledge” rewrote its description, which is the text the model reads security
- 26 Aug 26 79
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 0
- Stability: 0.97 → pass security
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 31 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 0
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 24 Sept 2026 · Probed https://mcp.singchat.org
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=singchat.org | CN=YE2,O=Let's Encrypt,C=US | 24 Sept 2026 | 23 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 6e43d9c1d47a2b6075050c3dfcd4c380c07 |
| SANs: *.singchat.org, singchat.org | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.singchat.org. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| org. | present | 26974 | 8 | Verified |
| singchat.org. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| x-content-type-options | nosniff |
| x-frame-options | SAMEORIGIN |
| referrer-policy | strict-origin-when-cross-origin |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.singchat.org | Verified | 200 | |
| http (plaintext) | http://mcp.singchat.org | HTTPS enforced | 301 | https://mcp.singchat.org/ |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
add_knowledge Add knowledge ~153
Train the AI agent by adding a knowledge source. type='url' crawls a website (up to 50 pages, fewer when the workspace knowledge-base quota is nearly full); type='qa' stores a single question/answer pair. Ingestion is asynchronous, the source starts as PENDING; poll `list_knowledge` for READY status.
| Name | Type | Req | Description |
|---|---|---|---|
| answer | string | – | The answer. Required when type='qa'. |
| question | string | – | The question. Required when type='qa'. |
| type | string | yes | 'url' to crawl a website, or 'qa' to add a question/answer pair. |
| url | string | – | Website root URL to crawl. Required when type='url'. |
No output schema declared.
No examples provided.
claim_account Claim SingChat account ~67
Return the link to claim (permanently secure) this SingChat workspace by setting an email and password. Use this for workspaces that were auto-created via MCP so the user does not lose access. The link is single-use and expires after 15 minutes. Requires an authenticated legacy workspace.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
configure_agent Configure AI agent ~172
Configure this workspace's AI support agent. All fields are optional, only the fields you pass are updated; the rest keep their current values. Call with no fields to just read back the current configuration. Does not touch or return any API keys.
| Name | Type | Req | Description |
|---|---|---|---|
| enabled | boolean | – | Turn the automated AI agent on (true) or off (false). |
| greetingMessage | string | – | First message visitors see when they open the chat. Pass an empty string to clear it. |
| model | string | – | Chat model id, e.g. gpt-4o-mini. |
| providerMode | string | – | 'platform' = platform-hosted keys (billed via AI credits); 'byok' = bring your own key. |
| systemPrompt | string | – | The agent's system prompt / persona and answering rules. |
No output schema declared.
No examples provided.
fetch Fetch ~80
Fetch the full text of a single document by id, using an id returned by the search tool. With a workspace API key this reads a knowledge document from that workspace; without a key it reads a SingChat help article. Returns id, title, text, url, and optional metadata.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | The document id returned by the search tool. |
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
| metadata | object | – | – |
| text | string | yes | – |
| title | string | yes | – |
| url | string | yes | – |
No examples provided.
get_analytics Get Analytics ~71
Return a compact analytics summary for this workspace over the last `days` days (default 30): conversation counts + resolution rate, message volume + AI share, plus a live snapshot of today (UTC).
| Name | Type | Req | Description |
|---|---|---|---|
| days | integer | – | Look-back window in days for the conversation/message stats (default 30). |
No output schema declared.
No examples provided.
get_conversation Get conversation ~45
Fetch a single conversation with its contact details and the most recent messages (oldest→newest).
| Name | Type | Req | Description |
|---|---|---|---|
| conversationId | string | yes | The conversation id (from list_conversations). |
No output schema declared.
No examples provided.
get_embed_snippet Get widget embed snippet ~80
Return the SingChat chat-widget embed code for this workspace's web inbox, in three flavors: plain HTML, React (useEffect), and Next.js (next/script). Requires a workspace API key. Optionally pass `platform` to get just one flavor.
| Name | Type | Req | Description |
|---|---|---|---|
| platform | string | – | Which snippet to return. Omit to get all three. |
No output schema declared.
No examples provided.
list_conversations List conversations ~112
List the workspace's support conversations (agent/inbox view), newest activity first. Optionally filter by status or a free-text search over the contact name/email and last message. Returns a compact list: id, contact name, status, unreadCount, last message preview, updatedAt.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Max conversations to return (default 100). |
| search | string | – | Free-text match on contact name/email and the last message preview. |
| status | string | – | Only conversations with this status. |
No output schema declared.
No examples provided.
list_knowledge List knowledge ~50
List all knowledge documents for this workspace with their processing status (PENDING | PROCESSING | READY | FAILED) and chunk counts. Use this to check whether items added via add_knowledge have finished training.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
manage_faq Manage FAQ ~170
List, create, update, or delete this workspace's FAQ items (shown in the chat widget and usable by the AI agent). Set `action` to 'list' | 'create' | 'update' | 'delete'. 'create' needs `question` + `answer`; 'update' and 'delete' need `id`.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | Which FAQ operation to run. |
| answer | string | – | Answer text. Required for 'create'; optional for 'update'. |
| enabled | boolean | – | Whether the FAQ item is visible/active. Optional for 'create' and 'update'. |
| id | string | – | FAQ item id. Required for 'update' and 'delete'. |
| question | string | – | Question text. Required for 'create'; optional for 'update'. |
No output schema declared.
No examples provided.
ping Ping ~30
Health check for the SingChat MCP server. Returns 'pong' and whether this request is authenticated to a workspace.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
reply_to_conversation Reply to conversation ~85
Send an agent reply through a supported SingChat real-time inbox. This takes the conversation over from the AI and broadcasts the message to the visitor and agent inbox. Email, Telegram, and WhatsApp conversations are rejected before any change.
| Name | Type | Req | Description |
|---|---|---|---|
| content | string | yes | The reply text to send to the visitor. |
| conversationId | string | yes | The conversation id to reply in. |
No output schema declared.
No examples provided.
resolve_conversation Resolve conversation ~46
Mark a conversation as RESOLVED (closes it). The visitor's widget will no longer show it as active.
| Name | Type | Req | Description |
|---|---|---|---|
| conversationId | string | yes | The conversation id to resolve. |
No output schema declared.
No examples provided.
search Search ~107
Search SingChat for relevant documents. When called with a workspace API key, this searches that workspace knowledge base; without a key it searches SingChat's own help content (what SingChat is, adding the chat widget, MCP setup, free tier, AI training, channels, white label, pricing). Returns a list of results with id, title, and url. Use the fetch tool with a result id to read the full text.
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | yes | The search query or user question. |
| Name | Type | Req | Description |
|---|---|---|---|
| results | array | yes | – |
No examples provided.
search_knowledge Search knowledge ~77
Semantic search over the workspace knowledge base. Returns the most relevant chunks (with source document title and similarity score) for a query. Only searches documents that have finished training (status READY).
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | yes | The search query / user question. |
| topK | integer | – | Max number of chunks to return (default 5). |
No output schema declared.
No examples provided.
set_keywords Add keyword auto-reply ~114
Add a keyword auto-reply rule: when an inbound message matches any of the keywords, the bot replies with the given text. Good for canned FAQ-style triggers (e.g. keyword 'invoice' -> 'Download it from the billing page').
| Name | Type | Req | Description |
|---|---|---|---|
| keywords | array | yes | Trigger words/phrases (case-insensitive). |
| matchType | string | – | CONTAINS (default) = keyword appears anywhere in the message; EXACT = whole message equals the keyword. |
| reply | string | yes | The reply text to send. |
No output schema declared.
No examples provided.
singchat_setup Set up SingChat ~128
Get the user up and running with SingChat live-chat. Call this FIRST. If no authenticated workspace is configured, this creates a brand-new free workspace and returns a short-lived, single-use browser claim link plus the website embed snippet. The user chooses their own sign-in details in the browser; no reusable credentials are returned to the model. If a workspace is already authenticated, it returns THIS workspace's embed snippet and dashboard link (it never creates a duplicate workspace).
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | – | Optional workspace/brand name for a newly created workspace. Ignored if a key is already set. |
No output schema declared.
No examples provided.
What is the SingChat MCP server?
SingChat is an MCP server listed in the public MCP registry as org.singchat/singchat. Free live chat and AI support agent. Auto-create a workspace and embed from your AI editor. This page covers its hosted endpoint (https://mcp.singchat.org).
Is the SingChat MCP server safe to use?
SingChat scores 79 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the SingChat MCP server expose?
SingChat exposes 17 tools: ping, singchat_setup, get_embed_snippet, claim_account, list_conversations, and 12 more. Their descriptions and schemas cost roughly 1,587 tokens of context every time the server is loaded.
Does the SingChat MCP server require authentication?
No. We connected to SingChat without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the SingChat MCP server still maintained?
SingChat is still listed as active in the MCP registry. We last reached this channel on 24 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.