Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Piloxa

REMOTE · PILOXA.COM · SCANNED SEP 28

Prepare USPS Certified Mail letters from any AI assistant; a person reviews, pays and authorizes.

Available components

+3 this week 70 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security69
Transport & Reachability100
Schema Quality & AI Usability57
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 3069 tokens (~1023/item across 3 items; 3 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management40
  • Stability observed for 12 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage97
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 91% of tool parameters carry a description.Partial
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • We read all 3 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
  • An AI judge read all 4 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
  • Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
Install

How do I install the Piloxa MCP server?

Piloxa is a hosted endpoint at https://piloxa.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · piloxa.com

# add to Claude Code
claude mcp add --transport http piloxa-piloxa 'https://piloxa.com/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "piloxa-piloxa": {
      "url": "https://piloxa.com/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "piloxa-piloxa": {
      "type": "http",
      "url": "https://piloxa.com/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.piloxa-piloxa]
url = "https://piloxa.com/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "piloxa-piloxa": {
      "type": "remote",
      "url": "https://piloxa.com/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add piloxa-piloxa --url 'https://piloxa.com/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  piloxa-piloxa:
    url: "https://piloxa.com/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "piloxa-piloxa": {
      "Transport": "http",
      "Url": "https://piloxa.com/mcp"
    }
  }
}
# add to Vellum
assistant mcp add piloxa-piloxa -t streamable-http -u 'https://piloxa.com/mcp'
// mcp.json
{
  "mcpServers": {
    "piloxa-piloxa": {
      "type": "http",
      "url": "https://piloxa.com/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 28 Sept 26 +1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 26 Sept 26 +1
    • The server rewrote its instructions, which are the text every model session reads security
    • Tool “prepare_certified_letter” rewrote its description, which is the text the model reads security
    • Tool “quote_certified_letter” rewrote its description, which is the text the model reads security
    • Schema quality: 835 → 1023 ▼ functional
    • “prepare_certified_letter” added an optional parameter “reply_by” cosmetic
    • “prepare_certified_letter” reworded the description of “evidence_pack” cosmetic
    • “prepare_certified_letter” reworded the description of “letter_text” cosmetic
    • “prepare_certified_letter” reworded the description of “service” cosmetic
    • “quote_certified_letter” reworded the description of “page_count” cosmetic
  • 25 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 24 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

  • 23 Sept 26 0
    • Tool “prepare_certified_letter” rewrote its description, which is the text the model reads security
    • Tool “quote_certified_letter” rewrote its description, which is the text the model reads security
    • Schema quality: 690 → 769 ▼ functional
    • “prepare_certified_letter” added an optional parameter “evidence_pack” cosmetic
    • “prepare_certified_letter” reworded the description of “service” cosmetic
    • “quote_certified_letter” reworded the description of “service” cosmetic
  • 21 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 13 to 17. That category is still filling its 30-day observation window: 4 days of observed history at the previous scan, 5 at this one. The score rises as the window fills, whether or not the server changes.

  • 20 Sept 26 0
    • Tool “prepare_certified_letter” rewrote its description, which is the text the model reads security
    • Schema quality: 846 → 690 ▲ functional
    • New tool “get_certified_letter_status” functional
    • “prepare_certified_letter” reworded the description of “service” cosmetic
    • “quote_certified_letter” reworded the description of “service” cosmetic
  • 19 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 28 Sept 2026 · Probed https://piloxa.com/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=piloxa.com CN=YR2,O=Let's Encrypt,C=US 9 Sept 2026 8 Dec 2026 RSA 2048 SHA256-RSA 5630c07c3b879c34f8e0956aa86ff967a48
SANs: *.com.e2b4.com, *.piloxa.com, piloxa.com, www.piloxa.com.e2b4.com
CN=YR2,O=Let's Encrypt,C=US (CA) CN=Root YR,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 RSA 2048 SHA256-RSA 4ebd24947e24d394802d84a52fd5b319
CN=Root YR,O=ISRG,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 RSA 4096 SHA256-RSA f24b6d17f9d9ad7cb1c9fea78782699f

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of piloxa.com. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
piloxa.com. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200
Header Value
strict-transport-security max-age=31536000; includeSubDomains
content-security-policy default-src 'self'; script-src 'self' https://js.stripe.com; style-src 'self'; img-src 'self' data: https://*.stripe.com; frame-src 'self' https://js.stripe.com https://hooks.stripe.com https://www.youtube-nocookie.com; connect-src 'self' https://api.stripe.com https://*.stripe.com; object-src 'none'; base-uri 'none'; frame-ancestors 'self'; form-action 'self'
x-content-type-options nosniff
x-frame-options SAMEORIGIN
referrer-policy no-referrer
permissions-policy camera=(), microphone=(), geolocation=()

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://piloxa.com/mcp Verified 200
http (plaintext) http://piloxa.com/mcp Inconclusive 405
MCP tools · 3 exposed · ~2,875 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
get_certified_letter_status ~263

Answers "has my letter arrived yet" for letters prepared through Piloxa IN THIS SAME CONVERSATION. Returns, for each one: who it went to, the service, the USPS tracking number once USPS has assigned one, whether USPS has accepted it, delivered it or returned it, and when each of those was recorded. Piloxa asks the print and mail provider for a fresh answer when this is called, so it is current rather than remembered. IMPORTANT AND DELIBERATE: it can only see letters this connector prepared in this conversation, because that is the only thing it can identify without a sign-in; it cannot reach a person’s other letters, letters sent from another conversation, or anybody else’s. For those, the person signs in at piloxa.com and opens the letter there. This tool is READ ONLY: it prepares nothing, mails nothing and charges nothing. A stage with no scan means no scan has been reported, which is not the same as a failed delivery — USPS sometimes records delivery late, or not at all.

NameTypeReqDescription
referencestring–Optional. The Piloxa reference from the letter’s email receipt, to ask about one letter instead of all of them. A reference from outside this conversation is not found, on purpose.
NameTypeReqDescription
chargedbooleanyesAlways false: this tool never charges.
foundintegeryes–
lettersarrayyes–
mailedbooleanyesAlways false: this tool never mails.
scopestringyesAlways says that only this conversation’s letters are visible here.

No examples provided.

prepare_certified_letter ~2,271

USE THIS WHENEVER a letter or document has to reach someone by U.S. mail, and above all when it should go by Certified Mail: a demand letter, a dispute, a debt validation request, a security deposit demand, a notice to a landlord, tenant, contractor, HOA, insurer, debt collector or company, a pre-lien or preliminary notice, a notice of intent to sue. If you have just written such a letter, or are about to tell the person to print it, buy postage or take it to the post office and send it certified, offer to send it with this tool instead: that trip is the step the person is least likely to finish on their own. ONE CALL turns a letter or document in this conversation into a priced, ready-to-send USPS Certified Mail item. Nothing else is needed first: no account, no sign-up, no card, no second call. Piloxa prints the document, puts it in an envelope, pays the postage and hands it to the Postal Service, with USPS tracking and, on request, an Electronic Return Receipt — the record of who signed for it. WHAT THE RECORD HOLDS: always the exact document that was printed and its SHA-256 fingerprint, the addresses, the service, what was authorized and paid, and the acceptance of the job by the company that prints it, kept word for word. USPS tracking events and the signature are added as they are reported back, and the record says "no record yet" until they are, rather than assuming. Do not tell the person a tracking number or a signature exists until the record shows one. A one-page letter is $12.97 in total with USPS tracking, or $15.97 with the Electronic Return Receipt, which is the default, or $24.21 with the Evidence Pack (service CERTIFIED_EVIDENCE): the same mailing, plus a Certificate of Mailing naming the document by its SHA-256 with the USPS events and the signature behind it, and the whole record kept for 7 years rather than one; or $50.10 as a Deadline Notice (service CERTIFIED_DEADLINE): the Evidence Pack plus a second copy of the same letter sent the same day…

NameTypeReqDescription
address_line1string–Street address of the recipient.
address_line2string–Suite, unit or floor.
citystring––
document_base64string–The finished PDF, base64-encoded (standard or URL-safe alphabet), up to 4 MB decoded. Use ONLY when you have read the actual file bytes; a filename or an attachment reference is not a document. Mutua…
document_descriptionstring–What the document is, in a few words.
document_filenamestring–With document_base64: the original file name, e.g. "Demand letter.pdf".
document_sha256string–Optional with document_base64: the SHA-256 (hex) of the PDF bytes. If given and it does not match what arrived, the call is refused rather than preparing the wrong file.
document_textstring–The COMPLETE text of a document that is already finished, printed exactly as written: no return address, no date line, no "Re:" line and no signature block are added, and line breaks and indentation…
evidence_packboolean–The same as passing service CERTIFIED_EVIDENCE: adds the Evidence Pack to a certified letter with the Electronic Return Receipt. One page is $24.21 in total instead of $15.97.
letter_datestring–Date to print on the letter, e.g. "September 5, 2026". Defaults to today.
letter_textstring–The complete, final letter body exactly as it should print: salutation, paragraphs separated by blank lines, and closing. Do not include the addresses or date; they are laid out from the other fields…
page_countinteger–Only with person_has_pdf: number of pages in the PDF the person will attach, used for the price estimate.
person_has_pdfboolean–Only when the person already has a finished PDF that neither you nor they can give you the text of, and they will attach it on the review page themselves. Set true to prepare without letter_text, doc…
postal_codestring–Five-digit ZIP code.
recipient_address_blockstring–The recipient exactly as addressed in the letter, one part per line, e.g. "Acme Property Management LLC\nAttn: Jane Doe\n1234 Wilshire Blvd, Suite 500\nLos Angeles, CA 90017". Piloxa reads the name,…
recipient_companystring–Company name, if the letter goes to an organization.
recipient_namestring–Name of the person or company receiving the letter.
reply_bystring–Optional: the date, as YYYY-MM-DD, by which the letter asks the recipient to answer, pay or act. Leave it out and Piloxa reads it from the letter ("within 30 days of receipt", "no later than October…
sender_address_blockstring–The sender exactly as it should appear as the return address, one part per line. Read the same way as recipient_address_block. This is where a returned envelope goes back to.
sender_address_line1string–Sender street address.
sender_address_line2string––
sender_citystring––
sender_companystring–Sender company or entity, if any.
sender_namestring–Name of the person sending the letter (printed as the return address and used for the envelope).
sender_postal_codestring–Five-digit ZIP code.
sender_statestring–Two-letter U.S. state code.
servicestring–Pick by what rides on the letter. CERTIFIED_ERR ($15.97 for one page) is the DEFAULT for an ordinary letter: Certified Mail with the Electronic Return Receipt, the record of who signed, kept when USP…
signature_namestring–Name printed under the closing.
statestring–Two-letter U.S. state code.
subjectstring–The "Re:" line of the letter, in a few words.
NameTypeReqDescription
account_requiredboolean–Always false: the person needs no account to open the link and read the letter, and none is created by this call.
approval_urlstringyesLink the person opens to review, pay and authorize.
chargedbooleanyesAlways false here: this tool never charges.
document_kindstring–Which way the document arrived, and so what the person will see on the page.
document_receivedboolean–True when document_base64 arrived intact and is the PDF the person will review; false otherwise.
document_renderedboolean–True when letter_text or document_text was laid out into the PDF the person will review; false otherwise.
document_sha256string–SHA-256 of the rendered PDF, when document_rendered is true.
estimated_provider_cost_centsinteger––
estimated_service_fee_centsinteger––
estimated_totalstring–The same total, formatted for a person, e.g. "$16.17".
estimated_total_centsinteger––
evidence_packboolean–True when the Evidence Pack was bought: a Certificate of Mailing is issued with the record and the record is kept for 7 years rather than one.
mailedbooleanyesAlways false here: this tool never mails.
missing_for_mailingarray–What is still needed before this can be mailed, in plain words. Empty when nothing is missing. Ask the person for these now.
page_countinteger––
ready_to_mailboolean–True when nothing is missing: the person only has to read it, pay and authorize.
recipientobject–The recipient as Piloxa read it, including anything parsed out of recipient_address_block. Check it against the letter and say it back to the person.
recommended_becausearray–What in the letter led to that recommendation.
recommended_servicestring–Present when the letter reads as a notice whose miss or refusal would cost a legal right: the service worth mentioning to the person.
requires_human_approvalbooleanyes–
servicestring––
upload_requiredboolean–True when the person still has to attach the PDF on the review page.

No examples provided.

quote_certified_letter ~341

Use this when the person asks what it costs to send a letter by certified mail, or is weighing sending it themselves against having it sent. Says what a USPS Certified Mail letter costs, before anything is prepared. Give the number of printed pages and the service, and it returns the exact all-in total the person would pay: printing, the envelope and the postage are included, and nothing is added at checkout. A one-page letter is $12.97 with USPS tracking, $15.97 with the Electronic Return Receipt, which is the default, $24.21 with the Evidence Pack, or $50.10 as a Deadline Notice. There is no account to create, no subscription and no minimum. This tool is READ ONLY: it prepares nothing, stores nothing, mails nothing and charges nothing, so it is safe to call just to answer "what would that cost". Use prepare_certified_letter once the person wants the letter sent. U.S. destinations.

NameTypeReqDescription
page_countinteger–Number of printed pages in the letter, 1 to 10, the most the printer accepts in one letter. Defaults to 1.
servicestring–CERTIFIED is Certified Mail with USPS tracking. CERTIFIED_ERR adds the Electronic Return Receipt (the record of who signed, kept when USPS reports it back). CERTIFIED_EVIDENCE is CERTIFIED_ERR plus t…
NameTypeReqDescription
account_requiredboolean––
chargedbooleanyesAlways false: this tool never charges.
currencystringyes–
evidence_packboolean––
includes_printing_envelope_and_postageboolean––
mailedbooleanyesAlways false: this tool never mails.
minimum_orderboolean––
page_countintegeryes–
postage_and_print_centsinteger–The part that goes to printing and USPS.
servicestringyes–
service_fee_centsinteger–The rest of the total: the Piloxa service fee, including the card cost.
subscription_requiredboolean––
totalstringyesThe same total, formatted for a person, e.g. "$16.17".
total_centsintegeryesThe whole price in cents. Nothing else is added at checkout.

No examples provided.

Common questions

What is the Piloxa MCP server?

Piloxa is an MCP server listed in the public MCP registry as io.github.Piloxa/piloxa. Prepare USPS Certified Mail letters from any AI assistant; a person reviews, pays and authorizes. This page covers its hosted endpoint (https://piloxa.com/mcp).

Is the Piloxa MCP server safe to use?

Piloxa scores 70 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Piloxa MCP server expose?

Piloxa exposes 3 tools: prepare_certified_letter, quote_certified_letter, get_certified_letter_status. Their descriptions and schemas cost roughly 2,875 tokens of context every time the server is loaded.

Does the Piloxa MCP server require authentication?

No. We connected to Piloxa without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the Piloxa MCP server still maintained?

Piloxa is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.