Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, email [email protected] and we’ll put it right.

Schematic

NPM · @SCHEMATICHQ/SCHEMATIC-MCP · SCANNED AUG 4

Manage companies, plans, features, and billing through SchematicHQ

+33 this week 78 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →

Supply Chain Security83
  • No malware found by supply-chain analysis.Pass
  • CVE check failed: a known medium-severity CVE affects hono 4.12.33, reached via @modelcontextprotocol/sdk > hono. A fixed version is available. View diagnostics → Fail
  • No install/post-install scripts declared.Pass
  • Only part of the dependency tree could be resolved (119 of 120), so this covers what we could see, not the whole tree. View diagnostics → Partial
Provenance & Transparency97
  • Source repository is publicly reachable at the declared URL. View diagnostics → Pass
  • Cryptographically verified build provenance (signed, bound to SchematicHQ/schematic-mcp). View diagnostics → Pass
  • Clear OSI-approved license (MIT).Pass
  • Actively maintained (last published 18 days ago).Pass
  • Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability73
  • AI-judged instruction clarity (good).Pass
  • Tool/resource definitions use about 2565 tokens (~98/item across 26 items; 26 tools + 0 resources), lean.Pass
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management30
  • Stability observed for 9 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage92
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 77% of tool parameters carry a description.Partial
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

npm · @schematichq/schematic-mcp

# add to Claude Code
claude mcp add schematichq-schematic-mcp -- npx -y @schematichq/schematic-mcp
# add to Codex CLI
codex mcp add schematichq-schematic-mcp -- npx -y @schematichq/schematic-mcp
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "schematichq-schematic-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@schematichq/schematic-mcp"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add schematichq-schematic-mcp --command npx --arg -y --arg @schematichq/schematic-mcp
# ~/.hermes/config.yaml
mcp_servers:
  schematichq-schematic-mcp:
    command: "npx"
    args: ["-y", "@schematichq/schematic-mcp"]
// mcp.json
{
  "mcpServers": {
    "schematichq-schematic-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@schematichq/schematic-mcp"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 4 Aug 26 −1
    • CVE-2026-69207 affects this package: medium security
    • Known CVEs: partial → fail security
  • 3 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

  • 2 Aug 26 +40
    • Provenance: pass → unverified security
    • Install scripts: pass → unverified security
    • Known CVEs: unverified → partial security
    • Malware scan: unverified → pass security
    • The attested source repository moved: SchematicHQ/schematic-mcp security
    • License: pass → unverified functional
    • Maintenance: pass → unverified functional
    • Dependency health: unverified → partial functional
    • MCP protocol: unverified → pass functional
    • Schema quality: unverified → good functional
    • Stability: unverified → 0.23 functional
    • Licence: MIT functional
  • 1 Aug 26 −11
    • Known CVEs: partial → unverified security
    • Dependency health: partial → unverified functional
  • 31 Jul 26 +43
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 30 Jul 26 −74
    • Provenance: pass → unverified security
    • Known CVEs: partial → unverified security
    • Malware scan: pass → unverified security
    • Install scripts: pass → unverified security
    • The attested source repository moved: SchematicHQ/schematic-mcp security
    • Security disclosure: fail → unverified functional
    • License: pass → unverified functional
    • Tool coverage: 100 → unverified functional
    • Dependency health: partial → unverified functional
    • Maintenance: pass → unverified functional
    • First check of Schema quality: unverified functional
    • Licence: MIT functional
  • 29 Jul 26 +35
    • Install scripts: unverified → pass security
    • Known CVEs: unverified → partial security
    • Provenance: unverified → pass security
    • The attested source repository moved: SchematicHQ/schematic-mcp security
    • Maintenance: unverified → pass functional
    • Dependency health: unverified → partial functional
    • License: unverified → pass functional
    • Licence: MIT functional
  • 28 Jul 26 0
    • Security disclosure: unverified → fail functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 4 Aug 2026 · Analysed npm/@schematichq/[email protected]

Provenance verified

Ecosystem: npm · Outcome: verified

Reason: verified

Source repo:
SchematicHQ/schematic-mcp
Certificate issuer:
https://token.actions.githubusercontent.com
Certificate SAN:
https://github.com/SchematicHQ/schematic-mcp/.github/workflows/publish.yml@refs/tags/v0.4.0
Rekor log index:
2187835945
Predicate type:
https://slsa.dev/provenance/v1
Subject digest:
sha512:5932b675ef7f7e0493ddc5e31c1a2f3891e2786f8ed58bdb46b0898cafc1e5247ae22d46ae568f8e0256dc6fbd0d89d8ab333dd456d3e070fcc7872d7
Discovery method:
attestation_endpoint
Vulnerabilities 1 finding
ID CVE Severity Vector Fix available
GHSA-8j4g-w8fx-2239 CVE-2026-69207 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L yes
Dependencies 119 packages

119 packages in the resolved dependency tree · 118 deprecated · 43 stale.

The dependency tree was only partially resolved, so these counts may be incomplete.

MCP tools — 26 exposed · ~2,565 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
add_entitlements_to_addon ~131

Add entitlements to an add-on. The feature type will be automatically determined by querying the feature. For boolean features, defaults to 'on' if no value is provided. For event-based or trait-based features, a value (number or 'unlimited') is required.

NameTypeReqDescription
addonIdstringAdd-on ID (e.g., plan_xxx)
addonNamestringAdd-on name
entitlementsarrayyesArray of entitlement configurations. For boolean features, value is optional (defaults to 'on'). For event/trait features, value is required.

No output schema declared.

No examples provided.

add_entitlements_to_plan ~116

Add entitlements to a plan. The feature type will be automatically determined by querying the feature. For boolean features, defaults to 'on' if no value is provided. For event-based or trait-based features, a value (number or 'unlimited') is required.

NameTypeReqDescription
entitlementsarrayyesArray of entitlement configurations. For boolean features, value is optional (defaults to 'on'). For event/trait features, value is required.
planIdstring
planNamestring

No output schema declared.

No examples provided.

check_companies_usage ~112

Check feature usage for a specific list of companies and identify which are at or above a usage threshold for any metered feature. Useful for proactive health checks on known accounts. Results are grouped by feature and sorted by percent used.

NameTypeReqDescription
companyIdsarrayyesList of Schematic company IDs to check (e.g., ['comp_xxx', 'comp_yyy'])
thresholdnumberUsage percentage threshold (0-100). Companies at or above this percentage are included. Defaults to 70.

No output schema declared.

No examples provided.

count_companies_on_addon ~51

Count how many companies have a specific add-on

NameTypeReqDescription
addonIdstringAdd-on ID (e.g., plan_xxx)
addonNamestringAdd-on name

No output schema declared.

No examples provided.

count_companies_on_plan ~48

Count how many companies are on a specific plan

NameTypeReqDescription
planIdstringPlan ID (e.g., plan_xxx)
planNamestringPlan name

No output schema declared.

No examples provided.

create_addon ~35

Create a new add-on

NameTypeReqDescription
descriptionstringAdd-on description
namestringyesAdd-on name

No output schema declared.

No examples provided.

create_company ~162

Create (upsert) a company, identified by a key. Companies are looked up by one or more keys (e.g. an 'id' key) — see Key Management. Optionally set a display name and traits. If a company with the given key already exists, it is updated rather than duplicated.

NameTypeReqDescription
keyNamestringyesThe key name used to identify the company (e.g. 'id'). Key names are configured in Schematic.
keyValuestringyesThe value for keyName (e.g. 'demo-co').
namestringOptional display name for the company.
traitsobjectOptional map of trait names to values (e.g. { "plan_tier": "pro" }).

No output schema declared.

No examples provided.

create_feature ~279

Create a new feature flag. Boolean features are simple on/off switches - the most commonly used type, ideal for enabling/disabling functionality and basic plan differentiation. Event-based features are metered against user events and track usage that typically increases over time (e.g., API calls, reports generated, database queries). Trait-based features are based on information reported to Schematic and can track usage that fluctuates up and down (e.g., user seats, projects, devices). Trait-based features must be created in the web app. Optionally entitle the feature to a plan in the same call.

NameTypeReqDescription
descriptionstringOptional: Feature description
eventSubtypestringREQUIRED for event-based features: The event subtype to associate with this feature (e.g., 'api_call', 'report_generated').
featureTypestringFeature type: 'boolean' (simple on/off switch, most common), 'event' (metered against events that increase over time), or 'trait' (based on information that can fluctuate - must be created in web app…
namestringyesFeature name/key
planIdstringOptional: Plan ID to entitle this feature to
planNamestringOptional: Plan name to entitle this feature to

No output schema declared.

No examples provided.

create_plan ~31

Create a new plan

NameTypeReqDescription
descriptionstringPlan description
namestringyesPlan name

No output schema declared.

No examples provided.

create_plan_with_billing ~172

Create a new plan with a Stripe-linked billing product. This creates both the plan and its associated Stripe product and prices in one step. Prices are specified in dollars (e.g., 29.99 for $29.99/month). If no prices are provided, the plan is created with $0 pricing. Use this instead of create_plan when you want the plan to be connected to Stripe billing.

NameTypeReqDescription
descriptionstringPlan description
monthlyPricenumberMonthly price in dollars (e.g., 29.99 for $29.99/month). Defaults to 0.
namestringyesPlan name
yearlyPricenumberYearly price in dollars (e.g., 299.99 for $299.99/year). Defaults to 0.

No output schema declared.

No examples provided.

find_companies_near_limit ~131

Find companies at or above a usage threshold for a specific metered feature. Queries all companies for the given feature sorted by usage percentage (highest first), stopping as soon as usage drops below the threshold. If no featureId is provided, returns a list of metered features to choose from.

NameTypeReqDescription
featureIdstringID of the metered feature to scan. If omitted, the tool returns a list of available metered features to choose from.
thresholdnumberUsage percentage threshold (0-100). Companies at or above this percentage are included. Defaults to 70.

No output schema declared.

No examples provided.

get_addon_entitlements ~63

Get all features/entitlements included in an add-on. Shows what features an add-on grants and their values.

NameTypeReqDescription
addonIdstringAdd-on ID (e.g., plan_xxx)
addonNamestringAdd-on name

No output schema declared.

No examples provided.

get_company ~194

Get company information by ID, name, Stripe customer ID, or custom key. Returns company details including plan, trial status, and links. For custom key lookups, the user must provide both keyName and keyValue. Key names are configured in Schematic - see https://docs.schematichq.com/developer_resources/key_management for details.

NameTypeReqDescription
companyIdstringSchematic company ID (e.g., comp_xxx)
companyNamestringCompany name to search for
keyNamestringCustom key name to look up the company by (e.g., 'app_id'). Must be used with keyValue. See https://docs.schematichq.com/developer_resources/key_management
keyValuestringCustom key value to look up the company by. Must be used with keyName.
stripeCustomerIdstringStripe customer ID

No output schema declared.

No examples provided.

get_company_plan ~80

Get the plan that a company is currently on

NameTypeReqDescription
companyIdstring
companyNamestring
keyNamestringCustom key name for company lookup (requires keyValue)
keyValuestringCustom key value for company lookup (requires keyName)
stripeCustomerIdstring

No output schema declared.

No examples provided.

get_company_trial_info ~84

Check if a company is on a trial and when it ends

NameTypeReqDescription
companyIdstring
companyNamestring
keyNamestringCustom key name for company lookup (requires keyValue)
keyValuestringCustom key value for company lookup (requires keyName)
stripeCustomerIdstring

No output schema declared.

No examples provided.

get_feature_usage ~126

Get feature usage data for a company. Shows access status, usage vs allocation, and entitlement source for each feature. Optionally filter to a specific feature by providing featureId. If you only know the feature name, use list_features first to find the feature ID, then pass it here as featureId.

NameTypeReqDescription
companyIdstringSchematic company ID
companyNamestringCompany name to search for
featureIdstringOptional: filter to a specific feature by ID. Use list_features to find the ID if you only have a name.

No output schema declared.

No examples provided.

get_flag ~87

Get full targeting detail for a single flag by its key: default value, every rule (type, value, priority, condition count), last-checked time, and the computed always-on / always-off / targeted determination. Use this to inspect why a flag resolves the way it does.

NameTypeReqDescription
keystringyesThe flag key (dot-delimited, e.g. "billing.credits")

No output schema declared.

No examples provided.

get_plan_entitlements ~71

Get all features/entitlements included in a plan. Shows what features a plan grants and their values (on/off for boolean, numeric limits for metered, unlimited).

NameTypeReqDescription
planIdstringPlan ID (e.g., plan_xxx)
planNamestringPlan name

No output schema declared.

No examples provided.

link_stripe_to_schematic ~60

Find the Schematic company for a Stripe customer ID, or vice versa. Returns both IDs and links to both platforms.

NameTypeReqDescription
companyIdstringSchematic company ID
stripeCustomerIdstringStripe customer ID

No output schema declared.

No examples provided.

list_addons ~19

List all add-ons in your Schematic account

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

list_company_overrides ~104

List company overrides. Filter by company (to see all overrides for a company) or by feature (to see which companies have an override for a feature)

NameTypeReqDescription
companyIdstringCompany ID to filter by
companyNamestringCompany name to filter by
featureIdstringFeature ID to filter by
featureNamestringFeature name to filter by (finds which companies have an override for this feature)

No output schema declared.

No examples provided.

list_features ~17

List all features in your Schematic account

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

list_flags ~111

List all feature flags in your Schematic account with their targeting summary. For each flag, reports its key, default value, linked feature (if any), and whether it currently resolves to always-on, always-off, or targeted (gated by rules). Use this to audit which flags are always-on (and so no longer need to be checked in code) or unused (and so can be deleted from Schematic).

NameTypeReqDescription
querystringOptional: filter flags by a search string matched against key/name

No output schema declared.

No examples provided.

list_plans ~24

List all plans in your Schematic account. Does not include add-ons.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

remove_company_override ~70

Remove a company override for a feature/entitlement. This will delete the override and the company will fall back to their plan's entitlements.

NameTypeReqDescription
companyIdstring
companyNamestring
featureIdstring
featureNamestring

No output schema declared.

No examples provided.

set_company_override ~187

Set or update a company override for a feature/entitlement. REQUIRES a value parameter - always ask the user for the desired value before calling this tool. For boolean features: use 'on'/'off' or 'true'/'false'. For event-based or trait-based features: use a numeric value (e.g., '10', '100') or 'unlimited'.

NameTypeReqDescription
companyIdstring
companyNamestring
featureIdstring
featureNamestring
valuestringyesREQUIRED: Override value. For boolean features: 'on'/'off' or 'true'/'false'. For event-based or trait-based features: a numeric value as a string (e.g., '10', '100') or 'unlimited'. Always ask the u…

No output schema declared.

No examples provided.