Schematic
NPM · @SCHEMATICHQ/SCHEMATIC-MCP · SCANNED AUG 4
Manage companies, plans, features, and billing through SchematicHQ
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →
Supply Chain Security83
- No malware found by supply-chain analysis.Pass
- CVE check failed: a known medium-severity CVE affects hono 4.12.33, reached via @modelcontextprotocol/sdk > hono. A fixed version is available. View diagnostics → Fail
- No install/post-install scripts declared.Pass
- Only part of the dependency tree could be resolved (119 of 120), so this covers what we could see, not the whole tree. View diagnostics → Partial
Provenance & Transparency97
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Cryptographically verified build provenance (signed, bound to SchematicHQ/schematic-mcp). View diagnostics → Pass
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 18 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability73
- AI-judged instruction clarity (good).Pass
- Tool/resource definitions use about 2565 tokens (~98/item across 26 items; 26 tools + 0 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management30
- Stability observed for 9 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage92
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 77% of tool parameters carry a description.Partial
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
npm · @schematichq/schematic-mcp
claude mcp add schematichq-schematic-mcp -- npx -y @schematichq/schematic-mcp
codex mcp add schematichq-schematic-mcp -- npx -y @schematichq/schematic-mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"schematichq-schematic-mcp": {
"type": "local",
"command": [
"npx",
"-y",
"@schematichq/schematic-mcp"
],
"enabled": true
}
}
} openclaw mcp add schematichq-schematic-mcp --command npx --arg -y --arg @schematichq/schematic-mcp
mcp_servers:
schematichq-schematic-mcp:
command: "npx"
args: ["-y", "@schematichq/schematic-mcp"] {
"mcpServers": {
"schematichq-schematic-mcp": {
"command": "npx",
"args": [
"-y",
"@schematichq/schematic-mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 4 Aug 26 −1
- CVE-2026-69207 affects this package: medium ▼ security
- Known CVEs: partial → fail ▼ security
- 3 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.
- 2 Aug 26 +40
- Provenance: pass → unverified ▼ security
- Install scripts: pass → unverified ▼ security
- Known CVEs: unverified → partial ▲ security
- Malware scan: unverified → pass ▲ security
- The attested source repository moved: SchematicHQ/schematic-mcp security
- License: pass → unverified ▼ functional
- Maintenance: pass → unverified ▼ functional
- Dependency health: unverified → partial ▲ functional
- MCP protocol: unverified → pass ▲ functional
- Schema quality: unverified → good ▲ functional
- Stability: unverified → 0.23 ▲ functional
- Licence: MIT functional
- 1 Aug 26 −11
- Known CVEs: partial → unverified ▼ security
- Dependency health: partial → unverified ▼ functional
- 31 Jul 26 +43
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 −74
- Provenance: pass → unverified ▼ security
- Known CVEs: partial → unverified ▼ security
- Malware scan: pass → unverified ▼ security
- Install scripts: pass → unverified ▼ security
- The attested source repository moved: SchematicHQ/schematic-mcp security
- Security disclosure: fail → unverified ▼ functional
- License: pass → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- Dependency health: partial → unverified ▼ functional
- Maintenance: pass → unverified ▼ functional
- First check of Schema quality: unverified functional
- Licence: MIT functional
- 29 Jul 26 +35
- Install scripts: unverified → pass ▲ security
- Known CVEs: unverified → partial ▲ security
- Provenance: unverified → pass ▲ security
- The attested source repository moved: SchematicHQ/schematic-mcp security
- Maintenance: unverified → pass ▲ functional
- Dependency health: unverified → partial ▲ functional
- License: unverified → pass ▲ functional
- Licence: MIT functional
- 28 Jul 26 0
- Security disclosure: unverified → fail ▼ functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 4 Aug 2026 · Analysed npm/@schematichq/[email protected]
Provenance verified
Ecosystem: npm · Outcome: verified
Reason: verified
- Source repo:
- SchematicHQ/schematic-mcp
- Certificate issuer:
- https://token.actions.githubusercontent.com
- Certificate SAN:
- https://github.com/SchematicHQ/schematic-mcp/.github/workflows/publish.yml@refs/tags/v0.4.0
- Rekor log index:
- 2187835945
- Predicate type:
- https://slsa.dev/provenance/v1
- Subject digest:
- sha512:5932b675ef7f7e0493ddc5e31c1a2f3891e2786f8ed58bdb46b0898cafc1e5247ae22d46ae568f8e0256dc6fbd0d89d8ab333dd456d3e070fcc7872d7
- Discovery method:
- attestation_endpoint
Vulnerabilities 1 finding
| ID | CVE | Severity | Vector | Fix available |
|---|---|---|---|---|
| GHSA-8j4g-w8fx-2239 | CVE-2026-69207 | medium | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L | yes |
Dependencies 119 packages
119 packages in the resolved dependency tree · 118 deprecated · 43 stale.
The dependency tree was only partially resolved, so these counts may be incomplete.
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
add_entitlements_to_addon ~131
Add entitlements to an add-on. The feature type will be automatically determined by querying the feature. For boolean features, defaults to 'on' if no value is provided. For event-based or trait-based features, a value (number or 'unlimited') is required.
| Name | Type | Req | Description |
|---|---|---|---|
| addonId | string | — | Add-on ID (e.g., plan_xxx) |
| addonName | string | — | Add-on name |
| entitlements | array | yes | Array of entitlement configurations. For boolean features, value is optional (defaults to 'on'). For event/trait features, value is required. |
No output schema declared.
No examples provided.
add_entitlements_to_plan ~116
Add entitlements to a plan. The feature type will be automatically determined by querying the feature. For boolean features, defaults to 'on' if no value is provided. For event-based or trait-based features, a value (number or 'unlimited') is required.
| Name | Type | Req | Description |
|---|---|---|---|
| entitlements | array | yes | Array of entitlement configurations. For boolean features, value is optional (defaults to 'on'). For event/trait features, value is required. |
| planId | string | — | — |
| planName | string | — | — |
No output schema declared.
No examples provided.
check_companies_usage ~112
Check feature usage for a specific list of companies and identify which are at or above a usage threshold for any metered feature. Useful for proactive health checks on known accounts. Results are grouped by feature and sorted by percent used.
| Name | Type | Req | Description |
|---|---|---|---|
| companyIds | array | yes | List of Schematic company IDs to check (e.g., ['comp_xxx', 'comp_yyy']) |
| threshold | number | — | Usage percentage threshold (0-100). Companies at or above this percentage are included. Defaults to 70. |
No output schema declared.
No examples provided.
count_companies_on_addon ~51
Count how many companies have a specific add-on
| Name | Type | Req | Description |
|---|---|---|---|
| addonId | string | — | Add-on ID (e.g., plan_xxx) |
| addonName | string | — | Add-on name |
No output schema declared.
No examples provided.
count_companies_on_plan ~48
Count how many companies are on a specific plan
| Name | Type | Req | Description |
|---|---|---|---|
| planId | string | — | Plan ID (e.g., plan_xxx) |
| planName | string | — | Plan name |
No output schema declared.
No examples provided.
create_addon ~35
Create a new add-on
| Name | Type | Req | Description |
|---|---|---|---|
| description | string | — | Add-on description |
| name | string | yes | Add-on name |
No output schema declared.
No examples provided.
create_company ~162
Create (upsert) a company, identified by a key. Companies are looked up by one or more keys (e.g. an 'id' key) — see Key Management. Optionally set a display name and traits. If a company with the given key already exists, it is updated rather than duplicated.
| Name | Type | Req | Description |
|---|---|---|---|
| keyName | string | yes | The key name used to identify the company (e.g. 'id'). Key names are configured in Schematic. |
| keyValue | string | yes | The value for keyName (e.g. 'demo-co'). |
| name | string | — | Optional display name for the company. |
| traits | object | — | Optional map of trait names to values (e.g. { "plan_tier": "pro" }). |
No output schema declared.
No examples provided.
create_feature ~279
Create a new feature flag. Boolean features are simple on/off switches - the most commonly used type, ideal for enabling/disabling functionality and basic plan differentiation. Event-based features are metered against user events and track usage that typically increases over time (e.g., API calls, reports generated, database queries). Trait-based features are based on information reported to Schematic and can track usage that fluctuates up and down (e.g., user seats, projects, devices). Trait-based features must be created in the web app. Optionally entitle the feature to a plan in the same call.
| Name | Type | Req | Description |
|---|---|---|---|
| description | string | — | Optional: Feature description |
| eventSubtype | string | — | REQUIRED for event-based features: The event subtype to associate with this feature (e.g., 'api_call', 'report_generated'). |
| featureType | string | — | Feature type: 'boolean' (simple on/off switch, most common), 'event' (metered against events that increase over time), or 'trait' (based on information that can fluctuate - must be created in web app… |
| name | string | yes | Feature name/key |
| planId | string | — | Optional: Plan ID to entitle this feature to |
| planName | string | — | Optional: Plan name to entitle this feature to |
No output schema declared.
No examples provided.
create_plan ~31
Create a new plan
| Name | Type | Req | Description |
|---|---|---|---|
| description | string | — | Plan description |
| name | string | yes | Plan name |
No output schema declared.
No examples provided.
create_plan_with_billing ~172
Create a new plan with a Stripe-linked billing product. This creates both the plan and its associated Stripe product and prices in one step. Prices are specified in dollars (e.g., 29.99 for $29.99/month). If no prices are provided, the plan is created with $0 pricing. Use this instead of create_plan when you want the plan to be connected to Stripe billing.
| Name | Type | Req | Description |
|---|---|---|---|
| description | string | — | Plan description |
| monthlyPrice | number | — | Monthly price in dollars (e.g., 29.99 for $29.99/month). Defaults to 0. |
| name | string | yes | Plan name |
| yearlyPrice | number | — | Yearly price in dollars (e.g., 299.99 for $299.99/year). Defaults to 0. |
No output schema declared.
No examples provided.
find_companies_near_limit ~131
Find companies at or above a usage threshold for a specific metered feature. Queries all companies for the given feature sorted by usage percentage (highest first), stopping as soon as usage drops below the threshold. If no featureId is provided, returns a list of metered features to choose from.
| Name | Type | Req | Description |
|---|---|---|---|
| featureId | string | — | ID of the metered feature to scan. If omitted, the tool returns a list of available metered features to choose from. |
| threshold | number | — | Usage percentage threshold (0-100). Companies at or above this percentage are included. Defaults to 70. |
No output schema declared.
No examples provided.
get_addon_entitlements ~63
Get all features/entitlements included in an add-on. Shows what features an add-on grants and their values.
| Name | Type | Req | Description |
|---|---|---|---|
| addonId | string | — | Add-on ID (e.g., plan_xxx) |
| addonName | string | — | Add-on name |
No output schema declared.
No examples provided.
get_company ~194
Get company information by ID, name, Stripe customer ID, or custom key. Returns company details including plan, trial status, and links. For custom key lookups, the user must provide both keyName and keyValue. Key names are configured in Schematic - see https://docs.schematichq.com/developer_resources/key_management for details.
| Name | Type | Req | Description |
|---|---|---|---|
| companyId | string | — | Schematic company ID (e.g., comp_xxx) |
| companyName | string | — | Company name to search for |
| keyName | string | — | Custom key name to look up the company by (e.g., 'app_id'). Must be used with keyValue. See https://docs.schematichq.com/developer_resources/key_management |
| keyValue | string | — | Custom key value to look up the company by. Must be used with keyName. |
| stripeCustomerId | string | — | Stripe customer ID |
No output schema declared.
No examples provided.
get_company_plan ~80
Get the plan that a company is currently on
| Name | Type | Req | Description |
|---|---|---|---|
| companyId | string | — | — |
| companyName | string | — | — |
| keyName | string | — | Custom key name for company lookup (requires keyValue) |
| keyValue | string | — | Custom key value for company lookup (requires keyName) |
| stripeCustomerId | string | — | — |
No output schema declared.
No examples provided.
get_company_trial_info ~84
Check if a company is on a trial and when it ends
| Name | Type | Req | Description |
|---|---|---|---|
| companyId | string | — | — |
| companyName | string | — | — |
| keyName | string | — | Custom key name for company lookup (requires keyValue) |
| keyValue | string | — | Custom key value for company lookup (requires keyName) |
| stripeCustomerId | string | — | — |
No output schema declared.
No examples provided.
get_feature_usage ~126
Get feature usage data for a company. Shows access status, usage vs allocation, and entitlement source for each feature. Optionally filter to a specific feature by providing featureId. If you only know the feature name, use list_features first to find the feature ID, then pass it here as featureId.
| Name | Type | Req | Description |
|---|---|---|---|
| companyId | string | — | Schematic company ID |
| companyName | string | — | Company name to search for |
| featureId | string | — | Optional: filter to a specific feature by ID. Use list_features to find the ID if you only have a name. |
No output schema declared.
No examples provided.
get_flag ~87
Get full targeting detail for a single flag by its key: default value, every rule (type, value, priority, condition count), last-checked time, and the computed always-on / always-off / targeted determination. Use this to inspect why a flag resolves the way it does.
| Name | Type | Req | Description |
|---|---|---|---|
| key | string | yes | The flag key (dot-delimited, e.g. "billing.credits") |
No output schema declared.
No examples provided.
get_plan_entitlements ~71
Get all features/entitlements included in a plan. Shows what features a plan grants and their values (on/off for boolean, numeric limits for metered, unlimited).
| Name | Type | Req | Description |
|---|---|---|---|
| planId | string | — | Plan ID (e.g., plan_xxx) |
| planName | string | — | Plan name |
No output schema declared.
No examples provided.
link_stripe_to_schematic ~60
Find the Schematic company for a Stripe customer ID, or vice versa. Returns both IDs and links to both platforms.
| Name | Type | Req | Description |
|---|---|---|---|
| companyId | string | — | Schematic company ID |
| stripeCustomerId | string | — | Stripe customer ID |
No output schema declared.
No examples provided.
list_addons ~19
List all add-ons in your Schematic account
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_company_overrides ~104
List company overrides. Filter by company (to see all overrides for a company) or by feature (to see which companies have an override for a feature)
| Name | Type | Req | Description |
|---|---|---|---|
| companyId | string | — | Company ID to filter by |
| companyName | string | — | Company name to filter by |
| featureId | string | — | Feature ID to filter by |
| featureName | string | — | Feature name to filter by (finds which companies have an override for this feature) |
No output schema declared.
No examples provided.
list_features ~17
List all features in your Schematic account
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_flags ~111
List all feature flags in your Schematic account with their targeting summary. For each flag, reports its key, default value, linked feature (if any), and whether it currently resolves to always-on, always-off, or targeted (gated by rules). Use this to audit which flags are always-on (and so no longer need to be checked in code) or unused (and so can be deleted from Schematic).
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | — | Optional: filter flags by a search string matched against key/name |
No output schema declared.
No examples provided.
list_plans ~24
List all plans in your Schematic account. Does not include add-ons.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
remove_company_override ~70
Remove a company override for a feature/entitlement. This will delete the override and the company will fall back to their plan's entitlements.
| Name | Type | Req | Description |
|---|---|---|---|
| companyId | string | — | — |
| companyName | string | — | — |
| featureId | string | — | — |
| featureName | string | — | — |
No output schema declared.
No examples provided.
set_company_override ~187
Set or update a company override for a feature/entitlement. REQUIRES a value parameter - always ask the user for the desired value before calling this tool. For boolean features: use 'on'/'off' or 'true'/'false'. For event-based or trait-based features: use a numeric value (e.g., '10', '100') or 'unlimited'.
| Name | Type | Req | Description |
|---|---|---|---|
| companyId | string | — | — |
| companyName | string | — | — |
| featureId | string | — | — |
| featureName | string | — | — |
| value | string | yes | REQUIRED: Override value. For boolean features: 'on'/'off' or 'true'/'false'. For event-based or trait-based features: a numeric value as a string (e.g., '10', '100') or 'unlimited'. Always ask the u… |
No output schema declared.
No examples provided.