# Schematic (npm · @schematichq/schematic-mcp)

Manage companies, plans, features, and billing through SchematicHQ

- Trust score: 78/100 (medium)
- Change this week: +33
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-04

## Components

- npm · `@schematichq/schematic-mcp`: 78/100 (this document), [markdown](https://verifymcp.io/servers/schematichq-schematic-mcp/schematichq-schematic-mcp.md), [page](https://verifymcp.io/servers/schematichq-schematic-mcp/schematichq-schematic-mcp)

## Channel facts

- Registry: `npm`
- Package: `@schematichq/schematic-mcp`
- Version: `0.4.0`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-04.

- **Supply Chain Security**: 83/100
  - No malware found by supply-chain analysis.
  - CVE check failed: a known medium-severity CVE affects hono 4.12.33, reached via @modelcontextprotocol/sdk > hono. A fixed version is available.
  - No install/post-install scripts declared.
  - Only part of the dependency tree could be resolved (119 of 120), so this covers what we could see, not the whole tree.
- **Provenance & Transparency**: 97/100
  - Source repository is publicly reachable at the declared URL.
  - Cryptographically verified build provenance (signed, bound to SchematicHQ/schematic-mcp).
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 18 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 73/100
  - AI-judged instruction clarity (good).
  - Tool/resource definitions use about 2565 tokens (~98/item across 26 items; 26 tools + 0 resources), lean.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 30/100
  - Stability observed for 9 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 92/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 77% of tool parameters carry a description.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### Claude

```bash
claude mcp add schematichq-schematic-mcp -- npx -y @schematichq/schematic-mcp
```

### Codex

```bash
codex mcp add schematichq-schematic-mcp -- npx -y @schematichq/schematic-mcp
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "schematichq-schematic-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@schematichq/schematic-mcp"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add schematichq-schematic-mcp --command npx --arg -y --arg @schematichq/schematic-mcp
```

### Hermes

```yaml
mcp_servers:
  schematichq-schematic-mcp:
    command: "npx"
    args: ["-y", "@schematichq/schematic-mcp"]
```

### Other

```json
{
  "mcpServers": {
    "schematichq-schematic-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@schematichq/schematic-mcp"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-04 (score 78, −1)

- [security regression] CVE-2026-69207 affects this package: medium
- [security regression] Known CVEs: partial → fail

### 2026-08-03 (score 79, +1)

No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-08-02 (score 78, +40)

- [security regression] Provenance: pass → unverified
- [security regression] Install scripts: pass → unverified
- [security improvement] Known CVEs: unverified → partial
- [security improvement] Malware scan: unverified → pass
- [security] The attested source repository moved: SchematicHQ/schematic-mcp
- [functional regression] License: pass → unverified
- [functional regression] Maintenance: pass → unverified
- [functional improvement] Dependency health: unverified → partial
- [functional improvement] MCP protocol: unverified → pass
- [functional improvement] Schema quality: unverified → good
- [functional improvement] Stability: unverified → 0.23
- [functional] Licence: MIT

### 2026-08-01 (score 38, −11)

- [security regression] Known CVEs: partial → unverified
- [functional regression] Dependency health: partial → unverified

### 2026-07-31 (score 49, +43)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-30 (score 6, −74)

- [security regression] Provenance: pass → unverified
- [security regression] Known CVEs: partial → unverified
- [security regression] Malware scan: pass → unverified
- [security regression] Install scripts: pass → unverified
- [security] The attested source repository moved: SchematicHQ/schematic-mcp
- [functional regression] Security disclosure: fail → unverified
- [functional regression] License: pass → unverified
- [functional regression] Tool coverage: 100 → unverified
- [functional regression] Dependency health: partial → unverified
- [functional regression] Maintenance: pass → unverified
- [functional] First check of Schema quality: unverified
- [functional] Licence: MIT

### 2026-07-29 (score 80, +35)

- [security improvement] Install scripts: unverified → pass
- [security improvement] Known CVEs: unverified → partial
- [security improvement] Provenance: unverified → pass
- [security] The attested source repository moved: SchematicHQ/schematic-mcp
- [functional improvement] Maintenance: unverified → pass
- [functional improvement] Dependency health: unverified → partial
- [functional improvement] License: unverified → pass
- [functional] Licence: MIT

### 2026-07-28 (score 45, 0)

- [functional regression] Security disclosure: unverified → fail

## MCP tools (26)

### `get_company` (~194 tokens)

Get company information by ID, name, Stripe customer ID, or custom key. Returns company details including plan, trial status, and links. For custom key lookups, the user must provide both keyName and keyValue. Key names are configured in Schematic - see https://docs.schematichq.com/developer_resources/key_management for details.

Input parameters:

- `companyId` (string): Schematic company ID (e.g., comp_xxx)
- `companyName` (string): Company name to search for
- `keyName` (string): Custom key name to look up the company by (e.g., 'app_id'). Must be used with keyValue. See https://docs.schematichq.com/developer_resources/key_management
- `keyValue` (string): Custom key value to look up the company by. Must be used with keyName.
- `stripeCustomerId` (string): Stripe customer ID

### `get_company_plan` (~80 tokens)

Get the plan that a company is currently on

Input parameters:

- `companyId` (string)
- `companyName` (string)
- `keyName` (string): Custom key name for company lookup (requires keyValue)
- `keyValue` (string): Custom key value for company lookup (requires keyName)
- `stripeCustomerId` (string)

### `get_company_trial_info` (~84 tokens)

Check if a company is on a trial and when it ends

Input parameters:

- `companyId` (string)
- `companyName` (string)
- `keyName` (string): Custom key name for company lookup (requires keyValue)
- `keyValue` (string): Custom key value for company lookup (requires keyName)
- `stripeCustomerId` (string)

### `count_companies_on_plan` (~48 tokens)

Count how many companies are on a specific plan

Input parameters:

- `planId` (string): Plan ID (e.g., plan_xxx)
- `planName` (string): Plan name

### `link_stripe_to_schematic` (~60 tokens)

Find the Schematic company for a Stripe customer ID, or vice versa. Returns both IDs and links to both platforms.

Input parameters:

- `companyId` (string): Schematic company ID
- `stripeCustomerId` (string): Stripe customer ID

### `create_company` (~162 tokens)

Create (upsert) a company, identified by a key. Companies are looked up by one or more keys (e.g. an 'id' key) — see Key Management. Optionally set a display name and traits. If a company with the given key already exists, it is updated rather than duplicated.

Input parameters:

- `keyName` (string, required): The key name used to identify the company (e.g. 'id'). Key names are configured in Schematic.
- `keyValue` (string, required): The value for keyName (e.g. 'demo-co').
- `name` (string): Optional display name for the company.
- `traits` (object): Optional map of trait names to values (e.g. { "plan_tier": "pro" }).

### `list_company_overrides` (~104 tokens)

List company overrides. Filter by company (to see all overrides for a company) or by feature (to see which companies have an override for a feature)

Input parameters:

- `companyId` (string): Company ID to filter by
- `companyName` (string): Company name to filter by
- `featureId` (string): Feature ID to filter by
- `featureName` (string): Feature name to filter by (finds which companies have an override for this feature)

### `set_company_override` (~187 tokens)

Set or update a company override for a feature/entitlement. REQUIRES a value parameter - always ask the user for the desired value before calling this tool. For boolean features: use 'on'/'off' or 'true'/'false'. For event-based or trait-based features: use a numeric value (e.g., '10', '100') or 'unlimited'.

Input parameters:

- `companyId` (string)
- `companyName` (string)
- `featureId` (string)
- `featureName` (string)
- `value` (string, required): REQUIRED: Override value. For boolean features: 'on'/'off' or 'true'/'false'. For event-based or trait-based features: a numeric value as a string (e.g., '10', '100') or 'unlimited'. Always ask the u…

### `remove_company_override` (~70 tokens)

Remove a company override for a feature/entitlement. This will delete the override and the company will fall back to their plan's entitlements.

Input parameters:

- `companyId` (string)
- `companyName` (string)
- `featureId` (string)
- `featureName` (string)

### `list_plans` (~24 tokens)

List all plans in your Schematic account. Does not include add-ons.

### `create_plan` (~31 tokens)

Create a new plan

Input parameters:

- `description` (string): Plan description
- `name` (string, required): Plan name

### `create_plan_with_billing` (~172 tokens)

Create a new plan with a Stripe-linked billing product. This creates both the plan and its associated Stripe product and prices in one step. Prices are specified in dollars (e.g., 29.99 for $29.99/month). If no prices are provided, the plan is created with $0 pricing. Use this instead of create_plan when you want the plan to be connected to Stripe billing.

Input parameters:

- `description` (string): Plan description
- `monthlyPrice` (number): Monthly price in dollars (e.g., 29.99 for $29.99/month). Defaults to 0.
- `name` (string, required): Plan name
- `yearlyPrice` (number): Yearly price in dollars (e.g., 299.99 for $299.99/year). Defaults to 0.

### `add_entitlements_to_plan` (~116 tokens)

Add entitlements to a plan. The feature type will be automatically determined by querying the feature. For boolean features, defaults to 'on' if no value is provided. For event-based or trait-based features, a value (number or 'unlimited') is required.

Input parameters:

- `entitlements` (array, required): Array of entitlement configurations. For boolean features, value is optional (defaults to 'on'). For event/trait features, value is required.
- `planId` (string)
- `planName` (string)

### `get_plan_entitlements` (~71 tokens)

Get all features/entitlements included in a plan. Shows what features a plan grants and their values (on/off for boolean, numeric limits for metered, unlimited).

Input parameters:

- `planId` (string): Plan ID (e.g., plan_xxx)
- `planName` (string): Plan name

### `list_addons` (~19 tokens)

List all add-ons in your Schematic account

### `create_addon` (~35 tokens)

Create a new add-on

Input parameters:

- `description` (string): Add-on description
- `name` (string, required): Add-on name

### `add_entitlements_to_addon` (~131 tokens)

Add entitlements to an add-on. The feature type will be automatically determined by querying the feature. For boolean features, defaults to 'on' if no value is provided. For event-based or trait-based features, a value (number or 'unlimited') is required.

Input parameters:

- `addonId` (string): Add-on ID (e.g., plan_xxx)
- `addonName` (string): Add-on name
- `entitlements` (array, required): Array of entitlement configurations. For boolean features, value is optional (defaults to 'on'). For event/trait features, value is required.

### `get_addon_entitlements` (~63 tokens)

Get all features/entitlements included in an add-on. Shows what features an add-on grants and their values.

Input parameters:

- `addonId` (string): Add-on ID (e.g., plan_xxx)
- `addonName` (string): Add-on name

### `count_companies_on_addon` (~51 tokens)

Count how many companies have a specific add-on

Input parameters:

- `addonId` (string): Add-on ID (e.g., plan_xxx)
- `addonName` (string): Add-on name

### `get_feature_usage` (~126 tokens)

Get feature usage data for a company. Shows access status, usage vs allocation, and entitlement source for each feature. Optionally filter to a specific feature by providing featureId. If you only know the feature name, use list_features first to find the feature ID, then pass it here as featureId.

Input parameters:

- `companyId` (string): Schematic company ID
- `companyName` (string): Company name to search for
- `featureId` (string): Optional: filter to a specific feature by ID. Use list_features to find the ID if you only have a name.

### `find_companies_near_limit` (~131 tokens)

Find companies at or above a usage threshold for a specific metered feature. Queries all companies for the given feature sorted by usage percentage (highest first), stopping as soon as usage drops below the threshold. If no featureId is provided, returns a list of metered features to choose from.

Input parameters:

- `featureId` (string): ID of the metered feature to scan. If omitted, the tool returns a list of available metered features to choose from.
- `threshold` (number): Usage percentage threshold (0-100). Companies at or above this percentage are included. Defaults to 70.

### `check_companies_usage` (~112 tokens)

Check feature usage for a specific list of companies and identify which are at or above a usage threshold for any metered feature. Useful for proactive health checks on known accounts. Results are grouped by feature and sorted by percent used.

Input parameters:

- `companyIds` (array, required): List of Schematic company IDs to check (e.g., ['comp_xxx', 'comp_yyy'])
- `threshold` (number): Usage percentage threshold (0-100). Companies at or above this percentage are included. Defaults to 70.

### `list_features` (~17 tokens)

List all features in your Schematic account

### `list_flags` (~111 tokens)

List all feature flags in your Schematic account with their targeting summary. For each flag, reports its key, default value, linked feature (if any), and whether it currently resolves to always-on, always-off, or targeted (gated by rules). Use this to audit which flags are always-on (and so no longer need to be checked in code) or unused (and so can be deleted from Schematic).

Input parameters:

- `query` (string): Optional: filter flags by a search string matched against key/name

### `get_flag` (~87 tokens)

Get full targeting detail for a single flag by its key: default value, every rule (type, value, priority, condition count), last-checked time, and the computed always-on / always-off / targeted determination. Use this to inspect why a flag resolves the way it does.

Input parameters:

- `key` (string, required): The flag key (dot-delimited, e.g. "billing.credits")

### `create_feature` (~279 tokens)

Create a new feature flag. Boolean features are simple on/off switches - the most commonly used type, ideal for enabling/disabling functionality and basic plan differentiation. Event-based features are metered against user events and track usage that typically increases over time (e.g., API calls, reports generated, database queries). Trait-based features are based on information reported to Schematic and can track usage that fluctuates up and down (e.g., user seats, projects, devices). Trait-based features must be created in the web app. Optionally entitle the feature to a plan in the same call.

Input parameters:

- `description` (string): Optional: Feature description
- `eventSubtype` (string): REQUIRED for event-based features: The event subtype to associate with this feature (e.g., 'api_call', 'report_generated').
- `featureType` (string): Feature type: 'boolean' (simple on/off switch, most common), 'event' (metered against events that increase over time), or 'trait' (based on information that can fluctuate - must be created in web app…
- `name` (string, required): Feature name/key
- `planId` (string): Optional: Plan ID to entitle this feature to
- `planName` (string): Optional: Plan name to entitle this feature to

## Diagnostics

Captured diagnostic sections: Provenance, Vulnerabilities, Dependencies. The full working is on the page: https://verifymcp.io/servers/schematichq-schematic-mcp/schematichq-schematic-mcp#diagnostics

## Score history

- 2026-08-04: 78
- 2026-08-03: 79
- 2026-08-02: 78
- 2026-08-01: 38
- 2026-07-31: 49
- 2026-07-30: 6
- 2026-07-29: 80
- 2026-07-28: 45
- 2026-07-27: 45

## Links

- npm package: https://www.npmjs.com/package/@schematichq/schematic-mcp
- Socket report: https://socket.dev/npm/package/@schematichq/schematic-mcp
- Repository: https://github.com/SchematicHQ/schematic-mcp
- Website: https://schematichq.com/
- Changelog RSS feed: https://verifymcp.io/servers/schematichq-schematic-mcp/schematichq-schematic-mcp/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/schematichq-schematic-mcp/schematichq-schematic-mcp/changelog.json
- HTML version of this page: https://verifymcp.io/servers/schematichq-schematic-mcp/schematichq-schematic-mcp
