AILANG Parse
REMOTE · DOCPARSE.AILANG.SUNHOLO.COM · 3 COMPONENTS · SCANNED AUG 3
Deterministic DOCX/PPTX/XLSX/PDF parser: track changes, comments, headers, footers, merged cells.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 31 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability67
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (fair).Partial
- Tool/resource definitions use about 2941 tokens (~91/item across 32 items; 31 tools + 1 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
- Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage71
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 13% of tool parameters carry a description.Partial
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · docparse.ailang.sunholo.com
claude mcp add --transport http sunholo-data-parse https://docparse.ailang.sunholo.com/mcp/
[mcp_servers.sunholo-data-parse] url = "https://docparse.ailang.sunholo.com/mcp/"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"sunholo-data-parse": {
"type": "remote",
"url": "https://docparse.ailang.sunholo.com/mcp/",
"enabled": true
}
}
} openclaw mcp add sunholo-data-parse --url https://docparse.ailang.sunholo.com/mcp/ --transport streamable-http
mcp_servers:
sunholo-data-parse:
url: "https://docparse.ailang.sunholo.com/mcp/" {
"mcpServers": {
"sunholo-data-parse": {
"type": "http",
"url": "https://docparse.ailang.sunholo.com/mcp/"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 2 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.
- 31 Jul 26 +2
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 29 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.
- 28 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 57
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://docparse.ailang.sunholo.com/mcp/
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=docparse.ailang.sunholo.com | CN=YR2,O=Let's Encrypt,C=US | 26 Jul 2026 | 24 Oct 2026 | RSA 2048 | SHA256-RSA | 6385294ac375c852f2ba2346b9fed170605 |
| SANs: docparse.ailang.sunholo.com | ||||||
| CN=YR2,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | 4ebd24947e24d394802d84a52fd5b319 |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
DNSSEC insecure
Validation of docparse.ailang.sunholo.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| sunholo.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://docparse.ailang.sunholo.com/mcp/ | Verified | 200 | |
| http (plaintext) | http://docparse.ailang.sunholo.com/mcp/ | HTTPS enforced | 302 | https://docparse.ailang.sunholo.com/mcp/ |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
agentCard ~104
A2A Agent Card for agent-to-agent discovery. Returns a hand-crafted Agent Card with AILANG Parse-specific skills, supported formats, and capability descriptions. @raw: return raw JSON (no {result:..., elapsed_ms:N} envelope) for A2A compliance. Switch to @nowrap once available (lighter than @raw). If using --a2a flag, the built-in route takes precedence (collision guard skips this).
| Name | Type | Req | Description |
|---|---|---|---|
| _ | string | yes | — |
No output schema declared.
No examples provided.
apiSamples ~45
Sample files inventory — delegates to the upstream package. Package @route annotations don't auto-register with serve-api, so we provide a local wrapper here.
| Name | Type | Req | Description |
|---|---|---|---|
| _ | string | yes | — |
No output schema declared.
No examples provided.
apiTools ~39
Tool definitions for Claude, OpenAI, MCP, and A2A agent frameworks. Delegates to the upstream package.
| Name | Type | Req | Description |
|---|---|---|---|
| _ | string | yes | — |
No output schema declared.
No examples provided.
capabilities ~25
capabilities(() -> string ! {Env}) [pure]
| Name | Type | Req | Description |
|---|---|---|---|
| _ | string | yes | — |
No output schema declared.
No examples provided.
deviceAuthApprove ~79
Approve a device authorization request. Called by the browser approval page after user signs in and confirms. Verifies Firebase ID token from Authorization header to ensure the caller is a real authenticated user. Extracts uid from the verified token. Dev mode: ALLOW_SELF_APPROVE=true skips Firebase verification (for testing).
| Name | Type | Req | Description |
|---|---|---|---|
| req | object | yes | — |
No output schema declared.
No examples provided.
deviceAuthInspect ~124
Look up a pending device code by user_code and return its provenance. No authentication required — possession of the user_code is the proof. The dashboard /approve.html page calls this BEFORE showing the approve UI so the user can see where the request came from (IP, User-Agent, Referer, age) and decide whether to trust it. Returns 404 if the user_code does not match any pending device_codes doc. Already-approved or expired codes return as INPUT_NOT_FOUND too — there is nothing to inspect after the fact.
| Name | Type | Req | Description |
|---|---|---|---|
| userCode | string | yes | — |
No output schema declared.
No examples provided.
deviceAuthPoll ~54
Poll for device authorization approval. Returns AUTHORIZATION_PENDING if user hasn't approved yet. Returns DEVICE_CODE_EXPIRED if the code has timed out. Returns approved status with API key on success.
| Name | Type | Req | Description |
|---|---|---|---|
| deviceCode | string | yes | — |
No output schema declared.
No examples provided.
deviceAuthRequest ~44
Request a device authorization code. Returns device_code, user_code, and verification URL. The agent should display the verification_url to the user.
| Name | Type | Req | Description |
|---|---|---|---|
| req | object | yes | — |
No output schema declared.
No examples provided.
editDocument ~192
Parse a document, apply JSON edit deltas, and return the modified blocks as JSON (same format as POST /api/v1/parse with outputFormat=blocks). filepath: uploaded file path (multipart upload). deltas: JSON array of edit operations — see edit_apply.ail for format. Empty array or "" → round-trip (parse + return unchanged blocks). apiKey: dp_ API key. Response: modified blocks JSON. Use the AILANG SDK or CLI to generate a file from the returned blocks (e.g. ailang run ... --convert output.docx). Only deterministic office formats are supported (docx, pptx, xlsx, odt, odp, ods). AI-required formats (pdf, image, audio, video) are rejected.
| Name | Type | Req | Description |
|---|---|---|---|
| apiKey | string | yes | — |
| deltas | string | yes | — |
| filepath | string | yes | — |
No output schema declared.
No examples provided.
estimate ~39
estimate((string, string) -> string ! {Clock, FS}) [pure]
| Name | Type | Req | Description |
|---|---|---|---|
| filepath | string | yes | — |
| outputFormat | string | yes | — |
No output schema declared.
No examples provided.
formats ~57
List all supported document formats for parsing and generation. Returns: parse formats (13), generate formats (9), output formats (blocks/markdown/html/a2ui), and which formats require AI (PDF, images).
| Name | Type | Req | Description |
|---|---|---|---|
| _ | string | yes | — |
No output schema declared.
No examples provided.
getKeyUsage ~46
Get usage stats for a user's API key. Accepts Firebase JWT or apiKey. Verifies that the requested keyId belongs to the authenticated user.
| Name | Type | Req | Description |
|---|---|---|---|
| req | object | yes | — |
No output schema declared.
No examples provided.
getUploadUrl ~95
Request a pre-authenticated GCS upload URL for direct file upload. Business tier only. The returned URL allows the client to PUT file content directly to GCS, bypassing the 32MB Cloud Run request limit. After upload, pass the gcs_ref to POST /api/v1/parse.
| Name | Type | Req | Description |
|---|---|---|---|
| apiKey | string | yes | — |
| filename | string | yes | — |
| mimeType | string | yes | — |
No output schema declared.
No examples provided.
health ~124
Health check for the AILANG Parse API. Returns service status, version, AILANG commit hash, supported format counts, and billing catalog status. `billing_catalog_loaded` is FALSE when the BILLING_PLAN_CATALOG env var is unset or parses to an empty list — in that mode every authenticated request silently falls back to the safety-net "fallback" plan (limit=1) and is rejected as over-quota. release.sh asserts `billing_catalog_loaded == true` after every promotion to catch this regressing.
| Name | Type | Req | Description |
|---|---|---|---|
| _ | string | yes | — |
No output schema declared.
No examples provided.
listApiKeys ~82
List API keys for a user. Accepts either: - Authorization: Bearer <firebase_id_token> (dashboard path) - {apiKey: "..."} or {args: ["dp_..."]} in body (CLI/SDK path) The resolved userId filters the Firestore query server-side.
| Name | Type | Req | Description |
|---|---|---|---|
| req | object | yes | — |
No output schema declared.
No examples provided.
mcpAccount ~108
View account info, pricing, entitlements, or list keys. Actions: "status" (default) → tier, quota, usage from /me/entitlements "pricing" → public pricing tiers (no auth required) "keys" → list user's API keys with per-key usage "usage" → alias for "keys" (per-key usage is shown there)
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | — |
| apiKey | string | yes | — |
No output schema declared.
No examples provided.
mcpAuth ~82
Start device authorization to get an API key. Returns device_code, user_code, and verification URL. The agent should display the verification URL to the user, who signs in and approves the code. Then call mcpAuthPoll with the device_code. MCP wrappers don't have HTTP request headers, so provenance is empty here.
| Name | Type | Req | Description |
|---|---|---|---|
| label | string | yes | — |
No output schema declared.
No examples provided.
mcpAuthPoll ~58
Poll for device authorization completion. Returns "pending" (keep polling every 5s), "approved" (with api_key and tier), or "expired" (start over with mcpAuth).
| Name | Type | Req | Description |
|---|---|---|---|
| deviceCode | string | yes | — |
No output schema declared.
No examples provided.
mcpConvert ~85
Convert is not supported on the hosted server (no persistent local filesystem to write the output file to). Use the local stdio SDK (@ailang/parse) for local conversions, where the user has filesystem access.
| Name | Type | Req | Description |
|---|---|---|---|
| apiKey | string | yes | — |
| input | string | yes | — |
| outputFormat | string | yes | — |
| outputPath | string | yes | — |
No output schema declared.
No examples provided.
mcpEstimate ~46
Estimate cost and latency for parsing a document. Accepts a file path or sample_id. No auth required.
| Name | Type | Req | Description |
|---|---|---|---|
| filepath | string | yes | — |
| outputFormat | string | yes | — |
No output schema declared.
No examples provided.
mcpFormats ~59
List supported formats, samples, and service capabilities. Pure JSON, no auth required. Delegates to package implementation. Single source of truth lives in pkg/sunholo/ailang_parse/services/mcp/tools.
| Name | Type | Req | Description |
|---|---|---|---|
| _ | string | yes | — |
No output schema declared.
No examples provided.
mcpParse ~105
Parse a document. Accepts a file path or sample_id (e.g. "sample_docx_formatting"). The hosted server requires a valid dp_ API key — get one via mcpAuth. Output formats: blocks (default), markdown, html, a2ui. requestId is reserved for future replay support.
| Name | Type | Req | Description |
|---|---|---|---|
| apiKey | string | yes | — |
| filepath | string | yes | — |
| outputFormat | string | yes | — |
| requestId | string | yes | — |
No output schema declared.
No examples provided.
myEntitlements ~64
Get the authenticated user's billing entitlements, usage, and plan details. Returns: plan name, monthly request limit, requests used, remaining requests, upgrade/manage URLs. Requires a valid AILANG Parse API key (dp_ prefix).
| Name | Type | Req | Description |
|---|---|---|---|
| apiKey | string | yes | — |
No output schema declared.
No examples provided.
parseFileSecure ~424
Parse a document. Requires a valid API key. Validates the key, checks entitlement quotas, logs for replay. filepath: file path OR sample_id (e.g. "sample_docx_formatting" → resolved via /api/v1/samples). outputFormat: "blocks", "markdown", "html", or "a2ui". editable: "true" to emit editable A2UI component variants with block_index props; only meaningful when outputFormat="a2ui". gcsRef: optional gs:// URI for Business tier large file uploads (>32MB). When provided, the file is downloaded from GCS via our service account. Business tier only — Free/Pro users get TIER_UPGRADE_REQUIRED error. sourceUrl: optional https:// URL (e.g., a signed GCS URL or any public file). When provided, the file is fetched over HTTPS by docparse and parsed. Available on all tiers; tier dictates the max fetched-file size. Cannot be combined with gcsRef or filepath — sourceUrl wins. pdfBackend: optional PDF extraction backend override. "" — use server default (DOCPARSE_PDF_BACKEND env var, default "pdftotext"). "pdftotext" — deterministic text extraction via poppler. Fast, no AI cost. "docling" — IBM Docling layout analysis. No AI cost. "liteparse" — run-llama LiteParse. No AI cost. "ai" — Gemini multimodal via Vertex AI. Required for scanned/image-only PDFs. Explicit non-"ai" selection returns an error on failure (no silent AI fallback). @nowrap: raw JSON (no envelope), _headers extracted as HTTP response headers.
| Name | Type | Req | Description |
|---|---|---|---|
| apiKey | string | yes | — |
| editable | string | yes | — |
| filepath | string | yes | — |
| gcsRef | string | yes | — |
| outputFormat | string | yes | — |
| pdfBackend | string | yes | — |
| sourceUrl | string | yes | — |
No output schema declared.
No examples provided.
partitionGeneral ~142
Unstructured API-compatible endpoint (drop-in replacement for Unstructured.io). Returns elements in Unstructured JSON format (Title, NarrativeText, Table, ListItem, etc.). Accepts file upload (multipart/form-data) or JSON body with filepath/sample_id. API key: via unstructured-api-key header (Unstructured convention) or apiKey form field. strategy parameter: "auto" (default), "hi_res", "fast", "ocr_only". Uses _headers for header access while keeping @route multipart support.
| Name | Type | Req | Description |
|---|---|---|---|
| _headers | object | yes | — |
| apiKey | string | yes | — |
| filepath | string | yes | — |
| strategy | string | yes | — |
No output schema declared.
No examples provided.
pricing ~22
pricing(() -> string) [pure]
| Name | Type | Req | Description |
|---|---|---|---|
| _ | string | yes | — |
No output schema declared.
No examples provided.
requestHistory ~104
List recent parse requests for a user. Returns up to 50 entries. Accepts Firebase ID token (dashboard) OR dp_ API key (programmatic). Dashboard sends Authorization: Bearer <firebase_token> with {args: [uid]}. API clients send {args: [apiKey]}. Uses Firestore structured query to filter by user_id server-side and order by timestamp descending. Only reads matching docs (not full scan).
| Name | Type | Req | Description |
|---|---|---|---|
| req | object | yes | — |
No output schema declared.
No examples provided.
requestReplay ~79
Retrieve a stored request/response pair for replay. Requires authentication: Firebase JWT or dp_ API key. The request must belong to the authenticated user (user_id match). Accepts optional outputFormat (blocks/markdown/html/a2ui) to re-render the stored blocks server-side using the ailang_parse pipeline.
| Name | Type | Req | Description |
|---|---|---|---|
| req | object | yes | — |
No output schema declared.
No examples provided.
revokeApiKey ~36
Revoke an API key by keyId. Authenticates via either Firebase JWT or apiKey.
| Name | Type | Req | Description |
|---|---|---|---|
| req | object | yes | — |
No output schema declared.
No examples provided.
rotateApiKey ~34
Rotate an API key: generate new key, revoke old one, preserve tier + usage.
| Name | Type | Req | Description |
|---|---|---|---|
| req | object | yes | — |
No output schema declared.
No examples provided.
submit_feedback ~325
Anonymous bug report / feature request / docs gap, queued for human review. Default routing: `public-feedback` inbox (general AILANG). Pass `package="vendor/name"` (e.g. "sunholo/auth") to route to that package's `pkg:vendor/name` inbox where its autonomous agent watches. Categories: bug, feature, docs, limitation. Body limit 10KB, snippet limit 4KB. Optional contact field for follow-up; opaque to the server. Set `auto_dispatch=true` to authorize the package agent to act on your submission immediately (default false — files for human triage; pkg-feedback agent template lands in a separate sprint).
| Name | Type | Req | Description |
|---|---|---|---|
| ailang_version | string | yes | The reporter's CLI version (free-form, used for triage) |
| auto_dispatch | boolean | — | Authorize the receiving package's autonomous agent to act on this submission. Default false (files for human triage). Tagged on the Pub/Sub notification as category=auto:<original> for coordinator fi… |
| body | string | yes | Full description (≤10 KB) |
| category | string | yes | bug | feature | docs | limitation |
| contact | string | — | Optional follow-up address (free-form, opaque to the server) |
| package | string | — | Optional vendor/name (e.g. "sunholo/auth") to route to that package's pkg:vendor/name inbox. Empty = general AILANG feedback. |
| snippet | string | — | Optional code/error snippet (≤4 KB) |
| title | string | yes | Short title for the report |
No output schema declared.
No examples provided.