io.github.vistoya/market
REMOTE · API.VISTOYA.COM · SCANNED OCT 4
Search and get fashion products recommendations across multiple e-ecom stores
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to connect, but we couldn't read the whole tool list to see what that exposes. View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability0
- Schema not yet verified: we couldn't read the endpoint's schema, or could read only part of its tool list.Unverified
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage0
- Tool coverage not yet verified: we couldn't read the endpoint's tools, or could read only part of the list.Unverified
Tool Safety0
- Tool safety not yet verified: we couldn't read the endpoint's tools, or could read only part of the list.Unverified
Capabilities0
- Capabilities not yet verified: we couldn't read the endpoint's capabilities.Unverified
Unverified: 5 categories
Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.
How do I install the io.github.vistoya/market MCP server?
io.github.vistoya/market is a hosted endpoint at https://api.vistoya.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · api.vistoya.com
claude mcp add --transport http vistoya-market 'https://api.vistoya.com/mcp'
{
"mcpServers": {
"vistoya-market": {
"url": "https://api.vistoya.com/mcp"
}
}
} {
"servers": {
"vistoya-market": {
"type": "http",
"url": "https://api.vistoya.com/mcp"
}
}
} [mcp_servers.vistoya-market] url = "https://api.vistoya.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"vistoya-market": {
"type": "remote",
"url": "https://api.vistoya.com/mcp",
"enabled": true
}
}
} openclaw mcp add vistoya-market --url 'https://api.vistoya.com/mcp' --transport streamable-http
mcp_servers:
vistoya-market:
url: "https://api.vistoya.com/mcp" {
"McpServers": {
"vistoya-market": {
"Transport": "http",
"Url": "https://api.vistoya.com/mcp"
}
}
} assistant mcp add vistoya-market -t streamable-http -u 'https://api.vistoya.com/mcp'
{
"mcpServers": {
"vistoya-market": {
"type": "http",
"url": "https://api.vistoya.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 28 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 17 Aug 26 0
- Endpoint reachability: unreachable → not serving MCP ▼ security
- Transport: fail → pass ▲ security
- 16 Aug 26 0
- Endpoint reachability: not serving MCP → unreachable ▼ security
- Transport: pass → fail ▼ security
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 7 Aug 26 0
- Endpoint reachability: reachable → not serving MCP ▼ security
- Stability: 0.37 → unverified ▼ security
- Authorization: partial → unverified ▼ security
- Schema quality: 100 → unverified ▼ functional
- Capabilities: pass → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- 31 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 6 Oct 2026 · Probed https://api.vistoya.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=vistoya.com | CN=WE1,O=Google Trust Services,C=US | 13 Sept 2026 | 12 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | b7cb97848cfcbb7f13abe823d430a545 |
| SANs: vistoya.com, *.vistoya.com | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of api.vistoya.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| vistoya.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://api.vistoya.com/mcp | Verified | 200 | |
| http (plaintext) | http://api.vistoya.com/mcp | HTTPS enforced | 301 | https://api.vistoya.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
discover_brands ~412
Find fashion brands using natural language, structured filters, or both. Best for queries like "Italian streetwear brands", "Scandinavian minimalist brands", "Japanese technical outerwear", "brands with avant-garde tailoring", or "brands like Rick Owens". Country adjectives ("Italian", "Scandinavian", "Nordic", "Japanese", "Iberian", "Benelux") are parsed server-side into shipping-origin filters; you don't need to translate them to ISO codes. `query` is optional — provide a query, structured filters, or both. Brand country/shipping signals are best-effort and separate from product availability.
| Name | Type | Req | Description |
|---|---|---|---|
| category_focus | array | – | Optional brand category focus filters, e.g. ["clothing", "shoes"]. |
| country | string | – | Optional shopper location as an ISO-3166-1 alpha-2 country code (e.g. "US", "GB", "DE"). Recorded for analytics and used to improve future offer geo-matching. Omit if unknown — absence preserves curr… |
| gender_focus | array | – | Optional brand audience focus filters. |
| limit | integer | – | Maximum number of brands to return (1-20, default 8). |
| price_tier | string | – | Optional brand price-tier focus filter. |
| query | string | – | Natural language brand search query, e.g. "Italian streetwear brands", "Scandinavian minimalist brands", "Japanese technical outerwear", or "brands like Rick Owens". Country adjectives are parsed ser… |
| ships_from_country | string | – | Optional ISO-3166 alpha-2 country filter for best-effort store shipping origin, e.g. "IT", "US", "GB". This is not the same as brand origin. |
| style | string | – | Optional style filter, e.g. streetwear, minimalist, elegant, avant-garde, techwear. |
| Name | Type | Req | Description |
|---|---|---|---|
| brands | array | yes | – |
No examples provided.
discover_products ~1,406
Find fashion products using natural language and/or structured filters. Provide a `query` for semantic ranking via multimodal text+image embeddings ("oversized wool coat", "black leather jacket", "minimalist gold jewelry", "linen shirt for a beach wedding under $200") — best for open-ended discovery. Keep queries concrete: noun-led with up to one or two modifiers works best ("summer linen shirt" beats "breathable linen shirt perfect for summer"). Provide only structured filters (category, brand, colors, gender, price, etc.) for pure browse — results are recency-ranked and paginate cleanly. Combine both for filtered semantic search. At least one of query or a filter must be provided. Example calls (notice the sparse filter population — descriptive attributes stay in `query`, not in structured fields): - "linen wedding guest dress under $200" → {query: "linen wedding guest dress", gender: "women", max_price: 200, materials: ["linen"]} - "wool coat under $300" → {query: "wool coat", gender: "women", max_price: 300, materials: ["wool"]} - "browse women's black dresses $100-$300" → {gender: "women", category: "clothing/dresses", colors: ["black"], min_price: 100, max_price: 300} - "Acne Studios outerwear" → {query: "outerwear", brand: "Acne Studios", gender: "women"} Returns compact product cards: AI-generated summary, price, images, tags, and compact availability by color/size; variant price differences are nested under the availability dimension that determines price. For merchant description, store info, SKU-level variants, exact variant prices, and all product images, call get_product with a product ID from these results. Multi-currency prices supported (e.g. "under 200 zł" or min_price=200 + currency="PLN"); returned prices render in the requested currency when provided.
| Name | Type | Req | Description |
|---|---|---|---|
| available_sizes | array | – | Filter by available size labels, e.g. ["s", "m", "38"]. |
| brand | string | – | Filter by brand name |
| category | string | – | Category slug, e.g. "clothing", "clothing/jackets", "clothing/jackets/bomber-jackets". Accepts last-segment shortcuts when unambiguous — e.g. "loafers-and-slip-ons" resolves the same as "shoes/loafer… |
| color_match | string | – | Color matching mode. "any" (default): product has at least one of the queried colors. "exact": product has at least one image where the ONLY colors are the queried colors — use for mono-color searche… |
| colors | array | – | Filter by lowercase colors: e.g. ["black", "navy", "sage green"] |
| country | string | – | Optional shopper location as an ISO-3166-1 alpha-2 country code (e.g. "US", "GB", "DE"). Recorded for analytics and used to improve future offer geo-matching. Omit if unknown — absence preserves curr… |
| currency | string | – | ISO 4217 currency code for min_price/max_price (e.g. "PLN", "EUR", "GBP"). Prices are converted to USD for filtering. Omit for USD. |
| exclude_colors | array | – | Exclude products with these colors: e.g. ["white", "beige"] |
| exclude_materials | array | – | Exclude products with these materials: e.g. ["polyester", "nylon"] |
| gender | string | – | Gender filter. |
| is_sustainable | boolean | – | True when the user explicitly wants products with sustainability claims. |
| limit | integer | – | Page size (1-20, default 12) |
| materials | array | – | Filter by lowercase materials: e.g. ["cotton", "silk", "leather"] |
| max_price | number | – | Maximum price (in the currency specified by "currency" param, or USD if omitted) |
| min_price | number | – | Minimum price (in the currency specified by "currency" param, or USD if omitted) |
| neckline | string | – | Neckline filter. Soft descriptor — set ONLY when the user explicitly named the neckline. Do not infer from category or query. |
| occasion | string | – | Occasion filter. Soft descriptor — set ONLY when the user explicitly named the occasion. The `query` field already captures occasion semantically; over-specifying is the most common cause of zero-res… |
| page | integer | – | Page number. |
| pattern | string | – | Pattern filter (e.g. solid, stripe, checked, floral). Soft descriptor — set ONLY when the user explicitly named the pattern. Default for unspecified ("solid") leaks into queries and zeros the candida… |
| query | string | – | Natural language search query — be descriptive for best results. Can include price with currency symbols (e.g. "white coat under 200 zł") which will be parsed automatically. Optional: when omitted, r… |
| season | string | – | Season filter. Soft descriptor — set ONLY when the user explicitly named the season. The `query` field already captures season semantically; over-specifying is the most common cause of zero-result ca… |
| silhouette | string | – | Silhouette/fit filter (e.g. fitted, slim, regular, relaxed, oversized). Soft descriptor — set ONLY when the user explicitly named the fit. The `query` field already captures silhouette semantically;… |
| sleeves | string | – | Sleeve style filter. Soft descriptor — set ONLY when the user explicitly named the sleeve style. Do not infer from category or query. |
| store_domain | string | – | Filter by store domain (e.g. "thereformation.com"). Accepts forms with protocol, www, locale subdomain, or path — they are normalized to match the registered store. |
| styles | array | – | Style filter (OR semantics — a product matches if any of its `styles` values is in this list). Pass a single value to filter by one style ("styles": ["minimalist"]); pass several to span a related se… |
| Name | Type | Req | Description |
|---|---|---|---|
| hasNextPage | boolean | yes | – |
| marketUrl | string | yes | – |
| page | integer | yes | – |
| products | array | yes | – |
No examples provided.
find_similar_brands ~120
Given a brand name, find similar brands using brand-profile vectors generated during product indexing. Returns up to 20 brands.
| Name | Type | Req | Description |
|---|---|---|---|
| brand | string | yes | Brand name (case-insensitive), e.g. "Rick Owens". |
| country | string | – | Optional shopper location as an ISO-3166-1 alpha-2 country code (e.g. "US", "GB", "DE"). Recorded for analytics and used to improve future offer geo-matching. Omit if unknown — absence preserves curr… |
| limit | integer | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| brands | array | yes | – |
No examples provided.
find_similar_products ~244
Given a product ID, find similar products across the entire catalog. Useful for "more like this" recommendations or finding alternatives. Returns compact product cards, not full variant detail; call get_product for SKU-level variants, exact variant prices, merchant description, store info, and all images. Returns page and hasNextPage. Returns up to 20 results per page, paginated (max 3 pages).
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | – | Optional shopper location as an ISO-3166-1 alpha-2 country code (e.g. "US", "GB", "DE"). Recorded for analytics and used to improve future offer geo-matching. Omit if unknown — absence preserves curr… |
| currency | string | – | ISO 4217 currency code to render prices in (e.g. "GBP", "EUR", "USD"). Defaults to USD. Stored native prices are preferred; falls back to FX conversion when a merchant-set price isn't available. |
| limit | integer | – | Page size (1-20) |
| page | integer | – | Page number (1-3) |
| product_id | string | yes | The product ID (from a previous search result) |
| Name | Type | Req | Description |
|---|---|---|---|
| hasNextPage | boolean | yes | – |
| page | integer | yes | – |
| products | array | yes | – |
No examples provided.
get_filters ~324
Returns available filter values in the catalog. By default returns categoryTree plus brands, colors, materials, genders, occasions, seasons, styles, silhouettes, currencies, and price range. Use "fields" to request only specific dimensions — faster and less data. "categoryTree" is a flat DFS-ordered list of { value, label } entries; hierarchy is encoded in the value slug (e.g. "clothing/jackets/bomber-jackets"), parents appear before descendants, and every value can be passed directly to discover_products.category. Use "brand_search" to search brands by prefix instead of listing all. Pass "gender" to scope categoryTree to that gender (women/men/girls/boys); omit to see the merged union.
| Name | Type | Req | Description |
|---|---|---|---|
| brand_page | integer | – | Page number for brands (12 per page). Use with or without brand_search. |
| brand_search | string | – | Search brands by name (case-insensitive, prefix matches first). Only affects the brands field. |
| country | string | – | Optional shopper location as an ISO-3166-1 alpha-2 country code (e.g. "US", "GB", "DE"). Recorded for analytics and used to improve future offer geo-matching. Omit if unknown — absence preserves curr… |
| fields | array | – | Which filter dimensions to return. Omit for all. Example: ["categoryTree", "colors", "priceRange"] |
| gender | string | – | Scope categoryTree to this gender. Omit to return the merged union across women/men/girls/boys. |
| Name | Type | Req | Description |
|---|---|---|---|
| brands | array | – | – |
| categoryTree | array | – | – |
| colors | array | – | – |
| currencies | array | – | – |
| genders | array | – | – |
| materials | array | – | – |
| occasions | array | – | – |
| patterns | array | – | – |
| priceRange | object | – | – |
| seasons | array | – | – |
| silhouettes | array | – | – |
| styles | array | – | – |
No examples provided.
get_product ~180
Get the detailed response for a specific product ID. Use this after discover_products or find_similar_products when you need merchant description, store info, all images, SKU-level availability variants, SKU, colorKey/size matrix, exact variant prices/compareAtPrice in the requested currency, and the direct link to purchase.
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | – | Optional shopper location as an ISO-3166-1 alpha-2 country code (e.g. "US", "GB", "DE"). Recorded for analytics and used to improve future offer geo-matching. Omit if unknown — absence preserves curr… |
| currency | string | – | ISO 4217 currency code to render prices in (e.g. "GBP", "EUR", "USD"). Defaults to USD. |
| product_id | string | yes | The product ID (from a previous search result) |
| Name | Type | Req | Description |
|---|---|---|---|
| availability | object | yes | – |
| brand | string | – | – |
| category | string | – | – |
| closures | array | – | – |
| colors | array | – | – |
| compareAtPrice | number|null | – | – |
| currency | string | yes | – |
| gender | string | – | – |
| id | string | yes | – |
| images | array | – | – |
| inStock | boolean | – | – |
| isSustainable | boolean | – | – |
| materials | array | – | – |
| merchantDescription | string | – | – |
| neckline | string | – | – |
| price | number|null | yes | – |
| productUrl | string | – | – |
| relevanceScore | number | – | – |
| silhouette | string | – | – |
| similarityScore | number | – | – |
| sleeves | string | – | – |
| store | – | – | – |
| summary | string | – | – |
| tags | array | – | – |
| title | string | yes | – |
No examples provided.
What is the io.github.vistoya/market MCP server?
io.github.vistoya/market is an MCP server listed in the public MCP registry as io.github.vistoya/market. Search and get fashion products recommendations across multiple e-ecom stores. This page covers its hosted endpoint (https://api.vistoya.com/mcp).
Is the io.github.vistoya/market MCP server safe to use?
io.github.vistoya/market scores 33 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.vistoya/market MCP server expose?
io.github.vistoya/market exposes 6 tools: discover_products, find_similar_products, discover_brands, find_similar_brands, get_product, get_filters. Their descriptions and schemas cost roughly 2,686 tokens of context every time the server is loaded.
Does the io.github.vistoya/market MCP server require authentication?
No. We connected to io.github.vistoya/market without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the io.github.vistoya/market MCP server still maintained?
io.github.vistoya/market is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.