Wavix
REMOTE · MCP.WAVIX.COM · SCANNED SEP 21
Hosted MCP server for the Wavix telecom platform: SMS, voice, 2FA, SIP, numbers, 10DLC, CDRs.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security92
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- The endpoint enforces authorisation, advertised via RFC 9728 protected-resource metadata. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server supports Client ID Metadata Documents, the current MCP client-registration mechanism. View diagnostics → Pass
Transport & Reachability0
- Transport blocked by authentication: the endpoint requires auth we don't have to verify streamable-http. See how to fix → View diagnostics → Unverified
Schema Quality & AI Usability0
- Schema blocked by authentication: the endpoint requires auth we don't have to read it. See how to fix → Unverified
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage0
- Tool coverage blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Tool Safety0
- Tool safety blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Capabilities0
- Capabilities blocked by authentication: the endpoint requires auth we don't have to read them. See how to fix → Unverified
Unverified: 6 categories
Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm. Claim this server and supply a read-only token to verify it and lift the score.
How do I install the Wavix MCP server?
Wavix is a hosted endpoint at https://mcp.wavix.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.wavix.com
claude mcp add --transport http wavix-mcp 'https://mcp.wavix.com/mcp'
{
"mcpServers": {
"wavix-mcp": {
"url": "https://mcp.wavix.com/mcp"
}
}
} {
"servers": {
"wavix-mcp": {
"type": "http",
"url": "https://mcp.wavix.com/mcp"
}
}
} [mcp_servers.wavix-mcp] url = "https://mcp.wavix.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"wavix-mcp": {
"type": "remote",
"url": "https://mcp.wavix.com/mcp",
"enabled": true
}
}
} openclaw mcp add wavix-mcp --url 'https://mcp.wavix.com/mcp' --transport streamable-http
mcp_servers:
wavix-mcp:
url: "https://mcp.wavix.com/mcp" {
"McpServers": {
"wavix-mcp": {
"Transport": "http",
"Url": "https://mcp.wavix.com/mcp"
}
}
} assistant mcp add wavix-mcp -t streamable-http -u 'https://mcp.wavix.com/mcp'
{
"mcpServers": {
"wavix-mcp": {
"type": "http",
"url": "https://mcp.wavix.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 9 Sept 26 −42
- Endpoint reachability: reachable → behind authorisation ▼ security
- Stability: pass → unverified ▼ security
- Tool safety: pass → unverified ▼ security
- Transport: pass → unverified ▼ security
- Authorization: unverified → pass ▲ security
- First check of Authorization: pass security
- Capabilities: pass → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- Schema quality: 100 → unverified ▼ functional
- 26 Aug 26 −1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 +1
- Stability: 0.97 → pass security
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 7 Aug 26 0
- The server no longer declares the “experimental” capability functional
- 31 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 21 Sept 2026 · Probed https://mcp.wavix.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_256_GCM_SHA384 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=*.wavix.com | CN=GlobalSign GCC R6 AlphaSSL CA 2025,O=GlobalSign nv-sa,C=BE | 16 Jun 2026 | 1 Jan 2027 | RSA 2048 | SHA256-RSA | 138eab06a957b419c83f0b22 |
| SANs: *.wavix.com, wavix.com | ||||||
| CN=GlobalSign GCC R6 AlphaSSL CA 2025,O=GlobalSign nv-sa,C=BE (CA) | CN=GlobalSign,OU=GlobalSign Root CA - R6,O=GlobalSign | 21 May 2025 | 21 May 2027 | RSA 2048 | SHA256-RSA | 837d4eb89e912fe72cad3bc7692ddc20 |
| CN=GlobalSign,OU=GlobalSign Root CA - R6,O=GlobalSign (CA) | CN=GlobalSign,OU=GlobalSign Root CA - R6,O=GlobalSign | 10 Dec 2014 | 10 Dec 2034 | RSA 4096 | SHA384-RSA | 45e6bb038333c3856548e6ff4551 |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.wavix.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| wavix.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On connection |
| HTTP status | 401 |
WWW-Authenticate challenge Bearer resource_metadata="https://mcp.wavix.com/.well-known/oauth-protected-resource/mcp"
Bearer resource_metadata="https://mcp.wavix.com/.well-known/oauth-protected-resource/mcp" | Header | Value |
|---|---|
| www-authenticate | Bearer resource_metadata="https://mcp.wavix.com/.well-known/oauth-protected-resource/mcp" |
Protected resource metadata
| Document | https://mcp.wavix.com/.well-known/oauth-protected-resource/mcp |
|---|---|
| Retrieved | Yes |
| Resource | https://mcp.wavix.com/mcp |
| Authorisation server | https://app.wavix.com |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.wavix.com/mcp | Auth required | 401 | |
| http (plaintext) | http://mcp.wavix.com/mcp | HTTPS enforced | 301 | https://wavix.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
ten_dlc_brands_list ~217
Returns a paginated list of 10DLC brands. Filter results by date, name, legal name, and status. Results are limited to 25 records per page by default. Use `page` and `per_page` to navigate results.
| Name | Type | Req | Description |
|---|---|---|---|
| company_name | string | – | Company legal name. |
| country | string | – | Brand registration country. |
| created_after | string | – | Brand creation start date in `YYYY-MM-DD` format. |
| created_before | string | – | Brand creation end date in `YYYY-MM-DD` format. |
| dba_name | string | – | Brand name. |
| ein_taxid | string | – | EIN/Tax ID. |
| entity_type | string | – | Business entity type. |
| mock | boolean | – | Indicates whether to include mock brands only. |
| page | integer | – | Page number. |
| per_page | integer | – | Number of records per page. |
| show_deleted | boolean | – | Indicates whether to include deleted brands. |
| status | string | – | Brand identity verification status. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | – | yes | – |
No examples provided.
ten_dlc_brands_update ~409
Updates a 10DLC brand. Updating identity-related parameters, including `ein_taxid`, `ein_taxid_country`, and `entity_type`, resets the Brand status to `UNVERIFIED` and triggers automatic re-submission. Brands in `VETTED_VERIFIED` status or with active Campaigns cannot be updated.
| Name | Type | Req | Description |
|---|---|---|---|
| brand_id | string | yes | Brand ID. |
| city | string | – | The city name |
| company_name | string | – | Legal name of the company |
| country | string | – | 2-letter ISO country code the business address |
| dba_name | string | – | Brand name or DBA |
| ein_taxid | string | – | IRS Employee Identification Number (EIN) for US-based or foreign companies with EIN. The numeric portion of Tax ID for companies incorporated in other countries. |
| ein_taxid_country | string | – | 2-letter ISO country code of the Tax ID issuing country |
| string | – | The email address of the support contact | |
| entity_type | string | – | The company entity type |
| first_name | string | – | The first name of the business contact |
| last_name | string | – | The last name of the business contact |
| mock | boolean | – | Mock flag for testing (optional, defaults to false) |
| phone_number | string | – | The support contact telephone in E.164 format |
| state_or_province | string|null | – | State or province. For the United States, use 2 character codes. |
| stock_exchange | string|null | – | The stock exchange code. For PUBLIC_PROFIT Brands only. |
| stock_symbol | string|null | – | The stock symbol of the Brand. For PUBLIC_PROFIT Brands only. |
| street_address | string | – | Street name and house number |
| vertical | string | – | The segment the business operates in |
| website | string | – | The website of the business |
| zip | string | – | The business zip or postal code |
| Name | Type | Req | Description |
|---|---|---|---|
| result | – | yes | – |
No examples provided.
ten_dlc_campaign_numbers_link ~72
Links a phone number to a 10DLC Campaign. Wavix automatically creates a Sender ID once the number is approved.
| Name | Type | Req | Description |
|---|---|---|---|
| brand_id | string | yes | Brand ID. |
| campaign_id | string | yes | Campaign ID. |
| number | string | yes | Phone number to associate with the Campaign. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | – | yes | – |
No examples provided.
ten_dlc_campaign_numbers_list ~47
Returns a list of phone numbers associated with a 10DLC Campaign.
| Name | Type | Req | Description |
|---|---|---|---|
| brand_id | string | yes | Brand ID. |
| campaign_id | string | yes | Campaign ID. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | – | yes | – |
No examples provided.
ten_dlc_campaign_numbers_unlink ~65
Unlinks a phone number from a 10DLC Campaign. The associated Sender ID is also deleted.
| Name | Type | Req | Description |
|---|---|---|---|
| brand_id | string | yes | Brand ID. |
| campaign_id | string | yes | Campaign ID. |
| number | string | yes | Phone number to unlink. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | – | yes | – |
No examples provided.
ten_dlc_campaigns_list ~170
Returns a paginated list of 10DLC Campaigns. Filter results by date, status, and use case. Results are limited to 25 records per page by default. Use `page` and `per_page` to navigate results.
| Name | Type | Req | Description |
|---|---|---|---|
| created_after | string | – | Campaign creation start date in `YYYY-MM-DD` format. |
| created_before | string | – | Campaign creation end date in `YYYY-MM-DD` format. |
| mock | boolean | – | Indicates whether to include mock 10DLC Campaigns only. |
| name | string | – | Campaign name. |
| page | integer | – | Page number to retrieve. |
| per_page | integer | – | Number of records per page. |
| status | string | – | Campaign status. |
| usecase | string | – | Use case. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | – | yes | – |
No examples provided.
ten_dlc_campaigns_nudge ~191
Requests action on a pending or rejected 10DLC Campaign. Use `nudge_intent` to specify the action: - `REVIEW`: Request review for a pending Campaign. - `APPEAL_REJECTION`: Appeal a rejected Campaign. Note: - The Campaign must be at least 72 hours old. - Only one nudge request per Campaign is allowed every 24 hours.
| Name | Type | Req | Description |
|---|---|---|---|
| brand_id | string | yes | Brand ID. |
| campaign_id | string | yes | Campaign ID. |
| description | string | yes | Description of the nudge request. |
| nudge_intent | string | yes | Nudge intent. Allowed values: `REVIEW`, `APPEAL_REJECTION`. Use `nudge_intent` to specify the action: - `REVIEW`: Request review for a pending Campaign. - `APPEAL_REJECTION`: Appeal a rejected Campa… |
| Name | Type | Req | Description |
|---|---|---|---|
| result | – | yes | – |
No examples provided.
ten_dlc_subscriptions_create ~75
Subscribes to Wavix 10DLC event callbacks.
| Name | Type | Req | Description |
|---|---|---|---|
| subscription_category | string | yes | The Wavix 10DLC event type. Can be one of the following: `brand`, `campaign`, or `number`. |
| url | string | yes | A webhook URL to send events to |
| Name | Type | Req | Description |
|---|---|---|---|
| result | – | yes | – |
No examples provided.
ten_dlc_subscriptions_delete ~34
Deletes a 10DLC event subscription.
| Name | Type | Req | Description |
|---|---|---|---|
| subscription_category | string | yes | Event category to unsubscribe from. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | – | yes | – |
No examples provided.
ten_dlc_subscriptions_list ~23
Returns a list of 10DLC event subscriptions.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| result | array | yes | – |
No examples provided.
two_fa_events_list ~37
Returns a list of events for a specific 2FA Verification.
| Name | Type | Req | Description |
|---|---|---|---|
| session_id | string | yes | 2FA Verification ID. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | array | yes | – |
No examples provided.
two_fa_sessions_list ~72
Returns a list of 2FA verifications. Filter by service or date.
| Name | Type | Req | Description |
|---|---|---|---|
| from | string | yes | Start date in `YYYY-MM-DD` format. |
| service_id | string | yes | 2FA Service ID. |
| to | string | yes | End date in `YYYY-MM-DD` format. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | array | yes | – |
No examples provided.
two_fa_verification_cancel ~63
Cancels a 2FA verification. After cancellation, no additional codes are sent, and previously sent codes can no longer be validated. You must create a new verification to send another code.
| Name | Type | Req | Description |
|---|---|---|---|
| session_id | string | yes | 2FA Verification ID. |
| Name | Type | Req | Description |
|---|---|---|---|
| success | boolean | – | – |
No examples provided.
two_fa_verification_check ~45
Validates the verification code.
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | yes | The code entered by an end user |
| session_id | string | yes | 2FA Verification ID. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | – | yes | – |
No examples provided.
two_fa_verification_create ~218
Creates a new 2FA Verification and sends a one-time password (OTP) to the destination phone number. Before using this endpoint, create a 2FA Service in the Wavix portal. The service is created once and reused to generate and validate OTPs. OTP flow: 1. Create a Verification to generate and send an OTP. 2. Reuse the same Verification to resend the OTP if needed. 3. Validate the OTP using the 2FA API When a Verification is created, Wavix generates a random code and sends it to the destination phone number via the selected channel.
| Name | Type | Req | Description |
|---|---|---|---|
| channel | string | yes | The communication channel you want to use. Can be either `sms` or `voice`. |
| service_id | string | yes | Unique Wavix 2FA Service ID. Find your 2FA Service ID on the Wavix portal. |
| to | string | yes | End user's phone number to which the verification code will be sent. The phone number must be in E.164 format. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | – | yes | – |
No examples provided.
two_fa_verification_resend ~67
Resends the verification code using the specified channel. Previously sent codes are invalidated.
| Name | Type | Req | Description |
|---|---|---|---|
| channel | string | yes | The communication channel you want to use. Can be either `sms` or `voice`. |
| session_id | string | yes | 2FA Verification ID. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | – | yes | – |
No examples provided.
voice_campaigns_create ~31
Triggers an outbound call based on a pre-configured scenario.
| Name | Type | Req | Description |
|---|---|---|---|
| voice_campaign | object | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| voice_campaign | object | – | – |
No examples provided.
voice_campaigns_get ~26
Returns a specific voice campaign.
| Name | Type | Req | Description |
|---|---|---|---|
| id | integer | yes | Voice campaign ID. |
| Name | Type | Req | Description |
|---|---|---|---|
| voice_campaign | object | – | – |
No examples provided.
webrtc_tokens_create ~71
Creates a Wavix Embeddable widget token.
| Name | Type | Req | Description |
|---|---|---|---|
| payload | object|null | – | Arbitrary data to be associated with the token |
| sip_trunk | string | yes | SIP trunk name |
| ttl | integer|null | yes | Time to live in seconds. Pass `null` for no expiration. |
| Name | Type | Req | Description |
|---|---|---|---|
| payload | object|null | – | Arbitrary data associated with the token |
| sip_trunk | string | yes | SIP trunk name |
| token | string | yes | Wavix Embeddable Widget token. |
| ttl | integer|null | – | Time to live, in seconds |
| uuid | string | yes | Token ID |
No examples provided.
webrtc_tokens_delete ~53
Deletes a Wavix Embeddable widget token. After deletion, the token can't be used to authenticate widget sessions, and any active session associated with it is terminated.
| Name | Type | Req | Description |
|---|---|---|---|
| uuid | string | yes | Token ID |
| Name | Type | Req | Description |
|---|---|---|---|
| success | boolean | – | – |
No examples provided.
webrtc_tokens_get ~31
Returns a Wavix Embeddable widget token configuration.
| Name | Type | Req | Description |
|---|---|---|---|
| uuid | string | yes | Token ID. |
| Name | Type | Req | Description |
|---|---|---|---|
| payload | object|null | – | Arbitrary data associated with the token |
| sip_trunk | string | yes | SIP trunk name |
| ttl | integer|null | – | Time to live, in seconds. `null` means no expiration. |
| uuid | string | yes | Token ID |
No examples provided.
webrtc_tokens_list ~51
Returns a paginated list of active Wavix Embeddable widget tokens. Results are limited to 25 records per page by default. Use `page` and `per_page` to navigate results.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| items | array | – | – |
| pagination | object | – | – |
No examples provided.
webrtc_tokens_update ~49
Updates the payload for a Wavix Embeddable widget token.
| Name | Type | Req | Description |
|---|---|---|---|
| payload | object | yes | Arbitrary data to be associated with the token |
| uuid | string | yes | Token ID |
| Name | Type | Req | Description |
|---|---|---|---|
| payload | object|null | – | Arbitrary data associated with the token |
| sip_trunk | string | yes | SIP trunk name |
| ttl | integer|null | – | Time to live, in seconds. `null` means no expiration. |
| uuid | string | yes | Token ID |
No examples provided.
What is the Wavix MCP server?
Wavix is an MCP server listed in the public MCP registry as io.github.Wavix/mcp. Hosted MCP server for the Wavix telecom platform: SMS, voice, 2FA, SIP, numbers, 10DLC, CDRs. This page covers its hosted endpoint (https://mcp.wavix.com/mcp).
Is the Wavix MCP server safe to use?
Wavix scores 37 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Wavix MCP server expose?
Wavix exposes 122 tools: call_recording_get, billing_invoices_download, speech_analytics_file_get, ten_dlc_brand_evidence_get, api_keys_list, and 117 more. Their descriptions and schemas cost roughly 11,872 tokens of context every time the server is loaded.
Does the Wavix MCP server require authentication?
Yes. Wavix asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the Wavix MCP server still maintained?
Wavix is still listed as active in the MCP registry. We last reached this channel on 21 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.