Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Worklittle Jobs

REMOTE · MCP.WORKLITTLE.COM · SCANNED SEP 29

Swipe to apply for jobs and search over 4 million roles with visa, distance, and salary filters.

0 this week 65 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security46
Transport & Reachability100
Schema Quality & AI Usability80
  • 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
  • AI-judged instruction clarity (good).Pass
  • Context-footprint check failed: tool/resource definitions use about 3638 tokens (~139/item across 26 items; 14 tools + 12 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management39
  • Stability check failed: schema churn in the 30 days we've observed: 12 tool removals, 0 breaking changes, 0 auth/transport breaks, 6 additions. See how to fix → Fail
Tool Coverage88
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 58% of tool parameters carry a description.Partial
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • An AI judge read all 16 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a current MCP spec version (2026-07-28).Pass
  • Supports UI / widget rendering.Pass
Install

How do I install the Worklittle Jobs MCP server?

Worklittle Jobs is a hosted endpoint at https://mcp.worklittle.com/, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · mcp.worklittle.com

# add to Claude Code
claude mcp add --transport http worklittle-jobs 'https://mcp.worklittle.com/'
// .cursor/mcp.json
{
  "mcpServers": {
    "worklittle-jobs": {
      "url": "https://mcp.worklittle.com/"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "worklittle-jobs": {
      "type": "http",
      "url": "https://mcp.worklittle.com/"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.worklittle-jobs]
url = "https://mcp.worklittle.com/"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "worklittle-jobs": {
      "type": "remote",
      "url": "https://mcp.worklittle.com/",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add worklittle-jobs --url 'https://mcp.worklittle.com/' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  worklittle-jobs:
    url: "https://mcp.worklittle.com/"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "worklittle-jobs": {
      "Transport": "http",
      "Url": "https://mcp.worklittle.com/"
    }
  }
}
# add to Vellum
assistant mcp add worklittle-jobs -t streamable-http -u 'https://mcp.worklittle.com/'
// mcp.json
{
  "mcpServers": {
    "worklittle-jobs": {
      "type": "http",
      "url": "https://mcp.worklittle.com/"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 29 Sept 26 0
    • Resource “Jobs” now points somewhere else: ui://worklittle/jobs → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://worklittle/jobs.html → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://widget/jobs.html → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://widget/jobs-native.html → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://widget/jobs-ui.html → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://widget/jobs-deck.html → ui://widget/.html security
  • 28 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 27 Sept 26 0
    • Resource “Jobs” now points somewhere else: ui://worklittle/jobs → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://worklittle/jobs.html → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://widget/jobs.html → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://widget/jobs-native.html → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://widget/jobs-ui.html → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://widget/jobs-deck.html → ui://widget/.html security
  • 26 Sept 26 0
    • Resource “Jobs” now points somewhere else: ui://worklittle/jobs → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://worklittle/jobs.html → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://widget/jobs.html → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://widget/jobs-native.html → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://widget/jobs-ui.html → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://widget/jobs-deck.html → ui://widget/.html security
  • 25 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 24 Sept 26 0
    • Resource “Jobs” now points somewhere else: ui://worklittle/jobs → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://worklittle/jobs.html → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://widget/jobs.html → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://widget/jobs-native.html → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://widget/jobs-ui.html → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://widget/jobs-deck.html → ui://widget/.html security
  • 23 Sept 26 0
    • Resource “Jobs” now points somewhere else: ui://worklittle/jobs → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://worklittle/jobs.html → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://widget/jobs.html → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://widget/jobs-native.html → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://widget/jobs-ui.html → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://widget/jobs-deck.html → ui://widget/.html security
  • 22 Sept 26 +1
    • Resource “Jobs” now points somewhere else: ui://worklittle/jobs → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://worklittle/jobs.html → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://widget/jobs.html → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://widget/jobs-native.html → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://widget/jobs-ui.html → ui://widget/.html security
    • Resource “Jobs” now points somewhere else: ui://widget/jobs-deck.html → ui://widget/.html security
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 29 Sept 2026 · Probed https://mcp.worklittle.com/

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=worklittle.com CN=WE1,O=Google Trust Services,C=US 23 Sept 2026 22 Dec 2026 ECDSA 256 ECDSA-SHA256 163bbba946f453b30e711d7b66d4b31f
SANs: worklittle.com, mcp.worklittle.com, *.mcp.worklittle.com
CN=WE1,O=Google Trust Services,C=US (CA) CN=GTS Root R4,O=Google Trust Services LLC,C=US 13 Dec 2023 20 Feb 2029 ECDSA 256 ECDSA-SHA384 7ff31977972c224a76155d13b6d685e3
CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE 15 Nov 2023 28 Jan 2028 ECDSA 384 SHA256-RSA 7fe530bf331343bedd821610493d8a1b

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of mcp.worklittle.com. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
worklittle.com. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://mcp.worklittle.com/ Verified 200
http (plaintext) http://mcp.worklittle.com/ Served over HTTP 200
MCP tools · 14 exposed · ~3,284 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
apply_for_job ~115

Jobs — Start applying to a catalog job (browser session) or submit a hosted Worklittle application. Pass job_id. Include name, email, and resume when applying to a hosted posting.

NameTypeReqDescription
auto_submitboolean–Ignored on API keys. Sessions started with a key always submit.
cover_letter_htmlstring–Optional cover letter HTML to seed.
job_idstringyesWorklittle job id from search_jobs / get_job_details.
resume_htmlstring–Optional resume HTML to seed.

Structured output declared, but exposes no named fields.

No examples provided.

delete_applied_job ~50

Jobs — Remove a job from the API key owner's personal saved-jobs pipeline (unheart / remove from Saved).

NameTypeReqDescription
job_idstringyesWorklittle job id to remove from the pipeline.
NameTypeReqDescription
deletedboolean––
okboolean––

No examples provided.

delete_resume ~32

Jobs — Delete the connected account's profile resume file. Used by Job Cards You/Settings. Requires jobs:apply.

Input schema present but exposes no named parameters.

NameTypeReqDescription
deletedboolean––
okboolean––

No examples provided.

get_account ~54

Jobs — Return the connected Worklittle account when the user already linked via Connect. If they have not connected, return connected: false. Do not call this to search jobs, and do not ask them to Connect just to browse.

Input schema present but exposes no named parameters.

Structured output declared, but exposes no named fields.

No examples provided.

get_job_details ~170

Jobs — Fetch detailed information about a specific job, including full responsibilities, qualifications, and company details. Pass job_id from search_jobs when you have one. If the user asks for full details of a role without an id (e.g. the first software engineer job in Austin), pass query and optional location instead — the tool loads the first matching live listing.

NameTypeReqDescription
job_idstring–The job ID from a previous search_jobs result when available.
locationstring–Optional location substring when resolving details by query.
querystring–Role/title search used when job_id is missing (picks the first live match).
summaryboolean–If true, request first-time AI generation via GET /jobs/:id?summary=true. Default is raw plus cached AI only.
NameTypeReqDescription
company_namestring––
descriptionstring––
idstring––
locationstring––
titlestring––
urlstring––

No examples provided.

get_job_keywords ~149

Jobs — Get skill and technology keywords from live Worklittle job data. Pass job_id for one posting. If the user asks what keywords show up for a role (resume tailoring, 'data scientist jobs', applications) and you do not have a job_id, pass query instead (optional location). Returns keywords plus keyword_count. Do not require a prior search when the question is about a role in general.

NameTypeReqDescription
job_idstring–Job ID from search_jobs when keywords are for one listing.
locationstring–Optional location substring when aggregating by query.
querystring–Role or title phrase when aggregating common keywords across live jobs (e.g. data scientist).

Structured output declared, but exposes no named fields.

No examples provided.

get_market_overview ~140

Jobs — Returns aggregate job-market statistics from Worklittle. Call with no args for the full indexed market (counts, workplace mix, top hiring companies). When the user names a role and/or city (e.g. product managers in San Francisco), pass query and location. The filtered slice includes match count, top companies in the sample, and salary signals from listings that publish pay.

NameTypeReqDescription
locationstring–Location substring for a market slice (e.g. San Francisco).
querystring–Role or title filter for a market slice (e.g. product manager).
workplace_typestring–Optional workplace filter for the slice.
NameTypeReqDescription
top_companiesarray––
total_jobsnumber––

No examples provided.

get_resume ~33

Jobs — Poll profile resume processing status after upload_profile_resume (ready | processing | idle | missing). Job Cards analyzing phase.

Input schema present but exposes no named parameters.

Structured output declared, but exposes no named fields.

No examples provided.

load_more_job_cards ~269

Jobs — Fetch Job Cards for the current search (same filters as search_jobs). Omit cursor for the first page; pass next_cursor to page. Used by the Job Cards widget. Do not call from the model.

NameTypeReqDescription
companystring–Same as search_jobs: bare slug include OR; leading '-' excludes (e.g. -lucid-motors).
countrystring––
cursorstring–next_cursor from the previous search_jobs / load_more_job_cards response. Omit for the first page.
description_languagestring––
employment_typestring––
exclude_idsstring–Comma-separated job IDs already in the deck (dedupe).
exclude_remoteboolean––
keywordsstring––
limitnumber––
locationstring––
location_orstring––
near_latnumber––
near_lngnumber––
posted_within_daysnumber––
querystring––
radius_kmnumber––
salary_minnumber––
seniority_levelstring––
visa_sponsorshipstring––
workplace_typestring––

Structured output declared, but exposes no named fields.

No examples provided.

search_companies ~166

Jobs — Search the Worklittle market company index by name or slug (ranked typeahead). Returns id, name, slug, logo_url, and enrichment fields for employers with open jobs. Use when the user names an employer and you need a real slug/id for search_jobs company= filters, job alerts, or automations. If zero hits, try alternate spellings or related employer names from further search_companies calls — do not invent company ids or slugs. If still empty, tell the user that employer is not in the index yet and offer any close matches you found.

NameTypeReqDescription
limitnumber–Max results to return. Default 5, max 20.
qstringyesCompany name or slug query (min 2 characters, max 80).

Structured output declared, but exposes no named fields.

No examples provided.

search_jobs ~1,598

Jobs — Search Worklittle job listings. People say Worklittle plus a role, city, company, or filters (or just 'jobs') — they will not name this tool. Call it whenever they want Worklittle jobs. Search by keyword, company, location, job type, seniority, or recency. Use for ANY industry (retail, finance, healthcare, tech, etc.). Search matches title and filter text (substring / FTS), not vector embeddings. Role / title text goes in query (+ optional keywords). The API matches job TITLE substrings only for that text — it does not mix company names into the same field. Preserve negative title terms with a leading dash, e.g. 'software engineer, -senior' excludes titles containing senior. Use company for employer slugs (include or exclude). Never concatenate many job titles into one query unless the user supplied comma-separated roles. Do not add seniority_level, stacks, or resume-derived terms unless they asked. Omit seniority_level unless they explicitly name a level as an inclusion filter (never infer from profile). Expand abbreviations only; umbrella phrases use neutral roles and/or company slugs. Umbrella or vague phrases ('big tech', 'FAANG', 'top retailers'): interpret intent, then one search_jobs with comma-separated company slugs and/or a broad role query — prefer one API call over many. company MUST be employer slug(s): bare slugs include (OR), e.g. meta,google,apple. Prefix a slug with '-' to exclude, e.g. -lucid-motors,-tesla. Same leading-dash rule as title negatives, but in company not query. Expand 'no car companies' / 'don't show Lucid' into -slug tokens. Never pass display names as query. If unsure of slug, try lowercase hyphenated brand. Add skills or stack to query/keywords only when the user mentioned them — not from profile by default. When an include company filter returns 0 results, try a broader query (drop include company, use role keywords) before telling the user nothing matched. Pass cursor from a previous response to paginate. Search is anonym…

NameTypeReqDescription
companystring–Employer slug(s): bare slug or comma-separated OR include (e.g. meta,google,apple). Prefix with '-' to exclude (e.g. -lucid-motors,-tesla). Mix allowed (meta,google,-amazon). Lowercase hyphenated. Mi…
countrystring–ISO 3166-1 alpha-2 country filter (e.g. US, GB, DE). Returns jobs in that country or workplace_type remote.
cursorstring–Pagination cursor from a previous search_jobs response to fetch the next page.
description_languagestring–ISO 639-1 code for the language of the job posting body. Examples: en, es, de, fr, pt.
employment_typestring–Type of employment contract.
exclude_idsstring–Comma-separated job IDs to exclude (e.g. postings already shown in the conversation).
exclude_remoteboolean–When using near_lat/near_lng: false includes remote-only jobs; true (default) excludes them so results are geographically local.
keywordsstring–Only if the user named skills or stacks in this turn. Omit by default — do not pull from resume or profile.
limitnumber–Number of results to return. Default 10, max 50.
locationstring–Text filter on job location strings (partial match). For metro-area or 'near me' intent, prefer near_lat + near_lng + radius_km (50–65 km typical) so results are not tied to one city spelling. Use lo…
location_orstring–Comma-separated place substrings when the user names two or more metros at once (e.g. San Francisco,New York). The API returns jobs whose location text matches ANY term. Mutually exclusive with dista…
near_latnumber–Latitude for distance search. Use with near_lng. Typical source: browser geolocation or geocoded city.
near_lngnumber–Longitude for distance search. Required with near_lat.
posted_within_daysnumber–Days of posted-date lookback. Omit → default 14. 0 → no cutoff (any age). 1 → today/last 24h. 7 → this week. Any positive integer allowed (e.g. 90, 365). Never encode recency words in query.
querystring–Job title or role phrase (merged with keywords). Sent as API title= — matches job TITLE text only, separate from company. Preserve negative title terms with a leading dash, e.g. 'product manager, sof…
radius_kmnumber–Radius in kilometers around near_lat/near_lng. Default 50, max 500.
salary_minnumber–Minimum annual salary in the job's listed currency. Only returns jobs where a salary is known and meets this threshold. Examples: 100000, 150000.
seniority_levelstring–Omit unless the user explicitly asked for a band. Never infer from profile. Enum when set:
visa_sponsorshipstring–Filter by explicit visa sponsorship text in the posting (AI-extracted). Use 'yes' for jobs that sponsor visas (H-1B, etc.). Use 'no' only when the user wants roles that explicitly state no sponsorshi…
workplace_typestring–Work arrangement.
NameTypeReqDescription
cursorstring|null–Pagination cursor for the next page.
jobsarray–Matching job listings.
locationstring––
near_latnumber––
near_lngnumber––
querystring––
searchobject–Echo of search_jobs filters for the Job Cards widget.
totalnumber–Total matches when provided by the API.

No examples provided.

track_applied_job ~161

Jobs — Record that the API key owner saved, applied to, clicked Apply, or skipped a job. Use status saved for heart/save and skipped for deck Skip. Defaults to in_progress (apply / apply_with_ai) or applied (api).

NameTypeReqDescription
apply_urlstring–Optional employer apply URL.
company_namestringyes–
job_idstringyesWorklittle job id from search_jobs or get_job_details.
job_titlestringyes–
methodstring–How the user applied. Defaults to apply.
statusstring–Pipeline stage when known. Use saved for heart/save, skipped for Job Cards / deck Skip. Defaults to in_progress for apply / apply_with_ai, applied for api.

Structured output declared, but exposes no named fields.

No examples provided.

update_account ~246

Jobs — Patch the connected account's Settings profile fields (name, school, desired role, phone, links, work authorization, driver's license, interests). Used by Job Cards You overlay. Requires jobs:apply. Syncs to cloud for worklittle.com.

NameTypeReqDescription
drivers_licensestring–valid | none | empty to clear
facebook_urlstring––
github_urlstring––
huggingface_urlstring––
instagram_urlstring––
linkedin_urlstring––
personal_website_urlstring––
phonestring––
phone_country_isostring––
phone_nationalstring––
profile_clear_fieldsarray–Field names to clear when empty
school_degreestring––
tiktok_urlstring––
work_authorization_countriesarray–ISO2 country codes
x_urlstring––
you_interestsstring––
you_namestring––
you_schoolstring––
you_workstring––
youtube_urlstring––

Structured output declared, but exposes no named fields.

No examples provided.

upload_resume ~101

Jobs — Upload the connected account's profile resume file (PDF, Word, text, or image). Used by Job Cards Apply resume gate before start_apply_with_ai. Requires jobs:apply.

NameTypeReqDescription
content_base64stringyesBase64-encoded file bytes (data: URLs accepted; strip prefix ok).
filenamestringyesOriginal file name, e.g. resume.pdf
mimestring–MIME type, e.g. application/pdf

Structured output declared, but exposes no named fields.

No examples provided.

Common questions

What is the Worklittle Jobs MCP server?

Worklittle Jobs is an MCP server listed in the public MCP registry as io.github.worklittle/jobs. Swipe to apply for jobs and search over 4 million roles with visa, distance, and salary filters. This page covers its hosted endpoint (https://mcp.worklittle.com/).

Is the Worklittle Jobs MCP server safe to use?

Worklittle Jobs scores 65 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Worklittle Jobs MCP server expose?

Worklittle Jobs exposes 14 tools: search_jobs, search_companies, load_more_job_cards, get_job_details, get_job_keywords, and 9 more. Their descriptions and schemas cost roughly 3,284 tokens of context every time the server is loaded.

Does the Worklittle Jobs MCP server require authentication?

No. We connected to Worklittle Jobs without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the Worklittle Jobs MCP server still maintained?

Worklittle Jobs is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.