# Worklittle Jobs (remote · mcp.worklittle.com)

Swipe to apply for jobs and search over 4 million roles with visa, distance, and salary filters.

- Trust score: 65/100 (medium)
- Change this week: 0
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-29

## Components

- remote · `mcp.worklittle.com`: 65/100 (this document), [markdown](https://verifymcp.io/servers/worklittle-jobs/mcp.md), [page](https://verifymcp.io/servers/worklittle-jobs/mcp)

## Channel facts

- Endpoint: `https://mcp.worklittle.com/`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.0.1`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-29.

- **Endpoint Security**: 46/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (delete_applied_job).
  - HTTPS check failed: the endpoint is reachable over plaintext HTTP.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 80/100
  - 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).
  - AI-judged instruction clarity (good).
  - Context-footprint check failed: tool/resource definitions use about 3638 tokens (~139/item across 26 items; 14 tools + 12 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 39/100
  - Stability check failed: schema churn in the 30 days we've observed: 12 tool removals, 0 breaking changes, 0 auth/transport breaks, 6 additions.
- **Tool Coverage**: 88/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 58% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - All 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.
  - An AI judge read all 16 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a current MCP spec version (2026-07-28).
  - Supports UI / widget rendering.

## Install

### How do I install the Worklittle Jobs MCP server?

Worklittle Jobs is a hosted endpoint at https://mcp.worklittle.com/, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http worklittle-jobs 'https://mcp.worklittle.com/'
```

### Cursor

```json
{
  "mcpServers": {
    "worklittle-jobs": {
      "url": "https://mcp.worklittle.com/"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "worklittle-jobs": {
      "type": "http",
      "url": "https://mcp.worklittle.com/"
    }
  }
}
```

### Codex

```toml
[mcp_servers.worklittle-jobs]
url = "https://mcp.worklittle.com/"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "worklittle-jobs": {
      "type": "remote",
      "url": "https://mcp.worklittle.com/",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add worklittle-jobs --url 'https://mcp.worklittle.com/' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  worklittle-jobs:
    url: "https://mcp.worklittle.com/"
```

### Netclaw

```json
{
  "McpServers": {
    "worklittle-jobs": {
      "Transport": "http",
      "Url": "https://mcp.worklittle.com/"
    }
  }
}
```

### Vellum

```bash
assistant mcp add worklittle-jobs -t streamable-http -u 'https://mcp.worklittle.com/'
```

### Other

```json
{
  "mcpServers": {
    "worklittle-jobs": {
      "type": "http",
      "url": "https://mcp.worklittle.com/"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-29 (score 65, 0)

- [security] Resource “Jobs” now points somewhere else: ui://worklittle/jobs → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://worklittle/jobs.html → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://widget/jobs.html → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://widget/jobs-native.html → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://widget/jobs-ui.html → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://widget/jobs-deck.html → ui://widget/.html

### 2026-09-28 (score 65, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-27 (score 65, 0)

- [security] Resource “Jobs” now points somewhere else: ui://worklittle/jobs → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://worklittle/jobs.html → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://widget/jobs.html → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://widget/jobs-native.html → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://widget/jobs-ui.html → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://widget/jobs-deck.html → ui://widget/.html

### 2026-09-26 (score 65, 0)

- [security] Resource “Jobs” now points somewhere else: ui://worklittle/jobs → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://worklittle/jobs.html → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://widget/jobs.html → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://widget/jobs-native.html → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://widget/jobs-ui.html → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://widget/jobs-deck.html → ui://widget/.html

### 2026-09-25 (score 65, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-24 (score 65, 0)

- [security] Resource “Jobs” now points somewhere else: ui://worklittle/jobs → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://worklittle/jobs.html → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://widget/jobs.html → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://widget/jobs-native.html → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://widget/jobs-ui.html → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://widget/jobs-deck.html → ui://widget/.html

### 2026-09-23 (score 65, 0)

- [security] Resource “Jobs” now points somewhere else: ui://worklittle/jobs → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://worklittle/jobs.html → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://widget/jobs.html → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://widget/jobs-native.html → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://widget/jobs-ui.html → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://widget/jobs-deck.html → ui://widget/.html

### 2026-09-22 (score 65, +1)

- [security] Resource “Jobs” now points somewhere else: ui://worklittle/jobs → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://worklittle/jobs.html → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://widget/jobs.html → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://widget/jobs-native.html → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://widget/jobs-ui.html → ui://widget/.html
- [security] Resource “Jobs” now points somewhere else: ui://widget/jobs-deck.html → ui://widget/.html

## MCP tools (14)

### `search_jobs` (~1598 tokens)

Jobs · Search Jobs

Jobs — Search Worklittle job listings. People say Worklittle plus a role, city, company, or filters (or just 'jobs') — they will not name this tool. Call it whenever they want Worklittle jobs. Search by keyword, company, location, job type, seniority, or recency. Use for ANY industry (retail, finance, healthcare, tech, etc.). Search matches title and filter text (substring / FTS), not vector embeddings. Role / title text goes in query (+ optional keywords). The API matches job TITLE substrings only for that text — it does not mix company names into the same field. Preserve negative title terms with a leading dash, e.g. 'software engineer, -senior' excludes titles containing senior. Use company for employer slugs (include or exclude). Never concatenate many job titles into one query unless the user supplied comma-separated roles. Do not add seniority_level, stacks, or resume-derived terms unless they asked. Omit seniority_level unless they explicitly name a level as an inclusion filter (never infer from profile). Expand abbreviations only; umbrella phrases use neutral roles and/or company slugs. Umbrella or vague phrases ('big tech', 'FAANG', 'top retailers'): interpret intent, then one search_jobs with comma-separated company slugs and/or a broad role query — prefer one API call over many. company MUST be employer slug(s): bare slugs include (OR), e.g. meta,google,apple. Prefix a slug with '-' to exclude, e.g. -lucid-motors,-tesla. Same leading-dash rule as title negatives, but in company not query. Expand 'no car companies' / 'don't show Lucid' into -slug tokens. Never pass display names as query. If unsure of slug, try lowercase hyphenated brand. Add skills or stack to query/keywords only when the user mentioned them — not from profile by default. When an include company filter returns 0 results, try a broader query (drop include company, use role keywords) before telling the user nothing matched. Pass cursor from a previous response to paginate. Search is anonym…

Input parameters:

- `company` (string): Employer slug(s): bare slug or comma-separated OR include (e.g. meta,google,apple). Prefix with '-' to exclude (e.g. -lucid-motors,-tesla). Mix allowed (meta,google,-amazon). Lowercase hyphenated. Mi…
- `country` (string): ISO 3166-1 alpha-2 country filter (e.g. US, GB, DE). Returns jobs in that country or workplace_type remote.
- `cursor` (string): Pagination cursor from a previous search_jobs response to fetch the next page.
- `description_language` (string): ISO 639-1 code for the language of the job posting body. Examples: en, es, de, fr, pt.
- `employment_type` (string): Type of employment contract.
- `exclude_ids` (string): Comma-separated job IDs to exclude (e.g. postings already shown in the conversation).
- `exclude_remote` (boolean): When using near_lat/near_lng: false includes remote-only jobs; true (default) excludes them so results are geographically local.
- `keywords` (string): Only if the user named skills or stacks in this turn. Omit by default — do not pull from resume or profile.
- `limit` (number): Number of results to return. Default 10, max 50.
- `location` (string): Text filter on job location strings (partial match). For metro-area or 'near me' intent, prefer near_lat + near_lng + radius_km (50–65 km typical) so results are not tied to one city spelling. Use lo…
- `location_or` (string): Comma-separated place substrings when the user names two or more metros at once (e.g. San Francisco,New York). The API returns jobs whose location text matches ANY term. Mutually exclusive with dista…
- `near_lat` (number): Latitude for distance search. Use with near_lng. Typical source: browser geolocation or geocoded city.
- `near_lng` (number): Longitude for distance search. Required with near_lat.
- `posted_within_days` (number): Days of posted-date lookback. Omit → default 14. 0 → no cutoff (any age). 1 → today/last 24h. 7 → this week. Any positive integer allowed (e.g. 90, 365). Never encode recency words in query.
- `query` (string): Job title or role phrase (merged with keywords). Sent as API title= — matches job TITLE text only, separate from company. Preserve negative title terms with a leading dash, e.g. 'product manager, sof…
- `radius_km` (number): Radius in kilometers around near_lat/near_lng. Default 50, max 500.
- `salary_min` (number): Minimum annual salary in the job's listed currency. Only returns jobs where a salary is known and meets this threshold. Examples: 100000, 150000.
- `seniority_level` (string): Omit unless the user explicitly asked for a band. Never infer from profile. Enum when set:
- `visa_sponsorship` (string): Filter by explicit visa sponsorship text in the posting (AI-extracted). Use 'yes' for jobs that sponsor visas (H-1B, etc.). Use 'no' only when the user wants roles that explicitly state no sponsorshi…
- `workplace_type` (string): Work arrangement.

Output parameters:

- `cursor` (string|null): Pagination cursor for the next page.
- `jobs` (array): Matching job listings.
- `location` (string)
- `near_lat` (number)
- `near_lng` (number)
- `query` (string)
- `search` (object): Echo of search_jobs filters for the Job Cards widget.
- `total` (number): Total matches when provided by the API.

### `search_companies` (~166 tokens)

Jobs · Search Companies

Jobs — Search the Worklittle market company index by name or slug (ranked typeahead). Returns id, name, slug, logo_url, and enrichment fields for employers with open jobs. Use when the user names an employer and you need a real slug/id for search_jobs company= filters, job alerts, or automations. If zero hits, try alternate spellings or related employer names from further search_companies calls — do not invent company ids or slugs. If still empty, tell the user that employer is not in the index yet and offer any close matches you found.

Input parameters:

- `limit` (number): Max results to return. Default 5, max 20.
- `q` (string, required): Company name or slug query (min 2 characters, max 80).

### `load_more_job_cards` (~269 tokens)

Jobs · Load More Job Cards

Jobs — Fetch Job Cards for the current search (same filters as search_jobs). Omit cursor for the first page; pass next_cursor to page. Used by the Job Cards widget. Do not call from the model.

Input parameters:

- `company` (string): Same as search_jobs: bare slug include OR; leading '-' excludes (e.g. -lucid-motors).
- `country` (string)
- `cursor` (string): next_cursor from the previous search_jobs / load_more_job_cards response. Omit for the first page.
- `description_language` (string)
- `employment_type` (string)
- `exclude_ids` (string): Comma-separated job IDs already in the deck (dedupe).
- `exclude_remote` (boolean)
- `keywords` (string)
- `limit` (number)
- `location` (string)
- `location_or` (string)
- `near_lat` (number)
- `near_lng` (number)
- `posted_within_days` (number)
- `query` (string)
- `radius_km` (number)
- `salary_min` (number)
- `seniority_level` (string)
- `visa_sponsorship` (string)
- `workplace_type` (string)

### `get_job_details` (~170 tokens)

Jobs · Get Job Details

Jobs — Fetch detailed information about a specific job, including full responsibilities, qualifications, and company details. Pass job_id from search_jobs when you have one. If the user asks for full details of a role without an id (e.g. the first software engineer job in Austin), pass query and optional location instead — the tool loads the first matching live listing.

Input parameters:

- `job_id` (string): The job ID from a previous search_jobs result when available.
- `location` (string): Optional location substring when resolving details by query.
- `query` (string): Role/title search used when job_id is missing (picks the first live match).
- `summary` (boolean): If true, request first-time AI generation via GET /jobs/:id?summary=true. Default is raw plus cached AI only.

Output parameters:

- `company_name` (string)
- `description` (string)
- `id` (string)
- `location` (string)
- `title` (string)
- `url` (string)

### `get_job_keywords` (~149 tokens)

Jobs · Get Job Keywords

Jobs — Get skill and technology keywords from live Worklittle job data. Pass job_id for one posting. If the user asks what keywords show up for a role (resume tailoring, 'data scientist jobs', applications) and you do not have a job_id, pass query instead (optional location). Returns keywords plus keyword_count. Do not require a prior search when the question is about a role in general.

Input parameters:

- `job_id` (string): Job ID from search_jobs when keywords are for one listing.
- `location` (string): Optional location substring when aggregating by query.
- `query` (string): Role or title phrase when aggregating common keywords across live jobs (e.g. data scientist).

### `get_market_overview` (~140 tokens)

Jobs · Get Market Overview

Jobs — Returns aggregate job-market statistics from Worklittle. Call with no args for the full indexed market (counts, workplace mix, top hiring companies). When the user names a role and/or city (e.g. product managers in San Francisco), pass query and location. The filtered slice includes match count, top companies in the sample, and salary signals from listings that publish pay.

Input parameters:

- `location` (string): Location substring for a market slice (e.g. San Francisco).
- `query` (string): Role or title filter for a market slice (e.g. product manager).
- `workplace_type` (string): Optional workplace filter for the slice.

Output parameters:

- `top_companies` (array)
- `total_jobs` (number)

### `track_applied_job` (~161 tokens)

Jobs · Track Applied Job

Jobs — Record that the API key owner saved, applied to, clicked Apply, or skipped a job. Use status saved for heart/save and skipped for deck Skip. Defaults to in_progress (apply / apply_with_ai) or applied (api).

Input parameters:

- `apply_url` (string): Optional employer apply URL.
- `company_name` (string, required)
- `job_id` (string, required): Worklittle job id from search_jobs or get_job_details.
- `job_title` (string, required)
- `method` (string): How the user applied. Defaults to apply.
- `status` (string): Pipeline stage when known. Use saved for heart/save, skipped for Job Cards / deck Skip. Defaults to in_progress for apply / apply_with_ai, applied for api.

### `delete_applied_job` (~50 tokens)

Jobs · Delete Applied Job

Jobs — Remove a job from the API key owner's personal saved-jobs pipeline (unheart / remove from Saved).

Input parameters:

- `job_id` (string, required): Worklittle job id to remove from the pipeline.

Output parameters:

- `deleted` (boolean)
- `ok` (boolean)

### `get_account` (~54 tokens)

Jobs · Get Account

Jobs — Return the connected Worklittle account when the user already linked via Connect. If they have not connected, return connected: false. Do not call this to search jobs, and do not ask them to Connect just to browse.

### `upload_resume` (~101 tokens)

Jobs · Upload Resume

Jobs — Upload the connected account's profile resume file (PDF, Word, text, or image). Used by Job Cards Apply resume gate before start_apply_with_ai. Requires jobs:apply.

Input parameters:

- `content_base64` (string, required): Base64-encoded file bytes (data: URLs accepted; strip prefix ok).
- `filename` (string, required): Original file name, e.g. resume.pdf
- `mime` (string): MIME type, e.g. application/pdf

### `get_resume` (~33 tokens)

Jobs · Get Resume

Jobs — Poll profile resume processing status after upload_profile_resume (ready | processing | idle | missing). Job Cards analyzing phase.

### `delete_resume` (~32 tokens)

Jobs · Delete Resume

Jobs — Delete the connected account's profile resume file. Used by Job Cards You/Settings. Requires jobs:apply.

Output parameters:

- `deleted` (boolean)
- `ok` (boolean)

### `update_account` (~246 tokens)

Jobs · Update Account

Jobs — Patch the connected account's Settings profile fields (name, school, desired role, phone, links, work authorization, driver's license, interests). Used by Job Cards You overlay. Requires jobs:apply. Syncs to cloud for worklittle.com.

Input parameters:

- `drivers_license` (string): valid | none | empty to clear
- `facebook_url` (string)
- `github_url` (string)
- `huggingface_url` (string)
- `instagram_url` (string)
- `linkedin_url` (string)
- `personal_website_url` (string)
- `phone` (string)
- `phone_country_iso` (string)
- `phone_national` (string)
- `profile_clear_fields` (array): Field names to clear when empty
- `school_degree` (string)
- `tiktok_url` (string)
- `work_authorization_countries` (array): ISO2 country codes
- `x_url` (string)
- `you_interests` (string)
- `you_name` (string)
- `you_school` (string)
- `you_work` (string)
- `youtube_url` (string)

### `apply_for_job` (~115 tokens)

Jobs · Apply For Job

Jobs — Start applying to a catalog job (browser session) or submit a hosted Worklittle application. Pass job_id. Include name, email, and resume when applying to a hosted posting.

Input parameters:

- `auto_submit` (boolean): Ignored on API keys. Sessions started with a key always submit.
- `cover_letter_html` (string): Optional cover letter HTML to seed.
- `job_id` (string, required): Worklittle job id from search_jobs / get_job_details.
- `resume_html` (string): Optional resume HTML to seed.

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/worklittle-jobs/mcp#diagnostics

## Score history

- 2026-09-29: 65
- 2026-09-28: 65
- 2026-09-27: 65
- 2026-09-26: 65
- 2026-09-25: 65
- 2026-09-24: 65
- 2026-09-23: 65
- 2026-09-22: 65
- 2026-09-21: 64
- 2026-09-20: 64
- 2026-09-19: 63
- 2026-09-18: 63
- 2026-09-17: 63
- 2026-09-16: 62
- 2026-09-15: 62
- 2026-09-14: 61
- 2026-09-13: 60
- 2026-09-12: 60
- 2026-09-11: 60
- 2026-09-10: 60
- 2026-09-09: 60
- 2026-09-08: 60
- 2026-09-07: 60
- 2026-09-06: 60
- 2026-09-05: 60
- 2026-09-04: 60
- 2026-09-03: 60
- 2026-09-02: 64
- 2026-09-01: 64
- 2026-08-31: 63

## Common questions

### What is the Worklittle Jobs MCP server?

Worklittle Jobs is an MCP server listed in the public MCP registry as io.github.worklittle/jobs. Swipe to apply for jobs and search over 4 million roles with visa, distance, and salary filters. This page covers its hosted endpoint (https://mcp.worklittle.com/).

### Is the Worklittle Jobs MCP server safe to use?

Worklittle Jobs scores 65 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Worklittle Jobs MCP server expose?

Worklittle Jobs exposes 14 tools: search_jobs, search_companies, load_more_job_cards, get_job_details, get_job_keywords, and 9 more. Their descriptions and schemas cost roughly 3,284 tokens of context every time the server is loaded.

### Does the Worklittle Jobs MCP server require authentication?

No. We connected to Worklittle Jobs without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the Worklittle Jobs MCP server still maintained?

Worklittle Jobs is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://mcp.worklittle.com/
- Website: https://docs.worklittle.com/mcp
- Changelog RSS feed: https://verifymcp.io/servers/worklittle-jobs/mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/worklittle-jobs/mcp.json
- HTML version of this page: https://verifymcp.io/servers/worklittle-jobs/mcp
