Linty
REMOTE · MCP.LINTY.XYZ
Find food, beverage and pet brands that sell direct, and where to apply for a wholesale account.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
No category breakdown is available for this channel yet.
How do I install the Linty MCP server?
Linty is a hosted endpoint at https://mcp.linty.xyz/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.linty.xyz
claude mcp add --transport http xyz-linty-linty 'https://mcp.linty.xyz/mcp'
{
"mcpServers": {
"xyz-linty-linty": {
"url": "https://mcp.linty.xyz/mcp"
}
}
} {
"servers": {
"xyz-linty-linty": {
"type": "http",
"url": "https://mcp.linty.xyz/mcp"
}
}
} [mcp_servers.xyz-linty-linty] url = "https://mcp.linty.xyz/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"xyz-linty-linty": {
"type": "remote",
"url": "https://mcp.linty.xyz/mcp",
"enabled": true
}
}
} openclaw mcp add xyz-linty-linty --url 'https://mcp.linty.xyz/mcp' --transport streamable-http
mcp_servers:
xyz-linty-linty:
url: "https://mcp.linty.xyz/mcp" {
"McpServers": {
"xyz-linty-linty": {
"Transport": "http",
"Url": "https://mcp.linty.xyz/mcp"
}
}
} assistant mcp add xyz-linty-linty -t streamable-http -u 'https://mcp.linty.xyz/mcp'
{
"mcpServers": {
"xyz-linty-linty": {
"type": "http",
"url": "https://mcp.linty.xyz/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
We have not recorded any changes for this component yet
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 9 Oct 2026 · Probed https://mcp.linty.xyz/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=mcp.linty.xyz | CN=YR2,O=Let's Encrypt,C=US | 6 Oct 2026 | 4 Jan 2027 | RSA 2048 | SHA256-RSA | 6ae5dd0535f234f7bddca5ba1c48a2f7352 |
| SANs: mcp.linty.xyz | ||||||
| CN=YR2,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | 4ebd24947e24d394802d84a52fd5b319 |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.linty.xyz. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| xyz. | present | 3599, 18130 | 8, 8 | Verified |
| linty.xyz. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000 |
| x-content-type-options | nosniff |
| referrer-policy | strict-origin-when-cross-origin |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.linty.xyz/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.linty.xyz/mcp | HTTPS enforced | 308 | https://mcp.linty.xyz/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
find_brands Find brands ~239
Find food, beverage and pet brands, and see where to apply to each for a wholesale account. Filter by text, category path, country, availability or `submittable`. `submittable` is true when the brand has an active web form at its address. It is false when a `robots.txt` file asks Linty not to use the page, or a part of the page where the form can be. Each page has up to 50 brands. To get the next page, send `next_cursor` as `cursor`.
| Name | Type | Req | Description |
|---|---|---|---|
| availability | string | – | – |
| category | string | – | A category path, for example `snacks/protein-bars`. |
| country | string | – | A two-letter country code in capitals, for example `US`. |
| cursor | string | – | The `next_cursor` of the earlier page. |
| q | string | – | Text to find in the brand name or description. |
| submittable | boolean | – | True: only brands with an active web form at their address, and no `robots.txt` refusal of the page or of a part of it where the form can be. |
| Name | Type | Req | Description |
|---|---|---|---|
| brands | array | yes | – |
| next_cursor | string|null | yes | – |
No examples provided.
get_brand Get a brand ~75
Get the facts of one brand by its slug: its company, its categories, each relationship with its availability, and the sources. The result is the JSON twin at `/brands/{slug}.json`.
| Name | Type | Req | Description |
|---|---|---|---|
| slug | string | yes | A slug: lower-case letters, digits and hyphens, for example `acme-foods`. |
| Name | Type | Req | Description |
|---|---|---|---|
| canonical_name | string | yes | – |
| categories | array | yes | – |
| country | string|null | yes | – |
| description | string|null | yes | – |
| owner | – | yes | – |
| programs | array | yes | – |
| publish_state | string | yes | – |
| slug | string | yes | – |
| social | – | yes | – |
| sources | array | yes | – |
| updated_at | string | yes | – |
| website | – | yes | – |
No examples provided.
get_company Get a company ~63
Get one company by its slug, with the brands that it owns. The result is the JSON twin at `/companies/{slug}.json`.
| Name | Type | Req | Description |
|---|---|---|---|
| slug | string | yes | A slug: lower-case letters, digits and hyphens, for example `acme-foods`. |
| Name | Type | Req | Description |
|---|---|---|---|
| brands | array | yes | – |
| canonical_name | string | yes | – |
| country | string|null | yes | – |
| description | string|null | yes | – |
| organization_type | string | yes | – |
| slug | string | yes | – |
| updated_at | string | yes | – |
| website | – | yes | – |
No examples provided.
get_relationship Get a relationship ~164
Get a brand's relationship: where to apply, each fact with its source quote, and whether Linty read the brand's terms. The facts include the form fields and the documents that the brand asks for. A fact has its quote in `source` only when LintyBot read it on the brand's page. Read `terms` before you apply: it says whether Linty read the agreement that the form asks you to accept. The default relationship is `wholesale`. The result is the JSON twin at `/brands/{slug}/{relationship}.json`.
| Name | Type | Req | Description |
|---|---|---|---|
| brand | string | yes | A slug: lower-case letters, digits and hyphens, for example `acme-foods`. |
| relationship | string | – | The relationship slug. The default is `wholesale`. |
| Name | Type | Req | Description |
|---|---|---|---|
| applicant_types | array | yes | – |
| availability | string | yes | – |
| brand | object | yes | – |
| confidence | string | yes | – |
| contact | – | yes | – |
| last_checked_at | – | yes | – |
| last_verified_at | – | yes | – |
| next_steps | array | yes | – |
| notes | array | yes | – |
| page_kind | – | yes | – |
| relationship_code | string | yes | – |
| relationship_name | string | yes | – |
| relationship_slug | string | yes | – |
| requirements | array | yes | – |
| routes | array | yes | – |
| sources | array | yes | – |
| terms | object | yes | – |
| updated_at | string | yes | – |
No examples provided.
list_categories List categories ~108
List the categories under a path, or the top-level categories, with counts of published brands. A category has a page when it has 10 published brands. With a page, the result also has that category and up to 200 of its brands. Without a page, `category` is null and the result has the categories under the path. A path that is no category answers `not_found`.
| Name | Type | Req | Description |
|---|---|---|---|
| path | string | – | A category path, for example `snacks/protein-bars`. |
| Name | Type | Req | Description |
|---|---|---|---|
| categories | array | yes | – |
| category | – | yes | – |
No examples provided.
report_correction Report a correction ~119
Report a wrong fact about a brand or one of its relationships. Write what is wrong and what is right, in 10 to 2,000 characters. A person at Linty reads each correction.
| Name | Type | Req | Description |
|---|---|---|---|
| body | string | yes | What is wrong, and what is right. |
| brand | string | yes | A slug: lower-case letters, digits and hyphens, for example `acme-foods`. |
| relationship | string | – | A slug: lower-case letters, digits and hyphens, for example `acme-foods`. |
| Name | Type | Req | Description |
|---|---|---|---|
| received | boolean | yes | – |
No examples provided.
What is the Linty MCP server?
Linty is an MCP server listed in the public MCP registry as xyz.linty/linty. Find food, beverage and pet brands that sell direct, and where to apply for a wholesale account. This page covers its hosted endpoint (https://mcp.linty.xyz/mcp).
What tools does the Linty MCP server expose?
Linty exposes 6 tools: find_brands, get_brand, get_relationship, get_company, list_categories, report_correction. Their descriptions and schemas cost roughly 768 tokens of context every time the server is loaded.
Does the Linty MCP server require authentication?
No. We connected to Linty without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.