SIMcloud
REMOTE · SIMCLOUD.CO.ZA · SCANNED SEP 20
South African MCP server for airtime, data, SMS, VAS, electricity, balance, and network lookup.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (register_simcloud_user). See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability78
- AI-judged instruction clarity (excellent).Pass
- Tool/resource definitions use about 1741 tokens (~102/item across 17 items; 17 tools + 0 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage90
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 65% of tool parameters carry a description.Partial
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 18 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the SIMcloud MCP server?
SIMcloud is a hosted endpoint at https://simcloud.co.za/api/mcp.php, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · simcloud.co.za
claude mcp add --transport http za-co-simcloud-simcloud 'https://simcloud.co.za/api/mcp.php'
{
"mcpServers": {
"za-co-simcloud-simcloud": {
"url": "https://simcloud.co.za/api/mcp.php"
}
}
} {
"servers": {
"za-co-simcloud-simcloud": {
"type": "http",
"url": "https://simcloud.co.za/api/mcp.php"
}
}
} [mcp_servers.za-co-simcloud-simcloud] url = "https://simcloud.co.za/api/mcp.php"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"za-co-simcloud-simcloud": {
"type": "remote",
"url": "https://simcloud.co.za/api/mcp.php",
"enabled": true
}
}
} openclaw mcp add za-co-simcloud-simcloud --url 'https://simcloud.co.za/api/mcp.php' --transport streamable-http
mcp_servers:
za-co-simcloud-simcloud:
url: "https://simcloud.co.za/api/mcp.php" {
"McpServers": {
"za-co-simcloud-simcloud": {
"Transport": "http",
"Url": "https://simcloud.co.za/api/mcp.php"
}
}
} assistant mcp add za-co-simcloud-simcloud -t streamable-http -u 'https://simcloud.co.za/api/mcp.php'
{
"mcpServers": {
"za-co-simcloud-simcloud": {
"type": "http",
"url": "https://simcloud.co.za/api/mcp.php"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 26 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 0
- Stability: 0.97 → pass security
- 24 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 31 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 29 Jul 26 0
- The server rewrote its instructions, which are the text every model session reads security
- Schema quality: 1363 → 1560 ▼ functional
- New tool “get_transaction_history” functional
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://simcloud.co.za/api/mcp.php
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=*.coincide.simcloud.co.za | CN=YR1,O=Let's Encrypt,C=US | 27 Aug 2026 | 25 Nov 2026 | RSA 2048 | SHA256-RSA | 556bc3510335daf8cd5909f0e4f2ac0541d |
| SANs: *.cellc.simcloud.co.za, *.coincide.simcloud.co.za, *.simcloud.co.za, *.vas.simcloud.co.za, mail.mobile.simcloud.co.za, simcloud.co.za, www.mobile.simcloud.co.za | ||||||
| CN=YR1,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | a20253f15f2691c05dc1ce13b9bcca4e |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of simcloud.co.za. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| za. | present | 45749 | 8 | Verified |
| co.za. | present | 41369 | 8 | Verified |
| simcloud.co.za. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://simcloud.co.za/api/mcp.php | Verified | 200 | |
| http (plaintext) | http://simcloud.co.za/api/mcp.php | HTTPS enforced | 301 | https://simcloud.co.za/api/mcp.php |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
check_electricity_meter Check electricity meter ~54
Use this before create_electricity_order to check whether a prepaid electricity meter is supported. This does not buy electricity or spend wallet funds.
| Name | Type | Req | Description |
|---|---|---|---|
| meter_number | string | yes | Prepaid electricity meter number to validate. |
| Name | Type | Req | Description |
|---|---|---|---|
| data | – | yes | Decoded SIMcloud API response body. |
| ok | boolean | yes | Whether the proxied SIMcloud API request returned a 2xx response. |
| status | integer | yes | HTTP status returned by the SIMcloud API, or 0 when no HTTP response was received. |
No examples provided.
create_airtime_order Send South African airtime ~181
Use this when an authenticated SIMcloud user asks to send or recharge prepaid airtime to a South African mobile number on MTN, Vodacom, Cell C or Telkom. Confirm the MSISDN, network, rand amount and reference before calling. This spends wallet funds and queues an irreversible external transaction. Never automatically retry an ambiguous result. Duplicate same-MSISDN-and-amount requests inside 5 minutes return HTTP 409.
| Name | Type | Req | Description |
|---|---|---|---|
| amount | number | yes | Airtime amount in South African rand, from R2 to R999. |
| msisdn | string | yes | South African mobile number to recharge, for example 0821234567 or +27821234567. |
| network | string | yes | Supported South African airtime network name or SIMcloud internal code. |
| reference | string | yes | User or system reference for this airtime order. |
| Name | Type | Req | Description |
|---|---|---|---|
| data | – | yes | Decoded SIMcloud API response body. |
| ok | boolean | yes | Whether the proxied SIMcloud API request returned a 2xx response. |
| status | integer | yes | HTTP status returned by the SIMcloud API, or 0 when no HTTP response was received. |
No examples provided.
create_data_order Create data order ~162
Use this when an authenticated SIMcloud user asks to send a confirmed South African mobile data bundle. Call list_data_products first and use an available network and sell value. This spends wallet funds and queues an irreversible external transaction. Never automatically retry an ambiguous result. Duplicate same-MSISDN-and-amount requests inside 5 minutes return HTTP 409.
| Name | Type | Req | Description |
|---|---|---|---|
| amount | number | yes | Exact data bundle sell value returned by list_data_products. |
| msisdn | string | yes | South African mobile number to recharge, for example 0821234567 or +27821234567. |
| network | string | yes | Supported South African data network name or SIMcloud internal code returned by list_data_products. |
| reference | string | yes | User or system reference for this data order. |
| Name | Type | Req | Description |
|---|---|---|---|
| data | – | yes | Decoded SIMcloud API response body. |
| ok | boolean | yes | Whether the proxied SIMcloud API request returned a 2xx response. |
| status | integer | yes | HTTP status returned by the SIMcloud API, or 0 when no HTTP response was received. |
No examples provided.
create_electricity_order Create electricity order ~141
Use this when an authenticated SIMcloud user asks to buy prepaid electricity for a meter already confirmed with check_electricity_meter. Confirm the meter, rand amount, reference and SMS recipient before calling. This spends wallet funds and submits an irreversible external transaction; do not automatically retry an ambiguous result.
| Name | Type | Req | Description |
|---|---|---|---|
| amount | number | yes | Electricity purchase amount in South African rand, from R50 to R1000. |
| client_reference | string | yes | User or system reference for this electricity order. |
| meter_number | string | yes | Prepaid electricity meter number previously checked with check_electricity_meter. |
| recipient | string | yes | Recipient mobile number for voucher notifications. |
| Name | Type | Req | Description |
|---|---|---|---|
| data | – | yes | Decoded SIMcloud API response body. |
| ok | boolean | yes | Whether the proxied SIMcloud API request returned a 2xx response. |
| status | integer | yes | HTTP status returned by the SIMcloud API, or 0 when no HTTP response was received. |
No examples provided.
create_vas_order Create VAS order ~119
Use this when an authenticated SIMcloud user asks to buy a confirmed VAS voucher. Call list_vas_products first and use an available product and denomination. This spends wallet funds and queues an irreversible external transaction; do not automatically retry an ambiguous result.
| Name | Type | Req | Description |
|---|---|---|---|
| amount | number | yes | – |
| product_id | integer | – | SIMcloud VAS product ID. Required when voucher_type is not supplied. |
| reference | string | yes | – |
| voucher_type | string | – | Exact VAS voucher type or slug. Required when product_id is not supplied. |
| Name | Type | Req | Description |
|---|---|---|---|
| data | – | yes | Decoded SIMcloud API response body. |
| ok | boolean | yes | Whether the proxied SIMcloud API request returned a 2xx response. |
| status | integer | yes | HTTP status returned by the SIMcloud API, or 0 when no HTTP response was received. |
No examples provided.
get_airtime_order Get airtime order ~74
Use this after create_airtime_order, or after an ambiguous create result, to fetch the authenticated account airtime order by request_id or orderno.
| Name | Type | Req | Description |
|---|---|---|---|
| orderno | string | – | SIMcloud platform order number returned during processing. |
| request_id | integer | – | SIMcloud request identifier returned when the order was queued. |
| Name | Type | Req | Description |
|---|---|---|---|
| data | – | yes | Decoded SIMcloud API response body. |
| ok | boolean | yes | Whether the proxied SIMcloud API request returned a 2xx response. |
| status | integer | yes | HTTP status returned by the SIMcloud API, or 0 when no HTTP response was received. |
No examples provided.
get_data_order Get data order ~71
Use this after create_data_order, or after an ambiguous create result, to fetch the authenticated account data order by request_id or orderno.
| Name | Type | Req | Description |
|---|---|---|---|
| orderno | string | – | SIMcloud platform order number returned during processing. |
| request_id | integer | – | SIMcloud request identifier returned when the order was queued. |
| Name | Type | Req | Description |
|---|---|---|---|
| data | – | yes | Decoded SIMcloud API response body. |
| ok | boolean | yes | Whether the proxied SIMcloud API request returned a 2xx response. |
| status | integer | yes | HTTP status returned by the SIMcloud API, or 0 when no HTTP response was received. |
No examples provided.
get_electricity_order Get electricity order ~70
Use this after create_electricity_order, or after an ambiguous create result, to fetch an authenticated account electricity order by order_id, client_reference or order_reference_id.
| Name | Type | Req | Description |
|---|---|---|---|
| client_reference | string | – | – |
| order_id | integer | – | – |
| order_reference_id | string | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| data | – | yes | Decoded SIMcloud API response body. |
| ok | boolean | yes | Whether the proxied SIMcloud API request returned a 2xx response. |
| status | integer | yes | HTTP status returned by the SIMcloud API, or 0 when no HTTP response was received. |
No examples provided.
get_sms_status Get SMS status ~36
Use this after send_sms to fetch the delivery status of an authenticated account SMS by sms_id.
| Name | Type | Req | Description |
|---|---|---|---|
| sms_id | integer | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| data | – | yes | Decoded SIMcloud API response body. |
| ok | boolean | yes | Whether the proxied SIMcloud API request returned a 2xx response. |
| status | integer | yes | HTTP status returned by the SIMcloud API, or 0 when no HTTP response was received. |
No examples provided.
get_transaction_history Get transaction history ~174
Use this to retrieve read-only transaction history for the authenticated SIMcloud account across web, CSV, recurring and API airtime, data, SMS, VAS and electricity activity. Require a date range; optionally filter one or more services with a comma-separated type value. SMS is successful only after a delivery receipt.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | Opaque cursor returned by the previous result. Keep the same date range and type filter. |
| date_from | string | yes | Inclusive start date in YYYY-MM-DD format, interpreted in Africa/Johannesburg time. |
| date_to | string | yes | Inclusive end date in YYYY-MM-DD format. The maximum range is 90 days. |
| limit | integer | – | – |
| type | string | – | Optional comma-separated service filter: airtime, data, electricity, vas and sms. |
| Name | Type | Req | Description |
|---|---|---|---|
| data | – | yes | Decoded SIMcloud API response body. |
| ok | boolean | yes | Whether the proxied SIMcloud API request returned a 2xx response. |
| status | integer | yes | HTTP status returned by the SIMcloud API, or 0 when no HTTP response was received. |
No examples provided.
get_vas_order Get VAS order ~56
Use this after create_vas_order, or after an ambiguous create result, to fetch an authenticated account VAS order by order_id or transaction_id.
| Name | Type | Req | Description |
|---|---|---|---|
| order_id | integer | – | – |
| transaction_id | string | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| data | – | yes | Decoded SIMcloud API response body. |
| ok | boolean | yes | Whether the proxied SIMcloud API request returned a 2xx response. |
| status | integer | yes | HTTP status returned by the SIMcloud API, or 0 when no HTTP response was received. |
No examples provided.
get_wallet_balance Get wallet balance ~42
Use this before a wallet-funded SIMcloud transaction or when the user asks for their available SIMcloud balance. Returns the authenticated account wallet balance and does not spend funds.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| data | – | yes | Decoded SIMcloud API response body. |
| ok | boolean | yes | Whether the proxied SIMcloud API request returned a 2xx response. |
| status | integer | yes | HTTP status returned by the SIMcloud API, or 0 when no HTTP response was received. |
No examples provided.
list_data_products List data products ~63
Use this before create_data_order to list the current SIMcloud data bundle products and exact sell values available for API ordering, optionally filtered by South African network.
| Name | Type | Req | Description |
|---|---|---|---|
| network | string | – | Optional friendly network name or internal code, for example mtn or pd-mtn. |
| Name | Type | Req | Description |
|---|---|---|---|
| data | – | yes | Decoded SIMcloud API response body. |
| ok | boolean | yes | Whether the proxied SIMcloud API request returned a 2xx response. |
| status | integer | yes | HTTP status returned by the SIMcloud API, or 0 when no HTTP response was received. |
No examples provided.
list_vas_products List VAS products ~31
Use this before create_vas_order to list active SIMcloud VAS voucher products and their available denominations.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| data | – | yes | Decoded SIMcloud API response body. |
| ok | boolean | yes | Whether the proxied SIMcloud API request returned a 2xx response. |
| status | integer | yes | HTTP status returned by the SIMcloud API, or 0 when no HTTP response was received. |
No examples provided.
lookup_network Look up mobile network ~64
Use this when the user needs to identify the South African mobile network for a number before sending airtime, data or SMS. The lookup is recorded in the authenticated account history.
| Name | Type | Req | Description |
|---|---|---|---|
| msisdn | string | yes | South African mobile number, for example 0821234567. |
| Name | Type | Req | Description |
|---|---|---|---|
| data | – | yes | Decoded SIMcloud API response body. |
| ok | boolean | yes | Whether the proxied SIMcloud API request returned a 2xx response. |
| status | integer | yes | HTTP status returned by the SIMcloud API, or 0 when no HTTP response was received. |
No examples provided.
register_simcloud_user Register a SIMcloud user ~181
Create a normal SIMcloud account under the authenticated account for a client application user. Confirm that the person consents to account creation and that their cell number, email and password are correct before calling. The response contains the child account API token, which must be stored securely and used only for that child account.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | – | – |
| business_name | string | – | – |
| business_reg | string | – | – |
| cell | string | yes | 10-digit South African mobile number beginning with 0. |
| string | yes | – | |
| first_name | string | yes | – |
| id_number | string | – | Optional valid South African ID number. |
| last_name | string | yes | – |
| password | string | yes | The new user's SIMcloud login password. Do not log or display it after this call. |
| vatno | string | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| data | – | yes | Decoded SIMcloud API response body. |
| ok | boolean | yes | Whether the proxied SIMcloud API request returned a 2xx response. |
| status | integer | yes | HTTP status returned by the SIMcloud API, or 0 when no HTTP response was received. |
No examples provided.
send_sms Send SMS ~84
Use this when an authenticated SIMcloud user asks to send a confirmed SMS to a South African recipient. Confirm the final recipient and message before calling. Sending is an irreversible external action and may spend wallet funds; do not automatically retry an ambiguous result.
| Name | Type | Req | Description |
|---|---|---|---|
| message | string | yes | SMS message body. |
| recipient | string | yes | Recipient number, for example +27821234567. |
| Name | Type | Req | Description |
|---|---|---|---|
| data | – | yes | Decoded SIMcloud API response body. |
| ok | boolean | yes | Whether the proxied SIMcloud API request returned a 2xx response. |
| status | integer | yes | HTTP status returned by the SIMcloud API, or 0 when no HTTP response was received. |
No examples provided.
What is the SIMcloud MCP server?
SIMcloud is an MCP server listed in the public MCP registry as za.co.simcloud/simcloud. South African MCP server for airtime, data, SMS, VAS, electricity, balance, and network lookup. This page covers its hosted endpoint (https://simcloud.co.za/api/mcp.php).
Is the SIMcloud MCP server safe to use?
SIMcloud scores 78 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the SIMcloud MCP server expose?
SIMcloud exposes 17 tools: register_simcloud_user, get_wallet_balance, get_transaction_history, lookup_network, send_sms, and 12 more. Their descriptions and schemas cost roughly 1,603 tokens of context every time the server is loaded.
Does the SIMcloud MCP server require authentication?
No. We connected to SIMcloud without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the SIMcloud MCP server still maintained?
SIMcloud is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.