French Due Diligence
REMOTE · MCP-FR.OPENDATA-APIS.WORKERS.DEV
Free, keyless French company checks (Sirene, BODACC, VIES, asset freezes) and DPE rental compliance
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
No category breakdown is available for this channel yet.
How do I install the French Due Diligence MCP server?
French Due Diligence is a hosted endpoint at https://mcp-fr.opendata-apis.workers.dev/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp-fr.opendata-apis.workers.dev
claude mcp add --transport http zansuken-french-due-diligence 'https://mcp-fr.opendata-apis.workers.dev/mcp'
{
"mcpServers": {
"zansuken-french-due-diligence": {
"url": "https://mcp-fr.opendata-apis.workers.dev/mcp"
}
}
} {
"servers": {
"zansuken-french-due-diligence": {
"type": "http",
"url": "https://mcp-fr.opendata-apis.workers.dev/mcp"
}
}
} [mcp_servers.zansuken-french-due-diligence] url = "https://mcp-fr.opendata-apis.workers.dev/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"zansuken-french-due-diligence": {
"type": "remote",
"url": "https://mcp-fr.opendata-apis.workers.dev/mcp",
"enabled": true
}
}
} openclaw mcp add zansuken-french-due-diligence --url 'https://mcp-fr.opendata-apis.workers.dev/mcp' --transport streamable-http
mcp_servers:
zansuken-french-due-diligence:
url: "https://mcp-fr.opendata-apis.workers.dev/mcp" {
"McpServers": {
"zansuken-french-due-diligence": {
"Transport": "http",
"Url": "https://mcp-fr.opendata-apis.workers.dev/mcp"
}
}
} assistant mcp add zansuken-french-due-diligence -t streamable-http -u 'https://mcp-fr.opendata-apis.workers.dev/mcp'
{
"mcpServers": {
"zansuken-french-due-diligence": {
"type": "http",
"url": "https://mcp-fr.opendata-apis.workers.dev/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
We have not recorded any changes for this component yet
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 9 Oct 2026 · Probed https://mcp-fr.opendata-apis.workers.dev/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=opendata-apis.workers.dev | CN=YE1,O=Let's Encrypt,C=US | 2 Oct 2026 | 31 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 61db19354270320b239850bf5e2891b481b |
| SANs: *.opendata-apis.workers.dev, opendata-apis.workers.dev | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp-fr.opendata-apis.workers.dev. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| dev. | present | 60074 | 8 | Verified |
| workers.dev. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp-fr.opendata-apis.workers.dev/mcp | Verified | 200 | |
| http (plaintext) | http://mcp-fr.opendata-apis.workers.dev/mcp | Inconclusive | 405 |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
check_rental_compliance Check whether a French dwelling can be rented (DPE) ~151
For a French postal address, returns each dwelling's energy performance certificate (DPE) and its rental verdict under the Climate and Resilience law: rentable now or not, rent frozen or not, ban date (G 2025, F 2028, E 2034), DPE validity, and the label estimated under current electricity rules. Narrow with floor, surface or address complement. Information, not legal advice.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | Full address with house number, postcode and town |
| complement | string | – | e.g. 'Apt 12', 'Bât B' |
| floor | integer | – | – |
| surface | number | – | Living area in m² |
No output schema declared.
No examples provided.
check_vat Check a French VAT number in VIES ~205
Checks live in VIES, the European Commission's VAT register, whether a French VAT number (or the VAT number of a SIREN or SIRET) is valid, with the name and address declared for VAT, crossed with the French registry: company active, insolvency proceeding, and a name_matches consistency signal between the VIES name and the registered name (not a proof of ownership). To confirm the number belongs to a given company, compare the returned names with that company's name. Pass requester_vat (the user's own EU VAT number) to get a VIES consultation number, proof of the check. vies.status 'unavailable' means VIES could not answer: try again later, it does not mean invalid.
| Name | Type | Req | Description |
|---|---|---|---|
| number | string | yes | FR VAT number, SIREN or SIRET; spaces allowed |
| requester_vat | string | – | The user's own EU VAT number, e.g. DE811569869, for a consultation number |
No output schema declared.
No examples provided.
get_company Get a French company's profile and insolvency status ~82
Profile of a French company by SIREN: legal name and form, activity, active or ceased, head office, officers (name and role), whether an insolvency proceeding is ongoing (in_insolvency) and its latest BODACC court announcements. Use it to answer 'can I do business with this company?'.
| Name | Type | Req | Description |
|---|---|---|---|
| siren | string | yes | – |
No output schema declared.
No examples provided.
get_dpe Get a French DPE and its rental verdict by number ~77
The dwelling of a French DPE (energy performance certificate) by its 13-character number (e.g. 2569E0160739C), with the same rental verdict as check_rental_compliance. Replaced DPEs are not available: the ADEME dataset drops them.
| Name | Type | Req | Description |
|---|---|---|---|
| dpe_number | string | yes | – |
No output schema declared.
No examples provided.
get_establishment Get a French establishment by SIRET ~55
One establishment of a French company by SIRET: address, NAF activity, open or closed, head office or not. Use it to check a supplier's or invoice's address.
| Name | Type | Req | Description |
|---|---|---|---|
| siret | string | yes | – |
No output schema declared.
No examples provided.
get_public_contracts Get the public contracts a French company won ~220
Public contracts a French company won (DECP, French public procurement data): their count, the summed maximum amounts (leaving out amounts the source flags as suspect or aberrant, given apart), first and latest notification, then the contracts newest first, 20 per page, with buyer, object, maximum amount, CPV code, procedure, duration and place; plus the company's name, whether it is active and whether an insolvency proceeding is ongoing. Amounts are ceilings declared by buyers (maximum estimated, excl. VAT), not spend or revenue; the count is approximate (computed by the source: a contract held by two establishments counts twice, and a holder whose identifier merely contains the SIREN may be included). Narrow with from and to (notification dates).
| Name | Type | Req | Description |
|---|---|---|---|
| from | string | – | Notified on or after, YYYY-MM-DD |
| page | integer | – | Page of 20 contracts, from 1 |
| siren | string | yes | – |
| to | string | – | Notified on or before, YYYY-MM-DD |
No output schema declared.
No examples provided.
screen_sanctions Screen a French company against asset freezes ~185
Screens a French company and its officers (people, with their month of birth, and companies) against the French national asset-freeze register (registre national des gels: UN, EU and French measures). result is clear, possible_match or strong_match; each match gives the register entry, its legal bases and its official page. A match is a lead to check on that page, not a decision; a different date of birth already rules namesakes out. strong: a person with the same name and year and month of birth, or a company whose own SIREN or SIRET the register entry lists; a same-named company without it is only possible. Beneficial owners, foreign lists (OFAC, UK) and politically exposed persons are not covered.
| Name | Type | Req | Description |
|---|---|---|---|
| number | string | yes | SIREN, SIRET or FR VAT number; spaces allowed |
No output schema declared.
No examples provided.
search_companies Search French companies ~115
Finds French companies by name, optionally narrowed by department (e.g. 75, 2A, 971), postal code or NAF activity code (e.g. 10.71C). Returns up to 10 companies with their SIREN. Use get_company next for the full profile.
| Name | Type | Req | Description |
|---|---|---|---|
| activity_code | string | – | NAF rév. 2 code |
| department | string | – | – |
| name | string | – | Company name, 3 characters minimum |
| postal_code | string | – | – |
No output schema declared.
No examples provided.
validate_identifier Validate a French company identifier ~84
Checks a French SIREN (9 digits), SIRET (14 digits) or intra-EU VAT number (FR + 11 characters): format, checksum, and whether the registered company or establishment exists. Use it first when an identifier was typed by a person.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | SIREN, SIRET or FR VAT number; spaces allowed |
No output schema declared.
No examples provided.
What is the French Due Diligence MCP server?
French Due Diligence is an MCP server listed in the public MCP registry as io.github.Zansuken/french-due-diligence. Free, keyless French company checks (Sirene, BODACC, VIES, asset freezes) and DPE rental compliance. This page covers its hosted endpoint (https://mcp-fr.opendata-apis.workers.dev/mcp).
What tools does the French Due Diligence MCP server expose?
French Due Diligence exposes 9 tools: validate_identifier, check_vat, search_companies, get_company, screen_sanctions, and 4 more. Their descriptions and schemas cost roughly 1,174 tokens of context every time the server is loaded.
Does the French Due Diligence MCP server require authentication?
No. We connected to French Due Diligence without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.