Show raw JSON evidence
{
"checks": {
"action_safety_probe": {
"details": {
"auth_present": true,
"confirmation_signals": [
"tracepass_products",
"tracepass_passports"
],
"reason": null,
"safeguard_count": 4,
"summary": {
"annotation_conflict_tools": 0,
"bulk_access_tools": 0,
"capability_distribution": {
"read": 4,
"write": 5
},
"declared_non_read_only_tools": 0,
"destructive_tools": 0,
"egress_tools": 0,
"exec_tools": 0,
"high_risk_tools": 0,
"risk_distribution": {
"critical": 0,
"high": 0,
"low": 1,
"medium": 5
},
"secret_tools": 0,
"tool_count": 6
}
},
"latency_ms": null,
"status": "ok"
},
"advanced_capabilities_probe": {
"details": {
"capabilities": {
"completions": false,
"elicitation": false,
"prompts": true,
"resource_links": true,
"resources": true,
"roots": false,
"sampling": false,
"structured_outputs": true
},
"enabled": [
"prompts",
"resource_links",
"resources",
"structured_outputs"
],
"enabled_count": 4,
"initialize_capability_keys": [
"prompts",
"resources",
"tools"
]
},
"latency_ms": null,
"status": "ok"
},
"connector_publishability_probe": {
"details": {
"blockers": [],
"criteria": {
"action_safety": true,
"auth_flow": true,
"connector_replay": true,
"initialize": true,
"protocol_version": true,
"remote_transport": true,
"request_association": true,
"server_card": true,
"session_resume": true,
"step_up_auth": true,
"tool_surface": true,
"tools_list": true,
"transport_compliance": true
},
"high_risk_tools": 0,
"tool_count": 6,
"transport": "streamable-http"
},
"latency_ms": null,
"status": "ok"
},
"connector_replay_probe": {
"details": {
"added_tools": [],
"additive_output_changes": [],
"backward_compatible": true,
"output_breaks": [],
"removed_tools": [],
"required_arg_breaks": [],
"would_break_after_refresh": false
},
"latency_ms": null,
"status": "ok"
},
"determinism_probe": {
"details": {
"attempts": 2,
"baseline_signature": "e8f92820469e7aae1d254fafd72a904e5edb82ba323508bc2f942280d8214cca",
"errors": [],
"matches": 2,
"stable_ratio": 1.0,
"successful": 2
},
"latency_ms": 204.46,
"status": "ok"
},
"initialize": {
"details": {
"headers": {
"content-type": "text/event-stream",
"strict-transport-security": "max-age=31536000; includeSubDomains"
},
"http_status": 200,
"payload": {
"id": 1,
"jsonrpc": "2.0",
"result": {
"capabilities": {
"prompts": {
"listChanged": true
},
"resources": {
"listChanged": true
},
"tools": {
"listChanged": true
}
},
"instructions": "Tools for the TracePass Digital Product Passport platform. Reads are free; writes that create passports are billable and consume plan quota \u2014 never create passports in bulk or accept an overage charge without the user's explicit consent. archive_passport is irreversible; prefer suspend_passport when a change might need undoing.",
"protocolVersion": "2025-03-26",
"serverInfo": {
"name": "tracepass",
"version": "1.7.3"
}
}
},
"url": "https://ai.tracepass.eu/mcp"
},
"latency_ms": 103.97,
"status": "ok"
},
"interactive_flow_probe": {
"details": {
"oauth_supported": true,
"prompt_available": false,
"risk_hits": [],
"safe_hits": [
"oauth",
"consent"
]
},
"latency_ms": null,
"status": "ok"
},
"oauth_authorization_server": {
"details": {
"headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=31536000; includeSubDomains"
},
"http_status": 200,
"payload": {
"authorization_endpoint": "https://app.tracepass.eu/api/oauth/authorize",
"code_challenge_methods_supported": [
"S256"
],
"grant_types_supported": [
"authorization_code",
"refresh_token"
],
"issuer": "https://app.tracepass.eu",
"registration_endpoint": "https://app.tracepass.eu/api/oauth/register",
"response_types_supported": [
"code"
],
"revocation_endpoint": "https://app.tracepass.eu/api/oauth/revoke",
"revocation_endpoint_auth_methods_supported": [
"client_secret_post",
"none"
],
"scopes_supported": [
"passports:read",
"passports:write",
"documents:read",
"documents:write",
"suppliers:read",
"suppliers:write",
"offline_access"
],
"token_endpoint": "https://app.tracepass.eu/api/oauth/token",
"token_endpoint_auth_methods_supported": [
"client_secret_post",
"none"
]
},
"url": "https://app.tracepass.eu/.well-known/oauth-authorization-server"
},
"latency_ms": 300.26,
"status": "ok"
},
"oauth_protected_resource": {
"details": {
"headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=31536000; includeSubDomains"
},
"http_status": 200,
"payload": {
"authorization_servers": [
"https://app.tracepass.eu"
],
"bearer_methods_supported": [
"header"
],
"resource": "https://ai.tracepass.eu/mcp",
"scopes_supported": [
"passports:read",
"passports:write",
"documents:read",
"documents:write",
"suppliers:read",
"suppliers:write",
"offline_access"
]
},
"url": "https://ai.tracepass.eu/.well-known/oauth-protected-resource"
},
"latency_ms": 94.03,
"status": "ok"
},
"official_registry_probe": {
"details": {
"direct_match": false,
"official_identifiers": [
"ai.mitosislabs/mitosis",
"ai.fugentic/service-provider-index",
"ai.retrodiffusion/pixel-art",
"ai.kifly/mcp",
"ai.hostprofit/mcp",
"ai.dinglebear/cortex",
"ai.dinglebear/runifi",
"ai.rolli/mcp",
"ai.dinglebear/soma",
"ai.aivonic/mcp"
],
"official_peer_count": 10,
"registry_source": "awesome_mcp_servers"
},
"latency_ms": null,
"status": "warning"
},
"openid_configuration": {
"details": {
"error": "Client error '404 Not Found' for url 'https://app.tracepass.eu/.well-known/openid-configuration'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404",
"url": "https://app.tracepass.eu/.well-known/openid-configuration"
},
"latency_ms": 99.32,
"status": "error"
},
"probe_noise_resilience": {
"details": {
"headers": {
"content-type": "text/html; charset=utf-8",
"strict-transport-security": "max-age=63072000; includeSubDomains; preload"
},
"http_status": 200,
"url": "https://ai.tracepass.eu/robots.txt",
"validation_disallowed": false
},
"latency_ms": 1073.25,
"status": "ok"
},
"prompt_get": {
"details": {
"error": "Client error '401 Unauthorized' for url 'https://ai.tracepass.eu/mcp'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/401",
"headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=31536000; includeSubDomains",
"www-authenticate": "Bearer realm=\"TracePass MCP\", error=\"invalid_token\", resource_metadata=\"https://ai.tracepass.eu/.well-known/oauth-protected-resource\", error_description=\"Authenticate with a TracePass API key (Developer -> API Keys, send Authorization: Bearer <tp_ key>) or via OAuth (see resource_metadata).\""
},
"http_status": 401,
"payload": {},
"prompt_arguments": [
{
"description": "The TracePass id of the passport to audit.",
"name": "passportId",
"required": true
}
],
"prompt_name": "audit_passport",
"reason": "auth_required",
"url": "https://ai.tracepass.eu/mcp"
},
"latency_ms": 305.0,
"status": "auth_required"
},
"prompts_list": {
"details": {
"headers": {
"content-type": "text/event-stream",
"strict-transport-security": "max-age=31536000; includeSubDomains"
},
"http_status": 200,
"payload": {
"id": 3,
"jsonrpc": "2.0",
"result": {
"prompts": [
{
"arguments": [
{
"description": "The TracePass id of the passport to audit.",
"name": "passportId",
"required": true
}
],
"description": "Review one Digital Product Passport for completeness and compliance readiness \u2014 which required fields are missing, which economic-operator parties are unset, whether it's publishable.",
"name": "audit_passport",
"title": "Audit a passport"
},
{
"arguments": [
{
"description": "The product's name.",
"name": "productName",
"required": true
},
{
"description": "Category key \u2014 battery, textile, electronics, construction, steel, chemicals, packaging, furniture, tyres, jewelry, toys, or fmcg.",
"name": "category",
"required": true
}
],
"description": "Walk through creating a new product and its first Digital Product Passport \u2014 gathering the details, then creating both.",
"name": "onboard_product",
"title": "Onboard a new product"
},
{
"arguments": [
{
"description": "Category key \u2014 battery, textile, electronics, construction, steel, chemicals, packaging, furniture, tyres, jewelry, toys, or fmcg.",
"name": "category",
"required": true
}
],
"description": "Explain what a Digital Product Passport in a given category must contain to be compliant \u2014 the required fields and the EU regulation behind them \u2014 before you create anything.",
"name": "explain_dpp_requirements",
"title": "What does a compliant DPP require?"
},
{
"arguments": [
{
"description": "The TracePass id of the passport to gap-check.",
"name": "passportId",
"required": true
}
],
"description": "Cross-check a draft passport against its category's regulatory schema and produce an exact, prioritised list of what's missing before it can be published compliantly.",
"name": "compliance_gap_check",
"title": "Compliance gap-check before publish"
},
{
"arguments": [
{
"description": "The TracePass id of the passport whose events to review.",
"name": "passportId",
"required": true
}
],
"description": "Inspect the EPCIS 2.0 supply-chain event history of a passport and summarise the product's traceability story.",
"name": "review_epcis_events",
"title": "Review a passport's EPCIS events"
}
]
}
},
"url": "https://ai.tracepass.eu/mcp"
},
"latency_ms": 296.26,
"status": "ok"
},
"protocol_version_probe": {
"details": {
"claimed_version": "2025-03-26",
"lag_days": 244,
"latest_known_version": "2025-11-25",
"releases_behind": 2,
"validator_protocol_version": "2025-03-26"
},
"latency_ms": null,
"status": "warning"
},
"provenance_divergence_probe": {
"details": {
"comparable_field_count": 0,
"compared_fields": [
"title",
"version",
"homepage",
"repository"
],
"direct_official_match": false,
"drift_fields": [],
"metadata_document_count": 2,
"readable_sources": [
"registry",
"server_card"
],
"registry_homepage": null,
"registry_repository": null,
"registry_title": null,
"registry_version": null,
"server_card_homepage": null,
"server_card_repository": null,
"server_card_title": "tracepass",
"server_card_version": "1.7.3"
},
"latency_ms": null,
"status": "not_assessed"
},
"request_association_probe": {
"details": {
"reason": "no_request_association_capabilities_advertised"
},
"latency_ms": null,
"status": "missing"
},
"resource_read": {
"details": {
"error": "Client error '401 Unauthorized' for url 'https://ai.tracepass.eu/mcp'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/401",
"headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=31536000; includeSubDomains",
"www-authenticate": "Bearer realm=\"TracePass MCP\", error=\"invalid_token\", resource_metadata=\"https://ai.tracepass.eu/.well-known/oauth-protected-resource\", error_description=\"Authenticate with a TracePass API key (Developer -> API Keys, send Authorization: Bearer <tp_ key>) or via OAuth (see resource_metadata).\""
},
"http_status": 401,
"payload": {},
"reason": "auth_required",
"resource_uri": "tracepass://products",
"url": "https://ai.tracepass.eu/mcp"
},
"latency_ms": 286.73,
"status": "auth_required"
},
"resources_list": {
"details": {
"headers": {
"content-type": "text/event-stream",
"strict-transport-security": "max-age=31536000; includeSubDomains"
},
"http_status": 200,
"payload": {
"id": 5,
"jsonrpc": "2.0",
"result": {
"resources": [
{
"description": "The account's TracePass product catalogue (first page). Attach this for an overview of what products exist.",
"mimeType": "application/json",
"name": "products",
"title": "Product catalogue",
"uri": "tracepass://products"
},
{
"description": "All 12 DPP category schemas with field count, required-field count, and governing regulation. Attach this to ground the model in what each category's compliance requirements are.",
"mimeType": "application/json",
"name": "templates",
"title": "DPP templates (regulatory schemas)",
"uri": "tracepass://templates"
}
]
}
},
"url": "https://ai.tracepass.eu/mcp"
},
"latency_ms": 289.73,
"status": "ok"
},
"schema_divergence_probe": {
"details": {
"card_server_name": "tracepass",
"compared_dimensions": [
"server_name",
"server_version",
"declared_vs_observed_auth",
"tool_membership",
"parameter_names",
"required_parameters",
"parameter_types",
"output_schema_presence"
],
"compared_tool_count": 0,
"live_server_name": "tracepass",
"reason": "no_server_card_tools",
"server_name_mismatch": false
},
"latency_ms": null,
"status": "missing"
},
"server_card": {
"details": {
"headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=31536000; includeSubDomains"
},
"http_status": 200,
"payload": {
"authentication": {
"description": "Two ways to authenticate, pick one. (1) OAuth 2.0 (recommended for AI assistants acting for a user): if your client supports OAuth, Connect the server and the user approves scopes on a TracePass consent screen \u2014 no secret to handle, access is scoped and revocable. Discovery is automatic via this card's resourceMetadata and the 401 WWW-Authenticate challenge (authorization-code + PKCE). (2) API key (simplest for a single user / scripts): the user mints a tp_ key at Developer -> API Keys and you send it as Authorization: Bearer <tp_ key>. The server forwards whichever you send; both reach the same v1 API.",
"required": true,
"resourceMetadata": "https://ai.tracepass.eu/.well-known/oauth-protected-resource",
"scheme": "bearer",
"schemes": [
"bearer",
"oauth2"
],
"type": "http"
},
"capabilities": {
"prompts": [
"audit_passport",
"onboard_product",
"explain_dpp_requirements",
"compliance_gap_check",
"review_epcis_events"
],
"resourceTemplates": [
"tracepass://product/{id}",
"tracepass://passport/{id}",
"tracepass://passport/{id}/epcis",
"tracepass://passport/{id}/compliance",
"tracepass://passport/{id}/registry-readiness",
"tracepass://template/{category}"
],
"resources": [
"tracepass://products",
"tracepass://templates"
],
"tools": [
"tracepass_products",
"tracepass_passports",
"tracepass_passport_fields",
"tracepass_passport_parties",
"tracepass_epcis",
"tracepass_templates"
]
},
"description": "Model Context Protocol server for TracePass \u2014 the EU Digital Product Passport platform. Manage products, Digital Product Passports, economic-operator parties, and GS1 EPCIS 2.0 supply-chain events.",
"documentation": "https://www.tracepass.eu/docs/mcp",
"name": "tracepass",
"serverInfo": {
"name": "tracepass",
"version": "1.7.3"
},
"transport": {
"endpoint": "https://ai.tracepass.eu/mcp",
"type": "streamable-http"
},
"version": "1.7.3"
},
"url": "https://ai.tracepass.eu/.well-known/mcp/server-card.json"
},
"latency_ms": 289.17,
"status": "ok"
},
"session_resume_probe": {
"details": {
"protocol_version": "2025-03-26",
"reason": "no_session_id",
"resume_expected": true,
"transport": "streamable-http"
},
"latency_ms": null,
"status": "warning"
},
"step_up_auth_probe": {
"details": {
"auth_required_checks": [
"prompt_get",
"resource_read"
],
"broad_scopes": [
"documents:write",
"passports:write",
"suppliers:write"
],
"challenge_headers": [
"Bearer realm=\"TracePass MCP\", error=\"invalid_token\", resource_metadata=\"https://ai.tracepass.eu/.well-known/oauth-protected-resource\", error_description=\"Authenticate with a TracePass API key (Developer -> API Keys, send Authorization: Bearer <tp_ key>) or via OAuth (see resource_metadata).\"",
"Bearer realm=\"TracePass MCP\", error=\"invalid_token\", resource_metadata=\"https://ai.tracepass.eu/.well-known/oauth-protected-resource\", error_description=\"Authenticate with a TracePass API key (Developer -> API Keys, send Authorization: Bearer <tp_ key>) or via OAuth (see resource_metadata).\""
],
"minimal_scope_documented": true,
"oauth_present": true,
"scope_specificity_ratio": 0.3636,
"step_up_signals": [
"Bearer realm=\"TracePass MCP\", error=\"invalid_token\", resource_metadata=\"https://ai.tracepass.eu/.well-known/oauth-protected-resource\", error_description=\"Authenticate with a TracePass API key (Developer -> API Keys, send Authorization: Bearer <tp_ key>) or via OAuth (see resource_metadata).\"",
"Bearer realm=\"TracePass MCP\", error=\"invalid_token\", resource_metadata=\"https://ai.tracepass.eu/.well-known/oauth-protected-resource\", error_description=\"Authenticate with a TracePass API key (Developer -> API Keys, send Authorization: Bearer <tp_ key>) or via OAuth (see resource_metadata).\""
],
"supported_scopes": [
"documents:read",
"documents:write",
"offline_access",
"passports:read",
"passports:write",
"suppliers:read",
"suppliers:write"
]
},
"latency_ms": null,
"status": "ok"
},
"tool_snapshot_probe": {
"details": {
"added": [],
"changed_outputs": [],
"current_tool_count": 6,
"previous_tool_count": 6,
"removed": [],
"similarity": 1.0
},
"latency_ms": null,
"status": "ok"
},
"tools_list": {
"details": {
"headers": {
"content-type": "text/event-stream",
"strict-transport-security": "max-age=31536000; includeSubDomains"
},
"http_status": 200,
"payload": {
"id": 2,
"jsonrpc": "2.0",
"result": {
"tools": [
{
"annotations": {
"idempotentHint": false
},
"description": "Manage the TracePass product catalogue. A product is the catalogue layer \u2014 one product can have many passports (one per serialised unit). Products are not billable on their own.\n\nActions (pass via `action`, with `args`):\n- list \u2014 args: { page?, limit? (\u2264100), category?, status?, search? }. Read-only.\n- get \u2014 args: { id }. Read-only.\n- create \u2014 args: { name, model, category, description? }. `category` is one of: battery, textile, electronics, construction, steel, chemicals, packaging, furniture, tyres, jewelry, toys, fmcg.\n- update \u2014 args: { id, name?, model?, description? }; pass at least one field to change.\n- create_batch \u2014 args: { products: [ { name, model, category, description? }, \u2026 ] }, up to 100. Partial-success: the response carries a per-item status, so some items can be created while others error. The whole batch consumes N writes upfront; if that would exceed the daily cap NOTHING is created (429).\n- archive \u2014 args: { id }. Soft-archive a product. Blocked with 409 while any non-archived passport still references it \u2014 archive those passports first. This is reversible and is NOT deletion.",
"execution": {
"taskSupport": "forbidden"
},
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"action": {
"description": "Which product operation to run: list | get | create | create_batch | update | archive.",
"enum": [
"list",
"get",
"create",
"create_batch",
"update",
"archive"
],
"type": "string"
},
"args": {
"description": "Arguments for the chosen action; required fields depend on `action` (see each action above).",
"properties": {
"category": {
"description": "DPP category for create: battery | textile | electronics | construction | steel | chemicals | packaging | furniture | tyres | jewelry | toys | fmcg.",
"type": "string"
},
"description": {
"description": "Free-text product description (create/update).",
"type": "string"
},
"id": {
"description": "Product id. Required for get and update.",
"type": "string"
},
"limit": {
"description": "Page size for list, max 100.",
"type": "number"
},
"model": {
"description": "Manufacturer model / SKU. Required for create; optional on update.",
"type": "string"
},
"name": {
"description": "Product name. Required for create; optional on update.",
"type": "string"
},
"page": {
"description": "Page number for list (1-based).",
"type": "number"
},
"products": {
"description": "Products to create for create_batch: [{ name, model, category, description? }], max 100.",
"items": {
"additionalProperties": {},
"propertyNames": {
"type": "string"
},
"type": "object"
},
"type": "array"
},
"search": {
"description": "Filter list by a search term.",
"type": "string"
},
"status": {
"description": "Filter list by product status.",
"type": "string"
}
},
"type": "object"
}
},
"required": [
"action"
],
"type": "object"
},
"name": "tracepass_products",
"outputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"error": {
"description": "Machine-readable error code, when the API rejected the request.",
"type": "string"
},
"id": {
"description": "The resource's TracePass id, when the response is a single entity.",
"type": "string"
},
"items": {
"description": "The page of results, when the action is a list.",
"items": {},
"type": "array"
},
"limit": {
"description": "Page size (list actions).",
"type": "number"
},
"message": {
"description": "Human-readable error or status detail, when present.",
"type": "string"
},
"page": {
"description": "Current page number (list actions).",
"type": "number"
},
"result": {
"description": "Wraps a non-object response body (e.g. a QR code string)."
},
"total": {
"description": "Total matching records across all pages (list actions).",
"type": "number"
},
"totalPages": {
"description": "Total number of pages (list actions).",
"type": "number"
}
},
"type": "object"
},
"title": "TracePass products"
},
{
"annotations": {
"idempotentHint": false
},
"description": "Manage Digital Product Passports \u2014 create, read, and run lifecycle actions.\n\nIMPORTANT: `create` consumes a DPP slot on the account's plan and IS BILLABLE. Creating a passport beyond the included quota incurs a per-passport overage charge; if over quota the tool returns a 402-style message \u2014 only re-run with args.confirmOverage=true after the user explicitly agrees to the charge. `archive` is IRREVERSIBLE (the public QR permanently 404s); prefer `suspend` when a change might be undone.\n\nActions (pass via `action`, with `args`):\n- list \u2014 args: { page?, limit? (\u2264100), productId?, status?, search? }. status \u2208 draft|in_review|approved|published|suspended|expired|archived. Read-only.\n- get \u2014 args: { id, format? (summary|full), lang? }. Read-only.\n- get_by_serial \u2014 args: { serial, format?, lang?, gtin? }. Read-only. Addresses the passport by your own serial. A serial is unique only WITHIN a GTIN \u2014 if the same serial exists under two GTINs in your account the call returns 409 ambiguous_serial; pass `gtin` (or use the by-id action) to resolve exactly.\n- compliance \u2014 args: { id }. Read-only. Returns a three-tier compliance verdict (compliant | compliant_with_warnings | incomplete) with regulation-cited findings \u2014 use to gap-check a passport against the rules for its category, fix the cited fields/parties, then re-check.\n- registry_readiness \u2014 args: { id }. Read-only. Returns { ready, findings[] } \u2014 whether the passport would pass the EU DPP Registry's FORMAL submission gate (mandatory fields present, correct formatting, a resolvable public link, item-level granularity via a serial number, and a well-formed commodity code where the category carries one). This is the registry's mechanical pre-submission check, NOT the substantive compliance verdict; a passport can be registry-ready yet not substantively compliant. Battery passports only.\n- create \u2014 args: { productId, gtin, serialNumber, confirmOverage? }. BILLABLE.\n- suspend \u2014 args: { id }. Reversible \u2014 public QR shows 'suspended'.\n- suspend_by_serial \u2014 args: { serial, gtin? }. Same as suspend, addressed by your serial. 409 ambiguous_serial if the serial isn't unique in your account \u2014 pass `gtin`.\n- archive \u2014 args: { id }. IRREVERSIBLE \u2014 confirm with the user first.\n- archive_by_serial \u2014 args: { serial, gtin? }. IRREVERSIBLE, addressed by your serial \u2014 confirm first. 409 ambiguous_serial if the serial isn't unique \u2014 pass `gtin`.\n- get_qr \u2014 args: { id, format? (svg|png) }. Read-only.\n- get_qr_by_serial \u2014 args: { serial, format? (svg|png), gtin? }. Read-only. Same as get_qr, addressed by your own serial. A serial is unique only WITHIN a GTIN \u2014 if the same serial exists under two GTINs in your account the call returns 409 ambiguous_serial; pass `gtin` (or use get_qr by id) to resolve exactly.",
"execution": {
"taskSupport": "forbidden"
},
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"action": {
"description": "Which passport operation to run. Reads: list | get | get_by_serial | compliance | registry_readiness | get_qr | get_qr_by_serial. Lifecycle: create (BILLABLE) | suspend (reversible) | archive (IRREVERSIBLE), each with a _by_serial variant.",
"enum": [
"list",
"get",
"get_by_serial",
"compliance",
"registry_readiness",
"create",
"suspend",
"suspend_by_serial",
"archive",
"archive_by_serial",
"get_qr",
"get_qr_by_serial"
],
"type": "string"
},
"args": {
"description": "Arguments for the chosen action; required fields depend on `action` (see each action above).",
"properties": {
"confirmOverage": {
"description": "Set true to accept a per-passport overage charge when create is over the plan quota (402).",
"type": "boolean"
},
"format": {
"description": "get/get_by_serial: summary|full. get_qr/get_qr_by_serial: svg|png.",
"type": "string"
},
"gtin": {
"description": "GTIN disambiguator for *_by_serial actions when a serial isn't unique across GTINs (else 409 ambiguous_serial).",
"type": "string"
},
"id": {
"description": "Passport id. Required for get/compliance/create-result/suspend/archive/get_qr (the by-id actions).",
"type": "string"
},
"lang": {
"description": "Resolve field values to one of the 24 EU locales server-side (get/get_by_serial).",
"type": "string"
},
"limit": {
"description": "Page size for list, max 100.",
"type": "number"
},
"page": {
"description": "Page number for list (1-based).",
"type": "number"
},
"productId": {
"description": "Parent product id. Required for create.",
"type": "string"
},
"search": {
"description": "Filter list by a search term.",
"type": "string"
},
"serial": {
"description": "Your own serial number. Required for the *_by_serial actions.",
"type": "string"
},
"serialNumber": {
"description": "Serial for the new passport. Required for create.",
"type": "string"
},
"status": {
"description": "Filter list by status: draft|in_review|approved|published|suspended|expired|archived.",
"type": "string"
}
},
"type": "object"
}
},
"required": [
"action"
],
"type": "object"
},
"name": "tracepass_passports",
"outputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"error": {
"description": "Machine-readable error code, when the API rejected the request.",
"type": "string"
},
"id": {
"description": "The resource's TracePass id, when the response is a single entity.",
"type": "string"
},
"items": {
"description": "The page of results, when the action is a list.",
"items": {},
"type": "array"
},
"limit": {
"description": "Page size (list actions).",
"type": "number"
},
"message": {
"description": "Human-readable error or status detail, when present.",
"type": "string"
},
"page": {
"description": "Current page number (list actions).",
"type": "number"
},
"result": {
"description": "Wraps a non-object response body (e.g. a QR code string)."
},
"total": {
"description": "Total matching records across all pages (list actions).",
"type": "number"
},
"totalPages": {
"description": "Total number of pages (list actions).",
"type": "number"
}
},
"type": "object"
},
"title": "TracePass passports"
},
{
"annotations": {
"idempotentHint": true
},
"description": "Update field values on a Digital Product Passport. Every change is recorded in the passport's audit trail, tagged as an API-key update.\n\nActions (pass via `action`, with `args`):\n- update \u2014 args: { id, fieldKey, value }. `value` type matches the field's dataType (string, number, boolean, array, object).\n- update_by_serial \u2014 args: { serial, fieldKey, value, gtin? }. Same as update, addressed by your own serial. A serial is unique only WITHIN a GTIN \u2014 if it isn't unique in your account the call returns 409 ambiguous_serial; pass `gtin` (or use update by id) to resolve exactly.",
"execution": {
"taskSupport": "forbidden"
},
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"action": {
"description": "Update one passport field, addressed by passport id (update) or by your serial (update_by_serial).",
"enum": [
"update",
"update_by_serial"
],
"type": "string"
},
"args": {
"description": "Arguments for the chosen action; required fields depend on `action`.",
"properties": {
"fieldKey": {
"description": "The field key to set (required).",
"type": "string"
},
"gtin": {
"description": "GTIN disambiguator for update_by_serial when the serial isn't unique (else 409).",
"type": "string"
},
"id": {
"description": "Passport id. Required for update.",
"type": "string"
},
"serial": {
"description": "Your serial. Required for update_by_serial.",
"type": "string"
},
"value": {
"description": "The new value for the field (required). Type depends on the field's dataType."
}
},
"type": "object"
}
},
"required": [
"action"
],
"type": "object"
},
"name": "tracepass_passport_fields",
"outputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"error": {
"description": "Machine-readable error code, when the API rejected the request.",
"type": "string"
},
"id": {
"description": "The resource's TracePass id, when the response is a single entity.",
"type": "string"
},
"items": {
"description": "The page of results, when the action is a list.",
"items": {},
"type": "array"
},
"limit": {
"description": "Page size (list actions).",
"type": "number"
},
"message": {
"description": "Human-readable error or status detail, when present.",
"type": "string"
},
"page": {
"description": "Current page number (list actions).",
"type": "number"
},
"result": {
"description": "Wraps a non-object response body (e.g. a QR code string)."
},
"total": {
"description": "Total matching records across all pages (list actions).",
"type": "number"
},
"totalPages": {
"description": "Total number of pages (list actions).",
"type": "number"
}
},
"type": "object"
},
"title": "TracePass passport fields"
},
{
"annotations": {
"idempotentHint": true
},
"description": "Manage the economic-operator parties on a passport \u2014 manufacturer, importer, authorisedRepresentative, distributor, recycler, producerResponsibilityOrg. Each party carries a legal name and ideally a validated 13-digit GS1 GLN.\n\nActions (pass via `action`, with `args`):\n- set \u2014 args: { id, role, legalName, gln?, country?, legacyOperatorId? }. Sets or updates one role.\n- remove \u2014 args: { id, role }. Clears one role.",
"execution": {
"taskSupport": "forbidden"
},
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"action": {
"description": "Set (add/replace) or remove an economic-operator party on a passport by its role.",
"enum": [
"set",
"remove"
],
"type": "string"
},
"args": {
"description": "Arguments for the chosen action; required fields depend on `action`.",
"properties": {
"country": {
"description": "Party country code (set, optional).",
"type": "string"
},
"gln": {
"description": "GS1 Global Location Number for the party (set, optional).",
"type": "string"
},
"id": {
"description": "Passport id (required).",
"type": "string"
},
"legacyOperatorId": {
"description": "Your internal operator id for the party (set, optional).",
"type": "string"
},
"legalName": {
"description": "Party legal name. Required for set.",
"type": "string"
},
"role": {
"description": "Economic-operator role, e.g. manufacturer | importer | distributor | authorised_representative (required).",
"type": "string"
}
},
"type": "object"
}
},
"required": [
"action"
],
"type": "object"
},
"name": "tracepass_passport_parties",
"outputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"error": {
"description": "Machine-readable error code, when the API rejected the request.",
"type": "string"
},
"id": {
"description": "The resource's TracePass id, when the response is a single entity.",
"type": "string"
},
"items": {
"description": "The page of results, when the action is a list.",
"items": {},
"type": "array"
},
"limit": {
"description": "Page size (list actions).",
"type": "number"
},
"message": {
"description": "Human-readable error or status detail, when present.",
"type": "string"
},
"page": {
"description": "Current page number (list actions).",
"type": "number"
},
"result": {
"description": "Wraps a non-object response body (e.g. a QR code string)."
},
"total": {
"description": "Total matching records across all pages (list actions).",
"type": "number"
},
"totalPages": {
"description": "Total number of pages (list actions).",
"type": "number"
}
},
"type": "object"
},
"title": "TracePass passport parties"
},
{
"annotations": {
"idempotentHint": false
},
"description": "GS1 EPCIS 2.0 supply-chain events. `export` is included on Starter plans and up; `capture`, `capture_job`, and `query` require the paid EPCIS add-on (those actions return a 403-style message without it).\n\nActions (pass via `action`, with `args`):\n- export \u2014 args: { id }. Export a passport's events as an EPCIS 2.0 JSON-LD document. Read-only.\n- export_by_serial \u2014 args: { serial, gtin? }. Same as export, addressed by your own serial. A serial is unique only WITHIN a GTIN \u2014 if it isn't unique in your account the call returns 409 ambiguous_serial; pass `gtin` (or use export by id). Read-only.\n- capture \u2014 args: { events }. `events` is an EPCISDocument, a single event, or an array of events (JSON-LD). Returns a 202 with a captureJobId.\n- capture_job \u2014 args: { jobId }. Poll an async capture job. Read-only.\n- query \u2014 args: { params? }. `params` is a key/value map of standard EPCIS query parameters (EQ_bizStep, GE_eventTime, MATCH_epc, \u2026). Read-only.",
"execution": {
"taskSupport": "forbidden"
},
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"action": {
"description": "EPCIS 2.0: export a passport's events (export | export_by_serial), capture new events, poll a capture job, or query events.",
"enum": [
"export",
"export_by_serial",
"capture",
"capture_job",
"query"
],
"type": "string"
},
"args": {
"description": "Arguments for the chosen action; required fields depend on `action`.",
"properties": {
"events": {
"description": "EPCIS 2.0 event payload (an EPCISDocument or event list). Required for capture."
},
"gtin": {
"description": "GTIN disambiguator for export_by_serial when the serial isn't unique (else 409).",
"type": "string"
},
"id": {
"description": "Passport id. Required for export.",
"type": "string"
},
"jobId": {
"description": "Capture job id to poll. Required for capture_job.",
"type": "string"
},
"params": {
"additionalProperties": {
"type": "string"
},
"description": "EPCIS query parameters as key\u2192value strings (query, optional).",
"propertyNames": {
"type": "string"
},
"type": "object"
},
"serial": {
"description": "Your serial. Required for export_by_serial.",
"type": "string"
}
},
"type": "object"
}
},
"required": [
"action"
],
"type": "object"
},
"name": "tracepass_epcis",
"outputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"error": {
"description": "Machine-readable error code, when the API rejected the request.",
"type": "string"
},
"id": {
"description": "The resource's TracePass id, when the response is a single entity.",
"type": "string"
},
"items": {
"description": "The page of results, when the action is a list.",
"items": {},
"type": "array"
},
"limit": {
"description": "Page size (list actions).",
"type": "number"
},
"message": {
"description": "Human-readable error or status detail, when present.",
"type": "string"
},
"page": {
"description": "Current page number (list actions).",
"type": "number"
},
"result": {
"description": "Wraps a non-object response body (e.g. a QR code string)."
},
"total": {
"description": "Total matching records across all pages (list actions).",
"type": "number"
},
"totalPages": {
"description": "Total number of pages (list actions).",
"type": "number"
}
},
"type": "object"
},
"title": "TracePass EPCIS 2.0"
},
{
"annotations": {
"idempotentHint": true,
"readOnlyHint": true
},
"description": "Discover the regulatory field schema for each DPP category \u2014 what a COMPLIANT passport must contain, per the governing EU regulation. Read-only reference data. Use this to advise on requirements before creating products/passports, and to gap-check a draft against the rules.\n\nActions (pass via `action`, with `args`):\n- list \u2014 args: {}. Lists all 12 categories with their field count, required-field count, and governing regulation (name + number + effective/mandatory dates).\n- get \u2014 args: { category }. Full field schema for one category: every field's key, label, dataType, whether it is REQUIRED, its access level (public/restricted/authority), enum options, validation bounds, and \u2014 where known \u2014 the regulation article/annex that mandates it. `category` is one of: battery, textile, electronics, construction, steel, chemicals, packaging, furniture, tyres, jewelry, toys, fmcg.\n\nBATTERY \u2014 required-ness is per-category, so `required` alone is the wrong answer. Resolve it in this order:\n 1. SCOPE FIRST. Only EV, LMT and industrial_gt_2kwh batteries owe a passport at all (Art. 77(1), Reg (EU) 2023/1542). For portable, SLI or industrial_lte_2kwh, NO field is required \u2014 do not list mandatory fields for them; say the battery is out of scope.\n 2. Then `requiredBy[batteryCategory]` where the field carries that map (required | conditional | notApplicable).\n 3. Then fall back to `required`.\nThe map is keyed ONLY by the three in-scope categories, so skipping step 1 falls through to `required` and invents an obligation the Regulation does not impose. Note also that EV and LMT report state-of-health through MUTUALLY EXCLUSIVE field sets \u2014 an EV battery must leave the remaining-capacity cluster empty and an LMT battery must leave stateOfCertifiedEnergy empty, so no single battery ever fills every field.",
"execution": {
"taskSupport": "forbidden"
},
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"action": {
"description": "List all DPP category templates, or get one template by category.",
"enum": [
"list",
"get"
],
"type": "string"
},
"args": {
"description": "Arguments for the chosen action; `category` is required for get, ignored for list.",
"properties": {
"category": {
"description": "DPP category to fetch (required for get): battery | textile | electronics | construction | steel | chemicals | packaging | furniture | tyres | jewelry | toys | fmcg.",
"type": "string"
}
},
"type": "object"
}
},
"required": [
"action"
],
"type": "object"
},
"name": "tracepass_templates",
"outputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"additionalProperties": false,
"properties": {
"error": {
"description": "Machine-readable error code, when the API rejected the request.",
"type": "string"
},
"id": {
"description": "The resource's TracePass id, when the response is a single entity.",
"type": "string"
},
"items": {
"description": "The page of results, when the action is a list.",
"items": {},
"type": "array"
},
"limit": {
"description": "Page size (list actions).",
"type": "number"
},
"message": {
"description": "Human-readable error or status detail, when present.",
"type": "string"
},
"page": {
"description": "Current page number (list actions).",
"type": "number"
},
"result": {
"description": "Wraps a non-object response body (e.g. a QR code string)."
},
"total": {
"description": "Total matching records across all pages (list actions).",
"type": "number"
},
"totalPages": {
"description": "Total number of pages (list actions).",
"type": "number"
}
},
"type": "object"
},
"title": "TracePass DPP templates (regulatory schemas)"
}
]
}
},
"url": "https://ai.tracepass.eu/mcp"
},
"latency_ms": 307.87,
"status": "ok"
},
"transport_compliance_probe": {
"details": {
"bad_protocol_error": null,
"bad_protocol_headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=31536000; includeSubDomains"
},
"bad_protocol_payload": {
"error": {
"code": -32000,
"message": "Bad Request: Unsupported protocol version: 1999-99-99 (supported versions: 2025-11-25, 2025-06-18, 2025-03-26, 2024-11-05, 2024-10-07)"
},
"id": null,
"jsonrpc": "2.0"
},
"bad_protocol_status_code": 400,
"delete_error": null,
"delete_status_code": null,
"expired_session_error": null,
"expired_session_status_code": null,
"issues": [
"missing_session_id",
"missing_protocol_header"
],
"last_event_id_visible": false,
"protocol_header_present": false,
"requested_protocol_version": "2025-03-26",
"session_id_present": false,
"transport": "streamable-http"
},
"latency_ms": 295.28,
"status": "warning"
},
"utility_coverage_probe": {
"details": {
"completions": {
"advertised": false,
"live_probe": "not_executed",
"sample_target": {
"argument_name": "passportId",
"name": "audit_passport",
"type": "prompt"
}
},
"initialize_capability_keys": [
"prompts",
"resources",
"tools"
],
"pagination": {
"metadata_signal": false,
"next_cursor_methods": [],
"supported": false
},
"tasks": {
"advertised": false,
"http_status": 401,
"probe_status": "auth_required"
}
},
"latency_ms": 95.54,
"status": "ok"
}
},
"failures": {
"openid_configuration": {
"error": "Client error '404 Not Found' for url 'https://app.tracepass.eu/.well-known/openid-configuration'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404",
"url": "https://app.tracepass.eu/.well-known/openid-configuration"
},
"prompt_get": {
"error": "Client error '401 Unauthorized' for url 'https://ai.tracepass.eu/mcp'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/401",
"headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=31536000; includeSubDomains",
"www-authenticate": "Bearer realm=\"TracePass MCP\", error=\"invalid_token\", resource_metadata=\"https://ai.tracepass.eu/.well-known/oauth-protected-resource\", error_description=\"Authenticate with a TracePass API key (Developer -> API Keys, send Authorization: Bearer <tp_ key>) or via OAuth (see resource_metadata).\""
},
"http_status": 401,
"payload": {},
"prompt_arguments": [
{
"description": "The TracePass id of the passport to audit.",
"name": "passportId",
"required": true
}
],
"prompt_name": "audit_passport",
"reason": "auth_required",
"url": "https://ai.tracepass.eu/mcp"
},
"resource_read": {
"error": "Client error '401 Unauthorized' for url 'https://ai.tracepass.eu/mcp'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/401",
"headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=31536000; includeSubDomains",
"www-authenticate": "Bearer realm=\"TracePass MCP\", error=\"invalid_token\", resource_metadata=\"https://ai.tracepass.eu/.well-known/oauth-protected-resource\", error_description=\"Authenticate with a TracePass API key (Developer -> API Keys, send Authorization: Bearer <tp_ key>) or via OAuth (see resource_metadata).\""
},
"http_status": 401,
"payload": {},
"reason": "auth_required",
"resource_uri": "tracepass://products",
"url": "https://ai.tracepass.eu/mcp"
}
},
"remote_url": "https://ai.tracepass.eu/mcp",
"server_card_payload": null,
"server_identifier": "awesome-malinoto/tracepass-mcp-server"
}