openaccountants/openaccountants
openaccountants/openaccountants openaccountants/openaccountants](https://glama.ai/mcp/servers/openaccountants/openaccountants) 📇 ☁️ - Open-source accounting skills reviewed by licensed accountants, covering income tax, VAT and payroll by country, US state and Canadian province.
Allow With Approval
trustsnap_e0543e7c71aedafb.- Utility Coverage
- Transport Compliance
- Resource Contract
- Add an explicit confirm/dry-run parameter or two-step confirmation flow to write, delete, exec, and egress-capable tool…
- Align MCP-Protocol-Version, MCP-Session-Id, DELETE teardown, and expired-session handling with the transport spec.
- Only send roots/list, sampling/createMessage, or elicitation/create requests while handling an active client-initiated…
- Machine trust evaluator activity
- Possible agent/script activity
- AI crawler activity
- Search crawler activity
- profile / compare / compare API / policy / ledger inspection
Dispute this assessment
If any published claim about this server -- its score, a risk flag, a capability classification, or its taxonomy -- is factually wrong, tell us what evidence shows and we will review it. This does not require claiming or verifying ownership of the server first.
Verify responds to disputes within 5 business days and resolves them within 15.
Dispute history
No disputes filed for this server.
Risks
Security posture
Tool capability & risk inventory
| Tool | Capabilities | Risk | Findings | Notes | Evidence |
|---|---|---|---|---|---|
list_skills |
read network admin | Medium | arbitrary network egress freeform input surface | Safeguards hinted in metadata. |
Schema & evidence{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": false,
"readOnlyHint": true,
"title": "List tax & accounting skills"
},
"capabilities": [
"read",
"network",
"admin"
],
"input_schema": {
"properties": {
"category": {
"description": "(Legacy) display label; prefer domain/role.",
"type": "string"
},
"domain": {
"description": "Filter by accounting domain: income-tax, vat-gst, payroll, bookkeeping, e-invoicing, formation, financial-statements, transfer-pricing, tax-optimization, crypto, cross-border, corporate-tax, estate-wealth-tax, references, sector-guidance, tooling.",
"type": "string"
},
"jurisdiction": {
"description": "Filter by jurisdiction code, e.g. 'US', 'MT', 'DE'",
"type": "string"
},
"limit": {
"description": "Max skills to return (default 100, max 200).",
"type": "integer"
},
"offset": {
"description": "Number of skills to skip \u2014 use the next_offset from the previous response to page through results (default 0).",
"type": "integer"
},
"role": {
"description": "Filter by pipeline role: foundation, compute, orchestrator, reference.",
"type": "string"
}
},
"type": "object"
},
"risk_flags": [
"arbitrary_network_egress",
"freeform_input_surface"
]
}
Dispute this classification
|
get_skill |
read | Low | none | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": false,
"readOnlyHint": true,
"title": "Get a tax skill"
},
"capabilities": [
"read"
],
"input_schema": {
"properties": {
"reason": {
"description": "One sentence on WHY you're making this call, in the user's terms (for routing analysis only). Optional.",
"type": "string"
},
"slug": {
"description": "Skill slug, e.g. 'us-schedule-c-and-se-computation'",
"type": "string"
}
},
"required": [
"slug"
],
"type": "object"
},
"risk_flags": []
}
Dispute this classification
|
get_skill_sections |
read | Low | none | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": false,
"readOnlyHint": true,
"title": "Get a skill's sections"
},
"capabilities": [
"read"
],
"input_schema": {
"properties": {
"section_index": {
"description": "Optional. Return only this section (matches the `index` from get_skill's `section_index`).",
"type": "integer"
},
"section_indices": {
"description": "Optional. Return only these sections.",
"items": {
"type": "integer"
},
"type": "array"
},
"slug": {
"description": "Skill slug",
"type": "string"
}
},
"required": [
"slug"
],
"type": "object"
},
"risk_flags": []
}
Dispute this classification
|
search_skills |
read network | Medium | arbitrary network egress freeform input surface | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": false,
"readOnlyHint": true,
"title": "Search skills by keyword"
},
"capabilities": [
"read",
"network"
],
"input_schema": {
"properties": {
"content_type": {
"description": "What kind of Guide to find. 'method' = step-by-step procedures you EXECUTE via start() (formerly 'workflows'); 'fact' or omitted = reference material (rates/thresholds/rules). A Guide can be either or both.",
"enum": [
"method",
"fact"
],
"type": "string"
},
"domain": {
"description": "Optional accounting domain to limit the search (e.g. 'vat-gst', 'payroll', 'income-tax', 'crypto').",
"type": "string"
},
"jurisdiction": {
"description": "Optional ISO 2-letter country code to limit the search",
"type": "string"
},
"query": {
"description": "Search term, e.g. 'home office deduction', 'crypto capital gains', 'reverse charge'. With content_type='method', a broad term (or the domain word) lists the available methods.",
"type": "string"
}
},
"required": [
"query"
],
"type": "object"
},
"risk_flags": [
"arbitrary_network_egress",
"freeform_input_surface"
]
}
Dispute this classification
|
search_rules |
read | Low | none | Safeguards hinted in metadata. |
Schema & evidence{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": false,
"readOnlyHint": true,
"title": "Search rules across jurisdictions"
},
"capabilities": [
"read"
],
"input_schema": {
"properties": {
"block_types": {
"description": "Rule kinds to include. Default = all of these (framing prose + workflow steps are excluded).",
"items": {
"enum": [
"rate",
"threshold",
"rule",
"formula",
"refusal_code",
"definition",
"table_ref",
"table"
],
"type": "string"
},
"type": "array"
},
"domains": {
"description": "Accounting domains, e.g. ['vat-gst','income-tax']. See list_rule_facets.",
"items": {
"type": "string"
},
"type": "array"
},
"jurisdictions": {
"description": "ISO codes to include, e.g. ['MT','US-CA']. Omit for all jurisdictions.",
"items": {
"type": "string"
},
"type": "array"
},
"limit": {
"description": "Max rules to return (default 200, max 500).",
"type": "integer"
},
"offset": {
"description": "Pagination offset \u2014 pass the previous response's next_offset.",
"type": "integer"
},
"reason": {
"description": "One sentence on WHY you're making this call, in the user's terms (for routing analysis only). Optional.",
"type": "string"
},
"roles": {
"description": "Skill roles: foundation | compute | orchestrator | reference.",
"items": {
"type": "string"
},
"type": "array"
},
"status": {
"description": "Shorthand for `statuses`: 'verified' = accountant- + research-verified only. Default 'all'.",
"enum": [
"all",
"verified"
],
"type": "string"
},
"statuses": {
"description": "Verification statuses to include. Default = all (each rule is tagged).",
"items": {
"enum": [
"draft",
"research_verified",
"accountant_verified",
"needs_update",
"unsure"
],
"type": "string"
},
"type": "array"
},
"tax_year": {
"description": "Limit to a tax year, e.g. 2025.",
"type": "integer"
},
"text": {
"description": "Free-text search over each rule's label, value, and citation.",
"type": "string"
},
"topic": {
"description": "Filter by a fact topic.",
"type": "string"
}
},
"type": "object"
},
"risk_flags": []
}
Dispute this classification
|
get_deadlines |
read network | Medium | arbitrary network egress | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": false,
"readOnlyHint": true,
"title": "Upcoming tax deadlines for a jurisdiction"
},
"capabilities": [
"read",
"network"
],
"input_schema": {
"properties": {
"horizon_days": {
"description": "How far ahead to look (default 120, max 366).",
"type": "integer"
},
"jurisdiction": {
"description": "ISO code, slug, or name ('MT', 'US-CA', 'Malta'). Optional for signed-in users with a saved home jurisdiction.",
"type": "string"
}
},
"type": "object"
},
"risk_flags": [
"arbitrary_network_egress"
]
}
Dispute this classification
|
list_rule_facets |
read | Low | none | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": false,
"readOnlyHint": true,
"title": "List queryable rule facets (no args)"
},
"capabilities": [
"read"
],
"input_schema": {
"properties": {},
"type": "object"
},
"risk_flags": []
}
Dispute this classification
|
start_help |
read | Low | none | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": false,
"readOnlyHint": true,
"title": "Get tax-workflow scoping guidance (no args)"
},
"capabilities": [
"read"
],
"input_schema": {
"properties": {},
"type": "object"
},
"risk_flags": []
}
Dispute this classification
|
start |
read network | Medium | arbitrary network egress | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": false,
"readOnlyHint": true,
"title": "Start a tax workflow"
},
"capabilities": [
"read",
"network"
],
"input_schema": {
"properties": {
"acting_as": {
"description": "REQUIRED. Who the user is: 'self' = a taxpayer handling their OWN taxes; 'client' = a professional (accountant/advisor) working on behalf of a CLIENT. Establish this before calling \u2014 if it isn't clear from the conversation, ask the user one short question ('Are these your own taxes, or are you helping a client?'). Never guess.",
"enum": [
"self",
"client"
],
"type": "string"
},
"intent": {
"description": "User intent \u2014 REQUIRED. Free text, e.g. 'taxes', 'VAT return', 'set up a company'.",
"type": "string"
},
"jurisdiction": {
"description": "ISO 2-letter code or US state code (e.g. 'MT', 'GB', 'US-CA').",
"type": "string"
},
"reason": {
"description": "One sentence, in the user's own words, on what they actually asked for here \u2014 captured only to improve routing. E.g. 'user sold ETH and wants to know what to report'. Optional but helpful.",
"type": "string"
},
"taxpayer_type": {
"description": "The taxpayer's occupation, when known. Some return-prep workflows fork by it (an employee's Form 1040 is a different guide from a freelancer's). Pass it if the conversation already makes it clear; otherwise omit \u2014 start() only asks for it (status:'needs_clarification', needs:['taxpayer_type']) when the guides for this jurisdiction/intent genuinely split by occupation. 'employee' = W-2 wages only; 'self-employed' = freelance / 1099 / sole-proprietor; 'both' = employed AND self-employed; 'company' = a corporate entity. Don't guess \u2014 ask the user one short question if unsure.",
"enum": [
"employee",
"self-employed",
"both",
"company",
"other"
],
"type": "string"
}
},
"required": [
"intent"
],
"type": "object"
},
"risk_flags": [
"arbitrary_network_egress"
]
}
Dispute this classification
|
list_jurisdictions |
read | Low | none | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": false,
"readOnlyHint": true,
"title": "List all jurisdictions covered"
},
"capabilities": [
"read"
],
"input_schema": {
"properties": {},
"type": "object"
},
"risk_flags": []
}
Dispute this classification
|
list_verifiers |
read network | Medium | arbitrary network egress | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": false,
"readOnlyHint": true,
"title": "List named accountant verifiers"
},
"capabilities": [
"read",
"network"
],
"input_schema": {
"properties": {
"jurisdiction": {
"description": "Optional ISO code filter \u2014 only return verifiers for this jurisdiction.",
"type": "string"
}
},
"type": "object"
},
"risk_flags": [
"arbitrary_network_egress"
]
}
Dispute this classification
|
validate_vat_number |
read network | Medium | arbitrary network egress freeform input surface | Safeguards hinted in metadata. |
Schema & evidence{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": true,
"readOnlyHint": true,
"title": "Validate an EU VAT number (live VIES lookup)"
},
"capabilities": [
"read",
"network"
],
"input_schema": {
"properties": {
"country_code": {
"description": "2-letter EU member-state code of the VAT number, e.g. 'DE', 'IE', 'FR'. Use 'EL' for Greece and 'XI' for Northern Ireland. May be omitted if the country prefix is already part of vat_number.",
"type": "string"
},
"vat_number": {
"description": "The VAT number, with or without the country prefix and spaces, e.g. 'IE6388047V', 'IE 6388047V', or '6388047V'.",
"type": "string"
}
},
"required": [
"vat_number"
],
"type": "object"
},
"risk_flags": [
"arbitrary_network_egress",
"freeform_input_surface"
]
}
Dispute this classification
|
check_audit_exemption |
read network | Medium | arbitrary network egress | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {
"destructiveHint": false,
"idempotentHint": true,
"openWorldHint": false,
"readOnlyHint": true,
"title": "Check statutory audit exemption"
},
"capabilities": [
"read",
"network"
],
"input_schema": {
"properties": {
"balance_sheet_total": {
"description": "Total assets at the balance sheet date.",
"type": "number"
},
"currency": {
"description": "Currency of the figures \u2014 must match the regime (EUR for MT, GBP for GB); convert first, never guess a rate.",
"type": "string"
},
"employees_average": {
"description": "Average number of employees during the year.",
"type": "number"
},
"entity_type": {
"description": "Optional. 'private_ltd' (default), 'plc', 'branch'. Non-private shapes route to a human.",
"type": "string"
},
"financial_year_end": {
"description": "ISO date the financial year ends, e.g. '2025-12-31'.",
"type": "string"
},
"group_member": {
"description": "Optional. True if the company is part of a group \u2014 group thresholds need a reviewer, so this forces 'review'.",
"type": "boolean"
},
"jurisdiction": {
"description": "ISO-style code. MT and GB supported today.",
"type": "string"
},
"prior_year": {
"description": "Prior-year figures for the two-consecutive-years test.",
"properties": {
"balance_sheet_total": {
"type": "number"
},
"employees_average": {
"type": "number"
},
"turnover": {
"type": "number"
}
},
"type": "object"
},
"turnover": {
"description": "Revenue/turnover for the year, in the jurisdiction's currency.",
"type": "number"
}
},
"required": [
"jurisdiction",
"financial_year_end",
"turnover",
"balance_sheet_total",
"employees_average",
"currency"
],
"type": "object"
},
"risk_flags": [
"arbitrary_network_egress"
]
}
Dispute this classification
|
share_with_openaccountants |
write delete network | High | destructive operation arbitrary network egress | No explicit safeguard hints detected. |
Schema & evidence{
"annotations": {
"destructiveHint": true,
"idempotentHint": false,
"openWorldHint": false,
"readOnlyHint": false,
"title": "Share this with OpenAccountants"
},
"capabilities": [
"write",
"delete",
"network"
],
"input_schema": {
"properties": {
"contact_email": {
"description": "Review only, REQUIRED when request_review: the user's email. Ask for it first.",
"type": "string"
},
"contact_name": {
"description": "Review only: the user's name.",
"type": "string"
},
"jurisdiction": {
"description": "Review only: ISO code or slug for the user's tax jurisdiction (e.g. 'US-CA').",
"type": "string"
},
"note": {
"description": "Anonymized improvement note: what the guidance covered vs what you added or worked around and why, or a bug in a specific skill. No names, amounts, or PII.",
"type": "string"
},
"request_review": {
"description": "true only when the user has asked for a licensed accountant to review their figures. Requires working_paper + jurisdiction + scenario + contact_email. Omit/false = just the note.",
"type": "boolean"
},
"scenario": {
"description": "Review only: brief description of the situation to review.",
"type": "string"
},
"skill_slug": {
"description": "Optional: set when the note is feedback about a SPECIFIC skill (e.g. 'us-sales-tax'). Replaces the old submit_feedback.",
"type": "string"
},
"tax_year": {
"description": "Review only: tax year, if relevant.",
"type": "integer"
},
"working_paper": {
"description": "Review only: the COMPLETE working paper markdown \u2014 every line item and assumption, not a summary.",
"type": "string"
}
},
"required": [
"note"
],
"type": "object"
},
"risk_flags": [
"destructive_operation",
"arbitrary_network_egress"
]
}
Dispute this classification
|
Write-action governance
Status detail: 1 high-risk tool(s), 1 destructive tool(s); auth boundary is oauth or auth required with 3 safeguard(s) and 3 confirmation signal(s).
| Tool | Risk | Flags | Safeguards |
|---|---|---|---|
share_with_openaccountants |
High | destructive operation arbitrary network egress | no |
Recommended runtime policy
No policy blockers under the default policy stance.
Action-controls diff
New actions
| Action | Risk | Flags |
|---|---|---|
| No newly added actions. | ||
Changed actions
| Action | Change types | Risk |
|---|---|---|
| No materially changed actions. | ||
Critical alerts
Compatibility
Client readiness verdicts
Client compatibility only means the server shape can work with a client. Production trust decision and write-action publishing are evaluated separately so a client-compatible server can still be blocked for production.
Evidence provenance
initialize• OKtools_list• OKtransport_compliance_probe• Errorstep_up_auth_probe• Warningconnector_replay_probe• OK — Frozen tool snapshots must survive refresh.request_association_probe• Warning — Roots, sampling, and elicitation should stay request-scoped.
Evidence provenance
initialize• OKtools_list• OKtransport_compliance_probe• Error
Evidence provenance
action_safety_probe• Warning
Evidence provenance
tool_snapshot_probe• OKconnector_replay_probe• OK
Client readiness gate details
Remediation checklist
- Resolve the transport compliance failure -- see the transport compliance probe evidence for what specifically broke.
- Limit the exposed surface to search/fetch-style read tools.
- Remove or isolate write, delete, and exec-capable tools before using this read/search-only client profile.
- Remove export, bulk, mutating, and high-blast-radius exposure before certifying company-knowledge use.
- Satisfy OAuth, compatibility, and connector-refresh requirements before using the Messages API remote MCP path.
- Resolve transport compliance issues before wider client rollout.
Remediation checklist
- Resolve the transport compliance failure -- see the transport compliance probe evidence for what specifically broke.
- Limit the exposed surface to search/fetch-style read tools.
- Remove or isolate write, delete, and exec-capable tools before using this read/search-only client profile.
- Remove export, bulk, mutating, and high-blast-radius exposure before certifying company-knowledge use.
- Satisfy OAuth, compatibility, and connector-refresh requirements before using the Messages API remote MCP path.
- Resolve transport compliance issues before wider client rollout.
Remediation checklist
- Confirm the flagged action-safety risk before treating this as write-safe.
Verdict traces
instruction_tool_reference_mismatch• low • Server instructions name unavailable tools
Client verdict trace table
| Verdict | Status | Checks | Winning source | Conflicts |
|---|---|---|---|---|
openai_connectors |
Not client-compatible | initialize, tools_list, transport_compliance_probe, step_up_auth_probe, connector_replay_probe, request_association_probe | live_validation | none |
claude_desktop |
Not client-compatible | initialize, tools_list, transport_compliance_probe | live_validation | none |
unsafe_for_write_actions |
Publishing blocked | action_safety_probe | live_validation | none |
snapshot_churn_risk |
Low | tool_snapshot_probe, connector_replay_probe | history | none |
Publishability policy profiles
- Search Fetch Only: No
- Write Actions Present: Yes
- Oauth Configured: Yes
- Admin Refresh Required: No
- Safe For Company Knowledge: No
- Safe For Messages Api Remote Mcp: No
- Search Fetch Only: No
- Write Actions Present: Yes
- Oauth Configured: Yes
- Admin Refresh Required: No
- Safe For Company Knowledge: No
- Safe For Messages Api Remote Mcp: No
Compatibility fixtures
- remote_http_endpoint: Passes
- oauth_discovery: Passes
- frozen_tool_snapshot_refresh: Passes
- request_association: Passes
- remote_transport: Passes
- tool_discovery: Passes
- auth_connect: Passes
- safe_write_review: Degraded
Recommended for
Evidence
Current trust snapshot
trustsnap_e0543e7c71aedafbCanonical machine links
Evidence confidence
Latest validation evidence
Failures
openid_configurationClient error '404 Not Found' for url 'https://www.openaccountants.com/.well-known/openid-configuration' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404resources_listJSON-RPC error -32601: Method not found: resources/listtransport_compliance_probeIssues: missing protocol header, bad protocol not rejected, delete session unexpected, expired session not 404 (bad protocol=200, DELETE=405, expired session=200).
Checks
| Check | Status | Latency | Evidence |
|---|---|---|---|
action_safety_probe |
Warning | n/a | 1 high-risk, 1 destructive, 8 egress-capable, 1 declared non-read-only, non-read capabilities: write, delete tool(s); auth present; safeguards=3; confirmation=search rules, start help, validate vat number. |
advanced_capabilities_probe |
Warning | n/a | Only 3 capability signal(s): prompts, sampling, structured outputs. |
connector_publishability_probe |
Warning | n/a | Publishability blockers: protocol version, step up auth, transport compliance, request association, +1 more. |
connector_replay_probe |
OK | n/a | Backward compatible with no breaking tool-surface changes. |
determinism_probe |
OK | 184.4 ms | Check completed |
initialize |
OK | 250.7 ms | Protocol 2025-03-26 |
instruction_tool_reference_probe |
Warning | n/a | Check completed |
interactive_flow_probe |
OK | n/a | Check completed |
oauth_authorization_server |
OK | 73.7 ms | authorization_endpoint, code_challenge_methods_supported, grant_types_supported, issuer |
oauth_protected_resource |
OK | 74.5 ms | 1 authorization server(s) |
official_registry_probe |
Missing | n/a | Check completed |
openid_configuration |
Error | 88.0 ms | Client error '404 Not Found' for url 'https://www.openaccountants.com/.well-known/openid-configuration' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404 |
probe_noise_resilience |
OK | 211.6 ms | Fetched https://www.openaccountants.com/robots.txt |
prompt_get |
OK | 178.8 ms | 1 prompt message(s) returned |
prompts_list |
OK | 178.9 ms | 13 prompt(s) exposed |
protocol_version_probe |
Warning | n/a | Claims 2025-03-26; 2 release(s) behind 2025-11-25. |
provenance_divergence_probe |
Not_Assessed | n/a | Check completed |
request_association_probe |
Warning | 72.6 ms | Advertised=sampling; observed=none. |
resource_read |
Missing | n/a | no resource uri |
resources_list |
Error | 177.9 ms | JSON-RPC error -32601: Method not found: resources/list |
schema_divergence_probe |
Missing | n/a | no server card tools |
server_card |
OK | 77.0 ms | authentication, branding, capabilities, categories |
session_resume_probe |
OK | 177.7 ms | 14 tool(s) exposed |
step_up_auth_probe |
Warning | n/a | Scopes=email, openid, profile. |
tool_snapshot_probe |
OK | n/a | Check completed |
tools_list |
OK | 190.1 ms | 14 tool(s) exposed |
transport_compliance_probe |
Error | 246.1 ms | Issues: missing protocol header, bad protocol not rejected, delete session unexpected, expired session not 404 (bad protocol=200, DELETE=405, expired session=200). |
utility_coverage_probe |
Warning | 175.2 ms | No completions evidence; pagination supported; tasks missing. |
Known versions
- No versions recorded.
Public server reputation
Benchmark tasks
| Benchmark task | Status | Evidence |
|---|---|---|
| Discover tools | Passes |
|
| Read-only fetch flow | Degraded |
|
| OAuth-required connect | Passes |
|
| Safe write flow with confirmation | Degraded |
|
Utility coverage
Tool snapshot diff & changelog
Required-argument changes
| Tool | Added required args | Removed required args |
|---|---|---|
| No required-argument changes detected. | ||
Output-schema drift
| Tool | Previous properties | Latest properties |
|---|---|---|
| No output-schema drift detected. | ||
Validation diff
Regressed checks: none
Improved checks: none
Newly assessed dimensions: none
No longer assessed dimensions: none
| Component | Previous | Latest | Delta |
|---|---|---|---|
| No component deltas between the latest two runs. | |||
Registry & provenance divergence
Active alerts
- Server instructions name unavailable tools (low)
Initialize instructions reference tools not present in tools/list: candidate_intents, human_backing, it, jurisdiction_source, note, one_action, orientation, personal_context, section_index, skill_slug
Aliases & registry graph
| Identifier | Source | Canonical | Identity evidence | Score |
|---|---|---|---|---|
awesome-openaccountants/openaccountants |
awesome_mcp_servers | yes | canonical | 72.9 |
openaccountants/openaccountants |
glama_registry | no | repo_slug | n/a |
Alias consolidation
Strong alias identity requires matching remote URL, server-card URL, repository slug, or explicit registry cross-reference; shared provider namespace alone is not identity.
Source disagreements
| Field | What differs | Observed values |
|---|---|---|
| Registry source | Multiple registries or registry sync paths claim this same canonical server. | awesome_mcp_servers glama_registry |
| Homepage | Registry entries disagree on the primary homepage for this server. | https://github.com/openaccountants/openaccountants https://glama.ai/mcp/servers/do7jqh56go |
| Registry identifier | Different registry-specific identifiers resolve to the same canonical server record here. | awesome_mcp_servers:openaccountants/openaccountants glama_registry:do7jqh56go |
Fix it
Why this score?
Algorithmic score breakdown
1 component(s) not assessed for this run: Provenance Divergence
Experimental candidate components
Actionable remediation
| Severity | Remediation | Why it matters | Recommended action |
|---|---|---|---|
| High | Add confirmation and dry-run semantics for risky actions | High-risk write, delete, exec, or egress tools should communicate safeguards clearly. | Add an explicit confirm/dry-run parameter or two-step confirmation flow to write, delete, exec, and egress-capable tools before they can make destructive changes.Playbook
|
| High | Align session and protocol behavior with Streamable HTTP expectations | Clients increasingly rely on MCP-Protocol-Version, session teardown, and expired-session semantics. | Align MCP-Protocol-Version, MCP-Session-Id, DELETE teardown, and expired-session handling with the transport spec.Playbook
|
| High | Associate roots, sampling, and elicitation with active client requests | Modern MCP guidance expects roots, sampling, and elicitation traffic to be tied to an active client request instead of arriving unsolicited on idle sessions. | Only send roots/list, sampling/createMessage, or elicitation/create requests while handling an active client-initiated request, never on idle sessions.Playbook
|
| Medium | Adopt a current MCP protocol revision | Older protocol revisions reduce compatibility with newer clients and registry programs. | Advertise a current MCP protocol revision (2025-06-18 or later) in both the initialize response and the MCP-Protocol-Version header.Playbook
|
| Medium | Close connector-publishing gaps | Connector catalogs care about protocol recency, session behavior, auth clarity, and tool-surface stability. | Resolve every blocker named by connector_publishability_probe, then rerun it before submitting or refreshing a connector listing.Playbook
|
| Medium | Document minimal scopes and return cleaner auth challenges | Modern clients expect granular scopes and step-up auth signals such as WWW-Authenticate scope hints. | Return granular scopes and WWW-Authenticate challenge hints instead of forcing overly broad auth upfront.Playbook
|
| Medium | Publish OpenID configuration | OIDC metadata improves token validation and client compatibility. | Expose /.well-known/openid-configuration with issuer, jwks_uri, and supported grants.Playbook
|
| Medium | Raise Adoption & Market score | Adoption clues and public evidence that the server is intended for external use. | Increase external documentation and directory coverage so users can discover and evaluate the server. |
| Medium | Repair resources/list or stop advertising resources | Resource metadata should either work live or be removed from the advertised capability set. | Only advertise resources if resources/list works and resources expose stable URIs/types.Playbook
|
| Low | Expose modern utility surfaces like completions, pagination, or tasks | Utility coverage improves interoperability with larger clients and long-lived agent workflows. | Expose completions, pagination, and task metadata where supported so larger clients can plan and resume work safely.Playbook
|
| Low | Publish newer MCP capability signals | Roots, sampling, elicitation, structured outputs, and related metadata improve client understanding and ranking. | Advertise only the advanced capabilities (roots, sampling, elicitation) you have actually implemented end to end in the initialize capabilities object.Playbook
|
| Low | Publish or reconcile the server in the official MCP registry | Official registry presence improves discovery confidence and cross-source consistency. | Create or update the official MCP registry entry with the canonical MCP endpoint and matching repository metadata, then rerun official_registry_probe.Playbook
|
| Low | Remove stale tool names from server instructions | Initialize instructions explicitly reference tools that tools/list does not expose. | Update initialize instructions so every explicitly named tool exists in tools/list.Playbook
|
Point loss breakdown
| Component | Current | Points missing |
|---|---|---|
| Utility Coverage | 1/4 | -3.0 |
| Transport Compliance | 1/4 | -3.0 |
| Resource Contract | 1/4 | -3.0 |
| Recovery Semantics | 1/4 | -3.0 |
| Error Contract Quality | 1/4 | -3.0 |
| Supply Chain Signal | 1/4 | -3.0 |
| Advanced Capability Coverage | 1/4 | -3.0 |
| Spec Recency | 2/4 | -2.0 |
| Security Hygiene | 2/4 | -2.0 |
| Request Association | 2/4 | -2.0 |
| Registry Consistency | 2/4 | -2.0 |
| Rate-Limit Semantics | 2/4 | -2.0 |
Technical compatibility profiles
These scores measure technical client compatibility only. Client publishability and production readiness are evaluated separately against policy, transport, and write-surface blockers.
Connector URL: https://www.openaccountants.com/api/mcp # Complete OAuth in the client when prompted. # Server: awesome-openaccountants/openaccountants
{
"mcpServers": {
"openaccountants": {
"command": "npx",
"args": ["mcp-remote", "https://www.openaccountants.com/api/mcp"]
}
}
}
smithery mcp add "https://www.openaccountants.com/api/mcp"
curl -sS https://www.openaccountants.com/api/mcp -H 'content-type: application/json' -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-03-26","capabilities":{},"clientInfo":{"name":"mcp-verify","version":"0.1.0"}}}'
Governance
MCP TrustOps
TrustOps turns this report into operational controls: validation targets and SLAs, authenticated validation, semantic benchmarks, policy exports, alert subscriptions, badges, cost/compliance metadata, and runtime routing. Fresh trusted index decisions stay separate from long-tail inventory so stale scores do not masquerade as current evidence.
/v1/decideAlert subscription types
MCP Runtime hosting
Verify Hosted MCP turns a trusted server report into a managed remote MCP endpoint with GitHub deployment provenance, sandbox policy, encrypted secrets, release history, rollback, and audit/usage events.
/hosted/{namespace}/{name}/mcp| Deployment | Status | Endpoint | Release |
|---|---|---|---|
| No hosted runtime deployments yet. | |||
Authenticated validation sessions
Public validation is free. Authenticated validation is paid and proves scoped behavior, write-action safeguards, and authenticated tool execution.
/v1/verify/v1/ci/previewInstall snippets
Connector URL: https://www.openaccountants.com/api/mcp # Complete OAuth in the client when prompted. # Server: awesome-openaccountants/openaccountants
{
"mcpServers": {
"openaccountants": {
"command": "npx",
"args": ["mcp-remote", "https://www.openaccountants.com/api/mcp"]
}
}
}
smithery mcp add "https://www.openaccountants.com/api/mcp"
curl -sS https://www.openaccountants.com/api/mcp -H 'content-type: application/json' -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-03-26","capabilities":{},"clientInfo":{"name":"mcp-verify","version":"0.1.0"}}}'
Agent access & tool surface
tools/list, prompts/list, and resources/list checks.awesome-openaccountants/openaccountants.History
Validation history
| Timestamp | Status | Score | Latency | Tools |
|---|---|---|---|---|
| Sep 27, 2026 11:09:20 PM UTC | Healthy | 72.9 | 2985.8 ms | 14 |
| Sep 27, 2026 05:09:00 PM UTC | Healthy | 72.9 | 3234.9 ms | 14 |
| Sep 27, 2026 11:08:29 AM UTC | Healthy | 72.9 | 3254.4 ms | 14 |
| Sep 27, 2026 05:08:08 AM UTC | Healthy | 72.9 | 3080.9 ms | 14 |
| Sep 26, 2026 11:07:40 PM UTC | Healthy | 72.9 | 3001.1 ms | 14 |
| Sep 26, 2026 05:07:11 PM UTC | Healthy | 72.9 | 3500.9 ms | 14 |
| Sep 26, 2026 11:06:57 AM UTC | Healthy | 72.9 | 2954.4 ms | 14 |
| Sep 26, 2026 05:06:26 AM UTC | Healthy | 72.9 | 2958.7 ms | 14 |
| Sep 25, 2026 11:06:09 PM UTC | Healthy | 72.9 | 2901.9 ms | 14 |
| Sep 25, 2026 05:05:56 PM UTC | Healthy | 72.9 | 3159.0 ms | 14 |
Validation timeline
| Validated | Summary | Score | Protocol | Auth mode | Tools | High-risk tools | Changes |
|---|---|---|---|---|---|---|---|
| Sep 27, 2026 11:09:20 PM UTC | Healthy | 72.9 | 2025-03-26 | oauth_supported | 14 | 1 | none |
| Sep 27, 2026 05:09:00 PM UTC | Healthy | 72.9 | 2025-03-26 | oauth_supported | 14 | 1 | none |
| Sep 27, 2026 11:08:29 AM UTC | Healthy | 72.9 | 2025-03-26 | oauth_supported | 14 | 1 | none |
| Sep 27, 2026 05:08:08 AM UTC | Healthy | 72.9 | 2025-03-26 | oauth_supported | 14 | 1 | none |
| Sep 26, 2026 11:07:40 PM UTC | Healthy | 72.9 | 2025-03-26 | oauth_supported | 14 | 1 | none |
| Sep 26, 2026 05:07:11 PM UTC | Healthy | 72.9 | 2025-03-26 | oauth_supported | 14 | 1 | none |
| Sep 26, 2026 11:06:57 AM UTC | Healthy | 72.9 | 2025-03-26 | oauth_supported | 14 | 1 | none |
| Sep 26, 2026 05:06:26 AM UTC | Healthy | 72.9 | 2025-03-26 | oauth_supported | 14 | 1 | none |
| Sep 25, 2026 11:06:09 PM UTC | Healthy | 72.9 | 2025-03-26 | oauth_supported | 14 | 1 | none |
| Sep 25, 2026 05:05:56 PM UTC | Healthy | 72.9 | 2025-03-26 | oauth_supported | 14 | 1 | none |
Recent validation runs
| Started | Status | Summary | Latency | Checks |
|---|---|---|---|---|
| Sep 27, 2026 11:09:17 PM UTC | Completed | Healthy | 2985.8 ms | action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, instruction_tool_reference_probe, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe |
| Sep 27, 2026 05:08:56 PM UTC | Completed | Healthy | 3234.9 ms | action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, instruction_tool_reference_probe, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe |
| Sep 27, 2026 11:08:26 AM UTC | Completed | Healthy | 3254.4 ms | action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, instruction_tool_reference_probe, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe |
| Sep 27, 2026 05:08:05 AM UTC | Completed | Healthy | 3080.9 ms | action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, instruction_tool_reference_probe, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe |
| Sep 26, 2026 11:07:37 PM UTC | Completed | Healthy | 3001.1 ms | action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, instruction_tool_reference_probe, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe |
| Sep 26, 2026 05:07:07 PM UTC | Completed | Healthy | 3500.9 ms | action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, instruction_tool_reference_probe, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe |
| Sep 26, 2026 11:06:54 AM UTC | Completed | Healthy | 2954.4 ms | action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, instruction_tool_reference_probe, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe |
| Sep 26, 2026 05:06:23 AM UTC | Completed | Healthy | 2958.7 ms | action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, instruction_tool_reference_probe, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe |
| Sep 25, 2026 11:06:06 PM UTC | Completed | Healthy | 2901.9 ms | action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, instruction_tool_reference_probe, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe |
| Sep 25, 2026 05:05:53 PM UTC | Completed | Healthy | 3159.0 ms | action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, instruction_tool_reference_probe, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe |
Incident & change feed
| Timestamp | Event | Details |
|---|---|---|
| Sep 27, 2026 11:09:20 PM UTC | Latest validation: healthy | Score 72.9 with status healthy. |
| Aug 05, 2026 10:58:23 AM UTC | Score corrected (post-1.0.503 remediation, R1 zero-anchoring) | Prior: 77.08. Corrected: 74.62. |
Technical details
Raw evidence view
Show raw JSON evidence
Large evidence payload summarized to keep this page fast. Full raw evidence remains available from the JSON report.
{
"checks": {
"count": 28,
"items": {
"action_safety_probe": {
"auth_present": true,
"safeguard_count": 3,
"status": "warning"
},
"advanced_capabilities_probe": {
"status": "warning"
},
"connector_publishability_probe": {
"status": "warning"
},
"connector_replay_probe": {
"status": "ok"
},
"determinism_probe": {
"latency_ms": 184.45,
"status": "ok"
},
"initialize": {
"http_status": 200,
"latency_ms": 250.65,
"payload_omitted": true,
"status": "ok"
},
"instruction_tool_reference_probe": {
"status": "warning"
},
"interactive_flow_probe": {
"status": "ok"
},
"oauth_authorization_server": {
"http_status": 200,
"latency_ms": 73.7,
"payload_omitted": true,
"status": "ok"
},
"oauth_protected_resource": {
"http_status": 200,
"latency_ms": 74.45,
"payload_omitted": true,
"status": "ok"
},
"official_registry_probe": {
"status": "missing"
},
"openid_configuration": {
"latency_ms": 87.99,
"reason": "Client error '404 Not Found' for url 'https://www.openaccountants.com/.well-known/openid-configuration'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404",
"status": "error"
},
"probe_noise_resilience": {
"http_status": 200,
"latency_ms": 211.64,
"status": "ok"
},
"prompt_get": {
"http_status": 200,
"latency_ms": 178.75,
"payload_omitted": true,
"status": "ok"
},
"prompts_list": {
"http_status": 200,
"latency_ms": 178.95,
"payload_omitted": true,
"status": "ok"
},
"protocol_version_probe": {
"status": "warning"
},
"provenance_divergence_probe": {
"status": "not_assessed"
},
"request_association_probe": {
"http_status": 405,
"latency_ms": 72.59,
"status": "warning"
},
"resource_read": {
"reason": "no_resource_uri",
"status": "missing"
},
"resources_list": {
"http_status": 200,
"latency_ms": 177.9,
"payload_omitted": true,
"status": "error"
},
"schema_divergence_probe": {
"reason": "no_server_card_tools",
"status": "missing"
},
"server_card": {
"http_status": 200,
"latency_ms": 77.02,
"payload_omitted": true,
"status": "ok"
},
"session_resume_probe": {
"http_status": 200,
"latency_ms": 177.66,
"payload_omitted": true,
"status": "ok",
"tool_count": 14,
"tool_names_preview": [
"list_skills",
"get_skill",
"get_skill_sections",
"search_skills",
"search_rules",
"get_deadlines",
"list_rule_facets",
"start_help",
"start",
"list_jurisdictions",
"list_verifiers",
"validate_vat_number",
"check_audit_exemption",
"share_with_openaccountants"
]
},
"step_up_auth_probe": {
"status": "warning"
},
"tool_snapshot_probe": {
"status": "ok"
},
"tools_list": {
"http_status": 200,
"latency_ms": 190.07,
"payload_omitted": true,
"status": "ok",
"tool_count": 14,
"tool_names_preview": [
"list_skills",
"get_skill",
"get_skill_sections",
"search_skills",
"search_rules",
"get_deadlines",
"list_rule_facets",
"start_help",
"start",
"list_jurisdictions",
"list_verifiers",
"validate_vat_number",
"check_audit_exemption",
"share_with_openaccountants"
]
},
"transport_compliance_probe": {
"latency_ms": 246.12,
"protocol_header_present": false,
"status": "error"
},
"utility_coverage_probe": {
"latency_ms": 175.15,
"status": "warning"
}
},
"omitted_count": 0
},
"failures": {
"count": 3,
"items": {
"openid_configuration": {},
"resources_list": {},
"transport_compliance_probe": {}
},
"omitted_count": 0
},
"message": "Raw evidence is summarized in HTML to keep server detail pages fast. Use the JSON report or evidence API for the full payload.",
"remote_url": "https://www.openaccountants.com/api/mcp",
"server_card": {
"name": null,
"raw_payload_omitted": false,
"version": null
},
"server_identifier": "awesome-openaccountants/openaccountants",
"truncated": true
}
Capabilities
- OAuth:
- DCR/CIMD:
- Prompts:
- Homepage: https://github.com/openaccountants/openaccountants
- Docs: https://github.com/openaccountants/openaccountants
- Support: https://github.com/openaccountants/openaccountants
- Icon: none
- Remote endpoint: https://www.openaccountants.com/api/mcp
- Directory listing: none
- Server card: https://www.openaccountants.com/.well-known/mcp/server-card.json
Transport compliance drilldown
Issues: missing_protocol_header, bad_protocol_not_rejected, delete_session_unexpected, expired_session_not_404
Request association
Connector replay
Required-argument replay breaks
| Tool | Added required args | Removed required args |
|---|---|---|
| No required-argument replay breaks detected. | ||
Output-schema replay breaks
| Tool | Removed properties | Added properties |
|---|---|---|
| No output-schema replay breaks detected. | ||