{"schema_version":"verify.report.v1","generated_at":"2026-07-31T10:27:42.343150+00:00","snapshot_id":"trustsnap_9a27dfe9b7af5257","server":{"namespace":"ai.analyticslegends","name":"sap-analytics","title":"Analytics Legends — SAP Analytics Intelligence","description":"AI agent for SAP analytics: firms, day rates, contract radar, news, concepts, studies","homepage_url":"https://analyticslegends.ai","docs_url":null,"icon_url":null,"support_url":null,"remote_url":"https://analyticslegends.ai/mcp","server_card_url":null,"latest_version":"1.0.0","current_status":"healthy","current_score":69.52,"transport_type":"streamable-http","has_oauth":false,"has_dcr":false,"has_prompts":true,"tool_count":10,"current_validation_schema_version":"16d1d270090d6c8f","last_validated_at":"2026-07-31T05:33:58.077161+00:00","registry_source":"official_registry","registry_identifier":"ai.analyticslegends/sap-analytics","canonical_identifier":"ai.analyticslegends/sap-analytics","current_score_components":{"auth_operability_score":2.0,"error_contract_score":0.0,"rate_limit_semantics_score":2.0,"schema_completeness_score":3.0,"backward_compatibility_score":2.0,"slo_health_score":3.0,"security_hygiene_score":3.0,"task_success_score":4.0,"trust_confidence_score":1.75,"abuse_noise_ratio_score":4.0,"prompt_contract_score":3.0,"resource_contract_score":4.0,"discovery_metadata_score":4.0,"registry_consistency_score":2.0,"installability_score":4.0,"session_semantics_score":3.0,"tool_surface_design_score":4.0,"result_shape_stability_score":3.0,"oauth_interop_score":3.0,"recovery_semantics_score":0.0,"maintenance_signal_score":3.0,"adoption_signal_score":3.0,"freshness_confidence_score":3.0,"transport_fidelity_score":4.0,"spec_recency_score":2.0,"session_resume_score":3.0,"step_up_auth_score":3.0,"transport_compliance_score":2.0,"utility_coverage_score":2.0,"advanced_capability_coverage_score":3.0,"connector_publishability_score":3.0,"tool_snapshot_churn_score":3.0,"connector_replay_score":3.0,"request_association_score":3.0,"interactive_flow_safety_score":3.0,"action_safety_score":2.0,"official_registry_presence_score":4.0,"provenance_divergence_score":4.0,"safety_transparency_score":2.0,"tool_capability_clarity_score":4.0,"destructive_operation_safety_score":2.0,"egress_ssrf_resilience_score":3.0,"execution_sandbox_safety_score":0.0,"data_exfiltration_resilience_score":3.0,"least_privilege_scope_score":2.0,"secret_handling_hygiene_score":3.0,"dependency_supply_chain_signal_score":2.5,"input_sanitization_safety_score":3.0,"tool_namespace_clarity_score":4.0},"capability_taxonomy":["development","database","search","web","read","write","exec","network","filesystem","export","healthcare","files","delete","admin","cloud","prompts","resources","streamable_http"],"machine_summary":{"verdict":"safe_for_evaluation","best_for":["Claude Desktop","Smithery","Generic Streamable HTTP"],"avoid_if":["You need a low-risk tool surface."],"requires_auth":false,"supports_oauth":false,"risk_level":"critical"},"taxonomy_tags":["development","database","search","web"],"score_decomposition":[{"key":"access_protocol","label":"Access & Protocol","score":31.0,"max_score":44.0,"hint":"Connectivity, auth, and transport expectations for common clients.","components":[{"key":"auth_operability_score","score":2.0},{"key":"installability_score","score":4.0},{"key":"session_semantics_score","score":3.0},{"key":"transport_fidelity_score","score":4.0},{"key":"spec_recency_score","score":2.0},{"key":"session_resume_score","score":3.0},{"key":"step_up_auth_score","score":3.0},{"key":"transport_compliance_score","score":2.0},{"key":"request_association_score","score":3.0},{"key":"oauth_interop_score","score":3.0},{"key":"least_privilege_scope_score","score":2.0}]},{"key":"interface_quality","label":"Interface Quality","score":38.0,"max_score":56.0,"hint":"How well the tool/resource interface communicates and behaves under automation.","components":[{"key":"error_contract_score","score":0.0},{"key":"rate_limit_semantics_score","score":2.0},{"key":"schema_completeness_score","score":3.0},{"key":"prompt_contract_score","score":3.0},{"key":"resource_contract_score","score":4.0},{"key":"tool_surface_design_score","score":4.0},{"key":"tool_capability_clarity_score","score":4.0},{"key":"tool_namespace_clarity_score","score":4.0},{"key":"result_shape_stability_score","score":3.0},{"key":"utility_coverage_score","score":2.0},{"key":"advanced_capability_coverage_score","score":3.0},{"key":"tool_snapshot_churn_score","score":3.0},{"key":"connector_replay_score","score":3.0},{"key":"recovery_semantics_score","score":0.0}]},{"key":"security_posture","label":"Security Posture","score":22.0,"max_score":36.0,"hint":"How safely the exposed tool surface handles destructive actions, egress, execution, secrets, and risky inputs.","components":[{"key":"security_hygiene_score","score":3.0},{"key":"destructive_operation_safety_score","score":2.0},{"key":"egress_ssrf_resilience_score","score":3.0},{"key":"execution_sandbox_safety_score","score":0.0},{"key":"data_exfiltration_resilience_score","score":3.0},{"key":"secret_handling_hygiene_score","score":3.0},{"key":"input_sanitization_safety_score","score":3.0},{"key":"interactive_flow_safety_score","score":3.0},{"key":"action_safety_score","score":2.0}]},{"key":"reliability_trust","label":"Reliability & Trust","score":17.75,"max_score":24.0,"hint":"Operational stability, consistency, and trustworthiness over time.","components":[{"key":"backward_compatibility_score","score":2.0},{"key":"slo_health_score","score":3.0},{"key":"task_success_score","score":4.0},{"key":"trust_confidence_score","score":1.75},{"key":"abuse_noise_ratio_score","score":4.0},{"key":"freshness_confidence_score","score":3.0}]},{"key":"discovery_governance","label":"Discovery & Governance","score":21.5,"max_score":28.0,"hint":"How well the server is documented, listed, and governed in public registries.","components":[{"key":"discovery_metadata_score","score":4.0},{"key":"registry_consistency_score","score":2.0},{"key":"maintenance_signal_score","score":3.0},{"key":"safety_transparency_score","score":2.0},{"key":"dependency_supply_chain_signal_score","score":2.5},{"key":"official_registry_presence_score","score":4.0},{"key":"provenance_divergence_score","score":4.0}]},{"key":"adoption_market","label":"Adoption & Market","score":6.0,"max_score":8.0,"hint":"Adoption clues and public evidence that the server is intended for external use.","components":[{"key":"adoption_signal_score","score":3.0},{"key":"connector_publishability_score","score":3.0}]}],"validation_diff":null,"tool_snapshot_diff":null,"connector_replay":{"status":"missing","backward_compatible":false,"would_break_after_refresh":false,"added_tools":[],"removed_tools":[],"required_arg_breaks":[],"output_breaks":[],"additive_output_changes":[]},"request_association":{"status":"missing","advertised_capabilities":[],"session_id_present":false,"protocol_version":null,"observed_methods":[],"violating_methods":[],"http_status":null,"issues":[]},"production_readiness":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use.","badge":"score-medium","critical_alerts":0},"recommended_for":[{"label":"Claude Desktop","reason":"Claude Desktop is marked compatible with score 100."},{"label":"Smithery","reason":"Smithery is marked compatible with score 80."},{"label":"Generic Streamable HTTP","reason":"Generic Streamable HTTP is marked compatible with score 100."}],"history_summary":{"points":[{"timestamp":"2026-07-31T05:33:58.077161+00:00","score":69.52,"status":"healthy","latency_ms":5167.1,"tool_count":10,"prompt_count":2,"resource_count":3}],"status_counts":{"healthy":1},"score_delta_7d":null,"score_delta_30d":null,"avg_latency_ms":5167.1,"healthy_ratio_recent":1.0,"freshness_hours":4.9,"latest_status":"healthy"},"validation_timeline":[{"timestamp":"2026-07-31T05:33:58.077161+00:00","summary_status":"healthy","score":69.52,"protocol_version":"2025-03-26","auth_mode":"public","tool_count":10,"prompt_count":2,"resource_count":3,"high_risk_tools":6,"safe_to_publish":false,"change_flags":[]}],"evidence_confidence":{"score":76.25,"label":"high","reason":"Based on 1 recent validations, 26 captured checks, and validation age of 4.9 hours.","live_check_count":26,"validation_age_hours":4.9},"incident_feed":[{"type":"validation_snapshot","timestamp":"2026-07-31T05:33:58.077161+00:00","title":"Latest validation: healthy","message":"Score 69.5 with status healthy."}],"remediations":[{"code":"add_confirmation_semantics","severity":"high","title":"Add confirmation and dry-run semantics for risky actions","why":"High-risk write, delete, exec, or egress tools should communicate safeguards clearly.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"fix_transport_compliance","severity":"high","title":"Align session and protocol behavior with Streamable HTTP expectations","why":"Clients increasingly rely on MCP-Protocol-Version, session teardown, and expired-session semantics.","action":"Align MCP-Protocol-Version, MCP-Session-Id, DELETE teardown, and expired-session handling with the transport spec.","playbook":["Return `Mcp-Session-Id` and `Mcp-Protocol-Version` headers consistently on streamable HTTP responses.","Honor `DELETE` session teardown and return `404` when a deleted session is reused.","Reject invalid protocol-version headers with `400 Bad Request`."],"maintainer_context":null},{"code":"enforce_request_association","severity":"high","title":"Associate roots, sampling, and elicitation with active client requests","why":"Modern MCP guidance expects roots, sampling, and elicitation traffic to be tied to an active client request instead of arriving unsolicited on idle sessions.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"publish_oauth_protected_resource","severity":"high","title":"Expose /.well-known/oauth-protected-resource","why":"Without a protected-resource document, OAuth clients cannot discover auth requirements reliably.","action":"Serve /.well-known/oauth-protected-resource and point it at your authorization server metadata.","playbook":["Serve `/.well-known/oauth-protected-resource` from the same host as the MCP endpoint.","Point it at the authorization server metadata URL.","Confirm clients receive consistent auth hints before tool execution."],"maintainer_context":null},{"code":"protect_connector_refreshes","severity":"high","title":"Keep connector refreshes backward compatible","why":"Managed connector clients freeze tool snapshots, so removed tools, new required args, and breaking output changes can break published integrations after refresh.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"publish_oauth_authorization_server","severity":"high","title":"Publish OAuth authorization-server metadata","why":"Clients need authorization-server metadata to discover issuer, endpoints, and DCR support.","action":"Publish /.well-known/oauth-authorization-server from your issuer and include registration_endpoint when supported.","playbook":["Publish `/.well-known/oauth-authorization-server` from the issuer.","Add `registration_endpoint` if DCR is supported.","Verify issuer, authorization, token, and jwks metadata are all reachable."],"maintainer_context":null},{"code":"publish_server_card","severity":"high","title":"Publish a complete server card","why":"Missing or incomplete server-card metadata weakens discovery, documentation, and trust signals.","action":"Serve /.well-known/mcp/server-card.json and include tools, prompts/resources, homepage, and support links.","playbook":["Publish `/.well-known/mcp/server-card.json`.","Include homepage, repository, support, tools, prompts/resources, and auth metadata.","Revalidate the server after publishing the card."],"maintainer_context":null},{"code":"harden_interactive_flows","severity":"high","title":"Stop asking users to paste secrets directly","why":"Public MCP servers should prefer OAuth or browser-based auth guidance over in-band secret collection.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"update_protocol_version","severity":"medium","title":"Adopt a current MCP protocol revision","why":"Older protocol revisions reduce compatibility with newer clients and registry programs.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"improve_connector_publishability","severity":"medium","title":"Close connector-publishing gaps","why":"Connector catalogs care about protocol recency, session behavior, auth clarity, and tool-surface stability.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"tighten_step_up_auth","severity":"medium","title":"Document minimal scopes and return cleaner auth challenges","why":"Modern clients expect granular scopes and step-up auth signals such as WWW-Authenticate scope hints.","action":"Return granular scopes and WWW-Authenticate challenge hints instead of forcing overly broad auth upfront.","playbook":["Advertise the narrowest viable scopes in OAuth metadata.","Return `WWW-Authenticate` challenges with scope or insufficient-scope hints when additional consent is needed.","Revalidate with both public discovery and auth-required flows."],"maintainer_context":null},{"code":"publish_openid_configuration","severity":"medium","title":"Publish OpenID configuration","why":"OIDC metadata improves token validation and client compatibility.","action":"Expose /.well-known/openid-configuration with issuer, jwks_uri, and supported grants.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"stabilize_tool_surface","severity":"medium","title":"Reduce tool-surface churn","why":"Frequent add/remove or output-shape drift makes published connectors and cached tool snapshots brittle.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"repair_session_resume","severity":"medium","title":"Support resumable HTTP sessions cleanly","why":"Modern MCP clients increasingly expect resumable session behavior on streamable HTTP transports.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"expand_utility_coverage","severity":"low","title":"Expose modern utility surfaces like completions, pagination, or tasks","why":"Utility coverage improves interoperability with larger clients and long-lived agent workflows.","action":"Expose completions, pagination, and task metadata where supported so larger clients can plan and resume work safely.","playbook":["Advertise `completions`, pagination cursors, and `tasks` only when they are actually supported.","Return `nextCursor` on large list operations when pagination is available.","Document task support and whether it requires step-up auth."],"maintainer_context":null}],"client_remediation_modes":[{"key":"openai_connectors","label":"ChatGPT custom connector","status":"partial","why_not_ready":[{"label":"OpenAI connectors expect OAuth for remote server auth.","state":"blocked"},{"label":"Dynamic client registration materially improves connector setup.","state":"blocked"},{"label":"search fetch only is not yet satisfied","state":"blocked"},{"label":"oauth configured is not yet satisfied","state":"blocked"},{"label":"admin refresh required is not yet satisfied","state":"blocked"},{"label":"safe for company knowledge is not yet satisfied","state":"blocked"}],"maintainer_context":null},{"key":"claude_desktop","label":"Claude remote MCP","status":"ready","why_not_ready":[{"label":"search fetch only is not yet satisfied","state":"blocked"},{"label":"oauth configured is not yet satisfied","state":"blocked"},{"label":"admin refresh required is not yet satisfied","state":"blocked"},{"label":"safe for company knowledge is not yet satisfied","state":"blocked"},{"label":"safe for messages api remote mcp is not yet satisfied","state":"blocked"},{"label":"Transport compliance issues should be resolved before wider client rollout.","state":"blocked"}],"maintainer_context":null},{"key":"write_safe","label":"Write-safe publishing","status":"blocked","why_not_ready":[{"label":"Add a clearer auth boundary around risky write actions.","state":"blocked"},{"label":"Add confirmation or dry-run semantics for risky actions.","state":"blocked"},{"label":"Constrain or sandbox exec-capable tools before publishing broadly.","state":"blocked"}],"maintainer_context":null}],"client_profiles":[{"key":"openai_connectors","label":"OpenAI Connectors","score":77.8,"compatibility":"partial","missing_requirements":["OpenAI connectors expect OAuth for remote server auth.","Dynamic client registration materially improves connector setup."],"snippet":"Connector URL: https://analyticslegends.ai/mcp\n# No OAuth metadata detected.\n# Server: ai.analyticslegends/sap-analytics"},{"key":"claude_desktop","label":"Claude Desktop","score":100.0,"compatibility":"compatible","missing_requirements":[],"snippet":"{\n  \"mcpServers\": {\n    \"sap-analytics\": {\n      \"command\": \"npx\",\n      \"args\": [\"mcp-remote\", \"https://analyticslegends.ai/mcp\"]\n    }\n  }\n}"},{"key":"smithery","label":"Smithery","score":80.0,"compatibility":"compatible","missing_requirements":["Machine-readable failure semantics should be present."],"snippet":"smithery mcp add \"https://analyticslegends.ai/mcp\""},{"key":"generic_streamable_http","label":"Generic Streamable HTTP","score":100.0,"compatibility":"compatible","missing_requirements":[],"snippet":"curl -sS https://analyticslegends.ai/mcp -H 'content-type: application/json' -d '{\"jsonrpc\":\"2.0\",\"id\":1,\"method\":\"initialize\",\"params\":{\"protocolVersion\":\"2025-03-26\",\"capabilities\":{},\"clientInfo\":{\"name\":\"mcp-verify\",\"version\":\"0.1.0\"}}}'"}],"client_readiness_verdicts":[{"key":"openai_connectors","label":"Client compatibility: ChatGPT","status":"partial","reason":"OpenAI connectors expect OAuth for remote server auth.; Dynamic client registration materially improves connector setup.","evidence":[{"check":"initialize","status":"ok","source":"live_validation","note":null,"http_status":200},{"check":"tools_list","status":"ok","source":"live_validation","note":null,"http_status":200},{"check":"transport_compliance_probe","status":"warning","source":"live_validation","note":null,"http_status":null},{"check":"step_up_auth_probe","status":"missing","source":"live_validation","note":null,"http_status":null},{"check":"connector_replay_probe","status":"missing","source":"live_validation","note":"Frozen tool snapshots must survive refresh.","http_status":null},{"check":"request_association_probe","status":"missing","source":"live_validation","note":"Roots, sampling, and elicitation should stay request-scoped.","http_status":null}],"confidence":{"score":76.25,"label":"high"},"source_resolution":{"winner":"live_validation","supporting_sources":["live_validation","history","server_card"],"disagreements":[]}},{"key":"claude_desktop","label":"Client compatibility: Claude","status":"ready","reason":"No major blockers detected.","evidence":[{"check":"initialize","status":"ok","source":"live_validation","note":null,"http_status":200},{"check":"tools_list","status":"ok","source":"live_validation","note":null,"http_status":200},{"check":"transport_compliance_probe","status":"warning","source":"live_validation","note":null,"http_status":null}],"confidence":{"score":76.25,"label":"high"},"source_resolution":{"winner":"live_validation","supporting_sources":["live_validation","history","server_card"],"disagreements":[]}},{"key":"unsafe_for_write_actions","label":"Write-action publishing","status":"yes","reason":"Blocked until safeguards and confirmation semantics are verified for write, exec, or destructive tools.","evidence":[{"check":"action_safety_probe","status":"error","source":"live_validation","note":null,"http_status":null}],"confidence":{"score":76.25,"label":"high"},"source_resolution":{"winner":"live_validation","supporting_sources":["live_validation","history"],"disagreements":[]}},{"key":"snapshot_churn_risk","label":"Snapshot churn risk","status":"low","reason":"No material tool-surface churn detected in the latest comparison.","evidence":[{"check":"tool_snapshot_probe","status":"missing","source":"live_validation","note":null,"http_status":null},{"check":"connector_replay_probe","status":"missing","source":"live_validation","note":null,"http_status":null}],"confidence":{"score":76.25,"label":"high"},"source_resolution":{"winner":"history","supporting_sources":["history","live_validation"],"disagreements":[]}}],"publishability_policy_profiles":[{"key":"chatgpt_custom_connector","label":"ChatGPT custom connector compatibility","status":"caution","gates":{"search_fetch_only":false,"write_actions_present":true,"oauth_configured":false,"admin_refresh_required":false,"safe_for_company_knowledge":false,"safe_for_messages_api_remote_mcp":false},"reason":"OpenAI connectors expect OAuth for remote server auth.; Dynamic client registration materially improves connector setup."},{"key":"claude_remote_mcp","label":"Claude remote MCP compatibility","status":"ready","gates":{"search_fetch_only":false,"write_actions_present":true,"oauth_configured":false,"admin_refresh_required":false,"safe_for_company_knowledge":false,"safe_for_messages_api_remote_mcp":false},"reason":"Transport, discovery, and remote-MCP assumptions are satisfied."}],"compatibility_fixtures":[{"key":"chatgpt_custom_connector","label":"ChatGPT custom connector fixture","status":"degraded","assumptions":[{"name":"remote_http_endpoint","status":"passes"},{"name":"oauth_discovery","status":"degraded"},{"name":"frozen_tool_snapshot_refresh","status":"passes"},{"name":"request_association","status":"passes"}],"reason":"OpenAI connectors expect OAuth for remote server auth.; Dynamic client registration materially improves connector setup."},{"key":"anthropic_remote_mcp","label":"Anthropic remote MCP fixture","status":"passes","assumptions":[{"name":"remote_transport","status":"passes"},{"name":"tool_discovery","status":"passes"},{"name":"auth_connect","status":"passes"},{"name":"safe_write_review","status":"degraded"}],"reason":"Remote MCP transport and discovery assumptions are satisfied."}],"install_snippets":{"openai_connectors":"Connector URL: https://analyticslegends.ai/mcp\n# No OAuth metadata detected.\n# Server: ai.analyticslegends/sap-analytics","claude_desktop":"{\n  \"mcpServers\": {\n    \"sap-analytics\": {\n      \"command\": \"npx\",\n      \"args\": [\"mcp-remote\", \"https://analyticslegends.ai/mcp\"]\n    }\n  }\n}","smithery":"smithery mcp add \"https://analyticslegends.ai/mcp\"","generic_http":"curl -sS https://analyticslegends.ai/mcp -H 'content-type: application/json' -d '{\"jsonrpc\":\"2.0\",\"id\":1,\"method\":\"initialize\",\"params\":{\"protocolVersion\":\"2025-03-26\",\"capabilities\":{},\"clientInfo\":{\"name\":\"mcp-verify\",\"version\":\"0.1.0\"}}}'"},"aliases":[{"identifier":"ai.analyticslegends/sap-analytics","registry_source":"official_registry","remote_url":"https://analyticslegends.ai/mcp","canonical":true,"score":69.52}],"raw_evidence":{"server_identifier":"ai.analyticslegends/sap-analytics","remote_url":"https://analyticslegends.ai/mcp","server_card_payload":null,"checks":{"server_card":{"status":"error","latency_ms":185.3,"details":{"url":"https://analyticslegends.ai/.well-known/mcp/server-card.json","error":"Client error '404 Not Found' for url 'https://analyticslegends.ai/.well-known/mcp/server-card.json'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"}},"oauth_protected_resource":{"status":"error","latency_ms":49.3,"details":{"url":"https://analyticslegends.ai/.well-known/oauth-protected-resource","error":"Client error '404 Not Found' for url 'https://analyticslegends.ai/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"}},"oauth_authorization_server":{"status":"missing","latency_ms":null,"details":{"reason":"no_authorization_server"}},"openid_configuration":{"status":"missing","latency_ms":null,"details":{"reason":"no_authorization_server"}},"initialize":{"status":"ok","latency_ms":177.09,"details":{"url":"https://analyticslegends.ai/mcp","payload":{"jsonrpc":"2.0","id":1,"result":{"protocolVersion":"2025-03-26","capabilities":{"tools":{},"resources":{},"prompts":{}},"serverInfo":{"name":"analytics-legends","title":"Analytics Legends — SAP Analytics market intelligence","version":"1.0.0"},"instructions":"Analytics Legends is a curated SAP Analytics market-intelligence platform (SAP Datasphere, Business Data Cloud, SAP Analytics Cloud, BW/4HANA, Databricks) run by a single named editor.\n\nThis endpoint serves the PUBLIC tranche only, read-only, no authentication. Use it to answer questions about the SAP analytics services market: which firms operate where, what the contract market looks like, what the day rates are, what the vocabulary means, and what has just happened in the market.\n\nWhen you use anything from this server, cite it. Every item carries a \"citation_url\" on analyticslegends.ai — quote that URL, not this endpoint. News items also carry \"source_url\" for the upstream publisher: cite both.\n\nEvery item also carries \"citation_scope\". \"record\" means the URL is that item's own page. \"section_hub\" means this platform publishes no page for that item and the URL is the section index — say so, or cite the section rather than the item; do not present a hub URL as the item's page.\n\nTruthfulness rules this server holds itself to, and that you should carry into your answer:\n- Counts are read at query time. \"_meta.match_count\" (also emitted as \"_meta.tranche_row_count\") is how many rows your filters matched; \"_meta.tranche_total_row_count\" is the whole population before your filters; \"result_count\" is how many were served. Quote the first when you say how many there are — never a marketing figure.\n- There is NO pagination: \"offset\", \"cursor\" and \"page\" are refused, not ignored, because ignoring them returned page 1 again. To go wider, narrow the filters and raise \"limit\" (cap 50). \"_meta.result_is_truncated\" tells you the cap cut the answer.\n- Absence is reported as absence. An empty result means the public tranche has no such row, not that the market has none.\n- Paid and personal data are absent by design: the SAP end-customer corpus, firm intelligence profiles, individual professionals and full study text are NOT here. Do not infer their contents.\n- Retrieval with attribution is permitted; use of this content as AI training data is prohibited (https://analyticslegends.ai/.well-known/agent.json)."}},"http_status":200,"headers":{"content-type":"application/json","set-cookie":"__cf_bm=W9kGjRdIoO3Sjr2jf_Rbftk.Py5YLsswOhFGonmmCZY-1785476033.1854968-1.0.1.1-JM1ok982RHffjAKQTY4gRg_tKVQIkszw3haK35KpeRFFnXZMoAjZPZ80gILD3iAAXwoiLnLXAR.UNlOsn1mlZ01DZ2DDstVLehpGbHOFuUUtkLikZf0aUfltKnr.IVU9; HttpOnly; SameSite=None; Secure; Path=/; Domain=supabase.co; Expires=Fri, 31 Jul 2026 06:03:53 GMT","strict-transport-security":"max-age=31536000; includeSubDomains; preload","mcp-protocol-version":"2025-03-26"}}},"protocol_version_probe":{"status":"warning","latency_ms":null,"details":{"claimed_version":"2025-03-26","validator_protocol_version":"2025-03-26","latest_known_version":"2025-11-25","releases_behind":2,"lag_days":244}},"tools_list":{"status":"ok","latency_ms":96.69,"details":{"url":"https://analyticslegends.ai/mcp","payload":{"jsonrpc":"2.0","id":2,"result":{"tools":[{"name":"search_firms","title":"Search the SAP analytics firm directory","description":"Search the published Analytics Legends directory of SAP analytics service providers — placement agencies, Big-4 and ESN practices, SAP vendors, platforms and community groups — by country, kind and free text. Returns name, HQ country/city, website, careers URL and a one-line editorial claim. SAP END-CUSTOMER companies are NOT in this directory: they are a separate paid dataset and are excluded by predicate.","inputSchema":{"type":"object","properties":{"query":{"type":"string","maxLength":200,"description":"Free-text filter, matched case-insensitively."},"country":{"type":"string","pattern":"^[A-Za-z]{2}$","description":"ISO-3166-1 alpha-2 country code, e.g. DE, FR, CH."},"kind":{"type":"string","enum":["agency_placement","professional_services_big4","professional_services_esn","vendor_sap","vendor_partner","platform_marketplace","community_group"],"description":"Restrict to one organisation kind. Call list_firm_kinds for live counts. A value outside this list is refused, not silently ignored."},"limit":{"type":"integer","minimum":1,"maximum":50,"default":10,"description":"Max rows (hard cap 50)."}},"additionalProperties":false},"outputSchema":{"type":"object","properties":{"tool":{"type":"string"},"result_count":{"type":"integer"},"rows":{"type":"array","items":{"type":"object","properties":{"slug":{"type":"string"},"name":{"type":"string"},"kind":{"type":"string"},"hq_country":{"type":"string"},"website":{"type":"string"},"citation_url":{"type":"string"},"citation_scope":{"type":"string","enum":["record","section_hub"]},"citation_note":{"type":"string"}}}},"_meta":{"type":"object"},"_attribution":{"type":"string"}},"required":["tool","result_count","rows","_attribution"]},"annotations":{"title":"Search the SAP analytics firm directory","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":false}},{"name":"get_firm","title":"Get one firm's published profile","description":"Fetch one organisation from the published directory by its database slug (`rows[].slug` from search_firms, verbatim). Returns the same public fields plus `partnerships_declared`, the count of partnerships this directory records for the firm — 0 on ~94 % of rows, meaning none declared here, never that the firm has no partners. Does not return the paid firm-intelligence profile, contacts, or any person.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The DATABASE slug, taken verbatim from search_firms.rows[].slug. It is not always the web slug in citation_url: re-measured 2026-07-31 against the tranche this tool actually serves (5 157 published rows), 429 of them (8,3 %) carry a numeric firm id instead — '00317' is BearingPoint Switzerland, whose page is /companies/bearingpoint-switzerland/. Deriving a slug from the citation URL fails on those rows; carry rows[].slug across instead."}},"required":["slug"],"additionalProperties":false},"outputSchema":{"type":"object","properties":{"tool":{"type":"string"},"result_count":{"type":"integer"},"rows":{"type":"array","items":{"type":"object","properties":{"slug":{"type":"string"},"name":{"type":"string"},"citation_url":{"type":"string"},"citation_scope":{"type":"string","enum":["record","section_hub"]},"citation_note":{"type":"string"}}}},"_meta":{"type":"object"},"_attribution":{"type":"string"}},"required":["tool","result_count","rows","_attribution"]},"annotations":{"title":"Get one firm's published profile","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":false}},{"name":"list_firm_kinds","title":"List firm kinds with live counts","description":"Breakdown of the published firm directory by organisation kind, with a live row count per kind. Use this before search_firms to know what the population actually is instead of guessing.","inputSchema":{"type":"object","properties":{},"additionalProperties":false},"outputSchema":{"type":"object","properties":{"tool":{"type":"string"},"result_count":{"type":"integer"},"rows":{"type":"array","items":{"type":"object","properties":{"kind":{"type":"string"},"n":{"type":"integer"},"citation_url":{"type":"string"},"citation_scope":{"type":"string","enum":["record","section_hub"]},"citation_note":{"type":"string"}}}},"_meta":{"type":"object"},"_attribution":{"type":"string"}},"required":["tool","result_count","rows","_attribution"]},"annotations":{"title":"List firm kinds with live counts","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":false}},{"name":"find_opportunities","title":"Search the public SAP analytics contract radar","description":"Search every SAP contract and permanent-role posting Analytics Legends publishes to an ANONYMOUS visitor — the same population a human browses on /opportunities/, where each posting has its own prerendered page. It merges the platform's TWO public legs, which are near-disjoint (measured 2026-07-30: 1 row in common): (a) the PROMOTED feed (`public.public_opportunities`) — general SAP work (FI/CO, SD, EWM, MDG, BTP, ABAP), all German cities, and it carries NO rate, contract_type, currency, posted_at or country_code: those fields come back null on that leg, so no rate or contract term can be read off it; (b) the SITE RADAR (`/api/contracts-lean.json`) — these DO carry country, category, seniority, posted_at and currency, and they are the analytics-specific ones (SAC Planning, Datasphere Technical Lead, Business Data Cloud). WHAT IS GATED IS A FIELD, NOT A ROW: on most radar rows `source_url` is null and `application_link` reads \"members_only\" — the verified link to the original listing is the paid Consultant-tier deliverable. Everything else about the posting is public, and `citation_url` is that posting's own page on analyticslegends.ai. Quote it. Report `_meta.tranche_row_count` as the published public population, never as the size of the market.","inputSchema":{"type":"object","properties":{"query":{"type":"string","maxLength":200,"description":"Free-text filter, matched case-insensitively."},"location":{"type":"string","description":"City or place, matched case-insensitively as a substring of the posting's location. The promoted leg is all-German (Hamburg, Frankfurt am Main, Bremen, Munich, Cologne, Dortmund, Hanover, Landshut, Mannheim, Stuttgart); the site-radar leg is worldwide."},"country":{"type":"string","pattern":"^[A-Za-z]{2}$","description":"ISO-3166-1 alpha-2 code. It can only match the SITE-RADAR leg: the promoted leg stores country_code NULL on every row, so filtering by country silently drops it rather than returning nothing. `_meta.note` says so on any country-filtered call."},"limit":{"type":"integer","minimum":1,"maximum":50,"default":10,"description":"Max rows (hard cap 50)."}},"additionalProperties":false},"outputSchema":{"type":"object","properties":{"tool":{"type":"string"},"result_count":{"type":"integer"},"rows":{"type":"array","items":{"type":"object","properties":{"title":{"type":"string"},"firm_name":{"type":"string"},"location":{"type":"string"},"source_url":{"type":"string"},"citation_url":{"type":"string"},"citation_scope":{"type":"string","enum":["record","section_hub"]},"citation_note":{"type":"string"}}}},"_meta":{"type":"object"},"_attribution":{"type":"string"}},"required":["tool","result_count","rows","_attribution"]},"annotations":{"title":"Search the public SAP analytics contract radar","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":false}},{"name":"search_news","title":"Search SAP analytics market news","description":"Search the Analytics Legends market-news corpus. It is watched FOR SAP analytics (Datasphere, Business Data Cloud, SAC, BW/4HANA, Databricks, the 2027/2030 maintenance window), but it is NOT an all-SAP corpus: measured 2026-07-30, ~84 % of active rows sit in the `AI` category and are general enterprise-AI trade press (cloud platforms, model releases, funding rounds) with no SAP content at all. An UNFILTERED call therefore returns mostly non-SAP items — pass `query` or `category` when the question is about SAP, and never present an unfiltered page as 'the SAP analytics news'. Say what you actually got. Each item returns the Analytics Legends citation URL AND the upstream publisher's source_url — cite both, and prefer source_url when you need a page that certainly carries the item.","inputSchema":{"type":"object","properties":{"query":{"type":"string","maxLength":200,"description":"Free-text filter, matched case-insensitively."},"category":{"type":"string","description":"Category code, matched case-insensitively. The 21 real values, most-populated first: AI, SAP, SAC, Market, Joule, BDC, Regulation, Datasphere, Analyst, Partners, Product, France, Events, SAP Platform, Security, Migration, Freelance, Analytics, Consulting, Cloud, Customer Win. Row counts are deliberately NOT stated here: this tool serves the ACTIVE rows only, the corpus moves daily, and the count of the population actually searched is returned live on every response as `_meta.tranche_row_count`. One bucket needs a warning. 'SAC' is the noisiest label in this corpus because the acronym collides with unrelated ones — Windows 'Smart App Control', and the surname 'Sacks'. Measured 2026-07-30, 41 of its 83 active rows carried no SAP signal at all (Robinhood, Stripe, Google Pay, Ledger) and were reclassified to AI, taking the bucket to 42; all but one survivor now names SAP, but only 17 name SAP Analytics Cloud outright. For genuine SAC product news, pair category:'SAC' with query:'analytics cloud'."},"limit":{"type":"integer","minimum":1,"maximum":50,"default":10,"description":"Max rows (hard cap 50)."}},"additionalProperties":false},"outputSchema":{"type":"object","properties":{"tool":{"type":"string"},"result_count":{"type":"integer"},"rows":{"type":"array","items":{"type":"object","properties":{"title":{"type":"string"},"published_at":{"type":"string"},"source_name":{"type":"string"},"source_url":{"type":"string"},"citation_url":{"type":"string"},"citation_scope":{"type":"string","enum":["record","section_hub"]},"citation_note":{"type":"string"}}}},"_meta":{"type":"object"},"_attribution":{"type":"string"}},"required":["tool","result_count","rows","_attribution"]},"annotations":{"title":"Search SAP analytics market news","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":false}},{"name":"search_concepts","title":"Search the SAP analytics concept encyclopaedia","description":"Search the SAP analytics concept encyclopaedia — the vocabulary of the stack, written for practitioners. Returns titles and summaries; call get_concept for the full entry.","inputSchema":{"type":"object","properties":{"query":{"type":"string","maxLength":200,"description":"Free-text filter, matched case-insensitively."},"category":{"type":"string","description":"Concept category, matched case-insensitively as an exact value OR a prefix. The 14 real values are long labels, measured 2026-07-30: Generative AI Foundations (55), Joule & SAP AI (42), Career & Practice (29), Governance & Compliance (25), Architecture & Performance (25), SAC (Analytics Cloud) (22), BDC Platform (22), Adjacent Stacks (19), Datasphere Core (17), Sales & Commercial (16), Productivity & AI (10), Industry Solutions (10), BW/4HANA & Migration (9), Data Engineering & Integration (1). So category:\"datasphere\" reaches Datasphere Core."},"limit":{"type":"integer","minimum":1,"maximum":50,"default":10,"description":"Max rows (hard cap 50)."}},"additionalProperties":false},"outputSchema":{"type":"object","properties":{"tool":{"type":"string"},"result_count":{"type":"integer"},"rows":{"type":"array","items":{"type":"object","properties":{"slug":{"type":"string"},"title":{"type":"string"},"citation_url":{"type":"string"},"citation_scope":{"type":"string","enum":["record","section_hub"]},"citation_note":{"type":"string"}}}},"_meta":{"type":"object"},"_attribution":{"type":"string"}},"required":["tool","result_count","rows","_attribution"]},"annotations":{"title":"Search the SAP analytics concept encyclopaedia","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":false}},{"name":"get_concept","title":"Get one concept entry in full","description":"Fetch one concept entry by slug: title, category, level, tags and the editor's summary. Written by a named human editor, not generated. The card body, why-it-matters, key points and pro tip are subscriber content and are NOT returned — follow citation_url for those.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"Concept slug from search_concepts."}},"required":["slug"],"additionalProperties":false},"outputSchema":{"type":"object","properties":{"tool":{"type":"string"},"result_count":{"type":"integer"},"rows":{"type":"array","items":{"type":"object","properties":{"slug":{"type":"string"},"title":{"type":"string"},"summary":{"type":"string"},"citation_url":{"type":"string"},"citation_scope":{"type":"string","enum":["record","section_hub"]},"citation_note":{"type":"string"}}}},"_meta":{"type":"object"},"_attribution":{"type":"string"}},"required":["tool","result_count","rows","_attribution"]},"annotations":{"title":"Get one concept entry in full","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":false}},{"name":"list_studies","title":"List the deep-research studies (metadata only)","description":"List the Analytics Legends deep-research studies with their edition, as-of date, audience, word count and canonical URL. METADATA ONLY: study bodies are a paid Legend-tier deliverable and are not served by this endpoint. Use this to tell a reader that a study exists and where to read it.","inputSchema":{"type":"object","properties":{"query":{"type":"string","maxLength":200,"description":"Free-text filter, matched case-insensitively."},"lang":{"type":"string","pattern":"^[A-Za-z]{2}$","description":"Language code, EN or FR."},"limit":{"type":"integer","minimum":1,"maximum":50,"default":10,"description":"Max rows (hard cap 50)."}},"additionalProperties":false},"outputSchema":{"type":"object","properties":{"tool":{"type":"string"},"result_count":{"type":"integer"},"rows":{"type":"array","items":{"type":"object","properties":{"slug":{"type":"string"},"title":{"type":"string"},"as_of":{"type":"string"},"word_count":{"type":"integer"},"access":{"type":"string"},"citation_url":{"type":"string"},"citation_scope":{"type":"string","enum":["record","section_hub"]},"citation_note":{"type":"string"}}}},"_meta":{"type":"object"},"_attribution":{"type":"string"}},"required":["tool","result_count","rows","_attribution"]},"annotations":{"title":"List the deep-research studies (metadata only)","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":false}},{"name":"get_day_rate_benchmark","title":"Public SAP analytics day-rate aggregate","description":"The PUBLIC day-rate aggregate for SAP analytics freelance work: min/max daily rate by country, specialisation and seniority, with a sample size and a quarter stamp. This is the free aggregate published at analyticslegends.ai/api/market-rates.json. The quartile bands (p25/p50/p75) are a paid Consultant-tier deliverable and are NOT in this response — do not infer them.","inputSchema":{"type":"object","properties":{"country":{"type":"string","pattern":"^[A-Za-z]{2}$","description":"ISO-3166-1 alpha-2 country code, e.g. DE, FR, CH."},"specialisation":{"type":"string","description":"e.g. datasphere, bdc, sac, bw4hana, joule."},"seniority":{"type":"string","description":"e.g. senior, principal."}},"additionalProperties":false},"outputSchema":{"type":"object","properties":{"tool":{"type":"string"},"result_count":{"type":"integer"},"rows":{"type":"array","items":{"type":"object","properties":{"country":{"type":"string"},"specialisation":{"type":"string"},"seniority":{"type":"string"},"sample_size":{"type":"integer"},"currency":{"type":"string"},"citation_url":{"type":"string"},"citation_scope":{"type":"string","enum":["record","section_hub"]},"citation_note":{"type":"string"}}}},"_meta":{"type":"object"},"_attribution":{"type":"string"}},"required":["tool","result_count","rows","_attribution"]},"annotations":{"title":"Public SAP analytics day-rate aggregate","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true}},{"name":"list_sap_modules","title":"SAP analytics module taxonomy","description":"The canonical SAP module/product taxonomy Analytics Legends classifies against (codes and EN/FR labels by category). Use it to normalise a user's loose product wording — 'SAC', 'Analytics Cloud', 'Datasphere' — onto the codes the other tools filter on.","inputSchema":{"type":"object","properties":{"query":{"type":"string","maxLength":200,"description":"Free-text filter, matched case-insensitively."},"limit":{"type":"integer","minimum":1,"maximum":50,"default":10,"description":"Max rows (hard cap 50)."}},"additionalProperties":false},"outputSchema":{"type":"object","properties":{"tool":{"type":"string"},"result_count":{"type":"integer"},"rows":{"type":"array","items":{"type":"object","properties":{"code":{"type":"string"},"label_en":{"type":"string"},"category":{"type":"string"},"citation_url":{"type":"string"},"citation_scope":{"type":"string","enum":["record","section_hub"]},"citation_note":{"type":"string"}}}},"_meta":{"type":"object"},"_attribution":{"type":"string"}},"required":["tool","result_count","rows","_attribution"]},"annotations":{"title":"SAP analytics module taxonomy","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":false}}]}},"http_status":200,"headers":{"content-type":"application/json","set-cookie":"__cf_bm=7L5A0pM_ije_aAtUJyaF_D_t79djjj5Fr_FZhvsPo1M-1785476033.337834-1.0.1.1-LqD3gkhAMsnwm9Rw2NA3d9US2gCZjk12H0YMR0geyFj.5Ri14pCkE9sC8nHN5QrUS_FLRN1brzNC9CZxB16aCm06FFZldlSIbTERcAGTqq3uaviSXqj6suRYEijLANvx; HttpOnly; SameSite=None; Secure; Path=/; Domain=supabase.co; Expires=Fri, 31 Jul 2026 06:03:53 GMT","strict-transport-security":"max-age=31536000; includeSubDomains; preload","mcp-protocol-version":"2025-03-26"}}},"prompts_list":{"status":"ok","latency_ms":121.47,"details":{"url":"https://analyticslegends.ai/mcp","payload":{"jsonrpc":"2.0","id":3,"result":{"prompts":[{"name":"brief_sap_analytics_market","title":"Brief me on the SAP analytics market in a country","description":"Assemble a sourced, cited briefing on the SAP analytics services market for one country: who the providers are, what is on the radar, what the day rates look like and what has just happened.","arguments":[{"name":"country","description":"ISO-3166 alpha-2 country code, e.g. DE.","required":true},{"name":"focus","description":"Optional product focus, e.g. Datasphere, BDC, SAC.","required":false}]},{"name":"explain_sap_analytics_term","title":"Explain an SAP analytics term with a citation","description":"Explain one SAP analytics term from the Analytics Legends encyclopaedia and cite the canonical URL.","arguments":[{"name":"term","description":"The term to explain.","required":true}]}]}},"http_status":200,"headers":{"content-type":"application/json","set-cookie":"__cf_bm=IgiDwEUlD1mhmRpYYwsrW04wHGnu4zpNUImhIubbRoU-1785476033.434199-1.0.1.1-h8393WbuHNdFU_pot_1iRh768wo44hS8pyIt1Xv9kOv.jY9iAAO9Gh80sUS19c2zVTJhsHJFt5d2WcajvQJODYdXaSnguTDcTnf_u.gLedIx5.wKwswy3Xphe1RfvcXi; HttpOnly; SameSite=None; Secure; Path=/; Domain=supabase.co; Expires=Fri, 31 Jul 2026 06:03:53 GMT","strict-transport-security":"max-age=31536000; includeSubDomains; preload","mcp-protocol-version":"2025-03-26"}}},"prompt_get":{"status":"ok","latency_ms":109.78,"details":{"url":"https://analyticslegends.ai/mcp","payload":{"jsonrpc":"2.0","id":4,"result":{"description":"Sourced SAP analytics market briefing for DE.","messages":[{"role":"user","content":{"type":"text","text":"Brief me on the SAP analytics services market in DE.\n\nUse the analytics-legends tools in this order and cite every claim:\n1. list_firm_kinds — establish the population before naming anyone.\n2. search_firms with country=\"DE\" — who provides these services there.\n3. find_opportunities with country=\"DE\" — what the demand side is asking for right now.\n4. get_day_rate_benchmark with country=\"DE\" — the public rate band; quote sample_size with it.\n5. search_news — what has just changed.\n\nRules: quote each item's citation_url. For news, quote source_url too. Report the tranche_row_count you searched, and say plainly when a result set is empty rather than filling the gap from memory. Do not state day-rate quartiles — they are not public."}}]}},"http_status":200,"headers":{"content-type":"application/json","set-cookie":"__cf_bm=T0Go4eCr9KHm9tEBtuPklG2cOuJjzzhPfoFB5vkFkus-1785476033.5557928-1.0.1.1-q6R53OK0SRicpZgRx40gOH0jmtyqcZ2Y0OB.HiG5gbqVm.SQ9oV9hI.aOlXc4N3eREoEl0YYtPYeN6fzrD95MFI1GNg1FJA.mS1a31VHudEzXIGk5BpYlBnnZz3TshaH; HttpOnly; SameSite=None; Secure; Path=/; Domain=supabase.co; Expires=Fri, 31 Jul 2026 06:03:53 GMT","strict-transport-security":"max-age=31536000; includeSubDomains; preload","mcp-protocol-version":"2025-03-26"},"prompt_name":"brief_sap_analytics_market","prompt_arguments":[{"name":"country","description":"ISO-3166 alpha-2 country code, e.g. DE.","required":true},{"name":"focus","description":"Optional product focus, e.g. Datasphere, BDC, SAC.","required":false}]}},"resources_list":{"status":"ok","latency_ms":127.77,"details":{"url":"https://analyticslegends.ai/mcp","payload":{"jsonrpc":"2.0","id":5,"result":{"resources":[{"uri":"analytics-legends://tranche","name":"Public tranche contract","title":"What this endpoint serves, and what it deliberately does not","description":"The explicit list of datasets this hosted MCP endpoint serves, the datasets it excludes and why, and the live row count of each. Read this before trusting or citing any tool result.","mimeType":"application/json"},{"uri":"analytics-legends://agents-policy","name":"AI access policy","title":"Retrieval-with-attribution carve-out (.well-known/agent.json)","description":"The machine-readable policy governing AI access to Analytics Legends: retrieval with attribution is permitted, training-data use is prohibited.","mimeType":"application/json"},{"uri":"analytics-legends://about","name":"Platform manifest","title":"Platform manifest (api/about.json)","description":"Auto-derived platform manifest: counts, tiers, routes, tech stack.","mimeType":"application/json"}]}},"http_status":200,"headers":{"content-type":"application/json","set-cookie":"__cf_bm=zaNospDs_cUruNf3myBx7J0ECKxPteynVAe9QJTi9z4-1785476033.666371-1.0.1.1-5voAE.4B5O2mGYYMjHGCJWbUNphppNslgeaN.K0bX1D6Vd3xlqTXuSqH_oMBhbnN13jjUfnuUKZe2VO3nJL84w.lPllXOLXtIcQHrKEPKucsrnSNUi5WlxbOxGq5KOAc; HttpOnly; SameSite=None; Secure; Path=/; Domain=supabase.co; Expires=Fri, 31 Jul 2026 06:03:53 GMT","strict-transport-security":"max-age=31536000; includeSubDomains; preload","mcp-protocol-version":"2025-03-26"}}},"resource_read":{"status":"ok","latency_ms":3826.14,"details":{"url":"https://analyticslegends.ai/mcp","payload":{"jsonrpc":"2.0","id":6,"result":{"contents":[{"uri":"analytics-legends://tranche","mimeType":"application/json","text":"{\n  \"endpoint\": \"https://analyticslegends.ai/mcp\",\n  \"auth\": \"none — public read-only tranche\",\n  \"served\": {\n    \"firms\": {\n      \"source\": \"database.organizations\",\n      \"rows\": 5048,\n      \"tools\": [\n        \"search_firms\",\n        \"get_firm\",\n        \"list_firm_kinds\"\n      ]\n    },\n    \"opportunities\": {\n      \"source\": \"public.public_opportunities + https://analyticslegends.ai/api/contracts-lean.json (all active rows; the application link alone is tier-gated)\",\n      \"rows\": 19,\n      \"rows_note\": \"`rows` counts the promoted leg only; the site-radar leg is read at query time.\",\n      \"tools\": [\n        \"find_opportunities\"\n      ]\n    },\n    \"news\": {\n      \"source\": \"content.news_items\",\n      \"rows\": 3543,\n      \"tools\": [\n        \"search_news\"\n      ]\n    },\n    \"concepts\": {\n      \"source\": \"content.concepts\",\n      \"rows\": 305,\n      \"tools\": [\n        \"search_concepts\",\n        \"get_concept\"\n      ]\n    },\n    \"studies\": {\n      \"source\": \"content.studies (metadata only)\",\n      \"rows\": 38,\n      \"tools\": [\n        \"list_studies\"\n      ]\n    },\n    \"modules\": {\n      \"source\": \"lookup.sap_modules\",\n      \"rows\": 40,\n      \"tools\": [\n        \"list_sap_modules\"\n      ]\n    },\n    \"day_rates\": {\n      \"source\": \"https://analyticslegends.ai/api/market-rates.json\",\n      \"rows\": null,\n      \"tools\": [\n        \"get_day_rate_benchmark\"\n      ]\n    }\n  },\n  \"excluded\": {\n    \"sap_end_customer_corpus\": \"paid Legend+ dataset, RLS-locked 2026-07-08, static JSON returns 404\",\n    \"firm_intelligence_profiles\": \"paid Legend+ dataset, same lockdown\",\n    \"professionals_and_people\": \"personal data — never served\",\n    \"study_bodies\": \"paid Legend tier; metadata only here\",\n    \"knowledge_graph\": \"build artefact with no Postgres home\",\n    \"day_rate_quartiles\": \"paid Consultant tier; only the public min/max aggregate is served\",\n    \"opportunity_consultant_matches\": \"paid Firm tier deliverable\"\n  },\n  \"_attribution\": \"Source: Analytics Legends (https://analyticslegends.ai) — retrieval-with-attribution permitted per https://analyticslegends.ai/.well-known/agent.json; use as AI training data is prohibited. Cite the canonical URL on each item.\"\n}"}]}},"http_status":200,"headers":{"content-type":"application/json","set-cookie":"__cf_bm=AhVFf_HPoF5ffRfVeBnMxX8Eorvj.aTO3v.p8G5rLWc-1785476033.7936084-1.0.1.1-5.alWTTmrez.6zkfNPCM9fVsE_JNSuj9XI1MJA7ZR0iYjZjnyLLGxfjlDv3CPH0eO4YRZnc4ES9eZZh3vKLMo.2p8G8W7O_U1pAtcV2rYCt_qb8ODGQEkQYfv1_.todK; HttpOnly; SameSite=None; Secure; Path=/; Domain=supabase.co; Expires=Fri, 31 Jul 2026 06:03:57 GMT","strict-transport-security":"max-age=31536000; includeSubDomains; preload","mcp-protocol-version":"2025-03-26"},"resource_uri":"analytics-legends://tranche"}},"probe_noise_resilience":{"status":"ok","latency_ms":39.3,"details":{"url":"https://analyticslegends.ai/robots.txt","http_status":200,"headers":{"content-type":"text/plain; charset=utf-8"}}},"determinism_probe":{"status":"ok","latency_ms":110.33,"details":{"attempts":2,"successful":2,"matches":2,"stable_ratio":1.0,"baseline_signature":"67dd1853f7b988042c2cd4555c1ce5417b84ca8b26208a89bd6474ab33f4cc74","errors":[]}},"session_resume_probe":{"status":"warning","latency_ms":null,"details":{"reason":"no_session_id","transport":"streamable-http","resume_expected":true,"protocol_version":"2025-03-26"}},"step_up_auth_probe":{"status":"missing","latency_ms":null,"details":{"oauth_present":false,"auth_required_checks":[],"supported_scopes":[],"scope_specificity_ratio":0.0,"broad_scopes":[],"challenge_headers":[],"step_up_signals":[],"minimal_scope_documented":false}},"transport_compliance_probe":{"status":"warning","latency_ms":111.69,"details":{"transport":"streamable-http","session_id_present":false,"protocol_header_present":true,"last_event_id_visible":false,"requested_protocol_version":"2025-03-26","bad_protocol_status_code":400,"bad_protocol_payload":{"jsonrpc":"2.0","id":410,"error":{"code":-32022,"message":"Unsupported protocol version","data":{"supported":["2026-07-28","2025-11-25","2025-06-18","2025-03-26"],"requested":"1999-99-99"}}},"bad_protocol_headers":{"content-type":"application/json","set-cookie":"__cf_bm=3kDnPGh4jCY7KMG34yi5GFOmNwwEMxvGn8CZvnHN5f0-1785476037.8862312-1.0.1.1-0hVrQvj6sx6DuAyA1MAhSAn9nHREF.XbaZ0gLHj2AtqFTheHlEQWTGuTVB6QY30PWflwBs.cjJu2.qAWN62rWgkkZexJXUumx07d.qA79PYkRj2ZSfAlRSS0cC47m15M; HttpOnly; SameSite=None; Secure; Path=/; Domain=supabase.co; Expires=Fri, 31 Jul 2026 06:03:57 GMT","strict-transport-security":"max-age=31536000; includeSubDomains; preload"},"bad_protocol_error":null,"delete_status_code":null,"delete_error":null,"expired_session_status_code":null,"expired_session_error":null,"issues":["missing_session_id"]}},"utility_coverage_probe":{"status":"missing","latency_ms":93.0,"details":{"completions":{"advertised":false,"sample_target":{"type":"prompt","name":"brief_sap_analytics_market","argument_name":"country"},"live_probe":"not_executed"},"pagination":{"supported":false,"next_cursor_methods":[],"metadata_signal":false},"tasks":{"advertised":false,"probe_status":"missing","http_status":404},"initialize_capability_keys":["prompts","resources","tools"]}},"advanced_capabilities_probe":{"status":"ok","latency_ms":null,"details":{"capabilities":{"prompts":true,"resources":true,"completions":false,"roots":false,"sampling":false,"elicitation":false,"structured_outputs":true,"resource_links":true},"enabled_count":4,"enabled":["prompts","resource_links","resources","structured_outputs"],"initialize_capability_keys":["prompts","resources","tools"]}},"tool_snapshot_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_historical_snapshot","current_tool_count":10}},"connector_replay_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_historical_snapshot"}},"request_association_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_request_association_capabilities_advertised"}},"interactive_flow_probe":{"status":"missing","latency_ms":null,"details":{"risk_hits":[],"safe_hits":[],"oauth_supported":false,"prompt_available":true}},"action_safety_probe":{"status":"error","latency_ms":null,"details":{"summary":{"tool_count":10,"high_risk_tools":6,"destructive_tools":1,"exec_tools":6,"egress_tools":0,"secret_tools":0,"bulk_access_tools":6,"risk_distribution":{"low":2,"medium":2,"high":5,"critical":1},"capability_distribution":{"read":10,"write":2,"exec":6,"network":6,"filesystem":4,"export":6,"delete":1,"admin":2}},"auth_present":false,"safeguard_count":0,"confirmation_signals":[]}},"official_registry_probe":{"status":"ok","latency_ms":null,"details":{"registry_source":"official_registry","registry_identifier":"ai.analyticslegends/sap-analytics","direct_match":true,"official_peer_count":1}},"provenance_divergence_probe":{"status":"ok","latency_ms":null,"details":{"direct_official_match":true,"registry_title":null,"server_card_title":null,"registry_version":null,"server_card_version":null,"registry_homepage":null,"server_card_homepage":null,"registry_repository":null,"server_card_repository":null,"drift_fields":[],"metadata_document_count":2}},"connector_publishability_probe":{"status":"warning","latency_ms":null,"details":{"transport":"streamable-http","tool_count":10,"high_risk_tools":6,"blockers":["action_safety","server_card"],"criteria":{"remote_transport":true,"initialize":true,"tools_list":true,"protocol_version":true,"session_resume":true,"step_up_auth":true,"transport_compliance":true,"connector_replay":true,"request_association":true,"action_safety":false,"server_card":false,"tool_surface":true,"auth_flow":true}}}},"failures":{"server_card":{"url":"https://analyticslegends.ai/.well-known/mcp/server-card.json","error":"Client error '404 Not Found' for url 'https://analyticslegends.ai/.well-known/mcp/server-card.json'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"},"oauth_protected_resource":{"url":"https://analyticslegends.ai/.well-known/oauth-protected-resource","error":"Client error '404 Not Found' for url 'https://analyticslegends.ai/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"},"oauth_authorization_server":{"reason":"no_authorization_server"},"openid_configuration":{"reason":"no_authorization_server"}}},"active_alerts":[],"maintainer_analytics":{"validation_run_count":1,"average_latency_ms":5167.1,"healthy_run_ratio_recent":1.0,"registry_presence_count":1,"active_alert_count":0,"watcher_count":0,"verified_claim":false,"taxonomy_tags":["development","database","search","web"],"score_trend":[69.52],"remediation_count":15,"high_risk_tool_count":6,"destructive_tool_count":1,"exec_tool_count":6},"public_server_reputation":{"validation_success_ratio_7d":1.0,"validation_success_ratio_30d":1.0,"mean_time_to_recover_hours":null,"breaking_diffs_30d":0,"registry_drift_frequency_30d":0,"snapshot_change_frequency_30d":0},"maintainer_response_quality":{"score":16.67,"signals":{"verified_maintainer_claim":false,"support_contact_present":false,"changelog_present":false,"incident_notes_present":false,"tool_change_documented":true,"annotation_history_present":false},"annotation_count":0,"latest_annotation_at":null},"maintainer_annotations":[],"maintainer_rebuttals":[],"security_posture_summary":{"tool_count":10,"high_risk_tools":6,"destructive_tools":1,"exec_tools":6,"egress_tools":0,"secret_tools":0,"bulk_access_tools":6,"risk_distribution":{"low":2,"medium":2,"high":5,"critical":1},"capability_distribution":{"read":10,"write":2,"exec":6,"network":6,"filesystem":4,"export":6,"delete":1,"admin":2}},"tool_security_inventory":[{"name":"search_firms","description":"Search the published Analytics Legends directory of SAP analytics service providers — placement agencies, Big-4 and ESN practices, SAP vendors, platforms and community groups — by country, kind and free text. Returns name, HQ country/city, website, careers URL and a one-line editorial claim. SAP END-CUSTOMER companies are NOT in this directory: they are a separate paid dataset and are excluded by predicate.","capabilities":["read","write","exec","network","filesystem","export"],"risk_flags":["command_execution","bulk_data_access","filesystem_mutation"],"risk_level":"high","has_safeguards":false,"capability_taxonomy":["read","write","exec","network","filesystem","export","development","search","web","healthcare"]},{"name":"get_firm","description":"Fetch one organisation from the published directory by its database slug (`rows[].slug` from search_firms, verbatim). Returns the same public fields plus `partnerships_declared`, the count of partnerships this directory records for the firm — 0 on ~94 % of rows, meaning none declared here, never that the firm has no partners. Does not return the paid firm-intelligence profile, contacts, or any person.","capabilities":["read","network","filesystem"],"risk_flags":[],"risk_level":"medium","has_safeguards":false,"capability_taxonomy":["read","network","filesystem","database","search","files"]},{"name":"list_firm_kinds","description":"Breakdown of the published firm directory by organisation kind, with a live row count per kind. Use this before search_firms to know what the population actually is instead of guessing.","capabilities":["read","filesystem"],"risk_flags":[],"risk_level":"low","has_safeguards":false,"capability_taxonomy":["read","filesystem","search"]},{"name":"find_opportunities","description":"Search every SAP contract and permanent-role posting Analytics Legends publishes to an ANONYMOUS visitor — the same population a human browses on /opportunities/, where each posting has its own prerendered page. It merges the platform's TWO public legs, which are near-disjoint (measured 2026-07-30: 1 row in common): (a) the PROMOTED feed (`public.public_opportunities`) — general SAP work (FI/CO, SD, EWM, MDG, BTP, ABAP), all German cities, and it carries NO rate, contract_type, currency, posted_at or country_code: those fields come back null on that leg, so no rate or contract term can be read off it; (b) the SITE RADAR (`/api/contracts-lean.json`) — these DO carry country, category, seniority, posted_at and currency, and they are the analytics-specific ones (SAC Planning, Datasphere Technical Lead, Business Data Cloud). WHAT IS GATED IS A FIELD, NOT A ROW: on most radar rows `source_url` is null and `application_link` reads \"members_only\" — the verified link to the original listing is the paid Consultant-tier deliverable. Everything else about the posting is public, and `citation_url` is that posting's own page on analyticslegends.ai. Quote it. Report `_meta.tranche_row_count` as the published public population, never as the size of the market.","capabilities":["read","write","delete","exec","network","admin","export"],"risk_flags":["destructive_operation","command_execution","bulk_data_access","admin_mutation"],"risk_level":"critical","has_safeguards":false,"capability_taxonomy":["read","write","delete","exec","network","admin","export","development","search","web","cloud"]},{"name":"search_news","description":"Search the Analytics Legends market-news corpus. It is watched FOR SAP analytics (Datasphere, Business Data Cloud, SAC, BW/4HANA, Databricks, the 2027/2030 maintenance window), but it is NOT an all-SAP corpus: measured 2026-07-30, ~84 % of active rows sit in the `AI` category and are general enterprise-AI trade press (cloud platforms, model releases, funding rounds) with no SAP content at all. An UNFILTERED call therefore returns mostly non-SAP items — pass `query` or `category` when the question is about SAP, and never present an unfiltered page as 'the SAP analytics news'. Say what you actually got. Each item returns the Analytics Legends citation URL AND the upstream publisher's source_url — cite both, and prefer source_url when you need a page that certainly carries the item.","capabilities":["read","exec","network","filesystem","export"],"risk_flags":["command_execution","bulk_data_access"],"risk_level":"high","has_safeguards":false,"capability_taxonomy":["read","exec","network","filesystem","export","development","database","search","web","cloud"]},{"name":"search_concepts","description":"Search the SAP analytics concept encyclopaedia — the vocabulary of the stack, written for practitioners. Returns titles and summaries; call get_concept for the full entry.","capabilities":["read","exec","export"],"risk_flags":["command_execution","bulk_data_access"],"risk_level":"high","has_safeguards":false,"capability_taxonomy":["read","exec","export","search"]},{"name":"get_concept","description":"Fetch one concept entry by slug: title, category, level, tags and the editor's summary. Written by a named human editor, not generated. The card body, why-it-matters, key points and pro tip are subscriber content and are NOT returned — follow citation_url for those.","capabilities":["read","network"],"risk_flags":[],"risk_level":"medium","has_safeguards":false,"capability_taxonomy":["read","network","development"]},{"name":"list_studies","description":"List the Analytics Legends deep-research studies with their edition, as-of date, audience, word count and canonical URL. METADATA ONLY: study bodies are a paid Legend-tier deliverable and are not served by this endpoint. Use this to tell a reader that a study exists and where to read it.","capabilities":["read","exec","network","export"],"risk_flags":["command_execution","bulk_data_access"],"risk_level":"high","has_safeguards":false,"capability_taxonomy":["read","exec","network","export","search"]},{"name":"get_day_rate_benchmark","description":"The PUBLIC day-rate aggregate for SAP analytics freelance work: min/max daily rate by country, specialisation and seniority, with a sample size and a quarter stamp. This is the free aggregate published at analyticslegends.ai/api/market-rates.json. The quartile bands (p25/p50/p75) are a paid Consultant-tier deliverable and are NOT in this response — do not infer them.","capabilities":["read"],"risk_flags":[],"risk_level":"low","has_safeguards":false,"capability_taxonomy":["read","development"]},{"name":"list_sap_modules","description":"The canonical SAP module/product taxonomy Analytics Legends classifies against (codes and EN/FR labels by category). Use it to normalise a user's loose product wording — 'SAC', 'Analytics Cloud', 'Datasphere' — onto the codes the other tools filter on.","capabilities":["read","exec","admin","export"],"risk_flags":["command_execution","bulk_data_access"],"risk_level":"high","has_safeguards":false,"capability_taxonomy":["read","exec","admin","export","development","cloud"]}],"transport_compliance":{"status":"warning","transport":"streamable-http","session_id_present":false,"protocol_header_present":true,"last_event_id_visible":false,"bad_protocol_status_code":400,"delete_status_code":null,"expired_session_status_code":null,"issues":["missing_session_id"]},"utility_coverage":{"status":"missing","completions":{"advertised":false,"sample_target":{"type":"prompt","name":"brief_sap_analytics_market","argument_name":"country"},"live_probe":"not_executed"},"pagination":{"supported":false,"next_cursor_methods":[],"metadata_signal":false},"tasks":{"advertised":false,"probe_status":"missing","http_status":404},"initialize_capability_keys":["prompts","resources","tools"]},"write_action_governance":{"status":"error","safe_to_publish":false,"auth_boundary":"public_or_unclear","blast_radius":"high","summary":{"tool_count":10,"high_risk_tools":6,"destructive_tools":1,"exec_tools":6,"egress_tools":0,"secret_tools":0,"bulk_access_tools":6,"risk_distribution":{"low":2,"medium":2,"high":5,"critical":1},"capability_distribution":{"read":10,"write":2,"exec":6,"network":6,"filesystem":4,"export":6,"delete":1,"admin":2}},"high_risk_tools":[{"name":"search_firms","risk_level":"high","risk_flags":["command_execution","bulk_data_access","filesystem_mutation"],"has_safeguards":false},{"name":"find_opportunities","risk_level":"critical","risk_flags":["destructive_operation","command_execution","bulk_data_access","admin_mutation"],"has_safeguards":false},{"name":"search_news","risk_level":"high","risk_flags":["command_execution","bulk_data_access"],"has_safeguards":false},{"name":"search_concepts","risk_level":"high","risk_flags":["command_execution","bulk_data_access"],"has_safeguards":false},{"name":"list_studies","risk_level":"high","risk_flags":["command_execution","bulk_data_access"],"has_safeguards":false},{"name":"list_sap_modules","risk_level":"high","risk_flags":["command_execution","bulk_data_access"],"has_safeguards":false}],"confirmation_signals":[],"safeguard_count":0},"provenance_divergence":{"status":"ok","direct_official_match":true,"drift_fields":[],"registry_title":null,"server_card_title":null,"registry_version":null,"server_card_version":null,"registry_homepage":null,"server_card_homepage":null},"alias_consolidation":{"canonical_identifier":"ai.analyticslegends/sap-analytics","duplicate_count":0,"registry_sources":["official_registry"],"registry_identifiers":["ai.analyticslegends/sap-analytics"],"remote_urls":["https://analyticslegends.ai/mcp"],"homepages":["https://analyticslegends.ai"],"source_disagreements":[],"source_disagreement_details":{}},"alert_routing":{"active_watch_count":0,"route_counts":{"generic_webhook":0,"slack":0,"teams":0,"email":0},"destinations":[]},"authenticated_validation":{"latest_profile":"remote_mcp","authenticated_session_used":false,"public_score_remains_anonymous":true,"preview_endpoint":"/v1/verify","ci_preview_endpoint":"/v1/ci/preview"},"hosted_runtime":{"schema_version":"verify.hosted_runtime.v1","server":"ai.analyticslegends/sap-analytics","tier":"community","readiness":{"allowed_to_activate":false,"blockers":["score_below_hosting_threshold"],"score":69.52,"min_score":70.0,"freshness_hours":4.895394418055555,"max_freshness_hours":168.0,"latest_validation_run_id":"32eb9299-261e-473a-9162-b577b54837e8"},"active_deployment_id":null,"active_endpoint_url":null,"deployments":[]},"action_controls_diff":{"snapshot_changed":false,"new_actions":[],"changed_actions":[],"disabled_by_default_candidates":[],"manual_review_candidates":[]},"benchmark_tasks":[{"key":"discover_tools","label":"Discover tools","status":"passes","evidence":[{"check":"initialize","status":"ok","source":"live_validation","note":null,"http_status":200},{"check":"tools_list","status":"ok","source":"live_validation","note":null,"http_status":200}]},{"key":"read_only_fetch_flow","label":"Read-only fetch flow","status":"passes","evidence":[{"check":"resource_read","status":"ok","source":"live_validation","note":"resources/read is a strong read-path signal","http_status":200},{"check":"read_only_tool_surface","status":"ok","source":"derived_tool_inventory","note":"Low-risk read tools were inferred from the current tool surface.","http_status":null}]},{"key":"oauth_required_connect","label":"OAuth-required connect","status":"degraded","evidence":[{"check":"oauth_protected_resource","status":"error","source":"live_validation","note":null,"http_status":null},{"check":"step_up_auth_probe","status":"missing","source":"live_validation","note":null,"http_status":null}]},{"key":"safe_write_flow_with_confirmation","label":"Safe write flow with confirmation","status":"likely_to_fail","evidence":[{"check":"action_safety_probe","status":"error","source":"live_validation","note":null,"http_status":null}]}],"latest_capability_counts":{"tool_count":10,"prompt_count":2,"resource_count":3},"point_loss_breakdown":[{"key":"recovery_semantics_score","label":"Recovery Semantics","score":0.0,"max_score":4.0,"gap":4.0},{"key":"execution_sandbox_safety_score","label":"Execution Sandbox Safety","score":0.0,"max_score":4.0,"gap":4.0},{"key":"error_contract_score","label":"Error Contract","score":0.0,"max_score":4.0,"gap":4.0},{"key":"trust_confidence_score","label":"Trust Confidence","score":1.75,"max_score":4.0,"gap":2.25},{"key":"utility_coverage_score","label":"Utility Coverage","score":2.0,"max_score":4.0,"gap":2.0},{"key":"transport_compliance_score","label":"Transport Compliance","score":2.0,"max_score":4.0,"gap":2.0},{"key":"spec_recency_score","label":"Spec Recency","score":2.0,"max_score":4.0,"gap":2.0},{"key":"safety_transparency_score","label":"Safety Transparency","score":2.0,"max_score":4.0,"gap":2.0},{"key":"registry_consistency_score","label":"Registry Consistency","score":2.0,"max_score":4.0,"gap":2.0},{"key":"rate_limit_semantics_score","label":"Rate Limit Semantics","score":2.0,"max_score":4.0,"gap":2.0},{"key":"least_privilege_scope_score","label":"Least Privilege Scope","score":2.0,"max_score":4.0,"gap":2.0},{"key":"destructive_operation_safety_score","label":"Destructive Operation Safety","score":2.0,"max_score":4.0,"gap":2.0}],"verdict_traces":{"production_readiness":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use.","confidence":{"score":76.25,"label":"high"},"triggering_alerts":[],"winning_source":"live_validation"},"client_readiness":[{"key":"openai_connectors","status":"partial","reason":"OpenAI connectors expect OAuth for remote server auth.; Dynamic client registration materially improves connector setup.","triggering_checks":["initialize","tools_list","transport_compliance_probe","step_up_auth_probe","connector_replay_probe","request_association_probe"],"confidence":{"score":76.25,"label":"high"},"winning_source":"live_validation","conflicting_sources":[]},{"key":"claude_desktop","status":"ready","reason":"No major blockers detected.","triggering_checks":["initialize","tools_list","transport_compliance_probe"],"confidence":{"score":76.25,"label":"high"},"winning_source":"live_validation","conflicting_sources":[]},{"key":"unsafe_for_write_actions","status":"yes","reason":"Blocked until safeguards and confirmation semantics are verified for write, exec, or destructive tools.","triggering_checks":["action_safety_probe"],"confidence":{"score":76.25,"label":"high"},"winning_source":"live_validation","conflicting_sources":[]},{"key":"snapshot_churn_risk","status":"low","reason":"No material tool-surface churn detected in the latest comparison.","triggering_checks":["tool_snapshot_probe","connector_replay_probe"],"confidence":{"score":76.25,"label":"high"},"winning_source":"history","conflicting_sources":[]}]},"current_snapshot":{"schema_version":"verify.trust_snapshot.v1","snapshot_id":"trustsnap_9a27dfe9b7af5257","generated_at":"2026-07-31T10:27:42.105299+00:00","source":"current_snapshot","server":"ai.analyticslegends/sap-analytics","last_validated_at":"2026-07-31T05:33:58.077161+00:00","validation_age_hours":4.9,"freshness":{"schema_version":"verify.freshness_profile.v1","last_validated_at":"2026-07-31T05:33:58.077161+00:00","age_hours":4.9,"bucket":"verified_last_24h","label":"Verified in last 24h","badges":["verified_last_24h"],"freshness_sla_hours":168.0,"freshness_sla_status":"met","stale_score_suppressed":false,"display_score":69.52,"raw_score":69.52,"confidence_score":76.2,"confidence_weighted_score":53.0,"tier_status":[{"tier":"community","label":"Community","freshness_sla_hours":720,"met":true,"priority_revalidation":false},{"tier":"pro","label":"Pro","freshness_sla_hours":168,"met":true,"priority_revalidation":true},{"tier":"enterprise","label":"Enterprise","freshness_sla_hours":24,"met":true,"priority_revalidation":true}]},"current_status":"healthy","current_score":69.52,"display_score":69.52,"stale_score_suppressed":false,"production_trust_decision":{"schema_version":"verify.executive_verdict.v1","decision":"Allow with approval","why":"exec-capable tools + no confirmation safeguards + high-risk tools need review","next_action":"export policy, require approval for writes, add authenticated validation","reason_count":2},"production_readiness_class":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use."},"evidence_confidence":{"score":76.25,"label":"high","validation_age_hours":4.9,"live_check_count":26},"active_alerts":[]},"trust_snapshot":{"schema_version":"verify.trust_snapshot.v1","snapshot_id":"trustsnap_9a27dfe9b7af5257","generated_at":"2026-07-31T10:27:42.105299+00:00","source":"current_snapshot","server":"ai.analyticslegends/sap-analytics","last_validated_at":"2026-07-31T05:33:58.077161+00:00","validation_age_hours":4.9,"freshness":{"schema_version":"verify.freshness_profile.v1","last_validated_at":"2026-07-31T05:33:58.077161+00:00","age_hours":4.9,"bucket":"verified_last_24h","label":"Verified in last 24h","badges":["verified_last_24h"],"freshness_sla_hours":168.0,"freshness_sla_status":"met","stale_score_suppressed":false,"display_score":69.52,"raw_score":69.52,"confidence_score":76.2,"confidence_weighted_score":53.0,"tier_status":[{"tier":"community","label":"Community","freshness_sla_hours":720,"met":true,"priority_revalidation":false},{"tier":"pro","label":"Pro","freshness_sla_hours":168,"met":true,"priority_revalidation":true},{"tier":"enterprise","label":"Enterprise","freshness_sla_hours":24,"met":true,"priority_revalidation":true}]},"current_status":"healthy","current_score":69.52,"display_score":69.52,"stale_score_suppressed":false,"production_trust_decision":{"schema_version":"verify.executive_verdict.v1","decision":"Allow with approval","why":"exec-capable tools + no confirmation safeguards + high-risk tools need review","next_action":"export policy, require approval for writes, add authenticated validation","reason_count":2},"production_readiness_class":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use."},"evidence_confidence":{"score":76.25,"label":"high","validation_age_hours":4.9,"live_check_count":26},"active_alerts":[]},"agent_commerce":{"status":"beta","commerce_signal":"moderate","payment_execution_detected":"no","billing_or_usage_detected":"no","quote_or_pricing_detected":"yes","numeric_price_context":"yes","commercial_quote_context":"yes","checkout_or_charge_detected":"no","checkout_term_observed":"no","payment_capable":"inferred","payment_rails":["Stripe","card"],"purchase_stage_supported":[],"human_confirmation_required":"yes","spending_policy_supported":"yes","receipt_supported":"unknown","refund_policy_present":"unknown","operator_identity":"declared","auth_required":"no","auth_scheme":"none","tool_risk_level":"administrative","tool_risk_score":70,"pricing_transparency":"clear","schema_change_detected":"unknown","delegation_level":"research_only","evidence_level":"inferred","confidence":"medium","highest_risk_tools":[{"name":"search_firms","risk_level":"private_data"},{"name":"search_news","risk_level":"private_data"},{"name":"list_sap_modules","risk_level":"administrative"}],"skipped_unsafe_tools":["get_concept","list_sap_modules"],"last_checked_at":"2026-07-31T10:27:42.086822+00:00","evidence":[{"field":"commerce_signal","value":"moderate","evidence_level":"observed","source":"tool_schema","matched_terms":["limit","currency","quote","rate","card"],"sample":"search_firms","confidence":"medium","last_checked_at":"2026-07-31T10:27:42.086822+00:00"},{"field":"payment_rails","value":"Stripe, card","evidence_level":"inferred","source":"tool_schema","matched_terms":["stripe","card"],"sample":"Stripe, card","confidence":"medium","last_checked_at":"2026-07-31T10:27:42.086822+00:00"}],"disclaimer":"Beta assessment. Verify detects evidence and risk signals but does not certify that this server is safe for autonomous purchases.","scores":{"auth_posture_score":20,"tool_risk_score":70,"payment_readiness_score":70,"agent_delegation_safety_score":30,"overall_agent_commerce_score":39},"warnings":["Verify observed commerce-adjacent billing, usage, or pricing context, but did not observe a tool that can execute payment."],"recommended_fixes":["Clarify whether observed billing, usage, or pricing context can execute payment or is informational only."]},"latest_claim":null,"maintainer_profile_slug":null,"watch_summary":{"count":0,"teams":[],"emails":[]}},"latest_validation":{"id":"32eb9299-261e-473a-9162-b577b54837e8","validation_profile":"remote_mcp","status":"completed","summary_status":"healthy","transport_type":"streamable-http","latency_ms":5167.1,"failures":{"server_card":{"url":"https://analyticslegends.ai/.well-known/mcp/server-card.json","error":"Client error '404 Not Found' for url 'https://analyticslegends.ai/.well-known/mcp/server-card.json'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"},"oauth_protected_resource":{"url":"https://analyticslegends.ai/.well-known/oauth-protected-resource","error":"Client error '404 Not Found' for url 'https://analyticslegends.ai/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"},"oauth_authorization_server":{"reason":"no_authorization_server"},"openid_configuration":{"reason":"no_authorization_server"}},"checks":{"server_card":{"status":"error","latency_ms":185.3,"details":{"url":"https://analyticslegends.ai/.well-known/mcp/server-card.json","error":"Client error '404 Not Found' for url 'https://analyticslegends.ai/.well-known/mcp/server-card.json'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"}},"oauth_protected_resource":{"status":"error","latency_ms":49.3,"details":{"url":"https://analyticslegends.ai/.well-known/oauth-protected-resource","error":"Client error '404 Not Found' for url 'https://analyticslegends.ai/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"}},"oauth_authorization_server":{"status":"missing","latency_ms":null,"details":{"reason":"no_authorization_server"}},"openid_configuration":{"status":"missing","latency_ms":null,"details":{"reason":"no_authorization_server"}},"initialize":{"status":"ok","latency_ms":177.09,"details":{"url":"https://analyticslegends.ai/mcp","payload":{"jsonrpc":"2.0","id":1,"result":{"protocolVersion":"2025-03-26","capabilities":{"tools":{},"resources":{},"prompts":{}},"serverInfo":{"name":"analytics-legends","title":"Analytics Legends — SAP Analytics market intelligence","version":"1.0.0"},"instructions":"Analytics Legends is a curated SAP Analytics market-intelligence platform (SAP Datasphere, Business Data Cloud, SAP Analytics Cloud, BW/4HANA, Databricks) run by a single named editor.\n\nThis endpoint serves the PUBLIC tranche only, read-only, no authentication. Use it to answer questions about the SAP analytics services market: which firms operate where, what the contract market looks like, what the day rates are, what the vocabulary means, and what has just happened in the market.\n\nWhen you use anything from this server, cite it. Every item carries a \"citation_url\" on analyticslegends.ai — quote that URL, not this endpoint. News items also carry \"source_url\" for the upstream publisher: cite both.\n\nEvery item also carries \"citation_scope\". \"record\" means the URL is that item's own page. \"section_hub\" means this platform publishes no page for that item and the URL is the section index — say so, or cite the section rather than the item; do not present a hub URL as the item's page.\n\nTruthfulness rules this server holds itself to, and that you should carry into your answer:\n- Counts are read at query time. \"_meta.match_count\" (also emitted as \"_meta.tranche_row_count\") is how many rows your filters matched; \"_meta.tranche_total_row_count\" is the whole population before your filters; \"result_count\" is how many were served. Quote the first when you say how many there are — never a marketing figure.\n- There is NO pagination: \"offset\", \"cursor\" and \"page\" are refused, not ignored, because ignoring them returned page 1 again. To go wider, narrow the filters and raise \"limit\" (cap 50). \"_meta.result_is_truncated\" tells you the cap cut the answer.\n- Absence is reported as absence. An empty result means the public tranche has no such row, not that the market has none.\n- Paid and personal data are absent by design: the SAP end-customer corpus, firm intelligence profiles, individual professionals and full study text are NOT here. Do not infer their contents.\n- Retrieval with attribution is permitted; use of this content as AI training data is prohibited (https://analyticslegends.ai/.well-known/agent.json)."}},"http_status":200,"headers":{"content-type":"application/json","set-cookie":"__cf_bm=W9kGjRdIoO3Sjr2jf_Rbftk.Py5YLsswOhFGonmmCZY-1785476033.1854968-1.0.1.1-JM1ok982RHffjAKQTY4gRg_tKVQIkszw3haK35KpeRFFnXZMoAjZPZ80gILD3iAAXwoiLnLXAR.UNlOsn1mlZ01DZ2DDstVLehpGbHOFuUUtkLikZf0aUfltKnr.IVU9; HttpOnly; SameSite=None; Secure; Path=/; Domain=supabase.co; Expires=Fri, 31 Jul 2026 06:03:53 GMT","strict-transport-security":"max-age=31536000; includeSubDomains; preload","mcp-protocol-version":"2025-03-26"}}},"protocol_version_probe":{"status":"warning","latency_ms":null,"details":{"claimed_version":"2025-03-26","validator_protocol_version":"2025-03-26","latest_known_version":"2025-11-25","releases_behind":2,"lag_days":244}},"tools_list":{"status":"ok","latency_ms":96.69,"details":{"url":"https://analyticslegends.ai/mcp","payload":{"jsonrpc":"2.0","id":2,"result":{"tools":[{"name":"search_firms","title":"Search the SAP analytics firm directory","description":"Search the published Analytics Legends directory of SAP analytics service providers — placement agencies, Big-4 and ESN practices, SAP vendors, platforms and community groups — by country, kind and free text. Returns name, HQ country/city, website, careers URL and a one-line editorial claim. SAP END-CUSTOMER companies are NOT in this directory: they are a separate paid dataset and are excluded by predicate.","inputSchema":{"type":"object","properties":{"query":{"type":"string","maxLength":200,"description":"Free-text filter, matched case-insensitively."},"country":{"type":"string","pattern":"^[A-Za-z]{2}$","description":"ISO-3166-1 alpha-2 country code, e.g. DE, FR, CH."},"kind":{"type":"string","enum":["agency_placement","professional_services_big4","professional_services_esn","vendor_sap","vendor_partner","platform_marketplace","community_group"],"description":"Restrict to one organisation kind. Call list_firm_kinds for live counts. A value outside this list is refused, not silently ignored."},"limit":{"type":"integer","minimum":1,"maximum":50,"default":10,"description":"Max rows (hard cap 50)."}},"additionalProperties":false},"outputSchema":{"type":"object","properties":{"tool":{"type":"string"},"result_count":{"type":"integer"},"rows":{"type":"array","items":{"type":"object","properties":{"slug":{"type":"string"},"name":{"type":"string"},"kind":{"type":"string"},"hq_country":{"type":"string"},"website":{"type":"string"},"citation_url":{"type":"string"},"citation_scope":{"type":"string","enum":["record","section_hub"]},"citation_note":{"type":"string"}}}},"_meta":{"type":"object"},"_attribution":{"type":"string"}},"required":["tool","result_count","rows","_attribution"]},"annotations":{"title":"Search the SAP analytics firm directory","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":false}},{"name":"get_firm","title":"Get one firm's published profile","description":"Fetch one organisation from the published directory by its database slug (`rows[].slug` from search_firms, verbatim). Returns the same public fields plus `partnerships_declared`, the count of partnerships this directory records for the firm — 0 on ~94 % of rows, meaning none declared here, never that the firm has no partners. Does not return the paid firm-intelligence profile, contacts, or any person.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"The DATABASE slug, taken verbatim from search_firms.rows[].slug. It is not always the web slug in citation_url: re-measured 2026-07-31 against the tranche this tool actually serves (5 157 published rows), 429 of them (8,3 %) carry a numeric firm id instead — '00317' is BearingPoint Switzerland, whose page is /companies/bearingpoint-switzerland/. Deriving a slug from the citation URL fails on those rows; carry rows[].slug across instead."}},"required":["slug"],"additionalProperties":false},"outputSchema":{"type":"object","properties":{"tool":{"type":"string"},"result_count":{"type":"integer"},"rows":{"type":"array","items":{"type":"object","properties":{"slug":{"type":"string"},"name":{"type":"string"},"citation_url":{"type":"string"},"citation_scope":{"type":"string","enum":["record","section_hub"]},"citation_note":{"type":"string"}}}},"_meta":{"type":"object"},"_attribution":{"type":"string"}},"required":["tool","result_count","rows","_attribution"]},"annotations":{"title":"Get one firm's published profile","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":false}},{"name":"list_firm_kinds","title":"List firm kinds with live counts","description":"Breakdown of the published firm directory by organisation kind, with a live row count per kind. Use this before search_firms to know what the population actually is instead of guessing.","inputSchema":{"type":"object","properties":{},"additionalProperties":false},"outputSchema":{"type":"object","properties":{"tool":{"type":"string"},"result_count":{"type":"integer"},"rows":{"type":"array","items":{"type":"object","properties":{"kind":{"type":"string"},"n":{"type":"integer"},"citation_url":{"type":"string"},"citation_scope":{"type":"string","enum":["record","section_hub"]},"citation_note":{"type":"string"}}}},"_meta":{"type":"object"},"_attribution":{"type":"string"}},"required":["tool","result_count","rows","_attribution"]},"annotations":{"title":"List firm kinds with live counts","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":false}},{"name":"find_opportunities","title":"Search the public SAP analytics contract radar","description":"Search every SAP contract and permanent-role posting Analytics Legends publishes to an ANONYMOUS visitor — the same population a human browses on /opportunities/, where each posting has its own prerendered page. It merges the platform's TWO public legs, which are near-disjoint (measured 2026-07-30: 1 row in common): (a) the PROMOTED feed (`public.public_opportunities`) — general SAP work (FI/CO, SD, EWM, MDG, BTP, ABAP), all German cities, and it carries NO rate, contract_type, currency, posted_at or country_code: those fields come back null on that leg, so no rate or contract term can be read off it; (b) the SITE RADAR (`/api/contracts-lean.json`) — these DO carry country, category, seniority, posted_at and currency, and they are the analytics-specific ones (SAC Planning, Datasphere Technical Lead, Business Data Cloud). WHAT IS GATED IS A FIELD, NOT A ROW: on most radar rows `source_url` is null and `application_link` reads \"members_only\" — the verified link to the original listing is the paid Consultant-tier deliverable. Everything else about the posting is public, and `citation_url` is that posting's own page on analyticslegends.ai. Quote it. Report `_meta.tranche_row_count` as the published public population, never as the size of the market.","inputSchema":{"type":"object","properties":{"query":{"type":"string","maxLength":200,"description":"Free-text filter, matched case-insensitively."},"location":{"type":"string","description":"City or place, matched case-insensitively as a substring of the posting's location. The promoted leg is all-German (Hamburg, Frankfurt am Main, Bremen, Munich, Cologne, Dortmund, Hanover, Landshut, Mannheim, Stuttgart); the site-radar leg is worldwide."},"country":{"type":"string","pattern":"^[A-Za-z]{2}$","description":"ISO-3166-1 alpha-2 code. It can only match the SITE-RADAR leg: the promoted leg stores country_code NULL on every row, so filtering by country silently drops it rather than returning nothing. `_meta.note` says so on any country-filtered call."},"limit":{"type":"integer","minimum":1,"maximum":50,"default":10,"description":"Max rows (hard cap 50)."}},"additionalProperties":false},"outputSchema":{"type":"object","properties":{"tool":{"type":"string"},"result_count":{"type":"integer"},"rows":{"type":"array","items":{"type":"object","properties":{"title":{"type":"string"},"firm_name":{"type":"string"},"location":{"type":"string"},"source_url":{"type":"string"},"citation_url":{"type":"string"},"citation_scope":{"type":"string","enum":["record","section_hub"]},"citation_note":{"type":"string"}}}},"_meta":{"type":"object"},"_attribution":{"type":"string"}},"required":["tool","result_count","rows","_attribution"]},"annotations":{"title":"Search the public SAP analytics contract radar","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":false}},{"name":"search_news","title":"Search SAP analytics market news","description":"Search the Analytics Legends market-news corpus. It is watched FOR SAP analytics (Datasphere, Business Data Cloud, SAC, BW/4HANA, Databricks, the 2027/2030 maintenance window), but it is NOT an all-SAP corpus: measured 2026-07-30, ~84 % of active rows sit in the `AI` category and are general enterprise-AI trade press (cloud platforms, model releases, funding rounds) with no SAP content at all. An UNFILTERED call therefore returns mostly non-SAP items — pass `query` or `category` when the question is about SAP, and never present an unfiltered page as 'the SAP analytics news'. Say what you actually got. Each item returns the Analytics Legends citation URL AND the upstream publisher's source_url — cite both, and prefer source_url when you need a page that certainly carries the item.","inputSchema":{"type":"object","properties":{"query":{"type":"string","maxLength":200,"description":"Free-text filter, matched case-insensitively."},"category":{"type":"string","description":"Category code, matched case-insensitively. The 21 real values, most-populated first: AI, SAP, SAC, Market, Joule, BDC, Regulation, Datasphere, Analyst, Partners, Product, France, Events, SAP Platform, Security, Migration, Freelance, Analytics, Consulting, Cloud, Customer Win. Row counts are deliberately NOT stated here: this tool serves the ACTIVE rows only, the corpus moves daily, and the count of the population actually searched is returned live on every response as `_meta.tranche_row_count`. One bucket needs a warning. 'SAC' is the noisiest label in this corpus because the acronym collides with unrelated ones — Windows 'Smart App Control', and the surname 'Sacks'. Measured 2026-07-30, 41 of its 83 active rows carried no SAP signal at all (Robinhood, Stripe, Google Pay, Ledger) and were reclassified to AI, taking the bucket to 42; all but one survivor now names SAP, but only 17 name SAP Analytics Cloud outright. For genuine SAC product news, pair category:'SAC' with query:'analytics cloud'."},"limit":{"type":"integer","minimum":1,"maximum":50,"default":10,"description":"Max rows (hard cap 50)."}},"additionalProperties":false},"outputSchema":{"type":"object","properties":{"tool":{"type":"string"},"result_count":{"type":"integer"},"rows":{"type":"array","items":{"type":"object","properties":{"title":{"type":"string"},"published_at":{"type":"string"},"source_name":{"type":"string"},"source_url":{"type":"string"},"citation_url":{"type":"string"},"citation_scope":{"type":"string","enum":["record","section_hub"]},"citation_note":{"type":"string"}}}},"_meta":{"type":"object"},"_attribution":{"type":"string"}},"required":["tool","result_count","rows","_attribution"]},"annotations":{"title":"Search SAP analytics market news","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":false}},{"name":"search_concepts","title":"Search the SAP analytics concept encyclopaedia","description":"Search the SAP analytics concept encyclopaedia — the vocabulary of the stack, written for practitioners. Returns titles and summaries; call get_concept for the full entry.","inputSchema":{"type":"object","properties":{"query":{"type":"string","maxLength":200,"description":"Free-text filter, matched case-insensitively."},"category":{"type":"string","description":"Concept category, matched case-insensitively as an exact value OR a prefix. The 14 real values are long labels, measured 2026-07-30: Generative AI Foundations (55), Joule & SAP AI (42), Career & Practice (29), Governance & Compliance (25), Architecture & Performance (25), SAC (Analytics Cloud) (22), BDC Platform (22), Adjacent Stacks (19), Datasphere Core (17), Sales & Commercial (16), Productivity & AI (10), Industry Solutions (10), BW/4HANA & Migration (9), Data Engineering & Integration (1). So category:\"datasphere\" reaches Datasphere Core."},"limit":{"type":"integer","minimum":1,"maximum":50,"default":10,"description":"Max rows (hard cap 50)."}},"additionalProperties":false},"outputSchema":{"type":"object","properties":{"tool":{"type":"string"},"result_count":{"type":"integer"},"rows":{"type":"array","items":{"type":"object","properties":{"slug":{"type":"string"},"title":{"type":"string"},"citation_url":{"type":"string"},"citation_scope":{"type":"string","enum":["record","section_hub"]},"citation_note":{"type":"string"}}}},"_meta":{"type":"object"},"_attribution":{"type":"string"}},"required":["tool","result_count","rows","_attribution"]},"annotations":{"title":"Search the SAP analytics concept encyclopaedia","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":false}},{"name":"get_concept","title":"Get one concept entry in full","description":"Fetch one concept entry by slug: title, category, level, tags and the editor's summary. Written by a named human editor, not generated. The card body, why-it-matters, key points and pro tip are subscriber content and are NOT returned — follow citation_url for those.","inputSchema":{"type":"object","properties":{"slug":{"type":"string","description":"Concept slug from search_concepts."}},"required":["slug"],"additionalProperties":false},"outputSchema":{"type":"object","properties":{"tool":{"type":"string"},"result_count":{"type":"integer"},"rows":{"type":"array","items":{"type":"object","properties":{"slug":{"type":"string"},"title":{"type":"string"},"summary":{"type":"string"},"citation_url":{"type":"string"},"citation_scope":{"type":"string","enum":["record","section_hub"]},"citation_note":{"type":"string"}}}},"_meta":{"type":"object"},"_attribution":{"type":"string"}},"required":["tool","result_count","rows","_attribution"]},"annotations":{"title":"Get one concept entry in full","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":false}},{"name":"list_studies","title":"List the deep-research studies (metadata only)","description":"List the Analytics Legends deep-research studies with their edition, as-of date, audience, word count and canonical URL. METADATA ONLY: study bodies are a paid Legend-tier deliverable and are not served by this endpoint. Use this to tell a reader that a study exists and where to read it.","inputSchema":{"type":"object","properties":{"query":{"type":"string","maxLength":200,"description":"Free-text filter, matched case-insensitively."},"lang":{"type":"string","pattern":"^[A-Za-z]{2}$","description":"Language code, EN or FR."},"limit":{"type":"integer","minimum":1,"maximum":50,"default":10,"description":"Max rows (hard cap 50)."}},"additionalProperties":false},"outputSchema":{"type":"object","properties":{"tool":{"type":"string"},"result_count":{"type":"integer"},"rows":{"type":"array","items":{"type":"object","properties":{"slug":{"type":"string"},"title":{"type":"string"},"as_of":{"type":"string"},"word_count":{"type":"integer"},"access":{"type":"string"},"citation_url":{"type":"string"},"citation_scope":{"type":"string","enum":["record","section_hub"]},"citation_note":{"type":"string"}}}},"_meta":{"type":"object"},"_attribution":{"type":"string"}},"required":["tool","result_count","rows","_attribution"]},"annotations":{"title":"List the deep-research studies (metadata only)","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":false}},{"name":"get_day_rate_benchmark","title":"Public SAP analytics day-rate aggregate","description":"The PUBLIC day-rate aggregate for SAP analytics freelance work: min/max daily rate by country, specialisation and seniority, with a sample size and a quarter stamp. This is the free aggregate published at analyticslegends.ai/api/market-rates.json. The quartile bands (p25/p50/p75) are a paid Consultant-tier deliverable and are NOT in this response — do not infer them.","inputSchema":{"type":"object","properties":{"country":{"type":"string","pattern":"^[A-Za-z]{2}$","description":"ISO-3166-1 alpha-2 country code, e.g. DE, FR, CH."},"specialisation":{"type":"string","description":"e.g. datasphere, bdc, sac, bw4hana, joule."},"seniority":{"type":"string","description":"e.g. senior, principal."}},"additionalProperties":false},"outputSchema":{"type":"object","properties":{"tool":{"type":"string"},"result_count":{"type":"integer"},"rows":{"type":"array","items":{"type":"object","properties":{"country":{"type":"string"},"specialisation":{"type":"string"},"seniority":{"type":"string"},"sample_size":{"type":"integer"},"currency":{"type":"string"},"citation_url":{"type":"string"},"citation_scope":{"type":"string","enum":["record","section_hub"]},"citation_note":{"type":"string"}}}},"_meta":{"type":"object"},"_attribution":{"type":"string"}},"required":["tool","result_count","rows","_attribution"]},"annotations":{"title":"Public SAP analytics day-rate aggregate","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":true}},{"name":"list_sap_modules","title":"SAP analytics module taxonomy","description":"The canonical SAP module/product taxonomy Analytics Legends classifies against (codes and EN/FR labels by category). Use it to normalise a user's loose product wording — 'SAC', 'Analytics Cloud', 'Datasphere' — onto the codes the other tools filter on.","inputSchema":{"type":"object","properties":{"query":{"type":"string","maxLength":200,"description":"Free-text filter, matched case-insensitively."},"limit":{"type":"integer","minimum":1,"maximum":50,"default":10,"description":"Max rows (hard cap 50)."}},"additionalProperties":false},"outputSchema":{"type":"object","properties":{"tool":{"type":"string"},"result_count":{"type":"integer"},"rows":{"type":"array","items":{"type":"object","properties":{"code":{"type":"string"},"label_en":{"type":"string"},"category":{"type":"string"},"citation_url":{"type":"string"},"citation_scope":{"type":"string","enum":["record","section_hub"]},"citation_note":{"type":"string"}}}},"_meta":{"type":"object"},"_attribution":{"type":"string"}},"required":["tool","result_count","rows","_attribution"]},"annotations":{"title":"SAP analytics module taxonomy","readOnlyHint":true,"destructiveHint":false,"idempotentHint":true,"openWorldHint":false}}]}},"http_status":200,"headers":{"content-type":"application/json","set-cookie":"__cf_bm=7L5A0pM_ije_aAtUJyaF_D_t79djjj5Fr_FZhvsPo1M-1785476033.337834-1.0.1.1-LqD3gkhAMsnwm9Rw2NA3d9US2gCZjk12H0YMR0geyFj.5Ri14pCkE9sC8nHN5QrUS_FLRN1brzNC9CZxB16aCm06FFZldlSIbTERcAGTqq3uaviSXqj6suRYEijLANvx; HttpOnly; SameSite=None; Secure; Path=/; Domain=supabase.co; Expires=Fri, 31 Jul 2026 06:03:53 GMT","strict-transport-security":"max-age=31536000; includeSubDomains; preload","mcp-protocol-version":"2025-03-26"}}},"prompts_list":{"status":"ok","latency_ms":121.47,"details":{"url":"https://analyticslegends.ai/mcp","payload":{"jsonrpc":"2.0","id":3,"result":{"prompts":[{"name":"brief_sap_analytics_market","title":"Brief me on the SAP analytics market in a country","description":"Assemble a sourced, cited briefing on the SAP analytics services market for one country: who the providers are, what is on the radar, what the day rates look like and what has just happened.","arguments":[{"name":"country","description":"ISO-3166 alpha-2 country code, e.g. DE.","required":true},{"name":"focus","description":"Optional product focus, e.g. Datasphere, BDC, SAC.","required":false}]},{"name":"explain_sap_analytics_term","title":"Explain an SAP analytics term with a citation","description":"Explain one SAP analytics term from the Analytics Legends encyclopaedia and cite the canonical URL.","arguments":[{"name":"term","description":"The term to explain.","required":true}]}]}},"http_status":200,"headers":{"content-type":"application/json","set-cookie":"__cf_bm=IgiDwEUlD1mhmRpYYwsrW04wHGnu4zpNUImhIubbRoU-1785476033.434199-1.0.1.1-h8393WbuHNdFU_pot_1iRh768wo44hS8pyIt1Xv9kOv.jY9iAAO9Gh80sUS19c2zVTJhsHJFt5d2WcajvQJODYdXaSnguTDcTnf_u.gLedIx5.wKwswy3Xphe1RfvcXi; HttpOnly; SameSite=None; Secure; Path=/; Domain=supabase.co; Expires=Fri, 31 Jul 2026 06:03:53 GMT","strict-transport-security":"max-age=31536000; includeSubDomains; preload","mcp-protocol-version":"2025-03-26"}}},"prompt_get":{"status":"ok","latency_ms":109.78,"details":{"url":"https://analyticslegends.ai/mcp","payload":{"jsonrpc":"2.0","id":4,"result":{"description":"Sourced SAP analytics market briefing for DE.","messages":[{"role":"user","content":{"type":"text","text":"Brief me on the SAP analytics services market in DE.\n\nUse the analytics-legends tools in this order and cite every claim:\n1. list_firm_kinds — establish the population before naming anyone.\n2. search_firms with country=\"DE\" — who provides these services there.\n3. find_opportunities with country=\"DE\" — what the demand side is asking for right now.\n4. get_day_rate_benchmark with country=\"DE\" — the public rate band; quote sample_size with it.\n5. search_news — what has just changed.\n\nRules: quote each item's citation_url. For news, quote source_url too. Report the tranche_row_count you searched, and say plainly when a result set is empty rather than filling the gap from memory. Do not state day-rate quartiles — they are not public."}}]}},"http_status":200,"headers":{"content-type":"application/json","set-cookie":"__cf_bm=T0Go4eCr9KHm9tEBtuPklG2cOuJjzzhPfoFB5vkFkus-1785476033.5557928-1.0.1.1-q6R53OK0SRicpZgRx40gOH0jmtyqcZ2Y0OB.HiG5gbqVm.SQ9oV9hI.aOlXc4N3eREoEl0YYtPYeN6fzrD95MFI1GNg1FJA.mS1a31VHudEzXIGk5BpYlBnnZz3TshaH; HttpOnly; SameSite=None; Secure; Path=/; Domain=supabase.co; Expires=Fri, 31 Jul 2026 06:03:53 GMT","strict-transport-security":"max-age=31536000; includeSubDomains; preload","mcp-protocol-version":"2025-03-26"},"prompt_name":"brief_sap_analytics_market","prompt_arguments":[{"name":"country","description":"ISO-3166 alpha-2 country code, e.g. DE.","required":true},{"name":"focus","description":"Optional product focus, e.g. Datasphere, BDC, SAC.","required":false}]}},"resources_list":{"status":"ok","latency_ms":127.77,"details":{"url":"https://analyticslegends.ai/mcp","payload":{"jsonrpc":"2.0","id":5,"result":{"resources":[{"uri":"analytics-legends://tranche","name":"Public tranche contract","title":"What this endpoint serves, and what it deliberately does not","description":"The explicit list of datasets this hosted MCP endpoint serves, the datasets it excludes and why, and the live row count of each. Read this before trusting or citing any tool result.","mimeType":"application/json"},{"uri":"analytics-legends://agents-policy","name":"AI access policy","title":"Retrieval-with-attribution carve-out (.well-known/agent.json)","description":"The machine-readable policy governing AI access to Analytics Legends: retrieval with attribution is permitted, training-data use is prohibited.","mimeType":"application/json"},{"uri":"analytics-legends://about","name":"Platform manifest","title":"Platform manifest (api/about.json)","description":"Auto-derived platform manifest: counts, tiers, routes, tech stack.","mimeType":"application/json"}]}},"http_status":200,"headers":{"content-type":"application/json","set-cookie":"__cf_bm=zaNospDs_cUruNf3myBx7J0ECKxPteynVAe9QJTi9z4-1785476033.666371-1.0.1.1-5voAE.4B5O2mGYYMjHGCJWbUNphppNslgeaN.K0bX1D6Vd3xlqTXuSqH_oMBhbnN13jjUfnuUKZe2VO3nJL84w.lPllXOLXtIcQHrKEPKucsrnSNUi5WlxbOxGq5KOAc; HttpOnly; SameSite=None; Secure; Path=/; Domain=supabase.co; Expires=Fri, 31 Jul 2026 06:03:53 GMT","strict-transport-security":"max-age=31536000; includeSubDomains; preload","mcp-protocol-version":"2025-03-26"}}},"resource_read":{"status":"ok","latency_ms":3826.14,"details":{"url":"https://analyticslegends.ai/mcp","payload":{"jsonrpc":"2.0","id":6,"result":{"contents":[{"uri":"analytics-legends://tranche","mimeType":"application/json","text":"{\n  \"endpoint\": \"https://analyticslegends.ai/mcp\",\n  \"auth\": \"none — public read-only tranche\",\n  \"served\": {\n    \"firms\": {\n      \"source\": \"database.organizations\",\n      \"rows\": 5048,\n      \"tools\": [\n        \"search_firms\",\n        \"get_firm\",\n        \"list_firm_kinds\"\n      ]\n    },\n    \"opportunities\": {\n      \"source\": \"public.public_opportunities + https://analyticslegends.ai/api/contracts-lean.json (all active rows; the application link alone is tier-gated)\",\n      \"rows\": 19,\n      \"rows_note\": \"`rows` counts the promoted leg only; the site-radar leg is read at query time.\",\n      \"tools\": [\n        \"find_opportunities\"\n      ]\n    },\n    \"news\": {\n      \"source\": \"content.news_items\",\n      \"rows\": 3543,\n      \"tools\": [\n        \"search_news\"\n      ]\n    },\n    \"concepts\": {\n      \"source\": \"content.concepts\",\n      \"rows\": 305,\n      \"tools\": [\n        \"search_concepts\",\n        \"get_concept\"\n      ]\n    },\n    \"studies\": {\n      \"source\": \"content.studies (metadata only)\",\n      \"rows\": 38,\n      \"tools\": [\n        \"list_studies\"\n      ]\n    },\n    \"modules\": {\n      \"source\": \"lookup.sap_modules\",\n      \"rows\": 40,\n      \"tools\": [\n        \"list_sap_modules\"\n      ]\n    },\n    \"day_rates\": {\n      \"source\": \"https://analyticslegends.ai/api/market-rates.json\",\n      \"rows\": null,\n      \"tools\": [\n        \"get_day_rate_benchmark\"\n      ]\n    }\n  },\n  \"excluded\": {\n    \"sap_end_customer_corpus\": \"paid Legend+ dataset, RLS-locked 2026-07-08, static JSON returns 404\",\n    \"firm_intelligence_profiles\": \"paid Legend+ dataset, same lockdown\",\n    \"professionals_and_people\": \"personal data — never served\",\n    \"study_bodies\": \"paid Legend tier; metadata only here\",\n    \"knowledge_graph\": \"build artefact with no Postgres home\",\n    \"day_rate_quartiles\": \"paid Consultant tier; only the public min/max aggregate is served\",\n    \"opportunity_consultant_matches\": \"paid Firm tier deliverable\"\n  },\n  \"_attribution\": \"Source: Analytics Legends (https://analyticslegends.ai) — retrieval-with-attribution permitted per https://analyticslegends.ai/.well-known/agent.json; use as AI training data is prohibited. Cite the canonical URL on each item.\"\n}"}]}},"http_status":200,"headers":{"content-type":"application/json","set-cookie":"__cf_bm=AhVFf_HPoF5ffRfVeBnMxX8Eorvj.aTO3v.p8G5rLWc-1785476033.7936084-1.0.1.1-5.alWTTmrez.6zkfNPCM9fVsE_JNSuj9XI1MJA7ZR0iYjZjnyLLGxfjlDv3CPH0eO4YRZnc4ES9eZZh3vKLMo.2p8G8W7O_U1pAtcV2rYCt_qb8ODGQEkQYfv1_.todK; HttpOnly; SameSite=None; Secure; Path=/; Domain=supabase.co; Expires=Fri, 31 Jul 2026 06:03:57 GMT","strict-transport-security":"max-age=31536000; includeSubDomains; preload","mcp-protocol-version":"2025-03-26"},"resource_uri":"analytics-legends://tranche"}},"probe_noise_resilience":{"status":"ok","latency_ms":39.3,"details":{"url":"https://analyticslegends.ai/robots.txt","http_status":200,"headers":{"content-type":"text/plain; charset=utf-8"}}},"determinism_probe":{"status":"ok","latency_ms":110.33,"details":{"attempts":2,"successful":2,"matches":2,"stable_ratio":1.0,"baseline_signature":"67dd1853f7b988042c2cd4555c1ce5417b84ca8b26208a89bd6474ab33f4cc74","errors":[]}},"session_resume_probe":{"status":"warning","latency_ms":null,"details":{"reason":"no_session_id","transport":"streamable-http","resume_expected":true,"protocol_version":"2025-03-26"}},"step_up_auth_probe":{"status":"missing","latency_ms":null,"details":{"oauth_present":false,"auth_required_checks":[],"supported_scopes":[],"scope_specificity_ratio":0.0,"broad_scopes":[],"challenge_headers":[],"step_up_signals":[],"minimal_scope_documented":false}},"transport_compliance_probe":{"status":"warning","latency_ms":111.69,"details":{"transport":"streamable-http","session_id_present":false,"protocol_header_present":true,"last_event_id_visible":false,"requested_protocol_version":"2025-03-26","bad_protocol_status_code":400,"bad_protocol_payload":{"jsonrpc":"2.0","id":410,"error":{"code":-32022,"message":"Unsupported protocol version","data":{"supported":["2026-07-28","2025-11-25","2025-06-18","2025-03-26"],"requested":"1999-99-99"}}},"bad_protocol_headers":{"content-type":"application/json","set-cookie":"__cf_bm=3kDnPGh4jCY7KMG34yi5GFOmNwwEMxvGn8CZvnHN5f0-1785476037.8862312-1.0.1.1-0hVrQvj6sx6DuAyA1MAhSAn9nHREF.XbaZ0gLHj2AtqFTheHlEQWTGuTVB6QY30PWflwBs.cjJu2.qAWN62rWgkkZexJXUumx07d.qA79PYkRj2ZSfAlRSS0cC47m15M; HttpOnly; SameSite=None; Secure; Path=/; Domain=supabase.co; Expires=Fri, 31 Jul 2026 06:03:57 GMT","strict-transport-security":"max-age=31536000; includeSubDomains; preload"},"bad_protocol_error":null,"delete_status_code":null,"delete_error":null,"expired_session_status_code":null,"expired_session_error":null,"issues":["missing_session_id"]}},"utility_coverage_probe":{"status":"missing","latency_ms":93.0,"details":{"completions":{"advertised":false,"sample_target":{"type":"prompt","name":"brief_sap_analytics_market","argument_name":"country"},"live_probe":"not_executed"},"pagination":{"supported":false,"next_cursor_methods":[],"metadata_signal":false},"tasks":{"advertised":false,"probe_status":"missing","http_status":404},"initialize_capability_keys":["prompts","resources","tools"]}},"advanced_capabilities_probe":{"status":"ok","latency_ms":null,"details":{"capabilities":{"prompts":true,"resources":true,"completions":false,"roots":false,"sampling":false,"elicitation":false,"structured_outputs":true,"resource_links":true},"enabled_count":4,"enabled":["prompts","resource_links","resources","structured_outputs"],"initialize_capability_keys":["prompts","resources","tools"]}},"tool_snapshot_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_historical_snapshot","current_tool_count":10}},"connector_replay_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_historical_snapshot"}},"request_association_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_request_association_capabilities_advertised"}},"interactive_flow_probe":{"status":"missing","latency_ms":null,"details":{"risk_hits":[],"safe_hits":[],"oauth_supported":false,"prompt_available":true}},"action_safety_probe":{"status":"error","latency_ms":null,"details":{"summary":{"tool_count":10,"high_risk_tools":6,"destructive_tools":1,"exec_tools":6,"egress_tools":0,"secret_tools":0,"bulk_access_tools":6,"risk_distribution":{"low":2,"medium":2,"high":5,"critical":1},"capability_distribution":{"read":10,"write":2,"exec":6,"network":6,"filesystem":4,"export":6,"delete":1,"admin":2}},"auth_present":false,"safeguard_count":0,"confirmation_signals":[]}},"official_registry_probe":{"status":"ok","latency_ms":null,"details":{"registry_source":"official_registry","registry_identifier":"ai.analyticslegends/sap-analytics","direct_match":true,"official_peer_count":1}},"provenance_divergence_probe":{"status":"ok","latency_ms":null,"details":{"direct_official_match":true,"registry_title":null,"server_card_title":null,"registry_version":null,"server_card_version":null,"registry_homepage":null,"server_card_homepage":null,"registry_repository":null,"server_card_repository":null,"drift_fields":[],"metadata_document_count":2}},"connector_publishability_probe":{"status":"warning","latency_ms":null,"details":{"transport":"streamable-http","tool_count":10,"high_risk_tools":6,"blockers":["action_safety","server_card"],"criteria":{"remote_transport":true,"initialize":true,"tools_list":true,"protocol_version":true,"session_resume":true,"step_up_auth":true,"transport_compliance":true,"connector_replay":true,"request_association":true,"action_safety":false,"server_card":false,"tool_surface":true,"auth_flow":true}}}},"score_components":{"auth_operability_score":2.0,"error_contract_score":0.0,"rate_limit_semantics_score":2.0,"schema_completeness_score":3.0,"backward_compatibility_score":2.0,"slo_health_score":3.0,"security_hygiene_score":3.0,"task_success_score":4.0,"trust_confidence_score":1.75,"abuse_noise_ratio_score":4.0,"prompt_contract_score":3.0,"resource_contract_score":4.0,"discovery_metadata_score":4.0,"registry_consistency_score":2.0,"installability_score":4.0,"session_semantics_score":3.0,"tool_surface_design_score":4.0,"result_shape_stability_score":3.0,"oauth_interop_score":3.0,"recovery_semantics_score":0.0,"maintenance_signal_score":3.0,"adoption_signal_score":3.0,"freshness_confidence_score":3.0,"transport_fidelity_score":4.0,"spec_recency_score":2.0,"session_resume_score":3.0,"step_up_auth_score":3.0,"transport_compliance_score":2.0,"utility_coverage_score":2.0,"advanced_capability_coverage_score":3.0,"connector_publishability_score":3.0,"tool_snapshot_churn_score":3.0,"connector_replay_score":3.0,"request_association_score":3.0,"interactive_flow_safety_score":3.0,"action_safety_score":2.0,"official_registry_presence_score":4.0,"provenance_divergence_score":4.0,"safety_transparency_score":2.0,"tool_capability_clarity_score":4.0,"destructive_operation_safety_score":2.0,"egress_ssrf_resilience_score":3.0,"execution_sandbox_safety_score":0.0,"data_exfiltration_resilience_score":3.0,"least_privilege_scope_score":2.0,"secret_handling_hygiene_score":3.0,"dependency_supply_chain_signal_score":2.5,"input_sanitization_safety_score":3.0,"tool_namespace_clarity_score":4.0},"validation_schema_version":"16d1d270090d6c8f","started_at":"2026-07-31T05:33:52.908916+00:00","completed_at":"2026-07-31T05:33:58.077161+00:00"},"current_snapshot":{"schema_version":"verify.trust_snapshot.v1","snapshot_id":"trustsnap_9a27dfe9b7af5257","generated_at":"2026-07-31T10:27:42.105299+00:00","source":"current_snapshot","server":"ai.analyticslegends/sap-analytics","last_validated_at":"2026-07-31T05:33:58.077161+00:00","validation_age_hours":4.9,"freshness":{"schema_version":"verify.freshness_profile.v1","last_validated_at":"2026-07-31T05:33:58.077161+00:00","age_hours":4.9,"bucket":"verified_last_24h","label":"Verified in last 24h","badges":["verified_last_24h"],"freshness_sla_hours":168.0,"freshness_sla_status":"met","stale_score_suppressed":false,"display_score":69.52,"raw_score":69.52,"confidence_score":76.2,"confidence_weighted_score":53.0,"tier_status":[{"tier":"community","label":"Community","freshness_sla_hours":720,"met":true,"priority_revalidation":false},{"tier":"pro","label":"Pro","freshness_sla_hours":168,"met":true,"priority_revalidation":true},{"tier":"enterprise","label":"Enterprise","freshness_sla_hours":24,"met":true,"priority_revalidation":true}]},"current_status":"healthy","current_score":69.52,"display_score":69.52,"stale_score_suppressed":false,"production_trust_decision":{"schema_version":"verify.executive_verdict.v1","decision":"Allow with approval","why":"exec-capable tools + no confirmation safeguards + high-risk tools need review","next_action":"export policy, require approval for writes, add authenticated validation","reason_count":2},"production_readiness_class":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use."},"evidence_confidence":{"score":76.25,"label":"high","validation_age_hours":4.9,"live_check_count":26},"active_alerts":[]},"trust_snapshot":{"schema_version":"verify.trust_snapshot.v1","snapshot_id":"trustsnap_9a27dfe9b7af5257","generated_at":"2026-07-31T10:27:42.105299+00:00","source":"current_snapshot","server":"ai.analyticslegends/sap-analytics","last_validated_at":"2026-07-31T05:33:58.077161+00:00","validation_age_hours":4.9,"freshness":{"schema_version":"verify.freshness_profile.v1","last_validated_at":"2026-07-31T05:33:58.077161+00:00","age_hours":4.9,"bucket":"verified_last_24h","label":"Verified in last 24h","badges":["verified_last_24h"],"freshness_sla_hours":168.0,"freshness_sla_status":"met","stale_score_suppressed":false,"display_score":69.52,"raw_score":69.52,"confidence_score":76.2,"confidence_weighted_score":53.0,"tier_status":[{"tier":"community","label":"Community","freshness_sla_hours":720,"met":true,"priority_revalidation":false},{"tier":"pro","label":"Pro","freshness_sla_hours":168,"met":true,"priority_revalidation":true},{"tier":"enterprise","label":"Enterprise","freshness_sla_hours":24,"met":true,"priority_revalidation":true}]},"current_status":"healthy","current_score":69.52,"display_score":69.52,"stale_score_suppressed":false,"production_trust_decision":{"schema_version":"verify.executive_verdict.v1","decision":"Allow with approval","why":"exec-capable tools + no confirmation safeguards + high-risk tools need review","next_action":"export policy, require approval for writes, add authenticated validation","reason_count":2},"production_readiness_class":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use."},"evidence_confidence":{"score":76.25,"label":"high","validation_age_hours":4.9,"live_check_count":26},"active_alerts":[]},"snapshot_invariant":{"schema_version":"verify.snapshot_invariant.v1","server":"ai.analyticslegends/sap-analytics","ok":true,"surface_snapshot_ids":{"page":"trustsnap_9a27dfe9b7af5257","badge":null,"report":"trustsnap_9a27dfe9b7af5257","policy":null},"checked_at":"2026-07-31T10:27:42.345060+00:00"},"history":{"points":[{"timestamp":"2026-07-31T05:33:58.077161+00:00","score":69.52,"status":"healthy","latency_ms":5167.1,"tool_count":10,"prompt_count":2,"resource_count":3}],"status_counts":{"healthy":1},"score_delta_7d":null,"score_delta_30d":null,"avg_latency_ms":5167.1,"healthy_ratio_recent":1.0,"freshness_hours":4.9,"latest_status":"healthy"},"production_readiness":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use.","badge":"score-medium","critical_alerts":0},"agent_commerce_readiness":{"status":"beta","commerce_signal":"moderate","payment_execution_detected":"no","billing_or_usage_detected":"no","quote_or_pricing_detected":"yes","numeric_price_context":"yes","commercial_quote_context":"yes","checkout_or_charge_detected":"no","checkout_term_observed":"no","payment_capable":"inferred","payment_rails":["Stripe","card"],"purchase_stage_supported":[],"human_confirmation_required":"yes","spending_policy_supported":"yes","receipt_supported":"unknown","refund_policy_present":"unknown","operator_identity":"declared","auth_required":"no","auth_scheme":"none","tool_risk_level":"administrative","tool_risk_score":70,"pricing_transparency":"clear","schema_change_detected":"unknown","delegation_level":"research_only","evidence_level":"inferred","confidence":"medium","highest_risk_tools":[{"name":"search_firms","risk_level":"private_data"},{"name":"search_news","risk_level":"private_data"},{"name":"list_sap_modules","risk_level":"administrative"}],"skipped_unsafe_tools":["get_concept","list_sap_modules"],"last_checked_at":"2026-07-31T10:27:42.086822+00:00","evidence":[{"field":"commerce_signal","value":"moderate","evidence_level":"observed","source":"tool_schema","matched_terms":["limit","currency","quote","rate","card"],"sample":"search_firms","confidence":"medium","last_checked_at":"2026-07-31T10:27:42.086822+00:00"},{"field":"payment_rails","value":"Stripe, card","evidence_level":"inferred","source":"tool_schema","matched_terms":["stripe","card"],"sample":"Stripe, card","confidence":"medium","last_checked_at":"2026-07-31T10:27:42.086822+00:00"}],"disclaimer":"Beta assessment. Verify detects evidence and risk signals but does not certify that this server is safe for autonomous purchases.","scores":{"auth_posture_score":20,"tool_risk_score":70,"payment_readiness_score":70,"agent_delegation_safety_score":30,"overall_agent_commerce_score":39},"warnings":["Verify observed commerce-adjacent billing, usage, or pricing context, but did not observe a tool that can execute payment."],"recommended_fixes":["Clarify whether observed billing, usage, or pricing context can execute payment or is informational only."]},"evidence_confidence":{"score":76.25,"label":"high","reason":"Based on 1 recent validations, 26 captured checks, and validation age of 4.9 hours.","live_check_count":26,"validation_age_hours":4.9},"recommended_for":[{"label":"Claude Desktop","reason":"Claude Desktop is marked compatible with score 100."},{"label":"Smithery","reason":"Smithery is marked compatible with score 80."},{"label":"Generic Streamable HTTP","reason":"Generic Streamable HTTP is marked compatible with score 100."}],"active_alerts":[],"remediations":[{"code":"add_confirmation_semantics","severity":"high","title":"Add confirmation and dry-run semantics for risky actions","why":"High-risk write, delete, exec, or egress tools should communicate safeguards clearly.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"fix_transport_compliance","severity":"high","title":"Align session and protocol behavior with Streamable HTTP expectations","why":"Clients increasingly rely on MCP-Protocol-Version, session teardown, and expired-session semantics.","action":"Align MCP-Protocol-Version, MCP-Session-Id, DELETE teardown, and expired-session handling with the transport spec.","playbook":["Return `Mcp-Session-Id` and `Mcp-Protocol-Version` headers consistently on streamable HTTP responses.","Honor `DELETE` session teardown and return `404` when a deleted session is reused.","Reject invalid protocol-version headers with `400 Bad Request`."],"maintainer_context":null},{"code":"enforce_request_association","severity":"high","title":"Associate roots, sampling, and elicitation with active client requests","why":"Modern MCP guidance expects roots, sampling, and elicitation traffic to be tied to an active client request instead of arriving unsolicited on idle sessions.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"publish_oauth_protected_resource","severity":"high","title":"Expose /.well-known/oauth-protected-resource","why":"Without a protected-resource document, OAuth clients cannot discover auth requirements reliably.","action":"Serve /.well-known/oauth-protected-resource and point it at your authorization server metadata.","playbook":["Serve `/.well-known/oauth-protected-resource` from the same host as the MCP endpoint.","Point it at the authorization server metadata URL.","Confirm clients receive consistent auth hints before tool execution."],"maintainer_context":null},{"code":"protect_connector_refreshes","severity":"high","title":"Keep connector refreshes backward compatible","why":"Managed connector clients freeze tool snapshots, so removed tools, new required args, and breaking output changes can break published integrations after refresh.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"publish_oauth_authorization_server","severity":"high","title":"Publish OAuth authorization-server metadata","why":"Clients need authorization-server metadata to discover issuer, endpoints, and DCR support.","action":"Publish /.well-known/oauth-authorization-server from your issuer and include registration_endpoint when supported.","playbook":["Publish `/.well-known/oauth-authorization-server` from the issuer.","Add `registration_endpoint` if DCR is supported.","Verify issuer, authorization, token, and jwks metadata are all reachable."],"maintainer_context":null},{"code":"publish_server_card","severity":"high","title":"Publish a complete server card","why":"Missing or incomplete server-card metadata weakens discovery, documentation, and trust signals.","action":"Serve /.well-known/mcp/server-card.json and include tools, prompts/resources, homepage, and support links.","playbook":["Publish `/.well-known/mcp/server-card.json`.","Include homepage, repository, support, tools, prompts/resources, and auth metadata.","Revalidate the server after publishing the card."],"maintainer_context":null},{"code":"harden_interactive_flows","severity":"high","title":"Stop asking users to paste secrets directly","why":"Public MCP servers should prefer OAuth or browser-based auth guidance over in-band secret collection.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"update_protocol_version","severity":"medium","title":"Adopt a current MCP protocol revision","why":"Older protocol revisions reduce compatibility with newer clients and registry programs.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"improve_connector_publishability","severity":"medium","title":"Close connector-publishing gaps","why":"Connector catalogs care about protocol recency, session behavior, auth clarity, and tool-surface stability.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"tighten_step_up_auth","severity":"medium","title":"Document minimal scopes and return cleaner auth challenges","why":"Modern clients expect granular scopes and step-up auth signals such as WWW-Authenticate scope hints.","action":"Return granular scopes and WWW-Authenticate challenge hints instead of forcing overly broad auth upfront.","playbook":["Advertise the narrowest viable scopes in OAuth metadata.","Return `WWW-Authenticate` challenges with scope or insufficient-scope hints when additional consent is needed.","Revalidate with both public discovery and auth-required flows."],"maintainer_context":null},{"code":"publish_openid_configuration","severity":"medium","title":"Publish OpenID configuration","why":"OIDC metadata improves token validation and client compatibility.","action":"Expose /.well-known/openid-configuration with issuer, jwks_uri, and supported grants.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"stabilize_tool_surface","severity":"medium","title":"Reduce tool-surface churn","why":"Frequent add/remove or output-shape drift makes published connectors and cached tool snapshots brittle.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"repair_session_resume","severity":"medium","title":"Support resumable HTTP sessions cleanly","why":"Modern MCP clients increasingly expect resumable session behavior on streamable HTTP transports.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"expand_utility_coverage","severity":"low","title":"Expose modern utility surfaces like completions, pagination, or tasks","why":"Utility coverage improves interoperability with larger clients and long-lived agent workflows.","action":"Expose completions, pagination, and task metadata where supported so larger clients can plan and resume work safely.","playbook":["Advertise `completions`, pagination cursors, and `tasks` only when they are actually supported.","Return `nextCursor` on large list operations when pagination is available.","Document task support and whether it requires step-up auth."],"maintainer_context":null}],"publisher_claim":{"verified":false,"status":"unclaimed","claim_url":"https://verify.sentinelsignal.io/claim?server=ai.analyticslegends%2Fsap-analytics&source=report_json","reason_code":"machine_attention_detected","reason":"Agents and crawlers are already evaluating this server. Claim to publish authoritative owner, security, trust, and integration metadata.","score_neutral":true},"observed_attention":{"schema":"verify.observed_attention.v1","window_days":30,"level":"moderate","label":"Moderate observed attention","summary":"Recent machine-readable trust and discovery activity observed for this server.","segments":{"useful_ai_user":{"level":"none","observed":false,"description":"AI-assisted user sessions such as ChatGPT/User or Claude/User."},"machine_trust_evaluator":{"level":"low","observed":true,"description":"Synthetic sessions inspecting multiple trust surfaces such as report, policy, ledger, badge, trust-summary, or compare."},"possible_agent_or_script":{"level":"low","observed":true,"description":"Structured direct sessions with rapid profile, compare, report, policy, badge, or trust-surface fan-out."},"isolated_machine_surface":{"level":"none","observed":false,"description":"Aged-out direct synthetic singleton sessions that touched a machine-readable trust surface without becoming a broader evaluator."},"ai_crawler":{"level":"moderate","observed":true,"description":"Known AI crawler activity such as ClaudeBot, GPTBot, or similar crawlers."},"search_crawler":{"level":"none","observed":false,"description":"Search and SEO crawler activity."},"browser_like_automation":{"level":"none","observed":false,"description":"Browser-like synthetic sessions with rapid structured endpoint activity."},"confirmed_human":{"level":"none","observed":false,"description":"Confirmed browser-session human activity."}},"surfaces_observed":{"server_profile":true,"compare":true,"compare_json":false,"compare_api":true,"report_json":true,"policy":true,"ledger":false,"badge_metadata":true,"badge_svg":false,"trust_summary":true,"mcp_tool":false},"claim_prompt":{"recommended":true,"reason":"This server has recent machine attention. A verified publisher claim can improve owner, policy, security, and trust metadata available to agents."},"notes":["Observed attention is based on segmented first-party telemetry.","Crawler and evaluator activity is not treated as confirmed human demand.","Public levels are bucketed to avoid exposing raw traffic counts."]},"owner_activation":{"claim_recommended":true,"reason":"ai_discovery_detected","headline":"AI discovery detected","message":"This server is being discovered by AI users, crawlers, or machine trust evaluators on Verify. Claim this profile to add publisher metadata, official links, a security contact, and machine-readable trust details agents can use.","claim_url":"https://verify.sentinelsignal.io/claim?server=ai.analyticslegends%2Fsap-analytics&source=report_json","trust_summary_url":"https://verify.sentinelsignal.io/v1/servers/ai.analyticslegends/sap-analytics/trust-summary"},"related_machine_surfaces":{"compare_index":"/compare.json","compare_api":"/v1/compare?server=ai.analyticslegends%2Fsap-analytics","trust_summary":"/v1/servers/ai.analyticslegends/sap-analytics/trust-summary","ledger":"/v1/servers/ai.analyticslegends/sap-analytics/ledger","policy":"/v1/servers/ai.analyticslegends/sap-analytics/policy","report":"/v1/servers/ai.analyticslegends/sap-analytics/report"},"intelligence_api":{"available":true,"signup_url":"https://verify.sentinelsignal.io/verify-intelligence-api","use_case":"Programmatic MCP server trust, comparison, policy, and evidence enrichment."}}