{"schema_version":"verify.report.v1","generated_at":"2026-07-31T11:03:18.060806+00:00","snapshot_id":"trustsnap_2242750e6ecf837e","server":{"namespace":"ai.boolsai","name":"directory","title":"Boolsai Directory","description":"Indexed ecommerce site directory — vendor lookups, brands by city/market/founder. 10 tools.","homepage_url":null,"docs_url":null,"icon_url":null,"support_url":null,"remote_url":"https://directory.boolsai.ai/mcp","server_card_url":null,"latest_version":"1.0.0","current_status":"healthy","current_score":67.57,"transport_type":"streamable-http","has_oauth":false,"has_dcr":false,"has_prompts":false,"tool_count":19,"current_validation_schema_version":"16d1d270090d6c8f","last_validated_at":"2026-07-31T05:35:59.278239+00:00","registry_source":"official_registry","registry_identifier":"ai.boolsai/directory","canonical_identifier":"ai.boolsai/directory","current_score_components":{"auth_operability_score":2.0,"error_contract_score":2.83,"rate_limit_semantics_score":2.0,"schema_completeness_score":2.0,"backward_compatibility_score":2.0,"slo_health_score":4.0,"security_hygiene_score":2.5,"task_success_score":4.0,"trust_confidence_score":1.75,"abuse_noise_ratio_score":4.0,"prompt_contract_score":2.0,"resource_contract_score":2.0,"discovery_metadata_score":3.0,"registry_consistency_score":2.0,"installability_score":4.0,"session_semantics_score":4.0,"tool_surface_design_score":3.0,"result_shape_stability_score":2.0,"oauth_interop_score":3.0,"recovery_semantics_score":0.0,"maintenance_signal_score":3.0,"adoption_signal_score":2.0,"freshness_confidence_score":3.0,"transport_fidelity_score":4.0,"spec_recency_score":2.0,"session_resume_score":3.0,"step_up_auth_score":3.0,"transport_compliance_score":0.0,"utility_coverage_score":2.0,"advanced_capability_coverage_score":2.0,"connector_publishability_score":3.0,"tool_snapshot_churn_score":3.0,"connector_replay_score":3.0,"request_association_score":3.0,"interactive_flow_safety_score":4.0,"action_safety_score":2.0,"official_registry_presence_score":4.0,"provenance_divergence_score":4.0,"safety_transparency_score":4.0,"tool_capability_clarity_score":4.0,"destructive_operation_safety_score":2.0,"egress_ssrf_resilience_score":2.0,"execution_sandbox_safety_score":0.5,"data_exfiltration_resilience_score":3.35,"least_privilege_scope_score":2.0,"secret_handling_hygiene_score":3.0,"dependency_supply_chain_signal_score":2.5,"input_sanitization_safety_score":3.0,"tool_namespace_clarity_score":4.0},"capability_taxonomy":["development","database","search","communication","filesystem","secrets","read","exec","network","finance","write","admin","productivity","web","automation","export","delete","cloud","security","monitoring","streamable_http"],"machine_summary":{"verdict":"safe_for_evaluation","best_for":["Claude Desktop","Smithery","Generic Streamable HTTP"],"avoid_if":["You need a low-risk tool surface."],"requires_auth":false,"supports_oauth":false,"risk_level":"critical"},"taxonomy_tags":["development","database","search","communication"],"score_decomposition":[{"key":"access_protocol","label":"Access & Protocol","score":30.0,"max_score":44.0,"hint":"Connectivity, auth, and transport expectations for common clients.","components":[{"key":"auth_operability_score","score":2.0},{"key":"installability_score","score":4.0},{"key":"session_semantics_score","score":4.0},{"key":"transport_fidelity_score","score":4.0},{"key":"spec_recency_score","score":2.0},{"key":"session_resume_score","score":3.0},{"key":"step_up_auth_score","score":3.0},{"key":"transport_compliance_score","score":0.0},{"key":"request_association_score","score":3.0},{"key":"oauth_interop_score","score":3.0},{"key":"least_privilege_scope_score","score":2.0}]},{"key":"interface_quality","label":"Interface Quality","score":33.83,"max_score":56.0,"hint":"How well the tool/resource interface communicates and behaves under automation.","components":[{"key":"error_contract_score","score":2.83},{"key":"rate_limit_semantics_score","score":2.0},{"key":"schema_completeness_score","score":2.0},{"key":"prompt_contract_score","score":2.0},{"key":"resource_contract_score","score":2.0},{"key":"tool_surface_design_score","score":3.0},{"key":"tool_capability_clarity_score","score":4.0},{"key":"tool_namespace_clarity_score","score":4.0},{"key":"result_shape_stability_score","score":2.0},{"key":"utility_coverage_score","score":2.0},{"key":"advanced_capability_coverage_score","score":2.0},{"key":"tool_snapshot_churn_score","score":3.0},{"key":"connector_replay_score","score":3.0},{"key":"recovery_semantics_score","score":0.0}]},{"key":"security_posture","label":"Security Posture","score":22.35,"max_score":36.0,"hint":"How safely the exposed tool surface handles destructive actions, egress, execution, secrets, and risky inputs.","components":[{"key":"security_hygiene_score","score":2.5},{"key":"destructive_operation_safety_score","score":2.0},{"key":"egress_ssrf_resilience_score","score":2.0},{"key":"execution_sandbox_safety_score","score":0.5},{"key":"data_exfiltration_resilience_score","score":3.35},{"key":"secret_handling_hygiene_score","score":3.0},{"key":"input_sanitization_safety_score","score":3.0},{"key":"interactive_flow_safety_score","score":4.0},{"key":"action_safety_score","score":2.0}]},{"key":"reliability_trust","label":"Reliability & Trust","score":18.75,"max_score":24.0,"hint":"Operational stability, consistency, and trustworthiness over time.","components":[{"key":"backward_compatibility_score","score":2.0},{"key":"slo_health_score","score":4.0},{"key":"task_success_score","score":4.0},{"key":"trust_confidence_score","score":1.75},{"key":"abuse_noise_ratio_score","score":4.0},{"key":"freshness_confidence_score","score":3.0}]},{"key":"discovery_governance","label":"Discovery & Governance","score":22.5,"max_score":28.0,"hint":"How well the server is documented, listed, and governed in public registries.","components":[{"key":"discovery_metadata_score","score":3.0},{"key":"registry_consistency_score","score":2.0},{"key":"maintenance_signal_score","score":3.0},{"key":"safety_transparency_score","score":4.0},{"key":"dependency_supply_chain_signal_score","score":2.5},{"key":"official_registry_presence_score","score":4.0},{"key":"provenance_divergence_score","score":4.0}]},{"key":"adoption_market","label":"Adoption & Market","score":5.0,"max_score":8.0,"hint":"Adoption clues and public evidence that the server is intended for external use.","components":[{"key":"adoption_signal_score","score":2.0},{"key":"connector_publishability_score","score":3.0}]}],"validation_diff":null,"tool_snapshot_diff":null,"connector_replay":{"status":"missing","backward_compatible":false,"would_break_after_refresh":false,"added_tools":[],"removed_tools":[],"required_arg_breaks":[],"output_breaks":[],"additive_output_changes":[]},"request_association":{"status":"missing","advertised_capabilities":[],"session_id_present":false,"protocol_version":null,"observed_methods":[],"violating_methods":[],"http_status":null,"issues":[]},"production_readiness":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use.","badge":"score-medium","critical_alerts":0},"recommended_for":[{"label":"Claude Desktop","reason":"Claude Desktop is marked compatible with score 83."},{"label":"Smithery","reason":"Smithery is marked compatible with score 100."},{"label":"Generic Streamable HTTP","reason":"Generic Streamable HTTP is marked compatible with score 100."}],"history_summary":{"points":[{"timestamp":"2026-07-31T05:35:59.278239+00:00","score":67.57,"status":"healthy","latency_ms":490.77,"tool_count":19,"prompt_count":0,"resource_count":0}],"status_counts":{"healthy":1},"score_delta_7d":null,"score_delta_30d":null,"avg_latency_ms":490.77,"healthy_ratio_recent":1.0,"freshness_hours":5.46,"latest_status":"healthy"},"validation_timeline":[{"timestamp":"2026-07-31T05:35:59.278239+00:00","summary_status":"healthy","score":67.57,"protocol_version":"2025-03-26","auth_mode":"public","tool_count":19,"prompt_count":0,"resource_count":0,"high_risk_tools":9,"safe_to_publish":false,"change_flags":[]}],"evidence_confidence":{"score":76.25,"label":"high","reason":"Based on 1 recent validations, 26 captured checks, and validation age of 5.5 hours.","live_check_count":26,"validation_age_hours":5.46},"incident_feed":[{"type":"validation_snapshot","timestamp":"2026-07-31T05:35:59.278239+00:00","title":"Latest validation: healthy","message":"Score 67.6 with status healthy."}],"remediations":[{"code":"add_confirmation_semantics","severity":"high","title":"Add confirmation and dry-run semantics for risky actions","why":"High-risk write, delete, exec, or egress tools should communicate safeguards clearly.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"fix_transport_compliance","severity":"high","title":"Align session and protocol behavior with Streamable HTTP expectations","why":"Clients increasingly rely on MCP-Protocol-Version, session teardown, and expired-session semantics.","action":"Align MCP-Protocol-Version, MCP-Session-Id, DELETE teardown, and expired-session handling with the transport spec.","playbook":["Return `Mcp-Session-Id` and `Mcp-Protocol-Version` headers consistently on streamable HTTP responses.","Honor `DELETE` session teardown and return `404` when a deleted session is reused.","Reject invalid protocol-version headers with `400 Bad Request`."],"maintainer_context":null},{"code":"enforce_request_association","severity":"high","title":"Associate roots, sampling, and elicitation with active client requests","why":"Modern MCP guidance expects roots, sampling, and elicitation traffic to be tied to an active client request instead of arriving unsolicited on idle sessions.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"publish_oauth_protected_resource","severity":"high","title":"Expose /.well-known/oauth-protected-resource","why":"Without a protected-resource document, OAuth clients cannot discover auth requirements reliably.","action":"Serve /.well-known/oauth-protected-resource and point it at your authorization server metadata.","playbook":["Serve `/.well-known/oauth-protected-resource` from the same host as the MCP endpoint.","Point it at the authorization server metadata URL.","Confirm clients receive consistent auth hints before tool execution."],"maintainer_context":null},{"code":"protect_connector_refreshes","severity":"high","title":"Keep connector refreshes backward compatible","why":"Managed connector clients freeze tool snapshots, so removed tools, new required args, and breaking output changes can break published integrations after refresh.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"publish_oauth_authorization_server","severity":"high","title":"Publish OAuth authorization-server metadata","why":"Clients need authorization-server metadata to discover issuer, endpoints, and DCR support.","action":"Publish /.well-known/oauth-authorization-server from your issuer and include registration_endpoint when supported.","playbook":["Publish `/.well-known/oauth-authorization-server` from the issuer.","Add `registration_endpoint` if DCR is supported.","Verify issuer, authorization, token, and jwks metadata are all reachable."],"maintainer_context":null},{"code":"publish_server_card","severity":"high","title":"Publish a complete server card","why":"Missing or incomplete server-card metadata weakens discovery, documentation, and trust signals.","action":"Serve /.well-known/mcp/server-card.json and include tools, prompts/resources, homepage, and support links.","playbook":["Publish `/.well-known/mcp/server-card.json`.","Include homepage, repository, support, tools, prompts/resources, and auth metadata.","Revalidate the server after publishing the card."],"maintainer_context":null},{"code":"update_protocol_version","severity":"medium","title":"Adopt a current MCP protocol revision","why":"Older protocol revisions reduce compatibility with newer clients and registry programs.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"improve_connector_publishability","severity":"medium","title":"Close connector-publishing gaps","why":"Connector catalogs care about protocol recency, session behavior, auth clarity, and tool-surface stability.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"tighten_step_up_auth","severity":"medium","title":"Document minimal scopes and return cleaner auth challenges","why":"Modern clients expect granular scopes and step-up auth signals such as WWW-Authenticate scope hints.","action":"Return granular scopes and WWW-Authenticate challenge hints instead of forcing overly broad auth upfront.","playbook":["Advertise the narrowest viable scopes in OAuth metadata.","Return `WWW-Authenticate` challenges with scope or insufficient-scope hints when additional consent is needed.","Revalidate with both public discovery and auth-required flows."],"maintainer_context":null},{"code":"publish_openid_configuration","severity":"medium","title":"Publish OpenID configuration","why":"OIDC metadata improves token validation and client compatibility.","action":"Expose /.well-known/openid-configuration with issuer, jwks_uri, and supported grants.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"stabilize_tool_surface","severity":"medium","title":"Reduce tool-surface churn","why":"Frequent add/remove or output-shape drift makes published connectors and cached tool snapshots brittle.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"fix_prompts_list","severity":"medium","title":"Repair prompts/list or stop advertising prompts","why":"Prompt metadata should either work live or be removed from the advertised capability set.","action":"Only advertise prompts if prompts/list works and prompt arguments are documented.","playbook":["Only advertise prompts that are actually accessible.","Add prompt descriptions and argument docs.","Run a live `prompts/list` check after any prompt changes."],"maintainer_context":null},{"code":"fix_resources_list","severity":"medium","title":"Repair resources/list or stop advertising resources","why":"Resource metadata should either work live or be removed from the advertised capability set.","action":"Only advertise resources if resources/list works and resources expose stable URIs/types.","playbook":["Only advertise resources with stable URIs and read semantics.","Add MIME/type hints where possible.","Run a live `resources/list` and `resources/read` check after updates."],"maintainer_context":null},{"code":"repair_session_resume","severity":"medium","title":"Support resumable HTTP sessions cleanly","why":"Modern MCP clients increasingly expect resumable session behavior on streamable HTTP transports.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"expand_utility_coverage","severity":"low","title":"Expose modern utility surfaces like completions, pagination, or tasks","why":"Utility coverage improves interoperability with larger clients and long-lived agent workflows.","action":"Expose completions, pagination, and task metadata where supported so larger clients can plan and resume work safely.","playbook":["Advertise `completions`, pagination cursors, and `tasks` only when they are actually supported.","Return `nextCursor` on large list operations when pagination is available.","Document task support and whether it requires step-up auth."],"maintainer_context":null},{"code":"expand_advanced_capabilities","severity":"low","title":"Publish newer MCP capability signals","why":"Roots, sampling, elicitation, structured outputs, and related metadata improve client understanding and ranking.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null}],"client_remediation_modes":[{"key":"openai_connectors","label":"ChatGPT custom connector","status":"partial","why_not_ready":[{"label":"OpenAI connectors expect OAuth for remote server auth.","state":"blocked"},{"label":"Dynamic client registration materially improves connector setup.","state":"blocked"},{"label":"Transport compliance should be in good shape.","state":"blocked"},{"label":"search fetch only is not yet satisfied","state":"blocked"},{"label":"oauth configured is not yet satisfied","state":"blocked"},{"label":"admin refresh required is not yet satisfied","state":"blocked"}],"maintainer_context":null},{"key":"claude_desktop","label":"Claude remote MCP","status":"ready","why_not_ready":[{"label":"Transport behavior should match Claude-compatible HTTP expectations.","state":"blocked"},{"label":"search fetch only is not yet satisfied","state":"blocked"},{"label":"oauth configured is not yet satisfied","state":"blocked"},{"label":"admin refresh required is not yet satisfied","state":"blocked"},{"label":"safe for company knowledge is not yet satisfied","state":"blocked"},{"label":"safe for messages api remote mcp is not yet satisfied","state":"blocked"}],"maintainer_context":null},{"key":"write_safe","label":"Write-safe publishing","status":"blocked","why_not_ready":[{"label":"Add a clearer auth boundary around risky write actions.","state":"blocked"},{"label":"Add confirmation or dry-run semantics for risky actions.","state":"blocked"},{"label":"Constrain or sandbox exec-capable tools before publishing broadly.","state":"blocked"}],"maintainer_context":null}],"client_profiles":[{"key":"openai_connectors","label":"OpenAI Connectors","score":66.7,"compatibility":"partial","missing_requirements":["OpenAI connectors expect OAuth for remote server auth.","Dynamic client registration materially improves connector setup.","Transport compliance should be in good shape."],"snippet":"Connector URL: https://directory.boolsai.ai/mcp\n# No OAuth metadata detected.\n# Server: ai.boolsai/directory"},{"key":"claude_desktop","label":"Claude Desktop","score":83.3,"compatibility":"compatible","missing_requirements":["Transport behavior should match Claude-compatible HTTP expectations."],"snippet":"{\n  \"mcpServers\": {\n    \"directory\": {\n      \"command\": \"npx\",\n      \"args\": [\"mcp-remote\", \"https://directory.boolsai.ai/mcp\"]\n    }\n  }\n}"},{"key":"smithery","label":"Smithery","score":100.0,"compatibility":"compatible","missing_requirements":[],"snippet":"smithery mcp add \"https://directory.boolsai.ai/mcp\""},{"key":"generic_streamable_http","label":"Generic Streamable HTTP","score":100.0,"compatibility":"compatible","missing_requirements":[],"snippet":"curl -sS https://directory.boolsai.ai/mcp -H 'content-type: application/json' -d '{\"jsonrpc\":\"2.0\",\"id\":1,\"method\":\"initialize\",\"params\":{\"protocolVersion\":\"2025-03-26\",\"capabilities\":{},\"clientInfo\":{\"name\":\"mcp-verify\",\"version\":\"0.1.0\"}}}'"}],"client_readiness_verdicts":[{"key":"openai_connectors","label":"Client compatibility: ChatGPT","status":"partial","reason":"OpenAI connectors expect OAuth for remote server auth.; Dynamic client registration materially improves connector setup.; Transport compliance should be in good shape.","evidence":[{"check":"initialize","status":"ok","source":"live_validation","note":null,"http_status":200},{"check":"tools_list","status":"ok","source":"live_validation","note":null,"http_status":200},{"check":"transport_compliance_probe","status":"error","source":"live_validation","note":null,"http_status":null},{"check":"step_up_auth_probe","status":"missing","source":"live_validation","note":null,"http_status":null},{"check":"connector_replay_probe","status":"missing","source":"live_validation","note":"Frozen tool snapshots must survive refresh.","http_status":null},{"check":"request_association_probe","status":"missing","source":"live_validation","note":"Roots, sampling, and elicitation should stay request-scoped.","http_status":null}],"confidence":{"score":76.25,"label":"high"},"source_resolution":{"winner":"live_validation","supporting_sources":["live_validation","history","server_card"],"disagreements":[]}},{"key":"claude_desktop","label":"Client compatibility: Claude","status":"ready","reason":"Transport behavior should match Claude-compatible HTTP expectations.","evidence":[{"check":"initialize","status":"ok","source":"live_validation","note":null,"http_status":200},{"check":"tools_list","status":"ok","source":"live_validation","note":null,"http_status":200},{"check":"transport_compliance_probe","status":"error","source":"live_validation","note":null,"http_status":null}],"confidence":{"score":76.25,"label":"high"},"source_resolution":{"winner":"live_validation","supporting_sources":["live_validation","history","server_card"],"disagreements":[]}},{"key":"unsafe_for_write_actions","label":"Write-action publishing","status":"yes","reason":"Blocked until safeguards and confirmation semantics are verified for write, exec, or destructive tools.","evidence":[{"check":"action_safety_probe","status":"error","source":"live_validation","note":null,"http_status":null}],"confidence":{"score":76.25,"label":"high"},"source_resolution":{"winner":"live_validation","supporting_sources":["live_validation","history"],"disagreements":[]}},{"key":"snapshot_churn_risk","label":"Snapshot churn risk","status":"low","reason":"No material tool-surface churn detected in the latest comparison.","evidence":[{"check":"tool_snapshot_probe","status":"missing","source":"live_validation","note":null,"http_status":null},{"check":"connector_replay_probe","status":"missing","source":"live_validation","note":null,"http_status":null}],"confidence":{"score":76.25,"label":"high"},"source_resolution":{"winner":"history","supporting_sources":["history","live_validation"],"disagreements":[]}}],"publishability_policy_profiles":[{"key":"chatgpt_custom_connector","label":"ChatGPT custom connector compatibility","status":"caution","gates":{"search_fetch_only":false,"write_actions_present":true,"oauth_configured":false,"admin_refresh_required":false,"safe_for_company_knowledge":false,"safe_for_messages_api_remote_mcp":false},"reason":"OpenAI connectors expect OAuth for remote server auth.; Dynamic client registration materially improves connector setup.; Transport compliance should be in good shape."},{"key":"claude_remote_mcp","label":"Claude remote MCP compatibility","status":"ready","gates":{"search_fetch_only":false,"write_actions_present":true,"oauth_configured":false,"admin_refresh_required":false,"safe_for_company_knowledge":false,"safe_for_messages_api_remote_mcp":false},"reason":"Transport behavior should match Claude-compatible HTTP expectations."}],"compatibility_fixtures":[{"key":"chatgpt_custom_connector","label":"ChatGPT custom connector fixture","status":"degraded","assumptions":[{"name":"remote_http_endpoint","status":"passes"},{"name":"oauth_discovery","status":"degraded"},{"name":"frozen_tool_snapshot_refresh","status":"passes"},{"name":"request_association","status":"passes"}],"reason":"OpenAI connectors expect OAuth for remote server auth.; Dynamic client registration materially improves connector setup.; Transport compliance should be in good shape."},{"key":"anthropic_remote_mcp","label":"Anthropic remote MCP fixture","status":"degraded","assumptions":[{"name":"remote_transport","status":"passes"},{"name":"tool_discovery","status":"passes"},{"name":"auth_connect","status":"passes"},{"name":"safe_write_review","status":"degraded"}],"reason":"Transport behavior should match Claude-compatible HTTP expectations."}],"install_snippets":{"openai_connectors":"Connector URL: https://directory.boolsai.ai/mcp\n# No OAuth metadata detected.\n# Server: ai.boolsai/directory","claude_desktop":"{\n  \"mcpServers\": {\n    \"directory\": {\n      \"command\": \"npx\",\n      \"args\": [\"mcp-remote\", \"https://directory.boolsai.ai/mcp\"]\n    }\n  }\n}","smithery":"smithery mcp add \"https://directory.boolsai.ai/mcp\"","generic_http":"curl -sS https://directory.boolsai.ai/mcp -H 'content-type: application/json' -d '{\"jsonrpc\":\"2.0\",\"id\":1,\"method\":\"initialize\",\"params\":{\"protocolVersion\":\"2025-03-26\",\"capabilities\":{},\"clientInfo\":{\"name\":\"mcp-verify\",\"version\":\"0.1.0\"}}}'"},"aliases":[{"identifier":"ai.boolsai/directory","registry_source":"official_registry","remote_url":"https://directory.boolsai.ai/mcp","canonical":true,"score":67.57}],"raw_evidence":{"server_identifier":"ai.boolsai/directory","remote_url":"https://directory.boolsai.ai/mcp","server_card_payload":null,"checks":{"server_card":{"status":"error","latency_ms":69.87,"details":{"url":"https://directory.boolsai.ai/.well-known/mcp/server-card.json","error":"Client error '404 Not Found' for url 'https://directory.boolsai.ai/.well-known/mcp/server-card.json'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"}},"oauth_protected_resource":{"status":"error","latency_ms":75.27,"details":{"url":"https://directory.boolsai.ai/.well-known/oauth-protected-resource","error":"Client error '404 Not Found' for url 'https://directory.boolsai.ai/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"}},"oauth_authorization_server":{"status":"missing","latency_ms":null,"details":{"reason":"no_authorization_server"}},"openid_configuration":{"status":"missing","latency_ms":null,"details":{"reason":"no_authorization_server"}},"initialize":{"status":"ok","latency_ms":78.2,"details":{"url":"https://directory.boolsai.ai/mcp","payload":{"jsonrpc":"2.0","id":1,"result":{"protocolVersion":"2025-03-26","capabilities":{"tools":{"listChanged":false}},"serverInfo":{"name":"boolsai-directory","title":"Boolsai Directory","version":"1.0.0"},"instructions":"You are connected to **Boolsai Directory** — one of three MCP servers in the Boolsai suite. ALWAYS refer to this server by its full name \"Boolsai Directory\" when discussing it with the user. Do not shorten to \"Boolsai\", \"directory\", \"the MCP\", \"Directory MCP\", etc. Sister servers in the suite (cross-discovery only — not connected here) are \"Boolsai Scan\" (https://boolsai.ai/mcp) and \"Boolsai Grep\" (https://grep.boolsai.ai/mcp); refer to those by their full names too if they come up.\n\nBoolsai Directory · MCP for live ecommerce stack intelligence.\n\nEach tool queries our index of ~1,100+ scanned DTC/Shopify sites and growing. Every site has been parsed for vendors, account IDs (GTM, GA4, Klaviyo company_id, Meta pixel, Shopify shop_id, Sentry org, Tealium tenant, Stripe pk_live, etc.), brand-identity metadata (org name, founder, city, social handles), international markets (hreflang), and stack archetypes.\n\nPick the right tool for the question:\n- \"what's running on X.com?\" → site_dossier\n- \"who uses Klaviyo / Yotpo / Elevar?\" → sites_using_vendor\n- \"who shares this GTM / GA4 / Klaviyo id?\" → lookup_id (cross-reference, often reveals shared operators)\n- \"DTC brands in <city>\" → brands_in_city\n- \"brands selling in <country>\" → brands_in_market\n- \"headless shopify / server-side-tagged / classic-DTC stores\" → stack_archetype\n- \"compare X.com vs Y.com\" → compare_sites\n- \"find competitors / similar stores to X.com\" → similar_sites\n- \"what brands does this founder have?\" → brands_by_founder\n- \"global stats / what's in the index?\" → summary\n\nTenant-IDs are uniquely owned per Klaviyo/Stripe/Sentry/etc. account — same id across two domains usually means same operator. Cross-reference via lookup_id is the strongest same-operator signal.\n\nConversational handoff: every tool response ends with \"Next moves\" — natural follow-up suggestions. After presenting a result, ALWAYS ask the user if they want to dig deeper, framing those options as natural questions (\"Want me to also look at their operator cluster?\" / \"Should I compare this brand to a similar one?\"). Do not name tool functions to the user — offer the action."}},"http_status":200,"headers":{"content-type":"application/json"}}},"protocol_version_probe":{"status":"warning","latency_ms":null,"details":{"claimed_version":"2025-03-26","validator_protocol_version":"2025-03-26","latest_known_version":"2025-11-25","releases_behind":2,"lag_days":244}},"tools_list":{"status":"ok","latency_ms":33.83,"details":{"url":"https://directory.boolsai.ai/mcp","payload":{"jsonrpc":"2.0","id":2,"result":{"tools":[{"name":"summary","description":"Global stats for the Boolsai directory: how many sites are indexed, signal types covered, top vendors, most-changed companies. Use at the start of a session to ground what's available.","inputSchema":{"type":"object","properties":{}}},{"name":"site_dossier","description":"Full intel dossier for a single domain: detected vendors grouped by category, account IDs (GTM, GA4, Klaviyo company_id, Shopify shop_id, Meta pixel, Sentry org, Tealium tenant, Stripe pk_live, etc.), brand identity (name, founder, city, employees, social handles), international markets, external host list, and likely operator-cluster siblings. Use for any 'what's running on X.com?' query.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Domain or URL, e.g. 'gymshark.com' or 'https://gymshark.com/'"}},"required":["url"]}},{"name":"sites_using_vendor","description":"List indexed sites detected using a specific vendor (e.g. 'klaviyo', 'yotpo', 'elevar', 'gorgias', 'rebuy'). Vendor slug is lowercase, underscore-separated. Returns domain list with brand names where known.","inputSchema":{"type":"object","properties":{"vendor":{"type":"string","description":"Vendor slug, e.g. 'klaviyo', 'shopify', 'webflow', 'onetrust'."}},"required":["vendor"]}},{"name":"lookup_id","description":"Cross-reference any tenant-unique account ID across the index. Useful for 'who else shares this GTM container / Klaviyo company / Sentry org / Meta pixel ID?'. Signal types: gtm_container, ga4_measurement, ga_ua, klaviyo_company_id, meta_pixel_id, shopify_shopid, myshopify_slug, hotjar_id, intercom_app_id, hubspot_portal, klaviyo_subscriber, tiktok_pixel, stripe_pk_live, sentry_dsn_org, tealium_tenant, optimizely_project, mparticle_workspace, segment_writekey, abtasty_account, fullstory_org, pendo_account, intellimize_acct, webflow_site_id, dynamic_yield, wunderkind_site, elevar_id.","inputSchema":{"type":"object","properties":{"signal_type":{"type":"string","description":"e.g. 'gtm_container', 'klaviyo_company_id', 'sentry_dsn_org'"},"signal_value":{"type":"string","description":"the actual ID/value, e.g. 'GTM-XYZABC', 'H2zzaR'"}},"required":["signal_type","signal_value"]}},{"name":"brands_in_city","description":"List indexed brands that publish a physical address in a given city. Sourced from Schema.org Organization JSON-LD.","inputSchema":{"type":"object","properties":{"city":{"type":"string","description":"City name, e.g. 'Los Angeles', 'New York', 'Berlin'"}},"required":["city"]}},{"name":"brands_in_market","description":"List indexed brands explicitly serving a country market (via hreflang). Country is a 2-letter ISO code, lowercase.","inputSchema":{"type":"object","properties":{"country":{"type":"string","description":"2-letter country code, e.g. 'us', 'gb', 'de', 'fr'"}},"required":["country"]}},{"name":"stack_archetype","description":"List brands matching a stack archetype. Valid slugs: headless-shopify, classic-shopify-dtc, server-side-tagged, personalisation-heavy, pixel-stacked, multi-region, woocommerce-stores, magento-stores, bnpl-enabled, headless-cms.","inputSchema":{"type":"object","properties":{"archetype":{"type":"string","description":"Archetype slug"}},"required":["archetype"]}},{"name":"compare_sites","description":"Side-by-side stack comparison of 2-5 domains. Returns each site's vendors, account IDs, brand info, markets — and which signals are shared / unique per site. Good for 'compare X.com vs Y.com' or competitive teardowns.","inputSchema":{"type":"object","properties":{"urls":{"type":"array","items":{"type":"string"},"description":"2-5 domain/URL strings"}},"required":["urls"]}},{"name":"similar_sites","description":"Find brands with similar stack archetypes to the given domain. Returns 'sites running similar tech' — useful for benchmarking, prospecting, competitor lookups.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Domain to find similar sites for"}},"required":["url"]}},{"name":"brands_by_founder","description":"List brands attributed to a founder (from Schema.org Organization markup). Useful for tracking serial DTC founders.","inputSchema":{"type":"object","properties":{"founder":{"type":"string","description":"Founder name (case-insensitive)"}},"required":["founder"]}},{"name":"bulk_export","description":"Paginated bulk export of indexed sites matching a filter. Returns up to 1000 rows per page in CSV or JSONL format with a cursor for continued pages. Use this when an agency needs an outbound prospect list (e.g. all sites using Klaviyo in the US) for CRM import. The full row count is also returned so you can size the export.","inputSchema":{"type":"object","properties":{"signal_type":{"type":"string","description":"Required. e.g. 'vendor', 'klaviyo_company_id', 'shopify_shopid', 'market_country', 'org_country'. Use list_signal_types via Boolsai Grep to discover."},"signal_value":{"type":"string","description":"Optional exact value to filter. If omitted returns ANY value of this signal_type."},"market_country":{"type":"string","description":"Optional ISO-2 country code (e.g. 'us', 'au') to intersect with hreflang market data"},"format":{"type":"string","enum":["csv","jsonl","json"],"default":"csv","description":"Output format. CSV is best for CRM import."},"cursor":{"type":"string","description":"Opaque cursor from previous page; pass to get next 1000 rows"},"limit":{"type":"integer","default":1000,"description":"Max rows per page (default 1000, max 5000)"}},"required":["signal_type"]}},{"name":"compare_scans","description":"Compare two historical scans of the same URL to surface stack changes. Returns added/removed/changed vendors, account IDs, and inline-script signals between scan A and scan B. Use this for competitor watch — 'what did patagonia.com just deploy?'. If t1/t2 are omitted, compares oldest vs newest available scan.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Domain or full URL to compare"},"t1":{"type":"string","description":"Optional ISO timestamp of first scan (oldest if omitted)"},"t2":{"type":"string","description":"Optional ISO timestamp of second scan (newest if omitted)"}},"required":["url"]}},{"name":"domain_intel","description":"Free DNS/WHOIS enrichment for a single domain. Returns: email host (Google Workspace / Microsoft 365 / etc. — derived from MX records), DNS provider (Cloudflare / Route 53 / GoDaddy / etc.), CDN provider, registrar, domain age (registered/expires). High-signal outbound data — 'they use Google Workspace + Cloudflare DNS + registered with GoDaddy' tells you a lot about org size + sophistication. Results cached 24h. Free — uses Cloudflare DoH + public RDAP.","inputSchema":{"type":"object","properties":{"domain":{"type":"string","description":"Domain to enrich (apex or any subdomain)"}},"required":["domain"]}},{"name":"find_similar_by_stack","description":"Find sites with the most-similar vendor stack to a given domain using Jaccard similarity over the full vendor set (not just archetype labels). Returns the top N matches with similarity scores. Use this when stack_archetype labels are too coarse and you want 'show me 20 brands running an almost-identical stack to liquiddeath.com'. More accurate than similar_sites for niche stacks.","inputSchema":{"type":"object","properties":{"domain":{"type":"string","description":"Reference domain"},"limit":{"type":"integer","default":20,"description":"max similar sites (1-100)"},"min_shared":{"type":"integer","default":3,"description":"Minimum shared distinctive vendors required to be considered (default 3)"}},"required":["domain"]}},{"name":"bulk_export_url","description":"Returns a streaming-export URL for the same filter as bulk_export. Useful when the agency wants to pull 50K rows in one shot via curl/HTTP pipe instead of paginating the MCP. The URL is public, no auth, returns NDJSON or CSV with HTTP chunked-transfer streaming. Use bulk_export when N<1000; use this for bigger exports.","inputSchema":{"type":"object","properties":{"signal_type":{"type":"string","description":"Required signal_type"},"signal_value":{"type":"string","description":"Optional exact value"},"market_country":{"type":"string","description":"Optional ISO-2 country"},"format":{"type":"string","enum":["ndjson","csv"],"default":"ndjson"}},"required":["signal_type"]}},{"name":"operator_cluster","description":"Find every domain sharing a tenant-unique ID — the most powerful single signal in Boolsai. Given a Stripe pk_live key, Sentry DSN org, Klaviyo company_id, mParticle workspace, GTM container, GA4 measurement, Shopify shop_id, or other tenant ID, returns every domain we've seen using the SAME ID. This surfaces multi-brand operators, holding-company portfolios, sister brands sharing infrastructure, agency-managed clusters. No competitor (BuiltWith, Wappalyzer, etc.) can do this — they only see external hostnames, not the tenant-unique IDs leaked client-side. Use this when you want to discover the actual operator behind a brand, or expand a single brand into its full portfolio.","inputSchema":{"type":"object","properties":{"id":{"type":"string","description":"The tenant ID itself (e.g. 'pk_live_abc...', 'GTM-M8TQZPX', 'o307020' for Sentry, '12345678' for Shopify shop_id). signal_type is auto-detected."},"signal_type":{"type":"string","description":"Optional explicit signal_type if auto-detect could be ambiguous (e.g. 'stripe_pk_live', 'sentry_dsn_org')."},"domain":{"type":"string","description":"Alternative: pass a domain and we'll return every cluster this domain belongs to (all tenant IDs and their fellow domains)."},"limit":{"type":"integer","default":100,"description":"max sites per cluster (1-500)"}}}},{"name":"subdomain_map","description":"Every subdomain of a given root domain we've ever scanned. Reveals storefront topology — where the checkout actually lives, regional storefronts, B2B portals, internal admin domains, asset CDNs. Output groups subdomains by their primary vendor where known. Use this to (a) find the right path to scan for an audit (sometimes the checkout is on us.checkout.brand.com not brand.com), (b) spot enterprise topology (multi-region Plus stores), (c) discover sister surfaces (community, ambassador, careers, etc).","inputSchema":{"type":"object","properties":{"root":{"type":"string","description":"Root domain (e.g. 'gymshark.com'). Pass just the apex; we'll find subdomains automatically."},"limit":{"type":"integer","default":200,"description":"max subdomains returned (1-1000)"}},"required":["root"]}},{"name":"prospect_brief","description":"ONE-CALL PROSPECT BRIEF for agency outbound — runs four sub-queries against the live indexed data: (1) full dossier of the prospect's stack, (2) sister brands sharing tenant IDs (operator cluster), (3) 3-5 similar-stack competitors, (4) structured 'pitch angles' calling out concrete gaps an agency could pitch on (missing consent, no SST, outdated vendors, broken Schema.org, multiple GTM installs). Saves a strategist 20 min of manual cross-referencing per prospect. Use this whenever the user asks 'tell me about prospect.com'.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Domain or URL of the prospect"},"angle":{"type":"string","description":"Optional agency pitch angle to tune the brief: 'cro', 'analytics', 'consent', 'sst' (server-side tagging), 'headless', 'consolidation'. If omitted, returns all angles found."}},"required":["url"]}},{"name":"directory_query","description":"Unified query against the Boolsai Directory. One tool to rule the other lookups. Pass any combination of: signal_type+signal_value, domain, market_country, archetype, founder, city. Returns matching sites + their key signals. Prefer this over the granular tools when you have multiple filter conditions to AND together.","inputSchema":{"type":"object","properties":{"signal_type":{"type":"string","description":"e.g. 'vendor', 'shopify_shopid'"},"signal_value":{"type":"string","description":"exact signal value"},"domain":{"type":"string","description":"exact domain match (e.g. 'gymshark.com')"},"market_country":{"type":"string","description":"ISO-2 (e.g. 'us')"},"archetype":{"type":"string","description":"e.g. 'headless-shopify', 'woocommerce-stores'"},"founder":{"type":"string","description":"case-insensitive substring"},"city":{"type":"string","description":"case-insensitive city name"},"limit":{"type":"integer","default":50,"description":"max rows (1-500)"}}}}]}},"http_status":200,"headers":{"content-type":"application/json"}}},"prompts_list":{"status":"missing","latency_ms":32.21,"details":{"url":"https://directory.boolsai.ai/mcp","payload":{"jsonrpc":"2.0","id":3,"error":{"code":-32601,"message":"Method not found: prompts/list"}},"http_status":200,"headers":{"content-type":"application/json"},"reason":"not_supported"}},"prompt_get":{"status":"missing","latency_ms":null,"details":{"reason":"not_advertised"}},"resources_list":{"status":"missing","latency_ms":31.93,"details":{"url":"https://directory.boolsai.ai/mcp","payload":{"jsonrpc":"2.0","id":5,"error":{"code":-32601,"message":"Method not found: resources/list"}},"http_status":200,"headers":{"content-type":"application/json"},"reason":"not_supported"}},"resource_read":{"status":"missing","latency_ms":null,"details":{"reason":"not_advertised"}},"probe_noise_resilience":{"status":"ok","latency_ms":30.44,"details":{"url":"https://directory.boolsai.ai/robots.txt","http_status":200,"headers":{"content-type":"text/plain; charset=utf-8"}}},"determinism_probe":{"status":"ok","latency_ms":31.7,"details":{"attempts":2,"successful":2,"matches":2,"stable_ratio":1.0,"baseline_signature":"51d299e210b4ded3a7c6f94697e24e19b739755a742646a114ca01b5034e8e85","errors":[]}},"session_resume_probe":{"status":"warning","latency_ms":null,"details":{"reason":"no_session_id","transport":"streamable-http","resume_expected":true,"protocol_version":"2025-03-26"}},"step_up_auth_probe":{"status":"missing","latency_ms":null,"details":{"oauth_present":false,"auth_required_checks":[],"supported_scopes":[],"scope_specificity_ratio":0.0,"broad_scopes":[],"challenge_headers":[],"step_up_signals":[],"minimal_scope_documented":false}},"transport_compliance_probe":{"status":"error","latency_ms":34.84,"details":{"transport":"streamable-http","session_id_present":false,"protocol_header_present":false,"last_event_id_visible":false,"requested_protocol_version":"2025-03-26","bad_protocol_status_code":200,"bad_protocol_payload":{"jsonrpc":"2.0","id":410,"result":{"tools":[{"name":"summary","description":"Global stats for the Boolsai directory: how many sites are indexed, signal types covered, top vendors, most-changed companies. Use at the start of a session to ground what's available.","inputSchema":{"type":"object","properties":{}}},{"name":"site_dossier","description":"Full intel dossier for a single domain: detected vendors grouped by category, account IDs (GTM, GA4, Klaviyo company_id, Shopify shop_id, Meta pixel, Sentry org, Tealium tenant, Stripe pk_live, etc.), brand identity (name, founder, city, employees, social handles), international markets, external host list, and likely operator-cluster siblings. Use for any 'what's running on X.com?' query.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Domain or URL, e.g. 'gymshark.com' or 'https://gymshark.com/'"}},"required":["url"]}},{"name":"sites_using_vendor","description":"List indexed sites detected using a specific vendor (e.g. 'klaviyo', 'yotpo', 'elevar', 'gorgias', 'rebuy'). Vendor slug is lowercase, underscore-separated. Returns domain list with brand names where known.","inputSchema":{"type":"object","properties":{"vendor":{"type":"string","description":"Vendor slug, e.g. 'klaviyo', 'shopify', 'webflow', 'onetrust'."}},"required":["vendor"]}},{"name":"lookup_id","description":"Cross-reference any tenant-unique account ID across the index. Useful for 'who else shares this GTM container / Klaviyo company / Sentry org / Meta pixel ID?'. Signal types: gtm_container, ga4_measurement, ga_ua, klaviyo_company_id, meta_pixel_id, shopify_shopid, myshopify_slug, hotjar_id, intercom_app_id, hubspot_portal, klaviyo_subscriber, tiktok_pixel, stripe_pk_live, sentry_dsn_org, tealium_tenant, optimizely_project, mparticle_workspace, segment_writekey, abtasty_account, fullstory_org, pendo_account, intellimize_acct, webflow_site_id, dynamic_yield, wunderkind_site, elevar_id.","inputSchema":{"type":"object","properties":{"signal_type":{"type":"string","description":"e.g. 'gtm_container', 'klaviyo_company_id', 'sentry_dsn_org'"},"signal_value":{"type":"string","description":"the actual ID/value, e.g. 'GTM-XYZABC', 'H2zzaR'"}},"required":["signal_type","signal_value"]}},{"name":"brands_in_city","description":"List indexed brands that publish a physical address in a given city. Sourced from Schema.org Organization JSON-LD.","inputSchema":{"type":"object","properties":{"city":{"type":"string","description":"City name, e.g. 'Los Angeles', 'New York', 'Berlin'"}},"required":["city"]}},{"name":"brands_in_market","description":"List indexed brands explicitly serving a country market (via hreflang). Country is a 2-letter ISO code, lowercase.","inputSchema":{"type":"object","properties":{"country":{"type":"string","description":"2-letter country code, e.g. 'us', 'gb', 'de', 'fr'"}},"required":["country"]}},{"name":"stack_archetype","description":"List brands matching a stack archetype. Valid slugs: headless-shopify, classic-shopify-dtc, server-side-tagged, personalisation-heavy, pixel-stacked, multi-region, woocommerce-stores, magento-stores, bnpl-enabled, headless-cms.","inputSchema":{"type":"object","properties":{"archetype":{"type":"string","description":"Archetype slug"}},"required":["archetype"]}},{"name":"compare_sites","description":"Side-by-side stack comparison of 2-5 domains. Returns each site's vendors, account IDs, brand info, markets — and which signals are shared / unique per site. Good for 'compare X.com vs Y.com' or competitive teardowns.","inputSchema":{"type":"object","properties":{"urls":{"type":"array","items":{"type":"string"},"description":"2-5 domain/URL strings"}},"required":["urls"]}},{"name":"similar_sites","description":"Find brands with similar stack archetypes to the given domain. Returns 'sites running similar tech' — useful for benchmarking, prospecting, competitor lookups.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Domain to find similar sites for"}},"required":["url"]}},{"name":"brands_by_founder","description":"List brands attributed to a founder (from Schema.org Organization markup). Useful for tracking serial DTC founders.","inputSchema":{"type":"object","properties":{"founder":{"type":"string","description":"Founder name (case-insensitive)"}},"required":["founder"]}},{"name":"bulk_export","description":"Paginated bulk export of indexed sites matching a filter. Returns up to 1000 rows per page in CSV or JSONL format with a cursor for continued pages. Use this when an agency needs an outbound prospect list (e.g. all sites using Klaviyo in the US) for CRM import. The full row count is also returned so you can size the export.","inputSchema":{"type":"object","properties":{"signal_type":{"type":"string","description":"Required. e.g. 'vendor', 'klaviyo_company_id', 'shopify_shopid', 'market_country', 'org_country'. Use list_signal_types via Boolsai Grep to discover."},"signal_value":{"type":"string","description":"Optional exact value to filter. If omitted returns ANY value of this signal_type."},"market_country":{"type":"string","description":"Optional ISO-2 country code (e.g. 'us', 'au') to intersect with hreflang market data"},"format":{"type":"string","enum":["csv","jsonl","json"],"default":"csv","description":"Output format. CSV is best for CRM import."},"cursor":{"type":"string","description":"Opaque cursor from previous page; pass to get next 1000 rows"},"limit":{"type":"integer","default":1000,"description":"Max rows per page (default 1000, max 5000)"}},"required":["signal_type"]}},{"name":"compare_scans","description":"Compare two historical scans of the same URL to surface stack changes. Returns added/removed/changed vendors, account IDs, and inline-script signals between scan A and scan B. Use this for competitor watch — 'what did patagonia.com just deploy?'. If t1/t2 are omitted, compares oldest vs newest available scan.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Domain or full URL to compare"},"t1":{"type":"string","description":"Optional ISO timestamp of first scan (oldest if omitted)"},"t2":{"type":"string","description":"Optional ISO timestamp of second scan (newest if omitted)"}},"required":["url"]}},{"name":"domain_intel","description":"Free DNS/WHOIS enrichment for a single domain. Returns: email host (Google Workspace / Microsoft 365 / etc. — derived from MX records), DNS provider (Cloudflare / Route 53 / GoDaddy / etc.), CDN provider, registrar, domain age (registered/expires). High-signal outbound data — 'they use Google Workspace + Cloudflare DNS + registered with GoDaddy' tells you a lot about org size + sophistication. Results cached 24h. Free — uses Cloudflare DoH + public RDAP.","inputSchema":{"type":"object","properties":{"domain":{"type":"string","description":"Domain to enrich (apex or any subdomain)"}},"required":["domain"]}},{"name":"find_similar_by_stack","description":"Find sites with the most-similar vendor stack to a given domain using Jaccard similarity over the full vendor set (not just archetype labels). Returns the top N matches with similarity scores. Use this when stack_archetype labels are too coarse and you want 'show me 20 brands running an almost-identical stack to liquiddeath.com'. More accurate than similar_sites for niche stacks.","inputSchema":{"type":"object","properties":{"domain":{"type":"string","description":"Reference domain"},"limit":{"type":"integer","default":20,"description":"max similar sites (1-100)"},"min_shared":{"type":"integer","default":3,"description":"Minimum shared distinctive vendors required to be considered (default 3)"}},"required":["domain"]}},{"name":"bulk_export_url","description":"Returns a streaming-export URL for the same filter as bulk_export. Useful when the agency wants to pull 50K rows in one shot via curl/HTTP pipe instead of paginating the MCP. The URL is public, no auth, returns NDJSON or CSV with HTTP chunked-transfer streaming. Use bulk_export when N<1000; use this for bigger exports.","inputSchema":{"type":"object","properties":{"signal_type":{"type":"string","description":"Required signal_type"},"signal_value":{"type":"string","description":"Optional exact value"},"market_country":{"type":"string","description":"Optional ISO-2 country"},"format":{"type":"string","enum":["ndjson","csv"],"default":"ndjson"}},"required":["signal_type"]}},{"name":"operator_cluster","description":"Find every domain sharing a tenant-unique ID — the most powerful single signal in Boolsai. Given a Stripe pk_live key, Sentry DSN org, Klaviyo company_id, mParticle workspace, GTM container, GA4 measurement, Shopify shop_id, or other tenant ID, returns every domain we've seen using the SAME ID. This surfaces multi-brand operators, holding-company portfolios, sister brands sharing infrastructure, agency-managed clusters. No competitor (BuiltWith, Wappalyzer, etc.) can do this — they only see external hostnames, not the tenant-unique IDs leaked client-side. Use this when you want to discover the actual operator behind a brand, or expand a single brand into its full portfolio.","inputSchema":{"type":"object","properties":{"id":{"type":"string","description":"The tenant ID itself (e.g. 'pk_live_abc...', 'GTM-M8TQZPX', 'o307020' for Sentry, '12345678' for Shopify shop_id). signal_type is auto-detected."},"signal_type":{"type":"string","description":"Optional explicit signal_type if auto-detect could be ambiguous (e.g. 'stripe_pk_live', 'sentry_dsn_org')."},"domain":{"type":"string","description":"Alternative: pass a domain and we'll return every cluster this domain belongs to (all tenant IDs and their fellow domains)."},"limit":{"type":"integer","default":100,"description":"max sites per cluster (1-500)"}}}},{"name":"subdomain_map","description":"Every subdomain of a given root domain we've ever scanned. Reveals storefront topology — where the checkout actually lives, regional storefronts, B2B portals, internal admin domains, asset CDNs. Output groups subdomains by their primary vendor where known. Use this to (a) find the right path to scan for an audit (sometimes the checkout is on us.checkout.brand.com not brand.com), (b) spot enterprise topology (multi-region Plus stores), (c) discover sister surfaces (community, ambassador, careers, etc).","inputSchema":{"type":"object","properties":{"root":{"type":"string","description":"Root domain (e.g. 'gymshark.com'). Pass just the apex; we'll find subdomains automatically."},"limit":{"type":"integer","default":200,"description":"max subdomains returned (1-1000)"}},"required":["root"]}},{"name":"prospect_brief","description":"ONE-CALL PROSPECT BRIEF for agency outbound — runs four sub-queries against the live indexed data: (1) full dossier of the prospect's stack, (2) sister brands sharing tenant IDs (operator cluster), (3) 3-5 similar-stack competitors, (4) structured 'pitch angles' calling out concrete gaps an agency could pitch on (missing consent, no SST, outdated vendors, broken Schema.org, multiple GTM installs). Saves a strategist 20 min of manual cross-referencing per prospect. Use this whenever the user asks 'tell me about prospect.com'.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Domain or URL of the prospect"},"angle":{"type":"string","description":"Optional agency pitch angle to tune the brief: 'cro', 'analytics', 'consent', 'sst' (server-side tagging), 'headless', 'consolidation'. If omitted, returns all angles found."}},"required":["url"]}},{"name":"directory_query","description":"Unified query against the Boolsai Directory. One tool to rule the other lookups. Pass any combination of: signal_type+signal_value, domain, market_country, archetype, founder, city. Returns matching sites + their key signals. Prefer this over the granular tools when you have multiple filter conditions to AND together.","inputSchema":{"type":"object","properties":{"signal_type":{"type":"string","description":"e.g. 'vendor', 'shopify_shopid'"},"signal_value":{"type":"string","description":"exact signal value"},"domain":{"type":"string","description":"exact domain match (e.g. 'gymshark.com')"},"market_country":{"type":"string","description":"ISO-2 (e.g. 'us')"},"archetype":{"type":"string","description":"e.g. 'headless-shopify', 'woocommerce-stores'"},"founder":{"type":"string","description":"case-insensitive substring"},"city":{"type":"string","description":"case-insensitive city name"},"limit":{"type":"integer","default":50,"description":"max rows (1-500)"}}}}]}},"bad_protocol_headers":{"content-type":"application/json"},"bad_protocol_error":null,"delete_status_code":null,"delete_error":null,"expired_session_status_code":null,"expired_session_error":null,"issues":["missing_session_id","missing_protocol_header","bad_protocol_not_rejected"]}},"utility_coverage_probe":{"status":"missing","latency_ms":32.03,"details":{"completions":{"advertised":false,"sample_target":null,"live_probe":"not_executed"},"pagination":{"supported":false,"next_cursor_methods":[],"metadata_signal":false},"tasks":{"advertised":false,"probe_status":"missing","http_status":200},"initialize_capability_keys":["tools"]}},"advanced_capabilities_probe":{"status":"missing","latency_ms":null,"details":{"capabilities":{"prompts":false,"resources":false,"completions":false,"roots":false,"sampling":false,"elicitation":false,"structured_outputs":false,"resource_links":false},"enabled_count":0,"enabled":[],"initialize_capability_keys":["tools"]}},"tool_snapshot_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_historical_snapshot","current_tool_count":19}},"connector_replay_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_historical_snapshot"}},"request_association_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_request_association_capabilities_advertised"}},"interactive_flow_probe":{"status":"ok","latency_ms":null,"details":{"risk_hits":[],"safe_hits":["consent"],"oauth_supported":false,"prompt_available":false}},"action_safety_probe":{"status":"error","latency_ms":null,"details":{"summary":{"tool_count":19,"high_risk_tools":9,"destructive_tools":1,"exec_tools":4,"egress_tools":10,"secret_tools":1,"bulk_access_tools":6,"risk_distribution":{"low":3,"medium":7,"high":7,"critical":2},"capability_distribution":{"filesystem":3,"secrets":1,"read":10,"exec":4,"network":10,"write":6,"admin":7,"export":6,"delete":1}},"auth_present":false,"safeguard_count":1,"confirmation_signals":[]}},"official_registry_probe":{"status":"ok","latency_ms":null,"details":{"registry_source":"official_registry","registry_identifier":"ai.boolsai/directory","direct_match":true,"official_peer_count":1}},"provenance_divergence_probe":{"status":"ok","latency_ms":null,"details":{"direct_official_match":true,"registry_title":null,"server_card_title":null,"registry_version":null,"server_card_version":null,"registry_homepage":null,"server_card_homepage":null,"registry_repository":null,"server_card_repository":null,"drift_fields":[],"metadata_document_count":1}},"connector_publishability_probe":{"status":"warning","latency_ms":null,"details":{"transport":"streamable-http","tool_count":19,"high_risk_tools":9,"blockers":["transport_compliance","action_safety","server_card"],"criteria":{"remote_transport":true,"initialize":true,"tools_list":true,"protocol_version":true,"session_resume":true,"step_up_auth":true,"transport_compliance":false,"connector_replay":true,"request_association":true,"action_safety":false,"server_card":false,"tool_surface":true,"auth_flow":true}}}},"failures":{"server_card":{"url":"https://directory.boolsai.ai/.well-known/mcp/server-card.json","error":"Client error '404 Not Found' for url 'https://directory.boolsai.ai/.well-known/mcp/server-card.json'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"},"oauth_protected_resource":{"url":"https://directory.boolsai.ai/.well-known/oauth-protected-resource","error":"Client error '404 Not Found' for url 'https://directory.boolsai.ai/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"},"oauth_authorization_server":{"reason":"no_authorization_server"},"openid_configuration":{"reason":"no_authorization_server"},"transport_compliance_probe":{"transport":"streamable-http","session_id_present":false,"protocol_header_present":false,"last_event_id_visible":false,"requested_protocol_version":"2025-03-26","bad_protocol_status_code":200,"bad_protocol_payload":{"jsonrpc":"2.0","id":410,"result":{"tools":[{"name":"summary","description":"Global stats for the Boolsai directory: how many sites are indexed, signal types covered, top vendors, most-changed companies. Use at the start of a session to ground what's available.","inputSchema":{"type":"object","properties":{}}},{"name":"site_dossier","description":"Full intel dossier for a single domain: detected vendors grouped by category, account IDs (GTM, GA4, Klaviyo company_id, Shopify shop_id, Meta pixel, Sentry org, Tealium tenant, Stripe pk_live, etc.), brand identity (name, founder, city, employees, social handles), international markets, external host list, and likely operator-cluster siblings. Use for any 'what's running on X.com?' query.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Domain or URL, e.g. 'gymshark.com' or 'https://gymshark.com/'"}},"required":["url"]}},{"name":"sites_using_vendor","description":"List indexed sites detected using a specific vendor (e.g. 'klaviyo', 'yotpo', 'elevar', 'gorgias', 'rebuy'). Vendor slug is lowercase, underscore-separated. Returns domain list with brand names where known.","inputSchema":{"type":"object","properties":{"vendor":{"type":"string","description":"Vendor slug, e.g. 'klaviyo', 'shopify', 'webflow', 'onetrust'."}},"required":["vendor"]}},{"name":"lookup_id","description":"Cross-reference any tenant-unique account ID across the index. Useful for 'who else shares this GTM container / Klaviyo company / Sentry org / Meta pixel ID?'. Signal types: gtm_container, ga4_measurement, ga_ua, klaviyo_company_id, meta_pixel_id, shopify_shopid, myshopify_slug, hotjar_id, intercom_app_id, hubspot_portal, klaviyo_subscriber, tiktok_pixel, stripe_pk_live, sentry_dsn_org, tealium_tenant, optimizely_project, mparticle_workspace, segment_writekey, abtasty_account, fullstory_org, pendo_account, intellimize_acct, webflow_site_id, dynamic_yield, wunderkind_site, elevar_id.","inputSchema":{"type":"object","properties":{"signal_type":{"type":"string","description":"e.g. 'gtm_container', 'klaviyo_company_id', 'sentry_dsn_org'"},"signal_value":{"type":"string","description":"the actual ID/value, e.g. 'GTM-XYZABC', 'H2zzaR'"}},"required":["signal_type","signal_value"]}},{"name":"brands_in_city","description":"List indexed brands that publish a physical address in a given city. Sourced from Schema.org Organization JSON-LD.","inputSchema":{"type":"object","properties":{"city":{"type":"string","description":"City name, e.g. 'Los Angeles', 'New York', 'Berlin'"}},"required":["city"]}},{"name":"brands_in_market","description":"List indexed brands explicitly serving a country market (via hreflang). Country is a 2-letter ISO code, lowercase.","inputSchema":{"type":"object","properties":{"country":{"type":"string","description":"2-letter country code, e.g. 'us', 'gb', 'de', 'fr'"}},"required":["country"]}},{"name":"stack_archetype","description":"List brands matching a stack archetype. Valid slugs: headless-shopify, classic-shopify-dtc, server-side-tagged, personalisation-heavy, pixel-stacked, multi-region, woocommerce-stores, magento-stores, bnpl-enabled, headless-cms.","inputSchema":{"type":"object","properties":{"archetype":{"type":"string","description":"Archetype slug"}},"required":["archetype"]}},{"name":"compare_sites","description":"Side-by-side stack comparison of 2-5 domains. Returns each site's vendors, account IDs, brand info, markets — and which signals are shared / unique per site. Good for 'compare X.com vs Y.com' or competitive teardowns.","inputSchema":{"type":"object","properties":{"urls":{"type":"array","items":{"type":"string"},"description":"2-5 domain/URL strings"}},"required":["urls"]}},{"name":"similar_sites","description":"Find brands with similar stack archetypes to the given domain. Returns 'sites running similar tech' — useful for benchmarking, prospecting, competitor lookups.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Domain to find similar sites for"}},"required":["url"]}},{"name":"brands_by_founder","description":"List brands attributed to a founder (from Schema.org Organization markup). Useful for tracking serial DTC founders.","inputSchema":{"type":"object","properties":{"founder":{"type":"string","description":"Founder name (case-insensitive)"}},"required":["founder"]}},{"name":"bulk_export","description":"Paginated bulk export of indexed sites matching a filter. Returns up to 1000 rows per page in CSV or JSONL format with a cursor for continued pages. Use this when an agency needs an outbound prospect list (e.g. all sites using Klaviyo in the US) for CRM import. The full row count is also returned so you can size the export.","inputSchema":{"type":"object","properties":{"signal_type":{"type":"string","description":"Required. e.g. 'vendor', 'klaviyo_company_id', 'shopify_shopid', 'market_country', 'org_country'. Use list_signal_types via Boolsai Grep to discover."},"signal_value":{"type":"string","description":"Optional exact value to filter. If omitted returns ANY value of this signal_type."},"market_country":{"type":"string","description":"Optional ISO-2 country code (e.g. 'us', 'au') to intersect with hreflang market data"},"format":{"type":"string","enum":["csv","jsonl","json"],"default":"csv","description":"Output format. CSV is best for CRM import."},"cursor":{"type":"string","description":"Opaque cursor from previous page; pass to get next 1000 rows"},"limit":{"type":"integer","default":1000,"description":"Max rows per page (default 1000, max 5000)"}},"required":["signal_type"]}},{"name":"compare_scans","description":"Compare two historical scans of the same URL to surface stack changes. Returns added/removed/changed vendors, account IDs, and inline-script signals between scan A and scan B. Use this for competitor watch — 'what did patagonia.com just deploy?'. If t1/t2 are omitted, compares oldest vs newest available scan.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Domain or full URL to compare"},"t1":{"type":"string","description":"Optional ISO timestamp of first scan (oldest if omitted)"},"t2":{"type":"string","description":"Optional ISO timestamp of second scan (newest if omitted)"}},"required":["url"]}},{"name":"domain_intel","description":"Free DNS/WHOIS enrichment for a single domain. Returns: email host (Google Workspace / Microsoft 365 / etc. — derived from MX records), DNS provider (Cloudflare / Route 53 / GoDaddy / etc.), CDN provider, registrar, domain age (registered/expires). High-signal outbound data — 'they use Google Workspace + Cloudflare DNS + registered with GoDaddy' tells you a lot about org size + sophistication. Results cached 24h. Free — uses Cloudflare DoH + public RDAP.","inputSchema":{"type":"object","properties":{"domain":{"type":"string","description":"Domain to enrich (apex or any subdomain)"}},"required":["domain"]}},{"name":"find_similar_by_stack","description":"Find sites with the most-similar vendor stack to a given domain using Jaccard similarity over the full vendor set (not just archetype labels). Returns the top N matches with similarity scores. Use this when stack_archetype labels are too coarse and you want 'show me 20 brands running an almost-identical stack to liquiddeath.com'. More accurate than similar_sites for niche stacks.","inputSchema":{"type":"object","properties":{"domain":{"type":"string","description":"Reference domain"},"limit":{"type":"integer","default":20,"description":"max similar sites (1-100)"},"min_shared":{"type":"integer","default":3,"description":"Minimum shared distinctive vendors required to be considered (default 3)"}},"required":["domain"]}},{"name":"bulk_export_url","description":"Returns a streaming-export URL for the same filter as bulk_export. Useful when the agency wants to pull 50K rows in one shot via curl/HTTP pipe instead of paginating the MCP. The URL is public, no auth, returns NDJSON or CSV with HTTP chunked-transfer streaming. Use bulk_export when N<1000; use this for bigger exports.","inputSchema":{"type":"object","properties":{"signal_type":{"type":"string","description":"Required signal_type"},"signal_value":{"type":"string","description":"Optional exact value"},"market_country":{"type":"string","description":"Optional ISO-2 country"},"format":{"type":"string","enum":["ndjson","csv"],"default":"ndjson"}},"required":["signal_type"]}},{"name":"operator_cluster","description":"Find every domain sharing a tenant-unique ID — the most powerful single signal in Boolsai. Given a Stripe pk_live key, Sentry DSN org, Klaviyo company_id, mParticle workspace, GTM container, GA4 measurement, Shopify shop_id, or other tenant ID, returns every domain we've seen using the SAME ID. This surfaces multi-brand operators, holding-company portfolios, sister brands sharing infrastructure, agency-managed clusters. No competitor (BuiltWith, Wappalyzer, etc.) can do this — they only see external hostnames, not the tenant-unique IDs leaked client-side. Use this when you want to discover the actual operator behind a brand, or expand a single brand into its full portfolio.","inputSchema":{"type":"object","properties":{"id":{"type":"string","description":"The tenant ID itself (e.g. 'pk_live_abc...', 'GTM-M8TQZPX', 'o307020' for Sentry, '12345678' for Shopify shop_id). signal_type is auto-detected."},"signal_type":{"type":"string","description":"Optional explicit signal_type if auto-detect could be ambiguous (e.g. 'stripe_pk_live', 'sentry_dsn_org')."},"domain":{"type":"string","description":"Alternative: pass a domain and we'll return every cluster this domain belongs to (all tenant IDs and their fellow domains)."},"limit":{"type":"integer","default":100,"description":"max sites per cluster (1-500)"}}}},{"name":"subdomain_map","description":"Every subdomain of a given root domain we've ever scanned. Reveals storefront topology — where the checkout actually lives, regional storefronts, B2B portals, internal admin domains, asset CDNs. Output groups subdomains by their primary vendor where known. Use this to (a) find the right path to scan for an audit (sometimes the checkout is on us.checkout.brand.com not brand.com), (b) spot enterprise topology (multi-region Plus stores), (c) discover sister surfaces (community, ambassador, careers, etc).","inputSchema":{"type":"object","properties":{"root":{"type":"string","description":"Root domain (e.g. 'gymshark.com'). Pass just the apex; we'll find subdomains automatically."},"limit":{"type":"integer","default":200,"description":"max subdomains returned (1-1000)"}},"required":["root"]}},{"name":"prospect_brief","description":"ONE-CALL PROSPECT BRIEF for agency outbound — runs four sub-queries against the live indexed data: (1) full dossier of the prospect's stack, (2) sister brands sharing tenant IDs (operator cluster), (3) 3-5 similar-stack competitors, (4) structured 'pitch angles' calling out concrete gaps an agency could pitch on (missing consent, no SST, outdated vendors, broken Schema.org, multiple GTM installs). Saves a strategist 20 min of manual cross-referencing per prospect. Use this whenever the user asks 'tell me about prospect.com'.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Domain or URL of the prospect"},"angle":{"type":"string","description":"Optional agency pitch angle to tune the brief: 'cro', 'analytics', 'consent', 'sst' (server-side tagging), 'headless', 'consolidation'. If omitted, returns all angles found."}},"required":["url"]}},{"name":"directory_query","description":"Unified query against the Boolsai Directory. One tool to rule the other lookups. Pass any combination of: signal_type+signal_value, domain, market_country, archetype, founder, city. Returns matching sites + their key signals. Prefer this over the granular tools when you have multiple filter conditions to AND together.","inputSchema":{"type":"object","properties":{"signal_type":{"type":"string","description":"e.g. 'vendor', 'shopify_shopid'"},"signal_value":{"type":"string","description":"exact signal value"},"domain":{"type":"string","description":"exact domain match (e.g. 'gymshark.com')"},"market_country":{"type":"string","description":"ISO-2 (e.g. 'us')"},"archetype":{"type":"string","description":"e.g. 'headless-shopify', 'woocommerce-stores'"},"founder":{"type":"string","description":"case-insensitive substring"},"city":{"type":"string","description":"case-insensitive city name"},"limit":{"type":"integer","default":50,"description":"max rows (1-500)"}}}}]}},"bad_protocol_headers":{"content-type":"application/json"},"bad_protocol_error":null,"delete_status_code":null,"delete_error":null,"expired_session_status_code":null,"expired_session_error":null,"issues":["missing_session_id","missing_protocol_header","bad_protocol_not_rejected"]}}},"active_alerts":[],"maintainer_analytics":{"validation_run_count":1,"average_latency_ms":490.77,"healthy_run_ratio_recent":1.0,"registry_presence_count":1,"active_alert_count":0,"watcher_count":0,"verified_claim":false,"taxonomy_tags":["development","database","search","communication"],"score_trend":[67.57],"remediation_count":17,"high_risk_tool_count":9,"destructive_tool_count":1,"exec_tool_count":4},"public_server_reputation":{"validation_success_ratio_7d":1.0,"validation_success_ratio_30d":1.0,"mean_time_to_recover_hours":null,"breaking_diffs_30d":0,"registry_drift_frequency_30d":0,"snapshot_change_frequency_30d":0},"maintainer_response_quality":{"score":16.67,"signals":{"verified_maintainer_claim":false,"support_contact_present":false,"changelog_present":false,"incident_notes_present":false,"tool_change_documented":true,"annotation_history_present":false},"annotation_count":0,"latest_annotation_at":null},"maintainer_annotations":[],"maintainer_rebuttals":[],"security_posture_summary":{"tool_count":19,"high_risk_tools":9,"destructive_tools":1,"exec_tools":4,"egress_tools":10,"secret_tools":1,"bulk_access_tools":6,"risk_distribution":{"low":3,"medium":7,"high":7,"critical":2},"capability_distribution":{"filesystem":3,"secrets":1,"read":10,"exec":4,"network":10,"write":6,"admin":7,"export":6,"delete":1}},"tool_security_inventory":[{"name":"summary","description":"Global stats for the Boolsai directory: how many sites are indexed, signal types covered, top vendors, most-changed companies. Use at the start of a session to ground what's available.","capabilities":["filesystem","secrets"],"risk_flags":["secret_material_access"],"risk_level":"medium","has_safeguards":false,"capability_taxonomy":["filesystem","secrets","search"]},{"name":"site_dossier","description":"Full intel dossier for a single domain: detected vendors grouped by category, account IDs (GTM, GA4, Klaviyo company_id, Shopify shop_id, Meta pixel, Sentry org, Tealium tenant, Stripe pk_live, etc.), brand identity (name, founder, city, employees, social handles), international markets, external host list, and likely operator-cluster siblings. Use for any 'what's running on X.com?' query.","capabilities":["read","exec","network"],"risk_flags":["command_execution","arbitrary_network_egress","freeform_input_surface"],"risk_level":"high","has_safeguards":false,"capability_taxonomy":["read","exec","network","development","database","finance"]},{"name":"sites_using_vendor","description":"List indexed sites detected using a specific vendor (e.g. 'klaviyo', 'yotpo', 'elevar', 'gorgias', 'rebuy'). Vendor slug is lowercase, underscore-separated. Returns domain list with brand names where known.","capabilities":["read"],"risk_flags":[],"risk_level":"low","has_safeguards":false,"capability_taxonomy":["read","development","search"]},{"name":"lookup_id","description":"Cross-reference any tenant-unique account ID across the index. Useful for 'who else shares this GTM container / Klaviyo company / Sentry org / Meta pixel ID?'. Signal types: gtm_container, ga4_measurement, ga_ua, klaviyo_company_id, meta_pixel_id, shopify_shopid, myshopify_slug, hotjar_id, intercom_app_id, hubspot_portal, klaviyo_subscriber, tiktok_pixel, stripe_pk_live, sentry_dsn_org, tealium_tenant, optimizely_project, mparticle_workspace, segment_writekey, abtasty_account, fullstory_org, pendo_account, intellimize_acct, webflow_site_id, dynamic_yield, wunderkind_site, elevar_id.","capabilities":["read","write","admin"],"risk_flags":["admin_mutation"],"risk_level":"medium","has_safeguards":false,"capability_taxonomy":["read","write","admin","search","productivity","web","finance"]},{"name":"brands_in_city","description":"List indexed brands that publish a physical address in a given city. Sourced from Schema.org Organization JSON-LD.","capabilities":["read","admin"],"risk_flags":[],"risk_level":"medium","has_safeguards":false,"capability_taxonomy":["read","admin","development","search"]},{"name":"brands_in_market","description":"List indexed brands explicitly serving a country market (via hreflang). Country is a 2-letter ISO code, lowercase.","capabilities":["read"],"risk_flags":[],"risk_level":"low","has_safeguards":false,"capability_taxonomy":["read","development","search"]},{"name":"stack_archetype","description":"List brands matching a stack archetype. Valid slugs: headless-shopify, classic-shopify-dtc, server-side-tagged, personalisation-heavy, pixel-stacked, multi-region, woocommerce-stores, magento-stores, bnpl-enabled, headless-cms.","capabilities":["read"],"risk_flags":[],"risk_level":"low","has_safeguards":false,"capability_taxonomy":["read","automation"]},{"name":"compare_sites","description":"Side-by-side stack comparison of 2-5 domains. Returns each site's vendors, account IDs, brand info, markets — and which signals are shared / unique per site. Good for 'compare X.com vs Y.com' or competitive teardowns.","capabilities":["network"],"risk_flags":["arbitrary_network_egress"],"risk_level":"medium","has_safeguards":false,"capability_taxonomy":["network"]},{"name":"similar_sites","description":"Find brands with similar stack archetypes to the given domain. Returns 'sites running similar tech' — useful for benchmarking, prospecting, competitor lookups.","capabilities":["read","exec","network"],"risk_flags":["command_execution","arbitrary_network_egress","freeform_input_surface"],"risk_level":"high","has_safeguards":false,"capability_taxonomy":["read","exec","network"]},{"name":"brands_by_founder","description":"List brands attributed to a founder (from Schema.org Organization markup). Useful for tracking serial DTC founders.","capabilities":["read","admin"],"risk_flags":[],"risk_level":"medium","has_safeguards":false,"capability_taxonomy":["read","admin"]},{"name":"bulk_export","description":"Paginated bulk export of indexed sites matching a filter. Returns up to 1000 rows per page in CSV or JSONL format with a cursor for continued pages. Use this when an agency needs an outbound prospect list (e.g. all sites using Klaviyo in the US) for CRM import. The full row count is also returned so you can size the export.","capabilities":["read","write","export"],"risk_flags":["bulk_data_access"],"risk_level":"medium","has_safeguards":true,"capability_taxonomy":["read","write","export","search","web"]},{"name":"compare_scans","description":"Compare two historical scans of the same URL to surface stack changes. Returns added/removed/changed vendors, account IDs, and inline-script signals between scan A and scan B. Use this for competitor watch — 'what did patagonia.com just deploy?'. If t1/t2 are omitted, compares oldest vs newest available scan.","capabilities":["write","delete","network"],"risk_flags":["destructive_operation","arbitrary_network_egress","freeform_input_surface"],"risk_level":"high","has_safeguards":false,"capability_taxonomy":["write","delete","network","cloud"]},{"name":"domain_intel","description":"Free DNS/WHOIS enrichment for a single domain. Returns: email host (Google Workspace / Microsoft 365 / etc. — derived from MX records), DNS provider (Cloudflare / Route 53 / GoDaddy / etc.), CDN provider, registrar, domain age (registered/expires). High-signal outbound data — 'they use Google Workspace + Cloudflare DNS + registered with GoDaddy' tells you a lot about org size + sophistication. Results cached 24h. Free — uses Cloudflare DoH + public RDAP.","capabilities":["network","admin"],"risk_flags":["arbitrary_network_egress","freeform_input_surface"],"risk_level":"medium","has_safeguards":false,"capability_taxonomy":["network","admin","communication","productivity","cloud"]},{"name":"find_similar_by_stack","description":"Find sites with the most-similar vendor stack to a given domain using Jaccard similarity over the full vendor set (not just archetype labels). Returns the top N matches with similarity scores. Use this when stack_archetype labels are too coarse and you want 'show me 20 brands running an almost-identical stack to liquiddeath.com'. More accurate than similar_sites for niche stacks.","capabilities":["write","exec","network","export"],"risk_flags":["command_execution","arbitrary_network_egress","bulk_data_access","freeform_input_surface"],"risk_level":"critical","has_safeguards":false,"capability_taxonomy":["write","exec","network","export"]},{"name":"bulk_export_url","description":"Returns a streaming-export URL for the same filter as bulk_export. Useful when the agency wants to pull 50K rows in one shot via curl/HTTP pipe instead of paginating the MCP. The URL is public, no auth, returns NDJSON or CSV with HTTP chunked-transfer streaming. Use bulk_export when N<1000; use this for bigger exports.","capabilities":["network","export"],"risk_flags":["arbitrary_network_egress","bulk_data_access"],"risk_level":"high","has_safeguards":false,"capability_taxonomy":["network","export","web","security"]},{"name":"operator_cluster","description":"Find every domain sharing a tenant-unique ID — the most powerful single signal in Boolsai. Given a Stripe pk_live key, Sentry DSN org, Klaviyo company_id, mParticle workspace, GTM container, GA4 measurement, Shopify shop_id, or other tenant ID, returns every domain we've seen using the SAME ID. This surfaces multi-brand operators, holding-company portfolios, sister brands sharing infrastructure, agency-managed clusters. No competitor (BuiltWith, Wappalyzer, etc.) can do this — they only see external hostnames, not the tenant-unique IDs leaked client-side. Use this when you want to discover the actual operator behind a brand, or expand a single brand into its full portfolio.","capabilities":["network","admin","export"],"risk_flags":["arbitrary_network_egress","bulk_data_access","freeform_input_surface"],"risk_level":"high","has_safeguards":false,"capability_taxonomy":["network","admin","export","search","productivity","finance"]},{"name":"subdomain_map","description":"Every subdomain of a given root domain we've ever scanned. Reveals storefront topology — where the checkout actually lives, regional storefronts, B2B portals, internal admin domains, asset CDNs. Output groups subdomains by their primary vendor where known. Use this to (a) find the right path to scan for an audit (sometimes the checkout is on us.checkout.brand.com not brand.com), (b) spot enterprise topology (multi-region Plus stores), (c) discover sister surfaces (community, ambassador, careers, etc).","capabilities":["write","filesystem","admin","export"],"risk_flags":["bulk_data_access","filesystem_mutation","admin_mutation"],"risk_level":"high","has_safeguards":false,"capability_taxonomy":["write","filesystem","admin","export","search","monitoring"]},{"name":"prospect_brief","description":"ONE-CALL PROSPECT BRIEF for agency outbound — runs four sub-queries against the live indexed data: (1) full dossier of the prospect's stack, (2) sister brands sharing tenant IDs (operator cluster), (3) 3-5 similar-stack competitors, (4) structured 'pitch angles' calling out concrete gaps an agency could pitch on (missing consent, no SST, outdated vendors, broken Schema.org, multiple GTM installs). Saves a strategist 20 min of manual cross-referencing per prospect. Use this whenever the user asks 'tell me about prospect.com'.","capabilities":["write","exec","network","admin"],"risk_flags":["command_execution","arbitrary_network_egress","freeform_input_surface","admin_mutation"],"risk_level":"critical","has_safeguards":false,"capability_taxonomy":["write","exec","network","admin","development","search"]},{"name":"directory_query","description":"Unified query against the Boolsai Directory. One tool to rule the other lookups. Pass any combination of: signal_type+signal_value, domain, market_country, archetype, founder, city. Returns matching sites + their key signals. Prefer this over the granular tools when you have multiple filter conditions to AND together.","capabilities":["read","network","filesystem","export"],"risk_flags":["arbitrary_network_egress","bulk_data_access","freeform_input_surface"],"risk_level":"high","has_safeguards":false,"capability_taxonomy":["read","network","filesystem","export","development","database"]}],"transport_compliance":{"status":"error","transport":"streamable-http","session_id_present":false,"protocol_header_present":false,"last_event_id_visible":false,"bad_protocol_status_code":200,"delete_status_code":null,"expired_session_status_code":null,"issues":["missing_session_id","missing_protocol_header","bad_protocol_not_rejected"]},"utility_coverage":{"status":"missing","completions":{"advertised":false,"sample_target":null,"live_probe":"not_executed"},"pagination":{"supported":false,"next_cursor_methods":[],"metadata_signal":false},"tasks":{"advertised":false,"probe_status":"missing","http_status":200},"initialize_capability_keys":["tools"]},"write_action_governance":{"status":"error","safe_to_publish":false,"auth_boundary":"public_or_unclear","blast_radius":"high","summary":{"tool_count":19,"high_risk_tools":9,"destructive_tools":1,"exec_tools":4,"egress_tools":10,"secret_tools":1,"bulk_access_tools":6,"risk_distribution":{"low":3,"medium":7,"high":7,"critical":2},"capability_distribution":{"filesystem":3,"secrets":1,"read":10,"exec":4,"network":10,"write":6,"admin":7,"export":6,"delete":1}},"high_risk_tools":[{"name":"site_dossier","risk_level":"high","risk_flags":["command_execution","arbitrary_network_egress","freeform_input_surface"],"has_safeguards":false},{"name":"similar_sites","risk_level":"high","risk_flags":["command_execution","arbitrary_network_egress","freeform_input_surface"],"has_safeguards":false},{"name":"compare_scans","risk_level":"high","risk_flags":["destructive_operation","arbitrary_network_egress","freeform_input_surface"],"has_safeguards":false},{"name":"find_similar_by_stack","risk_level":"critical","risk_flags":["command_execution","arbitrary_network_egress","bulk_data_access","freeform_input_surface"],"has_safeguards":false},{"name":"bulk_export_url","risk_level":"high","risk_flags":["arbitrary_network_egress","bulk_data_access"],"has_safeguards":false},{"name":"operator_cluster","risk_level":"high","risk_flags":["arbitrary_network_egress","bulk_data_access","freeform_input_surface"],"has_safeguards":false},{"name":"subdomain_map","risk_level":"high","risk_flags":["bulk_data_access","filesystem_mutation","admin_mutation"],"has_safeguards":false},{"name":"prospect_brief","risk_level":"critical","risk_flags":["command_execution","arbitrary_network_egress","freeform_input_surface","admin_mutation"],"has_safeguards":false},{"name":"directory_query","risk_level":"high","risk_flags":["arbitrary_network_egress","bulk_data_access","freeform_input_surface"],"has_safeguards":false}],"confirmation_signals":[],"safeguard_count":1},"provenance_divergence":{"status":"ok","direct_official_match":true,"drift_fields":[],"registry_title":null,"server_card_title":null,"registry_version":null,"server_card_version":null,"registry_homepage":null,"server_card_homepage":null},"alias_consolidation":{"canonical_identifier":"ai.boolsai/directory","duplicate_count":0,"registry_sources":["official_registry"],"registry_identifiers":["ai.boolsai/directory"],"remote_urls":["https://directory.boolsai.ai/mcp"],"homepages":[],"source_disagreements":[],"source_disagreement_details":{}},"alert_routing":{"active_watch_count":0,"route_counts":{"generic_webhook":0,"slack":0,"teams":0,"email":0},"destinations":[]},"authenticated_validation":{"latest_profile":"remote_mcp","authenticated_session_used":false,"public_score_remains_anonymous":true,"preview_endpoint":"/v1/verify","ci_preview_endpoint":"/v1/ci/preview"},"hosted_runtime":{"schema_version":"verify.hosted_runtime.v1","server":"ai.boolsai/directory","tier":"community","readiness":{"allowed_to_activate":false,"blockers":["score_below_hosting_threshold"],"score":67.57,"min_score":70.0,"freshness_hours":5.455095065,"max_freshness_hours":168.0,"latest_validation_run_id":"d5d33518-602b-46b0-9568-478aeda9e492"},"active_deployment_id":null,"active_endpoint_url":null,"deployments":[]},"action_controls_diff":{"snapshot_changed":false,"new_actions":[],"changed_actions":[],"disabled_by_default_candidates":[],"manual_review_candidates":[]},"benchmark_tasks":[{"key":"discover_tools","label":"Discover tools","status":"passes","evidence":[{"check":"initialize","status":"ok","source":"live_validation","note":null,"http_status":200},{"check":"tools_list","status":"ok","source":"live_validation","note":null,"http_status":200}]},{"key":"read_only_fetch_flow","label":"Read-only fetch flow","status":"degraded","evidence":[{"check":"resource_read","status":"missing","source":"live_validation","note":"resources/read is a strong read-path signal","http_status":null},{"check":"read_only_tool_surface","status":"ok","source":"derived_tool_inventory","note":"Low-risk read tools were inferred from the current tool surface.","http_status":null}]},{"key":"oauth_required_connect","label":"OAuth-required connect","status":"degraded","evidence":[{"check":"oauth_protected_resource","status":"error","source":"live_validation","note":null,"http_status":null},{"check":"step_up_auth_probe","status":"missing","source":"live_validation","note":null,"http_status":null}]},{"key":"safe_write_flow_with_confirmation","label":"Safe write flow with confirmation","status":"likely_to_fail","evidence":[{"check":"action_safety_probe","status":"error","source":"live_validation","note":null,"http_status":null}]}],"latest_capability_counts":{"tool_count":19,"prompt_count":0,"resource_count":0},"point_loss_breakdown":[{"key":"transport_compliance_score","label":"Transport Compliance","score":0.0,"max_score":4.0,"gap":4.0},{"key":"recovery_semantics_score","label":"Recovery Semantics","score":0.0,"max_score":4.0,"gap":4.0},{"key":"execution_sandbox_safety_score","label":"Execution Sandbox Safety","score":0.5,"max_score":4.0,"gap":3.5},{"key":"trust_confidence_score","label":"Trust Confidence","score":1.75,"max_score":4.0,"gap":2.25},{"key":"utility_coverage_score","label":"Utility Coverage","score":2.0,"max_score":4.0,"gap":2.0},{"key":"spec_recency_score","label":"Spec Recency","score":2.0,"max_score":4.0,"gap":2.0},{"key":"schema_completeness_score","label":"Schema Completeness","score":2.0,"max_score":4.0,"gap":2.0},{"key":"result_shape_stability_score","label":"Result Shape Stability","score":2.0,"max_score":4.0,"gap":2.0},{"key":"resource_contract_score","label":"Resource Contract","score":2.0,"max_score":4.0,"gap":2.0},{"key":"registry_consistency_score","label":"Registry Consistency","score":2.0,"max_score":4.0,"gap":2.0},{"key":"rate_limit_semantics_score","label":"Rate Limit Semantics","score":2.0,"max_score":4.0,"gap":2.0},{"key":"prompt_contract_score","label":"Prompt Contract","score":2.0,"max_score":4.0,"gap":2.0}],"verdict_traces":{"production_readiness":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use.","confidence":{"score":76.25,"label":"high"},"triggering_alerts":[],"winning_source":"live_validation"},"client_readiness":[{"key":"openai_connectors","status":"partial","reason":"OpenAI connectors expect OAuth for remote server auth.; Dynamic client registration materially improves connector setup.; Transport compliance should be in good shape.","triggering_checks":["initialize","tools_list","transport_compliance_probe","step_up_auth_probe","connector_replay_probe","request_association_probe"],"confidence":{"score":76.25,"label":"high"},"winning_source":"live_validation","conflicting_sources":[]},{"key":"claude_desktop","status":"ready","reason":"Transport behavior should match Claude-compatible HTTP expectations.","triggering_checks":["initialize","tools_list","transport_compliance_probe"],"confidence":{"score":76.25,"label":"high"},"winning_source":"live_validation","conflicting_sources":[]},{"key":"unsafe_for_write_actions","status":"yes","reason":"Blocked until safeguards and confirmation semantics are verified for write, exec, or destructive tools.","triggering_checks":["action_safety_probe"],"confidence":{"score":76.25,"label":"high"},"winning_source":"live_validation","conflicting_sources":[]},{"key":"snapshot_churn_risk","status":"low","reason":"No material tool-surface churn detected in the latest comparison.","triggering_checks":["tool_snapshot_probe","connector_replay_probe"],"confidence":{"score":76.25,"label":"high"},"winning_source":"history","conflicting_sources":[]}]},"current_snapshot":{"schema_version":"verify.trust_snapshot.v1","snapshot_id":"trustsnap_2242750e6ecf837e","generated_at":"2026-07-31T11:03:17.948550+00:00","source":"current_snapshot","server":"ai.boolsai/directory","last_validated_at":"2026-07-31T05:35:59.278239+00:00","validation_age_hours":5.46,"freshness":{"schema_version":"verify.freshness_profile.v1","last_validated_at":"2026-07-31T05:35:59.278239+00:00","age_hours":5.46,"bucket":"verified_last_24h","label":"Verified in last 24h","badges":["verified_last_24h"],"freshness_sla_hours":168.0,"freshness_sla_status":"met","stale_score_suppressed":false,"display_score":67.57,"raw_score":67.57,"confidence_score":76.2,"confidence_weighted_score":51.5,"tier_status":[{"tier":"community","label":"Community","freshness_sla_hours":720,"met":true,"priority_revalidation":false},{"tier":"pro","label":"Pro","freshness_sla_hours":168,"met":true,"priority_revalidation":true},{"tier":"enterprise","label":"Enterprise","freshness_sla_hours":24,"met":true,"priority_revalidation":true}]},"current_status":"healthy","current_score":67.57,"display_score":67.57,"stale_score_suppressed":false,"production_trust_decision":{"schema_version":"verify.executive_verdict.v1","decision":"Allow with approval","why":"exec-capable tools + no confirmation safeguards + high-risk tools need review","next_action":"export policy, require approval for writes, add authenticated validation","reason_count":2},"production_readiness_class":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use."},"evidence_confidence":{"score":76.25,"label":"high","validation_age_hours":5.46,"live_check_count":26},"active_alerts":[]},"trust_snapshot":{"schema_version":"verify.trust_snapshot.v1","snapshot_id":"trustsnap_2242750e6ecf837e","generated_at":"2026-07-31T11:03:17.948550+00:00","source":"current_snapshot","server":"ai.boolsai/directory","last_validated_at":"2026-07-31T05:35:59.278239+00:00","validation_age_hours":5.46,"freshness":{"schema_version":"verify.freshness_profile.v1","last_validated_at":"2026-07-31T05:35:59.278239+00:00","age_hours":5.46,"bucket":"verified_last_24h","label":"Verified in last 24h","badges":["verified_last_24h"],"freshness_sla_hours":168.0,"freshness_sla_status":"met","stale_score_suppressed":false,"display_score":67.57,"raw_score":67.57,"confidence_score":76.2,"confidence_weighted_score":51.5,"tier_status":[{"tier":"community","label":"Community","freshness_sla_hours":720,"met":true,"priority_revalidation":false},{"tier":"pro","label":"Pro","freshness_sla_hours":168,"met":true,"priority_revalidation":true},{"tier":"enterprise","label":"Enterprise","freshness_sla_hours":24,"met":true,"priority_revalidation":true}]},"current_status":"healthy","current_score":67.57,"display_score":67.57,"stale_score_suppressed":false,"production_trust_decision":{"schema_version":"verify.executive_verdict.v1","decision":"Allow with approval","why":"exec-capable tools + no confirmation safeguards + high-risk tools need review","next_action":"export policy, require approval for writes, add authenticated validation","reason_count":2},"production_readiness_class":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use."},"evidence_confidence":{"score":76.25,"label":"high","validation_age_hours":5.46,"live_check_count":26},"active_alerts":[]},"agent_commerce":{"status":"beta","commerce_signal":"weak","payment_execution_detected":"no","billing_or_usage_detected":"no","quote_or_pricing_detected":"no","numeric_price_context":"yes","commercial_quote_context":"no","checkout_or_charge_detected":"no","checkout_term_observed":"yes","payment_capable":"none","payment_rails":["Stripe"],"purchase_stage_supported":[],"human_confirmation_required":"unknown","spending_policy_supported":"yes","receipt_supported":"unknown","refund_policy_present":"unknown","operator_identity":"declared","auth_required":"no","auth_scheme":"none","tool_risk_level":"administrative","tool_risk_score":70,"pricing_transparency":"unknown","schema_change_detected":"unknown","delegation_level":"none","evidence_level":"inferred","confidence":"low","highest_risk_tools":[{"name":"subdomain_map","risk_level":"administrative"},{"name":"prospect_brief","risk_level":"administrative"}],"skipped_unsafe_tools":["compare_scans","bulk_export_url","operator_cluster","subdomain_map","prospect_brief","directory_query"],"last_checked_at":"2026-07-31T11:03:17.935535+00:00","evidence":[{"field":"commerce_signal","value":"weak","evidence_level":"inferred","source":"tool_schema","matched_terms":["checkout","limit","rate"],"sample":"bulk_export","confidence":"low","last_checked_at":"2026-07-31T11:03:17.935535+00:00"},{"field":"payment_rails","value":"Stripe","evidence_level":"inferred","source":"tool_schema","matched_terms":["stripe"],"sample":"Stripe","confidence":"medium","last_checked_at":"2026-07-31T11:03:17.935535+00:00"}],"disclaimer":"Beta assessment. Verify detects evidence and risk signals but does not certify that this server is safe for autonomous purchases.","scores":{"auth_posture_score":10,"tool_risk_score":70,"payment_readiness_score":10,"agent_delegation_safety_score":50,"overall_agent_commerce_score":null},"warnings":[],"recommended_fixes":[]},"latest_claim":null,"maintainer_profile_slug":null,"watch_summary":{"count":0,"teams":[],"emails":[]}},"latest_validation":{"id":"d5d33518-602b-46b0-9568-478aeda9e492","validation_profile":"remote_mcp","status":"completed","summary_status":"healthy","transport_type":"streamable-http","latency_ms":490.77,"failures":{"server_card":{"url":"https://directory.boolsai.ai/.well-known/mcp/server-card.json","error":"Client error '404 Not Found' for url 'https://directory.boolsai.ai/.well-known/mcp/server-card.json'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"},"oauth_protected_resource":{"url":"https://directory.boolsai.ai/.well-known/oauth-protected-resource","error":"Client error '404 Not Found' for url 'https://directory.boolsai.ai/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"},"oauth_authorization_server":{"reason":"no_authorization_server"},"openid_configuration":{"reason":"no_authorization_server"},"transport_compliance_probe":{"transport":"streamable-http","session_id_present":false,"protocol_header_present":false,"last_event_id_visible":false,"requested_protocol_version":"2025-03-26","bad_protocol_status_code":200,"bad_protocol_payload":{"jsonrpc":"2.0","id":410,"result":{"tools":[{"name":"summary","description":"Global stats for the Boolsai directory: how many sites are indexed, signal types covered, top vendors, most-changed companies. Use at the start of a session to ground what's available.","inputSchema":{"type":"object","properties":{}}},{"name":"site_dossier","description":"Full intel dossier for a single domain: detected vendors grouped by category, account IDs (GTM, GA4, Klaviyo company_id, Shopify shop_id, Meta pixel, Sentry org, Tealium tenant, Stripe pk_live, etc.), brand identity (name, founder, city, employees, social handles), international markets, external host list, and likely operator-cluster siblings. Use for any 'what's running on X.com?' query.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Domain or URL, e.g. 'gymshark.com' or 'https://gymshark.com/'"}},"required":["url"]}},{"name":"sites_using_vendor","description":"List indexed sites detected using a specific vendor (e.g. 'klaviyo', 'yotpo', 'elevar', 'gorgias', 'rebuy'). Vendor slug is lowercase, underscore-separated. Returns domain list with brand names where known.","inputSchema":{"type":"object","properties":{"vendor":{"type":"string","description":"Vendor slug, e.g. 'klaviyo', 'shopify', 'webflow', 'onetrust'."}},"required":["vendor"]}},{"name":"lookup_id","description":"Cross-reference any tenant-unique account ID across the index. Useful for 'who else shares this GTM container / Klaviyo company / Sentry org / Meta pixel ID?'. Signal types: gtm_container, ga4_measurement, ga_ua, klaviyo_company_id, meta_pixel_id, shopify_shopid, myshopify_slug, hotjar_id, intercom_app_id, hubspot_portal, klaviyo_subscriber, tiktok_pixel, stripe_pk_live, sentry_dsn_org, tealium_tenant, optimizely_project, mparticle_workspace, segment_writekey, abtasty_account, fullstory_org, pendo_account, intellimize_acct, webflow_site_id, dynamic_yield, wunderkind_site, elevar_id.","inputSchema":{"type":"object","properties":{"signal_type":{"type":"string","description":"e.g. 'gtm_container', 'klaviyo_company_id', 'sentry_dsn_org'"},"signal_value":{"type":"string","description":"the actual ID/value, e.g. 'GTM-XYZABC', 'H2zzaR'"}},"required":["signal_type","signal_value"]}},{"name":"brands_in_city","description":"List indexed brands that publish a physical address in a given city. Sourced from Schema.org Organization JSON-LD.","inputSchema":{"type":"object","properties":{"city":{"type":"string","description":"City name, e.g. 'Los Angeles', 'New York', 'Berlin'"}},"required":["city"]}},{"name":"brands_in_market","description":"List indexed brands explicitly serving a country market (via hreflang). Country is a 2-letter ISO code, lowercase.","inputSchema":{"type":"object","properties":{"country":{"type":"string","description":"2-letter country code, e.g. 'us', 'gb', 'de', 'fr'"}},"required":["country"]}},{"name":"stack_archetype","description":"List brands matching a stack archetype. Valid slugs: headless-shopify, classic-shopify-dtc, server-side-tagged, personalisation-heavy, pixel-stacked, multi-region, woocommerce-stores, magento-stores, bnpl-enabled, headless-cms.","inputSchema":{"type":"object","properties":{"archetype":{"type":"string","description":"Archetype slug"}},"required":["archetype"]}},{"name":"compare_sites","description":"Side-by-side stack comparison of 2-5 domains. Returns each site's vendors, account IDs, brand info, markets — and which signals are shared / unique per site. Good for 'compare X.com vs Y.com' or competitive teardowns.","inputSchema":{"type":"object","properties":{"urls":{"type":"array","items":{"type":"string"},"description":"2-5 domain/URL strings"}},"required":["urls"]}},{"name":"similar_sites","description":"Find brands with similar stack archetypes to the given domain. Returns 'sites running similar tech' — useful for benchmarking, prospecting, competitor lookups.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Domain to find similar sites for"}},"required":["url"]}},{"name":"brands_by_founder","description":"List brands attributed to a founder (from Schema.org Organization markup). Useful for tracking serial DTC founders.","inputSchema":{"type":"object","properties":{"founder":{"type":"string","description":"Founder name (case-insensitive)"}},"required":["founder"]}},{"name":"bulk_export","description":"Paginated bulk export of indexed sites matching a filter. Returns up to 1000 rows per page in CSV or JSONL format with a cursor for continued pages. Use this when an agency needs an outbound prospect list (e.g. all sites using Klaviyo in the US) for CRM import. The full row count is also returned so you can size the export.","inputSchema":{"type":"object","properties":{"signal_type":{"type":"string","description":"Required. e.g. 'vendor', 'klaviyo_company_id', 'shopify_shopid', 'market_country', 'org_country'. Use list_signal_types via Boolsai Grep to discover."},"signal_value":{"type":"string","description":"Optional exact value to filter. If omitted returns ANY value of this signal_type."},"market_country":{"type":"string","description":"Optional ISO-2 country code (e.g. 'us', 'au') to intersect with hreflang market data"},"format":{"type":"string","enum":["csv","jsonl","json"],"default":"csv","description":"Output format. CSV is best for CRM import."},"cursor":{"type":"string","description":"Opaque cursor from previous page; pass to get next 1000 rows"},"limit":{"type":"integer","default":1000,"description":"Max rows per page (default 1000, max 5000)"}},"required":["signal_type"]}},{"name":"compare_scans","description":"Compare two historical scans of the same URL to surface stack changes. Returns added/removed/changed vendors, account IDs, and inline-script signals between scan A and scan B. Use this for competitor watch — 'what did patagonia.com just deploy?'. If t1/t2 are omitted, compares oldest vs newest available scan.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Domain or full URL to compare"},"t1":{"type":"string","description":"Optional ISO timestamp of first scan (oldest if omitted)"},"t2":{"type":"string","description":"Optional ISO timestamp of second scan (newest if omitted)"}},"required":["url"]}},{"name":"domain_intel","description":"Free DNS/WHOIS enrichment for a single domain. Returns: email host (Google Workspace / Microsoft 365 / etc. — derived from MX records), DNS provider (Cloudflare / Route 53 / GoDaddy / etc.), CDN provider, registrar, domain age (registered/expires). High-signal outbound data — 'they use Google Workspace + Cloudflare DNS + registered with GoDaddy' tells you a lot about org size + sophistication. Results cached 24h. Free — uses Cloudflare DoH + public RDAP.","inputSchema":{"type":"object","properties":{"domain":{"type":"string","description":"Domain to enrich (apex or any subdomain)"}},"required":["domain"]}},{"name":"find_similar_by_stack","description":"Find sites with the most-similar vendor stack to a given domain using Jaccard similarity over the full vendor set (not just archetype labels). Returns the top N matches with similarity scores. Use this when stack_archetype labels are too coarse and you want 'show me 20 brands running an almost-identical stack to liquiddeath.com'. More accurate than similar_sites for niche stacks.","inputSchema":{"type":"object","properties":{"domain":{"type":"string","description":"Reference domain"},"limit":{"type":"integer","default":20,"description":"max similar sites (1-100)"},"min_shared":{"type":"integer","default":3,"description":"Minimum shared distinctive vendors required to be considered (default 3)"}},"required":["domain"]}},{"name":"bulk_export_url","description":"Returns a streaming-export URL for the same filter as bulk_export. Useful when the agency wants to pull 50K rows in one shot via curl/HTTP pipe instead of paginating the MCP. The URL is public, no auth, returns NDJSON or CSV with HTTP chunked-transfer streaming. Use bulk_export when N<1000; use this for bigger exports.","inputSchema":{"type":"object","properties":{"signal_type":{"type":"string","description":"Required signal_type"},"signal_value":{"type":"string","description":"Optional exact value"},"market_country":{"type":"string","description":"Optional ISO-2 country"},"format":{"type":"string","enum":["ndjson","csv"],"default":"ndjson"}},"required":["signal_type"]}},{"name":"operator_cluster","description":"Find every domain sharing a tenant-unique ID — the most powerful single signal in Boolsai. Given a Stripe pk_live key, Sentry DSN org, Klaviyo company_id, mParticle workspace, GTM container, GA4 measurement, Shopify shop_id, or other tenant ID, returns every domain we've seen using the SAME ID. This surfaces multi-brand operators, holding-company portfolios, sister brands sharing infrastructure, agency-managed clusters. No competitor (BuiltWith, Wappalyzer, etc.) can do this — they only see external hostnames, not the tenant-unique IDs leaked client-side. Use this when you want to discover the actual operator behind a brand, or expand a single brand into its full portfolio.","inputSchema":{"type":"object","properties":{"id":{"type":"string","description":"The tenant ID itself (e.g. 'pk_live_abc...', 'GTM-M8TQZPX', 'o307020' for Sentry, '12345678' for Shopify shop_id). signal_type is auto-detected."},"signal_type":{"type":"string","description":"Optional explicit signal_type if auto-detect could be ambiguous (e.g. 'stripe_pk_live', 'sentry_dsn_org')."},"domain":{"type":"string","description":"Alternative: pass a domain and we'll return every cluster this domain belongs to (all tenant IDs and their fellow domains)."},"limit":{"type":"integer","default":100,"description":"max sites per cluster (1-500)"}}}},{"name":"subdomain_map","description":"Every subdomain of a given root domain we've ever scanned. Reveals storefront topology — where the checkout actually lives, regional storefronts, B2B portals, internal admin domains, asset CDNs. Output groups subdomains by their primary vendor where known. Use this to (a) find the right path to scan for an audit (sometimes the checkout is on us.checkout.brand.com not brand.com), (b) spot enterprise topology (multi-region Plus stores), (c) discover sister surfaces (community, ambassador, careers, etc).","inputSchema":{"type":"object","properties":{"root":{"type":"string","description":"Root domain (e.g. 'gymshark.com'). Pass just the apex; we'll find subdomains automatically."},"limit":{"type":"integer","default":200,"description":"max subdomains returned (1-1000)"}},"required":["root"]}},{"name":"prospect_brief","description":"ONE-CALL PROSPECT BRIEF for agency outbound — runs four sub-queries against the live indexed data: (1) full dossier of the prospect's stack, (2) sister brands sharing tenant IDs (operator cluster), (3) 3-5 similar-stack competitors, (4) structured 'pitch angles' calling out concrete gaps an agency could pitch on (missing consent, no SST, outdated vendors, broken Schema.org, multiple GTM installs). Saves a strategist 20 min of manual cross-referencing per prospect. Use this whenever the user asks 'tell me about prospect.com'.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Domain or URL of the prospect"},"angle":{"type":"string","description":"Optional agency pitch angle to tune the brief: 'cro', 'analytics', 'consent', 'sst' (server-side tagging), 'headless', 'consolidation'. If omitted, returns all angles found."}},"required":["url"]}},{"name":"directory_query","description":"Unified query against the Boolsai Directory. One tool to rule the other lookups. Pass any combination of: signal_type+signal_value, domain, market_country, archetype, founder, city. Returns matching sites + their key signals. Prefer this over the granular tools when you have multiple filter conditions to AND together.","inputSchema":{"type":"object","properties":{"signal_type":{"type":"string","description":"e.g. 'vendor', 'shopify_shopid'"},"signal_value":{"type":"string","description":"exact signal value"},"domain":{"type":"string","description":"exact domain match (e.g. 'gymshark.com')"},"market_country":{"type":"string","description":"ISO-2 (e.g. 'us')"},"archetype":{"type":"string","description":"e.g. 'headless-shopify', 'woocommerce-stores'"},"founder":{"type":"string","description":"case-insensitive substring"},"city":{"type":"string","description":"case-insensitive city name"},"limit":{"type":"integer","default":50,"description":"max rows (1-500)"}}}}]}},"bad_protocol_headers":{"content-type":"application/json"},"bad_protocol_error":null,"delete_status_code":null,"delete_error":null,"expired_session_status_code":null,"expired_session_error":null,"issues":["missing_session_id","missing_protocol_header","bad_protocol_not_rejected"]}},"checks":{"server_card":{"status":"error","latency_ms":69.87,"details":{"url":"https://directory.boolsai.ai/.well-known/mcp/server-card.json","error":"Client error '404 Not Found' for url 'https://directory.boolsai.ai/.well-known/mcp/server-card.json'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"}},"oauth_protected_resource":{"status":"error","latency_ms":75.27,"details":{"url":"https://directory.boolsai.ai/.well-known/oauth-protected-resource","error":"Client error '404 Not Found' for url 'https://directory.boolsai.ai/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404"}},"oauth_authorization_server":{"status":"missing","latency_ms":null,"details":{"reason":"no_authorization_server"}},"openid_configuration":{"status":"missing","latency_ms":null,"details":{"reason":"no_authorization_server"}},"initialize":{"status":"ok","latency_ms":78.2,"details":{"url":"https://directory.boolsai.ai/mcp","payload":{"jsonrpc":"2.0","id":1,"result":{"protocolVersion":"2025-03-26","capabilities":{"tools":{"listChanged":false}},"serverInfo":{"name":"boolsai-directory","title":"Boolsai Directory","version":"1.0.0"},"instructions":"You are connected to **Boolsai Directory** — one of three MCP servers in the Boolsai suite. ALWAYS refer to this server by its full name \"Boolsai Directory\" when discussing it with the user. Do not shorten to \"Boolsai\", \"directory\", \"the MCP\", \"Directory MCP\", etc. Sister servers in the suite (cross-discovery only — not connected here) are \"Boolsai Scan\" (https://boolsai.ai/mcp) and \"Boolsai Grep\" (https://grep.boolsai.ai/mcp); refer to those by their full names too if they come up.\n\nBoolsai Directory · MCP for live ecommerce stack intelligence.\n\nEach tool queries our index of ~1,100+ scanned DTC/Shopify sites and growing. Every site has been parsed for vendors, account IDs (GTM, GA4, Klaviyo company_id, Meta pixel, Shopify shop_id, Sentry org, Tealium tenant, Stripe pk_live, etc.), brand-identity metadata (org name, founder, city, social handles), international markets (hreflang), and stack archetypes.\n\nPick the right tool for the question:\n- \"what's running on X.com?\" → site_dossier\n- \"who uses Klaviyo / Yotpo / Elevar?\" → sites_using_vendor\n- \"who shares this GTM / GA4 / Klaviyo id?\" → lookup_id (cross-reference, often reveals shared operators)\n- \"DTC brands in <city>\" → brands_in_city\n- \"brands selling in <country>\" → brands_in_market\n- \"headless shopify / server-side-tagged / classic-DTC stores\" → stack_archetype\n- \"compare X.com vs Y.com\" → compare_sites\n- \"find competitors / similar stores to X.com\" → similar_sites\n- \"what brands does this founder have?\" → brands_by_founder\n- \"global stats / what's in the index?\" → summary\n\nTenant-IDs are uniquely owned per Klaviyo/Stripe/Sentry/etc. account — same id across two domains usually means same operator. Cross-reference via lookup_id is the strongest same-operator signal.\n\nConversational handoff: every tool response ends with \"Next moves\" — natural follow-up suggestions. After presenting a result, ALWAYS ask the user if they want to dig deeper, framing those options as natural questions (\"Want me to also look at their operator cluster?\" / \"Should I compare this brand to a similar one?\"). Do not name tool functions to the user — offer the action."}},"http_status":200,"headers":{"content-type":"application/json"}}},"protocol_version_probe":{"status":"warning","latency_ms":null,"details":{"claimed_version":"2025-03-26","validator_protocol_version":"2025-03-26","latest_known_version":"2025-11-25","releases_behind":2,"lag_days":244}},"tools_list":{"status":"ok","latency_ms":33.83,"details":{"url":"https://directory.boolsai.ai/mcp","payload":{"jsonrpc":"2.0","id":2,"result":{"tools":[{"name":"summary","description":"Global stats for the Boolsai directory: how many sites are indexed, signal types covered, top vendors, most-changed companies. Use at the start of a session to ground what's available.","inputSchema":{"type":"object","properties":{}}},{"name":"site_dossier","description":"Full intel dossier for a single domain: detected vendors grouped by category, account IDs (GTM, GA4, Klaviyo company_id, Shopify shop_id, Meta pixel, Sentry org, Tealium tenant, Stripe pk_live, etc.), brand identity (name, founder, city, employees, social handles), international markets, external host list, and likely operator-cluster siblings. Use for any 'what's running on X.com?' query.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Domain or URL, e.g. 'gymshark.com' or 'https://gymshark.com/'"}},"required":["url"]}},{"name":"sites_using_vendor","description":"List indexed sites detected using a specific vendor (e.g. 'klaviyo', 'yotpo', 'elevar', 'gorgias', 'rebuy'). Vendor slug is lowercase, underscore-separated. Returns domain list with brand names where known.","inputSchema":{"type":"object","properties":{"vendor":{"type":"string","description":"Vendor slug, e.g. 'klaviyo', 'shopify', 'webflow', 'onetrust'."}},"required":["vendor"]}},{"name":"lookup_id","description":"Cross-reference any tenant-unique account ID across the index. Useful for 'who else shares this GTM container / Klaviyo company / Sentry org / Meta pixel ID?'. Signal types: gtm_container, ga4_measurement, ga_ua, klaviyo_company_id, meta_pixel_id, shopify_shopid, myshopify_slug, hotjar_id, intercom_app_id, hubspot_portal, klaviyo_subscriber, tiktok_pixel, stripe_pk_live, sentry_dsn_org, tealium_tenant, optimizely_project, mparticle_workspace, segment_writekey, abtasty_account, fullstory_org, pendo_account, intellimize_acct, webflow_site_id, dynamic_yield, wunderkind_site, elevar_id.","inputSchema":{"type":"object","properties":{"signal_type":{"type":"string","description":"e.g. 'gtm_container', 'klaviyo_company_id', 'sentry_dsn_org'"},"signal_value":{"type":"string","description":"the actual ID/value, e.g. 'GTM-XYZABC', 'H2zzaR'"}},"required":["signal_type","signal_value"]}},{"name":"brands_in_city","description":"List indexed brands that publish a physical address in a given city. Sourced from Schema.org Organization JSON-LD.","inputSchema":{"type":"object","properties":{"city":{"type":"string","description":"City name, e.g. 'Los Angeles', 'New York', 'Berlin'"}},"required":["city"]}},{"name":"brands_in_market","description":"List indexed brands explicitly serving a country market (via hreflang). Country is a 2-letter ISO code, lowercase.","inputSchema":{"type":"object","properties":{"country":{"type":"string","description":"2-letter country code, e.g. 'us', 'gb', 'de', 'fr'"}},"required":["country"]}},{"name":"stack_archetype","description":"List brands matching a stack archetype. Valid slugs: headless-shopify, classic-shopify-dtc, server-side-tagged, personalisation-heavy, pixel-stacked, multi-region, woocommerce-stores, magento-stores, bnpl-enabled, headless-cms.","inputSchema":{"type":"object","properties":{"archetype":{"type":"string","description":"Archetype slug"}},"required":["archetype"]}},{"name":"compare_sites","description":"Side-by-side stack comparison of 2-5 domains. Returns each site's vendors, account IDs, brand info, markets — and which signals are shared / unique per site. Good for 'compare X.com vs Y.com' or competitive teardowns.","inputSchema":{"type":"object","properties":{"urls":{"type":"array","items":{"type":"string"},"description":"2-5 domain/URL strings"}},"required":["urls"]}},{"name":"similar_sites","description":"Find brands with similar stack archetypes to the given domain. Returns 'sites running similar tech' — useful for benchmarking, prospecting, competitor lookups.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Domain to find similar sites for"}},"required":["url"]}},{"name":"brands_by_founder","description":"List brands attributed to a founder (from Schema.org Organization markup). Useful for tracking serial DTC founders.","inputSchema":{"type":"object","properties":{"founder":{"type":"string","description":"Founder name (case-insensitive)"}},"required":["founder"]}},{"name":"bulk_export","description":"Paginated bulk export of indexed sites matching a filter. Returns up to 1000 rows per page in CSV or JSONL format with a cursor for continued pages. Use this when an agency needs an outbound prospect list (e.g. all sites using Klaviyo in the US) for CRM import. The full row count is also returned so you can size the export.","inputSchema":{"type":"object","properties":{"signal_type":{"type":"string","description":"Required. e.g. 'vendor', 'klaviyo_company_id', 'shopify_shopid', 'market_country', 'org_country'. Use list_signal_types via Boolsai Grep to discover."},"signal_value":{"type":"string","description":"Optional exact value to filter. If omitted returns ANY value of this signal_type."},"market_country":{"type":"string","description":"Optional ISO-2 country code (e.g. 'us', 'au') to intersect with hreflang market data"},"format":{"type":"string","enum":["csv","jsonl","json"],"default":"csv","description":"Output format. CSV is best for CRM import."},"cursor":{"type":"string","description":"Opaque cursor from previous page; pass to get next 1000 rows"},"limit":{"type":"integer","default":1000,"description":"Max rows per page (default 1000, max 5000)"}},"required":["signal_type"]}},{"name":"compare_scans","description":"Compare two historical scans of the same URL to surface stack changes. Returns added/removed/changed vendors, account IDs, and inline-script signals between scan A and scan B. Use this for competitor watch — 'what did patagonia.com just deploy?'. If t1/t2 are omitted, compares oldest vs newest available scan.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Domain or full URL to compare"},"t1":{"type":"string","description":"Optional ISO timestamp of first scan (oldest if omitted)"},"t2":{"type":"string","description":"Optional ISO timestamp of second scan (newest if omitted)"}},"required":["url"]}},{"name":"domain_intel","description":"Free DNS/WHOIS enrichment for a single domain. Returns: email host (Google Workspace / Microsoft 365 / etc. — derived from MX records), DNS provider (Cloudflare / Route 53 / GoDaddy / etc.), CDN provider, registrar, domain age (registered/expires). High-signal outbound data — 'they use Google Workspace + Cloudflare DNS + registered with GoDaddy' tells you a lot about org size + sophistication. Results cached 24h. Free — uses Cloudflare DoH + public RDAP.","inputSchema":{"type":"object","properties":{"domain":{"type":"string","description":"Domain to enrich (apex or any subdomain)"}},"required":["domain"]}},{"name":"find_similar_by_stack","description":"Find sites with the most-similar vendor stack to a given domain using Jaccard similarity over the full vendor set (not just archetype labels). Returns the top N matches with similarity scores. Use this when stack_archetype labels are too coarse and you want 'show me 20 brands running an almost-identical stack to liquiddeath.com'. More accurate than similar_sites for niche stacks.","inputSchema":{"type":"object","properties":{"domain":{"type":"string","description":"Reference domain"},"limit":{"type":"integer","default":20,"description":"max similar sites (1-100)"},"min_shared":{"type":"integer","default":3,"description":"Minimum shared distinctive vendors required to be considered (default 3)"}},"required":["domain"]}},{"name":"bulk_export_url","description":"Returns a streaming-export URL for the same filter as bulk_export. Useful when the agency wants to pull 50K rows in one shot via curl/HTTP pipe instead of paginating the MCP. The URL is public, no auth, returns NDJSON or CSV with HTTP chunked-transfer streaming. Use bulk_export when N<1000; use this for bigger exports.","inputSchema":{"type":"object","properties":{"signal_type":{"type":"string","description":"Required signal_type"},"signal_value":{"type":"string","description":"Optional exact value"},"market_country":{"type":"string","description":"Optional ISO-2 country"},"format":{"type":"string","enum":["ndjson","csv"],"default":"ndjson"}},"required":["signal_type"]}},{"name":"operator_cluster","description":"Find every domain sharing a tenant-unique ID — the most powerful single signal in Boolsai. Given a Stripe pk_live key, Sentry DSN org, Klaviyo company_id, mParticle workspace, GTM container, GA4 measurement, Shopify shop_id, or other tenant ID, returns every domain we've seen using the SAME ID. This surfaces multi-brand operators, holding-company portfolios, sister brands sharing infrastructure, agency-managed clusters. No competitor (BuiltWith, Wappalyzer, etc.) can do this — they only see external hostnames, not the tenant-unique IDs leaked client-side. Use this when you want to discover the actual operator behind a brand, or expand a single brand into its full portfolio.","inputSchema":{"type":"object","properties":{"id":{"type":"string","description":"The tenant ID itself (e.g. 'pk_live_abc...', 'GTM-M8TQZPX', 'o307020' for Sentry, '12345678' for Shopify shop_id). signal_type is auto-detected."},"signal_type":{"type":"string","description":"Optional explicit signal_type if auto-detect could be ambiguous (e.g. 'stripe_pk_live', 'sentry_dsn_org')."},"domain":{"type":"string","description":"Alternative: pass a domain and we'll return every cluster this domain belongs to (all tenant IDs and their fellow domains)."},"limit":{"type":"integer","default":100,"description":"max sites per cluster (1-500)"}}}},{"name":"subdomain_map","description":"Every subdomain of a given root domain we've ever scanned. Reveals storefront topology — where the checkout actually lives, regional storefronts, B2B portals, internal admin domains, asset CDNs. Output groups subdomains by their primary vendor where known. Use this to (a) find the right path to scan for an audit (sometimes the checkout is on us.checkout.brand.com not brand.com), (b) spot enterprise topology (multi-region Plus stores), (c) discover sister surfaces (community, ambassador, careers, etc).","inputSchema":{"type":"object","properties":{"root":{"type":"string","description":"Root domain (e.g. 'gymshark.com'). Pass just the apex; we'll find subdomains automatically."},"limit":{"type":"integer","default":200,"description":"max subdomains returned (1-1000)"}},"required":["root"]}},{"name":"prospect_brief","description":"ONE-CALL PROSPECT BRIEF for agency outbound — runs four sub-queries against the live indexed data: (1) full dossier of the prospect's stack, (2) sister brands sharing tenant IDs (operator cluster), (3) 3-5 similar-stack competitors, (4) structured 'pitch angles' calling out concrete gaps an agency could pitch on (missing consent, no SST, outdated vendors, broken Schema.org, multiple GTM installs). Saves a strategist 20 min of manual cross-referencing per prospect. Use this whenever the user asks 'tell me about prospect.com'.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Domain or URL of the prospect"},"angle":{"type":"string","description":"Optional agency pitch angle to tune the brief: 'cro', 'analytics', 'consent', 'sst' (server-side tagging), 'headless', 'consolidation'. If omitted, returns all angles found."}},"required":["url"]}},{"name":"directory_query","description":"Unified query against the Boolsai Directory. One tool to rule the other lookups. Pass any combination of: signal_type+signal_value, domain, market_country, archetype, founder, city. Returns matching sites + their key signals. Prefer this over the granular tools when you have multiple filter conditions to AND together.","inputSchema":{"type":"object","properties":{"signal_type":{"type":"string","description":"e.g. 'vendor', 'shopify_shopid'"},"signal_value":{"type":"string","description":"exact signal value"},"domain":{"type":"string","description":"exact domain match (e.g. 'gymshark.com')"},"market_country":{"type":"string","description":"ISO-2 (e.g. 'us')"},"archetype":{"type":"string","description":"e.g. 'headless-shopify', 'woocommerce-stores'"},"founder":{"type":"string","description":"case-insensitive substring"},"city":{"type":"string","description":"case-insensitive city name"},"limit":{"type":"integer","default":50,"description":"max rows (1-500)"}}}}]}},"http_status":200,"headers":{"content-type":"application/json"}}},"prompts_list":{"status":"missing","latency_ms":32.21,"details":{"url":"https://directory.boolsai.ai/mcp","payload":{"jsonrpc":"2.0","id":3,"error":{"code":-32601,"message":"Method not found: prompts/list"}},"http_status":200,"headers":{"content-type":"application/json"},"reason":"not_supported"}},"prompt_get":{"status":"missing","latency_ms":null,"details":{"reason":"not_advertised"}},"resources_list":{"status":"missing","latency_ms":31.93,"details":{"url":"https://directory.boolsai.ai/mcp","payload":{"jsonrpc":"2.0","id":5,"error":{"code":-32601,"message":"Method not found: resources/list"}},"http_status":200,"headers":{"content-type":"application/json"},"reason":"not_supported"}},"resource_read":{"status":"missing","latency_ms":null,"details":{"reason":"not_advertised"}},"probe_noise_resilience":{"status":"ok","latency_ms":30.44,"details":{"url":"https://directory.boolsai.ai/robots.txt","http_status":200,"headers":{"content-type":"text/plain; charset=utf-8"}}},"determinism_probe":{"status":"ok","latency_ms":31.7,"details":{"attempts":2,"successful":2,"matches":2,"stable_ratio":1.0,"baseline_signature":"51d299e210b4ded3a7c6f94697e24e19b739755a742646a114ca01b5034e8e85","errors":[]}},"session_resume_probe":{"status":"warning","latency_ms":null,"details":{"reason":"no_session_id","transport":"streamable-http","resume_expected":true,"protocol_version":"2025-03-26"}},"step_up_auth_probe":{"status":"missing","latency_ms":null,"details":{"oauth_present":false,"auth_required_checks":[],"supported_scopes":[],"scope_specificity_ratio":0.0,"broad_scopes":[],"challenge_headers":[],"step_up_signals":[],"minimal_scope_documented":false}},"transport_compliance_probe":{"status":"error","latency_ms":34.84,"details":{"transport":"streamable-http","session_id_present":false,"protocol_header_present":false,"last_event_id_visible":false,"requested_protocol_version":"2025-03-26","bad_protocol_status_code":200,"bad_protocol_payload":{"jsonrpc":"2.0","id":410,"result":{"tools":[{"name":"summary","description":"Global stats for the Boolsai directory: how many sites are indexed, signal types covered, top vendors, most-changed companies. Use at the start of a session to ground what's available.","inputSchema":{"type":"object","properties":{}}},{"name":"site_dossier","description":"Full intel dossier for a single domain: detected vendors grouped by category, account IDs (GTM, GA4, Klaviyo company_id, Shopify shop_id, Meta pixel, Sentry org, Tealium tenant, Stripe pk_live, etc.), brand identity (name, founder, city, employees, social handles), international markets, external host list, and likely operator-cluster siblings. Use for any 'what's running on X.com?' query.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Domain or URL, e.g. 'gymshark.com' or 'https://gymshark.com/'"}},"required":["url"]}},{"name":"sites_using_vendor","description":"List indexed sites detected using a specific vendor (e.g. 'klaviyo', 'yotpo', 'elevar', 'gorgias', 'rebuy'). Vendor slug is lowercase, underscore-separated. Returns domain list with brand names where known.","inputSchema":{"type":"object","properties":{"vendor":{"type":"string","description":"Vendor slug, e.g. 'klaviyo', 'shopify', 'webflow', 'onetrust'."}},"required":["vendor"]}},{"name":"lookup_id","description":"Cross-reference any tenant-unique account ID across the index. Useful for 'who else shares this GTM container / Klaviyo company / Sentry org / Meta pixel ID?'. Signal types: gtm_container, ga4_measurement, ga_ua, klaviyo_company_id, meta_pixel_id, shopify_shopid, myshopify_slug, hotjar_id, intercom_app_id, hubspot_portal, klaviyo_subscriber, tiktok_pixel, stripe_pk_live, sentry_dsn_org, tealium_tenant, optimizely_project, mparticle_workspace, segment_writekey, abtasty_account, fullstory_org, pendo_account, intellimize_acct, webflow_site_id, dynamic_yield, wunderkind_site, elevar_id.","inputSchema":{"type":"object","properties":{"signal_type":{"type":"string","description":"e.g. 'gtm_container', 'klaviyo_company_id', 'sentry_dsn_org'"},"signal_value":{"type":"string","description":"the actual ID/value, e.g. 'GTM-XYZABC', 'H2zzaR'"}},"required":["signal_type","signal_value"]}},{"name":"brands_in_city","description":"List indexed brands that publish a physical address in a given city. Sourced from Schema.org Organization JSON-LD.","inputSchema":{"type":"object","properties":{"city":{"type":"string","description":"City name, e.g. 'Los Angeles', 'New York', 'Berlin'"}},"required":["city"]}},{"name":"brands_in_market","description":"List indexed brands explicitly serving a country market (via hreflang). Country is a 2-letter ISO code, lowercase.","inputSchema":{"type":"object","properties":{"country":{"type":"string","description":"2-letter country code, e.g. 'us', 'gb', 'de', 'fr'"}},"required":["country"]}},{"name":"stack_archetype","description":"List brands matching a stack archetype. Valid slugs: headless-shopify, classic-shopify-dtc, server-side-tagged, personalisation-heavy, pixel-stacked, multi-region, woocommerce-stores, magento-stores, bnpl-enabled, headless-cms.","inputSchema":{"type":"object","properties":{"archetype":{"type":"string","description":"Archetype slug"}},"required":["archetype"]}},{"name":"compare_sites","description":"Side-by-side stack comparison of 2-5 domains. Returns each site's vendors, account IDs, brand info, markets — and which signals are shared / unique per site. Good for 'compare X.com vs Y.com' or competitive teardowns.","inputSchema":{"type":"object","properties":{"urls":{"type":"array","items":{"type":"string"},"description":"2-5 domain/URL strings"}},"required":["urls"]}},{"name":"similar_sites","description":"Find brands with similar stack archetypes to the given domain. Returns 'sites running similar tech' — useful for benchmarking, prospecting, competitor lookups.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Domain to find similar sites for"}},"required":["url"]}},{"name":"brands_by_founder","description":"List brands attributed to a founder (from Schema.org Organization markup). Useful for tracking serial DTC founders.","inputSchema":{"type":"object","properties":{"founder":{"type":"string","description":"Founder name (case-insensitive)"}},"required":["founder"]}},{"name":"bulk_export","description":"Paginated bulk export of indexed sites matching a filter. Returns up to 1000 rows per page in CSV or JSONL format with a cursor for continued pages. Use this when an agency needs an outbound prospect list (e.g. all sites using Klaviyo in the US) for CRM import. The full row count is also returned so you can size the export.","inputSchema":{"type":"object","properties":{"signal_type":{"type":"string","description":"Required. e.g. 'vendor', 'klaviyo_company_id', 'shopify_shopid', 'market_country', 'org_country'. Use list_signal_types via Boolsai Grep to discover."},"signal_value":{"type":"string","description":"Optional exact value to filter. If omitted returns ANY value of this signal_type."},"market_country":{"type":"string","description":"Optional ISO-2 country code (e.g. 'us', 'au') to intersect with hreflang market data"},"format":{"type":"string","enum":["csv","jsonl","json"],"default":"csv","description":"Output format. CSV is best for CRM import."},"cursor":{"type":"string","description":"Opaque cursor from previous page; pass to get next 1000 rows"},"limit":{"type":"integer","default":1000,"description":"Max rows per page (default 1000, max 5000)"}},"required":["signal_type"]}},{"name":"compare_scans","description":"Compare two historical scans of the same URL to surface stack changes. Returns added/removed/changed vendors, account IDs, and inline-script signals between scan A and scan B. Use this for competitor watch — 'what did patagonia.com just deploy?'. If t1/t2 are omitted, compares oldest vs newest available scan.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Domain or full URL to compare"},"t1":{"type":"string","description":"Optional ISO timestamp of first scan (oldest if omitted)"},"t2":{"type":"string","description":"Optional ISO timestamp of second scan (newest if omitted)"}},"required":["url"]}},{"name":"domain_intel","description":"Free DNS/WHOIS enrichment for a single domain. Returns: email host (Google Workspace / Microsoft 365 / etc. — derived from MX records), DNS provider (Cloudflare / Route 53 / GoDaddy / etc.), CDN provider, registrar, domain age (registered/expires). High-signal outbound data — 'they use Google Workspace + Cloudflare DNS + registered with GoDaddy' tells you a lot about org size + sophistication. Results cached 24h. Free — uses Cloudflare DoH + public RDAP.","inputSchema":{"type":"object","properties":{"domain":{"type":"string","description":"Domain to enrich (apex or any subdomain)"}},"required":["domain"]}},{"name":"find_similar_by_stack","description":"Find sites with the most-similar vendor stack to a given domain using Jaccard similarity over the full vendor set (not just archetype labels). Returns the top N matches with similarity scores. Use this when stack_archetype labels are too coarse and you want 'show me 20 brands running an almost-identical stack to liquiddeath.com'. More accurate than similar_sites for niche stacks.","inputSchema":{"type":"object","properties":{"domain":{"type":"string","description":"Reference domain"},"limit":{"type":"integer","default":20,"description":"max similar sites (1-100)"},"min_shared":{"type":"integer","default":3,"description":"Minimum shared distinctive vendors required to be considered (default 3)"}},"required":["domain"]}},{"name":"bulk_export_url","description":"Returns a streaming-export URL for the same filter as bulk_export. Useful when the agency wants to pull 50K rows in one shot via curl/HTTP pipe instead of paginating the MCP. The URL is public, no auth, returns NDJSON or CSV with HTTP chunked-transfer streaming. Use bulk_export when N<1000; use this for bigger exports.","inputSchema":{"type":"object","properties":{"signal_type":{"type":"string","description":"Required signal_type"},"signal_value":{"type":"string","description":"Optional exact value"},"market_country":{"type":"string","description":"Optional ISO-2 country"},"format":{"type":"string","enum":["ndjson","csv"],"default":"ndjson"}},"required":["signal_type"]}},{"name":"operator_cluster","description":"Find every domain sharing a tenant-unique ID — the most powerful single signal in Boolsai. Given a Stripe pk_live key, Sentry DSN org, Klaviyo company_id, mParticle workspace, GTM container, GA4 measurement, Shopify shop_id, or other tenant ID, returns every domain we've seen using the SAME ID. This surfaces multi-brand operators, holding-company portfolios, sister brands sharing infrastructure, agency-managed clusters. No competitor (BuiltWith, Wappalyzer, etc.) can do this — they only see external hostnames, not the tenant-unique IDs leaked client-side. Use this when you want to discover the actual operator behind a brand, or expand a single brand into its full portfolio.","inputSchema":{"type":"object","properties":{"id":{"type":"string","description":"The tenant ID itself (e.g. 'pk_live_abc...', 'GTM-M8TQZPX', 'o307020' for Sentry, '12345678' for Shopify shop_id). signal_type is auto-detected."},"signal_type":{"type":"string","description":"Optional explicit signal_type if auto-detect could be ambiguous (e.g. 'stripe_pk_live', 'sentry_dsn_org')."},"domain":{"type":"string","description":"Alternative: pass a domain and we'll return every cluster this domain belongs to (all tenant IDs and their fellow domains)."},"limit":{"type":"integer","default":100,"description":"max sites per cluster (1-500)"}}}},{"name":"subdomain_map","description":"Every subdomain of a given root domain we've ever scanned. Reveals storefront topology — where the checkout actually lives, regional storefronts, B2B portals, internal admin domains, asset CDNs. Output groups subdomains by their primary vendor where known. Use this to (a) find the right path to scan for an audit (sometimes the checkout is on us.checkout.brand.com not brand.com), (b) spot enterprise topology (multi-region Plus stores), (c) discover sister surfaces (community, ambassador, careers, etc).","inputSchema":{"type":"object","properties":{"root":{"type":"string","description":"Root domain (e.g. 'gymshark.com'). Pass just the apex; we'll find subdomains automatically."},"limit":{"type":"integer","default":200,"description":"max subdomains returned (1-1000)"}},"required":["root"]}},{"name":"prospect_brief","description":"ONE-CALL PROSPECT BRIEF for agency outbound — runs four sub-queries against the live indexed data: (1) full dossier of the prospect's stack, (2) sister brands sharing tenant IDs (operator cluster), (3) 3-5 similar-stack competitors, (4) structured 'pitch angles' calling out concrete gaps an agency could pitch on (missing consent, no SST, outdated vendors, broken Schema.org, multiple GTM installs). Saves a strategist 20 min of manual cross-referencing per prospect. Use this whenever the user asks 'tell me about prospect.com'.","inputSchema":{"type":"object","properties":{"url":{"type":"string","description":"Domain or URL of the prospect"},"angle":{"type":"string","description":"Optional agency pitch angle to tune the brief: 'cro', 'analytics', 'consent', 'sst' (server-side tagging), 'headless', 'consolidation'. If omitted, returns all angles found."}},"required":["url"]}},{"name":"directory_query","description":"Unified query against the Boolsai Directory. One tool to rule the other lookups. Pass any combination of: signal_type+signal_value, domain, market_country, archetype, founder, city. Returns matching sites + their key signals. Prefer this over the granular tools when you have multiple filter conditions to AND together.","inputSchema":{"type":"object","properties":{"signal_type":{"type":"string","description":"e.g. 'vendor', 'shopify_shopid'"},"signal_value":{"type":"string","description":"exact signal value"},"domain":{"type":"string","description":"exact domain match (e.g. 'gymshark.com')"},"market_country":{"type":"string","description":"ISO-2 (e.g. 'us')"},"archetype":{"type":"string","description":"e.g. 'headless-shopify', 'woocommerce-stores'"},"founder":{"type":"string","description":"case-insensitive substring"},"city":{"type":"string","description":"case-insensitive city name"},"limit":{"type":"integer","default":50,"description":"max rows (1-500)"}}}}]}},"bad_protocol_headers":{"content-type":"application/json"},"bad_protocol_error":null,"delete_status_code":null,"delete_error":null,"expired_session_status_code":null,"expired_session_error":null,"issues":["missing_session_id","missing_protocol_header","bad_protocol_not_rejected"]}},"utility_coverage_probe":{"status":"missing","latency_ms":32.03,"details":{"completions":{"advertised":false,"sample_target":null,"live_probe":"not_executed"},"pagination":{"supported":false,"next_cursor_methods":[],"metadata_signal":false},"tasks":{"advertised":false,"probe_status":"missing","http_status":200},"initialize_capability_keys":["tools"]}},"advanced_capabilities_probe":{"status":"missing","latency_ms":null,"details":{"capabilities":{"prompts":false,"resources":false,"completions":false,"roots":false,"sampling":false,"elicitation":false,"structured_outputs":false,"resource_links":false},"enabled_count":0,"enabled":[],"initialize_capability_keys":["tools"]}},"tool_snapshot_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_historical_snapshot","current_tool_count":19}},"connector_replay_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_historical_snapshot"}},"request_association_probe":{"status":"missing","latency_ms":null,"details":{"reason":"no_request_association_capabilities_advertised"}},"interactive_flow_probe":{"status":"ok","latency_ms":null,"details":{"risk_hits":[],"safe_hits":["consent"],"oauth_supported":false,"prompt_available":false}},"action_safety_probe":{"status":"error","latency_ms":null,"details":{"summary":{"tool_count":19,"high_risk_tools":9,"destructive_tools":1,"exec_tools":4,"egress_tools":10,"secret_tools":1,"bulk_access_tools":6,"risk_distribution":{"low":3,"medium":7,"high":7,"critical":2},"capability_distribution":{"filesystem":3,"secrets":1,"read":10,"exec":4,"network":10,"write":6,"admin":7,"export":6,"delete":1}},"auth_present":false,"safeguard_count":1,"confirmation_signals":[]}},"official_registry_probe":{"status":"ok","latency_ms":null,"details":{"registry_source":"official_registry","registry_identifier":"ai.boolsai/directory","direct_match":true,"official_peer_count":1}},"provenance_divergence_probe":{"status":"ok","latency_ms":null,"details":{"direct_official_match":true,"registry_title":null,"server_card_title":null,"registry_version":null,"server_card_version":null,"registry_homepage":null,"server_card_homepage":null,"registry_repository":null,"server_card_repository":null,"drift_fields":[],"metadata_document_count":1}},"connector_publishability_probe":{"status":"warning","latency_ms":null,"details":{"transport":"streamable-http","tool_count":19,"high_risk_tools":9,"blockers":["transport_compliance","action_safety","server_card"],"criteria":{"remote_transport":true,"initialize":true,"tools_list":true,"protocol_version":true,"session_resume":true,"step_up_auth":true,"transport_compliance":false,"connector_replay":true,"request_association":true,"action_safety":false,"server_card":false,"tool_surface":true,"auth_flow":true}}}},"score_components":{"auth_operability_score":2.0,"error_contract_score":2.83,"rate_limit_semantics_score":2.0,"schema_completeness_score":2.0,"backward_compatibility_score":2.0,"slo_health_score":4.0,"security_hygiene_score":2.5,"task_success_score":4.0,"trust_confidence_score":1.75,"abuse_noise_ratio_score":4.0,"prompt_contract_score":2.0,"resource_contract_score":2.0,"discovery_metadata_score":3.0,"registry_consistency_score":2.0,"installability_score":4.0,"session_semantics_score":4.0,"tool_surface_design_score":3.0,"result_shape_stability_score":2.0,"oauth_interop_score":3.0,"recovery_semantics_score":0.0,"maintenance_signal_score":3.0,"adoption_signal_score":2.0,"freshness_confidence_score":3.0,"transport_fidelity_score":4.0,"spec_recency_score":2.0,"session_resume_score":3.0,"step_up_auth_score":3.0,"transport_compliance_score":0.0,"utility_coverage_score":2.0,"advanced_capability_coverage_score":2.0,"connector_publishability_score":3.0,"tool_snapshot_churn_score":3.0,"connector_replay_score":3.0,"request_association_score":3.0,"interactive_flow_safety_score":4.0,"action_safety_score":2.0,"official_registry_presence_score":4.0,"provenance_divergence_score":4.0,"safety_transparency_score":4.0,"tool_capability_clarity_score":4.0,"destructive_operation_safety_score":2.0,"egress_ssrf_resilience_score":2.0,"execution_sandbox_safety_score":0.5,"data_exfiltration_resilience_score":3.35,"least_privilege_scope_score":2.0,"secret_handling_hygiene_score":3.0,"dependency_supply_chain_signal_score":2.5,"input_sanitization_safety_score":3.0,"tool_namespace_clarity_score":4.0},"validation_schema_version":"16d1d270090d6c8f","started_at":"2026-07-31T05:35:58.786197+00:00","completed_at":"2026-07-31T05:35:59.278239+00:00"},"current_snapshot":{"schema_version":"verify.trust_snapshot.v1","snapshot_id":"trustsnap_2242750e6ecf837e","generated_at":"2026-07-31T11:03:17.948550+00:00","source":"current_snapshot","server":"ai.boolsai/directory","last_validated_at":"2026-07-31T05:35:59.278239+00:00","validation_age_hours":5.46,"freshness":{"schema_version":"verify.freshness_profile.v1","last_validated_at":"2026-07-31T05:35:59.278239+00:00","age_hours":5.46,"bucket":"verified_last_24h","label":"Verified in last 24h","badges":["verified_last_24h"],"freshness_sla_hours":168.0,"freshness_sla_status":"met","stale_score_suppressed":false,"display_score":67.57,"raw_score":67.57,"confidence_score":76.2,"confidence_weighted_score":51.5,"tier_status":[{"tier":"community","label":"Community","freshness_sla_hours":720,"met":true,"priority_revalidation":false},{"tier":"pro","label":"Pro","freshness_sla_hours":168,"met":true,"priority_revalidation":true},{"tier":"enterprise","label":"Enterprise","freshness_sla_hours":24,"met":true,"priority_revalidation":true}]},"current_status":"healthy","current_score":67.57,"display_score":67.57,"stale_score_suppressed":false,"production_trust_decision":{"schema_version":"verify.executive_verdict.v1","decision":"Allow with approval","why":"exec-capable tools + no confirmation safeguards + high-risk tools need review","next_action":"export policy, require approval for writes, add authenticated validation","reason_count":2},"production_readiness_class":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use."},"evidence_confidence":{"score":76.25,"label":"high","validation_age_hours":5.46,"live_check_count":26},"active_alerts":[]},"trust_snapshot":{"schema_version":"verify.trust_snapshot.v1","snapshot_id":"trustsnap_2242750e6ecf837e","generated_at":"2026-07-31T11:03:17.948550+00:00","source":"current_snapshot","server":"ai.boolsai/directory","last_validated_at":"2026-07-31T05:35:59.278239+00:00","validation_age_hours":5.46,"freshness":{"schema_version":"verify.freshness_profile.v1","last_validated_at":"2026-07-31T05:35:59.278239+00:00","age_hours":5.46,"bucket":"verified_last_24h","label":"Verified in last 24h","badges":["verified_last_24h"],"freshness_sla_hours":168.0,"freshness_sla_status":"met","stale_score_suppressed":false,"display_score":67.57,"raw_score":67.57,"confidence_score":76.2,"confidence_weighted_score":51.5,"tier_status":[{"tier":"community","label":"Community","freshness_sla_hours":720,"met":true,"priority_revalidation":false},{"tier":"pro","label":"Pro","freshness_sla_hours":168,"met":true,"priority_revalidation":true},{"tier":"enterprise","label":"Enterprise","freshness_sla_hours":24,"met":true,"priority_revalidation":true}]},"current_status":"healthy","current_score":67.57,"display_score":67.57,"stale_score_suppressed":false,"production_trust_decision":{"schema_version":"verify.executive_verdict.v1","decision":"Allow with approval","why":"exec-capable tools + no confirmation safeguards + high-risk tools need review","next_action":"export policy, require approval for writes, add authenticated validation","reason_count":2},"production_readiness_class":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use."},"evidence_confidence":{"score":76.25,"label":"high","validation_age_hours":5.46,"live_check_count":26},"active_alerts":[]},"snapshot_invariant":{"schema_version":"verify.snapshot_invariant.v1","server":"ai.boolsai/directory","ok":true,"surface_snapshot_ids":{"page":"trustsnap_2242750e6ecf837e","badge":null,"report":"trustsnap_2242750e6ecf837e","policy":null},"checked_at":"2026-07-31T11:03:18.062998+00:00"},"history":{"points":[{"timestamp":"2026-07-31T05:35:59.278239+00:00","score":67.57,"status":"healthy","latency_ms":490.77,"tool_count":19,"prompt_count":0,"resource_count":0}],"status_counts":{"healthy":1},"score_delta_7d":null,"score_delta_30d":null,"avg_latency_ms":490.77,"healthy_ratio_recent":1.0,"freshness_hours":5.46,"latest_status":"healthy"},"production_readiness":{"code":"safe_for_evaluation","label":"Safe for evaluation","reason":"The server is suitable for evaluation, but remaining gaps should be resolved before broad production use.","badge":"score-medium","critical_alerts":0},"agent_commerce_readiness":{"status":"beta","commerce_signal":"weak","payment_execution_detected":"no","billing_or_usage_detected":"no","quote_or_pricing_detected":"no","numeric_price_context":"yes","commercial_quote_context":"no","checkout_or_charge_detected":"no","checkout_term_observed":"yes","payment_capable":"none","payment_rails":["Stripe"],"purchase_stage_supported":[],"human_confirmation_required":"unknown","spending_policy_supported":"yes","receipt_supported":"unknown","refund_policy_present":"unknown","operator_identity":"declared","auth_required":"no","auth_scheme":"none","tool_risk_level":"administrative","tool_risk_score":70,"pricing_transparency":"unknown","schema_change_detected":"unknown","delegation_level":"none","evidence_level":"inferred","confidence":"low","highest_risk_tools":[{"name":"subdomain_map","risk_level":"administrative"},{"name":"prospect_brief","risk_level":"administrative"}],"skipped_unsafe_tools":["compare_scans","bulk_export_url","operator_cluster","subdomain_map","prospect_brief","directory_query"],"last_checked_at":"2026-07-31T11:03:17.935535+00:00","evidence":[{"field":"commerce_signal","value":"weak","evidence_level":"inferred","source":"tool_schema","matched_terms":["checkout","limit","rate"],"sample":"bulk_export","confidence":"low","last_checked_at":"2026-07-31T11:03:17.935535+00:00"},{"field":"payment_rails","value":"Stripe","evidence_level":"inferred","source":"tool_schema","matched_terms":["stripe"],"sample":"Stripe","confidence":"medium","last_checked_at":"2026-07-31T11:03:17.935535+00:00"}],"disclaimer":"Beta assessment. Verify detects evidence and risk signals but does not certify that this server is safe for autonomous purchases.","scores":{"auth_posture_score":10,"tool_risk_score":70,"payment_readiness_score":10,"agent_delegation_safety_score":50,"overall_agent_commerce_score":null},"warnings":[],"recommended_fixes":[]},"evidence_confidence":{"score":76.25,"label":"high","reason":"Based on 1 recent validations, 26 captured checks, and validation age of 5.5 hours.","live_check_count":26,"validation_age_hours":5.46},"recommended_for":[{"label":"Claude Desktop","reason":"Claude Desktop is marked compatible with score 83."},{"label":"Smithery","reason":"Smithery is marked compatible with score 100."},{"label":"Generic Streamable HTTP","reason":"Generic Streamable HTTP is marked compatible with score 100."}],"active_alerts":[],"remediations":[{"code":"add_confirmation_semantics","severity":"high","title":"Add confirmation and dry-run semantics for risky actions","why":"High-risk write, delete, exec, or egress tools should communicate safeguards clearly.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"fix_transport_compliance","severity":"high","title":"Align session and protocol behavior with Streamable HTTP expectations","why":"Clients increasingly rely on MCP-Protocol-Version, session teardown, and expired-session semantics.","action":"Align MCP-Protocol-Version, MCP-Session-Id, DELETE teardown, and expired-session handling with the transport spec.","playbook":["Return `Mcp-Session-Id` and `Mcp-Protocol-Version` headers consistently on streamable HTTP responses.","Honor `DELETE` session teardown and return `404` when a deleted session is reused.","Reject invalid protocol-version headers with `400 Bad Request`."],"maintainer_context":null},{"code":"enforce_request_association","severity":"high","title":"Associate roots, sampling, and elicitation with active client requests","why":"Modern MCP guidance expects roots, sampling, and elicitation traffic to be tied to an active client request instead of arriving unsolicited on idle sessions.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"publish_oauth_protected_resource","severity":"high","title":"Expose /.well-known/oauth-protected-resource","why":"Without a protected-resource document, OAuth clients cannot discover auth requirements reliably.","action":"Serve /.well-known/oauth-protected-resource and point it at your authorization server metadata.","playbook":["Serve `/.well-known/oauth-protected-resource` from the same host as the MCP endpoint.","Point it at the authorization server metadata URL.","Confirm clients receive consistent auth hints before tool execution."],"maintainer_context":null},{"code":"protect_connector_refreshes","severity":"high","title":"Keep connector refreshes backward compatible","why":"Managed connector clients freeze tool snapshots, so removed tools, new required args, and breaking output changes can break published integrations after refresh.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"publish_oauth_authorization_server","severity":"high","title":"Publish OAuth authorization-server metadata","why":"Clients need authorization-server metadata to discover issuer, endpoints, and DCR support.","action":"Publish /.well-known/oauth-authorization-server from your issuer and include registration_endpoint when supported.","playbook":["Publish `/.well-known/oauth-authorization-server` from the issuer.","Add `registration_endpoint` if DCR is supported.","Verify issuer, authorization, token, and jwks metadata are all reachable."],"maintainer_context":null},{"code":"publish_server_card","severity":"high","title":"Publish a complete server card","why":"Missing or incomplete server-card metadata weakens discovery, documentation, and trust signals.","action":"Serve /.well-known/mcp/server-card.json and include tools, prompts/resources, homepage, and support links.","playbook":["Publish `/.well-known/mcp/server-card.json`.","Include homepage, repository, support, tools, prompts/resources, and auth metadata.","Revalidate the server after publishing the card."],"maintainer_context":null},{"code":"update_protocol_version","severity":"medium","title":"Adopt a current MCP protocol revision","why":"Older protocol revisions reduce compatibility with newer clients and registry programs.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"improve_connector_publishability","severity":"medium","title":"Close connector-publishing gaps","why":"Connector catalogs care about protocol recency, session behavior, auth clarity, and tool-surface stability.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"tighten_step_up_auth","severity":"medium","title":"Document minimal scopes and return cleaner auth challenges","why":"Modern clients expect granular scopes and step-up auth signals such as WWW-Authenticate scope hints.","action":"Return granular scopes and WWW-Authenticate challenge hints instead of forcing overly broad auth upfront.","playbook":["Advertise the narrowest viable scopes in OAuth metadata.","Return `WWW-Authenticate` challenges with scope or insufficient-scope hints when additional consent is needed.","Revalidate with both public discovery and auth-required flows."],"maintainer_context":null},{"code":"publish_openid_configuration","severity":"medium","title":"Publish OpenID configuration","why":"OIDC metadata improves token validation and client compatibility.","action":"Expose /.well-known/openid-configuration with issuer, jwks_uri, and supported grants.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"stabilize_tool_surface","severity":"medium","title":"Reduce tool-surface churn","why":"Frequent add/remove or output-shape drift makes published connectors and cached tool snapshots brittle.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"fix_prompts_list","severity":"medium","title":"Repair prompts/list or stop advertising prompts","why":"Prompt metadata should either work live or be removed from the advertised capability set.","action":"Only advertise prompts if prompts/list works and prompt arguments are documented.","playbook":["Only advertise prompts that are actually accessible.","Add prompt descriptions and argument docs.","Run a live `prompts/list` check after any prompt changes."],"maintainer_context":null},{"code":"fix_resources_list","severity":"medium","title":"Repair resources/list or stop advertising resources","why":"Resource metadata should either work live or be removed from the advertised capability set.","action":"Only advertise resources if resources/list works and resources expose stable URIs/types.","playbook":["Only advertise resources with stable URIs and read semantics.","Add MIME/type hints where possible.","Run a live `resources/list` and `resources/read` check after updates."],"maintainer_context":null},{"code":"repair_session_resume","severity":"medium","title":"Support resumable HTTP sessions cleanly","why":"Modern MCP clients increasingly expect resumable session behavior on streamable HTTP transports.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null},{"code":"expand_utility_coverage","severity":"low","title":"Expose modern utility surfaces like completions, pagination, or tasks","why":"Utility coverage improves interoperability with larger clients and long-lived agent workflows.","action":"Expose completions, pagination, and task metadata where supported so larger clients can plan and resume work safely.","playbook":["Advertise `completions`, pagination cursors, and `tasks` only when they are actually supported.","Return `nextCursor` on large list operations when pagination is available.","Document task support and whether it requires step-up auth."],"maintainer_context":null},{"code":"expand_advanced_capabilities","severity":"low","title":"Publish newer MCP capability signals","why":"Roots, sampling, elicitation, structured outputs, and related metadata improve client understanding and ranking.","action":"Inspect the latest validation evidence and resolve the client-visible regression.","playbook":["Inspect the latest validation evidence.","Resolve the highest-severity client-facing gap first.","Revalidate and confirm the score and verdict improve."],"maintainer_context":null}],"publisher_claim":{"verified":false,"status":"unclaimed","claim_url":"https://verify.sentinelsignal.io/claim?server=ai.boolsai%2Fdirectory&source=report_json","reason_code":"machine_attention_detected","reason":"Agents and crawlers are already evaluating this server. Claim to publish authoritative owner, security, trust, and integration metadata.","score_neutral":true},"observed_attention":{"schema":"verify.observed_attention.v1","window_days":30,"level":"moderate","label":"Moderate observed attention","summary":"Recent machine-readable trust and discovery activity observed for this server.","segments":{"useful_ai_user":{"level":"none","observed":false,"description":"AI-assisted user sessions such as ChatGPT/User or Claude/User."},"machine_trust_evaluator":{"level":"none","observed":false,"description":"Synthetic sessions inspecting multiple trust surfaces such as report, policy, ledger, badge, trust-summary, or compare."},"possible_agent_or_script":{"level":"none","observed":false,"description":"Structured direct sessions with rapid profile, compare, report, policy, badge, or trust-surface fan-out."},"isolated_machine_surface":{"level":"none","observed":false,"description":"Aged-out direct synthetic singleton sessions that touched a machine-readable trust surface without becoming a broader evaluator."},"ai_crawler":{"level":"moderate","observed":true,"description":"Known AI crawler activity such as ClaudeBot, GPTBot, or similar crawlers."},"search_crawler":{"level":"none","observed":false,"description":"Search and SEO crawler activity."},"browser_like_automation":{"level":"none","observed":false,"description":"Browser-like synthetic sessions with rapid structured endpoint activity."},"confirmed_human":{"level":"none","observed":false,"description":"Confirmed browser-session human activity."}},"surfaces_observed":{"server_profile":true,"compare":false,"compare_json":false,"compare_api":true,"report_json":false,"policy":true,"ledger":true,"badge_metadata":true,"badge_svg":false,"trust_summary":true,"mcp_tool":false},"claim_prompt":{"recommended":true,"reason":"This server has recent machine attention. A verified publisher claim can improve owner, policy, security, and trust metadata available to agents."},"notes":["Observed attention is based on segmented first-party telemetry.","Crawler and evaluator activity is not treated as confirmed human demand.","Public levels are bucketed to avoid exposing raw traffic counts."]},"owner_activation":{"claim_recommended":true,"reason":"ai_discovery_detected","headline":"AI discovery detected","message":"This server is being discovered by AI users, crawlers, or machine trust evaluators on Verify. Claim this profile to add publisher metadata, official links, a security contact, and machine-readable trust details agents can use.","claim_url":"https://verify.sentinelsignal.io/claim?server=ai.boolsai%2Fdirectory&source=report_json","trust_summary_url":"https://verify.sentinelsignal.io/v1/servers/ai.boolsai/directory/trust-summary"},"related_machine_surfaces":{"compare_index":"/compare.json","compare_api":"/v1/compare?server=ai.boolsai%2Fdirectory","trust_summary":"/v1/servers/ai.boolsai/directory/trust-summary","ledger":"/v1/servers/ai.boolsai/directory/ledger","policy":"/v1/servers/ai.boolsai/directory/policy","report":"/v1/servers/ai.boolsai/directory/report"},"intelligence_api":{"available":true,"signup_url":"https://verify.sentinelsignal.io/verify-intelligence-api","use_case":"Programmatic MCP server trust, comparison, policy, and evidence enrichment."}}