Back to Browse

Luxembourg MCP Server

Developer ToolsLow Risk10.0MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Keyless MCP access to official Luxembourg public data: laws, statistics, mobility, and more.

About

Keyless MCP access to official Luxembourg public data: laws, statistics, mobility, and more.

Remote endpoints: streamable-http: https://mcp.luxembourg-mcp.com/mcp

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (1 strong, 1 medium validity signals). No known CVEs in dependencies. Package registry verified. Imported from the Official MCP Registry.

38 tools verified · Open access · 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

file_system

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

Luxembourg MCP

CI PyPI License: MIT

Keyless Model Context Protocol access to Luxembourg public data.

Hosted endpoint — no install needed: point any MCP client at https://mcp.luxembourg-mcp.com/mcp (streamable HTTP). Or run it yourself with uvx luxembourg-mcp. Website: luxembourg-mcp.com

Luxembourg MCP turns fragmented public APIs and open datasets into 38 consistent tools that AI agents can call directly. It covers laws, official statistics, mobility, environmental measurements, parliament, accessibility, addresses, geospatial features, and the national open-data catalogue.

  • 38 MCP tools
  • 26 public data systems
  • No API keys or accounts
  • No scraping
  • Source URL returned with every result
  • Stdio and Streamable HTTP transports

Origin and credit

This project is directly inspired by Allemannsdata, created by Thomas Heggelund.

Heggelund's original idea was to give public data the same openness suggested by Norway's allemannsretten, the right to roam: public information should be straightforward to reach, combine, and use. Allemannsdata removes the repetitive integration work between agents and Norwegian public services by presenting many unrelated data sources through consistent, keyless MCP tools.

Luxembourg MCP applies that idea to the Grand Duchy. It is an independent implementation for Luxembourg, not a fork, official regional edition, or affiliated project. Credit for the original public-data-over-MCP catalogue concept belongs to Thomas Heggelund and Allemannsdata.

Available tools

ToolPublic sourcePurpose
search_datasetsdata.public.luSearch the national open-data catalogue
get_datasetdata.public.luInspect metadata and current resources
geocode_addressGeoportailResolve an official address
reverse_geocodeGeoportailFind the nearest official address
list_geo_collectionsGeoportail OGC APIDiscover queryable geospatial layers
get_geo_featuresGeoportail OGC APIRetrieve bounded GeoJSON features
get_weather_alertsMeteoLuxRead current weather warnings
search_legislationLegiluxSearch legislation and consolidated laws
search_statisticsSTATEC LUSTATDiscover statistical dataflows
get_statisticsSTATEC LUSTATRetrieve labelled SDMX observations
get_city_parkingVille de LuxembourgRead live city parking availability
list_cfl_parkingCFLList Park and Ride facilities
get_cfl_parkingCFLRead live P+R occupancy and free spaces
get_trafficCITARead live motorway traffic measurements
get_water_levelsWater Management AdministrationRead current water-station levels
get_air_qualityEnvironment AdministrationRead national air-quality measurements
search_chamber_bodiesChamber of DeputiesSearch bodies, memberships, and roles
get_accessibility_figuresDigital Accessibility ObservatoryRead national accessibility totals
get_accessibility_auditsDigital Accessibility ObservatoryList recent public-sector audits
search_transit_stopsPublic Transport AdministrationSearch nationwide GTFS stops
get_city_mobilityVille de Luxembourg MapsRetrieve mobility locations as GeoJSON
get_weather_observationsMeteoLuxLive temperature, wind, pressure at Findel
get_public_holidaysdata.public.luLegal public holidays in four languages
search_parliamentary_questionsChamber of DeputiesSearch parliamentary questions and answers
get_housing_pricesObservatoire de l'HabitatAdvertised housing sale prices by commune
get_election_resultsCTIE2023 legislative election results
get_ev_chargingChargyPublic EV charging with live availability
get_waste_collectionsEnvironment AdministrationUpcoming waste-collection dates by commune
get_weather_forecastMeteoLuxOfficial forecast, UV index, sunrise and sunset
get_fuel_pricesMinistère de l'ÉconomieMonthly fuel, hydrogen and EV-charging prices
get_public_alertsLU-AlertNational warnings, including food recalls
get_commune_leadersMinistère des Affaires intérieuresCurrent mayor and aldermen per commune
get_commune_populationCTIEResident population by commune, age group and sex
get_pharmacies_on_dutyPharmacie.luPharmacies on duty, with address and phone
get_electricity_pricesOpen Data LëtzebuergDay-ahead power prices per quarter hour
get_carsharingCFL MobilityAvailable FLEX carsharing vehicles
get_bike_sharingVël'OKLive bike-sharing availability in the south
search_tendersPortail des marchés publicsOpen public procurement notices

Quick start

Python 3.11 or newer is required.

python -m venv .venv
. .venv/bin/activate
pip install -e .
luxembourg-mcp --transport http --port 8000

Once running:

InterfaceURL
Tool cataloguehttp://127.0.0.1:8000/
MCP endpointhttp://127.0.0.1:8000/mcp
Health checkhttp://127.0.0.1:8000/health

Stdio client

{
  "mcpServers": {
    "luxembourg": {
      "command": "luxembourg-mcp"
    }
  }
}

Docker

docker build -t luxembourg-mcp .
docker run --rm -i luxembourg-mcp                                          # stdio (default)
docker run --rm -p 8000:8000 luxembourg-mcp --transport http --host 0.0.0.0  # HTTP

Example questions

After connecting an MCP client, an agent can answer questions such as:

  • What weather warnings are active in Luxembourg?
  • How many spaces are free at a CFL Park and Ride?
  • What is the latest water level at Mersch?
  • Find legislation concerning pensions.
  • Which STATEC datasets contain population figures?
  • What are the latest traffic measurements on the A6?
  • Find the official coordinates for an address in Luxembourg City.
  • Which bus or tram stops match Hamilius?

Protocol behavior

The server:

  • validates arguments against every advertised tool input schema;
  • rejects JSON-RPC batches and other non-object JSON with -32600 Invalid Request;
  • supports MCP 2026-07-28 (stateless: per-request _meta, server/discover, cache hints) alongside the initialize-handshake revisions 2025-11-25, 2025-06-18, and 2025-03-26 on the same endpoint and over stdio;
  • validates the MCP-Protocol-Version, Mcp-Method, and Mcp-Name headers against the request body for HTTP requests;
  • returns tool failures as MCP tool results without terminating the server;
  • bounds large upstream responses before placing them in agent context.

The built-in HTTP server is stateless and does not provide an SSE stream. By default it accepts browser origins only from loopback addresses; hosted deployments can extend this with LUXEMBOURG_MCP_ALLOWED_ORIGINS (a comma-separated origin list, or *), which also enables CORS preflight and response headers for the allowed origins. Public deployments should add TLS, response caching, and observability at a reverse proxy or application gateway.

Security and deployment

The built-in server includes baseline controls, but it is not a replacement for a production API gateway:

  • HTTP request bodies are limited to 1 MiB.
  • Upstream responses are limited to 25 MiB.
  • Metadata-derived downloads are restricted to trusted data.public.lu HTTPS resource hosts, including redirects; fixed upstream URLs only follow HTTPS redirects on the same host.
  • Upstream XML declaring DTD entities is rejected before parsing, and user-supplied identifiers cannot form ./.. URL path segments.
  • GTFS ZIP members are checked for decompressed size, encryption, and suspicious compression ratios before extraction.
  • HTTP clients are limited to 60 MCP requests per minute by default; IPv6 clients are grouped by /64 prefix.
  • The HTTP server serves at most 32 concurrent connections by default and closes connections idle for 30 seconds.
  • The Docker image runs as an unprivileged app user from a digest-pinned base image.

Set LUXEMBOURG_MCP_RATE_LIMIT to change the per-minute, per-client limit. A value of 0 disables the built-in limiter. The limiter intentionally uses the direct TCP peer address and does not trust forwarding headers unless LUXEMBOURG_MCP_CLIENT_IP_HEADER names one explicitly (for example CF-Connecting-IP behind Cloudflare); only set it when a trusted proxy controls that header, since clients could otherwise spoof it to escape the limit. Set LUXEMBOURG_MCP_MAX_CONNECTIONS to change the concurrent-connection cap; connections beyond it are closed immediately.

Tool output is untrusted external data. Dataset descriptions, legislation titles, and other public text may contain misleading or adversarial instructions. MCP clients and agent hosts must treat tool results as data, not system instructions, and should require confirmation or policy checks before allowing powerful sibling tools to act on content returned here.

Testing

The default suite is deterministic and does not use the network. It covers JSON-RPC behavior, schema validation, provider parsers, catalogue packaging, and the tools/call contract for all 28 tools.

PYTHONPATH=src python -m unittest discover -s tests -v

The opt-in live suite calls every real upstream service:

LUXEMBOURG_MCP_LIVE=1 PYTHONPATH=src \
  python -m unittest tests.test_live_tools -v

Live tests may fail when a source is unavailable or changes its published data. They also download larger STATEC, air-quality, Chamber, and GTFS resources.

Current limitations

  • The official ATP API for real-time departures and journey planning requires a personal access key. This project exposes keyless static stops from the official GTFS feed instead.
  • The cache is bounded but local to one process. Multiple workers do not share cached data.
  • Upstream availability, update frequency, schemas, and licensing remain controlled by each data producer.
  • Tool coverage is not yet at parity with Allemannsdata. Candidates include parliamentary votes, court decisions, historical weather, EV charging, road works, and more environmental measurements.

Independence and data ownership

Luxembourg MCP is a community project. It is not affiliated with Thomas Heggelund, Allemannsdata, the Luxembourg government, or any agency whose data it exposes.

The project does not own the upstream data. Each producer's licence and terms continue to apply. Tool results preserve the upstream source URL so agents and users can inspect the authoritative record.

Licence

The Luxembourg MCP source code is released under the MIT licence. Upstream public data is licensed separately by its respective producer.


mcp-name: io.github.amirdaraee/luxembourg-mcp

Reviews

No reviews yet

Be the first to review this server!