Back to Browse

Factgrid MCP Server

Developer ToolsLow Risk10.0MCP RegistryRemote
Free

Server data from the Official MCP Registry

Reference data agents need before writing code: dependency advisories, API schemas, component specs.

About

Reference data agents need before writing code: dependency advisories, API schemas, component specs.

Remote endpoints: streamable-http: https://factgrid.co.uk/mcp

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (1 strong, 0 medium validity signals). No known CVEs in dependencies. Imported from the Official MCP Registry. 1 finding(s) downgraded by scanner intelligence.

10 tools verified · Open access · 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

How to Connect

Remote Plugin

No local installation needed. Your AI client connects to the remote endpoint directly.

Add this to your MCP configuration to connect:

{
  "mcpServers": {
    "io-github-factgridai-factgrid": {
      "url": "https://factgrid.co.uk/mcp"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

FactGrid

Reference data agents need before they write code. Dependency upgrade advisories for npm and PyPI, developer API schemas across 1,097 services, and electronic component specifications — over MCP, Ed25519-signed, with the evidence attached.

MCP endpoint: https://factgrid.co.uk/mcp · Agent-readable docs · factgrid.co.uk


Stop an agent shipping a broken dependency upgrade

Your agent wants to bump chalk from 4.1.2 to 5.0.0. Before it edits package.json, it asks what breaks:

GET /api/v1/packages/npm/chalk/advisory?from=4.1.2&to=5.0.0
Authorization: Bearer <key>
{
  "found": true,
  "packageName": "chalk",
  "fromVersion": "4.1.2",
  "toVersion": "5.0.0",
  "breakingCount": 2,
  "advisories": [
    {
      "severity": "breaking",
      "changeType": "MODULE_FORMAT_CHANGED",
      "description": "chalk 5.0.0 changed module format from \"commonjs (undeclared)\" to \"module\". CommonJS require() of this package will now fail.",
      "evidenceField": "type",
      "evidenceBefore": null,
      "evidenceAfter": "module",
      "migrationHint": "Convert the call site to import(), or pin to the last CommonJS release."
    },
    {
      "severity": "breaking",
      "changeType": "RUNTIME_REQUIREMENT_RAISED",
      "description": "chalk 5.0.0 raised its runtime requirement from \">=10\" to \"^12.17.0 || ^14.13 || >=16.0.0\". Older runtimes are no longer supported.",
      "evidenceField": "engines.node",
      "evidenceBefore": ">=10",
      "evidenceAfter": "^12.17.0 || ^14.13 || >=16.0.0",
      "migrationHint": "Confirm the deployment runtime satisfies the new floor before upgrading."
    }
  ]
}

Via MCP, the same question is one tool call:

{
  "name": "factgrid_package_upgrade_advisory",
  "arguments": { "registry": "npm", "name": "chalk", "from": "4.1.2", "to": "5.0.0" }
}

Every finding carries evidenceField, evidenceBefore and evidenceAfter — the exact registry metadata field and its values either side of the change. An agent can verify the claim against npm or PyPI directly rather than taking our word for it.


Connect

Streamable HTTP. No install, no package to pull.

{
  "mcpServers": {
    "factgrid": {
      "type": "http",
      "url": "https://factgrid.co.uk/mcp"
    }
  }
}

Manifest: /.well-known/mcp.json

Get a key — no signup, no card:

curl -X POST https://factgrid.co.uk/api/v1/keys/create \
  -H 'Content-Type: application/json' \
  -d '{"email":"you@example.com"}'

Tools

ToolWhat it answers
factgrid_package_upgrade_advisoryWhat breaks between two published npm/PyPI versions
factgrid_api_schemaExact request/response shape of an API endpoint at a version
factgrid_integration_briefEverything needed to write one working call to an API
factgrid_discover_apiWhich of 1,097 services can do X
factgrid_deprecation_scanWhich endpoints are deprecated, sunset dates, replacements
factgrid_auth_playbookAuth schemes, scopes, rate-limit headers, error-code table
factgrid_component_specElectronics component pinouts, voltages, packages
factgrid_subscribe_spec_changesWebhook or polling callback when a spec changes
factgrid_create_topup_linkStripe checkout link when credit runs out
factgrid_api_breaking_changesCurrently offline — see What we don't claim below

Catalogue

Package releases indexed10,190 across 16 npm/PyPI packages
Upgrade advisories357, of which 84 breaking
API endpoint schemas18,348 across 1,097 services
Electronic components994

Live counts, free and unauthenticated: /api/v1/stats · /api/v1/packages/stats


Pricing

50 free queries per key per day. No card, no signup.

TierPrice
Component lookup$0.001
API schema$0.002
Semantic search$0.003
Deprecation scan$0.005
Auth playbook$0.005
Capability search$0.005
Integration brief$0.01
Package upgrade advisory$0.02

Pay from prepaid credit, or per call in USDC over x402 — no account and no human in the loop. Live pricing: /api/v1/pricing

Misses are never billed. A query we can't answer returns found: false, billed: false and the nearest matches, at no charge. Cached revalidations (HTTP 304) and rate-limited requests are never charged either.


What we don't claim

This section exists because the alternative is worse.

The API breaking-change tier is offline. An earlier version of this project published 8,150 breaking-change diffs for third-party APIs. A spot-check found a 100% false-positive rate — they were computed from mis-ordered specification versions. We withdrew all of them. That tier still returns no data and bills nothing, and it will stay that way until we can show the output holds up against publishers' own changelogs.

That failure is why the package engine is built the way it is:

  • breaking is reserved for a removal or tightening provable from declared metadata — an entry point gone from an exports map, a runtime floor raised, a release the publisher yanked.
  • Additions can never be breaking. There is a test asserting exactly that.
  • Where a version range can't be parsed, the engine stays silent rather than guessing.
  • Across urllib3's 103 consecutive stable releases it emits 7 advisories, not thousands. The conservatism is the feature.

Package advisories cover publisher-declared registry metadata, not behavioural changes. If a maintainer silently changes what a function returns without touching package.json, we will not see it — read the changelog. We say so rather than implying coverage we don't have.

Mainnet x402 is configured and advertised but has never been exercised with real money. It settled against two independent facilitators on testnet. We won't call it proven until a real settlement lands.


Accuracy

Every response is Ed25519-signed; the public key is at /.well-known/jwks.json. Records are source-cited. API schema data derives from APIs.guru under CC-BY 4.0.

Accuracy is best-effort, not guaranteed — see /terms. Found an error? POST /api/v1/report-error — free, no auth.

Reviews

No reviews yet

Be the first to review this server!