About
IGE/IPI Swissreg trademarks, patents, SPCs
Security Report
Well-structured MCP server with strong security controls: credentials are properly handled via environment variables (never hardcoded), outgoing requests are restricted to an explicit allow-list of IGE hosts, and error handling masks internal details from clients. Input validation is comprehensive via Pydantic models. The server correctly implements read-only operations over public data. Minor code-quality findings (broad exception handling, potential null dereferences) and one config-validation timing issue do not significantly impact security given the server's purpose and threat model. Supply chain analysis found 5 known vulnerabilities in dependencies (1 critical, 3 high severity). Package verification found 1 issue.
3 files analyzed ยท 10 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
What You'll Need
Set these up before or after installing:
Environment variable: IGE_USERNAME
Environment variable: IGE_PASSWORD
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-malkreide-swiss-ip-mcp": {
"env": {
"IGE_PASSWORD": "your-ige-password-here",
"IGE_USERNAME": "your-ige-username-here"
},
"args": [
"swiss-ip-mcp"
],
"command": "uvx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
๐จ๐ญ Part of the Swiss Public Data MCP Portfolio
๐ก swiss-ip-mcp
MCP Server for Swiss Intellectual Property Data (IGE/IPI)
๐ฉ๐ช Deutsche Version โ README.de.md
Overview
swiss-ip-mcp is a Model Context Protocol (MCP) server that gives AI models structured, language-driven access to the Swiss intellectual property register Swissreg, operated by the Swiss Federal Institute of Intellectual Property (IGE/IPI).
It is the successor to patent-mcp and covers all available domains of the Swissreg Datadelivery API: trademarks, patents, patent publications, and supplementary protection certificates (SPC/ESZ).
This server is model-agnostic. It works with Claude, GPT-4, Llama, and any other MCP-compatible client โ not just Claude Desktop.
Example Queries
The real power is natural language. Instead of manually searching the register, just ask a question:
"Which trademarks does the City of Zurich hold at the IGE?"
"Is the name 'Learning City Zurich' registered as a trademark in Switzerland?"
"Which pharmaceutical companies have filed Swiss patents in the last six months?"
"Show me all trademark applications in the education sector (Nice class 41) since January 2025."
"What supplementary protection certificates does Novartis hold in Switzerland?"
Covered Domains
| Domain | Description |
|---|---|
| Trademarks | Swiss trademark register โ filing, protection, owners, Nice classes |
| Patents | CH patents โ filing, grant, IPC classes, applicants, inventors |
| Patent publications | Official patent publications in the Swiss Official Gazette |
| SPC / ESZ | Supplementary protection certificates for medicinal and plant-protection products |
Note: Design search is not yet available in the Swissreg Datadelivery API.
Tools (11)
| Tool | Function |
|---|---|
swiss_ip_search_trademarks | Free-text trademark search (wildcard * supported) |
swiss_ip_get_trademark | Retrieve a trademark by registration number |
swiss_ip_search_trademarks_by_owner | Find all trademarks held by a given owner |
swiss_ip_search_trademarks_by_class | Filter trademarks by Nice classification class |
swiss_ip_search_patents | Free-text patent search |
swiss_ip_get_patent | Retrieve a patent by number |
swiss_ip_search_patents_by_applicant | Find patents by applicant or inventor name |
swiss_ip_search_patent_publications | Search patent publications |
swiss_ip_search_spc | SPC/ESZ search (pharma and plant protection) |
swiss_ip_search_recent_filings | Filter filings by date range across all domains |
swiss_ip_get_quota | Check remaining API data transfer quota |
Resources & Prompts
Beyond tools, the server exposes two more MCP primitives:
Resources (read-only metadata, swissip:// URI scheme):
| URI | Content |
|---|---|
swissip://about | Server + data-source metadata (provenance, covered domains) |
swissip://domains | List of covered IP domains |
Prompts (curated workflow templates):
| Prompt | Arguments | Purpose |
|---|---|---|
trademark_availability | name | Check whether a name is a registered Swiss trademark |
competitor_ip_report | company | IP overview (trademarks + patents) for a company |
recent_ip_filings_report | ip_type, date_from, date_to | Report on recent filings in a period |
Error semantics
Tool execution errors (API failures, timeouts, missing credentials) are
returned with MCP isError: true and a masked, user-friendly message โ internal
details (stack traces, raw API bodies) go only to the server log. A specific
number lookup that finds nothing is not an error: it returns a normal result
with match_type: "none" and a message.
Project Phase
This server is in Phase 1 (read-only) of the MCP phased-rollout model: every
tool is read-only and writes nothing. See ROADMAP.md for the
phase plan and the prerequisites for any future write-capable phase.
Architecture
AI client (Claude Desktop, Cursor, VS Code + Continue, โฆ)
โ
โ MCP (stdio or SSE)
โผ
swiss-ip-mcp
โ
โ HTTPS + OAuth2 (IGE IDP)
โผ
Swissreg Datadelivery API
https://www.swissreg.ch/public/api/v1
โ
โโโ TrademarkSearch
โโโ PatentSearch
โโโ PatentPublicationSearch
โโโ SPCSearch
โโโ UserQuota
Transport Modes
| Transport | Use case | Configuration |
|---|---|---|
| stdio | Claude Desktop, local development | Default (no extra setup) |
| Streamable HTTP | Cloud deployment (Render.com etc.) | MCP_TRANSPORT=streamable-http |
| SSE | Legacy HTTP clients | MCP_TRANSPORT=sse |
Transport is selected at startup from the MCP_TRANSPORT environment variable
(default stdio). The HTTP transports are served by uvicorn and honour:
| Variable | Default | Purpose |
|---|---|---|
MCP_HOST | 127.0.0.1 | Bind address. Use 0.0.0.0 only inside a container / behind a reverse proxy. |
PORT / MCP_PORT | 8000 | Bind port (PORT wins โ PaaS convention). |
MCP_ALLOWED_ORIGINS | (empty) | Comma-separated CORS origin allow-list. No wildcard in production. |
MCP_ALLOWED_HOSTS | (empty) | Comma-separated Host-header allow-list; enables DNS-rebinding protection when set. |
The Mcp-Session-Id header is exposed via CORS so browser-based clients can
read and echo it on follow-up requests.
Prerequisites
- IGE credentials (free): Sign the terms of use and send the form by post to the IGE. Credentials are issued upon receipt.
- Python 3.11 or later
uv(recommended) orpip
Installation
# Run directly with uv (recommended, no local installation needed)
uvx swiss-ip-mcp
# Local development installation
git clone https://github.com/malkreide/swiss-ip-mcp
cd swiss-ip-mcp
pip install -e ".[dev]"
Configuration
Environment Variables
export IGE_USERNAME="your_username"
export IGE_PASSWORD="your_password"
Claude Desktop
Open the config file:
- macOS:
~/Library/Application Support/Claude/claude_desktop_config.json - Windows:
%APPDATA%\Claude\claude_desktop_config.json
{
"mcpServers": {
"swiss-ip": {
"command": "uvx",
"args": ["swiss-ip-mcp"],
"env": {
"IGE_USERNAME": "your_username",
"IGE_PASSWORD": "your_password"
}
}
}
}
Other MCP Clients
swiss-ip-mcp is compatible with any MCP-capable client:
| Client | Configuration |
|---|---|
| Cursor | Add to ~/.cursor/mcp.json (same format as Claude Desktop) |
| VS Code + Continue | Add via continue.json MCP server block |
| Windsurf | Add via MCP server settings |
| Self-hosted (mcp-proxy) | Use SSE transport with MCP_TRANSPORT=sse |
Cloud / Render.com (Streamable HTTP)
MCP_TRANSPORT=streamable-http \
MCP_HOST=0.0.0.0 PORT=8000 \
MCP_ALLOWED_ORIGINS="https://your-client.example" \
MCP_ALLOWED_HOSTS="your-app.onrender.com" \
IGE_USERNAME=... IGE_PASSWORD=... \
swiss-ip-mcp
Security note: bind to
0.0.0.0only inside a container or behind a reverse proxy. Always setMCP_ALLOWED_ORIGINSandMCP_ALLOWED_HOSTSfor public deployments โ this enables CORS scoping and DNS-rebinding protection. The endpoint is unauthenticated and serves only public IP-register data; do not place credentialed or non-public tools behind this transport without adding authentication first.
Docker / Kubernetes
A hardened multi-stage Dockerfile (non-root UID 10001,
HEALTHCHECK on /health), a docker-compose.yml with
resource limits, and Kubernetes manifests + an HAProxy sticky-session config
under deploy/ are included.
docker compose up --build # reads IGE_* from .env
See docs/deployment.md for hardening, resource limits and
scaling (stateless vs. sticky-session) details.
Tests
# Unit tests (no credentials needed)
PYTHONPATH=src pytest tests/ -v
# Including live integration tests against the real API
IGE_USERNAME=... IGE_PASSWORD=... PYTHONPATH=src pytest tests/ -v
The CI workflow runs on Python 3.11, 3.12, and 3.13.
Observability (optional)
The server can emit OpenTelemetry traces โ one span per tool call plus child spans for the backend Swissreg/IDP HTTP calls. Tracing is off by default and adds no overhead until enabled.
pip install 'swiss-ip-mcp[otel]'
MCP_OTEL_ENABLED=1 \
OTEL_EXPORTER_OTLP_ENDPOINT=http://your-collector:4318 \
MCP_ENV=production \
swiss-ip-mcp
| Variable | Purpose |
|---|---|
MCP_OTEL_ENABLED | Set to 1 to enable trace export (or just set the endpoint below). |
OTEL_EXPORTER_OTLP_ENDPOINT | OTLP/HTTP collector endpoint (standard OTEL variable). |
MCP_ENV | Value for the deployment.environment resource attribute (default production). |
Tool spans carry only mcp.tool.name and mcp.tool.result.is_error โ no
query arguments, credentials or response bodies are recorded.
Logging
The server logs structured JSON to stderr (stdout is reserved for the
stdio protocol). Every tool call binds a tool name and a correlation_id, so
all log lines for one call are correlated. Set the level with LOG_LEVEL
(DEBUG / INFO / WARNING / ERROR, default INFO):
{"event": "tool.call.start", "tool": "swiss_ip_search_trademarks", "correlation_id": "da55โฆ", "level": "info", "timestamp": "โฆZ"}
MCP Protocol Version
This server speaks two protocol eras over the same endpoint. The client's first request on a connection decides which one applies; a later claim from the other era is refused.
| Era | Revision | Who reaches it |
|---|---|---|
initialize handshake | 2024-11-05 โฆ 2025-11-25 | What today's clients speak. The server answers with the revision asked for, or with the 2025-11-25 ceiling when the request asks for something newer. |
| Per-request envelope | 2026-07-28 | A request carrying the 2026-07-28 _meta envelope opens a modern connection. |
Both revisions are pinned in
tests/test_protocol_version.py and asserted
against the installed SDK, so a Dependabot bump of mcp cannot move either one
silently. This server builds no ASGI app to send an initialize through, so
the gate asserts the SDK constants rather than a measured response โ the
weaker form, named rather than left unsaid.
Note that the SDK's LATEST_PROTOCOL_VERSION is an alias for the modern
era, not for the handshake era โ pinning against it alone would leave the era
that current clients actually negotiate free to drift.
Update policy. When the gate fails, do not edit the constant blindly: read
the spec changelog between the two revisions, verify the server still behaves,
then move the constant, this section, README.de.md and
CHANGELOG.md together.
Data Source
All data is provided by the IGE/IPI Swissreg Datadelivery API. The API is free after signing the usage terms, subject to a monthly data transfer quota. Check your remaining quota at any time using the swiss_ip_get_quota tool.
| Field | Value |
|---|---|
| Provider | Swiss Federal Institute of Intellectual Property (IGE/IPI) |
| Source | Swissreg Datadelivery API โ https://www.swissreg.ch/public/apidocs/ |
| License / terms | IGE/IPI Swissreg Datadelivery API Terms of Use |
Provenance: every tool response carries a source block (provider, source
URL, license) so downstream consumers retain attribution. The result envelope is
{ source, total, count, match_type, results, next_page_token }.
Safety & Limits
- Read-only: All tools perform authenticated POST requests to the Swissreg API โ no data is written, modified, or deleted on any system.
- No personal data: The API returns public IP register entries (trademark names, patent titles, applicant organisations). No personally identifiable information (PII) is processed or stored by this server beyond what the IGE API returns in its public records.
- Rate limits & quota: The IGE Swissreg API enforces a monthly data transfer quota per account. Use the
swiss_ip_get_quotatool to monitor remaining quota. The server enforces a 60s timeout per request. Avoid largepage_sizevalues (>20) for exploratory queries. - Authentication: Credentials (
IGE_USERNAME,IGE_PASSWORD) are read from environment variables at runtime and never logged or persisted. - Terms of service: Data is subject to the IGE Swissreg Datadelivery API terms of use. A signed usage agreement with IGE/IPI is required before API access is granted.
- Address list verified without credentials (2026-08-08). Every address, the Keycloak realm and the
client_idthis server builds are the ones the source publishes. A null result โ and recorded as one, because a null result nobody wrote down is not one on the next pass. Three independent proofs, because one would not have carried:- The IDP discriminates:
realms/egovwith wrong credentials โinvalid_grant("Invalid user credentials"); an invented realm โ 404 "Realm does not exist"; an inventedclient_idโinvalid_client. So realm and client exist and only the credentials are missing. - The realm declares its own token endpoint under
.well-known/openid-configurationโ identical to the URL built here. - The official API documentation states both addresses verbatim, including the
client_idas a "constant string".
- The IDP discriminates:
- Why the third proof is needed: the Swissreg API itself does not discriminate. A POST without a token returns 403, with an invented token 401 โ and a freely invented path under
/public/api/returns exactly the same. A status code proves nothing there.scripts/record_fixtures.pyre-measures this on every run and aborts if a control stops discriminating. - Response payloads are not recorded. They need credentials;
PROVENANCE.mdlists them as NOT RECORDED with the measured status rather than giving them a date they never had. What stays unproven is the shape of the responses โ whether the XML fields are named as the parser reads them. - No guarantees: This server is a community project, not affiliated with the Swiss Federal Institute of Intellectual Property (IGE/IPI). Availability depends on upstream API uptime.
Related Servers
| Server | Content |
|---|---|
zurich-opendata-mcp | City of Zurich open data (CKAN, weather, parking, geodata) |
fedlex-mcp | Swiss federal law via Fedlex SPARQL |
swiss-transport-mcp | Public transport, disruptions, tickets, train formations |
swiss-road-mobility-mcp | Shared mobility, EV charging stations, traffic data |
global-education-mcp | UNESCO / OECD education data |
patent-mcp | โ ๏ธ Deprecated โ superseded by this server |
Contributing
See CONTRIBUTING.md (Deutsch) for how to
report bugs and submit changes.
Security
See SECURITY.md for the security posture, hardening summary, and how to report a vulnerability.
License
MIT License โ see LICENSE
Author
Hayal Oezkan ยท github.com/malkreide
Installation
Run via uv's uvx โ no clone or manual install needed. Add to your MCP client config (mcpServers for Claude Desktop, Cursor and Windsurf; use a top-level servers key for VS Code in .vscode/mcp.json):
{
"mcpServers": {
"swiss-ip-mcp": {
"command": "uvx",
"args": [
"swiss-ip-mcp"
],
"env": {
"IGE_USERNAME": "<your IGE_USERNAME>",
"IGE_PASSWORD": "<your IGE_PASSWORD>"
}
}
}
}
Requires credentials: set IGE_USERNAME, IGE_PASSWORD (replace the placeholder values above).
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Fetch
Freeby Modelcontextprotocol ยท Developer Tools
Web content fetching and conversion for efficient LLM usage
Git
Freeby Modelcontextprotocol ยท Developer Tools
Read, search, and manipulate Git repositories programmatically
Toleno
Freeby Toleno ยท Developer Tools
Toleno Network MCP Server โ Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace ยท Developer Tools
Create, build, and publish Python MCP servers to PyPI โ conversationally.
MCP Marketplace
Freeby mcp-marketplace ยท Developer Tools
Search and install MCP servers from inside your AI client.
MarkItDown
Freeby Microsoft ยท Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
