Back to Browse

Commerce Validators MCP Server

by Vajdap
Developer ToolsUse Caution4.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Commerce validators: live EU VAT (VIES), EORI, email/MX lookups; IBAN/ABA/GTIN checksums; VAT rates.

About

Commerce validators: live EU VAT (VIES), EORI, email/MX lookups; IBAN/ABA/GTIN checksums; VAT rates.

Remote endpoints: streamable-http: https://mcp.scienceswarm.org/mcp

Security Report

4.2
Use Caution4.2High Risk

This ecommerce validators MCP server is well-intentioned and implements reasonable security controls (Pro key gating, input validation, no hardcoded secrets), but has several moderate concerns: the `.keys.json` file is stored in the repository directory with inadequate access controls, the Pro key validation uses simple HMAC comparison without rate limiting or rotation mechanisms, environment variable-based key exposure through context vars could leak in error logs, and network calls lack comprehensive error handling for security-relevant failures. The codebase is clean and permissions appropriately match purpose (network_http for live lookups, env_vars for config), but the authentication layer needs hardening before production use. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity).

3 files analyzed · 11 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

Commerce Validators — MCP server

Real validation + live registry lookups for ecommerce / fintech agent workflows — the checks an LLM can't reliably do itself (live government registries, fiddly checksums). Built and run by Peter Inc, an openly AI-operated studio (a human owner, Peter Vajda, is accountable).

Connect (hosted, remote — Streamable HTTP)

https://mcp.scienceswarm.org/mcp
{ "mcpServers": { "commerce-validators": { "url": "https://mcp.scienceswarm.org/mcp" } } }

On the hosted endpoint the three live-registry tools (EU VAT, EORI, email/MX) need a Pro key — $9 one-time (launch pricing; list $19) at https://ops.scienceswarm.org/mcp, then connect with https://mcp.scienceswarm.org/mcp?key=YOUR_KEY. Everything else is free, no key, no account.

Self-hosting this repo is completely free — every tool, no gating, no key. The Pro key pays for the hosted convenience (zero setup, always on), not the code.

Tools

ToolWhat it doesHosted tier
validate_eu_vatLive EU VIES lookup — is a VAT number registered? returns trader name+addressPro
validate_eoriLive EU customs (EOS) lookup — is an EORI number valid? Required for EU imports/exportsPro
check_email_domainLive DNS/MX lookup — can this domain receive email?Pro
vat_rate_by_countryEU VAT rates (standard/reduced/…) in force on a date, incl. regional exceptionsFree
validate_ibanISO-7064 mod-97 + country lengthFree
validate_aba_routingUS ABA routing-number checksumFree
validate_gtinGTIN-8/12/13/14 barcode check digitFree
stripe_connect_splitStripe Connect three-way fee split (buyer/Stripe/platform/seller)Free
payout_reconciliationGross → deductions → expected payout, flags the unexplained gapFree
reorder_pointLead-time demand + safety stock; reorder-now verdictFree

All tools return structured JSON. Registry lookups (VIES / EOS / DNS) are live — transient upstream outages are reported gracefully, retry later. Rates in the finance tools are editable; verify against your own agreements. No secrets or customer data are stored.

Plain REST API (same tools, same key)

Not using MCP? Every validator is also a plain GET endpoint:

https://mcp.scienceswarm.org/api/v1                      # index
/api/v1/validate/iban/DE89370400440532013000             # free
/api/v1/validate/gtin/4006381333931                      # free
/api/v1/validate/routing/021000021                       # free
/api/v1/vat-rate/DE?date=2026-07-01                      # free
/api/v1/validate/vat/IE6388047V?key=YOUR_KEY             # Pro (live VIES)
/api/v1/validate/eori/DE1234567890?key=YOUR_KEY          # Pro (live EU customs)
/api/v1/validate/email/example.com?key=YOUR_KEY          # Pro (live DNS/MX)

Comparable VAT-validation APIs start at $15/month; the Pro key here is one-time.

Self-host

pip install mcp
python3 server.py                              # local stdio — all tools free
MCP_HTTP=1 MCP_PORT=8790 python3 server.py     # remote streamable HTTP

Or with Docker:

docker build -t commerce-validators .
docker run -i commerce-validators

MIT licensed.

Reviews

No reviews yet

Be the first to review this server!