MCP.so
Sign In

Twosio

@2s-io

About Twosio

575+ pay-per-call tools for AI agents: ground-truth data, AI gateway, and agent infra. x402 USDC, no keys, upto usage billing.

Config

Add this server to your MCP-compatible client using the configuration below.

{
  "mcpServers": {
    "twosio": {
      "command": "npx",
      "args": [
        "-y",
        "@2sio/mcp"
      ],
      "env": {
        "TWOSIO_X402_PRIVATE_KEY": "<your 0x... EVM key with USDC on Base>"
      }
    }
  }
}

Tools

200

Find the right 2s endpoint(s) for a task using a natural-language query (e.g. "screen a company for sanctions", "decode a VIN", "check a domain's email security"). Returns ranked matches with id, path, method, price, and description. Use this to discover capabilities before calling.

Run up to 50 endpoint calls behind ONE x402 payment. Price = exact sum of the sub-call prices (no discount). Atomic: every sub-call must succeed or nothing is charged (failures are returned so you can retry for free). Sub-calls must be ordinary catalog endpoints (no bearer-only, deprecated, variable-priced, or metered-upstream endpoints; no nested batch). Each item carries that endpoint's own response in `data`.

Ground-truth soil profile for any US lat/lng from USDA-NRCS SSURGO. Returns the soil map unit + component soil types ranked by composition %, each with taxonomic order/class, drainage class, hydrologic group, and slope. Keyless, public-domain. For agronomy, land/septic/foundation suitability, hydrology, crop-fit. Water/unsurveyed points return an empty component list.

USDA Plant Hardiness Zone for a US ZIP code — planting zone (e.g. "9b") + average annual minimum-temperature range (°F) + ZIP centroid. Keyless, public-domain. The "what grows where" primitive for gardening/landscaping/nursery/agronomy.

US Drought Monitor severity for a county (5-digit FIPS) or state (2-letter). Weekly % of area in each category (None, D0 Abnormally Dry → D4 Exceptional), newest first, with the worst category per week. Keyless, public-domain (NDMC/USDA/NOAA). The official metric behind USDA disaster eligibility.

USDA NASS QuickStats — authoritative US ag statistics: crop yields, acreage, production, livestock inventory, prices received. Filter by commodity (CORN/SOYBEANS/CATTLE…), year (or year__GE/__LE range), state (2-letter), county, statistic category (YIELD/PRODUCTION/AREA HARVESTED/PRICE RECEIVED), aggregation level. 50k-row cap — narrow broad queries. Public-domain.

Search FCC ECFS filings for a proceeding/docket (e.g. 17-108 net neutrality, 11-42 Lifeline), optionally by filer. Returns newest filings with submission id, filer, type, lead bureau, received/disseminated dates, doc count. Track FCC regulatory dockets, comments, ex-parte filings. Public-domain.

Map a US lat/lon to its FCC spectrum-licensing geographies — Cellular Market Area (CMA), Basic/Major Trading Area (BTA/MTA), Partial Economic Area (PEA), and BEA/EAG/MEA/REAG economic areas — plus 2020 Census block FIPS, county, and block population. These define spectrum-license boundaries; distinct from ordinary geocoding. Keyless, public-domain.

Full occupation dossier from O*NET (US DOL) by SOC/O*NET-SOC code (e.g. 15-1252). Returns title, description, bright-outlook flag, sample job titles, and top skills, knowledge, abilities, work tasks, and technology tools. CC-BY. The canonical occupation reference for résumé/JD reasoning + career mapping; pair the code with labor.wages.

Find O*NET occupations by keyword (job title, skill, or activity). Returns ranked occupations with SOC/O*NET-SOC code + title. The "occupation code for this job/skill" primitive — every occupation.* / labor.wages call composes on the code. CC-BY.

Occupations related/career-adjacent to a given O*NET occupation, by SOC/O*NET-SOC code. Returns ranked related occupations (code + title). For career-pathing and transferable-skills reasoning. CC-BY.

Occupational employment + wages from BLS OEWS by SOC code, nationally or by US state. Pass soc (e.g. 15-1252 Software Developers) + optional 2-letter state. Returns employment, hourly mean, and annual mean + 10th/25th/median/75th/90th-percentile wages (latest survey year). Authoritative ground-truth wages for comp benchmarking. Public-domain.

US labor-market turnover from BLS JOLTS (total nonfarm, national), monthly newest-first. measure = openings (default) / hires / quits / layoffs / separations. Returns level in thousands per month. The standard labor-tightness (openings) + worker-confidence (quits) signal. Public-domain.

US unemployment from BLS, monthly newest-first — national (CPS, area="US") or by state (LAUS). measure = rate (default) / unemployed / employed / laborforce. Seasonally adjusted; rate in percent, counts in thousands. Public-domain.

Search the US Coast Guard PSIX vessel registry by name (partial), call sign, official number, hull number (HIN), flag, service type, or build year. Returns vessels with USCG vessel id, name, call sign, service type, build year, status, official number, HIN, flag. Keyless, public-domain. US-flagged vessels + foreign vessels with US PSC activity. Pair vesselId with maritime.cases.

US Coast Guard activity / port-state-control case history for a vessel, by USCG vessel id (from maritime.vessel). Returns cases newest-first with activity id, start date, type (Boarding, Inspection, Investigation…), and process status. Keyless, public-domain. The compliance/inspection record behind a vessel.

Look up world ports and terminals in the NGA World Port Index (Pub 150, ~2,950 ports) by port name (partial) and/or country (full name, e.g. "Japan"). Returns matching ports with location (lat/lon, country, region), UN/LOCODE, harbor size/type and shelter, max vessel length/draft (m), channel/anchorage/cargo-pier depths, tidal range, and chart number. Keyless, public-domain (NGA). Physical-port reference an LLM cannot recall; complements maritime.vessel + maritime.cases.

Resolve a song/recording from MusicBrainz (open, CC0 music encyclopedia). Pass artist + title, or a free-text/Lucene query. Returns ranked recordings with MBID, title, primary artist, length (ms), first-release date, disambiguation. Keyless, public-domain. Canonicalize a track to its MBID.

Resolve a music artist from MusicBrainz (CC0). Pass a name or query. Returns ranked artists with MBID, name, sort name, type (Person/Group), country, gender, life span, disambiguation. Keyless, public-domain.

Resolve an album/release from MusicBrainz (CC0). Pass a barcode (UPC/EAN), artist + album, or a free-text query. Returns ranked releases with MBID, title, artist, date, country, barcode, status, track count, label, catalog number. Barcode → album is the differentiated lookup. Keyless, public-domain.

Search US patent applications and grants (USPTO Open Data Portal). Returns titles, inventors, applicants, status, classification codes, and Patent Center URLs.

Full file-wrapper detail for a US patent application: bibliography, event timeline (filings, Office Actions, allowances), continuity chain (parents, divisionals), assignments, foreign priority.

List every document in a US patent application file wrapper: Office Actions (CTNF, CTFR), IDS, claims, notices of allowance. Returns code, description, official date, and Patent Center download URL.

Validate a cryptocurrency address with full checksum verification (not just regex). Catches typos before sending funds. Chains: btc, eth, sol, ltc, trx, xrp, bch.

Live EVM transaction status + receipt by hash: mined/reverted/pending, block, confirmations, timestamp, from/to, value, gas used, effective gas price, total fee, contract created, log count. Chains: base, ethereum, polygon, arbitrum, optimism. Confirm a payment settled or a tx reverted before acting. 404 if unknown.

Validate an IBAN (International Bank Account Number) with full ISO 13616 checks: country-specific length + ISO 7064 mod-97 checksum, not just regex. Returns valid flag, normalized + 4-char-grouped form, country, check digits, and BBAN. Deterministic, ~85 countries — validate AND canonicalize bank details in one call instead of doing checksum math in an LLM.

Validate a product barcode (GTIN-8/12/13/14, UPC-A, EAN-13, ISBN-10/13) with the GS1 mod-10 / ISBN mod-11 check digit. Returns valid, type, and the canonical GTIN-14 key for product-master dedup. Deterministic — no checksum math in the LLM.

Validate a US bank ABA routing number with the Federal Reserve weighted mod-10 (3-7-1) checksum, not just a regex. Returns valid, routingNumber, and routing-symbol district. Catches transposed digits in ACH/wire setup.

Validate a Legal Entity Identifier (LEI, ISO 17442) with the ISO 7064 mod-97-10 check digits. Returns valid, normalized LEI, and the issuing LOU prefix. Confirms a counterparty/vendor LEI is well-formed before GLEIF lookup.

Validate a SWIFT/BIC code (ISO 9362): 8 or 11 chars = institution + ISO country + location + optional branch, with the country checked against ISO 3166. Returns parsed parts. Structure only, not a directory lookup.

Validate a GS1 GLN (Global Location Number), 13 digits with the GS1 mod-10 check digit. GLNs identify trading parties + physical locations in CPG supply chains / EDI. Deterministic.

Validate a GS1 SSCC (Serial Shipping Container Code), 18 digits with the GS1 mod-10 check digit. SSCCs identify logistic units (pallets/cases) — the key field in shipping/ASN (EDI 856). Deterministic.

Validate an ISIN (ISO 6166 securities identifier): 2-letter country + 9-char NSIN + Luhn check digit. Returns valid, country, nsin, and the embedded CUSIP for US/CA issues. Catches transposed chars in security master data.

Validate a CUSIP (9-character US/Canada securities identifier) with its mod-10 weighted check digit. Returns valid + check digit. Deterministic security-master validation.

Validate up to 100 mixed identifiers in one deterministic call. Pass items=[{type,value}] with type one of iban, gtin, aba, lei, bic, gln, sscc, isin, cusip. Each result (in input order, with index + type) carries valid/reason plus the same type-specific fields the single endpoints return. One bad value or unsupported type degrades to that item only. Collapses a whole record of checksum checks into one round-trip.

Deterministic unit-of-measure conversion: mass (g/kg/lb/oz/t…), length (m/km/in/ft/mi…), volume (l/ml/gal/qt/cup…), area (m2/ft2/acre/ha), temperature (C/F/K). Case-insensitive with aliases (kg/kilogram). Returns the exact result + dimension. Cross-dimension (kg→m) is rejected. Ground-truth factors instead of an LLM approximation.

Convert an amount between currencies at a live or historical exchange rate. Pass from + to (3-letter ISO 4217) + optional amount (default 1) + date (YYYY-MM-DD for historical; omit for latest). Returns the converted result, per-unit rate, and effective rate date. Live ECB reference rates (via Frankfurter), fetched per request — never stale; weekends/holidays use the last business day. ECB major currencies.

ISO 4217 currency lookup. Pass code (alphabetic USD or 3-digit numeric 840) or country. Returns alphabetic + numeric code, English name, minor unit (decimal places — JPY 0, USD 2, BHD 3), and countries using it. Bundled authoritative ISO 4217 data.

ISO 639 language lookup. Pass code in any form — 639-1 (en), 639-2/B (ger), 639-2/T (deu) — or name. Returns the English name + all sibling codes (alpha-2, alpha3-B, alpha3-T), resolving the bibliographic/terminological split (German = de/deu/ger). Bundled authoritative ISO 639 data.

ISO 3166-2 subdivision lookup (states/provinces/regions). Pass code (US-CA) to resolve one → name + country, or country (2-letter, US) to list all its subdivisions with codes. Bundled authoritative ISO 3166-2 data (~3.8k subdivisions, 237 countries).

List the official holidays for a country and year with exact observed dates, including substitute days (e.g. a Saturday July 4th observed Friday). 200+ countries, regional subdivisions (US states, German Länder, Canadian provinces…), movable feasts and lunar-calendar holidays computed from maintained rules. Filter by type (public, bank, school, optional, observance) and localize names via lang. Returns {date, name, type, substitute, rule} per holiday.

Holiday-aware business-day calculator for 200+ countries — the ground-truth answer for payment terms, SLA deadlines, and delivery dates instead of guessing holidays. Three modes: start+addDays shifts a date by N business days (signed); start+end counts business days between two dates (exclusive of start, inclusive of end); start alone checks one date (business day? which holiday? next/previous business day). Custom weekends supported (e.g. fri,sat for the Gulf). Skipped holidays are itemized.

Validate an EU VAT number against the official VIES register in real time. Confirms current registration for intra-EU trade and, when the member state discloses it, returns the registered business name + address. Covers the 27 EU states (Greece as EL) plus Northern Ireland (XI); Great Britain (GB) is not in VIES. Pass vat (full identifier like DE811569869) OR country + number. Returns {valid, countryCode, vatNumber, name, address, requestDate, reason}.

Current EU VAT rates by member state — standard rate plus reduced/super-reduced/parking/zero rates — from the European Commission TEDB, refreshed regularly. Pass country (ISO 2-letter; Greece is EL) for one state, or omit for all 27. Each result returns standardRate, reducedRates[], every rate category with its percentage, and the date in force. Pairs with tax.vat (number validation).

Adjust a US dollar amount for inflation between two dates ('what is $100 in 1990 worth today?') using CPI-U. Returns the adjusted amount, cumulative inflation %, annualized rate, and the CPI values used. Source: BLS CPI via FRED.

Current US inflation by measure with index level + YoY/MoM %. Pass measure (cpi, core-cpi, pce, core-pce, ppi, cpi-shelter, cpi-energy, import-prices, ...) or omit for all. The YoY change is the headline inflation rate. Source: BLS/BEA via FRED.

US inflation expectations — 5y & 10y TIPS breakevens, 5y5y forward, and U-Michigan 1-year consumer expectation. Each a percent. Market breakevens update daily. Source: Fed/Treasury via FRED.

EU harmonized inflation (HICP annual rate) — the official cross-country-comparable inflation rate for the EU, euro area, and each member state. Pass country (Eurostat geo: DE, FR, EL=Greece, EA20=euro area, EU27_2020=EU) or omit for all. Source: Eurostat (keyless). For US inflation use inflation.rates.

Latest reading of a curated US macro indicator (+ prior, year-ago, YoY %). Pass indicator (unemployment-rate, fed-funds-rate, real-gdp, gdp-growth, nonfarm-payrolls, 10y-treasury, 30y-mortgage, consumer-sentiment, ...) or omit for all. Source: BLS/BEA/Fed via FRED.

Any series in the Federal Reserve's FRED database (800k+ economic time series). Pass seriesId (e.g. UNRATE, CPIAUCSL, GDP, DGS10, MORTGAGE30US) for metadata + recent observations (optionally bounded by start/end), or query to full-text search the catalog. Free, public-domain for most series (FRED attribution). Distinct from econ.indicator (curated headline set) — this is the full FRED catalog by id or search.

US economic-data release CALENDAR from FRED — when official reports are published. Returns upcoming release dates (date, release name, release id) from `from` (default today), ascending. Filter by name (e.g. "Consumer Price Index" for next CPI, "Employment Situation" for jobs) or releaseId. Free, public-domain. Future release dates an LLM cannot know — for trading/scheduling/macro agents. Pair with econ.fred for the numbers.

Point-in-time (vintage) economic data from FRED's ALFRED archive — what a figure was AS FIRST REPORTED / as known on a past date, before revisions. Give seriesId (GDP, GDPC1, PAYEMS…) + asOf date for the values as they stood then (omit asOf for current); also returns the series' revision dates. Free, public-domain. Eliminates look-ahead bias for backtesting/macro research — unavailable from any LLM or real-time API.

Browse the FRED category tree to DISCOVER economic series. Pass categoryId for that category (name+parent) + its child categories + its most-popular series (id/title/units/frequency); omit (or 0) for the 8 top-level categories. Walk down via child ids, then fetch with econ.fred. Free, public-domain.

FRED regional economic data — one snapshot of a regional FRED series across ALL its geographies (every U.S. state, county, or metro) for a single period. Pass a regional series id (e.g. WIPCPI = per-capita personal income by state) and get each region's name, FIPS region code, value, and per-region series id, plus units/frequency/available date range. Add date (YYYY-MM-DD) for a point-in-time cross-section; omit for latest. Authoritative St. Louis Fed (GeoFRED) data agents can't recite. Free, public-domain.

Current US Treasury yield curve (1M–30Y constant-maturity yields) plus the 2s10s and 3m10y spreads and an inversion flag (recession signal). Daily data. Source: US Treasury via FRED.

Latest benchmark commodity price + % change. Pass commodity (wti, brent, natural-gas, gasoline, diesel, heating-oil, propane, copper, aluminum, corn, wheat, sugar) or omit for all. Each names the FRED series + unit. Source: EIA/IMF via FRED.

Composite US recession-signal dashboard: NY Fed recession probability (12mo ahead), Sahm-rule real-time indicator (≥0.50 = recession begun), and 10y2y Treasury spread (negative = inverted). Each with value, date, triggered flag, and a count of signals flashing. A read of the standard gauges, not a forecast. Source: FRED.

Parse a raw ANSI X12 EDI document (B2B purchase orders, invoices, ship notices, etc.) into clean structured JSON. POST edi with the raw interchange text. Auto-detects delimiters; returns interchange metadata, each functional group + transaction set with its type decoded (850 PO, 810 invoice, 856 ASN, 855 PO ack, 997 ack), every segment named, and a semantic summary (PO/invoice numbers, parties, line items, totals). Deterministic, no external calls.

Parse a raw UN/EDIFACT document (the B2B EDI standard used across Europe, Asia, logistics and customs — international counterpart to ANSI X12) into clean structured JSON. POST edi with the raw interchange text. Reads the optional UNA service-string advice to auto-detect delimiters (or applies UN defaults); handles release-character escaping; returns the interchange envelope (UNB: sender/recipient with qualifiers, date/time, control reference, test indicator) and each message with its type decoded (ORDERS PO, INVOIC invoice, DESADV ASN, ORDRSP PO response, CONTRL ack), every segment named (BGM, DTM, NAD, LIN, QTY, MOA…), and a semantic summary (order/invoice numbers, dates, parties with role decoded, line items, totals). Deterministic, no external calls.

Generate an outbound UN/EDIFACT document from JSON (international counterpart to edi.generate/X12). POST type ('ORDERS' PO or 'INVOIC' invoice) + senderId, recipientId, documentNumber, optional date, parties (NAD role+name), items (quantity, productId, price), and for INVOIC optional total. Returns the full EDIFACT interchange in meta.edi (UNA/UNB/UNH…UNT/UNZ with BGM/DTM/NAD/LIN/QTY/PRI/MOA), proper delimiters + release-char escaping. Deterministic; round-trips through edi.edifact.

Grade a domain's email-authentication / DNS-security posture from live DNS in one call: SPF, DMARC (policy), DKIM (supplied/common selectors), MTA-STS, TLS-RPT, DNSSEC, CAA, BIMI. Pass domain (+ optional dkimSelector). Returns a letter grade, a summary (incl. spoofingProtected), and a per-mechanism block with the raw record, parsed tags, and specific issues. Live DNS via DoH (keyless) — an LLM can't know a domain's current records.

Certificate Transparency recon for a domain — discover its subdomains and issued certificates from public CT logs (passive attack-surface mapping). Pass domain (+ optional limit). Returns deduplicated subdomains + certs (issuer, validity, SAN names), newest first. certSpotter primary, crt.sh fallback, keyless. CT shows names that ever appeared in a cert, not necessarily live hosts.

Fetch a URL and grade its HTTP security headers (CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, COOP/CORP). Pass url. Returns a letter grade + score, present/missing headers, and a per-header analysis with the live value and issues. Also flags Server/X-Powered-By info disclosure. SSRF-guarded live fetch (private targets refused) — an LLM can't see a site's current headers.

Check whether a password appears in known breaches via Have I Been Pwned's k-anonymity model — only the first 5 chars of the password's SHA-1 are sent upstream, never the password or full hash. POST { password } (hashed server-side) or { sha1 } (the 40-hex SHA-1, for zero-knowledge). Returns breached + count. 900M+ breach corpus; for signup/password-policy enforcement. Absence ≠ strength.

Threat-intel reputation for an IOC — pass ioc as an IP, domain, URL, or file hash (auto-detected). Returns a malicious boolean + per-source breakdown: abuse.ch ThreatFox, URLhaus, MalwareBazaar, Feodo Tracker (botnet C2 IPs), Tor exit nodes, Spamhaus DROP. Live, hourly-rotating threat feeds an LLM cannot know — a ground-truth check for SOC alert triage. Absence ≠ safety.

Multi-source IP reputation with one combined authority score (0-100). Polls AbuseIPDB (crowd abuse confidence), abuse.ch threat-lists (Feodo C2 + ThreatFox + Spamhaus DROP + Tor), blocklist.de (fail2ban network), and StopForumSpam in parallel and blends them into a verdict (clean/low/suspicious/malicious) + flaggedBy + per-source opinions + enrichment (ISP, usage type, country, ASN, Tor). Authoritative threat-list hits hard-floor the verdict at malicious. The one-call 'should I trust this IP?'.

AbuseIPDB single-IP abuse check. Pass ip (IPv4/IPv6). Returns abuseConfidenceScore (0-100), totalReports, numDistinctUsers, lastReportedAt, usageType, ISP, domain, hostnames, isTor, isWhitelisted, country. verbose=true adds individual report records; maxAgeInDays (1-365, default 90) bounds the window. Live crowd data for SOC triage and login-abuse blocking.

AbuseIPDB bulk blacklist — most-reported abusive IPs above a confidence threshold (the fail2ban / firewall block-feed). Tune confidenceMinimum (25-100, default 90), limit (1-10000), ipVersion (4/6), onlyCountries / exceptCountries (ISO-2). Returns each IP with country, confidence, lastReportedAt + the list generatedAt.

AbuseIPDB subnet (CIDR) check — which IPs inside a network block have been reported. Pass network as a CIDR (e.g. 118.25.0.0/24; up to /16 IPv4, /112 IPv6). Returns block metadata + reportedAddress (each flagged IP with numReports, confidence, mostRecentReport, country). Optional maxAgeInDays (default 30), limit. Vet a hosting range or sweep your own allocation.

Authoritative MITRE CWE (Common Weakness Enumeration) lookup. Pass id (CWE-79 or 79) for the canonical weakness — name, abstraction, description, ChildOf/ParentOf relationships, mapped CAPEC patterns (all with names) — or query for keyword search. Bundled (~970), zero external calls. Anti-hallucination: agents cite CWE IDs/names that must be exact. Pairs with security.cve + security.capec.

Authoritative MITRE ATT&CK (Enterprise) technique lookup. Pass id (T1059 / T1059.001) for name, tactics, description, platforms, sub-technique parent, mitigations, detection — or query for keyword search. Bundled (~700 techniques), zero external calls. Agents cite T-numbers + tactics that must be exact. For threat modeling, detection engineering, report enrichment.

Authoritative MITRE CAPEC (Common Attack Pattern Enumeration) lookup. Pass id (CAPEC-66 or 66) for name, abstraction, description, likelihood, severity, mapped CWE weaknesses + related patterns (with names) — or query for keyword search. Bundled (~615), zero external calls. The attacker view; CAPEC↔CWE cross-links let an agent pivot between an attack and the weakness it exploits.

Does public exploit code exist for a CVE, and where? Pass cve (CVE-2021-44228). Returns hasPublicExploit, count, hasMetasploitModule + hasVerifiedExploit flags, and Exploit-DB entries (description, type, platform, date, link). Bundled Exploit-DB index (~25k CVEs). The 'is it weaponized?' triage signal BEYOND security.cve's KEV (in-the-wild) + EPSS (probability). Absence != no exploit exists.

RPKI Route Origin Validation for a (BGP origin AS, prefix) pair — is this AS authorized to originate this prefix? Pass asn (AS15169) + prefix (8.8.8.0/24). Returns status (valid / invalid = possible hijack / unknown), a hijackSignal boolean, validating ROAs, and a description. Live RIR/RPKI data via RIPEstat (keyless). The core BGP-security check.

Official US EPA/DOE fuel-economy, fuel-cost, and emissions data for a vehicle by year + make + model. Returns one entry per powertrain configuration: MPG city/highway/combined (MPGe for EVs), CO2 grams/mile, annual fuel cost, annual petroleum barrels, EPA greenhouse-gas score, 5-year savings vs average, transmission, drivetrain, cylinders, displacement, fuel type, size class, EV range. Authoritative EPA figures; keyless, public-domain, 1984+.

Canadian-market vehicle dimensions/weights from NHTSA vPIC Canadian Vehicle Specifications. Pass year + make (required) + optional model. Returns labeled dimensions — overall length/width/height (cm), wheelbase, curb weight (kg), track width, interior room, weight distribution — plus the raw spec map. Keyless, public-domain, 1971+.

CVE change feed — the CVE records MODIFIED within a time window, so an agent can incrementally maintain a vulnerability view instead of re-scanning. Pass since (YYYY-MM-DD or ISO datetime); until defaults to now (window ≤120 days). Optional keyword/cpe filter. Each result: id, published + lastModified, vulnStatus, CVSS score/severity, description, and kevListed (now on the CISA Known-Exploited catalog). Newest first. Live NVD + CISA KEV, keyless. Pairs with security.cve for full detail.

Compute a loan or mortgage amortization schedule. Pass principal, annualRatePct (e.g. 6.5), and term as termMonths or termYears; optional extraMonthly adds extra principal each month. Returns the fixed monthly payment, total interest, total paid, payoff month count, and the full month-by-month schedule (payment/principal/interest/balance). Deterministic, no external calls.

Validate an email address: RFC syntax validity, normalized address with local/domain, and flags for isDisposable (throwaway domain), isRoleAccount (info@/support@/…), isFreeProvider (gmail/outlook/…). With checkMx (default true) also reports hasMxRecords (domain MX presence, via DNS-over-HTTPS) + MX hosts. NOT a deliverability or mailbox-existence guarantee — signals only. For signup hygiene and lead scrubbing.

Current US State Department travel advisories. Omit country for the full list, or pass a country name (case-insensitive substring) for one. Returns the advisory level (1 Normal Precautions → 4 Do Not Travel) with label, a plain-text summary of reasons, the official link, and published date. Live from the official travel.state.gov RSS feed (public domain).

Visa requirement for a passport × destination. Pass passport and destination as ISO-3166 alpha-3, alpha-2, or country name. Returns the category — visa free (with visaFreeDays), visa on arrival, e-visa, eta, visa required, or no admission — plus a plain-language description. Community-maintained Passport Index dataset (MIT); informational, not official immigration advice.

US drug pricing from CMS NADAC (National Average Drug Acquisition Cost), the benchmark per-unit acquisition cost CMS surveys weekly. Pass ndc (11-digit NDC) for an exact product or name (e.g. 'atorvastatin 10 mg') to search. Returns NDC, description, nadacPerUnit (USD), pricingUnit, effectiveDate, OTC flag, brand/generic classification — newest first. Real surveyed acquisition costs (not retail/insured price). Public domain; current-year dataset auto-resolved.

Domain intelligence in one call — composes DNS (A/AAAA/MX/NS/TXT), WHOIS/RDAP (registrar, dates, status, nameservers, DNSSEC), and the live TLS certificate (issuer, validity, SANs, fingerprint) for a domain. Returns a summary (resolves, has MX, registrar, domain expiry, HTTPS valid, days to cert expiry) plus a found/error block per section. For domain due diligence, security recon, and expiry monitoring.

Full Know-Your-Business (KYB) intelligence dossier on a company in one call. Pass name (company name); optional state narrows federal awards, optional ticker pulls SEC EDGAR identity + filings. Fans out to SAM registration, SAM exclusions (debarment), OFAC sanctions, GLEIF LEI, USAspending awards, FARA foreign-agent registration, and USPTO trademarks owned. Returns riskFlags + a cleared boolean (debarment+sanctions), a summary of every signal, and a found/error block per source. For vendor onboarding, KYB/AML, and procurement due diligence. Probabilistic name matching — verify with a hard identifier before acting.

Generate the ANSI X12 997 Functional Acknowledgment for a received EDI interchange. POST edi with the raw inbound interchange (the 850/810/856 you received); returns the ready-to-send 997 in meta.ack — sender/receiver mirrored, delimiters echoed, one ST(997) per inbound functional group with correct AK1/AK2/AK5 and AK9 included/received/accepted counts. status controls the response: A=Accepted (default), E=Accepted with errors, P=Partial, R=Rejected, M/W/X=auth/security rejection. Deterministic, no external calls — the reply leg of EDI.

Generate an outbound ANSI X12 EDI document from JSON. POST type (850 = Purchase Order, 810 = Invoice) + senderId, receiverId, documentNumber (PO#/invoice#), optional date, parties (N1 role+name), items (quantity, uom, price, productId); for 810 optionally poNumber + total. Returns the full X12 interchange in meta.edi (correct ISA/GS/ST…SE/GE/IEA envelope). Deterministic — the outbound complement to edi.parse + edi.ack.

Search the global corpus of published fact-checks (ClaimReview) by claim text. Returns matching claims with the claimant, claim date, and each review's verdict (textualRating like "False"/"Misleading"/"True"), publisher (PolitiFact, Snopes, FactCheck.org, Reuters, AFP…), review URL and date. Covers all topics — politics, health, science, viral/misinformation. Optional language, maxAgeDays, and publisher-site filters. Check whether a claim was fact-checked + how it was rated instead of asserting from training.

Current aviation weather observation (METAR) for airports. Pass ids (comma-separated ICAO, e.g. KATL,EGLL). Returns raw METAR + decoded flight category, temp/dewpoint, wind, visibility, altimeter, clouds. Source: NOAA Aviation Weather Center (keyless).

Terminal Aerodrome Forecast (TAF) for airports — the official ~24–30h aviation forecast. Pass ids (comma-separated ICAO). Returns raw TAF + issue time. Source: NOAA Aviation Weather Center (keyless).

Active in-flight weather hazard advisories (SIGMETs/AIRMETs) from the NOAA Aviation Weather Center. Returns current advisories over a 1-24h window, optionally filtered by hazard (CONVECTIVE, TURB, ICE, IFR, MTN OBSCN, ASH). Each carries issuing office, type, hazard, severity, valid-from/to, altitude band (ft MSL), movement (dir/speed), and raw bulletin. Keyless, public-domain. The active-hazard layer beyond aviation.metar/taf. Not for navigation.

Search NTSB civil aviation accident/incident history (CAROL database). Filter by registration (N-number), state, make, model, city, and/or date range (dateFrom/dateTo YYYY-MM-DD). Returns events with date, location, aircraft, injury severity/counts, flight phase, and an NTSB report URL. Free, US public-domain. At least one filter required.

Current US disease surveillance from the CDC (NNDSS weekly notifiable-disease counts, MMWR 2022→current). Filter by condition (substring), location (state/region/territory/national), and/or year; weeks/limit page results. Returns current-week count, prior-52-week max, and cumulative YTD per condition+location+week. Free, keyless CDC data. At least one of condition/location required.

Look up an IETF RFC by number. Returns status (e.g. INTERNET STANDARD/PROPOSED STANDARD), title, authors, date, stream, DOI, and the obsoletes/obsoleted-by/updates/updated-by relationship chain. Bundled RFC index (~9.8k RFCs); anti-hallucination on RFC status/relationships.

Check whether a shell command is runnable before running it — a pre-execution gate for agent-generated commands. POST command (curl/wget/httpie or anything with a URL). Parses out method, target URL, and headers and returns a structured verdict: verdict ('runnable'/'invalid'), runnable boolean, and a checks breakdown (hasTarget, urlValid, schemeOk, hostPresent, methodValid, privateTarget). Default is STATIC + deterministic (no network) — a command with no URL is invalid. Pass probe=true to also run a guarded HEAD against the target and report dnsResolves/reachable/tlsValid/httpStatus. Private/loopback targets are refused (SSRF-safe).

Real-time US river/stream conditions from a USGS monitoring site. Pass site (USGS site number, e.g. 01646500). Returns latest streamflow, gage height, water temp + site name/location. Source: USGS NWIS (keyless).

DeFi total-value-locked (TVL) via DefiLlama. No params → top protocols by TVL (name, category, TVL, 1d/7d change, chains) + total DeFi TVL. protocol=<slug> (e.g. lido, aave, uniswap) → one protocol; chain=<name> (e.g. ethereum, solana) → that chain's TVL. Distinct from crypto.markets (spot prices) — protocol/chain capital locked. Free, keyless.

Decode an EVM smart contract. Pass chain (ethereum, base, polygon, arbitrum, optimism, bsc, avalanche) + address → whether source-verified (Sourcify), name/compiler/language, proxy + implementation, and human-readable function/event signatures from the ABI. Optional selector (0x 4-byte) → decode what it calls (from the contract ABI if verified, else the 4byte directory). Pairs with crypto.tx. Free, keyless.

Crypto Fear & Greed Index — 0–100 market sentiment (0 = Extreme Fear, 100 = Extreme Greed), updated daily, with classification. Pass limit (1–90) for recent history. Contrarian sentiment signal. Source: alternative.me.

Top cryptocurrencies by market cap with live price, market cap, 24h volume, and 24h + 7d % change. Pass limit (1–100, default 20). Source: CoinGecko. Single token = crypto.token-price; market overview = crypto.global.

Whole-crypto-market overview: total market cap, 24h volume, 24h change, BTC + ETH dominance, active-coin count. Source: CoinGecko.

Most-searched trending cryptocurrencies right now (24h), with symbol, name, market-cap rank, price. Attention signal. Source: CoinGecko.

Ground elevation above sea level (meters + feet) for any coordinate on Earth. Pass lat + lon. ~90m DEM. Source: Open-Meteo (keyless).

Look up or search the US Harmonized Tariff Schedule (HTS / HS codes). Pass code for an exact HTS number (returns the line + 10-digit stat suffixes with duty rates), or query for free-text → ranked candidate HS codes by hierarchical heading. ~29.6k public-domain USITC lines. The deterministic backbone for tariff classification.

Look up or search UN/LOCODE — the UN Code for Trade and Transport Locations (~116k locations, all countries). Pass locode for an exact code (e.g. USNYC), or query to search names with optional country (ISO alpha-2) and function (port, rail, road, airport, postal, multimodal, fixed, border) filters. Returns name, subdivision, transport functions, status, IATA code, coordinates. The standard location identifier in shipping, EDI, and customs documents.

Annual international merchandise-trade flows from UN Comtrade (HS classification). reporter = country whose trade you want (ISO-2/ISO-3 'US'/'USA', UN M49 number, or 'World'); optional partner (default World); year (YYYY); flow (export|import); commodity = 'TOTAL' (default), a specific HS code ('27','8703'), or 'AG2'/'AG4'/'AG6' for a top-commodity breakdown. Returns trade value (USD), net weight, quantity, HS commodity, sorted by value.

Live EVM gas oracle. Returns slow/standard/fast tiers derived from priority-fee percentiles over the trailing 4 blocks plus a 21,000-gas transfer cost estimate. Chains: base, ethereum, polygon, arbitrum, optimism.

Current Bitcoin network fee rates and mempool backlog from mempool.space. Returns recommended fee rates (sat/vByte) for fastest/half-hour/hour/economy/minimum confirmation, plus mempool size (tx count, vsize, total fees waiting). Keyless, live. The BTC counterpart to crypto.gas-oracle.

Summarize a webpage. Returns a short summary, 3-7 key points, title, audience, and reading time. Backed by an upstream LLM.

Translate text into a target language. Source language auto-detected if omitted.

Fetch a URL and extract typed data from its content per a user-supplied JSON Schema. Use when you need a structured payload conforming to your own shape.

Describe an image (JPEG/PNG/GIF/WebP, ≤1MB) via Claude Haiku vision. Returns caption + structured details.

Take a headless-browser screenshot of a URL. Returns base64 image + size metadata.

Provider 360 by NPI — merges NPPES identity (name, specialty, address, licenses) + CMS Open Payments (industry payments) + CMS Medicare billing in one call. Each section reports found/error independently. KYC, healthcare-fraud, provider due diligence.

Vehicle 360 by VIN — decodes the VIN (make/model/year/trim/engine, NHTSA vPIC) then returns THAT vehicle's open safety recalls and owner complaints, keyed to the decoded make/model/year. Used-car due diligence, fleet safety, insurance.

Company 360 by ticker — merges recent SEC filings + curated XBRL fundamentals (revenue, net income, EPS, assets) + recent insider (Form 4) transactions in one call. Equity research, due diligence, monitoring.

Asteroid/comet physical + orbital parameters from NASA JPL Small-Body Database by designation, number, or name (e.g. "433 Eros", "1P/Halley", "2024 YR4"). NEO/PHA flags, diameter, albedo, orbit class, eccentricity, period, Earth MOID.

Near-Earth asteroid/comet close approaches to Earth in a date window + max distance (NASA JPL CAD). Returns designation, date, distance (AU + lunar distances), relative velocity, magnitude. Sorted nearest-first.

Current position of any cataloged satellite by NORAD number (e.g. 25544=ISS) via fresh Celestrak elements + SGP4. Returns sub-point lat/lon/altitude + speed; pass observer lat/lon for azimuth/elevation/range look angles.

Search the catalog of ~69k cataloged Earth-orbiting objects (CelesTrak SATCAT). Filter by name (q, e.g. "starlink"), owner/launching country (owner = US/PRC/CIS… or a name), object type (payload|rocket body|debris|unknown), launch-year range, intlDesignator prefix, on-orbit vs decayed, or exact noradId. Each row has NORAD id, name, owner+country, launch/decay dates, and orbital params. The envelope total is the full count matching the filter — so onOrbit=true&type=payload answers "how many active satellites".

Upcoming or recent orbital rocket launches (Launch Library 2). when=upcoming|previous, optional search by rocket/provider/mission. Returns name, status, launch time + window, provider, rocket, pad, mission, webcast.

Observer-local sky almanac for a lat/lon + time (computed, no upstream): sun & moon rise/set + current alt/az, moon phase + illumination + next quarter, and all 7 naked-eye planets (alt/az, RA/dec, magnitude, above-horizon). Stargazing, astrophotography.

Confirmed exoplanets from the NASA Exoplanet Archive (~6k, weekly). Filter by name, hostStar, discoveryYear, or method. Returns orbital period, radius/mass (Earth units), equilibrium temp, host-star params, distance (parsecs + light-years).

Resolve any organism (scientific or common name) to the GBIF taxonomic backbone: accepted name, full lineage (kingdom→species), vernacular names, global occurrence count, GBIF link. Fuzzy-matches misspellings.

Gene lookup by symbol + organism (taxid, default 9606=human): NCBI Gene identity (description, chromosome, map location, aliases, RefSeq summary) joined with UniProt protein (accession, name, length, function).

Synthesis — what is notable in YOUR sky right now (lat/lon): the live almanac (sun, moon phase, planets above your horizon), near-Earth asteroid close approaches this week, and the ISS (position + whether it is above your horizon now). One call, three sources, per-section found/error.

Synthesis — profile a confirmed exoplanetary system by host-star name (e.g. "TRAPPIST-1"). Groups the star's planets, summarizes the host star, and COMPUTES the habitable zone (inner/outer AU from stellar luminosity), flagging which planets fall in it.

Where is an asteroid/comet in the sky and can you see it? Propagates JPL orbital elements (validated vs Horizons to <0.1 arcmin) to give geocentric RA/Dec, constellation, distance, phase angle, and apparent magnitude. With observer lat/lon: altitude/azimuth, visible-now flag, and the best dark-sky viewing window in the next 24h.

Full UniProtKB protein entry by accession (e.g. P04637): names, gene, organism, sequence length + molecular weight, function, subcellular locations, GO terms, PDB structures, keywords. Protein-centric sibling to bio.gene.

Identify a US-registered aircraft by tail (N-number) or icao24, AND screen its owner + operator against OFAC sanctions in one call. Returns the aircraft record + per-name sanctions screen with confidence + flagged. OSINT / asset-tracing / sanctions-evasion. Name-based screening is probabilistic.

KYC in one call: look up a business in a US state registry (NY/CO/CT) AND screen it + its registered agent against OFAC sanctions. Returns matched entities each with a sanctions screen (confidence + flagged). Counterparty due-diligence, AML. Probabilistic name match.

Resolve ENS live on Ethereum mainnet: pass an ENS name (e.g. "vitalik.eth") to get its address, or a 0x address to get its primary ENS name (reverse). Also returns avatar, email, url, twitter, github, description text records. On-chain lookup agents can't do from a sandbox.

Convert raw HTML you already have into clean reading markdown (no URL fetch). POST { html }. Strips scripts/nav/ads, extracts main content, preserves headings/links/lists. For fetching a live URL use url.clean instead.

Open a live TLS connection to a host and return its certificate: protocol + cipher, chain validity, leaf subject + issuer, valid-from/to, days-until-expiry, serial, SHA-256 fingerprint, SANs, chain length. Active probe; SSRF-guarded. Cert-expiry monitoring, TLS audits.

Search US federal court dockets (civil + criminal) from the RECAP/PACER archive. q full-text (case/party name) with optional court id + filed date range, or exact docketNumber. Returns case name, court, docket number, dates, judge, docket URL.

Federal Bureau of Prisons inmate search, 1982-present (current + released). By lastName (+ firstName/age/sex/race) or exact BOP register number. Returns name, register number, facility, projected/actual release dates.

US federal lobbying disclosures (Senate LDA) — who lobbies for whom, on what issues, for how much. Filter by registrant (firm), client, lobbyist, year, period, type. Returns income/expenses, registrant + client, issues, document URL.

Track US House members' financial-disclosure filings incl. Periodic Transaction Reports (PTRs — the STOCK Act stock-trade disclosures). Defaults to PTRs; type=annual|candidate|amendment|all for others. Filter by member name (q), state, year, or filing-date range. Returns member, state+district, filing type+label, filing date, and a direct link to the source document. The envelope total answers 'how many PTRs'. 2008→present, refreshed daily. Trades are disclosed up to 45 days after they happen — current-to-the-filing, not real-time.

Search individual US Congress member stock trades parsed from STOCK Act PTRs into clean rows. Filter by member (q), ticker (e.g. NVDA), type (purchase|sale|exchange), state, chamber, or transaction-date range. Each trade: member + state/district, owner (self/spouse/joint), ticker + asset, buy/sell, the disclosed dollar RANGE (amountMin/amountMax — ranges, not exact), transaction + disclosure dates, days-to-disclose, and a link to the source filing. envelope total answers 'how many bought NVDA'. Amounts are ranges; trades disclosed up to 45 days after they happen. Coverage: US House e-filed now, expanding to scanned + Senate.

US mortality statistics (CDC NCHS). dataset=leading-causes: annual deaths + age-adjusted rate by state and top-10 cause, 1999-2017. dataset=weekly-counts: provisional weekly deaths by jurisdiction + cause, 2020-2023.

CMS Care Compare hospital quality ratings (~5,300 Medicare-certified US hospitals): overall star rating + mortality/safety/readmission/patient-experience measure summaries. By facilityId, or state/city/name filters.

Medicare utilization + payments by provider (CMS annual dataset): beneficiary counts, total services, submitted charges, Medicare payment amounts per NPI. By npi, or lastName + state. Pairs with health.open-payments.

State Secretary-of-State business registry search, normalized across states (currently NY, CO). By name (partial) or exact entityId. Returns entity id, name, type, status, jurisdiction, formation date, address, registered agent.

Brazilian company registry lookup by CNPJ (14-digit company tax ID). Returns legal + trade name, registration status, start date, legal nature, size, share capital (BRL), primary CNAE activity, contact, address, and partners/officers (QSA). Free, open Receita Federal data (BrasilAPI). KYB/diligence for Brazilian companies.

Official UK company registry (Companies House). Pass query to search by name, or companyNumber for the full profile — legal name, status, type, jurisdiction, incorporation/cessation dates, SIC codes, registered office, accounts + confirmation-statement due dates, charges/insolvency flags, previous names, and officers (name, role, appointed/resigned, nationality, occupation). Free, Open Government Licence. Authoritative UK KYB lookup.

Full business-entity dossier from a state registry — master record plus officers/principals, registered agent (name, phone, email, address), and filing history. v1 state: CT (Connecticut). Resolve by entityId (registry record id), accountNumber, or name (partial; most recent registration wins). Returns status, type, registration date, mailing address, minority/woman/veteran/disability/LGBTQI ownership flags, officers, registered agent, and recent filings. KYB / counterparty due-diligence; official state open-data portal.

NAICS 2022 industry classification codes (US Census, public domain). Pass code for an exact NAICS code (2-6 digits, or a sector range like 31-33) → official title, hierarchy path, full description, activity index terms, and direct child codes. Or pass query for free-text search over titles + the official ~20k-entry activity index → ranked candidate codes, optionally filtered by level (2=sector … 6=national industry). Ground truth for industry coding in KYC, registrations, and ERP setup.

Look up or search the global LEI (Legal Entity Identifier) registry — the authoritative ISO 17442 directory of ~2.6M legal entities worldwide (GLEIF, CC0). Pass lei for an exact 20-character LEI, or query to search by legal/other name (ranked best-match). Filter name search by country (HQ ISO 2-letter) and status (active|all). Returns LEI, legal name, jurisdiction, entity category, legal-form code, entity + registration status, HQ address, registration/renewal dates, and managing LOU. Canonicalize a company name to its LEI, resolve a counterparty, or enrich a vendor master.

Fuzzy entity resolution: resolve a messy, free-text company name to its canonical GLEIF Legal Entity Identifier (LEI) with a 0-1 similarity score and high/medium/low confidence. Tolerant of legal-suffix noise (Inc/Ltd/GmbH/S.A.), word order, ampersands, punctuation, and former/alternate names (e.g. 'Apple Computer Inc' → Apple Inc.). Returns ranked candidates plus a single bestMatch (null below medium confidence — safe for KYB). The record-linkage complement to business.lei. Optional country (ISO-2) narrows the jurisdiction.

Every US public K-12 school (~102k, NCES Common Core of Data). Search by name/district (partial), state, city, zip, or exact 12-digit NCES id. Returns address, level, type, charter/magnet/virtual flags, enrollment, grade span.

US trade/occupational license verification (currently TX TDLR: electricians, A/C techs, cosmetologists, tow operators, +40 trades). By name (owner/business, partial), licenseNumber, licenseType, county. Returns type, number, names, expiration.

US real-estate license verification (currently TX TREC: brokers, sales agents, broker companies). By name (partial), licenseNumber, licenseType, status. Returns type, number, holder, status, dates, supervising broker.

Search US federal + state case law (CourtListener / Free Law Project).

Verify every US legal citation inside a passage of text against the real CourtListener corpus. Anti-hallucination check before quoting case law.

Anti-hallucination checker for legal references. POST text to verify every cited case (CourtListener), US Code section, and CFR regulation EXISTS, with canonical metadata + source URLs. POST quotes:[{citation,quote}] to deterministically verify an attributed QUOTE actually appears in the cited opinion (ellipsis-aware) — catches fabricated quotations. Returns per-reference exists/quote-present + a summary. Checks facts (existence, quote presence), NOT whether a case legally supports a proposition.

Fuzzy-match a name (person, company, vessel, aircraft) against the US Treasury OFAC SDN list. Returns ranked matches with similarity scores and sanctions program metadata. List refreshed daily.

Search US Federal Register documents (proposed rules, final rules, notices).

Fetch the authoritative full text of a US Code of Federal Regulations section by title + section number (e.g. title 17, section 240.10b-5). Optional date (yyyy-mm-dd, back to 2017) returns the historical text in force on that date. Returns citation, heading, plain text, Federal Register source credit, and official eCFR link. Public-domain, updated daily.

Fetch the full text of a US court opinion by CourtListener opinion ID OR by citation. Returns plain text + case metadata. Supply exactly one of opinionId or citation.

CourtListener attorney search by name and/or firm. Returns parsed attorney records with firm name, contact info, and CL IDs. Supply at least one of name or firmName. Case-insensitive matching via Title-Case + startswith.

CourtListener federal judge lookup by name. Returns parsed judge records with biographical data (DOB, DOD, FJC ID). Useful for venue research, judicial profile lookup, and bio enrichment.

Fetch the authoritative current text of a United States Code section by title + section number (e.g. title 17, section 107 = fair use). Returns citation, heading, hierarchy context, full statutory text, Statutes-at-Large source credit, and the official OLRC link; includeNotes adds amendment history. Handles hyphenated/lettered sections like 1395w-4 or 78j. Verify statutory citations instead of relying on model memory. Public-domain.

Verify a US trademark by USPTO serial number (8 digits) or registration number: word mark, LIVE/DEAD status with detail and dates, current owner, mark type, and international classes covered. Authoritative real-time USPTO TSDR data — confirm a mark exists and is active instead of trusting model memory. Number lookup only (no text search).

Search US trademarks by wordmark text, owner, or goods/services — the text search the USPTO offers no public API for. Pass query for full-text (best-match ranked), or serial / registrationNumber for an exact record. Filter by field (mark|owner|all), status (live=registered+pending, default; all includes dead), and intlClass (Nice class). Returns wordmark, serial, registration number, status (+ live flag), dates, owner, classes, and goods/services. Use law.trademark-status for live USPTO prosecution detail on a known serial.

USDA FoodData Central nutrition lookup (~400k foods). Search by name (query=cheddar cheese) for matching foods with fdcId, or fetch one food (fdcId=328637) for its full analyzed nutrient profile — energy, protein, fats, carbs, vitamins, minerals with amounts and units, plus ingredients for branded foods. Real analyzed values instead of model-estimated nutrition facts.

TLD registry + Public Suffix List intelligence. tld=io returns IANA root-zone metadata (type, managing organization, unicode form). domain=shop.example.co.uk runs the full PSL algorithm: effective public suffix, registrable domain, subdomain, matched rule, and whether the suffix is ICANN or private/corporate (github.io, s3.amazonaws.com). For cookie scoping, per-registrant rate limiting, URL dedup, and abuse analysis.

Historical daily weather observations (NOAA GHCN-Daily) for one station + date range (≤366 days): max/min/avg temperature °C, precipitation/snow mm, wind m/s. Records back to the 1800s — actual measured values for "what was the weather on this date". Find a station id with climate.station-near first.

Live web search: ranked results with title, URL, snippet, site name, and page age — fresh information past any training cutoff. Supports paging (count/offset), country, freshness (pd/pw/pm/py or date range), safesearch. Use for current events, fact verification, documentation, research.

Look up a CVE by id (e.g. CVE-2021-44228) across three authoritative vulnerability feeds in one call: the canonical record (description, CVSS base score + severity + vector, CWE ids, dates, references), whether it is on the US CISA Known Exploited Vulnerabilities catalog (with remediation due date + known-ransomware flag), and its EPSS exploit-probability score + percentile. The exploited and EPSS sections degrade independently. 404 if unknown. For vulnerability triage, prioritization, and anti-hallucination. Sources: NIST NVD, CISA KEV, FIRST.org EPSS.

Security + provenance for an open-source package, composed live in one call from OSV (known vulnerabilities — aggregates GitHub Security Advisories, PyPA, RustSec, Go vuln DB, etc., each with CVE aliases + severity + references), deps.dev (resolved license + deprecation), and OpenSSF Scorecard (source-repo health: overall 0-10 + per-check, plus stars/forks/open-issues). Pass ecosystem (npm/pypi/go/maven/cargo/nuget) + name (+ optional version). Live — new advisories appear within hours. Distinct from registry.npm/pypi-lookup (metadata only): "is this dependency safe to add, what license, how well-maintained."

Find CVEs affecting a product by searching the NIST NVD. Pass product (free-text keyword, e.g. "apache log4j", "openssl") or cpe (exact CPE 2.3 name). Returns matching CVEs newest-first with id, description, CVSS score/severity/vector, dates. Optional limit (1-50). For "what CVEs affect X" — distinct from security.cve (resolve one id across NVD+KEV+EPSS). Free, keyless.

Live news search: recent headlines with publisher source, relative age, and breaking flag. freshness narrows recency (pd=past day, pw, pm, py). Use for current events and monitoring.

Current spot price, market cap, 24h volume and 24h change for crypto assets by CoinGecko asset id (lowercase, e.g. "bitcoin,ethereum,solana" — not ticker symbols). vs sets quote currencies (default usd). Price data by CoinGecko.

Live flight status by flight designator (UAL1 / UA1) or tail number: origin/destination airports, status, cancellation/diversion, scheduled vs estimated vs actual gate + runway times, delays, progress percent, aircraft type and registration. Answers "where is this flight, is it delayed, when does it land".

Transcribe an audio file URL to text (wav, mp3, m4a, ogg/opus, flac, webm; ≤15 MB, ≤15 minutes — split longer recordings). Returns punctuated transcript, confidence, duration, detected language, word-level timestamps, and (diarize=true) speaker-segmented utterances.

Sweep a person name across five US public registries in one call: FINRA brokers, federal-court attorneys, federal inmates (BOP), Texas trade licenses, Texas real-estate licenses. Per-registry found/error blocks with matching records — name-matched CANDIDATES, not identity-resolved (verify with each registry's identifier). Due-diligence and background-research triage.

Everything around a coordinate in one call: nearby airports, public K-12 schools, NOAA climate stations, and past-week earthquakes, each with distance and an independent found/error block. radiusKm default 25 (max 200), limit per category. Site assessment, relocation research, risk screening.

Latest daily stock quote for a US-listed ticker (e.g. AAPL, MSFT, BRK.B): open/high/low/close, volume, VWAP, trade count, change and percent change vs the prior session, plus company name, exchange, security type, and market cap. NOTE: end-of-day / delayed data (response flags delayed=true) — for daily snapshots and post-close analysis, not real-time trading. Market data by Massive (formerly Polygon.io).

Normalize and verify drug names against RxNorm, the canonical US drug vocabulary (NIH). term="tylenol 500mg" returns ranked RxCUI candidates with normalized names (typos tolerated); rxcui=… returns the canonical concept plus related ingredients, brand names, and dose forms. Verify drugs exist and get stable identifiers instead of trusting model memory. Sibling of medical.icd10.

Look up US 501(c) nonprofits and screen each against the OFAC sanctions list in one call: registry record (EIN, name, location, NTEE) + per-org sanctions block (flagged, match count, SDN matches with confidence). Grant-making due diligence and donation compliance.

Recent SEC filings (10-K, 10-Q, 8-K, etc.) for a US public company by stock ticker. Returns parsed company info + a list of filings with accession numbers, forms, dates, primary document URLs. Backed by SEC EDGAR public submissions API.

Curated XBRL financial metrics for a US public company by stock ticker. Returns ~15 top-line metrics (revenue, gross profit, operating income, net income, EPS, R&D, total assets, liabilities, equity, cash, debt, operating cash flow, capex, shares outstanding) with their most recent annual + quarterly values. Each metric returns the originating form (10-K/10-Q), period dates, fiscal year/period, and filed date.

SEC EDGAR XBRL Frames — one financial concept across ALL public filers for one period, for cross-company screening. Give an XBRL tag (Revenues, NetIncomeLoss, Assets), period (CY2023 annual, CY2023Q1 quarter, CY2023Q4I instant), optional unit (default USD), and get every filer's value (company, CIK, location, period, value) sorted high-to-low (or asc), plus total filer count. Free, public-domain (SEC). Distinct from finance.company-facts (one company, many metrics) — this is one metric across all companies.

Recent SEC Form 4 insider transactions for a US public company by ticker. Returns parsed transactions: insider name + relationship (director, officer/title, 10%+ owner), date, SEC transaction code (P=purchase, S=sale, A=grant, D=disposition, M=exercise, F=tax-withholding, G=gift), security title, shares, price/share, total USD value, post-transaction balance, direct vs indirect ownership, derivative flag.

Indian bank branch lookup by IFSC code (11-char Indian Financial System Code). Returns bank + branch, centre, district, state, city, address, contact, MICR, and supported payment rails (IMPS/RTGS/NEFT/UPI). Free, open data. Deterministic bank-branch reference for India payments/KYC.

Identify a payment card from its BIN/IIN (leading 6-8 digits). Pass the BIN or leading card digits and get card brand (Visa/Mastercard/…), card type (debit/credit), category, issuing bank, and country (ISO alpha-2 + name). Longest-prefix match against an open CC-BY dataset. Identifies issuer/brand/country only — never the cardholder or account. For payment routing, fraud checks, checkout UX.

Map a security identifier to its FIGI (Financial Instrument Global Identifier) + metadata via OpenFIGI. Give idType (ISIN, CUSIP, SEDOL, TICKER, FIGI, COMMON, WKN, CINS, or raw OpenFIGI ID_* type) and idValue, optionally narrowed by exchCode/currency. Returns each listing with FIGI, composite/share-class FIGI, name, ticker, exchange, security type, market sector, description. Free, open symbology (Bloomberg OpenFIGI).

Free-text security search across global exchanges via OpenFIGI. Give a query (name/ticker/description), optionally narrow by exchCode/securityType/marketSector (Equity, Corp, Govt, Mtge, Muni, Pfd, Comdty, Index, Curncy). Returns relevance-ranked FIGIs + metadata and a next cursor (pass back as start). Free, open symbology. Distinct from finance.figi (exact id → FIGI) — this is discovery by name.

Parsed institutional holdings (Form 13F-HR) for an investment manager by CIK. Returns each holding's nameOfIssuer, cusip, market value (USD; converted from SEC's $000s convention), shares or principal amount + type, putCall flag for options, and voting authority (sole/shared/none). Sorted by value descending. Common manager CIKs: Berkshire Hathaway=1067983, Renaissance=1037389, Bridgewater=1350694, Vanguard=102909, BlackRock=1364742.

Look up a US-registered aircraft by tail number (N-number, e.g. N757F) or icao24 Mode-S hex (e.g. aa3487). Pass exactly one. Returns make/model/owner/operator + the icao24 that links to live ADS-B flight-tracking. ~307k US airframes (OpenSky, CC-BY-SA).

Look up an airport by IATA (3-letter) or ICAO (4-letter) code. ~85k airports (CC0 — OurAirports).

Find airports near a coordinate, ordered by distance.

Current US weather for a ZIP code (NOAA NWS).

Live US National Weather Service active alerts (watches/warnings/advisories) for a point ("lat,lon") OR an area (2-letter US state or marine code). Real-time severe-weather data. Optional severity/urgency filter; sorted most-severe first.

Official US National Weather Service forecast for a coordinate (US land + territories). Pass lat + lon for ~7 days of day/night periods, or hourly=true for an hourly forecast. Each period: temperature, wind, chance of precipitation, short + detailed forecast. Keyless, public domain. For active warnings use weather.alerts.

Current air quality for any coordinate worldwide: US AQI (+ category) and European AQI, plus PM2.5, PM10, ozone, NO2, SO2, CO concentrations. Source: Open-Meteo/CAMS (keyless).

Current marine/sea-state for an ocean or coastal coordinate: significant wave height, direction, period, plus wind-wave and swell components. Source: Open-Meteo marine (keyless). 404 for inland points.

Historical daily weather (ERA5, 1940→~5 days ago) for a coordinate + date range (start, end YYYY-MM-DD, ≤366 days): per-day max/min/mean temp, precipitation total + hours, max wind. Source: Open-Meteo archive (keyless).

Current weather conditions for any coordinate worldwide (global — not just US): temperature, feels-like, humidity, precipitation (rain/snow), cloud cover, pressure, wind speed/direction/gusts, day/night flag, and human-readable conditions, with local time + timezone. Optional units=metric|imperial (default metric). Source: Open-Meteo (keyless). For official US-only NWS data see weather.zip / weather.forecast.

Weather forecast for any coordinate worldwide, up to 16 days out (global — not just US). Daily items: max/min temperature, feels-like max, precipitation total + max probability, max wind + gusts, sunrise/sunset, conditions; hourly=true for hour-by-hour instead. Optional days (1-16, default 7) and units=metric|imperial. Source: Open-Meteo (keyless). For the official US-only NWS forecast see weather.forecast.

Find NOAA GHCN-Daily climate stations near a coordinate. Useful for long-term climate-history lookups.

Overview

What is Twosio?

Twosio is an MCP server that exposes over 575 pay-per-call endpoints from 2s.io to any MCP host. It uses the x402 protocol for micropayments from a USDC-funded wallet on Base or Solana, requiring no accounts, API keys, or signup.

How to use Twosio?

Install and run with npx -y @2sio/mcp. Set `EVM_PRIVATE_KEY

Comments

More Developer Tools MCP servers