@alignco/opensolar-mcp

MCPattesté
v0.1.3io.github.Align-Software-CompanyMITMis à jour il y a 12 jnpmGitHub

Unofficial, self-hosted MCP server for the documented OpenSolar API.

Fonctionne dans
ClaudeCursorCopilotGemini

Déduit des transports déclarés par cette annonce (stdio). Un client absent de cette liste n’est pas écarté pour autant — c’est simplement quelque chose que Forge ne peut pas confirmer.

Build attesté
Une attestation de provenance vérifiée lie cet artefact au dépôt indiqué. Personne n’a encore revendiqué l’annonce — cela prouve où le code a été construit, pas qui le soutient.
89Téléch./sem.
il y a 12 jDernière mise à jour
Nécessite 1 identifiant avant de pouvoir fonctionner
  • OPENSOLAR_API_TOKENClé d’APIobligatoire

    OpenSolar bearer token

Déclaré par l’auteur dans le registre MCP officiel. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Paquet
Auteurio.github.Align-Software-Company
LicenceMIT
Version0.1.3
Sourcenpm+mcp-registry
Statut de confiance
A
85/100Fiable
✓Listé dans l’index Forge+10/10
✓Identité vérifiée · build attesté+20/20
—Signature de publication Ed25519+0/5
→ Incluse automatiquement quand l’éditeur exécute `forge publish`
—Vérification de domaine+0/5
→ Éditeur : hébergez /.well-known/forge.json sur la page d’accueil du paquet avec { "publisher": "<github-login>" }
✓npm Trusted Publishing (Sigstore)+5/5
—Correspondance de mainteneur npm+0/5
→ Éditeur : ajoutez le login GitHub vérifié aux mainteneurs du paquet npm (npm owner add <login>)
✓Analyse CVE · propre+30/30
✓Analyse statique · propre+20/20
Collez-le dans Claude Code, Cursor ou tout assistant d’IA pour combler toutes les lacunes
StatutIdentité vérifiée
ÉditeurNon vérifié
SignatureNon signé
Domaine—
Provenance✓ Vérifié par Sigstore · 1dbf69b
Dépendances✓ 7 résolues · aucune vulnérable
Surface d’outils40 outils · 6 privilégiés
Analyse de sécurité✓ Proprev0.1.3 · aujourd’huiQuelle est l’efficacité de cette analyse ?
ÉvaluationsAucune
Indexé9 oct. 2026

La vérification confirme l’identité de l’éditeur (la propriété du dépôt), pas la sûreté du code. L’analyse de sécurité couvre les CVE connues et les scripts d’installation suspects.

Outils

40 outils · 6 privilégiés
Extrait statiquement du paquet publiév0.1.3 · 16h ago

Lu dans le code que npm livre réellement, au moment de l’analyse. Le paquet n’a jamais été exécuté. Les outils enregistrés dynamiquement à l’exécution, ou cachés dans du code empaqueté ou minifié, peuvent passer inaperçus — c’est donc un plancher de la surface d’outils, pas un recensement complet.

list_costingsLists one page of costings as `{ costings, page, limit }`. The only optional filter is boolean priority. Per-unit rates are omitted.

Lists one page of costings as `{ costings, page, limit }`. The only optional filter is boolean priority. Per-unit rates are omitted.

Aucun schéma d’entrée n’a été publié pour cet outil.

get_costingReturns one costing by id: title, description, and boolean priority. Per-unit rates are omitted.

Returns one costing by id: title, description, and boolean priority. Per-unit rates are omitted.

Aucun schéma d’entrée n’a été publié pour cet outil.

delete_costingprivilégiéRemoves the costing from the live org. This call is not retried.

Removes the costing from the live org. This call is not retried.

Aucun schéma d’entrée n’a été publié pour cet outil.

list_contactsLists one page of contacts as `{ contacts }`. Each contact includes `is_synthetic_email` for `@os.code` addresses. Passport, licence, and date of birth are redacted. Contacts have no created_date or modified_date.

Lists one page of contacts as `{ contacts }`. Each contact includes `is_synthetic_email` for `@os.code` addresses. Passport, licence, and date of birth are redacted. Contacts have no created_date or modified_date.

Aucun schéma d’entrée n’a été publié pour cet outil.

search_contactsAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

get_contactReturns one contact by id, including `is_synthetic_email`. Passport, licence, and date of birth are redacted. Contacts have no created_date or modified_date.

Returns one contact by id, including `is_synthetic_email`. Passport, licence, and date of birth are redacted. Contacts have no created_date or modified_date.

Aucun schéma d’entrée n’a été publié pour cet outil.

create_contactAdds a person to the live org. Send only first_name, family_name, email, and phone. This call is not retried.

Adds a person to the live org. Send only first_name, family_name, email, and phone. This call is not retried.

Aucun schéma d’entrée n’a été publié pour cet outil.

update_contactUpdates a person in the live org. Send at least one of first_name, family_name, email, and phone. This call is not retried.

Updates a person in the live org. Send at least one of first_name, family_name, email, and phone. This call is not retried.

Aucun schéma d’entrée n’a été publié pour cet outil.

delete_contactprivilégiéRemoves the person from the live org. This call is not retried.

Removes the person from the live org. This call is not retried.

Aucun schéma d’entrée n’a été publié pour cet outil.

get_eventReturns one event by id. Adds `event_type_name` and omits `url` and `org`. Use an id from get_project events. Unknown types become `Unknown event type`.

Returns one event by id. Adds `event_type_name` and omits `url` and `org`. Use an id from get_project events. Unknown types become `Unknown event type`.

Aucun schéma d’entrée n’a été publié pour cet outil.

list_event_typesReturns the OpenSolar event type ids and titles, including gaps. This is a copied docs table, not an API call.

Returns the OpenSolar event type ids and titles, including gaps. This is a copied docs table, not an API call.

Aucun schéma d’entrée n’a été publié pour cet outil.

list_private_filesLists one page of private files as `{ private_files, page, limit }`. Each row is id, title, file tag titles, and project id. The download URL is omitted.

Lists one page of private files as `{ private_files, page, limit }`. Each row is id, title, file tag titles, and project id. The download URL is omitted.

Aucun schéma d’entrée n’a été publié pour cet outil.

get_private_fileReturns one private file by id: title, file tag titles, project id, and size when OpenSolar sent it. The download URL stays on the server. `include_contents: true` downloads the file and refuses a body over 10 MB. Text is included for the model, capped at 100,000 characters. Images are image conten…

Returns one private file by id: title, file tag titles, project id, and size when OpenSolar sent it. The download URL stays on the server. `include_contents: true` downloads the file and refuses a body over 10 MB. Text is included for the model, capped at 100,000 characters. Images are image conten…

Aucun schéma d’entrée n’a été publié pour cet outil.

create_private_fileCreates a private file in the live org from a path confined to OPENSOLAR_UPLOAD_ROOT on this server. Uploads are disabled until that root is configured. The resolved real path must remain inside the root, including through symlinks. The server reads that file as multipart title and file_contents. F…

Creates a private file in the live org from a path confined to OPENSOLAR_UPLOAD_ROOT on this server. Uploads are disabled until that root is configured. The resolved real path must remain inside the root, including through symlinks. The server reads that file as multipart title and file_contents. F…

Aucun schéma d’entrée n’a été publié pour cet outil.

update_private_fileUpdates a private file title in the live org. The published sample sends only title. The download URL is omitted. This call is not retried.

Updates a private file title in the live org. The published sample sends only title. The download URL is omitted. This call is not retried.

Aucun schéma d’entrée n’a été publié pour cet outil.

delete_private_fileprivilégiéRemoves the private file from the live org. This call is not retried.

Removes the private file from the live org. This call is not retried.

Aucun schéma d’entrée n’a été publié pour cet outil.

generate_project_documentCreates a project document in the live org and returns the private file id. Omit format for the document type's default. pdf and csv set file_format on generate_document; docx calls generate_document_docx. The call sends action=save so OpenSolar stores a private file. File bytes are not returned. U…

Creates a project document in the live org and returns the private file id. Omit format for the document type's default. pdf and csv set file_format on generate_document; docx calls generate_document_docx. The call sends action=save so OpenSolar stores a private file. File bytes are not returned. U…

Aucun schéma d’entrée n’a été publié pour cet outil.

get_orgReturns the connected OpenSolar org: id, name, address, contact info, and measurement units. `verbose: true` returns the full redacted payload.

Returns the connected OpenSolar org: id, name, address, contact info, and measurement units. `verbose: true` returns the full redacted payload.

Aucun schéma d’entrée n’a été publié pour cet outil.

list_rolesLists roles in the connected org as `{ roles }`: id, display, email, phone, job title, and is_admin. Chat API keys are omitted.

Lists roles in the connected org as `{ roles }`: id, display, email, phone, job title, and is_admin. Chat API keys are omitted.

Aucun schéma d’entrée n’a été publié pour cet outil.

get_roleReturns one role by id: display, email, phone, job title, and is_admin. Chat API keys are omitted. Optional fieldset is list only.

Returns one role by id: display, email, phone, job title, and is_admin. Chat API keys are omitted. Optional fieldset is list only.

Aucun schéma d’entrée n’a été publié pour cet outil.

list_payment_optionsLists one page of payment options as `{ payment_options, page, limit }`. Optional filters are payment_type, auto_apply_enabled, and priority. `configuration_json` is omitted.

Lists one page of payment options as `{ payment_options, page, limit }`. Optional filters are payment_type, auto_apply_enabled, and priority. `configuration_json` is omitted.

Aucun schéma d’entrée n’a été publié pour cet outil.

get_payment_optionReturns one payment option by id: title, payment type, priority, auto-apply, and archived. `configuration_json` is omitted.

Returns one payment option by id: title, payment type, priority, auto-apply, and archived. `configuration_json` is omitted.

Aucun schéma d’entrée n’a été publié pour cet outil.

delete_payment_optionprivilégiéRemoves the payment option from the live org. This call is not retried.

Removes the payment option from the live org. This call is not retried.

Aucun schéma d’entrée n’a été publié pour cet outil.

list_pricing_schemesLists one page of pricing schemes as `{ pricing_schemes, page, limit }`. Optional filters are priority, auto_apply_enabled, and pricing_formula. `configuration_json` is omitted.

Lists one page of pricing schemes as `{ pricing_schemes, page, limit }`. Optional filters are priority, auto_apply_enabled, and pricing_formula. `configuration_json` is omitted.

Aucun schéma d’entrée n’a été publié pour cet outil.

get_pricing_schemeReturns one pricing scheme by id: title, formula, priority, auto-apply, and archived. `configuration_json` is omitted.

Returns one pricing scheme by id: title, formula, priority, auto-apply, and archived. `configuration_json` is omitted.

Aucun schéma d’entrée n’a été publié pour cet outil.

delete_pricing_schemeprivilégiéRemoves the pricing scheme from the live org. This call is not retried.

Removes the pricing scheme from the live org. This call is not retried.

Aucun schéma d’entrée n’a été publié pour cet outil.

list_projectsLists one page of projects in the connected org. Default result is `{ projects, page, limit }` with id, title, address, dates, stage, stage_milestone, and workflow ids when OpenSolar sent them. `verbose: true` returns `{ projects, page, limit }` with the full redacted list objects. Use search_proje…

Lists one page of projects in the connected org. Default result is `{ projects, page, limit }` with id, title, address, dates, stage, stage_milestone, and workflow ids when OpenSolar sent them. `verbose: true` returns `{ projects, page, limit }` with the full redacted list objects. Use search_proje…

Aucun schéma d’entrée n’a été publié pour cet outil.

search_projectsAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

get_projectReturns one project by id: address, stage, stage_milestone, workflow ids, contacts, assigned role, system_count, design_available, and events. Use it for fields a search row does not include. When search_projects reports `resolution: unique`, that target does not need this call before a write. `ver…

Returns one project by id: address, stage, stage_milestone, workflow ids, contacts, assigned role, system_count, design_available, and events. Use it for fields a search row does not include. When search_projects reports `resolution: unique`, that target does not need this call before a write. `ver…

Aucun schéma d’entrée n’a été publié pour cet outil.

get_project_snapshotAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

create_projectCreates a project in the live org. A new project can be blocked when the wallet is empty. API Access uses project-level paid entitlement while it is enabled. This call is not retried.

Creates a project in the live org. A new project can be blocked when the wallet is empty. API Access uses project-level paid entitlement while it is enabled. This call is not retried.

Aucun schéma d’entrée n’a été publié pour cet outil.

update_projectUpdates address, notes, and related fields on one project in the live org. Send at least one field besides id. Stage, design, workflow, and usage are not accepted. This call is not retried.

Updates address, notes, and related fields on one project in the live org. Send at least one field besides id. Stage, design, workflow, and usage are not accepted. This call is not retried.

Aucun schéma d’entrée n’a été publié pour cet outil.

update_project_stageSets the workflow stage on a project in the live org. Send active_stage_id with workflow_id, or stage_name. A stage title is resolved on that workflow and never matches an archived stage. No match or two matches with the same title do not PATCH. The deprecated stage field is not accepted. This call…

Sets the workflow stage on a project in the live org. Send active_stage_id with workflow_id, or stage_name. A stage title is resolved on that workflow and never matches an archived stage. No match or two matches with the same title do not PATCH. The deprecated stage field is not accepted. This call…

Aucun schéma d’entrée n’a été publié pour cet outil.

update_project_usageSets energy consumption on a project in the live org. Only the usage object is sent. values must match the source: one integer for annual, 12, 6, or 4 integers for the period sources, or Low, Medium, or High for estimate. This call is not retried.

Sets energy consumption on a project in the live org. Only the usage object is sent. values must match the source: one integer for annual, 12, 6, or 4 integers for the period sources, or Low, Medium, or High for estimate. This call is not retried.

Aucun schéma d’entrée n’a été publié pour cet outil.

delete_projectprivilégiéRemoves the project from the live org. This call is not retried.

Removes the project from the live org. This call is not retried.

Aucun schéma d’entrée n’a été publié pour cet outil.

get_proposal_dataReturns proposal figures for one project: system name, annual kWh, monthly kWh, payback year, net present value, IRR, and return on investment. Requires Raw Data API Access. A 402 means this org does not have that plan. One inaccessible project returns 403. A compressed output string is decoded on…

Returns proposal figures for one project: system name, annual kWh, monthly kWh, payback year, net present value, IRR, and return on investment. Requires Raw Data API Access. A 402 means this org does not have that plan. One inaccessible project returns 403. A compressed output string is decoded on…

Aucun schéma d’entrée n’a été publié pour cet outil.

get_project_designAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

list_roof_typesReturns the OpenSolar roof type ids and titles. This is a copied docs table, not an API call.

Returns the OpenSolar roof type ids and titles. This is a copied docs table, not an API call.

Aucun schéma d’entrée n’a été publié pour cet outil.

list_file_tagsReturns private-file tag titles. The title is the identifier. This is a copied docs table, not an API call.

Returns private-file tag titles. The title is the identifier. This is a copied docs table, not an API call.

Aucun schéma d’entrée n’a été publié pour cet outil.

list_project_systemsLists one page of systems for a project as `{ systems, page, limit }`. Each row has id, name, size, module count, battery kWh, annual output, and price. Not the full pricing breakdown.

Lists one page of systems for a project as `{ systems, page, limit }`. Each row has id, name, size, module count, battery kWh, annual output, and price. Not the full pricing breakdown.

Aucun schéma d’entrée n’a été publié pour cet outil.

36 outils sur 40 ont publié une description.

Les noms et descriptions d’outils sont écrits par l’éditeur et affichés tels quels, comme du texte inerte. Ce sont les chaînes qu’un client MCP transmet à un modèle, alors Forge y recherche des motifs d’injection de prompt — tout constat apparaît avec l’analyse de sécurité ci-dessus. « Privilégié » est une correspondance de mot-clé sur le nom de l’outil, pas un audit de ce qu’il fait : un nom anodin peut tout de même tout faire.

À propos

Unofficial, self-hosted MCP server for the documented OpenSolar API.

Mots-clés
mcp
Alternatives
Comparaison des surfaces d’outils…

Arbre de dépendances

Ce qu'une analyse Forge a résolu à partir des métadonnées npm le 2026-10-10 — résolution observée, et non une déclaration de l'éditeur.

7 paquets résolus · 6 directs · aucun porteur d'avis de sécurité La résolution s'arrête à la profondeur 4 et à 60 paquets.

Non suivies : peerDependencies. Cet arbre ne couvre que les dépendances d'exécution ; ce qu'elles entraînent n'a jamais été résolu.