# com.peppolstatus/api

Peppol market intelligence and network monitoring: migrations, provider churn, leads, and uptime.

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.0.0
- **Author:** com.peppolstatus
- **License:** Unknown
- **Endpoints:** streamable-http https://mcp.peppolstatus.com
- **Source:** https://peppolstatus.com/mcp
- **Endpoint health:** reachable (last checked 2026-09-20T11:49:41.959Z, 5 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 0 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-20T11:49:41.959Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.

## Tools

62 declared. Observed from a live `tools/list` probe.
- `list_hosts` — List monitored hosts Every monitored host with its current verdict, latest hourly all-locations latency and 24h uptime, worst-first, plus a network-wide rollup.
- `get_host` — Get a host's current state Current role, verdict, network attribution (IPs/PTR), TLS certificate and operating provider for a host. `?at=` returns point-in-time
- `list_host_incidents` — List a host's incidents Incidents for one host, newest-first, cursor-paginated.
- `get_host_uptime` — Get a host's uptime aggregates The aggregate ladder for a host at a chosen resolution, per-location plus the `__all__` rollup, optionally windowed by `[from, to
- `list_host_software` — List all hosts' software (Market) Every host with open software fingerprint rows, one row per (hostname, role) with the vendor / version / hosting axes folded i
- `get_host_software` — Get a host's software fingerprint The detected software of a host across ALL its roles: vendor, version and hosting per role, each with its confidence tier, fir
- `list_host_software_history` — List a host's software-fingerprint history The closed (superseded) software rows for one host, newest-first, cursor-paginated. Each row is one axis transition w
- `list_incidents` — List incidents The global incident feed, newest-first, cursor-paginated.
- `get_participant` — Get a participant's current state Directory presence, SML registration + current SMP, business card, the company-register enrichment block, endpoints and servin
- `list_participant_events` — List a participant's change events The participant's typed change events, newest-first, cursor-paginated.
- `get_participant_history` — List a participant's temporal history The participant's temporal rows across the directory/card/registration/SMP fact families, newest-first, cursor-paginated.
- `get_participant_availability` — Get a participant's measured availability The real, probe-measured reachability of one Peppol ID over time. Two lanes — the participant's SMP host (discovery) a
- `get_network_summary` — Get the network summary Current host verdict counts, open incidents and anomalies in the last 24h, plus how fresh the Peppol Directory export behind every other
- `get_network_history` — Get the network verdict history The host verdict mix over time, derived from the temporal verdict table in one windowed pass: per UTC day, the rows open at 00:0
- `get_summary` — Get the public dashboard summary The free marketing-dashboard rollup: the network-wide host rollup (fleet count + mean uptime/latency), the hourly fleet-average
- `get_adoption` — Get a country's adoption aggregates Peppol adoption for one country as one bare object: headline totals (universe, on_peppol, penetration), the single-dimension
- `list_providers` — List providers The OpenPeppol member registry with role flags, country, mapped hostnames and per-provider participant counts (market share), busiest first. Not 
- `get_provider` — Get a curated provider A curated provider navigable to its seats and each seat's observed hosts.
- `list_public_providers` — List public provider profiles The FREE, crawlable public subset for each curated provider, busiest first: identity + role flags, the seat-directory columns (leg
- `get_public_provider` — Get a public provider profile The FREE, crawlable public subset for one curated provider (same shape as a `GET /v1/providers/public` item). Reachable with no AP
- `get_provider_sla` — List provider SLA scorecards Per-provider SLA scorecards for one trailing period: checks-weighted uptime across each provider's mapped hosts, incident count, to
- `get_provider_sla_by_key` — Get a provider's SLA scorecards One provider's SLA scorecards, one per trailing period (30d and 90d). `key` is the provider's natural key (as reported by `GET /
- `list_provider_certs` — Get a provider's certificate posture A curated provider's whole-fleet certificate posture in one call: per-Seat cert counts, soonest expiry, expired / expiring-
- `list_access_points` — List access points The Access Point directory: every Provider in its serving role, with its member seats and roster size (current participant count), busiest fi
- `get_access_point` — Get an access point One Provider's detail: display name, verified flag, member seats (each with its embedded provider or unverified cert-CN), roster size, and t
- `get_access_point_roster_mix` — Get a filtered access point roster breakdown The five roster breakdowns of `GET /v1/aps/{key}` (country, entity type, NACE sector, size class, region) recompute
- `get_access_point_churn` — Get an access point's churn An Access Point's joiner / mover / leaver activity over a period: a daily category series with derived net growth, period totals, an
- `list_access_point_churn_participants` — List participants behind a churn category The drill-down: the participant IDs behind one churn category count for this Provider over the period. Bounded to 500 
- `list_smps` — List SMPs The SMP directory: every current SMP hostname with the seat(s) and provider that sign its metadata, busiest first. A hostname is listed if it currentl
- `get_seat` — Get a seat A Peppol certificate seat: its embedded provider (verified mapping or unverified cert-CN fallback) and the hosts it was observed operating.
- `get_seat_sla` — Get a seat's SLA scorecards One seat's SLA scorecards, one per trailing period (30d and 90d). `seatId` is the seat identifier (as reported by `GET /v1/aps/{key}
- `get_seat_compliance` — Get a seat's compliance scorecard One seat's compliance posture: the registrations under it, its OPEN findings broken down by rule, the daily trend, and where t
- `list_events` — List global change events Every typed change event, newest-first, cursor-paginated. Any anomaly an event triggered is embedded on it. `cursor` walks older event
- `list_participants` — List participants The participant set, keyset-paginated. Default sort is first-seen newest-first. Comma-array filters (`country`, `scheme`, `smp`, `ap`, `doctyp
- `get_participants_mix` — Get a filtered participant breakdown The participant set broken down by country, entity type, NACE sector, size class, region and serving Access Point, over a F
- `get_participant_stats` — Participant facet stats Global participant facet counts (per country/scheme/smp/ap/doctype/transport_profile, registered share, provenance split) plus an estima
- `get_participant_stats_history` — Participant facet history A daily time series over one participant facet dimension (adoption curves / QoQ trends), from daily snapshots of the rollup. History a
- `get_participant_joiners` — Network joiners curve The real onboarding curve (issue #222): joiner counts bucketed by derived network join date (business-card RegistrationDate, else genuine 
- `list_software` — List the software library (Market) The signature catalogue's PRODUCT taxonomy joined to what the network shows: for every engine, its display name, vendor, cate
- `get_software` — Get one software product (Market) One engine of the software library: the same row the list returns (product metadata, host count per observed role, first/last 
- …and 22 more

## Install

**Verdict: review** — Installable, but 2 things to check first: No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"api\": {\n      \"type\": \"http\",\n      \"url\": \"https://mcp.peppolstatus.com\"\n    }\n  }\n}"
```

## Blast radius

Moderate to extensive — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: mutates data; runs on someone else's infrastructure.
- Floor 26, ceiling 50 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/com.peppolstatus%2Fapi
- Install plan: https://forgeregistry.com/api/v1/packages/com.peppolstatus%2Fapi/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/com.peppolstatus%2Fapi
- HTML page: https://forgeregistry.com/registry/com.peppolstatus%2Fapi
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
