land.makeup/v1

MCPcommunitylive
v1.0.0land.makeupUnknownUpdated 4mo ago

Israeli cosmetics retailer: ΔE shade matching, customer wallet, cart, orders, gift cards.

Endpoint healthlive
checked 2 days ago · 629ms
100% of the last 6 checks reached this endpoint
Works in
ClaudeCursorCopilotChatGPTGemini

Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Automatically indexed from public sources. Not yet verified by the developer on Forge.Claim this listing →
4mo agoLast update
Package
Authorland.makeup
LicenseUnknown
Version1.0.0
Sourcemcp-registry
Trust Status
B
60/100Good
✓Listed in Forge index+10/10
—Publisher identity verified+0/30
→ Publisher: this listing has no repository on file, so `forge publish` cannot verify ownership automatically. Use "Claim this listing" above — Forge reviews these by hand.
—Domain verification+0/10
→ Not currently available for this listing type — the domain-verification check only runs for npm-backed packages today, so this row cannot be earned here yet regardless of what's hosted at the domain.
✓Prompt-injection scan · clean+30/30
✓Obfuscation / exfil scan · clean+20/20
StatusCommunity-indexed
PublisherUnverified
SignatureUnsigned
Domain—
Provenance—
DependenciesNot audited
Tool surface8 tools · none privileged
Security scan✓ Cleanvlive · 1mo agoHow well does this scan work?
EvalsNone
IndexedJun 13, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

8 tools · none privileged
Observed live from the vendor's endpoint1mo ago

Read from a real MCP initialize → tools/list handshake against the declared endpoint. No tool was ever invoked — tools/list is the read-only introspection call the protocol defines for this. It reflects what the server advertised at that moment; a hosted endpoint is not pinned to any version and can change without notice.

  • https://makeup.land/api/mcp8 tools · 915ms
list_productsBrowse the catalog with tag, brand, near_hex (ΔE shade match), hue_family, and sort filters. Bearer becomes required when passing `phone` (rewards projection).

Browse the catalog with tag, brand, near_hex (ΔE shade match), hue_family, and sort filters. Bearer becomes required when passing `phone` (rewards projection).

ParameterTypeDescription
qstringNatural-language query. Cross-lingual semantic search — `lipstick`, `שפתון`, `lápiz labial` each return Hebrew-tagged lipsticks (the sets may differ across lan…
tagstringFilter by an EXACT tag string. Tags are Hebrew (e.g. שפתון, ביוטי, עיניים, שפתיים). English category names rarely match — use `q` instead for natural-language…
brandstringFilter by brand slug or name.
near_hexstringTarget hex color for ΔE-ranked shade matching. Examples: '#C2185B', 'E8D4B8'. Each returned product carries a `shade_match: {hex, delta_e}` field with the clos…
hue_familystringPost-filter on hue family. Must be paired with another filter.
sortstringSort order. Default: relevance.
limitintegerPage size, default 20.
pageinteger1-indexed page number.
phonestringE.164 phone for per-customer rewards projection. REQUIRES bearer auth. Omit for anonymous catalog browse.
list_brandsReturn every brand with product counts and slugs. Bearer required.

Return every brand with product counts and slugs. Bearer required.

No input schema was published for this tool.

validate_gift_cardCheck a gift card's remaining balance using its code. Public endpoint — no bearer required (gated on knowledge of the code).

Check a gift card's remaining balance using its code. Public endpoint — no bearer required (gated on knowledge of the code).

ParameterTypeDescription
code*stringGift card code (full string as printed on the card).
get_customerReturn tags, ℳ-credit balance, M Club tier for the customer with the given E.164 phone. Bearer required.

Return tags, ℳ-credit balance, M Club tier for the customer with the given E.164 phone. Bearer required.

ParameterTypeDescription
phone*stringE.164 phone number, e.g. +972501234567.
get_cartReturn the customer's most-recently-updated cart with per-line and total reward projection. Bearer + phone required.

Return the customer's most-recently-updated cart with per-line and total reward projection. Bearer + phone required.

ParameterTypeDescription
phone*stringE.164 phone selecting the customer whose cart to return.
list_ordersRecent orders with 6-axis status (order / payment / fulfillment / delivery / return / review). Bearer + phone required.

Recent orders with 6-axis status (order / payment / fulfillment / delivery / return / review). Bearer + phone required.

ParameterTypeDescription
phone*stringE.164 phone selecting the customer.
limitintegerPage size.
pageinteger1-indexed page number.
list_payment_linksPending payment_requests on the customer's unpaid orders. Bearer + phone required.

Pending payment_requests on the customer's unpaid orders. Bearer + phone required.

ParameterTypeDescription
phone*stringE.164 phone selecting the customer.
get_customer_best_dealsTop deal projections based on the customer's tags + M Club tier. Bearer + phone required.

Top deal projections based on the customer's tags + M Club tier. Bearer + phone required.

ParameterTypeDescription
phone*stringE.164 phone selecting the customer.
limitintegerMax deals to return.

8 of 8 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

Israeli cosmetics retailer: ΔE shade matching, customer wallet, cart, orders, gift cards.

Keywords
mcp
Alternatives
Comparing tool surfaces…

No dependency coverage

This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.