Server data from the Official MCP Registry
530 MCP tools across 561 fintech tools: ChainGraph AP2 decisions, execution_hash. Zero PII.
About
530 MCP tools across 561 fintech tools: ChainGraph AP2 decisions, execution_hash. Zero PII.
Remote endpoints: streamable-http: https://mcp.ainumbers.co/mcp
Security Report
Valid MCP server (3 strong, 1 medium validity signals). No known CVEs in dependencies. Imported from the Official MCP Registry. 1 finding(s) downgraded by scanner intelligence.
530 tools verified · Open access · 1 issue found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
How to Connect
Remote Plugin
No local installation needed. Your AI client connects to the remote endpoint directly.
Add this to your MCP configuration to connect:
{
"mcpServers": {
"co-ainumbers-tools": {
"url": "https://mcp.ainumbers.co/mcp"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
AINumbers MCP Apps Server
An agent calling a fintech tool by name has no way to know if the tool actually ran the math it claims to have run. This server closes that gap for the AINumbers.co suite: every tool call is deterministic, zero PII, and served straight from the suite's own single-file HTML, not a paraphrase of it.
An MCP Apps (SEP-1865) server that exposes the AINumbers.co fintech tool suite to any MCP host, including Claude, ChatGPT, M365 Copilot, VS Code, and Cursor.

Quick start
# Claude: Settings -> Connectors -> Add custom connector
https://mcp.ainumbers.co/mcp
# Inspector
npx @modelcontextprotocol/inspector # then Streamable HTTP -> the URL above
No auth, no API key, no account. Production runs on Cloudflare Workers (/healthz reports runtime: cloudflare-workers), so there are no cold starts. Cursor and other Open Plugins directories pick this repo up automatically via the root .mcp.json, which declares the same endpoint.
Live endpoint: https://mcp.ainumbers.co/mcp (streamable HTTP) · Docs: ainumbers.co/mcp.html · Registry: co.ainumbers/tools on the Official MCP Registry
Run your own (org-hosted)
Fork this repo and deploy the button above to run the same server inside your own Cloudflare account: no auth to add, no build step at deploy time, the Worker boots straight from the data/ and kernels/ already committed here.
Two edits to wrangler.jsonc before that first deploy will succeed on a fresh account:
routespoints atmcp.ainumbers.co, a zone this fork doesn't own. Renamenameand either deleteroutes(ship on the freeworkers.devsubdomain) or point it at a zone in your own account.queues/workflowsfeed an internal analytics loop and are guarded in code (if (env.EVENTS_QUEUE),if (env.RENEWAL_WATCH_WORKFLOW)) — the MCP handshake and every tool call work without them. Queues need a Workers Paid plan; drop both blocks to stay free-tier.
Everything else, including the ASSETS binding serving the committed tool data, works unmodified. Full write-up (WAF rate-limit recipe, re-vendor cadence, conformance-attestation offer): ainumbers.co/mcp.html#deploy-your-own.
Tools
Read-only MCP tools — count intentionally not hardcoded here (it drifted stale the last time it was). See data/counts.json for the live figure; never hand-type this number, scripts/surface-parity.mjs and the site repo's count-drift gate both check against it. The flagship widgets below render as interactive widgets, the rest are ChainGraph compute nodes plus a handful of catalog and discovery utility tools: list_ainumbers_tools, find_tool, find_chain, build_workflow_links, run_chain, verify_execution_hash, build_chaingraph, emit_chaingraph_artifact, build_session_receipt.
Every tool declares readOnlyHint: true. No account, no auth, zero PII, nothing mutates state.
The flagship widgets
Each renders as the actual single-file AINumbers tool, served as a text/html;profile=mcp-app resource and driven by the AIN Bridge (prefill, run, Policy Mandate export). This table IS the enumeration — its row count is the widget count, never a number typed elsewhere:
| MCP tool | AINumbers tool |
|---|---|
baas_provider_comparator | T152 BaaS Provider Comparator |
validate_ap2_mcp_policy | T320 AP2 MCP Policy Validator & Bridge |
build_google_ap2_mandate | T285 Google AP2 Checkout/Payment Mandate Builder |
score_mcp_readiness | T288 MCP Developer Readiness Scorecard |
agentic_mandate_sandbox | RBE-06 Agentic Mandate Sandbox |
customer_risk_rating | T110 Customer Risk Rating Engine |
ap2_aml_mandate_builder | T131 AP2 AML Mandate Builder |
lint_mcp_tool_definition | T274 MCP Tool-Definition Linter |
validate_mcp_server_json | T275 MCP server.json Validator |
compare_agentic_payment_protocols | T276 Agentic Payments Protocol Comparator |
decode_x402_payment | T277 x402 Decoder & 402 Flow Simulator |
audit_mcp_oauth | T278 MCP OAuth 2.1 Authorization Auditor |
scan_tool_poisoning | T282 MCP Tool-Poisoning Scanner |
validate_a2a_agent_card | T283 A2A Agent Card Validator |
inspect_visa_tap_signature | T286 Visa TAP Signature Inspector |
run_kernel_vm | Kernel VM Widget |
list_ainumbers_tools and find_tool search the full catalog (see data/counts.json for the current tool count) and return deep-links. Prefill-enabled tools accept #in=<base64url(JSON of {element_id: value})>[&run=1] for one-click invocation. find_chain and build_workflow_links return ordered deep-links for a named multi-tool workflow. run_chain executes one server-side. verify_execution_hash independently re-verifies a returned artifact's hash.
Architecture
../repo (site repo, PostOakLabs/ainumbers)
| chaingraph.json, manifests/, pilot.mjs-referenced tool HTML
|
v node generate.mjs (build-time only, cannot run in cloud CI, needs the sibling repo)
data/ vendored: chaingraph.json, catalog.json, manifests, counts.json
kernels/ vendored: server-side compute kernels
|
v
worker.mjs (Cloudflare Workers, this repo's live runtime)
server.mjs (Node/express variant, local dev only, not deployed)
|
v
https://mcp.ainumbers.co/mcp (the one live endpoint: the Worker, not the express variant)
data/ and kernels/ are generated, committed artifacts. The Worker boots from what's committed, not from a live read of ../repo. Any change to chaingraph.json, a manifest, pilot.mjs, or a kernel in the site repo requires re-running generate.mjs here and committing data/ and kernels/ in the same push, or the worker deploys stale.
Deploy flow (CI-owned)
Branch, then PR. CI runs the validate job: tool-name collisions, surface-parity, kernel coverage, chain validation, vendor-freshness, and a wrangler deploy --dry-run. Merging to master runs the deploy job, which runs wrangler deploy against Cloudflare Workers, then a post-deploy /mcp smoke test (a real initialize call against the live endpoint). No manual wrangler deploy, ever: Cloudflare Workers Builds stays disconnected on purpose, since running both is a double-deployer and has caused outages before. A green CI bundle does not by itself prove the live handshake works; only the smoke step does.
Dependabot auto-merges every dependency update (patch, minor, and major, all CI-gated), so run git pull --rebase before pushing any local branch since master moves on its own.
Independent monitoring
MCP Queen is a third-party operational probe: it continuously re-checks the live /mcp endpoint's protocol handshake and tool-schema responses and grades what it observes. This is not a security or compliance attestation, ours or theirs — it describes observable server behavior only.
Develop
npm install
node generate.mjs # re-vendor tool HTML + manifests + catalog + kernels from ../repo into data/ + kernels/
npm start # http://localhost:3300/mcp (+ /healthz), Node/express variant (server.mjs), local dev only
node scripts/check-tool-names.mjs # verify no mcp_name collision before pushing
node scripts/surface-parity.mjs # verify counts.json matches the registered surface
pilot.mjs is the single source of truth for the widget tool set. After changing any pilot tool in the site repo, run node generate.mjs, commit data/ and kernels/, and push. CI validates and deploys.
All tool content is client-side, deterministic, and zero PII. Code is MIT licensed (see LICENSE); content is CC BY 4.0, Post Oak Labs. See README-SPEC.md for architecture and history.
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
