Back to Browse

I14y MCP Server

Developer ToolsLow Risk10.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

MCP server for I14Y — Switzerland's national open-data metadata catalogue (DCAT-AP-CH)

About

MCP server for I14Y — Switzerland's national open-data metadata catalogue (DCAT-AP-CH)

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (1 strong, 3 medium validity signals). No known CVEs in dependencies. Package registry verified. Imported from the Official MCP Registry. Trust signals: trusted author (43/43 approved).

4 files analyzed · 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-malkreide-i14y-mcp": {
      "args": [
        "i14y-mcp"
      ],
      "command": "uvx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Part of the Swiss Public Data MCP Portfolio — a collection of open-source MCP servers connecting AI agents to Swiss public and open data. This is a private project. It is not affiliated with, endorsed by, or operated on behalf of any employer or public authority.

i14y-mcp

License: MIT Python 3.10+ MCP Data: I14Y

MCP server for the I14Y interoperability platform — Switzerland's national metadata catalogue.

🇩🇪 Deutsche Version


Why this server exists

The other servers in this portfolio answer «what does the data say?». This one answers the question that comes first: «who publishes data on this topic, through which interface, under which licence?»

I14Y is the national data catalogue maintained by the Federal Statistical Office. It describes datasets, registered APIs, public services and harmonised concepts from the Confederation, cantons and communes, using the DCAT-AP-CH profile (eCH-0200).

Mnemonic: «Catalogue before shelf.» Without a catalogue, an agent has to already know a data source exists. With one, it can find it.


🎯 Anchor Demo Query

«Which authority publishes data on special needs education, through which interface is it available, and under which licence?»

search_catalog(query="Sonderpädagogik")
  → «Statistik der Sonderpädagogik» — Federal Statistical Office (BFS), theme: Bildung

get_dataset(dataset_id=...)
  → 2 distributions, licence: «Opendata BY ASK — attribution required,
    commercial use only with permission from the data supplier»
  → contact: auskunftsdienst@bfs.admin.ch

Two tool calls turn a vague topic into a named authority, a download URL and a licence you can act on — get_dataset aggregates the distributions, licences and contact point into one record.

Demo

Demo: Claude using search_catalog and get_dataset


Architecture

                 ┌──────────────────────────────┐
                 │      MCP Host (Claude)       │
                 └───────────────┬──────────────┘
                                 │ stdio | streamable-http
                 ┌───────────────▼──────────────┐
                 │          i14y-mcp            │
                 │  ┌────────────────────────┐  │
                 │  │ server.py  (13 tools)  │  │
                 │  ├────────────────────────┤  │
                 │  │ mappers.py             │  │  DCAT → flat, one language
                 │  ├────────────────────────┤  │
                 │  │ models.py  (Pydantic)  │  │  source + provenance envelope
                 │  ├────────────────────────┤  │
                 │  │ client.py              │  │  retry 2s/4s/8s, no-retry 4xx
                 │  └────────────────────────┘  │
                 └───────────────┬──────────────┘
                                 │ HTTPS, no auth
                 ┌───────────────▼──────────────┐
                 │  api.i14y.admin.ch/api       │
                 │  datasets · dataservices ·   │
                 │  concepts · publicservices · │
                 │  catalogs · agents · search  │
                 └──────────────────────────────┘

Architecture decision

This server uses Architecture A (live API only).

Rationale (verified live on 2026-07-21):

  • All read endpoints respond without authentication and paginate correctly.
  • No bulk download of catalogue metadata is offered, and none is needed.
  • Error responses follow RFC 7807, so failure modes are distinguishable.

Consequences:

  • Every HTTP call retries transient failures with 2 s / 4 s / 8 s backoff.
  • search_catalog caps results client-side because the upstream ignores paging.
  • api_status always returns an evaluable state instead of empty records.

Full probe report: docs/probe-i14y.md.

Project phase

This server is in Phase 1 (read-only) of the portfolio's «Read-only First» phase architecture: all tools are read-only, there is no authentication and no personal data. See docs/roadmap.md for the phase model and the prerequisites for any future write capability.


Tools

ToolPurpose
search_catalogFree-text search across the catalogue. Entry point.
list_datasetsPaginated dataset register (complete, unlike search).
get_datasetFull metadata record for one dataset.
get_dataset_distributionsDownload URLs, formats and licences.
list_data_servicesRegister of official Swiss APIs with endpoint URLs.
get_data_serviceFull record for one registered interface.
list_public_servicesAdministrative services for citizens.
list_conceptsHarmonised concepts and code lists.
get_conceptOne concept definition.
search_codelist_entriesIndividual codes of a code list.
list_publishersPublishing bodies, with Swiss UID.
list_catalogsContributing catalogues.
api_statusReachability check with graceful degradation.

All tools are annotated readOnlyHint: true. Write operations exist in the upstream API but are deliberately not exposed.

MCP primitives

This server exposes Tools only — no Resources, no Prompts. That is a deliberate choice, not an omission: I14Y is queried by free-text search and by opaque UUIDs, so there is no small, stable set of addressable URIs that would map cleanly onto MCP Resources, and the server ships no opinionated prompt templates. Every tool is read-only and idempotent; if a future stable entry point emerges (e.g. a fixed theme list) it is a candidate for a Resource.

MCP protocol version

Built against the MCP Python SDK (mcp >= 1.28.1), which negotiates the protocol version with the client at initialize time. The tested SDK floor is pinned in pyproject.toml; Dependabot opens monthly SDK-update PRs, and any change that bumps the negotiated spec version is called out in CHANGELOG.md.


MCP Protocol Version

This server speaks two protocol eras over the same endpoint. The client's first request on a connection decides which one applies; a later claim from the other era is refused.

EraRevisionWho reaches it
initialize handshake2024-11-052025-11-25What today's clients speak. The server answers with the revision asked for, or with the 2025-11-25 ceiling when the request asks for something newer.
Per-request envelope2026-07-28A request carrying the 2026-07-28 _meta envelope opens a modern connection.

Both revisions are pinned in tests/test_protocol_version.py and asserted against the installed SDK, so a Dependabot bump of mcp cannot move either one silently. The handshake ceiling is measured against a live initialize through the assembled ASGI stack, not read off a constant name.

Note that the SDK's LATEST_PROTOCOL_VERSION is an alias for the modern era, not for the handshake era — pinning against it alone would leave the era that current clients actually negotiate free to drift.

Update policy. When the gate fails, do not edit the constant blindly: read the spec changelog between the two revisions, verify the server still behaves, then move the constant, this section, README.de.md and CHANGELOG.md together.


Installation

uvx i14y-mcp

Or from source:

git clone https://github.com/malkreide/i14y-mcp
cd i14y-mcp
pip install -e ".[dev]"

Claude Desktop

{
  "mcpServers": {
    "i14y": {
      "command": "uvx",
      "args": ["i14y-mcp"]
    }
  }
}

Remote deployment (Render, Railway)

I14Y_MCP_TRANSPORT=sse HOST=0.0.0.0 PORT=8000 i14y-mcp

I14Y_MCP_TRANSPORT accepts stdio (default), sse or streamable-http. The HTTP transports bind to HOST, which defaults to 127.0.0.1 (loopback); set HOST=0.0.0.0 to expose the port on a PaaS (the Docker image already does). CORS exposes the Mcp-Session-Id header so browser MCP clients keep their session. Which browser origins may call the server comes from I14Y_MCP_CORS_ORIGINS, a comma-separated list — unset means no browser client is permitted at all, which is the default. * is still accepted and logs a warning. stdio and other non-browser clients are unaffected either way.

Docker

docker compose up --build      # SSE transport on http://localhost:8000

The image is a hardened multi-stage build: it runs as a non-root user, ships no build tools, and needs no secrets (the API is unauthenticated). See Dockerfile and compose.yaml.


Join keys

I14Y is a connector layer. Two identifiers make it composable with the rest of the portfolio:

KeyFieldJoins to
Swiss UIDPublisher.uidregister-mcp (Zefix)
Endpoint URLDataServiceSummary.endpoint_urlsany portfolio server wrapping that API

Known limitations

Verified live on 2026-07-21.

  1. The search index covers roughly half the register. search_catalog returns at most 1013 records; list_datasets reaches about 2003. Use list_datasets when completeness matters.
  2. Search returns Datasets only. Filtering by types=["Concept"] or types=["DataService"] yields zero results even though those entities exist. Use list_concepts and list_data_services instead.
  3. The upstream ignores paging on search. The full result set is always returned; this server caps it at 200 records and sets truncated: true.
  4. Licences vary per distribution, not per dataset. Most carry «Opendata BY ASK», which requires attribution and restricts commercial use. Always read the licence field before reuse.
  5. Some metadata fields are simply empty. Frequency, temporal coverage and distribution format are optional and frequently unset by publishers. This is a data-quality property of the catalogue, not a bug in this server.
  6. Not every entry with an endpoint has a URL. Entries labelled only «OpenAPI Spezifikation» without a URI are surfaced as (no URI) <label> rather than dropped.

Testing

PYTHONPATH=src pytest tests/ -m "not live"   # offline, used in CI
PYTHONPATH=src pytest tests/ -m "live"       # hits the real API
PYTHONPATH=src pytest tests/                 # everything
python -m ruff check src tests

The live tests are not decoration: fundstück 4 in the probe report — keywords nesting their language object under label — was caught by a live test after the unit tests were already green.


Contributing

See CONTRIBUTING.md for the ground rules (read-only, one egress host, no secrets) and the local dev loop. Maintainers: PUBLISHING.md covers the PyPI / MCP Registry release process.


Security

See SECURITY.md for the security posture and how to report a vulnerability.


License

MIT License — see LICENSE. The catalogue data remains subject to the terms declared by each publisher.


Author

Hayal Oezkan · github.com/malkreide


Credits & related projects

Licence: MIT. The catalogue data remains subject to the terms declared by each publisher.


MCP Registry

Ownership marker used by the MCP Registry to link this PyPI package to the GitHub namespace:

mcp-name: io.github.malkreide/i14y-mcp

Reviews

No reviews yet

Be the first to review this server!