Back to Browse

Sbb Opendata MCP Server

Developer ToolsLow Risk10.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

SBB Open Data via OpenDataSoft

About

SBB Open Data via OpenDataSoft

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (1 strong, 2 medium validity signals). No known CVEs in dependencies. Package registry verified. Imported from the Official MCP Registry. Trust signals: trusted author (57/59 approved).

4 files analyzed Β· 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

file_system

Check that this permission is expected for this type of plugin.

env_vars

Check that this permission is expected for this type of plugin.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-malkreide-sbb-opendata-mcp": {
      "args": [
        "sbb-opendata-mcp"
      ],
      "command": "uvx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

πŸš† sbb-opendata-mcp

πŸ‡¨πŸ‡­ Part of the Swiss Public Data MCP Portfolio

PyPI License: MIT Python 3.11+ MCP Data Source CI

MCP server connecting AI models to Swiss Federal Railways (SBB) open data – passenger frequency, live rail disruptions, infrastructure & real-estate projects, train counts, platform data, rolling stock and station search from data.sbb.ch. No API key required.

πŸ‡©πŸ‡ͺ Deutsche Version

Demo

Demo: Claude queries SBB passenger frequency


Overview

sbb-opendata-mcp gives AI assistants like Claude direct access to public SBB data – no copy-pasting or manual API calls. A question like "How many passengers passed through ZΓΌrich HB every day in 2024?" is answered with real measured data.

The SBB Open Data portal speaks the OpenDataSoft REST API (v2.1). This server translates it into clean Markdown and JSON for the AI model, and adds MCP structuredContent alongside the human-readable text so programmatic clients can consume the underlying records without re-parsing. The server is model-agnostic and works with any MCP-compatible client.

Anchor demo query: "Compare ZΓΌrich HB, Bern and Basel SBB by passenger frequency and platform capacity." β†’ More use cases by audience β†’


Features

  • πŸ“Š Passenger frequency – boardings/alightings by station and year (daily averages)
  • 🚨 Live rail disruptions – traffic messages, updated every 5 minutes
  • πŸ—οΈ Infrastructure projects – station and line construction
  • 🏒 Real-estate projects – SBB property development (daily updates)
  • πŸš† Trains per segment – train counts per route (SBB, BLS, SOB …)
  • πŸ›€οΈ Platform data – length, type, area, step-free access
  • πŸšƒ Rolling stock – capacity and year built
  • πŸ” Station comparison – up to 10 stations across multiple datasets
  • πŸ” Stop search – Swiss DiDok register (all of Switzerland)
  • πŸ“¦ Dataset catalogue – list all ~89 SBB open datasets
  • πŸ”‘ No API key – all data is public and free to use
  • ☁️ Dual transport – stdio for Claude Desktop, Streamable HTTP for cloud deployment

Prerequisites

  • Python 3.11+
  • No API key β€” all data comes from the public data.sbb.ch portal

Install uv (recommended):

curl -LsSf https://astral.sh/uv/install.sh | sh

Installation

From PyPI:

pip install sbb-opendata-mcp

Or with uvx (no permanent installation):

uvx sbb-opendata-mcp

For local development, install from a clone in editable mode:

git clone https://github.com/malkreide/sbb-opendata-mcp.git
cd sbb-opendata-mcp
pip install -e ".[dev]"

Quickstart

# Start the server (stdio mode for Claude Desktop)
sbb-opendata-mcp

Try it immediately in Claude Desktop:

"How many people boarded at ZΓΌrich HB daily in 2024?" "Are there any current disruptions on the Swiss rail network?"


Configuration

Environment Variables

The server needs no configuration to run over stdio. The variables below tune the optional Streamable HTTP transport, logging and observability.

VariableEffectDefault
MCP_HOSTBind host for the HTTP transport. Keep 127.0.0.1 locally; only bind 0.0.0.0 inside a controlled container/cloud environment.127.0.0.1
MCP_PORTPort for the HTTP transport.8000
MCP_ALLOWED_HOSTSComma-separated host allow-list for DNS-rebinding protection (e.g. your-app.onrender.com,your-app.onrender.com:*).localhost only
MCP_ALLOWED_ORIGINSComma-separated browser-origin allow-list (e.g. https://your-app.onrender.com).(none)
LOG_LEVELLog verbosity (DEBUG/INFO/WARNING/…).INFO
LOG_FORMATjson for structured logs; anything else for human-readable text. Always written to stderr.text

πŸ”’ DNS-rebinding / Origin protection is always on; localhost is allow-listed so local HTTP development works out of the box. Logs go to stderr β€” stdout is reserved for the stdio JSON-RPC channel.

Claude Desktop Configuration

{
  "mcpServers": {
    "sbb-opendata": {
      "command": "uvx",
      "args": ["sbb-opendata-mcp"]
    }
  }
}

Config file locations:

  • macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
  • Windows: %APPDATA%\Claude\claude_desktop_config.json

Restart Claude Desktop β€” the server is downloaded automatically on first use.

Other MCP Clients

Works with Cursor, Windsurf, VS Code + Continue, LibreChat, Cline and self-hosted models via mcp-proxy β€” same configuration as above.

Cloud Deployment (Streamable HTTP)

For use via claude.ai in the browser or remote servers (e.g. Render.com). The cloud transport is Streamable HTTP (endpoint /mcp).

Docker (recommended):

# Build + run with explicit resource limits (see docker-compose.yml)
docker compose up --build
# β†’ http://127.0.0.1:8000/mcp

The image is a multi-stage build running as a non-root user; docker-compose.yml adds read_only, no-new-privileges and memory/CPU/PID limits.

Manual / Render.com:

pip install -e .

# Bind publicly (behind a rate-limiting reverse proxy) and configure
# DNS-rebinding / Origin protection for your hostname:
export MCP_HOST=0.0.0.0
export MCP_ALLOWED_HOSTS="your-app.onrender.com,your-app.onrender.com:*"
export MCP_ALLOWED_ORIGINS="https://your-app.onrender.com"
python -m sbb_opendata_mcp.server --http --port 8000

⚠️ Binding: In a network transport the server binds to 127.0.0.1 by default so a locally started server is not exposed to your whole network. Set MCP_HOST=0.0.0.0 only in a container/cloud environment where binding to all interfaces is intended (the Docker image does this for you), and place the server behind a reverse proxy that enforces rate limiting (and authentication, if the endpoint should not be public). See SECURITY.md.


Available Tools

ToolDescriptionData Update
sbb_get_passenger_frequencyBoardings/alightings by station and year (daily avg.)Annual
sbb_get_rail_disruptionsLive rail traffic messagesEvery 5 min.
sbb_get_real_estate_projectsSBB real estate development projectsDaily
sbb_get_trains_per_segmentTrain counts per route segment (SBB, BLS, SOB …)Annual
sbb_get_platform_dataPlatform data (length, type, area)Ongoing
sbb_get_rolling_stockRolling stock (capacity, year built)Ongoing
sbb_compare_stationsCompare up to 10 stations (multi-dataset)–
sbb_search_stationsSearch stops (Swiss DiDok register, all CH)Ongoing
sbb_list_datasetsList all ~89 SBB open datasets–

All tools support response_format: "markdown" (human-readable) and "json" (machine-readable), plus pagination. Every tool also returns MCP structuredContent (the underlying records/metadata) alongside the rendered text.

Example Use Cases

QueryTool
"How many people boarded at ZΓΌrich HB daily in 2024?"sbb_get_passenger_frequency
"Are there any current disruptions on the Swiss rail network?"sbb_get_rail_disruptions
"Compare ZΓΌrich HB, Bern and Basel SBB"sbb_compare_stations
"Which SBB real-estate construction projects are running?"sbb_get_real_estate_projects
"How many trains run yearly on the ZΓΌrich–Winterthur route?"sbb_get_trains_per_segment
"Which stops exist in WΓ€denswil?"sbb_search_stations

β†’ More use cases by audience


Architecture

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”     β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”     β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚   Claude / AI   │────▢│   SBB Open Data MCP       │────▢│       data.sbb.ch        β”‚
β”‚   (MCP Host)    │◀────│   (MCP Server)            │◀────│                          β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜     β”‚                           β”‚     β”‚  OpenDataSoft REST v2.1  β”‚
                        β”‚  9 Tools                  β”‚     β”‚  (public, no API key)    β”‚
                        β”‚  Stdio | Streamable HTTP  β”‚     β”‚                          β”‚
                        β”‚                           β”‚     β”‚  passagierfrequenz       β”‚
                        β”‚  Shared httpx client      β”‚     β”‚  rail-traffic-information β”‚
                        β”‚  (pooled, lifespan-managed)β”‚    β”‚  construction-projects   β”‚
                        β”‚  ODSQL escaping + Pydantic β”‚     β”‚  perron Β· rollmaterial   β”‚
                        β”‚  validation               β”‚     β”‚  zugzahlen Β· dienststellenβ”‚
                        β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜     β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Project Structure

sbb-opendata-mcp/
β”œβ”€β”€ src/sbb_opendata_mcp/
β”‚   β”œβ”€β”€ __init__.py
β”‚   └── server.py                   # FastMCP server, all 10 tool definitions
β”œβ”€β”€ tests/
β”‚   └── test_server.py              # Unit + live API smoke tests
β”œβ”€β”€ audits/                         # MCP best-practice audit evidence
β”œβ”€β”€ docs/assets/demo.svg            # README demo asset
β”œβ”€β”€ .github/workflows/ci.yml        # GitHub Actions (Python 3.11/3.12/3.13)
β”œβ”€β”€ Dockerfile                      # Multi-stage, non-root runtime image
β”œβ”€β”€ docker-compose.yml              # Local run with resource limits
β”œβ”€β”€ claude_desktop_config.json      # Example Claude Desktop config
β”œβ”€β”€ pyproject.toml
β”œβ”€β”€ CHANGELOG.md
β”œβ”€β”€ CONTRIBUTING.md
β”œβ”€β”€ SECURITY.md
β”œβ”€β”€ EXAMPLES.md
β”œβ”€β”€ LICENSE
β”œβ”€β”€ README.md                       # This file (English)
└── README.de.md                    # German version

Safety & Limits

  • Read-only: All 9 tools perform read-only HTTP GET requests β€” no data is written, modified, or deleted upstream.
  • No personal data: Queries are transient and not stored. The portal returns aggregated statistics, infrastructure and operational metadata. No PII is processed or retained.
  • No API key: Data is public and free. There is no authentication and no secret to manage.
  • Injection-hardened: year/canton are regex-validated and every value interpolated into an ODSQL where clause is escaped via a central helper.
  • Data freshness: Real-time tools (disruptions) reflect the upstream source at query time; statistical datasets update annually/daily (see the tool table).
  • Terms of service: Data is published under the data.sbb.ch licence (NonCommercialAllowed-CommercialAllowed-ReferenceRequired).
  • No guarantees: This server is a community project, not affiliated with SBB. Availability depends on the upstream API.

See SECURITY.md for the full security posture.


Known Limitations

  • Passenger frequency: Updated annually; the latest full year may lag by some months.
  • Rail disruptions: Returns all current Swiss rail messages β†’ use limit and pagination.
  • Trains per segment: Counts are yearly aggregates, not real-time.
  • Station search: Covers the full Swiss DiDok register (all operators), not just SBB.
  • No rate limiting of its own: Place a public HTTP deployment behind a rate-limiting reverse proxy.

MCP Protocol Version

This server speaks two protocol eras over the same endpoint. The client's first request on a connection decides which one applies; a later claim from the other era is refused.

EraRevisionWho reaches it
initialize handshake2024-11-05 … 2025-11-25What today's clients speak. The server answers with the revision asked for, or with the 2025-11-25 ceiling when the request asks for something newer.
Per-request envelope2026-07-28A request carrying the 2026-07-28 _meta envelope opens a modern connection.

Both revisions are pinned in tests/test_protocol_version.py and asserted against the installed SDK, so a Dependabot bump of mcp cannot move either one silently. This server builds no ASGI app to send an initialize through, so the gate asserts the SDK constants rather than a measured response β€” the weaker form, named rather than left unsaid.

Note that the SDK's LATEST_PROTOCOL_VERSION is an alias for the modern era, not for the handshake era β€” pinning against it alone would leave the era that current clients actually negotiate free to drift.

Update policy. When the gate fails, do not edit the constant blindly: read the spec changelog between the two revisions, verify the server still behaves, then move the constant, this section, README.de.md and CHANGELOG.md together.


Testing

No API key is required.

# Unit tests (no network required)
PYTHONPATH=src pytest tests/ -m "not live"

# Live API smoke tests (require network access to data.sbb.ch)
PYTHONPATH=src pytest tests/ -m live

# Re-record the fixtures from data.sbb.ch (writes tests/fixtures/PROVENANCE.md)
python scripts/record_fixtures.py

The unit-test payloads are recorded, not invented. Source, retrieval date, selection rule and SHA-256 per file are in tests/fixtures/PROVENANCE.md.

tests/fixtures/dataset_fields.json is not a data excerpt but the contract: the Explore v2.1 API declares each dataset's field names, and a select or order_by on a field it does not have is answered with HTTP 400 β€” not with fewer columns. TestFieldContract holds every field name the server uses against that declaration, so the next rename fails a test instead of a user's request. Until 2026-08-08 three of ten tools were permanently broken for exactly this reason.

Live tests are not run by CI (-m "not live"). Two of those three broken tools had live tests covering them β€” test_live_search_waedenswil and test_live_list_datasets. The coverage existed; the run did not.


Changelog

See CHANGELOG.md


Contributing

See CONTRIBUTING.md


Security

See SECURITY.md (Deutsch) for the security posture and how to report a vulnerability.


License

MIT License β€” see LICENSE


Author

Hayal Oezkan Β· github.com/malkreide


Credits & Related Projects

Installation

Run via uv's uvx β€” no clone or manual install needed. Add to your MCP client config (mcpServers for Claude Desktop, Cursor and Windsurf; use a top-level servers key for VS Code in .vscode/mcp.json):

{
  "mcpServers": {
    "sbb-opendata-mcp": {
      "command": "uvx",
      "args": [
        "sbb-opendata-mcp"
      ]
    }
  }
}

Reviews

No reviews yet

Be the first to review this server!