Back to Browse

Vaquill MCP Server

Developer ToolsUse Caution3.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Search US federal and 50-state statutes, regulations, constitutions, and court rules.

About

Search US federal and 50-state statutes, regulations, constitutions, and court rules.

Remote endpoints: streamable-http: https://mcp.vaquill.ai/s/_

Security Report

3.2
Use Caution3.2High Risk

The server is a legitimate MCP wrapper for the Vaquill legal research API with reasonable architecture. However, there are several security concerns: API keys can be extracted from URL paths (though Bearer header auth is preferred), a critical incomplete tool implementation in remote.py, overly broad environment variable access, and missing input validation on several parameters. The incomplete code and potential for unvalidated user input to be passed to external APIs represents moderate risk. Supply chain analysis found 3 known vulnerabilities in dependencies (1 critical, 1 high severity).

4 files analyzed · 13 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

vaquill-mcp

MCP server for Vaquill legal research API. Covers US federal and 50-state primary law: USC, CFR, state statutes and regulations, state and US constitutions, court rules, the Federal Register, executive orders, and agency guidance. Search primary law, resolve statutory citations, browse the hierarchy, and ground answers in official sources, all from your AI tools.

Quick Start

Prerequisites

Sign up at vaquill.ai to get your API key.

Claude.ai (Web)

No installation needed. Add as a remote MCP server from Customize > Connectors > Add custom connector:

Option A: Simple URL (API key in path)

https://mcp.vaquill.ai/s/vq_key_your_key_here

Option B: Bearer token (recommended)

Open the Request headers section of the same dialog and add the credential there:

URL:            https://mcp.vaquill.ai/s/_
Header name:    Authorization
Header value:   Bearer vq_key_your_key_here

Claude sends the value exactly as you type it and adds no scheme of its own, so the value field holds Bearer vq_key_... and not Authorization: Bearer vq_key_....

Available on Claude Pro, Max, Team, and Enterprise plans. The Request headers section is in beta and is enabled per account, it accepts a short allowlist of header names, and it holds at most four. On Team and Enterprise an owner adds the connector under Organization settings first.

Claude Desktop

Open the config file from Settings > Developer > Edit Config:

  • macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
  • Windows: %APPDATA%\Claude\claude_desktop_config.json
  • Linux: ~/.config/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "vaquill": {
      "command": "uvx",
      "args": ["vaquill-mcp"],
      "env": {
        "VAQUILL_API_KEY": "vq_key_your_key_here"
      }
    }
  }
}

Quit Claude completely and reopen it. It does not reload the file.

Claude Code

Remote (no install):

claude mcp add --transport http --scope user vaquill \
  https://mcp.vaquill.ai/s/_ \
  --header "Authorization: Bearer vq_key_your_key_here"

Local (via uvx):

claude mcp add --scope user vaquill -e VAQUILL_API_KEY=vq_key_your_key_here \
  -- uvx vaquill-mcp

--scope user registers the server for every project; the default is the current directory only. -e stores the key with the registration, so it survives Claude Code being launched from an IDE, which an export in your shell profile does not. Both --header and -e are variadic, so they have to come after the server name.

Cursor

Edit ~/.cursor/mcp.json for every project, or .cursor/mcp.json for one.

Remote:

{
  "mcpServers": {
    "vaquill": {
      "url": "https://mcp.vaquill.ai/s/_",
      "headers": {
        "Authorization": "Bearer vq_key_your_key_here"
      }
    }
  }
}

Local (via uvx):

{
  "mcpServers": {
    "vaquill": {
      "command": "uvx",
      "args": ["vaquill-mcp"],
      "env": {
        "VAQUILL_API_KEY": "vq_key_your_key_here"
      }
    }
  }
}

VS Code (Copilot)

Add to .vscode/mcp.json. For every project instead of one, run the MCP: Open User Configuration command and use the same shape there.

Remote:

{
  "inputs": [
    {
      "type": "promptString",
      "id": "vaquill-authorization",
      "description": "Authorization header value",
      "password": true
    }
  ],
  "servers": {
    "vaquill": {
      "type": "http",
      "url": "https://mcp.vaquill.ai/s/_",
      "headers": {
        "Authorization": "${input:vaquill-authorization}"
      }
    }
  }
}

The credential goes in a prompt rather than in the file, so the file is safe to commit. VS Code asks for it on first start and remembers it. Restart the server after saving, or the tools will not appear.

Local (via uvx):

{
  "servers": {
    "vaquill": {
      "type": "stdio",
      "command": "uvx",
      "args": ["vaquill-mcp"],
      "env": {
        "VAQUILL_API_KEY": "vq_key_your_key_here"
      }
    }
  }
}

Windsurf

Add to ~/.codeium/windsurf/mcp_config.json.

Remote:

{
  "mcpServers": {
    "vaquill": {
      "serverUrl": "https://mcp.vaquill.ai/s/_",
      "headers": {
        "Authorization": "Bearer vq_key_your_key_here"
      }
    }
  }
}

Windsurf uses serverUrl for a remote server, not url, and interpolates ${env:VAR} if you would rather read the credential from the environment.

Local (via uvx):

{
  "mcpServers": {
    "vaquill": {
      "command": "uvx",
      "args": ["vaquill-mcp"],
      "env": {
        "VAQUILL_API_KEY": "vq_key_your_key_here"
      }
    }
  }
}

Available Tools

Tools are generated from the live Vaquill API's OpenAPI spec at startup, so the set always matches the current API. For the authoritative, up-to-date list and per-call credit costs, run the free get_pricing tool or inspect your MCP client's tool list. The main groups (representative tools shown):

US statutes & regulations

USC, CFR, all 50 state codes, constitutions, state court rules, the Federal Register, and agency guidance.

ToolDescription
search_us_statutesHybrid semantic + keyword search; filter by corpusType, state, titleNumber, chapter, year, and more.
get_us_statute_sectionSection metadata by actId (citation, hierarchy, official-source links).
get_us_statute_section_textFull HTML + plain text of a section.
get_sections_batchMetadata for up to 50 sections in one call.
resolve_statute_citationResolve a Bluebook citation (e.g. 42 U.S.C. § 1983) straight to its section.
list_statute_divisionsBrowse the statutory hierarchy one level at a time.
list_statutes_coverageSelf-describing coverage matrix: which corpora exist in which jurisdiction.
list_statutes_lawsCatalog the distinct bodies of law available, with their corpusType values.

Reading a section in context

ToolDescription
get_section_neighborsThe sections immediately before and after, in statutory order.
get_section_definitionsThe defined terms that govern a section, from its chapter's definitions section.
get_section_cited_byWhich USC/CFR sections cross-reference this one (the inverse of crossReferences).
get_section_cross_stateProvisions in other states addressing the same subject, ranked by similarity.
get_section_changesWhat our refreshes observed changing on this section over time.

Law change alerts

Subscribe to a corpus source and get a webhook or email when it changes. Subscribing, polling and inspecting deliveries are all free; only get_watch_change_diff is metered, because it is the only one that returns section text.

ToolDescription
list_boardsThe watchable sources (Federal Register, CFR, a state's statutes, ...).
create_watchSubscribe to a board via webhook (HMAC-SHA256 signed) or email.
list_watches, update_watch, delete_watchManage your subscriptions.
test_watchSend a synthetic delivery to verify signing, auth and reachability.
list_watch_changesWhat changed on a watched source. Metadata only, and safe to poll.
get_watch_change_diffBefore/after text for one change, as whole documents.
list_watch_deliveriesPer-attempt webhook delivery log (90 days).

Utility

ToolDescription
get_pricingLive API credit pricing (free, no auth).

Environment Variables

VariableRequiredDefaultDescription
VAQUILL_API_KEYYes-API key (vq_key_...) from vaquill.ai
VAQUILL_BASE_URLNohttps://api.vaquill.aiAPI base URL
VAQUILL_TIMEOUTNo120Request timeout in seconds

Example Usage

Once configured, you can ask your AI assistant things like:

  • "What does 17 CFR 240.10b-5 say about insider trading?"
  • "Resolve 42 U.S.C. § 1983 to its section and show the full text"
  • "Find California statutes on tenant repair obligations"
  • "Browse the Texas statutory codes, then drill into the Penal Code"

Development

# Clone and install
git clone https://github.com/Vaquill-AI/vaquill-mcp.git
cd vaquill-mcp
uv sync --all-extras

# Run locally
VAQUILL_API_KEY=vq_key_... uv run vaquill-mcp

# Run tests
uv run pytest

# Test with FastMCP inspector
uv run fastmcp dev src/vaquill_mcp/server.py

How It Works

This package is a thin MCP wrapper around the Vaquill Developer API. At startup, it fetches the OpenAPI spec from the live API and auto-generates MCP tools using FastMCP. Tool names are derived automatically from each endpoint's OpenAPI operation id, so new API endpoints show up as clean, ready-to-use tools with no package update; key descriptions are refined for optimal LLM performance.

Because the spec is fetched at startup (not bundled), tools automatically reflect any API changes without a package update.

Credits & Pricing

API calls consume credits. The credit costs in the tables above are current at the time of writing; the get_pricing tool and each tool's own description always reflect the live price, so treat those as authoritative if they differ.

1 credit = $0.01 USD

License

MIT

Reviews

No reviews yet

Be the first to review this server!