Openarchieven Mcp Server — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Openarchieven Mcp Server (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Production-grade hybrid MCP + HTTP + SSE server generated from the Open Archives OpenAPI specification. Covers genealogical records (births, deaths, marriages, censuses), archive statistics, historical weather, and full-text page transcriptions of historical documents.
OpenAPI source used to generate tools:
../api/openapi.yaml (local)
https://api.openarchieven.nl/openapi.yaml (remote)A schema-aware server that automatically converts the OpenAPI specification into callable tools and exposes them through multiple transports:
A hosted endpoint is available — no installation required.
In claude.ai or Claude Desktop:
https://mcp.openarchieven.nl/No authentication is required — Open Archives is a public dataset.
Once the connector is added you can ask Claude, for example:
Claude will call the matching tool (search_records, show_record, get_marriages, get_historical_weather, get_census_data, …) and return links to the corresponding record pages on https://www.openarchieven.nl.
If you prefer running the server locally as a stdio MCP server:
npx -y @coret/openarchieven-mcp-serverEvery API operation becomes a tool automatically via generate.ts.
All 21 operations:
| Tool Name | Description |
|---|---|
search_records | Search genealogical records |
show_record | Show a single genealogical record |
match_record | Match a person to birth and death records |
get_births_years_ago | List births from N years ago |
get_births | Find birth records |
get_deaths | Find death records |
get_marriages | Find marriage records |
get_archives | List all archives with statistics |
get_record_stats | Record count per archive |
get_source_type_stats | Record count per source type |
get_event_type_stats | Record count per event type |
get_comment_stats | Comment count statistics |
get_family_name_stats | Family name frequency |
get_first_name_stats | First name frequency |
get_profession_stats | Profession frequency |
get_breakdown | Cross-tabulation grouped by archive, source type, event type, place or year |
get_historical_weather | Historical weather from KNMI |
get_census_data | Dutch census data 1795–1899 |
search_transcriptions | Full-text search across page transcriptions of historical documents |
browse_transcriptions | Hierarchically browse transcriptions by source archive, archive number or inventory |
show_transcription | Retrieve a single page transcription by id |
Note: The callback (JSONP) parameter present in the upstream API is excluded from all tools — it is irrelevant in an MCP/JSON-RPC context.Beyond the 21 auto-generated tools, the server registers one hand-written tool — `view_transcription` — that opens transcribed pages in an interactive IIIF deep-zoom viewer (OpenSeadragon) with the transcription text alongside, using the MCP Apps extension (io.modelcontextprotocol/ui).
| Tool Name | Description |
|---|---|
view_transcription | Open one or more transcribed pages (ids: ["NL-SdmGA_1504889_11", …]) in a deep-zoom IIIF viewer with the transcript; optional highlight_term |
ui://openarchieven/viewer.html) in a sandboxed iframe that loads images directly from the transcription image hosts (CSP-allowlisted as *.transkribus.eu, *.archief.nl, *.archieven.nl, *.memorix.nl). Transkribus and the archief.nl iipsrv server provide true IIIF deep zoom; the preserve*.archieven.nl thumbnail hosts render as flat images.The viewer is a single self-contained dist/viewer.html, bundled at build time with npm run build:viewer (vite + vite-plugin-singlefile); it is not listed by the REST GET /tools endpoint, only via MCP tools/list.
Uses actual OpenAPI parameter schemas. Validates:
POST / ← canonical public endpoint (mcp.openarchieven.nl)
POST /mcp ← local / legacy aliasStateless JSON-RPC transport — a new MCP server instance is created per request.
Origin validation: Browser requests must come fromclaude.ai,claude.com, or any domain listed inALLOWED_ORIGINS. Requests with noOriginheader (native MCP clients,curl, server-to-server) are accepted. Unknown origins receive HTTP 403.
GET /tools
POST /tools/:nameGET /events/:namePOST /stream/:name/.well-known)Static, hand-editable JSON files served verbatim from well-known/:
GET /.well-known/mcp/server-card.json ← SEP-1649 MCP Server Card
GET /.well-known/mcp.json ← alias of the server card
GET /.well-known/agent-card.json ← A2A v0.3 Agent Card
GET /.well-known/agent.json ← alias of the agent cardEdit well-known/mcp-server-card.json and well-known/agent-card.json directly — no restart required (files are read on each request). Responses are sent with Content-Type: application/json; charset=utf-8 and Cache-Control: public, max-age=3600.
Streaming endpoints (/events/:name, /stream/:name) automatically paginate through results for endpoints that support a start offset:
start by number_show per page: heartbeat comment every 10 seconds to keep connections aliveOptional Redis support.
If Redis is running, upstream responses are cached with a per-tool TTL tuned to the data's volatility:
| Category | TTL | Tools |
|---|---|---|
| Immutable historical | never expires | get_historical_weather, get_census_data |
| Slowly-changing metadata | 7 days | get_archives |
| Stats aggregations | 1 day | get_record_stats, get_source_type_stats, get_event_type_stats, get_comment_stats, get_family_name_stats, get_first_name_stats, get_profession_stats, get_breakdown |
| Individual record lookups | 1 day | show_record, show_transcription |
| Search-style | 6 hours | search_records, match_record, get_births, get_deaths, get_marriages, search_transcriptions, browse_transcriptions |
| Date-bound | next UTC midnight | get_births_years_ago |
CACHE_TTL (default 3600) is the fallback for any tool not in the map above.
If Redis is unavailable:
The upstream API enforces 4 requests per second per IP. The server queues all upstream calls through a token-bucket rate limiter (configurable via RATE_LIMIT_RPS).
GET /healthgenerate.ts
server.ts
tsconfig.json
package.json
.env.example
generated/
tools.json
spec.jsonCopy .env.example to .env and adjust:
cp .env.example .env| Variable | Default | Description |
|---|---|---|
PORT | 3001 | HTTP port |
OPENAPI_PATH | ../api/openapi.yaml | Path or URL to OpenAPI spec |
UPSTREAM_BASE | https://api.openarchieven.nl/1.1 | Upstream API base URL |
RATE_LIMIT_RPS | 4 | Upstream requests per second |
REDIS_URL | redis://localhost:6379/5 | Redis connection URL (db 5) |
CACHE_TTL | 3600 | Fallback cache TTL in seconds (used for tools not in the per-tool map; see Redis Cache) |
LOG_LEVEL | info | trace debug info warn error fatal |
NODE_ENV | _(unset)_ | Set to production for JSON logs (default: pretty-printed) |
ALLOWED_ORIGINS | _(empty)_ | Extra Origin headers allowed on the MCP endpoint (comma-separated). Claude domains and requests without an Origin header are always allowed. |
npm installRun from local spec:
npx tsx generate.tsOr from remote URL:
npx tsx generate.ts https://api.openarchieven.nl/openapi.yamlExpected result:
Generated 21 tools
Output: generated/tools.json, generated/spec.jsonCreates:
generated/tools.json
generated/spec.jsonnpx tsx server.tsExpected startup (development — pretty-printed):
[12:00:00] INFO: Open Archieven MCP server started
port: 3001
tools: 21
upstream: "https://api.openarchieven.nl/1.1"
rateLimit: "4 req/s"
redis: "redis://localhost:6379/5"
env: "development"In production (NODE_ENV=production) each log line is a single JSON object.
Server binds to:
http://0.0.0.0:3001curl http://localhost:3001/healthExpected:
{
"ok": true,
"tools": 21,
"redis": false,
"uptime": 1.23
}curl http://localhost:3001/toolsExpected:
[
"search_records",
"show_record",
"match_record",
"get_births_years_ago",
"get_births",
"get_deaths",
"get_marriages",
"get_archives",
"get_record_stats",
"get_source_type_stats",
"get_event_type_stats",
"get_comment_stats",
"get_family_name_stats",
"get_first_name_stats",
"get_profession_stats",
"get_historical_weather",
"get_census_data",
"search_transcriptions",
"browse_transcriptions",
"show_transcription"
]curl -X POST http://localhost:3001/tools/search_records \
-H "Content-Type: application/json" \
-d '{"name":"Coret"}'curl -X POST http://localhost:3001/tools/show_record \
-H "Content-Type: application/json" \
-d '{"archive":"hua","identifier":"E13B9821-C0B0-4AED-B20B-8DE627ED99BD"}'curl -N "http://localhost:3001/events/search_records?name=Coret"Expected stream:
event: page
data: {...}
event: page
data: {...}
event: done
data: {}Leave SSE open for 15+ seconds — expect periodic keep-alive lines:
: heartbeatcurl -N -X POST http://localhost:3001/stream/search_records \
-H "Content-Type: application/json" \
-d '{"name":"Coret"}'Expected (newline-delimited JSON):
{"query":{...},"response":{"number_found":...,"docs":[...]}}
{"query":{...},"response":{"number_found":...,"docs":[...]}}curl -X POST http://localhost:3001/ \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "initialize",
"params": {
"protocolVersion": "2025-03-26",
"capabilities": {},
"clientInfo": { "name": "test", "version": "1.0" }
}
}'curl -X POST http://localhost:3001/ \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{
"jsonrpc": "2.0",
"id": 2,
"method": "tools/list"
}'curl -X POST http://localhost:3001/ \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{
"jsonrpc": "2.0",
"id": 3,
"method": "tools/call",
"params": {
"name": "search_records",
"arguments": { "name": "Coret" }
}
}'redis-serverRestart the MCP server. Expected in /health:
{ "redis": true }Stop Redis and restart. Expected:
{ "redis": false }npx tsx generate.tsnpx tsx server.tsnpm testTests cover the per-tool TTL strategy (cache-ttl.ts) using Node's built-in test runner — no extra dependencies. The coverage test asserts every tool emitted by generate.ts has an explicit TTL entry, so re-running npm run generate after an upstream OpenAPI change will surface any new tool that needs a TTL decision.
npx tsx generate.tsLinux / macOS:
lsof -i :3001
kill -9 <PID>Windows:
netstat -ano | findstr :3001
taskkill /PID <PID> /FServer runs normally without Redis. Check REDIS_URL in .env.
The upstream API allows 4 req/s per IP. The built-in rate limiter queues requests automatically. If you are running multiple server instances, reduce RATE_LIMIT_RPS or use a shared queue.
This server is a thin proxy over the public Open Archives API. It does not require user authentication and does not collect personal data of its own.
The full privacy policies of the operators apply in addition to this section:
identifier) are received from the MCP client.
source IP — is observed by the reverse proxy in front of the hosted endpoint at mcp.openarchieven.nl.
The server is anonymous-by-design.
https://api.openarchieven.nl/1.1 to fulfill the request, and the upstream response is returned to the caller.
to stdout via pino. On the hosted endpoint these logs are ephemeral: they are not written to disk and are lost on process restart. Set LOG_LEVEL=warn to suppress argument logging.
cached under keys of the form mcp:<tool>:<sorted-params-json>. The cache contains response bodies only; no user identifiers are stored.
No data is sent to any service other than the upstream Open Archives API listed above. There are no analytics, telemetry, advertising, or observability third parties involved.
| Data | Retention |
|---|---|
| Tool arguments and responses | Not persisted by the application |
| Application logs | Ephemeral (stdout, lost on restart) |
| Redis cache entries | Per-tool TTL (6 hours – 7 days; immutable historical lookups never expire). See Redis Cache. |
| Reverse-proxy access logs | Per the hosting provider's standard retention policy |
The MCP endpoint validates the Origin header on every request and rejects unknown browser origins (DNS-rebinding defense). All transport is over HTTPS.
Tool responses include URLs that point to record pages on https://www.openarchieven.nl. The submission declares the following allowed link URI so users are not prompted to confirm each link:
https://www.openarchieven.nlFor privacy questions or requests, contact:
[email protected]v1.0Schema-perfect OpenAPI-generated MCP server for Open Archives.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.