Official MCP server: EU VAT validation via VIES, plus offline rates and format checks.
SaferSkills independently audited vatnode-mcp (MCP Server) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Official Model Context Protocol server for [vatnode](https://vatnode.dev) — VAT validation and EU tax data for AI agents.
Lets AI assistants (Claude Desktop, Cursor, ChatGPT, Continue, Cline, …) look up VAT rates, check VAT number formats, and validate VAT IDs against the EU VIES service without leaving the chat.
npx| Tool | Free | Description |
|---|---|---|
get_country_vat_rates | ✅ | Standard / reduced / super-reduced / parking rates + VAT number format for a country |
list_eu_vat_rates | ✅ | All 27 EU member states (plus XI for Northern Ireland) at once |
check_vat_format | ✅ | Offline syntactic check of a VAT number against the country regex |
list_supported_countries | ✅ | All 45 supported countries and which ones support full VIES validation |
validate_vat_number | 🔑 | Live VIES validation — returns validity, company name, address, registration date, and optional consultation number for audit proof |
Free tools work fully offline — data is bundled via eu-vat-rates-data and updated daily from the European Commission TEDB.
validate_vat_number requires a vatnode API key. The free tier includes a monthly request quota — get one in 30 seconds.
Add to your claude_desktop_config.json (macOS: ~/Library/Application Support/Claude/claude_desktop_config.json):
{
"mcpServers": {
"vatnode": {
"command": "npx",
"args": ["-y", "vatnode-mcp"],
"env": {
"VATNODE_API_KEY": "vat_live_..."
}
}
}
}Restart Claude Desktop. The vatnode tools will appear in the tool picker.
You can omit VATNODE_API_KEY if you only need the free tools (rates, format checks).
Settings → MCP → Add new server:
{
"mcpServers": {
"vatnode": {
"command": "npx",
"args": ["-y", "vatnode-mcp"],
"env": { "VATNODE_API_KEY": "vat_live_..." }
}
}
}Configure as an stdio MCP server with the same npx -y vatnode-mcp command. See the Apps SDK docs.
Any MCP-compatible client can connect — point it at npx -y vatnode-mcp and (optionally) pass VATNODE_API_KEY via environment.
validate_vat_number requires a vatnode account. The platform also offers things the MCP doesn't expose:
You: What's the VAT rate in Finland and Germany?
>
(Agent calls `get_country_vat_rates` for FI and DE — free, no key.)
>
Agent: Finland's standard VAT is 25.5%, Germany's is 19%. Finland has reduced rates of 14% and 10%; Germany has 7%.
You: Is IE6388047V a valid VAT?
>
(Agent calls `validate_vat_number` — requires API key.)
>
Agent: Yes, it's valid. Registered to GOOGLE IRELAND LIMITED at Gordon House, Barrow Street, Dublin 4.
| Env var | Required | Default | Purpose |
|---|---|---|---|
VATNODE_API_KEY | for validate_vat_number | — | API key from https://vatnode.dev |
VATNODE_API_URL | no | https://api.vatnode.dev | Override the API base (self-hosting / staging) |
Bug reports and PRs welcome. Open an issue first for non-trivial changes so we can align on direction.
git clone https://github.com/vatnode/vatnode-mcp.git
cd vatnode-mcp
npm install
npm testReleases are published to npm via Trusted Publishing — no NPM_TOKEN secret, every release signed with npm provenance.
# bump version in package.json (and VERSION in src/index.ts), commit, then:
git tag v0.2.1
git push --tagsCI on .github/workflows/release.yml picks up the tag and publishes.
MIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.