MCP server

Give Claude, Cursor, or your own AI booking agent direct access to FMCSA carrier risk intelligence: identity lookup, two validated risk indices, batch monitoring, and timestamped Montgomery carrier-selection evidence reports.

Remote server · Streamable HTTP · https://mcp.carrierscore.io/mcp

Quick start

Claude.ai / Claude Desktop

Settings → Connectors → Add custom connector. Name: CarrierScore. URL: https://mcp.carrierscore.io/mcp. Leave client ID and secret blank. Public tools work immediately; when a tool needs an account, Claude shows a Connect card and opens our sign-in page.

Claude Code

claude mcp add --transport http carrierscore https://mcp.carrierscore.io/mcp
Then /mcp to authenticate if you want to use your API key.

Cursor

Add to ~/.cursor/mcp.json (or the project's .cursor/mcp.json) — see the snippet below. Cursor runs the OAuth flow in your browser when a protected tool is called.

Anything else

Any MCP client that speaks Streamable HTTP can POST JSON-RPC to the endpoint. No auth needed for the free tier; OAuth 2.1 (PKCE, dynamic client registration or client-ID metadata documents) for accounts.

Cursor · mcp.json

{
  "mcpServers": {
    "carrierscore": {
      "url": "https://mcp.carrierscore.io/mcp"
    }
  }
}

Claude Desktop · claude_desktop_config.json (via mcp-remote)

Prefer the Connectors UI above; this is for older builds or when you want a static config file.

{
  "mcpServers": {
    "carrierscore": {
      "command": "npx",
      "args": ["-y", "mcp-remote", "https://mcp.carrierscore.io/mcp"]
    }
  }
}

Self-hosted / server-wide key

Running the server yourself (source in the mcp-server/ directory of the repo)? CARRIERSCORE_API_KEY applies one key to every request that carries no OAuth token; AUTH_MODE=none turns the embedded OAuth server off entirely.

Authentication

You can use CarrierScore without any account. Every request that carries no token runs on the free tier: rate-limited (30 requests per hour per IP), both risk indices with full components, and the text evidence report.

To use a Monitor or Compliance subscription from an MCP client, connect through OAuth: the client sends you to https://mcp.carrierscore.io/oauth/login, where you either Continue with free tier or paste the API key from your welcome email. The key is stored on our server and mapped to the access token issued to that client; the client itself never sees your key.

ItemValue
Resource (MCP endpoint)https://mcp.carrierscore.io/mcp
Protected-resource metadata (RFC 9728)https://mcp.carrierscore.io/.well-known/oauth-protected-resource/mcp
Authorization-server metadata (RFC 8414)https://mcp.carrierscore.io/.well-known/oauth-authorization-server
Grantsauthorization_code + PKCE (S256, required), refresh_token (rotating)
Client registrationDynamic (RFC 7591, POST /register) or Client ID Metadata Documents (client_id is an https URL)
Scopescarrierscore:read — public tools; carrierscore:monitor — saved lists, alerts and the audit archive (paid key required)
Token lifetimeAccess 24 h, refresh 90 d; revoke at POST /revoke or by disconnecting the client
Behaviour without a tokenPublic tools run as free tier. Paid tools answer 401 + WWW-Authenticate so clients that support lazy auth (Claude) offer to connect; a free-tier token gets 403 insufficient_scope (step-up) instead.

Tools

All tools carry MCP annotations (title, readOnlyHint, destructiveHint, idempotentHint, openWorldHint) and return structured JSON (structuredContent) plus text.

ToolWhat it doesTierAnnotations
carrier_lookupIdentity by US DOT number: legal name, DBA, operating status, FMCSA safety rating, fleet size, address, registration dates.Freeread-only, idempotent
carrier_scoreTwo validated 0–100 risk indices (higher = riskier): inspection / compliance risk and crash risk, each with components, percentile basis, activity band, validation record, plus hard flags and data sufficiency.Freeread-only, idempotent
montgomery_fileTimestamped carrier-selection evidence report ("Montgomery file") — text on the free tier, structured JSON on paid tiers.Free (text) / paid (json)read-only, idempotent
monitor_carriersBatch score summary and hard flags for up to 100 DOT numbers per call.Freeread-only, idempotent
save_carrier_listSave a named carrier list for daily change detection (OOS orders, authority loss, insurance lapse, index deterioration), optional webhook / digest email.Monitor / Compliancewrite (creates), non-destructive
list_alertsAlert history for a saved list, newest first, optionally since a date.Monitor / Complianceread-only, idempotent
audit_entriesList the immutable audit archive of every evidence report your key generated (entry id, timestamp, DOT, SHA-256), newest first; filter by DOT / date. Monitor: last 90 days; Compliance: unlimited.Monitor / Complianceread-only, idempotent
verify_evidenceRecompute the SHA-256 of an archived report by entry id and confirm it matches the hash recorded at generation (optionally against a hash you supply).Monitor / Complianceread-only, idempotent

Example prompts

Is DOT 165826 safe to book for a dry-van load next week? Give me both risk indices and any hard flags.
Look up DOT 2213480 and confirm the legal name matches "Sunbelt Freight Lines LLC" on this rate confirmation.
Generate and save the Montgomery evidence file for DOT 1234567 — I'm selecting them for load 44921 today.
Here are the 40 DOT numbers on my active carrier roster. Which ones have an out-of-service order, no insurance, or a crash-risk index above 80?
Compare the inspection-risk components for DOT 55555 and DOT 66666 and tell me which has the worse recent (6-month) out-of-service trend.
Save these carriers as "Q3 core roster" for daily monitoring and show me any alerts since Monday.
Explain what "data sufficiency 0.4" means for a carrier that got its authority six months ago.

Rate limits and data

Disclaimer

CarrierScore is a summary of public FMCSA data and computed statistical indicators. It is not a safety fitness determination, is not endorsed by FMCSA, and does not substitute for a carrier's official safety rating or a user's own judgment. Every score and report the server returns embeds this disclaimer; agents should relay it when presenting results.