Give Claude, Cursor, or your own AI booking agent direct access to FMCSA carrier risk intelligence: identity lookup, two validated risk indices, batch monitoring, and timestamped Montgomery carrier-selection evidence reports.
Remote server · Streamable HTTP ·https://mcp.carrierscore.io/mcp
Settings → Connectors → Add custom connector. Name: CarrierScore. URL: https://mcp.carrierscore.io/mcp. Leave client ID and secret blank. Public tools work immediately; when a tool needs an account, Claude shows a Connect card and opens our sign-in page.
claude mcp add --transport http carrierscore https://mcp.carrierscore.io/mcp
Then /mcp to authenticate if you want to use your API key.
Add to ~/.cursor/mcp.json (or the project's .cursor/mcp.json) — see the snippet below. Cursor runs the OAuth flow in your browser when a protected tool is called.
Any MCP client that speaks Streamable HTTP can POST JSON-RPC to the endpoint. No auth needed for the free tier; OAuth 2.1 (PKCE, dynamic client registration or client-ID metadata documents) for accounts.
mcp.json{
"mcpServers": {
"carrierscore": {
"url": "https://mcp.carrierscore.io/mcp"
}
}
}
claude_desktop_config.json (via mcp-remote)Prefer the Connectors UI above; this is for older builds or when you want a static config file.
{
"mcpServers": {
"carrierscore": {
"command": "npx",
"args": ["-y", "mcp-remote", "https://mcp.carrierscore.io/mcp"]
}
}
}
Running the server yourself (source in the mcp-server/ directory of the repo)? CARRIERSCORE_API_KEY applies one key to every request that carries no OAuth token; AUTH_MODE=none turns the embedded OAuth server off entirely.
You can use CarrierScore without any account. Every request that carries no token runs on the free tier: rate-limited (30 requests per hour per IP), both risk indices with full components, and the text evidence report.
To use a Monitor or Compliance subscription from an MCP client, connect through OAuth: the client sends you to https://mcp.carrierscore.io/oauth/login, where you either Continue with free tier or paste the API key from your welcome email. The key is stored on our server and mapped to the access token issued to that client; the client itself never sees your key.
| Item | Value |
|---|---|
| Resource (MCP endpoint) | https://mcp.carrierscore.io/mcp |
| Protected-resource metadata (RFC 9728) | https://mcp.carrierscore.io/.well-known/oauth-protected-resource/mcp |
| Authorization-server metadata (RFC 8414) | https://mcp.carrierscore.io/.well-known/oauth-authorization-server |
| Grants | authorization_code + PKCE (S256, required), refresh_token (rotating) |
| Client registration | Dynamic (RFC 7591, POST /register) or Client ID Metadata Documents (client_id is an https URL) |
| Scopes | carrierscore:read — public tools; carrierscore:monitor — saved lists, alerts and the audit archive (paid key required) |
| Token lifetime | Access 24 h, refresh 90 d; revoke at POST /revoke or by disconnecting the client |
| Behaviour without a token | Public tools run as free tier. Paid tools answer 401 + WWW-Authenticate so clients that support lazy auth (Claude) offer to connect; a free-tier token gets 403 insufficient_scope (step-up) instead. |
All tools carry MCP annotations (title, readOnlyHint, destructiveHint, idempotentHint, openWorldHint) and return structured JSON (structuredContent) plus text.
| Tool | What it does | Tier | Annotations |
|---|---|---|---|
carrier_lookup | Identity by US DOT number: legal name, DBA, operating status, FMCSA safety rating, fleet size, address, registration dates. | Free | read-only, idempotent |
carrier_score | Two validated 0–100 risk indices (higher = riskier): inspection / compliance risk and crash risk, each with components, percentile basis, activity band, validation record, plus hard flags and data sufficiency. | Free | read-only, idempotent |
montgomery_file | Timestamped carrier-selection evidence report ("Montgomery file") — text on the free tier, structured JSON on paid tiers. | Free (text) / paid (json) | read-only, idempotent |
monitor_carriers | Batch score summary and hard flags for up to 100 DOT numbers per call. | Free | read-only, idempotent |
save_carrier_list | Save a named carrier list for daily change detection (OOS orders, authority loss, insurance lapse, index deterioration), optional webhook / digest email. | Monitor / Compliance | write (creates), non-destructive |
list_alerts | Alert history for a saved list, newest first, optionally since a date. | Monitor / Compliance | read-only, idempotent |
audit_entries | List the immutable audit archive of every evidence report your key generated (entry id, timestamp, DOT, SHA-256), newest first; filter by DOT / date. Monitor: last 90 days; Compliance: unlimited. | Monitor / Compliance | read-only, idempotent |
verify_evidence | Recompute the SHA-256 of an archived report by entry id and confirm it matches the hash recorded at generation (optionally against a hash you supply). | Monitor / Compliance | read-only, idempotent |
montgomery_file text only; no saved lists.scored_as_of.monitor_carriers takes up to 100 DOTs per call; split larger rosters.CarrierScore is a summary of public FMCSA data and computed statistical indicators. It is not a safety fitness determination, is not endorsed by FMCSA, and does not substitute for a carrier's official safety rating or a user's own judgment. Every score and report the server returns embeds this disclaimer; agents should relay it when presenting results.