{"name":"com.coiops/coiops","title":"COIOps","version":"0.1.0","transport":"streamable-http","protocol":"MCP tools, prompts, and resources over JSON-RPC","endpoint":"https://coiops.com/api/mcp","documentation":"https://coiops.com/mcp","llms_txt":"https://coiops.com/llms.txt","registry":{"server_json":"https://coiops.com/server.json","smithery":"https://smithery.ai","smithery_note":"Publish from repo smithery.yaml when DNS TXT is set (see docs/MCP-REGISTRY.md).","oauth_protected_resource":"https://coiops.com/.well-known/oauth-protected-resource","oauth_authorization_server":"https://coiops.com/.well-known/oauth-authorization-server"},"auth":{"api_key":"Authorization: Bearer coiops_… (org API key; POST requires auth)","oauth":"Interactive OAuth is not enabled. PRM at /.well-known/oauth-protected-resource; AS metadata states API keys are the production path."},"cors":"Browser MCP hosts may call GET/POST /api/mcp cross-origin with Bearer org keys only (no cookies). Allowed Origins include coiops.com, common agent hosts, and localhost.","idempotency":"Idempotency-Key header on ingest_coi_pdf, request_updated_coi, set_gate_status","metering":{"units":"read=1, write=5, heavy=25","included_monthly_units":{"free":500,"pro":10000,"growth":25000,"ops":50000},"docs":"https://coiops.com/mcp"},"catalog":"https://coiops.com/mcp.md","write_tools_require_pro":["upsert_vendor","ingest_coi_pdf","check_requirements","request_updated_coi","block_vendor_if_noncompliant","set_gate_status","run_morning_compliance_brief","upsert_template","export_compliance_pack","sync_status_outbound","create_customer_ask"],"disclaimer":"Document scores only — not live carrier verification. Certificate ≠ policy.","tools":[{"name":"list_vendors","description":"List vendors for the authenticated org. Optional gate_status / query filter."},{"name":"get_vendor","description":"Vendor + latest certificate summary + gate + open deficiencies."},{"name":"upsert_vendor","description":"Create or update a vendor."},{"name":"ingest_coi_pdf","description":"Store the real COI PDF and run extraction. Queues needs_review. Does not invent a carrier or auto-clear the gate."},{"name":"check_requirements","description":"Score vendor against template (explicit → job → org default). Writes RequirementScore + Deficiencies. Document score only — not live carrier verify."},{"name":"list_expiring_cois","description":"Coverage lines expiring within N days."},{"name":"request_updated_coi","description":"Create a chase record and email a magic-link upload when Resend or SMTP is configured. If mail is unset, the chase is stored and not marked sent."},{"name":"block_vendor_if_noncompliant","description":"Confirm-gated: block vendor when latest score fail or coverage expired."},{"name":"set_gate_status","description":"Set gate status. confirm required for cleared / override_cleared. Reason mandatory."},{"name":"run_morning_compliance_brief","description":"Ops brief: blocked, expiring, unanswered chases, review queue."},{"name":"list_templates","description":"List requirement templates for the org."},{"name":"upsert_template","description":"Create or update a requirement template. confirm required when changing org-default template."},{"name":"export_compliance_pack","description":"Post-MVP: generate compliance pack download URL."},{"name":"sync_status_outbound","description":"Post-MVP: push gate status to external system."},{"name":"create_customer_ask","description":"Insert ask→build→ping backlog item."}],"server_card":"experimental","note":"Public discovery only. Tool calls require org API key via POST /api/mcp."}