@cyanheads/cpsc-recalls-mcp-server
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@@cyanheads/cpsc-recalls-mcp-serverSearch for recent recalls about fire hazards"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Public Hosted Server: https://cpsc-recalls.caseyjhand.com/mcp
Overview
Consumer product recalls from the CPSC saferproducts.gov database — toys, electronics, furniture, appliances, children's products, tools, and clothing. Search recalls by product, brand, retailer, or hazard, fetch full detail for a specific recall number, or pull a recent-recalls feed for a date window. Runs as a stdio process, a local Streamable HTTP server, or the public hosted endpoint above.
Tools
Tool | Description |
| Search consumer product recalls by title, product name, brand, retailer, importer, distributor, hazard, remedy, or description keyword, with optional date filtering and offset paging |
| Full detail for a single recall by recall number — hazards, remedy, products, injuries, images, and the official CPSC page |
| Fetch the most recent recalls ordered newest-first, scoped to a configurable date window |
CPSC jurisdiction is consumer products only — food/drugs (FDA), motor vehicles/tires (NHTSA), boats (USCG), and pesticides (EPA) are not in this database; every response carries a jurisdiction note.
Related MCP server: mcp-cpsc
Capability reference
cpsc_search_recalls tool
Nine text filters —
product_name,manufacturer,retailer,importer,distributor,title_search,description_search,remedy(free-text instructions, not theremedy_optionscategories), andhazard_search(hazard text, product names, or remedy instructions;hazardis accepted as an alias) — all combine with AND;title_searchis usually highest-signalA search needs at least one criterion — a non-blank text filter or a date bound;
limit/offsetalone fail withmissing_criteria, whose hint points browsing tocpsc_get_recent. A blank or whitespace-only filter counts as omittedWord matching: every whitespace-separated word of a text filter must appear in that filter's field, in any order and case-insensitively; straight and curly apostrophes match each other, and
%,_, and[…]match literally. Words match the plain text the results show, soStoopher & Bootsmatches a record CPSC stores asStoopher & Boots, and tag markup such asvalignmatches nothing. No stemming or fuzzy matching. Each text filter accepts up to 500 charactersTwo independent date axes:
date_start/date_endbound the recall issue date,updated_start/updated_endbound the date CPSC last published it; all four must be real calendar dates and a reversed range throwsinvalid_date_rangelimit(1–200, default 20) andoffset(default 0) page throughtotal_found, which counts every match before the window; a page returns fewer thanlimitrecalls when it reaches the 64,000-byte response size budget, and its notice names the offset to continue from.has_moreis the paging signal andtruncatedalways equals itReturns hazard descriptions, remedy options and instructions, products, UPCs, manufacturer/importer/retailer/distributor names, images,
cpsc_url, and per-recalldata_quality_notes; manufacturer and importer render as separate roles — tryimporter,retailer, ordistributorwhenmanufacturercomes back emptyZero matches is an empty success, not an error:
effectiveQueryechoes the criteria as applied, and a notice says which criterion to relax (the count beforehazard_searchemptied the set, fewer words, another company role, wider dates). An offset past the last match returns an empty page with its own notice.upstream_rejected(non-retryable) relays CPSC's own rejection,upstream_error(retryable) covers transient outages, including a temporary CPSC data-source failure the server has already retried once
cpsc_get_recall tool
Accepts modern 5-digit recall numbers (e.g.
"25043") and historical 1998–2001 records with letter suffixes (e.g."99003a"); a malformed number is rejected as invalid input with both forms spelled outReturns the complete record — full description, all hazard and remedy detail, every product variant, UPCs, incident/injury narrative, manufacturer/importer/retailer/distributor names, country of manufacture, images, and coordinated-agency recall URLs
descriptionis nullable — a small number of genuine CPSC records carry no description text, and model numbers are usually embedded there rather than in a structured fieldManufacturer and importer render under separate headings so role attribution survives into
content[]data_quality_notesrecords gaps in the upstream record (absent description, hazard text, or product entries); empty when nothing is missingnot_foundwhen the recall number doesn't exist — resolve one viacpsc_search_recallsorcpsc_get_recentfirst;upstream_rejected(non-retryable) relays CPSC's own rejection,upstream_error(retryable) covers transient outages, including a temporary CPSC data-source failure the server has already retried once
cpsc_get_recent tool
Look-back window of 1–365 days (default 30), anchored to today; older recalls are reachable through
cpsc_search_recallsdate boundslimit(1–100, default 20) andoffset(default 0) page throughtotal_found; a page returns fewer thanlimitrecalls when it reaches the 64,000-byte response size budget. Narrowingdayscannot page further back — the window is anchored to today, so shrinking it drops the oldest records rather than advancing past the newesthas_moreis the paging signal andtruncatedalways equals it; an empty window, an offset past the last recall, and a budget-cut page each carry a notice saying what to do nextReturns a lightweight record per recall — number, date, title, hazards, remedy types, product names,
cpsc_url— plusdata_quality_notesfor gaps CPSC left emptyUse
cpsc_get_recallto retrieve full detail for any result
Features
Built on @cyanheads/mcp-ts-core: stdio and Streamable HTTP transports, pluggable auth (none / jwt / oauth), swappable storage (in-memory, filesystem, Supabase, Cloudflare KV/R2/D1), structured logging with optional OpenTelemetry tracing.
CPSC-specific:
Full client for the CPSC saferproducts.gov public recalls API — search, single-recall detail, and a recent-recalls feed
Every-word matching on all nine text filters, applied over the complete result set before paging so
total_foundandhas_morestay accurateHandles both modern 5-digit recall numbers and historical 1998–2001 records with letter suffixes
Jurisdiction boundary documented in every response — flags food, vehicle, and drug recalls as out of scope before an agent misattributes them
Agent-friendly output:
Provenance on every response —
source_note,cpsc_url, and(CPSC source text)blockquote labels distinguish relayed CPSC narrative from the server's own guidancePlain text on both surfaces — the HTML markup and character codes CPSC stores in some records (
&,<br>, stray table tags) are converted to plain text before matching and output, andcontent[]escapes Markdown so model and serial numbers such as1HFVE05**K4000003keep every character; recall page, image, and coordinated-recall addresses that contain spaces are percent-encoded incontent[]so each renders as one working link, whilestructuredContentcarries them as CPSC stores themPagination discriminators —
total_found,offset,has_more, andtruncatedon every search/recent response so agents can tell when results are clipped and page withoffset; each surface of a page stays within a 64,000-byte budget, and a notice gives the next offset when the budget ends a page earlydata_quality_noteson every response — gaps observed in the upstream record (missing hazard text, no product entries), derived from which fields CPSC left blank rather than any judgment callJurisdiction note (
cpsc_jurisdiction) on every response — lets agents route callers to the correct agency (FDA, NHTSA, USCG, EPA) when a product is out of scope
Getting started
Public Hosted Instance
A public instance is available at https://cpsc-recalls.caseyjhand.com/mcp — no installation required. Point any MCP client at it via Streamable HTTP:
{
"mcpServers": {
"cpsc-recalls-mcp-server": {
"type": "streamable-http",
"url": "https://cpsc-recalls.caseyjhand.com/mcp"
}
}
}Self-Hosted / Local
Add the following to your MCP client configuration file.
{
"mcpServers": {
"cpsc-recalls-mcp-server": {
"type": "stdio",
"command": "bunx",
"args": ["@cyanheads/cpsc-recalls-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info"
}
}
}
}Or with npx (no Bun required):
{
"mcpServers": {
"cpsc-recalls-mcp-server": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@cyanheads/cpsc-recalls-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info"
}
}
}
}Or with Docker:
{
"mcpServers": {
"cpsc-recalls-mcp-server": {
"type": "stdio",
"command": "docker",
"args": ["run", "-i", "--rm", "-e", "MCP_TRANSPORT_TYPE=stdio", "ghcr.io/cyanheads/cpsc-recalls-mcp-server:latest"]
}
}
}For Streamable HTTP, set the transport and start the server:
MCP_TRANSPORT_TYPE=http MCP_HTTP_PORT=3010 bun run start:http
# Server listens at http://localhost:3010/mcpPrerequisites
Bun v1.4.0 or higher (or Node.js v24+).
No API key required — the CPSC public recalls API is freely accessible.
Installation
Clone the repository:
git clone https://github.com/cyanheads/cpsc-recalls-mcp-server.gitNavigate into the directory:
cd cpsc-recalls-mcp-serverInstall dependencies:
bun installConfigure environment:
cp .env.example .env
# edit .env if needed — no required API keysConfiguration
All configuration is validated at startup via Zod schemas. Key environment variables:
Variable | Description | Default |
| Transport: |
|
| HTTP server port |
|
| HTTP server host |
|
| HTTP endpoint path |
|
| Public origin for TLS-terminating reverse-proxy deployments | — |
| Session handling: |
|
| Authentication: |
|
| Log level ( |
|
| Directory for log files (Node.js only) |
|
| Storage backend: |
|
| Enable OpenTelemetry |
|
No server-specific API keys are required. See .env.example for the full list of optional overrides.
Running the server
Local development
Build and run the production version:
# One-time build bun run rebuild # Run the built server bun run start:stdio # or bun run start:httpRun checks and tests:
bun run devcheck # Lint, format, typecheck, security bun run test # Vitest test suite
Docker
docker build -t cpsc-recalls-mcp-server .
docker run --rm -p 3010:3010 cpsc-recalls-mcp-serverThe Dockerfile defaults to HTTP transport, stateless session mode, and logs to /var/log/cpsc-recalls-mcp-server. OpenTelemetry peer dependencies are installed by default — build with --build-arg OTEL_ENABLED=false to omit them.
Project structure
Directory | Purpose |
|
|
| Tool definitions ( |
| CPSC recall service — API client, types, and |
Development guide
See CLAUDE.md / AGENTS.md for development guidelines and architectural rules. The short version:
Handlers throw, framework catches — no
try/catchin tool logicUse
ctx.logfor request-scoped logging,ctx.statefor tenant-scoped storageRegister new tools in the
createApp()arrays insrc/index.tsWrap external API calls: validate raw → normalize to domain type → return output schema; never fabricate missing fields
Contributing
Issues are welcome. Run checks and tests before submitting:
bun run devcheck
bun run testLicense
Apache-2.0 — see LICENSE for details.
This server cannot be deployed
Maintenance
Related MCP Connectors
Query FDA data on drugs, food, devices, and recalls via openFDA. STDIO or Streamable HTTP.
Query SEC EDGAR filings, XBRL financials, and company data through MCP. STDIO & Streamable HTTP.
CPSC MCP — US consumer-product safety recalls (CPSC, free, no auth).
Search U.S. FDA, USDA FSIS, and CPSC recalls, fetch one, or diff since a date. API key or x402.
Related MCP Servers
- AlicenseNot gradedqualityAmaintenanceAccess FEC campaign finance data through MCP. Query data about candidates, money trails, and election filings. STDIO & Streamable HTTP.473 npm2Apache 2.0
- AlicenseNot gradedqualityBmaintenanceAccess US consumer-product safety recalls from the CPSC, free and without authentication.218 npmMIT

deeprecall-mcpofficial
AlicenseNot gradedqualityCmaintenanceSearch 120,000+ recalled products from CPSC, FDA, EU Safety Gate, and other global agencies via MCP. Enables AI agents to check product safety by text or image.Apache 2.0- AlicenseNot gradedqualityAmaintenanceSearch and fetch ~800K Federal Reserve economic time-series from the FRED API via MCP, with STDIO or Streamable HTTP transport.81 npm1Apache 2.0