nhtsa-vehicle-safety-mcp-server
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@nhtsa-vehicle-safety-mcp-serverWhat are the safety ratings and recalls for a 2022 Honda Civic?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Public Hosted Server: https://nhtsa.caseyjhand.com/mcp
Overview
Vehicle safety data from NHTSA — recall campaigns, consumer complaints, NCAP crash ratings, defect investigations, and VIN decoding. Search, decode, and cross-reference across five NHTSA data sources from any MCP client. Runs as a stdio process, a local Streamable HTTP server, or the public hosted endpoint above.
Tools
Tool | Description |
| Comprehensive safety profile combining crash test ratings, recalls, and complaint summary with per-section availability status. |
| Search recall campaigns by vehicle or campaign number with optional date filtering. |
| Consumer safety complaints with component breakdown and severity stats. |
| NCAP crash test ratings and ADAS feature availability. |
| Decode VINs for make, model, year, engine, safety equipment (single or batch up to 50). |
| Search NHTSA defect investigations (PE, EA, DP, RQ, AQ, and more) with cached index. |
| Look up valid makes, models, vehicle types, and manufacturer details from VPIC. |
Related MCP server: Vincario MCP Server
Capability reference
nhtsa_get_vehicle_safety tool
Combines NCAP crash test ratings, recall history, and complaint summary in a single response
Frontal crash, side crash, and rollover ratings per vehicle variant
Recall consequence text plus the do-not-drive, park-outside, and over-the-air-update advisories
Complaint breakdown by component with crash, fire, injury, and death counts
Returns
sectionStatus(available/partial/unavailable per section) pluswarningsso a partial NHTSA outage is not mistaken for a clean record
nhtsa_search_recalls tool
Look up by make/model/year or by specific NHTSA campaign number — the two are mutually exclusive
Campaign lookups return every make/model the campaign covers, plus the ODI investigation that preceded it
Optional date range filtering (ISO 8601), applied locally
Includes do-not-drive advisories, park-outside warnings, and OTA update availability
nhtsa_search_complaints tool
Component breakdown covers every matching complaint regardless of pagination; up to 50 complaint narratives per page (default 20), offset pagination, sorted by filing date descending
Optional
componentfilter matches within comma-separated component lists (e.g., "ENGINE", "AIR BAGS")Crash, fire, injury, and death counts on both the breakdown and each complaint
An incident date NHTSA reported that the complaint's own filing date or model year rules out is disclosed as
unreliableIncidentDaterather than served as the incident date
nhtsa_get_safety_ratings tool
Accepts either make + model + modelYear, or a follow-up
vehicleIdfrom an earlier resultFrontal crash, side crash (barrier + pole), and rollover ratings, plus ESC/forward-collision/lane-departure ADAS availability
Per-record complaint, recall, and investigation counts are variant-scoped — not vehicle-level totals
NCAP coverage starts at 1990, most complete for 2011+ model years
nhtsa_decode_vin tool
Single VIN or batch of up to 50; partial VINs accepted using
*for unknown positionsOptional
modelYearhelps disambiguate pre-1980 or partial VINsPreserves sparse VPIC fields instead of filling missing data with placeholders
Every result carries VPIC's own
errorCode/errorTextdecode-quality signal, including the clean "0" case
nhtsa_search_investigations tool
Investigation types: Preliminary Evaluations (PE), Engineering Analyses (EA), Defect Petitions (DP), Recall Queries (RQ), Audit Queries (AQ), and additional ODI codes (SQ, EQ, RP, and others)
Free-text search across investigation IDs, subjects, and summaries, plus structured make, model, and component filters — all ANDed
nhtsaIdfetches one investigation by its exact ID, mutually exclusive with the other filters — the reverse of the recall link, closing the campaign-to-investigation round tripSourced from NHTSA's ODI bulk file (
FLAT_INV.zip) — the first query downloads and parses it (~10s), subsequent queries use the cached index (24h TTL, matching the file's daily refresh)Up to 25 investigations per page (default 20), offset pagination
nhtsa_lookup_vehicles tool
Four operations:
makes,models,vehicle_types,manufacturer— partial match supported on make/manufacturer namesmodelscan be filtered by year;modelsandvehicle_typesboth requiremakeUp to 200 results per page (default 100), offset pagination
manufacturerlookups stop at a 500-record ceiling and disclosetruncatedwhen more may exist — VPIC publishes no match total
Features
Built on @cyanheads/mcp-ts-core: stdio and Streamable HTTP transports, pluggable auth (none / jwt / oauth), swappable storage (in-memory, filesystem, Supabase, Cloudflare KV/R2/D1), structured logging with optional OpenTelemetry tracing.
NHTSA-specific:
Type-safe client wrapping four NHTSA JSON APIs with retry logic and sparse-field normalization, plus a streaming parser for the ODI investigations bulk file
Investigation index caching (24h TTL) for fast repeated queries
No API key required — all NHTSA APIs are public
Agent-friendly output:
Provenance: every tool echoes
effectiveQueryin its enrichment block, so callers can verify exactly what was searchedGraceful partial failure:
nhtsa_get_vehicle_safetyreturnssectionStatusper section pluswarnings, so a partial NHTSA outage isn't mistaken for a clean safety recordDiscriminated outputs:
unreliableIncidentDate(complaints), VIN decodeerrorCode/errorText, and manufacturer-lookuptruncateddisclose data-quality limits rather than silently omitting or fabricating values
Getting started
Public Hosted Instance
A public instance is available at https://nhtsa.caseyjhand.com/mcp — no installation required. Point any MCP client at it via Streamable HTTP:
{
"mcpServers": {
"nhtsa-vehicle-safety-mcp-server": {
"type": "streamable-http",
"url": "https://nhtsa.caseyjhand.com/mcp"
}
}
}Self-Hosted / Local
Add the following to your MCP client configuration file:
{
"mcpServers": {
"nhtsa-vehicle-safety-mcp-server": {
"type": "stdio",
"command": "bunx",
"args": ["@cyanheads/nhtsa-vehicle-safety-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info"
}
}
}
}Or with npx (no Bun required):
{
"mcpServers": {
"nhtsa-vehicle-safety-mcp-server": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@cyanheads/nhtsa-vehicle-safety-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info"
}
}
}
}Or with Docker:
{
"mcpServers": {
"nhtsa-vehicle-safety-mcp-server": {
"type": "stdio",
"command": "docker",
"args": ["run", "-i", "--rm", "-e", "MCP_TRANSPORT_TYPE=stdio", "ghcr.io/cyanheads/nhtsa-vehicle-safety-mcp-server:latest"]
}
}
}For Streamable HTTP, set the transport and start the server:
MCP_TRANSPORT_TYPE=http MCP_HTTP_PORT=3010 bun run start:http
# Server listens at http://localhost:3010/mcpPrerequisites
Bun v1.4.0 or higher (or Node.js >= 24.0.0)
Installation
Clone the repository:
git clone https://github.com/cyanheads/nhtsa-vehicle-safety-mcp-server.gitNavigate into the directory:
cd nhtsa-vehicle-safety-mcp-serverInstall dependencies:
bun installConfigure environment (optional):
cp .env.example .env
# edit .env to override transport, auth, or storage defaults — no API key requiredConfiguration
No API keys required — all NHTSA APIs are public.
Variable | Description | Default |
| Transport: |
|
| HTTP server host. |
|
| HTTP server port. |
|
| HTTP endpoint path. |
|
| Auth mode: |
|
| HTTP session posture: |
|
| Log level (RFC 5424). |
|
See .env.example for the full list of optional overrides.
Running the server
Local development
Build and run:
# One-time build bun run rebuild # Run the built server bun run start:stdio # or bun run start:httpRun checks and tests:
bun run devcheck # Lint, format, typecheck, security bun run test # Vitest test suite bun run lint:mcp # Validate MCP definitions against spec
Docker
docker build -t nhtsa-vehicle-safety-mcp-server .
docker run --rm -p 3010:3010 nhtsa-vehicle-safety-mcp-serverThe Dockerfile defaults to HTTP transport and logs to /var/log/nhtsa-vehicle-safety-mcp-server; it restates the stateless session mode the server already declares. OpenTelemetry peer dependencies are installed by default — build with --build-arg OTEL_ENABLED=false to omit them.
Project structure
Directory | Purpose |
|
|
| Tool definitions ( |
| NHTSA API client, ODI bulk-file parser, and field normalization. |
| Unit and integration tests mirroring |
Development guide
See CLAUDE.md for development guidelines and architectural rules. The short version:
Handlers throw, framework catches — no
try/catchin tool logicUse
ctx.logfor request-scoped loggingOne tool per file,
nhtsa_prefix for every tool name, registered increateApp()Validate raw NHTSA responses → normalize to domain types → return the output schema; never fabricate a field NHTSA didn't provide
Data sources
All data comes from NHTSA's public APIs and bulk files:
Recalls API —
api.nhtsa.gov/recallsComplaints API —
api.nhtsa.gov/complaintsSafety Ratings API —
api.nhtsa.gov/SafetyRatingsInvestigations bulk file —
static.nhtsa.gov/odi/ffdd/inv/FLAT_INV.zipVPIC API —
vpic.nhtsa.dot.gov/api/vehicles
Contributing
Issues are welcome. Run checks and tests before submitting:
bun run devcheck
bun run testLicense
Apache-2.0 — see LICENSE for details.
This server cannot be deployed
Maintenance
Related MCP Connectors
NHTSA MCP — wraps the NHTSA vPIC (Vehicle Product Information Catalog) API (free, no auth)
Decodes US VINs and looks up open NHTSA safety recall campaigns for a vehicle.
VIN recall API + MCP: VIN decode + every NHTSA recall, Do Not Drive first. $19/mo; 50 free/day.
Decode any VIN and check open NHTSA safety recalls. Free official US government data, no auth.
Related MCP Servers
- AlicenseAqualityBmaintenanceConnects Claude to NHTSA vehicle safety data, enabling VIN decoding, recall checks, crash-test ratings, and consumer complaints via natural language.5MIT

Vincario MCP Serverofficial
FlicenseNot gradedqualityDmaintenanceEnables AI assistants to decode VINs, check stolen vehicle databases, and retrieve market valuations through natural language.2-- AlicenseNot gradedqualityBmaintenanceEnables querying U.S. vehicle safety and specification data, including VIN decoding, recalls, complaints, investigations, and crash test ratings.53 npmMIT
- AlicenseNot gradedqualityCmaintenanceEnables MCP clients to look up US vehicle-safety data read-only — decoding VINs, and retrieving recalls, owner complaints, and 5-Star NCAP safety ratings by make, model, and year through NHTSA's public APIs.MIT