Skip to main content
Glama
endoflife-ai

endoflife-mcp

Official

endoflife.ai — MCP Server

Node.js EOL status EOL data: endoflife.ai

Exposes endoflife.ai's lifecycle intelligence to AI agents over the Model Context Protocol (MCP, Streamable HTTP transport). A dependency-free Cloudflare Worker that wraps the public api.endoflife.ai/v1 endpoints and the site's published feeds — no data duplicated, every answer carries a source URL.

Current version: 1.3.0 (SERVER_INFO.version in src/index.js, server.json, package.json — keep all three in step; CI fails if they disagree; the registry and Glama read server.json).

Tools (all read-only)

Tool

What it does

Backed by

check_eol

Is product X version Y end-of-life?

GET /v1/status/:slug/:version

get_risk_score

EOL Risk Score (0–100) + factor breakdown

GET /v1/score/:slug[/:version]

scan_stack

Score a whole stack at once

POST /v1/batch

list_products

Search the 500+ tracked products → resolve slugs

GET /v1/products

get_product_lifecycle

Full version history + dates for one product

GET /v1/product/:slug

get_kev_exposure

Every CISA KEV entry attributed to a product (date added, due date, required action verbatim) + Exploited & Unpatchable entries

endoflife.ai/kev-products.json, exploited-and-unpatchable.json

get_upcoming_eol

Everything reaching EOL in the next N days (catalog-wide or a product list)

endoflife.ai/scanner-db.json

get_edge_device_status

EOS Edge Device feed with BOD 26-02 statuses, filter by platform / status / model

endoflife.ai/eos-edge-devices.json

get_upgrade_path

Supported targets, the site's recommendation, vendor-stated successor

GET /v1/product/:slug, checker-db.json, edge feed

check_sbom

CycloneDX / SPDX JSON → components resolved by package URL (exact, purl-map.json) or by name when no purl → scored; unmatched listed with a reason, never guessed

purl-map.json + POST /v1/batch

Every tool advertises annotations (readOnlyHint, idempotentHint) and a permissive outputSchema; results are returned both as JSON text and as structuredContent. Lookup misses return "did you mean" slug suggestions (prefix / substring / edit-distance ≤ 2 against the live product list).

Resources (resources/list / resources/read): llms.txt, the EOS Edge Device feed, Exploited & Unpatchable, KEV by product, the edge change log.

Prompts (prompts/list / prompts/get): audit_stack, eol_calendar, edge_device_review.

Endpoints: POST / (JSON-RPC), GET / (info page), GET /health (liveness JSON), GET /.well-known/mcp/server-card.json (discovery card).

Related MCP server: EndOfLife MCP Server

Usage telemetry

With the USAGE Analytics Engine binding (see wrangler.toml, dataset endoflife_mcp_usage) each method / tool call writes one data point: tool name, client user agent, ok/error, keyed/anon, latency in ms. No request bodies. Query via the Cloudflare Analytics Engine SQL API, e.g.

SELECT blob1 AS tool, count() AS calls, sum(_sample_interval) AS weighted
FROM endoflife_mcp_usage WHERE timestamp > NOW() - INTERVAL '7' DAY
GROUP BY tool ORDER BY calls DESC

The binding is optional; the code no-ops without it.

Deploy

The hosted server at mcp.endoflife.ai is deployed by the maintainers from the endoflife.ai site repository's GitHub Actions workflow (pinned wrangler, Cloudflare credentials held there as repository secrets); this public repository carries no deploy workflow of its own. To run your own copy, wrangler deploy from this repository works with your own Cloudflare account, and wrangler dev runs it locally; the API service binding and the USAGE dataset in wrangler.toml are declared for both the default and production environments.

Custom domain (mcp.endoflife.ai)

The route in wrangler.toml needs mcp.endoflife.ai to resolve through Cloudflare: an AAAA record, name mcp, IPv6 100::, proxied. Already in place.

Test before deploying

CI (.github/workflows/ci.yml) runs on every push and pull request and once a day: syntax checks, manifest validity, the version-agreement check, and a live smoke test that calls the deployed server's tools. The same smoke test runs locally:

node --check src/index.js && node --check stdio.js
node .github/scripts/smoke.mjs   # real tool calls against mcp.endoflife.ai, expects 0 failures

Run as a container (Red Hat UBI)

server.mjs runs the same handler that serves mcp.endoflife.ai inside a plain Node.js process, and Dockerfile packages it on registry.access.redhat.com/ubi9/nodejs-22-minimal for cluster deploys (the form the OpenShift AI MCP catalog expects). No build step, no dependencies; the container talks to https://api.endoflife.ai over HTTPS and runs as the unprivileged UBI user (uid 1001).

docker build -t endoflife-mcp .
docker run --rm -p 8080:8080 endoflife-mcp
curl -s localhost:8080/health

Endpoints are the Worker's own: POST / (Streamable HTTP JSON-RPC), GET /health (readiness), GET /.well-known/mcp/server-card.json. Set ENDOFLIFE_API_KEY to forward a Pro key. The image is built on Red Hat UBI 9 with Node 22; the maintainers run it on RHEL 9 and 10 as part of their Red Hat partner validation, which lives outside this repository.

Connect from an MCP client

Claude Desktop / Cursor / VS Code (mcpServers):

{
  "mcpServers": {
    "endoflife": { "command": "npx", "args": ["mcp-remote", "https://mcp.endoflife.ai"] }
  }
}

Clients with native remote-MCP support can use the URL directly:

{ "mcpServers": { "endoflife": { "url": "https://mcp.endoflife.ai" } } }

Test without a client

# tools/list
curl -s https://mcp.endoflife.ai -X POST -H 'Content-Type: application/json' \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}' | jq

# KEV exposure for a product
curl -s https://mcp.endoflife.ai -X POST -H 'Content-Type: application/json' \
  -d '{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"get_kev_exposure","arguments":{"product":"ivanti-connect-secure"}}}' | jq

# health + discovery card
curl -s https://mcp.endoflife.ai/health | jq
curl -s https://mcp.endoflife.ai/.well-known/mcp/server-card.json | jq

Auth & tiers

Free tier works with no key. Forward an X-API-Key header (your existing Pro keys) to unlock Pro limits — the Worker passes it straight through to api.endoflife.ai.

Notes

  • Same-zone trap: api.endoflife.ai is a Worker on this zone; a plain fetch() to it goes to origin and fails. The API service binding is mandatory in prod.

  • Static feeds are fetched from the site origin with cf.cacheTtl = 600 and memoised in the isolate for 10 minutes.

  • Per-client rate limits: relies on the upstream API's limits. If MCP traffic grows, add a KV rate-limiter keyed on CF-Connecting-IP before the upstream call.

  • Discovery card is also served from the main site at https://endoflife.ai/.well-known/mcp/server-card.json.

Available Tools

5 tools
check_eolAInspect

Check whether a specific version of a software product is end-of-life (EOL). Returns lifecycle status, the EOL date, days remaining or days past EOL, and the latest release. Use this for "is X version Y still supported?" questions.

ParametersJSON Schema
NameRequiredDescriptionDefault
productYesProduct slug or name, e.g. "postgresql", "nodejs", "ubuntu".
versionYesVersion/cycle, e.g. "14", "18", "20.04".

TDQS

A4.3/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations provided. Description lists return values (lifecycle status, EOL date, days remaining, latest release) and indicates it's a read-only query. Does not disclose authentication requirements or rate limits, but sufficient for a simple check tool.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences: first states purpose and outputs, second gives clear usage example. No wasted words, front-loaded with essential information.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

No output schema, but description enumerates return values. Covers all necessary information for an agent to understand input, action, and expected output.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Input schema has 100% coverage with descriptions for both parameters (product and version), including examples. Description does not add additional parameter meaning beyond what schema provides, meeting baseline expectation.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Description clearly states the tool checks EOL status for a specific product version, with verb 'check' and resource 'version of a software product'. It distinguishes from siblings like list_products and get_product_lifecycle by focusing on a single version's EOL status.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Includes explicit usage example ('Use this for "is X version Y still supported?" questions') and context of when to use. Does not explicitly mention when not to use or alternatives, but sibling tool list provides implicit differentiation.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

get_product_lifecycleAInspect

Get the full version history for one product: every tracked version/cycle with its release date, EOL date, support status, and EOL Risk Score™. Use for "give me the whole EOL schedule for X".

ParametersJSON Schema
NameRequiredDescriptionDefault
productYesProduct slug or name, e.g. "postgresql".

TDQS

A3.6/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations provided. Description does not disclose behavioral traits such as data freshness, authentication requirements, potential cost, or whether it invokes external APIs. It only describes output, not side effects or constraints.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Description is two sentences with zero wasted words: first sentence defines function, second sentence provides usage context. Each sentence is informative and necessary.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given no output schema, the description lists key return fields (release date, EOL date, support status, risk score), which is fairly complete. It could clarify ordering or version count, but for a simple list tool it is adequate.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Input schema has 100% coverage for the one parameter, which is well-described. The description adds no additional semantics beyond what the schema provides, so baseline score of 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Description clearly states it retrieves full version history for one product, listing specific fields (release date, EOL date, support status, risk score). It distinguishes from sibling tools like list_products (lists products) and check_eol (single check).

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The phrase 'Use for "give me the whole EOL schedule for X"' gives a clear use case, but it does not specify when not to use it or mention alternatives among siblings like check_eol or get_risk_score.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

get_risk_scoreAInspect

Get the proprietary EOL Risk Score™ (0–100) for a product version, with the four-factor breakdown (EOL recency, attack surface, CISA KEV exposure, extended support). Omit "version" to score the product's highest-risk (most recently end-of-lifed) release. Use this to quantify how dangerous it is to keep running something.

ParametersJSON Schema
NameRequiredDescriptionDefault
productYesProduct slug or name, e.g. "openssl", "python".
versionNoOptional version/cycle. Omit for the highest-risk release.

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Describes the output as a score 0–100 with a four-factor breakdown, and explains behavior when version is omitted. Although no annotations exist, the description adequately conveys the tool's read-only nature and scope.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences, no redundant words. First sentence states purpose and output, second provides a usage tip. Perfectly front-loaded and efficient.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given no output schema, the description explains the return format (score and breakdown) sufficiently. It covers the key usage scenarios and parameter behavior, though it could briefly mention any prerequisites or limitations.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% and the schema already describes the parameters (product slug, optional version). The description repeats the hint about omitting version but adds no new semantic detail beyond that.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Clearly states what the tool does: 'Get the proprietary EOL Risk Score™ (0–100) for a product version' with a breakdown of four factors. It distinguishes from siblings like list_products and get_product_lifecycle by focusing on risk quantification.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Provides clear guidance on when to use ('Omit version to score the product's highest-risk release' and 'use this to quantify how dangerous it is to keep running something'), though it does not explicitly exclude scenarios or mention siblings as alternatives.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

list_productsAInspect

List or search the products endoflife.ai tracks (480+). Pass an optional "query" substring to find the canonical slug for a product before calling the other tools (e.g. "postgres" → "postgresql"). Returns matching product slugs.

ParametersJSON Schema
NameRequiredDescriptionDefault
queryNoOptional case-insensitive substring filter.

TDQS

A4.2/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden. It states the tool returns matching product slugs and supports case-insensitive substring filtering. However, it does not disclose potential limits like pagination, or the behavior when no query is provided (e.g., returns all). This is adequate but lacks full transparency.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is two sentences with no extraneous information. It is front-loaded with the primary action, then provides usage detail and what is returned. Every sentence adds value.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the simple nature of the tool (one optional parameter, no output schema), the description covers the main points: what it does, how to use the parameter, and the return value. It does not mention pagination or rate limits, but for a list/search tool of 480+ items, this is acceptable.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% and the schema already describes the query parameter. The description adds valued context by explaining the parameter's purpose (finding canonical slug for sibling tools) and providing a concrete example, going beyond the schema's description.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description explicitly states the tool lists or searches products from endoflife.ai (480+), and distinguishes from siblings by explaining it retrieves canonical slugs for use with other tools. The example 'postgres' → 'postgresql' clarifies the resource and action.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description clearly suggests using this tool 'before calling the other tools' to find the canonical slug, providing a specific use case. It does not explicitly list alternatives or when not to use, but the context is well understood.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

scan_stackAInspect

Audit a whole stack at once. Provide a list of products (optionally with versions) — e.g. parsed from a package.json, Dockerfile, or SBOM — and get an EOL Risk Score for each, so you can see what is unsupported and dangerous in one call. Free tier: up to 5 items; Pro: up to 50.

ParametersJSON Schema
NameRequiredDescriptionDefault
itemsYesList of stack components to score.

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description bears full burden. It discloses that the tool returns an EOL Risk Score per item, allows optional versions, and specifies tier limitations. No contradictory statements or hidden behaviors.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two concise sentences: first covers purpose and examples, second covers tier limits. No filler, every sentence adds value.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a tool with one parameter and no output schema, the description adequately explains input format, output (EOL Risk Score per item), and constraints. Could detail return structure more, but sufficient for the agent to understand usage.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% with descriptions for both 'product' and 'version'. The description adds real-world examples (package.json, Dockerfile, SBOM) and explains the effect of omitting version (gets highest-risk release), going beyond the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the verb 'Audit' and the resource 'a whole stack', and explains it returns an EOL Risk Score for each product. It distinguishes itself from siblings like list_products and get_product_lifecycle by emphasizing batch processing.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Provides clear context on when to use: when you want to audit a stack at once, with examples like package.json, Dockerfile, or SBOM. Also mentions tier limits (free up to 5, Pro up to 50). Does not explicitly exclude single-product cases but the sibling tools handle those.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 5 tool updatesv1.0.2
    • First observedcheck_eol
    • First observedget_product_lifecycle
    • First observedget_risk_score
    • First observedlist_products
    • First observedscan_stack

TDQS

A4.2/5.0

Scored across 5 tools

Disambiguation5/5

Each tool has a clear, distinct purpose: listing products, getting full lifecycle, checking EOL for a specific version, getting risk scores, and scanning a stack. No overlap in functionality.

Naming Consistency5/5

All tool names follow a consistent snake_case verb_noun pattern (e.g., list_products, check_eol, scan_stack), making them predictable and easy to understand.

Tool Count5/5

Five tools cover the core EOL domain without being too few or too many. Each tool earns its place, providing essential operations for managing end-of-life information.

Completeness5/5

The tool set covers the full workflow: discovering products, retrieving lifecycle details, checking EOL status, quantifying risk, and auditing a stack. No obvious missing operations.

Maintenance

ActivityMaintained
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    D
    maintenance
    Enables AI assistants to check software end-of-life dates and support status using the endoflife.date API, providing accurate information on software lifecycle, security status, and upgrade recommendations in real-time.
    5
    8
    MIT
  • A
    license
    A
    quality
    F
    maintenance
    Provides access to the endoflife.date API to query support and end-of-life information for thousands of software products. It enables users to retrieve detailed release schedules, lifecycle data, and product categories through natural language.
    16
    7
    7 npm
    MIT