endoflife-mcp
OfficialThis server gives AI agents end-of-life (EOL) intelligence for software products via MCP tools, resources, and prompts.
check_eol: Ask whether a specific product version is EOL, with EOL date, days remaining/past, and latest release.
get_risk_score: Get a 0–100 EOL Risk Score with factor breakdown for a product version (or its highest-risk release).
scan_stack: Score a whole stack of products/versions at once to spot unsupported dependencies.
list_products: Search the 500+ tracked products to resolve canonical slugs.
get_product_lifecycle: Retrieve full version history with release/EOL dates, support status, and risk scores.
get_kev_exposure: See CISA KEV entries attributed to a product, including due dates and required actions.
get_upcoming_eol: Find everything reaching EOL in the next N days, catalog-wide or for specific products.
get_edge_device_status: Check EOS edge device feed with BOD 26-02 statuses, filterable by platform/status/model.
get_upgrade_path: Get supported targets, recommended upgrades, and vendor-stated successors.
check_sbom: Validate CycloneDX/SPDX SBOMs by resolving components via package URLs or names, scoring them and listing unmatched items.
Resources: Read llms.txt, KEV by product, exploited & unpatchable lists, edge device feed, and change log.
Prompts: Use ready-made prompts like audit_stack, eol_calendar, and edge_device_review.
endoflife.ai — MCP Server
Exposes endoflife.ai's lifecycle intelligence to AI agents over the Model Context
Protocol (MCP, Streamable HTTP transport). A dependency-free Cloudflare Worker
that wraps the public api.endoflife.ai/v1 endpoints and the site's published
feeds — no data duplicated, every answer carries a source URL.
Current version: 1.3.0 (SERVER_INFO.version in src/index.js, server.json,
package.json — keep all three in step; CI fails if they disagree; the registry and
Glama read server.json).
Tools (all read-only)
Tool | What it does | Backed by |
| Is product X version Y end-of-life? |
|
| EOL Risk Score (0–100) + factor breakdown |
|
| Score a whole stack at once |
|
| Search the 500+ tracked products → resolve slugs |
|
| Full version history + dates for one product |
|
| Every CISA KEV entry attributed to a product (date added, due date, required action verbatim) + Exploited & Unpatchable entries |
|
| Everything reaching EOL in the next N days (catalog-wide or a product list) |
|
| EOS Edge Device feed with BOD 26-02 statuses, filter by platform / status / model |
|
| Supported targets, the site's recommendation, vendor-stated successor |
|
| CycloneDX / SPDX JSON → components resolved by package URL (exact, purl-map.json) or by name when no purl → scored; unmatched listed with a reason, never guessed |
|
Every tool advertises annotations (readOnlyHint, idempotentHint) and a
permissive outputSchema; results are returned both as JSON text and as
structuredContent. Lookup misses return "did you mean" slug suggestions
(prefix / substring / edit-distance ≤ 2 against the live product list).
Resources (resources/list / resources/read): llms.txt, the EOS Edge Device
feed, Exploited & Unpatchable, KEV by product, the edge change log.
Prompts (prompts/list / prompts/get): audit_stack, eol_calendar,
edge_device_review.
Endpoints: POST / (JSON-RPC), GET / (info page), GET /health (liveness JSON),
GET /.well-known/mcp/server-card.json (discovery card).
Related MCP server: EndOfLife MCP Server
Usage telemetry
With the USAGE Analytics Engine binding (see wrangler.toml, dataset
endoflife_mcp_usage) each method / tool call writes one data point: tool name,
client user agent, ok/error, keyed/anon, latency in ms. No request bodies. Query
via the Cloudflare Analytics Engine SQL API, e.g.
SELECT blob1 AS tool, count() AS calls, sum(_sample_interval) AS weighted
FROM endoflife_mcp_usage WHERE timestamp > NOW() - INTERVAL '7' DAY
GROUP BY tool ORDER BY calls DESCThe binding is optional; the code no-ops without it.
Deploy
The hosted server at mcp.endoflife.ai is deployed by the maintainers from the
endoflife.ai site repository's GitHub Actions workflow (pinned wrangler, Cloudflare
credentials held there as repository secrets); this public repository carries no
deploy workflow of its own. To run your own copy, wrangler deploy from this
repository works with your own Cloudflare account, and wrangler dev runs it locally;
the API service binding and the USAGE dataset in wrangler.toml are declared for
both the default and production environments.
Custom domain (mcp.endoflife.ai)
The route in wrangler.toml needs mcp.endoflife.ai to resolve through Cloudflare:
an AAAA record, name mcp, IPv6 100::, proxied. Already in place.
Test before deploying
CI (.github/workflows/ci.yml) runs on every push and pull request and once a day:
syntax checks, manifest validity, the version-agreement check, and a live smoke test
that calls the deployed server's tools. The same smoke test runs locally:
node --check src/index.js && node --check stdio.js
node .github/scripts/smoke.mjs # real tool calls against mcp.endoflife.ai, expects 0 failuresRun as a container (Red Hat UBI)
server.mjs runs the same handler that serves mcp.endoflife.ai inside a plain Node.js process, and Dockerfile packages it on registry.access.redhat.com/ubi9/nodejs-22-minimal for cluster deploys (the form the OpenShift AI MCP catalog expects). No build step, no dependencies; the container talks to https://api.endoflife.ai over HTTPS and runs as the unprivileged UBI user (uid 1001).
docker build -t endoflife-mcp .
docker run --rm -p 8080:8080 endoflife-mcp
curl -s localhost:8080/healthEndpoints are the Worker's own: POST / (Streamable HTTP JSON-RPC), GET /health (readiness), GET /.well-known/mcp/server-card.json. Set ENDOFLIFE_API_KEY to forward a Pro key. The image is built on Red Hat UBI 9 with Node 22; the maintainers run it on RHEL 9 and 10 as part of their Red Hat partner validation, which lives outside this repository.
Connect from an MCP client
Claude Desktop / Cursor / VS Code (mcpServers):
{
"mcpServers": {
"endoflife": { "command": "npx", "args": ["mcp-remote", "https://mcp.endoflife.ai"] }
}
}Clients with native remote-MCP support can use the URL directly:
{ "mcpServers": { "endoflife": { "url": "https://mcp.endoflife.ai" } } }Test without a client
# tools/list
curl -s https://mcp.endoflife.ai -X POST -H 'Content-Type: application/json' \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}' | jq
# KEV exposure for a product
curl -s https://mcp.endoflife.ai -X POST -H 'Content-Type: application/json' \
-d '{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"get_kev_exposure","arguments":{"product":"ivanti-connect-secure"}}}' | jq
# health + discovery card
curl -s https://mcp.endoflife.ai/health | jq
curl -s https://mcp.endoflife.ai/.well-known/mcp/server-card.json | jqAuth & tiers
Free tier works with no key. Forward an X-API-Key header (your existing Pro keys)
to unlock Pro limits — the Worker passes it straight through to api.endoflife.ai.
Notes
Same-zone trap:
api.endoflife.aiis a Worker on this zone; a plainfetch()to it goes to origin and fails. TheAPIservice binding is mandatory in prod.Static feeds are fetched from the site origin with
cf.cacheTtl = 600and memoised in the isolate for 10 minutes.Per-client rate limits: relies on the upstream API's limits. If MCP traffic grows, add a KV rate-limiter keyed on
CF-Connecting-IPbefore the upstream call.Discovery card is also served from the main site at
https://endoflife.ai/.well-known/mcp/server-card.json.
Available Tools
5 toolscheck_eolAInspect
Check whether a specific version of a software product is end-of-life (EOL). Returns lifecycle status, the EOL date, days remaining or days past EOL, and the latest release. Use this for "is X version Y still supported?" questions.
| Name | Required | Description | Default |
|---|---|---|---|
| product | Yes | Product slug or name, e.g. "postgresql", "nodejs", "ubuntu". | |
| version | Yes | Version/cycle, e.g. "14", "18", "20.04". |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations provided. Description lists return values (lifecycle status, EOL date, days remaining, latest release) and indicates it's a read-only query. Does not disclose authentication requirements or rate limits, but sufficient for a simple check tool.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences: first states purpose and outputs, second gives clear usage example. No wasted words, front-loaded with essential information.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
No output schema, but description enumerates return values. Covers all necessary information for an agent to understand input, action, and expected output.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Input schema has 100% coverage with descriptions for both parameters (product and version), including examples. Description does not add additional parameter meaning beyond what schema provides, meeting baseline expectation.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Description clearly states the tool checks EOL status for a specific product version, with verb 'check' and resource 'version of a software product'. It distinguishes from siblings like list_products and get_product_lifecycle by focusing on a single version's EOL status.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Includes explicit usage example ('Use this for "is X version Y still supported?" questions') and context of when to use. Does not explicitly mention when not to use or alternatives, but sibling tool list provides implicit differentiation.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_product_lifecycleAInspect
Get the full version history for one product: every tracked version/cycle with its release date, EOL date, support status, and EOL Risk Score™. Use for "give me the whole EOL schedule for X".
| Name | Required | Description | Default |
|---|---|---|---|
| product | Yes | Product slug or name, e.g. "postgresql". |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations provided. Description does not disclose behavioral traits such as data freshness, authentication requirements, potential cost, or whether it invokes external APIs. It only describes output, not side effects or constraints.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Description is two sentences with zero wasted words: first sentence defines function, second sentence provides usage context. Each sentence is informative and necessary.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given no output schema, the description lists key return fields (release date, EOL date, support status, risk score), which is fairly complete. It could clarify ordering or version count, but for a simple list tool it is adequate.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Input schema has 100% coverage for the one parameter, which is well-described. The description adds no additional semantics beyond what the schema provides, so baseline score of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Description clearly states it retrieves full version history for one product, listing specific fields (release date, EOL date, support status, risk score). It distinguishes from sibling tools like list_products (lists products) and check_eol (single check).
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The phrase 'Use for "give me the whole EOL schedule for X"' gives a clear use case, but it does not specify when not to use it or mention alternatives among siblings like check_eol or get_risk_score.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_risk_scoreAInspect
Get the proprietary EOL Risk Score™ (0–100) for a product version, with the four-factor breakdown (EOL recency, attack surface, CISA KEV exposure, extended support). Omit "version" to score the product's highest-risk (most recently end-of-lifed) release. Use this to quantify how dangerous it is to keep running something.
| Name | Required | Description | Default |
|---|---|---|---|
| product | Yes | Product slug or name, e.g. "openssl", "python". | |
| version | No | Optional version/cycle. Omit for the highest-risk release. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Describes the output as a score 0–100 with a four-factor breakdown, and explains behavior when version is omitted. Although no annotations exist, the description adequately conveys the tool's read-only nature and scope.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two sentences, no redundant words. First sentence states purpose and output, second provides a usage tip. Perfectly front-loaded and efficient.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given no output schema, the description explains the return format (score and breakdown) sufficiently. It covers the key usage scenarios and parameter behavior, though it could briefly mention any prerequisites or limitations.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% and the schema already describes the parameters (product slug, optional version). The description repeats the hint about omitting version but adds no new semantic detail beyond that.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Clearly states what the tool does: 'Get the proprietary EOL Risk Score™ (0–100) for a product version' with a breakdown of four factors. It distinguishes from siblings like list_products and get_product_lifecycle by focusing on risk quantification.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Provides clear guidance on when to use ('Omit version to score the product's highest-risk release' and 'use this to quantify how dangerous it is to keep running something'), though it does not explicitly exclude scenarios or mention siblings as alternatives.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_productsAInspect
List or search the products endoflife.ai tracks (480+). Pass an optional "query" substring to find the canonical slug for a product before calling the other tools (e.g. "postgres" → "postgresql"). Returns matching product slugs.
| Name | Required | Description | Default |
|---|---|---|---|
| query | No | Optional case-insensitive substring filter. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden. It states the tool returns matching product slugs and supports case-insensitive substring filtering. However, it does not disclose potential limits like pagination, or the behavior when no query is provided (e.g., returns all). This is adequate but lacks full transparency.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences with no extraneous information. It is front-loaded with the primary action, then provides usage detail and what is returned. Every sentence adds value.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the simple nature of the tool (one optional parameter, no output schema), the description covers the main points: what it does, how to use the parameter, and the return value. It does not mention pagination or rate limits, but for a list/search tool of 480+ items, this is acceptable.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% and the schema already describes the query parameter. The description adds valued context by explaining the parameter's purpose (finding canonical slug for sibling tools) and providing a concrete example, going beyond the schema's description.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description explicitly states the tool lists or searches products from endoflife.ai (480+), and distinguishes from siblings by explaining it retrieves canonical slugs for use with other tools. The example 'postgres' → 'postgresql' clarifies the resource and action.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description clearly suggests using this tool 'before calling the other tools' to find the canonical slug, providing a specific use case. It does not explicitly list alternatives or when not to use, but the context is well understood.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
scan_stackAInspect
Audit a whole stack at once. Provide a list of products (optionally with versions) — e.g. parsed from a package.json, Dockerfile, or SBOM — and get an EOL Risk Score for each, so you can see what is unsupported and dangerous in one call. Free tier: up to 5 items; Pro: up to 50.
| Name | Required | Description | Default |
|---|---|---|---|
| items | Yes | List of stack components to score. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description bears full burden. It discloses that the tool returns an EOL Risk Score per item, allows optional versions, and specifies tier limitations. No contradictory statements or hidden behaviors.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two concise sentences: first covers purpose and examples, second covers tier limits. No filler, every sentence adds value.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a tool with one parameter and no output schema, the description adequately explains input format, output (EOL Risk Score per item), and constraints. Could detail return structure more, but sufficient for the agent to understand usage.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% with descriptions for both 'product' and 'version'. The description adds real-world examples (package.json, Dockerfile, SBOM) and explains the effect of omitting version (gets highest-risk release), going beyond the schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the verb 'Audit' and the resource 'a whole stack', and explains it returns an EOL Risk Score for each product. It distinguishes itself from siblings like list_products and get_product_lifecycle by emphasizing batch processing.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Provides clear context on when to use: when you want to audit a stack at once, with examples like package.json, Dockerfile, or SBOM. Also mentions tier limits (free up to 5, Pro up to 50). Does not explicitly exclude single-product cases but the sibling tools handle those.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
5 tool updates
v1.0.2- First observed
check_eol - First observed
get_product_lifecycle - First observed
get_risk_score - First observed
list_products - First observed
scan_stack
TDQS
Scored across 5 tools
Each tool has a clear, distinct purpose: listing products, getting full lifecycle, checking EOL for a specific version, getting risk scores, and scanning a stack. No overlap in functionality.
All tool names follow a consistent snake_case verb_noun pattern (e.g., list_products, check_eol, scan_stack), making them predictable and easy to understand.
Five tools cover the core EOL domain without being too few or too many. Each tool earns its place, providing essential operations for managing end-of-life information.
The tool set covers the full workflow: discovering products, retrieving lifecycle details, checking EOL status, quantifying risk, and auditing a stack. No obvious missing operations.
Maintenance
Related MCP Connectors
Latest versions, LTS windows, and EOL dates for 300+ products. Fresh ground truth for stale models.
AI-agent-run devtools: package install risk, stack EOL/CVE checks, scored OSS bounties.
Open-source licence risk checks for AI coding agents and dependency trees.
Package intelligence for AI agents across npm, PyPI, crates.io and deps.dev. No API keys.
Related MCP Servers
- AlicenseAqualityDmaintenanceEnables AI assistants to check software end-of-life dates and support status using the endoflife.date API, providing accurate information on software lifecycle, security status, and upgrade recommendations in real-time.58MIT
- AlicenseAqualityFmaintenanceProvides access to the endoflife.date API to query support and end-of-life information for thousands of software products. It enables users to retrieve detailed release schedules, lifecycle data, and product categories through natural language.1677 npmMIT
- AlicenseNot gradedqualityCmaintenanceBlocker-aware decision layer for AI coding agents. Adds source-linked, time-sensitive blockers to AI technical choices — breaking changes, EOLs, lock-in, pricing shifts, and migration risk.4MIT
- AlicenseAqualityAmaintenanceDependency intelligence for AI agents. CVE scanning, health checks, upgrade planning.9112 npm2Apache 2.0