{"server":{"$schema":"https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json","name":"com.jithox/eu-sanctions-preflight","description":"Read-only EU counterparty sanctions preflight over MCP: screen names & identifiers, evidence","title":"Jithox EU Counterparty Sanctions Preflight","version":"0.2.1","websiteUrl":"https://sanctions.mcp.jithox.com/docs","remotes":[{"type":"streamable-http","url":"https://sanctions.mcp.jithox.com/mcp","headers":[{"description":"OAuth 2.1 bearer. Discover the authorization server via /.well-known/oauth-protected-resource; PKCE S256 is mandatory; tokens are audience-bound to https://sanctions.mcp.jithox.com/mcp with least-privilege per-tool scopes. The workspace access key may also be sent directly per call (Authorization: Bearer <access key> or X-Jithox-Api-Key) when an OAuth browser callback is not possible. A token issued for the Jithox E-Invoice or Import Preflight server is rejected here (separate resource/audience).","isRequired":true,"isSecret":true,"name":"Authorization"}]}],"_meta":{"io.modelcontextprotocol.registry/publisher-provided":{"accessModel":"OAuth 2.1 + PKCE S256; discover at https://sanctions.mcp.jithox.com/.well-known/oauth-protected-resource. Or send the workspace access key per call as Authorization: Bearer <key> or X-Jithox-Api-Key — never both. A key in a config file is a password; rotate at jithox.com.","commercialStatus":"SELLABLE_SELF_SERVICE_EUR — public self-service; prepaid EUR credit; signed receipts on the product's own key. 0 paying Sanctions Preflight developers at publication; no revenue claim.","doesNotSend":true,"lastVerified":"2026-09-03","licenseCaveat":"EU FSF reuse per Commission Decision 2011/833/EU (default CC BY 4.0): commercial and non-commercial reuse is permitted provided the source is acknowledged, the meaning is not distorted, and the Commission accepts no liability — no separate EU data licence is required. Only the EU Official Journal is authentic and only official EU legislation has legal effect. EUR self-service pricing is a Jithox owner choice, not a licence restriction.","links":{"llmsTxt":"https://sanctions.mcp.jithox.com/llms.txt","oauthProtectedResource":"https://sanctions.mcp.jithox.com/.well-known/oauth-protected-resource","product":"https://sanctions.mcp.jithox.com/docs"},"noComplianceGuarantee":true,"notIndependentlyPenetrationTested":true,"notLegalDetermination":true,"officialSource":"EU Consolidated Financial Sanctions List (FSF), xmlFullSanctionsList_1_1, published by the European Union / European Commission (DG FISMA). The operator supplies the export; the runtime never downloads. Jithox normalizes names/identifiers for matching (a change indicated per attribution). Coverage: EU consolidated list ONLY, not global.","pricing":"EUR 0.50 per accepted chargeable call. Failed, refused, rate-limited and source-unavailable calls cost EUR 0.00. Free trial first; prepaid credit from EUR 10.","protocolVersions":["2026-07-28","2025-11-25","2025-06-18","2025-03-26"],"publicationStatus":"PUBLIC SELF-SERVICE — generally available through the official MCP Registry.","readOnly":true,"remoteDeployment":"Live at https://sanctions.mcp.jithox.com/mcp (owner-run). Five read-only tools, OAuth 2.1 + PKCE, least-privilege per-tool scopes, own resource/audience and receipt key. Not independently penetration-tested.","sanctionsBaselineRequired":"Official EU FSF snapshot is live with auto-refresh and fail-closed freshness. If freshness fails, tools go truthfully unavailable — never a false clear. A no-match is never a guarantee of non-designation, and a stale list is never served as current.","scopeLimit":"Does not evaluate the 50%-ownership/control rule, beneficial ownership, PEP status or adverse media; does not block, approve or reject; not legal/compliance advice.","scopes":{"get_sanctions_listing":"listing:read","list_sanctions_regimes":"regime:read","prepare_screening_receipt":"receipt:screening","screen_sanctioned_identifier":"screen:identifier","screen_sanctioned_name":"screen:name"},"toolDescriptions":{"get_sanctions_listing":"Full official listing detail for a candidate logicalId from a prior screen, with provenance.","list_sanctions_regimes":"Enumerate the EU sanctions programmes/regimes in the snapshot (legal basis, since, counts).","prepare_screening_receipt":"Idempotent Ed25519 receipt over HASHED inputs/sources/decision states — attests the checks, not a clearance.","screen_sanctioned_identifier":"Deterministic EXACT identifier match against listed designations; no fuzzy matching.","screen_sanctioned_name":"Screen a name against a dated official EU FSF snapshot; ranked CANDIDATE matches with deterministic scores; never a false clear."},"tools":["screen_sanctioned_name","screen_sanctioned_identifier","get_sanctions_listing","list_sanctions_regimes","prepare_screening_receipt"],"toolsLiveProven":"All five tools are live-proven against the ACTIVE official snapshot.","transport":"streamable-http (remote); no local package."}}},"_meta":{"io.modelcontextprotocol.registry/official":{"status":"active","statusChangedAt":"2026-09-04T14:42:24.469209Z","publishedAt":"2026-09-04T14:42:24.469209Z","updatedAt":"2026-09-04T14:42:24.469209Z","isLatest":true}}}
