Skip to content
LayerCall logo

LayerCall MCP server

Which servers in the official MCP registry are LayerCall's own, whether they answer, and what they offer. A program checked each of these, nobody copied them from a product page.

read 2026-10-09

← Back to LayerCall

Whose server it is
  • Registry namecom.layercall/trust-apiverified in the MCP registry

The registry name sits under layercall.com. The registry only lets a publisher use that namespace after proving control of the domain through DNS or HTTP.

When we asked itchecked 2026-10-09
  • Stateanswerschecked 2026-10-09
  • Tools7
  • Server calls itselflayercall
  • Server version1.0.0
  • Protocol version2025-06-18

On 2026-10-09 the server answered initialize and tools/list without a sign-in. First answer in 152 ms.

Tools it offers7 tools · read 2026-10-09
  • score_ip

    Risk-score an IPv4 or IPv6 address. Detects commercial VPNs (naming the provider where its own published list confirms it), proxies, Tor exit nodes and datacenter hosting, and returns geolocation, ASN and a 0-100 risk score with an…

  • verify_email

    Check an email for syntax, MX records, disposable/throwaway providers, role accounts (info@, admin@), homograph lookalikes and domain age. Returns a 0-100 risk score and an allow/review/block verdict.

  • lookup_phone

    Validate a phone number worldwide against its national numbering plan. Returns E.164, country, line type (mobile/fixed/VoIP/toll-free/premium) and a risk score. Works globally, not US-only.

  • score_domain

    Profile a domain: registration date from RDAP, registrar, MX/SPF/DMARC configuration, disposable-mail and risky-TLD detection. newly_registered is null when the age genuinely could not be determined — treat that as unknown, not as…

  • score_device

    Judge a browser fingerprint from /fp.js: headless detection, automation frameworks (Selenium, Puppeteer, Playwright), timezone-versus-IP mismatch and repeat-device history. Note the ceiling honestly — the declared signals it relies on are…

  • verify_agent

    Cryptographically verify a Web Bot Auth signature (RFC 9421) — proof of WHICH agent is calling, not a guess from the user-agent. Returns verified true/false plus the agent's identity and declared purpose. This is the only check here that…

  • score_user

    Score an entire signup in one call — any combination of IP, email, phone and domain — returning a single weighted risk score, a verdict, and the top contributing signals. A hard block on any component is never averaged away. This is the…

How to connect

Add the server to your MCP client config. Claude Desktop, Cursor and most other clients read this shape:

{
  "mcpServers": {
    "trust-api": {
      "type": "http",
      "url": "https://www.layercall.com/api/mcp"
    }
  }
}

OpenAPI spec

15 paths, read 2026-10-09. Open the spec ↗

Each line is something a program found when it went looking: the registry entry, the server's own answer, a spec that parses. A missing line means we did not find it, not that it does not exist.