EOL dates and risk scores for 480+ software products. Check versions, score risk, audit stacks.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag β we're steadily working through the catalog.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Exposes endoflife.ai's lifecycle intelligence to AI agents over the Model Context
Protocol (MCP, Streamable HTTP transport). A dependency-free Cloudflare Worker
that wraps the public api.endoflife.ai/v1 endpoints and the site's published
feeds β no data duplicated, every answer carries a source URL.
Current version: 1.1.0 (SERVER_INFO.version in src/index.js, server.json,
package.json β keep all three in step; the registry and Glama read server.json).
| Tool | What it does | Backed by |
|---|---|---|
check_eol | Is product X version Y end-of-life? | GET /v1/status/:slug/:version |
get_risk_score | EOL Risk Score (0β100) + factor breakdown | GET /v1/score/:slug[/:version] |
scan_stack | Score a whole stack at once | POST /v1/batch |
list_products | Search the 500+ tracked products β resolve slugs | GET /v1/products |
get_product_lifecycle | Full version history + dates for one product | GET /v1/product/:slug |
get_kev_exposure | Every CISA KEV entry attributed to a product (date added, due date, required action verbatim) + Exploited & Unpatchable entries | endoflife.ai/kev-products.json, exploited-and-unpatchable.json |
get_upcoming_eol | Everything reaching EOL in the next N days (catalog-wide or a product list) | endoflife.ai/scanner-db.json |
get_edge_device_status | EOS Edge Device feed with BOD 26-02 statuses, filter by platform / status / model | endoflife.ai/eos-edge-devices.json |
get_upgrade_path | Supported targets, the site's recommendation, vendor-stated successor | GET /v1/product/:slug, checker-db.json, edge feed |
check_sbom | CycloneDX / SPDX JSON β components resolved by package URL (exact, purl-map.json) or by name when no purl β scored; unmatched listed with a reason, never guessed | purl-map.json + POST /v1/batch |
Every tool advertises annotations (readOnlyHint, idempotentHint) and a
permissive outputSchema; results are returned both as JSON text and as
structuredContent. Lookup misses return "did you mean" slug suggestions
(prefix / substring / edit-distance β€ 2 against the live product list).
Resources (resources/list / resources/read): llms.txt, the EOS Edge Device
feed, Exploited & Unpatchable, KEV by product, the edge change log.
Prompts (prompts/list / prompts/get): audit_stack, eol_calendar,
edge_device_review.
Endpoints: POST / (JSON-RPC), GET / (info page), GET /health (liveness JSON),
GET /.well-known/mcp/server-card.json (discovery card).
With the USAGE Analytics Engine binding (see wrangler.toml, dataset
endoflife_mcp_usage) each method / tool call writes one data point: tool name,
client user agent, ok/error, keyed/anon, latency in ms. No request bodies. Query
via the Cloudflare Analytics Engine SQL API, e.g.
The binding is optional; the code no-ops without it.
Production deploys run from GitHub Actions, never a local wrangler:
(.github/workflows/mcp-server-deploy.yml, pinned wrangler; needs the
CLOUDFLARE_API_TOKEN / CLOUDFLARE_ACCOUNT_ID repository secrets.) Local
wrangler dev still works for development; the API service binding and the
USAGE dataset are declared for both the default and production environments.
The route in wrangler.toml needs mcp.endoflife.ai to resolve through Cloudflare:
an AAAA record, name mcp, IPv6 100::, proxied. Already in place.
A Node harness exercises every method against the live API and feeds (the module
runs unchanged in Node with env.API = { fetch }):
server.mjs runs the same handler that serves mcp.endoflife.ai inside a plain Node.js process, and Dockerfile packages it on registry.access.redhat.com/ubi9/nodejs-22-minimal for cluster deploys (the form the OpenShift AI MCP catalog expects). No build step, no dependencies; the container talks to https://api.endoflife.ai over HTTPS and runs as the unprivileged UBI user (uid 1001).
Endpoints are the Worker's own: POST / (Streamable HTTP JSON-RPC), GET /health (readiness), GET /.well-known/mcp/server-card.json. Set ENDOFLIFE_API_KEY to forward a Pro key. Validated on RHEL 9 and 10 with Node 20 and 22 by .github/workflows/rhel-validation.yml (evidence in docs/company/redhat-validation-evidence.md).
Claude Desktop / Cursor / VS Code (mcpServers):
Clients with native remote-MCP support can use the URL directly:
Free tier works with no key. Forward an X-API-Key header (your existing Pro keys)
to unlock Pro limits β the Worker passes it straight through to api.endoflife.ai.
api.endoflife.ai is a Worker on this zone; a plain fetch()
to it goes to origin and fails. The API service binding is mandatory in prod.cf.cacheTtl = 600 and
memoised in the isolate for 10 minutes.CF-Connecting-IP before the upstream call.https://endoflife.ai/.well-known/mcp/server-card.json.No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/endoflife-ai-software-lifecycle-intelligence)<a href="https://allmcps.com/mcp/endoflife-ai-software-lifecycle-intelligence"><img src="https://allmcps.com/api/badge/endoflife-ai-software-lifecycle-intelligence?style=directory" alt="Endoflife.ai β Software Lifecycle Intelligence on AllMCPs" /></a>