Cited product-compliance ground truth for AI agents. Never generates; always cites.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
US product recall lookup for AI agents β CPSC consumer products and FDA food, drug and device enforcement, with every result pinned to an official source.
The point is not that it searches; it is that it refuses to answer without a citation. Ask it something it has no record of and it says so, rather than inventing a plausible answer.
Live API: https://rattlewatch.rattled.ca MCP endpoint: https://rattlewatch.rattled.ca/mcp Interactive docs: https://rattlewatch.rattled.ca/docs
Machine-readable discovery, for agents rather than browsers:
| Document | URL |
|---|---|
llms.txt | /llms.txt |
| MCP server card | /.well-known/mcp/server.json |
One container serves both surfaces β the REST API and MCP over streamable
HTTP at /mcp. That matters for registry discovery: directories introspect the
image's default command, so it has to be a working MCP server.
Rattlewatch answers the questions an agent cannot safely answer itself:
Every answer carries an official source URL and a last-verified date. Rattlewatch never generates an answer β it returns records that exist in its store, or it says "no verified record". Absence is an honest negative, not a guess.
An answer without a citation does not ship.
verified_at tells you exactly when.verify() returns only matching records. If nothing matches,
it returns found: false with an explicit reason. It will not invent one.| Tool | What it returns |
|---|---|
search_recalls | Cited recall records matching a product name, brand, model, or UPC |
get_requirement | Cited compliance requirements for a subject + market |
list_changes | The change feed: new recalls and rule changes since a timestamp |
verify | Cited records matching a claim/query, or an explicit no verified record |
The engine is domain-agnostic: new markets (UK, CA, AU, JP, and beyond) and new rule sets are added as more cited facts and feeds are compiled, without code change.
| Endpoint | Tier |
|---|---|
GET /v1/recalls/search?q=... | Free (rate-limited) |
GET /v1/requirements?subject=...&market=... | Free |
GET /v1/changes?since=... | Free |
POST /v1/verify | Free |
GET /v1/premium/export | Metered β returns HTTP 402 with an x402 payment requirement |
Interactive docs: /docs.
Free discovery and lookups, metered premium calls. The premium endpoint implements
the x402 payment flow: the server returns 402 Payment Required with a
structured payment requirement, and a paying agent retries with proof of payment.
This is the monetization thesis in one endpoint β agents discover, agents pay.
The payment rail (x402/USDC or Stripe metered billing) is wired at deploy time.
AI generates infinite plausible text for free, so content is worth nothing. But AI hallucinates β especially on current rules, specific numbers, and what changed last week. Rattlewatch is the opposite of a generative model: a small, boring, cited layer of truth that agents and the software they power can depend on when being wrong is expensive.
See SECURITY.md for the full threat model, the implemented
controls, and β listed explicitly β what is not protected. Every claim there
is backed by a test in tests/test_api.py.
Highlights: query input bounded at two independent layers; per-client rate limiting; API keys compared in constant time that fail closed; CORS denied by default; hardened response headers; no stack-trace leakage; container runs as an unprivileged user (UID 10001).
See TESTING.md for the coverage map and an explicit list of what is not tested. A green run is not the same as "verified secure."
MIT β see LICENSE.
The code is open source; the hosted service is the product. Nothing about the moat lives in the source: the defensible asset is the curated, daily-refreshed, cited corpus and the freshness pipeline that maintains it. Open-sourcing the code also means the citation machinery is auditable β which matters for a product whose entire claim is that its answers can be trusted.
You can self-host it:
Or use the hosted endpoint: https://rattlewatch.rattled.ca
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/verity-3)<a href="https://allmcps.com/mcp/verity-3"><img src="https://allmcps.com/api/badge/verity-3?style=directory" alt="Verity on AllMCPs" /></a>