Model Context Protocol
Connect EOL intelligence
to your AI agent
The endoflife.ai MCP server lets Claude, Cursor, and any MCP-compatible agent answer
end-of-life questions by calling our live data directly — not by scraping a web page and hoping.
Ask "is my PostgreSQL 14 still supported?" or "score the dependencies in this package.json," and the agent
pulls exact EOL dates and the proprietary EOL Risk Score™ in real time. Free to connect.
Add it to Claude or Cursor
Paste this into your client's MCP config (in Claude Desktop: Settings → Developer → Edit Config), then restart the app.
claude_desktop_config.json
{
"mcpServers": {
"endoflife": {
"command": "npx",
"args": ["mcp-remote", "https://mcp.endoflife.ai"]
}
}
}
Clients with native remote-MCP support can use the endpoint URL directly: https://mcp.endoflife.ai.
What you can ask
- "Is Node.js 18 end of life, and what should I move to?"
- "What's the EOL Risk Score for OpenSSL right now?"
- "Here's my package.json — which dependencies are unsupported or dangerous?"
- "Give me the full PostgreSQL version support schedule."
- "Which of these are in the CISA KEV catalog: redis, mongodb, jenkins?"
The tools it exposes
Every date a tool returns carries its provenance: eol_date_source (the vendor's own page, a documented correction, a human check, our catalog, or the upstream dataset), the source URL, the day it was last verified, and a confidence grade. The fields are the same ones the API documents, so an agent can decide how much to trust a date before acting on it.
check_eol
Is a specific product version end-of-life? Returns status, EOL date, and days remaining or past.
get_risk_score
The EOL Risk Score™ (0–100) for a version, with the four-factor breakdown.
scan_stack
Score a whole stack at once — paste a dependency list and get a risk-ranked audit.
list_products
Search the 500+ tracked products to resolve a name to its canonical slug.
get_product_lifecycle
Full version history, release and EOL dates for one product.
get_kev_exposure
Every CISA KEV entry attributed to a product — date added, due date, required action verbatim — plus its Exploited & Unpatchable entries.
get_upcoming_eol
Everything reaching end-of-life in the next N days, catalog-wide or for a list of products, sorted by date.
get_edge_device_status
The EOS Edge Device feed with BOD 26-02 statuses — filter by vendor, status or model; KEV summary and vendor-stated successor per platform.
get_upgrade_path
Where to move: supported releases with the longest runway, our recommended target, and the vendor-stated successor where published.
check_sbom
Audit a CycloneDX or SPDX JSON SBOM — components resolved by package URL first (exact, via purl-map.json), by name only when no purl is present, then scored; unmatched components listed with a reason, never guessed.
Free to evaluate; production use on a paid key
The read tools work with no key for individual use and evaluation. Agents that run inside a company's tooling, check inventories or call on a schedule belong on a paid key, from $89 a month (Starter, 25 components per SBOM or batch call) or $199 a month (Pro, unlimited requests, 50 per call). Your client sends it as an
X-API-Key header on the hosted endpoint or in the npm package's config. Get an API key →
Open source, and independently checked
The server is MIT-licensed — source at github.com/endoflife-ai/endoflife-mcp. It is published in the official MCP registry and listed on Glama, where the original five tools score an A on tool-definition quality. Version 1.1.0 adds five more tools, resources (the site feeds), prompts, and a
/health endpoint.
Prefer raw HTTP?
The same data powers our REST API and one-shot tools — no agent required.
Developer API Stack Scanner Risk Score methodology