XBOSS MCP server
Korean national tax and social insurance filings, invoices and payroll data as MCP tools.
Little public usage data yet
Reviews
Write oneNobody has reviewed XBOSS yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
XBOSS tools (99, 7 write)
write = sends, deletes, buys or postscomwel__auth__npki_session__loginFreeCall this FIRST before any other tool for this provider. Login to COMWEL via NPKI AnySign certificate.
comwel__auth__session__statusFreeCheck COMWEL session status.
comwel__info__individual_billed_premium__detailFreeREQUIRES prior comwel__auth__npki_session__login call with same account_link_id. Fetch COMWEL individual billed-premium detail for a selected worker.
comwel__info__individual_billed_premium__worker_selectFreeREQUIRES prior comwel__auth__npki_session__login call with same account_link_id. Search and select a worker for COMWEL individual billed-premium inquiry.
comwel__info__premium_billing_notice__detailFreeREQUIRES prior comwel__auth__npki_session__login call with same account_link_id. Fetch COMWEL premium billing notice detail.
comwel__info__premium_billing_notice__searchFreeREQUIRES prior comwel__auth__npki_session__login call with same account_link_id. Search COMWEL premium billing notices.
fourinsure__session__loginFreeCall this FIRST before any other tool for this provider. Login to FourInsure (4대보험) EDI. Returns API_KEY.
hometax__cash_receipt__daily_issue__searchFreeREQUIRES prior hometax__session__login call with same account_link_id. Search cash receipt issuance records for a single day (당일 발급 조회). trs_dt is optional; omitting it means today. The adapter documents this endpoint as same-day only, so other dates are not a supported lookup. Counts: totalCount (and the same value in pageInfoVO.totalCount) is the record count for this query and is never fewer than the rows in this response; collectionMeta says whether this response already holds all of them (complete) and how many came back (collectedCount). When complete is false, ask for the next page.
hometax__cash_receipt__purchase__search_historywrite actionFreeREQUIRES prior hometax__session__login call with same account_link_id. Search cash receipt purchase history. from_date/to_date are required (YYYYMMDD or YYYY-MM-DD). 국세청 rejects ranges longer than 3 months with '조회기간은 최대 3개월 까지 가능합니다.' — split longer periods into 3-month calls. Counts: totalCount (and the same value in pageInfoVO.totalCount) is the record count for this query and is never fewer than the rows in this response; collectionMeta says whether this response already holds all of them (complete) and how many came back (collectedCount). When complete is false, ask for the next page.
hometax__cash_receipt__sales__search_historyFreeREQUIRES prior hometax__session__login call with same account_link_id. Search cash receipt sales history. from_date/to_date are required (YYYYMMDD or YYYY-MM-DD). Counts: totalCount (and the same value in pageInfoVO.totalCount) is the record count for this query and is never fewer than the rows in this response; collectionMeta says whether this response already holds all of them (complete) and how many came back (collectedCount). When complete is false, ask for the next page.
hometax__cash_receipt__sales__search_summaryFreeREQUIRES prior hometax__session__login call with same account_link_id. Search cash receipt sales annual summary. Use cmtt_yr for the target year. Optionally specify qrt (quarter 1-4) for quarterly breakdown.
hometax__certificate__apply__business_registrationFreeREQUIRES prior hometax__session__login call with same account_link_id. Apply for Business Registration Certificate. IRREVERSIBLE: this files an application with the NTS and a receipt record (cvaId + rcatNo) is created; there is no cancel action. Call without confirm first to get a preview, show it to the user, then retry with confirm=true. Never set confirm=true on your own.
hometax__certificate__apply__business_registration_reissueFreeREQUIRES prior hometax__session__login call with same account_link_id. Apply for Business Registration Reissuance. IRREVERSIBLE: this files an application with the NTS and a receipt record (cvaId + rcatNo) is created; there is no cancel action. Call without confirm first to get a preview, show it to the user, then retry with confirm=true. Never set confirm=true on your own.
hometax__certificate__apply__financial_statementFreeREQUIRES prior hometax__session__login call with same account_link_id. Apply for Standard Financial Statement Certificate. IRREVERSIBLE: this files an application with the NTS and a receipt record (cvaId + rcatNo) is created; there is no cancel action. Call without confirm first to get a preview, show it to the user, then retry with confirm=true. Never set confirm=true on your own.
hometax__certificate__apply__national_tax_paymentFreeREQUIRES prior hometax__session__login call with same account_link_id. Apply for National Tax Payment Certificate from Hometax. IRREVERSIBLE: this files an application with the NTS and a receipt record (cvaId + rcatNo) is created; there is no cancel action. Call without confirm first to get a preview, show it to the user, then retry with confirm=true. Never set confirm=true on your own.
hometax__certificate__apply__tax_payment_recordFreeREQUIRES prior hometax__session__login call with same account_link_id. Apply for Tax Payment Record Certificate. IRREVERSIBLE: this files an application with the NTS and a receipt record (cvaId + rcatNo) is created; there is no cancel action. Call without confirm first to get a preview, show it to the user, then retry with confirm=true. Never set confirm=true on your own.
hometax__certificate__apply__vat_standardFreeREQUIRES prior hometax__session__login call with same account_link_id. Apply for VAT Standard Certificate. IRREVERSIBLE: this files an application with the NTS and a receipt record (cvaId + rcatNo) is created; there is no cancel action. Call without confirm first to get a preview, show it to the user, then retry with confirm=true. Never set confirm=true on your own.
hometax__certificate__apply_autoFreeREQUIRES prior hometax__session__login call with same account_link_id. Apply for a certificate using the logged-in taxpayer's own details. IRREVERSIBLE: this files an application with the NTS and a receipt record (cvaId + rcatNo) is created; there is no cancel action. Call without confirm first to get a preview, show it to the user, then retry with confirm=true. Never set confirm=true on your own.
hometax__certificate__apply_with_templateFreeREQUIRES prior hometax__session__login call with same account_link_id. Apply for a certificate with an explicitly chosen template. IRREVERSIBLE: this files an application with the NTS and a receipt record (cvaId + rcatNo) is created; there is no cancel action. Call without confirm first to get a preview, show it to the user, then retry with confirm=true. Never set confirm=true on your own.
hometax__certificate__downloadFreeREQUIRES prior hometax__session__login call with same account_link_id. Download an issued certificate as PDF (returned base64-encoded). Get cva_id/rcat_no from the certificate application result (hometax__certificate__apply_auto or apply_with_template).
hometax__certificate__listFreeREQUIRES prior hometax__session__login call with same account_link_id. List certificate applications already filed at Hometax (민원증명 발급 목록) with their receipt ids (cvaId, rcatNo). Read-only. Without strt_dt/end_dt only the last 3 days are returned, so an empty result does not mean the taxpayer has no certificates — widen the period to look further back. Send both dates or neither. One call covers at most one calendar month (strt_dt no earlier than end_dt minus one month); a longer period is refused, because the institution returns an empty list for it instead of an error — split it into monthly calls.
hometax__certificate__list_templatesFreeREQUIRES prior hometax__session__login call with same account_link_id. List the certificate templates that can be applied for (9). The slugs returned here are exactly the values accepted by cert_template; nothing else is.
hometax__etax__business_info__getFreeREQUIRES prior hometax__session__login call with same account_link_id. Get business info for e-tax invoice purposes.
hometax__etax__client_info__getFreeREQUIRES prior hometax__session__login call with same account_link_id. Get client/counterparty info for e-tax invoicing.
hometax__etax__invoice__issueFreeREQUIRES prior hometax__session__login call with same account_link_id. Issue an e-tax invoice to 국세청. IRREVERSIBLE: once issued the buyer is notified and it enters VAT filing; it can only be corrected by issuing a 수정세금계산서. Call without confirm first — you get a preview of exactly what will be issued; show it to the user, get their approval, then retry with confirm=true. Never set confirm=true on your own.
hometax__etax__invoice__modifyFreeREQUIRES prior hometax__session__login call with same account_link_id. Issue a correcting e-tax invoice (수정세금계산서) against an existing one. IRREVERSIBLE, same as issuing: call without confirm first to get a preview, show it to the user, then retry with confirm=true. You MUST ask the user which correction reason applies and pass etxiv_mdf_rsn_cd; never guess it.
hometax__etax__invoice__search_detailFreeREQUIRES prior hometax__session__login call with same account_link_id. Get detailed information for a specific e-tax invoice by its 승인번호 (etan). Get etan from hometax__etax__invoice__search_list results.
hometax__etax__invoice__search_listFreeREQUIRES prior hometax__session__login call with same account_link_id. Search e-tax invoices by date range. Use from_date/to_date (YYYYMMDD or YYYY-MM-DD). prh_sls_cl_cd: '01'=issued(매출), '02'=received(매입). 국세청 rejects long ranges with '6개월이상은 조회할 수 없습니다.' — keep the window under 6 months and split longer periods into several calls.
hometax__etax__invoice__search_statisticsFreeREQUIRES prior hometax__session__login call with same account_link_id. Search e-tax invoice monthly statistics. Use wrt_ym_strt/wrt_ym_end in YYYYMM format (e.g. 202507/202509 for July-September 2025).
hometax__etax__invoice__search_summaryFreeREQUIRES prior hometax__session__login call with same account_link_id. Search e-tax invoice summary (totals). Choose ONE date mode: (1) daily: set date_type='01' and start_date+end_date YYYYMMDD. (2) monthly: set date_type='02' and year+month. (3) quarterly: set date_type='03' and year+quarter. search_type '01'=issued(매출), '02'=received(매입).
hometax__session__loginFreeCall this FIRST before any other tool for this provider. Login to Hometax via NPKI certificate. Returns a session credential.
hometax__session__user_infoFreeRetrieve logged-in user info from Hometax.
hometax__tax__business_registration__search_infoFreeREQUIRES prior hometax__session__login call with same account_link_id. Search detailed business registration information.
hometax__tax__business_registration__search_statusFreeREQUIRES prior hometax__session__login call with same account_link_id. Search business registration status by business registration number (사업자등록번호).
hometax__tax__credit_card__search_sales_dataFreeREQUIRES prior hometax__session__login call with same account_link_id. Search credit card sales data. Use bsno (business number), stl_yr (year YYYY), qrt_from/qrt_to (quarter 1-4).
hometax__tax__electronic_notice__check_statusFreeREQUIRES prior hometax__session__login call with same account_link_id. Check electronic notice reception status.
hometax__tax__my_tax_agent__searchFreeREQUIRES prior hometax__session__login call with same account_link_id. Search assigned tax agent information.
hometax__tax__notice__search_historyFreeREQUIRES prior hometax__session__login call with same account_link_id. Search tax notice history. Use strt_dt/end_dt (YYYYMMDD). The NTS accepts start dates within the last 10 years.
hometax__tax__overdue__search_historyFreeREQUIRES prior hometax__session__login call with same account_link_id. Search overdue tax history (체납 내역). Narrow the period with strt_dt/end_dt; without them the NTS default period applies. Only 3 rows come back per page unless you raise page_size.
hometax__tax__payment_due__search_or_paywrite actionFreeREQUIRES prior hometax__session__login call with same account_link_id. Search tax amounts due by payment deadline (납부할 세액 조회). Read-only: this tool never executes a payment; the 'or_pay' in its name is historical.
hometax__tax__payment_statement__searchFreeREQUIRES prior hometax__session__login call with same account_link_id. Search tax payment statement. mate_knd_cd: document type code. sbms_ym_strt/sbms_ym_end: submission year-month YYYYMM.
hometax__tax__payment_statement__search_submit_historywrite actionFreeREQUIRES prior hometax__session__login call with same account_link_id. Search tax declaration and payment submission history. Use sbms_ym_strt/sbms_ym_end (YYYYMM).
hometax__tax__refund__search_detailwrite actionFreeREQUIRES prior hometax__session__login call with same account_link_id. Search tax refund details. Use strt_dt/end_dt (YYYYMMDD). The NTS only serves the last 5 years from today.
hometax__tax__return_history__search_vatFreeREQUIRES prior hometax__session__login call with same account_link_id. Search VAT return history. Use rtn_dt_srt/rtn_dt_end (YYYYMMDD). Dates before 2015-02-23 are refused ('2015년 2월 23일 이후 신고내역만 조회 가능합니다.'), and the NTS screen documents a maximum window of one year — split longer periods into several calls.
hometax__tax__trade_partner__search_listFreeREQUIRES prior hometax__session__login call with same account_link_id. Search list of trade partners (buyers/sellers) from tax records.
hometax__tax__unclaimed_refund__searchwrite actionFreeREQUIRES prior hometax__session__login call with same account_link_id. Search unclaimed tax refunds (최근 5년간 미수령 국세환급금). Both txpr_dscm_no and txpr_nm are required by 국세청 — the session TIN does not substitute for them.
ibk_fast_account__accounts__quick_summary__getFreeREQUIRES prior ibk_fast_account__session__login call with same account_link_id. Read the balance and daily summary for one registered IBK bank account.
ibk_fast_account__session__loginFreeCall this FIRST before any other tool for this provider. Create an IBK fast-account session from the parent account link.
kb_biz_card__approvals__initFreeREQUIRES prior kb_biz_card__session__login call with same account_link_id. Initialize KB Biz Card approvals inquiry for a date range.
kb_biz_card__approvals__pageFreeREQUIRES prior kb_biz_card__session__login call with same account_link_id. Fetch one KB Biz Card approvals page from a prior search context.
kb_biz_card__approvals__resultFreeREQUIRES prior kb_biz_card__session__login call with same account_link_id. Collect KB Biz Card approvals result rows.
kb_biz_card__approvals__searchFreeREQUIRES prior kb_biz_card__session__login call with same account_link_id. Search KB Biz Card approvals rows.
kb_biz_card__common__cards__selectFreeREQUIRES prior kb_biz_card__session__login call with same account_link_id. Select KB Biz Card cards available to the current session.
kb_biz_card__common__departments__selectFreeREQUIRES prior kb_biz_card__session__login call with same account_link_id. Select KB Biz Card departments available to the current session.
kb_biz_card__payments__initFreeREQUIRES prior kb_biz_card__session__login call with same account_link_id. Initialize KB Biz Card payments inquiry for a date range.
kb_biz_card__payments__pageFreeREQUIRES prior kb_biz_card__session__login call with same account_link_id. Fetch one KB Biz Card payments page from a prior search context.
kb_biz_card__payments__resultFreeREQUIRES prior kb_biz_card__session__login call with same account_link_id. Collect KB Biz Card payments result rows.
kb_biz_card__payments__searchFreeREQUIRES prior kb_biz_card__session__login call with same account_link_id. Search KB Biz Card payments rows.
kb_biz_card__purchases__initFreeREQUIRES prior kb_biz_card__session__login call with same account_link_id. Initialize KB Biz Card purchases inquiry for a date range.
kb_biz_card__purchases__pageFreeREQUIRES prior kb_biz_card__session__login call with same account_link_id. Fetch one KB Biz Card purchases page from a prior search context.
kb_biz_card__purchases__resultFreeREQUIRES prior kb_biz_card__session__login call with same account_link_id. Collect KB Biz Card purchases result rows.
kb_biz_card__purchases__searchFreeREQUIRES prior kb_biz_card__session__login call with same account_link_id. Search KB Biz Card purchases rows.
kb_biz_card__session__loginFreeCall this FIRST before any other tool for this provider. Create a KB Biz Card certificate/NPKI session from a registered account link.
kb_fast_account__accounts__transaction_history__searchFreeREQUIRES prior kb_fast_account__session__login call with same account_link_id. Search transaction history for one registered KB Kookmin Bank fast-account using the existing provider session.
kb_fast_account__session__loginFreeCall this FIRST before any other tool for this provider. Create a KB Kookmin Bank fast-account inquiry session from an existing account link. Secrets are never accepted as MCP inputs.
nhis_edi__public__notices__listFreeNo credential or login required. List public NHIS notices.
nhis_edi__public__resources__listFreeNo credential or login required. List public NHIS resources/documents.
nhis_edi__session__loginFreeCall this FIRST before any other tool for this provider. Login to NHIS EDI via NPKI certificate. Returns API_KEY for chaining.
nhis_edi__session__statusFreeCheck NHIS EDI session status.
nps_edi__auth__npki_session__loginFreeCall this FIRST before any other tool for this provider. Login to NPS EDI via NPKI certificate.
nps_edi__auth__session__statusFreeCheck NPS EDI session status.
opendata__env__waste_sanctionFreeLook up workplace waste administrative disposition rows (data.go.kr 15156661) from the local batch M1 index by bizno/brno. Upstream getlist accepts bzentyNm/admdspYmd only — not brno; Jobs never call live bizno GET. Empty matches mean no non-expired index row — not a certified clean claim. Index ingest requires 15156661 활용신청 (ops 심의승인). Platform service key only — no account_link_id. Requires OPENDATA_ENABLED=1 on the server.
opendata__g2b__sanctionFreeLook up G2B (나라장터) unfair-supplier sanction records (data.go.kr 15129466 getUnptRsttCorpInfo02, inqryDiv=1 + bizno). Empty upstream rows mean no matching record in this API response — not a certified 'no sanction ever' claim. Platform service key only — no account_link_id. Requires OPENDATA_ENABLED=1 on the server.
opendata__kiscon__sanctionFreeLook up KISCON construction-firm disclosure rows (data.go.kr 15061362 ConAdminInfoSvc1/GongsiReg). Upstream requires sDate/eDate (not bizno); server scans the window and matches ncrMasterNum (M1), with optional corp_name fallback when source bizno is blank (B-5 M1_WITH_FALLBACK, missing_rate=0.14). Empty matches mean no hit in this window — not a certified clean claim. Platform service key only — no account_link_id. Requires OPENDATA_ENABLED=1 on the server.
opendata__nts__statusFreeLook up NTS business registration status (data.go.kr 15081808). Platform service key only — no account_link_id. Requires OPENDATA_ENABLED=1 on the server.
opendata__nts__validateFreeValidate NTS business registration identity (data.go.kr 15081808). Requires b_no, start_dt (YYYYMMDD), p_nm per businesses[] item. Platform service key only — no account_link_id. Requires OPENDATA_ENABLED=1 on the server.
payroll_artifact__payslip_xlsxFreeBuild one payroll payslip workbook (xlsx) with one sheet per employee from attribution_ym, payment_date, and employees[]. Platform key Job — no account_link_id. Result is a single signed download_url (not composite merge; not Gmail).
payroll_artifact__register_xlsxFreeBuild a standard payroll register workbook (xlsx) from attribution_ym and employees[] (tax/deduction amounts already computed). Platform key Job — no account_link_id. Result is a signed download_url via jobs.result_storage_uri (not composite merge).
payroll_pack__employment_insurance_summary_v1__generateFreeComposite employment-insurance summary v1: runs COMWEL premium billing notice search then employment detail as internal Jobs, and returns computed employment_insurance_won material. Requires prior comwel session login. requires_account_link=False — links resolve per leg provider. If computed is null the result could not be assembled: read computed_error for the reason and do not present the result as complete. Two shapes carry that case: this envelope with partial set to true (we fetched everything - the legs hold it - but could not calculate), or an error whose data carries the same envelope. partial is true whenever the result is incomplete, whether a leg failed or the calculation did.
payroll_pack__insurance_deduction_material_v1__generateFreeComposite insurance-deduction material v1: combines NHIS, NPS, and COMWEL employment billing notice Jobs, then returns computed insurance deduction material fields. Requires prior session login for 건강보험·국민연금·고용산재. Tax fields remain out of scope. One 고지 (고지년월 + 고지차수) reissued as several NHIS 작성회차 (WRT_CHASU) resolves to the newest revision; rows from different 고지 are never collapsed and stay skipped unless the provider-specific row key disambiguates them. requires_account_link=False — links resolve per leg provider. If computed is null the result could not be assembled: read computed_error for the reason and do not present the result as complete. Two shapes carry that case: this envelope with partial set to true (we fetched everything - the legs hold it - but could not calculate), or an error whose data carries the same envelope. partial is true whenever the result is incomplete, whether a leg failed or the calculation did.
payroll_pack__premium_summary_v1__generateFreeComposite premium summary v1: searches NHIS and NPS premium notices, then passes each selected row to the corresponding premium-summary Job. Requires prior session login for 건강보험·국민연금. One 고지 (고지년월 + 고지차수) reissued as several NHIS 작성회차 (WRT_CHASU) resolves to the newest revision; rows from different 고지 are never collapsed and stay skipped unless the provider-specific row key disambiguates them. requires_account_link=False — links resolve per leg provider. If computed is null the result could not be assembled: read computed_error for the reason and do not present the result as complete. Two shapes carry that case: this envelope with partial set to true (we fetched everything - the legs hold it - but could not calculate), or an error whose data carries the same envelope. partial is true whenever the result is incomplete, whether a leg failed or the calculation did.
payroll_pack__smoke__generateFreeComposite smoke tool: runs hometax.session.user_info and nhis_edi.session.status as internal Jobs, merges results. Requires prior session login per institution. requires_account_link=False — links resolve per leg provider.
shinhan_easy__accounts__listFreeREQUIRES prior shinhan_easy__auth__id_password_session__login call with same account_link_id. List Shinhan easy-inquiry accounts for a registered account link.
shinhan_easy__accounts__transaction_history__searchFreeREQUIRES prior shinhan_easy__auth__id_password_session__login call with same account_link_id. Search Shinhan easy-inquiry transaction history for one account.
shinhan_easy__auth__id_password_session__loginFreeCall this FIRST before any other tool for this provider. Create a Shinhan easy-inquiry session from a registered ID/password account link.
work24__auth__npki_session__loginFreeCall this FIRST before any other tool for this provider. Login to work24 (고용24) via 공동인증서 (corporate joint certificate).
work24__auth__session__statusFreeCheck work24 session status.
work24__subsidy__application__deletewrite actionFreeREQUIRES prior work24__auth__npki_session__login call with same account_link_id. Delete a work24 subsidy draft that has not been submitted. Requires explicit caller acknowledgement. Submitted applications must be withdrawn instead.
work24__subsidy__application__draft_validateFreeREQUIRES prior work24__auth__npki_session__login call with same account_link_id. Validate a work24 subsidy draft against the live screen and report the attachment set and whether submission is allowed. Nothing is saved or submitted. Read-only — the mandatory dry run before submit.
work24__subsidy__application__historyFreeREQUIRES prior work24__auth__npki_session__login call with same account_link_id. List past work24 subsidy applications for this programme with their processing state (작성중/처리중/보완요청/반려/처리완료/…). Read-only — the state SSOT is work24, not XDATA. Covered only for programmes whose svcCd is measured on the '참여 사업관리(기존 신청자)' screen; other programmes answer 501 with the measured list.
work24__subsidy__application__initFreeREQUIRES prior work24__auth__npki_session__login call with same account_link_id. Enter a work24 (고용24) employer-subsidy application. Confirms the 사전진단 verdict for the programme and returns the screen contract. Read-only.
work24__subsidy__application__modifyFreeREQUIRES prior work24__auth__npki_session__login call with same account_link_id. Modify an already-submitted work24 subsidy application (prssMode=UPDT). Same endpoint as submit, different mode. Requires explicit caller acknowledgement and the LIVE write mode.
work24__subsidy__application__requirementsFreeREQUIRES prior work24__auth__npki_session__login call with same account_link_id. List what the applicant must supply before any write: institution-provided values, customer-required fields, registered payment accounts, and how attachments are procured (the document list itself is issued by draft_validate, keyed by 접수번호). Read-only — call this before workplace_save.
work24__subsidy__application__submitwrite actionFreeREQUIRES prior work24__auth__npki_session__login call with same account_link_id. Submit a work24 subsidy application to 고용노동부 (prssMode=SNDG). Irreversible: requires explicit caller acknowledgement, the LIVE write mode, and a draft_validate that reports can_submit. Undo is withdraw (반려요청), not delete.
work24__subsidy__application__target_initFreeREQUIRES prior work24__auth__npki_session__login call with same account_link_id. Enter the 대상자정보 step of an existing work24 subsidy draft and return its form contract. Requires a 접수번호 from workplace_save. Read-only.
work24__subsidy__application__target_saveFreeREQUIRES prior work24__auth__npki_session__login call with same account_link_id. Name the chosen 피보험자 as subsidy targets on a draft, identified by the irno values returned by target_search. Write — reversible while the draft is 작성중.
work24__subsidy__application__target_searchFreeREQUIRES prior work24__auth__npki_session__login call with same account_link_id. List the 사업장 고용보험 피보험자 who can be named as subsidy targets. Targets are chosen from this list, never created, so no resident registration number is required from the caller. Read-only.
work24__subsidy__application__withdrawFreeREQUIRES prior work24__auth__npki_session__login call with same account_link_id. Withdraw a submitted work24 subsidy application (반려요청). Requires explicit caller acknowledgement. This is the undo for submit.
work24__subsidy__application__workplace_saveFreeREQUIRES prior work24__auth__npki_session__login call with same account_link_id. Save 사업장정보 into a work24 subsidy draft and obtain the 접수번호 (cvplRqutRcno). Write — business-key idempotent: a retry returns the existing 접수번호 instead of creating a second draft.
Public scan report
scanner v0.1.9 · 2026-09-22 · same rubric, same numbers if you re-run it
- –Code scanremote-only server, no package to scann/a
- Live reliabilityremote reachable in 2803ms17/20
- Tool poisoning99 tool descriptions checked15/15
- Auth qualityopen endpoint exposes 7 write-action tools with no auth3/15
- Maintenanceno repository listed3/15
- Maintainer identityverified namespace with website, no repo4/10
Findings (2)
- highWrite-action tools reachable without authentication
auth.open-write - lowNo source repository listed
maint.no-repo
Install directly
claude mcp add --transport http xdata-mcp https://api.xdata.kr/mcp
XBOSS: common questions
- Is XBOSS MCP server safe?
- With care: it is graded C, so read the findings first (56/100). Read the XBOSS safety report
- How do I install XBOSS?
- It runs remotely at api.xdata.kr. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
- Does XBOSS need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is XBOSS maintained?
- The latest release is v1.0.0.
- Is XBOSS up?
- 100% of our last 9 checks got an answer. We check remote servers about four times a day.