← All servers

ZEN SecDB

connects

secdb.nttzen.cloud

ZEN SecDB MCP server for CVE intelligence, CVSS/EPSS scoring, advisories, SSVC, and package audits.

https://secdb.nttzen.cloud/mcpWebsiteOAuthMCP 2025-11-25v26.8.0last checked 24 Aug 2026spoke MCP on 2 of 2 checks (30 days)initialize in 73 ms

How to authenticate

Checked against the endpoint by our probe on 24 Aug 2026. These are the capabilities the server advertises, not a prediction about any particular client.

Scheme
OAuth
Issuer
https://secdb.nttzen.cloud/
Dynamic client registration
Advertised (RFC 7591)
Client ID Metadata Document
Not advertised
PKCE
S256
Grant types
authorization_code, refresh_token, client_credentials
Scopes
read, audit, report, viewer
Protected-resource metadata
Published (RFC 9728)
Anonymous access
Handshake succeeds; 11 tools listable
Documentation
https://secdb.nttzen.cloud/docs

What the probe found

No CORS headers for browser-based clients

A cross-origin preflight came back without Access-Control-Allow-Origin, so the endpoint is reachable from native clients only — code running in a web page is stopped by the browser before a request is ever sent.

11 tools usable without signing in

The server exposes a public surface before authorization: epss_timeseries, linux_audit, linux_os, sightings_search, ssvc_calculator, vulnerability_info, vulnerability_score, vulnerability_search, feed_report_catalog, feed_report, purl_audit.

Tools

epss_timeseriesfeed_reportfeed_report_cataloglinux_auditlinux_ospurl_auditsightings_searchssvc_calculatorvulnerability_infovulnerability_scorevulnerability_search

Contract history

24 Aug 2026v26.8.0first recorded contract

Get alerted when this contract changes

Depend on this server? Leave an email and get a message when a probe records a change — a tool removed, an argument newly required, an enum narrowed. Alerts are being built; signing up is what tells us to hurry.

Prefer a feed reader? This page's contract changes are also an Atom feed.

Status badge

Status for a README, from the last probe — cached an hour, so up to seven hours behind the endpoint. Links back to this page.

MCP status badge for ZEN SecDB
[![MCP status](https://mcpi.app/servers/zen-secdb/badge.svg)](https://mcpi.app/servers/zen-secdb)

Own this server?

Sign in to claim this listing by proving control of the endpoint.