Incorporates a Delaware C-Corp from your AI agent — documents, e-signatures, and human-reviewed filing.
Do not connect
A critical issue was found. Do not connect this server as-is.
Scanned 9 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The corply MCP server exposes 52 tools, focused primarily on database and AI capabilities. Its published description reads: "Incorporates a Delaware C-Corp from your AI agent — documents, e-signatures, and human-reviewed filing". It communicates over Streamable HTTP using the 2026-07-28 protocol revision, and does not require authorization to connect. MCPGrade currently rates corply F — a critical issue was found and the server should not be connected as-is. Its most notable findings include "Data-exfiltration parameters" and "Cross-tool shadowing". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check corply's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add corply to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://corply.dev/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
Use for a broad company briefing, company disambiguation, or a founder asking what matters next. It is not a prerequisite for a goal-specific tool because every Corply result now carries server-author
Attach an already-existing company without creating a Corply formation. Records name, jurisdiction, entity type, date, and file number as founder assertions—not verified facts—then returns a refreshed
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: get_company_briefing
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: get_company_briefing
A tool description tries to alter the model’s use of another tool.
ad of adding a state-recovery call. Idempotency: obey the tool-specific reRecommendationDescriptions must describe only their own tool.
tool: adopt_existing_company
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: adopt_existing_company
A tool description tries to alter the model’s use of another tool.
of adding a state-recovery call. Idempotency: obey the tool-specific retrRecommendationDescriptions must describe only their own tool.
tool: whoami
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: whoami
A tool description tries to alter the model’s use of another tool.
(confirm before redeem_invite). Prerequisite: authenticated active organizatiRecommendationDescriptions must describe only their own tool.
tool: get_org
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: get_org
A tool description tries to alter the model’s use of another tool.
ntities. Prefer get_company_briefing for company-specific work. Prerequisite: authenRecommendationDescriptions must describe only their own tool.
tool: get_status
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: prepare_83b_tin_input
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: prepare_83b_tin_input
A tool description tries to alter the model’s use of another tool.
d of adding a state-recovery call. Idempotency: obey the tool-specific retRecommendationDescriptions must describe only their own tool.
tool: get_cap_table
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: import_cap_table
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: import_cap_table
A tool description tries to alter the model’s use of another tool.
nstead of adding a state-recovery call. Idempotency: obey the tool-specifiRecommendationDescriptions must describe only their own tool.
tool: save_application
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
ype":"string"},"secretaryFounderId":{"type":"string"},"governanceConfiRecommendationRemove side-channel parameters; constrain tool inputs.
tool: save_application
A tool description tries to alter the model’s use of another tool.
nstead of adding a state-recovery call. Idempotency: obey the tool-specifiRecommendationDescriptions must describe only their own tool.
tool: amend_frozen_application
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: amend_frozen_application
A tool description tries to alter the model’s use of another tool.
f adding a state-recovery call. Idempotency: obey the tool-specific retryRecommendationDescriptions must describe only their own tool.
tool: validate_application
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: validate_application
A tool description tries to alter the model’s use of another tool.
ad of adding a state-recovery call. Idempotency: obey the tool-specific reRecommendationDescriptions must describe only their own tool.
tool: check_company_names
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: check_company_names
A tool description tries to alter the model’s use of another tool.
ead of adding a state-recovery call. Idempotency: obey the tool-specific rRecommendationDescriptions must describe only their own tool.
tool: generate_documents
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: generate_documents
A tool description tries to alter the model’s use of another tool.
tead of adding a state-recovery call. Idempotency: obey the tool-specificRecommendationDescriptions must describe only their own tool.
tool: request_payment
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: request_payment
A tool description tries to alter the model’s use of another tool.
instead of adding a state-recovery call. Idempotency: obey the tool-specifRecommendationDescriptions must describe only their own tool.
tool: await_payment
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: await_payment
A tool description tries to alter the model’s use of another tool.
g instead of adding a state-recovery call. Idempotency: obey the tool-specRecommendationDescriptions must describe only their own tool.
tool: request_registered_agent_upgrade
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: request_registered_agent_upgrade
A tool description tries to alter the model’s use of another tool.
a state-recovery call. Idempotency: obey the tool-specific retry key or gRecommendationDescriptions must describe only their own tool.
tool: await_registered_agent_upgrade
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: await_registered_agent_upgrade
A tool description tries to alter the model’s use of another tool.
ng a state-recovery call. Idempotency: obey the tool-specific retry key orRecommendationDescriptions must describe only their own tool.
tool: request_signature
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: request_signature
A tool description tries to alter the model’s use of another tool.
stead of adding a state-recovery call. Idempotency: obey the tool-specificRecommendationDescriptions must describe only their own tool.
tool: sign_bundle
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: sign_bundle
A tool description tries to alter the model’s use of another tool.
ing instead of adding a state-recovery call. Idempotency: obey the tool-spRecommendationDescriptions must describe only their own tool.
tool: submit_for_formation
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: submit_for_formation
A tool description tries to alter the model’s use of another tool.
ad of adding a state-recovery call. Idempotency: obey the tool-specific reRecommendationDescriptions must describe only their own tool.
tool: remember
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: remember
A tool description tries to alter the model’s use of another tool.
eering instead of adding a state-recovery call. Idempotency: obey the toolRecommendationDescriptions must describe only their own tool.
tool: recall
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: invite_member
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: invite_member
A tool description tries to alter the model’s use of another tool.
g instead of adding a state-recovery call. Idempotency: obey the tool-specRecommendationDescriptions must describe only their own tool.
tool: redeem_invite
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: redeem_invite
A tool description tries to alter the model’s use of another tool.
g instead of adding a state-recovery call. Idempotency: obey the tool-specRecommendationDescriptions must describe only their own tool.
tool: invite_cofounders
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: invite_cofounders
A tool description tries to alter the model’s use of another tool.
stead of adding a state-recovery call. Idempotency: obey the tool-specificRecommendationDescriptions must describe only their own tool.
tool: nudge_signer
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: nudge_signer
A tool description tries to alter the model’s use of another tool.
ng instead of adding a state-recovery call. Idempotency: obey the tool-speRecommendationDescriptions must describe only their own tool.
tool: mark_task_done
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: mark_task_done
A tool description tries to alter the model’s use of another tool.
instead of adding a state-recovery call. Idempotency: obey the tool-speciRecommendationDescriptions must describe only their own tool.
tool: prepare_revenue_launch
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: prepare_revenue_launch
A tool description tries to alter the model’s use of another tool.
companyId from get_company_briefing. Trust nextTool and do not bypass an unsupporteRecommendationDescriptions must describe only their own tool.
tool: create_payment_project
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: create_payment_project
A tool description tries to alter the model’s use of another tool.
ath only. After prepare_revenue_launch returns sandbox_build_ready, deterministicallyRecommendationDescriptions must describe only their own tool.
tool: configure_payment_catalog
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: configure_payment_catalog
A tool description tries to alter the model’s use of another tool.
ions. Next call create_payment_integration_bundle. Prerequisite: authenticated active organizatioRecommendationDescriptions must describe only their own tool.
tool: create_payment_integration_bundle
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
d never handles credential values. The manifest is verify-exact and must nRecommendationRemove side-channel parameters; constrain tool inputs.
tool: create_payment_integration_bundle
Tools that execute commands / write files / make arbitrary requests are exposed without annotations or guards.
s itself, never overwrites existing files, and never handles credential values. The manifRecommendationAnnotate destructive tools and require human approval.
tool: create_payment_integration_bundle
A tool description tries to alter the model’s use of another tool.
eferences, call verify_payment_integration with truthful pass/fail/not-run evidence, repaiRecommendationDescriptions must describe only their own tool.
tool: verify_payment_integration
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
URL validation, secret scan, and sandbox checkout. This tool reports oRecommendationRemove side-channel parameters; constrain tool inputs.
tool: get_payment_pipeline_status
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: get_payment_pipeline_status
A tool description tries to alter the model’s use of another tool.
he legacy Paddle integration planner when the founder wants Corply-controlRecommendationDescriptions must describe only their own tool.
tool: create_payment_route_draft
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: create_payment_route_draft
A tool description tries to alter the model’s use of another tool.
adding a state-recovery call. Idempotency: obey the tool-specific retry keRecommendationDescriptions must describe only their own tool.
tool: start_payment_route_onboarding
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: start_payment_route_onboarding
A tool description tries to alter the model’s use of another tool.
ng a state-recovery call. Idempotency: obey the tool-specific retry key orRecommendationDescriptions must describe only their own tool.
tool: refresh_payment_route_onboarding
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: refresh_payment_route_onboarding
A tool description tries to alter the model’s use of another tool.
a state-recovery call. Idempotency: obey the tool-specific retry key or gRecommendationDescriptions must describe only their own tool.
tool: reconcile_payment_route
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: reconcile_payment_route
A tool description tries to alter the model’s use of another tool.
of adding a state-recovery call. Idempotency: obey the tool-specific retryRecommendationDescriptions must describe only their own tool.
tool: run_sandbox_payment_probe
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: run_sandbox_payment_probe
A tool description tries to alter the model’s use of another tool.
adding a state-recovery call. Idempotency: obey the tool-specific retry kRecommendationDescriptions must describe only their own tool.
tool: run_sandbox_payout_probe
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: run_sandbox_payout_probe
A tool description tries to alter the model’s use of another tool.
f adding a state-recovery call. Idempotency: obey the tool-specific retryRecommendationDescriptions must describe only their own tool.
tool: get_bank_onboarding_status
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: start_bank_onboarding
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
cument, Mercury credential, or legal name/EIN override; Corply loads trustRecommendationRemove side-channel parameters; constrain tool inputs.
tool: start_bank_onboarding
A tool description tries to alter the model’s use of another tool.
d of adding a state-recovery call. Idempotency: obey the tool-specific retRecommendationDescriptions must describe only their own tool.
tool: reconcile_bank_onboarding
A tool description tries to alter the model’s use of another tool.
adding a state-recovery call. Idempotency: obey the tool-specific retry kRecommendationDescriptions must describe only their own tool.
tool: resolve_company_plan
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: resolve_company_plan
A tool description tries to alter the model’s use of another tool.
ad of adding a state-recovery call. Idempotency: obey the tool-specific reRecommendationDescriptions must describe only their own tool.
tool: upsert_operating_subject
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: upsert_operating_subject
A tool description tries to alter the model’s use of another tool.
f adding a state-recovery call. Idempotency: obey the tool-specific retryRecommendationDescriptions must describe only their own tool.
tool: manage_operating_access_grant
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: manage_operating_access_grant
A tool description tries to alter the model’s use of another tool.
ing a state-recovery call. Idempotency: obey the tool-specific retry key oRecommendationDescriptions must describe only their own tool.
tool: record_operating_fact
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: record_operating_fact
A tool description tries to alter the model’s use of another tool.
d of adding a state-recovery call. Idempotency: obey the tool-specific retRecommendationDescriptions must describe only their own tool.
tool: record_operating_event
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: record_operating_event
A tool description tries to alter the model’s use of another tool.
of adding a state-recovery call. Idempotency: obey the tool-specific retrRecommendationDescriptions must describe only their own tool.
tool: upload_operating_evidence
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: upload_operating_evidence
A tool description tries to alter the model’s use of another tool.
adding a state-recovery call. Idempotency: obey the tool-specific retry kRecommendationDescriptions must describe only their own tool.
tool: record_operating_evidence
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
named reviewer credentials. A guidance link or model assertion is never prRecommendationRemove side-channel parameters; constrain tool inputs.
tool: record_operating_evidence
A tool description tries to alter the model’s use of another tool.
adding a state-recovery call. Idempotency: obey the tool-specific retry kRecommendationDescriptions must describe only their own tool.
tool: submit_operating_fact_evidence
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: submit_operating_fact_evidence
A tool description tries to alter the model’s use of another tool.
ng a state-recovery call. Idempotency: obey the tool-specific retry key orRecommendationDescriptions must describe only their own tool.
tool: record_existing_completion
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: record_existing_completion
A tool description tries to alter the model’s use of another tool.
adding a state-recovery call. Idempotency: obey the tool-specific retry keRecommendationDescriptions must describe only their own tool.
tool: transition_operating_work_item
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "_corply_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: transition_operating_work_item
A tool description tries to alter the model’s use of another tool.
ng a state-recovery call. Idempotency: obey the tool-specific retry key orRecommendationDescriptions must describe only their own tool.
tool: (server instructions)
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
ly call in this conversation. Treat actual_tool_output as canonical. Treat cRecommendationRemove side-channel parameters; constrain tool inputs.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: import_cap_table
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: amend_frozen_application
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: check_company_names
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: request_payment
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: await_payment
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: request_registered_agent_upgrade
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: await_registered_agent_upgrade
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: sign_bundle
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: submit_for_formation
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: invite_member
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: redeem_invite
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: invite_cofounders
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: nudge_signer
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: create_payment_integration_bundle
One tool both accesses the filesystem and reaches the network. Combining two capability classes in a single tool widens its blast radius and is the substrate for confused-deputy and exfiltration abuse.
/network calls, writes no files itself, never overwrites existing files, and neRecommendationSeparate filesystem and network capabilities into distinct, independently-scoped tools.
tool: start_payment_route_onboarding
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: refresh_payment_route_onboarding
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: reconcile_payment_route
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: run_sandbox_payment_probe
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: run_sandbox_payout_probe
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: start_bank_onboarding
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: reconcile_bank_onboarding
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: manage_operating_access_grant
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: transition_operating_work_item
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
Vantaj uptime monitoring via MCP — manage monitors, heartbeats, incidents, and status pages.
Unified gateway to Algeria's TKAWEN ecosystem: commerce, certification, and AI tools.
Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Agentic rails for complex workflows with receipts, fees, and MCP tool access.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Return the resolved caller identity (user + org). If pendingInvites is non-empty, tell the user and OFFER to join (confirm before redeem_invite). Prerequisite: authenticated active organization access
Compatibility read returning the caller's organization and company identities. Prefer get_company_briefing for company-specific work. Prerequisite: authenticated active organization access plus every
Return the formation status for a company (or its latest formation): founder-facing checklist, the payment block, THIS caller's pendingSignatures + who else is awaitingOthers, postIncorp tasks, webDas
Create a short-lived, one-time external-browser link for the taxpayer to enter the SSN/ITIN required on their exact signed 83(b) election. Use only after that founder has signed. Never ask for, accept
Return the company's live cap table: every holder with their security type, shares, price paid, and computed ownership %, plus total shares issued. Auto-seeded with founder common stock at formation.
Import a cap table from a Carta/Pulley CSV export (one-way — Corply becomes the system of record). Owner/founder only. Call with confirm:false first to PREVIEW the parsed holders; confirming REPLACES
Deep-merge upsert of the structured formation application for a company: incremental saves merge over what's already stored — a partial payload never wipes untouched sections. This reversible intake s
Apply confirmed answer changes to a frozen, pre-submission formation. This supersedes the frozen legal documents and open signature requests, reopens intake, and requires document regeneration and fre
Validate the formation application and return missing fields as dotted paths. Promotes the formation to 'ready' when complete and returns the canonical next step. Prerequisite: authenticated active or
Check the formation's saved company name and up to five supplied alternatives through OpenSOSData. Pass the currently saved selectedName exactly and preserve the desired alternative order. Returns eve
Phase-aware immutable generation. Company-name search results are advisory and do not gate this action. Before filing, status 'ready' produces only the filing-stage Certificate of Incorporation. After
MANDATORY before any signing: prepare (or reuse) the checkout link for the one-time Corply incorporation fee. Two tiers, and the ONLY difference is how long registered agent is covered: registeredAgen
Wait for the incorporation payment to land. Returns {status: 'paid'|'pending'|'expired'|'unpaid'}. Call it in a LOOP until it returns 'paid' — do not call request_signature, invite_cofounders, or subm
Upgrade a company from first-year registered agent to LIFETIME registered agent for $350, at any time after the incorporation fee is paid. This is the difference between the $449 Essential tier and th
Wait for the $350 lifetime registered-agent upgrade to land. Returns {status:'lifetime'|'pending'|'expired'|'unpaid'}. Call in a LOOP until 'lifetime'. 'expired' → call request_registered_agent_upgrad
Requires the incorporation fee to be PAID first (request_payment → await_payment). Phase-aware and idempotent: before Delaware acceptance it prepares each founder's one filing-stage bundle. The incorp
Record one binding ESIGN/UETA consent for the exact server-issued bundle returned by get_status or request_signature. CALLER GATE: only the live signer may call it, after reviewing every listed docume
Requires the incorporation fee to be PAID first (request_payment → await_payment). Hand the fully-signed formation to the human filing pipeline, then best-effort notify the organization and email the
Persist a durable decision/fact into the organization's context memory. Prerequisite: authenticated active organization access plus every prerequisite stated above. Canonicality: invokes the shared ba
Search the organization's context memory + Corply reference KB for relevant facts. Prerequisite: authenticated active organization access plus every prerequisite stated above. Canonicality: reads curr
Invite a cofounder to this organization by email. Call only after the founder explicitly confirms the invitation. This membership invitation is independent of name checks, documents, payment, and sign
Join an organization with an invite join code. Ask the user to confirm first ('Join {company} as a cofounder?') — joining switches your active organization and best-effort emails the other active orga
Requires the incorporation fee to be PAID first (request_payment → await_payment). Compatibility action that emails each OTHER listed founder's pending review-and-sign link after documents are generat
Re-send the signature reminder email to a cofounder who hasn't signed yet. Only when the lead asks. Prerequisite: authenticated active organization access plus every prerequisite stated above. Canonic
Report one of YOUR post-incorporation tasks as done (for example, opening your bank account) with an optional note. Corply's team verifies and completes it — status becomes 'pending review'. Only work
LEGACY PADDLE SUBSCRIPTION MIGRATION ONLY; for a new Corply-controlled payment portal call get_payment_pipeline_status instead. The calling coding agent must inspect framework, package manager, app/so
Legacy Paddle path only. After prepare_revenue_launch returns sandbox_build_ready, deterministically generate the integrity-hashed sandbox-only manifest that the agent will commit inside an existing l
Validate and deterministically add the founder-approved fixed-price SaaS subscription catalog to an integrity-hashed Corply Pay manifest. The agent derives technical product/price/entitlement keys, en
Generate a reviewable repository patch plan from a valid catalog manifest: the unpublished local @corply/payments alpha package coordinate, exact manifest, environment-variable-name template, structur
Inventory caller-reported local/sandbox evidence references against every required Corply Pay control: build/type tests, webhook authenticity/idempotency/out-of-order delivery, subscription lifecycle,
Canonical read for Corply's own payment pipeline: returns non-secret merchant routes, lifecycle counts, gross settled/refunded/paid-out totals, recent payment state, reconciliation state, and exact bl
Create or exactly replay one local sandbox merchant-route draft for Corply's own payment pipeline. This reversible backend save accepts only company, route key, USD, and an idempotency key; it cannot
Create or recover the secure hosted Moov sandbox onboarding link for one existing Corply payment route. This makes an idempotent provider call after a durable local claim, pre-fills only the canonical
Read the exact hosted Moov sandbox onboarding invite, required capability statuses, default wallet, and verified payout-bank method for one Corply route, then converge the server-only route connection
Read the exact active Moov sandbox wallet balance and compare it with Corply's immutable route-scoped platform-cash postings, then record a hash-bound reconciliation run. It makes provider reads only,
After fresh founder confirmation of the exact USD 1.00 Moov sandbox charge, create or replay one server-priced diagnostic order and send its server-configured card-payment source through Corply's dura
After fresh founder confirmation of the exact USD 0.01 Moov sandbox payout, send one cent from one exact settled diagnostic payment through Corply's durable payout command to the route's server-resolv
First tool for opening a company bank account. Returns any durable Mercury prefill handoff, an in-flight or reconciliation state, or the current direct Mercury fallback. It never reads or returns SSNs
Create one consented Mercury partner prefill and return the founder-only signup link. Call get_bank_onboarding_status first. Never request or include an SSN, identity image, raw formation document, Me
Owner/operator recovery for one uncertain Mercury onboarding attempt. Call only after Mercury directly confirms either the exact onboardingDataId and mercury.com signup link, or that no active applica
Deterministically resolve and materialize the company's current operating graph. The lifecycle is always running—never report globally done. Treat unknown facts as unknown and ask only returned questi
Create or update one durable company-owned subject, including a person, location, product, offering, customer, vendor, contract, equity award, account, or obligation, then freshly resolve the plan. Us
Owner/operator-only grant or revocation of one person's expiring access to one restricted operating-data class. Use the narrowest subject and class, explain the business purpose, cap access at 90 days
Record a typed, versioned company or subject fact and freshly resolve the plan. High-impact facts become canonical only with the registry's required confirmation/evidence. Never infer immigration stat
Atomically stage or promote one event occurrence's stable ID and mutable anchor fact. Use this for every fact named by an event rule; scalar writes are rejected to prevent mixed IDs/deadlines. If evid
Store exact caller-supplied evidence bytes in the active company's private canonical evidence prefix and return the server-computed SHA-256 needed by record_operating_evidence. Use only when the clien
Record a company-owned evidence artifact, then freshly resolve the plan. Evidence is not task completion by itself; attach its id when transitioning a work item. For new files, call upload_operating_e
Submit one founder-provided document for an evidence-confirmed operating fact. This stages the exact typed assertion, binds the server-verified immutable artifact, and creates a durable operator-revie
Record evidence that the company completed one exact materialized work occurrence outside Corply. The command pins rule/version/subject/occurrence, requires a durable idempotency key and explicit atte
Transition one materialized work occurrence by workItemId, then freshly resolve the company plan. Completion is rejected until attached company evidence covers every requirement and required human/pro