registry-mcp — national company registries
io.github.foretakv0.4.2更新於 Oct 7, 2026
The company registry MCP: brreg orgnr, Companies House, Bolagsverket organisationsnummer.
概覽
查詢英國、挪威與瑞典國家企業登記機關的公司紀錄,並回傳法定申報截止日期。
- 功能
- 提供五個登記工具:lookup_company 依國家識別碼回傳完整公司報告,search_company 依名稱檢索,company_deadlines 回傳下一批法定申報日期,validate_company_id 離線驗證識別碼,list_countries 列出支援的國家。另有 search 與 fetch 兩個連接器別名,為 ChatGPT 包裝相同資料。各國回應採用一致 JSON 結構,並帶有 cached、fetched_at、source 與 license 欄位;選用附件可補充 filings、charges、insolvency、financials、LEI、母公司及 Peppol 資訊。
- 適用情境
- 適合在引進供應商、客戶或交易對手前,讓助理核實公司登記資訊、法律形式、狀態或申報截止日期,或驗證 organisasjonsnummer、company number 等識別碼。也適合需要可引用、帶時間戳記之登記證據,而非一般網頁搜尋的工作流程。
- 執行需求
- 可使用託管遠端端點(不需金鑰或帳號),也可在本機執行:uvx registry-mcp(需 Python 3.12+ 及 uv 或 pipx)或 npx registry-mcp(內部會呼叫 uvx)。選用環境變數:REGISTRY_MCP_CONTACT_EMAIL、REGISTRY_MCP_CACHE_PATH(預設 ./data/cache.sqlite3)。自行架設時 GB 需要免費的 Companies House 金鑰,SE 需要 Bolagsverket 的 OAuth 2 用戶端組;挪威不需任何憑證。需要連線各國登記機關的網路。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 registry-mcp — national company registries,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。
其他 MCP 客戶端
把它新增到你客戶端的 mcpServers 設定中。
{
"mcpServers": {
"registry-mcp": {
"type": "http",
"url": "https://api.foretak.dev/mcp"
}
}
}README
registry-mcp — the company registry MCP
[PyPI] [PyPI alias] [npm] [CI] [License: MIT] [Listed on mcpservers.org] [Rated A on Glama]
Company data for AI agents, any country. One MCP server and REST API, three national registers today: the United Kingdom's Companies House, looked up by company number; Norway's Enhetsregisteret / Brønnøysundregistrene (brreg), looked up by organisasjonsnummer (orgnr); and Sweden's Bolagsverket, looked up by organisationsnummer — one JSON shape whichever you ask.
No install step, over stdio:
What makes it worth a tool slot:
- Deadlines that cite the rule, not just a date.
company_deadlinesgives the next filing date and names why inapplies_because— a Norwegian legal form's statutory duty, or "Companies House publishes this date for the company itself" when the register states it rather than us computing it. Quote the reason, not just the number. - Never more than 24 hours stale, and it says so. Every response carries
cachedandfetched_at. OpenCorporates' own knowledge base tells users to "allow 30 days" for a correction to reach its site — a 30× freshness gap, stated by the incumbent about itself. - Seven tools, not fifty — five registry tools plus two ChatGPT connector aliases. Tool-selection accuracy degrades past 30-50 tools loaded into an agent's context, and some clients cap around 40. Seven tools is roughly 17% of that budget, next to competitors in this space shipping 23 to 78 tools for the same job.
Security. Read-only, always — nothing here writes to a register or anywhere else. No credentials are required from a caller; this deployment's own upstream credential (COMPANIES_HOUSE_API_KEY) is read from the environment and never logged or returned. The base lookup calls three named upstreams and nothing else: data.brreg.no, api.company-information.service.gov.uk and gw.api.bolagsverket.se. include=["lei"]/include=["parents"] additionally call api.gleif.org (GLEIF, CC0, keyless); include=["peppol"] additionally resolves a DNS record at the Peppol SML and calls whichever SMP host it names for that participant, falling back to the Peppol Directory (directory.peppol.eu) only when neither answers — see the attachments above. No personal data beyond what each national register already publishes about the entity itself — and because a Swedish sole trader's company number is their personnummer, the usage log stores no identifier at all for a country whose identifiers can be a natural person's (legal/privacy.md). This service does not perform sanctions, PEP or adverse-media screening, and it does not verify bank account details. Details: SECURITY.md.
One-click install, for a remote streamable-HTTP server:
[Install in VS Code] [Install in VS Code Insiders] [Install in Cursor]
Other clients (Claude Desktop, Cursor, VS Code, Cline, plain JSON configs): see docs/clients.md.
Add to ChatGPT
ChatGPT reaches an MCP server through a custom connector, and its deep research mode calls
exactly two tools — search and fetch — which this server ships alongside the five registry
tools. In ChatGPT, open Settings → Connectors, add a custom connector, and give it:
No authentication, no key, no account. If your ChatGPT plan does not show custom connectors under Settings → Connectors, turn on Settings → Security and login → Developer mode first, then add the URL from https://chatgpt.com/plugins.
search takes one free-text query — a company name, a national identifier, or a name plus a
country ("Tesco United Kingdom") — and returns citable rows; fetch takes a row's id
("NO:923609016") and returns that company's register record and its statutory filing
deadlines, with the full JSON of both in metadata.
Add to Claude Desktop
Claude Desktop takes the same URL as a custom connector: Settings → Connectors → Add custom
connector, then https://api.foretak.dev/mcp?src=readme. No key. For a local stdio install instead, see
Configuration.
Status:
0.4.2, live —GET /healthreturns{"version":"0.4.2","countries":["GB","NO","SE"]}. The five registry tools and their response shapes are frozen; two connector aliases (search,fetch) wrap them for ChatGPT and add no new shape. The hosted API atapi.foretak.devis live, and listed in the official MCP registry asio.github.foretak/registry-mcp. Countries: United Kingdom (Companies House), Norway (brreg), Sweden (Bolagsverket) — see below for each country's identifier format and example calls.
Add to Claude Code
The same two commands as above — Streamable HTTP or local stdio. To add it as a project-level .mcp.json file instead of the CLI, see Configuration.
What it returns
Abridged — the full CompanyReport also carries previous_names, industry_codes, registers, purpose, parent_id, confidence, cached, fetched_at and notes. Every field is documented in llms-full.txt §5.
euid is the EU-wide identifier some member-state registers publish (Finland does; none of ours do yet) — never the LEI, never constructed from parts. advertising_protected is true/false/null: whether the register marks this entity as protected against direct-marketing use, null meaning the register publishes no such flag at all (Norway and the UK, today); where it is true (Sweden's reklamspärr, for one), a notes sentence states it and that marking must travel with any contact details you pass on.
The United Kingdom, same shape, same abridgement:
published_deadlines carries the dates the register publishes itself, with the upstream field each came from. It is [] for Norway and Sweden, which compute all of their own.
Sweden, added in 0.3.0, is where "one shape" starts to earn the claim:
Bolagsverket names no licence for this data, so neither do we: the string says what the permission is and says plainly that there is no licence name to quote, because a familiar name in that field would be a fabrication.
Sweden publishes no status field at all. status is derived from three independent signals — a strike-off date, an ongoing winding-up or restructuring procedure, and Statistics Sweden's "economically active" flag — and is_active therefore means on the register and not winding down, which is not the same as trading. Where any of that is unavailable the answer is unknown, never active.
Two dates are computed, and each carries the provision it comes from:
Six months to the annual general meeting (aktiebolagslagen 7 kap. 10 §) and seven to the filing before a late fee bites (årsredovisningslagen 8 kap. 6 §). Neither date is rolled forward off a weekend, because no Swedish source says it moves. Both assume a financial year ending 31 December by default — a notes sentence says exactly that, including how to shift both dates if the year end is different — but Bolagsverket's document list does publish a filed annual report's own year end: pass include=["filings"] (company_deadlines accepts it on both surfaces) to read it and replace the assumption with the register's own figure. search_company answers not_implemented for Sweden: the free API has four operations and none of them accepts a name.
Note the nulls. Companies House publishes no VAT status, no employee count and no share capital for any company, so those fields are null rather than guessed — null means "this register does not say", never "no". That honesty is the point of one shape across countries.
And the deadlines, which is where the UK module earns its keep:
Where Companies House publishes a date, it is quoted; where it does not, the date is computed from a cited statute and applies_because says so. UK deadlines never roll forward off a weekend or bank holiday, and days_until goes negative for a filing the register still shows as overdue.
Running it yourself? The hosted service at api.foretak.dev has every credential configured. A self-hosted copy needs a free Companies House key for GB and an OAuth 2 client pair from Bolagsverket (BOLAGSVERKET_CLIENT_ID, BOLAGSVERKET_CLIENT_SECRET) for SE; without them those two countries return upstream_error naming the variable, and every other country keeps answering. Norway needs nothing.
Tools
Connector aliases — for ChatGPT, which reaches an MCP server through exactly search and fetch (Add to ChatGPT); add no new response shape and have no REST twin.
Plus the resource registry://rules/{country} (identifier rules, legal forms, deadline rules — read once instead of validating in a loop) and the prompt explain_company.
Attachments — a second, independent fetch alongside the base report, opt-in per name: include=["filings"] on MCP, ?include=filings on REST.
filings— what the entity has filed, and when (GB,NO,SE)charges— registered charges against the entity (GBonly)insolvency— winding-up and administration proceedings (GBonly)financials— the register's own financial figures (turnover, profit, balance sheet, equity and liabilities) for the latest filed accounting period, answering whether a supplier looks solvent — Norway's own key-figures feed, Sweden's read out of the entity's own filed annual report (NO,SE)lei— the Legal Entity Identifier GLEIF publishes for the entity, CC0-licensed and keyless (every country exceptSE)parents— the direct and ultimate corporate parent GLEIF's Level 2 data discloses, or the entity's own stated reason — a category word such asNATURAL_PERSONS, never a name — when it discloses none (same countries aslei)peppol— whether the entity can receive an e-invoice over the Peppol network, read live from the SML/SMP walk ahead of the 1 January 2027 e-invoicing duty (NOonly)
A country's declared set is supported_includes on list_countries / GET /v1/countries; see llms-full.txt for the two-level nullability and the per-country scope of filings.
parent_id and in_group on a Norwegian CompanyReport describe Enhetsregisteret's own parent/sub-unit relation for that entity — nothing more. There is no group-walk tool: following a corporate group upward means calling lookup_company again on parent_id, repeatedly, and that walk answers "what does the register list as this entity's parent?", not "who beneficially owns or controls this company?" — a different question this service does not answer. include=["parents"] above is a different route to an adjacent fact — GLEIF's opinion of who consolidates this entity's accounts, not Enhetsregisteret's own hierarchy and not beneficial ownership either. See llms-full.txt §5.
Why an agent checks a company
Three rules make this a duty rather than a nicety. Finanstilsynet's Rundskriv 15/2019 § 4.4.1 accepts an oppslag against Enhetsregisteret no older than three months, one month where the check rests on company details the customer supplied, and asks for notoritet about the lookup: what was consulted, and when. From 1 January 2027 Norwegian bookkeeping-obliged businesses must invoice each other by e-invoice, and the receiver is resolved in ELMA as 0192: plus organisasjonsnummer, the identifier these tools already take. From 10 July 2027, AMLR Article 23(4) requires "valid proof of registration or a recently issued excerpt of the register" for every new business relationship with a legal entity.
That is what source_url, fetched_at, cached, license and applies_because are for: which record was consulted, when it was read, whether it came from the 24 h cache, the terms it travels under, and whether a deadline was quoted from the register or computed from a named rule.
The limits, stated rather than implied: no sanctions or PEP screening; no bank-account verification, and the commonest invoice fraud is payment redirection, where the supplier is real and only the account number is wrong; and no beneficial owners, which brreg releases on application only, to categories of applicant that do not include a product vendor. Fuller version in llms-full.txt §9.
Configuration
Claude Code — .mcp.json in the project root
Drop COMPANIES_HOUSE_API_KEY if you only need Norway; every other country works without it.
Cursor — ~/.cursor/mcp.json (or .cursor/mcp.json in the project)
Claude Desktop — claude_desktop_config.json
macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
Windows: %APPDATA%\Claude\claude_desktop_config.json
npm instead of uvx — same server, Node launcher
npx registry-mcp shells out to uvx registry-mcp (falling back to pipx run registry-mcp), so Python 3.12+ and one of uv or pipx must be present.
Hosted, no local install — Streamable HTTP
Environment variables — all optional:
REST
Every tool has a REST twin returning the identical JSON document.
Machine-readable docs: /llms.txt, /llms-full.txt, /openapi.json.
Adding your country
Norway is one folder. So is the United Kingdom: registries/gb/ was added as four files and one import line, and GB appeared in list_countries, in every tool, in /openapi.json and in registry://rules/GB on its own. So is Sweden — registries/se/ shipped in 0.3.0 with no change to core/, including the parts of Sweden that fit the abstraction worst: a register that publishes no status field, an operation the upstream does not offer (search_company answers not_implemented), and an identifier that can be a natural person's national ID.
Copy src/registry_mcp/registries/xx/ to registries/<cc>/, implement four methods, add one import line — nothing in core/ changes, and both surfaces plus the manifests light up for the new country automatically.
→ CONTRIBUTING.md — "Add your country", and the new country issue template to claim one first.
Development
Layout:
Documents
NORBIZ_SPEC.md— technical spec of the Norwegian moduleUK_SPEC.md— technical spec of the UK moduleSWEDEN_SPEC.md— technical spec of the Swedish moduleDECISIONS.md— interface and schema decisionsKEYWORDS.md— the canonical alias listSUBMISSIONS.md— registry submission statuslegal/terms.md— terms of use and data attribution
Data source and licence
Norwegian data comes from Enhetsregisteret (Brønnøysundregistrene), published under NLOD 2.0 — attribution required. UK data comes from the Companies House public register, Crown copyright, free to re-use with no attribution condition; we cite it anyway. Swedish data comes from Bolagsverket, with Statistics Sweden (SCB) as a second producer inside the same payload, free to re-use as a värdefull datamängd under the EU high-value-datasets regime — Bolagsverket's own words are "Det krävs inget avtal för att du ska få använda vårt API för värdefulla datamängder" and "Värdefulla datamängder är avgiftsfritt" — and Bolagsverket names no licence, so neither do we: the license string states the permission and states plainly that there is no licence name to quote. Every response carries source, source_url and license so the attribution travels with the data. This project's own code is MIT licensed. Not affiliated with or endorsed by Brønnøysundregistrene, Companies House or Bolagsverket.
來源:README.md,提交 1aba1ff
工具
0版本歷史
1- v0.4.2最新Sep 16, 2026


