Decode VINs, search recalls, complaints, crash ratings, and investigations.
Decode VINs, search recalls, complaints, crash ratings, and investigations via MCP. STDIO or Streamable HTTP.
Public Hosted Server: https://nhtsa.caseyjhand.com/mcp
Vehicle safety data from NHTSA — recall campaigns, consumer complaints, NCAP crash ratings, defect investigations, and VIN decoding. Search, decode, and cross-reference across five NHTSA data sources from any MCP client. Runs as a stdio process, a local Streamable HTTP server, or the public hosted endpoint above.
| Tool | Description |
|---|---|
nhtsa_get_vehicle_safety | Comprehensive safety profile combining crash test ratings, recalls, and complaint summary with per-section availability status. |
nhtsa_search_recalls | Search recall campaigns by vehicle or campaign number with optional date filtering. |
nhtsa_search_complaints | Consumer safety complaints with component breakdown and severity stats. |
nhtsa_get_safety_ratings | NCAP crash test ratings and ADAS feature availability. |
nhtsa_decode_vin | Decode VINs for make, model, year, engine, safety equipment (single or batch up to 50). |
nhtsa_search_investigations | Search NHTSA defect investigations (PE, EA, DP, RQ, AQ, and more) with cached index. |
nhtsa_lookup_vehicles | Look up valid makes, models, vehicle types, and manufacturer details from VPIC. |
nhtsa_get_vehicle_safety toolsectionStatus (available/partial/unavailable per section) plus warnings so a partial NHTSA outage is not mistaken for a clean recordnhtsa_search_recalls toolnhtsa_search_complaints toolcomponent filter matches within comma-separated component lists (e.g., "ENGINE", "AIR BAGS")unreliableIncidentDate rather than served as the incident datenhtsa_get_safety_ratings toolvehicleId from an earlier resultnhtsa_decode_vin tool* for unknown positionsmodelYear helps disambiguate pre-1980 or partial VINserrorCode/errorText decode-quality signal, including the clean "0" casenhtsa_search_investigations toolnhtsaId fetches one investigation by its exact ID, mutually exclusive with the other filters — the reverse of the recall link, closing the campaign-to-investigation round tripFLAT_INV.zip) — the first query downloads and parses it (~10s), subsequent queries use the cached index (24h TTL, matching the file's daily refresh)nhtsa_lookup_vehicles toolmakes, models, vehicle_types, manufacturer — partial match supported on make/manufacturer namesmodels can be filtered by year; models and vehicle_types both require makemanufacturer lookups stop at a 500-record ceiling and disclose truncated when more may exist — VPIC publishes no match totalBuilt on @cyanheads/mcp-ts-core: stdio and Streamable HTTP transports, pluggable auth (none / jwt / oauth), swappable storage (in-memory, filesystem, Supabase, Cloudflare KV/R2/D1), structured logging with optional OpenTelemetry tracing.
NHTSA-specific:
Agent-friendly output:
effectiveQuery in its enrichment block, so callers can verify exactly what was searchednhtsa_get_vehicle_safety returns sectionStatus per section plus warnings, so a partial NHTSA outage isn't mistaken for a clean safety recordunreliableIncidentDate (complaints), VIN decode errorCode/errorText, and manufacturer-lookup truncated disclose data-quality limits rather than silently omitting or fabricating valuesA public instance is available at https://nhtsa.caseyjhand.com/mcp — no installation required. Point any MCP client at it via Streamable HTTP:
{
"mcpServers": {
"nhtsa-vehicle-safety-mcp-server": {
"type": "streamable-http",
"url": "https://nhtsa.caseyjhand.com/mcp"
}
}
}
Add the following to your MCP client configuration file:
{
"mcpServers": {
"nhtsa-vehicle-safety-mcp-server": {
"type": "stdio",
"command": "bunx",
"args": ["@cyanheads/nhtsa-vehicle-safety-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info"
}
}
}
}
Or with npx (no Bun required):
{
"mcpServers": {
"nhtsa-vehicle-safety-mcp-server": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@cyanheads/nhtsa-vehicle-safety-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info"
}
}
}
}
Or with Docker:
{
"mcpServers": {
"nhtsa-vehicle-safety-mcp-server": {
"type": "stdio",
"command": "docker",
"args": ["run", "-i", "--rm", "-e", "MCP_TRANSPORT_TYPE=stdio", "ghcr.io/cyanheads/nhtsa-vehicle-safety-mcp-server:latest"]
}
}
}
For Streamable HTTP, set the transport and start the server:
MCP_TRANSPORT_TYPE=http MCP_HTTP_PORT=3010 bun run start:http
# Server listens at http://localhost:3010/mcp
git clone https://github.com/cyanheads/nhtsa-vehicle-safety-mcp-server.git
cd nhtsa-vehicle-safety-mcp-server
bun install
cp .env.example .env
# edit .env to override transport, auth, or storage defaults — no API key required
No API keys required — all NHTSA APIs are public.
| Variable | Description | Default |
|---|---|---|
MCP_TRANSPORT_TYPE | Transport: stdio or http. | stdio |
MCP_HTTP_HOST | HTTP server host. | 127.0.0.1 |
MCP_HTTP_PORT | HTTP server port. | 3010 |
MCP_HTTP_ENDPOINT_PATH | HTTP endpoint path. | /mcp |
MCP_AUTH_MODE | Auth mode: none, jwt, or oauth. | none |
MCP_SESSION_MODE | HTTP session posture: auto, stateful, or stateless. The server declares stateless in code — it keeps no per-session state — and this variable overrides that. | stateless |
MCP_LOG_LEVEL | Log level (RFC 5424). | info |
See .env.example for the full list of optional overrides.
Build and run:
# One-time build
bun run rebuild
# Run the built server
bun run start:stdio
# or
bun run start:http
Run checks and tests:
bun run devcheck # Lint, format, typecheck, security
bun run test # Vitest test suite
bun run lint:mcp # Validate MCP definitions against spec
docker build -t nhtsa-vehicle-safety-mcp-server .
docker run --rm -p 3010:3010 nhtsa-vehicle-safety-mcp-server
The Dockerfile defaults to HTTP transport and logs to /var/log/nhtsa-vehicle-safety-mcp-server; it restates the stateless session mode the server already declares. OpenTelemetry peer dependencies are installed by default — build with --build-arg OTEL_ENABLED=false to omit them.
| Directory | Purpose |
|---|---|
src/index.ts | createApp() entry point — registers tools and inits the NHTSA service. |
src/mcp-server/tools/definitions/ | Tool definitions (*.tool.ts). |
src/services/nhtsa/ | NHTSA API client, ODI bulk-file parser, and field normalization. |
tests/ | Unit and integration tests mirroring src/. |
See CLAUDE.md for development guidelines and architectural rules. The short version:
try/catch in tool logicctx.log for request-scoped loggingnhtsa_ prefix for every tool name, registered in createApp()All data comes from NHTSA's public APIs and bulk files:
api.nhtsa.gov/recallsapi.nhtsa.gov/complaintsapi.nhtsa.gov/SafetyRatingsstatic.nhtsa.gov/odi/ffdd/inv/FLAT_INV.zipvpic.nhtsa.dot.gov/api/vehiclesIssues are welcome. Run checks and tests before submitting:
bun run devcheck
bun run test
Apache-2.0 — see LICENSE for details.
Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
npx -y @cyanheads/nhtsa-vehicle-safety-mcp-serverMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"io-github-cyanheads-nhtsa-vehicle-safety-mcp-server": {
"command": "npx",
"args": [
"-y",
"@cyanheads/nhtsa-vehicle-safety-mcp-server"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup referenceio.github.cyanheads/nhtsa-vehicle-safety-mcp-server works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.