Your Data · Attack Surface

list_my_services

List detected services across your assets (product/version, HTTP server/title, TLS flag). Filter by product, port, or SSL-only. Costs 1 credit.

POST
tools/call

Cost: 1 credit per successful call  ·  Scope: mcp:org  ·  Response shape: jsonb

Returns data scoped to your own organisation only — the organisation is resolved from your API key and injected server-side, never read from the request.

Parameters

productstringoptional

Filter by detected service product. Maximum 128 characters. Optional.

portintegeroptional

Filter by port number. Accepted range: 1–65535. Optional.

ssl_onlybooleanoptionaldefault: false

When true, only return services served over TLS.

limitintegeroptionaldefault: 100

Maximum number of services to return. Accepted range: 1–500.

Example invocation

Ask your agent: "What HTTPS services are we exposing?"

curl -s https://api.precursorintelligence.com/functions/v1/mcp \
  -H "Authorization: Bearer $PRECURSOR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"list_my_services","arguments":{"ssl_only":true,"limit":100}}}'

Response

result.content[0].text (parsed)
{
  "count": 2,
  "items": [
    {
      "fqdn": "autodiscover.precursorsecurity.com",
      "ip": "40.99.153.136",
      "port_number": 443,
      "service_name": "https",
      "service_product": "Microsoft IIS httpd",
      "service_version": "10.0",
      "is_ssl": true,
      "http_status_code": 200,
      "http_server": "Microsoft-IIS/10.0",
      "http_title": "Outlook"
    },
    {
      "fqdn": "mail.precursorsecurity.com",
      "ip": "203.0.113.10",
      "port_number": 443,
      "service_name": "https",
      "service_product": "nginx",
      "service_version": "1.24.0",
      "is_ssl": true,
      "http_status_code": 200,
      "http_server": "nginx/1.24.0",
      "http_title": "Webmail"
    }
  ],
  "generated_at": "2026-06-18T08:15:00.000Z"
}

The full MCP envelope, including _meta.precursor with request_id, credits, and response_truncated, is documented in Response Format.

Response fields

countintegeroptional

Number of services returned (equals items.length).

itemsarrayoptional

Detected services matching the filters within your organisation. Each object contains the fields below.

items[].fqdnstringoptional

Fully qualified domain name of the asset.

items[].ipstringoptional

IP address the service was observed on, e.g. 40.99.153.136.

items[].port_numberintegeroptional

Port number the service is exposed on, e.g. 443.

items[].service_namestring | nulloptional

Detected service name, e.g. https.

items[].service_productstring | nulloptional

Detected service product, e.g. Microsoft IIS httpd, nginx.

items[].service_versionstring | nulloptional

Detected service version, e.g. 10.0.

items[].is_sslbooleanoptional

Whether the service is served over TLS.

items[].http_status_codeinteger | nulloptional

HTTP status code returned by the service, when applicable.

items[].http_serverstring | nulloptional

Value of the HTTP Server response header, when present.

items[].http_titlestring | nulloptional

HTML page title captured from the service, when present.

generated_atstringoptional

ISO 8601 timestamp indicating when this response was generated.

Errors

CodeMessageWhen
-32602invalid_params: product: max:128product exceeds 128 characters
-32602invalid_params: port: min:1port is less than 1
-32602invalid_params: port: max:65535port exceeds 65535
-32602invalid_params: limit: min:1limit is less than 1
-32602invalid_params: limit: max:500limit exceeds 500
-32001unauthorizedThe API key is invalid/revoked, the IP is not allowed, or the key lacks the mcp:org scope.
-32002insufficient_creditsYour credit balance is zero; top up from the dashboard
-32603internalUnexpected server error; the credit is automatically refunded