# Nhtsa Vehicle Safety Mcp Server

> Vehicle safety data from NHTSA — recalls, complaints, crash ratings, investigations, VIN decoding.

- **Type:** MCP server
- **Install:** `agentstack add mcp-cyanheads-nhtsa-vehicle-safety-mcp-server`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [cyanheads](https://agentstack.voostack.com/s/cyanheads)
- **Installs:** 0
- **Category:** [Integrations](https://agentstack.voostack.com/c/integrations)
- **Latest version:** 0.1.0
- **License:** Apache-2.0
- **Upstream author:** [cyanheads](https://github.com/cyanheads)
- **Source:** https://github.com/cyanheads/nhtsa-vehicle-safety-mcp-server
- **Website:** https://www.npmjs.com/package/@cyanheads/nhtsa-vehicle-safety-mcp-server

## Install

```sh
agentstack add mcp-cyanheads-nhtsa-vehicle-safety-mcp-server
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

@cyanheads/nhtsa-vehicle-safety-mcp-server
  Decode VINs, search recalls, complaints, crash ratings, and investigations via MCP. STDIO or Streamable HTTP.
  7 Tools
  

[](./CHANGELOG.md) [](./LICENSE) [](https://github.com/users/cyanheads/packages/container/package/nhtsa-vehicle-safety-mcp-server) [](https://modelcontextprotocol.io/) [](https://www.npmjs.com/package/@cyanheads/nhtsa-vehicle-safety-mcp-server) [](https://www.typescriptlang.org/) [](https://bun.sh/)

[](https://github.com/cyanheads/nhtsa-vehicle-safety-mcp-server/releases/latest/download/nhtsa-vehicle-safety-mcp-server.mcpb) [](https://cursor.com/en/install-mcp?name=nhtsa-vehicle-safety-mcp-server&config=eyJjb21tYW5kIjoibnB4IiwiYXJncyI6WyIteSIsIkBjeWFuaGVhZHMvbmh0c2EtdmVoaWNsZS1zYWZldHktbWNwLXNlcnZlciJdfQ==) [](https://vscode.dev/redirect?url=vscode:mcp/install?%7B%22name%22%3A%22nhtsa-vehicle-safety-mcp-server%22%2C%22command%22%3A%22npx%22%2C%22args%22%3A%5B%22-y%22%2C%22%40cyanheads/nhtsa-vehicle-safety-mcp-server%22%5D%7D)

[](https://www.npmjs.com/package/@cyanheads/mcp-ts-core)

**Public Hosted Server:** [https://nhtsa.caseyjhand.com/mcp](https://nhtsa.caseyjhand.com/mcp)

---

## Tools

Seven tools for querying NHTSA vehicle safety data:

| Tool Name | Description |
|:----------|:------------|
| `nhtsa_get_vehicle_safety` | Comprehensive safety profile combining crash test ratings, recalls, and complaint summary with per-section availability status. |
| `nhtsa_search_recalls` | Search recall campaigns by vehicle or campaign number with optional date filtering. |
| `nhtsa_search_complaints` | Consumer safety complaints with component breakdown and severity stats. |
| `nhtsa_get_safety_ratings` | NCAP crash test ratings and ADAS feature availability. |
| `nhtsa_decode_vin` | Decode VINs for make, model, year, engine, safety equipment (single or batch up to 50). |
| `nhtsa_search_investigations` | Search NHTSA defect investigations (PE, EA, DP, RQ, AQ, and more) with cached index. |
| `nhtsa_lookup_vehicles` | Look up valid makes, models, vehicle types, and manufacturer details from VPIC. |

### `nhtsa_get_vehicle_safety`

Composite safety profile — the default tool when asked about vehicle safety, reliability, or purchase decisions.

- Combines NCAP crash test ratings, recall history, and complaint summary in a single response
- Frontal crash, side crash, and rollover ratings per vehicle variant
- Complaint breakdown by component with crash, fire, injury, and death counts
- Returns `sectionStatus` plus warnings so upstream outages are not mistaken for a clean record

---

### `nhtsa_search_recalls`

Search recall campaigns by vehicle or campaign number.

- Look up by make/model/year or by specific NHTSA campaign number
- Optional date range filtering (ISO 8601)
- Includes do-not-drive advisories, park-outside warnings, and OTA update availability

---

### `nhtsa_decode_vin`

Decode Vehicle Identification Numbers for manufacturing and safety details.

- Single VIN or batch decode up to 50 VINs
- Partial VINs accepted — use `*` for unknown positions
- Preserves sparse VPIC fields instead of filling missing data with empty placeholders

---

### `nhtsa_search_investigations`

Search NHTSA defect investigations.

- Investigation types: Preliminary Evaluations (PE), Engineering Analyses (EA), Defect Petitions (DP), Recall Queries (RQ), Audit Queries (AQ), and additional ODI codes (SQ, EQ, RP, and others)
- Free-text search across subjects and descriptions
- First query loads the full investigation index (~10s); subsequent queries use a cached index (1h TTL)

---

### `nhtsa_search_complaints`

Search consumer safety complaints filed with NHTSA.

- Component breakdown with crash, fire, injury, and death counts
- Optional component filter (e.g., "ENGINE", "AIR BAGS")
- Returns up to 50 most recent complaints sorted by filing date

---

### `nhtsa_get_safety_ratings`

NCAP crash test ratings and ADAS feature data.

- Frontal crash, side crash (barrier + pole), and rollover ratings
- ADAS features: ESC, forward collision warning, lane departure warning
- Accepts either make/model/year or a follow-up `vehicleId` from earlier NCAP results
- Counts of complaints, recalls, and investigations on file

---

### `nhtsa_lookup_vehicles`

Reference lookups against NHTSA's VPIC database.

- Four operations: `makes`, `models`, `vehicle_types`, `manufacturer`
- `makes` supports `limit` and `offset` pagination for the full VPIC catalog
- Use to resolve ambiguous vehicle names or verify correct spelling
- Models can be filtered by year; manufacturers support partial match

## Features

Built on [`@cyanheads/mcp-ts-core`](https://github.com/cyanheads/mcp-ts-core):

- Declarative tool definitions — single file per tool, framework handles registration and validation
- Unified error handling across all tools
- Pluggable auth (`none`, `jwt`, `oauth`)
- Swappable storage backends: `in-memory`, `filesystem`, `Supabase`, `Cloudflare KV/R2/D1`
- Structured logging with optional OpenTelemetry tracing
- Runs locally (stdio/HTTP) from the same codebase

NHTSA-specific:

- Type-safe client wrapping five NHTSA public APIs with retry logic and sparse-field normalization
- Investigation index caching (1h TTL) for fast repeated queries
- No API key required — all NHTSA APIs are public

## Getting started

### Public Hosted Instance

A public instance is available at `https://nhtsa.caseyjhand.com/mcp` — no installation required. Point any MCP client at it via Streamable HTTP:

```json
{
  "mcpServers": {
    "nhtsa-vehicle-safety-mcp-server": {
      "type": "streamable-http",
      "url": "https://nhtsa.caseyjhand.com/mcp"
    }
  }
}
```

### Self-Hosted / Local

Add the following to your MCP client configuration file:

```json
{
  "mcpServers": {
    "nhtsa-vehicle-safety-mcp-server": {
      "type": "stdio",
      "command": "bunx",
      "args": ["@cyanheads/nhtsa-vehicle-safety-mcp-server@latest"],
      "env": {
        "MCP_TRANSPORT_TYPE": "stdio",
        "MCP_LOG_LEVEL": "info"
      }
    }
  }
}
```

Or with npx (no Bun required):

```json
{
  "mcpServers": {
    "nhtsa-vehicle-safety-mcp-server": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "@cyanheads/nhtsa-vehicle-safety-mcp-server@latest"],
      "env": {
        "MCP_TRANSPORT_TYPE": "stdio",
        "MCP_LOG_LEVEL": "info"
      }
    }
  }
}
```

Or with Docker:

```json
{
  "mcpServers": {
    "nhtsa-vehicle-safety-mcp-server": {
      "type": "stdio",
      "command": "docker",
      "args": ["run", "-i", "--rm", "-e", "MCP_TRANSPORT_TYPE=stdio", "ghcr.io/cyanheads/nhtsa-vehicle-safety-mcp-server:latest"]
    }
  }
}
```

For Streamable HTTP, set the transport and start the server:

```sh
MCP_TRANSPORT_TYPE=http MCP_HTTP_PORT=3010 bun run start:http
# Server listens at http://localhost:3010/mcp
```

### Prerequisites

- [Bun v1.3.2](https://bun.sh/) or higher (or Node.js >= 24.0.0)

### Installation

1. **Clone the repository:**

```sh
git clone https://github.com/cyanheads/nhtsa-vehicle-safety-mcp-server.git
```

2. **Navigate into the directory:**

```sh
cd nhtsa-vehicle-safety-mcp-server
```

3. **Install dependencies:**

```sh
bun install
```

## Configuration

No API keys required — all NHTSA APIs are public.

| Variable | Description | Default |
|:---------|:------------|:--------|
| `MCP_TRANSPORT_TYPE` | Transport: `stdio` or `http`. | `stdio` |
| `MCP_HTTP_HOST` | HTTP server host. | `127.0.0.1` |
| `MCP_HTTP_PORT` | HTTP server port. | `3010` |
| `MCP_HTTP_ENDPOINT_PATH` | HTTP endpoint path. | `/mcp` |
| `MCP_AUTH_MODE` | Auth mode: `none`, `jwt`, or `oauth`. | `none` |
| `MCP_LOG_LEVEL` | Log level (RFC 5424). | `info` |

## Data sources

All data comes from NHTSA's public APIs:

- **Recalls API** — `api.nhtsa.gov/recalls`
- **Complaints API** — `api.nhtsa.gov/complaints`
- **Safety Ratings API** — `api.nhtsa.gov/SafetyRatings`
- **Investigations API** — `api.nhtsa.gov/investigations`
- **VPIC API** — `vpic.nhtsa.dot.gov/api/vehicles`

## Running the server

### Local development

```sh
bun run devcheck  # Lints, formats, type-checks, and more
bun run test      # Runs the test suite
```

### Production

```sh
bun run build
bun run start:stdio   # Production stdio
bun run start:http    # Production HTTP
```

### Docker

```sh
docker build -t nhtsa-vehicle-safety-mcp-server .
docker run -p 3010:3010 nhtsa-vehicle-safety-mcp-server
```

## Project structure

| Directory | Purpose |
|:----------|:--------|
| `src/index.ts` | Server entry point — `createApp()` registration. |
| `src/mcp-server/tools/definitions/` | Tool definitions (`*.tool.ts`). |
| `src/services/nhtsa/` | NHTSA API client with retry logic and field normalization. |

## Development guide

See [`CLAUDE.md`](./CLAUDE.md) for development guidelines and architectural rules. The short version:

- Handlers throw, framework catches — no `try/catch` in tool logic
- Use `ctx.log` for logging
- One tool per file, `nhtsa_` prefix for all tool names

## Contributing

Issues and pull requests are welcome. Run checks before submitting:

```sh
bun run devcheck
bun run test
```

## License

Apache-2.0 — see [LICENSE](LICENSE) for details.

## Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [cyanheads](https://github.com/cyanheads)
- **Source:** [cyanheads/nhtsa-vehicle-safety-mcp-server](https://github.com/cyanheads/nhtsa-vehicle-safety-mcp-server)
- **License:** Apache-2.0
- **Homepage:** https://www.npmjs.com/package/@cyanheads/nhtsa-vehicle-safety-mcp-server

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/mcp-cyanheads-nhtsa-vehicle-safety-mcp-server
- Seller: https://agentstack.voostack.com/s/cyanheads
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
