# TracePass MCP server

Manage products, EU Digital Product Passports, operator parties, and GS1 EPCIS supply-chain events.

## Links
- Registry page: https://www.getdrio.com/mcp/eu-tracepass-tracepass
- Repository: https://github.com/malinoto/tracepass-mcp-server
- Website: https://www.tracepass.eu

## Install
- Command: `npx -y tracepass-mcp-server`
- Endpoint: https://ai.tracepass.eu/mcp
- Auth: Auth required by registry metadata

## Setup notes
- Remote header: Authorization (required; secret)
- Package: Npm tracepass-mcp-server v1.7.1
- The upstream registry signals required auth or secrets.
- Remote endpoint: https://ai.tracepass.eu/mcp
- Header: Authorization

## Tools
- tracepass_products (TracePass products) - Manage the TracePass product catalogue. A product is the catalogue layer — one product can have many passports (one per serialised unit). Products are not billable on their own.

Actions (pass via `action`, with `args`):
- list — args: { page?, limit? (≤100), category?, status?, search? }. Read-only.
- get — args: { id }. Read-only.
- create — args: { name, model, category, description? }. `category` is one of: battery, textile, electronics, construction, steel, chemicals, packaging, furniture, tyres, jewelry, toys, fmcg.
- update — args: { id, name?, model?, description? }; pass at least one field to change. Endpoint: https://ai.tracepass.eu/mcp
- tracepass_passports (TracePass passports) - Manage Digital Product Passports — create, read, and run lifecycle actions.

IMPORTANT: `create` consumes a DPP slot on the account's plan and IS BILLABLE. Creating a passport beyond the included quota incurs a per-passport overage charge; if over quota the tool returns a 402-style message — only re-run with args.confirmOverage=true after the user explicitly agrees to the charge. `archive` is IRREVERSIBLE (the public QR permanently 404s); prefer `suspend` when a change might be undone.

Actions (pass via `action`, with `args`):
- list — args: { page?, limit? (≤100), productId?, status?, search? }. status ∈ draft|in_review|approved|published|suspended|expired|archived. Read-only.
- get — args: { id, format? (summary|full), lang? }. Read-only.
- get_by_serial — args: { serial, format?, lang?, gtin? }. Read-only. Addresses the passport by your own serial. A serial is unique only WITHIN a GTIN — if the same serial exists under two GTINs in your account the call returns 409 ambiguous_serial; pass `gtin` (or use the by-id action) to resolve exactly.
- compliance — args: { id }. Read-only. Returns a three-tier compliance verdict (compliant | compliant_with_warnings | incomplete) with regulation-cited findings — use to gap-check a passport against the rules for its category, fix the cited fields/parties, then re-check.
- registry_readiness — args: { id }. Read-only. Returns { ready, findings[] } — whether the passport would pass the EU DPP Registry's FORMAL submission gate (mandatory fields present, correct formatting, a resolvable public link, item-level granularity via a serial number, and a well-formed commodity code where the category carries one). This is the registry's mechanical pre-submission check, NOT the substantive compliance verdict; a passport can be registry-ready yet not substantively compliant. Battery passports only.
- create — args: { productId, gtin, serialNumber, confirmOverage? }. BILLABLE.
- suspend — args: { id }. Reversible — public QR shows 'suspended'.
- suspend_by_serial — args: { serial, gtin? }. Same as suspend, addressed by your serial. 409 ambiguous_serial if the serial isn't unique in your account — pass `gtin`.
- archive — args: { id }. IRREVERSIBLE — confirm with the user first.
- archive_by_serial — args: { serial, gtin? }. IRREVERSIBLE, addressed by your serial — confirm first. 409 ambiguous_serial if the serial isn't unique — pass `gtin`.
- get_qr — args: { id, format? (svg|png) }. Read-only.
- get_qr_by_serial — args: { serial, format? (svg|png), gtin? }. Read-only. Same as get_qr, addressed by your own serial. A serial is unique only WITHIN a GTIN — if the same serial exists under two GTINs in your account the call returns 409 ambiguous_serial; pass `gtin` (or use get_qr by id) to resolve exactly. Endpoint: https://ai.tracepass.eu/mcp
- tracepass_passport_fields (TracePass passport fields) - Update field values on a Digital Product Passport. Every change is recorded in the passport's audit trail, tagged as an API-key update.

Actions (pass via `action`, with `args`):
- update — args: { id, fieldKey, value }. `value` type matches the field's dataType (string, number, boolean, array, object).
- update_by_serial — args: { serial, fieldKey, value, gtin? }. Same as update, addressed by your own serial. A serial is unique only WITHIN a GTIN — if it isn't unique in your account the call returns 409 ambiguous_serial; pass `gtin` (or use update by id) to resolve exactly. Endpoint: https://ai.tracepass.eu/mcp
- tracepass_passport_parties (TracePass passport parties) - Manage the economic-operator parties on a passport — manufacturer, importer, authorisedRepresentative, distributor, recycler, producerResponsibilityOrg. Each party carries a legal name and ideally a validated 13-digit GS1 GLN.

Actions (pass via `action`, with `args`):
- set — args: { id, role, legalName, gln?, country?, legacyOperatorId? }. Sets or updates one role.
- remove — args: { id, role }. Clears one role. Endpoint: https://ai.tracepass.eu/mcp
- tracepass_epcis (TracePass EPCIS 2.0) - GS1 EPCIS 2.0 supply-chain events. `export` is included on Starter plans and up; `capture`, `capture_job`, and `query` require the paid EPCIS add-on (those actions return a 403-style message without it).

Actions (pass via `action`, with `args`):
- export — args: { id }. Export a passport's events as an EPCIS 2.0 JSON-LD document. Read-only.
- export_by_serial — args: { serial, gtin? }. Same as export, addressed by your own serial. A serial is unique only WITHIN a GTIN — if it isn't unique in your account the call returns 409 ambiguous_serial; pass `gtin` (or use export by id). Read-only.
- capture — args: { events }. `events` is an EPCISDocument, a single event, or an array of events (JSON-LD). Returns a 202 with a captureJobId.
- capture_job — args: { jobId }. Poll an async capture job. Read-only.
- query — args: { params? }. `params` is a key/value map of standard EPCIS query parameters (EQ_bizStep, GE_eventTime, MATCH_epc, …). Read-only. Endpoint: https://ai.tracepass.eu/mcp
- tracepass_templates (TracePass DPP templates (regulatory schemas)) - Discover the regulatory field schema for each DPP category — what a COMPLIANT passport must contain, per the governing EU regulation. Read-only reference data. Use this to advise on requirements before creating products/passports, and to gap-check a draft against the rules.

Actions (pass via `action`, with `args`):
- list — args: {}. Lists all 12 categories with their field count, required-field count, and governing regulation (name + number + effective/mandatory dates).
- get — args: { category }. Full field schema for one category: every field's key, label, dataType, whether it is REQUIRED, its access level (public/restricted/authority), enum options, validation bounds, and — where known — the regulation article/annex that mandates it. `category` is one of: battery, textile, electronics, construction, steel, chemicals, packaging, furniture, tyres, jewelry, toys, fmcg. Endpoint: https://ai.tracepass.eu/mcp

## Resources
- tracepass://products - Product catalogue The account's TracePass product catalogue (first page). Attach this for an overview of what products exist. MIME type: application/json
- tracepass://templates - DPP templates (regulatory schemas) All 12 DPP category schemas with field count, required-field count, and governing regulation. Attach this to ground the model in what each category's compliance requirements are. MIME type: application/json

## Prompts
- audit_passport - Audit a passport Review one Digital Product Passport for completeness and compliance readiness — which required fields are missing, which economic-operator parties are unset, whether it's publishable. Arguments: passportId
- onboard_product - Onboard a new product Walk through creating a new product and its first Digital Product Passport — gathering the details, then creating both. Arguments: productName, category
- explain_dpp_requirements - What does a compliant DPP require? Explain what a Digital Product Passport in a given category must contain to be compliant — the required fields and the EU regulation behind them — before you create anything. Arguments: category
- compliance_gap_check - Compliance gap-check before publish Cross-check a draft passport against its category's regulatory schema and produce an exact, prioritised list of what's missing before it can be published compliantly. Arguments: passportId
- review_epcis_events - Review a passport's EPCIS events Inspect the EPCIS 2.0 supply-chain event history of a passport and summarise the product's traceability story. Arguments: passportId

## Metadata
- Owner: eu.tracepass
- Version: 1.7.1
- Runtime: Npm
- Transports: STDIO, HTTP
- License: Not captured
- Language: Not captured
- Stars: Not captured
- Updated: Jul 28, 2026
- Source: https://registry.modelcontextprotocol.io
