Public MCP Server
TrackForge runs a public remote MCP (Model Context Protocol) server. It gives Claude and other AI assistants four tools: an ISRC lookup, a catalogue registration check against The MLC's data, a CWR 2.1 file check, and a way for the user to ask TrackForge to follow up.
The server is unauthenticated. There is no account, API key or OAuth flow.
Every answer is a finding from registration data as of the date shown. It is not legal advice and not a statement of who owns a song or who may use a recording.
Connect
| Setting | Value |
|---|---|
| Server URL | https://api.trackforge.studio/api/v1/mcp |
| Transport | Streamable HTTP (JSON-RPC over POST; GET and DELETE return 405) |
| Authentication | None |
| Protocol versions | 2025-11-25, 2025-06-18, 2025-03-26, 2024-11-05 |
| Registry entry | studio.trackforge/isrc-lookup (server.json) |
Claude
On Free, Pro and Max plans:
- Open Customize → Connectors in Claude.
- Select +, then Add custom connector.
- Enter
https://api.trackforge.studio/api/v1/mcpand select Add. Leave the OAuth settings empty. - In a conversation, turn the connector on from + → Connectors.
On Team and Enterprise plans, an Owner adds it first under Organization settings → Connectors → Add → Custom → Web; members then select Connect under Customize → Connectors. Free plans allow one custom connector.
Other MCP clients
Add the URL as a remote Streamable HTTP server with no authentication. initialize returns an Mcp-Session-Id header; send it on later requests. A session id the server does not recognise returns 404: send initialize again without it.
Tools
lookup_recording
Finds one recording and reports its MLC registration. Give exactly one of:
| Input | Notes |
|---|---|
isrc | 12 characters, e.g. USIR20400274; hyphens and spaces are accepted |
spotify_url | A Spotify track link or spotify:track: URI; album and playlist links are refused |
title | With optional artist |
youtube_url | Resolved from the video title, so matches are low confidence |
It returns the candidate recordings and MLC works, how each was matched and how confidently, and a verdict for each recording. When several matches are equally likely, ambiguous is true and all of them are returned for the user to choose from.
check_catalogue
Checks up to 50 ISRCs in one call. It returns a verdict and next step for each ISRC, a count of each verdict, and the snapshot date. Invalid ISRCs are listed and skipped, and duplicates are removed. Split larger catalogues into several calls.
validate_cwr
Checks the text of a CWR 2.1 (Common Works Registration) file, up to 10 MB of ASCII text. An optional filename such as CW260001TF_000.V21 lets the society receiver code select that society's rules; recipient_profile sets them directly, and cisac_base is the default. It returns whether the file is valid, error and warning counts, and each issue with its line, rule, a plain-language explanation and how to fix it. The file is not stored. A valid result does not guarantee that a society will accept the file.
request_full_report
Records a request for a person at TrackForge to follow up by email about a catalogue review. It takes a contact name and email, an optional organisation, and the catalogue's ISRCs (up to 200), a description (up to 2,000 characters), or both. consent_to_contact must be true: an assistant should call this tool only after the user has asked for a follow-up and agreed to be contacted. No report is generated or sent automatically.
Reading the answers
Each recording gets one verdict. When several apply, the first in this table wins.
| Verdict | Meaning |
|---|---|
unknown | TrackForge's copy of The MLC's data could not be read. It is never a negative finding. |
conflict | The recording is linked to more than one MLC work. |
nobody | The data was read and no MLC work is linked to the recording. This does not by itself mean the work is unregistered: the next step says whether to match the recording to an existing work or register one. |
partial | The recording is linked to one work, and a share is unclaimed or in dispute. |
registered | The recording is linked to one work with nothing unclaimed or in dispute. |
Each verdict carries a confidence, dated evidence, an as_of date and a next_step that names who can act. A nobody verdict for a recording released within about 60 days of the snapshot date is marked low confidence: The MLC may not have processed it yet.
Where the data comes from
- The MLC: TrackForge's copy of The MLC's monthly public bulk data (BWARM). The server never queries The MLC live, so every MLC answer is true as of the snapshot date it carries.
- Recording details: the Spotify Web API and MusicBrainz, used to identify the recording from a link, title or ISRC.
Example prompts
- "Is ISRC USIR20400274 registered with The MLC, and is any share unclaimed?"
- "Check these ISRCs against The MLC and tell me which have no linked work: …"
- "Here is the CWR file I'm about to send to The MLC. Is it valid, and what should I fix?"
- "Who is registered for the song at this Spotify link: …?"
Limits
Limits apply to each MCP session. Clients that send no session id are counted by source address and user agent.
| Limit | Value |
|---|---|
| Usage units | 60 per 5 minutes and 600 per UTC day |
| Unit cost | lookup_recording 1; check_catalogue 1 per 5 ISRCs; validate_cwr 2; request_full_report 1 |
| CWR validations | 20 per hour |
| Report requests | 5 per day |
A call over a limit returns a tool error that says how long to wait.
Requests that carry an Origin header are accepted only from trackforge.studio. Server-to-server clients, including hosted assistants, send none.
Privacy
Requests are logged for usage measurement: the method and tool, the client name and version sent at initialize, the input kind, the ISRCs requested or resolved, the outcome, and a keyed one-way hash of the client address. The address itself is not stored. Titles, artist names, CWR file content and the contact details given to request_full_report are not logged; those contact details are stored only so that a person can follow up.
The request log is kept for 12 months, and the address hash is removed after 90 days. Report requests are kept for 24 months, or less if the person who made one asks for it to be deleted. The privacy policy has the full terms, and auth.md gives the same details in a form for automated clients.
Support
Email hello@trackforge.studio.