Skip to main content
Version: v1.1

Public MCP Server

TrackForge runs a public remote MCP (Model Context Protocol) server. It gives Claude and other AI assistants four tools: an ISRC lookup, a catalogue registration check against The MLC's data, a CWR 2.1 file check, and a way for the user to ask TrackForge to follow up.

The server is unauthenticated. There is no account, API key or OAuth flow.

Findings, not advice

Every answer is a finding from registration data as of the date shown. It is not legal advice and not a statement of who owns a song or who may use a recording.

Connect​

SettingValue
Server URLhttps://api.trackforge.studio/api/v1/mcp
TransportStreamable HTTP (JSON-RPC over POST; GET and DELETE return 405)
AuthenticationNone
Protocol versions2025-11-25, 2025-06-18, 2025-03-26, 2024-11-05
Registry entrystudio.trackforge/isrc-lookup (server.json)

Claude​

On Free, Pro and Max plans:

  1. Open Customize → Connectors in Claude.
  2. Select +, then Add custom connector.
  3. Enter https://api.trackforge.studio/api/v1/mcp and select Add. Leave the OAuth settings empty.
  4. In a conversation, turn the connector on from + → Connectors.

On Team and Enterprise plans, an Owner adds it first under Organization settings → Connectors → Add → Custom → Web; members then select Connect under Customize → Connectors. Free plans allow one custom connector.

Other MCP clients​

Add the URL as a remote Streamable HTTP server with no authentication. initialize returns an Mcp-Session-Id header; send it on later requests. A session id the server does not recognise returns 404: send initialize again without it.

Tools​

lookup_recording​

Finds one recording and reports its MLC registration. Give exactly one of:

InputNotes
isrc12 characters, e.g. USIR20400274; hyphens and spaces are accepted
spotify_urlA Spotify track link or spotify:track: URI; album and playlist links are refused
titleWith optional artist
youtube_urlResolved from the video title, so matches are low confidence

It returns the candidate recordings and MLC works, how each was matched and how confidently, and a verdict for each recording. When several matches are equally likely, ambiguous is true and all of them are returned for the user to choose from.

check_catalogue​

Checks up to 50 ISRCs in one call. It returns a verdict and next step for each ISRC, a count of each verdict, and the snapshot date. Invalid ISRCs are listed and skipped, and duplicates are removed. Split larger catalogues into several calls.

validate_cwr​

Checks the text of a CWR 2.1 (Common Works Registration) file, up to 10 MB of ASCII text. An optional filename such as CW260001TF_000.V21 lets the society receiver code select that society's rules; recipient_profile sets them directly, and cisac_base is the default. It returns whether the file is valid, error and warning counts, and each issue with its line, rule, a plain-language explanation and how to fix it. The file is not stored. A valid result does not guarantee that a society will accept the file.

request_full_report​

Records a request for a person at TrackForge to follow up by email about a catalogue review. It takes a contact name and email, an optional organisation, and the catalogue's ISRCs (up to 200), a description (up to 2,000 characters), or both. consent_to_contact must be true: an assistant should call this tool only after the user has asked for a follow-up and agreed to be contacted. No report is generated or sent automatically.

Reading the answers​

Each recording gets one verdict. When several apply, the first in this table wins.

VerdictMeaning
unknownTrackForge's copy of The MLC's data could not be read. It is never a negative finding.
conflictThe recording is linked to more than one MLC work.
nobodyThe data was read and no MLC work is linked to the recording. This does not by itself mean the work is unregistered: the next step says whether to match the recording to an existing work or register one.
partialThe recording is linked to one work, and a share is unclaimed or in dispute.
registeredThe recording is linked to one work with nothing unclaimed or in dispute.

Each verdict carries a confidence, dated evidence, an as_of date and a next_step that names who can act. A nobody verdict for a recording released within about 60 days of the snapshot date is marked low confidence: The MLC may not have processed it yet.

Where the data comes from​

  • The MLC: TrackForge's copy of The MLC's monthly public bulk data (BWARM). The server never queries The MLC live, so every MLC answer is true as of the snapshot date it carries.
  • Recording details: the Spotify Web API and MusicBrainz, used to identify the recording from a link, title or ISRC.

Example prompts​

  • "Is ISRC USIR20400274 registered with The MLC, and is any share unclaimed?"
  • "Check these ISRCs against The MLC and tell me which have no linked work: …"
  • "Here is the CWR file I'm about to send to The MLC. Is it valid, and what should I fix?"
  • "Who is registered for the song at this Spotify link: …?"

Limits​

Limits apply to each MCP session. Clients that send no session id are counted by source address and user agent.

LimitValue
Usage units60 per 5 minutes and 600 per UTC day
Unit costlookup_recording 1; check_catalogue 1 per 5 ISRCs; validate_cwr 2; request_full_report 1
CWR validations20 per hour
Report requests5 per day

A call over a limit returns a tool error that says how long to wait.

Requests that carry an Origin header are accepted only from trackforge.studio. Server-to-server clients, including hosted assistants, send none.

Privacy​

Requests are logged for usage measurement: the method and tool, the client name and version sent at initialize, the input kind, the ISRCs requested or resolved, the outcome, and a keyed one-way hash of the client address. The address itself is not stored. Titles, artist names, CWR file content and the contact details given to request_full_report are not logged; those contact details are stored only so that a person can follow up.

The request log is kept for 12 months, and the address hash is removed after 90 days. Report requests are kept for 24 months, or less if the person who made one asks for it to be deleted. The privacy policy has the full terms, and auth.md gives the same details in a form for automated clients.

Support​

Email hello@trackforge.studio.