
Company News
Free Business Plan Upgrades for Open Source Maintainers
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.
nordic-data-mcp
Advanced tools
MCP server exposing Nordic Data API — company, VAT, sanctions, KYB and address data across 15 EU countries to AI agents
A Model Context Protocol server that gives AI agents (Claude, Cursor, Claude Code, ChatGPT, Copilot, etc.) direct access to official European business data across 15 EU countries.
Look up companies, validate VAT numbers, run KYB reports, screen against sanctions lists, autocomplete addresses, and resolve LEI ownership — all from inside your AI assistant.
DK · NO · SE · FI · IE · UK · FR · DE · CZ · PL · LV · EE · NL · BE · LU
NL and DE require a Starter+ subscription (free-tier API keys receive HTTP 402
upgrade_required). On paid tiers, NL calls cost 5x quota units and DE calls cost 3x; all other countries cost 1x.
Sign up at addonnordic.com and grab your NORDIC_API_KEY. Free tier available.
Edit ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%/Claude/claude_desktop_config.json (Windows):
{
"mcpServers": {
"nordic-data": {
"command": "npx",
"args": ["-y", "nordic-data-mcp"],
"env": {
"NORDIC_API_KEY": "YOUR_KEY_HERE"
}
}
}
}
Restart Claude Desktop. You should see "nordic-data" appear in the tools menu.
In Cursor settings → MCP → Add new server, or edit ~/.cursor/mcp.json:
{
"mcpServers": {
"nordic-data": {
"command": "npx",
"args": ["-y", "nordic-data-mcp"],
"env": {
"NORDIC_API_KEY": "YOUR_KEY_HERE"
}
}
}
}
claude mcp add nordic-data --env NORDIC_API_KEY=YOUR_KEY_HERE -- npx -y nordic-data-mcp
ChatGPT supports remote MCP servers as custom connectors. No API key needed from you — the hosted server handles upstream authentication.
https://nordic-data-mcp-production.up.railway.app/mcpCustom connectors require a ChatGPT Pro, Business, Team, or Enterprise plan.
Same hosted endpoint, no local install:
https://nordic-data-mcp-production.up.railway.app/mcp| Tool | What it does |
|---|---|
lookup_company | Basic company data from official registries (CVR, Brønnøysund, Bolagsverket, Companies House, INSEE, etc.) |
validate_vat | Validate a VAT number against VIES (EU) or HMRC (GB) |
screen_sanctions | Bulk screen up to 1000 names against UN/EU/OFAC/PEP lists (OpenSanctions, 768K+ entries) |
kyb_full | Master Know-Your-Business report — identity, persons, financials, LEI, VAT, sanctions, adverse media, risk score |
autocomplete_address | Address autocomplete via DAWA (DK), Kartverket (NO), BAN (FR), MML (FI), Nominatim (others) |
lookup_lei | GLEIF Legal Entity Identifier lookup — forward, reverse, and parent/children relationships |
company_enriched | Company data + geocoded address + industry stats + Wikidata (website, employees, CEO, ticker, logo) |
fr_history | French company history timeline (name, activity, status, legal-form changes) from INSEE Sirene bitemporal data |
list_endpoints | Discovery: list all read-only data endpoints in the underlying API (230+), with optional keyword filter |
get_endpoint_schema | Discovery: full parameter + response schema for one endpoint, before calling it |
call_endpoint | Discovery: execute a read-only request (GET/HEAD, plus three allowlisted POST screening queries) against any discovered endpoint |
"Look up CVR 61056416 in Denmark" → calls
lookup_company { country: "dk", id: "61056416" }→ Carlsberg A/S
"Run a full KYB report on Equinor (NO 923609016)" → calls
kyb_full { country: "no", id: "923609016" }
"Is
LU26375245a valid VAT number?" → callsvalidate_vat { country: "LU", vat_number: "26375245" }
"Screen these names against sanctions: Vladimir Putin, Acme Corp, John Smith" → calls
screen_sanctions { names: [...] }
"Find the LEI for Tesco UK (00445790) and include parent and subsidiaries" → calls
lookup_lei { mode: "reverse", country: "uk", id: "00445790" }
| Country | ID type | Format |
|---|---|---|
| DK | CVR | 8 digits |
| NO | Organisasjonsnummer | 9 digits |
| SE | Organisationsnummer | 10 digits (with or without dash) |
| FI | Y-tunnus | NNNNNNN-D (7 digits + check digit) |
| IE | CRO number | 1–7 digits |
| UK | Companies House | 8 chars (digits, or prefix like SC, NI, OC) |
| FR | SIREN | 9 digits |
| DE | LEI or HRB | LEI = 20 alphanum; HRB = prefix + digits |
| CZ | IČO | 8 digits |
| PL | NIP / REGON / KRS | NIP=10, REGON=9/14, KRS=10 |
| LV | Reģistrācijas nr. | 11 digits |
| EE | Registrikood | 8 digits |
| NL | KvK-nummer | 8 digits |
| BE | BCE/KBO | 10 digits |
| LU | RCSL | B + digits |
For validate_vat, country codes are uppercase and cover the broader EU plus GB (use GB, not UK — HMRC requires GB).
The only environment variable you need to set is:
| Variable | Required | Description |
|---|---|---|
NORDIC_API_KEY | yes | Your API key from addonnordic.com |
That's it. The MCP server connects to the hosted Nordic Data API for you.
For remote MCP hosting (e.g. Anthropic Connectors, Smithery, web-based clients), deploy the bundled Streamable HTTP transport:
npm install
npm run build
NORDIC_API_KEY=sk_... npm run start:http # listens on :$PORT (default 3000)
Endpoints:
GET /healthz — health check (returns version + status)ALL /mcp — public MCP endpoint. No key required; all upstream calls are billed to the server's own NORDIC_API_KEY (freemium / discovery). Per-IP rate-limited.ALL /mcp/auth — authenticated MCP endpoint. Requires Authorization: Bearer ndk_... on every request; each call is billed to that customer's own key + quota.Both are session-based via the Mcp-Session-Id header.
This server uses static API-key authentication, not OAuth. How you connect depends on your client:
…/mcp/auth and supply your key as Authorization: Bearer ndk_.... Each request is billed to your own tenant + quota.…/mcp (no key). Otherwise such clients attempt OAuth Dynamic Client Registration (POST /register) and fail — this server has no OAuth endpoints by design and answers them with a clear JSON oauth_not_supported error (not a sign-in flow).npx -y nordic-data-mcp with NORDIC_API_KEY set (see Quick start above).Full OAuth 2.1 (so arbitrary external clients can self-onboard with their own key) is a planned Phase-2 item, not yet implemented.
A railway.toml is included for one-click deploy on Railway:
Mnymann/nordic-data-mcpnordic-data-mcpNORDIC_API_KEYNORDIC_API_KEY./mcp endpoint as defense-in-depth (tunable via PUBLIC_RATE_LIMIT / PUBLIC_RATE_WINDOW_MS). Caching is handled upstream.Issues and PRs welcome at github.com/Mnymann/nordic-data-mcp.
Please do not include API keys, request bodies, or response payloads in bug reports.
Nordic Data returns informational decision-support aggregated from official and public sources. It is not legal, compliance, financial, or professional advice, and not a definitive determination. KYB reports, sanctions/PEP matches, adverse-media hits, and risk scores are signals to review, not verdicts — verify independently and apply your own professional judgment before acting. Use of the service is subject to the AddonNordic Terms.
MIT © AddonNordic ApS
FAQs
MCP server exposing Nordic Data API — company, VAT, sanctions, KYB and address data across 15 EU countries to AI agents
The npm package nordic-data-mcp receives a total of 98 weekly downloads. As such, nordic-data-mcp popularity was classified as not popular.
We found that nordic-data-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.