Search, compare, and validate SPDX licenses, exceptions, expressions, and SBOMs.
Copy the install command and let the AI configure it · recommended for beginners
No copy-paste install info for "Licentia MCP" yet — see the docs or source repo.
Validate this SPDX license expression: MIT OR Apache-2.0, and explain whether it has any formatting issues.
Returns whether the expression is valid and identifies any syntax or formatting issues.
Compare GPL-3.0-only and AGPL-3.0-only, explain whether they are different licenses, and what differences I should review further.
Provides a license comparison result and helps the user confirm whether a different license was selected or needs further review.
Analyze the license information in this SBOM and check for invalid SPDX expressions, unrecognized licenses, or exceptions.
Outputs license-related checks for the SBOM and flags suspicious or non-compliant entries.
Developers can use it before publishing code or dependency manifests to search and validate SPDX licenses and expressions, reducing labeling errors. It is also useful for checking whether the correct license exception is used.
DevOps teams can integrate this tool into automated workflows to analyze license information in SBOMs. This helps detect invalid expressions or exception-related issues early and supports continuous compliance checks.
Researchers or auditors can use it to search, compare, and validate SPDX licenses and exceptions when reviewing open-source components. This makes it easier to confirm whether records are standardized and consistent.
It is an MCP tool for searching, comparing, and validating SPDX licenses and exceptions. It also supports SPDX expression validation and SBOM analysis through a Streamable HTTP endpoint.
Yes. The original description explicitly states support for SPDX expression validation, so it can be used to check whether an expression is valid.
The provided information only says it exposes its capabilities through a Streamable HTTP endpoint, and does not include installation steps, runtime details, or key requirements. For specifics, see the source repository.
Generate SBOMs, scan CVEs, and check license compliance in VS Code.
Generate and validate CycloneDX and SPDX SBOMs for compliance and supply chain security.
Scan npm dependencies for license risks and GPL contamination.
Analyze software dependencies for licenses, vulnerabilities, SBOMs, and policy compliance.
Query official licensing process records with read-only MCP access.
Securely access signed build conformance reports and SPDX SBOM supply chain data.