# PerilScore > Catastrophe risk scores for US properties. Per-peril (hurricane, wildfire, > hail, flood, earthquake, tornado) plus a standalone crime peril (excluded > from the overall property risk), nearest fire station, Protection score, > and an explicit premium report with property and construction data, COPE, > indicative replacement-cost (RCV) estimates, permit signals, imagery, and an > AI-assisted underwriting summary. ## API - REST full report: GET https://app.perilscore.com/api/v1/score/?address={address} with Bearer API key and available capacity - Signup: POST https://app.perilscore.com/api/v1/signup/ (JSON body with `email`; magic link → API key) - MCP (mixed auth, 10 tools, 2025-11-25): POST https://app.perilscore.com/mcp - Legacy MCP full report (Bearer API key and available capacity): POST https://app.perilscore.com/api/mcp/ - MCP anonymous demo (single tool): POST https://app.perilscore.com/claude/mcp/ - ChatGPT App MCP: POST https://app.perilscore.com/chatgpt/mcp ## Connector tools (mixed-auth /mcp) - score_address (public, read-only) — free score; never consumes a credit - build_underwriting_report (score:write) — explicit premium report; requires OAuth or a Bearer API key plus an idempotency_key; may consume one credit - get_score (read) — look up a score by public_id - list_scores (read) — cursor-paginated history - get_share_score_url (read) — open the owned human sharing workflow - get_report_pdf_url (read) — PDF report URL - get_account_credits (read) — balance + plan info - export_score_factors (read) — underwriter-ready score factor transparency - get_acord_url (read) — eligible ACORD PDF URL; defaults to form_type 140 and supports 80 ## Auth OAuth 2.1 + PKCE (Connector Directory): https://app.perilscore.com/.well-known/oauth-authorization-server Bearer API keys: `Authorization: Bearer ps_api_<32 hex>`. Sign in at https://app.perilscore.com/developers/api/ to generate a key (or POST https://app.perilscore.com/api/v1/signup/). `initialize`, `tools/list`, `resources/list`, `resources/read`, and `score_address` are public. Protected tools trigger OAuth lazy authentication or accept a PerilScore organization API key. Hosted Claude uses Anthropic-held OAuth credentials; Claude Code uses Anthropic's trusted CIMD client metadata. ## Tier policy - Authenticated REST is a full-report operation: a fresh score may consume one credit and REST has no caller-supplied idempotency key. Prefer canonical MCP when replay-safe creation or explicit charge/reuse metadata matters. - `score_address`: always free and non-billable; per-peril scores + fire station + Protection score only. - `build_underwriting_report`: protected and explicit; returns normalized property/construction data, COPE, indicative RCV, permits where available, imagery, AI-assisted findings, and billing metadata. A fresh report may use one credit; idempotent replays and recent matches are not charged again. PerilScore provides decision-support evidence, not a coverage decision. A qualified insurance professional must verify the data and review any customer-authored eligibility or underwriting rule before a consumer-impacting decision is finalized or communicated. ## Discovery - llms-full.txt: https://app.perilscore.com/llms-full.txt - OpenAPI spec: https://app.perilscore.com/openapi.json - MCP manifest: https://app.perilscore.com/.well-known/mcp.json - Agent skill: https://app.perilscore.com/developers/agent-kit/SKILL.md - Installable Agent Kit: https://app.perilscore.com/developers/agent-kit/build-with-perilscore.zip - Public docs: https://app.perilscore.com/developers/ ## Support - Email: info@perilscore.com - Connector reviewers: connectors@perilscore.com - Privacy policy: https://app.perilscore.com/privacy/ - Terms: https://app.perilscore.com/terms/