Skip to content
Sergii Mavrov edited this page Oct 4, 2026 · 2 revisions

FAQ

Straight answers, including the ones that are "we do not publish a number for that".

Is it really free?

Yes. No API key, no account, no sign-up, no quota to negotiate. Point a client at https://mcp.viafrei.de/mcp and the tools appear.

It is free while ViaFrei stabilises. That is stated as a state of affairs rather than a forever promise — the honest version is that it is free today, there is nothing to sign, and nothing on this wiki says what happens after stabilisation because nothing has been decided.

What are the limits?

There is fair use and there are per-tool ceilings. The ceilings are documented because they are part of the tool contract; the fair-use line is not a number, and inventing one here would be worse than saying so.

Per-tool ceilings (these are the real caps, from the tool schemas):

tool ceiling
check_autobahn_traffic 5 roads per call, 50 events
check_road_status 1 road per call, 14 days ahead, 11 entries
find_roadworks_ahead 1 road per call, 90-day window, 20 sites
find_cheapest_fuel radius ≤ 25 km, ≤ 10 stations — the provider's terms, not ours
find_charging_station radius ≤ 25 km, ≤ 10 sites
find_parking radius ≤ 25 km, ≤ 10 facilities per list — share-alike sources (ODbL, CC BY-SA) come back as a separate list
find_nearby radius ≤ 15 km, up to 3 per category
find_place ≤ 10 results, radius ≤ 200 km
find_poi ≤ 10 results, radius ≤ 50 km
find_address ≤ 5 results
get_train_departures ≤ 15 departures, window ≤ 120 min
check_station_facilities ≤ 50 facilities
check_transit_disruption window ≤ 120 min, region-wide only
watch_situation ≤ 10 watches at once, ≤ 24 h each (3 h default), session-scoped

Several of those are deliberate: a departure board above 15 is refused because that is a dataset and not a board, and the fuel caps are set by the publisher.

One provider limit you can hit indirectly: MTS-K sets a minimum interval per station for fuel prices, and its terms make needless querying a real risk to the access itself — attempts to pull the data in bulk are blocked and the key deactivated. So do not loop find_cheapest_fuel. Ask when somebody is about to buy fuel, which is the only thing that licence permits anyway.

Fair use, qualitatively: a briefing that runs once in the morning is fine; the same briefing looping every thirty seconds is not. Serialise rather than fanning out. And from the security policy, explicitly: please do not load-test the public endpoint — volumetric denial of service is out of scope for reports and not welcome as an experiment.

No request-per-second figure, no monthly cap and no uptime number is published, and none is invented here.

Which languages?

German and English. Every tool takes language (de | en, default de) and answers in that language — not translated out of one house language.

Set it on every call to the language the person is writing in. The default is only the fallback for when the language is genuinely unclear, and an English question answered in German is a wrong answer.

Place names, station names and road numbers are never translated in either direction. In English the German term is kept in parentheses so the person recognises it on signs and in local apps.

The nine prompts all take language too. Bilingual resources (viafrei://rules/driving-in-germany, viafrei://rules/low-emission-zones, viafrei://rules/electric-driving, viafrei://emergency) carry both languages in one document.

Making the rest of the surface — pages, digest, panels — genuinely bilingual is a 1.5 intention; see Roadmap.

What happens when a source is down?

A tool answers about what it has, and says so. That is the design rule, and it shows up in specific behaviours worth knowing:

  • check_weather_warnings says so when the data is not current, rather than reporting an all-clear it cannot stand behind. "No warnings" and "we could not check" are different answers and you get the right one.
  • find_charging_station marks a site with no status feed keine Statusdaten and closes with a sentence saying that means unknown, not free. Live availability only exists for the operators who publish it.
  • find_parking: no "free now" means the operator publishes no count, not that it is full.
  • check_station_facilities reports three states — in service, out of service, unknown — and lists out-of-service first, with counts that cover all of them so a truncated list cannot hide a broken lift.
  • A station missing from the station directory produces "I cannot resolve that station", not an empty facility list. That distinction tells you whether to retry.
  • find_place returns candidates rather than guessing when a name is ambiguous.

Freshness is stated per tool, where the tool states it. check_autobahn_traffic says its data is ~5 min old. find_cheapest_fuel names the age of any price over an hour old, and find_parking gives the age of an occupancy reading. No global freshness figure is published, and none is invented here.

Two resources answer the question directly:

  • viafrei://status/feeds — per feed: green (a cycle inside the feed's own freshness window), red (stale or errored) or grey (never ran here). Resources support subscribe, so you can be told when a feed changes colour.
  • viafrei://coverage — which feeds, places and vehicles can be answered for right now, with licence, cadence and freshness per feed, plus what is deliberately not covered.

And some things are thinner than they will be, stated rather than hidden: fuel covers a limited set of stations on the publisher's terms, and find_parking answers today with motorway lorry parking rather than town car parks (the licence is read and the loader exists; nothing came back for a car_park on 2026-09-27).

Can I use this commercially?

It depends on the source, and the answer is in SOURCES.md — per publisher, with the licence and the exact attribution line. The authoritative, always-current version is the resource viafrei://attribution on the server; if the two disagree, the resource is right.

The general shape: most sources are CC BY 4.0 or similar, which permits commercial use provided you attribute — and CC BY 4.0 § 3 terminates the grant when the condition is not met, so the attribution line is a condition and not a courtesy. Some are CC0 1.0 (no condition at all). Two are stricter, and getting either wrong is a licence breach rather than a style problem:

  1. MTS-K fuel prices (Tankerkönig) are consumer information only. German competition law (§ 47k GWB) lets a consumer-information service receive them for one purpose: telling consumers what fuel costs right now. No redistribution in any form — not raw, not a table, not a comparison, not an average, not a chart, not a derived dataset; the Bundeskartellamt's guidance says the form makes no difference and names analyses built from the data as caught too. Never to the fuel industry or its IT providers, and if your recipient might pass it on to that sector you may not supply them either. Misuse costs the licence to receive the data at all — ViaFrei's and yours. See Use case Fleet and logistics briefings for the concrete do-and-don't list.
  2. DELFI public-transport realtime is CC BY-SA 4.0. Share-alike travels: anything you derive from it has to be offered under CC BY-SA 4.0 too, and it may not be blended into a work you publish under a different licence. If that is not what you want for your product, keep it in its own section or leave it out.

Three more worth knowing before you ship:

  • OpenStreetMap-derived results are ODbL 1.0. The share-alike is on the database, not the sentence: showing a user an address is ordinary use, but if you build your own database out of address or POI results and use it publicly, you owe your recipients the same § 4.6 offer ViaFrei makes. The test for whether a result is affected is which table answered — read _meta.sources on the answer, never infer it from your question.
  • Autobahn GmbH publishes openly but publishes no reuse licence text. ViaFrei names the source on every answer and treats redistribution beyond showing the answer as an open question with the publisher rather than as something the absence of a licence permits. If you intend to republish it, ask them.
  • The DWD source note is prescribed by law (§ 7 DWD-Gesetz): Quelle: Deutscher Wetterdienst, three words, not to be reworded, translated or abbreviated, sitting next to the DWD information it belongs to.

Two mechanical rules that apply to every commercial surface you build:

  • Reproduce the attribution line the server sent you, not a copy from a page. The real one names each source's URI, and CC BY 4.0 § 3(a)(1)(A)(iv) makes you retain a URI the licensor supplied. Lines printed in documentation are shortened on purpose.
  • When a result carries _meta.purposeNote, reproduce that sentence verbatim. It is a legal condition of the data, not a caption.

Note that the licence on this repository's code (Apache-2.0) covers the code only. Data obtained through the server is not ViaFrei's to relicense and keeps its provider's terms.

Why is there an npm package at all?

Because some MCP clients can only launch a local process that speaks MCP over stdin/stdout. They cannot add a remote server by URL. For those clients — and only those — npx -y viafrei bridges stdio to the hosted endpoint.

Most people never need it. If your client can add a remote MCP server, use https://mcp.viafrei.de/mcp and ignore the package.

The bridge is deliberately tiny: a transport shim that holds no data and no credentials, makes no decision about any answer, sends no telemetry, and writes no file outside the OS temp directory. It is not a local copy of ViaFrei, and --url is not a way to self-host — there is no self-hosted ViaFrei; the server is a hosted service whose source is closed.

Being a separate package also means the client-side failure modes are machine-readable: one line to stderr and a distinct exit code per cause, so a supervisor can tell "your network is down" from "you typed the flag wrong" without parsing English. The codes are in Connecting your assistant.

Is my query logged?

Here is what the repository's own documents support, and where they stop.

The bridge (npx viafrei, this repository) — documented and verifiable, since the code is public and Apache-2.0: no telemetry, no analytics, no usage counter, no update check. It writes no file outside the OS temp directory and stores no credential; a --header you pass is relayed to the endpoint and never persisted or logged. It also refuses to follow a redirect off the origin you pointed it at, so a header cannot be forwarded somewhere you did not choose.

The server — it necessarily receives your question, because it has to in order to answer it, and the README says as much: the server sees the question and sees it fail; what it cannot see is that an answer was useless to you. That is the limit of what these documents state.

What the server retains, for how long, and whether anything is written to a log is not documented in this repository, and this page will not guess at it. If that matters for your deployment — and for some it will — ask the maintainer: smavrov@web.de, or open a discussion on the repository. A privacy question deserves an answer from the person who can give a binding one, not an inference from a wiki page.

How do I report a problem?

Three channels, and picking the right one matters.

1. An issue — https://github.com/mavrovde/viafrei-mcp/issues

For a bug in the bridge, a tool that fails, a wrong answer, a documentation error. One template is worth knowing about before you need it: "the answer was wrong or useless". A tool that fails is something the server sees for itself; a tool that answers confidently with the wrong thing is not, and that report cannot be obtained any other way. Include what you asked and what came back.

2. A discussion — https://github.com/mavrovde/viafrei-mcp/discussions

For a question, an idea, "is this the right tool for X", or anything that is not yet a defect.

3. The private security advisory form — https://github.com/mavrovde/viafrei-mcp/security/advisories/new

Never open a public issue, discussion or pull request for a key, a token, a password, a certificate or a private URL — a public report is the disclosure. If the secret is yours: rotate it first, report it second.

That form is private to the maintainers and is the right channel for a vulnerability in the bridge and for one in the ViaFrei MCP server itself — the server's source is closed, so this repository is the only address you have, and a server report is welcome there.

The policy promises a first answer within two working days — an acknowledgement that a human has read it and what happens next, not a fix in two days. In scope: the bridge, the published viafrei npm package, and the public MCP endpoint (authentication, transport, origin handling, rate limits, injection, data exposure). Out of scope: volumetric denial of service (please do not load-test), scanner output with no demonstrated impact, anything requiring a compromised client machine, social engineering.

A licence report goes through the same private channel. Some of this data carries purpose limitations — MTS-K fuel prices are consumer information only — so a report about data being redistributed where it should not be is welcome there and is treated as a licence matter, not a bug.

Anything else?

Clone this wiki locally