Affinity
Search your CRM, prep for meetings and update deal records from your AI assistant.
Run KYB, sanctions and PEP screening, UBO mapping and supplier risk.
Opens Agent Studio, where connecting is one click. The connector URL below works in any MCP client.
Paste it into any MCP client. Setup docs
The D&B Risk Analytics MCP server connects Dun & Bradstreet's compliance and third-party risk platform to Claude, ChatGPT and any MCP-compatible agent. It runs KYB onboarding, sanctions and PEP screening, ultimate beneficial ownership mapping and supplier risk assessment from a conversation. Sign-in is OAuth 2.1 with PKCE, or client credentials, using an ID you generate in your Risk Analytics workspace.
Verified connector
Listed by Anthropic as a partner connector in its Connectors Directory.
Connection checked by Agentman on .
Anthropic states this reflects the level of review a connector received, not a security audit.
Tool names from Anthropic's directory listing. This server requires sign-in, so we could not read tool descriptions or parameter schemas.
mcp.read and mcp.write are real, named and enforceable — better than the identity-only scopes many connectors ship. But mcp.write is a single grant covering the free write, the metered write, the compliance adjudication and the user-administration capability alike. Nothing separates updating a tag from adding a user or from dispositioning a sanctions match. These are advertised scopes; we could not observe enforcement without credentials.RACreateEntity and RAScreeningMgmtTool are marked Y for RUM usage. Everything else is marked N.RAScreeningAdjudicationTool, RAAddCounterPartiesTool, RADocumentManagementTool, RAAllowDenyListTool, RAPolicyHistoryTool and RAScreeningPolicyTool.scopes_supported with mcp.read and mcp.write; the live descriptor at /.well-known/oauth-protected-resource/mcp omits scopes_supported entirely and the scopes appear on the authorization server instead. The guide's sample also lists authorization_code as the only grant type, while the live metadata advertises refresh_token and client_credentials too. The live server wins; both were read on 2026-08-22.code_challenge_method=plain is accepted. The authorization server advertises both S256 and plain, and D&B documents the plain behaviour as comparing the verifier to the challenge directly. Plain offers no protection against code interception. Use S256./register returns 404. Credentials must be created inside the Risk Analytics product first.readOnlyHint or destructiveHint is published here.support.dnb.com/robots.txt is a blanket Disallow: / for all crawlers, so the support portal D&B links for troubleshooting could not be consulted for this page.One, by D&B's own account. Its tools reference carries a column headed Tool Exposed via MCP whose single value is RiskAnalyticsAgent, and describes that agent as a single MCP entry point that accepts natural language risk requests and picks the workflow. The 39 RA-prefixed names are what the agent calls internally, not what your client sees.
Yes. D&B documents the server as supporting read and authorized write operations, naming entity creation, screening initiation, record updates, tag and custom field management, workflow configuration and portfolio management. Internal capabilities also cover adding and removing users and changing their roles, and writing screening adjudication decisions back to the audit trail.
Two operations are marked as metered. D&B's tools sheet carries a RUM Usage column set to Y on exactly RACreateEntity and RAScreeningMgmtTool, and N on the other 37. Those are the tools that add a record to your portfolio and initiate or rescreen a screening workflow, so an agent adding an entity consumes entitlement.
Named individuals at companies, not just company records. Internal capabilities cover ultimate beneficial owners, control and ownership, principals and contacts, and counterparties with roles such as PSC, director and shareholder. D&B's Professional Contact Data statement lists names, job titles, business addresses, professional email addresses and mobile telephone numbers among the elements it holds.
No, not without written consent. D&B's terms of use state you agree not to reproduce, copy, retransmit, distribute, disseminate, sell, sub-license, publish, broadcast or circulate information received through the Service to anyone without prior written consent, and separately forbid using it to build a comparison database furnished to a third party.
With a client ID you generate in your Risk Analytics workspace. D&B documents two routes: OAuth 2.1 with PKCE and the authorization code grant, or client credentials. The server publishes no dynamic client registration endpoint, so a client that expects to register itself automatically cannot; you must create credentials in the product first.
Three host domains only. D&B's quick start guide names claude.ai, global.consent.azure-apim.net and vertexaisearch.cloud.google.com as the allowed redirect hosts on the authorize endpoint. A self-hosted client or a local callback is therefore not covered by the documented allowlist, which constrains which MCP clients can complete the browser flow.
D&B says they are opinions, not facts. Its analytics transparency statement calls the models, ratings, scores and predictors statements of opinion as of the date expressed, notes they may be estimated from peer-group benchmarks where a business's own data is missing, and disclaims all warranties of fitness for a particular purpose.
documentation URL D&B supplies to Anthropic's directory. The viewer page itself renders about five words to a plain fetch; the substance is the PDF it hosts, which the share is configured to allow downloading. view.highspot.com/robots.txt disallows the host generally but explicitly allows /viewer. · retrieved 2026-08-22www-authenticate naming https://agents.riskanalytics.dnb.com/.well-known/oauth-protected-resource/mcp, RFC 9728 descriptor at that URL, and authorization server metadata at https://agents.riskanalytics.dnb.com/.well-known/oauth-authorization-server (2026-08-22). Four control probes for interpolating catch-alls all returned an identical 404 body, so the descriptor is genuine. · retrieved 2026-08-22dnb-public GitHub organisation (retrieved 2026-08-22). D&B's own plain-text statement that the server "exposes a Risk Analytics Agent as a Tool", plus the Admin → Integrations → API credential location. · retrieved 2026-08-22www.dnb.com/robots.txt carries Content-Signal: ai-train=yes, search=yes, ai-input=yes, and the index documents Markdown content negotiation via an Accept: text/markdown header, which is how the pages above were read. · retrieved 2026-08-22robots.txt disallows all crawlers)Connect D&B Risk Analytics once and your agents call these tools on their own: on a schedule, in a workflow, with nobody at the keyboard.