# Matchory > Matchory (Matchory GmbH, Blaustein/Munich, Germany) is a supplier data platform for enterprise procurement. It resolves fragmented, duplicated supplier records into a single stable identity — the MatchoryID (90%+ accuracy) — and continuously enriches each supplier with verified profiles, market intelligence, and five-dimension risk signals (financial, country, supply-chain, compliance, ESG) from a database of 15M+ verified global suppliers. Data is reached via a web UI, a REST/GraphQL API, webhooks, and a first-party OAuth-protected Model Context Protocol (MCP) server. EU-sovereign: hosted in Germany, GDPR-compliant, ISO 27001 certified. Customers include Bosch, Kärcher, Deutsche Bahn, E.ON, DMG Mori, and Trumpf. ## APIs - [Matchory Discovery API](https://matchory.com/en/technology): REST + GraphQL supplier data layer — verified profiles, MatchoryID resolution, portfolio consolidation, risk signals, market intelligence. Base: https://discovery.matchory.com. Role-scoped API keys; OAuth2/OIDC; SAML 2.0 / OIDC SSO; webhooks for portfolio changes; bulk import/export. ## MCP - [Matchory MCP server](https://matchory.com/en/mcp): Remote MCP endpoint at https://discovery.matchory.com/mcp. Deployment mode: **remote** (hosted HTTPS endpoint; no stdio/npx package is published). OAuth-protected (RFC 9728 protected-resource metadata, required scope `mcp:use`). Works with Microsoft Copilot, Claude, and any MCP-compatible agent. Grounds agents in source-traceable, confidence-scored supplier data. The tool list is not public — `tools/list` returns HTTP 401 `invalid_token` without a tenant access token. ## Authentication - OAuth 2.0 / OpenID Connect authorization server: https://discovery.matchory.com (issuer https://matchory.com) - OIDC discovery: https://discovery.matchory.com/.well-known/openid-configuration - Authorization-server metadata (RFC 8414): https://discovery.matchory.com/.well-known/oauth-authorization-server - Protected-resource metadata (RFC 9728): https://discovery.matchory.com/.well-known/oauth-protected-resource - Authorize: https://discovery.matchory.com/auth/oauth/authorize - Token: https://discovery.matchory.com/auth/oauth/token - Pushed authorization requests (PAR): https://discovery.matchory.com/auth/oauth/par - Dynamic client registration: https://discovery.matchory.com/auth/oauth/register - Revocation: https://discovery.matchory.com/auth/oauth/revoke - Scopes: openid, profile, email, mcp:use - Grant types: authorization_code (PKCE S256), client_credentials, refresh_token, token-exchange - Also: role-scoped API keys, SAML 2.0 / OIDC SSO with just-in-time provisioning and role mapping ## Data model - One immutable **MatchoryID** (UUID) per supplier, stable across mergers, rebrands, and relocations. - Three separated intelligence layers: Global Index (15M+ deduplicated verified profiles), Customer Portfolio (your scoped view with custom attributes), Agent Enrichments (AI-sourced). - Every field carries a source URL, a confidence score, and a verification tier: unverified, auto-confirmed, human-confirmed. - Third-party enrichment partners: Creditsafe, EcoVadis, Prewave, D&B. ERP sync via Workato (SAP, Dynamics, others). ## Plans - Three tiers, contact-sales only, no published prices: **Get started fast** (1–2 categories, single team), **Most popular** (5–10 categories, cross-category), **Custom scope** (10+ categories, org-wide). Every feature is on every plan; scaling is by sourcing projects per year and suppliers actively managed. Unlimited users, teams, and RFIs on all tiers. - No separate API, MCP, or per-call pricing is published. ## Not published These were probed on 2026-08-14 and are genuinely absent — do not assume they exist: - No OpenAPI/Swagger document on any host (matchory.com, discovery.matchory.com, api.matchory.com). - No publicly introspectable GraphQL endpoint (a GraphQL endpoint is advertised; its location is not published). - No public MCP tool list, and no listing in the public MCP registry. - No A2A agent card at `/.well-known/agent-card.json` or `/.well-known/agent.json` on any host. - No `security.txt`, no vulnerability-disclosure programme, no trust centre. - No status page, no changelog, no roadmap, no SLA, no deprecation policy. - No published rate limits and no rate-limit response headers. - No client SDK for the Discovery API on any package registry. ## Docs - [Technology](https://matchory.com/en/technology) - [MCP](https://matchory.com/en/mcp) - [Plans / Pricing](https://matchory.com/en/pricing) - [Functions](https://matchory.com/en/functions) - [Use cases](https://matchory.com/en/use-cases) - [Partners](https://matchory.com/en/partners) - [Newsroom](https://matchory.com/en/newsroom) - [Contact / Support](https://matchory.com/en/contact-us) - [Book a demo](https://matchory.com/en/book-a-demo) - [Login](https://discovery.matchory.com/auth/signin) - [Terms of use](https://matchory.com/en/gtc) - [Privacy Policy](https://matchory.com/en/privacy-policy) - [Imprint](https://matchory.com/en/imprint) - [GitHub](https://github.com/matchory) ## Open source Matchory publishes first-party open-source packages, none of which is a client for the Discovery API: `matchory/elasticsearch` (Laravel Elasticsearch ORM), `matchory/response-cache`, `matchory/laravel-server-timing`, `matchory/herodot` (an OpenAPI documentation generator for Laravel), `matchory/data-pipe`, `matchory/coding-style`, `@matchory/coding-style`, `@matchory/hetzner-cloud-prometheus-sd`. ## Compliance - ISO 27001 certified; GDPR compliant; EU-sovereign hosting in Germany; government-funded (Germany's Federal Ministry for Economics); Gartner Cool Vendor, Procurement, 2023. - Role-based access, full audit trail, SSO + encryption. No SOC 2 attestation published. ## Content signals - `https://matchory.com/robots.txt` publishes a Cloudflare-managed Content-Signal policy: `search=yes, ai-train=no, use=reference`, an express reservation of rights under Article 4 of EU Directive 2019/790, plus explicit `Disallow: /` for Amazonbot, Applebot-Extended, Bytespider, CCBot, ClaudeBot, CloudflareBrowserRenderingCrawler, Google-Extended, GPTBot, and meta-externalagent. ## Company - Matchory GmbH, Ferdinand-Sauerbruch-Str. 3, 89134 Blaustein, Germany. Amtsgericht Ulm HRB 738197. VAT DE323407784. Managing directors: Aiko Wiegand, Nils Liskien, Martin Konradi. sourcing@matchory.com, +49 (0) 89 / 319 0 126 0.