wipearound
לפיתוח

WIPE Around לסוכני AIMCP, API ו־OpenAPI, בלי מפתח

WIPE Around הוא מפה ציבורית של העסקים המקומיים בישראל, מכל התחומים, והוא חלק מ־WIPE. החיפוש והעמודים שלו פתוחים גם למכונות: שרת MCP לעוזרי AI, API חיפוש שעונה ב־JSON, תיאור OpenAPI, ועמודים שעונים ב־Markdown. הכול לקריאה בלבד, בלי מפתח ובלי הרשמה.

שרת MCP

כתובת השרת: around.iw.pe/mcp. התעבורה היא Streamable HTTP בלי מצב: כל בקשת POST נושאת הודעת JSON-RPC אחת (או כמה, במערך), והתשובה חוזרת מיד כ־JSON. אין session ואין stream, ובקשת GET עונה 405.

השרת עונה ל־initialize, ping, tools/list ו־tools/call, בגרסאות הפרוטוקול 2025-06-18, 2025-03-26 ו־2024-11-05. לגרסה אחרת הוא עונה ב־2025-06-18. הודעה בלי id (notification) מקבלת 202 בלי גוף. שני כלים:

  • search_businesses: חיפוש עסקים. מקבל q, מה שמחפשים בעברית פשוטה (העיר, התחום, תקציב וזמן נקראים מהמילים), ואם רוצים גם city, kind, lat ו־lng, max, when ו־limit, כמו API החיפוש. מחזיר את התשובה של API החיפוש: כ־JSON בטקסט, ואותו אובייקט ב־structuredContent.
  • get_business: קריאת עסק אחד. מקבל business: ה־slug של העסק או הכתובת של העמוד שלו (https://around.iw.pe/b/…). מחזיר את העמוד של העסק ב־Markdown, כמו /b/{slug}.md: תחום, עיר, כתובת, טלפון, וואטסאפ, אתר, שעות, קביעת תור, שירותים ומחירים ועוד. עסק שלא נמצא חוזר עם isError.

כרטיס השרת: around.iw.pe/.well-known/mcp.json. דוגמה: אתחול, ואז חיפוש.

curl -s https://around.iw.pe/mcp \
  -H 'content-type: application/json' \
  -H 'accept: application/json, text/event-stream' \
  -d '{"jsonrpc": "2.0", "id": 1, "method": "initialize",
       "params": {"protocolVersion": "2025-06-18", "capabilities": {},
                  "clientInfo": {"name": "example-agent", "version": "1.0"}}}'

curl -s https://around.iw.pe/mcp \
  -H 'content-type: application/json' \
  -H 'accept: application/json, text/event-stream' \
  -d '{"jsonrpc": "2.0", "id": 2, "method": "tools/call",
       "params": {"name": "search_businesses",
                  "arguments": {"q": "קוסמטיקאית ברעננה", "limit": 3}}}'

תיאורים למכונות

איפה סוכן מוצא מה Around מציע, בלי לקרוא את העמוד הזה:

  • around.iw.pe/openapi.json: תיאור OpenAPI 3.1 של API החיפוש, עם הפרמטרים והשדות.
  • around.iw.pe/.well-known/api-catalog: קטלוג לפי RFC 9727, שמפנה ל־API החיפוש ולשרת ה־MCP, ולתיאורים שלהם.
  • around.iw.pe/.well-known/mcp.json (וגם /.well-known/mcp/server-card.json): הכרטיס של שרת ה־MCP: הכתובת, התעבורה, שני הכלים, ושלא צריך הזדהות.
  • around.iw.pe/.well-known/mcp-registry-auth: המפתח הציבורי שמוכיח ל־MCP Registry הרשמי ש־around.iw.pe שייך ל־WIPE.
  • around.iw.pe/llms.txt: Around מוסבר לסוכני AI: איך מחפשים, אילו עמודים יש, איך נקבעים הציון והסדר, ומאיפה הנתונים. בקשה לעמוד הבית עם Accept: text/markdown מקבלת אותו.
  • around.iw.pe/sitemap.xml: כל עמוד של Around ששווה לקרוא. ה־robots.txt פותח לעוזרי AI את כל העמודים ואת API החיפוש.

עמודים ב־Markdown

העמודים האלה עונים גם ב־Markdown, באותו סדר כמו העמוד, וכל עסק ברשימה עם הדרך להגיע אליו: מוסיפים .md לכתובת, או מבקשים את העמוד עם Accept: text/markdown.

  • עסק: /b/{slug}
  • עיר: /{town}, למשל /haifa
  • תחום: /t/{kind}, ותחום בעיר: /{town}/{kind}, למשל /raanana/cosmetics
  • תחום לפי מה שלקוחות מוסיפים לו: /t/{kind}/{question} ו־/{town}/{kind}/{question}, למשל /t/cosmetics/russian
  • מחירים: /prices, /prices/{kind} ו־/prices/{kind}/{town}
  • מספרים: /numbers ו־/numbers/websites
  • והעמוד הזה: /developers

עמוד אחר שמתבקש כ־Markdown עונה ב־HTML, והכתובת שלו עם .md לא קיימת (404). כל תשובה ב־Markdown נושאת כותרת Link עם הכתובת הקנונית של העמוד, וכתובת עם .md לא נכנסת לאינדקס.

curl -s https://around.iw.pe/raanana/cosmetics.md

curl -s -H 'accept: text/markdown' https://around.iw.pe/prices/facial

בלי מפתח, CORS ומגבלת קצב

אין מפתח, אין הרשמה ואין הזדהות. API החיפוש, שרת ה־MCP, /openapi.json, /.well-known/api-catalog ו־/.well-known/mcp.json עונים עם Access-Control-Allow-Origin: *, כך שאפשר לקרוא להם גם מדף באתר אחר. API החיפוש הוא GET פשוט, ושרת ה־MCP עונה גם ל־OPTIONS (preflight).

מבין הכתובות שבעמוד הזה, רק ל־API החיפוש יש מגבלת קצב בקוד: עד 60 בקשות ב־60 שניות לכל כתובת IP. מעבר לזה התשובה היא 429 עם {"error":"too_many"}. הספירה נשמרת בזיכרון של כל עותק של ה־Worker, ולכן היא בלם ולא מכסה מדויקת. הכלי search_businesses של שרת ה־MCP נספר באותה מגבלה, לפי הכתובת של מי ששולח אליו, אבל מעבר לה אין 429: בקשת ה־HTTP מקבלת 200, והתוצאה של tools/call היא isError: true עם הטקסט {"error":"too_many"}.

לכל השאר (get_business, העמודים ב־Markdown, llms.txt ו־OpenAPI) אין מגבלה בקוד, אז מבקשים מסוכנים להיות עדינים: בקשה אחת בכל פעם, לשמור מה שכבר נקרא, ולא לעבור על כל הארץ דרך החיפוש. ה־sitemap.xml מונה כל עמוד ששווה לקרוא.

רישיונות הנתונים

עסק שהצטרף כותב ומעדכן את הפרטים שלו בעצמו, בעמוד שלו ב־Around או באתר WIPE שלו. עסקים שעוד לא הצטרפו מגיעים מנתונים פתוחים, ולחלק מהם נוסף מה שהאתר של העסק עצמו אומר (שירותים ומחירים, קישור לקביעת תור), כפי ש־WIPE קרא אותו. הנתונים הפתוחים:

  • OpenStreetMap: © תורמי OpenStreetMap, ברישיון ODbL (www.openstreetmap.org/copyright). שימוש בנתונים האלה מחייב קרדיט, ומאגר שנגזר מהם ומשמש בפומבי משותף באותו רישיון.
  • Overture Maps Foundation: ברישיון CDLA-Permissive-2.0.
  • מאגרי רישוי העסקים של עיריית תל אביב־יפו (מידע פתוח), עיריית באר שבע (data.gov.il) ועיריית כפר סבא (ODbL).

בכל תוצאה של API החיפוש, source אומר את הרישיון של הרשומה בנתונים הפתוחים שממנה באה השורה של העסק, או WIPE כשלא נרשם לה רישיון, ו־about נותן את הקרדיט לכל המקורות.

עסק שרוצה לתקן את העמוד שלו

כל עסק יכול לקחת בעלות על העמוד שלו ב־Around בחינם, עם חשבון WIPE: בעמוד של העסק לוחצים ״זה העסק שלך?״, מוכיחים שהעסק שלכם לפי מה שמופיע בעמוד (קוד למייל של העסק, קוד בביו של האינסטגרם שלו או באתר שלו, או שיחה למספר שלו), ואז, מיד או אחרי שאדם ב־WIPE מאשר, מתקנים ומוסיפים את מה שמוצג: תמונות, שעות, שירותים ומחירים. כשבעמוד אין מייל, אינסטגרם, אתר או טלפון, כותבים ל־support@iw.pe. עמוד שבא מאתר WIPE מתעדכן מהאתר עצמו.

ה־API, שרת ה־MCP והעמודים ב־Markdown קוראים מאותם נתונים כמו העמוד של העסק, חוץ ממה שהעמוד טוען מ־Google בשביל מי שגולש בו (דירוג, ביקורות ותמונה), שלא נכנס אליהם.

פרט שגוי, עסק שנסגר או התחזות: בכל עמוד של עסק אפשר לדווח, ואדם בודק כל דיווח. לבעלי עסקים: around.iw.pe/for-business

פרטיות: מה נשמר מבקשה

API החיפוש ושרת ה־MCP לא כותבים למסד הנתונים של Around שום דבר מבקשה: לא המילים, לא העיר והתחום, ולא מי ששאל.

מספרי החיפושים ש־Around מראה לבעלי עסקים (כמה חיפשו את התחום שלהם בעיר שלהם) נספרים רק מחיפושים במפה שבאתר, לפי עיר ותחום ובלי המילים. חיפוש דרך ה־API או שרת ה־MCP לא נספר בהם.

בשביל מגבלת הקצב, כתובת ה־IP של מי שמחפש נשמרת עם הזמנים של הבקשות שלו בזיכרון של העותק של ה־Worker שענה, והקוד של Around לא כותב אותה לשום מקום.

Around רץ על Cloudflare Workers, ו־Cloudflare שומרת לכמה ימים יומן של כל בקשה (Workers Logs): הכתובת שנשאלה עם הפרמטרים שלה, כלומר גם המילים של חיפוש ב־API, והכותרות של הבקשה, שיכולות לכלול את כתובת ה־IP. גוף הבקשה לא נשמר ביומן, ולכן גם לא מה שנשלח לשרת ה־MCP.

גם ניתוח התנועה ש־Cloudflare עושה לדומיין רושם את הבקשות: איזו כתובת נשאלה ומי שאל, למשל איזה עוזר AI.

יצירת קשר

שאלות, תקלות ובקשות: support@iw.pe

In English

WIPE Around, part of WIPE, is a public map of Israel's local businesses. Its search and its pages are open to machines: read-only, no key, no sign-up.

  • MCP server: around.iw.pe/mcp. Streamable HTTP, stateless: each POST carries one JSON-RPC message (or a batch) and gets its answer as JSON; no session, no stream, and a GET answers 405. Protocol versions 2025-06-18, 2025-03-26 and 2024-11-05. Tools: search_businesses (q in plain Hebrew, and city, kind, lat and lng, max, when, limit as in the search API; returns the search API's JSON as text and as structuredContent) and get_business (a slug or an around.iw.pe/b/… address; returns the business's page as Markdown). Card: around.iw.pe/.well-known/mcp.json
  • Search API: GET https://around.iw.pe/api/around/search with q (plain Hebrew; the town, the trade, a budget and a time are read from the words; in English give them as parameters), city, kind, lat and lng, max (shekels), when (today or week) and limit (1 to 20, ten by default). city and kind filter, with two exceptions: when fewer than three businesses match in the town, matching ones from towns within 35 km of its centre follow (each result's city names its own town, and query.relaxed does not say so); and a treatment or a cuisine (facial, brows, sushi) that fewer than three businesses match is widened to its trade (a cuisine first to the towns around), which query.relaxed reports as kind→{trade}. When when or max leave no business at all, they are let go, and query.relaxed says when or max_price. Described in OpenAPI 3.1 at around.iw.pe/openapi.json, with a catalog (RFC 9727) at around.iw.pe/.well-known/api-catalog. How results are ordered, and what lifts a business (online booking, more so with free time in a WIPE calendar, and a page its owner runs from a WIPE site or verified): around.iw.pe/how
  • Markdown: a business, a town, a trade, a trade in a town, a trade by a question clients add to it, the price pages, the numbers and this page answer in Markdown at their address with .md, or asked for with Accept: text/markdown. Other pages answer in HTML.
  • For agents: around.iw.pe/llms.txt, and every page worth reading in around.iw.pe/sitemap.xml
  • No key. The search API, the MCP server, /openapi.json, /.well-known/api-catalog and /.well-known/mcp.json answer with Access-Control-Allow-Origin: *. Of the addresses on this page, only the search API has a rate limit in the code: 60 requests in 60 seconds per IP address, counted in each copy of the Worker's memory; past it, 429 {"error":"too_many"}. search_businesses counts in it too, and past it there is no 429: the HTTP answer is 200, and the tools/call result has isError: true and the text {"error":"too_many"}. Nothing else on this page has a limit in the code: please be gentle (one request at a time, keep what you read, use the sitemap rather than walking the country through the search).
  • Data: businesses that joined write and update their own details. The rest come from open data: © OpenStreetMap contributors (ODbL), Overture Maps Foundation (CDLA-Permissive-2.0), and the business-licensing registers of Tel Aviv-Yafo (municipal open data), Be'er Sheva (data.gov.il) and Kfar Saba (ODbL); and, for some, what the business's own website says (treatments, prices, a booking link), as WIPE read it. Each search result's source names the licence of the open-data record its row came from (WIPE when none is recorded), and about credits every source.
  • Businesses: any business can take its page for free with a WIPE account (״זה העסק שלך?״ on its page), prove it is theirs by what the page lists (a code sent to its email, or put in its Instagram bio or on its website, or a call to its number) and, at once or once a person at WIPE confirms, correct what it shows. For a page with none of these, write to support@iw.pe; a page from a WIPE site is updated from that site. The API, the MCP server and the Markdown read the same data as the page, except what the page loads from Google for people browsing it (a rating, reviews, a photo). Anyone can report a wrong detail from a business's page, and a person reads each report. around.iw.pe/for-business
  • Privacy: the search API and the MCP server write nothing of a request to Around's database: not the words, not the town or the trade, not who asked. The search counts shown to business owners come only from searches on the map, by town and trade, never the words. For the rate limit, the caller's IP address and the times of its requests are held in the memory of the copy of the Worker that answered, and Around's code writes it nowhere. Cloudflare, which runs Around, keeps a log of each request for a few days (Workers Logs): its address with its parameters, a search's words included, and its headers, which can include the IP address. Request bodies are not in it, so neither is what is sent to the MCP server. Cloudflare's own traffic analytics for the domain also record requests: the address asked for and who asked, such as which AI assistant.
  • Contact: support@iw.pe