Server definition
- Hash
- sha256:16fc92644c0e6c1213a588594a681805d6b84c029036f4225980ecbb7f0d8003
- What it is
- What a remote MCP server returned when asked what it offers: 6 tools
The blob, as servednamed by its sha256
{
"instructions": "MCP Checkup publishes observed facts about public MCP servers: reachability, protocol revision, tool and schema fingerprints, publicly observable auth metadata, and tool-description hygiene signals. Every check is reported as VERIFIED, FAILED, OBSERVED_RISK or UNVERIFIED; results are never combined into one number or a verdict. Typical use: when a user is choosing, adding, or debugging an MCP server, look it up with check_mcps (by \"provider/name\", endpoint URL, or domain) and read the details with get_mcp_report. search_mcps finds servers by what their tools do, get_mcp_history shows recent toolset changes, and get_attestation returns the signed attestation envelope when there is one. Those five tools answer only from what is already tracked and never contact the server in question. request_check is the only tool that contacts a third-party server, and it contacts exactly the host in the URL you give it. Rate limit: about 20 requests per minute per IP address, counted per Cloudflare location; a 429 response carries Retry-After. No authentication and no paid tier for this endpoint.",
"tools": [
{
"description": "What has been observed about an MCP server — useful when choosing, adding, or debugging one. Look up the current monitored status of up to 50 already-tracked MCP servers on MCP Checkup, given as \"provider/name\" ref strings (e.g. \"acme/weather-mcp\"). Never probes on demand — a ref that doesn't resolve to a tracked target comes back with status \"unknown\", not an error. Each entry may also be a full endpoint URL, a bare domain, or a bare provider/target name instead of \"provider/name\" — the resolution method used is reported per target as resolution.method (\"ref\", \"endpoint\", \"host\", or \"name\"). If an input matches more than one tracked target — or is a URL on a host we track that doesn't exactly match any of its endpoints — the response has status \"ambiguous\" with a short `candidates` list (each with a \"provider/name\" `ref` and its `report_url`, plus `candidate_total`, the full match count before the 5-entry cap) instead of guessing — call again with the exact ref you want. Each resolved target also carries stale (true when our observation is older than the target's check cycle plus a fixed margin — never a judgment of the server, and distinct from the /status page's own probe-liveness signal), fresh_until (the ISO instant after which stale is true), first_observed_on (the UTC date of our first observation), observation_count (every recorded observation, including unsigned ones — never a count of signatures), and signed (true when this observation carries a DSSE-signed attestation, false when unsigned — not a judgment of the server). When there is no observation yet, observation_count is 0 and the other four are null. Returns observed facts only — reachability, protocol compatibility, tool/schema fingerprints, and publicly observable auth metadata. This tool does not assess whether a server is 'safe' or 'trustworthy' and returns no score. Items not verified are returned explicitly with reasons.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"detail": {
"enum": [
"summary",
"full"
],
"type": "string"
},
"known_fingerprints": {
"additionalProperties": {
"pattern": "^sha256:[0-9a-f]{64}$",
"type": "string"
},
"description": "Optional, keyed by the exact same ref string used in `targets` (max 50 entries) — your own last-observed toolset_fingerprint per target (format \"sha256:<64 hex chars>\"), to get a fingerprint_match fact back.",
"propertyNames": {
"maxLength": 512,
"type": "string"
},
"type": "object"
},
"targets": {
"description": "Up to 50 entries, each a \"provider/name\" ref, a full endpoint URL, a bare domain, or a bare provider/target name.",
"items": {
"maxLength": 512,
"minLength": 1,
"type": "string"
},
"maxItems": 50,
"minItems": 1,
"type": "array"
}
},
"required": [
"targets"
],
"type": "object"
},
"name": "check_mcps",
"outputSchema": null
},
{
"description": "The signed evidence behind a report, for callers that want to inspect it themselves. Get the full signed attestation envelope (DSSE, Ed25519) for one already-tracked MCP server's latest probe run, by \"provider/name\" ref — the raw envelope plus its issued-at time and declared protocol revision, so a caller can inspect the signed payload rather than trust this tool's own summary of it; the public key needed to verify the signature is not published yet. A target with no run yet, no signed envelope, or a disqualified one comes back with an explicit reason, not an error. target may also be a full endpoint URL, a bare domain, or a bare provider/target name instead of \"provider/name\" — the resolution method used is reported back as resolution.method (\"ref\", \"endpoint\", \"host\", or \"name\"). If an input matches more than one tracked target — or is a URL on a host we track that doesn't exactly match any of its endpoints — the response has status \"ambiguous\" with a short `candidates` list (each with a \"provider/name\" `ref` and its `report_url`, plus `candidate_total`, the full match count before the 5-entry cap) instead of guessing — call again with the exact ref you want. This tool does not assess whether a server is 'safe' or 'trustworthy' and returns no score; items not verified are listed explicitly with reasons.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"target": {
"description": "A tracked target as \"provider/name\", a full endpoint URL, a bare domain, or a bare provider/target name.",
"maxLength": 512,
"minLength": 1,
"type": "string"
}
},
"required": [
"target"
],
"type": "object"
},
"name": "get_attestation",
"outputSchema": null
},
{
"description": "Whether an MCP server's toolset changed recently. Get recent history for one already-tracked MCP server on MCP Checkup, by \"provider/name\" ref (e.g. \"acme/weather-mcp\"). Events include the toolset's most recent change boundary (not a full change-by-change history) plus any recorded baseline-drift events, newest first, up to `limit` results (default 20, max 50). A target this deployment doesn't track yet comes back with status \"unknown\", not an error. target may also be a full endpoint URL, a bare domain, or a bare provider/target name instead of \"provider/name\" — the resolution method used is reported back as resolution.method (\"ref\", \"endpoint\", \"host\", or \"name\"). If an input matches more than one tracked target — or is a URL on a host we track that doesn't exactly match any of its endpoints — the response has status \"ambiguous\" with a short `candidates` list (each with a \"provider/name\" `ref` and its `report_url`, plus `candidate_total`, the full match count before the 5-entry cap) instead of guessing — call again with the exact ref you want. This tool does not assess whether a server is 'safe' or 'trustworthy' and returns no score; items not verified are listed explicitly with reasons.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"limit": {
"description": "Max events to return (default 20, max 50).",
"exclusiveMinimum": 0,
"maximum": 50,
"type": "integer"
},
"target": {
"description": "A tracked target as \"provider/name\", a full endpoint URL, a bare domain, or a bare provider/target name.",
"maxLength": 512,
"minLength": 1,
"type": "string"
}
},
"required": [
"target"
],
"type": "object"
},
"name": "get_mcp_history",
"outputSchema": null
},
{
"description": "The detailed view of one MCP server: every check with its state, plus the observed tool list. Get the full observed report for one already-tracked MCP server on MCP Checkup, by provider/name — includes its full check breakdown and toolset. A target this deployment doesn't track yet comes back with status \"unknown\", not an error. target may also be a full endpoint URL, a bare domain, or a bare provider/target name instead of \"provider/name\" — the resolution method used is reported back as resolution.method (\"ref\", \"endpoint\", \"host\", or \"name\"). If an input matches more than one tracked target — or is a URL on a host we track that doesn't exactly match any of its endpoints — the response has status \"ambiguous\" with a short `candidates` list (each with a \"provider/name\" `ref` and its `report_url`, plus `candidate_total`, the full match count before the 5-entry cap) instead of guessing — call again with the exact ref you want. Each resolved target also carries stale (true when our observation is older than the target's check cycle plus a fixed margin — never a judgment of the server, and distinct from the /status page's own probe-liveness signal), fresh_until (the ISO instant after which stale is true), first_observed_on (the UTC date of our first observation), observation_count (every recorded observation, including unsigned ones — never a count of signatures), and signed (true when this observation carries a DSSE-signed attestation, false when unsigned — not a judgment of the server). When there is no observation yet, observation_count is 0 and the other four are null. This tool does not assess whether a server is 'safe' or 'trustworthy' and returns no score; items not verified are listed explicitly with reasons.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"target": {
"description": "A tracked target as \"provider/name\", a full endpoint URL, a bare domain, or a bare provider/target name.",
"maxLength": 512,
"minLength": 1,
"type": "string"
}
},
"required": [
"target"
],
"type": "object"
},
"name": "get_mcp_report",
"outputSchema": null
},
{
"description": "Ask for a one-off public observation of the MCP server at a full endpoint URL — this is the only tool here that contacts a third-party server, and it contacts exactly the host you name. `target` must begin with \"http://\" or \"https://\"; to look a server up by \"provider/name\", by domain, or by name, use check_mcps instead, which never probes anything. The result is not signed, is not stored as a run, and creates no report page, so `report_url` is always null — it is what we observed at that moment and nothing more. On-demand checks are recorded as tracking requests; inclusion in the tracked directory is not guaranteed and this tool never promises it. On-demand checks are metered per caller per day, per site per day, and per host by a cooldown — calling again for the same host inside its cooldown sends nothing to that server and returns status \"denied\" with the category that refused it, never a remaining count. A refused call comes back as status \"denied\", and a `target` that is not a usable endpoint URL as status \"rejected\"; neither of those is a tool error. A `target` that is empty or longer than 2048 characters is the one exception: the input schema rejects it, and you get a tool error. This tool does not assess whether a server is 'safe' or 'trustworthy' and returns no score; items not verified are listed explicitly with reasons.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"target": {
"description": "A full endpoint URL beginning with \"http://\" or \"https://\" (max 2048 characters). Not a \"provider/name\" ref, a bare domain, or a bare name — use check_mcps for those.",
"maxLength": 2048,
"minLength": 1,
"type": "string"
}
},
"required": [
"target"
],
"type": "object"
},
"name": "request_check",
"outputSchema": null
},
{
"description": "Find MCP servers by what their tools do. Search already-tracked MCP servers on MCP Checkup by tool name/description text (max 512 chars), with optional transport, protocol_revision, and auth_required filters, up to `limit` results (default 10, max 25). Ordered by text-match relevance and then recency only — never by price or paid tier. Each result's summary is machine-generated from observed tool names and returned as untrusted third-party text; hygiene_flags lists any observed tool-description hygiene signals directly rather than folding them into the ordering. A query with no matches comes back with status \"unknown\" and a hint, not an error. Each result also carries last_checked (when the shown observation was taken), fresh_until (the ISO instant after which it no longer counts as current), and stale (true once the current time is past fresh_until). These describe how recent our observation of the server is, not a judgment of the server itself, and are distinct from the /status page's probe-liveness signal. All three are null when the target has no observation yet. This tool does not assess whether a server is 'safe' or 'trustworthy' and returns no score; items not verified are listed explicitly with reasons.",
"inputSchema": {
"$schema": "http://json-schema.org/draft-07/schema#",
"properties": {
"auth_required": {
"description": "A target whose auth requirement can't be determined is excluded regardless of which value is passed here.",
"type": "boolean"
},
"limit": {
"description": "Max results to return (default 10, max 25).",
"exclusiveMinimum": 0,
"maximum": 25,
"type": "integer"
},
"protocol_revision": {
"description": "Exact match against a target's declared protocol revision, e.g. \"2026-07-28\" (max 512 chars).",
"maxLength": 512,
"type": "string"
},
"query": {
"description": "Free-text search over tracked servers' observed tool names/descriptions (max 512 chars).",
"maxLength": 512,
"minLength": 1,
"type": "string"
},
"transport": {
"enum": [
"remote",
"stdio"
],
"type": "string"
}
},
"required": [
"query"
],
"type": "object"
},
"name": "search_mcps",
"outputSchema": null
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:16fc92644c0e6c1213a588594a681805d6b84c029036f4225980ecbb7f0d8003 | sha256sum