mcpcensus

Check an MCP server before you install

Health and ownership for 27,000+ servers. Every claim links to public evidence. Look one up, audit your whole config, or let your agent check before every call. Free to try.

free · 10/day · no signup·Lookup·Preflight·Audit a config·API for agents

manual install·developers·prompt.md·llms.txt

32,763
servers
12,988
GitHub
3,874
issues
19,254
remotes

Current daily projection · source 2026-09-13 17:41:05 · generated 2026-09-13T17:41:08.381Z

new in the registry
loading…
  • loading…

Directories list. We check.

Is it the vendor’s server or a lookalike? Still maintained? What can you open as proof?

Forbuilders and agents that install MCP servers
Notstar rankings, black-box scores, or fake logos

How we differ → · Policy preflight → · Live coverage →

for agents

Your agent checks. Every time.

One call audits a whole MCP config. One rule line makes the agent run it before every install or tool call. One cursor tells it what changed since last time. Nothing to remember, nothing to re-read.

AuditPOST /v1/audit · .mcp.json in, one verdict per server out
VerdictsPASS · REVIEW · BLOCK · UNKNOWN, with reasons and an exit code
Ruleone line in CLAUDE.md, AGENTS.md or .cursor/rules
ChangesGET /v1/changes?since=cursor · unmetered
CIcensus-preflight.yml · fails the PR on BLOCK
Cost1 credit per config per day · keyless: one config a day
# the whole recurrence mechanism — paste into your agent's instructions
Before adding, enabling or calling any MCP server, run a Census stamp. Stop on BLOCK. Ask on REVIEW.

Audit your config → · Claude Code, Codex, Cursor, VS Code → · GitHub Action →

changes

What changed since you last looked

Every cron writes what it saw: a server appears in the registry, a hosted endpoint goes down or comes back, a tool list changes, health or verification flips, an endpoint moves. Pull it with a cursor. No key, no credits.

live · last 24 h
loading…
  • loading…
PullGET /v1/changes?since=cursor or census_changes
PushPOST /v1/watch · one server to your webhook · API key

Feed contract → · Watch docs → · llms.txt →

findings

16% have a verified problem

Gone repo, archived, deprecated package, or no push in 6+ months. Unknown stays unknown.

Healthy (repo active <6mo)10,444Unknown (insufficient eviden2,496Has verified issues2,442
View as table
VerdictServers
Healthy (repo active <6mo)10,444
Unknown (insufficient evidence)2,496
Has verified issues2,442
Problems by type · categories
GitHub repo gone (deleted/pr1,880No repo push in 6+ months299npm package deprecated218registry_deprecated166GitHub repo archived126npm package missing25PyPI package missing15
View as table
ProblemServers
GitHub repo gone (deleted/private)1,880
No repo push in 6+ months299
npm package deprecated218
registry_deprecated166
GitHub repo archived126
npm package missing25
PyPI package missing15
dev-tools11,697ai-ml1,943api-integration1,672security864finance847communication544media536files-documents461data-analytics406databases399weather-geo377productivity302
View as table
CategoryServers
dev-tools11,697
ai-ml1,943
api-integration1,672
security864
finance847
communication544
media536
files-documents461
data-analytics406
databases399
weather-geo377
productivity302

Full report → · Live coverage →

pricing

Free to check. Credits when agents run at scale.

Anonymous10 unique lookups/day · no account
Free1,000 credits/month · account + API key
Builder$19/mo · 2,000 credits
Pack$9 · 1,000 never-expire credits

Team $49/mo · 10,000 credits. Search/lookup 1 · config audit 1 per config per day · preflight/stamp 5 · watch 10. Repeats same UTC day are free. The change feed is unmetered. A daily audit of a 10-server config stays inside the free grant.

See prices Check a server

faq

Should I install this MCP server?

Look it up first. You get healthy / issues / unknown from repo, package, and registry facts. Not a pen-test. Try free →

Can my agent check automatically?

Yes. Add the rule line above to its instructions. It runs census_stamp for one server or census_audit_config for the whole config before it connects. Stop on BLOCK. Ask on REVIEW. PASS is not a sandbox. Setup →

What does UNKNOWN mean?

The Census has no row for that entry yet: a local script, a Docker image, or a package nobody has submitted. It is not a pass. Packages seen in audits are queued for verification and land in the Census once the evidence holds. Audit contract →

limits

What this is not

The MCP Census is a live registry health and identity check. It is not a full security audit, pen-test, compliance certification, or guarantee that a server is safe to run in production. Unknown means we lack evidence, not that the server is fine. Methodology →

[email protected] · 14-day refunds · ACL applies · no marketing cookies

Support is human. Data is public sources; the product is the live check.

pricing · agent-setup/prompt.md · llms.txt · manual install →