close

Terms & Privacy

Last updated 1 August 2026

mcpscore is a free service that audits an MCP server you point it at and returns a 0–100 quality score. There are no user accounts, and we do not ask you to create a profile or provide a name. We nevertheless process limited technical data as described below.

Who operates this service

mcpscore is an independent project operated by Alex Akimov. For privacy questions, data requests, or questions about these terms, contact feedback@mcpscore.dev.

By submitting an audit or otherwise using the service, you agree to these terms. Nothing here limits rights that cannot be excluded under applicable law.

Acceptable use

You may audit any publicly reachable MCP server — including one you are evaluating before adopting it, or one you depend on and want to keep an eye on. You do not need to own it. That is a large part of what mcpscore is for: knowing whether a server is any good is most useful before you wire it into your agent.

Audits are designed to be non-mutating. mcpscore connects, negotiates the protocol, lists advertised protocol surfaces, and sends diagnostic requests. It never invokes a server’s tools and does not intentionally change server data. The requests may create ordinary traffic and log entries on the target server. We audit public servers ourselves on the same basis.

Two limits, both about not being a nuisance rather than about permission:

  • Audits are rate limited to 30 per hour per IP address. Don’t circumvent that, and don’t use the service to flood, disrupt, or degrade anyone’s server.
  • Non-public targets are off limits. Internal hostnames, loopback, link-local, private, reserved, and other non-public addresses are rejected. Submitted targets must use HTTPS.

Credentials are different. This website never asks for one and cannot accept one — it takes a URL and nothing else. The command-line tool can send a token or header for auditing a server behind authentication, and there the usual rule applies: use credentials that are yours, or that you are authorized to use.

What an audit does to your server

mcpscore establishes an MCP connection where supported, inspects initialization data, lists advertised tools, resources, resource templates, and prompts, and sends read-only diagnostic requests that test protocol behavior. It does not invoke tools, read resource contents, or resolve prompts.

The audit is designed not to mutate application data. It still consumes a small amount of network and server capacity and may appear in access or application logs. We cannot guarantee how a faulty or non-conforming server reacts to otherwise non-mutating requests.

What we store

  • Audit request and report data for 14 days. The audit record contains the submitted server URL, status, score, rule results, timestamps, and error information. The record is deleted automatically 14 days after submission.
  • A durable statistics record. After a completed audit, we separately retain the normalized server URL, the first and most recent completed-audit dates, and the number of completed audits. This record does not contain the report or your IP address. It is retained while we operate cumulative service statistics, including the count shown on the home page, or until we determine it is no longer needed or approve a removal request.
  • Your IP address, transiently. It is hashed and held in a short-lived cache purely to enforce the hourly rate limit. It is not stored alongside audit results and is not used to profile you.
  • Standard server logs from Amazon Web Services, retained for up to one month in production for operation, troubleshooting, and security. We redact URL user information and query strings from our application logs; the scheme, hostname, port, and path may remain.
  • Messages you send us. If you email us, we process your address and message to respond and retain the correspondence as long as reasonably needed to handle the request and maintain an appropriate record.

Reports are public to anyone with the link

Audit results are not secret. Anyone holding a report link can view it, and the badge endpoint returns the latest score for any server URL that has been audited. Don’t audit a server whose URL is itself sensitive — for example one containing a token in the path or query string.

The other side of that: because anyone may audit any public server, a score for your server can exist without you having asked for it. If you believe a report should not be public, write to us and we will consider removal.

Include the report link or exact server URL and the reason for the request. We may ask for information needed to understand or verify the request. Say whether you are asking us to remove a 14-day report, the durable statistics record, or both. Removing current data does not prevent a public server from being audited again later.

Analytics and cookies

We use Google Analytics to understand which pages are useful. It loads only if you accept in the banner. Before consent, no Google Analytics script is loaded, no analytics request is sent, and no analytics cookie is set. After consent, Google Analytics may process page paths, page locations, approximate location, and browser or device information and may set_ga cookies. Advertising storage, advertising user data, and ad personalization remain disabled.

Google acts as an analytics service provider and may process data outside your country under its applicable data-protection safeguards. Analytics information is retained according to the retention setting of our Google Analytics property and Google’s own retention rules. We use it only for aggregate product analysis, not advertising or user profiling. See Google’s Privacy Policy.

Your choice is stored in browser local storage. Auditing works the same either way. You can change the choice at any time:

Current choice: not chosen

Why we process data and your choices

  • We process submitted URLs and reports to provide the audit you requested and make its public report available.
  • We process rate-limit and operational information for our legitimate interests in keeping the service reliable, secure, and resistant to abuse.
  • We maintain the durable server statistics record for our legitimate interest in measuring the service and MCP ecosystem. You may object or request removal.
  • We process Google Analytics data only with your consent.

Depending on applicable law, you may ask to access, correct, erase, restrict, or receive a copy of personal data about you, and may object to processing based on legitimate interests. You may withdraw analytics consent at any time without affecting earlier lawful processing. Contact us at feedback@mcpscore.dev. You may also complain to the data-protection authority where you live or work. These rights can be limited where the data does not identify you or another legal exception applies.

Service availability and changes

Do not circumvent technical limits, interfere with the service, or use it unlawfully. We may reject or suspend abusive traffic and may change, interrupt, or discontinue any part of this free service.

We may update these terms when the service or its data practices change. The date at the top identifies the current version. Material changes will be presented prominently on the site where reasonably practical. If any provision is unenforceable, the remaining provisions continue to apply.

No warranty

The service is provided “as is”, without warranty of any kind. A score is an automated quality assessment against published rules — it is not a security audit, a penetration test, or a certification, and it does not guarantee that a server is safe or fit for any purpose. We may change the rules, the scoring, or the availability of the service at any time. To the fullest extent permitted by law, we are not liable for any damages arising from your use of the service or reliance on a score.

The mcpscore engine is open source under the MIT license; the license terms govern your use of the software itself. See the repository.

Trademarks

mcpscore is an independent project. It is not affiliated with, endorsed by, sponsored by, or certified by the Agentic AI Foundation, the Linux Foundation, Anthropic, or Google.

The Model Context Protocol (MCP) is an open standard governed by the Agentic AI Foundation, a directed fund of the Linux Foundation. “Model Context Protocol” and “MCP” are used here only to identify the protocol that mcpscore audits — a descriptive, nominative use. The specification is published under the MIT license.

“Lighthouse” is a trademark of Google LLC. We describe mcpscore as “Lighthouse for MCP” only to convey what kind of tool it is — a quality score for a thing you build — by analogy to a tool developers already know. We claim no rights in that name and no association with Google.

A score from mcpscore is our own assessment against our own published rules. It is not an official MCP certification, conformance mark, or approval of any kind, and it does not indicate that a server has been reviewed by the Agentic AI Foundation or any standards body.

All other trademarks are the property of their respective owners. If you believe we have used a mark incorrectly, tell us at feedback@mcpscore.dev and we will fix it.

Contact

Questions, corrections, or a request to remove a report: feedback@mcpscore.dev. These terms apply to https://mcpscore.dev.