How we check
Every number on this site comes from one of four sources, and every page says which one and when it was read.
1. The official MCP registry
We read every entry from the official MCP registry through its public API. Last read: 2026-10-03, 38,992 servers. Names, descriptions, versions, endpoints and packages are shown as the publisher wrote them.
2. The handshake check
For each active server that lists a Streamable HTTP endpoint, we open an MCP connection and ask for its tool list. That is all:
- We never call a tool, read a resource or send any user data.
- We try the 2026 protocol first and fall back to the 2025 handshake, the same way a current client does.
- At most one open connection per host, so a host that serves many entries is not flooded.
- Requests carry the user agent
agora-probe/0.1 (+https://openforallofus.com/probe). - A server gets 12 seconds. Failures for a network reason are checked again before they are counted.
Last check: 2026-10-04. Of 22,587 endpoints checked, 14,029 completed the handshake, 6,007 asked for sign-in, 63 asked for payment and 2,488 did not complete the handshake (no response, an HTTP error, or a reply that is not valid MCP). 537 rate-limited us and are counted as unknown.
A server that answers the handshake is up. It is not thereby safe, correct or well behaved. Servers that run on your own machine (npm, PyPI, Docker packages) cannot be checked from outside and are marked so.
3. GitHub
For servers that link a GitHub repository we read stars, last push, licence and whether it is archived, through the GitHub API. Last read: 2026-10-04. 3,463 of 23,013 linked repositories did not resolve.
4. Signed reports
Anyone who runs a gate that signs its decisions can report that a server works, is broken or is unsafe, and attach the signed record. We verify the signature against the reporter's public key with the open @cedulon/core verifier. A signed report shows a call went through that gate; today it does not prove which server answered, and the page says so. How to file one.
What we hide from search engines
Every server has a page, but we ask search engines to index only pages where we add something: a successful check or a live repository. Entries that look like tests, sit behind temporary tunnels, copy one template many times, come from a namespace with more than 500 entries, or link a missing repository are kept out of the index. Today 25,011 of 38,992 pages are indexable.
If you run a server
To stop the check against your endpoint, or to correct anything on your page, write to hello@openforallofus.com or open an issue on GitHub.