Skip to content
MCP Vetted

Agent quickstart

One address, nine tools, no account. Your agent can search, compare and install on its own.

Connect

The MCP server speaks Streamable HTTP and needs no sign-in.

https://mcpvetted.com/api/mcp
  • Claude (web or desktop): Settings, Connectors, Add custom connector, paste the address.
  • Claude Code: claude mcp add --transport http mcpvetted https://mcpvetted.com/api/mcp
  • Cursor: one-click install, or add {"url": "https://mcpvetted.com/api/mcp"} to mcp.json.
  • VS Code: one-click install, or code --add-mcp.

The nine tools

ToolKindWhat it does
search_toolsreadSearches the vetted index of MCP servers by keyword or by the job a tool does. Returns each result's trust tier, observed access, check results and trust page URL.
get_toolreadReturns one indexed tool by slug, registry name or server URL: versions, tier history, observed access and supported apps.
get_trust_reportreadReturns each check's verdict and findings for one version of a tool, with the rules version and when each check ran.
compare_toolsreadCompares 2 to 5 tools side by side on tier, observed access, agent-reported outcomes and latest release.
get_install_configreadReturns the exact install link, command or config block one app accepts for a tool, pinned to the vetted version, plus the access to show the user before installing. Records an install id for outcome reports.
check_policyreadChecks one tool against a minimum tier and a list of blocked access types, and returns allow or deny with the reasons.
list_revocationsreadLists tool versions revoked after failing a check, newest first, optionally since a date or for specific tools.
submit_urlwriteAdds a tool to the index from an address: a remote MCP server URL, a domain, a GitHub repo, or an npm or PyPI package. Reads the server's self-description without calling its tools, then runs the standard checks.
report_outcomewriteRecords whether a tool did its job after an install made with get_install_config. Reports from distinct agents feed the Proven tier.

Every tool declares an output schema and returns structured content plus a one-line summary. Full schemas: API reference.

A typical flow

  1. search_tools with the job, e.g. schedule LinkedIn posts, and min_tier: "scanned".
  2. compare_tools on the top two or three.
  3. get_install_config for the user's app. Show the access list before installing, and keep the install_id.
  4. After using the tool, report_outcome with that install_id. These reports build the Proven tier.

REST API

The same operations over HTTP, described in /openapi.json.

curl "https://mcpvetted.com/api/v1/search?q=calendar&min_tier=scanned&limit=3"
curl "https://mcpvetted.com/api/v1/tools/<slug>/trust"
curl "https://mcpvetted.com/api/v1/tools/<slug>/install?client=cursor"
curl -X POST "https://mcpvetted.com/api/v1/submit" -H "content-type: application/json" -d '{"url":"example.com/mcp"}'

Registry API for companies

Point VS Code and Copilot's MCP registry setting at https://mcpvetted.com/api/registry. It serves the MCP Registry v0.1 shape with only Scanned-and-up, unrevoked servers; our tier and check date ride in _meta["com.mcpvetted/trust"].

Rate limits and errors

Anonymous callers get 1,000 calls a day; an API key we issue (ask at the support address), sent in X-API-Key, raises that to 20,000. Submissions are limited to 20 an hour. Every response carries X-RateLimit-Limit, -Remaining and -Reset.

Errors say what was wrong and how to fix the call: REST returns { "error": { "code", "message", "hint" } }; MCP returns a tool result with isError: true and the same text.

For crawlers

/llms.txt summarizes the service, and every trust page has a Markdown twin at /t/<slug>.md.