Agent quickstart
Connect
The MCP server speaks Streamable HTTP and needs no sign-in.
https://mcpvetted.com/api/mcp- Claude (web or desktop): Settings, Connectors, Add custom connector, paste the address.
- Claude Code:
claude mcp add --transport http mcpvetted https://mcpvetted.com/api/mcp - Cursor: one-click install, or add
{"url": "https://mcpvetted.com/api/mcp"}tomcp.json. - VS Code: one-click install, or
code --add-mcp.
The nine tools
| Tool | Kind | What it does |
|---|---|---|
search_tools | read | Searches the vetted index of MCP servers by keyword or by the job a tool does. Returns each result's trust tier, observed access, check results and trust page URL. |
get_tool | read | Returns one indexed tool by slug, registry name or server URL: versions, tier history, observed access and supported apps. |
get_trust_report | read | Returns each check's verdict and findings for one version of a tool, with the rules version and when each check ran. |
compare_tools | read | Compares 2 to 5 tools side by side on tier, observed access, agent-reported outcomes and latest release. |
get_install_config | read | Returns the exact install link, command or config block one app accepts for a tool, pinned to the vetted version, plus the access to show the user before installing. Records an install id for outcome reports. |
check_policy | read | Checks one tool against a minimum tier and a list of blocked access types, and returns allow or deny with the reasons. |
list_revocations | read | Lists tool versions revoked after failing a check, newest first, optionally since a date or for specific tools. |
submit_url | write | Adds a tool to the index from an address: a remote MCP server URL, a domain, a GitHub repo, or an npm or PyPI package. Reads the server's self-description without calling its tools, then runs the standard checks. |
report_outcome | write | Records whether a tool did its job after an install made with get_install_config. Reports from distinct agents feed the Proven tier. |
Every tool declares an output schema and returns structured content plus a one-line summary. Full schemas: API reference.
A typical flow
search_toolswith the job, e.g. schedule LinkedIn posts, andmin_tier: "scanned".compare_toolson the top two or three.get_install_configfor the user's app. Show the access list before installing, and keep theinstall_id.- After using the tool,
report_outcomewith thatinstall_id. These reports build the Proven tier.
REST API
The same operations over HTTP, described in /openapi.json.
curl "https://mcpvetted.com/api/v1/search?q=calendar&min_tier=scanned&limit=3"
curl "https://mcpvetted.com/api/v1/tools/<slug>/trust"
curl "https://mcpvetted.com/api/v1/tools/<slug>/install?client=cursor"
curl -X POST "https://mcpvetted.com/api/v1/submit" -H "content-type: application/json" -d '{"url":"example.com/mcp"}'Registry API for companies
Point VS Code and Copilot's MCP registry setting at https://mcpvetted.com/api/registry. It serves the MCP Registry v0.1 shape with only Scanned-and-up, unrevoked servers; our tier and check date ride in _meta["com.mcpvetted/trust"].
Rate limits and errors
Anonymous callers get 1,000 calls a day; an API key we issue (ask at the support address), sent in X-API-Key, raises that to 20,000. Submissions are limited to 20 an hour. Every response carries X-RateLimit-Limit, -Remaining and -Reset.
Errors say what was wrong and how to fix the call: REST returns { "error": { "code", "message", "hint" } }; MCP returns a tool result with isError: true and the same text.
For crawlers
/llms.txt summarizes the service, and every trust page has a Markdown twin at /t/<slug>.md.