Check an MCP server for conformance and disclosure
check_conformanceRead-only
Measure a public MCP endpoint against five conditions: it speaks MCP, it publishes an A2A agent card, it declares who pays it, identical input returns identical output, and the verdict itself can be recomputed by anyone. Free, no key. Conformance and disclosure only; this says nothing about whether any figure the checked server returns is correct. By default no tool on the checked server is called, so determinism comes back as not measured rather than guessed. It is measured when the owner has published /.well-known/mcp-conduct.json with allow_tool_call true.
Input Schema
TableJSON Schema
| Name | Required | Description | Default |
|---|---|---|---|
| endpoint | Yes | https URL of the MCP endpoint to measure | |
| allow_tool_call | No | Kept for compatibility. Since 2026-10-08 an assertion alone calls no tool: consent is proven only by the owner's /.well-known/mcp-conduct.json. Default false. |
Output Schema
TableJSON Schema
| Name | Required | Description | Default |
|---|---|---|---|
| gate | No | Name of this gate. | |
| checks | No | One entry per condition, each with whether it was measured, whether it passed, and the detail. | |
| status | No | verified = every measured condition passed. pending = measured, not all passing. held = could not be reached, nothing established. | |
| endpoint | No | The MCP endpoint that was measured. | |
| reachable | No | Three-valued on purpose (gate58). true = measured and answered. false = measured and did not answer. null = NOT MEASURED. null is never to be read as a failing endpoint; it means this gate has nothing to say. | |
| checked_at | No | When the measurement started, ISO 8601 UTC. | |
| probed_via | No | The network path the probe took (relay or direct). | |
| scope_note | No | What this measurement covers and what it does not. | |
| establishes | No | What this verdict establishes, as sentences. | |
| gate_commit | No | Git commit of the deployed gate, or a sentence saying the deployment did not pin one. | |
| gate_version | No | Version of the gate code that took this measurement. | |
| tools_called | No | Whether a tool on the checked server was executed, in words. | |
| consent_basis | No | On what basis a tool call was or was not made. | |
| number_safety | No | Whether every number in this verdict survives a JSON round trip unchanged. | |
| record_sha256 | No | Hash of this verdict with record_sha256 and recompute_note removed. Recompute it yourself; verify_verdict does the same arithmetic. | |
| consent_lookup | No | Present when no proven consent was found: the consent file that was read, the result, and how to consent. | |
| consent_source | No | Where the consent came from: operator_list, well_known, requester or none. | |
| recompute_note | No | How to recompute record_sha256. Not part of the hashed bytes. | |
| canonicalization | No | Condition 07, disclosed and never a verdict: whether the declared tool surface canonicalizes under RFC 8785. | |
| measurement_note | No | Present only when the gate's own relay failed, so that nothing here is read as a statement about the target. | |
| absence_vs_failure | No | Condition 06, disclosed and never a verdict: whether the server's tools can tell a failed lookup from an empty one. | |
| does_not_establish | No | What this verdict does not establish, as sentences. | |
| coordinate_derivation | No | How the measured tool and instant were derived, or that the legacy rule applied. | |
| consent_assertion_ignored | No | Present when the request set allow_tool_call true without proven consent: the assertion was recorded and no tool was called. |