Skip to main content
Glama

MCP Verification Gate: check an MCP server or an A2A agent before you connect or delegate

Check an MCP server for conformance and disclosure

check_conformance
Read-only

Measure a public MCP endpoint against five conditions: it speaks MCP, it publishes an A2A agent card, it declares who pays it, identical input returns identical output, and the verdict itself can be recomputed by anyone. Free, no key. Conformance and disclosure only; this says nothing about whether any figure the checked server returns is correct. By default no tool on the checked server is called, so determinism comes back as not measured rather than guessed. It is measured when the owner has published /.well-known/mcp-conduct.json with allow_tool_call true.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
endpointYeshttps URL of the MCP endpoint to measure
allow_tool_callNoKept for compatibility. Since 2026-10-08 an assertion alone calls no tool: consent is proven only by the owner's /.well-known/mcp-conduct.json. Default false.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
gateNoName of this gate.
checksNoOne entry per condition, each with whether it was measured, whether it passed, and the detail.
statusNoverified = every measured condition passed. pending = measured, not all passing. held = could not be reached, nothing established.
endpointNoThe MCP endpoint that was measured.
reachableNoThree-valued on purpose (gate58). true = measured and answered. false = measured and did not answer. null = NOT MEASURED. null is never to be read as a failing endpoint; it means this gate has nothing to say.
checked_atNoWhen the measurement started, ISO 8601 UTC.
probed_viaNoThe network path the probe took (relay or direct).
scope_noteNoWhat this measurement covers and what it does not.
establishesNoWhat this verdict establishes, as sentences.
gate_commitNoGit commit of the deployed gate, or a sentence saying the deployment did not pin one.
gate_versionNoVersion of the gate code that took this measurement.
tools_calledNoWhether a tool on the checked server was executed, in words.
consent_basisNoOn what basis a tool call was or was not made.
number_safetyNoWhether every number in this verdict survives a JSON round trip unchanged.
record_sha256NoHash of this verdict with record_sha256 and recompute_note removed. Recompute it yourself; verify_verdict does the same arithmetic.
consent_lookupNoPresent when no proven consent was found: the consent file that was read, the result, and how to consent.
consent_sourceNoWhere the consent came from: operator_list, well_known, requester or none.
recompute_noteNoHow to recompute record_sha256. Not part of the hashed bytes.
canonicalizationNoCondition 07, disclosed and never a verdict: whether the declared tool surface canonicalizes under RFC 8785.
measurement_noteNoPresent only when the gate's own relay failed, so that nothing here is read as a statement about the target.
absence_vs_failureNoCondition 06, disclosed and never a verdict: whether the server's tools can tell a failed lookup from an empty one.
does_not_establishNoWhat this verdict does not establish, as sentences.
coordinate_derivationNoHow the measured tool and instant were derived, or that the legacy rule applied.
consent_assertion_ignoredNoPresent when the request set allow_tool_call true without proven consent: the assertion was recorded and no tool was called.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed2 schema fields changed
    • changedInput schema / properties / allow_tool_call / description
      Previous value: -"Consent to executing one tool on the checked server, twice, with empty arguments. Only set this for a server you own. Default false."New value: +"Kept for compatibility. Since 2026-10-08 an assertion alone calls no tool: consent is proven only by the owner's /.well-known/mcp-conduct.json. Default false."
    • addedOutput schema / properties / consent_assertion_ignored
      Added value: +{
      +  "description": "Present when the request set allow_tool_call true without proven consent: the assertion was recorded and no tool was called.",
      +  "type": "object"
      +}
  2. Changed24 schema fields changed
    • addedOutput schema / properties / absence_vs_failure
      Added value: +{
      +  "description": "Condition 06, disclosed and never a verdict: whether the server's tools can tell a failed lookup from an empty one.",
      +  "type": "object"
      +}
    • addedOutput schema / properties / canonicalization
      Added value: +{
      +  "description": "Condition 07, disclosed and never a verdict: whether the declared tool surface canonicalizes under RFC 8785.",
      +  "type": "object"
      +}
    • addedOutput schema / properties / checked_at
      Added value: +{
      +  "description": "When the measurement started, ISO 8601 UTC.",
      +  "type": "string"
      +}
    • addedOutput schema / properties / checks
      Added value: +{
      +  "description": "One entry per condition, each with whether it was measured, whether it passed, and the detail.",
      +  "type": "object"
      +}
    • removedOutput schema / properties / conditions
      Removed value: -{
      -  "type": [
      -    "array",
      -    "object"
      -  ]
      -}
    • addedOutput schema / properties / consent_basis
      Added value: +{
      +  "description": "On what basis a tool call was or was not made.",
      +  "type": "string"
      +}
    • addedOutput schema / properties / consent_lookup
      Added value: +{
      +  "description": "Present when no proven consent was found: the consent file that was read, the result, and how to consent.",
      +  "type": "object"
      +}
    • addedOutput schema / properties / consent_source
      Added value: +{
      +  "description": "Where the consent came from: operator_list, well_known, requester or none.",
      +  "type": "string"
      +}
    • addedOutput schema / properties / coordinate_derivation
      Added value: +{
      +  "description": "How the measured tool and instant were derived, or that the legacy rule applied.",
      +  "type": "object"
      +}
    • addedOutput schema / properties / does_not_establish
      Added value: +{
      +  "description": "What this verdict does not establish, as sentences.",
      +  "type": "array"
      +}
    • addedOutput schema / properties / endpoint / description
      Added value: +"The MCP endpoint that was measured."
    • addedOutput schema / properties / establishes
      Added value: +{
      +  "description": "What this verdict establishes, as sentences.",
      +  "type": "array"
      +}
    • addedOutput schema / properties / gate
      Added value: +{
      +  "description": "Name of this gate.",
      +  "type": "string"
      +}
    • addedOutput schema / properties / gate_commit
      Added value: +{
      +  "description": "Git commit of the deployed gate, or a sentence saying the deployment did not pin one.",
      +  "type": "string"
      +}
    • addedOutput schema / properties / gate_version
      Added value: +{
      +  "description": "Version of the gate code that took this measurement.",
      +  "type": "string"
      +}
    • addedOutput schema / properties / measurement_note
      Added value: +{
      +  "description": "Present only when the gate's own relay failed, so that nothing here is read as a statement about the target.",
      +  "type": "string"
      +}
    • addedOutput schema / properties / number_safety
      Added value: +{
      +  "description": "Whether every number in this verdict survives a JSON round trip unchanged.",
      +  "type": "object"
      +}
    • removedOutput schema / properties / pass
      Removed value: -{
      -  "type": [
      -    "boolean",
      -    "null"
      -  ]
      -}
    • addedOutput schema / properties / probed_via
      Added value: +{
      +  "description": "The network path the probe took (relay or direct).",
      +  "type": "string"
      +}
    • addedOutput schema / properties / reachable / type
      Added value: +[
      +  "boolean",
      +  "null"
      +]
    • addedOutput schema / properties / recompute_note / description
      Added value: +"How to recompute record_sha256. Not part of the hashed bytes."
    • addedOutput schema / properties / scope_note
      Added value: +{
      +  "description": "What this measurement covers and what it does not.",
      +  "type": "string"
      +}
    • addedOutput schema / properties / status
      Added value: +{
      +  "description": "verified = every measured condition passed. pending = measured, not all passing. held = could not be reached, nothing established.",
      +  "type": "string"
      +}
    • addedOutput schema / properties / tools_called
      Added value: +{
      +  "description": "Whether a tool on the checked server was executed, in words.",
      +  "type": "string"
      +}
  3. Changed1 schema field changed
    • changedOutput schema / (root)
      Previous value: -nullNew value: +{
      +  "additionalProperties": true,
      +  "properties": {
      +    "conditions": {
      +      "type": [
      +        "array",
      +        "object"
      +      ]
      +    },
      +    "endpoint": {
      +      "type": "string"
      +    },
      +    "pass": {
      +      "type": [
      +        "boolean",
      +        "null"
      +      ]
      +    },
      +    "reachable": {
      +      "description": "Three-valued on purpose (gate58). true = measured and answered. false = measured and did not answer. null = NOT MEASURED. null is never to be read as a failing endpoint; it means this gate has nothing to say."
      +    },
      +    "recompute_note": {
      +      "type": "string"
      +    },
      +    "record_sha256": {
      +      "description": "Hash of this verdict with record_sha256 and recompute_note removed. Recompute it yourself; verify_verdict does the same arithmetic.",
      +      "type": "string"
      +    }
      +  },
      +  "type": "object"
      +}
  4. First observed

TDQS

Score is being calculated.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.