MCP Server

The MCP Census

com.mcpcensus/census
MCP & Agent Infrastructure Security Public & reachable MCP 2026-07-28

What this MCP does

Vets MCP servers and client configurations with health checks, install-policy preflight verdicts, change monitoring, and signed stamps.

census_audit_config
Audit a whole MCP client config in one call (.mcp.json, claude_desktop_config.json, .cursor/mcp.json, .vscode/mcp.json, Codex config.toml text). Resolves every entry without guessing (url → remote_url, npx → npm package, uvx → PyPI package) and returns one PASS / REVIEW / BLOCK / UNKNOWN verdict per entry under a built-in policy, plus CENSUS-AUDIT/1 text, valid_until_epoch and exit_code (1 on any BLOCK). UNKNOWN is never upgraded to PASS. Cost 1 credit per config per UTC day; keyless callers get one config of ≤25 entries per IP per day. Not a malware scan; PASS is not a sandbox. Strip env/headers before sending.
Open world
Input schema
{'type': 'object', 'required': ['config'], 'properties': {'config': {'anyOf': [{'type': 'object'}, {'type': 'string'}, {'type': 'array'}], 'description': 'The config document: an object with mcpServers | servers | mcp_servers, a list under entries[], or raw text (JSON or Codex config.toml)'}, 'format': {'enum': ['json', 'toml'], 'type': 'string'}, 'strict': {'type': 'boolean', 'default': False, 'description': 'exit_code 2 when any entry is REVIEW or UNKNOWN'}, 'policy_id': {'enum': ['builtin:baseline', 'builtin:first-party', 'builtin:strict'], 'type': 'string', 'default': 'builtin:baseline'}, 'previous_tools_digests': {'type': 'object', 'description': 'alias → tools_digest from your last audit; sets tools_drift per entry', 'additionalProperties': {'type': 'string'}}}, 'additionalProperties': False}
census_changes
The Census change feed (CENSUS-CHANGES/1): observed transitions across every server — server_new, remote_down, remote_up, tools_changed, health_change, verified_change, security, endpoint_moved, registry_status, spec_era_change. Cursor-paginated: pass next_cursor back as since. Filter by events, server_names or namespace_domain. Only real transitions, never 'still fine'. Unmetered in v1; poll hourly. Not a malware scan.
Read only Idempotent
Input schema
{'type': 'object', 'properties': {'limit': {'type': 'integer', 'default': 100, 'maximum': 200, 'minimum': 1}, 'since': {'type': 'string', 'description': 'next_cursor from the previous page, or an RFC 3339 time for the first call'}, 'events': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Event names to include (default all)'}, 'server_names': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Exact canonical names to include (≤50)'}, 'namespace_domain': {'type': 'string', 'description': 'Registrable domain of a DNS-verified namespace, e.g. notion.com'}}, 'additionalProperties': False}
census_coverage
Public transparency report (same payload as GET /v1/coverage). Unmetered. Live D1 census/identity/remote/protocol/adoption/pipeline counts plus method notes — never invents completeness percentages or a brand_audit punch list.
Input schema
{'type': 'object', 'properties': {}}
census_credits
Show remaining Census credits for this API key (wallet after the UTC-month grant). Unmetered. Without a key, returns anonymous unique-per-day remaining — not a wallet.
Input schema
{'type': 'object', 'properties': {}}
census_lookalikes
Contested identity for one exact server_name: official_for, name_collision_count, and up to 10 other census server_name values sharing the same namespace brand or tail. Never invents lookalikes. Cost 1.
Input schema
{'type': 'object', 'required': ['server_name'], 'properties': {'server_name': {'type': 'string', 'description': 'Exact canonical Census server name'}}}
census_lookup
Get the live health verdict for one MCP server by its exact registry name (e.g. 'io.github.owner/name'). Returns stars, last-push recency, gone/archived/deprecated flags, name-collision count, and a fact-based health verdict (healthy | issues | unknown).
Input schema
{'type': 'object', 'required': ['name'], 'properties': {'name': {'type': 'string', 'description': 'Exact MCP registry server name'}}}
census_policy_list
List the exact immutable Preflight v1 built-in policy objects, canonical ruleset, and policy digests. Unmetered.
Read only Idempotent
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'properties': {}, 'additionalProperties': False}
Output schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['ok', 'policies', 'ruleset', 'policy_digests', 'audit_signed'], 'properties': {'ok': {'const': True}, 'ruleset': {'type': 'object'}, 'policies': {'type': 'array', 'items': {'type': 'object'}, 'maxItems': 3, 'minItems': 3}, 'audit_signed': {'const': False}, 'policy_digests': {'type': 'object', 'additionalProperties': {'type': 'string', 'pattern': '^sha256:'}}}, 'additionalProperties': False}
census_preflight
Evaluate one exact MCP server under a documented built-in install policy. Returns PASS, REVIEW, or BLOCK with evidence reasons, freshness, digests, and explicit limits. This is a first gate, not a security audit. refresh=if_stale requires x-api-key.
Open world
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['server_name'], 'properties': {'refresh': {'enum': ['never', 'if_stale'], 'type': 'string', 'default': 'never'}, 'policy_id': {'enum': ['builtin:baseline', 'builtin:first-party', 'builtin:strict'], 'type': 'string', 'default': 'builtin:baseline'}, 'server_name': {'type': 'string', 'maxLength': 300, 'minLength': 1, 'description': 'Exact canonical Census server name'}}, 'additionalProperties': False}
Output schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['ok', 'decision', 'decision_scope', 'meaning', 'server_name', 'policy', 'reasons', 'facts', 'facts_digest', 'decision_input_digest', 'engine_version', 'evaluated_at', 'valid_until', 'audit_id', 'audit_signed', 'limitations'], 'properties': {'ok': {'const': True}, 'facts': {'type': 'object'}, 'policy': {'type': 'object', 'required': ['id', 'revision', 'digest'], 'properties': {'id': {'type': 'string'}, 'digest': {'type': 'string', 'pattern': '^sha256:'}, 'revision': {'type': 'integer', 'minimum': 1}}, 'additionalProperties': False}, 'meaning': {'type': 'string'}, 'reasons': {'type': 'array', 'items': {'type': 'object', 'required': ['code', 'result', 'summary', 'evidence'], 'properties': {'code': {'type': 'string'}, 'result': {'type': 'string'}, 'summary': {'type': 'string'}, 'evidence': {'type': 'array', 'items': {'type': 'object'}}}}}, 'audit_id': {'type': ['string', 'null']}, 'decision': {'enum': ['PASS', 'REVIEW', 'BLOCK'], 'type': 'string'}, 'limitations': {'type': 'array', 'items': {'type': 'string'}}, 'server_name': {'type': 'string'}, 'valid_until': {'type': 'string', 'format': 'date-time'}, 'audit_signed': {'const': False}, 'evaluated_at': {'type': 'string', 'format': 'date-time'}, 'facts_digest': {'type': 'string', 'pattern': '^sha256:'}, 'decision_scope': {'const': 'public_evidence_policy'}, 'engine_version': {'type': 'string'}, 'decision_input_digest': {'type': 'string', 'pattern': '^sha256:'}}, 'additionalProperties': False}
census_recent
Newest MCP servers by real first_seen_at (same payload as GET /v1/recent). Unmetered. Only rows with a known first-seen date — never invents or guesses discovery times. Optional limit 1–50 (default 20).
Input schema
{'type': 'object', 'properties': {'limit': {'type': 'number', 'description': 'Max results 1–50 (default 20)'}}}
census_search
Search MCP servers by keyword or partial name (e.g. 'github', 'postgres'). Returns ranked matches with health/trust. Also returns: resolved_query (auto typo fix), disambiguate (when unsure), known_brand (we recognize a strong product but it has no official MCP — e.g. CodeRabbit), research (watchlist/confirmed_absent), query_intent (brand_lookup|category|package|install_gate|junk — does not change ranking), intent_cta (preflight when they asked an install-gate question). Prefer official_match=true rows. Never invent servers.
Input schema
{'type': 'object', 'required': ['query'], 'properties': {'limit': {'type': 'number', 'description': 'Max results 1–50 (default 20)'}, 'query': {'type': 'string', 'description': 'Keyword or partial server name (>= 2 chars). Typos and space variants are resolved when confident.'}}}
census_stamp
Census stamp for one exact MCP server under a built-in policy. Same input as census_preflight. Returns the preflight body plus compact CENSUS-STAMP/1 text and stamp_json. Cost matches preflight. Never connect without a stamp. PASS is not a malware scan or permission review.
Input schema
{'type': 'object', '$schema': 'https://json-schema.org/draft/2020-12/schema', 'required': ['server_name'], 'properties': {'refresh': {'enum': ['never', 'if_stale'], 'type': 'string', 'default': 'never'}, 'policy_id': {'enum': ['builtin:baseline', 'builtin:first-party', 'builtin:strict'], 'type': 'string', 'default': 'builtin:baseline'}, 'server_name': {'type': 'string', 'maxLength': 300, 'minLength': 1, 'description': 'Exact canonical Census server name'}}, 'additionalProperties': False}
census_stats
Ecosystem headline numbers from the live census (same payload as GET /v1/stats). Unmetered. Returns total servers, healthy/issues counts, popular (gh_stars>=1000), remote-capable count, github-linked count, and captured_at. No invented metrics.
Input schema
{'type': 'object', 'properties': {}}
census_watch_list
List active per-server watches for this API key. Requires x-api-key.
Input schema
{'type': 'object', 'properties': {}}
census_watch_subscribe
Subscribe this agent (or a human email) to alerts for ONE specific MCP server. Fires only on real observed changes: remote_down, remote_up, health_change, verified_change, security. Requires x-api-key. Prefer webhook_url (https) so your agent can receive POST callbacks; email optional. Returns a watch id + HMAC secret (X-Census-Signature: sha256=…). Free tier: 5 watches; pro: 50.
Input schema
{'type': 'object', 'required': ['server_name'], 'properties': {'email': {'type': 'string', 'description': 'Optional human email for the same alerts'}, 'label': {'type': 'string', 'description': 'Optional agent-chosen label'}, 'events': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Subset of remote_down,remote_up,health_change,verified_change,security,tools_changed (default: all)'}, 'server_name': {'type': 'string', 'description': 'Exact registry name to watch'}, 'webhook_url': {'type': 'string', 'description': 'https URL that will receive signed POST event payloads'}}}
census_watch_unsubscribe
Deactivate a watch by id. Requires x-api-key that owns the watch.
Input schema
{'type': 'object', 'required': ['id'], 'properties': {'id': {'type': 'string', 'description': 'Watch id from census_watch_subscribe'}}}
Changed
census_search
Sept. 21, 2026, 3 a.m.
Added
census_changes
Sept. 17, 2026, 12:36 p.m.
Added
census_audit_config
Sept. 17, 2026, 12:36 p.m.
Added
census_lookalikes
Sept. 17, 2026, 12:36 p.m.
Added
census_stamp
Sept. 17, 2026, 12:36 p.m.
Added
census_credits
Sept. 17, 2026, 12:36 p.m.
Added
census_policy_list
Sept. 17, 2026, 12:36 p.m.
Added
census_preflight
Sept. 17, 2026, 12:36 p.m.
Added
census_watch_unsubscribe
Sept. 17, 2026, 12:36 p.m.
Added
census_watch_list
Sept. 17, 2026, 12:36 p.m.
Added
census_watch_subscribe
Sept. 17, 2026, 12:36 p.m.
Added
census_coverage
Sept. 17, 2026, 12:36 p.m.
Added
census_recent
Sept. 17, 2026, 12:36 p.m.
Added
census_stats
Sept. 17, 2026, 12:36 p.m.
Added
census_search
Sept. 17, 2026, 12:36 p.m.
Added
census_lookup
Sept. 17, 2026, 12:36 p.m.