MCP Server Card
A well-known MCP descriptor lets agents discover an available Model Context Protocol server.
- Category
- Protocol discovery
- Standard
- Recommended
What it checks
The extension looks for a document describing a Model Context Protocol (MCP) server at these paths on the site’s origin, in order, and stops at the first one that answers:
/.well-known/mcp.json/.well-known/mcp/server-card.json/.well-known/mcp/server.json/.well-known/mcp
A path counts when it returns a successful response with a non-empty body that
is JSON: either the Content-Type mentions json, or the body starts with {
or [. That rules out an HTML page served with a 200 for a missing path. The
extension does not validate the fields inside the document.
If none of those paths answers, the extension follows a pointer the site
publishes to an MCP server hosted elsewhere, for example on a developer
subdomain. It only follows a pointer the site itself declares: an entry in its
agent catalog (/.well-known/ard.json or /.well-known/ai-catalog.json), or,
with emerging checks enabled, a DNS-AID record. It never guesses a hostname, it
does not follow redirects from the declared address, and it never requests an
address on your local network unless the site being audited is on it too. The
result names the host the descriptor was found on.
Results
| Status | When |
|---|---|
| Pass | One of the paths returns a JSON document |
| Pass | A host the site declares serves one |
| N/A | None of the paths returns a JSON document |
N/A is not charged against the site. Most sites do not run an MCP server.
How to fix
If you offer an MCP server, publish a JSON descriptor for it at
/.well-known/mcp.json or /.well-known/mcp/server-card.json, served with
Content-Type: application/json. It should at least name the server and say
where to connect:
{
"name": "Example MCP server",
"description": "Search and manage orders.",
"url": "https://example.com/mcp"
}
If you do not offer one, there is nothing to do.
Related: Agent Skills and WebMCP.