MCP Server Card

A well-known MCP descriptor lets agents discover an available Model Context Protocol server.

Standard
Recommended

What it checks

The extension looks for a document describing a Model Context Protocol (MCP) server at these paths on the site’s origin, in order, and stops at the first one that answers:

  1. /.well-known/mcp.json
  2. /.well-known/mcp/server-card.json
  3. /.well-known/mcp/server.json
  4. /.well-known/mcp

A path counts when it returns a successful response with a non-empty body that is JSON: either the Content-Type mentions json, or the body starts with { or [. That rules out an HTML page served with a 200 for a missing path. The extension does not validate the fields inside the document.

If none of those paths answers, the extension follows a pointer the site publishes to an MCP server hosted elsewhere, for example on a developer subdomain. It only follows a pointer the site itself declares: an entry in its agent catalog (/.well-known/ard.json or /.well-known/ai-catalog.json), or, with emerging checks enabled, a DNS-AID record. It never guesses a hostname, it does not follow redirects from the declared address, and it never requests an address on your local network unless the site being audited is on it too. The result names the host the descriptor was found on.

Results

Status When
Pass One of the paths returns a JSON document
Pass A host the site declares serves one
N/A None of the paths returns a JSON document

N/A is not charged against the site. Most sites do not run an MCP server.

How to fix

If you offer an MCP server, publish a JSON descriptor for it at /.well-known/mcp.json or /.well-known/mcp/server-card.json, served with Content-Type: application/json. It should at least name the server and say where to connect:

{
  "name": "Example MCP server",
  "description": "Search and manage orders.",
  "url": "https://example.com/mcp"
}

If you do not offer one, there is nothing to do.

Related: Agent Skills and WebMCP.