MCPSafe.io
RegistryThreatsMethodologyDocsPricingScanSign in

Scan an MCP server

Vet a package before you install it — reads the source (GitHub, npm, PyPI, Docker), no running server needed. Free, no sign-in.

Try one
Visibility
Scan depth

Probe a server you operate after it’s live — auth, transport security, OAuth metadata, schema risk. Sign in required.

Dynamic scanning requires a free account.

Dynamic scans connect to your running MCP server and probe it live — checking authentication, tool descriptions, transport security, and 40+ protocol-level rules that static analysis can't catch.

Free. We never store your server's credentials. Acceptable Use Policy

Learn how scanning worksSee all detection rulesAcceptable Use Policy
MCPSafe.io

Security checks for MCP servers — public packages and private repos, fast or deep.

Legal

Privacy PolicyCookie PolicyTerms of ServiceSecurity disclosure

Resources

State of MCP SecuritySupportSystem statusMade in Germany 🇩🇪

© 2026 MCPSafe. All rights reserved.

GDPR — Privacy Policy