CertScore.ai
About
Scan public websites for privacy, cookie, tracker, consent, policy, and disclosure risk signals—start instantly with zero-auth Light mode.
Details
- Author
- Unknown
- Categories
- Developer Tools, Security
Jump to
No account, API key, bearer token, browser login, or OAuth. Use it for first-time setup, testing, discovery, and low-volume public website scans.
Hosted MCP — OAuthis for managed remote clients.Local MCP — scoped API keyis for stdio, backend, and controlled local environments.
Your browser does not support embedded video.Open the MP4 directly.
Watch the OpenAI/ChatGPT flow from prompt to CertScore tool calls, public-safe scan observations, and the full report. It is the quickest way to understand what the Light route feels like in practice.
Run this command, then paste the first-run prompt into Codex. The connection uses Streamable HTTP and should not open a browser, request OAuth, or ask for an API key.
codex mcp add certscore --url https://mcp.certscore.ai/mcp/light
Scan https://ergoveritas.com/.well-known/certscore-canary/sentinels/broad-baseline.html. If certscore_scan_site returns a queued, running, or finalizing result, retain the returned scanId and poll certscore_get_scan_status using scanId only. If certscore_scan_site returns a retryable error without a scanId, wait for retryAfterSeconds and retry certscore_scan_site; do not call certscore_get_scan_status until a scanId exists. Once the scan reaches a terminal status, call certscore_get_scan_bundle with detail=findings and maxBytes=8000. Summarize whether the result was new or reused, the score, risk level, findings, evidence links, coverage limitations, and report URL. Explain truncation or omitted sections when present. Treat results as automated public-web observations, not legal conclusions, certifications, or compliance determinations.
The ErgoVeritas canary page is a controlled, stable test site for demonstrating the complete scan, status, and bundle flow. Substitute your own public URL at any time.
CertScore results are automated observations from a public-web scan. No-go, not-observed, and limited-coverage results are not proof of compliance, absence of risk, or legal status. Review the retained evidence and applicable context before relying on a finding.
certscore_scan_site → retry certscore_scan_site if a retryable error has no scanId → certscore_get_scan_status with scanId if still running → certscore_get_scan_bundle after terminal status
- 1Call certscore_scan_site with a public URL.
- 2If a retryable error has no scanId, wait retryAfterSeconds and retry certscore_scan_site.
- 3If the result is queued, running, or finalizing, retain scanId.
- 4Poll certscore_get_scan_status using scanId only. Never poll until scanId exists.
- 5Stop polling when the scan reaches a terminal status, then call certscore_get_scan_bundle.
- 6Use detail=findings for a compact finding review.
- 7Use detail=evidence for evidence digests and references.
- 8If truncated, follow recommendedNextAction or increase maxBytes.
- 9Summarize findings together with coverage limitations and the report URL.
Terminal statuses arecompleted,completed_limited,failed,expired, andrate_limited. Acompleted_limitedor no-go result is a usable observation with explicit limitations, not a transport failure.
certscore_get_scan_statusshould only be called aftercertscore_scan_sitereturns ascanId.
This starts the same no-account scan available to Light agents and opens its shareable public report.
Need more scans or advanced tools? Upgrade to Authenticated MCP.
Add a custom remote MCP connector and paste the Light endpoint.
Add the remote MCP server in developer mode and paste the Light endpoint.
Add a remote Streamable HTTP MCP server using the Light endpoint.
Add an HTTP MCP server and use the Light endpoint as its URL.
Run: codex mcp add certscore --urlhttps://mcp.certscore.ai/mcp/light
Transport: Streamable HTTP URL: https://mcp.certscore.ai/mcp/light Authentication: None
Bundle detail is explicit:summaryreturns the compact default,findingsadds bounded finding detail,evidenceadds retained-evidence summaries and references, andfulladds the bounded public report. UsemaxBytesto set a 5,000–200,000 byte budget; the response reports requested bytes, actual bytes, and any truncation reason.
A 5,000-byte response may intentionally omit optional sections while still returning a compact finding or evidence reference when available. InspectactualBytes,truncated,omittedSections,nextRecommendedMaxBytes, and the report or evidence content URLs before retrying.
Prefer a managed directory connection? Find CertScore.ai onSmithery.
List the available CertScore tools and confirm that certscore_scan_site, certscore_get_scan_status, and certscore_get_scan_bundle are available. Then scan https://ergoveritas.com/.well-known/certscore-canary/sentinels/broad-baseline.html and report whether the result was new or reused.
Success means Codex lists exactlycertscore_scan_site,certscore_get_scan_status, andcertscore_get_scan_bundle; no OAuth prompt appears; andcertscore_scan_sitereturns a stablescanIdplus an explicit new-or-reused decision. A reused eligible result should show that quota was not consumed.
- Unexpected OAuth:remove the connection and add it again with the exact URLhttps://mcp.certscore.ai/mcp/light. Do not configure a bearer token; the Light endpoint has no authentication.
- Connection check:a successful Streamable HTTP connection completes initialization and lists the three Light tools without opening an authorization page.
- Missing scanId:retrycertscore_scan_siteonly when the error saysretryable: true; never pollcertscore_get_scan_statuswithoutscanId.
- Rate limited:followretryAfterSecondsandrecommendedNextAction, or reuse an eligible result. The daily allowance resets at the returned UTC time.
- Reused result:report that the eligible prior scan was reused and quota was not consumed.
- Truncated bundle:follownextRecommendedMaxBytes, increasemaxBytes, or open one of the returned content URLs.
- Invalid URL:correct theurlfield using the structuredinvalid_argumentsresponse, then retrycertscore_scan_sitewith a public HTTP or HTTPS URL.
- Limited result:completed_limited, no-go, not-observed, and limited coverage are observations only, never proof of compliance. Transport failures instead returnfailed,expired, or a connection error with retry guidance.
Review this domain before vendor onboarding and summarize evidence-backed concerns.
Identify the most important privacy, consent, policy, and disclosure risks on this site.
Scan this list of public websites and create a concise review table with coverage limitations.
Upgrade when you need a dedicated higher-volume allowance, production or team access, backend automation, scan history, advanced diagnostic tools, or support-managed scopes.
Use the full endpoint, authenticate with hosted OAuth or a local scoped API key, and receive the quota and tools granted to that access.
Core identifiers and canonical response fields—includingscanId, status, score, risk, coverage, and timestamps—remain compatible.
Need more scans or advanced tools? Upgrade to Authenticated MCP.
CertScore results are automated observations from a public-web scan. No-go, not-observed, and limited-coverage results are not proof of compliance, absence of risk, or legal status. Review the retained evidence and applicable context before relying on a finding.
This is a web browser that enables your coding agent, such as Claude Code, to visit websites on your behalf and assist you in identifying bugs or creating UI test cases.
Model Context Protocol server for Skycloak managed Keycloak. Manage clusters, realms, applications, SSO and users from any MCP client.
The first MCP server governed by ICA. A remote streamable HTTP server at https://mcp.aleeth.com/mcp with 37 governed tools: every call is risk-checked by Rail Guard before it runs and sealed with a signed Ed25519 receipt on a hash-chained public ledger anchored to Bitcoin. Fails closed: no receipt, no response. OAuth 2.0 with RFC 9728 discovery; anonymous requests get 401. This repository is the public interface and provenance record: a generated tool manifest with per-tool annotations, an SBOM and vulnerability scan with digested provenance, and a TRUST.md of verify-it-yourself commands. The implementation is private by design. Independent probe grade A from mcp-spec-check, re-verified 2026-07-24.
Turn any OpenAPI spec into a hosted MCP server in 30 seconds. One typed tool per endpoint, server-side auth injection, stable URL across spec updates. EU-hosted, GDPR-native.
Discover powerful AI agents, invoke them instantly, and verify every result with Ed25519 cryptographic proofs. Nine tools — five free, four billed — all protected by OAuth 2.1.
AI-safe approval plan gated Kubernetes operations through MCP with OAuth, RBAC, audit, guardrails.
A remote MCP server with GitHub OAuth authentication and built-in analytics tracking.
A local MCP server that breaks on demand. Test your client against auth failures, disappearing tools, flaky responses, and token expiry, all from a web UI.
An MCP server with built-in GitHub OAuth support, deployable on Cloudflare Workers.
An MCP server with built-in GitHub OAuth support, designed for deployment on Cloudflare Workers.
Hosted mock-API MCP server: agents create live REST/GraphQL mock APIs, import OpenAPI/CSV/db.json, seed fake data, query and write records — free, no auth, stateless Streamable HTTP.
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.





