Free tool · No sign-up required
MCP Inspector —
test any MCP server from your browser.
Enter a URL and run a live JSON-RPC 2.0 handshake against any Model Context Protocol server — no install, no client config. See serverInfo, capabilities, the full tools/list, and whether the server is OAuth-protected.
Built for servers in the MCP ecosystem
What it shows you
Live initialize handshake
Sends a real JSON-RPC 2.0 initialize request over Streamable HTTP — with SSE-framed responses handled — and shows the serverInfo, protocolVersion, and declared capabilities the server answers with.
Tool enumeration
Calls tools/list after the handshake and renders every exposed tool with its name and description — the same view a Claude or Cursor client gets when it connects to the server.
OAuth-protected server detection
A 401 with a WWW-Authenticate challenge doesn't end the scan — the inspector recognizes it as an OAuth-protected MCP server, reports it as such, and surfaces the RFC 9728 protected-resource metadata URL.
Server card discovery (SEP-2127)
Checks /.well-known/mcp/server-card — the experimental MCP discovery extension — so you can see whether a server publishes discovery metadata before any client connects.
A2A and ARD on the same scan
Every scan also checks for an A2A agent card and an ARD ai-catalog.json, so you see a service's full agent-protocol surface — not just MCP — in one result.
Full report download
Download the complete scan — handshake result, capabilities, tool list, server card, and raw JSON — as a single report file for documentation or review. Pro feature.
Endpoints probed on every scan
Addresses OWASP Agentic Skills Top 10
Detection and reporting, not enforcement — pairs with the permission-manifest, cryptographic-pinning, and approval-workflow controls OWASP also recommends for each risk.
Who uses it
MCP server developers
Verify your Streamable HTTP endpoint from the outside before announcing it: does initialize answer, are your tools listed with useful descriptions, does your OAuth challenge carry the right resource metadata?
AI engineers evaluating servers
Check what a third-party MCP server actually exposes before wiring it into Claude, Cursor, or a LangGraph agent — tool surface, capabilities, and auth requirements in one scan, no client config needed.
Security teams
MCP servers are a new class of externally reachable endpoint. Enumerate what a server advertises to any anonymous client and confirm auth-protected servers actually reject unauthenticated initialize calls.