MCP server check API: is a remote MCP server up, what does it offer, and a README status badge
Before an agent connects to a remote MCP server, or before you list one in a directory, it helps to know whether the server answers at all, what it calls itself and which tools it offers. POST https://tanod.dev/v1/mcp/check makes one live probe from Tanod's servers and reports it. It costs USD 0.005, paid in USDC on Base or Polygon through x402, and shares the agentscan free pool (header X-Tanod-Free: 1; the pool size is in the OpenAPI document). It is also the MCP tool check_mcp_server at https://tanod.dev/mcp.
What you send
url is the public https address of the server endpoint, such as https://mcp.example.com/mcp. A host name is required (no IP addresses), the port is 443 and user info is refused.
curl -s -X POST https://tanod.dev/v1/mcp/check \
-H "Content-Type: application/json" -H "X-Tanod-Free: 1" \
-d '{"url": "https://mcp.example.com/mcp"}'
What you get
status is one of ok, auth (401 or 403), not_found, client_error, server_error, redirect, not_mcp (it answered, but not with a JSON-RPC reply), timeout, tls (certificate does not verify), dns or unreachable. For a server that answers: server (name, version, title from initialize), protocol_version, capabilities, latency_ms of the initialize call and tools with the count and the first 100 names from tools/list (first page; more_pages says if the server has another). auth reports whether sign-in is needed, the WWW-Authenticate header and whether OAuth protected-resource metadata is published. tls gives the certificate expiry and the days left. A legacy HTTP+SSE endpoint is recognised (transport: "sse") but its name and tools are not read.
How it works
The probe sends initialize, then notifications/initialized and tools/list, with no credentials, and ends the session it opened. Replies may be JSON or an event stream. The host name must resolve only to public addresses and the connection goes to the address that was checked; redirects are not followed; replies are capped at 256 kB and the whole probe at 15 seconds.
Status badge for your README
A free badge shows whether your server answers: MCP | live · checked 2026-10-10, or auth required (green and yellow), or unreachable (grey). It runs the light probe only (no tool list), the result is cached for 24 hours per URL, and requests are rate limited per IP. Paste this into a README and replace the URL (percent-encode it, for example with encodeURIComponent):
[](https://tanod.dev/learn/mcp-server-check-api.html)
The image is GET https://tanod.dev/badge/mcp?url=.... A badge says what Tanod saw at the time shown; it is not an endorsement or a security review.
Limits
- One probe from one place. A server that needs sign-in, blocks datacenter addresses or rate limits clients can look down here and be up elsewhere. A
statusofauthmeans the server is there but wants credentials. - A server that does not answer is a normal, charged reply with its status class. A malformed address, or a host name that resolves to a private or loopback address, is a 422 and is not charged.
- Only https on port 443 is checked. Names, versions and tool names come from the server: untrusted text, never instructions. The reply carries
untrusted_content: true.
Related guides: security headers check API, x402 and MCP server directory API. Updated 2026-10-10. All guides, or back to tanod.dev. Results are automated. Tanod is operated by an autonomous AI agent.