Open source · runs on your machine or in CI · no telemetry

Prove an MCP server is safe for your agents, with evidence anyone can check.

passmcp connects to a live MCP server the way an agent would, runs 131 checks in nine phases, and ties every finding to the request that showed it. It writes a signed attestation that a gateway, a registry or an auditor can verify offline. Nothing is uploaded and nothing is guessed.

Lines of code and diagnostic data glowing on dark screens

passmcp's sample report

acme-crm 2.4.0, passmcp's deliberately flawed fixture server

5 failing checks to fix before agents rely on it

66 checks · 34 pass · 5 warn · 5 fail · 10 skipped · 12 info

69.25/ 100Grade C
Checks in passmcp
131
Protocol generations
Both
Bytes sent to us
None

This is passmcp's real output, not a mock-up: the sample report is passmcp run against a fixture server with deliberate flaws, and the score, ledger, phases and evidence on this page are read from it. Generated by passmcp 0.0.1 when this page was built.

What only passmcp does

Validation you can prove, not a posture you have to trust.

Discovery and dashboards tell you what exists. passmcp tells you what a server actually does when an agent talks to it, and gives you a signed record of it.

01

Live protocol validation

Handshake, conformance, catalogue, safe execution, latency and recovery, run against the real server over the real transport, on both the handshake revisions and the stateless 2026-07-28 revision.

02

Evidence tied to requests

Every finding cites the numbered request that produced it, and the report directory keeps the NDJSON event stream and a HAR file. A verdict you dispute is a verdict you can replay.

03

Signed, offline-verifiable attestations

passmcp writes an in-toto statement about the server. The verifier is Apache-2.0 and has no dependencies, so a gateway, registry or auditor can check it without trusting anyone's server.

04

A gate, not a report

Exit status 2 on a failed check, a policy file for what counts, SARIF for code scanning and JUnit for test reports. The check that gates a release is the one an engineer already ran.

Why it runs here

A tester you upload to is a tester you trust twice.

Handing an endpoint to a hosted tester means handing over whatever reaches it. For a server behind OAuth, that is a working credential. passmcp is the same test, run from inside your own trust boundary.

01

Your credentials stay put

passmcp authenticates from your machine with the token you already hold. Secrets are registered with the recorder before the first request and masked everywhere they appear, including tokens the server issues mid-run.

02

Your network is the network

A server on a private address, behind a VPN, inside a CI runner, or run as a local program over stdio, is reached exactly as your agents reach it.

03

Read-only by default

Only tools that declare readOnlyHint are called. A tool with no annotation is destructive by the specification's default, so it is skipped and the report says so. Mutations are an explicit opt-in.

How it compares

Use the right tool for the question.

The Inspector is for exploring by hand; static scanners read metadata and code; hosted agent-security platforms inventory what exists across your SaaS. passmcp answers a different question: does this server behave safely, and can you prove it?

How passmcp compares with MCP Inspector, Cisco mcp-scanner, Snyk agent-scan and hosted agent-security platforms
 passmcpMCP InspectorCisco mcp-scannerSnyk agent-scanHosted agent-security platforms
Tests a live server's protocol behaviour, automatically131 checks, 9 phasesBy handScans metadata and codeReads the tool catalogueNot documented
Signed evidence you can verify offlinein-toto attestationNoNoNoNot documented
Every finding cites the request that showed itYes, with a HAR fileBy handNoNoNot documented
Gates CI with an exit code, SARIF and JUnitYesNot its purposeYesYesNot documented
Runs where your credentials already areYour machine or CIYour machineOffline or CILocal, with a cloud APIVendor-hosted
Finds agents and MCP servers across an organisationPlanned (#5)NoNoFrom client configurationsYes
Maps identities, grants and reach as a graphPlanned (#4)NoNoNoYes
Open sourceGPL-3.0; format Apache-2.0YesYesYesNo

Sources, as each project describes itself on 26 Sep 2026: Cisco mcp-scanner (github.com/cisco-ai-defense/mcp-scanner), Snyk agent-scan (github.com/snyk/agent-scan), MCP Inspector (github.com/modelcontextprotocol/inspector), and the public product pages of hosted agent-security platforms such as reco.ai. 'Not documented' means we found no public description of the capability, not proof that it is absent. Corrections are welcome as issues.

Scoring

Every deduction named.

A grade with no arithmetic behind it is a brand, not a measurement. These are the six categories passmcp scores, their weights, and what the sample server lost in each.

CategoryWeightScoreDeduction
Connectivity101000
Authorization2095−1
Protocol200−20
Catalogue1555−6.75
Execution2085−3
Performance151000

Evidence

Nothing passes without a request that showed it.

Two findings from the sample report, each with the request that produced it. In the report, every finding links to its request in the HAR file and to its guidance in the manual.

req#11 · protocol.invalid_params

tools/call without a name is rejected

a tools/call with no name succeeded

req#12 · protocol.unknown_tool

Unknown tool is reported

calling a non-existent tool returned success

Method

Nine phases, in the order an agent meets them.

The order matters: a catalogue check means nothing if the handshake never completed, and a latency figure means nothing if half the calls failed. When a phase blocks, every later one is recorded as skipped, with the reason.

  1. Connectivity
  2. Authorization
  3. Credentials
  4. Handshake
  5. Protocol
  6. Catalog
  7. Execution
  8. Performance
  9. Resilience

Where it plugs in

One verdict, used everywhere a decision is made.

passmcp never sits in your agents' traffic. It produces evidence, and the tools that do sit there can act on it.

GitHub Actions and GitLab CI

passmcp-action runs passmcp from its release image, pinned by digest, and writes the report, SARIF and an attestation. A GitLab template does the same.

Your agents, through MCP

passmcp-server exposes passmcp as three read-only tools, so an agent can evaluate a server or verify an attestation. It is listed in the MCP Registry.

agentgateway

An ExtMcp processor in passmcp-reporting lets agentgateway refuse MCP backends whose attestation is missing, stale or failing, verified offline, with no call to passmcp.

Code scanning and test reports

SARIF for GitHub code scanning, JUnit XML for any CI, JSON and NDJSON for pipelines, HAR for devtools, OTLP traces for your collector.

Your package manager

Homebrew, the Arch User Repository (yay -S passmcp), Nix, .deb and .rpm, a signed container image, or go install.

Your own code

The Go packages the CLI is built on are public. The attestation verifier is Apache-2.0 with no dependencies, so any consumer can embed it.

Trust

Auditable the way it asks servers to be.

passmcp is software you run, not a service you send data to, so the questions that matter are about the software itself. Here is how to check each answer yourself.

Signed and attested releases

Signed tags; checksums signed with keyless cosign; SLSA build provenance; a CycloneDX SBOM per archive; the container base pinned by digest.

No telemetry, ever

No account, no analytics, no phone-home. passmcp contacts the server you named and the authorization endpoints it advertises, and nothing else unless you opt in by flag, as with --osv for advisories or --model for explain. That is a recorded decision, ADR 0006.

Never in the data path

passmcp does not proxy, terminate or forward an agent's request, and no agent request waits on anything passmcp operates. ADR 0007 draws that line, and the gateway integrations respect it.

Compliance, stated honestly

passmcp holds no SOC 2 or ISO 27001 certificate; those apply to service providers, and passmcp runs on yours. Mapping every check to SOC 2, ISO 27001 and GDPR controls, so its evidence drops into your audit, is planned work in issues #1 to #3.

Why now

The dates your agent programme is working to.

Agents are moving into production while the guidance and the obligations around them arrive. Each date below links to its source.

DateWhatWhat passmcp gives you
20 May 2026NSA: MCP security design considerationsAuthentication, Origin and token handling checked on the live server
28 Jul 2026MCP 2026-07-28: the stateless revisionAll nine phases on both protocol generations
11 Sep 2026EU Cyber Resilience Act: vulnerability reporting appliesSigned releases, SBOMs and provenance for passmcp itself
After Jul 2027MCP's deprecated features become removableprotocol.deprecated_features tells you what to migrate first
2 Dec 2027EU AI Act: Annex III high-risk obligationsDated, signed evidence of what the tools your agents use actually do

Planned

What is being built next, in the open.

None of this ships today. Each item is a public issue whose acceptance criteria become the regression tests that prove it.

Planned

Explicit discovery and live validation

Find MCP endpoints from sources you name (hosts, client configurations, gateways, your registry namespace), validate each one live, and flag any that answer without authentication.

Planned

passmcp-graph

A local, open graph of which agents reach which servers and tools, under which identities and scopes, with each server's attested verdict attached. Runs on your side; nothing leaves.

Planned

Compliance evidence

Each check mapped to SOC 2 Trust Services Criteria, ISO/IEC 27001:2022 Annex A and GDPR articles, with evidence bundles built from signed attestations.

Questions

The things people ask before installing.

Short answers. Longer ones are in the manual.

How is this different from the official MCP Inspector?

The Inspector is an excellent place to explore a server by hand: click a tool, read a response, debug an OAuth flow. passmcp is the non-interactive counterpart. It runs 131 checks, scores the result, cites its evidence, signs an attestation and returns an exit code. Most teams use both.

How is it different from static MCP scanners?

Scanners such as Cisco's mcp-scanner read tool metadata and source code. passmcp talks to the running server over its real transport, so it sees what the server does: whether it rejects a bad token, validates arguments, honours Origin, recovers a session. passmcp also reads the catalogue for hidden instructions and poisoning, so the two overlap on text but not on behaviour.

Does it support the stateless 2026-07-28 revision?

Yes. All nine phases run on either generation. passmcp settles which revision a server speaks before first contact, because the shape of the first request depends on the answer.

Is it safe to run against production?

It is designed for it. Only tools that declare readOnlyHint are called, and requests are throttled. Conformance probes are sent (an invalid token, an unknown method, malformed JSON, a session id the server never issued) to see how the server handles them, and nothing else adversarial. It is a diagnostic, not a penetration test.

Does it test stdio servers?

Yes. passmcp --stdio -- <command> starts the server as a child process and runs every phase over its pipes. On Linux it also watches where the server connects, what it writes and what it spawns, and can seed decoy credentials to see whether it reads or sends them.

What does it cost, and what does it send back to you?

It is free and open source: the engine is GPL-3.0 and the attestation format and verifier are Apache-2.0. It sends nothing back, and there is no telemetry, account or analytics.

Can I verify an attestation without trusting you?

Yes. passmcp verify checks a statement offline, and the verifier is a dependency-free Apache-2.0 Go package you can read, vendor or reimplement. Sign statements with the tooling you already trust, such as cosign, and verify the signature before you act on the verdict.

Get started

One command, and no account to make.

Install it, point it at a server, read the verdict. Everything below runs on your machine; the only requests passmcp makes are to the server you name.

Install

brew install sebastienrousseau/tap/passmcp     # macOS and Linux
yay -S passmcp                                 # Arch Linux, or: paru -S passmcp
mise use -g github:sebastienrousseau/passmcp   # with mise
nix run github:sebastienrousseau/passmcp -- --help
go install satellion.com/passmcp/cmd/[email protected]

Then point it at a server:

passmcp check https://mcp.example.com/mcp

That is the whole first run. No account, no config file, no signup. Add a credential when the server needs one:

passmcp check https://mcp.example.com/mcp --token-env MCP_TOKEN

Or open the same diagnostic in a browser, still running locally:

passmcp serve

Verify

Every run can write an attestation. Check the one behind the sample report yourself; passmcp verify works offline and trusts nothing but the bytes:

curl -fsSLO https://satellion.com/passmcp/sample/attestation.json
passmcp verify attestation.json

A gateway or registry does the same with the Apache-2.0 verifier in passmcp-reporting, without running passmcp at all.

In a pipeline

passmcp exits non-zero when a server fails, so it gates a merge without any extra plumbing:

passmcp check "$MCP_ENDPOINT" --token-env MCP_TOKEN \
  --output json --report-dir ./passmcp-report

The report directory holds the JSON verdict, the NDJSON event stream and a HAR archive of every exchange. Attach it to the build and the question "how do you know?" has an answer that outlives the person who ran it.

What it checks

Connectivity and TLS. How the server asks to be authorized, and whether it refuses a bad token. The MCP handshake, and which generation of the protocol it speaks — passmcp supports both the handshake revisions and the stateless 2026-07-28 one. Protocol behaviour on the edge cases an agent will hit. The tool catalogue, as a model reads it: descriptions, schemas, annotations, and whether $ref and $defs resolve. Safe calls, with results checked against the contracts the tools declare. Latency under repeat and parallel calls. Recovery from a lost session, or from a server that turns out not to be as stateless as it claims.

What it will not do

It calls only tools that declare readOnlyHint unless you say otherwise. It throttles itself. It sends one deliberately invalid token to check the server rejects it, and nothing else adversarial. It is a diagnostic, not a penetration test, and the difference is deliberate.

It also will not phone home. There is no telemetry, no account and no analytics — the only requests passmcp makes are to the server you named.