Getting started¶
Install¶
go install satellion.com/passmcp/cmd/[email protected]
A binary installed this way reports the version it was installed at.
Release archives, .deb/.rpm packages and the Homebrew formula are
described in the repository's pkg/ directory.
From source:
git clone https://github.com/sebastienrousseau/passmcp && cd passmcp
make build # build/passmcp
make install # /usr/local/bin/passmcp, manpages, completions
First run¶
Against an open server:
passmcp check https://mcp.example.com/mcp
Against a server that gave you a bearer token:
export MCP_TOKEN=…
passmcp check https://mcp.example.com/mcp --token-env MCP_TOKEN
Against a server that is a program rather than a URL — which most of them are:
passmcp check --stdio -- npx -y @modelcontextprotocol/server-everything stdio
passmcp starts it, diagnoses it, and stops it again. Everything after --
belongs to the server, including its own flags. See
Servers that are programs for what it is handed and which
checks apply.
The text report lists the nine phases in order, each finding with its
status, what was observed and what to do about it, then the catalog,
execution and performance tables, the score with every deduction, and a
telemetry summary. Add --report-dir ./out to keep every format plus the
raw telemetry.
Commands¶
| Command | Does |
|---|---|
passmcp check <endpoint> |
the full nine-phase diagnostic |
passmcp connect <endpoint> |
net, discovery, auth and handshake only |
passmcp tools <endpoint> |
the connection phases plus the catalog audit, no invocations |
passmcp call <endpoint> <tool> |
one tool invocation with --arg field=value or --json |
passmcp login <endpoint> |
authorize as a user in the browser and store the token |
passmcp config init\|validate\|show |
the configuration file |
passmcp version |
print the version |
An endpoint can be replaced by --profile <name> when the config file
names one; see Configuration. check, connect, tools
and call also accept --stdio -- <command> in place of an endpoint; for
call the tool name comes before the --.
Exit status¶
| Code | Meaning |
|---|---|
| 0 | the run completed and no finding failed |
| 2 | the run completed and at least one finding failed |
| 1 | passmcp itself could not run: bad flags, unreachable config, an internal error |
Warnings do not change the exit status. A CI job that should fail on a
warning can read the JSON report's counts.warn instead.
Where output goes¶
Results go to stdout in the format --output selects. Diagnostics, what
passmcp is doing and why something was skipped, go to stderr under
--log-level (error, warn, info, debug), or PASSMCP_LOG_LEVEL
for a whole shell session. --output json therefore stays pipeable no
matter how noisy the run is.