← All servers

AxioRank: Zero-Trust for AI Agents

warnings

app.axiorank.com

Zero-trust gateway for AI agents: score tool calls, verify agent cards, enforce policy, audit.

https://app.axiorank.com/api/mcp-server/mcpWebsiteOAuthMCP 2025-11-25v1.0.1last checked 8 Oct 2026spoke MCP on 100% of 92 checks (30 days)initialize in 233 ms

Will my client connect?

Decided from what the probe found at the endpoint, and from what each client's own documentation says it can complete. Every row carries the day that documentation was read.

✓Claude CodeConnects

The authorization server advertises RFC 7591 registration, so Claude Code can register itself and sign you in through the browser.

claude mcp add --transport http axiorank-zero-trust-for-ai-agents https://app.axiorank.com/api/mcp-server/mcp

Claude Code docs · read on 2026-08-30

✓Claude (claude.ai & Desktop)Connects

The authorization server advertises RFC 7591 registration, so Claude (claude.ai & Desktop) can register itself and sign you in through the browser.

Settings → Connectors → Add custom connector, then paste https://app.axiorank.com/api/mcp-server/mcp.

Claude (claude.ai & Desktop) docs · read on 2026-08-30

✓ChatGPTConnects

The authorization server advertises RFC 7591 registration, so ChatGPT can register itself and sign you in through the browser.

Settings → Apps → Advanced settings → Developer mode, then create a connector pointing at https://app.axiorank.com/api/mcp-server/mcp.

ChatGPT docs · read on 2026-08-30

✓CursorConnects

The authorization server advertises RFC 7591 registration, so Cursor can register itself and sign you in through the browser.

{
  "mcpServers": {
    "axiorank-zero-trust-for-ai-agents": {
      "url": "https://app.axiorank.com/api/mcp-server/mcp"
    }
  }
}

Cursor docs · read on 2026-08-30

✓VS Code (Copilot)Connects

The authorization server advertises RFC 7591 registration, so VS Code (Copilot) can register itself and sign you in through the browser.

{
  "servers": {
    "axiorank-zero-trust-for-ai-agents": {
      "type": "http",
      "url": "https://app.axiorank.com/api/mcp-server/mcp"
    }
  }
}

VS Code (Copilot) docs · read on 2026-08-30

How to authenticate

Checked against the endpoint by our probe on 8 Oct 2026. These are the capabilities the server advertises, not a prediction about any particular client.

Scheme
OAuth
Issuer
https://app.axiorank.com
Dynamic client registration
✓Advertised (RFC 7591)
Client ID Metadata Document
✕Not advertised
PKCE
✓S256
Grant types
authorization_code, refresh_token
Scopes
logs:read, agents:read, policies:read, gateway:write, cards:verify
Protected-resource metadata
✓Published (RFC 9728)
Anonymous access
Handshake succeeds; 22 tools listable
Credentials demanded in prose
✕axiorank_verify_card, axiorank_revoke_agent, axiorank_issue_token

These tools are listed anonymously and their own descriptions ask for an account or key, but no challenge is issued — so a client has nothing to act on and the refusal arrives as a tool error.

What the probe found

warningTools needing credentials are listed without a challenge

3 of the 22 tools listed anonymously say in their own descriptions that they need an account or a key (axiorank_verify_card, axiorank_revoke_agent, axiorank_issue_token), but the endpoint issued no WWW-Authenticate challenge. The requirement is stated only in prose, so a call reaches the tool and comes back as a tool error instead of an authorization step.

No CORS headers for browser-based clients

A cross-origin preflight came back without Access-Control-Allow-Origin, so the endpoint is reachable from native clients only — code running in a web page is stopped by the browser before a request is ever sent.

22 tools usable without signing in

The server exposes a public surface before authorization: axiorank_score_tool_call, axiorank_verify_card, axiorank_check_approval, axiorank_get_protocol_coverage, axiorank_get_health, axiorank_list_agents, axiorank_get_agent, axiorank_quarantine_agent, axiorank_revoke_agent, axiorank_list_policies, axiorank_get_policy, axiorank_create_policy, axiorank_update_policy, axiorank_search_audit_logs, axiorank_list_incidents, axiorank_get_incident, axiorank_list_threat_intel, axiorank_list_ml_assessments, axiorank_get_usage, axiorank_issue_token, axiorank_create_agent, axiorank_author_detector.

Tools

axiorank_author_detectoraxiorank_check_approvalaxiorank_create_agentaxiorank_create_policyaxiorank_get_agentaxiorank_get_healthaxiorank_get_incidentaxiorank_get_policyaxiorank_get_protocol_coverageaxiorank_get_usageaxiorank_issue_tokenaxiorank_list_agentsaxiorank_list_incidentsaxiorank_list_ml_assessmentsaxiorank_list_policiesaxiorank_list_threat_intelaxiorank_quarantine_agentaxiorank_revoke_agentaxiorank_score_tool_callaxiorank_search_audit_logsaxiorank_update_policyaxiorank_verify_card

Contract history

24 Aug 2026v1.0.1first recorded contract

Watch this server

Save its public contract as a baseline and manage breaking-change email alerts.

Set up a watch

Own this server?

Sign in to claim this listing by proving control of its host.

Status badge

Status for a README, from the last probe — cached an hour, so up to seven hours behind the endpoint. Links back to this page.

MCP status badge for AxioRank: Zero-Trust for AI Agents
[![MCP status](https://mcpi.app/servers/axiorank-zero-trust-for-ai-agents/badge.svg)](https://mcpi.app/servers/axiorank-zero-trust-for-ai-agents)