← All servers

AxioRank: Zero-Trust for AI Agents

warnings

app.axiorank.com

Zero-trust gateway for AI agents: score tool calls, verify agent cards, enforce policy, audit.

https://app.axiorank.com/api/mcp-server/mcpWebsiteOAuthMCP 2025-11-25v1.0.1last checked 24 Aug 2026spoke MCP on 2 of 2 checks (30 days)initialize in 370 ms

How to authenticate

Checked against the endpoint by our probe on 24 Aug 2026. These are the capabilities the server advertises, not a prediction about any particular client.

Scheme
OAuth
Issuer
https://app.axiorank.com
Dynamic client registration
Advertised (RFC 7591)
Client ID Metadata Document
Not advertised
PKCE
S256
Grant types
authorization_code, refresh_token
Scopes
logs:read, agents:read, policies:read, gateway:write, cards:verify
Protected-resource metadata
Published (RFC 9728)
Anonymous access
Handshake succeeds; 22 tools listable
Credentials demanded in prose
axiorank_verify_card, axiorank_revoke_agent, axiorank_issue_token

These tools are listed anonymously and their own descriptions ask for an account or key, but no challenge is issued — so a client has nothing to act on and the refusal arrives as a tool error.

What the probe found

warningTools needing credentials are listed without a challenge

3 of the 22 tools listed anonymously say in their own descriptions that they need an account or a key (axiorank_verify_card, axiorank_revoke_agent, axiorank_issue_token), but the endpoint issued no WWW-Authenticate challenge. The requirement is stated only in prose, so a call reaches the tool and comes back as a tool error instead of an authorization step.

No CORS headers for browser-based clients

A cross-origin preflight came back without Access-Control-Allow-Origin, so the endpoint is reachable from native clients only — code running in a web page is stopped by the browser before a request is ever sent.

22 tools usable without signing in

The server exposes a public surface before authorization: axiorank_score_tool_call, axiorank_verify_card, axiorank_check_approval, axiorank_get_protocol_coverage, axiorank_get_health, axiorank_list_agents, axiorank_get_agent, axiorank_quarantine_agent, axiorank_revoke_agent, axiorank_list_policies, axiorank_get_policy, axiorank_create_policy, axiorank_update_policy, axiorank_search_audit_logs, axiorank_list_incidents, axiorank_get_incident, axiorank_list_threat_intel, axiorank_list_ml_assessments, axiorank_get_usage, axiorank_issue_token, axiorank_create_agent, axiorank_author_detector.

Tools

axiorank_author_detectoraxiorank_check_approvalaxiorank_create_agentaxiorank_create_policyaxiorank_get_agentaxiorank_get_healthaxiorank_get_incidentaxiorank_get_policyaxiorank_get_protocol_coverageaxiorank_get_usageaxiorank_issue_tokenaxiorank_list_agentsaxiorank_list_incidentsaxiorank_list_ml_assessmentsaxiorank_list_policiesaxiorank_list_threat_intelaxiorank_quarantine_agentaxiorank_revoke_agentaxiorank_score_tool_callaxiorank_search_audit_logsaxiorank_update_policyaxiorank_verify_card

Contract history

24 Aug 2026v1.0.1first recorded contract

Get alerted when this contract changes

Depend on this server? Leave an email and get a message when a probe records a change — a tool removed, an argument newly required, an enum narrowed. Alerts are being built; signing up is what tells us to hurry.

Prefer a feed reader? This page's contract changes are also an Atom feed.

Status badge

Status for a README, from the last probe — cached an hour, so up to seven hours behind the endpoint. Links back to this page.

MCP status badge for AxioRank: Zero-Trust for AI Agents
[![MCP status](https://mcpi.app/servers/axiorank-zero-trust-for-ai-agents/badge.svg)](https://mcpi.app/servers/axiorank-zero-trust-for-ai-agents)

Own this server?

Sign in to claim this listing by proving control of the endpoint.