← All servers
R

raccha.ai

warnings

MCP-first toolbox for agents: KV storage, auth, queue, and utility tools. Free in early access.

https://raccha.ai/mcpWebsiteOAuthMCP 2025-11-25v3.1.2last checked 24 Aug 2026spoke MCP on 2 of 2 checks (30 days)initialize in 908 ms

How to authenticate

Checked against the endpoint by our probe on 24 Aug 2026. These are the capabilities the server advertises, not a prediction about any particular client.

Scheme
OAuth
Issuer
https://raccha.ai
Dynamic client registration
Advertised (RFC 7591)
Client ID Metadata Document
Not advertised
PKCE
S256
Grant types
authorization_code, refresh_token
Protected-resource metadata
Not found

Without it a client has to guess where the authorization server lives.

Anonymous access
Handshake succeeds; 51 tools listable
Credentials demanded in prose
invite_member, revoke_access_key, switch_org

These tools are listed anonymously and their own descriptions ask for an account or key, but no challenge is issued — so a client has nothing to act on and the refusal arrives as a tool error.

What the probe found

warningTools needing credentials are listed without a challenge

3 of the 51 tools listed anonymously say in their own descriptions that they need an account or a key (invite_member, revoke_access_key, switch_org), but the endpoint issued no WWW-Authenticate challenge. The requirement is stated only in prose, so a call reaches the tool and comes back as a tool error instead of an authorization step.

No CORS headers for browser-based clients

A cross-origin preflight came back without Access-Control-Allow-Origin, so the endpoint is reachable from native clients only — code running in a web page is stopped by the browser before a request is ever sent.

51 tools usable without signing in

The server exposes a public surface before authorization: cert_inspect, create_access_key, create_role, delete_role, device_claim, device_start, discussion_claim_role, discussion_create, discussion_get, discussion_join, discussion_list, discussion_list_open, discussion_post, discussion_resolve, hash, invite_member, ip_cidr, isdomainreachable, isemailreachable, jwt_decode, kv_cas, kv_delete, kv_delete_prefix, kv_get, kv_incr, kv_list, kv_put, kv_put_ttl, list_access_keys, list_profiles, list_roles, queue_ack, queue_nack, queue_pop, queue_pop_lease, queue_push, queue_push_delayed, register_client, request_link, revoke_access_key, send_email_reply, stats, switch_org, telegram_pair_code, telegram_send, topic_publish, topic_read, update_access_key, update_role, verify, whoami.

Tools

cert_inspectcreate_access_keycreate_roledelete_roledevice_claimdevice_startdiscussion_claim_rolediscussion_creatediscussion_getdiscussion_joindiscussion_listdiscussion_list_opendiscussion_postdiscussion_resolvehashinvite_memberip_cidrisdomainreachableisemailreachablejwt_decodekv_caskv_deletekv_delete_prefixkv_getkv_incrkv_listkv_putkv_put_ttllist_access_keyslist_profileslist_rolesqueue_ackqueue_nackqueue_popqueue_pop_leasequeue_pushqueue_push_delayedregister_clientrequest_linkrevoke_access_keysend_email_replystatsswitch_orgtelegram_pair_codetelegram_sendtopic_publishtopic_readupdate_access_keyupdate_roleverifywhoami

Contract history

24 Aug 2026v3.1.2first recorded contract

Get alerted when this contract changes

Depend on this server? Leave an email and get a message when a probe records a change — a tool removed, an argument newly required, an enum narrowed. Alerts are being built; signing up is what tells us to hurry.

Prefer a feed reader? This page's contract changes are also an Atom feed.

Status badge

Status for a README, from the last probe — cached an hour, so up to seven hours behind the endpoint. Links back to this page.

MCP status badge for raccha.ai
[![MCP status](https://mcpi.app/servers/raccha-ai/badge.svg)](https://mcpi.app/servers/raccha-ai)

Own this server?

Sign in to claim this listing by proving control of the endpoint.