← All servers

squirrelscan

warnings

mcp.squirrelscan.com

Website QA for your coding agent: audit SEO, performance, security, accessibility over MCP.

https://mcp.squirrelscan.com/mcpWebsiteOAuthMCP 2025-11-25v0.0.1last checked 24 Aug 2026spoke MCP on 3 of 3 checks (30 days)initialize in 3045 ms

How to authenticate

Checked against the endpoint by our probe on 24 Aug 2026. These are the capabilities the server advertises, not a prediction about any particular client.

Scheme
OAuth
Issuer
https://mcp.squirrelscan.com
Dynamic client registration
Advertised (RFC 7591)
Client ID Metadata Document
Supported

A client identifies itself by a URL to its own metadata, so no registration step is required.

PKCE
S256
Grant types
authorization_code, refresh_token
Scopes
audits:read, audits:write, credits:read, org:read, keys:write
Protected-resource metadata
Published (RFC 9728)
Anonymous access
Handshake succeeds; 18 tools listable
Credentials demanded in prose
create_api_key

These tools are listed anonymously and their own descriptions ask for an account or key, but no challenge is issued — so a client has nothing to act on and the refusal arrives as a tool error.

What the probe found

warningTools needing credentials are listed without a challenge

1 of the 18 tools listed anonymously say in their own descriptions that they need an account or a key (create_api_key), but the endpoint issued no WWW-Authenticate challenge. The requirement is stated only in prose, so a call reaches the tool and comes back as a tool error instead of an authorization step.

No CORS headers for browser-based clients

A cross-origin preflight came back without Access-Control-Allow-Origin, so the endpoint is reachable from native clients only — code running in a web page is stopped by the browser before a request is ever sent.

18 tools usable without signing in

The server exposes a public surface before authorization: run_audit, get_audit_status, list_audits, list_websites, add_website, delete_website, delete_websites, get_report, list_issues, get_issue, comment_on_issue, list_rules, get_rule, whoami, get_credit_balance, list_credit_transactions, create_api_key, send_feedback.

Tools

add_websitecomment_on_issuecreate_api_keydelete_websitedelete_websitesget_audit_statusget_credit_balanceget_issueget_reportget_rulelist_auditslist_credit_transactionslist_issueslist_ruleslist_websitesrun_auditsend_feedbackwhoami

Contract history

24 Aug 2026v0.0.1first recorded contract

Get alerted when this contract changes

Depend on this server? Leave an email and get a message when a probe records a change — a tool removed, an argument newly required, an enum narrowed. Alerts are being built; signing up is what tells us to hurry.

Prefer a feed reader? This page's contract changes are also an Atom feed.

Status badge

Status for a README, from the last probe — cached an hour, so up to seven hours behind the endpoint. Links back to this page.

MCP status badge for squirrelscan
[![MCP status](https://mcpi.app/servers/squirrelscan/badge.svg)](https://mcpi.app/servers/squirrelscan)

Own this server?

Sign in to claim this listing by proving control of the endpoint.