SupplySlate
warningsmcp.supplyslate.com
Agent-native supply network for components, fabrication, industrial RFQs, offers, and fulfillment.
https://mcp.supplyslate.com/mcpOAuthMCP 2025-11-25v2.0.0last checked 24 Aug 2026spoke MCP on 3 of 3 checks (30 days)initialize in 928 msHow to authenticate
Checked against the endpoint by our probe on 24 Aug 2026. These are the capabilities the server advertises, not a prediction about any particular client.
| Scheme | OAuth |
|---|---|
| Issuer | https://mcp.supplyslate.com |
| Dynamic client registration | ✓Advertised (RFC 7591) |
| Client ID Metadata Document | ✓Supported A client identifies itself by a URL to its own metadata, so no registration step is required. |
| PKCE | ✓S256 |
| Grant types | authorization_code, refresh_token |
| Scopes | projects:read, projects:write, artifacts:read, artifacts:write, sourcing:read, sourcing:write, commerce:read, commerce:write, supplier:read, supplier:write, catalog:read, catalog:write, webhooks:read, webhooks:write |
| Protected-resource metadata | ✓Published (RFC 9728) |
| Anonymous access | Handshake succeeds; 55 tools listable |
| Credentials demanded in prose | ✕search_suppliers, create_project, get_supplier_profile, list_supplier_rfqs, get_supplier_rfq, submit_sourcing_request These tools are listed anonymously and their own descriptions ask for an account or key, but no challenge is issued — so a client has nothing to act on and the refusal arrives as a tool error. |
What the probe found
6 of the 55 tools listed anonymously say in their own descriptions that they need an account or a key (search_suppliers, create_project, get_supplier_profile, list_supplier_rfqs, get_supplier_rfq, submit_sourcing_request), but the endpoint issued no WWW-Authenticate challenge. The requirement is stated only in prose, so a call reaches the tool and comes back as a tool error instead of an authorization step.
A cross-origin preflight came back without Access-Control-Allow-Origin, so the endpoint is reachable from native clients only — code running in a web page is stopped by the browser before a request is ever sent.
The server exposes a public surface before authorization: describe_supplyslate, list_sourcing_categories, get_connection_guide, list_fabrication_processes, get_live_fabrication_capabilities, search_live_components, get_requirement_schema, search_products, get_product, get_compatibility, list_supplier_taxonomy, search_suppliers, get_supplier, create_project, get_project, update_project_requirements, create_artifact_upload, attach_artifact_reference, upsert_bom, get_bom, validate_project, list_project_validations, source_project, create_purchase_plan, get_purchase_plan, request_purchase_approval, get_checkout_handoffs, create_provider_checkout_handoff, list_orders, get_order, report_order_issue, request_order_cancellation, request_order_return, open_warranty_claim, get_supplier_profile, upsert_supplier_catalog, create_catalog_import, update_supplier_capabilities, update_availability, list_supplier_rfqs, get_supplier_rfq, submit_supplier_quote, ask_rfq_clarification, revise_supplier_quote, decline_supplier_rfq, list_supplier_orders, update_supplier_order, update_supplier_order_issue, decide_supplier_order_cancellation, update_supplier_order_return, update_supplier_warranty_claim, submit_sourcing_request, list_sourcing_requests, get_sourcing_request, get_supplier_offers.
Tools
Contract history
Get alerted when this contract changes
Depend on this server? Leave an email and get a message when a probe records a change — a tool removed, an argument newly required, an enum narrowed. Alerts are being built; signing up is what tells us to hurry.
Prefer a feed reader? This page's contract changes are also an Atom feed.
Status badge
Status for a README, from the last probe — cached an hour, so up to seven hours behind the endpoint. Links back to this page.
[](https://mcpi.app/servers/supplyslate)Own this server?
Sign in to claim this listing by proving control of the endpoint.