validoria-mcp
warningsapi.teste.no
Continuous website testing by Validoria — monitor security, SEO, performance, and accessibility.
https://api.teste.no/api/mcpWebsiteOAuthMCP 2025-11-25v1.0.0last checked 24 Aug 2026spoke MCP on 3 of 3 checks (30 days)initialize in 165 msHow to authenticate
Checked against the endpoint by our probe on 24 Aug 2026. These are the capabilities the server advertises, not a prediction about any particular client.
| Scheme | OAuth |
|---|---|
| Issuer | http://localhost:4205/auth |
| Dynamic client registration | ✓Advertised (RFC 7591) |
| Client ID Metadata Document | ✕Not advertised |
| PKCE | ✓S256 |
| Grant types | authorization_code, client_credentials, refresh_token |
| Scopes | openid, profile, email, tno:read, tno:write |
| Protected-resource metadata | ✓Published (RFC 9728) |
| Anonymous access | Handshake succeeds; 74 tools listable |
| Credentials demanded in prose | ✕guest_get_scan These tools are listed anonymously and their own descriptions ask for an account or key, but no challenge is issued — so a client has nothing to act on and the refusal arrives as a tool error. |
What the probe found
1 of the 74 tools listed anonymously say in their own descriptions that they need an account or a key (guest_get_scan), but the endpoint issued no WWW-Authenticate challenge. The requirement is stated only in prose, so a call reaches the tool and comes back as a tool error instead of an authorization step.
A cross-origin preflight came back without Access-Control-Allow-Origin, so the endpoint is reachable from native clients only — code running in a web page is stopped by the browser before a request is ever sent.
The server exposes a public surface before authorization: guest_start_scan, guest_get_scan, list_targets, get_target, get_target_scores, list_findings, get_finding, list_incidents, get_incident, list_runs, get_run, active_runs, team_stats, target_stats, daily_trends, get_site_map, list_maintenance_windows, list_tests, trigger_test, trigger_all_tests, acknowledge_incident, resolve_incident, mute_finding, create_maintenance_window, delete_maintenance_window, record_deployment, recompute_scores, list_automation_rules, get_automation_rule, create_automation_rule, update_automation_rule, delete_automation_rule, list_journeys, get_journey, create_journey, update_journey, delete_journey, trigger_journey, list_scheduled_reports, create_scheduled_report, update_scheduled_report, delete_scheduled_report, get_team_settings, update_team_settings, list_notification_rules, create_notification_rule, update_notification_rule, delete_notification_rule, list_notification_channels, list_keywords, add_keyword, remove_keyword, start_load_test, cancel_load_test, get_load_test, list_load_tests, list_secrets, store_secret, rotate_secret, delete_secret, list_page_fragments, create_page_fragment, update_page_fragment, delete_page_fragment, create_target, update_target, delete_target, analyze_target, import_targets, create_muting_rule, system_health, update_test, enable_all_tests, disable_all_tests.
Tools
Contract history
Get alerted when this contract changes
Depend on this server? Leave an email and get a message when a probe records a change — a tool removed, an argument newly required, an enum narrowed. Alerts are being built; signing up is what tells us to hurry.
Prefer a feed reader? This page's contract changes are also an Atom feed.
Status badge
Status for a README, from the last probe — cached an hour, so up to seven hours behind the endpoint. Links back to this page.
[](https://mcpi.app/servers/validoria-mcp)Own this server?
Sign in to claim this listing by proving control of the endpoint.