← All servers

validoria-mcp

warnings

api.teste.no

Continuous website testing by Validoria — monitor security, SEO, performance, and accessibility.

https://api.teste.no/api/mcpWebsiteOAuthMCP 2025-11-25v1.0.0last checked 24 Aug 2026spoke MCP on 3 of 3 checks (30 days)initialize in 165 ms

How to authenticate

Checked against the endpoint by our probe on 24 Aug 2026. These are the capabilities the server advertises, not a prediction about any particular client.

Scheme
OAuth
Issuer
http://localhost:4205/auth
Dynamic client registration
Advertised (RFC 7591)
Client ID Metadata Document
Not advertised
PKCE
S256
Grant types
authorization_code, client_credentials, refresh_token
Scopes
openid, profile, email, tno:read, tno:write
Protected-resource metadata
Published (RFC 9728)
Anonymous access
Handshake succeeds; 74 tools listable
Credentials demanded in prose
guest_get_scan

These tools are listed anonymously and their own descriptions ask for an account or key, but no challenge is issued — so a client has nothing to act on and the refusal arrives as a tool error.

What the probe found

warningTools needing credentials are listed without a challenge

1 of the 74 tools listed anonymously say in their own descriptions that they need an account or a key (guest_get_scan), but the endpoint issued no WWW-Authenticate challenge. The requirement is stated only in prose, so a call reaches the tool and comes back as a tool error instead of an authorization step.

No CORS headers for browser-based clients

A cross-origin preflight came back without Access-Control-Allow-Origin, so the endpoint is reachable from native clients only — code running in a web page is stopped by the browser before a request is ever sent.

74 tools usable without signing in

The server exposes a public surface before authorization: guest_start_scan, guest_get_scan, list_targets, get_target, get_target_scores, list_findings, get_finding, list_incidents, get_incident, list_runs, get_run, active_runs, team_stats, target_stats, daily_trends, get_site_map, list_maintenance_windows, list_tests, trigger_test, trigger_all_tests, acknowledge_incident, resolve_incident, mute_finding, create_maintenance_window, delete_maintenance_window, record_deployment, recompute_scores, list_automation_rules, get_automation_rule, create_automation_rule, update_automation_rule, delete_automation_rule, list_journeys, get_journey, create_journey, update_journey, delete_journey, trigger_journey, list_scheduled_reports, create_scheduled_report, update_scheduled_report, delete_scheduled_report, get_team_settings, update_team_settings, list_notification_rules, create_notification_rule, update_notification_rule, delete_notification_rule, list_notification_channels, list_keywords, add_keyword, remove_keyword, start_load_test, cancel_load_test, get_load_test, list_load_tests, list_secrets, store_secret, rotate_secret, delete_secret, list_page_fragments, create_page_fragment, update_page_fragment, delete_page_fragment, create_target, update_target, delete_target, analyze_target, import_targets, create_muting_rule, system_health, update_test, enable_all_tests, disable_all_tests.

Tools

acknowledge_incidentactive_runsadd_keywordanalyze_targetcancel_load_testcreate_automation_rulecreate_journeycreate_maintenance_windowcreate_muting_rulecreate_notification_rulecreate_page_fragmentcreate_scheduled_reportcreate_targetdaily_trendsdelete_automation_ruledelete_journeydelete_maintenance_windowdelete_notification_ruledelete_page_fragmentdelete_scheduled_reportdelete_secretdelete_targetdisable_all_testsenable_all_testsget_automation_ruleget_findingget_incidentget_journeyget_load_testget_runget_site_mapget_targetget_target_scoresget_team_settingsguest_get_scanguest_start_scanimport_targetslist_automation_ruleslist_findingslist_incidentslist_journeyslist_keywordslist_load_testslist_maintenance_windowslist_notification_channelslist_notification_ruleslist_page_fragmentslist_runslist_scheduled_reportslist_secretslist_targetslist_testsmute_findingrecompute_scoresrecord_deploymentremove_keywordresolve_incidentrotate_secretstart_load_teststore_secretsystem_healthtarget_statsteam_statstrigger_all_teststrigger_journeytrigger_testupdate_automation_ruleupdate_journeyupdate_notification_ruleupdate_page_fragmentupdate_scheduled_reportupdate_targetupdate_team_settingsupdate_test

Contract history

24 Aug 2026v1.0.0first recorded contract

Get alerted when this contract changes

Depend on this server? Leave an email and get a message when a probe records a change — a tool removed, an argument newly required, an enum narrowed. Alerts are being built; signing up is what tells us to hurry.

Prefer a feed reader? This page's contract changes are also an Atom feed.

Status badge

Status for a README, from the last probe — cached an hour, so up to seven hours behind the endpoint. Links back to this page.

MCP status badge for validoria-mcp
[![MCP status](https://mcpi.app/servers/validoria-mcp/badge.svg)](https://mcpi.app/servers/validoria-mcp)

Own this server?

Sign in to claim this listing by proving control of the endpoint.