atx/registry

apis.io

https://apis.io/mcp

75
trust
0.55
confidence
low
risk
trust-2026-08-12.2
observed 2d ago

Why this score

oauth_metadata_present+14
tls_present_and_valid+12
mcp.unauthenticated_consequential_tools-8
reachable+6
mcp_capabilities_discoverable+4
headers.missing_hsts-3

Findings (3)

mediumCapabilities are listable without authentication, including 5 whose names suggest state change (add_to_list, create_list, delete_list, …) — inferred from tool names, not confirmed
mcp.unauthenticated_consequential_tools @ 1.0.0
lowNo Strict-Transport-Security header
headers.missing_hsts @ 1.0.0
infoCORS allows any origin
cors.wildcard_origin @ 1.0.0

Evidence (7)

TypeObservedSHA-256
dns_resolution_observation2d ago6e9505e9a8c59e15…
http_response_observation2d ago17a75643e9aa3670…
availability_observation2d ago44beca55971e1e34…
tls_certificate_observation2d ago3e7b98e92aaaa061…
oauth_metadata_observation2d ago60368530eef5fed7…
mcp_protocol_observation2d ago69f8444f41a8dc35…
mcp_capability_observation2d ago2ce82c6c78fe70c2…

Every record is append-only and content-hashed. Corrections supersede; nothing is overwritten.

Operate this service?

Prove control of apis.io to correct the record and request a rescan after fixing a finding. One DNS record — no account needed.

Claim this profile →