BusinessMCP

MCP server tester

Paste a remote MCP endpoint and find out in seconds whether it speaks the protocol — initialize handshake, server info, and the full tools list. The fastest way to debug "why won't my client connect".

Free tool, fair-use limited (10 tests/hour). HTTPS endpoints only; tokens are never stored.

Data API

Scan it for prompt injection, then get alerted when it changes

The same check is an API call and an MCP tool your AI agent can use, on one key. The first 1,000 credits every month are free, no card needed.

MCP server scan

5 credits per call

Is an MCP server live, and do its tool descriptions hide prompt injection?

POST/api/hub/v1/mcp/scan

curl -X POST https://businessmcp.com/api/hub/v1/mcp/scan \
  -H "Authorization: Bearer $BUSINESSMCP_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url":"https://mcp.example.com/mcp"}'

MCP tool mcp_server_scan · full reference

Monitor an MCP server

5 credits per call

Watch an MCP server for downtime and silent tool changes. 1 credit per check.

POST/api/hub/v1/mcp/monitors

curl -X POST https://businessmcp.com/api/hub/v1/mcp/monitors \
  -H "Authorization: Bearer $BUSINESSMCP_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url":"https://mcp.example.com/mcp","interval":"daily"}'

MCP tool mcp_monitor_create · full reference

Building or hosting a server?

The build-an-MCP-server tutorial walks through the current SDK, and the MCP hosting guide covers managed vs self-hosted. Your own business already has an endpoint on BusinessMCP — test it right here with an mcph_ key.

Free plan available · No credit card

Frequently asked questions

What does this tester actually do?

It speaks the Model Context Protocol to your endpoint over streamable HTTP: an initialize handshake (protocol version, server info, capabilities) followed by tools/list. If both succeed, your server is valid MCP and any compliant client — Claude Desktop, Cursor, the OpenAI ecosystem — should be able to connect.

My server works locally over stdio — can I test it here?

No — this tool tests REMOTE servers over HTTPS. For local stdio servers use the official MCP Inspector (npx @modelcontextprotocol/inspector). To make a local server remotely reachable, deploy it with a streamable-HTTP transport first.

Is my bearer token safe?

The token is used for the two test requests and never stored or logged. Still, best practice applies: use a scoped, revocable key for testing — BusinessMCP keys, for example, can be scoped by access policy so a test key can’t read revenue or contact data.

It says "reachable but no valid JSON-RPC initialize result" — what now?

Common causes: the URL is a website not an MCP endpoint; the server only speaks the older SSE transport (GET-based) rather than streamable HTTP; or a proxy strips POST bodies. Check that POST with Accept: application/json, text/event-stream reaches your MCP handler.