{"schemaVersion":"zeroworker-http-api-discovery-v1","documentType":"http_api_discovery","trustEvidence":{"enabled":true,"policy":"mcp-trust-evidence-v1","mode":"non_invoking_public_metadata","defaultWhenEnabled":true,"callerOptOut":"options.trustEvidence=false","registryHint":"options.registryName","persistence":false,"note":"Protocol, Official Registry and public OAuth metadata evidence; available only when MCP_TRUST_EVIDENCE_ENABLED=true. Best-effort, non-invoking, no OAuth flow, no safety certification; vulnerabilityGate semantics unchanged."},"name":"ZeroWorker MCP Trust Gate","version":"0.3.0","description":"MCP security checks and feedback for users and developers. Choose paid access without reports, or ongoing free access within limits: POST /v1/client-token; 1 check/24h + 1 for a previous-use report. Check URL/DNS, metadata/schema/auth, OSV/CVE risk and catalog drift before connecting. Verified owners can read consented weekly reports. ALLOW/BLOCK/UNKNOWN uses caller-confirmed versions. No tool execution or safety certification. Terms: /complimentary-policy.","tagline":"Check before connecting. Turn feedback into better MCPs.","purpose":"ZeroWorker MCP Trust Gate connects MCP users and developers through security checks and feedback. Users can build pre-connection checks into their workflows; developers can self-check their MCPs and use Provider Insights to read protected, consented weekly feedback for endpoints they control.","canonical":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/discovery.json","endpoint":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/mcp","serverCard":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/mcp/server-card","guide":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/mcp-guide","registryMetadata":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/server.json","compatibility":{"httpJsonApi":true,"a2a":false,"mcpServer":true,"note":"MCP tools are available through Streamable HTTP at /mcp; native HTTP JSON operations remain available through OpenAPI. See /mcp-guide for access and supported versions. This is a tool/API service, not an A2A agent."},"api":{"method":"POST","url":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/v1/analyze","contentType":"application/json","openapi":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/openapi.json"},"operations":[{"id":"mcp_preflight","name":"Check a public MCP endpoint before connecting","description":"Inspect public MCP reachability, catalog metadata, static risks, caller-confirmed package vulnerabilities and catalog changes. Returns evidence for your connection policy; does not execute tools or certify safety.","tags":["mcp","security","preflight","vulnerability-check","catalog-drift"],"examples":["Check this public MCP before adding it to my project.","Recheck my MCP after an update and review catalog changes."],"inputModes":["application/json"],"outputModes":["application/json"],"invocation":{"transport":"http_json","method":"POST","url":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/v1/analyze","openapi":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/openapi.json#/paths/~1v1~1analyze/post","requestExample":{"url":"https://your-public-mcp.example/mcp","options":{"mcpSecurity":true,"catalogHistory":true}},"access":"Use paid x402 access, or first obtain a client token and add complimentary access as documented in the quickstart. Free limits apply.","instructions":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/quickstart"}},{"id":"mcp_provider_insights","name":"Read feedback for an MCP endpoint you control","description":"After endpoint ownership verification, read protected weekly aggregates of explicitly shared complimentary reports. Shows reported outcomes and non-use reasons only after maturity and minimum data thresholds; no individual reports or verified-user counts.","tags":["mcp","developer-feedback","weekly-reports","endpoint-ownership"],"examples":["Review reported authentication problems for the MCP endpoint I control."],"inputModes":["application/json"],"outputModes":["application/json"],"invocation":{"transport":"http_json","method":"GET","urlTemplate":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/v1/provider-targets/{id}/insights","openapi":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/openapi.json#/paths/~1v1~1provider-targets~1{id}~1insights/get","access":"Requires a separate owner bearer token from endpoint verification. The anonymous free-analysis token does not grant report access.","instructions":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/developers/reports"}}],"audiences":["MCP users","AI agent builders","MCP developers"],"useCases":["Before first MCP use","Before a scheduled workflow","After updates","Developer checks before release"],"checks":["Public URL and DNS safety","MCP reachability and catalog metadata","Static poisoning/schema/auth inspection (Phase 1)","OSV known-vulnerability matching","CVE priority enrichment (EPSS/KEV/ransomware)","Catalog drift (Phase 2)"],"access":{"model":"paid_or_recurring_free","sameAnalysisPipeline":true,"paid":{"enabled":true,"protocol":"x402 v2","price":"$0.005","currency":"USDC","reportRequired":false,"paymentOptions":[{"scheme":"exact","network":"eip155:8453","asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","payTo":"0xad277cf8B5D9fa5008D06cBdBE349F5DF3c0Cc8f","currency":"USDC","price":"$0.005","amount":"5000"},{"scheme":"exact","network":"solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp","asset":"EPjFWdd5AufqSSqeM2qN1xzybapC8G4wEGGkZwyTDt1v","payTo":"EtmJof6dunotKvh18rBhfqeML5kZp6gCUmiY6MSf4qjb","currency":"USDC","price":"$0.005","amount":"5000"}],"policy":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/payment-policy"},"free":{"version":"complimentary-discovery-v1","enabled":true,"accessModel":"recurring_free_with_optional_feedback","message":"Ongoing free access available: POST /v1/client-token with {}. Reuse your token. One check per rolling 24h plus nine unlocked by one honest previous-use report. Client quotas and shared capacity apply; no paid upgrade is required to keep using available free grants.","walletRequired":false,"accountRequired":false,"quotaScope":"anonymous_client_not_verified_person","daily":{"count":1,"rollingHours":24},"contribution":{"count":9,"rollingHours":24,"unlockHours":24,"requires":"One unused observation token and an honest report; subsequent unlocked calls need no report"},"clientToken":{"method":"POST","url":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/v1/client-token","headers":{"Content-Type":"application/json"},"body":{},"responseField":"anonymousClientToken","reuseForDays":90},"analyze":{"method":"POST","url":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/v1/analyze","headers":{"Content-Type":"application/json"},"bodyExample":{"url":"https://your-public-mcp.example/mcp","access":{"mode":"complimentary","clientToken":"YOUR_SAVED_CLIENT_TOKEN"}}},"onLimit":"Wait for your allowance or explicitly authorize x402 payment. Do not rotate client tokens to evade quotas. No automatic charge follows a 402.","reportTrust":"unverified_self_report","policy":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/complimentary-policy","guide":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/llms.txt","browser":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/complimentary","browserTrial":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/complimentary","developers":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/developers"}},"feedback":{"purpose":"Honest success, failure and not-used reports all earn the same contribution credit. With explicit sharing consent, new reports contribute to protected weekly Provider Insights for verified endpoint owners. Existing service-only reports remain private to the service. Sharing is optional and does not change free credit. Small groups are suppressed; self-reports do not establish verified users or safety.","reportTrust":"unverified_self_report","currentSharing":"explicit_new_ticket_consent_only","ownerSharingAvailable":true},"developerCapabilities":{"guide":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/developers","selfCheck":{"status":"available","method":"POST","url":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/v1/analyze","purpose":"Check your public MCP before release and after updates using the same evidence agents see."},"providerInsights":{"status":"available","releaseStatus":"released","apiAvailable":true,"purpose":"Owner-scoped, consented aggregate feedback to help MCP developers understand reported use, failures and reasons for not using their MCP.","currentSharing":"explicit_new_ticket_consent_only","sharingConsentAvailable":true,"dashboard":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/developers/reports","policy":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/provider-policy","claims":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/v1/provider-claims","ownership":"Endpoint control must be verified before sharing any provider report.","evidence":"Unverified self-reports; not a user count, benchmark, security score or safety certification."}},"boundaries":["No target tool execution or runtime monitoring","No safety certification","Client enforces its connection decision","Provider Insights requires endpoint control and explicit sharing consent"],"documentation":{"demo":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/demo","quickstart":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/quickstart","freeAccess":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/complimentary","developers":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/developers","llms":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/llms.txt","workflow":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/SKILL.md","x402":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/.well-known/x402","history":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/history-policy"},"x-zeroworker-mcp":{"endpoint":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/mcp","serverCard":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/mcp/server-card","guide":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/mcp-guide","registryMetadata":"https://zeroworker-mcp-preflight-api.zeroworker-lab.workers.dev/server.json","transport":"streamable-http","supportedProtocolVersions":["2025-11-25","2025-06-18","2025-03-26"]}}