Free listing · human-reviewed · scanned first

List your MCP server.

Every server in the gate directory carries a live tool list and a security grade. Scan yours, and if it grades B or better, submit it for review.

Streamable-HTTP endpoint, reachable without sign-in. The scan takes ~30 seconds.

How it works

Three steps, one email.

01

Scan

Paste your Streamable-HTTP endpoint. gate connects, lists the tools and grades them for prompt injection, hidden instructions and over-broad permissions.

02

Submit

At grade B or better, a short form opens — prefilled from your server card and registry entry where we can. Two minutes.

03

Review & list

A human checks the listing against the guidelines below and you get an email either way, usually within a few days.

Guidelines

What gets a server listed.

Reachable, HTTPS, Streamable HTTP

The endpoint must complete the MCP handshake and list tools without sign-in. SSE-only and stdio servers can't be listed.

Grade B or better

No high-severity findings. Fix what the scan flags, redeploy, scan again.

Honest tool descriptions

Descriptions say what a tool does and when to use it — no instructions to the model, no promo copy, no hidden text.

Read and write kept apart

Prefer separate tools for reading and for changing data, with readOnlyHint / destructiveHint annotations. Not required, but reviewers look for it.

A privacy policy you can link

Optional at submit time, but listings without one are marked as such and reviewed more strictly.

No surveillance, no money movement

No identity recognition, tracking of people, or tools that move funds or assets.

FAQ

Questions authors ask.

Does it cost anything?

No. Listing is free, the scan is free, and the grade is re-checked weekly for free. Authors who want alerts when a tool changes or the grade drops can monitor their server in gate (paid).

My server needs an API key or OAuth. Can I list it?

Not through this form yet — the scanner can't grade what it can't reach. Publish the server in the official MCP registry: gate imports it within a day and lists it as a sign-in server.

How is the grade computed?

Deterministic checks (prompt-injection patterns, hidden Unicode, exfiltration hints, over-broad permissions, oversized definitions) plus a Claude review of every tool description. 100 points minus deductions; A ≥ 90, B ≥ 78.

Can I edit the listing later?

Reply to your listing email for now. Author accounts with self-serve edits are next on the roadmap.

What if I don't own the server?

You can still submit it. Leave the ownership box unchecked; the listing won't carry the verified-author mark until the operator claims it.

Not the author? Browse what’s already listed.

Open the directory
List Your MCP Server — Free, Security-Scanned Directory Listing | gate