mcp_transport — pass · 4 of 4 points
The MCP endpoint answers, negotiates a protocol revision and LISTS its tools.
Request: GET https://wix.demo.busymate.ai/mcp. Expected: initialize and tools/list succeed over the transport the handshake actually ran on. Listing is not authorization to call. Received: initialize ok — offered protocol 2025-06-18, server returned 2024-11-05, session ran on 2024-11-05; tools/list ok — 7 tool(s) listed, which says they are listed and not that an agent may call them; transport streamable-http
MCP endpoint https://wix.demo.busymate.ai/mcp · transport streamable-http · protocol offered 2025-06-18, returned 2024-11-05, session ran on 2024-11-05 · initialize true · tools/list true · auth open · OAuth metadata false · access requirements documented the capability manifest · PKCE not measured · dynamic registration not measured (optional either way) · tools LISTED without a token 7 — listed, not usable · authenticated not measured · authenticated execution tested false · readOnlyHint on 7 (the negotiated protocol revision predates tool annotations)
Deeper check
access_requirements — partial · 1.5 of 3 points
The service documents which capabilities need a token and which do not.
Request: GET https://wix.demo.busymate.ai/mcp. Expected: A manifest, a WWW-Authenticate challenge or protected-resource metadata that states the access requirements. Received: Documented in the capability manifest, but no interface in the capability manifest states its own access requirements
MCP endpoint https://wix.demo.busymate.ai/mcp · transport streamable-http · protocol offered 2025-06-18, returned 2024-11-05, session ran on 2024-11-05 · initialize true · tools/list true · auth open · OAuth metadata false · access requirements documented the capability manifest · PKCE not measured · dynamic registration not measured (optional either way) · tools LISTED without a token 7 — listed, not usable · authenticated not measured · authenticated execution tested false · readOnlyHint on 7 (the negotiated protocol revision predates tool annotations)
How to fix (closest guide)
oauth_metadata — fail · 0 of 3 points
OAuth metadata discovery resolves, and advertises PKCE where a client must verify it.
Request: GET https://wix.demo.busymate.ai/mcp. Expected: RFC 8414 / RFC 9728 metadata that resolves, with code_challenge_methods_supported. Dynamic client registration is optional. Received: auth mode open; no RFC 8414 / RFC 9728 metadata resolved at the conventional addresses
MCP endpoint https://wix.demo.busymate.ai/mcp · transport streamable-http · protocol offered 2025-06-18, returned 2024-11-05, session ran on 2024-11-05 · initialize true · tools/list true · auth open · OAuth metadata false · access requirements documented the capability manifest · PKCE not measured · dynamic registration not measured (optional either way) · tools LISTED without a token 7 — listed, not usable · authenticated not measured · authenticated execution tested false · readOnlyHint on 7 (the negotiated protocol revision predates tool annotations)
How to fix · Deeper check
authenticated_execution — unverified · 0 of 2 points
An authenticated call actually succeeds — proof that a listed tool is a usable tool.
Request: GET https://wix.demo.busymate.ai/mcp. Expected: An authenticated tools/call that returns a result. This scanner holds no token for your server and never calls a stranger's tool, so this stays UNVERIFIED — reported, never counted as a pass or as your failure. Received: Could not check: this scanner holds no credential for https://wix.demo.busymate.ai/mcp and never calls a stranger's tool. 7 tool(s) are LISTED without a token; whether any of them executes — with or without one — is untested.
MCP endpoint https://wix.demo.busymate.ai/mcp · transport streamable-http · protocol offered 2025-06-18, returned 2024-11-05, session ran on 2024-11-05 · initialize true · tools/list true · auth open · OAuth metadata false · access requirements documented the capability manifest · PKCE not measured · dynamic registration not measured (optional either way) · tools LISTED without a token 7 — listed, not usable · authenticated not measured · authenticated execution tested false · readOnlyHint on 7 (the negotiated protocol revision predates tool annotations)
Deeper check
tool_annotation_coverage — optional-missing · optional
Listed tools declare readOnlyHint, so a client can tell a read from a write before it calls.
Request: GET https://wix.demo.busymate.ai/mcp. Expected: Optional: annotations on the listed tool definitions. Only meaningful from protocol revision 2025-03-26, which introduced them. Received: Not applicable at the negotiated protocol revision: the session ran on 2024-11-05, and tool annotations were introduced in 2025-03-26. 7 tool(s) listed.
How to fix · Deeper check
openapi_spec — optional-missing · optional
An OpenAPI document describes the HTTP API.
Request: GET https://wix.demo.busymate.ai/openapi.json. Expected: Optional when MCP or another API already describes the interface. Received: HTTP 404, application/json
How to fix (closest guide)
protocol_discovery_aliases — optional-found · optional
Optional well-known aliases (mcp.json, agent-card.json, api-catalog, …) are served cleanly or not at all.
Expected: Optional: each alias is valid JSON or a clean non-200 — never the site's own HTML shell. Received: 5 of 5 answered cleanly