About our probing
If you operate an MCP server and noticed a request with this User-Agent, this page explains why.
Your endpoint is on our initial public tracking list — a short, hand-picked set of well-known MCP servers. Every request identifies itself with the User-Agent below.
MCPCheckup-Probe/1.0 (+https://mcpcheckup.com/probe)Scheduled checks, on servers without an active operator claim: one round every 12 hours, at most 8 requests per round, per endpoint.
Scheduled checks, on servers with an active operator claim: one round every 8 hours on the Free plan and every 15 minutes on Indie, at most 8 requests per round, per endpoint.
One-off checks started by a visitor or by an agent through our MCP endpoint: at most 8 requests per check, and never more than one check per host every 10 minutes. These run only when someone explicitly asks for a check of that endpoint.
When we discover a server on our own, we read its robots.txt first and skip servers that disallow automated clients. Checks that a maintainer or a visitor asks for are not subject to robots.txt.
We never send authentication credentials of our own — if your server requires auth, we only observe how it challenges for it, not attempt to bypass it.
Email us and we will stop every check of that endpoint. The server is removed from the directory, and its report and attestation pages return 404 from then on. Signed records already issued stay in our database unchanged; we no longer publish them.