How it works
From a registry entry to a Trust Score you can act on
Vouchity doesn't audit MCP servers by hand. It reads the same public signals you could check yourself — maintenance, adoption, licensing, declared auth, permissions and publisher identity — and turns them into one transparent number, for every server in the registry.
320 servers scored · snapshot refreshed 2 months ago
We ingest the official registry
Every server starts at the official MCP community registry (registry.modelcontextprotocol.io) — its namespace, version, transports and package identifiers.
We enrich with GitHub & npm
We pull real signals from the server's source repo and package registry: stars, last push, license, archived/deprecated status, open issues and weekly downloads.
We compute five weighted signals
Maintenance, adoption, transparency, security and provenance are each scored 0–100 from concrete evidence, then combined into one overall Trust Score and an A–F grade.
You browse & compare
Search the full registry, filter by category or grade, and see exactly which signals are missing or flagged on any server before you connect it.
Pro tracks what you depend on
Watch the servers your agents actually use and get alerted the moment a Trust Score drops, a new risk flag appears, or a server is deprecated.
Agents vet servers live
Every score is available over a public JSON API and Vouchity's own hosted MCP endpoint, so an agent can check a server's trustworthiness before it ever calls it.
Common questions
Is a Trust Score a security audit?
No. It's an automated heuristic computed from public metadata — maintenance activity, adoption, licensing, declared auth, permission patterns and publisher identity. It's a strong first filter, not a substitute for reading the code of anything you give real permissions to.
How often does the score update?
Vouchity re-syncs the official MCP registry, GitHub and npm on a regular cadence, and every server page shows exactly when its data was last refreshed.
What if a signal can't be verified?
It's excluded from the score entirely, never guessed. The score is a weighted mean over only the signals that are actually verifiable for that server — its coverage (how many of the five were available) is shown alongside it.
Vet before you connect.
Browse every MCP server's Trust Score free. Upgrade to Pro to watch the servers you depend on and get alerted when something changes.