Superflow Free Tools
REMOTE · USESUPERFLOW.AI · SCANNED SEP 20
19 free website QA and AI-visibility tools. Remote HTTP MCP, no account, no API key.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 14 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability65
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 4824 tokens (~344/item across 14 items; 14 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 14 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 15 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
- Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
How do I install the Superflow Free Tools MCP server?
Superflow Free Tools is a hosted endpoint at https://usesuperflow.ai/api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · usesuperflow.ai
claude mcp add --transport http ai-usesuperflow-tools 'https://usesuperflow.ai/api/mcp'
{
"mcpServers": {
"ai-usesuperflow-tools": {
"url": "https://usesuperflow.ai/api/mcp"
}
}
} {
"servers": {
"ai-usesuperflow-tools": {
"type": "http",
"url": "https://usesuperflow.ai/api/mcp"
}
}
} [mcp_servers.ai-usesuperflow-tools] url = "https://usesuperflow.ai/api/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"ai-usesuperflow-tools": {
"type": "remote",
"url": "https://usesuperflow.ai/api/mcp",
"enabled": true
}
}
} openclaw mcp add ai-usesuperflow-tools --url 'https://usesuperflow.ai/api/mcp' --transport streamable-http
mcp_servers:
ai-usesuperflow-tools:
url: "https://usesuperflow.ai/api/mcp" {
"McpServers": {
"ai-usesuperflow-tools": {
"Transport": "http",
"Url": "https://usesuperflow.ai/api/mcp"
}
}
} assistant mcp add ai-usesuperflow-tools -t streamable-http -u 'https://usesuperflow.ai/api/mcp'
{
"mcpServers": {
"ai-usesuperflow-tools": {
"type": "http",
"url": "https://usesuperflow.ai/api/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Sept 26 0
- Stability: 0.97 → pass security
- 19 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.
- 14 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 77 to 80. That category is still filling its 30-day observation window: 23 days of observed history at the previous scan, 24 at this one. The score rises as the window fills, whether or not the server changes.
- 12 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 70 to 73. That category is still filling its 30-day observation window: 21 days of observed history at the previous scan, 22 at this one. The score rises as the window fills, whether or not the server changes.
- 10 Sept 26 +1
- The server rewrote its instructions, which are the text every model session reads security
- Schema quality: 4274 → 4824 ▼ functional
- New tool “find_meeting_times” functional
- 8 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.
- 6 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 50 to 53. That category is still filling its 30-day observation window: 15 days of observed history at the previous scan, 16 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://usesuperflow.ai/api/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=usesuperflow.ai | CN=YR1,O=Let's Encrypt,C=US | 27 Jul 2026 | 25 Oct 2026 | RSA 2048 | SHA256-RSA | 5f2d86790d4f40b6d3f0cfe05eb0b019d67 |
| SANs: usesuperflow.ai | ||||||
| CN=YR1,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | a20253f15f2691c05dc1ce13b9bcca4e |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of usesuperflow.ai. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| ai. | present | 3799 | 8 | Verified |
| usesuperflow.ai. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://usesuperflow.ai/api/mcp | Verified | 200 | |
| http (plaintext) | http://usesuperflow.ai/api/mcp | HTTPS enforced | 308 | https://usesuperflow.ai/api/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
build_utm_url UTM Builder ~360
Build a campaign URL with utm parameters, normalised to one tagging convention, and report which GA4 default channel group the link will land in. Warns about the mistakes that silently break reporting: an unrecognised medium that drops traffic into Unassigned, casing that splits one source into several report rows, PII in a campaign name. Pure string work: nothing is fetched and nothing is stored. Returns { url, normalized, channel, issues[] with level, field and message }. Limit: None. The work is local and costs nothing.. Allow up to 10s for a response. Free, no account, no API key.
| Name | Type | Req | Description |
|---|---|---|---|
| campaign | string | – | utm_campaign. The campaign name, e.g. spring_launch. |
| caseRule | string | – | How values are cased before they go in the URL. Default lower, which is what keeps one source from becoming three report rows. |
| content | string | – | utm_content. Optional variant, e.g. header_link. |
| id | string | – | utm_id. Optional campaign ID. |
| medium | string | – | utm_medium. How it gets there, e.g. email, cpc, social. This is the field GA4 reads to pick a channel. |
| source | string | – | utm_source. Where the traffic comes from, e.g. newsletter. |
| spaceRule | string | – | What happens to spaces inside a value. |
| stripPunctuation | boolean | – | Drop accents and punctuation that make report rows hard to match. |
| term | string | – | utm_term. Optional paid keyword. |
| url | string | yes | The destination page. Existing utm parameters on it are rewritten; any other query parameter is left alone. |
No output schema declared.
No examples provided.
capture_full_page_screenshot Full Page Screenshot ~325
Capture a full-height PNG of a page in a real headless browser, scrolling first so lazy-loaded content renders. Returns a signed link to the image that expires in about 24 hours; download the bytes if you need to keep them. No watermark and no height cap. Cannot capture anything behind a login. Returns { imageUrl, expiresAt, bytes, width, height, deviceType }. Limit: 10 runs per hour per IP. Allow up to 90s for a response. Free, no account, no API key. Pass `url` to start a run. A slow run answers with `{ status: "pending", runId }` instead of a result: call this same tool again with just that `runId` to collect it, as many times as it takes. Collecting costs no rate-limit slot.
| Name | Type | Req | Description |
|---|---|---|---|
| refresh | boolean | – | Skip the 24 hour cache and run again. Costs a rate-limit slot even when a cached result exists, so leave it off unless the page has changed. |
| runId | string | – | Collect a run that answered with `{ status: "pending", runId }` instead of a result. Send the runId back on its own, with no url, and the same tool returns the finished result once the run is done. C… |
| url | string | – | The page to run against. A bare domain like example.com is fine; https is assumed. Must be a public URL: anything behind a login, on a private network, or on localhost is refused. |
No output schema declared.
No examples provided.
check_ai_visibility AI Visibility Checker ~399
Check whether AI assistants (ChatGPT, Claude, Perplexity, Google AI) can reach, read, and cite a web page. Runs the full suite: robots.txt rules per AI crawler, a live firewall test that requests the page as GPTBot, JavaScript dependency, llms.txt, headings, structured data, and author identity. Returns a score out of 100 with a grade, a score per category, and a finding per check with why it matters and how to fix it. Use this for a whole-page verdict; use check_robots_txt_for_ai when the question is only about crawler access. Returns { ok, report: { score, grade, scoredOutOf, categories[], findings[] with why and fix, detection }, cached, ageSeconds }. Limit: 10 runs per hour per IP. Allow up to 75s for a response. Free, no account, no API key. Pass `url` to start a run. A slow run answers with `{ status: "pending", runId }` instead of a result: call this same tool again with just that `runId` to collect it, as many times as it takes. Collecting costs no rate-limit slot.
| Name | Type | Req | Description |
|---|---|---|---|
| refresh | boolean | – | Skip the 24 hour cache and run again. Costs a rate-limit slot even when a cached result exists, so leave it off unless the page has changed. |
| runId | string | – | Collect a run that answered with `{ status: "pending", runId }` instead of a result. Send the runId back on its own, with no url, and the same tool returns the finished result once the run is done. C… |
| url | string | – | The page to run against. A bare domain like example.com is fine; https is assumed. Must be a public URL: anything behind a login, on a private network, or on localhost is refused. |
No output schema declared.
No examples provided.
check_favicon Favicon Checker ~280
Check whether a site's favicon actually works. Reads every icon declaration in the page head, then fetches each one, the web app manifest, and the implicit /favicon.ico, and identifies the real format and pixel dimensions from each file's header bytes. Catches the failures a status-code check misses: a catch-all route answering an icon path with HTML at HTTP 200, a sizes attribute that disagrees with the file, an icon served over http on an https page. Use this when a favicon is missing or blurry; use check_social_preview for the image that appears when a link is shared. Returns { hasWorkingFavicon, tabIcon, icons[] with format, dimensions, bytes and problem, manifest, themeColor, checks[] with id, status and fix, counts }. Limit: 60 runs per hour per IP. Allow up to 30s for a response. Free, no account, no API key.
| Name | Type | Req | Description |
|---|---|---|---|
| refresh | boolean | – | Skip the 24 hour cache and run again. Costs a rate-limit slot even when a cached result exists, so leave it off unless the page has changed. |
| url | string | yes | The page to run against. A bare domain like example.com is fine; https is assumed. Must be a public URL: anything behind a login, on a private network, or on localhost is refused. |
No output schema declared.
No examples provided.
check_robots_txt_for_ai robots.txt AI Checker ~366
Test a site's robots.txt against every AI crawler that matters (GPTBot, ClaudeBot, PerplexityBot, Google-Extended, CCBot, Googlebot, Bingbot and the rest) and report which are allowed, which are blocked, and which rule decided it. Also runs a firewall test, because CDN-level blocks stop crawlers before robots.txt is ever read. This is the access-scoped view of check_ai_visibility. Returns { ok, report: { accessScore, crawlers[] with the rule that decided each verdict, firewall, findings[] }, cached, ageSeconds }. Limit: 10 runs per hour per IP. Allow up to 75s for a response. Free, no account, no API key. Pass `url` to start a run. A slow run answers with `{ status: "pending", runId }` instead of a result: call this same tool again with just that `runId` to collect it, as many times as it takes. Collecting costs no rate-limit slot.
| Name | Type | Req | Description |
|---|---|---|---|
| refresh | boolean | – | Skip the 24 hour cache and run again. Costs a rate-limit slot even when a cached result exists, so leave it off unless the page has changed. |
| runId | string | – | Collect a run that answered with `{ status: "pending", runId }` instead of a result. Send the runId back on its own, with no url, and the same tool returns the finished result once the run is done. C… |
| url | string | – | The page to run against. A bare domain like example.com is fine; https is assumed. Must be a public URL: anything behind a login, on a private network, or on localhost is refused. |
No output schema declared.
No examples provided.
check_social_preview Social Preview Checker ~328
Read a page's Open Graph and Twitter card tags and report how the link will render on X, LinkedIn, Facebook, Slack, Discord, and Google. Returns a per-platform preview (title, description, image) plus the findings for tags that are missing, truncated, or the wrong size. Returns { ok, report: { previews[] per platform, tags, summary, findings[] }, cached, ageSeconds }. Limit: 10 runs per hour per IP. Allow up to 75s for a response. Free, no account, no API key. Pass `url` to start a run. A slow run answers with `{ status: "pending", runId }` instead of a result: call this same tool again with just that `runId` to collect it, as many times as it takes. Collecting costs no rate-limit slot.
| Name | Type | Req | Description |
|---|---|---|---|
| refresh | boolean | – | Skip the 24 hour cache and run again. Costs a rate-limit slot even when a cached result exists, so leave it off unless the page has changed. |
| runId | string | – | Collect a run that answered with `{ status: "pending", runId }` instead of a result. Send the runId back on its own, with no url, and the same tool returns the finished result once the run is done. C… |
| url | string | – | The page to run against. A bare domain like example.com is fine; https is assumed. Must be a public URL: anything behind a login, on a private network, or on localhost is refused. |
No output schema declared.
No examples provided.
detect_tech_stack Tech Stack Detector ~211
Identify the platform, framework, CMS, ecommerce apps, analytics, CDN, and hosting behind a site by fingerprinting one page's HTML and response headers. One fetch, no rendering and no crawl, so it answers in about a second. A site behind bot protection is reported as blocked rather than as empty. Returns { platformName, theme, apps[], fonts[], analytics[], hosting[], renderMode, url, status, fetchedAt }. Limit: 60 runs per hour per IP. Allow up to 30s for a response. Free, no account, no API key.
| Name | Type | Req | Description |
|---|---|---|---|
| refresh | boolean | – | Skip the 24 hour cache and run again. Costs a rate-limit slot even when a cached result exists, so leave it off unless the page has changed. |
| url | string | yes | The page to run against. A bare domain like example.com is fine; https is assumed. Must be a public URL: anything behind a login, on a private network, or on localhost is refused. |
No output schema declared.
No examples provided.
find_meeting_times Time Zone Converter & Meeting Planner ~482
Find overlapping working hours and meeting times across cities or countries. Resolves locations to IANA time zones and applies daylight saving for the requested date. Returns resolved locations, overlap windows, the earliest matching meeting starts with UTC and local times, readable copy text, and a link to open the plan. Ambiguous names or countries with multiple zones return choices: retry with a returned location ID or a more specific city/region/country. The same working schedule is applied in each location's local time; the browser plan supports individual schedules. Does not access calendars, account for holidays, send invitations, or book meetings. Returns { ok, date, dateZone, durationMinutes, locations[], overlapMinutes, overlapWindows[], slots[] with UTC/local times and copyText, totalAvailableStarts, hasMore, planUrl, availability }. Limit: No application rate limit. Up to 8 locations, 20 returned starts, and a 16 KB request body; no result storage.. Allow up to 10s for a response. Free, no account, no API key.
| Name | Type | Req | Description |
|---|---|---|---|
| date | string | yes | Meeting date as YYYY-MM-DD (2000–2099), in the first location's time zone. Required: use the actual meeting date so daylight saving is correct. |
| durationMinutes | number | – | Length of the whole meeting, 15–1440 minutes in 15-minute increments. |
| limit | number | – | Maximum suggested meeting starts to return, 1–20. Earliest first, at 15-minute intervals; totalAvailableStarts reports the full count. |
| locations | array | yes | Cities, single-zone countries, or location IDs returned in choices. Include a region/country to distinguish namesakes, e.g. San Francisco California or London United Kingdom. The first location deter… |
| workDays | string | – | Comma-separated working days: 0=Sunday through 6=Saturday. For overnight shifts, the day the shift starts. Applied to all locations. |
| workEnd | string | – | End of working hours, as local 24-hour HH:mm, in 15-minute increments. An earlier end means an overnight shift. Must differ from workStart. |
| workStart | string | – | Start of working hours, as local 24-hour HH:mm, in 15-minute increments. Applied to all locations. |
No output schema declared.
No examples provided.
generate_alt_text Alt Text Generator ~347
Find every image on a page and draft alt text for the ones that need it, using a vision model that actually looks at the image. Lists every image with the alt it has today, the suggested alt, whether it looks decorative, and why any image was skipped. Up to 10 images per run go to the model. The suggestions are drafts for a human to review. Returns { images[] with src, hadAlt, currentAlt, suggestedAlt, isDecorative, skippedReason; counts; model }. Limit: 10 runs per hour per IP. Allow up to 90s for a response. Free, no account, no API key. Pass `url` to start a run. A slow run answers with `{ status: "pending", runId }` instead of a result: call this same tool again with just that `runId` to collect it, as many times as it takes. Collecting costs no rate-limit slot.
| Name | Type | Req | Description |
|---|---|---|---|
| refresh | boolean | – | Skip the 24 hour cache and run again. Costs a rate-limit slot even when a cached result exists, so leave it off unless the page has changed. |
| runId | string | – | Collect a run that answered with `{ status: "pending", runId }` instead of a result. Send the runId back on its own, with no url, and the same tool returns the finished result once the run is done. C… |
| url | string | – | The page to run against. A bare domain like example.com is fine; https is assumed. Must be a public URL: anything behind a login, on a private network, or on localhost is refused. |
No output schema declared.
No examples provided.
generate_json_ld JSON-LD Generator ~339
Read a page and write a schema.org JSON-LD block for it, then validate that block against the same checks a validator would run. The markup is model-written from the page's own content and should be reviewed before it is published. Returns the block ready to paste into a <script type="application/ld+json"> tag. Returns { ok, report: { detectedType, jsonLd, jsonLdString, validation: { findings[], passed }, model } }. Limit: 10 runs per hour per IP. Allow up to 75s for a response. Free, no account, no API key. Pass `url` to start a run. A slow run answers with `{ status: "pending", runId }` instead of a result: call this same tool again with just that `runId` to collect it, as many times as it takes. Collecting costs no rate-limit slot.
| Name | Type | Req | Description |
|---|---|---|---|
| refresh | boolean | – | Skip the 24 hour cache and run again. Costs a rate-limit slot even when a cached result exists, so leave it off unless the page has changed. |
| runId | string | – | Collect a run that answered with `{ status: "pending", runId }` instead of a result. Send the runId back on its own, with no url, and the same tool returns the finished result once the run is done. C… |
| url | string | – | The page to run against. A bare domain like example.com is fine; https is assumed. Must be a public URL: anything behind a login, on a private network, or on localhost is refused. |
No output schema declared.
No examples provided.
generate_llms_txt llms.txt Generator ~362
Generate llms.txt and llms-full.txt for a site, following the llmstxt.org convention. Inventories the site from its robots.txt, sitemaps, and homepage links, then writes an index file and a full file with page content inlined. Deterministic: no model is involved, so two runs over an unchanged site produce the same bytes. Returns the file contents ready to write to disk. Returns { ok, report: { siteName, llmsTxt, llmsFullTxt, pagesDiscovered, pagesIncluded, truncated }, cached, ageSeconds }. Limit: 10 runs per hour per IP. Allow up to 75s for a response. Free, no account, no API key. Pass `url` to start a run. A slow run answers with `{ status: "pending", runId }` instead of a result: call this same tool again with just that `runId` to collect it, as many times as it takes. Collecting costs no rate-limit slot.
| Name | Type | Req | Description |
|---|---|---|---|
| refresh | boolean | – | Skip the 24 hour cache and run again. Costs a rate-limit slot even when a cached result exists, so leave it off unless the page has changed. |
| runId | string | – | Collect a run that answered with `{ status: "pending", runId }` instead of a result. Send the runId back on its own, with no url, and the same tool returns the finished result once the run is done. C… |
| url | string | – | The page to run against. A bare domain like example.com is fine; https is assumed. Must be a public URL: anything behind a login, on a private network, or on localhost is refused. |
No output schema declared.
No examples provided.
hash_md5 MD5 Hash Generator ~116
Hash text to an MD5 hex digest. Useful for checksums, cache keys, dedupe keys, and Gravatar-style identifiers. MD5 is broken for anything security-related: never use it for passwords or to verify authenticity. Returns { md5, algorithm, bytes }. Limit: None. The work is local and costs nothing.. Allow up to 10s for a response. Free, no account, no API key.
| Name | Type | Req | Description |
|---|---|---|---|
| text | string | yes | The text to hash. Up to 1 MB of UTF-8. |
No output schema declared.
No examples provided.
page_to_markdown Markdown for Agents ~326
Fetch one web page and convert it to clean CommonMark, with the navigation, cookie banners, and boilerplate stripped out. Use this to read a page as text an agent can reason over, or to publish a .md copy of a page alongside the HTML. Returns { ok, report: { markdown, title, description, wordCount, bytes, truncated, httpStatus }, cached, ageSeconds }. Limit: 10 runs per hour per IP. Allow up to 75s for a response. Free, no account, no API key. Pass `url` to start a run. A slow run answers with `{ status: "pending", runId }` instead of a result: call this same tool again with just that `runId` to collect it, as many times as it takes. Collecting costs no rate-limit slot.
| Name | Type | Req | Description |
|---|---|---|---|
| refresh | boolean | – | Skip the 24 hour cache and run again. Costs a rate-limit slot even when a cached result exists, so leave it off unless the page has changed. |
| runId | string | – | Collect a run that answered with `{ status: "pending", runId }` instead of a result. Send the runId back on its own, with no url, and the same tool returns the finished result once the run is done. C… |
| url | string | – | The page to run against. A bare domain like example.com is fine; https is assumed. Must be a public URL: anything behind a login, on a private network, or on localhost is refused. |
No output schema declared.
No examples provided.
validate_json_ld JSON-LD Validator ~311
Read the structured data already on a page and check it against Schema.org and what search engines actually accept. Reports every JSON-LD block found, the type of each, and the errors and warnings per block. Returns { ok, report: { blockCount, invalidBlockCount, declaredTypes[], eligibility[], categories[], findings[] } }. Limit: 10 runs per hour per IP. Allow up to 75s for a response. Free, no account, no API key. Pass `url` to start a run. A slow run answers with `{ status: "pending", runId }` instead of a result: call this same tool again with just that `runId` to collect it, as many times as it takes. Collecting costs no rate-limit slot.
| Name | Type | Req | Description |
|---|---|---|---|
| refresh | boolean | – | Skip the 24 hour cache and run again. Costs a rate-limit slot even when a cached result exists, so leave it off unless the page has changed. |
| runId | string | – | Collect a run that answered with `{ status: "pending", runId }` instead of a result. Send the runId back on its own, with no url, and the same tool returns the finished result once the run is done. C… |
| url | string | – | The page to run against. A bare domain like example.com is fine; https is assumed. Must be a public URL: anything behind a login, on a private network, or on localhost is refused. |
No output schema declared.
No examples provided.
What is the Superflow Free Tools MCP server?
Superflow Free Tools is an MCP server listed in the public MCP registry as ai.usesuperflow/tools. 19 free website QA and AI-visibility tools. Remote HTTP MCP, no account, no API key. This page covers its hosted endpoint (https://usesuperflow.ai/api/mcp).
Is the Superflow Free Tools MCP server safe to use?
Superflow Free Tools scores 77 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Superflow Free Tools MCP server expose?
Superflow Free Tools exposes 14 tools: find_meeting_times, check_ai_visibility, check_robots_txt_for_ai, generate_llms_txt, page_to_markdown, and 9 more. Their descriptions and schemas cost roughly 4,552 tokens of context every time the server is loaded.
Does the Superflow Free Tools MCP server require authentication?
No. We connected to Superflow Free Tools without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Superflow Free Tools MCP server still maintained?
Superflow Free Tools is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.