# Portamora (remote · portamora.app)

Discover atmospheric 3D worlds, read controls, and build and publish authorized environments.

- Trust score: 39/100 (low)
- Change this week: −29
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-02

## Components

- remote · `portamora.app`: 39/100 (this document), [markdown](https://verifymcp.io/servers/app-portamora-mcp/portamora.md), [page](https://verifymcp.io/servers/app-portamora-mcp/portamora)

## Channel facts

- Endpoint: `https://portamora.app/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `0.2.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-02.

- **Endpoint Security**: 97/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - The endpoint enforces authorisation, advertised via RFC 9728 protected-resource metadata.
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC is configured correctly; the domain's records validate against the full chain to the root.
  - The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents.
- **Transport & Reachability**: 0/100
  - Transport blocked by authentication: the endpoint requires auth we don't have to verify streamable-http.
- **Schema Quality & AI Usability**: 0/100
  - Schema blocked by authentication: the endpoint requires auth we don't have to read it.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 0/100
  - Tool coverage blocked by authentication: the endpoint requires auth we don't have to read its tools.
- **Tool Safety**: 0/100
  - Tool safety blocked by authentication: the endpoint requires auth we don't have to read its tools.
- **Capabilities**: 0/100
  - Capabilities blocked by authentication: the endpoint requires auth we don't have to read them.

**Unverified: 6 categories.** Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.

## Install

### How do I install the Portamora MCP server?

Portamora is a hosted endpoint at https://portamora.app/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http app-portamora-mcp 'https://portamora.app/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "app-portamora-mcp": {
      "url": "https://portamora.app/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "app-portamora-mcp": {
      "type": "http",
      "url": "https://portamora.app/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.app-portamora-mcp]
url = "https://portamora.app/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "app-portamora-mcp": {
      "type": "remote",
      "url": "https://portamora.app/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add app-portamora-mcp --url 'https://portamora.app/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  app-portamora-mcp:
    url: "https://portamora.app/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "app-portamora-mcp": {
      "Transport": "http",
      "Url": "https://portamora.app/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add app-portamora-mcp -t streamable-http -u 'https://portamora.app/mcp'
```

### Other

```json
{
  "mcpServers": {
    "app-portamora-mcp": {
      "type": "http",
      "url": "https://portamora.app/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-28 (score 39, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-26 (score 39, −29)

- [security regression] Endpoint reachability: reachable → behind authorisation
- [security regression] Stability: fail → unverified
- [security regression] Tool safety: pass → unverified
- [security regression] Transport: pass → unverified
- [security improvement] Authorization: unverified → pass
- [security] First check of Authorization: partial
- [functional regression] Capabilities: pass → unverified
- [functional regression] Tool coverage: 100 → unverified
- [functional regression] Schema quality: 100 → unverified

### 2026-09-25 (score 68, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-24 (score 68, 0)

- [security] The server rewrote its instructions, which are the text every model session reads

### 2026-09-15 (score 68, −2)

- [security regression] Authorization: fail → unverified
- [security regression] Tool “create_comment” was removed
- [security regression] Tool “create_image_upload” was removed
- [security regression] Tool “create_report” was removed
- [security regression] Tool “create_upload” was removed
- [security regression] Tool “delete_comment” was removed
- [security regression] Tool “delete_feature_flag” was removed
- [security regression] Tool “delete_world” was removed
- [security regression] Tool “dislike_world” was removed
- [security regression] Tool “edit_comment” was removed
- [security regression] Tool “favorite_world” was removed
- [security regression] Tool “find_admin_users” was removed
- [security regression] Tool “follow_creator” was removed
- [security regression] Tool “get_moderation_evidence” was removed
- [security regression] Tool “get_moderation_report” was removed
- [security regression] Tool “get_my_profile” was removed
- [security regression] Tool “get_my_version” was removed
- [security regression] Tool “get_my_world” was removed
- [security regression] Tool “get_upload” was removed
- [security regression] Tool “identify_agent” was removed
- [security regression] Tool “like_world” was removed
- [security regression] Tool “list_admin_audit” was removed
- [security regression] Tool “list_favorites” was removed
- [security regression] Tool “list_feature_flags” was removed
- [security regression] Tool “list_followed_creators” was removed
- [security regression] Tool “list_following_worlds” was removed
- [security regression] Tool “list_moderation_reports” was removed
- [security regression] Tool “list_my_versions” was removed
- [security regression] Tool “list_my_worlds” was removed
- [security regression] Tool “list_notices” was removed
- [security regression] Tool “mark_notice_read” was removed
- [security regression] Tool “moderate_report” was removed
- [security regression] Tool “preview_version” was removed
- [security regression] Tool “publish_world” was removed
- [security regression] Tool “refresh_upload” was removed
- [security regression] Tool “remove_dislike” was removed
- [security regression] Tool “remove_favorite” was removed
- [security regression] Tool “remove_like” was removed
- [security regression] Tool “save_feature_flag” was removed
- [security regression] Tool “take_world_offline” was removed
- [security regression] Tool “unfollow_creator” was removed
- [security regression] Tool “update_world” was removed
- [security] Tool “search_worlds” rewrote its description, which is the text the model reads
- [functional improvement] Schema quality: 3110 → 837
- [functional improvement] Tool “get_creator” now declares an output schema
- [functional improvement] Tool “get_version” now declares an output schema
- [functional improvement] Tool “get_world” now declares an output schema
- [functional improvement] Tool “search_worlds” now declares an output schema
- [functional] First check of Tool coverage: 50
- [functional] Destructive annotations: 100 → pass
- [functional] New resource “agents”
- [functional] Server version: 0.1.0 → 0.2.0

### 2026-09-14 (score 70, +1)

No change was recorded against any check on this day. Stability & Change Management went from 9 to 12.

### 2026-09-12 (score 69, +1)

- [security regression] Stability: 0.03 → fail
- [security regression] A breaking change shipped without a version bump: still 0.1.0
- [security] Tool “create_comment” rewrote its description, which is the text the model reads
- [security] Tool “create_image_upload” rewrote its description, which is the text the model reads
- [security] Tool “create_report” rewrote its description, which is the text the model reads
- [security] Tool “create_upload” rewrote its description, which is the text the model reads
- [security] Tool “delete_comment” rewrote its description, which is the text the model reads
- [security] Tool “dislike_world” rewrote its description, which is the text the model reads
- [security] Tool “edit_comment” rewrote its description, which is the text the model reads
- [security] Tool “favorite_world” rewrote its description, which is the text the model reads
- [security] Tool “follow_creator” rewrote its description, which is the text the model reads
- [security] Tool “get_community” rewrote its description, which is the text the model reads
- [security] Tool “like_world” rewrote its description, which is the text the model reads
- [security] Tool “list_comments” rewrote its description, which is the text the model reads
- [security] Tool “list_favorites” rewrote its description, which is the text the model reads
- [security] Tool “list_followed_creators” rewrote its description, which is the text the model reads
- [security] Tool “list_following_worlds” rewrote its description, which is the text the model reads
- [security] Tool “moderate_report” rewrote its description, which is the text the model reads
- [security] Tool “remove_dislike” rewrote its description, which is the text the model reads
- [security] Tool “remove_favorite” rewrote its description, which is the text the model reads
- [security] Tool “remove_like” rewrote its description, which is the text the model reads
- [security] Tool “search_worlds” rewrote its description, which is the text the model reads
- [security] Tool “unfollow_creator” rewrote its description, which is the text the model reads
- [security] Tool “create_comment” no longer declares itself destructive
- [security] Tool “create_image_upload” no longer declares itself destructive
- [security] Tool “create_upload” no longer declares itself destructive
- [security] Tool “favorite_world” no longer declares itself destructive
- [security] Tool “follow_creator” no longer declares itself destructive
- [functional regression] “search_worlds” changed the type of “days”: number → integer|string
- [cosmetic] “get_creator” reworded the description of “handle”
- [cosmetic] “search_worlds” reworded the description of “creator”
- [cosmetic] “search_worlds” reworded the description of “tag”
- [cosmetic] Tool “create_comment” changed its title: Create comment
- [cosmetic] Tool “create_image_upload” changed its title: Create image upload
- [cosmetic] Tool “create_report” changed its title: Create report
- [cosmetic] Tool “create_upload” changed its title: Create upload
- [cosmetic] Tool “delete_comment” changed its title: Delete comment
- [cosmetic] Tool “delete_feature_flag” changed its title: Delete feature flag
- [cosmetic] Tool “delete_world” changed its title: Delete world
- [cosmetic] Tool “dislike_world” changed its title: Dislike world
- [cosmetic] Tool “edit_comment” changed its title: Edit comment
- [cosmetic] Tool “favorite_world” changed its title: Favorite world
- [cosmetic] Tool “find_admin_users” changed its title: Find admin users
- [cosmetic] Tool “follow_creator” changed its title: Follow creator
- [cosmetic] Tool “get_community” changed its title: Get community
- [cosmetic] Tool “get_creator” changed its title: Get creator
- [cosmetic] Tool “get_moderation_evidence” changed its title: Get moderation evidence
- [cosmetic] Tool “get_moderation_report” changed its title: Get moderation report
- [cosmetic] Tool “get_my_profile” changed its title: Get my profile
- [cosmetic] Tool “get_my_version” changed its title: Get my version
- [cosmetic] Tool “get_my_world” changed its title: Get my world
- [cosmetic] Tool “get_upload” changed its title: Get upload
- [cosmetic] Tool “get_version” changed its title: Get version
- [cosmetic] Tool “get_world” changed its title: Get world
- [cosmetic] Tool “identify_agent” changed its title: Identify agent
- [cosmetic] Tool “like_world” changed its title: Like world
- [cosmetic] Tool “list_admin_audit” changed its title: List admin audit
- [cosmetic] Tool “list_comments” changed its title: List comments
- [cosmetic] Tool “list_favorites” changed its title: List favorites
- [cosmetic] Tool “list_feature_flags” changed its title: List feature flags
- [cosmetic] Tool “list_followed_creators” changed its title: List followed creators
- [cosmetic] Tool “list_following_worlds” changed its title: List following worlds
- [cosmetic] Tool “list_moderation_reports” changed its title: List moderation reports
- [cosmetic] Tool “list_my_versions” changed its title: List my versions
- [cosmetic] Tool “list_my_worlds” changed its title: List my worlds
- [cosmetic] Tool “list_notices” changed its title: List notices
- [cosmetic] Tool “mark_notice_read” changed its title: Mark notice read
- [cosmetic] Tool “moderate_report” changed its title: Moderate report
- [cosmetic] Tool “preview_version” changed its title: Preview version
- [cosmetic] Tool “publish_world” changed its title: Publish world
- [cosmetic] Tool “refresh_upload” changed its title: Refresh upload
- [cosmetic] Tool “remove_dislike” changed its title: Remove dislike
- [cosmetic] Tool “remove_favorite” changed its title: Remove favorite
- [cosmetic] Tool “remove_like” changed its title: Remove like
- [cosmetic] Tool “save_feature_flag” changed its title: Save feature flag
- [cosmetic] Tool “search_worlds” changed its title: Search worlds
- [cosmetic] Tool “take_world_offline” changed its title: Take world offline
- [cosmetic] Tool “unfollow_creator” changed its title: Unfollow creator
- [cosmetic] Tool “update_world” changed its title: Update world

### 2026-09-11 (score 68, 0)

- [functional improvement] Stability: unverified → 0.03

## MCP tools (8)

### `search_worlds` (~253 tokens)

Search worlds

Browse and search published worlds. Sort by newest, liked, or trending. The days filter accepts 1, 7 (API default), or 30 UTC calendar days including today, or all for any sort. Newest filters publication date unless days=all or creator is specified. Liked ranks period likes, or lifetime likes when days=all. Trending ranks period activity, or lifetime plays and likes when days=all, with publication-age decay in both cases. Older worlds may appear in activity rankings. The Explore website defaults to liked/all; API defaults remain newest/7. Search text can include exact #tags; custom tags are supported without a fixed vocabulary. Liked and trending require the community flag. Follow nextCursor with unchanged filters until null. Drafts and offline worlds are excluded. Public; no authentication is required.

Input parameters:

- `creator` (string): An existing creator handle; lookup ignores case.
- `cursor` (string)
- `days` (integer|string)
- `limit` (integer)
- `q` (string)
- `sort` (string)
- `tag` (string): One to 32 tag characters; optional leading #, surrounding whitespace, and uppercase letters are normalized.

Output parameters:

- `data` (object)
- `status` (integer)

### `get_world` (~49 tokens)

Get world

Read a public world page. Offline and removed worlds retain a notice; drafts are not exposed.

Input parameters:

- `worldId` (string, required): Case-sensitive world identifier with 10 safe-alphabet characters after the prefix.

Output parameters:

- `data` (object)
- `status` (integer)

### `get_version` (~47 tokens)

Get version

Read the current ready version of a published world. Unpublished versions are not exposed.

Input parameters:

- `versionId` (string, required): Case-sensitive version identifier with 10 safe-alphabet characters after the prefix.

Output parameters:

- `data` (object)
- `status` (integer)

### `get_creator` (~40 tokens)

Get creator

Read an active creator profile. Email addresses, roles and account state are never exposed.

Input parameters:

- `handle` (string, required): An existing creator handle; lookup ignores case.

Output parameters:

- `data` (object)
- `status` (integer)

### `get_community` (~34 tokens)

Get community

Read server-evaluated community and play-counting flags. Personal state is returned by me.get. Lists use cursor pagination.

### `list_comments` (~69 tokens)

List comments

Read plain-text comments, newest first, with deletion placeholders. Viewer controls are private; no-store. Lists use cursor pagination.

Input parameters:

- `cursor` (string)
- `limit` (integer)
- `worldId` (string, required): Case-sensitive world identifier with 10 safe-alphabet characters after the prefix.

### `read_guide` (~45 tokens)

Read an official Portamora guide, policy, agent discovery file, or OpenAPI specification. Start with worlds before building and workflows before uploading.

Input parameters:

- `guide` (string, required)

### `get_starter` (~37 tokens)

Get the editable starter ZIP and the build guide. Download and build it in your own workspace; the MCP server does not execute world code.

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/app-portamora-mcp/portamora#diagnostics

## Score history

- 2026-10-02: 39
- 2026-10-01: 39
- 2026-09-30: 39
- 2026-09-29: 39
- 2026-09-28: 39
- 2026-09-27: 39
- 2026-09-26: 39
- 2026-09-25: 68
- 2026-09-24: 68
- 2026-09-23: 68
- 2026-09-22: 68
- 2026-09-21: 68
- 2026-09-20: 68
- 2026-09-19: 68
- 2026-09-18: 68
- 2026-09-17: 68
- 2026-09-16: 68
- 2026-09-15: 68
- 2026-09-14: 70
- 2026-09-13: 69
- 2026-09-12: 69
- 2026-09-11: 68
- 2026-09-10: 68

## Common questions

### What is the Portamora MCP server?

Portamora is an MCP server listed in the public MCP registry as app.portamora/mcp. Discover atmospheric 3D worlds, read controls, and build and publish authorized environments. This page covers its hosted endpoint (https://portamora.app/mcp).

### Is the Portamora MCP server safe to use?

Portamora scores 39 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Portamora MCP server expose?

Portamora exposes 8 tools: search_worlds, get_world, get_version, get_creator, get_community, and 3 more. Their descriptions and schemas cost roughly 574 tokens of context every time the server is loaded.

### Does the Portamora MCP server require authentication?

Yes. Portamora asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

### Is the Portamora MCP server still maintained?

Portamora is still listed as active in the MCP registry. We last reached this channel on 2 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://portamora.app/mcp
- Website: https://portamora.app/agents
- Changelog RSS feed: https://verifymcp.io/servers/app-portamora-mcp/portamora.xml
- Changelog JSON feed: https://verifymcp.io/servers/app-portamora-mcp/portamora.json
- HTML version of this page: https://verifymcp.io/servers/app-portamora-mcp/portamora
