Beleeg (public, no account)
REMOTE · BELEEG.COM · SCANNED OCT 3
Public league standings, schedules and brackets; start a league or bracket with no account.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security80
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability62
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1515 tokens (~378/item across 4 items; 4 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management17
- Stability observed for 5 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (75% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 4 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the Beleeg (public, no account) MCP server?
Beleeg (public, no account) is a hosted endpoint at https://beleeg.com/api/mcp/public, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · beleeg.com
claude mcp add --transport http com-beleeg-beleeg-public 'https://beleeg.com/api/mcp/public'
{
"mcpServers": {
"com-beleeg-beleeg-public": {
"url": "https://beleeg.com/api/mcp/public"
}
}
} {
"servers": {
"com-beleeg-beleeg-public": {
"type": "http",
"url": "https://beleeg.com/api/mcp/public"
}
}
} [mcp_servers.com-beleeg-beleeg-public] url = "https://beleeg.com/api/mcp/public"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-beleeg-beleeg-public": {
"type": "remote",
"url": "https://beleeg.com/api/mcp/public",
"enabled": true
}
}
} openclaw mcp add com-beleeg-beleeg-public --url 'https://beleeg.com/api/mcp/public' --transport streamable-http
mcp_servers:
com-beleeg-beleeg-public:
url: "https://beleeg.com/api/mcp/public" {
"McpServers": {
"com-beleeg-beleeg-public": {
"Transport": "http",
"Url": "https://beleeg.com/api/mcp/public"
}
}
} assistant mcp add com-beleeg-beleeg-public -t streamable-http -u 'https://beleeg.com/api/mcp/public'
{
"mcpServers": {
"com-beleeg-beleeg-public": {
"type": "http",
"url": "https://beleeg.com/api/mcp/public"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Oct 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 13 to 17. That category is still filling its 30-day observation window: 4 days of observed history at the previous scan, 5 at this one. The score rises as the window fills, whether or not the server changes.
- 1 Oct 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.
- 29 Sept 26 +1
- Stability: unverified → 0.03 ▲ functional
- 28 Sept 26 71
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Oct 2026 · Probed https://beleeg.com/api/mcp/public
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=beleeg.com | CN=YR1,O=Let's Encrypt,C=US | 18 Sept 2026 | 17 Dec 2026 | RSA 2048 | SHA256-RSA | 6aeadd028d57f9e94c4881a6bf18fb1c479 |
| SANs: beleeg.com | ||||||
| CN=YR1,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | a20253f15f2691c05dc1ce13b9bcca4e |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of beleeg.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| beleeg.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000 |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(self), geolocation=(self), payment=(self "https://js.stripe.com" "https://checkout.stripe.com") |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://beleeg.com/api/mcp/public | Verified | 200 | |
| http (plaintext) | http://beleeg.com/api/mcp/public | HTTPS enforced | 308 | https://beleeg.com/api/mcp/public |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
beleeg_look_up_public Look up a public page ~305
Look up what anyone can see on Beleeg — a league, team, match or tournament public page — no membership needed. Read-only. Pick `what` and give the slug or id listed for it. what (params; ? = optional): - league: A league's public page by its slug: sport, current season, teams, standings. [slug] - team: A team's public page by its slug: roster, captain, colours, recent matches. [slug] - match: One match by match_id: teams, lineups, set scores, venue. [match_id] - tournament: One tournament's public page by tournament_id: status, entrants, bracket. [tournament_id] - league_tournaments: The tournaments a league shows the public, by the league slug. [league_slug]
| Name | Type | Req | Description |
|---|---|---|---|
| league_slug | string | – | Public league slug (not UUID). Used with what: league_tournaments. |
| match_id | string | – | One match id (from what "schedule"). For the match-day lookups, leave out to mean the person's next match. Used with what: match. |
| slug | string | – | Public URL-safe league slug. Used with what: league, team. |
| tournament_id | string | – | A tournament id, from what "tournaments". Used with what: tournament. |
| what | string | yes | What to look up. Every value is listed, with its params, in the tool description. |
No output schema declared.
No examples provided.
beleeg_send_feedback Tell Beleeg what was missing ~199
Send Beleeg a note when it cannot do something the person asked for, or when a tool was confusing or gave a wrong answer. Say what they wanted and, if one did, which tool fell short. Never include personal details — names, emails or phone numbers — of the person or anyone else. The Beleeg team reads these to decide what to build; nothing is done automatically and nobody replies, so still tell the person what you could not do and, where there is one, where in Beleeg they can do it themselves.
| Name | Type | Req | Description |
|---|---|---|---|
| message | string | yes | What Beleeg could not do, or what was confusing or wrong, in a sentence or two. No names, emails or phone numbers of anyone. |
| tool | string | – | The tool that fell short, if one did. |
| trying_to | string | – | What the person was trying to get done, e.g. "move all of Saturday's games to Sunday". |
| Name | Type | Req | Description |
|---|---|---|---|
| received | boolean | yes | – |
No examples provided.
beleeg_start_league Start a league (no account needed) ~540
Creates a real league on Beleeg right away for someone who does not have a Beleeg account yet: the league, its first season with registration open, optional teams, and a public page. It is held for the organizer whose email you give: to take it over they open the claim_url, sign in at beleeg.com with THAT email address (email code, Google or Apple), and choose to keep it. Signing in alone does not make it theirs. Always give the person the claim_url exactly as returned (never build a link from the name) and tell them which email to sign in with. Ask the person for their email; never guess one. If Beleeg refuses, tell the person to sign in to Beleeg with that email and ask again. After signing in, the organizer is asked whether to keep the league or discard it; it is theirs only once they keep it. Invited people are saved but not emailed until the organizer has kept the league and sends them. If the organizer has not kept it within 30 days, the league is removed. Limits: 3 per organizer email per day, 5 per caller per day, and at most 3 leagues or brackets waiting on the organizer. Team names that differ only by capitals or spacing are treated as one team. Tell the person what you are about to create and get a yes BEFORE calling this; there is no separate confirm step.
| Name | Type | Req | Description |
|---|---|---|---|
| city | string | – | Town or city, shown on the public page. |
| client | string | – | Which assistant this is, for example muse, claude, chatgpt, cursor. |
| inviteEmails | array | – | People to invite (up to 200). They are only SAVED as pending invites: no email goes out until the organizer has signed in, kept the league, and sends them. |
| name | string | yes | League name, plain text, for example "Tuesday Night Pickleball". |
| organizationName | string | – | Club or group name. Defaults to the league name. |
| organizerEmail | string | yes | The organizer's own email address. They sign in with it to take over the league. Ask for it; never guess. |
| registrationClosesOn | string | – | Last day to register, YYYY-MM-DD. Defaults to 30 days from today. |
| sport | string | yes | Sport key, for example pickleball, platform-tennis, tennis, softball, volleyball. |
| teams | array | – | Team names to create right away (up to 64). |
| timezone | string | yes | IANA time zone the league plays in, for example America/Chicago. |
| Name | Type | Req | Description |
|---|---|---|---|
| claim_instructions | string | yes | Read this to the person. |
| claim_url | string | yes | Give this to the organizer: it explains how to take over the league. |
| invites_pending | integer | yes | Invites saved but NOT sent. |
| league_id | string | yes | – |
| name | string | yes | – |
| organization_id | string | yes | – |
| organizer_email | string | yes | – |
| public_url | string | yes | The public league page. Works right away, and says the league is waiting for its organizer until it is kept. Use it exactly as returned: while the league waits its address ends in a few extra charact… |
| slug | string | yes | – |
| teams | array | yes | – |
| unclaimed_expires_on | string | yes | If the organizer has not signed in and kept the league by this date, it is removed. |
No examples provided.
beleeg_start_tournament Start a tournament bracket (no account needed) ~471
Creates a real standalone tournament bracket on Beleeg right away for someone who does not have a Beleeg account yet: the draw is built from the entrants you give. It is never attached to an existing league or organization. It is held for the organizer whose email you give: to take it over they open the claim_url, sign in at beleeg.com with THAT email address (email code, Google or Apple), and choose to keep it. Signing in alone does not make it theirs. Always give the person the claim_url exactly as returned (never build a link from the name) and tell them which email to sign in with. Ask the person for their email; never guess one. If Beleeg refuses, tell the person to sign in to Beleeg with that email and ask again. After signing in, the organizer is asked whether to keep the bracket or discard it; it is theirs only once they keep it. Until then nobody else can see the entrants or the draw: the bracket page only says it is waiting for its organizer. If the organizer has not kept it within 30 days, the bracket is removed. Limits: up to 64 entrants (32 for round robin); 3 per organizer email per day, 5 per caller per day, and at most 3 leagues or brackets waiting on the organizer. Tell the person what you are about to create and get a yes BEFORE calling this; there is no separate confirm step.
| Name | Type | Req | Description |
|---|---|---|---|
| bestOf | integer | – | Sets per match, 1 to 9. Defaults to 3. |
| client | string | – | Which assistant this is, for example muse, claude, chatgpt, cursor. |
| entrants | – | yes | Who is playing: a list of names, or text with one entrant per line. For pairs write "Ann Lee / Bo Park". 2 to 64 entrants (2 to 32 for round_robin). |
| format | string | – | Bracket format. Defaults to single_elim. |
| name | string | yes | Tournament name, plain text. |
| organizerEmail | string | yes | The organizer's own email address. They sign in with it to run the bracket. Ask for it; never guess. |
| registrationUnit | string | – | solo (default) or pair (doubles). |
| Name | Type | Req | Description |
|---|---|---|---|
| claim_instructions | string | yes | Read this to the person. |
| claim_url | string | yes | Give this to the organizer: it explains how to run the bracket. |
| entrants | integer | yes | – |
| format | string | yes | – |
| name | string | yes | – |
| organizer_email | string | yes | – |
| public_url | string | yes | The bracket page. Until the organizer keeps the bracket it only says the tournament is waiting for its organizer; the entrants and the draw show once it is kept. |
| tournament_id | string | yes | – |
| unclaimed_expires_on | string | – | If the organizer has not signed in and kept the bracket by this date, it is removed. |
No examples provided.
What is the Beleeg (public, no account) MCP server?
Beleeg (public, no account) is an MCP server listed in the public MCP registry as com.beleeg/beleeg-public. Public league standings, schedules and brackets; start a league or bracket with no account. This page covers its hosted endpoint (https://beleeg.com/api/mcp/public).
Is the Beleeg (public, no account) MCP server safe to use?
Beleeg (public, no account) scores 74 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Beleeg (public, no account) MCP server expose?
Beleeg (public, no account) exposes 4 tools: beleeg_look_up_public, beleeg_start_league, beleeg_start_tournament, beleeg_send_feedback. Their descriptions and schemas cost roughly 1,515 tokens of context every time the server is loaded.
Does the Beleeg (public, no account) MCP server require authentication?
No. We connected to Beleeg (public, no account) without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Beleeg (public, no account) MCP server still maintained?
Beleeg (public, no account) is still listed as active in the MCP registry. We last reached this channel on 3 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.