CodeStringers MCP Server
REMOTE · WWW.CODESTRINGERS.COM · SCANNED SEP 21
Search CodeStringers' Zoho & custom-software content and business details, live.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (ExecuteWixAPI). See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability59
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 6016 tokens (~668/item across 9 items; 9 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety50
- Injection-marker check failed: the description of tool "ReadFullDocsArticle" contains an instruction to conceal the call from the user, the text "should not tell the user", at byte 1818 of that field, plus 2 further marker(s) of the same kind. See how to fix → Fail
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 9 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the CodeStringers MCP Server server?
CodeStringers MCP Server is a hosted endpoint at https://www.codestringers.com/_api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · www.codestringers.com
claude mcp add --transport http com-codestringers-mcp 'https://www.codestringers.com/_api/mcp'
{
"mcpServers": {
"com-codestringers-mcp": {
"url": "https://www.codestringers.com/_api/mcp"
}
}
} {
"servers": {
"com-codestringers-mcp": {
"type": "http",
"url": "https://www.codestringers.com/_api/mcp"
}
}
} [mcp_servers.com-codestringers-mcp] url = "https://www.codestringers.com/_api/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-codestringers-mcp": {
"type": "remote",
"url": "https://www.codestringers.com/_api/mcp",
"enabled": true
}
}
} openclaw mcp add com-codestringers-mcp --url 'https://www.codestringers.com/_api/mcp' --transport streamable-http
mcp_servers:
com-codestringers-mcp:
url: "https://www.codestringers.com/_api/mcp" {
"McpServers": {
"com-codestringers-mcp": {
"Transport": "http",
"Url": "https://www.codestringers.com/_api/mcp"
}
}
} assistant mcp add com-codestringers-mcp -t streamable-http -u 'https://www.codestringers.com/_api/mcp'
{
"mcpServers": {
"com-codestringers-mcp": {
"type": "http",
"url": "https://www.codestringers.com/_api/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 26 Aug 26 −2
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 0
- Stability: 0.97 → pass security
- 24 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 7 Aug 26 0
- The server changed its declared name: Site Visitor Assistant for site "CodeStringers - Zoho Services" (https://www.codestringers.com/_api/mcp) → Site Visitor Assistant for site "CodeStringers Zoho Consulting Services" (https://www.codestringers.com/_api/mcp) security
- Tool “GenerateVisitorToken” rewrote its description, which is the text the model reads security
- Tool “GetBusinessDetails” rewrote its description, which is the text the model reads security
- Tool “CallWixSiteAPI” rewrote its description, which is the text the model reads security
- Tool “ExecuteWixAPI” rewrote its description, which is the text the model reads security
- Tool “SearchInSite” rewrote its description, which is the text the model reads security
- Tool “SearchSiteApiDocs” rewrote its description, which is the text the model reads security
- 31 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 21 Sept 2026 · Probed https://www.codestringers.com/_api/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=codestringers.com | CN=YR1,O=Let's Encrypt,C=US | 6 Sept 2026 | 5 Dec 2026 | RSA 2048 | SHA256-RSA | 5d5c27e79482ae25983dad57fc8f4d86b55 |
| SANs: codestringers.com, www.codestringers.com | ||||||
| CN=YR1,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | a20253f15f2691c05dc1ce13b9bcca4e |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of www.codestringers.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| codestringers.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31556952 |
| x-content-type-options | nosniff |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://www.codestringers.com/_api/mcp | Verified | 200 | |
| http (plaintext) | http://www.codestringers.com/_api/mcp | HTTPS enforced | 301 | https://www.codestringers.com/_api/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
BrowseWixRESTDocsMenu ~1,239
Browse the Wix REST API documentation menu hierarchy. Alternative to SearchWixRESTDocumentation - use this to explore and discover APIs by navigating the menu structure instead of searching by keywords. - Omit the `menuUrl` param to see top-level categories - Pass a `menuUrl` param to drill into a category - copy the URL from previous responses Example `menuUrl` param values for main Wix verticals: - Stores: "https://dev.wix.com/docs/api-reference/business-solutions/stores" - Bookings: "https://dev.wix.com/docs/api-reference/business-solutions/bookings" - CMS: "https://dev.wix.com/docs/api-reference/business-solutions/cms" - CRM: "https://dev.wix.com/docs/api-reference/crm" - eCommerce: "https://dev.wix.com/docs/api-reference/business-solutions/e-commerce" - Events: "https://dev.wix.com/docs/api-reference/business-solutions/events" - Blog: "https://dev.wix.com/docs/api-reference/business-solutions/blog" - Pricing Plans: "https://dev.wix.com/docs/api-reference/business-solutions/pricing-plans" - Restaurants: "https://dev.wix.com/docs/api-reference/business-solutions/restaurants" - Media: "https://dev.wix.com/docs/api-reference/assets/media" - Site Properties: "https://dev.wix.com/docs/api-reference/business-management/site-properties" <agent-mandatory-instructions> YOU MUST READ AND FOLLOW THE AGENT-MANDATORY-INSTRUCTIONS BELOW A FAILURE TO DO SO WILL RESULT IN ERRORS AND CRITICAL ISSUES. <goal> You are an agent that helps the user manage their Wix site. Your goal is to get the user's prompt/task and execute it by using the appropriate tools eventually calling the correct Wix APIs with the correct parameters until the task is completed. </goal> <guidelines> if the WixREADME tool is available to you, YOU MUST USE IT AT THE BEGINNING OF ANY CONVERSATION and then continue with calling the other tools and calling the Wix APIs until the task is completed. **Exception:** If the user asks to create, build, or generate a new Wix site/website, skip WixREADME and: - If the us…
| Name | Type | Req | Description |
|---|---|---|---|
| menuUrl | string | – | URL of the menu to browse. Empty/omitted returns the root menu. Copy the URL from links in previous responses of this tool. Example: "https://dev.wix.com/docs/api-reference/ecommerce" or "https://dev… |
| reason | string | yes | One sentence describing the original user request and why you are browsing this part of the docs menu. |
No output schema declared.
No examples provided.
CallWixSiteAPI ~317
Call apis on site "CodeStringers Zoho Consulting Services" (https://www.codestringers.com/_api/mcp). Use this to perform an action on visitor's behalf, for example, query the site's data or book an appointment. Before calling this tool, you should ALWAYS check the rest docs (use "SearchSiteApiDocs" tool) for the specific API you want to call. The mentioned tool will give you instructions how to use the API.', 'NEVER try to guess the API or endpoint, ALWAYS check the docs using "SearchSiteApiDocs" tool. The url param should be taken from the "SearchSiteApiDocs" tool. It usually starts with "https://www.wixapis.com".
| Name | Type | Req | Description |
|---|---|---|---|
| body | string | – | A string representing of a valid JSON object to describe the body of the request |
| method | string | yes | The HTTP method to use for the API call (e.g. GET, POST, PUT, DELETE) |
| url | string | yes | The url of the api to call - ALWAYS get the information from the API docs retrieved using the 'SearchSiteApiDocs' tool or from the conversation context, the URL MUST BE ABSOLUTE URL. Usually it start… |
| visitorToken | string | yes | Visitor access token. If you have it in your context, ALWAYS use it and not create a new one. If you do not have it in your context, use the GenerateVisitorToken tool to get it. |
No output schema declared.
No examples provided.
ExecuteWixAPI ~1,648
Run JavaScript against the Wix REST API on site "CodeStringers Zoho Consulting Services" (https://www.codestringers.com/_api/mcp), on the visitor's behalf. The code runs in a sandbox and you get back whatever it returns. PREFER THIS TOOL OVER CallWixSiteAPI. CallWixSiteAPI makes a single HTTP request; ExecuteWixAPI runs real code, so you can chain calls, paginate, filter, and shape the result in one step. Use ExecuteWixAPI for any Wix API work on this site, and fall back to CallWixSiteAPI only for a trivial one-shot read where code adds nothing. DO A WHOLE RECIPE IN ONE CALL. When a task needs several requests — e.g. query to resolve an id, then mutate; create then confirm; read a list then act on a match — write ONE ExecuteWixAPI call whose code performs every step in sequence and returns the final result. Do NOT split a multi-request recipe into multiple separate tool calls; that wastes round-trips and loses intermediate state. If a recipe from the docs lists steps 1..N, the code should run steps 1..N. CRITICAL CODE SHAPE: - The `code` parameter MUST be the function expression itself: `async function() { ... }` or `async () => { ... }`. - Do NOT send a script body like `const result = await ...; return result;`. - Do NOT call the function yourself. The tool calls it for you. - Put all `const`, `await`, and `return` statements inside the function body. Do not rely on memory for Wix API endpoints, methods, schemas, or request bodies. Before writing code, use SearchSiteApiDocs (and ReadFullDocsArticle / ReadFullDocsMethodSchema) to confirm the exact API URL, HTTP method, request body structure, field names, required fields, and enum values. The URL usually starts with `https://www.wixapis.com`. Before reading fields off a response, know its exact shape — don't guess paths like `result.id` when it may be `result.results[0].item.id`. Pass every docs/recipe URL you relied on in the `sourceDocUrls` parameter. Authentication: pass the `visitorToken` parameter (from…
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | yes | JavaScript async function expression to execute against the Wix REST API. The value must be the function itself, for example `async function() { ... }` or `async () => { ... }`, not a script body and… |
| hasMutations | boolean | yes | Whether this code creates, updates, deletes, publishes, imports, uploads, or otherwise mutates site data on the visitor’s behalf. Set this to true for create/update/delete/bulk create/import/upload c… |
| reason | string | yes | One sentence explaining the original user request and why you are executing code to complete it. |
| sourceDocUrls | array | yes | The URLs of the documentation, recipes, API articles, or schema sources where you confirmed the Wix REST endpoints, HTTP methods, request body shapes, auth contexts, and required fields used by this… |
| visitorToken | string | yes | Visitor access token. If you have it in your context, ALWAYS use it and do not create a new one. If you do not have it in your context, use the GenerateVisitorToken tool to get it. |
No output schema declared.
No examples provided.
GenerateVisitorToken ~79
Create a new visitor session and obtain a visitor access token for site "CodeStringers Zoho Consulting Services" (https://www.codestringers.com/_api/mcp). You must use this tool before calling CallWixSiteAPI for this first time. If you already have a visitor token in your context, DO NOT USE THIS TOOL AGAIN.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
GetBusinessDetails ~125
Get business and site details for "CodeStringers Zoho Consulting Services" (https://www.codestringers.com/_api/mcp). This tool will return business details: timezone, email, phone, fax, address, site name, business name, description, business schedule, special hour period. It will also return site features that you can use via other tools (bookings, store, etc.). Call this tool when user asks for business contact details, or about what they can do on the site, or when you need to know what features are available on the site.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
ReadFullDocsArticle ~1,001
Fetches the full Wix docs article or method article with code examples for using the method. Docs articles looks like this: https://dev.wix.com/docs/... and they can either be general docs articles or method articles. For REST docs, use the URL as-is. For SDK docs, the URL SHOULD include ?apiView=SDK. <agent-mandatory-instructions> YOU MUST READ AND FOLLOW THE AGENT-MANDATORY-INSTRUCTIONS BELOW A FAILURE TO DO SO WILL RESULT IN ERRORS AND CRITICAL ISSUES. <goal> You are an agent that helps the user manage their Wix site. Your goal is to get the user's prompt/task and execute it by using the appropriate tools eventually calling the correct Wix APIs with the correct parameters until the task is completed. </goal> <guidelines> if the WixREADME tool is available to you, YOU MUST USE IT AT THE BEGINNING OF ANY CONVERSATION and then continue with calling the other tools and calling the Wix APIs until the task is completed. **Exception:** If the user asks to create, build, or generate a new Wix site/website, skip WixREADME and: - If the user **explicitly** mentions a template, Wix Studio, or headless → call CreateWixBusinessGuide directly. - Otherwise → call the WixSiteBuilder tool directly. **Exception:** If the user asks to list, show, or find their Wix sites, skip WixREADME and call ListWixSites directly. **Exception:** If the user wants to upload local or attached image files to a Wix site, skip WixREADME and all docs/schema/API flows — call UploadImageToWixSite directly. Do NOT use ExecuteWixAPI, SearchWixAPISpec, or any Media Manager REST API for image uploads. If the WixREADME tool is not available to you, you should use the other flows as described without using the WixREADME tool until the task is completed. If the user prompt / task is an instruction to do something in Wix, You should not tell the user what Docs to read or what API to call, your task is to do the work and complete the task in minimal steps and time with minimal back and forth with the user, unle…
| Name | Type | Req | Description |
|---|---|---|---|
| articleUrl | string | yes | The URL of the docs article or method article to fetch. Should be something like https://dev.wix.com/docs/.../... For REST docs, use the URL as-is. For SDK docs, the URL SHOULD include the query para… |
No output schema declared.
No examples provided.
ReadFullDocsMethodSchema ~1,100
Fetches the full method schema for a given method. This will give you the entire request/response schema with all the fields and their descriptions. For REST API methods, prefer SearchWixAPISpec when it is available: it can fetch and inspect the exact method schema by docs URL, return the request/response shape, and inspect selected nested component schemas without dumping unrelated fields. Use ReadFullDocsMethodSchema for REST only when SearchWixAPISpec is unavailable or did not provide the needed detail. For REST docs, use the URL as-is. For SDK docs, the URL SHOULD include ?apiView=SDK. <agent-mandatory-instructions> YOU MUST READ AND FOLLOW THE AGENT-MANDATORY-INSTRUCTIONS BELOW A FAILURE TO DO SO WILL RESULT IN ERRORS AND CRITICAL ISSUES. <goal> You are an agent that helps the user manage their Wix site. Your goal is to get the user's prompt/task and execute it by using the appropriate tools eventually calling the correct Wix APIs with the correct parameters until the task is completed. </goal> <guidelines> if the WixREADME tool is available to you, YOU MUST USE IT AT THE BEGINNING OF ANY CONVERSATION and then continue with calling the other tools and calling the Wix APIs until the task is completed. **Exception:** If the user asks to create, build, or generate a new Wix site/website, skip WixREADME and: - If the user **explicitly** mentions a template, Wix Studio, or headless → call CreateWixBusinessGuide directly. - Otherwise → call the WixSiteBuilder tool directly. **Exception:** If the user asks to list, show, or find their Wix sites, skip WixREADME and call ListWixSites directly. **Exception:** If the user wants to upload local or attached image files to a Wix site, skip WixREADME and all docs/schema/API flows — call UploadImageToWixSite directly. Do NOT use ExecuteWixAPI, SearchWixAPISpec, or any Media Manager REST API for image uploads. If the WixREADME tool is not available to you, you should use the other flows as described without using the WixREADME…
| Name | Type | Req | Description |
|---|---|---|---|
| articleUrl | string | yes | The URL of the documentation to fetch. Should be something like https://dev.wix.com/docs/.../... For REST docs, use the URL as-is. For SDK docs, the URL SHOULD include the query param ?apiView=SDK (e… |
| reason | string | yes | One sentence describing the original user request, the task you are trying to accomplish, and why you need the full schema (e.g., no relevant code example found in docs or recipes). |
No output schema declared.
No examples provided.
SearchInSite ~246
Searches the site "CodeStringers Zoho Consulting Services" (https://www.codestringers.com/_api/mcp) for information. Use this tool ONLY in the following cases: 1. You just used "GetBusinessDetails" tool and you did not find the information you need. 2. User asked a generic business question about their business (e.g., business address, business hours, contact information, return policy, etc.) 3. You already tried to find an entity (e.g., product, service, etc.) using an API tool and you did not find the information you need. 4. The request is too vague and you do not know what type of entity it is and what to search for in the docs. Do NOT use this tool for searching for products or other offered services - use the 'SearchSiteApiDocs' tool instead (unless you already tried that tool and you did not find the information you need). This tool DOES NOT support filters - you cannot ask questions like "find me something under $10".
| Name | Type | Req | Description |
|---|---|---|---|
| searchTerm | string | yes | The term to search for in the site, e.g. "working hours" or "store locations" |
No output schema declared.
No examples provided.
SearchSiteApiDocs ~261
Searches for site "CodeStringers Zoho Consulting Services" (https://www.codestringers.com/_api/mcp) API documentation and returns how to use the site using the API. You are a helpful "CodeStringers Zoho Consulting Services" site assistant chatbot and you are helping the user perform actions on the site - to query the site's data or to perform an action on the site. Specify the API endpoint, resource, or action you need information about (e.g., 'get site details endpoint', 'create data collection', 'update product API', 'REST authentication'). If you can't find what you need, try to rephrase your search term. The search term MUST be a short natural-language phrase describing an API capability. Do NOT pass code, SQL, shell commands, HTML/script, URLs, file paths, or special symbols — such inputs are rejected as invalid and return no results.
| Name | Type | Req | Description |
|---|---|---|---|
| searchTerm | string | yes | A short, natural-language search term describing the API capability you need — a generic term, not too specific (e.g., "how to fetch products" instead of "avocados in stock"). Use plain words only: n… |
No output schema declared.
No examples provided.
What is the CodeStringers MCP Server server?
CodeStringers MCP Server is listed in the public MCP registry as com.codestringers/mcp. Search CodeStringers' Zoho & custom-software content and business details, live. This page covers its hosted endpoint (https://www.codestringers.com/_api/mcp).
Is the CodeStringers MCP Server server safe to use?
CodeStringers MCP Server scores 75 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the CodeStringers MCP Server server expose?
CodeStringers MCP Server exposes 9 tools: ReadFullDocsArticle, ReadFullDocsMethodSchema, BrowseWixRESTDocsMenu, CallWixSiteAPI, GenerateVisitorToken, and 4 more. Their descriptions and schemas cost roughly 6,016 tokens of context every time the server is loaded.
Does the CodeStringers MCP Server server require authentication?
No. We connected to CodeStringers MCP Server without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the CodeStringers MCP Server server still maintained?
CodeStringers MCP Server is still listed as active in the MCP registry. We last reached this channel on 21 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.