# com.gitbuyer/mcp (remote · gitbuyer.com)

Find the repo to build from: search 100k+ repos by base-fitness, clone free or buy over x402.

- Trust score: 77/100 (medium)
- Change this week: +3
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-20

## Components

- remote · `gitbuyer.com`: 77/100 (this document), [markdown](https://verifymcp.io/servers/com-gitbuyer-mcp/gitbuyer.md), [page](https://verifymcp.io/servers/com-gitbuyer-mcp/gitbuyer)

## Channel facts

- Endpoint: `https://gitbuyer.com/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.0.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-20.

- **Endpoint Security**: 57/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (delete_store).
  - HTTPS is enforced; there's no plaintext access path.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 85/100
  - 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).
  - AI-judged instruction clarity (good).
  - Tool/resource definitions use about 1675 tokens (~98/item across 17 items; 16 tools + 1 resources), lean.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 97/100
  - Stability observed for 29 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 87/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 55% of tool parameters carry a description.
  - Structured output schemas are declared (19% of tools); any adoption earns full credit.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.
  - An AI judge read all 18 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 60/100
  - Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28.

## Install

### How do I install the com.gitbuyer/mcp server?

com.gitbuyer/mcp is a hosted endpoint at https://gitbuyer.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http com-gitbuyer-mcp 'https://gitbuyer.com/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "com-gitbuyer-mcp": {
      "url": "https://gitbuyer.com/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "com-gitbuyer-mcp": {
      "type": "http",
      "url": "https://gitbuyer.com/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.com-gitbuyer-mcp]
url = "https://gitbuyer.com/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-gitbuyer-mcp": {
      "type": "remote",
      "url": "https://gitbuyer.com/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add com-gitbuyer-mcp --url 'https://gitbuyer.com/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  com-gitbuyer-mcp:
    url: "https://gitbuyer.com/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "com-gitbuyer-mcp": {
      "Transport": "http",
      "Url": "https://gitbuyer.com/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add com-gitbuyer-mcp -t streamable-http -u 'https://gitbuyer.com/mcp'
```

### Other

```json
{
  "mcpServers": {
    "com-gitbuyer-mcp": {
      "type": "http",
      "url": "https://gitbuyer.com/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-20 (score 77, +1)

No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-17 (score 76, +1)

No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-15 (score 75, +1)

No change was recorded against any check on this day. Stability & Change Management went from 77 to 80. That category is still filling its 30-day observation window: 23 days of observed history at the previous scan, 24 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-13 (score 74, +1)

No change was recorded against any check on this day. Stability & Change Management went from 70 to 73. That category is still filling its 30-day observation window: 21 days of observed history at the previous scan, 22 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-11 (score 73, +1)

No change was recorded against any check on this day. Stability & Change Management went from 63 to 67. That category is still filling its 30-day observation window: 19 days of observed history at the previous scan, 20 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-09 (score 72, +1)

No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-07 (score 71, +1)

No change was recorded against any check on this day. Stability & Change Management went from 50 to 53. That category is still filling its 30-day observation window: 15 days of observed history at the previous scan, 16 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-05 (score 70, +1)

No change was recorded against any check on this day. Stability & Change Management went from 43 to 47. That category is still filling its 30-day observation window: 13 days of observed history at the previous scan, 14 at this one. The score rises as the window fills, whether or not the server changes.

## MCP tools (16)

### `whoami` (~23 tokens)

Who am I

Who am I signed in as, how many listings, live or rehearsal.

### `seller_setup` (~88 tokens)

Set up selling

The seller setup wizard. Returns wizard_url: a one-time signed-in link to the full browser wizard — it can GENERATE a payout wallet safely (keys shown once in the browser, never stored, user must confirm saving them), connect GitHub, and list the first repo. Call this when the user wants to start selling, has no wallet, or asks to finish setup; offer wizard_url.

### `list_stores` (~25 tokens)

List my stores

Every listed repo in this account: repo, page, price, checkout URLs.

### `get_store` (~45 tokens)

Get one store

One listing's full settings: price, payout wallets, preview paths, whether a GitHub key is on file.

Input parameters:

- `owner` (string, required)
- `repo` (string, required)

### `set_payout_wallets` (~120 tokens)

Set payout wallets

Save the account's default payout wallets: USDC on Base (0x…) and/or Solana (base58). The onboarding wallet step: once saved, create_store needs only the repo URL, and a chain added here propagates to existing listings so the whole inventory offers it. An empty string clears a wallet.

Input parameters:

- `wallet_base` (string): USDC payout wallet on Base (0x…); empty string clears
- `wallet_solana` (string): USDC payout wallet on Solana (base58); empty string clears

### `create_payout_wallet` (~78 tokens)

Create a payout wallet

The seller needs a payout wallet and does not have one: returns wizard_url, a one-time signed-in link to gitbuyer's in-browser wallet generator (keys created in the browser, shown once, never stored, never in the chat). Call whenever a user asks to create, make or generate a wallet, or says they have none.

### `create_store` (~193 tokens)

List a repo for sale

List a GitHub repo for sale: URL, price, payout wallet(s); USDC on Base (0x…) and/or Solana (base58); both offers the buyer the choice. Private repos need a fine-grained PAT (Contents read-only, that one repo), unless the account has the GitHub App installed on the repo, in which case no key is needed at all. The listing is live at `page` immediately.

Input parameters:

- `github_pat` (string): fine-grained PAT for private repos
- `github_url` (string, required)
- `preview_paths` (array): globs buyers may read free before paying
- `price_usd` (string): e.g. "25.00"; defaults to 20.00
- `wallet_base` (string): USDC payout wallet on Base (0x…)
- `wallet_solana` (string): USDC payout wallet on Solana

### `update_store` (~112 tokens)

Update a listing

Edit a listing without re-listing it: reprice, rewallet, rekey, or change preview paths. Only the fields you send change; the old checkout is voided so stale links stop selling.

Input parameters:

- `github_pat` (string): new key; empty string clears
- `owner` (string, required)
- `preview_paths` (array)
- `price_usd` (string)
- `repo` (string, required)
- `wallet_base` (string)
- `wallet_solana` (string)

### `delete_store` (~37 tokens)

Take a listing down

Take a store down and void its checkout so old links stop being payable.

Input parameters:

- `owner` (string, required)
- `repo` (string, required)

### `get_sales` (~44 tokens)

Sales for a store

One store's settled payments, newest first: count and revenue (real money only), rehearsals flagged beside.

Input parameters:

- `owner` (string, required)
- `repo` (string, required)

### `get_traffic` (~70 tokens)

Traffic for a store

One store's audience: humans vs agents by day, unique visitors, countries and cities, referrers, the files buyers tried to open before paying.

Input parameters:

- `days` (integer): window, default 30, max 365
- `owner` (string, required)
- `repo` (string, required)

### `get_github` (~38 tokens)

get github

The GitHub connection: installations, their repos (listed or not), and orphaned listings whose repo left the installation: the catalogue-management view.

### `get_stats` (~63 tokens)

get stats

The whole account at a glance: every store with its sales, revenue, visits, human/agent split and buy-intent file views, plus account totals. Start here for 'how am I doing?'.

Input parameters:

- `days` (integer): traffic window, default 30

### `find_base` (~105 tokens)

Find a base to build from

Say what you are building; get ONE repo to build from. The verdict is chosen by kind (starters first), freshness, and relevance, and comes with a plain-words why, the clone command target, and two alternatives. Adapting a proven base ships production-shaped code instead of a from-scratch demo. Needs no account.

Input parameters:

- `building` (string, required): what you are building, in task words, e.g. "a saas with stripe subscriptions and auth"

Output parameters:

- `alternatives` (array)
- `building` (string)
- `matched` (string)
- `note` (string)
- `pick` (object|null)

### `get_repo` (~81 tokens)

Read one repo in depth

Read one gitbuyer repo in depth before cloning or buying: facts (stars, forks, freshness, releases, license, repo_kind), topics, the README excerpt, and the exact next move (clone command for free repos; x402 checkout and test URL for paid listings). Needs no account.

Input parameters:

- `owner` (string, required)
- `repo` (string, required)

Output parameters:

- `kind` (string)
- `license` (string|null)
- `pushed_at` (number|null)
- `repo` (string)
- `repo_kind` (string|null)
- `stars` (integer|null)
- `starter` (boolean|null)

### `search_repos` (~318 tokens)

Search the marketplace

Find the best repo to BUILD ON: terms match names, descriptions, topics, categories, licenses and READMEs, ranked by relevance (name beats topics beats description beats README) plus base fitness (stars band, freshness, releases). Returns paid listings (buy at `page`, x402) and free indexed repos (clone from `github`) together, listed first, each with stars, forks, pushed_at, releases, license and a starter flag. Needs no account. Empty query browses.

Input parameters:

- `category` (string): exact category filter
- `language` (string): exact primary-language filter
- `license` (string): SPDX id (MIT, Apache-2.0, ...) or 'permissive' for the whole build-on-it set
- `limit` (integer): max results, default 30
- `min_stars` (integer): only repos with at least this many stars
- `query` (string): e.g. "fastapi stripe starter"
- `repo_kind` (string): what the repo IS: starter | app | library | tool | generator. Use 'starter' or 'app' when you want a base to ADAPT; results also carry repo_kind so you can reject mismatches before cloning.
- `sort` (string): relevance (default with a query), stars (default without), or updated
- `starters` (boolean): only templates, boilerplates and starters — repos meant as a base
- `updated_within_days` (integer): only repos pushed within this many days

Output parameters:

- `count` (integer)
- `note` (string)
- `results` (array)

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/com-gitbuyer-mcp/gitbuyer#diagnostics

## Score history

- 2026-09-20: 77
- 2026-09-19: 76
- 2026-09-18: 76
- 2026-09-17: 76
- 2026-09-16: 75
- 2026-09-15: 75
- 2026-09-14: 74
- 2026-09-13: 74
- 2026-09-12: 73
- 2026-09-11: 73
- 2026-09-10: 72
- 2026-09-09: 72
- 2026-09-08: 71
- 2026-09-07: 71
- 2026-09-06: 70
- 2026-09-05: 70
- 2026-09-04: 69
- 2026-09-03: 69
- 2026-09-02: 69
- 2026-09-01: 68
- 2026-08-31: 68
- 2026-08-30: 67
- 2026-08-29: 67
- 2026-08-28: 66
- 2026-08-27: 66
- 2026-08-26: 65
- 2026-08-25: 63
- 2026-08-24: 63
- 2026-08-23: 62
- 2026-08-22: 60

## Common questions

### What is the com.gitbuyer/mcp server?

com.gitbuyer/mcp is listed in the public MCP registry as com.gitbuyer/mcp. Find the repo to build from: search 100k+ repos by base-fitness, clone free or buy over x402. This page covers its hosted endpoint (https://gitbuyer.com/mcp).

### Is the com.gitbuyer/mcp server safe to use?

com.gitbuyer/mcp scores 77 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the com.gitbuyer/mcp server expose?

com.gitbuyer/mcp exposes 16 tools: whoami, seller_setup, list_stores, get_store, set_payout_wallets, and 11 more. Their descriptions and schemas cost roughly 1,440 tokens of context every time the server is loaded.

### Does the com.gitbuyer/mcp server require authentication?

No. We connected to com.gitbuyer/mcp without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the com.gitbuyer/mcp server still maintained?

com.gitbuyer/mcp is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://gitbuyer.com/mcp
- Repository: https://github.com/bitfent/gitbuyer
- Changelog RSS feed: https://verifymcp.io/servers/com-gitbuyer-mcp/gitbuyer.xml
- Changelog JSON feed: https://verifymcp.io/servers/com-gitbuyer-mcp/gitbuyer.json
- HTML version of this page: https://verifymcp.io/servers/com-gitbuyer-mcp/gitbuyer
