StewAI
REMOTE · API.STEWAI.COM · SCANNED SEP 26
Discover, run, inspect, build, test, and privately reuse AI workflows.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (commit_recipe_build). See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability59
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 2248 tokens (~160/item across 14 items; 14 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management90
- Stability observed for 27 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage75
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 13% of tool parameters carry a description.Partial
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 14 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 15 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the StewAI MCP server?
StewAI is a hosted endpoint at https://api.stewai.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · api.stewai.com
claude mcp add --transport http com-stewai-stewai 'https://api.stewai.com/mcp'
{
"mcpServers": {
"com-stewai-stewai": {
"url": "https://api.stewai.com/mcp"
}
}
} {
"servers": {
"com-stewai-stewai": {
"type": "http",
"url": "https://api.stewai.com/mcp"
}
}
} [mcp_servers.com-stewai-stewai] url = "https://api.stewai.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-stewai-stewai": {
"type": "remote",
"url": "https://api.stewai.com/mcp",
"enabled": true
}
}
} openclaw mcp add com-stewai-stewai --url 'https://api.stewai.com/mcp' --transport streamable-http
mcp_servers:
com-stewai-stewai:
url: "https://api.stewai.com/mcp" {
"McpServers": {
"com-stewai-stewai": {
"Transport": "http",
"Url": "https://api.stewai.com/mcp"
}
}
} assistant mcp add com-stewai-stewai -t streamable-http -u 'https://api.stewai.com/mcp'
{
"mcpServers": {
"com-stewai-stewai": {
"type": "http",
"url": "https://api.stewai.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 25 Sept 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 23 Sept 26 0
- Server version: 0.3.124 → 0.3.130 functional
- 22 Sept 26 +1
- Server version: 0.3.123 → 0.3.124 functional
- 21 Sept 26 0
- Server version: 0.3.122 → 0.3.123 functional
- 20 Sept 26 +1
- Server version: 0.3.121 → 0.3.122 functional
- 19 Sept 26 0
- Tool “update_recipe_build” rewrote its description, which is the text the model reads security
- Server version: 0.3.117 → 0.3.121 functional
- 18 Sept 26 0
- Tool “get_recipe_preview” rewrote its description, which is the text the model reads security
- Tool “get_results” rewrote its description, which is the text the model reads security
- Tool “get_run” rewrote its description, which is the text the model reads security
- Tool “run_recipe” rewrote its description, which is the text the model reads security
- Tool “search_recipes” rewrote its description, which is the text the model reads security
- Schema quality: 133 → 157 ▼ functional
- Server version: 0.3.114 → 0.3.117 functional
- “get_results” added an optional parameter “detail” cosmetic
- “get_results” reworded the description of “limit” cosmetic
- 17 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 26 Sept 2026 · Probed https://api.stewai.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=api.stewai.com | CN=WE1,O=Google Trust Services,C=US | 4 Aug 2026 | 2 Nov 2026 | ECDSA 256 | ECDSA-SHA256 | 3137d9ab619a37450edaa4797ec1ed5b |
| SANs: api.stewai.com | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of api.stewai.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| stewai.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains |
| content-security-policy | default-src 'self'; script-src 'self' https://www.googletagmanager.com https://www.clarity.ms; style-src 'self' 'unsafe-inline'; img-src 'self' data: https://api.stewai.com https://www.google-analytics.com; font-src 'self' data:; connect-src 'self' https://api.stewai.com https://stewai.com wss://api.stewai.com wss://stewai.com https://www.google-analytics.com https://region1.google-analytics.com https://www.clarity.ms; frame-src 'self' https://www.youtube-nocookie.com; frame-ancestors 'none'; base-uri 'self'; form-action 'self' |
| x-content-type-options | nosniff |
| x-frame-options | SAMEORIGIN |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | geolocation=(), microphone=(), camera=() |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://api.stewai.com/mcp | Verified | 200 | |
| http (plaintext) | http://api.stewai.com/mcp | HTTPS enforced | 301 | https://api.stewai.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
check_recipe_build Check a StewAI Recipe Build ~67
Run free deterministic lint, render, policy, and compiler checks. Omit fixtures for the normal structural check; a supplied fixture probe must also provide every referenced upstream dependency value.
| Name | Type | Req | Description |
|---|---|---|---|
| build_ref | string | yes | – |
| fixtures | object | – | – |
| render_only | boolean | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
commit_recipe_build Commit a StewAI Recipe Build ~69
Preflight and privately publish only the exact fully qualified recipe revision.
| Name | Type | Req | Description |
|---|---|---|---|
| build_ref | string | yes | – |
| commit_capability | string | – | Required for commit; omit for preflight. |
| idempotency_key | string | yes | – |
| mode | – | yes | – |
| revision | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
discover_stewai Discover and Connect to StewAI ~43
Learn how any MCP agent can authenticate, discover, preview, run, author, qualify, commit, inspect, and recover StewAI recipes. Call this first.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| account | object | – | – |
| authenticated | boolean | yes | – |
| authoring_available | boolean | yes | – |
| authoring_journey | array | yes | – |
| capabilities | array | yes | – |
| connection | object | yes | – |
| consumer_journey | array | yes | – |
| gateway_contract_version | string | yes | – |
| granted_scopes | array | yes | – |
| rules | array | yes | – |
| scope_groups | object | yes | – |
No examples provided.
get_recipe_build Inspect a StewAI Recipe Build ~221
List or inspect only the authenticated creator's private recipe builds. To list builds omit both build_ref and view; limit/cursor paginate that list. With or without build_ref, use view='authoring_schema' and schema_name='update_recipe_build', 'acceptance_suite', or 'start_recipe_build' to read the complete executable JSON Schema when a client hides nested operation or assertion fields. Large acceptance_plan reads return data.suite_page JSON fragments: append content in offset order, pass data.next_cursor as cursor until null, then parse the complete suite and verify its sha256. Small plans retain data.suite. Use view='capabilities' to discover the complete 24-handler authoring and automatic-acceptance capability catalog.
| Name | Type | Req | Description |
|---|---|---|---|
| build_ref | string | – | – |
| cursor | string | – | – |
| include_archived | boolean | – | – |
| limit | integer | – | – |
| model_id | string | – | – |
| node_id | string | – | – |
| node_type | string | – | – |
| schema_name | – | – | – |
| view | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
get_recipe_build_activity Get recipe build activity ~44
Poll a review or acceptance batch through a bounded, disclosure-safe view.
| Name | Type | Req | Description |
|---|---|---|---|
| activity_ref | string | yes | – |
| cursor | string | – | – |
| section | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
get_recipe_preview Preview a StewAI Recipe ~96
Inspect a safe summary with bounded method and limitations excerpts, output-contract state, and evidence context. For complete authorized published details and executable contracts, use view=details. Concatenate content fragments in offset order per section; decode JSON sections after completion. Use next_cursor with the same recipe_ref until null. Opaque internals remain withheld.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | – |
| recipe_ref | string | yes | – |
| view | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
get_results Get StewAI Run Results ~227
Read declared outputs or a sanitized per-step trace from an owned run, including signed chunks for oversized steps. view=steps returns compact summaries, 10 per page by default and at most 20 (limit 1-20); follow next_cursor until it is null, pass detail=full for whole steps, or use view=step with step_id for one full step. Step reads are provisional until get_run reports a finished status. If outputs is empty, read view=steps; for a failed run, read the failed step and let the user decide.
| Name | Type | Req | Description |
|---|---|---|---|
| chunk_ref | string | – | – |
| cursor | string | – | – |
| detail | – | – | For view=steps: summary (default) lists each step's id, title, kind, status, timing and result type; full returns parameters, rendered input and result. view=step always returns the full step. |
| limit | integer | – | Steps per page for view=steps: default 10, at most 20. |
| run_id | string | yes | – |
| step_id | string | – | – |
| view | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
get_run Get StewAI Run Status ~119
Read an owned run, view=history to resume normal runs (recipe_ref/status/cursor/limit), or view=diagnostics for its settled UI receipt. Default status requires run_id and includes live progress: updated_at is the run record time, progress.last_step_activity_at is the latest step activity. A blocked run paused for credits reports credit_pause.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | – |
| limit | integer | – | – |
| recipe_ref | string | – | – |
| run_id | string | – | – |
| status | – | – | – |
| view | – | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
review_recipe_build Review recipe build ~54
Quote or run a bounded semantic quality review of the exact private draft revision.
| Name | Type | Req | Description |
|---|---|---|---|
| build_ref | string | yes | – |
| idempotency_key | string | yes | – |
| mode | – | yes | – |
| revision | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
run_recipe Run a StewAI Recipe ~115
Estimate or run a previewed public or account-authorized published recipe. dry_run returns history (credits charged by past runs of this recipe), fees, your balance, and estimated_credits, a theoretical worst case. If credits run out during a run, it pauses and can be resumed after adding credits. On recipe_ref_expired, search or preview again and retry.
| Name | Type | Req | Description |
|---|---|---|---|
| dry_run | boolean | – | – |
| idempotency_key | string | yes | – |
| inputs | object | yes | – |
| recipe_ref | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
run_recipe_acceptance Run recipe acceptance ~171
Quote or run selected or complete behavioral acceptance cases for an exact private draft revision. Quotes explain enforced input bounds, output caps and retry allowances in acceptance_cost. Preserve representative fixtures and assertions; remove unnecessary model stages rather than weakening tests to lower a quote. Paid work requires an approved budget. A full run that needs user approval returns supervised_required before any case, reservation, or external effect; first bind every returned required resource with update_recipe_build bind_resource, then open action_url for user approval, and finally resume the same activity with update_recipe_build resume_activity.
| Name | Type | Req | Description |
|---|---|---|---|
| build_ref | string | yes | – |
| case_ids | array | – | Required for selected_cases, optional for quote, forbidden for full. |
| idempotency_key | string | yes | – |
| mode | – | yes | – |
| revision | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
search_recipes Search StewAI Recipes ~259
Find safe public recipes and published recipes available to the current account. results are direct fits (exact or strong); related_results are adjacent recipes, not direct fits. Each row states its output contract, past-run cost history and, for reviewed public recipes, that safety review is not output-quality validation. required_inputs and required_outputs match exact handles or normalized labels, never meanings. When paging.has_more is true, repeat the identical call with cursor=next_cursor.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | next_cursor from the previous page of the identical query and filters. Omit for the first page. |
| query | string | yes | At least 3 non-padding characters, up to 2000. Name the task in a few words; add constraints as required_inputs or required_outputs; follow next_cursor when results are cut. |
| required_inputs | array | – | Exact normalized handle/label matching, not semantic meaning; inspect filter_diagnostics for available labels. |
| required_outputs | array | – | Exact normalized handle/label matching, not semantic meaning; filters are never weakened automatically. |
| runnable_only | boolean | – | – |
| sources | array | – | When omitted, search public recipes and any library lanes authorized by this connection. Explicit private lanes require recipes:read permission. |
Structured output declared, but exposes no named fields.
No examples provided.
start_recipe_build Start a StewAI Recipe Build ~194
Create a private recipe build from a bounded intent and declared contract. Recipe inputs are strings: use type:string, positive maxLength, and only minLength:1 on required inputs. Richer input constraints must be handled in recipe logic and tested, not claimed as enforced by the input node. The response returns the stored contracts when they fit the bounded result; the archetype bundle is optional guidance, not the build contract. Optionally provide source_recipe_ref to adapt an owned recipe or a fully viewable public-open recipe into a new private draft.
| Name | Type | Req | Description |
|---|---|---|---|
| capabilities | array | yes | – |
| idempotency_key | string | yes | – |
| input_contract | object | yes | – |
| intent | string | yes | – |
| name | string | yes | – |
| output_contract | object | yes | – |
| quality_profile | – | yes | – |
| research_policy | – | yes | – |
| risk_domains | array | yes | – |
| source_recipe_ref | string | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
update_recipe_build Update a StewAI Recipe Build ~515
Apply bounded optimistic changes to an owned private recipe build. After an uncertain response, inspect the build and replay the identical request with the same idempotency key; a new key duplicates the work. Use only the exact op names and payload keys in inputSchema: set_metadata takes metadata, upsert_schema takes schema_id and schema, and acceptance uses set_acceptance_cases with suite. Never invent set_schema or set_acceptance_suite. If an op appears unknown, read get_recipe_build view='authoring_schema', schema_name='update_recipe_build'; read schema_name='acceptance_suite' for the complete suite shape and every assertion operator with its required, allowed and forbidden fields. Do not guess them. Use set_contracts to replace the declared executable input and output contracts; this changes the revision and invalidates qualification. For a supervised acceptance handoff, use bind_resource only to approve an exact selector already frozen in the draft, then resume_activity or cancel_activity with the returned opaque handoff and activity references. Each handoff control operation must be the only op in its request. An acceptance suite is {version:1,cases:[{case_id,label,kind,fixtures,assertions}]}. Each fixture is {target,content_type,value}. A minimal assertion is {assertion_id:'result_exists',type:'scalar',operator:'exists',path:'/result'}. JSON Pointer paths start with '/'. A metamorphic case also requires pair_with naming another case. Use a paired assertion such as {assertion_id:'stable',type:'paired',operator:'fields_unchanged',path:'',pair_case_id:'base',fields:['/summary']}; pair_case_id is not valid on a scalar assertion. Client transport recommendation, not a server limit: keep serialized tool arguments below 32 KiB including JSON escaping and the request envelope. For larger spec, suite, or research content use begin_chunk, ordered append_chunk (seq starts at 0), then commit_chunk. Keep each complete append request below 12 KiB; split text further after…
| Name | Type | Req | Description |
|---|---|---|---|
| build_ref | string | yes | – |
| idempotency_key | string | yes | – |
| ops | array | yes | – |
| revision | string | yes | – |
Structured output declared, but exposes no named fields.
No examples provided.
What is the StewAI MCP server?
StewAI is an MCP server listed in the public MCP registry as com.stewai/stewai. Discover, run, inspect, build, test, and privately reuse AI workflows. This page covers its hosted endpoint (https://api.stewai.com/mcp).
Is the StewAI MCP server safe to use?
StewAI scores 74 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the StewAI MCP server expose?
StewAI exposes 14 tools: check_recipe_build, commit_recipe_build, discover_stewai, get_recipe_build, get_recipe_build_activity, and 9 more. Their descriptions and schemas cost roughly 2,194 tokens of context every time the server is loaded.
Does the StewAI MCP server require authentication?
No. We connected to StewAI without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the StewAI MCP server still maintained?
StewAI is still listed as active in the MCP registry. We last reached this channel on 26 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.