Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

com.validoria/validoria-mcp

REMOTE · API.TESTE.NO · 2 COMPONENTS · SCANNED AUG 20

Continuous website testing by Validoria — monitor security, SEO, performance, and accessibility.

+3 this week 66 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →

Endpoint Security63
Transport & Reachability100
Schema Quality & AI Usability57
  • 20% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Partial
  • AI-judged instruction clarity (excellent).Pass
  • Tool/resource definitions use about 5738 tokens (~73/item across 78 items; 74 tools + 4 resources), lean.Pass
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management33
  • Stability observed for 10 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage99
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 96% of tool parameters carry a description.Partial
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

remote · api.teste.no

# add to Claude Code
claude mcp add --transport http com-validoria-validoria-mcp https://api.teste.no/api/mcp
# ~/.codex/config.toml
[mcp_servers.com-validoria-validoria-mcp]
url = "https://api.teste.no/api/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-validoria-validoria-mcp": {
      "type": "remote",
      "url": "https://api.teste.no/api/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add com-validoria-validoria-mcp --url https://api.teste.no/api/mcp --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  com-validoria-validoria-mcp:
    url: "https://api.teste.no/api/mcp"
// mcp.json
{
  "mcpServers": {
    "com-validoria-validoria-mcp": {
      "type": "http",
      "url": "https://api.teste.no/api/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 18 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

  • 16 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.

  • 15 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 13 to 17. That category is still filling its 30-day observation window: 4 days of observed history at the previous scan, 5 at this one. The score rises as the window fills, whether or not the server changes.

  • 12 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.

  • 11 Aug 26 +1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 10 Aug 26 61

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 20 Aug 2026 · Probed https://api.teste.no/api/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=api.teste.no CN=YR2,O=Let's Encrypt,C=US 7 Aug 2026 5 Nov 2026 RSA 2048 SHA256-RSA 5b42b04ec3cd36270bea67138ee7f9d3129
SANs: api.teste.no
CN=YR2,O=Let's Encrypt,C=US (CA) CN=Root YR,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 RSA 2048 SHA256-RSA 4ebd24947e24d394802d84a52fd5b319
CN=Root YR,O=ISRG,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 RSA 4096 SHA256-RSA f24b6d17f9d9ad7cb1c9fea78782699f
DNSSEC insecure

Validation of api.teste.no. Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
no. present 38032 13 Verified
teste.no. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200
Header Value
strict-transport-security max-age=31536000; includeSubDomains
x-content-type-options nosniff
x-frame-options SAMEORIGIN
referrer-policy no-referrer
Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://api.teste.no/api/mcp Verified 200
http (plaintext) http://api.teste.no/api/mcp HTTPS enforced 301 https://api.teste.no/api/mcp
MCP tools · 74 exposed · ~5,717 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
acknowledge_incident ~47

Acknowledge an open incident to signal that someone is looking at it. Changes status from OPEN to ACKNOWLEDGED.

NameTypeReqDescription
incidentIdstringyesThe incident ID to acknowledge

No output schema declared.

No examples provided.

active_runs ~41

Get currently running and queued tests across all targets. Useful for checking what tests are in progress right now.

NameTypeReqDescription
targetIdstringFilter by target ID

No output schema declared.

No examples provided.

add_keyword ~82

Add an SEO keyword to track for a target. Max 50 keywords per target.

NameTypeReqDescription
isPrimarybooleanMark as primary keyword
keywordstringyesThe keyword to track
pageScopestringURL pathname pattern to scope the keyword to (e.g. /kategori/*)
targetIdstringyesThe target ID

No output schema declared.

No examples provided.

analyze_target ~94

Fingerprint a URL and get test recommendations before creating a target. Detects platform (Shopify, WordPress, etc.), CDN, server stack, frontend framework, analytics, and B2B/ecommerce signals. Returns recommended tests with explanations. Use this before create_target to know what type to assign and which tests will be enabled.

NameTypeReqDescription
urlstringyesURL to analyze, e.g. "https://example.com"

No output schema declared.

No examples provided.

cancel_load_test ~32

Cancel a running load test.

NameTypeReqDescription
loadTestRunIdstringyesThe load test run ID to cancel

No output schema declared.

No examples provided.

create_automation_rule ~149

Create an automation rule that reacts to events. Triggers: TEST_FAILED, TEST_RECOVERED, INCIDENT_CREATED, INCIDENT_RESOLVED, TARGET_DOWN, TARGET_RECOVERED. Actions: escalate (change severity), suppress (mute), rerun (schedule retry), notify, webhook, add_note.

NameTypeReqDescription
actionsarrayyesActions to execute when triggered
conditionsobjectOptional conditions that must be met
namestringyesRule name
priorityOrderintegerPriority order (lower = evaluated first)
targetIdstringOptional target ID to scope rule to a specific target
triggerstringyesEvent that triggers the rule

No output schema declared.

No examples provided.

create_journey ~147

Create a custom browser test flow for a target. Steps are executed sequentially in a Playwright browser. Supports actions: navigate, click, type, fill, select, assert, wait, screenshot, scroll, hover, use_fragment. Variables like {{LOGIN_EMAIL}} are resolved from the target secrets vault.

NameTypeReqDescription
descriptionstringJourney description
namestringyesJourney name
platformstringPlatform tag (e.g. "shopify", "woocommerce")
stepsarrayyesOrdered list of browser actions
targetIdstringyesTarget ID to create the journey for
timeoutSecondsnumberMax execution time in seconds

No output schema declared.

No examples provided.

create_maintenance_window ~173

Schedule a maintenance window for a target. During maintenance, alerts and notifications are suppressed. Supports one-time, daily, and weekly recurring windows.

NameTypeReqDescription
descriptionstringOptional description
endsAtstringyesEnd time as ISO 8601 string, e.g. "2026-04-05T04:00:00Z"
isRecurringbooleanWhether this window repeats
namestringyesName for the window, e.g. "Weekly deploy"
recurrencestringRecurrence pattern (required if isRecurring is true)
startsAtstringyesStart time as ISO 8601 string, e.g. "2026-04-05T02:00:00Z"
targetIdstringyesThe target ID

No output schema declared.

No examples provided.

create_muting_rule ~192

Create a rule to auto-mute findings matching a pattern. Existing open findings matching the rule are muted immediately. Supports muting by fingerprint pattern, test definition, or test+target combination.

NameTypeReqDescription
expiresAtstringOptional expiry as ISO 8601 string. Rule auto-expires after this time.
fingerprintPatternstringSubstring to match in finding fingerprints (required for FINGERPRINT scope)
reasonstringReason for muting
scopestringyesFINGERPRINT: match by finding fingerprint substring. TEST_DEFINITION: mute all findings from a test. TEST_TARGET: mute findings from a specific test on a specific target.
targetIdstringTarget ID to scope the rule to (required for TEST_TARGET, optional for others)
testDefinitionIdstringTest definition ID (required for TEST_DEFINITION and TEST_TARGET scopes)

No output schema declared.

No examples provided.

create_notification_rule ~139

Create a notification alert rule. Defines which events at which severity levels trigger notifications on which channels. Supports quiet hours and per-target scoping.

NameTypeReqDescription
channelTypesarrayyesChannels to notify
enabledbooleanWhether the rule is active
eventTypesarrayyesEvents that trigger this rule
namestringyesRule name
quietHoursEndnumberQuiet hours end (hour UTC)
quietHoursStartnumberQuiet hours start (hour UTC)
severitiesarrayOnly trigger for these severities
targetIdstringScope to a specific target

No output schema declared.

No examples provided.

create_page_fragment ~65

Create a reusable step sequence that can be shared across multiple Journeys. Fragment names must be unique per team.

NameTypeReqDescription
descriptionstringFragment description
namestringyesFragment name (unique per team)
stepsarrayyesOrdered list of browser actions

No output schema declared.

No examples provided.

create_scheduled_report ~117

Create a new scheduled email report. Reports include run stats, open findings, composite scores, and per-target status.

NameTypeReqDescription
dayOfWeeknumberDay of week for WEEKLY reports (0=Sunday, 1=Monday, ..., 6=Saturday)
frequencystringHow often to send
hourUtcnumberHour in UTC to send the report
namestringReport name
recipientsstringComma-separated email addresses. Empty = all team members.

No output schema declared.

No examples provided.

create_target ~197

Add a new website, API, or webshop target for monitoring with full onboarding. Automatically enables compatible tests, triggers an initial scan, and captures a page screenshot. Requires write scope (Free plan: 1 target). Use analyze_target first to detect platform and get test recommendations.

NameTypeReqDescription
environmentstringDeployment environment
namestringyesDisplay name for the target
tagsarrayOptional tags for categorization
typestringyesTarget type: WEBSITE, API, or WEBSHOP. Use analyze_target to auto-detect.
uptimeEnabledbooleanEnable background uptime monitoring
urlstringyesURL to monitor, e.g. "https://example.com"
weightstringBusiness weight, used to rank findings by consequence: REVENUE_PATH (checkout, payment, signup), PUBLIC (customer-visible but not transactional), INTERNAL (staging, admin tooling).

No output schema declared.

No examples provided.

daily_trends ~70

Get daily time-series data for runs, findings, and average duration. Useful for identifying trends over time. Returns up to 90 days of data.

NameTypeReqDescription
daysnumberNumber of days of history to return
targetIdstringFilter by target ID (omit for team-wide)

No output schema declared.

No examples provided.

delete_automation_rule ~31

Permanently delete an automation rule.

NameTypeReqDescription
ruleIdstringyesThe automation rule ID to delete

No output schema declared.

No examples provided.

delete_journey ~32

Permanently delete a journey and all its steps.

NameTypeReqDescription
journeyIdstringyesThe journey ID to delete

No output schema declared.

No examples provided.

delete_maintenance_window ~45

Remove a scheduled maintenance window.

NameTypeReqDescription
targetIdstringyesThe target ID (for access verification)
windowIdstringyesThe maintenance window ID to delete

No output schema declared.

No examples provided.

delete_notification_rule ~30

Permanently delete a notification rule.

NameTypeReqDescription
ruleIdstringyesThe notification rule ID to delete

No output schema declared.

No examples provided.

delete_page_fragment ~29

Permanently delete a page fragment.

NameTypeReqDescription
fragmentIdstringyesThe fragment ID to delete

No output schema declared.

No examples provided.

delete_scheduled_report ~31

Permanently delete a scheduled report.

NameTypeReqDescription
reportIdstringyesThe scheduled report ID to delete

No output schema declared.

No examples provided.

delete_secret ~47

Permanently delete a secret from a target's vault.

NameTypeReqDescription
secretIdstringyesThe secret ID to delete
targetIdstringyesThe target ID (for access verification)

No output schema declared.

No examples provided.

delete_target ~58

Permanently delete a target and all its associated data (runs, findings, incidents, artifacts). This cannot be undone.

NameTypeReqDescription
confirmbooleanyesMust be true to confirm deletion
targetIdstringyesThe target ID to delete

No output schema declared.

No examples provided.

disable_all_tests ~51

Disable all test definitions globally. Optionally filter by category to only disable tests in that category. Requires admin scope.

NameTypeReqDescription
categorystringOnly disable tests in this category. Omit to disable all.

No output schema declared.

No examples provided.

enable_all_tests ~51

Enable all test definitions globally. Optionally filter by category to only enable tests in that category. Requires admin scope.

NameTypeReqDescription
categorystringOnly enable tests in this category. Omit to enable all.

No output schema declared.

No examples provided.

get_automation_rule ~31

Get full details of a specific automation rule.

NameTypeReqDescription
ruleIdstringyesThe automation rule ID

No output schema declared.

No examples provided.

get_finding ~38

Get full details of a specific finding, including evidence, AI analysis, and recommended fix.

NameTypeReqDescription
findingIdstringyesThe finding ID

No output schema declared.

No examples provided.

get_incident ~38

Get full details of a specific incident including linked findings, AI analysis, and deployment correlation.

NameTypeReqDescription
incidentIdstringyesThe incident ID

No output schema declared.

No examples provided.

get_journey ~31

Get full details of a specific journey including all steps.

NameTypeReqDescription
journeyIdstringyesThe journey ID

No output schema declared.

No examples provided.

get_load_test ~34

Get details and results of a load test run.

NameTypeReqDescription
loadTestRunIdstringyesThe load test run ID

No output schema declared.

No examples provided.

get_run ~40

Get full details of a specific test run including metrics, score, summary, errors, and associated findings.

NameTypeReqDescription
runIdstringyesThe run ID

No output schema declared.

No examples provided.

get_site_map ~108

Get the latest crawl snapshot for a target. Returns page inventory stats, SEO issues, broken pages/assets, response times, and a diff against the previous crawl. Optionally include page-level details.

NameTypeReqDescription
includePagesbooleanInclude individual page data (can be large). Default: false.
pageLimitnumberMax pages to return when includePages is true
pageStatusstringFilter pages by status
targetIdstringyesThe target ID

No output schema declared.

No examples provided.

get_target ~40

Get detailed information about a specific target including status, uptime, fingerprint, and composite scores.

NameTypeReqDescription
targetIdstringyesThe target ID to look up

No output schema declared.

No examples provided.

get_target_scores ~48

Get composite scores (Security, SEO, Performance, Accessibility) for a target. Each score is 0-100 with a status rating.

NameTypeReqDescription
targetIdstringyesThe target ID

No output schema declared.

No examples provided.

get_team_settings ~40

Get the team's configuration including AI enrichment, uptime monitoring, severity escalation, run policies, notification coalescing, SEO, and Kloner Tasks integration settings.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

guest_get_scan ~67

Poll results for a guest_start_scan. Pass the scanId and guestSessionId from the start response. No API key required.

NameTypeReqDescription
guestSessionIdstringGuest session id returned by guest_start_scan
scanIdstringyesScan workflow id from guest_start_scan

No output schema declared.

No examples provided.

guest_start_scan ~92

Run a free 6-test HTTP scan against a public URL without an API key. Rate-limited (5/IP/hour, 3/session/day). Returns scanId — poll with guest_get_scan. For continuous monitoring, sign up free and use create_target. See teste-no://docs/quickstart.

NameTypeReqDescription
urlstringyesPublic http(s) URL to scan, e.g. https://example.com

No output schema declared.

No examples provided.

import_targets ~60

Bulk import up to 100 websites for monitoring. Each URL gets a target created with auto-enabled tests, initial scan, and screenshot capture. Partial success — failed URLs are reported individually without blocking others.

NameTypeReqDescription
itemsarrayyesArray of targets to import

No output schema declared.

No examples provided.

list_automation_rules ~62

List all automation rules for the team. Rules automatically react to events (test failures, incidents, downtime) with configurable actions (escalate severity, suppress, rerun, webhook, notify).

NameTypeReqDescription
enabledbooleanFilter by enabled/disabled status

No output schema declared.

No examples provided.

list_findings ~95

List findings (discovered issues) across your targets. Filter by status, severity, or target. Returns title, severity, status, test name, and AI enrichment if available.

NameTypeReqDescription
limitnumberMax number of findings to return
severitystringFilter by severity
statusstringFilter by finding status (default: OPEN)
targetIdstringFilter by target ID

No output schema declared.

No examples provided.

list_incidents ~75

List incidents (grouped operational issues) across your targets. Filter by status. Returns title, severity, status, findings count, and deployment correlation.

NameTypeReqDescription
limitnumberMax number of incidents to return
statusstringFilter by incident status
targetIdstringFilter by target ID

No output schema declared.

No examples provided.

list_journeys ~67

List custom browser test flows (journeys) for a target or all team targets. Journeys are multi-step Playwright tests that verify user flows like checkout, login, and search.

NameTypeReqDescription
targetIdstringFilter by target ID. If omitted, lists all team journeys.

No output schema declared.

No examples provided.

list_keywords ~40

List all SEO keywords tracked for a target, including latest Google rank position. Max 50 per target.

NameTypeReqDescription
targetIdstringyesThe target ID

No output schema declared.

No examples provided.

list_load_tests ~38

List recent load test runs for a target.

NameTypeReqDescription
limitnumberMax results
targetIdstringyesThe target ID

No output schema declared.

No examples provided.

list_maintenance_windows ~38

List maintenance windows for a target. Shows scheduled and recurring maintenance periods that suppress alerts.

NameTypeReqDescription
targetIdstringyesThe target ID

No output schema declared.

No examples provided.

list_notification_channels ~38

List all notification channels (Email, Slack, Webhook, SMS, Web Push) configured for the team. Sensitive config values are redacted.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

list_notification_rules ~29

List all notification alert rules for the team. Rules map event types + severity levels to notification channels.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

list_page_fragments ~50

List all reusable page fragments for the team. Fragments are shared step sequences (e.g. "Login", "Dismiss Cookies") that can be inserted into multiple Journeys via the use_fragment action.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

list_runs ~94

List recent test runs. Filter by target, status, or test slug. Returns run status, score, summary, duration, and finding count.

NameTypeReqDescription
limitnumberMax number of runs to return
statusstringFilter by run status
targetIdstringFilter by target ID
testSlugstringFilter by test definition slug (e.g. "security-headers")

No output schema declared.

No examples provided.

list_scheduled_reports ~31

List all scheduled reports for the team. Reports are automatically generated and emailed on a daily or weekly basis.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

list_secrets ~70

List secrets stored in a target's vault. Values are masked — only key names and labels are shown. Secrets are used by test plugins (e.g. LOGIN_EMAIL, LOGIN_PASSWORD for B2B shops, ga4_service_account for GA4).

NameTypeReqDescription
targetIdstringyesThe target ID

No output schema declared.

No examples provided.