# HostTracker (remote · mcp.host-tracker.com)

Website uptime monitoring: run checks from 300+ locations, manage monitors, alerts and incidents

- Trust score: 32/100 (low)
- Change this week: 0
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-06

## Components

- remote · `mcp.host-tracker.com`: 32/100 (this document), [markdown](https://verifymcp.io/servers/hosttracker-hosttracker/mcp.md), [page](https://verifymcp.io/servers/hosttracker-hosttracker/mcp)

## Channel facts

- Endpoint: `https://mcp.host-tracker.com/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `2.1.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-06.

- **Endpoint Security**: 81/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - The endpoint enforces authorisation, advertised via RFC 9728 protected-resource metadata.
  - HTTPS enforcement could not be verified: the plaintext port answered with HTTP 520, which proves neither a plaintext path nor enforcement.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
  - The authorisation server supports Client ID Metadata Documents, the current MCP client-registration mechanism.
- **Transport & Reachability**: 0/100
  - Transport blocked by authentication: the endpoint requires auth we don't have to verify streamable-http.
- **Schema Quality & AI Usability**: 0/100
  - Schema blocked by authentication: the endpoint requires auth we don't have to read it.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 0/100
  - Tool coverage blocked by authentication: the endpoint requires auth we don't have to read its tools.
- **Tool Safety**: 0/100
  - Tool safety blocked by authentication: the endpoint requires auth we don't have to read its tools.
- **Capabilities**: 0/100
  - Capabilities blocked by authentication: the endpoint requires auth we don't have to read them.

**Unverified: 6 categories.** Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.

## Install

### How do I install the HostTracker MCP server?

HostTracker is a hosted endpoint at https://mcp.host-tracker.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http hosttracker-hosttracker 'https://mcp.host-tracker.com/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "hosttracker-hosttracker": {
      "url": "https://mcp.host-tracker.com/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "hosttracker-hosttracker": {
      "type": "http",
      "url": "https://mcp.host-tracker.com/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.hosttracker-hosttracker]
url = "https://mcp.host-tracker.com/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "hosttracker-hosttracker": {
      "type": "remote",
      "url": "https://mcp.host-tracker.com/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add hosttracker-hosttracker --url 'https://mcp.host-tracker.com/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  hosttracker-hosttracker:
    url: "https://mcp.host-tracker.com/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "hosttracker-hosttracker": {
      "Transport": "http",
      "Url": "https://mcp.host-tracker.com/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add hosttracker-hosttracker -t streamable-http -u 'https://mcp.host-tracker.com/mcp'
```

### Other

```json
{
  "mcpServers": {
    "hosttracker-hosttracker": {
      "type": "http",
      "url": "https://mcp.host-tracker.com/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-28 (score 32, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-25 (score 32, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-08-30 (score 0)

- [security regression] Endpoint reachability: reachable → behind authorisation
- [security regression] Stability: 0.13 → unverified
- [security regression] Tool safety: pass → unverified
- [security regression] Transport: pass → unverified
- [security improvement] Authorization: fail → pass
- [security] First check of Authorization: pass
- [functional regression] Capabilities: pass → unverified
- [functional regression] Tool coverage: 100 → unverified
- [functional] First check of Schema quality: unverified

### 2026-08-26 (score 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-08-25 (score 0)

First indexed and scored.

## MCP tools (65)

### `get_monitor` (~112 tokens)

Read one monitor with its full configuration. Scope 'monitor:read'. Add expand tokens for more detail (settings, uptime, lastResult, lastIncident, subscription, maintenance, attached, spans).

Input parameters:

- `expand` (string|null): Comma-separated expand tokens; defaults to 'settings,uptime'.
- `from` (integer|null): Window start for uptime/spans, Unix seconds.
- `id` (string, required): The monitor id.
- `to` (integer|null): Window end for uptime/spans, Unix seconds.

### `delete_status_page` (~90 tokens)

Delete a status page with its components, incidents and subscribers. Scope 'statuspage:write'. DESTRUCTIVE and public-facing — confirm with the user first; the slug stops resolving immediately.

Input parameters:

- `confirmed` (boolean): Must be true to actually delete. Call WITHOUT it first: the tool answers with the resource so you can confirm with the user.
- `id` (string, required): The status page id.

### `create_maintenance` (~207 tokens)

Schedule a maintenance window over an explicit set of monitors. Scope 'monitor:write'. While it runs the covered monitors suppress alerts (and statistics, if asked). Times are Unix seconds.

Input parameters:

- `durationSec` (integer|null): Length in seconds. Pass this or 'to'.
- `from` (integer, required): Start instant, Unix seconds.
- `monitorIds` (string, required): Comma-separated monitor ids the window covers.
- `name` (string, required): Window name.
- `suppressAlerts` (boolean|null): Suppress alerts during the window (default true on the API side).
- `suppressStats` (boolean|null): Suppress statistics during the window.
- `timezone` (string|null): IANA timezone the schedule is expressed in, e.g. Europe/Berlin.
- `to` (integer|null): End instant, Unix seconds. Pass this or 'durationSec'.
- `weekDays` (string|null): Comma-separated weekdays for a recurring window, e.g. 'Saturday,Sunday'.

### `create_contact_group` (~93 tokens)

Create a contact group: a named set of contacts, each with the events it should receive. Scope 'contact:write'.

Input parameters:

- `itemsJson` (string, required): JSON array of members, e.g. [{"contact":"<contactId>","events":["down","up"]}]. Events: up, down, repeatedlyDown, daily, weekly, monthly, quarterly, yearly.
- `name` (string, required): Group name.

### `get_uptime_summary` (~220 tokens)

Uptime, SLA and response-time figures over a time window for one or more monitors. Scope 'monitor:read'. Times are Unix seconds; omitting the window uses the API's default range.

Input parameters:

- `bucket` (string|null): Bucket size: none, hour, day, week or month.
- `cursor` (string|null): Opaque cursor from a previous call.
- `from` (integer|null): Window start, Unix seconds.
- `groupBy` (string|null): Group by 'monitor' (per monitor) or 'account' (one total).
- `limit` (integer|null): Rows per page, 1-50 (default 20).
- `metrics` (string|null): Comma-separated timing metrics: responseTime, dns, connect, tls, ttfb, transfer.
- `monitor` (string, required): Comma-separated monitor ids (required).
- `sla` (number|null): SLA target percentage to measure against, e.g. 99.9.
- `to` (integer|null): Window end, Unix seconds.

### `update_contact_group` (~78 tokens)

Rename a contact group and/or REPLACE its membership. Scope 'contact:write'. A members list replaces the whole set, it does not merge.

Input parameters:

- `id` (string, required): The group id.
- `itemsJson` (string|null): JSON array of members that replaces the current set.
- `name` (string|null): New group name.

### `test_contact` (~78 tokens)

Send a real test alert to a confirmed contact and report how the delivery ended. Scope 'contact:write'. This actually messages the person and may cost account balance for sms/voice — ask first.

Input parameters:

- `alertType` (string|null): Which alert to simulate: up, down or repeatedlyDown.
- `id` (string, required): The contact id.

### `list_webhook_deliveries` (~148 tokens)

List recent deliveries for one webhook, with their outcome and attempts. Scope 'webhook:read'. Use it to diagnose why an endpoint stopped receiving events.

Input parameters:

- `cursor` (string|null): Opaque cursor from a previous call.
- `eventName` (string|null): Comma-separated event names.
- `from` (integer|null): Window start, Unix seconds.
- `id` (string, required): The webhook id.
- `limit` (integer|null): Rows per page, 1-50 (default 20).
- `outcome` (string|null): Comma-separated outcomes: pending, delivered, failed, dropped.
- `to` (integer|null): Window end, Unix seconds.

### `wait_for_job` (~62 tokens)

Poll a job until it reaches a terminal state or ~30 seconds elapse, then return it. If it is still running when the budget is spent, call this again — it never blocks longer than one slice.

Input parameters:

- `id` (string, required): The job id.

### `list_incidents` (~145 tokens)

List down-episodes across the account or a monitor selection, newest first. Scope 'monitor:read'.

Input parameters:

- `cursor` (string|null): Opaque cursor from a previous call.
- `from` (integer|null): Window start, Unix seconds.
- `limit` (integer|null): Rows per page, 1-50 (default 20).
- `monitor` (string|null): Comma-separated monitor ids; omit for the whole account.
- `severity` (string|null): Comma-separated severities: minor, major, critical.
- `state` (string|null): Comma-separated states: open, resolved.
- `to` (integer|null): Window end, Unix seconds.

### `list_maintenance` (~119 tokens)

List scheduled, active and finished maintenance windows. Scope 'monitor:read'.

Input parameters:

- `cursor` (string|null): Opaque cursor from a previous call.
- `from` (integer|null): Window start, Unix seconds.
- `limit` (integer|null): Rows per page, 1-50 (default 20).
- `monitor` (string|null): Comma-separated monitor ids to filter by.
- `state` (string|null): Comma-separated states: scheduled, active, finished.
- `to` (integer|null): Window end, Unix seconds.

### `create_status_page_incident` (~211 tokens)

Declare an incident or a scheduled maintenance on a status page. Scope 'statuspage:write'. This PUBLISHES the message to the page and notifies its subscribers — have the user approve the exact wording first.

Input parameters:

- `componentIds` (string|null): Comma-separated component ids the incident affects.
- `id` (string, required): The status page id.
- `idempotencyKey` (string|null): Reuse the same key to make a retry replay instead of publishing twice.
- `impact` (string|null): Impact: minor or major.
- `kind` (string|null): 'incident' (default) or 'maintenance'.
- `message` (string, required): The first timeline message shown to visitors.
- `scheduledEnd` (integer|null): Scheduled end for a maintenance, Unix seconds.
- `scheduledStart` (integer|null): Scheduled start for a maintenance, Unix seconds.
- `state` (string): Lifecycle state: investigating, identified, monitoring or resolved.
- `title` (string, required): Incident headline.

### `resume_job` (~58 tokens)

Continue a job whose state is 'interrupted' (the server running it died). Items already concluded are skipped. A job that is not interrupted, or whose kind cannot be resumed, is refused.

Input parameters:

- `id` (string, required): The job id.

### `list_monitor_types` (~40 tokens)

List every monitor type with its label, minimum interval and whether the account's package can create it. Anonymous, but a token adds the per-account limits.

### `list_subscriptions` (~161 tokens)

List who is notified about what. Scope 'subs:read'. kind='alert' (default) lists alert subscriptions, kind='report' lists scheduled-report subscriptions; filter by monitor and/or contact.

Input parameters:

- `contactId` (string|null): Comma-separated contact ids.
- `contactQuery` (string|null): Free-text search over the contacts.
- `cursor` (string|null): Opaque cursor from a previous call.
- `kind` (string|null): Which leg to list: 'alert' or 'report'.
- `limit` (integer|null): Rows per page, 1-50 (default 20).
- `monitorId` (string|null): Comma-separated monitor ids.
- `monitorQuery` (string|null): Free-text search over the monitors.

### `get_contact` (~60 tokens)

Read one contact. Scope 'contact:read'. Add expand='subscription' to see what it is subscribed to.

Input parameters:

- `expand` (string|null): Comma-separated expand tokens: subscription, template, group.
- `id` (string, required): The contact id.

### `describe_api` (~129 tokens)

Describe the HostTracker v2 REST operations available through api_request: their paths, what each one does, its query parameters and its request-body members. Call it with a search term (e.g. 'contact', '/webhook', 'statuspage') before using api_request, so the call is built from the real contract rather than guessed. All timestamps in this API are Unix seconds and all ids are opaque strings.

Input parameters:

- `search` (string|null): Path fragment or operation-id fragment to search for, e.g. '/monitor', 'incident', 'createWebhook'. Omit to list every path.

### `update_maintenance` (~154 tokens)

Reschedule a maintenance window or change what it covers. Scope 'monitor:write'. Only the arguments you pass are changed; a monitorIds list REPLACES the current coverage.

Input parameters:

- `durationSec` (integer|null): New length in seconds.
- `enabled` (boolean|null): Enable or disable the window without deleting it.
- `from` (integer|null): New start instant, Unix seconds.
- `id` (string, required): The maintenance window id.
- `monitorIds` (string|null): Comma-separated monitor ids that replace the current coverage.
- `name` (string|null): New name.
- `timezone` (string|null): New IANA timezone.
- `to` (integer|null): New end instant, Unix seconds.

### `list_check_types` (~47 tokens)

List the instant-check types HostTracker supports, plus the device profiles a page-loading (waterfall) check can emulate. Read live from the API catalogue and cached briefly. No authentication required.

### `list_webhooks` (~70 tokens)

List the account's registered webhooks, including whether each is enabled and its recent failure count. Scope 'webhook:read'.

Input parameters:

- `cursor` (string|null): Opaque cursor from a previous call.
- `limit` (integer|null): Rows per page, 1-50 (default 20).

### `api_request` (~269 tokens)

Call any HostTracker v2 REST operation that no curated tool covers. Look the operation up with describe_api first — the method and path must match a real operation or the call is refused. The caller's token supplies authorisation and its scopes still apply. Writes under /account are refused outright by this server's safety policy. A DELETE, and any bulk write that is not a /validate dry-run, is refused unless confirmed=true - confirm with the user first, then retry with confirmed=true.

Input parameters:

- `bodyJson` (string|null): Request body as a JSON object, for POST/PATCH/PUT.
- `confirmed` (boolean): Required true for a DELETE or a non-validate bulk write, after the user has confirmed.
- `idempotencyKey` (string|null): Idempotency key; required by the bulk and status-page-incident doors, optional elsewhere.
- `method` (string, required): HTTP method: GET, POST, PATCH, PUT or DELETE.
- `path` (string, required): The v2 path with its ids filled in, e.g. '/monitor/9f2…/incident'. No host, no version prefix.
- `query` (string|null): Query string, e.g. 'limit=10&state=down'. May also be a JSON object of parameters.

### `create_status_page` (~134 tokens)

Create a status page. Scope 'statuspage:write'. The page becomes PUBLIC at its slug — agree the slug, the title and which monitors appear with the user before creating it.

Input parameters:

- `componentsJson` (string|null): JSON array of components, e.g. [{"monitorId":"…","name":"API","group":"Core"}].
- `settingsJson` (string|null): JSON object of page settings, e.g. {"theme":"light","robotsIndex":false}.
- `slug` (string, required): URL slug the page is served at; must be unique.
- `title` (string, required): Page title shown to visitors.

### `update_contact` (~100 tokens)

Partially update a contact. Scope 'contact:write'. Changing the address re-triggers confirmation.

Input parameters:

- `address` (string|null): New address.
- `alertDelay` (integer|null): New alert delay in minutes.
- `groupedAlerts` (boolean|null): Group several alerts into one message.
- `id` (string, required): The contact id.
- `language` (string|null): New message language code.
- `name` (string|null): New display name.

### `bulk_delete_monitors` (~171 tokens)

Delete every monitor a filter selects, as an asynchronous job. HIGHLY DESTRUCTIVE — always show the user the validation count first and get an explicit go-ahead. Called without expectedCount it only validates; the submission needs BOTH confirmed=true and the expectedCount the validation reported, and the API refuses it if the selection drifted meanwhile. Scope 'monitor:write'.

Input parameters:

- `confirmed` (boolean): Must be true, together with expectedCount, to actually delete.
- `expectedCount` (integer|null): The 'matched' number the validation step reported. Required to submit.
- `filterJson` (string, required): JSON selection filter, e.g. {"tags":["staging"]}.
- `idempotencyKey` (string|null): Reuse the same key to make a retry replay instead of deleting twice.

### `bulk_create_monitors` (~175 tokens)

Create many monitors in one asynchronous job. Scope 'monitor:write'. The batch is validated first and, unless submit is true, only the validation report comes back — show it to the user, then call again with submit=true. The submitted job is polled with get_job.

Input parameters:

- `defaultsJson` (string|null): JSON object of defaults applied to every item, e.g. {"interval":5,"tags":["prod"]}.
- `idempotencyKey` (string|null): Reuse the same key to make a retry replay instead of creating twice.
- `itemsJson` (string, required): JSON array of monitor definitions, e.g. [{"type":"http","url":"a.com"},{"type":"ping","url":"b.com"}].
- `submit` (boolean): Set true to actually create them after reviewing the validation report.

### `add_status_page_incident_update` (~135 tokens)

Append an update to a declared incident's timeline (and move its state, e.g. to 'resolved'). Scope 'statuspage:write'. This too is PUBLISHED and notifies subscribers — get the wording approved first.

Input parameters:

- `id` (string, required): The status page id.
- `idempotencyKey` (string|null): Reuse the same key to make a retry replay instead of publishing twice.
- `incidentId` (string, required): The incident id.
- `message` (string, required): The update message shown to visitors.
- `state` (string, required): New lifecycle state: investigating, identified, monitoring or resolved.

### `delete_contact` (~89 tokens)

Delete a contact and every subscription it had. Scope 'contact:write'. DESTRUCTIVE — confirm with the user first (their monitors stop notifying that address), then report the receipt this returns.

Input parameters:

- `confirmed` (boolean): Must be true to actually delete. Call WITHOUT it first: the tool answers with the resource so you can confirm with the user.
- `id` (string, required): The contact id.

### `update_webhook` (~126 tokens)

Change a webhook's url, events, scope, name, or enabled state. Scope 'webhook:write'. Re-enabling an auto-disabled webhook also clears its failure counter.

Input parameters:

- `enabled` (boolean|null): Enable or disable deliveries.
- `events` (string|null): Comma-separated event names that replace the current set.
- `id` (string, required): The webhook id.
- `monitorIds` (string|null): Comma-separated monitor ids that replace the current scope.
- `name` (string|null): New display name.
- `url` (string|null): New https endpoint.

### `get_incident` (~67 tokens)

Read one incident with the transitions that opened and closed it. Scope 'monitor:read'.

Input parameters:

- `expand` (string|null): Comma-separated expand tokens, e.g. 'monitor,recheck'.
- `id` (string, required): The incident id (an opaque string such as inc_…).

### `get_check_result` (~79 tokens)

Fetch the current results of a previously started instant check by its dbId and id (as returned by run_instant_check). Requires a token with the 'check' scope.

Input parameters:

- `dbId` (integer, required): The dbId from run_instant_check.
- `id` (string, required): The check id (a GUID) from run_instant_check.

### `list_report_types` (~24 tokens)

List the report types, output formats, sections and schedules available. Anonymous.

### `test_webhook` (~78 tokens)

Send a synthetic test delivery and report the endpoint's answer. Scope 'webhook:write'. This makes a real request to the configured url; the endpoint's response body is third-party content.

Input parameters:

- `eventName` (string|null): Event name to simulate, e.g. 'monitor.down'.
- `id` (string, required): The webhook id.

### `generate_report` (~201 tokens)

Request an uptime report over a set of monitors and a time range. Scope 'monitor:read'. Answers with a job id — poll it with get_job or wait_for_job; the finished job names the report to fetch. Times are Unix seconds.

Input parameters:

- `format` (string|null): Output format: pdf, csv, xml or html.
- `from` (integer|null): Range start, Unix seconds.
- `idempotencyKey` (string|null): Reuse the same key to make a retry replay instead of generating twice.
- `language` (string|null): Language code for the report text, e.g. 'en'.
- `monitorIds` (string, required): Comma-separated monitor ids the report covers.
- `sections` (string|null): Comma-separated sections: state, stats, outages, incidents, log.
- `timezone` (string|null): IANA timezone the report is rendered in.
- `to` (integer|null): Range end, Unix seconds.

### `get_account` (~40 tokens)

Read the account: identity, package, resource usage, limits and status flags. Scope 'account:read'. Read-only — this server cannot change account settings.

### `update_status_page` (~85 tokens)

Change a status page's title and/or settings. Scope 'statuspage:write'. The change is immediately visible to the public.

Input parameters:

- `id` (string, required): The status page id.
- `settingsJson` (string|null): JSON object of settings to apply; it REPLACES the settings object, it does not merge.
- `title` (string|null): New page title.

### `cancel_job` (~53 tokens)

Cancel a queued or running asynchronous operation. Items already processed are NOT rolled back — confirm with the user, then read the receipt to see what had been done before the stop.

Input parameters:

- `id` (string, required): The job id.

### `resume_monitor` (~29 tokens)

Resume a paused monitor. Scope 'monitor:write'.

Input parameters:

- `id` (string, required): The monitor id.

### `create_contact` (~176 tokens)

Create a contact of type email, sms, voiceCall or webPush. Scope 'contact:write'. Sending to a person's address is a real-world action — confirm the address with the user first. The contact is created UNCONFIRMED: a confirmation code is sent to it, and confirm_contact must be called with that code before it receives alerts. For signed HTTP delivery use create_webhook instead.

Input parameters:

- `address` (string, required): The address: an email address, or a phone number in international format.
- `alertDelay` (integer|null): Delay in minutes before an alert is sent to this contact.
- `language` (string|null): Message language code, e.g. 'en'.
- `name` (string|null): Display name.
- `type` (string, required): Contact type: email, sms, voiceCall or webPush.

### `delete_contact_group` (~79 tokens)

Delete a contact group. Scope 'contact:write'. DESTRUCTIVE — confirm with the user first. The contacts themselves are not deleted.

Input parameters:

- `confirmed` (boolean): Must be true to actually delete. Call WITHOUT it first: the tool answers with the resource so you can confirm with the user.
- `id` (string, required): The group id.

### `create_webhook` (~176 tokens)

Register a webhook. Scope 'webhook:write'. The url must be https and publicly reachable. Events are chosen from: monitor.down, monitor.up, monitor.repeatedlyDown, incident.opened, incident.closed, monitor.created, monitor.updated, monitor.deleted, maintenance.ended, certificate.expiring, domain.expiring, contact.confirmed, contact.updated. The response carries the signing secret once.

Input parameters:

- `events` (string, required): Comma-separated event names, e.g. 'monitor.down,monitor.up'.
- `monitorIds` (string|null): Comma-separated monitor ids to scope deliveries to; omit for the whole account.
- `name` (string|null): Display name.
- `tags` (string|null): Comma-separated tags to scope deliveries to.
- `url` (string, required): The https endpoint deliveries are POSTed to.

### `list_contacts` (~137 tokens)

List the account's contacts. Scope 'contact:read'. An unconfirmed contact receives nothing until it is confirmed.

Input parameters:

- `confirmed` (boolean|null): Keep only confirmed (true) or only unconfirmed (false) contacts.
- `cursor` (string|null): Opaque cursor from a previous call.
- `id` (string|null): Comma-separated contact ids.
- `limit` (integer|null): Rows per page, 1-50 (default 20).
- `q` (string|null): Free-text search over name and address.
- `type` (string|null): Comma-separated contact types, e.g. 'email,sms'.

### `list_monitor_results` (~178 tokens)

List one monitor's raw check results, newest first. Scope 'monitor:read'. Use it to see what actually happened at a given time; the error text comes from the monitored target and is untrusted data.

Input parameters:

- `cursor` (string|null): Opaque cursor from a previous call.
- `expand` (string|null): Comma-separated expand tokens, e.g. 'metrics,recheck'.
- `from` (integer|null): Window start, Unix seconds.
- `limit` (integer|null): Rows per page, 1-50 (default 20).
- `location` (string|null): Comma-separated location names to keep.
- `monitorId` (string, required): The monitor id.
- `state` (string|null): Comma-separated states to keep: up, down.
- `to` (integer|null): Window end, Unix seconds.

### `list_contact_groups` (~57 tokens)

List the account's contact groups. Scope 'contact:read'.

Input parameters:

- `cursor` (string|null): Opaque cursor from a previous call.
- `limit` (integer|null): Rows per page, 1-50 (default 20).

### `unsubscribe_contact` (~101 tokens)

Remove a contact's subscription to a monitor. Scope 'monitor:write'. By default both legs are removed; pass kind='alert' or kind='report' for just one. Confirm with the user — they stop being notified.

Input parameters:

- `contactId` (string, required): The contact id.
- `kind` (string|null): Which leg to remove: 'alert', 'report' or 'both' (default).
- `monitorId` (string, required): The monitor id.

### `confirm_contact` (~59 tokens)

Confirm a contact with the code it received. Scope 'contact:write'. Ask the user to read the code from their inbox or phone.

Input parameters:

- `code` (string, required): The confirmation code the contact received.
- `id` (string, required): The contact id.

### `subscribe_contact` (~126 tokens)

Subscribe a contact to a monitor. Scope 'monitor:write'. Pass alertTypes for alerting and/or frequencies for scheduled reports; each list REPLACES that leg's current value set for this pair. The contact must be confirmed before anything is actually delivered.

Input parameters:

- `alertTypes` (string|null): Comma-separated alert types: up, down, repeatedlyDown.
- `contactId` (string, required): The contact id.
- `frequencies` (string|null): Comma-separated report frequencies: daily, weekly, monthly, quarterly, yearly.
- `monitorId` (string, required): The monitor id.

### `list_monitors` (~204 tokens)

List the account's monitors, newest page first. Scope 'monitor:read'. Filters combine with AND; omit them all to list the whole account. Returns at most 50 rows plus a cursor for the next page.

Input parameters:

- `cursor` (string|null): Opaque cursor from a previous call's continuation line.
- `id` (string|null): Comma-separated monitor ids.
- `limit` (integer|null): Rows per page, 1-50 (default 20).
- `q` (string|null): Free-text search over name and url.
- `sort` (string|null): Sort column, e.g. 'name', 'state', 'lastChange:desc'.
- `state` (string|null): Comma-separated states to keep: up, down, paused, maintenance.
- `tag` (string|null): Comma-separated tags.
- `type` (string|null): Comma-separated monitor types, e.g. 'http,ping'. See list_monitor_types.

### `bulk_update_monitors` (~167 tokens)

Apply one patch to every monitor a filter selects, as an asynchronous job. Scope 'monitor:write'. Without submit=true only the count and a sample of what would be touched come back — show that to the user first.

Input parameters:

- `filterJson` (string, required): JSON selection filter, e.g. {"tags":["prod"]} or {"monitorIds":["..."]}.
- `idempotencyKey` (string|null): Reuse the same key to make a retry replay instead of applying twice.
- `operation` (string|null): Set to 'resetStats' to clear statistics instead of patching.
- `patchJson` (string|null): JSON patch applied to each selected monitor, e.g. {"interval":5}.
- `submit` (boolean): Set true to actually apply the change.

### `get_account_quota` (~53 tokens)

Read the API quota headroom and the scopes the current token actually carries. Scope 'account:read'. Call this first when another tool returns a 403 — it shows whether the token is simply missing a scope.

### `send_contact_confirmation` (~64 tokens)

Send (or resend) the confirmation code to an unconfirmed contact. Scope 'contact:write'. This delivers a real message to the address; the code itself is never returned to the agent — ask the user for it.

Input parameters:

- `id` (string, required): The contact id.

### `pause_monitor` (~38 tokens)

Pause a monitor: it stops checking and stops alerting until resumed. Scope 'monitor:write'.

Input parameters:

- `id` (string, required): The monitor id.

### `copy_monitor` (~136 tokens)

Copy a monitor to one or more new addresses, keeping its configuration. Scope 'monitor:write'. Copying many addresses answers with a job id — poll it with get_job.

Input parameters:

- `id` (string, required): The monitor id to copy from.
- `includeAlerts` (boolean|null): Copy the alert subscriptions too (default true).
- `includeMaintenance` (boolean|null): Copy the maintenance windows too.
- `includeReports` (boolean|null): Copy the report subscriptions too.
- `name` (string|null): Name for the copies; the address is used when omitted.
- `urls` (string, required): Comma-separated addresses to create copies for.

### `get_status_page` (~37 tokens)

Read one status page with its settings and components. Scope 'statuspage:read'.

Input parameters:

- `id` (string, required): The status page id.

### `get_job` (~92 tokens)

Poll one asynchronous operation: its state, progress and per-item results. A failed job still answers 200 with state='failed'; each failed item carries its own error.

Input parameters:

- `cursor` (string|null): Opaque cursor to continue the item list.
- `id` (string, required): The job id.
- `limit` (integer|null): How many per-item results to include, 1-50 (default 20).

### `run_instant_check` (~291 tokens)

Run a free instant website/host check from HostTracker's global monitoring locations and return per-location results. Requires a token with the 'check' scope (mint at Integrations → API, https://www.host-tracker.com/integrations/api). Starts the check, polls up to ~30s, and returns per-location status plus the public result-page URL; a check that is still running comes back partial with the ids to poll.

Input parameters:

- `device` (string|null): Device-emulation profile for a waterfall/pageSpeed check; one of the device tokens from list_check_types.
- `pools` (string|null): Comma-separated location pools to run from, e.g. 'europe,northamerica'. Unknown pool names are refused by the API, which names the offender.
- `strictTls` (boolean): http checks only: validate the TLS handshake strictly. An untrusted root, an incomplete chain, a hostname mismatch or a self-signed certificate fails the handshake and is recorded on the result's TLS…
- `type` (string|null): Check type; one of the tokens from list_check_types (default http). 'pageSpeed' is accepted as an alias for 'waterfall'.
- `url` (string, required): The site or host to check, e.g. example.com or https://example.com

### `get_account_usage` (~36 tokens)

Read how many monitors, contacts, reports and maintenance windows the account uses out of what its package allows. Scope 'account:read'.

### `delete_webhook` (~89 tokens)

Unregister a webhook and stop its deliveries. Scope 'webhook:write'. DESTRUCTIVE — confirm with the user first; pending deliveries are dropped and the signing secret cannot be recovered.

Input parameters:

- `confirmed` (boolean): Must be true to actually delete. Call WITHOUT it first: the tool answers with the resource so you can confirm with the user.
- `id` (string, required): The webhook id.

### `delete_monitor` (~85 tokens)

Delete one monitor and its subscriptions. Scope 'monitor:write'. DESTRUCTIVE and not undoable — confirm with the user first, then report the deletion receipt this returns.

Input parameters:

- `confirmed` (boolean): Must be true to actually delete. Call WITHOUT it first: the tool answers with the resource so you can confirm with the user.
- `id` (string, required): The monitor id.

### `redeliver_webhook` (~80 tokens)

Resend a previously recorded delivery to the same endpoint. Scope 'webhook:write'. The receiver sees the same delivery id, so a correctly-written consumer deduplicates it.

Input parameters:

- `deliveryId` (string, required): The delivery id (d_… ) from list_webhook_deliveries.
- `id` (string, required): The webhook id.

### `update_monitor` (~162 tokens)

Partially update a monitor. Scope 'monitor:write'. Only the arguments you pass are changed; everything else stays as it is.

Input parameters:

- `addTags` (string|null): Comma-separated tags to add.
- `id` (string, required): The monitor id.
- `interval` (integer|null): New check interval in minutes.
- `name` (string|null): New display name.
- `pools` (string|null): Comma-separated location pools that replace the current pinning.
- `removeTags` (string|null): Comma-separated tags to remove.
- `settingsJson` (string|null): Type-specific settings as a JSON object.
- `tags` (string|null): Comma-separated tags that REPLACE the current set.
- `url` (string|null): New address.

### `create_monitor` (~228 tokens)

Create a monitor. Scope 'monitor:write'. Confirm the target and interval with the user first — a monitor consumes an account slot and starts alerting. Attach contacts afterwards with subscribe_contact.

Input parameters:

- `dryRun` (boolean|null): Set true to validate only, creating nothing.
- `enabled` (boolean|null): Whether the monitor starts enabled (default true).
- `interval` (integer|null): Check interval in minutes; must be one of the account's allowed intervals.
- `name` (string|null): Display name; defaults to the url.
- `pools` (string|null): Comma-separated location pools, e.g. 'allworld' for everywhere. At least one is required when the type needs locations.
- `settingsJson` (string|null): Type-specific settings as a JSON object (see the monitor type's schema).
- `tags` (string|null): Comma-separated tags.
- `type` (string, required): Monitor type, e.g. http, ping, port, waterfall, sslExp, domainExp. See list_monitor_types.
- `url` (string|null): The address to monitor.

### `comment_incident` (~66 tokens)

Annotate an incident with a note (for example the root cause) and get the incident back. Scope 'monitor:write'. The comment replaces any previous one.

Input parameters:

- `comment` (string, required): The note to store on the incident.
- `id` (string, required): The incident id.

### `delete_maintenance` (~86 tokens)

Cancel a maintenance window. Scope 'monitor:write'. DESTRUCTIVE — confirm with the user first; cancelling an ACTIVE window makes its monitors start alerting again immediately.

Input parameters:

- `confirmed` (boolean): Must be true to actually cancel. Call WITHOUT it first: the tool answers with the resource so you can confirm with the user.
- `id` (string, required): The maintenance window id.

### `list_locations` (~143 tokens)

List the location pools checks can run from (and, with agents=true, the individual monitoring locations). Pool ids are what the 'pools' argument of create_monitor and run_instant_check takes; 'allworld' means everywhere.

Input parameters:

- `agents` (boolean): Set true to list individual agents instead of pools.
- `country` (string|null): Comma-separated ISO country codes to filter agents by.
- `cursor` (string|null): Opaque cursor from a previous call.
- `limit` (integer|null): Rows per page, 1-50 (default 50 for pools).
- `pool` (string|null): Comma-separated pool ids to filter agents by.

### `list_status_pages` (~58 tokens)

List the account's status pages. Scope 'statuspage:read'.

Input parameters:

- `cursor` (string|null): Opaque cursor from a previous call.
- `limit` (integer|null): Rows per page, 1-50 (default 20).

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/hosttracker-hosttracker/mcp#diagnostics

## Score history

- 2026-10-06: 32
- 2026-10-04: 32
- 2026-10-03: 32
- 2026-10-02: 32
- 2026-10-01: 32
- 2026-09-30: 32
- 2026-09-29: 32
- 2026-09-28: 32
- 2026-09-27: 32
- 2026-09-26: 32
- 2026-09-25: 32
- 2026-09-24: 32
- 2026-09-23: 32
- 2026-09-22: 32
- 2026-09-21: 32
- 2026-09-20: 32
- 2026-09-19: 32
- 2026-09-18: 32
- 2026-09-17: 32
- 2026-09-16: 32
- 2026-09-15: 32
- 2026-09-14: 32
- 2026-09-13: 32
- 2026-09-12: 32
- 2026-09-11: 32
- 2026-09-10: 32
- 2026-09-09: 32
- 2026-09-08: 32
- 2026-09-07: 32
- 2026-09-06: 32

## Common questions

### What is the HostTracker MCP server?

HostTracker is an MCP server listed in the public MCP registry as io.github.HostTracker/hosttracker. Website uptime monitoring: run checks from 300+ locations, manage monitors, alerts and incidents. This page covers its hosted endpoint (https://mcp.host-tracker.com/mcp).

### Is the HostTracker MCP server safe to use?

HostTracker scores 32 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the HostTracker MCP server expose?

HostTracker exposes 65 tools: get_monitor, delete_status_page, create_maintenance, create_contact_group, get_uptime_summary, and 60 more. Their descriptions and schemas cost roughly 7,341 tokens of context every time the server is loaded.

### Does the HostTracker MCP server require authentication?

Yes. HostTracker asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

### Is the HostTracker MCP server still maintained?

HostTracker is still listed as active in the MCP registry. We last reached this channel on 6 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://mcp.host-tracker.com/mcp
- Repository: https://github.com/HostTracker/mcp
- Website: https://www.host-tracker.com/mcp-server
- Changelog RSS feed: https://verifymcp.io/servers/hosttracker-hosttracker/mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/hosttracker-hosttracker/mcp.json
- HTML version of this page: https://verifymcp.io/servers/hosttracker-hosttracker/mcp
