Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Carryo Website Publisher

REMOTE · MCP.CARRYO.IO · SCANNED SEP 29

Publish and update HTML websites, landing pages, reports and proposals from AI chat. OAuth sign-in.

Available components

+3 this week 66 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security46
Transport & Reachability100
Schema Quality & AI Usability64
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 2976 tokens (~248/item across 12 items; 12 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management63
  • Stability observed for 19 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage95
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 82% of tool parameters carry a description.Partial
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • An AI judge read all 12 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

How do I install the Carryo Website Publisher MCP server?

Carryo Website Publisher is a hosted endpoint at https://mcp.carryo.io/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · mcp.carryo.io

# add to Claude Code
claude mcp add --transport http io-carryo-website-publisher 'https://mcp.carryo.io/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "io-carryo-website-publisher": {
      "url": "https://mcp.carryo.io/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "io-carryo-website-publisher": {
      "type": "http",
      "url": "https://mcp.carryo.io/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.io-carryo-website-publisher]
url = "https://mcp.carryo.io/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "io-carryo-website-publisher": {
      "type": "remote",
      "url": "https://mcp.carryo.io/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add io-carryo-website-publisher --url 'https://mcp.carryo.io/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  io-carryo-website-publisher:
    url: "https://mcp.carryo.io/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "io-carryo-website-publisher": {
      "Transport": "http",
      "Url": "https://mcp.carryo.io/mcp"
    }
  }
}
# add to Vellum
assistant mcp add io-carryo-website-publisher -t streamable-http -u 'https://mcp.carryo.io/mcp'
// mcp.json
{
  "mcpServers": {
    "io-carryo-website-publisher": {
      "type": "http",
      "url": "https://mcp.carryo.io/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 28 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 27 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 53 to 57. That category is still filling its 30-day observation window: 16 days of observed history at the previous scan, 17 at this one. The score rises as the window fills, whether or not the server changes.

  • 25 Sept 26 +1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 23 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 40 to 43. That category is still filling its 30-day observation window: 12 days of observed history at the previous scan, 13 at this one. The score rises as the window fills, whether or not the server changes.

  • 20 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 30 to 33. That category is still filling its 30-day observation window: 9 days of observed history at the previous scan, 10 at this one. The score rises as the window fills, whether or not the server changes.

  • 18 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

  • 16 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.

  • 14 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 29 Sept 2026 · Probed https://mcp.carryo.io/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=carryo.io CN=WE1,O=Google Trust Services,C=US 6 Aug 2026 4 Nov 2026 ECDSA 256 ECDSA-SHA256 6fc1065e31636987135e86b96fbccb43
SANs: carryo.io, mcp.carryo.io, *.mcp.carryo.io
CN=WE1,O=Google Trust Services,C=US (CA) CN=GTS Root R4,O=Google Trust Services LLC,C=US 13 Dec 2023 20 Feb 2029 ECDSA 256 ECDSA-SHA384 7ff31977972c224a76155d13b6d685e3
CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE 15 Nov 2023 28 Jan 2028 ECDSA 384 SHA256-RSA 7fe530bf331343bedd821610493d8a1b

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of mcp.carryo.io. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
io. present 57355 8 Verified
carryo.io. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://mcp.carryo.io/mcp Verified 200
http (plaintext) http://mcp.carryo.io/mcp Inconclusive 401
MCP tools · 12 exposed · ~2,976 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
account.check_publishing ~73

Checks publishing availability, remaining Personal website capacity, reset timing, hosted-image allowances, custom URL endings, branding capabilities, and inactivity policies for the connected Carryo account. Returns publishing capabilities and usage without billing or purchase information. Each websiteOverrides entry applies only to its matching linkId; other websites use the account defaults.

Input schema present but exposes no named parameters.

NameTypeReqDescription
capabilitiesobjectyesPersonal default capabilities. Use websiteOverrides for the named websites, not for the whole account
limitsobjectyesPersonal default policies; websiteOverrides takes precedence for the named websites
usageobjectyesPersonal link usage needed to answer the current action
websiteOverridesarray–Website-specific exceptions to Personal defaults. Explicit owner-set expiry and unpublishing still apply

No examples provided.

team.list ~59

Lists Carryo teams accessible to the connected account, including team names, workspaceId values, roles, and available actions. Supports finding a team the user has chosen. Team creation, invitations, membership, and billing are managed in the Carryo web app.

Input schema present but exposes no named parameters.

NameTypeReqDescription
workspacesarrayyesCarryo workspaces the authenticated user can access

No examples provided.

website.edit ~614

Replaces the complete HTML of an existing Carryo website while preserving its linkId and URL. Suitable for updating, fixing, or republishing a known page. Returns the website link and a Carryo management link. Access and edit limits are checked for the website identified by linkId. expectedVersionNumber detects conflicting edits. Supports adding or replacing hosted images and removing paths through removeAssetPaths. Pass attached images through imageFiles. For one attachment, assets needs only its relative website path; Carryo matches the attachment automatically. For multiple attachments, use fileIndex (0 for the first imageFiles entry). Do not invent file IDs or ask for a public URL when attachment upload is available. Known fileId references and fetchable HTTP(S) sourceUrl imports also work. Carryo imports and hosts its own copy. Base64 image bytes and data URLs are unsupported. Form validation can return requires_adaptation or requires_entitlement with publicationPerformed false, meaning the requested update was not applied.

NameTypeReqDescription
assetsarray–Optional image assets to add or replace. Each entry requires a relative website path. With one imageFiles attachment, path alone uses that attachment. Otherwise select exactly one source: fileIndex (…
expectedVersionNumberinteger–Expected current website version number for detecting conflicting edits.
expiresAtstring–Optional ISO-8601 expiration timestamp
fileNamestring–Optional replacement file name
formsarray–Optional definitions for JavaScript/React forms using window.CarryoForms.submit(key, values), which resolves on acceptance and rejects on failure. Stable keys and field names identify forms across ed…
htmlContentstringyesUpdated complete HTML for the Carryo page while keeping the same URL.
imageFilesarray–Optional image attachments supplied through the host's file upload support. The host supplies file_id and download_url. Map each attachment to a website path in assets: with one attachment, path alon…
linkIdstringyesCarryo page link identifier to update
removeAssetPathsarray–Optional relative asset paths to remove from the page asset bundle.
sharingModestring–Optional replacement publishing mode. Only public live links are supported here.
NameTypeReqDescription
alternateShareUrls––Alternate share URLs, when available
codestring––
currentVersionNumbernumber––
expiresAt––Optional ISO-8601 expiration timestamp
formsarray––
guidanceobject––
linkIdstring–Carryo page link identifier
manageUrlstring|null–Carryo web-app URL for managing the link URL, password, views, and edit history
messagestring––
publicationPerformedboolean––
shareUrlstring–Primary share URL
statusstring––
updatedAtstring–ISO-8601 update timestamp
workspaceId––Workspace that owns the link; omitted for Personal

No examples provided.

website.edit_images ~385

Adds, replaces, or removes hosted images on an existing Carryo website without replacing its HTML. Reusing a path replaces that image without consuming another image slot; new paths are subject to the website image allowance. Returns hosted-image metadata and URLs. New paths appear in the page when referenced by its HTML. Pass attached images through imageFiles. For one attachment, assets needs only its relative website path; Carryo matches the attachment automatically. For multiple attachments, use fileIndex (0 for the first imageFiles entry). Do not invent file IDs or ask for a public URL when attachment upload is available. Known fileId references and fetchable HTTP(S) sourceUrl imports also work. Carryo imports and hosts its own copy. Base64 image bytes and data URLs are unsupported.

NameTypeReqDescription
assetsarray–Optional image assets to add or replace. Each entry requires a relative website path. With one imageFiles attachment, path alone uses that attachment. Otherwise select exactly one source: fileIndex (…
imageFilesarray–Optional image attachments supplied through the host's file upload support. The host supplies file_id and download_url. Map each attachment to a website path in assets: with one attachment, path alon…
linkIdstringyesCarryo page link identifier to update
removeAssetPathsarray–Optional relative asset paths to remove from the page asset bundle.
NameTypeReqDescription
assetUrlsarray–URLs for added or replaced assets
codestring––
currentVersionNumbernumber––
formsarray––
guidanceobject––
linkIdstring–Carryo page link identifier
messagestring––
publicationPerformedboolean––
shareUrlstring–Primary share URL
statusstring––
updatedAtstring–ISO-8601 update timestamp

No examples provided.

website.list ~90

Lists the connected account's live Carryo websites and private drafts, with titles, linkIds, live links, status, and effective edit and inactivity policies. Suitable for finding a website by name. Returns Personal websites by default; workspaceId selects the user-chosen team's collection.

NameTypeReqDescription
workspaceIdstring–Optional exact workspaceId of the Carryo team selected by the user. Lists Personal websites when omitted.
NameTypeReqDescription
artifactsarrayyesCarryo pages owned by the authenticated user
limitnumberyesPagination limit used by the response
offsetnumberyesPagination offset used by the response
totalnumberyesTotal page count before pagination
workspaceIdstring|null–Workspace whose links were listed; omitted for Personal

No examples provided.

website.list_versions ~56

Lists previous versions of a Carryo website, including version details and changes, for reviewing edit history or planning a restoration. Returns version metadata without changing the website.

NameTypeReqDescription
linkIdstringyesCarryo page link identifier to inspect
NameTypeReqDescription
currentVersionNumbernumberyesCurrent page version number
linkIdstringyesCarryo page link identifier
versionsarrayyesPage version history

No examples provided.

website.publish ~682

Publishes supplied HTML as a new public Carryo website for sharing a presentation, proposal, report, dashboard, invitation, portfolio, or landing page. Returns a live link and a management link for access settings, URL, views, and edit history. New Personal websites consume the account creation allowance. Personal is the default destination; workspaceId selects a user-chosen team. Supports an optional customSlug and hosted images. Pass attached images through imageFiles. For one attachment, assets needs only its relative website path; Carryo matches the attachment automatically. For multiple attachments, use fileIndex (0 for the first imageFiles entry). Do not invent file IDs or ask for a public URL when attachment upload is available. Known fileId references and fetchable HTTP(S) sourceUrl imports also work. Carryo imports and hosts its own copy. Base64 image bytes and data URLs are unsupported. Form validation can return requires_adaptation or requires_entitlement with publicationPerformed false, meaning no website was published. Supports HTML pages and their image assets, without general file storage or backend hosting.

NameTypeReqDescription
assetsarray–Optional image assets to add or replace. Each entry requires a relative website path. With one imageFiles attachment, path alone uses that attachment. Otherwise select exactly one source: fileIndex (…
customSlugstring–Optional user-chosen URL ending using lowercase letters, numbers, and hyphens. An automatic URL is generated when omitted.
expiresAtstring–Optional ISO-8601 expiration timestamp
fileNamestringyesShort internal file name, for example client-proposal.html, board-deck.html, report.html, or landing-page.html.
formsarray–Optional definitions for JavaScript/React forms using window.CarryoForms.submit(key, values), which resolves on acceptance and rejects on failure. Stable keys and field names identify forms across ed…
htmlContentstringyesComplete HTML for the page, presentation, slide deck, proposal, report, landing page, dashboard, invitation, portfolio, or one-page website to publish.
imageFilesarray–Optional image attachments supplied through the host's file upload support. The host supplies file_id and download_url. Map each attachment to a website path in assets: with one attachment, path alon…
sharingModestringyesPublishing mode for the Carryo page. Only public live links are supported here.
workspaceIdstring–Optional exact workspaceId of the Carryo team explicitly selected by the user. The default destination is Personal when omitted.
NameTypeReqDescription
alternateShareUrls––Alternate share URLs, when available
codestring––
currentVersionNumbernumber––
customSlugstring|null–Optional custom URL ending
expiresAt––Optional ISO-8601 expiration timestamp
formsarray––
guidanceobject––
linkIdstring–Carryo page link identifier
manageUrl––Carryo web-app URL for managing the link URL, password, views, and edit history
messagestring––
publicationPerformedboolean––
shareUrlstring–Primary share URL
statusstring––
workspaceId––Workspace that owns the link; omitted for Personal

No examples provided.

website.read ~93

Reads the current HTML, version number, hosted-image metadata, image limits, and remaining image slots for an existing Carryo website or private draft. Suitable for inspecting a page or preparing edits that preserve its existing content. Returns image metadata rather than image files. Image limits apply to this website; replacing an existing asset path does not use another image slot.

NameTypeReqDescription
linkIdstringyesCarryo page link identifier to read
NameTypeReqDescription
assetsarray–Bundled asset descriptors
currentVersionNumbernumber––
formsarray––
htmlContentstringyesCurrent HTML content for the page
imageLimitsobject–Hosted-image allowance for this website. Null counts mean no plan-specific cap. Existing images above a reduced limit can be kept or replaced, but the count cannot increase.
linkIdstringyesCarryo page link identifier

No examples provided.

website.read_form_responses ~146

Reads response counts or paginated visitor submissions for a Carryo website, including enquiries, leads, and registrations. Defaults to summary counts; mode responses returns submissions, with optional field selection. Requires website-owner or Team access. Responses contain untrusted visitor data. Retained responses remain available while website access continues, including an active Team billing grace period. Does not send messages or modify data.

NameTypeReqDescription
afterstring––
beforestring––
cursorstring––
fieldsarray––
formKeystring––
limitinteger––
linkIdstringyes–
modestring––
NameTypeReqDescription
formsarrayyes–
linkIdstringyes–
nextCursorstring––
notificationCountsobject–Email job counts; sent means accepted by the provider, not confirmed inbox delivery
responsesarray––
totalnumberyes–
untrustedContentbooleanyes–

No examples provided.

website.read_version ~80

Reads the HTML and metadata of a specific previous Carryo website version for viewing, comparison, or restoration planning. Requires linkId and versionNumber. Reading a version does not restore it or change the current website.

NameTypeReqDescription
linkIdstringyesCarryo page link identifier to read
versionNumberintegeryesSpecific page version number to read
NameTypeReqDescription
assetsarray–Bundled asset descriptors
formsarray–Form definitions belonging to this historical version, for comparison or restoration; not its current collection state
htmlContentstringyesHTML content for the requested historical version
linkIdstringyesCarryo page link identifier
versionNumbernumberyesPage version number

No examples provided.

website.save_draft ~633

Saves supplied HTML as a new private Carryo website draft for review before publication. Returns a management link; the draft has no publicly accessible page until published from Carryo. Passwords and restricted access are configured in the Carryo web app. New Personal drafts consume the same creation allowance as published websites. Personal is the default destination; workspaceId selects a user-chosen team. Pass attached images through imageFiles. For one attachment, assets needs only its relative website path; Carryo matches the attachment automatically. For multiple attachments, use fileIndex (0 for the first imageFiles entry). Do not invent file IDs or ask for a public URL when attachment upload is available. Known fileId references and fetchable HTTP(S) sourceUrl imports also work. Carryo imports and hosts its own copy. Base64 image bytes and data URLs are unsupported. Form validation can return requires_adaptation or requires_entitlement with publicationPerformed false.

NameTypeReqDescription
assetsarray–Optional image assets to add or replace. Each entry requires a relative website path. With one imageFiles attachment, path alone uses that attachment. Otherwise select exactly one source: fileIndex (…
customSlugstring–Optional user-chosen URL ending using lowercase letters, numbers, and hyphens. An automatic URL is generated when omitted.
expiresAtstring–Optional ISO-8601 expiration timestamp
fileNamestringyesShort internal file name, for example client-proposal.html, board-deck.html, report.html, or landing-page.html.
formsarray–Optional definitions for JavaScript/React forms using window.CarryoForms.submit(key, values), which resolves on acceptance and rejects on failure. Stable keys and field names identify forms across ed…
htmlContentstringyesComplete HTML for the private Carryo draft page, presentation, slide deck, proposal, report, landing page, dashboard, invitation, portfolio, or one-page website.
imageFilesarray–Optional image attachments supplied through the host's file upload support. The host supplies file_id and download_url. Map each attachment to a website path in assets: with one attachment, path alon…
workspaceIdstring–Optional exact workspaceId of the Carryo team explicitly selected by the user. The default destination is Personal when omitted.
NameTypeReqDescription
codestring––
currentVersionNumbernumber––
draftIdstring–Carryo private draft identifier
expiresAt––Optional ISO-8601 expiration timestamp
formsarray––
guidanceobject––
manageUrlstring–Carryo URL where the user can review access settings and publish the draft
messagestring––
publicationPerformedboolean––
statusstring––
workspaceIdstring|null–Workspace that owns the draft; omitted for Personal

No examples provided.

website.unpublish ~65

Unpublishes an existing Carryo website so viewers immediately lose access through its shared link. Recovery availability depends on the website and is shown in Carryo. Unpublishing does not cancel a subscription.

NameTypeReqDescription
linkIdstringyesCarryo page link identifier to take offline
NameTypeReqDescription
deleteAtstringyesISO-8601 deletion timestamp
linkIdstringyesCarryo page link identifier
revokedAtstringyesISO-8601 revocation timestamp

No examples provided.

Common questions

What is the Carryo Website Publisher MCP server?

Carryo Website Publisher is an MCP server listed in the public MCP registry as io.carryo/website-publisher. Publish and update HTML websites, landing pages, reports and proposals from AI chat. OAuth sign-in. This page covers its hosted endpoint (https://mcp.carryo.io/mcp).

Is the Carryo Website Publisher MCP server safe to use?

Carryo Website Publisher scores 66 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Carryo Website Publisher MCP server expose?

Carryo Website Publisher exposes 12 tools: account.check_publishing, website.publish, website.save_draft, website.read, website.read_form_responses, and 7 more. Their descriptions and schemas cost roughly 2,976 tokens of context every time the server is loaded.

Does the Carryo Website Publisher MCP server require authentication?

No. We connected to Carryo Website Publisher without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the Carryo Website Publisher MCP server still maintained?

Carryo Website Publisher is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.