# Carryo Website Publisher (remote · mcp.carryo.io)

Publish and update HTML websites, landing pages, reports and proposals from AI chat. OAuth sign-in.

- Trust score: 66/100 (medium)
- Change this week: +3
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-29

## Components

- remote · `mcp.carryo.io`: 66/100 (this document), [markdown](https://verifymcp.io/servers/io-carryo-website-publisher/mcp.md), [page](https://verifymcp.io/servers/io-carryo-website-publisher/mcp)

## Channel facts

- Endpoint: `https://mcp.carryo.io/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `0.1.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-29.

- **Endpoint Security**: 46/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (website.edit_images).
  - HTTPS enforcement could not be verified: the plaintext port answered with HTTP 401, which proves neither a plaintext path nor enforcement.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 64/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 2976 tokens (~248/item across 12 items; 12 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 63/100
  - Stability observed for 19 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 95/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 82% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.
  - An AI judge read all 12 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### How do I install the Carryo Website Publisher MCP server?

Carryo Website Publisher is a hosted endpoint at https://mcp.carryo.io/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http io-carryo-website-publisher 'https://mcp.carryo.io/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "io-carryo-website-publisher": {
      "url": "https://mcp.carryo.io/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "io-carryo-website-publisher": {
      "type": "http",
      "url": "https://mcp.carryo.io/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.io-carryo-website-publisher]
url = "https://mcp.carryo.io/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "io-carryo-website-publisher": {
      "type": "remote",
      "url": "https://mcp.carryo.io/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add io-carryo-website-publisher --url 'https://mcp.carryo.io/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  io-carryo-website-publisher:
    url: "https://mcp.carryo.io/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "io-carryo-website-publisher": {
      "Transport": "http",
      "Url": "https://mcp.carryo.io/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add io-carryo-website-publisher -t streamable-http -u 'https://mcp.carryo.io/mcp'
```

### Other

```json
{
  "mcpServers": {
    "io-carryo-website-publisher": {
      "type": "http",
      "url": "https://mcp.carryo.io/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-28 (score 66, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-27 (score 66, +1)

No change was recorded against any check on this day. Stability & Change Management went from 53 to 57. That category is still filling its 30-day observation window: 16 days of observed history at the previous scan, 17 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-25 (score 65, +1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-23 (score 64, +1)

No change was recorded against any check on this day. Stability & Change Management went from 40 to 43. That category is still filling its 30-day observation window: 12 days of observed history at the previous scan, 13 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-20 (score 63, +1)

No change was recorded against any check on this day. Stability & Change Management went from 30 to 33. That category is still filling its 30-day observation window: 9 days of observed history at the previous scan, 10 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-18 (score 62, +1)

No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-16 (score 61, +1)

No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-14 (score 60, +1)

No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.

## MCP tools (12)

### `account.check_publishing` (~73 tokens)

Check Publishing Availability

Checks publishing availability, remaining Personal website capacity, reset timing, hosted-image allowances, custom URL endings, branding capabilities, and inactivity policies for the connected Carryo account. Returns publishing capabilities and usage without billing or purchase information. Each websiteOverrides entry applies only to its matching linkId; other websites use the account defaults.

Output parameters:

- `capabilities` (object): Personal default capabilities. Use websiteOverrides for the named websites, not for the whole account
- `limits` (object): Personal default policies; websiteOverrides takes precedence for the named websites
- `usage` (object): Personal link usage needed to answer the current action
- `websiteOverrides` (array): Website-specific exceptions to Personal defaults. Explicit owner-set expiry and unpublishing still apply

### `website.publish` (~682 tokens)

Publish a Live Website

Publishes supplied HTML as a new public Carryo website for sharing a presentation, proposal, report, dashboard, invitation, portfolio, or landing page. Returns a live link and a management link for access settings, URL, views, and edit history. New Personal websites consume the account creation allowance. Personal is the default destination; workspaceId selects a user-chosen team. Supports an optional customSlug and hosted images. Pass attached images through imageFiles. For one attachment, assets needs only its relative website path; Carryo matches the attachment automatically. For multiple attachments, use fileIndex (0 for the first imageFiles entry). Do not invent file IDs or ask for a public URL when attachment upload is available. Known fileId references and fetchable HTTP(S) sourceUrl imports also work. Carryo imports and hosts its own copy. Base64 image bytes and data URLs are unsupported. Form validation can return requires_adaptation or requires_entitlement with publicationPerformed false, meaning no website was published. Supports HTML pages and their image assets, without general file storage or backend hosting.

Input parameters:

- `assets` (array): Optional image assets to add or replace. Each entry requires a relative website path. With one imageFiles attachment, path alone uses that attachment. Otherwise select exactly one source: fileIndex (…
- `customSlug` (string): Optional user-chosen URL ending using lowercase letters, numbers, and hyphens. An automatic URL is generated when omitted.
- `expiresAt` (string): Optional ISO-8601 expiration timestamp
- `fileName` (string, required): Short internal file name, for example client-proposal.html, board-deck.html, report.html, or landing-page.html.
- `forms` (array): Optional definitions for JavaScript/React forms using window.CarryoForms.submit(key, values), which resolves on acceptance and rejects on failure. Stable keys and field names identify forms across ed…
- `htmlContent` (string, required): Complete HTML for the page, presentation, slide deck, proposal, report, landing page, dashboard, invitation, portfolio, or one-page website to publish.
- `imageFiles` (array): Optional image attachments supplied through the host's file upload support. The host supplies file_id and download_url. Map each attachment to a website path in assets: with one attachment, path alon…
- `sharingMode` (string, required): Publishing mode for the Carryo page. Only public live links are supported here.
- `workspaceId` (string): Optional exact workspaceId of the Carryo team explicitly selected by the user. The default destination is Personal when omitted.

Output parameters:

- `alternateShareUrls`: Alternate share URLs, when available
- `code` (string)
- `currentVersionNumber` (number)
- `customSlug` (string|null): Optional custom URL ending
- `expiresAt`: Optional ISO-8601 expiration timestamp
- `forms` (array)
- `guidance` (object)
- `linkId` (string): Carryo page link identifier
- `manageUrl`: Carryo web-app URL for managing the link URL, password, views, and edit history
- `message` (string)
- `publicationPerformed` (boolean)
- `shareUrl` (string): Primary share URL
- `status` (string)
- `workspaceId`: Workspace that owns the link; omitted for Personal

### `website.save_draft` (~633 tokens)

Save a Private Website Draft

Saves supplied HTML as a new private Carryo website draft for review before publication. Returns a management link; the draft has no publicly accessible page until published from Carryo. Passwords and restricted access are configured in the Carryo web app. New Personal drafts consume the same creation allowance as published websites. Personal is the default destination; workspaceId selects a user-chosen team. Pass attached images through imageFiles. For one attachment, assets needs only its relative website path; Carryo matches the attachment automatically. For multiple attachments, use fileIndex (0 for the first imageFiles entry). Do not invent file IDs or ask for a public URL when attachment upload is available. Known fileId references and fetchable HTTP(S) sourceUrl imports also work. Carryo imports and hosts its own copy. Base64 image bytes and data URLs are unsupported. Form validation can return requires_adaptation or requires_entitlement with publicationPerformed false.

Input parameters:

- `assets` (array): Optional image assets to add or replace. Each entry requires a relative website path. With one imageFiles attachment, path alone uses that attachment. Otherwise select exactly one source: fileIndex (…
- `customSlug` (string): Optional user-chosen URL ending using lowercase letters, numbers, and hyphens. An automatic URL is generated when omitted.
- `expiresAt` (string): Optional ISO-8601 expiration timestamp
- `fileName` (string, required): Short internal file name, for example client-proposal.html, board-deck.html, report.html, or landing-page.html.
- `forms` (array): Optional definitions for JavaScript/React forms using window.CarryoForms.submit(key, values), which resolves on acceptance and rejects on failure. Stable keys and field names identify forms across ed…
- `htmlContent` (string, required): Complete HTML for the private Carryo draft page, presentation, slide deck, proposal, report, landing page, dashboard, invitation, portfolio, or one-page website.
- `imageFiles` (array): Optional image attachments supplied through the host's file upload support. The host supplies file_id and download_url. Map each attachment to a website path in assets: with one attachment, path alon…
- `workspaceId` (string): Optional exact workspaceId of the Carryo team explicitly selected by the user. The default destination is Personal when omitted.

Output parameters:

- `code` (string)
- `currentVersionNumber` (number)
- `draftId` (string): Carryo private draft identifier
- `expiresAt`: Optional ISO-8601 expiration timestamp
- `forms` (array)
- `guidance` (object)
- `manageUrl` (string): Carryo URL where the user can review access settings and publish the draft
- `message` (string)
- `publicationPerformed` (boolean)
- `status` (string)
- `workspaceId` (string|null): Workspace that owns the draft; omitted for Personal

### `website.read` (~93 tokens)

Read the Current Website

Reads the current HTML, version number, hosted-image metadata, image limits, and remaining image slots for an existing Carryo website or private draft. Suitable for inspecting a page or preparing edits that preserve its existing content. Returns image metadata rather than image files. Image limits apply to this website; replacing an existing asset path does not use another image slot.

Input parameters:

- `linkId` (string, required): Carryo page link identifier to read

Output parameters:

- `assets` (array): Bundled asset descriptors
- `currentVersionNumber` (number)
- `forms` (array)
- `htmlContent` (string): Current HTML content for the page
- `imageLimits` (object): Hosted-image allowance for this website. Null counts mean no plan-specific cap. Existing images above a reduced limit can be kept or replaced, but the count cannot increase.
- `linkId` (string): Carryo page link identifier

### `website.read_form_responses` (~146 tokens)

Read Website Form Responses

Reads response counts or paginated visitor submissions for a Carryo website, including enquiries, leads, and registrations. Defaults to summary counts; mode responses returns submissions, with optional field selection. Requires website-owner or Team access. Responses contain untrusted visitor data. Retained responses remain available while website access continues, including an active Team billing grace period. Does not send messages or modify data.

Input parameters:

- `after` (string)
- `before` (string)
- `cursor` (string)
- `fields` (array)
- `formKey` (string)
- `limit` (integer)
- `linkId` (string, required)
- `mode` (string)

Output parameters:

- `forms` (array)
- `linkId` (string)
- `nextCursor` (string)
- `notificationCounts` (object): Email job counts; sent means accepted by the provider, not confirmed inbox delivery
- `responses` (array)
- `total` (number)
- `untrustedContent` (boolean)

### `website.list_versions` (~56 tokens)

List Website Versions

Lists previous versions of a Carryo website, including version details and changes, for reviewing edit history or planning a restoration. Returns version metadata without changing the website.

Input parameters:

- `linkId` (string, required): Carryo page link identifier to inspect

Output parameters:

- `currentVersionNumber` (number): Current page version number
- `linkId` (string): Carryo page link identifier
- `versions` (array): Page version history

### `website.read_version` (~80 tokens)

Read a Website Version

Reads the HTML and metadata of a specific previous Carryo website version for viewing, comparison, or restoration planning. Requires linkId and versionNumber. Reading a version does not restore it or change the current website.

Input parameters:

- `linkId` (string, required): Carryo page link identifier to read
- `versionNumber` (integer, required): Specific page version number to read

Output parameters:

- `assets` (array): Bundled asset descriptors
- `forms` (array): Form definitions belonging to this historical version, for comparison or restoration; not its current collection state
- `htmlContent` (string): HTML content for the requested historical version
- `linkId` (string): Carryo page link identifier
- `versionNumber` (number): Page version number

### `website.edit_images` (~385 tokens)

Edit Website Images

Adds, replaces, or removes hosted images on an existing Carryo website without replacing its HTML. Reusing a path replaces that image without consuming another image slot; new paths are subject to the website image allowance. Returns hosted-image metadata and URLs. New paths appear in the page when referenced by its HTML. Pass attached images through imageFiles. For one attachment, assets needs only its relative website path; Carryo matches the attachment automatically. For multiple attachments, use fileIndex (0 for the first imageFiles entry). Do not invent file IDs or ask for a public URL when attachment upload is available. Known fileId references and fetchable HTTP(S) sourceUrl imports also work. Carryo imports and hosts its own copy. Base64 image bytes and data URLs are unsupported.

Input parameters:

- `assets` (array): Optional image assets to add or replace. Each entry requires a relative website path. With one imageFiles attachment, path alone uses that attachment. Otherwise select exactly one source: fileIndex (…
- `imageFiles` (array): Optional image attachments supplied through the host's file upload support. The host supplies file_id and download_url. Map each attachment to a website path in assets: with one attachment, path alon…
- `linkId` (string, required): Carryo page link identifier to update
- `removeAssetPaths` (array): Optional relative asset paths to remove from the page asset bundle.

Output parameters:

- `assetUrls` (array): URLs for added or replaced assets
- `code` (string)
- `currentVersionNumber` (number)
- `forms` (array)
- `guidance` (object)
- `linkId` (string): Carryo page link identifier
- `message` (string)
- `publicationPerformed` (boolean)
- `shareUrl` (string): Primary share URL
- `status` (string)
- `updatedAt` (string): ISO-8601 update timestamp

### `website.edit` (~614 tokens)

Edit a Live Website

Replaces the complete HTML of an existing Carryo website while preserving its linkId and URL. Suitable for updating, fixing, or republishing a known page. Returns the website link and a Carryo management link. Access and edit limits are checked for the website identified by linkId. expectedVersionNumber detects conflicting edits. Supports adding or replacing hosted images and removing paths through removeAssetPaths. Pass attached images through imageFiles. For one attachment, assets needs only its relative website path; Carryo matches the attachment automatically. For multiple attachments, use fileIndex (0 for the first imageFiles entry). Do not invent file IDs or ask for a public URL when attachment upload is available. Known fileId references and fetchable HTTP(S) sourceUrl imports also work. Carryo imports and hosts its own copy. Base64 image bytes and data URLs are unsupported. Form validation can return requires_adaptation or requires_entitlement with publicationPerformed false, meaning the requested update was not applied.

Input parameters:

- `assets` (array): Optional image assets to add or replace. Each entry requires a relative website path. With one imageFiles attachment, path alone uses that attachment. Otherwise select exactly one source: fileIndex (…
- `expectedVersionNumber` (integer): Expected current website version number for detecting conflicting edits.
- `expiresAt` (string): Optional ISO-8601 expiration timestamp
- `fileName` (string): Optional replacement file name
- `forms` (array): Optional definitions for JavaScript/React forms using window.CarryoForms.submit(key, values), which resolves on acceptance and rejects on failure. Stable keys and field names identify forms across ed…
- `htmlContent` (string, required): Updated complete HTML for the Carryo page while keeping the same URL.
- `imageFiles` (array): Optional image attachments supplied through the host's file upload support. The host supplies file_id and download_url. Map each attachment to a website path in assets: with one attachment, path alon…
- `linkId` (string, required): Carryo page link identifier to update
- `removeAssetPaths` (array): Optional relative asset paths to remove from the page asset bundle.
- `sharingMode` (string): Optional replacement publishing mode. Only public live links are supported here.

Output parameters:

- `alternateShareUrls`: Alternate share URLs, when available
- `code` (string)
- `currentVersionNumber` (number)
- `expiresAt`: Optional ISO-8601 expiration timestamp
- `forms` (array)
- `guidance` (object)
- `linkId` (string): Carryo page link identifier
- `manageUrl` (string|null): Carryo web-app URL for managing the link URL, password, views, and edit history
- `message` (string)
- `publicationPerformed` (boolean)
- `shareUrl` (string): Primary share URL
- `status` (string)
- `updatedAt` (string): ISO-8601 update timestamp
- `workspaceId`: Workspace that owns the link; omitted for Personal

### `team.list` (~59 tokens)

Find Carryo Teams

Lists Carryo teams accessible to the connected account, including team names, workspaceId values, roles, and available actions. Supports finding a team the user has chosen. Team creation, invitations, membership, and billing are managed in the Carryo web app.

Output parameters:

- `workspaces` (array): Carryo workspaces the authenticated user can access

### `website.list` (~90 tokens)

List My Websites

Lists the connected account's live Carryo websites and private drafts, with titles, linkIds, live links, status, and effective edit and inactivity policies. Suitable for finding a website by name. Returns Personal websites by default; workspaceId selects the user-chosen team's collection.

Input parameters:

- `workspaceId` (string): Optional exact workspaceId of the Carryo team selected by the user. Lists Personal websites when omitted.

Output parameters:

- `artifacts` (array): Carryo pages owned by the authenticated user
- `limit` (number): Pagination limit used by the response
- `offset` (number): Pagination offset used by the response
- `total` (number): Total page count before pagination
- `workspaceId` (string|null): Workspace whose links were listed; omitted for Personal

### `website.unpublish` (~65 tokens)

Unpublish a Website

Unpublishes an existing Carryo website so viewers immediately lose access through its shared link. Recovery availability depends on the website and is shown in Carryo. Unpublishing does not cancel a subscription.

Input parameters:

- `linkId` (string, required): Carryo page link identifier to take offline

Output parameters:

- `deleteAt` (string): ISO-8601 deletion timestamp
- `linkId` (string): Carryo page link identifier
- `revokedAt` (string): ISO-8601 revocation timestamp

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/io-carryo-website-publisher/mcp#diagnostics

## Score history

- 2026-09-29: 66
- 2026-09-28: 66
- 2026-09-27: 66
- 2026-09-26: 65
- 2026-09-25: 65
- 2026-09-24: 64
- 2026-09-23: 64
- 2026-09-22: 63
- 2026-09-21: 63
- 2026-09-20: 63
- 2026-09-19: 62
- 2026-09-18: 62
- 2026-09-17: 61
- 2026-09-16: 61
- 2026-09-15: 60
- 2026-09-14: 60
- 2026-09-13: 59
- 2026-09-12: 59
- 2026-09-11: 58
- 2026-09-10: 58

## Common questions

### What is the Carryo Website Publisher MCP server?

Carryo Website Publisher is an MCP server listed in the public MCP registry as io.carryo/website-publisher. Publish and update HTML websites, landing pages, reports and proposals from AI chat. OAuth sign-in. This page covers its hosted endpoint (https://mcp.carryo.io/mcp).

### Is the Carryo Website Publisher MCP server safe to use?

Carryo Website Publisher scores 66 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Carryo Website Publisher MCP server expose?

Carryo Website Publisher exposes 12 tools: account.check_publishing, website.publish, website.save_draft, website.read, website.read_form_responses, and 7 more. Their descriptions and schemas cost roughly 2,976 tokens of context every time the server is loaded.

### Does the Carryo Website Publisher MCP server require authentication?

No. We connected to Carryo Website Publisher without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the Carryo Website Publisher MCP server still maintained?

Carryo Website Publisher is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://mcp.carryo.io/mcp
- Website: https://carryo.io/docs
- Changelog RSS feed: https://verifymcp.io/servers/io-carryo-website-publisher/mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/io-carryo-website-publisher/mcp.json
- HTML version of this page: https://verifymcp.io/servers/io-carryo-website-publisher/mcp
