# MCP Marketplace (remote · mcp-marketplace.io)

Search and install 4,000+ security-scanned MCP servers from inside any MCP-aware AI client.

- Trust score: 69/100 (medium)
- Change this week: +4
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- remote · `mcp-marketplace.io`: 69/100 (this document), [markdown](https://verifymcp.io/servers/io-mcp-marketplace-search/api-mcp-mcp.md), [page](https://verifymcp.io/servers/io-mcp-marketplace-search/api-mcp-mcp)

## Channel facts

- Endpoint: `https://mcp-marketplace.io/api/mcp/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.0.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Endpoint Security**: 63/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation not fully verified: no authorisation is required to call this server, and 7 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe.
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 73/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 1136 tokens (~162/item across 7 items; 7 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 27/100
  - Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### Claude

```bash
claude mcp add --transport http io-mcp-marketplace-search https://mcp-marketplace.io/api/mcp/mcp
```

### Codex

```toml
[mcp_servers.io-mcp-marketplace-search]
url = "https://mcp-marketplace.io/api/mcp/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "io-mcp-marketplace-search": {
      "type": "remote",
      "url": "https://mcp-marketplace.io/api/mcp/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add io-mcp-marketplace-search --url https://mcp-marketplace.io/api/mcp/mcp --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  io-mcp-marketplace-search:
    url: "https://mcp-marketplace.io/api/mcp/mcp"
```

### Other

```json
{
  "mcpServers": {
    "io-mcp-marketplace-search": {
      "type": "http",
      "url": "https://mcp-marketplace.io/api/mcp/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-03 (score 69, +1)

No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-08-01 (score 68, +1)

No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-07-31 (score 67, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-30 (score 67, +1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-29 (score 66, +1)

No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-07-27 (score 65, +1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-26 (score 64)

First indexed and scored.

## MCP tools (7)

### `search_servers` (~356 tokens)

Search the MCP Marketplace catalog. With a free-text `query` and default `sort`, results are ranked by semantic similarity (gte-small embeddings + cosine similarity), so natural-language queries like 'manage my calendar', 'something to read PDFs', or 'database for my agent' work as well as keyword searches. Each result includes `security_score` (0-10), `risk_level` (low/moderate/high/critical), `critical_findings` (count of severity=critical|high findings), pricing, rating, install count, and a URL. `ranking_mode` in the response indicates whether semantic or keyword matching was used. Before recommending an install, call get_server for full details including every flagged finding — critical_findings > 0 means the server has known security issues you must surface to the user.

Input parameters:

- `category` (string): Category slug filter. Call list_categories to see valid slugs.
- `free_only` (boolean): If true, exclude paid servers.
- `limit` (integer): Max results per page (1-25). Default 10.
- `page` (integer): 1-indexed page number. Combine with `limit` to paginate past the first window. Defaults to 1.
- `query` (string): Free-text search across name, tagline, description, tags, and MCP tool names.
- `sort` (string): Ranking order. Defaults to 'relevance' when query is set, else 'installs'.
- `transport` (string): Filter by transport. 'stdio' = local (npm/pip); 'streamable-http' = hosted remote. SSE is not exposed because the catalog doesn't distinguish SSE from streamable-HTTP and filtering on it would always…

### `get_server` (~128 tokens)

Fetch full details for a single MCP server by its slug. Returns description, install commands, security score/risk/findings, ratings, creator info, setup requirements (API keys/credentials the user will need), and the list of MCP tools the server exposes. The `security.critical_findings` array lists every severity=critical|high issue — you MUST show these to the user before recommending they install. Use this as the last step before any install recommendation.

Input parameters:

- `slug` (string, required): Server slug (from search_servers results or the URL: mcp-marketplace.io/server/{slug}).

### `similar_to` (~178 tokens)

Find MCP servers that are semantically similar to a reference server. Use when a user picked a candidate but wants alternatives — e.g. 'like this but safer', 'like this but free', 'what else does this'. Reuses the catalog's gte-small embeddings: the reference server's embedding is the query vector. Returns servers sorted by cosine similarity (highest first), excluding the reference itself. Each result carries the same security/risk/pricing fields as search_servers so callers can immediately compare on `security_score`, `has_critical_findings`, and pricing.

Input parameters:

- `free_only` (boolean): If true, exclude paid servers from the comparison set.
- `limit` (integer): Max similar servers to return (1-10). Default 5.
- `slug` (string, required): Reference server slug (the one you want similar alternatives to).

### `recently_added` (~125 tokens)

List the most recently added MCP servers. Use for discovery: 'what's new', 'latest servers', 'servers from this week'. Optionally constrain to the last N days. Ordered by creation date descending. Each result carries the same security/risk/pricing fields as search_servers.

Input parameters:

- `days` (integer): Only include servers created within the last N days (1-365). Omit for no date bound.
- `free_only` (boolean): If true, exclude paid servers.
- `limit` (integer): Max servers to return (1-25). Default 10.

### `creator_profile` (~121 tokens)

List all MCP servers by a single creator, plus aggregate trust signals. Use to evaluate a publisher holistically: 'do they ship consistently?', 'what's their security track record?', 'are there other servers by the same author?'. Match is case-insensitive on display name. Returns aggregate stats (total servers, avg security score, grade distribution, critical-finding count) plus the per-server list.

Input parameters:

- `creator` (string, required): Creator display name (case-insensitive) OR GitHub username. From a search_servers result, use the `creator` field.

### `compare` (~103 tokens)

Compare 2-5 MCP servers side by side on the fields users actually decide on: security score, critical findings, pricing, transport mode, tool count, and install command availability. Use when a user is choosing between candidates from a search. Returns a structured comparison table plus a short per-field summary, so the agent can surface the important contrasts without a second pass over each server.

Input parameters:

- `slugs` (array, required): Array of 2-5 server slugs to compare.

### `list_categories` (~41 tokens)

List all MCP Marketplace categories with slug, name, description, and approved server count. Use the returned `slug` as the `category` filter in search_servers.

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/io-mcp-marketplace-search/api-mcp-mcp#diagnostics

## Score history

- 2026-08-03: 69
- 2026-08-02: 68
- 2026-08-01: 68
- 2026-07-31: 67
- 2026-07-30: 67
- 2026-07-29: 66
- 2026-07-28: 65
- 2026-07-27: 65
- 2026-07-26: 64

## Links

- Remote endpoint: https://mcp-marketplace.io/api/mcp/mcp
- Repository: https://github.com/gmoneyn/mcp-marketplace
- Website: https://mcp-marketplace.io/
- Changelog RSS feed: https://verifymcp.io/servers/io-mcp-marketplace-search/api-mcp-mcp/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/io-mcp-marketplace-search/api-mcp-mcp/changelog.json
- HTML version of this page: https://verifymcp.io/servers/io-mcp-marketplace-search/api-mcp-mcp
