# io.usefulapi/updown-io (remote · updown-io.usefulapi.io)

Check updown.io uptime checks, downtimes, response metrics and status pages, and create checks.

- Trust score: 76/100 (medium)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-04

## Components

- remote · `updown-io.usefulapi.io`: 76/100 (this document), [markdown](https://verifymcp.io/servers/io-usefulapi-updown-io/updown-io.md), [page](https://verifymcp.io/servers/io-usefulapi-updown-io/updown-io)

## Channel facts

- Endpoint: `https://updown-io.usefulapi.io/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.0.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-04.

- **Endpoint Security**: 89/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token.
  - HTTPS is enforced; there's no plaintext access path.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
  - The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 72/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 2441 tokens (~174/item across 14 items; 14 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 7/100
  - Stability observed for 2 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 14 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 14 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 60/100
  - Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28.

## Install

### How do I install the io.usefulapi/updown-io MCP server?

io.usefulapi/updown-io is a hosted endpoint at https://updown-io.usefulapi.io/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http io-usefulapi-updown-io 'https://updown-io.usefulapi.io/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "io-usefulapi-updown-io": {
      "url": "https://updown-io.usefulapi.io/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "io-usefulapi-updown-io": {
      "type": "http",
      "url": "https://updown-io.usefulapi.io/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.io-usefulapi-updown-io]
url = "https://updown-io.usefulapi.io/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "io-usefulapi-updown-io": {
      "type": "remote",
      "url": "https://updown-io.usefulapi.io/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add io-usefulapi-updown-io --url 'https://updown-io.usefulapi.io/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  io-usefulapi-updown-io:
    url: "https://updown-io.usefulapi.io/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "io-usefulapi-updown-io": {
      "Transport": "http",
      "Url": "https://updown-io.usefulapi.io/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add io-usefulapi-updown-io -t streamable-http -u 'https://updown-io.usefulapi.io/mcp'
```

### Other

```json
{
  "mcpServers": {
    "io-usefulapi-updown-io": {
      "type": "http",
      "url": "https://updown-io.usefulapi.io/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-10-04 (score 76, +1)

No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-10-03 (score 75, 0)

- [functional improvement] Stability: unverified → 0.03

### 2026-10-02 (score 75, +42)

- [security improvement] Authorization: unverified → pass
- [security improvement] Injection markers: unverified → pass
- [security] First check of Judged manipulation: pass
- [security] First check of Authorization: partial
- [functional regression] MCP protocol: unverified → fail
- [functional improvement] Tool coverage: unverified → 100
- [functional] First check of Schema quality: fail
- [functional] First check of Schema quality: excellent
- [functional] First check of Destructive annotations: pass
- [functional] First check of Schema quality: fail
- [functional] First check of Tool coverage: 100

### 2026-10-01 (score 33, +15)

- [security improvement] HTTPS: unverified → pass
- [security improvement] Transport: fail → pass
- [security] Authorization: Authorisation not fully verified: no authorisation is required to connect, but we couldn't read the whole tool list to see what that exposes.
- [security] Tool safety: Tool safety blocked by authentication: the endpoint requires auth we don't have to read its tools.
- [functional] Tool coverage: Tool coverage blocked by authentication: the endpoint requires auth we don't have to read its tools.
- [functional] Schema quality: Schema blocked by authentication: the endpoint requires auth we don't have to read it.
- [functional] Capabilities: Capabilities blocked by authentication: the endpoint requires auth we don't have to read them.

### 2026-09-29 (score 18)

First indexed and scored.

## MCP tools (14)

### `updown_list_checks` (~99 tokens)

List checks

List all monitoring checks on the account with their status (down, uptime, last_status, error), period, SSL certificate and domain-expiry info. Optionally filter client-side by status or a text match on URL/alias. updown: GET /api/checks.

Input parameters:

- `search` (string): Case-insensitive substring to match against the check URL or alias.
- `status` (string): Only checks in this state (default all).

### `updown_get_check` (~106 tokens)

Get one check

Fetch a single check by token, optionally with the last hour of performance metrics and/or the detailed results of the last 5 requests. updown: GET /api/checks/:token.

Input parameters:

- `metrics` (boolean): Include performance metrics for the last hour.
- `results` (boolean): Include detailed results of the last 5 requests (can be large).
- `token` (string, required): The check's unique token, e.g. ngg8 (from updown_list_checks).

### `updown_list_downtimes` (~128 tokens)

List a check's downtimes

List the downtimes of one check, newest first, 100 per page: error, started_at, ended_at, duration (seconds) and a details URL. updown: GET /api/checks/:token/downtimes.

Input parameters:

- `page` (integer): Page to fetch (100 per page, default 1).
- `results` (boolean): Include detailed results (last 5 requests before the downtime and recovery). Can be large.
- `token` (string, required): The check's unique token, e.g. ngg8 (from updown_list_checks).

### `updown_get_check_metrics` (~210 tokens)

Get a check's metrics

Get aggregated metrics for one check over a time range: uptime, apdex, timings (redirect/namelookup/connection/handshake/response/total, ms) and request counts by response time. Optionally group by 'time' or by 'host' (monitoring location). Data is hourly (daily after 2 days, monthly after 40 days); the range must span at least one hour. Uptime is not returned when grouping. updown: GET /api/checks/:token/metrics.

Input parameters:

- `from` (string): Start time (ISO8601, RFC2822 or YYYY-MM-DD; UTC if no zone). Default: 1 month ago.
- `group` (string): Group results by 'time' or by 'host' (location).
- `to` (string): End time, same formats. Default: now.
- `token` (string, required): The check's unique token, e.g. ngg8 (from updown_list_checks).

### `updown_find_problems` (~101 tokens)

Find checks with problems

One-call health overview across every check: which are DOWN (since when, error), which have an invalid SSL certificate, which certificates or domains expire within N days, and which checks are paused or muted. Built from GET /api/checks.

Input parameters:

- `domain_days` (integer): Flag domains expiring within this many days (default 30).
- `ssl_days` (integer): Flag SSL certificates expiring within this many days (default 14).

### `updown_list_recipients` (~71 tokens)

List alert recipients

List the alert recipients/channels on the account (email, sms, slack, telegram, webhook, zapier, ...). The `id` (e.g. email:3719031852) is what check `recipients` take. updown: GET /api/recipients.

### `updown_list_status_pages` (~50 tokens)

List status pages

List the account's status pages: token, public URL, name, description, visibility (public/protected/private) and the ordered check tokens shown. updown: GET /api/status_pages.

### `updown_list_nodes` (~74 tokens)

List monitoring nodes

List updown.io's monitoring/webhook servers keyed by location code (lan, mia, tor, rbx, fra, cap, hel, sin, tok, syd) with IPv4, IPv6, city, country and coordinates. Public — no API key needed. updown: GET /api/nodes.

### `updown_list_node_ips` (~87 tokens)

List monitoring node IPs

List updown.io's server IP addresses — e.g. to allowlist the monitors in a firewall. Choose all, ipv4 or ipv6. Public — no API key needed. updown: GET /api/nodes/ips, /api/nodes/ipv4, /api/nodes/ipv6.

Input parameters:

- `family` (string): Address family (default all).

### `updown_create_check` (~514 tokens)

Create a check

Add a new monitoring check. The type (http, https, tcp, tcps, icmp) is inferred from the URL scheme; pass type 'pulse' (and no URL) for a cron/heartbeat check. Each check consumes updown credits while enabled. Requires the read/write API key. updown: POST /api/checks.

Input parameters:

- `alias` (string): Human-readable name for the check.
- `apdex_t` (number): APDEX threshold in seconds: 0.125, 0.25, 0.5, 1.0, 2.0, 4.0 or 8.0 (default 0.5).
- `custom_headers` (object): HTTP headers updown sends with each request, e.g. { "X-Api-Key": "..." }.
- `disabled_locations` (array): Monitoring locations to disable: lan, mia, tor, rbx, fra, cap, hel, sin, tok, syd.
- `enabled` (boolean): Whether the check runs. false pauses it (reversible).
- `http_body` (string): HTTP body sent with the request.
- `http_verb` (string): HTTP verb for the request (default GET/HEAD).
- `mute_until` (string): Mute notifications until a time (ISO8601, e.g. 2026-10-01T08:00:00Z), or 'recovery', or 'forever'.
- `period` (integer): Interval in seconds. Regular checks: 15, 30, 60, 120, 300, 600, 1800 or 3600 (default 60). Pulse checks: anywhere from 15 s to 1 month.
- `published` (boolean): Whether the check's public status page is visible (default false).
- `recipients` (array): Alert recipient ids to select, e.g. ['email:12345', 'sms:67890'] (from updown_list_recipients).
- `string_match` (string): Text that must appear in the response. For TCP/TCPS checks, '<closed>' inverts the check (alert if the port is open).
- `type` (string): Check type; inferred from the URL by default — mainly useful for 'pulse'.
- `url` (string): The URL to monitor, e.g. https://example.com, tcp://host:port, icmp://host. Omit for pulse checks.

### `updown_update_check` (~514 tokens)

Update a check

Change a check's settings — URL, period, alias, string match, recipients, headers, locations — or pause/resume it (enabled) or mute its alerts (mute_until). Only the fields you pass are changed. Caution: URLs returned by a read-only key hide basic-auth credentials; re-sending such a URL erases them. Requires the read/write API key. updown: PUT /api/checks/:token.

Input parameters:

- `alias` (string): Human-readable name for the check.
- `apdex_t` (number): APDEX threshold in seconds: 0.125, 0.25, 0.5, 1.0, 2.0, 4.0 or 8.0 (default 0.5).
- `custom_headers` (object): HTTP headers updown sends with each request, e.g. { "X-Api-Key": "..." }.
- `disabled_locations` (array): Monitoring locations to disable: lan, mia, tor, rbx, fra, cap, hel, sin, tok, syd.
- `enabled` (boolean): Whether the check runs. false pauses it (reversible).
- `http_body` (string): HTTP body sent with the request.
- `http_verb` (string): HTTP verb for the request (default GET/HEAD).
- `mute_until` (string): Mute notifications until a time (ISO8601, e.g. 2026-10-01T08:00:00Z), or 'recovery', or 'forever'.
- `period` (integer): Interval in seconds. Regular checks: 15, 30, 60, 120, 300, 600, 1800 or 3600 (default 60). Pulse checks: anywhere from 15 s to 1 month.
- `published` (boolean): Whether the check's public status page is visible (default false).
- `recipients` (array): Alert recipient ids to select, e.g. ['email:12345', 'sms:67890'] (from updown_list_recipients).
- `string_match` (string): Text that must appear in the response. For TCP/TCPS checks, '<closed>' inverts the check (alert if the port is open).
- `token` (string, required): The check's unique token, e.g. ngg8 (from updown_list_checks).
- `url` (string): New URL to monitor (not for pulse checks).

### `updown_add_recipient` (~175 tokens)

Add an alert recipient

Add an alert recipient: an email address, phone number (sms), webhook URL, Slack-compatible incoming-webhook URL, or Microsoft Teams webhook URL. Returns the new (or already-existing) recipient with its id. By default it is selected on ALL existing checks; pass selected=false to add it unattached. Slack/Telegram/Zapier/Statuspage integrations must be set up in the web UI. Requires the read/write API key. updown: POST /api/recipients.

Input parameters:

- `name` (string): Optional friendly label (webhooks only at the moment).
- `selected` (boolean): true (default) = selected on all existing checks; false = not selected on any check.
- `type` (string, required): Recipient type.
- `value` (string, required): The email address, phone number or URL.

### `updown_create_status_page` (~137 tokens)

Create a status page

Create a status page showing the given checks, in order. Returns its token and URL. Requires the read/write API key. updown: POST /api/status_pages.

Input parameters:

- `access_key` (string): Access key for protected pages (defaults to a random 30-byte string).
- `checks` (array, required): Check tokens to show, in display order, e.g. ['dmbe', 'ngg8'].
- `description` (string): Text displayed below the name (supports newlines and links).
- `name` (string): Name of the status page.
- `visibility` (string): Page visibility (default public).

### `updown_update_status_page` (~175 tokens)

Update a status page

Change a status page's checks (replaces the list, order respected), name, description, visibility or access key. Only the fields you pass are changed. Requires the read/write API key. updown: PUT /api/status_pages/:token.

Input parameters:

- `access_key` (string): Access key for protected pages (defaults to a random 30-byte string).
- `checks` (array): New ordered list of check tokens to show (replaces the current list).
- `description` (string): Text displayed below the name (supports newlines and links).
- `name` (string): Name of the status page.
- `token` (string, required): The status page's unique token, e.g. 3ji4k (from updown_list_status_pages).
- `visibility` (string): Page visibility (default public).

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/io-usefulapi-updown-io/updown-io#diagnostics

## Score history

- 2026-10-04: 76
- 2026-10-03: 75
- 2026-10-02: 75
- 2026-10-01: 33
- 2026-09-30: 18
- 2026-09-29: 18

## Common questions

### What is the io.usefulapi/updown-io MCP server?

io.usefulapi/updown-io is an MCP server listed in the public MCP registry as io.usefulapi/updown-io. Check updown.io uptime checks, downtimes, response metrics and status pages, and create checks. This page covers its hosted endpoint (https://updown-io.usefulapi.io/mcp).

### Is the io.usefulapi/updown-io MCP server safe to use?

io.usefulapi/updown-io scores 76 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the io.usefulapi/updown-io MCP server expose?

io.usefulapi/updown-io exposes 14 tools: updown_list_checks, updown_get_check, updown_list_downtimes, updown_get_check_metrics, updown_find_problems, and 9 more. Their descriptions and schemas cost roughly 2,441 tokens of context every time the server is loaded.

### Does the io.usefulapi/updown-io MCP server require authentication?

Yes. io.usefulapi/updown-io asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

### Is the io.usefulapi/updown-io MCP server still maintained?

io.usefulapi/updown-io is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://updown-io.usefulapi.io/mcp
- Repository: https://github.com/m190/usefulapi-mcp
- Changelog RSS feed: https://verifymcp.io/servers/io-usefulapi-updown-io/updown-io.xml
- Changelog JSON feed: https://verifymcp.io/servers/io-usefulapi-updown-io/updown-io.json
- HTML version of this page: https://verifymcp.io/servers/io-usefulapi-updown-io/updown-io
