BetaFinds
REMOTE · BETAFINDS.COM · SCANNED SEP 20
Publish and update your startup on BetaFinds from an AI agent — listings, changelog, releases.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security94
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents. View diagnostics → Partial
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability74
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1864 tokens (~133/item across 14 items; 14 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 15 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
- Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
How do I install the BetaFinds MCP server?
BetaFinds is a hosted endpoint at https://betafinds.com/api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · betafinds.com
claude mcp add --transport http pendurov-betafinds-mcp 'https://betafinds.com/api/mcp'
{
"mcpServers": {
"pendurov-betafinds-mcp": {
"url": "https://betafinds.com/api/mcp"
}
}
} {
"servers": {
"pendurov-betafinds-mcp": {
"type": "http",
"url": "https://betafinds.com/api/mcp"
}
}
} [mcp_servers.pendurov-betafinds-mcp] url = "https://betafinds.com/api/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"pendurov-betafinds-mcp": {
"type": "remote",
"url": "https://betafinds.com/api/mcp",
"enabled": true
}
}
} openclaw mcp add pendurov-betafinds-mcp --url 'https://betafinds.com/api/mcp' --transport streamable-http
mcp_servers:
pendurov-betafinds-mcp:
url: "https://betafinds.com/api/mcp" {
"McpServers": {
"pendurov-betafinds-mcp": {
"Transport": "http",
"Url": "https://betafinds.com/api/mcp"
}
}
} assistant mcp add pendurov-betafinds-mcp -t streamable-http -u 'https://betafinds.com/api/mcp'
{
"mcpServers": {
"pendurov-betafinds-mcp": {
"type": "http",
"url": "https://betafinds.com/api/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 26 Aug 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 0
- Stability: 0.97 → pass security
- 24 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 31 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 0
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://betafinds.com/api/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=betafinds.com | CN=YE2,O=Let's Encrypt,C=US | 13 Sept 2026 | 12 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 6cb662901d759d2b29de5f0118247af9c49 |
| SANs: betafinds.com, buildbeat.co, downloads.betafinds.com, www.betafinds.com, www.buildbeat.co | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of betafinds.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| betafinds.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer resource_metadata="https://betafinds.com/.well-known/oauth-protected-resource"
Bearer resource_metadata="https://betafinds.com/.well-known/oauth-protected-resource" | Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains; preload |
| x-content-type-options | nosniff |
| x-frame-options | SAMEORIGIN |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(), geolocation=() |
Protected resource metadata
| Document | https://betafinds.com/.well-known/oauth-protected-resource |
|---|---|
| Retrieved | Yes |
| Resource | https://betafinds.com/api/mcp |
| Authorisation server | https://betafinds.com |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://betafinds.com/api/mcp | Verified | 200 | |
| http (plaintext) | http://betafinds.com/api/mcp | HTTPS enforced | 301 | https://betafinds.com:443/api/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
announce_launch ~136
Announce your startup's official launch: the stage becomes LAUNCHED, a LAUNCH update is published, and waitlist members are notified (once). A working product link is required (url or an already saved store link).
| Name | Type | Req | Description |
|---|---|---|---|
| body | string | yes | Description of the first public version, Markdown (10–20000 characters) |
| notify_waitlist | boolean | – | Notify the waitlist (default true) |
| startup_slug | string | yes | Startup slug (from list_my_startups) |
| title | string | yes | Launch headline (3–200 characters) |
| url | string | – | Working product link (if not set yet) |
| Name | Type | Req | Description |
|---|---|---|---|
| firstLaunch | boolean | – | – |
| message | string | – | – |
| slug | string | – | – |
| stage | string | – | – |
No examples provided.
change_startup_stage ~126
Change your startup's product stage: PRELAUNCH — preparing to launch, BETA — recruiting beta testers, PAUSED — development paused (requires public_note). To move to LAUNCHED use announce_launch. Allowed transitions: PRELAUNCH→BETA/PAUSED, BETA→PAUSED, PAUSED→PRELAUNCH/BETA.
| Name | Type | Req | Description |
|---|---|---|---|
| public_note | string | – | Public note (required for PAUSED, up to 500 characters) |
| stage | string | yes | New stage |
| startup_slug | string | yes | Startup slug (from list_my_startups) |
| Name | Type | Req | Description |
|---|---|---|---|
| message | string | – | – |
| slug | string | – | – |
| stage | string | – | – |
No examples provided.
complete_asset_upload ~49
Confirm that the release file has been uploaded. Verifies the file's presence and size in storage and makes it available for download.
| Name | Type | Req | Description |
|---|---|---|---|
| asset_id | string | yes | File ID from request_asset_upload |
| Name | Type | Req | Description |
|---|---|---|---|
| downloadUrl | string | – | – |
No examples provided.
create_release ~98
Create a release (version) of your startup. By default also publishes a RELEASE-type update with the notes text. After creation, upload files via request_asset_upload.
| Name | Type | Req | Description |
|---|---|---|---|
| announce | boolean | – | Whether to publish an update in the feed (default true) |
| notes | string | – | Release notes in Markdown |
| startup_slug | string | yes | Startup slug |
| version | string | yes | Version, e.g. 1.4.0 |
| Name | Type | Req | Description |
|---|---|---|---|
| message | string | – | – |
| release_id | string | – | – |
| version | string | – | – |
No examples provided.
create_startup ~383
Create a new startup on BetaFinds (submitted for review). Upload the logo and screenshots first via upload_image (or POST https://betafinds.com/api/v1/images) and pass the returned URLs here. Set the category by slug — get the list via list_categories (a category name also works, case-insensitive).
| Name | Type | Req | Description |
|---|---|---|---|
| appStoreUrl | string | – | App Store page link (iOS) |
| category_slug | string | – | Category slug (e.g. ai, saas, fintech) |
| description | string | yes | Full description (min 50 characters) |
| googlePlayUrl | string | – | Google Play page link (Android) |
| logo | string | – | Logo URL from upload_image (optional) |
| name | string | yes | Product name |
| prelaunch_audience | string | – | Who the product is for (up to 1000 characters) |
| prelaunch_promise | string | – | What a waitlist subscriber will get (up to 1000 characters) |
| prelaunch_ready | string | – | What is already done: prototype, design, private beta… (up to 1000 characters) |
| screenshots | array | – | Screenshot URLs from upload_image (up to 5, optional) |
| stage | string | – | Product stage: PRELAUNCH — preparing to launch, BETA — recruiting beta testers, LAUNCHED — already launched (default) |
| tagline | string | yes | One-line tagline (up to 160 characters) |
| tags | array | – | Tags (up to 6) |
| target_launch_date | string | – | Estimated launch date in YYYY-MM-DD format (for prelaunch; empty string clears it) |
| testflightUrl | string | – | TestFlight link (iOS beta) |
| url | string | – | Product website URL (required for stage=LAUNCHED, optional for prelaunch) |
| Name | Type | Req | Description |
|---|---|---|---|
| message | string | – | – |
| slug | string | – | – |
| status | string | – | – |
| url | string | – | – |
No examples provided.
get_releases ~80
Список опубликованных релизов стартапа с файлами. Для LAUNCHED-проектов downloadUrl — постоянная прямая ссылка. На закрытых стадиях ссылка возвращается только для своих стартапов или где у вас открыт доступ (иначе locked=true, downloadUrl=null).
| Name | Type | Req | Description |
|---|---|---|---|
| startup_slug | string | yes | Startup slug |
| Name | Type | Req | Description |
|---|---|---|---|
| items | array | yes | – |
No examples provided.
get_store_reviews ~77
Public Google Play and App Store reviews of your startup: monitoring state per store and the latest reviews (rating, text, developer response). Reviews are collected automatically via the app links.
| Name | Type | Req | Description |
|---|---|---|---|
| page | number | – | Page (20 reviews each, default 1) |
| startup_slug | string | yes | Startup slug (from list_my_startups) |
| Name | Type | Req | Description |
|---|---|---|---|
| monitors | array | – | – |
| reviews | array | – | – |
| slug | string | – | – |
| total | number | – | – |
No examples provided.
get_waitlist ~73
Waitlist summary for your startup: aggregated counters (active, per week/month, ready to test, invited/accepted), answer distribution for the question, recent anonymized answers and campaigns with aggregated statistics. Participants' contact details are not returned.
| Name | Type | Req | Description |
|---|---|---|---|
| startup_slug | string | yes | Startup slug (from list_my_startups) |
| Name | Type | Req | Description |
|---|---|---|---|
| campaigns | array | – | – |
| question | object | – | – |
| slug | string | – | – |
| stage | string | – | – |
| waitlist | object | – | – |
No examples provided.
list_categories ~22
List of available categories (slug and name) for create_startup.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| items | array | yes | – |
No examples provided.
list_my_startups ~37
List of your startups on BetaFinds (slug, name, status). Updates can only be published for startups with APPROVED status.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| items | array | yes | – |
No examples provided.
publish_update ~136
Publish an update (an entry in the «What's new» feed) for your startup. Subscribers receive an email summary within ~10 minutes. body supports Markdown.
| Name | Type | Req | Description |
|---|---|---|---|
| body | string | yes | Text in Markdown (10–20000 characters) |
| startup_slug | string | yes | Startup slug (from list_my_startups) |
| title | string | yes | Update title (3–200 characters) |
| type | string | – | Type: RELEASE — new version, UPDATE — improvement, FIX — fix, NEWS — news. Defaults to NEWS. |
| version | string | – | Version, if applicable (e.g. 1.4.0) |
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | – | – |
| message | string | – | – |
| publishedAt | string | – | – |
No examples provided.
request_asset_upload ~130
Get a one-time link to upload a release file (Windows/Mac/Android/Linux, up to 1 GB). Then upload the file: curl -T <file> '<upload_url>'. After uploading, call complete_asset_upload.
| Name | Type | Req | Description |
|---|---|---|---|
| filename | string | yes | File name, e.g. MyApp-1.4.0.dmg |
| platform | string | yes | File platform |
| release_id | string | yes | Release ID from create_release |
| sha256 | string | – | File SHA-256 (hex, optional) |
| size | number | yes | File size in bytes (exact) |
| Name | Type | Req | Description |
|---|---|---|---|
| assetId | string | – | – |
| downloadUrl | string | – | – |
| instructions | string | – | – |
| uploadUrl | string | – | – |
No examples provided.
update_startup ~365
Update an existing startup: app-store links, website, short/full description, tags, category, logo and screenshots. Upload the logo and screenshots first via upload_image and pass the returned URLs (screenshots fully replace the current set; to clear the logo, pass an empty string). Pass only the fields you want to change. See current values via list_my_startups. Note: editing an approved startup sends it back to moderation.
| Name | Type | Req | Description |
|---|---|---|---|
| appStoreUrl | string | – | App Store page link (iOS) |
| category_slug | string | – | Category slug (see list_categories) |
| description | string | – | Full description (min 50 characters) |
| googlePlayUrl | string | – | Google Play page link (Android) |
| logo | string | – | Logo URL from upload_image (empty string to clear) |
| prelaunch_audience | string | – | Who the product is for (up to 1000 characters) |
| prelaunch_promise | string | – | What a waitlist subscriber will get (up to 1000 characters) |
| prelaunch_ready | string | – | What is already done: prototype, design, private beta… (up to 1000 characters) |
| screenshots | array | – | Screenshot URLs from upload_image (up to 5; fully replace the current set) |
| startup_slug | string | yes | Startup slug (from list_my_startups) |
| tagline | string | – | One-line tagline (up to 160 characters) |
| tags | array | – | Tags (up to 6) |
| target_launch_date | string | – | Estimated launch date in YYYY-MM-DD format (for prelaunch; empty string clears it) |
| testflightUrl | string | – | TestFlight link (iOS beta) |
| url | string | – | Product website URL |
| Name | Type | Req | Description |
|---|---|---|---|
| message | string | – | – |
| slug | string | – | – |
| status | string | – | – |
| url | string | – | – |
No examples provided.
upload_image ~113
Upload an image (logo or screenshot) for create_startup. Pass the file content as base64 (data is base64 only, no data: prefix). Returns a url to pass into create_startup. Max 2 MB; formats: JPEG, PNG, WebP, GIF.
| Name | Type | Req | Description |
|---|---|---|---|
| data | string | yes | File content in base64 |
| filename | string | – | File name (optional) |
| mime_type | string | yes | MIME type: image/png, image/jpeg, image/webp, image/gif |
| Name | Type | Req | Description |
|---|---|---|---|
| path | string | – | – |
| url | string | – | – |
No examples provided.
What is the BetaFinds MCP server?
BetaFinds is an MCP server listed in the public MCP registry as io.github.pendurov/betafinds-mcp. Publish and update your startup on BetaFinds from an AI agent, listings, changelog, releases. This page covers its hosted endpoint (https://betafinds.com/api/mcp).
Is the BetaFinds MCP server safe to use?
BetaFinds scores 91 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the BetaFinds MCP server expose?
BetaFinds exposes 14 tools: create_startup, update_startup, list_categories, upload_image, list_my_startups, and 9 more. Their descriptions and schemas cost roughly 1,825 tokens of context every time the server is loaded.
Does the BetaFinds MCP server require authentication?
Yes. BetaFinds asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the BetaFinds MCP server still maintained?
BetaFinds is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.