Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Pushary

REMOTE · PUSHARY.COM · 2 COMPONENTS · SCANNED SEP 20

Reach a human from a running agent. Approvals on the lock screen, plus a cross-agent audit trail.

0 this week 93 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security94
Transport & Reachability100
Schema Quality & AI Usability77
  • 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 3387 tokens (~338/item across 10 items; 5 tools + 5 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
  • No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • An AI judge read all 7 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

How do I install the Pushary MCP server?

Pushary is a hosted endpoint at https://pushary.com/api/mcp/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · pushary.com

# add to Claude Code
claude mcp add --transport http pushary-pushary 'https://pushary.com/api/mcp/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "pushary-pushary": {
      "url": "https://pushary.com/api/mcp/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "pushary-pushary": {
      "type": "http",
      "url": "https://pushary.com/api/mcp/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.pushary-pushary]
url = "https://pushary.com/api/mcp/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "pushary-pushary": {
      "type": "remote",
      "url": "https://pushary.com/api/mcp/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add pushary-pushary --url 'https://pushary.com/api/mcp/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  pushary-pushary:
    url: "https://pushary.com/api/mcp/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "pushary-pushary": {
      "Transport": "http",
      "Url": "https://pushary.com/api/mcp/mcp"
    }
  }
}
# add to Vellum
assistant mcp add pushary-pushary -t streamable-http -u 'https://pushary.com/api/mcp/mcp'
// mcp.json
{
  "mcpServers": {
    "pushary-pushary": {
      "type": "http",
      "url": "https://pushary.com/api/mcp/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 16 Sept 26 +7
    • Judged manipulation: unverified → pass security
    • Schema quality: unverified → excellent functional
  • 15 Sept 26 −7
    • Judged manipulation: pass → unverified security
    • Schema quality: excellent → unverified functional
    • “ask_user” added an optional parameter “toolPath” cosmetic
  • 14 Sept 26 0
    • The server rewrote its instructions, which are the text every model session reads security
  • 9 Sept 26 +10
    • Stability: fail → pass security
  • 3 Sept 26 0
    • “send_notification” added an optional parameter “env” cosmetic
    • “ask_user” added an optional parameter “env” cosmetic
    • “cancel_question” added an optional parameter “handoff” cosmetic

    3 cosmetic changes on this day. Switch on “Show cosmetic changes” to see them.

  • 1 Sept 26 0
    • “ask_user” added an optional parameter “waitEndsAt” cosmetic

    1 cosmetic change on this day. Switch on “Show cosmetic changes” to see it.

  • 30 Aug 26 0
    • “ask_user” reworded the description of “questions” cosmetic

    1 cosmetic change on this day. Switch on “Show cosmetic changes” to see it.

  • 28 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 20 to 23.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 20 Sept 2026 · Probed https://pushary.com/api/mcp/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=*.pushary.com CN=YR1,O=Let's Encrypt,C=US 28 Aug 2026 26 Nov 2026 RSA 2048 SHA256-RSA 5e3c676da7e759fa969ac34d3eca3102acb
SANs: *.pushary.com, pushary.com
CN=YR1,O=Let's Encrypt,C=US (CA) CN=Root YR,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 RSA 2048 SHA256-RSA a20253f15f2691c05dc1ce13b9bcca4e
CN=Root YR,O=ISRG,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 RSA 4096 SHA256-RSA f24b6d17f9d9ad7cb1c9fea78782699f

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of pushary.com. Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
pushary.com. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication Enforced and verified

The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.

Result Enforced and verified
Enforced On tool calls
HTTP status 200

WWW-Authenticate challenge Bearer error="invalid_token", error_description="No authorization provided", resource_metadata="https://pushary.com/.well-known/oauth-protected-resource/api/mcp/mcp"

Bearer error="invalid_token", error_description="No authorization provided", resource_metadata="https://pushary.com/.well-known/oauth-protected-resource/api/mcp/mcp"
Header Value
strict-transport-security max-age=31536000; includeSubDomains; preload
x-content-type-options nosniff
x-frame-options SAMEORIGIN
referrer-policy strict-origin-when-cross-origin

Protected resource metadata

Document https://pushary.com/.well-known/oauth-protected-resource/api/mcp/mcp
Retrieved Yes
Resource https://pushary.com/api/mcp/mcp
Authorisation server https://clerk.pushary.com

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://pushary.com/api/mcp/mcp Verified 200
http (plaintext) http://pushary.com/api/mcp/mcp HTTPS enforced 308 https://pushary.com/api/mcp/mcp
MCP tools · 5 exposed · ~3,030 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
ask_user ~1,474

Ask the user a question as a push notification on their phone and block until they answer. Reach for this whenever you need the user's decision and they may be away from the current client: approving a risky or irreversible step (deleting files, force pushing, spending money, sending external messages), picking between implementation options, or supplying missing input. The user answers from the lock screen or a decision page; you do not need a separate wait_for_answer call because this tool waits by default. Three question types: "confirm" (yes/no), "select" (2 to 6 fixed choices), "input" (free text). A single call blocks for at most 55 seconds. If a live question times out, nextAction is "wait_for_answer": poll once with timeoutMs 55000. If that poll is also unanswered, cancel the phone question before asking in the current chat or client. If cancellation returns handoffAction "stop", stop. Otherwise, if cancellation returns false, poll once for 1 second and honor the answer that won the race. Cancelled, expired, and missing questions are reported as terminal states rather than as timeouts. Every response carries answerUrl, the signed-in dashboard page where this question is waiting. When you report that you are waiting, print that URL to the user so they can answer from a browser instead of hunting for it. Works from Claude Code, Codex, Cursor, Hermes, or any MCP client; no Claude subscription is required. SIDE EFFECT: sends a real push notification.

NameTypeReqDescription
actionstringThe concrete operation about to happen, one line. Shown as the Action line.
actionBodystringThe diff (Edit/Write) or full command (Bash/apply_patch), secret-redacted and size-capped. Rendered as a collapsible detail block; never used as the push body.
agentNamestringName of the agent asking, format "{Agent} - {project}" (e.g. "Claude Code - myproject"). Shown in the notification title so the user knows which session needs them. Falls back to the MCP client name…
blockerstringThe single gating reason the agent stopped, one line. Shown as the Blocker line.
callbackUrlstringWebhook URL that receives a POST with the answer when the user responds, signed with the X-Pushary-Signature header. Useful when the agent process may exit before the answer arrives.
contextstringOne or two sentences about what the agent is working on, shown above the question so the user can decide without opening the terminal.
envstringSet to "test" from a test suite. The question is stored and returned as pending, and nothing is delivered to a phone, browser or Slack. The X-Pushary-Env: test header does the same for every call on…
externalIdsarrayDeliver only to subscribers matching these external IDs.
intentstringThe user's stated task (from their last prompt), one line. Shown as the Intent line so the user can see why the agent stopped.
machineIdstringStable machine id of the asking agent, so two machines never collapse into one session.
optionsarrayThe 2 to 6 choices for a select question. Required when type is "select", ignored otherwise. The answered value is the chosen option string.
placeholderstringHint text shown inside the free-text field for input questions
questionstringyesThe question shown on the user's lock screen (max 500 chars). Phrase it so it is answerable at a glance; put background in context instead.
questionsarrayONE question, in the richer Claude-compatible shape: a header, per-option descriptions, multiSelect, and an optional write-in. Exactly one keeps already-installed clients answerable; asking several m…
repoKeystringStable repository identity for the working directory, e.g. "github.com/acme/api". Lets an approval routing rule scoped to one repository avoid governing another. Optional; omit it and only workspace-…
requestIdstringMACHINE-POPULATED. The CALLER's own identifier for one logical invocation, used only when the runtime supplies no toolUseId. Mint it once, outside your retry loop, and send the same value on every at…
scopePathstringSet ONLY when this approval exists because the path falls outside the scope the user ratified via propose_scope. Approving then widens the run scope to include this exact path, so the user is not ask…
sessionIdstringOpaque per-session id of the asking agent, so parallel sessions are attributed separately.
subscriberIdsarrayDeliver only to these subscriber IDs. Omit all targeting fields to reach every connected device.
tagsarrayDeliver only to subscribers that have any of these tags.
timeoutMsintegerHow long this call blocks, in milliseconds (max 55000). Defaults to the site policy timeout. The question stays open for 10 minutes regardless, so a timeout here is not a refusal; follow up with wait…
toolNamestringThe tool this approval is for (e.g. "Bash"), so the user can choose to always-allow it.
toolPathstringMACHINE-POPULATED. Exact absolute Write file_path from the runtime, for diagnostic correlation only. Models must omit it.
toolTargetstringCompact target of the tool call (e.g. the command head "git push" for Bash, or a file extension like ".ts" for Edit/Write). Used to mine policy suggestions.
toolUseIdstringMACHINE-POPULATED. The agent RUNTIME's own identifier for the tool call this approval gates, forwarded verbatim by a hook that received it. Do NOT invent, guess, derive, or reuse a value: two differe…
typestringQuestion type: confirm renders yes/no buttons, select renders the options list, input renders a free-text field.
waitbooleantrue (default) blocks until the user answers or the timeout fires. Set false to return immediately with a pending correlationId and poll it yourself via wait_for_answer.
waitEndsAtstringMACHINE-POPULATED. When the agent hook stops waiting live and hands control back to the terminal. The question may remain answerable after this time. Ordinary callers should omit it.
NameTypeReqDescription
answerSourcestringRecorded answering surface, when known. Missing provenance is not proof of a phone answer; sandbox is simulated.
answerUrlstringThe signed-in dashboard page where this question is waiting. Print it when you tell the user you are waiting, so they can answer from a browser.
answeredbooleanTrue once the user responded. Absent on the wait:false path, where nothing was awaited.
correlationIdstringyesId of the question that was created. Pass it to wait_for_answer to keep waiting, or to cancel_question to retract it.
deliveryobjectPer-channel reach for the push carrying this question.
deliveryModestringEffective delivery policy for this decision.
envstringEchoed when the call was test traffic.
expiresInSecondsnumberHow long the question stays answerable.
handoffActionstringRace-safe directive for updated clients. Takes precedence over nextAction: cancel before asking in the current client, or stop the handoff.
heldstringPresent when the question was stored but deliberately not delivered: test traffic, or a permission ask with no toolName and no sessionId.
hintstringWhat to do next, when there is a next step.
modestringThe site delivery mode that stopped this call from waiting.
nextActionstringBackward-compatible next step: poll once or ask in the current client. Follow handoffAction first when present.
noDevicesbooleanTrue when no phone, browser, or Slack channel could receive the question. Do not wait; follow handoffAction immediately.
notestringFree text the user added alongside their answer.
policyTimeoutMsnumberPolicy wait window in milliseconds. Callers must also honor their host deadline.
questionstringyesThe question exactly as the user saw it.
statusstringThe question state. Only pending is a live unanswered wait; cancelled, expired, missing, and unavailable must not be described as timeouts.
suppressedbooleanTrue when the PHONE push was deliberately held because a terminal on this machine is active. It says nothing about the notch, the dashboard or Slack, which are unaffected and may still be showing thi…
timedOutbooleanTrue when the initial wait ended while the question was still live. Poll once with wait_for_answer, then follow handoffAction when present, otherwise nextAction.
typestringyesThe question type that was rendered.
valuestringThe user's answer: "yes" or "no" for confirm, the chosen option for select, the typed text for input.
waitEndsAtstringWhen the agent hook stops waiting live. On an idempotent replay this is the original question's deadline, which the hook must reuse.
warningstringPresent only when no channel is connected, naming what the user has to connect.

No examples provided.

cancel_question ~220

Retract a pending question so it can no longer be answered. Use this when a question became irrelevant before the user replied: the agent found the answer itself, the task was aborted, or a newer question supersedes it. Cancelling prevents a stale approval from arriving later and acting on work that has moved on. Only affects questions that are still pending; questions expire on their own 10 minutes after creation. Returns { cancelled: true } when a pending question was removed. False means it was already answered, expired, unknown, or unavailable; when status is unavailable, follow handoffAction and stop rather than opening another answer surface.

NameTypeReqDescription
correlationIdstringyesThe correlationId of the pending question to cancel, as returned by ask_user or send_notification
handoffbooleanTrue when you are cancelling because you are about to ask the same question in the current client. For the next minute the Pushary hook then lets your own question tool through instead of sending it…
NameTypeReqDescription
askHandoffbooleanTrue when the session was marked as handing off to the current client, so the hook will not re-ask on the phone for the next minute.
cancelledbooleanyesTrue when a still-pending question was removed. False when it was already terminal, missing, or unavailable; inspect status and handoffAction when present.
correlationIdstringyesThe question this result refers to, echoed back.
handoffActionstringStop rather than opening another answer surface when the question state is unavailable.
hintstringWhat to do when cancellation could not safely inspect the question.
statusstringPresent when Pushary could not safely read or fence the question state.

No examples provided.

propose_scope ~472

Propose what this run will touch and block until the user ratifies it. Call ONCE at the start of a multi-step run, before doing work. The user sees the paths you intend to change, the areas you promise to leave alone, and your definition of done, and approves the whole thing in one tap. After that, editing a file outside the agreed scope stops being auto-approvable: it becomes a separate "wants to widen scope" question instead of a silent approval, so you are asked once about the boundary rather than repeatedly about each file. Use glob syntax ("src/**", "**/*.test.ts"). Shell commands are NOT scoped here, they stay governed by the permission policy. Scope lives for this session only and is never inherited by another run. Returns { correlationId, ratified, answered, value }; only ratified:true means the contract is enforced. If the first wait times out, poll its correlationId once; a late phone yes ratifies the stored proposal. If that poll is also pending, cancel it before asking in the current chat whether to continue without an enforced scope. If cancellation loses a race, honor the phone answer instead. Never describe a client-only agreement as ratification. SIDE EFFECT: sends a real push notification.

NameTypeReqDescription
agentNamestringName of the agent asking, format "{Agent} - {project}".
allowedPathsarrayGlobs you intend to change, e.g. ["src/**", "docs/*.md"]. Omit or leave empty to propose no path restriction, which the user is told plainly.
doneWhenstringyesWhat "finished" means for this run, one or two lines. Carried for the human to judge against; never enforced automatically.
machineIdstringStable machine id, so two machines never collapse into one session.
offLimitsPathsarrayGlobs you promise not to touch, e.g. ["**/.env*", "infra/**"]. These win wherever they overlap allowedPaths.
sessionIdstringyesYour per-session id. Required: a scope with no session cannot be enforced, and must never leak into another run.
timeoutMsintegerHow long this call blocks, in milliseconds (max 55000).
NameTypeReqDescription
answeredbooleanyesTrue when the user responded at all. Answered but not ratified means they declined, so ask what scope they want rather than proceeding.
contractobjectyesThe scope exactly as it was put to the user, echoed back so the agent and the human are holding the same contract.
correlationIdstringyesId of the scope question. Pass it to wait_for_answer once when the first wait times out.
handoffActionstringRace-safe directive for updated clients. Takes precedence over nextAction.
nextActionstringPoll one live question once; otherwise ask in the current chat whether to continue without an enforced scope.
notestringPresent only when the scope is not in force, saying what to do instead of proceeding.
ratifiedbooleanyesTrue only on an explicit yes. The contract is in force for this session only when this is true; anything else means proceed as if no scope was agreed.
statusstringThe underlying scope-question state.
valuestringThe raw answer behind ratified, "yes" or "no".

No examples provided.

send_notification ~606

Send a one-way push notification to the user's phone and browser. Nothing is awaited; use ask_user instead when you need an answer back. Reach for this when a long-running task finishes and the user asked to be told, when the agent hits an error it cannot resolve on its own, or for any "notify me when my agent needs me" moment while the user is away from the terminal. By default the notification reaches every device connected to the site; narrow delivery with subscriberIds, externalIds, or tags. The optional context object turns the tap-through into a rich detail page (summary, bullet details, changed files, error info, next steps), and context.askQuestion embeds a decision prompt on that page, returning a linkedCorrelationId you can poll with wait_for_answer. Returns per-channel delivery counts for web and mobile, plus a warning when zero devices are connected. Works from Claude Code, Codex, Cursor, Hermes, or any MCP client; no Claude subscription is required. SIDE EFFECT: delivers real notifications to real devices immediately.

NameTypeReqDescription
agentNamestringName of the agent sending this notification, format "{Agent} - {project}" (e.g. "Claude Code - myproject"). Shown in the notification so the user knows which session is talking. Falls back to the MCP…
bodystringyesNotification body text (max 500 chars). One or two sentences the user can act on without opening anything.
contextobjectStructured context rendered as a rich detail page when the user taps the notification. Strongly recommended for task_complete and error notifications so the user can act from their phone.
envstringSet to "test" from a test suite. The notification is recorded in the activity feed and nothing is delivered to a phone or browser. The X-Pushary-Env: test header does the same for every call on the c…
externalIdsarrayDeliver only to subscribers matching these external IDs.
iconUrlstringURL of the notification icon image
imageUrlstringURL of a large image shown in the notification
machineIdstringStable machine id of the sending agent, so two machines never collapse into one session.
sessionIdstringOpaque per-session id of the sending agent, so parallel sessions are attributed separately in the activity feed.
subscriberIdsarrayDeliver only to these subscriber IDs. Omit all targeting fields to reach every connected device.
tagsarrayDeliver only to subscribers that have any of these tags.
titlestringyesNotification title shown on the lock screen (max 100 chars). Lead with the outcome, e.g. "Build finished" or "Migration failed".
urlstringURL opened when the user taps the notification. Ignored if context is provided, because a context detail page URL is generated automatically.
NameTypeReqDescription
deliveryobjectPer-channel outcome. The two channels are independent with no cross-fallback, so each reports its own result.
envstringEchoed when the call was test traffic.
hintstringWhat to do next, when there is a next step.
linkedCorrelationIdstringPresent only when context.askQuestion embedded a decision prompt. Pass it to wait_for_answer to collect the response.
sentnumberTotal devices reached, web plus mobile. Zero is a successful call that found nobody to deliver to, not an error.
warningstringPresent only when the notification reached zero devices, naming what the user has to connect.

No examples provided.

wait_for_answer ~258

Poll once for the user's answer to a previously created question: after ask_user times out, after ask_user with wait:false, or with a linkedCorrelationId from send_notification. Each call blocks until the answer arrives or timeoutMs expires (default 30 seconds, max 55). If a live question is still unanswered after this poll, handoffAction is "cancel_then_ask_in_current_client": cancel the phone question before asking in the current chat or client. If cancellation returns handoffAction "stop", stop. Otherwise, if cancellation returns false, poll once for 1 second and honor the answer that won the race. The response distinguishes pending, cancelled, expired, missing, and unavailable states; cancelled and unavailable mean stop rather than re-ask. nextAction retains only its original values for older clients. Returns { answered:true, status:"answered", value } once the user responds.

NameTypeReqDescription
correlationIdstringyesThe correlationId from an earlier ask_user response, or the linkedCorrelationId from a send_notification with an embedded askQuestion
timeoutMsintegerHow long this one poll blocks, in milliseconds (default 30000, max 55000). Follow handoffAction when present, otherwise nextAction.
NameTypeReqDescription
answerSourcestringRecorded answering surface, when known. Missing provenance is not proof of a phone answer; sandbox is simulated.
answeredbooleanyesTrue once the user responded. False means follow handoffAction when present, otherwise nextAction; do not guess that every unanswered state is a timeout.
handoffActionstringRace-safe directive for updated clients. Takes precedence over nextAction.
hintstringWhat to do next, when there is a next step.
nextActionstringBackward-compatible next step for older clients. Follow handoffAction first when present.
notestringFree text the user added alongside their answer.
statusstringyesThe actual question state. Only pending is a live unanswered wait.
valuestringThe user's answer: "yes" or "no" for confirm, the chosen option for select, the typed text for input. Present only when answered is true.

No examples provided.

Common questions

What is the Pushary MCP server?

Pushary is an MCP server listed in the public MCP registry as io.github.Pushary/pushary. Reach a human from a running agent. Approvals on the lock screen, plus a cross-agent audit trail. This page covers its hosted endpoint (https://pushary.com/api/mcp/mcp).

Is the Pushary MCP server safe to use?

Pushary scores 93 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Pushary MCP server expose?

Pushary exposes 5 tools: send_notification, ask_user, propose_scope, wait_for_answer, cancel_question. Their descriptions and schemas cost roughly 3,030 tokens of context every time the server is loaded.

Does the Pushary MCP server require authentication?

Yes. Pushary asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.

Is the Pushary MCP server still maintained?

Pushary is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.