Pushary
REMOTE · PUSHARY.COM · 2 COMPONENTS · SCANNED SEP 20
Reach a human from a running agent. Approvals on the lock screen, plus a cross-agent audit trail.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security94
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents. View diagnostics → Partial
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability77
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 3387 tokens (~338/item across 10 items; 5 tools + 5 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 7 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the Pushary MCP server?
Pushary is a hosted endpoint at https://pushary.com/api/mcp/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · pushary.com
claude mcp add --transport http pushary-pushary 'https://pushary.com/api/mcp/mcp'
{
"mcpServers": {
"pushary-pushary": {
"url": "https://pushary.com/api/mcp/mcp"
}
}
} {
"servers": {
"pushary-pushary": {
"type": "http",
"url": "https://pushary.com/api/mcp/mcp"
}
}
} [mcp_servers.pushary-pushary] url = "https://pushary.com/api/mcp/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"pushary-pushary": {
"type": "remote",
"url": "https://pushary.com/api/mcp/mcp",
"enabled": true
}
}
} openclaw mcp add pushary-pushary --url 'https://pushary.com/api/mcp/mcp' --transport streamable-http
mcp_servers:
pushary-pushary:
url: "https://pushary.com/api/mcp/mcp" {
"McpServers": {
"pushary-pushary": {
"Transport": "http",
"Url": "https://pushary.com/api/mcp/mcp"
}
}
} assistant mcp add pushary-pushary -t streamable-http -u 'https://pushary.com/api/mcp/mcp'
{
"mcpServers": {
"pushary-pushary": {
"type": "http",
"url": "https://pushary.com/api/mcp/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 16 Sept 26 +7
- Judged manipulation: unverified → pass ▲ security
- Schema quality: unverified → excellent ▲ functional
- 15 Sept 26 −7
- Judged manipulation: pass → unverified ▼ security
- Schema quality: excellent → unverified ▼ functional
- “ask_user” added an optional parameter “toolPath” cosmetic
- 14 Sept 26 0
- The server rewrote its instructions, which are the text every model session reads security
- 9 Sept 26 +10
- Stability: fail → pass ▲ security
- 3 Sept 26 0
- “send_notification” added an optional parameter “env” cosmetic
- “ask_user” added an optional parameter “env” cosmetic
- “cancel_question” added an optional parameter “handoff” cosmetic
3 cosmetic changes on this day. Switch on “Show cosmetic changes” to see them.
- 1 Sept 26 0
- “ask_user” added an optional parameter “waitEndsAt” cosmetic
1 cosmetic change on this day. Switch on “Show cosmetic changes” to see it.
- 30 Aug 26 0
- “ask_user” reworded the description of “questions” cosmetic
1 cosmetic change on this day. Switch on “Show cosmetic changes” to see it.
- 28 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 20 to 23.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://pushary.com/api/mcp/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=*.pushary.com | CN=YR1,O=Let's Encrypt,C=US | 28 Aug 2026 | 26 Nov 2026 | RSA 2048 | SHA256-RSA | 5e3c676da7e759fa969ac34d3eca3102acb |
| SANs: *.pushary.com, pushary.com | ||||||
| CN=YR1,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | a20253f15f2691c05dc1ce13b9bcca4e |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of pushary.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| pushary.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer error="invalid_token", error_description="No authorization provided", resource_metadata="https://pushary.com/.well-known/oauth-protected-resource/api/mcp/mcp"
Bearer error="invalid_token", error_description="No authorization provided", resource_metadata="https://pushary.com/.well-known/oauth-protected-resource/api/mcp/mcp" | Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains; preload |
| x-content-type-options | nosniff |
| x-frame-options | SAMEORIGIN |
| referrer-policy | strict-origin-when-cross-origin |
Protected resource metadata
| Document | https://pushary.com/.well-known/oauth-protected-resource/api/mcp/mcp |
|---|---|
| Retrieved | Yes |
| Resource | https://pushary.com/api/mcp/mcp |
| Authorisation server | https://clerk.pushary.com |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://pushary.com/api/mcp/mcp | Verified | 200 | |
| http (plaintext) | http://pushary.com/api/mcp/mcp | HTTPS enforced | 308 | https://pushary.com/api/mcp/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
ask_user Ask User a Question ~1,474
Ask the user a question as a push notification on their phone and block until they answer. Reach for this whenever you need the user's decision and they may be away from the current client: approving a risky or irreversible step (deleting files, force pushing, spending money, sending external messages), picking between implementation options, or supplying missing input. The user answers from the lock screen or a decision page; you do not need a separate wait_for_answer call because this tool waits by default. Three question types: "confirm" (yes/no), "select" (2 to 6 fixed choices), "input" (free text). A single call blocks for at most 55 seconds. If a live question times out, nextAction is "wait_for_answer": poll once with timeoutMs 55000. If that poll is also unanswered, cancel the phone question before asking in the current chat or client. If cancellation returns handoffAction "stop", stop. Otherwise, if cancellation returns false, poll once for 1 second and honor the answer that won the race. Cancelled, expired, and missing questions are reported as terminal states rather than as timeouts. Every response carries answerUrl, the signed-in dashboard page where this question is waiting. When you report that you are waiting, print that URL to the user so they can answer from a browser instead of hunting for it. Works from Claude Code, Codex, Cursor, Hermes, or any MCP client; no Claude subscription is required. SIDE EFFECT: sends a real push notification.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | – | The concrete operation about to happen, one line. Shown as the Action line. |
| actionBody | string | – | The diff (Edit/Write) or full command (Bash/apply_patch), secret-redacted and size-capped. Rendered as a collapsible detail block; never used as the push body. |
| agentName | string | – | Name of the agent asking, format "{Agent} - {project}" (e.g. "Claude Code - myproject"). Shown in the notification title so the user knows which session needs them. Falls back to the MCP client name… |
| blocker | string | – | The single gating reason the agent stopped, one line. Shown as the Blocker line. |
| callbackUrl | string | – | Webhook URL that receives a POST with the answer when the user responds, signed with the X-Pushary-Signature header. Useful when the agent process may exit before the answer arrives. |
| context | string | – | One or two sentences about what the agent is working on, shown above the question so the user can decide without opening the terminal. |
| env | string | – | Set to "test" from a test suite. The question is stored and returned as pending, and nothing is delivered to a phone, browser or Slack. The X-Pushary-Env: test header does the same for every call on… |
| externalIds | array | – | Deliver only to subscribers matching these external IDs. |
| intent | string | – | The user's stated task (from their last prompt), one line. Shown as the Intent line so the user can see why the agent stopped. |
| machineId | string | – | Stable machine id of the asking agent, so two machines never collapse into one session. |
| options | array | – | The 2 to 6 choices for a select question. Required when type is "select", ignored otherwise. The answered value is the chosen option string. |
| placeholder | string | – | Hint text shown inside the free-text field for input questions |
| question | string | yes | The question shown on the user's lock screen (max 500 chars). Phrase it so it is answerable at a glance; put background in context instead. |
| questions | array | – | ONE question, in the richer Claude-compatible shape: a header, per-option descriptions, multiSelect, and an optional write-in. Exactly one keeps already-installed clients answerable; asking several m… |
| repoKey | string | – | Stable repository identity for the working directory, e.g. "github.com/acme/api". Lets an approval routing rule scoped to one repository avoid governing another. Optional; omit it and only workspace-… |
| requestId | string | – | MACHINE-POPULATED. The CALLER's own identifier for one logical invocation, used only when the runtime supplies no toolUseId. Mint it once, outside your retry loop, and send the same value on every at… |
| scopePath | string | – | Set ONLY when this approval exists because the path falls outside the scope the user ratified via propose_scope. Approving then widens the run scope to include this exact path, so the user is not ask… |
| sessionId | string | – | Opaque per-session id of the asking agent, so parallel sessions are attributed separately. |
| subscriberIds | array | – | Deliver only to these subscriber IDs. Omit all targeting fields to reach every connected device. |
| tags | array | – | Deliver only to subscribers that have any of these tags. |
| timeoutMs | integer | – | How long this call blocks, in milliseconds (max 55000). Defaults to the site policy timeout. The question stays open for 10 minutes regardless, so a timeout here is not a refusal; follow up with wait… |
| toolName | string | – | The tool this approval is for (e.g. "Bash"), so the user can choose to always-allow it. |
| toolPath | string | – | MACHINE-POPULATED. Exact absolute Write file_path from the runtime, for diagnostic correlation only. Models must omit it. |
| toolTarget | string | – | Compact target of the tool call (e.g. the command head "git push" for Bash, or a file extension like ".ts" for Edit/Write). Used to mine policy suggestions. |
| toolUseId | string | – | MACHINE-POPULATED. The agent RUNTIME's own identifier for the tool call this approval gates, forwarded verbatim by a hook that received it. Do NOT invent, guess, derive, or reuse a value: two differe… |
| type | string | – | Question type: confirm renders yes/no buttons, select renders the options list, input renders a free-text field. |
| wait | boolean | – | true (default) blocks until the user answers or the timeout fires. Set false to return immediately with a pending correlationId and poll it yourself via wait_for_answer. |
| waitEndsAt | string | – | MACHINE-POPULATED. When the agent hook stops waiting live and hands control back to the terminal. The question may remain answerable after this time. Ordinary callers should omit it. |
| Name | Type | Req | Description |
|---|---|---|---|
| answerSource | string | – | Recorded answering surface, when known. Missing provenance is not proof of a phone answer; sandbox is simulated. |
| answerUrl | string | – | The signed-in dashboard page where this question is waiting. Print it when you tell the user you are waiting, so they can answer from a browser. |
| answered | boolean | – | True once the user responded. Absent on the wait:false path, where nothing was awaited. |
| correlationId | string | yes | Id of the question that was created. Pass it to wait_for_answer to keep waiting, or to cancel_question to retract it. |
| delivery | object | – | Per-channel reach for the push carrying this question. |
| deliveryMode | string | – | Effective delivery policy for this decision. |
| env | string | – | Echoed when the call was test traffic. |
| expiresInSeconds | number | – | How long the question stays answerable. |
| handoffAction | string | – | Race-safe directive for updated clients. Takes precedence over nextAction: cancel before asking in the current client, or stop the handoff. |
| held | string | – | Present when the question was stored but deliberately not delivered: test traffic, or a permission ask with no toolName and no sessionId. |
| hint | string | – | What to do next, when there is a next step. |
| mode | string | – | The site delivery mode that stopped this call from waiting. |
| nextAction | string | – | Backward-compatible next step: poll once or ask in the current client. Follow handoffAction first when present. |
| noDevices | boolean | – | True when no phone, browser, or Slack channel could receive the question. Do not wait; follow handoffAction immediately. |
| note | string | – | Free text the user added alongside their answer. |
| policyTimeoutMs | number | – | Policy wait window in milliseconds. Callers must also honor their host deadline. |
| question | string | yes | The question exactly as the user saw it. |
| status | string | – | The question state. Only pending is a live unanswered wait; cancelled, expired, missing, and unavailable must not be described as timeouts. |
| suppressed | boolean | – | True when the PHONE push was deliberately held because a terminal on this machine is active. It says nothing about the notch, the dashboard or Slack, which are unaffected and may still be showing thi… |
| timedOut | boolean | – | True when the initial wait ended while the question was still live. Poll once with wait_for_answer, then follow handoffAction when present, otherwise nextAction. |
| type | string | yes | The question type that was rendered. |
| value | string | – | The user's answer: "yes" or "no" for confirm, the chosen option for select, the typed text for input. |
| waitEndsAt | string | – | When the agent hook stops waiting live. On an idempotent replay this is the original question's deadline, which the hook must reuse. |
| warning | string | – | Present only when no channel is connected, naming what the user has to connect. |
No examples provided.
cancel_question Cancel Pending Question ~220
Retract a pending question so it can no longer be answered. Use this when a question became irrelevant before the user replied: the agent found the answer itself, the task was aborted, or a newer question supersedes it. Cancelling prevents a stale approval from arriving later and acting on work that has moved on. Only affects questions that are still pending; questions expire on their own 10 minutes after creation. Returns { cancelled: true } when a pending question was removed. False means it was already answered, expired, unknown, or unavailable; when status is unavailable, follow handoffAction and stop rather than opening another answer surface.
| Name | Type | Req | Description |
|---|---|---|---|
| correlationId | string | yes | The correlationId of the pending question to cancel, as returned by ask_user or send_notification |
| handoff | boolean | – | True when you are cancelling because you are about to ask the same question in the current client. For the next minute the Pushary hook then lets your own question tool through instead of sending it… |
| Name | Type | Req | Description |
|---|---|---|---|
| askHandoff | boolean | – | True when the session was marked as handing off to the current client, so the hook will not re-ask on the phone for the next minute. |
| cancelled | boolean | yes | True when a still-pending question was removed. False when it was already terminal, missing, or unavailable; inspect status and handoffAction when present. |
| correlationId | string | yes | The question this result refers to, echoed back. |
| handoffAction | string | – | Stop rather than opening another answer surface when the question state is unavailable. |
| hint | string | – | What to do when cancellation could not safely inspect the question. |
| status | string | – | Present when Pushary could not safely read or fence the question state. |
No examples provided.
propose_scope Propose Run Scope ~472
Propose what this run will touch and block until the user ratifies it. Call ONCE at the start of a multi-step run, before doing work. The user sees the paths you intend to change, the areas you promise to leave alone, and your definition of done, and approves the whole thing in one tap. After that, editing a file outside the agreed scope stops being auto-approvable: it becomes a separate "wants to widen scope" question instead of a silent approval, so you are asked once about the boundary rather than repeatedly about each file. Use glob syntax ("src/**", "**/*.test.ts"). Shell commands are NOT scoped here, they stay governed by the permission policy. Scope lives for this session only and is never inherited by another run. Returns { correlationId, ratified, answered, value }; only ratified:true means the contract is enforced. If the first wait times out, poll its correlationId once; a late phone yes ratifies the stored proposal. If that poll is also pending, cancel it before asking in the current chat whether to continue without an enforced scope. If cancellation loses a race, honor the phone answer instead. Never describe a client-only agreement as ratification. SIDE EFFECT: sends a real push notification.
| Name | Type | Req | Description |
|---|---|---|---|
| agentName | string | – | Name of the agent asking, format "{Agent} - {project}". |
| allowedPaths | array | – | Globs you intend to change, e.g. ["src/**", "docs/*.md"]. Omit or leave empty to propose no path restriction, which the user is told plainly. |
| doneWhen | string | yes | What "finished" means for this run, one or two lines. Carried for the human to judge against; never enforced automatically. |
| machineId | string | – | Stable machine id, so two machines never collapse into one session. |
| offLimitsPaths | array | – | Globs you promise not to touch, e.g. ["**/.env*", "infra/**"]. These win wherever they overlap allowedPaths. |
| sessionId | string | yes | Your per-session id. Required: a scope with no session cannot be enforced, and must never leak into another run. |
| timeoutMs | integer | – | How long this call blocks, in milliseconds (max 55000). |
| Name | Type | Req | Description |
|---|---|---|---|
| answered | boolean | yes | True when the user responded at all. Answered but not ratified means they declined, so ask what scope they want rather than proceeding. |
| contract | object | yes | The scope exactly as it was put to the user, echoed back so the agent and the human are holding the same contract. |
| correlationId | string | yes | Id of the scope question. Pass it to wait_for_answer once when the first wait times out. |
| handoffAction | string | – | Race-safe directive for updated clients. Takes precedence over nextAction. |
| nextAction | string | – | Poll one live question once; otherwise ask in the current chat whether to continue without an enforced scope. |
| note | string | – | Present only when the scope is not in force, saying what to do instead of proceeding. |
| ratified | boolean | yes | True only on an explicit yes. The contract is in force for this session only when this is true; anything else means proceed as if no scope was agreed. |
| status | string | – | The underlying scope-question state. |
| value | string | – | The raw answer behind ratified, "yes" or "no". |
No examples provided.
send_notification Send Push Notification ~606
Send a one-way push notification to the user's phone and browser. Nothing is awaited; use ask_user instead when you need an answer back. Reach for this when a long-running task finishes and the user asked to be told, when the agent hits an error it cannot resolve on its own, or for any "notify me when my agent needs me" moment while the user is away from the terminal. By default the notification reaches every device connected to the site; narrow delivery with subscriberIds, externalIds, or tags. The optional context object turns the tap-through into a rich detail page (summary, bullet details, changed files, error info, next steps), and context.askQuestion embeds a decision prompt on that page, returning a linkedCorrelationId you can poll with wait_for_answer. Returns per-channel delivery counts for web and mobile, plus a warning when zero devices are connected. Works from Claude Code, Codex, Cursor, Hermes, or any MCP client; no Claude subscription is required. SIDE EFFECT: delivers real notifications to real devices immediately.
| Name | Type | Req | Description |
|---|---|---|---|
| agentName | string | – | Name of the agent sending this notification, format "{Agent} - {project}" (e.g. "Claude Code - myproject"). Shown in the notification so the user knows which session is talking. Falls back to the MCP… |
| body | string | yes | Notification body text (max 500 chars). One or two sentences the user can act on without opening anything. |
| context | object | – | Structured context rendered as a rich detail page when the user taps the notification. Strongly recommended for task_complete and error notifications so the user can act from their phone. |
| env | string | – | Set to "test" from a test suite. The notification is recorded in the activity feed and nothing is delivered to a phone or browser. The X-Pushary-Env: test header does the same for every call on the c… |
| externalIds | array | – | Deliver only to subscribers matching these external IDs. |
| iconUrl | string | – | URL of the notification icon image |
| imageUrl | string | – | URL of a large image shown in the notification |
| machineId | string | – | Stable machine id of the sending agent, so two machines never collapse into one session. |
| sessionId | string | – | Opaque per-session id of the sending agent, so parallel sessions are attributed separately in the activity feed. |
| subscriberIds | array | – | Deliver only to these subscriber IDs. Omit all targeting fields to reach every connected device. |
| tags | array | – | Deliver only to subscribers that have any of these tags. |
| title | string | yes | Notification title shown on the lock screen (max 100 chars). Lead with the outcome, e.g. "Build finished" or "Migration failed". |
| url | string | – | URL opened when the user taps the notification. Ignored if context is provided, because a context detail page URL is generated automatically. |
| Name | Type | Req | Description |
|---|---|---|---|
| delivery | object | – | Per-channel outcome. The two channels are independent with no cross-fallback, so each reports its own result. |
| env | string | – | Echoed when the call was test traffic. |
| hint | string | – | What to do next, when there is a next step. |
| linkedCorrelationId | string | – | Present only when context.askQuestion embedded a decision prompt. Pass it to wait_for_answer to collect the response. |
| sent | number | – | Total devices reached, web plus mobile. Zero is a successful call that found nobody to deliver to, not an error. |
| warning | string | – | Present only when the notification reached zero devices, naming what the user has to connect. |
No examples provided.
wait_for_answer Wait for User Answer ~258
Poll once for the user's answer to a previously created question: after ask_user times out, after ask_user with wait:false, or with a linkedCorrelationId from send_notification. Each call blocks until the answer arrives or timeoutMs expires (default 30 seconds, max 55). If a live question is still unanswered after this poll, handoffAction is "cancel_then_ask_in_current_client": cancel the phone question before asking in the current chat or client. If cancellation returns handoffAction "stop", stop. Otherwise, if cancellation returns false, poll once for 1 second and honor the answer that won the race. The response distinguishes pending, cancelled, expired, missing, and unavailable states; cancelled and unavailable mean stop rather than re-ask. nextAction retains only its original values for older clients. Returns { answered:true, status:"answered", value } once the user responds.
| Name | Type | Req | Description |
|---|---|---|---|
| correlationId | string | yes | The correlationId from an earlier ask_user response, or the linkedCorrelationId from a send_notification with an embedded askQuestion |
| timeoutMs | integer | – | How long this one poll blocks, in milliseconds (default 30000, max 55000). Follow handoffAction when present, otherwise nextAction. |
| Name | Type | Req | Description |
|---|---|---|---|
| answerSource | string | – | Recorded answering surface, when known. Missing provenance is not proof of a phone answer; sandbox is simulated. |
| answered | boolean | yes | True once the user responded. False means follow handoffAction when present, otherwise nextAction; do not guess that every unanswered state is a timeout. |
| handoffAction | string | – | Race-safe directive for updated clients. Takes precedence over nextAction. |
| hint | string | – | What to do next, when there is a next step. |
| nextAction | string | – | Backward-compatible next step for older clients. Follow handoffAction first when present. |
| note | string | – | Free text the user added alongside their answer. |
| status | string | yes | The actual question state. Only pending is a live unanswered wait. |
| value | string | – | The user's answer: "yes" or "no" for confirm, the chosen option for select, the typed text for input. Present only when answered is true. |
No examples provided.
What is the Pushary MCP server?
Pushary is an MCP server listed in the public MCP registry as io.github.Pushary/pushary. Reach a human from a running agent. Approvals on the lock screen, plus a cross-agent audit trail. This page covers its hosted endpoint (https://pushary.com/api/mcp/mcp).
Is the Pushary MCP server safe to use?
Pushary scores 93 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Pushary MCP server expose?
Pushary exposes 5 tools: send_notification, ask_user, propose_scope, wait_for_answer, cancel_question. Their descriptions and schemas cost roughly 3,030 tokens of context every time the server is loaded.
Does the Pushary MCP server require authentication?
Yes. Pushary asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the Pushary MCP server still maintained?
Pushary is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.