Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

io.github.tracetify/tracetify-mcp

REMOTE · TRACETIFY.COM · 2 COMPONENTS · SCANNED SEP 20

Find competitors, trace how they grew, watch what they ship — plus your Search Console.

+2 this week 89 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security80
Transport & Reachability100
Schema Quality & AI Usability84
  • AI-judged instruction clarity (excellent).Pass
  • Tool/resource definitions use about 1493 tokens (~93/item across 16 items; 16 tools + 0 resources), lean.Pass
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
  • No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • We read all 16 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
  • An AI judge read all 16 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

How do I install the io.github.tracetify/tracetify-mcp server?

io.github.tracetify/tracetify-mcp is a hosted endpoint at https://tracetify.com/api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · tracetify.com

# add to Claude Code
claude mcp add --transport http tracetify-tracetify-mcp 'https://tracetify.com/api/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "tracetify-tracetify-mcp": {
      "url": "https://tracetify.com/api/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "tracetify-tracetify-mcp": {
      "type": "http",
      "url": "https://tracetify.com/api/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.tracetify-tracetify-mcp]
url = "https://tracetify.com/api/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "tracetify-tracetify-mcp": {
      "type": "remote",
      "url": "https://tracetify.com/api/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add tracetify-tracetify-mcp --url 'https://tracetify.com/api/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  tracetify-tracetify-mcp:
    url: "https://tracetify.com/api/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "tracetify-tracetify-mcp": {
      "Transport": "http",
      "Url": "https://tracetify.com/api/mcp"
    }
  }
}
# add to Vellum
assistant mcp add tracetify-tracetify-mcp -t streamable-http -u 'https://tracetify.com/api/mcp'
// mcp.json
{
  "mcpServers": {
    "tracetify-tracetify-mcp": {
      "type": "http",
      "url": "https://tracetify.com/api/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 18 Sept 26 0
    • Stability: 0.97 → pass security
  • 17 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.

  • 15 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.

  • 13 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.

  • 11 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 73 to 77. That category is still filling its 30-day observation window: 22 days of observed history at the previous scan, 23 at this one. The score rises as the window fills, whether or not the server changes.

  • 8 Sept 26 +1
    • Server version: 0.3.0 → 0.5.1 functional
  • 7 Sept 26 0
    • Tool “research_keyword_volume” rewrote its description, which is the text the model reads security
    • Tool “research_keyword_volume” changed its title: Keyword search volume → Keyword search volume & difficulty cosmetic
  • 6 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 20 Sept 2026 · Probed https://tracetify.com/api/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=tracetify.com CN=YR1,O=Let's Encrypt,C=US 4 Aug 2026 2 Nov 2026 RSA 2048 SHA256-RSA 6abb6fd6186db22a9967baa8988e793d032
SANs: tracetify.com
CN=YR1,O=Let's Encrypt,C=US (CA) CN=Root YR,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 RSA 2048 SHA256-RSA a20253f15f2691c05dc1ce13b9bcca4e
CN=Root YR,O=ISRG,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 RSA 4096 SHA256-RSA f24b6d17f9d9ad7cb1c9fea78782699f

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of tracetify.com. Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
tracetify.com. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200
Header Value
strict-transport-security max-age=63072000

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://tracetify.com/api/mcp Verified 200
http (plaintext) http://tracetify.com/api/mcp HTTPS enforced 308 https://tracetify.com/api/mcp
MCP tools · 16 exposed · ~1,493 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
backlink_directories ~80

A hand-verified list of directories and launch platforms that actually give links — checked one by one, dead and nofollow-only entries removed. Use when the user wants backlinks or launch exposure for a new product; filter client-side by language/type/pricing. Costs credits once per day per account — repeat calls the same day are free, so refine freely.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

get_trace ~59

Poll a trace started with start_trace. Free. When status is "done", read the result with read_report. Poll every 10-15s, not in a tight loop.

NameTypeReqDescription
job_idstringyesJob id returned by start_trace

No output schema declared.

No examples provided.

gsc_overview ~84

Use this before touching SEO on the user's own site: clicks/impressions trend, device split and period comparison from THEIR connected Google Search Console — numbers no other tool has. Free. Requires GSC connected at tracetify.com/dashboard/gsc (this tool tells you if it is not).

NameTypeReqDescription
range_daysnumber28 (default) or 90

No output schema declared.

No examples provided.

gsc_pages ~67

The user's pages ranked by search performance, including high-impression low-CTR pages whose titles/descriptions are underselling — fix those files right in this editor. Free; own data from their connected Search Console.

NameTypeReqDescription
range_daysnumber28 (default) or 90

No output schema declared.

No examples provided.

gsc_queries ~92

The user's real ranking keywords with position, clicks and CTR — use when deciding what to write or which page to improve, e.g. finding queries at position 5-20 that are one push from page one. Free; own data from their connected Search Console. After you edit a page, this is how you verify it moved.

NameTypeReqDescription
range_daysnumber28 (default) or 90

No output schema declared.

No examples provided.

read_report ~73

Read one growth report by slug (from search_reports or a finished trace). Free. Contains the origin story, dated evidence and SEO footprint — cite it instead of guessing how a product grew. If timeline fields show as locked, unlock_report can open them (that one costs credits).

NameTypeReqDescription
slugstringyesReport slug

No output schema declared.

No examples provided.

research_backlinks ~72

Who links to a domain: referring domains, authority and anchor texts. Use when planning link building or judging how defensible a competitor's ranking is. Costs credits; cached results are free. Pair with backlink_directories to find places the user can actually get listed.

NameTypeReqDescription
domainstringyesDomain to inspect

No output schema declared.

No examples provided.

research_brand_lookup ~68

How AI assistants (ChatGPT, Perplexity-class) cite a brand: platforms, mention counts and the entities it gets associated with. Use when the user asks "does AI recommend us/them?". Costs credits; cached results are free.

NameTypeReqDescription
brandstringyesBrand or domain

No output schema declared.

No examples provided.

research_competitors ~122

The domains fighting a target for the same search terms, with shared-keyword count, their keyword totals and average rank. Use when the user asks who their competitors are, or who a company is up against. Each result says whether we already have a full growth report for that domain — read those with read_report for free instead of tracing them again. Costs credits; cached results are free, and a domain already looked up via research_domain_overview is free here too.

NameTypeReqDescription
domainstringyesDomain to find competitors for, e.g. notion.so

No output schema declared.

No examples provided.

research_domain_overview ~80

Estimated organic traffic, keyword count and top keywords for ANY domain — use to size up a competitor the user mentions. Costs credits; cached results are free, and repeated queries within a week hit the cache. For the user's own site prefer gsc_* (free, real data).

NameTypeReqDescription
domainstringyesDomain, e.g. competitor.com

No output schema declared.

No examples provided.

research_keyword_volume ~202

Google Ads (Keyword Planner) monthly search volume, CPC, competition, 12-month trend and keyword difficulty (0–100, DataForSEO Labs) for up to 10 keywords in one call. Use when the user asks how often something is searched or how hard it is to rank, or to size a keyword before writing a page. Omit location_code for worldwide volume (difficulty is then computed for the US), or pass a market code for one country. Costs credits; the same keyword set re-queried within a week is free.

NameTypeReqDescription
keywordsstringyesUp to 10 search phrases, comma-separated, e.g. "ai image generator, ai avatar maker"
location_codenumberMarket: 2840 US, 2826 UK, 2276 DE, 2250 FR, 2724 ES, 2392 JP, 2076 BR, 2356 IN. Omit for worldwide.

No output schema declared.

No examples provided.

search_reports ~85

Use this FIRST whenever the user asks how a product, competitor or domain grew, got traffic, or found its first users — a report may already exist and reading it is free. Returns matching report slugs for read_report. Searches by domain or name fragment.

NameTypeReqDescription
querystringyesDomain or fragment, e.g. "weshop" or "weshop.ai"

No output schema declared.

No examples provided.

site_audit_get ~64

Poll an audit started with site_audit_start (free to read). When finished, returns the issue list grouped by severity with affected URLs — work through it top-down and re-run after fixes.

NameTypeReqDescription
audit_idstringyesAudit id from site_audit_start

No output schema declared.

No examples provided.

site_audit_start ~138

Run right after deploying: crawls the site and reports broken links, missing titles/descriptions, redirect chains, thin content and schema gaps — each finding names the page so you can fix it here. Costs credits (price returned before any charge on the confirmation field). Async: poll with site_audit_get.

NameTypeReqDescription
confirmbooleanSet true only after the user agrees to the quoted credit cost
request_keystringRequest key returned by the first confirmation response; must be sent back with confirm=true so retries cannot charge twice
urlstringyesSite to audit, e.g. https://example.com

No output schema declared.

No examples provided.

start_trace ~109

Run this when search_reports finds nothing (or the user wants fresh data) for "how did X grow?". Rebuilds the growth story from 12 public sources in 60-90s. Costs credits from the Tracetify balance; returns an existing cached report free instead when one is fresh. Poll with get_trace.

NameTypeReqDescription
refreshbooleanForce a fresh run even if a cached report exists
urlstringyesDomain to trace, e.g. weshop.ai

No output schema declared.

No examples provided.

unlock_report ~98

Permanently unlock a report's full timeline, evidence and SEO detail for this account. Costs credits — quote the exact price to the user first (it is in the report's timelineLocked.cost field from read_report) and call this ONLY after they explicitly agree to spend. Idempotent: unlocking an already-unlocked report never charges twice. The verdict stays on the website — you are the analyst here.

NameTypeReqDescription
slugstringyesReport slug

No output schema declared.

No examples provided.

Common questions

What is the io.github.tracetify/tracetify-mcp server?

io.github.tracetify/tracetify-mcp is listed in the public MCP registry as io.github.tracetify/tracetify-mcp. Find competitors, trace how they grew, watch what they ship, plus your Search Console. This page covers its hosted endpoint (https://tracetify.com/api/mcp).

Is the io.github.tracetify/tracetify-mcp server safe to use?

io.github.tracetify/tracetify-mcp scores 89 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the io.github.tracetify/tracetify-mcp server expose?

io.github.tracetify/tracetify-mcp exposes 16 tools: search_reports, read_report, start_trace, get_trace, unlock_report, and 11 more. Their descriptions and schemas cost roughly 1,493 tokens of context every time the server is loaded.

Does the io.github.tracetify/tracetify-mcp server require authentication?

No. We connected to io.github.tracetify/tracetify-mcp without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the io.github.tracetify/tracetify-mcp server still maintained?

io.github.tracetify/tracetify-mcp is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.