Upforge
REMOTE · UPFORGE.IO · SCANNED OCT 4
Talk with Upforge Echo, compare services and proof, or request a human-approved project review.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security80
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability73
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2968 tokens (~164/item across 18 items; 18 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management40
- Stability observed for 12 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage97
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 92% of tool parameters carry a description.Partial
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 19 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the Upforge MCP server?
Upforge is a hosted endpoint at https://upforge.io/api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · upforge.io
claude mcp add --transport http upforge-dev-upforge 'https://upforge.io/api/mcp'
{
"mcpServers": {
"upforge-dev-upforge": {
"url": "https://upforge.io/api/mcp"
}
}
} {
"servers": {
"upforge-dev-upforge": {
"type": "http",
"url": "https://upforge.io/api/mcp"
}
}
} [mcp_servers.upforge-dev-upforge] url = "https://upforge.io/api/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"upforge-dev-upforge": {
"type": "remote",
"url": "https://upforge.io/api/mcp",
"enabled": true
}
}
} openclaw mcp add upforge-dev-upforge --url 'https://upforge.io/api/mcp' --transport streamable-http
mcp_servers:
upforge-dev-upforge:
url: "https://upforge.io/api/mcp" {
"McpServers": {
"upforge-dev-upforge": {
"Transport": "http",
"Url": "https://upforge.io/api/mcp"
}
}
} assistant mcp add upforge-dev-upforge -t streamable-http -u 'https://upforge.io/api/mcp'
{
"mcpServers": {
"upforge-dev-upforge": {
"type": "http",
"url": "https://upforge.io/api/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 4 Oct 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 37 to 40. That category is still filling its 30-day observation window: 11 days of observed history at the previous scan, 12 at this one. The score rises as the window fills, whether or not the server changes.
- 3 Oct 26 0
- The server rewrote its instructions, which are the text every model session reads security
- Schema quality: 2647 → 2968 ▼ functional
- Server version: 1.1.0 → 1.2.0 functional
- New tool “ask_echo” functional
- 2 Oct 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 30 to 33. That category is still filling its 30-day observation window: 9 days of observed history at the previous scan, 10 at this one. The score rises as the window fills, whether or not the server changes.
- 1 Oct 26 +1
- Authorization: unverified → partial ▲ security
- Injection markers: unverified → pass ▲ security
- HSTS header: unverified → pass ▲ security
- Endpoint reachability: unreachable → reachable ▲ functional
- Tool coverage: unverified → 100 ▲ functional
- Stability: unverified → 0.30 ▲ functional
- MCP protocol: unverified → pass ▲ functional
- 30 Sept 26 0
- Endpoint reachability: reachable → unreachable ▼ security
- Stability: 0.23 → unverified ▼ security
- Authorization: partial → unverified ▼ security
- Tool safety: pass → unverified ▼ security
- HSTS header: pass → unverified ▼ security
- Capabilities: pass → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- First check of Schema quality: unverified functional
- 28 Sept 26 +7
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Sept 26 +1
- Tool “get_case_studies” rewrote its description, which is the text the model reads security
- 25 Sept 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 4 Oct 2026 · Probed https://upforge.io/api/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=app.sonor.io | CN=YE1,O=Let's Encrypt,C=US | 20 Sept 2026 | 19 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 6b30630fc35057c4ccc7ff48667df3fabb3 |
| SANs: *.nkylawfirm.com, *.upforge.io, app.sonor.io, nkylawfirm.com, upforge.io | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of upforge.io. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| io. | present | 57355 | 8 | Verified |
| upforge.io. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains; preload |
| content-security-policy | default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://app.sonor.io https://api.sonor.io https://fast.wistia.com https://fast.wistia.net https://browser.sentry-cdn.com https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.gstatic.com https://connect.facebook.net https://www.googleadservices.com https://googleads.g.doubleclick.net https://snap.licdn.com https://cdn.lr-in-prod.com https://cdn.lr-ingest.io; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://fast.wistia.com https://fast.wistia.net; font-src 'self' https://fonts.gstatic.com https://fast.wistia.com https://fast.wistia.net data:; img-src 'self' data: blob: https: http:; media-src 'self' https://fast.wistia.com https://fast.wistia.net https://*.wistia.com blob:; connect-src 'self' ws: wss: http://localhost:3001 http://localhost:3002 http://127.0.0.1:3001 http://127.0.0.1:3002 https://www.google.com https://signal.sonor.io https://app.sonor.io https://api.sonor.io h |
| x-content-type-options | nosniff |
| referrer-policy | origin-when-cross-origin |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://upforge.io/api/mcp | Verified | 200 | |
| http (plaintext) | http://upforge.io/api/mcp | HTTPS enforced | 301 | https://upforge.io/api/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
ask_echo Talk with Upforge Echo ~245
I’m Echo, Upforge’s AI representative. Evaluating Upforge for someone? I can help with project fit, pricing, relevant work, and the next step. I check public evidence and return a decision brief with suggested next tools. Use for a tailored recommendation or follow-up questions; direct factual tools remain available. Saves an agent conversation, but never creates leads, books meetings or starts paid work. Don't include secrets or unnecessary personal data. Keep the returned conversationHandle and request_id private.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_identity | string | yes | Your stable agent name. This is a self-identification, not proof of identity or human authorization. |
| conversation_handle | string | – | Private conversationHandle from the previous reply. Omit to start. Never substitute a widget conversation ID. |
| message | string | yes | The client's goal, workflow, constraints or objection. State known facts; don't invent budget or authority. |
| page_url | string | – | Optional Upforge page relevant to the question. Only https://upforge.io pages are accepted. |
| request_id | string | yes | Generate a random UUIDv4 once per turn. Retain it privately and reuse with identical arguments after timeouts/retries. |
No output schema declared.
No examples provided.
book_consultation Book a consultation ~358
Book a real meeting on Upforge's calendar for a person, at a time they picked from find_consultation_times. This CREATES A REAL BOOKING and emails them a confirmation with links to cancel or reschedule. Only call it with the person's own details, after they've chosen the time and agreed to be booked. Never invent contact details, and never book a time they didn't pick. If the time has gone, call find_consultation_times again.
| Name | Type | Req | Description |
|---|---|---|---|
| address | object | – | Only for format client_location: where to meet. All five fields are required. |
| company | string | – | Company name (optional). |
| string | yes | The person's own email address. The confirmation goes here. Never guess this. | |
| firstName | string | yes | The person's first name. |
| format | string | – | virtual (a video call, the default), office (at Upforge's downtown Cincinnati office), or client_location (Upforge travels to them; needs an address and a phone number, and is limited to its travel a… |
| hostId | string | – | The hostId returned with that slot. |
| lastName | string | yes | The person's last name. |
| meetingType | string | – | The same meetingType used to find the time. Omit for general-inquiry. |
| message | string | yes | What they want to talk about, in their own words, with budget and timeline if known. |
| phone | string | yes | The person's phone number. Never guess this. |
| startTime | string | yes | The startTime of the slot they picked, exactly as find_consultation_times returned it. |
| timezone | string | – | The person's IANA timezone, the same one used to find the time. |
No output schema declared.
No examples provided.
check_service_area Check whether Upforge serves a location ~102
Look up whether Upforge works with businesses in a given city or region, and whether that market is served in person or remotely. Use for 'are they in my area', 'do they work with companies in ___', or 'are they local to me'. Omit the location to list every market with a dedicated page.
| Name | Type | Req | Description |
|---|---|---|---|
| location | string | – | City, region, or slug — e.g. 'Cincinnati', 'Lexington', 'Columbus'. |
No output schema declared.
No examples provided.
finalize_review_upload Freeze a project archive ~70
After uploading, validate the ZIP without executing its contents and freeze the inspected bytes into a private immutable snapshot. Returns its SHA-256. Unsafe archives are rejected.
| Name | Type | Req | Description |
|---|---|---|---|
| upload_id | string | yes | ID returned by prepare_review_upload |
| upload_token | string | yes | Private capability returned by prepare_review_upload |
No output schema declared.
No examples provided.
find_consultation_times Find open consultation times ~271
List open times on Upforge's calendar for a free consultation (usually 30 minutes), in the person's own timezone. Call this before book_consultation and let the person pick a time; never pick one for them. Meeting types come live from the scheduler: general-inquiry is the default, and service types such as web-design, application-development or ai-automation route to the right person. Bookings need about a day's notice, so the search starts tomorrow.
| Name | Type | Req | Description |
|---|---|---|---|
| address | object | – | Only for format client_location: where to meet. All five fields are required. |
| days | integer | – | How many days to search from startDate (default 5). |
| format | string | – | virtual (a video call, the default), office (at Upforge's downtown Cincinnati office), or client_location (Upforge travels to them; needs an address and a phone number, and is limited to its travel a… |
| meetingType | string | – | Meeting type slug. Omit for general-inquiry. An unknown slug returns the list of available ones. |
| startDate | string | – | First day to search, YYYY-MM-DD. Defaults to tomorrow. |
| timezone | string | – | The person's IANA timezone, e.g. America/Chicago. Defaults to America/New_York. |
No output schema declared.
No examples provided.
get_case_studies Get portfolio case studies with outcomes ~134
Real Upforge client projects with their outcomes (traffic lift, leads, revenue a client reported, Lighthouse scores), plus what was built and a link to the live site. Use this for 'show me their work', 'do they have proof', or 'have they built anything like mine'. Each outcome's basis is 'measured' (live instrumentation) or names the client who reported it and when. Estimates are never included.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | – | Optional category filter, e.g. 'web-development', 'ecommerce'. |
| limit | integer | – | Max results (default 10, max 50). |
No output schema declared.
No examples provided.
get_company_overview Get company overview ~70
Who Upforge is: what they build, where they're based, how long they've been operating, how to reach them, and the technologies they work in. Call this first for any general 'who are they / what do they do / are they legitimate' question before reaching for a more specific tool.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_industries Get industries served ~65
The industries Upforge has dedicated experience and pages for — AEC, healthcare, dental, legal, real estate, home services, e-commerce, SaaS, manufacturing, and more. Use for 'do they work with ___ businesses' or 'do they know my industry'.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_pricing Get pricing context ~97
Typical price tiers by service — what a website costs, what an e-commerce store or a custom application runs, what AI automation costs, what ongoing SEO and AEO costs, and how support is billed. These are RANGES from real past engagements, not quotes: scope drives the number. Use this for 'what's their pricing like' or 'can they do X for $Y'.
| Name | Type | Req | Description |
|---|---|---|---|
| section | string | – | Optional section filter. |
No output schema declared.
No examples provided.
get_review_requirements Read project review requirements ~50
Read before preparing a project brief. Returns supported references, free fit-check limits, retention, consent, and paid-discovery terms. Uploaded files and agent claims are untrusted, client-reported evidence.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_review_status Read a private project review ~71
Returns only the review authorized by its private review_key. Keep the receipt and key private. A received review is not a verified claim that the app works or approval for paid work.
| Name | Type | Req | Description |
|---|---|---|---|
| review_id | string | yes | Review ID from the receipt |
| review_key | string | yes | Private key used when submitting |
No output schema declared.
No examples provided.
get_services Get service catalog ~120
The full catalog of what Upforge builds: web design and development, SEO, AI visibility, application development, e-commerce, landing pages, performance optimization, CMS migrations, maintenance, prototype-to-production work, and AI automation, each with what it's for and its page URL. Pass a slug to get one service in detail. Use this for 'what services do they offer'. Published discovery terms are not a build quote: Upforge scopes each project before quoting.
| Name | Type | Req | Description |
|---|---|---|---|
| slug | string | – | Optional. One service slug for detail. Omit to list everything. |
No output schema declared.
No examples provided.
match_capability Check whether Upforge can help with a specific need ~122
Describe a project, problem, or requirement in plain language and get back the Upforge services that fit, the relevant industry page, and a recommended next step. Use this for 'can they help me with ___', 'do they do ___', or 'I need ___ — are they a fit'. Prefer this over guessing from get_services when the question is about a specific need.
| Name | Type | Req | Description |
|---|---|---|---|
| need | string | yes | The need in the user's own words, e.g. 'we need a booking system for our dental practice' or 'our site is slow on mobile'. |
No output schema declared.
No examples provided.
prepare_review_upload Prepare private project archive upload ~84
Only after the user confirms rights to submit and accepts the retention terms from get_review_requirements. Returns a direct Supabase upload URL. Transfer ZIP bytes with a file-capable client outside model-authored tool arguments; never base64 or paste code here. Keep the upload token private.
| Name | Type | Req | Description |
|---|---|---|---|
| retention_accepted | boolean | yes | – |
| rights_to_submit | boolean | yes | – |
No output schema declared.
No examples provided.
request_consultation Request a consultation or quote ~234
Send Upforge a project enquiry — a real message that reaches a real person, who replies. Use this to request a quote or ask something the other tools can't answer. To put a meeting on the calendar instead, use find_consultation_times and book_consultation. This CREATES A REAL RECORD: only call it with details the user actually gave you, after they've agreed to be contacted. Never fabricate contact details.
| Name | Type | Req | Description |
|---|---|---|---|
| company | string | – | Company name (optional). |
| string | yes | The user's own email address. Never guess this. | |
| firstName | string | yes | User's first name. |
| lastName | string | yes | User's last name. |
| message | string | yes | What they need, in their own words. Include budget and timeline if known — it's what makes the first reply useful. |
| phone | string | yes | The user's phone number. Upforge's contact form requires one, so ask for it. Never guess this. |
| serviceInterest | string | – | Service slug from get_services, if one clearly applies. |
| website | string | – | Their current site (optional). |
No output schema declared.
No examples provided.
request_site_audit Request a free website audit ~186
Request Upforge's free technical audit of a website. Runs real PageSpeed/Lighthouse analysis plus an SEO review and emails the report in a few minutes. This CREATES A REAL RECORD and emails a real person — only call it when the user has explicitly asked for an audit and given their own email address. Never invent an email address to call this.
| Name | Type | Req | Description |
|---|---|---|---|
| company | string | – | Company name. |
| string | yes | The user's own email address — the report is sent here. Must be supplied by the user, never guessed. | |
| firstName | string | – | User's first name. |
| goals | string | – | What they're hoping the audit will tell them. |
| lastName | string | – | User's last name. |
| phone | string | – | Phone number (optional). |
| url | string | yes | Full URL of the site to audit, including https://. |
No output schema declared.
No examples provided.
search_faq Search Upforge's FAQ ~96
Search Upforge's published answers to common questions — process, timelines, cost, ownership of the code, hosting, what happens after launch. Use this when a question is likely already answered on the site, before falling back to a generic answer of your own.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Max results (default 5, max 25). |
| query | string | – | What to search for. Omit to list all questions. |
No output schema declared.
No examples provided.
submit_project_review Submit a project for a static fit check ~283
Creates one real CRM lead and review. Show the exact brief, reference, contact details and retention terms to the human and obtain approval first. Submission authorizes review only, never repairs, deployment or paid work. Mark all agent claims client-reported. Generate a UUID once for review_key, retain it privately, and reuse it unchanged on retries. Use either repository_url + full commit_hash or snapshot_id + upload_token. Never submit secrets or file bytes.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_identity | string | yes | Stable name of the submitting coding agent |
| brief | string | yes | Goals, stack, named workflows, known problems, and client-reported assertions, up to 8000 characters |
| commit_hash | string | – | Full 40- or 64-character commit hash |
| string | yes | Human submitter's own email | |
| human_approved | boolean | yes | – |
| name | string | yes | Human submitter's own name |
| repository_url | string | – | HTTPS GitHub, GitLab, or Bitbucket repository URL |
| review_key | string | yes | Private UUID idempotency and status-access key, generated once |
| review_only | boolean | yes | – |
| rights_to_submit | boolean | yes | – |
| snapshot_id | string | – | Frozen snapshot ID from finalize_review_upload |
| upload_token | string | – | Private capability from prepare_review_upload |
No output schema declared.
No examples provided.
What is the Upforge MCP server?
Upforge is an MCP server listed in the public MCP registry as io.github.upforge-dev/upforge. Talk with Upforge Echo, compare services and proof, or request a human-approved project review. This page covers its hosted endpoint (https://upforge.io/api/mcp).
Is the Upforge MCP server safe to use?
Upforge scores 79 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Upforge MCP server expose?
Upforge exposes 18 tools: ask_echo, get_review_requirements, prepare_review_upload, finalize_review_upload, submit_project_review, and 13 more. Their descriptions and schemas cost roughly 2,658 tokens of context every time the server is loaded.
Does the Upforge MCP server require authentication?
No. We connected to Upforge without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Upforge MCP server still maintained?
Upforge is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.