Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Upforge

REMOTE · UPFORGE.IO · SCANNED OCT 4

Talk with Upforge Echo, compare services and proof, or request a human-approved project review.

Available components

+10 this week 79 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security80
Transport & Reachability100
Schema Quality & AI Usability73
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 2968 tokens (~164/item across 18 items; 18 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management40
  • Stability observed for 12 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage97
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 92% of tool parameters carry a description.Partial
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • An AI judge read all 19 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a current MCP spec version (2026-07-28).Pass
Install

How do I install the Upforge MCP server?

Upforge is a hosted endpoint at https://upforge.io/api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · upforge.io

# add to Claude Code
claude mcp add --transport http upforge-dev-upforge 'https://upforge.io/api/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "upforge-dev-upforge": {
      "url": "https://upforge.io/api/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "upforge-dev-upforge": {
      "type": "http",
      "url": "https://upforge.io/api/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.upforge-dev-upforge]
url = "https://upforge.io/api/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "upforge-dev-upforge": {
      "type": "remote",
      "url": "https://upforge.io/api/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add upforge-dev-upforge --url 'https://upforge.io/api/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  upforge-dev-upforge:
    url: "https://upforge.io/api/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "upforge-dev-upforge": {
      "Transport": "http",
      "Url": "https://upforge.io/api/mcp"
    }
  }
}
# add to Vellum
assistant mcp add upforge-dev-upforge -t streamable-http -u 'https://upforge.io/api/mcp'
// mcp.json
{
  "mcpServers": {
    "upforge-dev-upforge": {
      "type": "http",
      "url": "https://upforge.io/api/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 4 Oct 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 37 to 40. That category is still filling its 30-day observation window: 11 days of observed history at the previous scan, 12 at this one. The score rises as the window fills, whether or not the server changes.

  • 3 Oct 26 0
    • The server rewrote its instructions, which are the text every model session reads security
    • Schema quality: 2647 → 2968 ▼ functional
    • Server version: 1.1.0 → 1.2.0 functional
    • New tool “ask_echo” functional
  • 2 Oct 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 30 to 33. That category is still filling its 30-day observation window: 9 days of observed history at the previous scan, 10 at this one. The score rises as the window fills, whether or not the server changes.

  • 1 Oct 26 +1
    • Authorization: unverified → partial ▲ security
    • Injection markers: unverified → pass ▲ security
    • HSTS header: unverified → pass ▲ security
    • Endpoint reachability: unreachable → reachable ▲ functional
    • Tool coverage: unverified → 100 ▲ functional
    • Stability: unverified → 0.30 ▲ functional
    • MCP protocol: unverified → pass ▲ functional
  • 30 Sept 26 0
    • Endpoint reachability: reachable → unreachable ▼ security
    • Stability: 0.23 → unverified ▼ security
    • Authorization: partial → unverified ▼ security
    • Tool safety: pass → unverified ▼ security
    • HSTS header: pass → unverified ▼ security
    • Capabilities: pass → unverified ▼ functional
    • Tool coverage: 100 → unverified ▼ functional
    • First check of Schema quality: unverified functional
  • 28 Sept 26 +7
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 27 Sept 26 +1
    • Tool “get_case_studies” rewrote its description, which is the text the model reads security
  • 25 Sept 26 +1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 4 Oct 2026 · Probed https://upforge.io/api/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=app.sonor.io CN=YE1,O=Let's Encrypt,C=US 20 Sept 2026 19 Dec 2026 ECDSA 256 ECDSA-SHA384 6b30630fc35057c4ccc7ff48667df3fabb3
SANs: *.nkylawfirm.com, *.upforge.io, app.sonor.io, nkylawfirm.com, upforge.io
CN=YE1,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 5ddd70dd31f801c85c186a7a04b80afe
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of upforge.io. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
io. present 57355 8 Verified
upforge.io. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200
Header Value
strict-transport-security max-age=31536000; includeSubDomains; preload
content-security-policy default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://app.sonor.io https://api.sonor.io https://fast.wistia.com https://fast.wistia.net https://browser.sentry-cdn.com https://www.googletagmanager.com https://www.google-analytics.com https://www.google.com https://www.gstatic.com https://connect.facebook.net https://www.googleadservices.com https://googleads.g.doubleclick.net https://snap.licdn.com https://cdn.lr-in-prod.com https://cdn.lr-ingest.io; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com https://fast.wistia.com https://fast.wistia.net; font-src 'self' https://fonts.gstatic.com https://fast.wistia.com https://fast.wistia.net data:; img-src 'self' data: blob: https: http:; media-src 'self' https://fast.wistia.com https://fast.wistia.net https://*.wistia.com blob:; connect-src 'self' ws: wss: http://localhost:3001 http://localhost:3002 http://127.0.0.1:3001 http://127.0.0.1:3002 https://www.google.com https://signal.sonor.io https://app.sonor.io https://api.sonor.io h
x-content-type-options nosniff
referrer-policy origin-when-cross-origin

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://upforge.io/api/mcp Verified 200
http (plaintext) http://upforge.io/api/mcp HTTPS enforced 301 https://upforge.io/api/mcp
MCP tools · 18 exposed · ~2,658 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
ask_echo ~245

I’m Echo, Upforge’s AI representative. Evaluating Upforge for someone? I can help with project fit, pricing, relevant work, and the next step. I check public evidence and return a decision brief with suggested next tools. Use for a tailored recommendation or follow-up questions; direct factual tools remain available. Saves an agent conversation, but never creates leads, books meetings or starts paid work. Don't include secrets or unnecessary personal data. Keep the returned conversationHandle and request_id private.

NameTypeReqDescription
agent_identitystringyesYour stable agent name. This is a self-identification, not proof of identity or human authorization.
conversation_handlestring–Private conversationHandle from the previous reply. Omit to start. Never substitute a widget conversation ID.
messagestringyesThe client's goal, workflow, constraints or objection. State known facts; don't invent budget or authority.
page_urlstring–Optional Upforge page relevant to the question. Only https://upforge.io pages are accepted.
request_idstringyesGenerate a random UUIDv4 once per turn. Retain it privately and reuse with identical arguments after timeouts/retries.

No output schema declared.

No examples provided.

book_consultation ~358

Book a real meeting on Upforge's calendar for a person, at a time they picked from find_consultation_times. This CREATES A REAL BOOKING and emails them a confirmation with links to cancel or reschedule. Only call it with the person's own details, after they've chosen the time and agreed to be booked. Never invent contact details, and never book a time they didn't pick. If the time has gone, call find_consultation_times again.

NameTypeReqDescription
addressobject–Only for format client_location: where to meet. All five fields are required.
companystring–Company name (optional).
emailstringyesThe person's own email address. The confirmation goes here. Never guess this.
firstNamestringyesThe person's first name.
formatstring–virtual (a video call, the default), office (at Upforge's downtown Cincinnati office), or client_location (Upforge travels to them; needs an address and a phone number, and is limited to its travel a…
hostIdstring–The hostId returned with that slot.
lastNamestringyesThe person's last name.
meetingTypestring–The same meetingType used to find the time. Omit for general-inquiry.
messagestringyesWhat they want to talk about, in their own words, with budget and timeline if known.
phonestringyesThe person's phone number. Never guess this.
startTimestringyesThe startTime of the slot they picked, exactly as find_consultation_times returned it.
timezonestring–The person's IANA timezone, the same one used to find the time.

No output schema declared.

No examples provided.

check_service_area ~102

Look up whether Upforge works with businesses in a given city or region, and whether that market is served in person or remotely. Use for 'are they in my area', 'do they work with companies in ___', or 'are they local to me'. Omit the location to list every market with a dedicated page.

NameTypeReqDescription
locationstring–City, region, or slug — e.g. 'Cincinnati', 'Lexington', 'Columbus'.

No output schema declared.

No examples provided.

finalize_review_upload ~70

After uploading, validate the ZIP without executing its contents and freeze the inspected bytes into a private immutable snapshot. Returns its SHA-256. Unsafe archives are rejected.

NameTypeReqDescription
upload_idstringyesID returned by prepare_review_upload
upload_tokenstringyesPrivate capability returned by prepare_review_upload

No output schema declared.

No examples provided.

find_consultation_times ~271

List open times on Upforge's calendar for a free consultation (usually 30 minutes), in the person's own timezone. Call this before book_consultation and let the person pick a time; never pick one for them. Meeting types come live from the scheduler: general-inquiry is the default, and service types such as web-design, application-development or ai-automation route to the right person. Bookings need about a day's notice, so the search starts tomorrow.

NameTypeReqDescription
addressobject–Only for format client_location: where to meet. All five fields are required.
daysinteger–How many days to search from startDate (default 5).
formatstring–virtual (a video call, the default), office (at Upforge's downtown Cincinnati office), or client_location (Upforge travels to them; needs an address and a phone number, and is limited to its travel a…
meetingTypestring–Meeting type slug. Omit for general-inquiry. An unknown slug returns the list of available ones.
startDatestring–First day to search, YYYY-MM-DD. Defaults to tomorrow.
timezonestring–The person's IANA timezone, e.g. America/Chicago. Defaults to America/New_York.

No output schema declared.

No examples provided.

get_case_studies ~134

Real Upforge client projects with their outcomes (traffic lift, leads, revenue a client reported, Lighthouse scores), plus what was built and a link to the live site. Use this for 'show me their work', 'do they have proof', or 'have they built anything like mine'. Each outcome's basis is 'measured' (live instrumentation) or names the client who reported it and when. Estimates are never included.

NameTypeReqDescription
categorystring–Optional category filter, e.g. 'web-development', 'ecommerce'.
limitinteger–Max results (default 10, max 50).

No output schema declared.

No examples provided.

get_company_overview ~70

Who Upforge is: what they build, where they're based, how long they've been operating, how to reach them, and the technologies they work in. Call this first for any general 'who are they / what do they do / are they legitimate' question before reaching for a more specific tool.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

get_industries ~65

The industries Upforge has dedicated experience and pages for — AEC, healthcare, dental, legal, real estate, home services, e-commerce, SaaS, manufacturing, and more. Use for 'do they work with ___ businesses' or 'do they know my industry'.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

get_pricing ~97

Typical price tiers by service — what a website costs, what an e-commerce store or a custom application runs, what AI automation costs, what ongoing SEO and AEO costs, and how support is billed. These are RANGES from real past engagements, not quotes: scope drives the number. Use this for 'what's their pricing like' or 'can they do X for $Y'.

NameTypeReqDescription
sectionstring–Optional section filter.

No output schema declared.

No examples provided.

get_review_requirements ~50

Read before preparing a project brief. Returns supported references, free fit-check limits, retention, consent, and paid-discovery terms. Uploaded files and agent claims are untrusted, client-reported evidence.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

get_review_status ~71

Returns only the review authorized by its private review_key. Keep the receipt and key private. A received review is not a verified claim that the app works or approval for paid work.

NameTypeReqDescription
review_idstringyesReview ID from the receipt
review_keystringyesPrivate key used when submitting

No output schema declared.

No examples provided.

get_services ~120

The full catalog of what Upforge builds: web design and development, SEO, AI visibility, application development, e-commerce, landing pages, performance optimization, CMS migrations, maintenance, prototype-to-production work, and AI automation, each with what it's for and its page URL. Pass a slug to get one service in detail. Use this for 'what services do they offer'. Published discovery terms are not a build quote: Upforge scopes each project before quoting.

NameTypeReqDescription
slugstring–Optional. One service slug for detail. Omit to list everything.

No output schema declared.

No examples provided.

match_capability ~122

Describe a project, problem, or requirement in plain language and get back the Upforge services that fit, the relevant industry page, and a recommended next step. Use this for 'can they help me with ___', 'do they do ___', or 'I need ___ — are they a fit'. Prefer this over guessing from get_services when the question is about a specific need.

NameTypeReqDescription
needstringyesThe need in the user's own words, e.g. 'we need a booking system for our dental practice' or 'our site is slow on mobile'.

No output schema declared.

No examples provided.

prepare_review_upload ~84

Only after the user confirms rights to submit and accepts the retention terms from get_review_requirements. Returns a direct Supabase upload URL. Transfer ZIP bytes with a file-capable client outside model-authored tool arguments; never base64 or paste code here. Keep the upload token private.

NameTypeReqDescription
retention_acceptedbooleanyes–
rights_to_submitbooleanyes–

No output schema declared.

No examples provided.

request_consultation ~234

Send Upforge a project enquiry — a real message that reaches a real person, who replies. Use this to request a quote or ask something the other tools can't answer. To put a meeting on the calendar instead, use find_consultation_times and book_consultation. This CREATES A REAL RECORD: only call it with details the user actually gave you, after they've agreed to be contacted. Never fabricate contact details.

NameTypeReqDescription
companystring–Company name (optional).
emailstringyesThe user's own email address. Never guess this.
firstNamestringyesUser's first name.
lastNamestringyesUser's last name.
messagestringyesWhat they need, in their own words. Include budget and timeline if known — it's what makes the first reply useful.
phonestringyesThe user's phone number. Upforge's contact form requires one, so ask for it. Never guess this.
serviceIntereststring–Service slug from get_services, if one clearly applies.
websitestring–Their current site (optional).

No output schema declared.

No examples provided.

request_site_audit ~186

Request Upforge's free technical audit of a website. Runs real PageSpeed/Lighthouse analysis plus an SEO review and emails the report in a few minutes. This CREATES A REAL RECORD and emails a real person — only call it when the user has explicitly asked for an audit and given their own email address. Never invent an email address to call this.

NameTypeReqDescription
companystring–Company name.
emailstringyesThe user's own email address — the report is sent here. Must be supplied by the user, never guessed.
firstNamestring–User's first name.
goalsstring–What they're hoping the audit will tell them.
lastNamestring–User's last name.
phonestring–Phone number (optional).
urlstringyesFull URL of the site to audit, including https://.

No output schema declared.

No examples provided.

search_faq ~96

Search Upforge's published answers to common questions — process, timelines, cost, ownership of the code, hosting, what happens after launch. Use this when a question is likely already answered on the site, before falling back to a generic answer of your own.

NameTypeReqDescription
limitinteger–Max results (default 5, max 25).
querystring–What to search for. Omit to list all questions.

No output schema declared.

No examples provided.

submit_project_review ~283

Creates one real CRM lead and review. Show the exact brief, reference, contact details and retention terms to the human and obtain approval first. Submission authorizes review only, never repairs, deployment or paid work. Mark all agent claims client-reported. Generate a UUID once for review_key, retain it privately, and reuse it unchanged on retries. Use either repository_url + full commit_hash or snapshot_id + upload_token. Never submit secrets or file bytes.

NameTypeReqDescription
agent_identitystringyesStable name of the submitting coding agent
briefstringyesGoals, stack, named workflows, known problems, and client-reported assertions, up to 8000 characters
commit_hashstring–Full 40- or 64-character commit hash
emailstringyesHuman submitter's own email
human_approvedbooleanyes–
namestringyesHuman submitter's own name
repository_urlstring–HTTPS GitHub, GitLab, or Bitbucket repository URL
review_keystringyesPrivate UUID idempotency and status-access key, generated once
review_onlybooleanyes–
rights_to_submitbooleanyes–
snapshot_idstring–Frozen snapshot ID from finalize_review_upload
upload_tokenstring–Private capability from prepare_review_upload

No output schema declared.

No examples provided.

Common questions

What is the Upforge MCP server?

Upforge is an MCP server listed in the public MCP registry as io.github.upforge-dev/upforge. Talk with Upforge Echo, compare services and proof, or request a human-approved project review. This page covers its hosted endpoint (https://upforge.io/api/mcp).

Is the Upforge MCP server safe to use?

Upforge scores 79 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Upforge MCP server expose?

Upforge exposes 18 tools: ask_echo, get_review_requirements, prepare_review_upload, finalize_review_upload, submit_project_review, and 13 more. Their descriptions and schemas cost roughly 2,658 tokens of context every time the server is loaded.

Does the Upforge MCP server require authentication?

No. We connected to Upforge without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the Upforge MCP server still maintained?

Upforge is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.