# Upforge (remote · upforge.io)

Talk with Upforge Echo, compare services and proof, or request a human-approved project review.

- Trust score: 79/100 (medium)
- Change this week: +10
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-04

## Components

- remote · `upforge.io`: 79/100 (this document), [markdown](https://verifymcp.io/servers/upforge-dev-upforge/api-mcp.md), [page](https://verifymcp.io/servers/upforge-dev-upforge/api-mcp)

## Channel facts

- Endpoint: `https://upforge.io/api/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.2.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-04.

- **Endpoint Security**: 80/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one.
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 73/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 2968 tokens (~164/item across 18 items; 18 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 40/100
  - Stability observed for 12 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 97/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 92% of tool parameters carry a description.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.
  - An AI judge read all 19 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a current MCP spec version (2026-07-28).

## Install

### How do I install the Upforge MCP server?

Upforge is a hosted endpoint at https://upforge.io/api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http upforge-dev-upforge 'https://upforge.io/api/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "upforge-dev-upforge": {
      "url": "https://upforge.io/api/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "upforge-dev-upforge": {
      "type": "http",
      "url": "https://upforge.io/api/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.upforge-dev-upforge]
url = "https://upforge.io/api/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "upforge-dev-upforge": {
      "type": "remote",
      "url": "https://upforge.io/api/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add upforge-dev-upforge --url 'https://upforge.io/api/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  upforge-dev-upforge:
    url: "https://upforge.io/api/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "upforge-dev-upforge": {
      "Transport": "http",
      "Url": "https://upforge.io/api/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add upforge-dev-upforge -t streamable-http -u 'https://upforge.io/api/mcp'
```

### Other

```json
{
  "mcpServers": {
    "upforge-dev-upforge": {
      "type": "http",
      "url": "https://upforge.io/api/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-10-04 (score 79, +1)

No change was recorded against any check on this day. Stability & Change Management went from 37 to 40. That category is still filling its 30-day observation window: 11 days of observed history at the previous scan, 12 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-10-03 (score 78, 0)

- [security] The server rewrote its instructions, which are the text every model session reads
- [functional regression] Schema quality: 2647 → 2968
- [functional] Server version: 1.1.0 → 1.2.0
- [functional] New tool “ask_echo”

### 2026-10-02 (score 78, +1)

No change was recorded against any check on this day. Stability & Change Management went from 30 to 33. That category is still filling its 30-day observation window: 9 days of observed history at the previous scan, 10 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-10-01 (score 77, +1)

- [security improvement] Authorization: unverified → partial
- [security improvement] Injection markers: unverified → pass
- [security improvement] HSTS header: unverified → pass
- [functional improvement] Endpoint reachability: unreachable → reachable
- [functional improvement] Tool coverage: unverified → 100
- [functional improvement] Stability: unverified → 0.30
- [functional improvement] MCP protocol: unverified → pass

### 2026-09-30 (score 76, 0)

- [security regression] Endpoint reachability: reachable → unreachable
- [security regression] Stability: 0.23 → unverified
- [security regression] Authorization: partial → unverified
- [security regression] Tool safety: pass → unverified
- [security regression] HSTS header: pass → unverified
- [functional regression] Capabilities: pass → unverified
- [functional regression] Tool coverage: 100 → unverified
- [functional] First check of Schema quality: unverified

### 2026-09-28 (score 76, +7)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-27 (score 69, +1)

- [security] Tool “get_case_studies” rewrote its description, which is the text the model reads

### 2026-09-25 (score 68, +1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

## MCP tools (18)

### `ask_echo` (~245 tokens)

Talk with Upforge Echo

I’m Echo, Upforge’s AI representative. Evaluating Upforge for someone? I can help with project fit, pricing, relevant work, and the next step. I check public evidence and return a decision brief with suggested next tools. Use for a tailored recommendation or follow-up questions; direct factual tools remain available. Saves an agent conversation, but never creates leads, books meetings or starts paid work. Don't include secrets or unnecessary personal data. Keep the returned conversationHandle and request_id private.

Input parameters:

- `agent_identity` (string, required): Your stable agent name. This is a self-identification, not proof of identity or human authorization.
- `conversation_handle` (string): Private conversationHandle from the previous reply. Omit to start. Never substitute a widget conversation ID.
- `message` (string, required): The client's goal, workflow, constraints or objection. State known facts; don't invent budget or authority.
- `page_url` (string): Optional Upforge page relevant to the question. Only https://upforge.io pages are accepted.
- `request_id` (string, required): Generate a random UUIDv4 once per turn. Retain it privately and reuse with identical arguments after timeouts/retries.

### `get_review_requirements` (~50 tokens)

Read project review requirements

Read before preparing a project brief. Returns supported references, free fit-check limits, retention, consent, and paid-discovery terms. Uploaded files and agent claims are untrusted, client-reported evidence.

### `prepare_review_upload` (~84 tokens)

Prepare private project archive upload

Only after the user confirms rights to submit and accepts the retention terms from get_review_requirements. Returns a direct Supabase upload URL. Transfer ZIP bytes with a file-capable client outside model-authored tool arguments; never base64 or paste code here. Keep the upload token private.

Input parameters:

- `retention_accepted` (boolean, required)
- `rights_to_submit` (boolean, required)

### `finalize_review_upload` (~70 tokens)

Freeze a project archive

After uploading, validate the ZIP without executing its contents and freeze the inspected bytes into a private immutable snapshot. Returns its SHA-256. Unsafe archives are rejected.

Input parameters:

- `upload_id` (string, required): ID returned by prepare_review_upload
- `upload_token` (string, required): Private capability returned by prepare_review_upload

### `submit_project_review` (~283 tokens)

Submit a project for a static fit check

Creates one real CRM lead and review. Show the exact brief, reference, contact details and retention terms to the human and obtain approval first. Submission authorizes review only, never repairs, deployment or paid work. Mark all agent claims client-reported. Generate a UUID once for review_key, retain it privately, and reuse it unchanged on retries. Use either repository_url + full commit_hash or snapshot_id + upload_token. Never submit secrets or file bytes.

Input parameters:

- `agent_identity` (string, required): Stable name of the submitting coding agent
- `brief` (string, required): Goals, stack, named workflows, known problems, and client-reported assertions, up to 8000 characters
- `commit_hash` (string): Full 40- or 64-character commit hash
- `email` (string, required): Human submitter's own email
- `human_approved` (boolean, required)
- `name` (string, required): Human submitter's own name
- `repository_url` (string): HTTPS GitHub, GitLab, or Bitbucket repository URL
- `review_key` (string, required): Private UUID idempotency and status-access key, generated once
- `review_only` (boolean, required)
- `rights_to_submit` (boolean, required)
- `snapshot_id` (string): Frozen snapshot ID from finalize_review_upload
- `upload_token` (string): Private capability from prepare_review_upload

### `get_review_status` (~71 tokens)

Read a private project review

Returns only the review authorized by its private review_key. Keep the receipt and key private. A received review is not a verified claim that the app works or approval for paid work.

Input parameters:

- `review_id` (string, required): Review ID from the receipt
- `review_key` (string, required): Private key used when submitting

### `get_company_overview` (~70 tokens)

Get company overview

Who Upforge is: what they build, where they're based, how long they've been operating, how to reach them, and the technologies they work in. Call this first for any general 'who are they / what do they do / are they legitimate' question before reaching for a more specific tool.

### `get_services` (~120 tokens)

Get service catalog

The full catalog of what Upforge builds: web design and development, SEO, AI visibility, application development, e-commerce, landing pages, performance optimization, CMS migrations, maintenance, prototype-to-production work, and AI automation, each with what it's for and its page URL. Pass a slug to get one service in detail. Use this for 'what services do they offer'. Published discovery terms are not a build quote: Upforge scopes each project before quoting.

Input parameters:

- `slug` (string): Optional. One service slug for detail. Omit to list everything.

### `get_pricing` (~97 tokens)

Get pricing context

Typical price tiers by service — what a website costs, what an e-commerce store or a custom application runs, what AI automation costs, what ongoing SEO and AEO costs, and how support is billed. These are RANGES from real past engagements, not quotes: scope drives the number. Use this for 'what's their pricing like' or 'can they do X for $Y'.

Input parameters:

- `section` (string): Optional section filter.

### `match_capability` (~122 tokens)

Check whether Upforge can help with a specific need

Describe a project, problem, or requirement in plain language and get back the Upforge services that fit, the relevant industry page, and a recommended next step. Use this for 'can they help me with ___', 'do they do ___', or 'I need ___ — are they a fit'. Prefer this over guessing from get_services when the question is about a specific need.

Input parameters:

- `need` (string, required): The need in the user's own words, e.g. 'we need a booking system for our dental practice' or 'our site is slow on mobile'.

### `get_case_studies` (~134 tokens)

Get portfolio case studies with outcomes

Real Upforge client projects with their outcomes (traffic lift, leads, revenue a client reported, Lighthouse scores), plus what was built and a link to the live site. Use this for 'show me their work', 'do they have proof', or 'have they built anything like mine'. Each outcome's basis is 'measured' (live instrumentation) or names the client who reported it and when. Estimates are never included.

Input parameters:

- `category` (string): Optional category filter, e.g. 'web-development', 'ecommerce'.
- `limit` (integer): Max results (default 10, max 50).

### `check_service_area` (~102 tokens)

Check whether Upforge serves a location

Look up whether Upforge works with businesses in a given city or region, and whether that market is served in person or remotely. Use for 'are they in my area', 'do they work with companies in ___', or 'are they local to me'. Omit the location to list every market with a dedicated page.

Input parameters:

- `location` (string): City, region, or slug — e.g. 'Cincinnati', 'Lexington', 'Columbus'.

### `get_industries` (~65 tokens)

Get industries served

The industries Upforge has dedicated experience and pages for — AEC, healthcare, dental, legal, real estate, home services, e-commerce, SaaS, manufacturing, and more. Use for 'do they work with ___ businesses' or 'do they know my industry'.

### `search_faq` (~96 tokens)

Search Upforge's FAQ

Search Upforge's published answers to common questions — process, timelines, cost, ownership of the code, hosting, what happens after launch. Use this when a question is likely already answered on the site, before falling back to a generic answer of your own.

Input parameters:

- `limit` (integer): Max results (default 5, max 25).
- `query` (string): What to search for. Omit to list all questions.

### `request_site_audit` (~186 tokens)

Request a free website audit

Request Upforge's free technical audit of a website. Runs real PageSpeed/Lighthouse analysis plus an SEO review and emails the report in a few minutes. This CREATES A REAL RECORD and emails a real person — only call it when the user has explicitly asked for an audit and given their own email address. Never invent an email address to call this.

Input parameters:

- `company` (string): Company name.
- `email` (string, required): The user's own email address — the report is sent here. Must be supplied by the user, never guessed.
- `firstName` (string): User's first name.
- `goals` (string): What they're hoping the audit will tell them.
- `lastName` (string): User's last name.
- `phone` (string): Phone number (optional).
- `url` (string, required): Full URL of the site to audit, including https://.

### `find_consultation_times` (~271 tokens)

Find open consultation times

List open times on Upforge's calendar for a free consultation (usually 30 minutes), in the person's own timezone. Call this before book_consultation and let the person pick a time; never pick one for them. Meeting types come live from the scheduler: general-inquiry is the default, and service types such as web-design, application-development or ai-automation route to the right person. Bookings need about a day's notice, so the search starts tomorrow.

Input parameters:

- `address` (object): Only for format client_location: where to meet. All five fields are required.
- `days` (integer): How many days to search from startDate (default 5).
- `format` (string): virtual (a video call, the default), office (at Upforge's downtown Cincinnati office), or client_location (Upforge travels to them; needs an address and a phone number, and is limited to its travel a…
- `meetingType` (string): Meeting type slug. Omit for general-inquiry. An unknown slug returns the list of available ones.
- `startDate` (string): First day to search, YYYY-MM-DD. Defaults to tomorrow.
- `timezone` (string): The person's IANA timezone, e.g. America/Chicago. Defaults to America/New_York.

### `book_consultation` (~358 tokens)

Book a consultation

Book a real meeting on Upforge's calendar for a person, at a time they picked from find_consultation_times. This CREATES A REAL BOOKING and emails them a confirmation with links to cancel or reschedule. Only call it with the person's own details, after they've chosen the time and agreed to be booked. Never invent contact details, and never book a time they didn't pick. If the time has gone, call find_consultation_times again.

Input parameters:

- `address` (object): Only for format client_location: where to meet. All five fields are required.
- `company` (string): Company name (optional).
- `email` (string, required): The person's own email address. The confirmation goes here. Never guess this.
- `firstName` (string, required): The person's first name.
- `format` (string): virtual (a video call, the default), office (at Upforge's downtown Cincinnati office), or client_location (Upforge travels to them; needs an address and a phone number, and is limited to its travel a…
- `hostId` (string): The hostId returned with that slot.
- `lastName` (string, required): The person's last name.
- `meetingType` (string): The same meetingType used to find the time. Omit for general-inquiry.
- `message` (string, required): What they want to talk about, in their own words, with budget and timeline if known.
- `phone` (string, required): The person's phone number. Never guess this.
- `startTime` (string, required): The startTime of the slot they picked, exactly as find_consultation_times returned it.
- `timezone` (string): The person's IANA timezone, the same one used to find the time.

### `request_consultation` (~234 tokens)

Request a consultation or quote

Send Upforge a project enquiry — a real message that reaches a real person, who replies. Use this to request a quote or ask something the other tools can't answer. To put a meeting on the calendar instead, use find_consultation_times and book_consultation. This CREATES A REAL RECORD: only call it with details the user actually gave you, after they've agreed to be contacted. Never fabricate contact details.

Input parameters:

- `company` (string): Company name (optional).
- `email` (string, required): The user's own email address. Never guess this.
- `firstName` (string, required): User's first name.
- `lastName` (string, required): User's last name.
- `message` (string, required): What they need, in their own words. Include budget and timeline if known — it's what makes the first reply useful.
- `phone` (string, required): The user's phone number. Upforge's contact form requires one, so ask for it. Never guess this.
- `serviceInterest` (string): Service slug from get_services, if one clearly applies.
- `website` (string): Their current site (optional).

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/upforge-dev-upforge/api-mcp#diagnostics

## Score history

- 2026-10-04: 79
- 2026-10-03: 78
- 2026-10-02: 78
- 2026-10-01: 77
- 2026-09-30: 76
- 2026-09-29: 76
- 2026-09-28: 76
- 2026-09-27: 69
- 2026-09-26: 68
- 2026-09-25: 68
- 2026-09-24: 67
- 2026-09-23: 67
- 2026-09-22: 67

## Common questions

### What is the Upforge MCP server?

Upforge is an MCP server listed in the public MCP registry as io.github.upforge-dev/upforge. Talk with Upforge Echo, compare services and proof, or request a human-approved project review. This page covers its hosted endpoint (https://upforge.io/api/mcp).

### Is the Upforge MCP server safe to use?

Upforge scores 79 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Upforge MCP server expose?

Upforge exposes 18 tools: ask_echo, get_review_requirements, prepare_review_upload, finalize_review_upload, submit_project_review, and 13 more. Their descriptions and schemas cost roughly 2,658 tokens of context every time the server is loaded.

### Does the Upforge MCP server require authentication?

No. We connected to Upforge without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the Upforge MCP server still maintained?

Upforge is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://upforge.io/api/mcp
- Repository: https://github.com/upforge-dev/upforge
- Website: https://upforge.io/
- Changelog RSS feed: https://verifymcp.io/servers/upforge-dev-upforge/api-mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/upforge-dev-upforge/api-mcp.json
- HTML version of this page: https://verifymcp.io/servers/upforge-dev-upforge/api-mcp
