You.com Web Access & AI
REMOTE · API.YOU.COM · 2 COMPONENTS · SCANNED OCT 8
Web search, AI agent, and content extraction via You.com APIs
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security89
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- The endpoint enforces authorisation, advertised via RFC 9728 protected-resource metadata. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents. View diagnostics → Partial
Transport & Reachability0
- Transport blocked by authentication: the endpoint requires auth we don't have to verify streamable-http. See how to fix → View diagnostics → Unverified
Schema Quality & AI Usability0
- Schema blocked by authentication: the endpoint requires auth we don't have to read it. See how to fix → Unverified
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage0
- Tool coverage blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Tool Safety0
- Tool safety blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Capabilities0
- Capabilities blocked by authentication: the endpoint requires auth we don't have to read them. See how to fix → Unverified
Unverified: 6 categories
Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm. Claim this server and supply a read-only token to verify it and lift the score.
How do I install the You.com Web Access & AI MCP server?
You.com Web Access & AI is a hosted endpoint at https://api.you.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · api.you.com
claude mcp add --transport http youdotcom-oss-mcp 'https://api.you.com/mcp'
{
"mcpServers": {
"youdotcom-oss-mcp": {
"url": "https://api.you.com/mcp"
}
}
} {
"servers": {
"youdotcom-oss-mcp": {
"type": "http",
"url": "https://api.you.com/mcp"
}
}
} [mcp_servers.youdotcom-oss-mcp] url = "https://api.you.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"youdotcom-oss-mcp": {
"type": "remote",
"url": "https://api.you.com/mcp",
"enabled": true
}
}
} openclaw mcp add youdotcom-oss-mcp --url 'https://api.you.com/mcp' --transport streamable-http
mcp_servers:
youdotcom-oss-mcp:
url: "https://api.you.com/mcp" {
"McpServers": {
"youdotcom-oss-mcp": {
"Transport": "http",
"Url": "https://api.you.com/mcp"
}
}
} assistant mcp add youdotcom-oss-mcp -t streamable-http -u 'https://api.you.com/mcp'
{
"mcpServers": {
"youdotcom-oss-mcp": {
"type": "http",
"url": "https://api.you.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 28 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 29 Aug 26 0
- Endpoint reachability: reachable → behind authorisation ▼ security
- Stability: 0.67 → unverified ▼ security
- Transport: pass → unverified ▼ security
- Tool safety: pass → unverified ▼ security
- Authorization: unverified → pass ▲ security
- Tool coverage: 100 → unverified ▼ functional
- Capabilities: pass → unverified ▼ functional
- 26 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 19 Aug 26 0
- A breaking change shipped without a version bump: still 3.7.0 ▼ security
- Tool “you-answers” was removed ▼ security
- New tool “you-answer” functional
- 18 Aug 26 0
- Schema quality: 953 → 1227 ▼ functional
- Server version: 3.6.1 → 3.7.0 functional
- New tool “you-answers” functional
- “you-search” reworded the description of “query” cosmetic
- “you-search” dropped the optional parameter “livecrawl” cosmetic
- “you-search” dropped the optional parameter “livecrawl_formats” cosmetic
- 14 Aug 26 0
- Tool “you-contents” rewrote its description, which is the text the model reads security
- Tool “you-search” rewrote its description, which is the text the model reads security
- Tool “you-research” rewrote its description, which is the text the model reads security
- Server version: 3.6.0 → 3.6.1 functional
- “you-search” added an optional parameter “extraction” cosmetic
- “you-search” reworded the description of “query” cosmetic
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 8 Oct 2026 · Probed https://api.you.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=api.you.com | CN=WE1,O=Google Trust Services,C=US | 22 Aug 2026 | 20 Nov 2026 | ECDSA 256 | ECDSA-SHA256 | 500c053e1a7cbc130e857195ff0d03b4 |
| SANs: api.you.com | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of api.you.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| you.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On connection |
| HTTP status | 401 |
WWW-Authenticate challenge Bearer resource_metadata="https://api.you.com/mcp/.well-known/oauth-protected-resource" scope="Tools offline_access"
Bearer resource_metadata="https://api.you.com/mcp/.well-known/oauth-protected-resource" scope="Tools offline_access" | Header | Value |
|---|---|
| www-authenticate | Bearer resource_metadata="https://api.you.com/mcp/.well-known/oauth-protected-resource" scope="Tools offline_access" |
Protected resource metadata
| Document | https://api.you.com/mcp/.well-known/oauth-protected-resource |
|---|---|
| Retrieved | Yes |
| Resource | https://api.you.com/mcp |
| Authorisation server | https://auth.you.com/v1/apps/agentic/P2jInttRMuXpyYZMbVcsc4C9Z0RT/MS3BitzWFxlSigWFUNJHHNsIYt5qp |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://api.you.com/mcp | Auth required | 401 | |
| http (plaintext) | http://api.you.com/mcp | HTTPS enforced | 301 | https://api.you.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
you-answer Web Answer ~217
Fast live-web answer generation returning one synthesized answer with verified inline citations, citation excerpts, and supporting web results. Use when the caller wants a single sourced answer; use research for deeper multi-step investigation, effort control, structured output, or background tasks. Supports freshness, country, language, and domain filters.
| Name | Type | Req | Description |
|---|---|---|---|
| boost_domains | array | – | Domains to prefer in ranking (up to 500). Can combine with exclude_domains, not include_domains. |
| country | string | – | A supported country code that determines the geographical focus |
| exclude_domains | array | – | Domains to exclude from results (up to 500) |
| freshness | string | – | day/week/month/year or YYYY-MM-DDtoYYYY-MM-DD |
| include_domains | array | – | Domains to exclusively include (up to 500) |
| language | string | – | A supported BCP 47 language tag that determines the language |
| query | string | yes | Focused live-web question or lookup request. Returns a synthesized answer with inline citations, citation excerpts, and supporting web results. |
| Name | Type | Req | Description |
|---|---|---|---|
| answer | string | yes | The synthesized response with numbered inline citations |
| citations | array | yes | The sources cited in the answer, in citation order |
| results | object | yes | Search results grouped by result type |
No examples provided.
you-balance Account Balance ~38
Get the remaining credit balance for the billing entity associated with your You.com API key. Balance is in cents (divide by 100 for USD).
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| data | object | yes | – |
No examples provided.
you-contents Extract Web Page Contents ~164
Extract full content from specific URLs in markdown, HTML, or structured metadata. Use when you already have URLs and need to read them before relying on exact details.
| Name | Type | Req | Description |
|---|---|---|---|
| crawl_timeout | number | – | Optional timeout in seconds (1-60) for page crawling |
| formats | array | – | Output formats: array of "markdown" (text), "html" (layout), or "metadata" (structured data) |
| max_age | – | – | Maximum allowed age of cached content in seconds. When set, cached content older than this threshold is ignored and the page is re-fetched. Must be 0 or greater. Default: null (no age limit). |
| urls | array | yes | Array of webpage URLs to extract content from (e.g., ["https://example.com"]) |
| Name | Type | Req | Description |
|---|---|---|---|
| output | array | yes | Extracted page content, one entry per requested URL |
No examples provided.
you-discover Agent Discovery ~115
Discover AI agents, MCP servers, A2A agents, and skills via ARD Agent Finder services. Search-only — never installs or connects. Returns ranked results with relevance scores.
| Name | Type | Req | Description |
|---|---|---|---|
| finder | string | – | Which Agent Finder discovery service(s) to query. |
| finder_url | string | – | Optional custom finder URL (must be public http/https). Augments selected finders. |
| limit | integer | – | Max consolidated results (1–25). |
| query | string | yes | Natural-language task to find agents/tools for. |
| Name | Type | Req | Description |
|---|---|---|---|
| finders | object | yes | Per-finder request status |
| query | string | yes | The original discovery query |
| referrals | array | yes | Informational referrals to non-result resources |
| results | array | yes | Ranked consolidated results, highest score first |
No examples provided.
you-research Research ~242
One-shot cited synthesis — research a topic and return a concise answer with inline citations and source list. Use when a synthesized, sourced answer is needed rather than raw search results. Configurable effort levels (lite, standard, deep, exhaustive, frontier).
| Name | Type | Req | Description |
|---|---|---|---|
| background | boolean | – | When true, queue a research task and return a task handle immediately instead of waiting for the result inline. Defaults to synchronous. |
| input | string | yes | The research question or complex query requiring in-depth investigation and multi-step reasoning. Maximum length: 40,000 characters. |
| output_schema | object | – | Beta. Requests structured JSON output in output.content using a supported JSON Schema subset. Supported only with research_effort standard, deep, exhaustive, and frontier. Sending with lite returns 4… |
| research_effort | string | – | Controls how much time and effort the Research API spends on your question. lite: fast answers, standard: balanced (default), deep: thorough, exhaustive: most comprehensive, frontier: long-running de… |
| source_control | – | – | Beta. Controls which web sources the research agent searches and visits. include_domains and exclude_domains cannot be used together. |
| Name | Type | Req | Description |
|---|---|---|---|
| created_at | string | – | When the task was created, in RFC 3339 format |
| output | object | – | The research output containing the answer and sources |
| status | string | – | The current status of the background research task |
| stream_url | string | – | The URL path for the Server-Sent Events stream for this task |
| task_id | string | – | Unique identifier for the background research task |
| type | string | – | The task type |
| warnings | array | – | Warnings generated during research |
No examples provided.
you-search Web Search ~381
Current web and news search returning snippets, source URLs, and metadata. Default for finding current information; supports domain, country, language, and freshness filters, and extraction (highlights or full page content). For multi-part questions, issue a separate focused query per sub-question — one facet each, not the whole question.
| Name | Type | Req | Description |
|---|---|---|---|
| boost_domains | array | – | Domains to boost in search ranking (up to 500). Can combine with exclude_domains, but cannot combine with include_domains. |
| count | integer | – | Max results per section |
| country | string | – | Country code |
| crawl_timeout | integer | – | Crawl timeout in seconds (1-60) |
| exclude_domains | array | – | Domains to exclude from results (up to 500) |
| extraction | object | – | Ask for content to be extracted from each result. Omit for a plain search that returns snippets only. |
| freshness | string | – | day/week/month/year or YYYY-MM-DDtoYYYY-MM-DD |
| include_domains | array | – | Domains to include in results (up to 500) |
| language | string | – | Language code (BCP 47 format) |
| offset | integer | – | Pagination offset |
| query | string | yes | Concise keyword query, 3–6 words. ALLOWED search operators: `"exact phrase"`, `intitle:term`, `inbody:term`, `-term`, `+term`, and `AND`/`OR` (MUST be uppercase; never mix `AND` with `OR`). DO NOT us… |
| safesearch | string | – | Filter level |
| Name | Type | Req | Description |
|---|---|---|---|
| metadata | object | yes | – |
| results | object | yes | – |
No examples provided.
What is the You.com Web Access & AI MCP server?
You.com Web Access & AI is an MCP server listed in the public MCP registry as io.github.youdotcom-oss/mcp. Web search, AI agent, and content extraction via You.com APIs. This page covers its hosted endpoint (https://api.you.com/mcp).
Is the You.com Web Access & AI MCP server safe to use?
You.com Web Access & AI scores 36 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the You.com Web Access & AI MCP server expose?
You.com Web Access & AI exposes 6 tools: you-search, you-contents, you-research, you-answer, you-balance, you-discover. Their descriptions and schemas cost roughly 1,157 tokens of context every time the server is loaded.
Does the You.com Web Access & AI MCP server require authentication?
Yes. You.com Web Access & AI asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the You.com Web Access & AI MCP server still maintained?
You.com Web Access & AI is still listed as active in the MCP registry. We last reached this channel on 5 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.