Pricing

Start free. Scale when you ship.

Auditing any public MCP server is free, forever. Paid plans add private OAuth audits, more monitored servers and drift webhooks. Cancel anytime.

200+ public MCP servers already scored against the OWASP MCP Top 10 · open methodology · no lock-in

Free

current
$0/mo

Audit any public MCP server, forever.

  • Unlimited public audits & full reports
  • Public directory, badges & embeds
  • Up to 3 monitored servers
  • CLI & GitHub Action (50 API audits/day)

Pro

popular
$19/mo

For teams shipping their own MCP servers.

  • Everything in Free
  • Private OAuth-gated audits (never cached)
  • Up to 50 monitored servers
  • Drift & score-threshold webhook alerts
  • 2,000 API audits/day (CLI & CI)

Team

$99/mo

For platforms auditing MCP at scale.

  • Everything in Pro
  • Up to 500 monitored servers
  • 20,000 API audits/day
  • Multiple API keys & priority probing
  • Continuous rug-pull monitoring

Verified badge

for maintainers
$79one-time

A fresh independent re-audit of your MCP server — earn the badge, don't buy it.

46% of audited MCP servers score D or F — see the data. A passing grade is worth showing.

  • Fresh full re-audit of your server (OWASP MCP Top 10, quality, context-cost)
  • “✓ Verified by CheckMCP” embeddable badge — if you pass (grade C or better)
  • Continuous monitoring: drift & rug-pull re-checks keep the badge honest
  • Featured listing in the public directory
  • If you don't pass: full detailed report + one free re-audit after fixes
Get verified ›
How verification works

Payment buys a fresh independent re-audit, continuous monitoring and a featured listing — and the Verified badge only if your server passes (grade C or better). Payment never changes the score. If the audit fails, you get the full detailed report and one free re-audit after you ship fixes.

✓ Cancel anytime, no contract✓ Private audits are never cached or published✓ Secure checkout by Stripe

Questions before you upgrade

The CLI is free — why pay?

The open-source CLI and GitHub Action audit one server on demand, free under MIT. Paid plans add continuous monitoring with drift & rug-pull alerts, private OAuth audits, more monitored servers and webhooks — the things you can’t run by hand.

My server is private / behind OAuth. Is it safe to audit?

Yes. Pro runs private audits that are never cached or published to the public directory. The self-hosted gateway processes tool traffic entirely inside your own infrastructure — that data never reaches us.

Can I cancel or change plans?

Anytime, from the self-serve billing portal. There’s no contract or lock-in; you keep access until the end of the period you’ve paid for.

Can I pay for a better score?

No — and that's the point. The Verified badge buys a fresh independent re-audit and monitoring, never the outcome. The badge is only granted if your server scores C or better, and it falls back automatically if the server later degrades. If the audit fails, you get the full report and one free re-audit after fixes.

How is the MCP Score calculated?

A live probe of your server plus an OWASP MCP Top 10 security pass, tool-design and schema checks, context-cost and protocol compliance — rolled into one explainable /100 with a “why” for every penalty. See the methodology.

Still unsure? Email [email protected] — a human will answer.

Prices in USD. The open-source CLI and GitHub Action are free under MIT — paid plans cover the hosted directory, private audits and continuous monitoring.