Standalone MCP directory — 19037 servers across 8375 domains, each exposing a remote (streamable-http) endpoint and health-probed via a JSON-RPC initialize handshake.
Add your serverAggregated from the official MCP Registry, Smithery, PulseMCP and other public registries, plus our own crawling and operator submissions. Every server is de-duplicated by endpoint, health-probed via a live JSON-RPC initialize handshake, and statically scanned for malware & prompt-injection patterns in its advertised tools before listing — yielding 19037 indexed servers, of which 10057 answered within the last 6 h.
Top rated
by quality score · health · trust signals| # | Tool | Grade | Score |
|---|---|---|---|
| 1 |
Wiremi Marketing MCP
uptime_30d 1.0%; p95 66.8ms; conformance: fail
|
A | 8.73 |
| 2 |
Biosamples
uptime_30d 1.0%; p95 36.5ms; conformance: pass
|
A | 8.72 |
| 3 |
Manifold
uptime_30d 1.0%; p95 27.5ms; conformance: pass
|
A | 8.70 |
| 4 |
Data Brussels
uptime_30d 1.0%; p95 23.8ms; conformance: pass
|
A | 8.70 |
| 5 |
Landprice
uptime_30d 1.0%; p95 64.1ms; conformance: pass
|
A | 8.70 |
| 6 |
Data Centrevaldeloire
uptime_30d 1.0%; p95 46.8ms; conformance: pass
|
A | 8.70 |
| 7 |
Travel Advisories
uptime_30d 1.0%; p95 45.7ms; conformance: pass
|
A | 8.70 |
| 8 |
LatLng
uptime_30d 1.0%; p95 279.6ms; conformance: pass
|
A | 8.69 |
| 9 |
io.github.comil27/solrisk-mcp
uptime_30d 1.0%; p95 67.0ms; conformance: pass
|
A | 8.69 |
| 10 |
Barcelona Events
uptime_30d 1.0%; p95 103.0ms; conformance: pass
|
A | 8.69 |
All MCP servers
Continuously aggregated · refreshed every 6 h.
-
uptime_30d 1.0%; p95 231.9ms; conformance: pass
A8.2 🔓 open streamable-http -
uptime_30d 1.0%; p95 80.0ms; conformance: pass
A8.5 🔓 open streamable-http -
uptime_30d 1.0%; p95 214.6ms; conformance: pass
A8.5 ⚡ agent-pays · x402 streamable-http -
uptime_30d 1.0%; p95 310.8ms; conformance: pass
A8.5 🔓 open streamable-http -
uptime_30d 1.0%; p95 533.5ms; conformance: pass
A8.3 🔓 open streamable-http -
uptime_30d 1.0%; p95 271.4ms; conformance: pass
A8.5 🔓 open streamable-http -
uptime_30d 1.0%; p95 173.1ms; conformance: pass
A8.2 🔓 open streamable-http -
uptime_30d 1.0%; p95 75.6ms; conformance: pass
A8.6 🔓 open streamable-http -
uptime_30d 1.0%; p95 251.9ms; conformance: pass
A8.5 🔓 open streamable-http -
Orbuchttps://mcp.orbuc.io/mcp/orbuc● healthy
uptime_30d 1.0%; p95 464.3ms; conformance: pass
B+7.9 🔓 open streamable-http -
uptime_30d 1.0%; p95 433.3ms; conformance: fail
A8.1 🔓 open streamable-http -
uptime_30d 1.0%; p95 309.3ms; conformance: pass
A8.4 🔓 open streamable-http -
Dockholdhttps://api.dockhold.eu/mcp● healthy
uptime_30d 1.0%; p95 806.8ms; conformance: pass
B+7.7 🔓 open streamable-http -
uptime_30d 1.0%; p95 342.2ms; conformance: pass
A8.5 ⚡ agent-pays · x402 streamable-http -
ai.dataecho/mcphttps://dataecho.ai/mcp● healthy
uptime_30d 1.0%; p95 803.8ms; conformance: pass
B+7.9 🔓 open streamable-http -
Cloud-deployed Semgrep static analysis for AI agents. Scan code for security vulnerabilities (SQL injection, XSS, command injection), detect OWASP Top 10 & CWE issues, run custom rules. Supports 30+ languages via MCP. — 70 runs
C+5.8 🔑 human key streamable-http apify_token -
SpaceMolthttps://game.spacemolt.com/mcp● healthy
uptime_30d 1.0%; p95 144.3ms; conformance: partial
A8.4 🔓 open streamable-http -
ChiefLabhttps://api.chieflab.io/api/mcp● healthy
uptime_30d 1.0%; p95 562.0ms; conformance: pass
A8.3 🔓 open streamable-http -
AXIS Toolbox — Agentic Commerce Codebase Intelligencehttps://axis-api-6c7z.onrender.com/mcp● healthy
uptime_30d 1.0%; p95 690.7ms; conformance: pass
A8.3 🔓 open streamable-http -
uptime_30d 1.0%; p95 78.2ms; conformance: pass
A8.5 🔓 open streamable-http -
uptime_30d 1.0%; p95 156.2ms; conformance: pass
B+7.0 ⚡ agent-pays · x402 streamable-http -
ac.tandem/docs-mcphttps://tandem.ac/mcp● healthy
Remote MCP server for Tandem docs, install guides, SDKs, workflows, and agent setup help.
B+7.3 🔓 open streamable-http -
uptime_30d 1.0%; p95 529.3ms; conformance: pass
B7.0 🔓 open streamable-http -
Zephexhttps://zephex.dev/mcp● healthy
uptime_30d 1.0%; p95 651.8ms; conformance: pass
B+7.6 🔓 open streamable-http -
Fracterahttps://www.fractera.ai/api/mcp● healthy
uptime_30d 1.0%; p95 1315.9ms; conformance: pass
A8.1 🔓 open streamable-http -
uptime_30d 1.0%; p95 807.4ms; conformance: pass
B7.0 🔓 open streamable-http -
uptime_30d 1.0%; p95 219.6ms; conformance: fail
A8.3 🔓 open streamable-http -
uptime_30d 1.0%; p95 197.4ms; conformance: fail
C+5.7 🔓 open streamable-http -
uptime_30d 1.0%; p95 376.6ms; conformance: partial
B+7.8 🔓 open streamable-http -
Build and run AI workflows and prompt chains. Create, test, and deploy content generation pipelines with structured outputs.
C4.4 🔑 human key streamable-http smithery_api_key -
Make structured decisions in under 100ms — faster than any LLM API call. Define any decision type your app needs, train a lightweight ML model from AI-generated examples, and get instant decisions with confidence scores and reason codes. No ML team or historical data required. From moderation to routing to fraud — if an LLM can judge it, Sparkient can compile it.
D3.1 🔑 human key streamable-http smithery_api_key -
BorealHosthttps://borealhost.ai/mcp● healthy
Agent-native web hosting — deploy sites, manage DNS, register domains, scale infrastructure
⚠ review B+8.0 🔓 open streamable-http -
uptime_30d 1.0%; p95 118.9ms; conformance: fail
B+7.6 ⚡ agent-pays · x402 streamable-http -
uptime_30d 1.0%; p95 387.1ms; conformance: fail
B+8.0 🔓 open streamable-http -
uptime_30d 1.0%; p95 430.6ms; conformance: fail
C+6.0 🔓 open streamable-http -
uptime_30d 1.0%; p95 157.0ms; conformance: fail
A8.2 🔓 open streamable-http -
uptime_30d 1.0%; p95 62.0ms; conformance: fail
A8.3 🔓 open streamable-http -
Amendorhttps://amendor.site/mcp● healthy
uptime_30d 1.0%; p95 258.3ms; conformance: fail
A8.1 🔓 open streamable-http -
MCP server for Supabase — 31 tools for database CRUD, storage, auth admin, project management, edge functions, and secrets via REST + Management APIs. ## Features - Database CRUD with PostgREST filtering, resource embedding (JOINs), and RPC - Storage bucket and object management with signed URLs - Auth admin for user creation, updates, bans, and deletion - Project lifecycle management (create, pause, restore) - Execute SQL queries and generate TypeScript types - Edge function inspection and secret/API key management ## 31 Tools - **Database REST (6):** sb_list_records, sb_insert_records, sb_update_records, sb_upsert_records, sb_delete_records, sb_call_function - **Storage (6):** sb_list_buckets, sb_create_bucket, sb_delete_bucket, sb_list_objects, sb_delete_objects, sb_create_signed_url - **Auth Admin (5):** sb_list_users, sb_get_user, sb_create_user, sb_update_user, sb_delete_user - **Projects (5):** sb_list_projects, sb_get_project, sb_create_project, sb_pause_project, sb_restore_project - **Database Management (3):** sb_run_query, sb_list_migrations, sb_get_typescript_types - **Edge Functions (2):** sb_list_functions, sb_get_function - **Secrets & Keys (4):** sb_list_secrets, sb_create_secrets, sb_delete_secrets, sb_list_api_keys ## Configuration - `SUPABASE_URL` — Project URL (e.g. `https://xxx.supabase.co`) — for database, storage, auth tools - `SUPABASE_SERVICE_ROLE_KEY` — Service role key (bypasses RLS) — from Settings → API - `SUPABASE_ACCESS_TOKEN` — Personal access token — for project management tools (from dashboard → Account → Access Tokens)
B6.2 🔑 human key streamable-http smithery_api_key -
Give your AI agent its own money on AgentsCoin — create a wallet, mine AGENT, check balance, and send. MCP-native money for the AI-agent economy.
B6.9 🔑 human key streamable-http smithery_api_key -
**Just Publish** turns a website you built with AI into a live, public URL — without leaving the chat. No git, no CLI, no build step, no dashboard, and no login to fumble through. You hand it your files, it hands back a working link. It's built for the person who made a site with ChatGPT, Claude, or Cursor and just wants it online. ### How it works Call `deploy` with your files (HTML, CSS, JS, images) and an email. You get back a live `url`, a `site_id`, and an `edit_token`. Keep the token and you can update the same site anytime — either a full redeploy or a single-file edit. That's the whole flow. ### Tools - **`deploy`** — Publish a static site to a public URL. First call creates a new site and returns its `url`, `site_id`, and `edit_token`; pass those back to update it in place. - **`update_site_file`** — Change one or a few files on an existing site without resending the whole thing. - **`get_site_files`** — Read what's currently live before you edit. ### Who it's for Non-technical builders and AI agents that generate a static site and need it hosted in one step. If you can describe a page, you can publish it. ### Good to know - **No accounts required.** Edit access is held by the `edit_token` returned at publish time. - **Static sites only** — files in, URL out. No frameworks or build pipelines. - Free to start; a **$9/mo Builder** plan and **custom-domain** connection are available at [justpublish.ai](https://justpublish.ai).
B+7.7 🔑 human key streamable-http smithery_api_key -
Zero-Ops deploy of a private AI coding workspace onto your own VPS — straight from your AI chat. Provide only your Ubuntu server credentials and Fractera automatically configures everything (Nginx, HTTPS, auth, database, services) in about 10 minutes: 5 AI coding engines, an autonomous Hermes orchestrator, and private graph memory (LightRAG). No terminal, no DevOps. The deployment is IP-first and free; attaching a custom domain with HTTPS is an optional later step. The connector can register the user, recommend a VPS, run and monitor the full deploy, and answer questions about the project via get_project_info. Tagline (если просят одну строку): Zero-Ops deploy of a private AI workspace to your own VPS — from your AI chat.
C+6.0 🔑 human key streamable-http smithery_api_key -
x402-gated agentic vending stack for AI agents — dynamic-priced payload vending, Ghost Layer decision-notarization resale, and a real multi-seller marketplace for x402-payable APIs. ScriptMasterLabs' own tools are offered first by default, but every listing (ours or a third party's) is independently discoverable and payable. **Settlement:** Base/USDC (primary) + XRPL/RLUSD (secondary) **Tools:** 5 — ghost_layer_status (free), ghost_layer_notarize, vend_dynamic, marketplace_browse (free), marketplace_list
B6.3 🔑 human key streamable-http smithery_api_key -
On-chain stablecoin market cap and Bitcoin institutional holdings data.
C+5.2 🔑 human key streamable-http smithery_api_key -
PulseChain on-chain analytics for AI agents. Token safety scores (0-100, A-F), honeypot detection, whale tracking, smart money feed, scam alerts, DEX volume, bridge stats, holder leagues. 11 free + 9 pro tools.
B6.0 🔑 human key streamable-http smithery_api_key -
Built by someone with a weak stomach who loves ramen. When the emergency hits at Shinjuku station — a dozen train lines, hundreds of exits — you don't have time to guess. This server knows. Find accessible restrooms across 526 Tokyo stations: exit numbers, floor, inside/outside ticket gates, wheelchair access, ostomate facilities, diaper tables. Government open data, no auth, no signup. Try asking: - "Nearest accessible restroom at Shinjuku station?" (Marunouchi Line B1F, 11m from Exit A8) - "Which restrooms near Kanda have a diaper table?" - "I'm at Shibuya with a wheelchair — where's the closest toilet inside the gates?" Bonus tools on the same server: live train status, JMA flood/landslide alerts, hazard risk & official stats for any station or municipality in Japan.
B6.3 🔑 human key streamable-http smithery_api_key -
62,144 active ramen shops across all 47 prefectures of Japan. Names verified by dual-AI audit (26,975 romanization fixes). Re-verified monthly, closures web-confirmed with evidence URLs, and every response is stamped with data_as_of so you can always check exactly how current the data is. No auth, no signup — just connect and ask. Try asking: - "Is there a ramen shop on Iriomote Island?" (yes — two, actually) - "Northernmost ramen shop in Japan?" (a diner literally named "Northernmost", Cape Soya, 45.5°N) - "How many Ramen Shop franchise locations in Saitama?" (47) - "Find tonkotsu ramen near Ebisu station"
B6.6 🔑 human key streamable-http smithery_api_key -
AI Constraint Engine with AI Patch Firewall. 42 MCP tools. Patch Gateway (ALLOW/WARN/BLOCK verdicts), diff-native review (10 scored signals, hard escalation rules), Spec Compiler, Code Graph, Typed constraints, Python SDK, ROS2. Works with Claude Code, Cursor, Windsurf, Cline, Bolt.new, Lovable. 1073 tests. Free and open source. By Sandeep Roy.
C+5.4 🔑 human key streamable-http smithery_api_key -
USDV Capital — Your Real Estate CFOhttps://server.smithery.ai/usdv-capital/real-estate-cfo/mcp● healthy
Real estate market intelligence, financial calculators, and capital advisory tools covering all 50 US states plus DC and Puerto Rico. Access CFO-level market data for 86,000+ locations, calculate DSCR and flip ROI with professional assessments, check financing eligibility, and screen investment opportunities — powered by Census ACS and Zillow data. **23 tools** across 5 categories: - **Market Intelligence** — Search 86K+ locations, compare markets side-by-side, find nearby opportunities, screen pre-scored investment cities - **Financial Calculators** — DSCR, flip ROI, rental cash flow, BRRRR, STR revenue, cash-to-close, construction budget — each with CFO-level assessment - **Eligibility & Products** — Check financing availability by state, browse capital solutions (Fix & Flip, DSCR, Bridge, Construction, Multifamily up to $50M, Build-to-Rent up to $50M) - **Deal Analysis** — Full deal underwriting combining market data, calculator output, and eligibility in one call - **Utility** — Property tax lookup, insurance estimates, rent estimates, neighborhood analysis, 1031 exchange calculator, entity structure guidance USDV Capital is Your Real Estate CFO — a capital advisory platform helping real estate investors structure, source, and optimize financing from $150K to $50M.
B6.0 🔑 human key streamable-http smithery_api_key -
KHEPRA MCP Server MCP Registry License Container PQC Sovereign compliance engine with 36,195 STIG/CCI/NIST/CMMC mappings. Air-gappable. Zero token costs. Run ert_scan → get a Godfather Report with dollar-denominated business impact. The only MCP compliance server that runs on your metal — with the World's First DoD PQC STIG built in. PQC-01-STIG-V1R1 — Full Whitepaper → 17 controls covering CNSA 2.0, FIPS 203/204/205, and the NSA's May 2026 MCP security advisory. The world's first DoD-style Post-Quantum Cryptography STIG, including the first PQC controls for agentic AI and MCP deployments. Tiers Tier License Key Tools Telemetry Egress Community ❌ Not required pqc_stig + 12 core tools Opt-in Dark Crypto Intel Zero (sovereign mode) Sovereign ✅ Required All 34 tools Zero Zero Pharaoh ✅ Required All 34 tools + priority support Zero Zero Community tier is free. Run pqc_stig to assess your project's quantum readiness against PQC-01-STIG-V1R1 — the World's First DoD-style Post-Quantum Cryptography STIG — no license key needed. What It Does KHEPRA MCP connects your AI assistant directly to a hardened compliance engine. Ask Claude or any MCP client to scan a system, map findings to STIG/NIST/CMMC controls, and generate an executive-ready risk report — all without sending data to external APIs. Key capabilities: 36,195 STIG/CCI/NIST 800-53/800-171/CMMC mappings (offline, bundled) Post-quantum cryptographic attestation on every tool call (ML-DSA-65 / FIPS 204) World's First DoD PQC STIG — 17 controls covering CNSA 2.0 / FIPS 203/204/205 + agentic AI / MCP (PQC-01-STIG-V1R1) Godfather Report: dollar-denominated business impact per finding (FAIR model) Air-gap and SCIF compatible — sovereign/ironbank modes make zero egress calls Flat annual licensing — no per-token or per-query charges Runs on your metal: on-prem, DoD, IC, classified environments Installation There are two delivery methods: Docker (recommended, no build required) and compiled binary (fastest startup, required for air-gap). Both support the same environment variables and all MCP clients. Choose your path: Method Best For Startup Docker Most users, easiest setup ~2s Compiled Binary Air-gap, SCIF, performance ~300ms Option A: Docker (Recommended) Requires Docker Desktop or Docker Engine. The image is pre-built and ships the full compliance database — no additional downloads in sovereign mode. # Pull once docker pull ghcr.io/nouchix/pqc-khepra-mcp:latest # Test it (should print the initialize response and exit) echo '{"jsonrpc":"2.0","method":"initialize","params":{"protocolVersion":"2025-11-25","capabilities":{},"clientInfo":{"name":"test","version":"1.0"}},"id":0}' \ | docker run --rm -i -e KHEPRA_MODE=sovereign ghcr.io/nouchix/pqc-khepra-mcp:latest Option B: Compiled Binary Requires Go 1.21+ for building, or download a pre-built release from GitHub Releases. git clone https://github.com/nouchix/PQC-Khepra-MCP.git cd PQC-Khepra-MCP # Build (cross-compile for your OS) go build -o khepra-mcp ./cmd/khepra-mcp # Linux / macOS go build -o khepra-mcp.exe ./cmd/khepra-mcp # Windows # Test the binary echo '{"jsonrpc":"2.0","method":"initialize","params":{"protocolVersion":"2025-11-25","capabilities":{},"clientInfo":{"name":"test","version":"1.0"}},"id":0}' \ | KHEPRA_MODE=sovereign ./khepra-mcp Windows — using the batch launcher The repo ships a run-mcp.bat launcher for Windows. It uses the pre-built binary (fast path) and falls back to go run automatically: :: run-mcp.bat is already in the repo at the root of PQC-Khepra-MCP :: Point your MCP client to: cmd /c C:\path\to\PQC-Khepra-MCP\run-mcp.bat Adding to Your AI Client Claude Desktop Config file location: macOS: ~/Library/Application Support/Claude/claude_desktop_config.json Windows: %APPDATA%\Claude\claude_desktop_config.json Linux: ~/.config/Claude/claude_desktop_config.json Community tier — Docker (macOS / Linux) { "mcpServers": { "khepra": { "command": "docker", "args": [ "run", "--rm", "-i", "-e", "KHEPRA_MODE=sovereign", "-v", "/var/lib/khepra:/var/lib/khepra", "ghcr.io/nouchix/pqc-khepra-mcp:latest" ] } } } Community tier — Docker (Windows) { "mcpServers": { "khepra": { "command": "docker", "args": [ "run", "--rm", "-i", "-e", "KHEPRA_MODE=sovereign", "-v", "C:\\Users\\YourName\\.khepra:/var/lib/khepra", "ghcr.io/nouchix/pqc-khepra-mcp:latest" ] } } } Community tier — Binary (Windows, fastest startup) { "mcpServers": { "khepra": { "command": "C:\\path\\to\\PQC-Khepra-MCP\\khepra-mcp.exe", "args": [], "env": { "KHEPRA_MODE": "sovereign", "KHEPRA_NETWORK_POLICY": "lan", "MCP_PQC_ENABLED": "true", "KHEPRA_MANIFEST_PATH": "C:\\path\\to\\PQC-Khepra-MCP\\manifest.json" } } } } Community tier — Binary via batch launcher (Windows) { "mcpServers": { "khepra": { "command": "cmd", "args": ["/c", "C:\\path\\to\\PQC-Khepra-MCP\\run-mcp.bat"], "env": { "KHEPRA_MODE": "sovereign", "KHEPRA_NETWORK_POLICY": "lan", "MCP_PQC_ENABLED": "true" } } } } Sovereign / Pharaoh tier (with license key) { "mcpServers": { "khepra": { "command": "docker", "args": [ "run", "--rm", "-i", "-e", "KHEPRA_LICENSE_KEY", "-e", "KHEPRA_MODE=sovereign", "-v", "/var/lib/khepra:/var/lib/khepra", "-v", "/var/log/khepra:/var/log/khepra", "ghcr.io/nouchix/pqc-khepra-mcp:latest" ], "env": { "KHEPRA_LICENSE_KEY": "YOUR_LICENSE_KEY_HERE" } } } } After editing, restart Claude Desktop. Verify in Settings → Developer — you should see khepra with status running and all tools listed. Cursor Config file: .cursor/mcp.json in your project root, or ~/.cursor/mcp.json globally. Docker (macOS / Linux) { "servers": { "khepra": { "type": "stdio", "command": "docker", "args": [ "run", "--rm", "-i", "-e", "KHEPRA_MODE=sovereign", "-v", "/var/lib/khepra:/var/lib/khepra", "ghcr.io/nouchix/pqc-khepra-mcp:latest" ] } } } Binary (macOS / Linux) { "servers": { "khepra": { "type": "stdio", "command": "/path/to/khepra-mcp", "args": [], "env": { "KHEPRA_MODE": "sovereign", "KHEPRA_MANIFEST_PATH": "/path/to/PQC-Khepra-MCP/manifest.json" } } } } Binary (Windows) { "servers": { "khepra": { "type": "stdio", "command": "C:\\path\\to\\PQC-Khepra-MCP\\khepra-mcp.exe", "args": [], "env": { "KHEPRA_MODE": "sovereign", "KHEPRA_MANIFEST_PATH": "C:\\path\\to\\PQC-Khepra-MCP\\manifest.json" } } } } VS Code (with GitHub Copilot or Cline extension) Config file: .vscode/mcp.json in your project, or user settings. { "servers": { "khepra": { "type": "stdio", "command": "docker", "args": [ "run", "--rm", "-i", "-e", "KHEPRA_MODE=sovereign", "-v", "${env:HOME}/.khepra:/var/lib/khepra", "ghcr.io/nouchix/pqc-khepra-mcp:latest" ] } } } Or via user settings.json for the Cline extension: { "cline.mcpServers": { "khepra": { "command": "docker", "args": [ "run", "--rm", "-i", "-e", "KHEPRA_MODE=sovereign", "ghcr.io/nouchix/pqc-khepra-mcp:latest" ] } } } Windsurf Config file: ~/.codeium/windsurf/mcp_config.json { "mcpServers": { "khepra": { "command": "docker", "args": [ "run", "--rm", "-i", "-e", "KHEPRA_MODE=sovereign", "-v", "/var/lib/khepra:/var/lib/khepra", "ghcr.io/nouchix/pqc-khepra-mcp:latest" ] } } } Continue.dev Config file: ~/.continue/config.json — add to the experimental.modelContextProtocolServers array: { "experimental": { "modelContextProtocolServers": [ { "name": "khepra", "transport": { "type": "stdio", "command": "docker", "args": [ "run", "--rm", "-i", "-e", "KHEPRA_MODE=sovereign", "ghcr.io/nouchix/pqc-khepra-mcp:latest" ] } } ] } } Cloud / SaaS AI Tools (Claude.ai, ChatGPT, Gemini, etc.) Cloud-based AI tools cannot directly spawn local subprocesses — they need an HTTP/SSE bridge to reach your local KHEPRA server. There are two approaches: Approach 1 — mcp-remote proxy (easiest, no server required) mcp-remote tunnels a local stdio MCP server over HTTPS, making it accessible to any cloud tool. This is what the Kaggle MCP entry in the config above uses. # Install once npm install -g mcp-remote # Start the bridge (exposes your local KHEPRA server at https://localhost:3000) KHEPRA_MODE=sovereign mcp-remote \ --server "docker run --rm -i -e KHEPRA_MODE=sovereign ghcr.io/nouchix/pqc-khepra-mcp:latest" \ --port 3000 Then in Claude.ai (or any cloud tool that accepts MCP SSE URLs): MCP Server URL: http://localhost:3000/sse Security note: mcp-remote binds to localhost by default. Do not expose it to the public internet without TLS and authentication. In sovereign/ironbank mode, KHEPRA itself makes zero egress calls — only the bridge connection to the cloud tool carries data. Approach 2 — Self-hosted HTTP/SSE endpoint For teams running KHEPRA on a shared server (e.g., Hostinger VPS at IP_ADDRESS), start the server in HTTP mode: # On your server — start KHEPRA in HTTP/SSE mode docker run -d \ -e KHEPRA_MODE=hybrid \ -e KHEPRA_HTTP_PORT=8443 \ -e KHEPRA_LICENSE_KEY="${KHEPRA_LICENSE_KEY}" \ -p 8443:8443 \ ghcr.io/nouchix/pqc-khepra-mcp:latest # Point your cloud tool to: # https://your-server.com:8443/sse Then configure any cloud AI tool that supports MCP SSE: Cloud Tool Where to add MCP URL Claude.ai (Pro/Team) Settings → Integrations → MCP Servers OpenAI Assistants API tools field with type: "mcp" Gemini for Workspace Extensions → Custom MCP (preview) Glama.ai Workspace → MCP Servers Smithery.ai Catalog → Self-hosted server Note: HTTP/SSE mode (hybrid/edge) enables external connections. Always terminate TLS at a reverse proxy (nginx/Caddy) and restrict access by IP or API key. The sovereign mode refuses HTTP connections by design — air-gap integrity is preserved. Approach 3 — Smithery / MCP Registry (Community tier only) KHEPRA is listed on Smithery.ai and the MCP Registry. Cloud tools that support registry-based discovery can install it directly: Registry ID: io.github.nouchix/pqc-khepra-mcp This runs the Community tier via Smithery's managed infrastructure. For sovereign deployment (air-gap, your data stays on your metal), use Options A or B above. Validation — Test Your Installation Run this from your terminal to verify the server responds correctly: # Docker echo '{"jsonrpc":"2.0","method":"tools/list","params":{},"id":1}' \ | docker run --rm -i -e KHEPRA_MODE=sovereign ghcr.io/nouchix/pqc-khepra-mcp:latest # Binary (Linux / macOS) echo '{"jsonrpc":"2.0","method":"tools/list","params":{},"id":1}' \ | KHEPRA_MODE=sovereign ./khepra-mcp # Binary (Windows PowerShell) '{"jsonrpc":"2.0","method":"tools/list","params":{},"id":1}' \ | & ".\khepra-mcp.exe" Expected output: a JSON-RPC response listing all available tools. If you see "tools": [...] with 12+ entries — you're connected. Full protocol validation (Windows) # Runs the complete Claude Desktop handshake sequence and validates all responses .\scripts\test-mcp-handshake.ps1 -BinaryPath ".\khepra-mcp.exe" # Expected output: # [PASS] initialize | protocolVersion=2025-11-25 | listChanged=False # [PASS] tools/list | count=34 # TRL-10 READY - Server passes full Claude Desktop protocol validation MCP Tools Community Tier (Free — No License Key) pqc_stig — World's First DoD PQC STIG ⭐ Assesses a source code directory against PQC-01-STIG-V1R1: 12 controls covering CNSA 2.0 algorithm approval, ML-DSA-65 key strength, ML-KEM-768 encapsulation, hybrid cryptography, key storage, constant-time implementation, and certificate chain requirements. pqc_stig(scan_path?: string, profile?: "quick" | "full" | "executive") Example: "Run pqc_stig on my project and tell me if I'm CNSA 2.0 compliant" nist_map Map CCI identifiers or STIG findings to NIST 800-53 Rev 5 controls. khepra_query_stig Query the 36,195-row STIG/CCI/NIST/CMMC compliance database by control ID. dark_crypto_contribute (opt-in) Contribute anonymized cryptographic algorithm telemetry to the SouHimBou AI Dark Crypto Intelligence Network. No PII. Opt-in only — never fires without explicit invocation. Sovereign / Pharaoh Tier ert_scan Enterprise Risk & Threat scan across STIG, NIST 800-53, NIST 800-171, CMMC, and FedRAMP. Returns Godfather Report with dollar-denominated business impact. ert_scan(target: string, frameworks?: string[], output_format?: "godfather" | "json" | "csv") Example: "Run ert_scan on /etc and generate a Godfather Report" stig_check Automated RHEL-09-STIG-V1R3 compliance scan against a live system or configuration path. cmmc_assess Full CMMC Level 1, 2, or 3 assessment with gap analysis and POA&M generation. godfather_report Generate an executive Godfather Report from prior scan results: top 10 findings ranked by dollar exposure, remediation ROI, and FAIR model business impact. + 20 additional tools agent_record, dag_attestation, flight_export, khepra_get_dag_chain, nhi_inventory, acp_status, owasp_agent_assess, khepra_export_attestation, khepra_export_poam, khepra_get_compliance_score, ert_crypto, ert_readiness, stig_benchmark, ir_analysis, vuln_hunter, sbom_generate, threat_model, khepra_query_threat_intel, discover_assets, and more. The Godfather Report Unlike compliance scanners that output a wall of CVEs, KHEPRA translates findings into the language executives care about: Finding: RHEL-09-212030 — No FIPS-validated crypto on /etc/ssh Severity: CAT I (HIGH) Business Impact: $2.4M estimated breach exposure (FAIR model) Remediation Cost: $800 (4 hours engineer time) ROI: 3,000x Every finding includes control ID, framework mapping, business impact in dollars, remediation cost estimate, and ROI. Deployment Modes Mode Air-Gap Egress Telemetry Use Case sovereign ✅ Yes Zero Zero On-prem, SCIF, classified (DEFAULT) ironbank ✅ Yes Zero Zero DoD/IC production, FIPS-only hybrid ❌ No LAN Zero Edge + cloud coordination edge ❌ No Unrestricted Zero Fully stateless SaaS Set via KHEPRA_MODE environment variable. Unknown values are rejected at startup and fall back to sovereign (fail-closed). Environment Variables Variable Required Default Description KHEPRA_LICENSE_KEY Sovereign/Pharaoh only — License key. Community tier runs without one. Get at nouchix.com KHEPRA_MODE No sovereign Deployment mode: sovereign, ironbank, hybrid, edge KHEPRA_MANIFEST_PATH No manifest.json Path to signed tool manifest file KHEPRA_HOME No /var/lib/khepra Data and compliance DB directory KHEPRA_LOG_DIR No /var/log/khepra Log directory KHEPRA_DAG_PATH No ~/.khepra/dag DAG audit chain storage path KHEPRA_AUDIT_LOG_PATH No ~/.khepra/audit.ndjson Signed audit log path KHEPRA_MAX_CONCURRENT No 5 Max concurrent tool calls per agent KHEPRA_NETWORK_POLICY No lan Network scope: lan, none, unrestricted MCP_PQC_ENABLED No true Enable ML-DSA-65 PQC attestation on all responses Air-Gap & SCIF Deployment KHEPRA makes zero external network calls in sovereign and ironbank modes: License validated offline via ML-DSA-65 signed license.adinkhepra file Compliance databases (36,195 mappings) bundled in container — no external downloads No telemetry, no heartbeat, no egress — verified at the transport layer # Transfer image to air-gapped network docker save ghcr.io/nouchix/pqc-khepra-mcp:latest | gzip > khepra-mcp.tar.gz # On air-gapped host: docker load < khepra-mcp.tar.gz Note on telemetry: The dark_crypto_contribute tool (Community tier) sends anonymized cryptographic algorithm telemetry to the SouHimBou AI intelligence network only when explicitly invoked by the user. It is never triggered automatically. In sovereign/ironbank mode, all network calls are blocked at the transport layer regardless. Compliance Coverage Framework Version Mappings STIG (RHEL 9) V1R3 Automated scanning NIST 800-53 Rev 5 2,120 CCIs NIST 800-171 Rev 2 320 controls CMMC Level 3 Full practice set FedRAMP High Baseline scanning PQC-01-STIG-V1R1 V1R1 17 PQC controls (CNSA 2.0) Total 36,195+ mappings Licensing Flat annual licensing — no per-token or per-query charges. Tier Cost License Key Tools Community Free Not required pqc_stig + 12 core tools Sovereign Annual flat fee Required All 34 tools, air-gap, on-prem Pharaoh Annual flat fee Required All 34 tools + priority support + SLA Community tier is permanently free — contribute to open-source PQC adoption Sovereign/Pharaoh: contact [email protected] or visit nouchix.com Security Reporting Vulnerabilities Do not open public issues for security vulnerabilities. Report privately via GitHub Security Advisories or email [email protected]. SLA Target Acknowledgement 24 hours Initial assessment 5 business days Patch / mitigation (Critical) 30 days We accept encrypted reports via PGP (keys/security_contact.asc) and Post-Quantum channels (Dilithium / ML-DSA-65 keys in keys/). See SECURITY.md for the full disclosure policy and ASAF event taxonomy. Security Posture Deploying advanced post-quantum cryptography, air-gapped isolation, and comprehensive STIG mappings — built in direct alignment with NSA & ASD Model Context Protocol guidelines. NSA & ASD MCP Security Alignment The NSA and Australian Signals Directorate (ASD) have published specific threat vectors for AI systems interacting with local environments. KHEPRA MCP is explicitly designed to mitigate every identified vector: NSA/ASD Requirement KHEPRA Implementation Cryptographic validation of tool responses ML-DSA-65 (Dilithium) signatures on all JSON-RPC 2.0 payloads Input validation & sanitization Parameter injection resistance via strict JSON Schema validation Principle of least privilege credentials Short-lived ephemeral tokens tied to specific task execution windows Comprehensive audit logging Tamper-evident events compiled into an immutable DAG structure Resource consumption limits Rate limiting + backpressure for LLM request loops Authorization gates for sensitive actions Human-in-the-loop gate for destructive state changes Environment isolation Containerized execution with zero-egress sovereign mode Software supply chain integrity Manifest pinning for all loaded tools and dependencies Network exposure reduction Air-gappable — zero internet transit in sovereign/ironbank modes Post-quantum resilience PQC-signed DAG trail protecting against harvest-now-decrypt-later Compliance Certifications Framework Status Coverage CMMC Level 2 ✅ Automates evidence collection for AU, CM, SI, SC domains NIST SP 800-171 Rev 2 ✅ Logging, accountability, system integrity NIST SP 800-53 Rev 5 ✅ Continuous monitoring (AU-2, SI-4) FIPS 203 (ML-KEM) ✅ Key encapsulation for secure transit FIPS 204 (ML-DSA) ✅ Digital signatures for payload authentication NSM-10 PQC Mandate ✅ National Security Memorandum 10 compliance DFARS 252.204-7012 ✅ Immutable forensic trails for cyber incident reporting NSA MCP Security Guidelines ✅ Direct mapping to all published AI agent threat mitigations Live Deployment — Physical Edge Running continuously on constrained edge hardware since May 12, 2026 to prove efficiency in sovereign environments: Hardware: Raspberry Pi 2 · 1 GB RAM · 900 MHz ARM · Live Spectrum Router SCADA Pod: STM32U585 / QRB2210 · Modbus TCP · MQTT · Zephyr RTOS 3.4+ · Live Dilithium Signature Verification Controls active: 3 open ports secured · 12 STIG violations detected · 100% file integrity monitoring (AIDE) · 24/7 continuous operation Academic Validation Event Date Institution UAlbany AI Plus Symposium 2026 — "KHEPRA Protocol: Quantum-Resilient Agentic AI Security Using Cultural Cryptography" March 7, 2026 NSA CAE-CDE Institution · 200+ audience SUNY Albany Cybersecurity Showcase — First PQC key ceremony on STM32-class device (SCADA Pod) May 12–13, 2026 Live demo · SCADA architecture poster USPTO Provisional Patent #73565085 — pending. 🔒 Iron Bank containers in DISA vetting process. About NouchiX Veteran-led advisory firm translating CMMC, NIST, and STIG mandates into executive roadmaps. Sales / General: [email protected] Support: [email protected] Website: https://nouchix.com Phone: (518) 304-4450 Developed by SecRed Knowledge Inc. dba NouchiX, Albany, NY.
B+7.3 🔑 human key streamable-http smithery_api_key -
XGR.Network MCP is a connector for XGRChain and the XDaLa on-chain process engine, enabling AI agents to access chain data, inspect process activity, and prepare secure workflow actions for user-controlled wallet signing.
C+5.8 🔑 human key streamable-http smithery_api_key -
Korean market data for AI agents and e-commerce sellers sourcing from Korea — K-beauty/K-food/K-pop product search, Naver search trends, Korean stocks with English DART disclosure summaries, apartment transactions, tourism, and weather. English JSON. 13 tools. Free pilot: preview works without any key; self-serve free keys at https://kdata-gate.vercel.app
B+7.6 🔑 human key streamable-http smithery_api_key -
—
C+5.8 🔑 human key streamable-http smithery_api_key -
Email infrastructure for AI agents — send, receive, search, and manage email over a clean HTTP API. Connect verified domains, route inbound mail, set up webhooks, and automate email workflows. Authenticate with a Primitive API key or via OAuth.
C+6.0 🔑 human key streamable-http smithery_api_key -
uptime_30d 1.0%; p95 248.0ms; conformance: fail
A8.1 🔓 open streamable-http -
xProofhttps://xproof.app/mcp● healthy
uptime_30d 1.0%; p95 181.8ms; conformance: fail
A8.1 🔓 open streamable-http -
uptime_30d 1.0%; p95 90.2ms; conformance: fail
B+7.5 🔓 open streamable-http -
uptime_30d 1.0%; p95 148.7ms; conformance: fail
A8.2 🔓 open streamable-http -
orbuchttps://orbuc--ben-c8tp.run.tools● healthy
uptime_30d 1.0%; p95 187.8ms; conformance: fail
B6.2 🔓 open -
TradeStaqhttps://mcp.tradestaq.com/mcp● healthy
AI-powered crypto trading tools for strategies, backtesting, bots, and portfolio management.
C+5.2 🔑 human key streamable_http oauth