Tools / MCP Server Probe
MCP Server Probe
Send a standard MCP initialize handshake to an endpoint and see what it reveals: server identity, exposed tools, auth requirements. Runs from your browser — probe only servers you own or are authorized to test.
Tries /mcp, then /sse, then the raw URL. Sends one standard MCP initialize handshake — nothing more. If the browser blocks the request (CORS), the tool hands you a curl sequence to run instead.
Enter an endpoint and hit Probe. Authorized testing only — this sends a real handshake to whatever you point it at.
// About this tool
MCP Server Probe
This tool sends one standard MCP initialize JSON-RPC request to the endpoint you provide, then a tools/list request when the handshake succeeds. It reports the server's identity, the tools it exposes, and whether it requires authentication (HTTP 401/403).
It tries /mcp, then /sse, then the raw URL you entered, because MCP-over-HTTP servers commonly mount their endpoint at one of those paths. If the browser blocks the cross-origin request (CORS), the tool says so explicitly and hands you a copyable curl sequence to run instead — a CORS block says nothing about the server's health.
This is a passive handshake, not an attack. It sends no tool calls and executes nothing. Use it only on servers you own or are authorized to test.
// When to use it
Check a server you just deployed
Point it at your MCP endpoint and confirm the handshake succeeds, the serverInfo is correct, and the expected tools are listed.
Verify auth is actually enforced
A 401/403 response means the server is reachable and requires credentials — a good finding if you expected it, a red flag if you didn't.
Audit a server before wiring it into your agent
See what tools an MCP server exposes before you grant it access to your environment. Pair with the AI Agent Config Checker for the config side.
// Questions
Is this an attack tool?
No. It sends a standard MCP initialize handshake — the same request any MCP client sends — and reads the response. It never calls tools, never executes anything, and never sends credentials. Use it only on servers you own or are authorized to test.
Why did the browser block my request?
Cross-origin requests are blocked by the browser unless the server sends CORS headers. That's a browser policy, not a server verdict — the server may be perfectly healthy. Use the copyable curl sequence to probe it directly.
What does a 401/403 mean?
The server is reachable and enforcing authentication. That's a good finding if you expected auth, and a red flag if you didn't — an MCP endpoint that should be private but answers without auth is an exposed service.
What endpoints does it try?
/mcp, then /sse, then the raw URL you entered. MCP-over-HTTP servers commonly mount at one of those paths, so the tool tries them in order and reports which one answered.
Is this tool free?
Yes. Free, runs locally in your browser, no account required.