Measurement, never certification

The MCP Trust Board

One question per round: how many publicly enumerable MCP servers answer a correct protocol handshake, and under what authentication posture? Nothing more. Never server quality, never safety, never a trust score. Host names are withheld by design — naming is not the product.

Latest round · 2026-09-14T10:38:01Z

257 of 500 enumerated hosts answered a correct MCP initialize; 207 answered with an auth challenge (a term sheet, not delivery); 18 were unreachable or gone (never FAIL). Counts only by doctrine.

Enumeration: 500 unique hosts from 2244 registry rows (https://registry.modelcontextprotocol.io/v0/servers). Enumeration incomplete — recorded, never passed off as complete (cap reached).

Answered handshake · tools counted238
Answered handshake · open19
Auth challenge (401/403 — a term sheet, not delivery)207
Payment challenge (402 — an invoice, not delivery)0
Alive, but no protocol-valid MCP reply6
Listed, no usable reply0
Unreachable or gone (never FAIL)18
Other error12

Round-to-round delta — a single observation is a snapshot; the delta is the board

vs previous round 2026-09-12.json (2026-09-12T17:09:11Z). Arithmetic on the two published count sets — derived, never typed.

alive_not_mcp+1
auth_scheme_bearer_or_oauth+1
auth_scheme_unspecified-1
dead_404_or_unreachable-1
initialize_ok_open-1
initialize_ok_tools_listed-1
other_error+2
registry_rows_seen+31
servers_reporting_tools-1
tools_listed_total+56

Hosts added / dropped / bucket migrations: UNCHECKABLE — per-host rows are retained operator-side and never published, so a counts-only diff never invents host-level claims.

Auth posture observed

188

challenges indicating bearer/OAuth-family schemes

Tools listed (aggregate)

1657

across 238 answering servers · median 3 each — counted, never called, never named

Rate-limited probes

0

the board backs off; it never retries into a rate limit

What this does not measure

This snapshot does not measure server quality, the safety of any tool, whether a listed tool does what its name claims, compliance with the MCP authorization specification, or any property of servers not listed in the enumeration source. The true internet-facing population is larger than the enumerable one and stays an open, unmeasured cell.

Third-party context

A third-party study ('Exposed by Design') reportedly found ~21,000 internet-facing MCP servers, 91.8% without OAuth. That figure is cited as context only — it is NOT a CSOAI measurement and is not reproduced here.

Method

One POST initialize (protocol 2025-06-18) per host, identifiable UA 'csoai-mcp-trust/0.1 (+https://councilof.ai/trust)', 14s timeout, 12 workers; exactly one tools/list if and only if initialize answered — tools counted, never called, never named. Zero authentication attempted, zero payment, zero signing, zero side effect.

The rules of this board

  • Read-only by construction: one initialize per host per week; one tools/list only if the handshake answers. Tools are counted, never called.
  • No authentication is ever attempted — the board holds no credentials and never will.
  • A 401/402 challenge is recorded as a term sheet. It is never a verdict.
  • UNREACHABLE is never FAIL. A timeout says where we stood, not what they are.
  • Counts, snapshots and diffs are free, public, forever. A named party may commission a signed card for their own server via the existing metered door; host-level data about other parties' servers is not for sale at any price.