See inside an MCP server before you connect it.
Inspect tools, schemas, capabilities and MCP annotations in seconds. Free, fast and no signup required.
Browser-first inspection with a secure fallback when needed. No tools are ever executed.
- No signup
- No database
- No tool execution
What is an MCP server inspector?
An MCP inspector reads the public interface exposed by a Model Context Protocol server and lists tools, resources, prompts, schemas and declared metadata without needing to execute those tools. MCP X-Ray does this from the browser when possible, then uses a secure Worker fallback if the server blocks cross-origin requests.
What MCP X-Ray checks
It reports whether an HTTP endpoint answers as an MCP server, then shows server identity, protocol version, transport, capabilities, tools, input and output schemas, resources, prompts, and any declared MCP annotations.
What MCP X-Ray does not check
It does not prove a server is safe, does not execute tools, does not detect malware, does not guarantee annotations are truthful, and does not perform penetration testing.
FAQ
What is an MCP server?
An MCP server is a program that exposes tools, resources and prompts to AI clients through the Model Context Protocol, usually over Streamable HTTP or a local stdio process.
What is an MCP server inspector?
An MCP server inspector reads discovery metadata from a server so you can see the tools and schemas it advertises before connecting it to a client.
Does MCP X-Ray execute tools?
No. MCP X-Ray only uses MCP discovery and metadata operations needed to inspect the server interface.
Can MCP X-Ray tell me if an MCP server is safe?
No. MCP X-Ray helps you understand what a server exposes, but it cannot guarantee the server behaves as described.
What are MCP tool annotations?
Annotations such as read-only, destructive, idempotent and open-world are hints supplied by the server. They are informational and can be incomplete or untrue.
Why can't MCP X-Ray inspect some servers?
Some servers require authentication, live on private networks, use stdio instead of HTTP, or speak a transport MCP X-Ray does not support. CORS can also block browser-direct inspection; the Worker fallback covers that case for public HTTP endpoints.
Does MCP X-Ray support local stdio MCP servers?
The URL inspector supports remote HTTP MCP endpoints. For local or stdio servers, paste the tools JSON instead.
Does MCP X-Ray store the servers I inspect?
There is no account, application database, or saved inspection history. Browser-direct inspections stay in your browser. Worker fallback requests are processed to complete the inspection and are not intentionally persisted.