Privacy

No account. No saved inspection history. MCP X-Ray does not intentionally persist the endpoints you inspect.

  • There are no user accounts and no application database.
  • When possible, inspection happens directly in your browser and never leaves your device as a fallback request.
  • If the browser cannot reach the server, a Cloudflare Worker fetches only the MCP discovery metadata needed to build the report.
  • Target endpoints are not intentionally stored after that request completes. Successful public fallback results may be cached briefly to keep the free service fast.
  • MCP tools are never executed.
  • Pasted manual JSON is parsed in your browser and is not sent to the backend.
  • MCP X-Ray does not set cookies and does not use a consent banner.
  • Optional Cloudflare Web Analytics may be enabled. When the site token is configured, a cookie-free beacon counts visits and referrers. If the token is empty, no beacon is loaded.
  • The page may send a tiny same-origin POST /api/e for these counts only: inspection run (browser-direct vs Worker fallback), inspection failed, shared-link page load, and copy actions (link, post, markdown). The endpoint accepts a fixed event-name allowlist. Accepted events are written as Worker log lines with the event name and optional via only. It does not store endpoint URLs, paths, query strings, tokens, or IP addresses.

This page describes MCP X-Ray's application behavior. It does not make absolute claims about infrastructure providers never processing request metadata.