Registry
by policylayer.com in Security & trust
The MCP server that vets MCP servers: identity, risk grade and per-tool risk before you install.
https://api.policylayer.com/mcp
Last 30 days
- Uptime
- 100%
- Response time
- 313 ms typical, 313 ms slowest 5%
- Last check
- 2 h ago
- Next check
- in 4 h
How to call it
Add it to any MCP client that supports remote servers.
{
"mcpServers": {
"registry-2": {
"type": "http",
"url": "https://api.policylayer.com/mcp"
}
}
}5 tools
- check_mcp_server
Check an MCP server against the PolicyLayer registry BEFORE installing or allowing it. Accepts a registry slug, an npm package name (scoped or not), a remote server URL (https://…), or a server name. Returns the full published record: identity verification with its evidence, risk
- check_mcp_stack
Check a whole MCP stack against the PolicyLayer registry in one call — up to 25 servers, each given as candidate identifiers (npm package name, registry slug, or remote URL) tried in order until one resolves. Returns the published record for every hit — plus a deterministic verdi
- search_registry
Search the PolicyLayer registry of published MCP servers by name, slug or package substring. Returns candidate matches with risk grade, identity confidence (verified / unverified / mismatch — mismatch means it claims to be an official server with no verifiable link to the brand)
- check_tool
One tool's full risk classification on a published MCP server: category, severity, risk analysis and evidence, OWASP classes, parameter schema and the recommended policy default. Use when deciding whether to allow a specific tool call, e.g. "should execute_sql on this server be p
- get_change_events
The registry change feed: tool-surface drift, auth-posture flips, impostor flags, version bumps — every event the freshness watchers emit, id-cursored so a consumer resumes exactly where it stopped. Requires a Registry Licence key (Authorization: Bearer plr_...); self-serve at ht
Security scan
- No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.
Recent checks
| When | Result | HTTP | Time |
|---|---|---|---|
| 2 h ago | Passed | 200 | 313 ms |