legal / listing-guidelines

Listing guidelines

What we look for before a server goes live in the directory — and what gets a listing removed.

last updated: 2026-08-26

01Baseline requirements

A public repository with a README and a license, a working install path for at least one MCP client, and tools documented with names and descriptions. Remote servers must expose a reachable endpoint over HTTPS and state their auth method (OAuth, API key, or none).

02Honest descriptions

Describe what the server actually does today, not a roadmap. No keyword stuffing, no impersonating another project, and no claiming "Official" status unless the listing is maintained by the vendor of the product it integrates with — official badges are assigned by our review, not self-declared.

03Security expectations

No credential harvesting, no undisclosed telemetry, no writing outside the scopes the user granted. Servers should request the minimum permissions they need and document required environment variables and tokens. We remove listings reported for malicious behavior and may note the removal publicly.

04Icons and branding

Icons must be square, at most 1 MB, and yours to use. Using another company's logo is acceptable only for integrations that company itself ships or sanctions.

05Staying listed

We re-index listings regularly. Repositories that disappear, endpoints that stay unreachable, or projects archived by their authors may be delisted. You can request an update or removal at any time from the server's page or by emailing listings@mcp.site.

06Built with GetMCP

Servers created on the GetMCP platform are listed automatically with hosting details and auth type filled in. The same guidelines apply; automation does not exempt a listing from review or removal.

Questions about this page? Email legal@mcp.site.
>_ esc
↑↓ navigate↵ openesc close