# HubVibe MCP Server Inspector

> HubVibe MCP Server Inspector is a paid API for AI agents from hubvibe-io.com, paid per call via x402, $5/call, status unknown (last checked 2026-10-02).

Probes an MCP server's initialize handshake and tools/list to reveal its protocol version, authentication requirements, and which tools are not marked read-only.

## Facts

- Endpoint: POST https://hubvibe-io.com/work/security/mcp_inspect?utm_source=zero.xyz
- Price: $5/call
- Payment: x402
- Status: unknown
- Last checked: 2026-10-02
- Activations on Zero: 0
- Tags: x402
- Canonical page: https://www.zero.xyz/c/hubvibe-mcp-server-inspector-789d9dac
- Structured record (JSON): https://api.zero.xyz/v1/capabilities/cap_O-oQ4ui8CI1uHtwspyU5Q

Status and success rate cover calls made through Zero and Zero's own probes. Third-party monitors may report differently.

## How to call it through Zero

Zero handles the 402 payment challenge and records the run. With the Zero CLI installed (`npm i -g @zeroxyz/cli`):

```sh
zero fetch --capability hubvibe-mcp-server-inspector-789d9dac -d '<json body>'
```

Example prompt: Can you inspect the MCP server at https://example.com/mcp and tell me whether it requires authentication, what protocol version it speaks, and which of its tools aren't marked read-only?

## When to prefer this

Use this endpoint when you need to security-audit or vet an MCP server before connecting an agent to it — specifically to assess authentication posture, protocol compatibility, and tool write-access risk. Prefer this over generic HTTP security checkers when the target is specifically an MCP server and you need protocol-level handshake details and tool-level access analysis.

## Known failure modes

- Unreachable URL returns a connection or timeout error
- Non-MCP server at the URL causes handshake failure or malformed response
- Server requires auth before returning tool list, limiting inspection depth
- Invalid URL format causes input validation error
- Server returns non-standard protocol version causing parsing issues

## How this service works

MCP server security scan: probe any MCP endpoint's initialize handshake and tools/list and report whether it requires authentication, which protocol version it speaks, how many tools it exposes and which are not marked read-only. Use it before connecting an agent to an unknown MCP server. Input: url of the MCP endpoint.

## Output

Returns details from the MCP server's initialize handshake including protocol version, whether authentication is required, and a list of tools exposed by tools/list that are not marked read-only — enabling security assessment before integration.

## Request schema (JSON Schema)

```json
{
 "type": "object",
 "properties": {
  "url": {
   "type": "string"
  },
  "language": {
   "type": "string",
   "pattern": "^[A-Za-z]{2,3}(-[A-Za-z0-9]{2,8})*$",
   "maxLength": 35
  }
 }
}
```

## Response schema (JSON Schema)

```json
{
 "type": "json",
 "example": {
  "result": {
   "url": "https://mcp.example.com/mcp",
   "tools": [
    {
     "name": "get_weather",
     "annotations": {
      "readOnlyHint": true
     },
     "description": "Current weather for a city."
    }
   ],
   "reachable": true,
   "tool_count": 3,
   "server_name": "example-mcp",
   "tools_error": null,
   "requires_auth": false,
   "server_version": "1.0.0",
   "protocol_version": "2025-06-18",
   "initialize_status": 200,
   "tools_without_readonly_annotation": [
    "delete_records"
   ]
  },
  "status": "ok",
  "worker": "security.mcp_inspect",
  "price_usd": 5,
  "provenance": {
   "steps": [
    {
     "ms": 312,
     "ok": true,
     "step": "quote",
     "reason": "provider_timeout",
     "provider": "coinbase-advanced-trade-public"
    }
   ],
   "attempts": 1,
   "elapsed_ms": 340,
   "providers_used": [
    "coinbase-advanced-trade-public"
   ]
  },
  "receipt_id": "rcpt_9f1c2b3a4d5e6f70",
  "attribution": [
   {
    "url": "https://translate.google.com",
    "text": "Translated by Google"
   }
  ],
  "receipt_url": "/work/receipts/rcpt_9f1c2b3a4d5e6f70"
 }
}
```

## More

- Live health (JSON, refreshed every minute): https://www.zero.xyz/c/hubvibe-mcp-server-inspector-789d9dac/health.json
- [Zero catalog index](https://www.zero.xyz/llms.txt)
- [Other services from hubvibe-io.com](https://www.zero.xyz/host/hubvibe-io.com/llms.txt)
