METHODOLOGY
MCP Verify methodology
How MCP Verify scores servers, handles freshness, reports confidence, and keeps paid status separate from objective trust evidence.
Search • Governance: TrustOps / Gateway / Compare • Publishers: Claim / Badges / Profiles • Research: Trust Index / Rankings • Docs: Methodology / Security / MCP API • Pricing • Sign in
More: About • Changelog • Status • Shortlists • Digests • RSS • RSS XML • Discovery sources • Scan my server • Submit repo • GitHub Action • Docs Compiler • Agent commerce
What the score means
The public Verify score is evidence-based and derived from validation, metadata, transport, auth, tool-surface, compatibility, and maintenance signals.
- Scores are objective evidence summaries, not paid placement.
- Claimed or paid publisher status can add evidence but never directly improves the objective score.
- Server pages show the score with percentile, evidence age, confidence, and risk drivers so the number is not interpreted in isolation.
Freshness
Freshness is measured from the latest completed validation. Public freshness filters use the configured validation freshness window; strong live candidates use a fixed 48-hour window.
- Fresh evidence is preferred in default ranking.
- Stale evidence remains searchable but should not be treated as production approval.
- Validation history is shown as a trend only after at least two validation runs.
Percentile and confidence
Percentile compares a server to the currently scored public catalog. Confidence communicates evidence completeness, recency, and validation density.
- Percentile is a catalog-relative signal and may move as the catalog grows.
- Confidence is not a replacement for the score or the production decision.
- Buyers should review top risk drivers before approving a server for production use.
Limits
Verify cannot prove every runtime behavior from public metadata alone.
- Authenticated validation provides stronger evidence than unauthenticated metadata.
- Write and execution-capable tools require policy review even when the server initializes cleanly.
- Publishers can improve profiles by claiming ownership, adding metadata, and keeping validation evidence fresh.