Outlit
Outlit gives agents real-time understanding of customers to automate support and revenue workflows.
Block For Production
trustsnap_dfd1aded2546652b.- Transport Compliance
- Tool Surface Design
- Tool Snapshot Churn
- Make tools/list succeed unauthenticated when possible, or document the auth flow in the server card.
- Allow initialize to succeed consistently, or return a deterministic auth-required response with clear metadata.
- Compare initialize responses between the latest two runs and restore the previous stable behavior.
- Search crawler activity
- profile inspection
Dispute this assessment
If any published claim about this server -- its score, a risk flag, a capability classification, or its taxonomy -- is factually wrong, tell us what evidence shows and we will review it. This does not require claiming or verifying ownership of the server first.
Verify responds to disputes within 5 business days and resolves them within 15.
Dispute history
No disputes filed for this server.
Risk
Security posture
Tool capability & risk inventory
No tool inventory available from the latest validation run.
Write-action governance
Status detail: No write-action governance evidence is available yet.
| Tool | Risk | Flags | Safeguards |
|---|---|---|---|
| No high-risk tools were detected on the latest run. | |||
Action-controls diff
Need at least two validation runs before diffing action controls.
Critical alerts
Compatibility
Client compatibility verdicts
Client compatibility only means the server shape can work with a client. Production trust decision and write-action publishing are evaluated separately so a client-compatible server can still be blocked for production.
Evidence provenance
initialize• Auth Requiredtools_list• Auth Requiredtransport_compliance_probe• Errorstep_up_auth_probe• Warningconnector_replay_probe• Missing — Frozen tool snapshots must survive refresh.request_association_probe• Missing — Roots, sampling, and elicitation should stay request-scoped.
Evidence provenance
initialize• Auth Requiredtools_list• Auth Requiredtransport_compliance_probe• Error
Evidence provenance
action_safety_probe• Not_Assessed
Evidence provenance
tool_snapshot_probe• Missingconnector_replay_probe• Missing
Client compatibility gate details
Remediation checklist
OpenAI connectors expect OAuth for remote server auth.Dynamic client registration materially improves connector setup.tools/list must succeed.Transport compliance should be in good shape.OAuth interoperability should be strong.The tool surface is not limited to search/fetch-style read tools.
Remediation checklist
tools/list must succeed.Transport behavior should match Claude-compatible HTTP expectations.A useful Claude integration needs at least one exposed tool.The tool surface is not limited to search/fetch-style read tools.OAuth is not configured, so this client cannot authenticate without additional setup.Not yet safe for company-knowledge use: requires a search/fetch-only surface with no write actions present.
Remediation checklist
Add confirmation or dry-run semantics for risky actions.Production readiness is blocked by an active alert: Initialize flow regressed.Production readiness is blocked by an active alert: tools/list regressed.
Verdict traces
initialize_regressed• critical • Initialize flow regressedtools_list_regressed• critical • tools/list regressed
Client verdict trace table
| Verdict | Status | Checks | Winning source | Conflicts |
|---|---|---|---|---|
openai_connectors |
Not client-compatible | initialize, tools_list, transport_compliance_probe, step_up_auth_probe, connector_replay_probe, request_association_probe | live_validation | none |
claude_desktop |
Not client-compatible | initialize, tools_list, transport_compliance_probe | live_validation | none |
unsafe_for_write_actions |
Publishing blocked | action_safety_probe | live_validation | none |
snapshot_churn_risk |
Low | tool_snapshot_probe, connector_replay_probe | history | none |
Publishability policy profiles
- Search Fetch Only: No
- Write Actions Present: No
- Oauth Configured: No
- Admin Refresh Required: No
- Safe For Company Knowledge: No
- Safe For Messages Api Remote Mcp: No
- Search Fetch Only: No
- Write Actions Present: No
- Oauth Configured: No
- Admin Refresh Required: No
- Safe For Company Knowledge: No
- Safe For Messages Api Remote Mcp: No
Compatibility fixtures
- remote_http_endpoint: Passes
- oauth_discovery: Degraded
- frozen_tool_snapshot_refresh: Passes
- request_association: Passes
- remote_transport: Passes
- tool_discovery: Likely to fail
- auth_connect: Passes
- safe_write_review: Degraded
Recommended for
No recommendation profile is available yet.
Evidence
Current trust snapshot
trustsnap_dfd1aded2546652bCanonical machine links
Evidence confidence
Latest validation evidence
Failures
initializeClient error '401 Unauthorized' for url 'https://mcp.outlit.ai/mcp' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/401oauth_authorization_serverno authorization serveroauth_protected_resourceClient error '404 Not Found' for url 'https://mcp.outlit.ai/.well-known/oauth-protected-resource' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404openid_configurationno authorization servertools_listClient error '401 Unauthorized' for url 'https://mcp.outlit.ai/mcp' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/401transport_compliance_probeIssues: missing protocol header, bad protocol not rejected (bad protocol=401).
Checks
| Check | Status | Latency | Evidence |
|---|---|---|---|
action_safety_probe |
Not_Assessed | n/a | No write-action risk evidence recorded. |
advanced_capabilities_probe |
Warning | n/a | Only 3 capability signal(s): completions, prompts, resources. |
connector_publishability_probe |
Error | n/a | Publishability blockers: tools list, protocol version, transport compliance, action safety, +2 more. |
connector_replay_probe |
Missing | n/a | No connector replay evidence recorded. |
determinism_probe |
Missing | n/a | tools list unavailable |
initialize |
Auth Required | 171.1 ms | Client error '401 Unauthorized' for url 'https://mcp.outlit.ai/mcp' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/401 |
interactive_flow_probe |
OK | n/a | Check completed |
oauth_authorization_server |
Missing | n/a | no authorization server |
oauth_protected_resource |
Error | 47.7 ms | Client error '404 Not Found' for url 'https://mcp.outlit.ai/.well-known/oauth-protected-resource' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404 |
official_registry_probe |
OK | n/a | Check completed |
openid_configuration |
Missing | n/a | no authorization server |
probe_noise_resilience |
OK | 963.6 ms | Fetched https://mcp.outlit.ai/robots.txt |
prompt_get |
Missing | n/a | not advertised |
prompts_list |
Auth Required | 193.4 ms | Client error '401 Unauthorized' for url 'https://mcp.outlit.ai/mcp' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/401 |
protocol_version_probe |
Missing | n/a | No protocol version was advertised. |
provenance_divergence_probe |
Not_Assessed | n/a | Check completed |
request_association_probe |
Missing | n/a | No request-association capabilities were advertised. |
resource_read |
Missing | n/a | not advertised |
resources_list |
Auth Required | 277.0 ms | Client error '401 Unauthorized' for url 'https://mcp.outlit.ai/mcp' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/401 |
schema_divergence_probe |
Missing | n/a | no live tools |
server_card |
OK | 310.0 ms | 0 prompt(s) exposed |
session_resume_probe |
Missing | n/a | no session id |
step_up_auth_probe |
Warning | n/a | Step-up challenge hints present. |
tool_snapshot_probe |
Missing | n/a | no tools |
tools_list |
Auth Required | 172.5 ms | Client error '401 Unauthorized' for url 'https://mcp.outlit.ai/mcp' For more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/401 |
transport_compliance_probe |
Error | 271.4 ms | Issues: missing protocol header, bad protocol not rejected (bad protocol=401). |
utility_coverage_probe |
OK | 149.7 ms | Completions advertised; no pagination evidence; tasks auth required. |
Raw evidence view
Show raw JSON evidence
{
"checks": {
"action_safety_probe": {
"details": {
"auth_present": true,
"confirmation_signals": [],
"reason": "empty_observation_set",
"safeguard_count": 0,
"summary": {
"annotation_conflict_tools": 0,
"bulk_access_tools": 0,
"capability_distribution": {},
"declared_non_read_only_tools": 0,
"destructive_tools": 0,
"egress_tools": 0,
"exec_tools": 0,
"has_non_read_capability": false,
"high_risk_tools": 0,
"risk_distribution": {
"critical": 0,
"high": 0,
"low": 0,
"medium": 0
},
"secret_tools": 0,
"tool_count": 0
}
},
"latency_ms": null,
"status": "not_assessed"
},
"advanced_capabilities_probe": {
"details": {
"capabilities": {
"completions": true,
"elicitation": false,
"prompts": true,
"resource_links": false,
"resources": true,
"roots": false,
"sampling": false,
"structured_outputs": false
},
"enabled": [
"completions",
"prompts",
"resources"
],
"enabled_count": 3,
"initialize_capability_keys": []
},
"latency_ms": null,
"status": "warning"
},
"connector_publishability_probe": {
"details": {
"blockers": [
"tools_list",
"protocol_version",
"transport_compliance",
"action_safety",
"tool_surface",
"auth_flow"
],
"criteria": {
"action_safety": false,
"auth_flow": false,
"connector_replay": true,
"initialize": true,
"protocol_version": false,
"remote_transport": true,
"request_association": true,
"server_card": true,
"session_resume": true,
"step_up_auth": true,
"tool_surface": false,
"tools_list": false,
"transport_compliance": false
},
"high_risk_tools": 0,
"tool_count": 0,
"transport": "streamable-http"
},
"latency_ms": null,
"status": "error"
},
"connector_replay_probe": {
"details": {
"reason": "no_tools"
},
"latency_ms": null,
"status": "missing"
},
"determinism_probe": {
"details": {
"reason": "tools_list_unavailable"
},
"latency_ms": null,
"status": "missing"
},
"initialize": {
"details": {
"error": "Client error '401 Unauthorized' for url 'https://mcp.outlit.ai/mcp'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/401",
"headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=31536000; includeSubDomains",
"www-authenticate": "Bearer error=\"invalid_token\", error_description=\"Outlit MCP requires an Authorization: Bearer token. Use the workspace MCP URL and complete OAuth in your MCP client. Legacy or headless clients that do not support OAuth must send their configured bearer credential.\", resource_metadata=\"https://mcp.outlit.ai/.well-known/oauth-protected-resource/mcp\""
},
"http_status": 401,
"payload": {},
"url": "https://mcp.outlit.ai/mcp"
},
"latency_ms": 171.11,
"status": "auth_required"
},
"interactive_flow_probe": {
"details": {
"oauth_supported": false,
"prompt_available": false,
"risk_hits": [],
"safe_hits": [
"oauth",
"browser"
]
},
"latency_ms": null,
"status": "ok"
},
"oauth_authorization_server": {
"details": {
"reason": "no_authorization_server"
},
"latency_ms": null,
"status": "missing"
},
"oauth_protected_resource": {
"details": {
"error": "Client error '404 Not Found' for url 'https://mcp.outlit.ai/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404",
"url": "https://mcp.outlit.ai/.well-known/oauth-protected-resource"
},
"latency_ms": 47.69,
"status": "error"
},
"official_registry_probe": {
"details": {
"direct_match": true,
"official_peer_count": 1,
"registry_identifier": "ai.outlit/outlit",
"registry_source": "official_registry"
},
"latency_ms": null,
"status": "ok"
},
"openid_configuration": {
"details": {
"reason": "no_authorization_server"
},
"latency_ms": null,
"status": "missing"
},
"probe_noise_resilience": {
"details": {
"headers": {
"content-type": "text/html; charset=utf-8",
"strict-transport-security": "max-age=31536000; includeSubDomains"
},
"http_status": 404,
"url": "https://mcp.outlit.ai/robots.txt",
"validation_disallowed": false
},
"latency_ms": 963.61,
"status": "ok"
},
"prompt_get": {
"details": {
"reason": "not_advertised"
},
"latency_ms": null,
"status": "missing"
},
"prompts_list": {
"details": {
"error": "Client error '401 Unauthorized' for url 'https://mcp.outlit.ai/mcp'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/401",
"headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=31536000; includeSubDomains",
"www-authenticate": "Bearer error=\"invalid_token\", error_description=\"Outlit MCP requires an Authorization: Bearer token. Use the workspace MCP URL and complete OAuth in your MCP client. Legacy or headless clients that do not support OAuth must send their configured bearer credential.\", resource_metadata=\"https://mcp.outlit.ai/.well-known/oauth-protected-resource/mcp\""
},
"http_status": 401,
"payload": {},
"reason": "auth_required",
"url": "https://mcp.outlit.ai/mcp"
},
"latency_ms": 193.36,
"status": "auth_required"
},
"protocol_version_probe": {
"details": {
"latest_known_version": "2025-11-25",
"reason": "no_protocol_version",
"validator_protocol_version": "2025-03-26"
},
"latency_ms": null,
"status": "missing"
},
"provenance_divergence_probe": {
"details": {
"comparable_field_count": 0,
"compared_fields": [
"title",
"version",
"homepage",
"repository"
],
"direct_official_match": true,
"drift_fields": [],
"metadata_document_count": 3,
"readable_sources": [
"registry",
"server_card"
],
"registry_homepage": null,
"registry_repository": null,
"registry_title": null,
"registry_version": null,
"server_card_homepage": null,
"server_card_repository": null,
"server_card_title": "Outlit",
"server_card_version": "1.0.0"
},
"latency_ms": null,
"status": "not_assessed"
},
"request_association_probe": {
"details": {
"reason": "no_request_association_capabilities_advertised"
},
"latency_ms": null,
"status": "missing"
},
"resource_read": {
"details": {
"reason": "not_advertised"
},
"latency_ms": null,
"status": "missing"
},
"resources_list": {
"details": {
"error": "Client error '401 Unauthorized' for url 'https://mcp.outlit.ai/mcp'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/401",
"headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=31536000; includeSubDomains",
"www-authenticate": "Bearer error=\"invalid_token\", error_description=\"Outlit MCP requires an Authorization: Bearer token. Use the workspace MCP URL and complete OAuth in your MCP client. Legacy or headless clients that do not support OAuth must send their configured bearer credential.\", resource_metadata=\"https://mcp.outlit.ai/.well-known/oauth-protected-resource/mcp\""
},
"http_status": 401,
"payload": {},
"reason": "auth_required",
"url": "https://mcp.outlit.ai/mcp"
},
"latency_ms": 277.01,
"status": "auth_required"
},
"schema_divergence_probe": {
"details": {
"card_server_name": "Outlit",
"compared_dimensions": [
"server_name",
"server_version",
"declared_vs_observed_auth",
"tool_membership",
"parameter_names",
"required_parameters",
"parameter_types",
"output_schema_presence"
],
"compared_tool_count": 0,
"live_server_name": null,
"reason": "no_live_tools",
"server_name_mismatch": false
},
"latency_ms": null,
"status": "missing"
},
"server_card": {
"details": {
"headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=31536000; includeSubDomains"
},
"http_status": 200,
"payload": {
"authentication": {
"description": "Use the workspace-specific MCP URL from Outlit settings and complete OAuth in your MCP client.",
"required": true,
"schemes": [
"oauth2"
],
"type": "oauth2"
},
"description": "Outlit is the real-time understanding of every customer, the infrastructure agents use to automate customer operations.",
"documentationUrl": "https://docs.outlit.ai/ai-integrations/mcp",
"icon": "https://outlit.ai/images/logos/outlit-logo-square.png",
"icons": [
{
"sizes": "516x516",
"src": "https://outlit.ai/images/logos/outlit-logo-square.png",
"type": "image/png"
}
],
"name": "Outlit",
"prompts": [],
"resources": [],
"serverInfo": {
"name": "Outlit",
"version": "1.0.0"
},
"serverUrl": "https://mcp.outlit.ai/mcp",
"serverUrlUsage": "The generic serverUrl is available for discovery and OAuth-capable MCP clients. Prefer the workspace-specific URL from Outlit settings when configuring a client.",
"tools": [
{
"description": "Browse and filter customers. Use this to find customers by billing status, activity recency, revenue, or name. Returns a paginated list with summary info (MRR, last activity, status).",
"name": "outlit_list_customers"
},
{
"description": "Browse and filter users. Use this to find users by journey stage, activity recency, customer, or email/name. Returns a paginated list with activity info.",
"name": "outlit_list_users"
},
{
"description": "Browse internal workspace users such as CSMs, managers, account owners, and admins. Use this to discover who owns customers before composing dynamic reports across account books.",
"name": "outlit_list_workspace_users"
},
{
"description": "Get full details for a single customer. Use this when you already know which customer you want to inspect. Optionally include related data (users, revenue, recent activity, engagement metrics, company enrichment).",
"name": "outlit_get_customer"
},
{
"description": "Assign an active workspace member as this customer\u2019s primary owner. The former owner keeps Editor access.",
"name": "outlit_assign_customer_owner"
},
{
"description": "Share a customer with an active workspace member as a Viewer or Editor. The customer ID must be exact.",
"name": "outlit_grant_customer_access"
},
{
"description": "Change an existing customer collaborator between Viewer and Editor.",
"name": "outlit_update_customer_access"
},
{
"description": "Remove a collaborator\u2019s explicit access to a customer.",
"name": "outlit_revoke_customer_access"
},
{
"description": "Get the chronological activity timeline for a customer. Use this to see what happened and when \u2014 emails, calls, Slack messages, billing events, etc. Supports channel and date filtering.",
"name": "outlit_get_timeline"
},
{
"description": "List structured facts known about a customer. Use filters like status, sourceTypes, factTypes, factCategories, and date bounds to narrow the result set. For topic-specific retrieval, use outlit_search_customer_context instead.",
"name": "outlit_list_facts"
},
{
"description": "Get one exact fact by ID. Returns the canonical fact shape and optionally expands requested related data such as evidence.",
"name": "outlit_get_fact"
},
{
"description": "Get one exact source record by generic sourceType and sourceId. Use this when you already know the concrete underlying source you want to inspect.",
"name": "outlit_get_source"
},
{
"description": "List concrete source records deterministically. Use this instead of semantic search when you need enumerated calls, emails, calendar events, support tickets, Slack conversations, or opportunities.",
"name": "outlit_list_sources"
},
{
"description": "Search across all known customer context using a natural-language query. Returns ranked artifact-level discovery previews with at most two matching excerpts per source or fact. Use outlit_get_source with a returned sourceType and sourceId when you need the canonical source contents. Omit customer to search across all customers in the organization.",
"name": "outlit_search_customer_context"
},
{
"description": "Execute read-only SQL queries against your analytics views.\n\nAvailable views:\n- activity: Customer activity events (event_name, event_type, event_channel, customer_id, occurred_at, properties, ...)\n- customers: Customer attributes (customer_id, domain, name, billing_status, plan, mrr_cents, traits, ...)\n- users: User attributes (user_id, email, name, customer_id, traits, ...)\n- revenue: Revenue snapshots over time (customer_id, snapshot_date, mrr_cents, ...)\n\nAll queries are automatically filtered to your organization's data.\nOnly SELECT queries are allowed.\nProperties and traits are JSON strings; inspect schemas and examples before filtering nested values.\n\nExample queries:\n- SELECT event_name, count(*) FROM activity GROUP BY 1 ORDER BY 2 DESC LIMIT 10\n- SELECT billing_status, sum(mrr_cents)/100 as mrr FROM customers GROUP BY 1\n- SELECT * FROM activity WHERE customer_id = 'cust_123' ORDER BY occurred_at DESC LIMIT 50",
"name": "outlit_query"
},
{
"description": "Get schemas for available analytics views.\n\nUse this to discover column names, types, and descriptions before writing SQL queries.\nReturns column definitions and example queries for each view.",
"name": "outlit_schema"
},
{
"description": "List configured destinations using safe status fields and masked configuration only.",
"name": "outlit_list_destinations"
},
{
"description": "Get one destination using safe status fields and masked configuration only.",
"name": "outlit_get_destination"
},
{
"description": "Create a Slack channel destination from an available channel.",
"name": "outlit_create_destination"
},
{
"description": "Update ordinary destination metadata. Use the dedicated enable or disable tool for lifecycle state.",
"name": "outlit_update_destination"
},
{
"description": "Enable an ordinary destination that is ready for delivery.",
"name": "outlit_enable_destination"
},
{
"description": "Disable an ordinary non-default destination.",
"name": "outlit_disable_destination"
},
{
"description": "Archive an ordinary destination.",
"name": "outlit_archive_destination"
},
{
"description": "List available integrations and safe connection health for the current actor.",
"name": "outlit_list_integrations"
},
{
"description": "Describe safe integration setup modes without exposing credential fields or provider configuration.",
"name": "outlit_get_integration_capabilities"
},
{
"description": "Begin a short-lived browser handoff for an integration that supports browser authentication.",
"name": "outlit_begin_integration_setup"
},
{
"description": "Check a browser setup handoff owned by the current actor.",
"name": "outlit_get_integration_setup_status"
},
{
"description": "Get safe model-level sync status for a connection visible to the current actor.",
"name": "outlit_get_integration_sync_status"
},
{
"description": "Get the product event currently configured to activate customers and users.",
"name": "outlit_get_customer_activation"
},
{
"description": "Preview the bounded recent impact of choosing a product event for customer activation without changing configuration.",
"name": "outlit_preview_customer_activation"
},
{
"description": "Set the product event used for future customer activation, or disable event-based activation with null. This does not backfill history.",
"name": "outlit_update_customer_activation"
},
{
"description": "Get the workspace default timezone used by time-based product behavior.",
"name": "outlit_get_workspace_settings"
},
{
"description": "Update the workspace default timezone using a valid IANA timezone.",
"name": "outlit_update_workspace_settings"
}
],
"transport": "streamable-http",
"version": "1.0.0",
"workspaceServerUrlTemplate": "https://mcp.outlit.ai/w/{workspaceSlug}/mcp"
},
"url": "https://mcp.outlit.ai/.well-known/mcp/server-card.json"
},
"latency_ms": 309.98,
"status": "ok"
},
"session_resume_probe": {
"details": {
"protocol_version": null,
"reason": "no_session_id",
"resume_expected": false,
"transport": "streamable-http"
},
"latency_ms": null,
"status": "missing"
},
"step_up_auth_probe": {
"details": {
"auth_required_checks": [
"initialize",
"tools_list",
"prompts_list",
"resources_list"
],
"broad_scopes": [],
"challenge_headers": [
"Bearer error=\"invalid_token\", error_description=\"Outlit MCP requires an Authorization: Bearer token. Use the workspace MCP URL and complete OAuth in your MCP client. Legacy or headless clients that do not support OAuth must send their configured bearer credential.\", resource_metadata=\"https://mcp.outlit.ai/.well-known/oauth-protected-resource/mcp\"",
"Bearer error=\"invalid_token\", error_description=\"Outlit MCP requires an Authorization: Bearer token. Use the workspace MCP URL and complete OAuth in your MCP client. Legacy or headless clients that do not support OAuth must send their configured bearer credential.\", resource_metadata=\"https://mcp.outlit.ai/.well-known/oauth-protected-resource/mcp\"",
"Bearer error=\"invalid_token\", error_description=\"Outlit MCP requires an Authorization: Bearer token. Use the workspace MCP URL and complete OAuth in your MCP client. Legacy or headless clients that do not support OAuth must send their configured bearer credential.\", resource_metadata=\"https://mcp.outlit.ai/.well-known/oauth-protected-resource/mcp\"",
"Bearer error=\"invalid_token\", error_description=\"Outlit MCP requires an Authorization: Bearer token. Use the workspace MCP URL and complete OAuth in your MCP client. Legacy or headless clients that do not support OAuth must send their configured bearer credential.\", resource_metadata=\"https://mcp.outlit.ai/.well-known/oauth-protected-resource/mcp\""
],
"minimal_scope_documented": false,
"oauth_present": false,
"scope_specificity_ratio": 0.0,
"step_up_signals": [
"Bearer error=\"invalid_token\", error_description=\"Outlit MCP requires an Authorization: Bearer token. Use the workspace MCP URL and complete OAuth in your MCP client. Legacy or headless clients that do not support OAuth must send their configured bearer credential.\", resource_metadata=\"https://mcp.outlit.ai/.well-known/oauth-protected-resource/mcp\"",
"Bearer error=\"invalid_token\", error_description=\"Outlit MCP requires an Authorization: Bearer token. Use the workspace MCP URL and complete OAuth in your MCP client. Legacy or headless clients that do not support OAuth must send their configured bearer credential.\", resource_metadata=\"https://mcp.outlit.ai/.well-known/oauth-protected-resource/mcp\"",
"Bearer error=\"invalid_token\", error_description=\"Outlit MCP requires an Authorization: Bearer token. Use the workspace MCP URL and complete OAuth in your MCP client. Legacy or headless clients that do not support OAuth must send their configured bearer credential.\", resource_metadata=\"https://mcp.outlit.ai/.well-known/oauth-protected-resource/mcp\"",
"Bearer error=\"invalid_token\", error_description=\"Outlit MCP requires an Authorization: Bearer token. Use the workspace MCP URL and complete OAuth in your MCP client. Legacy or headless clients that do not support OAuth must send their configured bearer credential.\", resource_metadata=\"https://mcp.outlit.ai/.well-known/oauth-protected-resource/mcp\""
],
"supported_scopes": []
},
"latency_ms": null,
"status": "warning"
},
"tool_snapshot_probe": {
"details": {
"reason": "no_tools"
},
"latency_ms": null,
"status": "missing"
},
"tools_list": {
"details": {
"error": "Client error '401 Unauthorized' for url 'https://mcp.outlit.ai/mcp'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/401",
"headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=31536000; includeSubDomains",
"www-authenticate": "Bearer error=\"invalid_token\", error_description=\"Outlit MCP requires an Authorization: Bearer token. Use the workspace MCP URL and complete OAuth in your MCP client. Legacy or headless clients that do not support OAuth must send their configured bearer credential.\", resource_metadata=\"https://mcp.outlit.ai/.well-known/oauth-protected-resource/mcp\""
},
"http_status": 401,
"payload": {},
"url": "https://mcp.outlit.ai/mcp"
},
"latency_ms": 172.52,
"status": "auth_required"
},
"transport_compliance_probe": {
"details": {
"bad_protocol_error": null,
"bad_protocol_headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=31536000; includeSubDomains",
"www-authenticate": "Bearer error=\"invalid_token\", error_description=\"Outlit MCP requires an Authorization: Bearer token. Use the workspace MCP URL and complete OAuth in your MCP client. Legacy or headless clients that do not support OAuth must send their configured bearer credential.\", resource_metadata=\"https://mcp.outlit.ai/.well-known/oauth-protected-resource/mcp\""
},
"bad_protocol_payload": {
"error": "invalid_token",
"error_description": "Outlit MCP requires an Authorization: Bearer token. Use the workspace MCP URL and complete OAuth in your MCP client. Legacy or headless clients that do not support OAuth must send their configured bearer credential."
},
"bad_protocol_status_code": 401,
"delete_error": null,
"delete_status_code": null,
"expired_session_error": null,
"expired_session_status_code": null,
"issues": [
"missing_protocol_header",
"bad_protocol_not_rejected"
],
"last_event_id_visible": false,
"protocol_header_present": false,
"requested_protocol_version": "2025-03-26",
"session_id_present": false,
"transport": "streamable-http"
},
"latency_ms": 271.37,
"status": "error"
},
"utility_coverage_probe": {
"details": {
"completions": {
"advertised": true,
"live_probe": "not_executed",
"sample_target": null
},
"initialize_capability_keys": [],
"pagination": {
"metadata_signal": false,
"next_cursor_methods": [],
"supported": false
},
"tasks": {
"advertised": false,
"http_status": 401,
"probe_status": "auth_required"
}
},
"latency_ms": 149.74,
"status": "ok"
}
},
"failures": {
"initialize": {
"error": "Client error '401 Unauthorized' for url 'https://mcp.outlit.ai/mcp'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/401",
"headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=31536000; includeSubDomains",
"www-authenticate": "Bearer error=\"invalid_token\", error_description=\"Outlit MCP requires an Authorization: Bearer token. Use the workspace MCP URL and complete OAuth in your MCP client. Legacy or headless clients that do not support OAuth must send their configured bearer credential.\", resource_metadata=\"https://mcp.outlit.ai/.well-known/oauth-protected-resource/mcp\""
},
"http_status": 401,
"payload": {},
"url": "https://mcp.outlit.ai/mcp"
},
"oauth_authorization_server": {
"reason": "no_authorization_server"
},
"oauth_protected_resource": {
"error": "Client error '404 Not Found' for url 'https://mcp.outlit.ai/.well-known/oauth-protected-resource'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/404",
"url": "https://mcp.outlit.ai/.well-known/oauth-protected-resource"
},
"openid_configuration": {
"reason": "no_authorization_server"
},
"tools_list": {
"error": "Client error '401 Unauthorized' for url 'https://mcp.outlit.ai/mcp'\nFor more information check: https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/401",
"headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=31536000; includeSubDomains",
"www-authenticate": "Bearer error=\"invalid_token\", error_description=\"Outlit MCP requires an Authorization: Bearer token. Use the workspace MCP URL and complete OAuth in your MCP client. Legacy or headless clients that do not support OAuth must send their configured bearer credential.\", resource_metadata=\"https://mcp.outlit.ai/.well-known/oauth-protected-resource/mcp\""
},
"http_status": 401,
"payload": {},
"url": "https://mcp.outlit.ai/mcp"
},
"transport_compliance_probe": {
"bad_protocol_error": null,
"bad_protocol_headers": {
"content-type": "application/json",
"strict-transport-security": "max-age=31536000; includeSubDomains",
"www-authenticate": "Bearer error=\"invalid_token\", error_description=\"Outlit MCP requires an Authorization: Bearer token. Use the workspace MCP URL and complete OAuth in your MCP client. Legacy or headless clients that do not support OAuth must send their configured bearer credential.\", resource_metadata=\"https://mcp.outlit.ai/.well-known/oauth-protected-resource/mcp\""
},
"bad_protocol_payload": {
"error": "invalid_token",
"error_description": "Outlit MCP requires an Authorization: Bearer token. Use the workspace MCP URL and complete OAuth in your MCP client. Legacy or headless clients that do not support OAuth must send their configured bearer credential."
},
"bad_protocol_status_code": 401,
"delete_error": null,
"delete_status_code": null,
"expired_session_error": null,
"expired_session_status_code": null,
"issues": [
"missing_protocol_header",
"bad_protocol_not_rejected"
],
"last_event_id_visible": false,
"protocol_header_present": false,
"requested_protocol_version": "2025-03-26",
"session_id_present": false,
"transport": "streamable-http"
}
},
"remote_url": "https://mcp.outlit.ai/mcp",
"server_card_payload": {
"authentication": {
"description": "Use the workspace-specific MCP URL from Outlit settings and complete OAuth in your MCP client.",
"required": true,
"schemes": [
"oauth2"
],
"type": "oauth2"
},
"description": "Outlit is the real-time understanding of every customer, the infrastructure agents use to automate customer operations.",
"documentationUrl": "https://docs.outlit.ai/ai-integrations/mcp",
"icon": "https://outlit.ai/images/logos/outlit-logo-square.png",
"icons": [
{
"sizes": "516x516",
"src": "https://outlit.ai/images/logos/outlit-logo-square.png",
"type": "image/png"
}
],
"name": "Outlit",
"prompts": [],
"resources": [],
"serverInfo": {
"name": "Outlit",
"version": "1.0.0"
},
"serverUrl": "https://mcp.outlit.ai/mcp",
"serverUrlUsage": "The generic serverUrl is available for discovery and OAuth-capable MCP clients. Prefer the workspace-specific URL from Outlit settings when configuring a client.",
"tools": [
{
"description": "Browse and filter customers. Use this to find customers by billing status, activity recency, revenue, or name. Returns a paginated list with summary info (MRR, last activity, status).",
"name": "outlit_list_customers"
},
{
"description": "Browse and filter users. Use this to find users by journey stage, activity recency, customer, or email/name. Returns a paginated list with activity info.",
"name": "outlit_list_users"
},
{
"description": "Browse internal workspace users such as CSMs, managers, account owners, and admins. Use this to discover who owns customers before composing dynamic reports across account books.",
"name": "outlit_list_workspace_users"
},
{
"description": "Get full details for a single customer. Use this when you already know which customer you want to inspect. Optionally include related data (users, revenue, recent activity, engagement metrics, company enrichment).",
"name": "outlit_get_customer"
},
{
"description": "Assign an active workspace member as this customer\u2019s primary owner. The former owner keeps Editor access.",
"name": "outlit_assign_customer_owner"
},
{
"description": "Share a customer with an active workspace member as a Viewer or Editor. The customer ID must be exact.",
"name": "outlit_grant_customer_access"
},
{
"description": "Change an existing customer collaborator between Viewer and Editor.",
"name": "outlit_update_customer_access"
},
{
"description": "Remove a collaborator\u2019s explicit access to a customer.",
"name": "outlit_revoke_customer_access"
},
{
"description": "Get the chronological activity timeline for a customer. Use this to see what happened and when \u2014 emails, calls, Slack messages, billing events, etc. Supports channel and date filtering.",
"name": "outlit_get_timeline"
},
{
"description": "List structured facts known about a customer. Use filters like status, sourceTypes, factTypes, factCategories, and date bounds to narrow the result set. For topic-specific retrieval, use outlit_search_customer_context instead.",
"name": "outlit_list_facts"
},
{
"description": "Get one exact fact by ID. Returns the canonical fact shape and optionally expands requested related data such as evidence.",
"name": "outlit_get_fact"
},
{
"description": "Get one exact source record by generic sourceType and sourceId. Use this when you already know the concrete underlying source you want to inspect.",
"name": "outlit_get_source"
},
{
"description": "List concrete source records deterministically. Use this instead of semantic search when you need enumerated calls, emails, calendar events, support tickets, Slack conversations, or opportunities.",
"name": "outlit_list_sources"
},
{
"description": "Search across all known customer context using a natural-language query. Returns ranked artifact-level discovery previews with at most two matching excerpts per source or fact. Use outlit_get_source with a returned sourceType and sourceId when you need the canonical source contents. Omit customer to search across all customers in the organization.",
"name": "outlit_search_customer_context"
},
{
"description": "Execute read-only SQL queries against your analytics views.\n\nAvailable views:\n- activity: Customer activity events (event_name, event_type, event_channel, customer_id, occurred_at, properties, ...)\n- customers: Customer attributes (customer_id, domain, name, billing_status, plan, mrr_cents, traits, ...)\n- users: User attributes (user_id, email, name, customer_id, traits, ...)\n- revenue: Revenue snapshots over time (customer_id, snapshot_date, mrr_cents, ...)\n\nAll queries are automatically filtered to your organization's data.\nOnly SELECT queries are allowed.\nProperties and traits are JSON strings; inspect schemas and examples before filtering nested values.\n\nExample queries:\n- SELECT event_name, count(*) FROM activity GROUP BY 1 ORDER BY 2 DESC LIMIT 10\n- SELECT billing_status, sum(mrr_cents)/100 as mrr FROM customers GROUP BY 1\n- SELECT * FROM activity WHERE customer_id = 'cust_123' ORDER BY occurred_at DESC LIMIT 50",
"name": "outlit_query"
},
{
"description": "Get schemas for available analytics views.\n\nUse this to discover column names, types, and descriptions before writing SQL queries.\nReturns column definitions and example queries for each view.",
"name": "outlit_schema"
},
{
"description": "List configured destinations using safe status fields and masked configuration only.",
"name": "outlit_list_destinations"
},
{
"description": "Get one destination using safe status fields and masked configuration only.",
"name": "outlit_get_destination"
},
{
"description": "Create a Slack channel destination from an available channel.",
"name": "outlit_create_destination"
},
{
"description": "Update ordinary destination metadata. Use the dedicated enable or disable tool for lifecycle state.",
"name": "outlit_update_destination"
},
{
"description": "Enable an ordinary destination that is ready for delivery.",
"name": "outlit_enable_destination"
},
{
"description": "Disable an ordinary non-default destination.",
"name": "outlit_disable_destination"
},
{
"description": "Archive an ordinary destination.",
"name": "outlit_archive_destination"
},
{
"description": "List available integrations and safe connection health for the current actor.",
"name": "outlit_list_integrations"
},
{
"description": "Describe safe integration setup modes without exposing credential fields or provider configuration.",
"name": "outlit_get_integration_capabilities"
},
{
"description": "Begin a short-lived browser handoff for an integration that supports browser authentication.",
"name": "outlit_begin_integration_setup"
},
{
"description": "Check a browser setup handoff owned by the current actor.",
"name": "outlit_get_integration_setup_status"
},
{
"description": "Get safe model-level sync status for a connection visible to the current actor.",
"name": "outlit_get_integration_sync_status"
},
{
"description": "Get the product event currently configured to activate customers and users.",
"name": "outlit_get_customer_activation"
},
{
"description": "Preview the bounded recent impact of choosing a product event for customer activation without changing configuration.",
"name": "outlit_preview_customer_activation"
},
{
"description": "Set the product event used for future customer activation, or disable event-based activation with null. This does not backfill history.",
"name": "outlit_update_customer_activation"
},
{
"description": "Get the workspace default timezone used by time-based product behavior.",
"name": "outlit_get_workspace_settings"
},
{
"description": "Update the workspace default timezone using a valid IANA timezone.",
"name": "outlit_update_workspace_settings"
}
],
"transport": "streamable-http",
"version": "1.0.0",
"workspaceServerUrlTemplate": "https://mcp.outlit.ai/w/{workspaceSlug}/mcp"
},
"server_identifier": "ai.outlit/outlit"
}
Known versions
1.0.0
Validation history
| Timestamp | Status | Score | Latency | Tools |
|---|---|---|---|---|
| Aug 07, 2026 07:30:55 PM UTC | Unknown | 17.6 | 2572.8 ms | 0 |
| Aug 07, 2026 07:30:38 AM UTC | Failing | 5.5 | 2307.7 ms | 0 |
| Aug 06, 2026 07:30:14 PM UTC | Failing | 5.2 | 1236.7 ms | 0 |
| Aug 06, 2026 07:30:09 PM UTC | Failing | 5.2 | 1312.0 ms | 0 |
| Aug 06, 2026 07:29:30 AM UTC | Failing | 5.8 | 1180.2 ms | 0 |
| Aug 06, 2026 07:29:29 AM UTC | Failing | 5.8 | 1457.0 ms | 0 |
| Aug 05, 2026 11:28:57 PM UTC | Failing | 6.1 | 2192.4 ms | 0 |
| Aug 05, 2026 11:28:56 PM UTC | Failing | 6.1 | 1311.4 ms | 0 |
Validation timeline
| Validated | Summary | Score | Protocol | Auth mode | Tools | High-risk tools | Changes |
|---|---|---|---|---|---|---|---|
| Aug 07, 2026 07:30:55 PM UTC | Unknown | 17.6 | unknown | unknown | 0 | 0 | summary_changed |
| Aug 07, 2026 07:30:38 AM UTC | Failing | 5.5 | unknown | unknown | 0 | 0 | none |
| Aug 06, 2026 07:30:14 PM UTC | Failing | 5.2 | unknown | unknown | 0 | 0 | none |
| Aug 06, 2026 07:30:09 PM UTC | Failing | 5.2 | unknown | unknown | 0 | 0 | none |
| Aug 06, 2026 07:29:30 AM UTC | Failing | 5.8 | unknown | unknown | 0 | 0 | none |
| Aug 06, 2026 07:29:29 AM UTC | Failing | 5.8 | unknown | unknown | 0 | 0 | none |
| Aug 05, 2026 11:28:57 PM UTC | Failing | 6.1 | unknown | unknown | 0 | 0 | none |
| Aug 05, 2026 11:28:56 PM UTC | Failing | 6.1 | unknown | unknown | 0 | 0 | none |
| Aug 05, 2026 07:28:10 PM UTC | Failing | 13.9 | unknown | unknown | 0 | 0 | none |
| Aug 03, 2026 11:53:30 PM UTC | Failing | 20.5 | unknown | unknown | 0 | 0 | none |
Recent validation runs
| Started | Status | Summary | Latency | Checks |
|---|---|---|---|---|
| Aug 07, 2026 07:30:53 PM UTC | Completed | Unknown | 2572.8 ms | action_safety_probe, advanced_capabilities_probe, connector_publishability_probe, connector_replay_probe, determinism_probe, initialize, interactive_flow_probe, oauth_authorization_server, oauth_protected_resource, official_registry_probe, openid_configuration, probe_noise_resilience, prompt_get, prompts_list, protocol_version_probe, provenance_divergence_probe, request_association_probe, resource_read, resources_list, schema_divergence_probe, server_card, session_resume_probe, step_up_auth_probe, tool_snapshot_probe, tools_list, transport_compliance_probe, utility_coverage_probe |
| Aug 07, 2026 07:30:36 AM UTC | Completed | Failing | 2307.7 ms | |
| Aug 06, 2026 07:30:13 PM UTC | Completed | Failing | 1236.7 ms | |
| Aug 06, 2026 07:30:08 PM UTC | Completed | Failing | 1312.0 ms | |
| Aug 06, 2026 07:29:29 AM UTC | Completed | Failing | 1180.2 ms | |
| Aug 06, 2026 07:29:28 AM UTC | Completed | Failing | 1457.0 ms | |
| Aug 05, 2026 11:28:55 PM UTC | Completed | Failing | 2192.4 ms | |
| Aug 05, 2026 11:28:54 PM UTC | Completed | Failing | 1311.4 ms | |
| Aug 05, 2026 07:28:08 PM UTC | Completed | Failing | 1290.0 ms | |
| Aug 03, 2026 11:53:29 PM UTC | Completed | Failing | 1412.4 ms | |
Public server reputation
Incident & change feed
| Timestamp | Event | Details |
|---|---|---|
| Aug 07, 2026 07:30:55 PM UTC | Latest validation: unverified | Score 29.3 with status unverified. |
| Aug 07, 2026 07:30:55 PM UTC | Validation summary changed | Summary moved from failing to unverified. |
| Aug 07, 2026 07:30:55 PM UTC | Score changed | Score delta +12.0 versus the previous run. |
| Aug 07, 2026 07:30:38 AM UTC | Score changed | Score delta +0.3 versus the previous run. |
| Aug 05, 2026 11:01:31 AM UTC | Score corrected (post-1.0.503 remediation, R1 zero-anchoring) | Prior: 20.49. Corrected: 12.88. |
Capabilities
- OAuth:
- DCR/CIMD:
- Prompts:
- Homepage: https://outlit.ai
- Docs: none
- Support: none
- Icon: none
- Remote endpoint: https://mcp.outlit.ai/mcp
- Server card: https://mcp.outlit.ai/.well-known/mcp/server-card.json
Benchmark tasks
| Benchmark task | Status | Evidence |
|---|---|---|
| Discover tools | Likely to fail |
|
| Read-only fetch flow | Likely to fail |
|
| OAuth-required connect | Degraded |
|
| Safe write flow with confirmation | Likely to fail |
|
Utility coverage
Transport compliance drilldown
Issues: missing_protocol_header, bad_protocol_not_rejected
Request association
Connector replay
Required-argument replay breaks
| Tool | Added required args | Removed required args |
|---|---|---|
| No required-argument replay breaks detected. | ||
Output-schema replay breaks
| Tool | Removed properties | Added properties |
|---|---|---|
| No output-schema replay breaks detected. | ||
Tool snapshot diff & changelog
Need at least two validation runs before building a tool changelog.
Validation diff
Regressed checks: action_safety_probe, connector_publishability_probe, initialize, oauth_protected_resource, prompts_list, provenance_divergence_probe, resources_list, tools_list, transport_compliance_probe
Improved checks: interactive_flow_probe, official_registry_probe, probe_noise_resilience, server_card, utility_coverage_probe
Newly assessed dimensions: none
No longer assessed dimensions: none
| Component | Previous | Latest | Delta |
|---|---|---|---|
| No component deltas between the latest two runs. | |||
Registry & provenance divergence
| Field | Registry | Live server card |
|---|---|---|
| Title | n/a | Outlit |
| Version | n/a | 1.0.0 |
| Homepage | n/a | n/a |
Active alerts
- Initialize flow regressed (critical)
A client-visible initialize behavior changed for the worse. - tools/list regressed (critical)
Tool discovery became less reliable on the latest run.
Aliases & registry graph
| Identifier | Source | Canonical | Score |
|---|---|---|---|
ai.outlit/outlit |
official_registry | yes | n/a |
Alias consolidation
Source disagreements
| Field | What differs | Observed values |
|---|---|---|
| No source disagreements detected. | ||
Fix it
Why this score?
Algorithmic score breakdown
Actionable remediation
| Severity | Remediation | Why it matters | Recommended action |
|---|---|---|---|
| Critical | Ensure tools/list succeeds consistently | Tools discovery is the minimum viable contract for most MCP clients and directories. | Make tools/list succeed unauthenticated when possible, or document the auth flow in the server card.Playbook
|
| Critical | Make initialize deterministic and client-friendly | If initialize fails or requires undocumented auth, many MCP clients cannot connect. | Allow initialize to succeed consistently, or return a deterministic auth-required response with clear metadata.Playbook
|
| Critical | Respond to initialize flow regressed | A client-visible initialize behavior changed for the worse. | Compare initialize responses between the latest two runs and restore the previous stable behavior. |
| Critical | Respond to tools/list regressed | Tool discovery became less reliable on the latest run. | Compare tool enumeration outputs between runs and remove non-deterministic behavior. |
| High | Align session and protocol behavior with Streamable HTTP expectations | Clients increasingly rely on MCP-Protocol-Version, session teardown, and expired-session semantics. | Align MCP-Protocol-Version, MCP-Session-Id, DELETE teardown, and expired-session handling with the transport spec.Playbook
|
| High | Expose /.well-known/oauth-protected-resource | Without a protected-resource document, OAuth clients cannot discover auth requirements reliably. | Serve /.well-known/oauth-protected-resource and point it at your authorization server metadata.Playbook
|
| High | Publish OAuth authorization-server metadata | Clients need authorization-server metadata to discover issuer, endpoints, and DCR support. | Publish /.well-known/oauth-authorization-server from your issuer and include registration_endpoint when supported.Playbook
|
| Medium | Adopt a current MCP protocol revision | Older protocol revisions reduce compatibility with newer clients and registry programs. | Advertise a current MCP protocol revision (2025-06-18 or later) in both the initialize response and the MCP-Protocol-Version header.Playbook
|
| Medium | Close connector-publishing gaps | Connector catalogs care about protocol recency, session behavior, auth clarity, and tool-surface stability. | |
| Medium | Document minimal scopes and return cleaner auth challenges | Modern clients expect granular scopes and step-up auth signals such as WWW-Authenticate scope hints. | Return granular scopes and WWW-Authenticate challenge hints instead of forcing overly broad auth upfront.Playbook
|
| Medium | Publish OpenID configuration | OIDC metadata improves token validation and client compatibility. | Expose /.well-known/openid-configuration with issuer, jwks_uri, and supported grants.Playbook
|
| Medium | Raise Access & Protocol score | Connectivity, auth, and transport expectations for common clients. | Tighten auth discovery, session behavior, and transport metadata until remote clients can connect without guesswork. |
| Medium | Raise Adoption & Market score | Adoption clues and public evidence that the server is intended for external use. | Increase external documentation and directory coverage so users can discover and evaluate the server. |
| Medium | Raise Interface Quality score | How well the tool/resource interface communicates and behaves under automation. | Improve schemas, error contracts, and recovery messages so agents can reason about the surface automatically. |
| Medium | Raise Reliability & Trust score | Operational stability, consistency, and trustworthiness over time. | Stabilize behavior over time and reduce failure drift between validation runs. |
| Medium | Raise Security Posture score | How safely the exposed tool surface handles destructive actions, egress, execution, secrets, and risky inputs. | Reduce destructive, egress, exec, secret, and freeform-input risk across the exposed tool surface.Playbook
|
| Medium | Repair prompts/list or stop advertising prompts | Prompt metadata should either work live or be removed from the advertised capability set. | Only advertise prompts if prompts/list works and prompt arguments are documented.Playbook
|
| Medium | Repair resources/list or stop advertising resources | Resource metadata should either work live or be removed from the advertised capability set. | Only advertise resources if resources/list works and resources expose stable URIs/types.Playbook
|
| Low | Publish newer MCP capability signals | Roots, sampling, elicitation, structured outputs, and related metadata improve client understanding and ranking. | Advertise only the advanced capabilities (roots, sampling, elicitation) you have actually implemented end to end in the initialize capabilities object.Playbook
|
Point loss breakdown
| Component | Current | Points missing |
|---|---|---|
| Transport Compliance | 0/4 | -4.0 |
| Tool Surface Design | 0/4 | -4.0 |
| Tool Snapshot Churn | 0/4 | -4.0 |
| Tool Namespace Clarity | 0/4 | -4.0 |
| Tool Capability Clarity | 0/4 | -4.0 |
| Task Success | 0/4 | -4.0 |
| Spec Recency | 0/4 | -4.0 |
| SLO Health | 0/4 | -4.0 |
| Session Semantics | 0/4 | -4.0 |
| Session Resume | 0/4 | -4.0 |
| Schema Completeness | 0/4 | -4.0 |
| Result Shape Stability | 0/4 | -4.0 |
Compatibility profiles
Connector URL: https://mcp.outlit.ai/mcp # No OAuth metadata detected. # Server: ai.outlit/outlit
{
"mcpServers": {
"outlit": {
"command": "npx",
"args": ["mcp-remote", "https://mcp.outlit.ai/mcp"]
}
}
}
smithery mcp add "https://mcp.outlit.ai/mcp"
curl -sS https://mcp.outlit.ai/mcp -H 'content-type: application/json' -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-03-26","capabilities":{},"clientInfo":{"name":"mcp-verify","version":"0.1.0"}}}'
Governance
MCP TrustOps
TrustOps turns this report into operational controls: freshness SLAs, authenticated validation, semantic benchmarks, policy exports, alert subscriptions, badges, cost/compliance metadata, and runtime routing. Fresh trusted index decisions stay separate from long-tail inventory so stale scores do not masquerade as current evidence.
/v1/decideAlert subscription types
MCP Runtime hosting
Verify Hosted MCP turns a trusted server report into a managed remote MCP endpoint with GitHub deployment provenance, sandbox policy, encrypted secrets, release history, rollback, and audit/usage events.
/hosted/{namespace}/{name}/mcp| Deployment | Status | Endpoint | Release |
|---|---|---|---|
| No hosted runtime deployments yet. | |||
Authenticated validation sessions
Public validation is free. Authenticated validation is paid and proves scoped behavior, write-action safeguards, and authenticated tool execution.
/v1/verify/v1/ci/previewInstall snippets
Connector URL: https://mcp.outlit.ai/mcp # No OAuth metadata detected. # Server: ai.outlit/outlit
{
"mcpServers": {
"outlit": {
"command": "npx",
"args": ["mcp-remote", "https://mcp.outlit.ai/mcp"]
}
}
}
smithery mcp add "https://mcp.outlit.ai/mcp"
curl -sS https://mcp.outlit.ai/mcp -H 'content-type: application/json' -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-03-26","capabilities":{},"clientInfo":{"name":"mcp-verify","version":"0.1.0"}}}'
Agent access & tool surface
tools/list, prompts/list, and resources/list checks.ai.outlit/outlit.