Observe the MCP ecosystem without turning measurement into endorsement.
Protocol Observatory is the inspection and longitudinal-evidence station inside the SaSame institution and its mature Factory capability surface. This Knowledge page owns the human experience; the existing live-vps runtime continues to own signed feeds, indexes, badges, certificates and lookup endpoints.
- Domains graded
- 57,068
- Observed-ready
- 6,897
- Observation snapshot
- Sep 16, 2026, 08:19 PM UTC
- Business role
- Factory station
- Pending observation
- 58
- Census snapshot size
- 30,000
Census, Observatory and Mission Control update on independent schedules: currently 51 server(s) of cross-artifact lag (Mission Control as of Sep 16, 2026, 09:10 PM UTC, Observatory as of Sep 16, 2026, 08:19 PM UTC) — normal pending sync, not an outage.
Data freshness: STALE — older than expected: observation_history (oldest as of Aug 27, 2026, 08:11 AM UTC). This reflects each source's own last-write time, not merely when this page's data was regenerated.
Observed means measured from outside. Claimed means an operator proved control. Neither state means safe, recommended, high quality or legally verified. Unknown remains unknown, and unavailable live data is never replaced with invented values.
Try it live, no LLM involved
This calls SaSame's public MCP server directly over JSON-RPC (initialize, then tools/call for audit_mcp) and shows the raw result. No chatbot in the loop, no API key required.
52.7% of state-changing tools on the enumerable surface publish NO machine-readable safety annotation — a calling agent cannot automatically tell a read from a write, delete, or payment before invoking them.
- Endpoints observed
- 57,099
- Handshake response
- 8,714
- Declared tools
- 129,882
- Annotated
- 32.2%
Deterministic classifier, no LLM. This describes the published tool surface and annotation hygiene. It is not proof of runtime behavior, a vulnerability finding or a safety verdict.
A stratified sample across grades A–D from the current readiness index. It is deliberately not a showcase of only the strongest results.
ai.agentdm/agentdm
api.agentdm.ai
Flagged: this record's grade does not reconcile with its own checks-passed count (expected grade D under the legacy rubric for 3/10 (30%) checks passed, but the signed grade is A). Shown as measured — not hidden or corrected — pending re-audit.
- Checks passed
- 3/10
- Reachable
- yes
- Owner claim
- unclaimed
- Measured
- 2026-06-18
Top observed gap: C1 Protocol handshake conformance — initialize result keys: (none, status 401)
ai.agentrapay/agentra
api.agentrapay.ai
- Checks passed
- 10/10
- Reachable
- yes
- Owner claim
- unclaimed
- Measured
- 2026-06-18
Top observed gap: none (passes all checks)
ac.tandem/docs-mcp
tandem.ac
Flagged: this record's grade does not reconcile with its own checks-passed count (expected grade A under the legacy rubric for 9/10 (90%) checks passed, but the signed grade is B). Shown as measured — not hidden or corrected — pending re-audit.
- Checks passed
- 9/10
- Reachable
- yes
- Owner claim
- unclaimed
- Measured
- 2026-06-18
Top observed gap: C10 Honest error behavior — no structured error
ai.aarna/atars-mcp
mcp.aarna.ai
Flagged: this record's grade does not reconcile with its own checks-passed count (expected grade A under the legacy rubric for 9/10 (90%) checks passed, but the signed grade is B). Shown as measured — not hidden or corrected — pending re-audit.
- Checks passed
- 9/10
- Reachable
- yes
- Owner claim
- unclaimed
- Measured
- 2026-06-18
Top observed gap: C5 Safety annotation presence — 0/18 tools carry a valid safety-hint annotation
ac.inference.sh/mcp
sh.inference.ac
Flagged: this record's grade does not reconcile with its own checks-passed count (expected grade D under the legacy rubric for 2/10 (20%) checks passed, but the signed grade is C). Shown as measured — not hidden or corrected — pending re-audit.
- Checks passed
- 2/10
- Reachable
- yes
- Owner claim
- unclaimed
- Measured
- 2026-06-18
Top observed gap: C1 Protocol handshake conformance — initialize result keys: (none, status 301)
agency.lona/trading
mcp.lona.agency
Flagged: this record's grade does not reconcile with its own checks-passed count (expected grade D under the legacy rubric for 2/10 (20%) checks passed, but the signed grade is C). Shown as measured — not hidden or corrected — pending re-audit.
- Checks passed
- 2/10
- Reachable
- yes
- Owner claim
- unclaimed
- Measured
- 2026-06-18
Top observed gap: C1 Protocol handshake conformance — initialize result keys: (none, status 401)
ai.alpic.test/test-mcp-server
test.alpic.ai
- Checks passed
- 0/0
- Reachable
- yes
- Owner claim
- unclaimed
- Measured
- 2026-06-18
Top observed gap: No bounded gap was published.
ai.buyersense/buyersense
mcp.buyersense.ai
- Checks passed
- 0/0
- Reachable
- yes
- Owner claim
- unclaimed
- Measured
- 2026-06-18
Top observed gap: No bounded gap was published.
Observation and control status
- Certified records
- 2
- Third-party certified
- 1
- Monitored
- 2
- Meaning
- bounded evidence
1) Claim your endpoint for free (https://github.com/shigeki7777/sasame-mcp-observatory/issues/new?template=claim-passport.yml) by proving control via .well-known / DNS / repo. 2) SaSame re-audits hourly. 3) After >= 2 reproducible cycles still at the A/B bar, it is auto-promoted to Certified. No fee, no application, no sales call.
A claim proves control of a record or endpoint only. It is not KYC, identity verification, endorsement or a general certification of safety.
Citation and reuse guidance
When reusing an Observatory finding in search, generated answers, reports or software, cite the specific human page together with the corresponding raw evidence URL below. Include the source-declared observation or generation time and preserve the stated measurement caveat so a dated observation is not presented as a timeless fact.
These machine-readable files improve reproducibility and attribution; they do not guarantee indexing, ranking or citation by any search or AI system.
Stable machine evidence
The human interface can evolve without breaking externally referenced evidence URLs. Raw feeds remain on the dedicated runtime origin.
