How it works.
In short
What Talandor checks
A manual check reads a public HTTPS address: whether the server is reachable, which protocol it announces, whether it asks you to sign in, and whether a public catalog can be read. Tools are not executed.
What it does not check
It does not sign in for you, does not call tools, and does not prove that your assistant or each tool will work. Publisher text is copied as provided.
What the main results mean
- Server reachable — the endpoint answered this check. That does not by itself mean the public catalog was readable.
- Authentication required — the server asked you to sign in inside your assistant. Private tools were not checked. This is not a failure.
- Public catalog accessible — a public tool list was read. This is a separate fact from the server answering.
- Tools not executed — a public check never calls the tools.
Date and limits
Every report shows when the observation was made. It describes that moment only. A later check can differ. An address that still contains a placeholder such as {workspace} has not been checked.
Manual check and Watch
A manual check runs when you ask for it. Saving a connector does not repeat it. Watch, the paid monitoring offer, is not open: there is no subscription and no automatic alert yet.
Technical detail
In one minute
We check public MCP endpoints without credentials or tool calls, record what is observable, and compare complete public snapshots over time. The result separates measured facts, catalog measurements and publisher-provided content.
How to read a report
Measured by Talandor : reachability, MCP protocol, authentication challenge, public tool count and latency.
Estimated by Talandor : client setup guidance based on published configuration requirements. “Likely compatible” is not a hands-on client test.
Provided by the MCP publisher: tool names, descriptions, schemas and annotations. This content can be written in any language, copied as provided and clearly labelled.
Operational states
- Unknown
- The public check could not read a complete MCP contract. Reports show this as Insufficient evidence. It is not a quality score and not a claim that the server is down.
- Server reachable
- The endpoint answered. This fact alone does not mean the public catalog was readable.
- Public catalog accessible
- A public tools/list was read. Reports may then say the server is reachable and the public catalog is readable. Tools were not executed.
- Authentication required
- The endpoint answered and returned an authentication challenge. This is a complete public result, not a failed check. Private tools were not inspected and no credentials were used. Sign-in stays in the assistant.
- Degraded
- An MCP response was observed, but compared with a complete unauthenticated tools/list at least one step was incomplete. A missing catalog or HTTP 404 is not this state.
- Unreachable now
- This point-in-time scan failed to reach or qualify the endpoint. It does not prove a lasting outage.
Cadence and scope
An anonymous check runs once when submitted. Every checkable Official Registry endpoint is measured when first seen; complete public contracts are re-checked over time. When public worker monitoring is enabled, availability checks run about every five minutes and deep public-contract checks about every hour. Personal watches are selected from search or a report in your watch space.
Snapshots and diffs
Only snapshots marked full (a recognized protocol and an exhausted public tools/list) can become a contract baseline. A partial snapshot never replaces a full baseline and is never called complete. A diff compares protocol-compatible full snapshots by semantic hash, then classifies changes such as removed tools or newly required inputs. The current contract-diff rule version is 0.1.0.
The page Observed connector changes lists warning and critical diffs, unreachable checks and contracts that are no longer observable from that measured sample. It is not a ranking of the Official Registry, it does not use catalog metadata as evidence, and it is not a product changelog. Open a report for the changes that apply to one connector.
Client rules and dates
Client setup guidance is inference, not a certification. The displayed client rules are versioned as v0.2 and reviewed . Each report also shows the observed protocol version and observation time.
Glossary
- Official Registry
- The upstream catalogue. Talandor indexes only entries with a safe public HTTPS Streamable HTTP endpoint; package-only and unsafe targets are excluded.
- Catalog coverage
- Every checkable Official Registry HTTPS Streamable HTTP endpoint. Coverage grows as first-seen measurements complete.
- Public watch
- A worker watch explicitly marked for the public monitoring page; it is separate from the endpoints you select in your personal space.
- Personal watch
- A private user watch selected from search or a report in your personal space.
What we test
Talandor checks public HTTPS Streamable HTTP endpoints, negotiates the supported MCP protocol versions, reads public tools/list pages within bounded limits, records authentication challenges and compares snapshots over time.
What we never do
We never collect credentials, follow redirects to private networks, execute third-party code or call your tools. Descriptions and schemas are untrusted data.
Reporting and opt-out
For a report correction or endpoint opt-out request, email support@talandor.com and include the public report URL. Never send credentials.
Anonymous reports do not enroll an endpoint in a personal watch. Public worker monitoring is limited to watches explicitly marked public.
Limits
A protected server may expose only its authentication surface. Without credentials, Talandor cannot claim a private tools contract or a contract diff. Publisher-provided content is copied as provided and clearly labelled, and is not translated or verified.