Using GenReadyโ€ขSeptember 28, 2026

    Using the GenReady API and MCP Server

    Run scans from your own code with an API key, or connect an AI assistant to GenReady through MCP. How to get started with each.

    Two ways to use GenReady outside the website

    The REST API is for your own code: CI checks, internal dashboards, client reporting. The MCP server is for AI assistants: connect one, and it can scan pages and read reports for you in a conversation.

    MCP tools call the same API with your own credentials, so both count against your plan's monthly API allowance. See the pricing page for current limits.

    The REST API

    1. Create a key on the API keys page. Keys start with gr_live_. Copy it when it is shown, because it is not shown again.
    2. Send it as a Bearer token on every request.
    3. Start an analysis, then poll its status until the report is ready.
    curl -X POST https://genready.ai/api/v1/analyze \
      -H "Authorization: Bearer gr_live_YOUR_API_KEY" \
      -H "Content-Type: application/json" \
      -d '{"url": "https://example.com/page"}'

    The response includes a statusUrl to poll and a reportUrl for the finished report. If you would rather not poll, add a webhook on the API keys page and we notify you when an analysis completes.

    The full reference, with every endpoint and response field, is in the API documentation.

    The MCP server

    GenReady runs a remote MCP server at https://genready.ai/mcp. There is nothing to install. Coding agents connect with an API key. For example, in Claude Code:

    claude mcp add --transport http genready https://genready.ai/mcp \
      --header "Authorization: Bearer gr_live_YOUR_API_KEY"

    If you want the assistant to read site-wide fix plans, enable Read site data when you create the key. Connector-style clients such as claude.ai use OAuth instead: they ask you to sign in to GenReady and approve access, and you never paste a key. The MCP documentation covers each client and lists every tool the server offers.

    Keeping keys safe

    • Store keys in environment variables or a secret manager, never in code you commit.
    • Use one key per integration, with a clear name, so you can revoke one without breaking the others.
    • If a key may have been exposed, revoke it. It stops working immediately. Rotating instead gives you a new key and keeps the old one working for 24 hours, so you can update your integrations without downtime.

    ๐Ÿ’ก Quick win

    Add a GenReady scan of your homepage to your deploy pipeline and fail the build if the score drops sharply. You find out about a regression before your visitors or an AI crawler do.

    Was this article helpful?