Agent readinessโ€ขSeptember 28, 2026

    MCP Server Card: Letting AI Clients Discover Your MCP Server

    The well-known JSON file that tells AI clients your MCP server exists and how to connect. Paths, required fields, and common mistakes.

    What we check

    We look for an MCP server card at three paths, in this order, and the first valid one wins:

    1. /.well-known/mcp/server-card.json
    2. /.well-known/mcp.json
    3. /.well-known/mcp

    A card counts as valid when it is JSON (not HTML), has a name string, and has at least one of transport, endpoint, url, protocolVersion or capabilities. Those are the fields a client needs to connect.

    When we find a card, we also check /.well-known/oauth-authorization-server for OAuth discovery metadata (RFC 8414). That shows up as a detail in your report and does not affect the score.

    What an MCP server card is for

    MCP, the Model Context Protocol, is how AI clients such as Claude connect to outside tools and data. If your product runs an MCP server, the card lets a client find it from your domain alone. Without one, each user has to find your server URL in your docs and paste it into their client's settings.

    The card only announces the server. It is not the server. If you do not run an MCP server, this check is not for you, and missing it costs you nothing.

    A minimal card

    {
      "name": "Acme Widgets",
      "description": "Search the Acme catalog and check order status.",
      "version": "1.0.0",
      "protocolVersion": "2025-06-18",
      "transport": "streamable-http",
      "endpoint": "https://acme.com/mcp"
    }

    This is the shape our check recognises. The server card format is still being standardised in the MCP project, so check the current MCP specification for the full field list and add authentication details if your server needs them.

    Common reasons it fails

    • The path returns your SPA's HTML shell with a 200 status. We reject any HTML content type.
    • The file contains invalid JSON, often a trailing comma.
    • The card has a name but no endpoint, URL or transport, so a client would have nothing to connect to.
    • The file sits behind a login, a bot challenge, or a firewall rule that blocks unfamiliar user agents.

    Test it

    curl -s -D - https://yoursite.com/.well-known/mcp/server-card.json
    # expect: a 200, content-type: application/json, and your card

    ๐Ÿ’ก Quick win

    If your MCP server is already running, the card is a static JSON file. Publish it at the primary path. If you already serve /.well-known/mcp.json, copy it to the primary path as well so newer clients find it first.

    Was this article helpful?