Is com.contrastcyber/api up? Live MCP status
Yes, it is up. It answered an MCP server/discover with no credential and negotiated protocol 2026-07-28.
A stock client connected with no credential and negotiated 2026-07-28. Use it.
| Outcome | usable |
|---|---|
| HTTP status | 200 |
| Protocol version | 2026-07-28 |
| Server says it is | contrastapi 1.36.3 |
| Answered in | 356 ms |
| Endpoint checked | https://api.contrastcyber.com/mcp/ |
| Checked |
One MCP handshake with the listed endpoint (server/discover at 2026-07-28, then initialize for a server on the older revision), with no credential and no retry, identifying itself as agentwares-mcp-liveness/0.1 (+https://agentwares-agentcheck.vercel.app/bot). It runs when this page is requested and the result is reused for 10 minutes, so the time above is when it was taken.
Live status every few hours: Wellknown
Email me when this server changes
That was one look. To hear when it stops answering or its tools change, leave an address.
Free, no password or GitHub: one confirmation email first, then a check every hour and an email when it stops answering or its tools change. Every email has a link to stop. More about it.
Monthly census, 6 October 2026
The census sends the same request to every remote listing in the official registry once a month. On 6 October 2026 this one answered a stock client with no credential. Every listing’s result: index.ndjson (what the files hold: index.meta.json).
Agent discovery documents at this origin
| A2A agent card | Published, does not validate: supportedInterfaces[0].protocolVersion is required (and 4 more). A2A 1.0 shape; 52 skills; MCP-HTTP, OpenAPI, HTTP-REST./.well-known/agent-card.json |
|---|---|
| MCP server card (SEP-2127) | Published, does not validate: `$schema` is required (and 2 more). ContrastAPI MCP Server 1.36.3; not served as application/mcp-server-card+json.https://api.contrastcyber.com/mcp/server-card |
| MCP server card (SEP-1649 location) | Published, does not validate: `transport` with a `type` is required (and 1 more). SEP-1649 shape; contrastapi 1.36.3; MCP 2026-07-28./.well-known/mcp/server-card.json — SEP-1649, a draft superseded by SEP-2127 on 21 January 2026 |
| Web Bot Auth key directory | Not published (HTTP 404)./.well-known/http-message-signatures-directory |
Read at https://api.contrastcyber.com with the monthly census on 9 October 2026: one GET each, no credential, never a signed request. A2A against v1.0.1, the server card against the MCP Server Card schema (SEP-2127), the card at SEP-1649’s location against the shape it has, the key directory against the Web Bot Auth draft of 1 September 2026. Who publishes them.
Tool changes between snapshots
In the 2026-10 snapshot it listed 55 tools: asn_lookup, atlas_case_study_lookup, atlas_case_study_search, atlas_technique_lookup, atlas_technique_search, audit_domain, brand_assets, bulk_atlas_technique_lookup, bulk_cve_lookup, bulk_ioc_lookup, bulk_sigma_rule_lookup, calculate_risk_score, check_dependencies, check_headers, check_injection, check_secrets, contrast_scan, cve_leading, cve_lookup, cve_search, cwe_lookup, d3fend_attack_coverage, d3fend_defense_for_attack, d3fend_defense_lookup, d3fend_defense_search, dns_lookup, domain_report, email_disposable, email_mx, email_security_posture, email_verify, exploit_lookup, geo_audit, get_cvss_details, hash_lookup, ioc_lookup, ip_lookup, kev_detail, password_check, phishing_check, phone_lookup, redirect_chain, robots_txt, scan_headers, seo_audit, sigma_rule_lookup, ssl_check, subdomain_enum, tech_fingerprint, tech_stack_cve_audit, threat_intel, threat_report, username_lookup, wayback_lookup, whois_lookup.
Its tools changed between 2026-09 and 2026-10:
check_dependencies: description changed
Which tools were added or removed, and whose description or schemas changed, from content hashes in the monthly snapshots. Per tool, as JSON: /v1/drift.
The listing
| Registry name | com.contrastcyber/api |
|---|---|
| Title | ContrastAPI |
| Description | 55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key. |
| Endpoint | https://api.contrastcyber.com/mcp/ |
| Publisher repository | https://github.com/UPinar/contrastapi |
| Version | 1.36.2 |
| Listing updated |
Also
The full check by name, as JSON (on a 401 it also follows the OAuth discovery chain) · Watch it · Check another server · llms.txt