An assistant reviewing a website can call MachineRead through MCP rather than asking a person to copy an audit report into the conversation. The assistant uses MachineRead's tools to request an audit and inspect its results.
A separate feature looks for MCP discovery documents on the site being audited. These are different connections: your client calls MachineRead, while MachineRead fetches public evidence from the target. Finding a target's server card does not mean the audit connected to that server or invoked its tools.
MCP is a client-to-server protocol
The Model Context Protocol describes MCP as an open-source standard for connecting AI applications to external systems (Model Context Protocol, "What is MCP?"). In MCP terms, a client connects to a server, discovers available tools, and may invoke one of those tools.
The 2025-06-18 tools specification separates those two client actions. A client sends tools/list to discover available tools, then sends tools/call to invoke a named tool (Model Context Protocol, "Tools"). The transport specification also makes the HTTP boundary explicit for that version: every client-sent JSON-RPC message is a new POST to the MCP endpoint, with an Accept header that lists JSON and event-stream responses (Model Context Protocol, "Transports").
Those protocol details matter because a successful MCP workflow is more than a URL existing on the web. The client has to reach the right endpoint, negotiate the expected transport, list tools, call the intended tool, and receive a useful response. A site can publish a discovery file and still fail one of those later steps.
MachineRead's MCP server is read-only
The hosted endpoint is https://api.machineread.ai/.well-known/mcp/mcp, using Streamable HTTP. The Agent Integration guide lists four tools: run_essentials_audit, get_audit_report, list_available_checks, and explain_check.
Start by listing the tools in a compatible client. Request an audit with a public URL and the intended preset. The audit tool returns a compact MCP result with an audit ID, scores, strict readiness, and caveats; it does not return the REST endpoint's full per-check evidence array. Use the follow-up tools to inspect the report and explain unfamiliar checks.
These tools inspect public website evidence. They do not log into the target, change its content, or complete a task through the target's own tools. Calling an audit is still a network operation, so use it for sites you are authorized to assess and respect the returned rate-limit guidance.
A target MCP card is discovery evidence
MachineRead can also inspect whether a target publishes an MCP Server Card candidate. The bounded candidate paths include /.well-known/mcp/server-card.json, and the check applies a minimum JSON-shape screen that rejects generic error-only responses.
That check is useful, but it is deliberately small. It can show that a candidate discovery URL was reachable enough to parse and that the response had some expected structure. It cannot show that the card's endpoint is live, that its listed tools exist, that authorization would succeed, or that an agent can complete a task through that target.
How to use this in practice
Use MachineRead's MCP server when an agentic workflow needs a read-only audit tool. The client should list the MachineRead tools, call run_essentials_audit for the target URL, then inspect the returned audit and check explanations before deciding what to change.
If the audit reports target-side MCP discovery evidence, treat it as a lead for deeper validation. Open the advertised card, inspect the endpoint and tool metadata, and test a real client connection only if the site owner intends that workflow to work. If authentication is required, verify the authorization path rather than assuming public discovery is enough.
Works Cited
Model Context Protocol. "Tools." Model Context Protocol Specification, 18 June 2025, https://modelcontextprotocol.io/specification/2025-06-18/server/tools.md. Accessed 9 Sept. 2026.
Model Context Protocol. "Transports." Model Context Protocol Specification, 18 June 2025, https://modelcontextprotocol.io/specification/2025-06-18/basic/transports.md. Accessed 9 Sept. 2026.
Model Context Protocol. "What is MCP?" Model Context Protocol Documentation, https://modelcontextprotocol.io/docs/2025-03-26/getting-started/intro.md. Accessed 9 Sept. 2026.
See also
- Methodology reference - separates discovery, protocol, and audit evidence by check group
- How an OpenAPI document makes an API easier to inspect - another machine-readable contract that should not be overread
- What an entity lookup can and cannot confirm - a parallel example of bounded evidence, not proof