SaSame Observatory · Reproducible · 2026-07-31
An outside-in, reproducible measurement of how many public MCP endpoints are actually reachable, callable, and schema-valid across fragmented registries. Verification status only — no risk verdict on any named server.
Registry entries indexed across four public sources, reduced to auditable public endpoints, rolling-audited over time. Audit window 2026-06-17 → 2026-07-31.
Of 35,174 audited endpoints (latest state), share by outside-in grade. Observed-ready = A or B. Grade is a deterministic function of pass count against the standard — not a safety or quality verdict.
Observed-ready (A or B): 3,879 of 35,174 (11%). On a single bounded read-only call, 1,989 of 35,174 (5.7%) returned substantive content. These counts describe what was observable under one declared method at one point in time. They are NOT integration-success rates, availability guarantees, security findings, or a statement that the remaining records are unusable. Authentication requirements, the absence of a safely callable read-only tool, argument or context requirements, and transient errors are all counted as not-observed. Denominator = latest unique endpoint audit records; it is not the registry-side auditable count above.
Indexed entries by source. No single registry is a complete or authoritative slice of the ecosystem.
| Source | Indexed entries |
|---|---|
| Glama | 15,918 |
| official MCP registry | 14,082 |
Overlap finding (2026-07-31): two independent registries shared only ~0% of their union (0 in both; 0 and 14,765 unique to each). A single source is a biased lens; buyers should cross-reference.
Independent 2026 security research reports a serious auth/SSRF posture problem across the MCP ecosystem — on the order of ~37% SSRF-exposed, ~41% requiring no authentication, only ~8.5% on OAuth across ~7,000 public servers, with 30+ CVEs filed in a single 60-day window and hundreds of zero-auth servers found publicly exposed.
SaSame's distinct role: we do not assign a risk, badness, or safety score to any named server. We publish continuous verification status — reachable, callable, schema-valid, owner-claimed, re-checked — so the readiness gap is measurable without naming-and-shaming. (Consistent with the external picture, "Security & Compliance" is among the thinnest verticals we index: 77 endpoints.)
Everything here is observation-only and free to correct. Claiming proves you control the endpoint and clears unconfirmed items — no secrets, no sales call.
Integrating an MCP server and want a readiness check on that endpoint before you wire it in? Request a readiness report →