← Back to Blog

The PolicyLayer MCP Registry: live risk records for 32,000 servers

Connecting an MCP server today works like this: you find it on a directory, skim the README, and hope the tool list in the docs matches what the server actually exposes. Nobody records what a server can reach, whether the endpoint sits behind auth, or what changed since you last looked. The ecosystem ships thousands of new servers a month and the metadata layer never caught up.

So we built it. The PolicyLayer MCP Registry is live: 32,000 servers, 510,000 tool versions, each one classified, graded and continuously re-scanned. Type a server name, get its record.

What a record contains

One JSON document per server, materialised from an append-only product log. Each record carries:

  • Identity, with confidence. Who publishes this server, with evidence: npm scope, repository org, domain linkage. Records are marked verified, unverified or mismatch, and the evidence is published alongside the verdict so you can check our working.
  • The full tool surface. Every tool, its parameters, its risk classification (category, severity, OWASP classes), what it can reach: code execution, outbound comms, credential access, money movement.
  • Auth posture. Whether the remote endpoint is gated, open or ambiguous, observed first-hand, and folded into the grade. A credential wall is a real control; an open endpoint with destructive tools is not.
  • A grade and a recommended policy. Computed at publish time from the tool surface and posture, with a deterministic policy template you can drop into a gateway.
  • Change history. Tools added, tools removed, reclassifications, auth downgrades. The record shows you what moved and when.

How it stays current

A registry is only as good as its freshness. The machine behind this one runs around the clock:

  • Version watchers poll npm every 10 minutes and PyPI and GitHub hourly. A version bump queues an immediate re-scan.
  • Live remote servers get an hourly credential-free handshake. A changed tool surface or a posture flip re-scans at top priority.
  • Discovery watchers sweep npm, PyPI and GitHub for new servers every hour, so the catalogue grows on its own.
  • Drift monitors watch the whole catalogue for shapes honest crawling doesn’t produce, and a hand-verified gold set gates publication for anchor servers. A record that fails its gate is held, not published.

The practical effect: when a server you depend on changes, its record reflects it within the hour.

Two APIs

The registry speaks the official MCP Registry API shape at /v0, public and unauthenticated:

curl https://api.policylayer.com/v0/servers

The licensed /v1 API adds the parts teams actually build on: full risk records, a global change feed, webhooks and bulk snapshots.

# One server's full record
curl -H "Authorization: Bearer plr_..." \
  https://api.policylayer.com/v1/registry/servers/github

# The change feed: everything that moved across the catalogue,
# cursor-paginated, filterable by severity
curl -H "Authorization: Bearer plr_..." \
  "https://api.policylayer.com/v1/registry/events?severity=critical"

Webhooks deliver the same events as HMAC-signed batches, and a nightly snapshot ships the entire catalogue as gzipped NDJSON via a signed URL. Full reference on the API page.

When the record says “mismatch”

Identity is where registries usually stay silent. Ours takes a position, conservatively. A server is flagged as a mismatch only when it asserts being official, the brand exists in our verified ground truth, and there is zero linkage between the two. Referential naming (“a port of the official X server”) never triggers it. Across the full catalogue that standard produces a handful of flags, not a witch hunt, and every flag ships with its evidence and a public dispute path.

Getting a licence

Search and individual records are on the site. The /v1 API, change feed, webhooks and snapshots come with a registry licence, normally $499 a month. For launch it is $199 a month, for a limited time. Checkout on the pricing page, key emailed straight to your inbox. No sales call unless you want redistribution rights, which is a conversation.


See what your servers actually expose.

// THE REGISTRY

Every MCP server your agents touch has a registry record.

Type a name, get the breakdown: verified identity, auth posture, risk grade, every tool classified, recommended policy. Re-checked continuously.

Teams ship this data inside their own products. See what a licence covers →

Take your agents live. Without losing control.

Route your MCP traffic through PolicyLayer. Every tool call is checked against your policy before it runs: allow, deny, or require approval. Per-identity grants. Full audit log. Live in minutes.

Instant setup, no code required.

46,500+ MCP servers and 515,000+ tools scanned and risk-classified.

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.