Reference
MCP servers
The public server (scan, scores, plans) and the customer-scoped audit server.
Vorza runs two MCP servers, both streamable HTTP, both advertised in /.well-known/mcp.json. The public one lets any agent scan and score domains and draft audit plans; the audit one is scoped to a single purchased audit and powers the Fix Loop.
The public server — /api/mcp
claude mcp add --transport http vorza https://www.vorza.dev/api/mcp
| tool | what it does |
|---|---|
scan_domain | Runs a fresh pre-check on a URL (~10s) and returns the scored result — every failing check with its fix. Works on tunneled localhost URLs for fix loops. |
get_score | The stored scan result for a domain — cheaper than re-scanning when nothing changed. |
get_leaderboard | Domains ranked by pre-check score, filterable by category, pageable. |
get_skill | The fix-loop playbook: tunnel, scan, fix worst-first, re-scan to target. |
create_audit_plan | Generates a full audit plan for an MCP server, SDK, or CLI — the scenario preview plus the next step (requesting the audit) for your human. Requires an email-bound token (the tool explains how to get one). |
No authentication; rate limits per caller and a global budget on scans. Committing to an audit always goes through a human — the tool returns the next step, never spends money.
The audit server — /api/mcp/audit
One credential per audit (from the results page), presented as a bearer header. initialize and tools/list work without it; every tool call requires it. Nine tools — findings, evidence, acceptance criteria, and the verification re-run — documented in full on the Fix Loop page.