Published scenario set
CurrentMCP connection test mcp-connection v1.0
The tasks behind a test result, written down so anybody can run the same test and compare. A remote MCP server reached over HTTPS, by streamable HTTP or by server-sent events. Released 2026-09-30 (UTC) and never edited after release: a change is a new version. A receipt that records test runs names the set it ran by id, version and the digest below, and the site will not issue one that names a set not published here.
sha256:f2e2177539d98ab70a47eeb50cab1357302cda4b1687e91aa28110c9a799dbfb
The tasks, 2 of them
A test attempts every task once, in order. A task not reached because an earlier task failed counts as attempted and not passed. A test the address check refuses attempts nothing.
- 01
Handshake
handshakesends initialize, then notifications/initialized
Passes when the server answers initialize with a JSON-RPC result, not an error, within the time limit.
- 02
Tool list
tool_listsends tools/list
Passes when the server answers tools/list with a result. Up to three pages are read by following nextCursor, and an empty list passes.
What goes over the wire
As client assay-connection-test 1.0.0, asking for protocol version 2025-06-18.
Credentials: None. No token, no cookie and no header a person supplied. A server that expects a key can only be asked whether it answers without one, and is recorded as asking for credentials.
- Nothing else is sent: no tools/call, no resources or prompts, and no argument anybody typed. A tool can send an email or move money, and the only way to be sure a test does neither is never to call one.
- Over streamable HTTP, a session the server opened is closed with an HTTP DELETE, waiting two seconds at most for the answer.
- Over server-sent events, the stream is opened with a GET and every request goes to the address its endpoint event names, which must be on the same host.
The address check
The address comes from a public declaration anybody can write, so it is treated as hostile.
- The address must be an https URL on a host name with a dot in it: no IP address, no user name or password, no localhost, .local or .internal name, and no spaces or braces left to fill in.
- Every address the name resolves to must be public. Private, loopback, link-local, shared address space, benchmarking, multicast, reserved and documentation ranges are refused, in IPv4 and IPv6, as is NAT64, and an IPv4 address written as IPv6 is judged as IPv4.
- The check runs inside the connection's own DNS lookup, at connect time, so a name that answers differently between a check and a connection is still refused.
- Redirects are never followed.
Limits
- Whole test, at most
- 12 seconds
- Largest answer read
- 1,000,000 bytes
- Tool list pages read
- 3
- Wait for a session to close
- 2 seconds
What it measures
Latency: Milliseconds from sending initialize to reading its answer, recorded only when the handshake is answered.
Tools: How many tools the list named. Descriptions are also read with the current tool description pattern set, which does not change whether a task passed, and a description that matches a rule is withheld rather than stored. Pattern set v1.0.
How a result is recorded
- answered
- It completed the handshake.
- needs_credentials
- It asked for credentials: HTTP 401 or 403, a WWW-Authenticate header, or a handshake error about authentication.
- no_answer
- The name did not resolve, the connection was refused, dropped or unreachable, or nothing came back within the time limit.
- error
- Anything else that stopped it: a certificate that did not verify, a redirect, an HTTP error, or an answer that was not an MCP handshake.
- refused
- Not tested: the address check refused the address, or an event stream asked for requests to go to another host, so no task was attempted.
What a pass does not establish
- What any tool does when it is called. No tool is ever called.
- How the server behaves for a client that sends credentials.
- That the endpoint runs any particular code, including code this site has read.
- Speed or reliability from anywhere but the site's own servers, at the times shown.
Canonical scenario set JSON
RFC 8785 JSON. The digest above is SHA-256 over the line assay-scenarios/v1 and this text.
{"addressCheck":["The address must be an https URL on a host name with a dot in it: no IP address, no user name or password, no localhost, .local or .internal name, and no spaces or braces left to fill in.","Every address the name resolves to must be public. Private, loopback, link-local, shared address space, benchmarking, multicast, reserved and documentation ranges are refused, in IPv4 and IPv6, as is NAT64, and an IPv4 address written as IPv6 is judged as IPv4.","The check runs inside the connection's own DNS lookup, at connect time, so a name that answers differently between a check and a connection is still refused.","Redirects are never followed."],"appliesTo":"A remote MCP server reached over HTTPS, by streamable HTTP or by server-sent events.","client":{"name":"assay-connection-test","protocolVersion":"2025-06-18","version":"1.0.0"},"credentials":"None. No token, no cookie and no header a person supplied. A server that expects a key can only be asked whether it answers without one, and is recorded as asking for credentials.","doesNotEstablish":["What any tool does when it is called. No tool is ever called.","How the server behaves for a client that sends credentials.","That the endpoint runs any particular code, including code this site has read.","Speed or reliability from anywhere but the site's own servers, at the times shown."],"id":"mcp-connection","limits":{"maxResponseBytes":1000000,"sessionCloseWaitMs":2000,"timeoutMs":12000,"toolListPages":3},"measures":{"latency":"Milliseconds from sending initialize to reading its answer, recorded only when the handshake is answered.","tools":"How many tools the list named. Descriptions are also read with the current tool description pattern set, which does not change whether a task passed, and a description that matches a rule is withheld rather than stored."},"outcomes":[{"key":"answered","means":"It completed the handshake."},{"key":"needs_credentials","means":"It asked for credentials: HTTP 401 or 403, a WWW-Authenticate header, or a handshake error about authentication."},{"key":"no_answer","means":"The name did not resolve, the connection was refused, dropped or unreachable, or nothing came back within the time limit."},{"key":"error","means":"Anything else that stopped it: a certificate that did not verify, a redirect, an HTTP error, or an answer that was not an MCP handshake."},{"key":"refused","means":"Not tested: the address check refused the address, or an event stream asked for requests to go to another host, so no task was attempted."}],"released":"2026-09-30","runs":"A test attempts every task once, in order. A task not reached because an earlier task failed counts as attempted and not passed. A test the address check refuses attempts nothing.","tasks":[{"id":"handshake","label":"Handshake","passes":"The server answers initialize with a JSON-RPC result, not an error, within the time limit.","sends":["initialize","notifications/initialized"]},{"id":"tool_list","label":"Tool list","passes":"The server answers tools/list with a result. Up to three pages are read by following nextCursor, and an empty list passes.","sends":["tools/list"]}],"title":"MCP connection test","version":"1.0","wire":["Nothing else is sent: no tools/call, no resources or prompts, and no argument anybody typed. A tool can send an email or move money, and the only way to be sure a test does neither is never to call one.","Over streamable HTTP, a session the server opened is closed with an HTTP DELETE, waiting two seconds at most for the answer.","Over server-sent events, the stream is opened with a GET and every request goes to the address its endpoint event names, which must be on the same host."]}Version archive