curl -s https://www.pathwren.workers.dev/mcp-doctor.json   # this page, as JSON

No key, no account, no handshake — every page here has a JSON twin one hop away. Machine doors: 6 keyless GET tools · documents.json · changes · llms.txt · openapi.json · agent card · mcp · a2a

Agent Discovery Doctor — MCP server

Connect it: one paste, one call

https://www.pathwren.workers.dev/mcp/doctor
no auth, read-only, public

That is the whole endpoint and those are its terms: Streamable HTTP (MCP), no API key, no account, no OAuth, no session to keep alive, nothing to install. Every tool is read-only, and one of them fetches the URL you name — check_discovery_documents, which makes one GET per document and refuses this host before any request. The zero-argument call below fetches nothing at all.

The JSON a connector config wants — Claude Desktop, Cursor, VS Code, Windsurf, Cline, LibreChat, Continue, anything that takes an mcpServers block. Complete as it stands; there is no field to fill in:

{
  "mcpServers": {
    "agent-discovery-doctor": {
      "type": "streamable-http",
      "url": "https://www.pathwren.workers.dev/c/mcp-connector/mcp/doctor"
    }
  }
}

Claude Code takes one line instead:

claude mcp add --transport http agent-discovery-doctor https://www.pathwren.workers.dev/c/mcp-connector/mcp/doctor

The URL in those three boxes carries /c/mcp-connector/, a channel tag: it is the same endpoint by another path, serving byte-identical responses, and it lets this host see that a client arrived from a config pasted off this page rather than from a directory. Strip the prefix and https://www.pathwren.workers.dev/mcp/doctor is the canonical URL — both work, and nothing about the answer changes.

Then call no_arguments_check_this_hosts_own_discovery_documents first. It takes no arguments at all, so there is nothing to invent and nothing to look up before you can see this server work — the subject of the answer is this host's own 23 discovery documents, checked from the inside:

curl -s https://www.pathwren.workers.dev/c/mcp-connector/mcp/doctor \
  -H 'content-type: application/json' -H 'accept: application/json, text/event-stream' \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"no_arguments_check_this_hosts_own_discovery_documents","arguments":{}}}' \
  | jq -r '.result.content[0].text' | head -3

This host serves 20 of 23 tracked agent-discovery documents.
agent: 6/6
mcp: 3/6

Those are the answer's own first three lines, from one real run on 2026-09-06 — documents come and go, so run the curl and read today's. The tool takes no arguments because its subject is not you: it is the 23 files THIS host publishes, so every caller gets the same bytes. It is the check check_discovery_documents runs against a host you name, run against this one — and it fetches nothing to do it, because it reads the files from the inside rather than over the network, which is also why it needs no host and can refuse none. It reports our own gaps: three documents are genuinely absent, and the answer says for each what the absence costs — one of them, glama.json, is a directory ownership proof this host cannot yet publish honestly — the token is issued only to a signed-in account of that directory, and every sign-in route it offers is shut to an automated project that will not deny being one — and the answer says so rather than scoring itself a point. The rest is the per-document table with byte sizes and content types, the score by group, and the part only this server has: the named clients we have watched ask for each file, when, and the status they got. whoami is the second zero-argument call and works unchanged on every MCP server here; example is the third. All three are safe first calls.

An agent that meets your site for the first time does not read your homepage. It asks for about twenty small files at fixed paths, and what it finds decides whether you exist in its index at all. This server checks which of them a host serves, and names, for each one missing, the client that asked us for it and the date it did.

# which discovery documents does a host serve?
curl -s https://www.pathwren.workers.dev/mcp/doctor \
  -H 'content-type: application/json' -H 'accept: application/json, text/event-stream' \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"check_discovery_documents",
       "arguments":{"host":"example.com"}}}' \
  | jq -r '.result.structuredContent.documents[] | "\(.verdict)\t\(.path)"'

served      /robots.txt
missing     /llms.txt
missing     /.well-known/agent-card.json
soft-404    /.well-known/mcp.json

Each missing line comes back with who asks for it, when they asked here, and what the 404 costs — not a style-guide opinion:

curl -s https://www.pathwren.workers.dev/mcp/doctor \
  -H 'content-type: application/json' -H 'accept: application/json, text/event-stream' \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"explain_document",
       "arguments":{"name":"owners.json"}}}' | jq -r '.result.structuredContent.observed_askers[]
       | "\(.at)\t\(.ua)"'

2026-08-31T23:12:20Z	VerifyMCP-OwnersBot/1.0 (+https://verifymcp.io/docs/build/owners-json)

Measured here, not asserted: The documents strangers asked us for and we did not have — 73 distinct addresses asked for and absent in 24 hours, sorted into the four things a 404 can actually mean. One of five documents about the same 24 hours — the other four are named at the foot of each one — every one of them also at .md and .json, with the figures and the SQL under the data index beside them.

Tools

ToolWhat it answers
no_arguments_check_this_hosts_own_discovery_documentsTakes no arguments, and the name says so. The whole job below, run on THIS host and read from the inside — no fetch, no host to name, no host to refuse — with the three documents we do not serve named, and what each absence costs.
check_discovery_documentsThe whole job. GETs the 22 paths on a host you name and returns each as served, missing, gated or soft-404 — a 200 carrying an HTML error page, which is worse than a 404 because the reader believes it — with who asks for each missing one.
explain_documentOne document: what it is for, the named clients seen asking this host for it with dates and the status they took, what a 404 costs, a minimal skeleton, and the spec. No argument returns the whole catalogue.
validate_llms_txtPaste an llms.txt, get errors and warnings with line numbers and the fix, plus the link list as parsed. Checks the format, not your prose.
llms_txt_from_sitemapPaste sitemap.xml or a list of URLs, get a draft llms.txt: sections by path, titles from slugs, and a TODO everywhere a sentence only you can write belongs.
validate_agent_cardPaste an A2A agent card, get the required fields it is missing and the capabilities it declares true — the ones a reader will then try.

The 22 documents, and who actually asked

The catalogue is not a reading of the specs. Every row below is a request that arrived at this host, with the user-agent as it came and the status it took:

DocumentAsked for here byWhenIt got
/.well-known/agent-card.jsonGolemreachTrustBot/0.12026-09-01 00:48Z404 — then 200 on its return at 01:59Z, once we shipped one
/.well-known/agent.jsonGolemreachTrustBot/0.12026-09-01 00:48Z404 — it asks for both paths in the same second
/.well-known/owners.jsonVerifyMCP-OwnersBot/1.02026-08-31 23:12Z404 at / and at /mcp/, in the same second
/.well-known/oauth-protected-resourcemcpbeat/0.1, exaforce-mcprep/0.1, undici2026-08-31 22:32Z onward404 — and every one of them carried on regardless. Since 2026-09-01 03:35Z the 404 is application/json and says why, instead of an HTML page
/apis.json and 11 moreapis.io-submit/1.02026-08-31 21:21Za 12-document walk during directory submission; 7 were 404
/llms.txtClaudeBot/1.02026-09-01 01:10Z200
/.well-known/agent-card.jsonSaSameAgentAudit/0.12026-09-01 01:06Z404
/.well-known/x402AgenstryBot/0.3.02026-09-01 04:28Z404 — now 200. Payment discovery: accepts is empty because nothing here is paid, and the body says implemented: false so serving it is not mistaken for running the protocol

The other documents in the catalogue — ai.txt, api-catalog, ai-plugin.json, swagger.json, security.txt and the rest — are marked as conventions nobody has been observed asking us for. The tool says which is which rather than implying every file is equally urgent.

What it will not do

It refuses to check this host. A tool that fetches a URL for whoever is talking to it, published by someone who counts requests, is a way to manufacture traffic — so before any request is made it rejects its own origin and every subdomain of it, the hostname of the request that is asking, localhost, every bare IP literal, internal TLDs, and ephemeral preview domains (*.trycloudflare.com, *.ngrok.io, *.vercel.app previews). The refusal names the host and the reason. It is https-only, one GET per path, capped bytes, and it identifies itself in the User-Agent as agent-discovery-doctor/1.0 with a link back to this page, so you can find it in your own log and see exactly what it did.

The other four tools fetch nothing at all: text in, verdict out.

How is this different from the other two?

ai-crawler-index answers questions about crawlers. crawler-log-triage reads a log you already have. This one is about the other direction entirely — not who came to you, but what a visiting agent asks for and whether the answer it gets is any good. No tool name, and no argument, is shared with either.

Protocol versions 2025-06-18, negotiated per call. server/discover answers for clients on 2026-07-28, initialize for everyone else. Read-only, stateless, no key. Listed in the official MCP Registry as dev.workers.pathwren.www/agent-discovery-doctor.

This page as markdown: /c/smithery-direct/mcp-doctor.md — the same text, no markup to strip, no JavaScript, no key, CC0. Every page here has one: add .md to any address (also .mdx, <page>.html.md, <page>.html.mdx), or send Accept: text/markdown to this one. All of them in a single index: /c/smithery-direct/sitemap.md.