# Fix MCP census entry: answer at /mcp and sell through x402

> This check asks whether agents can call you, not just read you. It gives one point for an MCP endpoint at `/mcp` and one for being listed among the hosts that sell to agents through x402.

Checked 2026-09-30 against Agent-Readiness Grade 1.3.0. HTML version: https://grade.agentexchange.work/fix/mcp-endpoint

## What the grade checks

- **Endpoint (1 point):** `GET https://example.com/mcp` with a 7-second timeout. Any answer other than HTTP 404 or a 200 HTML page counts. Under the MCP 2026-07-28 transport, a POST-only endpoint answers GET with `405 Method Not Allowed`, which counts.
- **Census (1 point):** the host (with or without `www.`) appears in the [agent-economy index](https://index.agentexchange.work) hosts file, a daily walk of the Coinbase x402 Bazaar discovery catalog. Listing follows x402 routes in that catalog; there is no form to fill in.
- Both are Agent Exchange's own measurements, described on the [methodology page](https://grade.agentexchange.work/methodology#measured).

2 of the 12 points.

## Why it matters for AI agents and crawlers

The [MCP Streamable HTTP transport](https://modelcontextprotocol.io/specification/2026-07-28/basic/transports/streamable-http), revision 2026-07-28, requires a single endpoint path that accepts POST, for example `https://example.com/mcp`. That revision removed the GET stream and protocol-level sessions, so GET and DELETE on the endpoint answer 405. Servers must validate the `Origin` header on every request and answer 403 when it is invalid.

Authorization is optional in MCP. When a server requires it, the [MCP authorization spec](https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization) requires OAuth 2.0 Protected Resource Metadata ([RFC 9728](https://www.rfc-editor.org/rfc/rfc9728)) naming at least one authorization server, advertised in the `WWW-Authenticate` header of 401 answers.

The [x402 Bazaar](https://docs.x402.org/extensions/bazaar) is the catalog of x402 services; routes become discoverable when they declare the bazaar extension and settle through a facilitator that supports it.

## How to fix it

### 1. Start from an official template or SDK

Hand-rolling the protocol is not worth it; each stack has a maintained starting point.

#### Cloudflare

Cloudflare's [remote MCP server guide](https://developers.cloudflare.com/agents/guides/remote-mcp-server/) scaffolds a Worker whose endpoint is `/mcp`:

shell:

```sh
npm create cloudflare@latest -- remote-mcp-server-authless --template=cloudflare/ai/demos/remote-mcp-authless
```

#### Next.js

The [mcp-handler](https://www.npmjs.com/package/mcp-handler) package is a framework-agnostic HTTP adapter for MCP servers; its README shows the Next.js route setup.

shell:

```sh
npm install mcp-handler
```

#### WordPress

The official WordPress [MCP Adapter](https://github.com/WordPress/mcp-adapter) exposes WordPress abilities as MCP tools, resources and prompts.

#### Static site

A static host cannot run an MCP server. Run one on a Worker or a serverless function and route `/mcp` on your domain to it.

### 2. Check the endpoint

A browser cannot talk to `/mcp`; use curl for the status and the MCP Inspector for a real session.

shell:

```sh
curl -s -o /dev/null -w "%{http_code} %{content_type}\n" https://example.com/mcp
# 405 (POST-only, 2026-07-28), 400, 401 or 406: an endpoint answers. 404 or a text/html 200: none.
npx @modelcontextprotocol/inspector
```

### 3. If it requires OAuth, publish protected-resource metadata

RFC 9728 places the metadata for the resource `https://example.com/mcp` at `https://example.com/.well-known/oauth-protected-resource/mcp` (the well-known suffix goes between the host and the path). Advertise the exact URL in the 401 answer.

/.well-known/oauth-protected-resource/mcp:

```json
{
  "resource": "https://example.com/mcp",
  "authorization_servers": ["https://auth.example.com"],
  "scopes_supported": ["mcp:tools"],
  "bearer_methods_supported": ["header"]
}
```

401 answer from /mcp:

```http
HTTP/1.1 401 Unauthorized
WWW-Authenticate: Bearer resource_metadata="https://example.com/.well-known/oauth-protected-resource/mcp"
```

### 4. Census listing (only if you sell to agents)

Sell a route through x402 with the bazaar extension and a Bazaar-enabled facilitator; the index picks the host up on its next daily walk. See the [x402 guide](https://grade.agentexchange.work/fix/x402-manifest).

## How to verify

Check the endpoint status, then re-grade. The evidence shows the /mcp status and whether the census lists the host.

```sh
curl -s -o /dev/null -w "%{http_code} %{content_type}\n" https://example.com/mcp
```

Anything but `404` or a `text/html` 200. For the census point, the host appears on [index.agentexchange.work](https://index.agentexchange.work) the day after its x402 routes are in the Bazaar.

Re-grade: https://grade.agentexchange.work/grade?url=example.com&fresh=1

## Questions

### Why does GET /mcp return 405 on my working server?

Revision 2026-07-28 made the endpoint POST-only; GET and DELETE answer 405 Method Not Allowed. The grade counts that as an endpoint.

### Do I need OAuth for an MCP server?

No. Authorization is optional in MCP. When a server does require it over HTTP, the MCP authorization spec requires RFC 9728 protected-resource metadata.

### How do I get listed in the census?

The census is a daily copy of the Coinbase x402 Bazaar catalog, so it lists hosts whose x402 routes are in that catalog. There is no submission form.

### My site is content only. Should I build an MCP server for the points?

No. This area shows which sites agents can call. A content site that is readable and well described (robots.txt, llms.txt, structured data) is in good shape with 0/2 here.

## Sources

- [Streamable HTTP transport (revision 2026-07-28)](https://modelcontextprotocol.io/specification/2026-07-28/basic/transports/streamable-http) (Model Context Protocol)
- [Authorization (revision 2026-07-28)](https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization) (Model Context Protocol)
- [RFC 9728: OAuth 2.0 Protected Resource Metadata](https://www.rfc-editor.org/rfc/rfc9728) (IETF)
- [Bazaar (Discovery Layer)](https://docs.x402.org/extensions/bazaar) (x402 docs)
- [Build a remote MCP server](https://developers.cloudflare.com/agents/guides/remote-mcp-server/) (Cloudflare)
- [mcp-handler: framework-agnostic HTTP adapter for MCP servers](https://www.npmjs.com/package/mcp-handler) (npm)
- [MCP Inspector](https://www.npmjs.com/package/@modelcontextprotocol/inspector) (npm (@modelcontextprotocol/inspector))
- [MCP Adapter (official WordPress package)](https://github.com/WordPress/mcp-adapter) (WordPress)

## Related

- [x402 manifest](https://grade.agentexchange.work/fix/x402-manifest.md): A JSON list of your x402 paid routes at /.well-known/x402; only if you sell per request.
- [mcp-registry-auth](https://grade.agentexchange.work/fix/mcp-registry-auth.md): The public-key proof at /.well-known/mcp-registry-auth; only if you publish MCP servers.
- [agent-card.json](https://grade.agentexchange.work/fix/agent-card-json.md): The A2A agent card at /.well-known/agent-card.json; one of four files for the agent-surface point.
- [All fix guides](https://grade.agentexchange.work/fix)
