Agent-Readiness Grade / Fix guides / mcp-registry-auth
Fix mcp-registry-auth: prove your domain to the official MCP Registry
The official MCP Registry lets you publish MCP servers under a name derived from your domain, such as com.example/weather. HTTP authentication proves you control the domain with a public key served at /.well-known/mcp-registry-auth. It matters only if you publish MCP servers.
Checked 2026-09-30 against grader version 1.3.0 and the 4 sources listed below.
Area: Machine-readable surfaces. The agent-surface point of the machine-readable surfaces area (shared with three other files).
What the grade checksWhy it mattersHow to fix itVerifyQuestionsSources
What the grade checks
GET https://example.com/.well-known/mcp-registry-authwith a 7-second timeout. It counts when the answer is HTTP 200, text (not HTML and not a binary content type) and not empty; a value starting withv=MCPv1is reported as an MCPv1 record.- Any one of mcp-registry-auth, agent-card.json, openapi.json or /.well-known/x402 earns the agent-surface point.
The agent-surface point of the machine-readable surfaces area (shared with three other files). The full scoring rules are on the methodology page.
Why it matters for AI agents and crawlers
The MCP Registry authentication guide says server names under your own domain must use its reverse-DNS form (com.example/*) and are proven by a DNS TXT record or by the HTTP file this check reads. The registry is in preview; the guide warns that breaking changes or data resets may happen before general availability.
The file holds one line with a public key, v=MCPv1; k=ed25519; p=<base64 public key> (or k=ecdsap384). The matching private key never goes on the web server.
How to fix it
Create the file
Generate the key pair and the file with the commands in the official authentication guide (Ed25519, ECDSA P-384, or a key held in Google Cloud KMS or Azure Key Vault). The guide notes that the Ed25519 commands need OpenSSL 3, which macOS does not ship by default. The result is a one-line file named
mcp-registry-auth:mcp-registry-auth (format)
v=MCPv1; k=ed25519; p=<base64 public key>Serve it as text at /.well-known/mcp-registry-auth
The file has no extension, so set
text/plainexplicitly; otherwise many hosts sendapplication/octet-stream, which the grade does not count as text.Static site
Save the file as
.well-known/mcp-registry-authin the web root and set the type:nginx, or Apache .htaccess in .well-known
# nginx location = /.well-known/mcp-registry-auth { default_type text/plain; } # Apache (.htaccess inside the .well-known folder) <Files "mcp-registry-auth"> ForceType text/plain </Files>WordPress
Upload the file to
.well-known/mcp-registry-authin the WordPress root folder and add the server rule above (or ask your host to).Next.js
Save it as
public/.well-known/mcp-registry-authand set the type innext.config.js:next.config.js
module.exports = { async headers() { return [ { source: '/.well-known/mcp-registry-auth', headers: [{ key: 'Content-Type', value: 'text/plain; charset=utf-8' }] }, ] }, }Cloudflare
With static assets or Pages, add the rule to a
_headersfile:_headers
/.well-known/mcp-registry-auth Content-Type: text/plain; charset=utf-8Log in and publish
With the file live, log in with the
mcp-publisherCLI's HTTP method forexample.comas the official guide shows, then publish yourserver.json.
How to verify
Check the content type and the record.
shell
curl -s -o /dev/null -w "%{http_code} %{content_type}\n" https://example.com/.well-known/mcp-registry-auth
curl -s https://example.com/.well-known/mcp-registry-auth
200 text/plain and one line starting with v=MCPv1; k=.
Then re-grade your site: the result lists the evidence for this check.
$49 AI Visibility Full Report
The fixes on this site are free. The paid next step is the $49 AI Visibility Full Report (what ChatGPT, Claude and Perplexity say about your brand, with a prioritized fix list) from aivisibility.agentexchange.work. It includes:
- 8 real buyer questions tested across ChatGPT-class models
- Competitor share-of-voice: who AI names, how often, versus you
- Full GEO site audit with prioritized, specific fixes
- Agent-Readiness Score: crawler access, llms.txt, schema, discovery manifest
- Custom 30/60/90-day action plan to get cited by ChatGPT, Perplexity and Google AI Overviews
- Shareable report, generated in about 60 seconds after checkout
Get the Full Report — $49 Stripe checkout; you enter your brand and site right after paying.
Questions
Do I need this file if I don't publish MCP servers?
No. It exists only to prove domain ownership to the MCP Registry.
DNS or HTTP: which method should I use?
Both prove the same thing: DNS uses a TXT record with the same v=MCPv1 value, HTTP uses this file. Only the HTTP file is visible to this check.
Is it safe to publish?
Yes. The file carries a public key only; the private key stays off the server.
Sources
Primary documentation, read 2026-09-30. Vendors change these pages; follow the link before relying on a detail.
- How to Authenticate When Publishing to the Official MCP Registry (Model Context Protocol)
- Official MCP Registry (Model Context Protocol)
- headers in next.config.js (Next.js)
- Workers static assets: headers and the _headers file (Cloudflare)