Agent-Readiness Grade

Agent-Readiness Grade / Fix guides / mcp-registry-auth

Fix mcp-registry-auth: prove your domain to the official MCP Registry

The official MCP Registry lets you publish MCP servers under a name derived from your domain, such as com.example/weather. HTTP authentication proves you control the domain with a public key served at /.well-known/mcp-registry-auth. It matters only if you publish MCP servers.

Checked 2026-09-30 against grader version 1.3.0 and the 4 sources listed below.

Area: Machine-readable surfaces. The agent-surface point of the machine-readable surfaces area (shared with three other files).

What the grade checksWhy it mattersHow to fix itVerifyQuestionsSources

What the grade checks

  • GET https://example.com/.well-known/mcp-registry-auth with a 7-second timeout. It counts when the answer is HTTP 200, text (not HTML and not a binary content type) and not empty; a value starting with v=MCPv1 is reported as an MCPv1 record.
  • Any one of mcp-registry-auth, agent-card.json, openapi.json or /.well-known/x402 earns the agent-surface point.

The agent-surface point of the machine-readable surfaces area (shared with three other files). The full scoring rules are on the methodology page.

Why it matters for AI agents and crawlers

The MCP Registry authentication guide says server names under your own domain must use its reverse-DNS form (com.example/*) and are proven by a DNS TXT record or by the HTTP file this check reads. The registry is in preview; the guide warns that breaking changes or data resets may happen before general availability.

The file holds one line with a public key, v=MCPv1; k=ed25519; p=<base64 public key> (or k=ecdsap384). The matching private key never goes on the web server.

How to fix it

  1. Create the file

    Generate the key pair and the file with the commands in the official authentication guide (Ed25519, ECDSA P-384, or a key held in Google Cloud KMS or Azure Key Vault). The guide notes that the Ed25519 commands need OpenSSL 3, which macOS does not ship by default. The result is a one-line file named mcp-registry-auth:

    mcp-registry-auth (format)

    v=MCPv1; k=ed25519; p=<base64 public key>
  2. Serve it as text at /.well-known/mcp-registry-auth

    The file has no extension, so set text/plain explicitly; otherwise many hosts send application/octet-stream, which the grade does not count as text.

    Static site

    Save the file as .well-known/mcp-registry-auth in the web root and set the type:

    nginx, or Apache .htaccess in .well-known

    # nginx
    location = /.well-known/mcp-registry-auth { default_type text/plain; }
    
    # Apache (.htaccess inside the .well-known folder)
    <Files "mcp-registry-auth">
      ForceType text/plain
    </Files>

    WordPress

    Upload the file to .well-known/mcp-registry-auth in the WordPress root folder and add the server rule above (or ask your host to).

    Next.js

    Save it as public/.well-known/mcp-registry-auth and set the type in next.config.js:

    next.config.js

    module.exports = {
      async headers() {
        return [
          { source: '/.well-known/mcp-registry-auth', headers: [{ key: 'Content-Type', value: 'text/plain; charset=utf-8' }] },
        ]
      },
    }

    Cloudflare

    With static assets or Pages, add the rule to a _headers file:

    _headers

    /.well-known/mcp-registry-auth
      Content-Type: text/plain; charset=utf-8
  3. Log in and publish

    With the file live, log in with the mcp-publisher CLI's HTTP method for example.com as the official guide shows, then publish your server.json.

How to verify

Check the content type and the record.

shell

curl -s -o /dev/null -w "%{http_code} %{content_type}\n" https://example.com/.well-known/mcp-registry-auth
curl -s https://example.com/.well-known/mcp-registry-auth

200 text/plain and one line starting with v=MCPv1; k=.

Then re-grade your site: the result lists the evidence for this check.

$49 AI Visibility Full Report

The fixes on this site are free. The paid next step is the $49 AI Visibility Full Report (what ChatGPT, Claude and Perplexity say about your brand, with a prioritized fix list) from aivisibility.agentexchange.work. It includes:

  • 8 real buyer questions tested across ChatGPT-class models
  • Competitor share-of-voice: who AI names, how often, versus you
  • Full GEO site audit with prioritized, specific fixes
  • Agent-Readiness Score: crawler access, llms.txt, schema, discovery manifest
  • Custom 30/60/90-day action plan to get cited by ChatGPT, Perplexity and Google AI Overviews
  • Shareable report, generated in about 60 seconds after checkout

Get the Full Report — $49 Stripe checkout; you enter your brand and site right after paying.

Questions

Do I need this file if I don't publish MCP servers?

No. It exists only to prove domain ownership to the MCP Registry.

DNS or HTTP: which method should I use?

Both prove the same thing: DNS uses a TXT record with the same v=MCPv1 value, HTTP uses this file. Only the HTTP file is visible to this check.

Is it safe to publish?

Yes. The file carries a public key only; the private key stays off the server.

Sources

Primary documentation, read 2026-09-30. Vendors change these pages; follow the link before relying on a detail.