# Fix mcp-registry-auth: prove your domain to the official MCP Registry

> The official MCP Registry lets you publish MCP servers under a name derived from your domain, such as `com.example/weather`. HTTP authentication proves you control the domain with a public key served at `/.well-known/mcp-registry-auth`. It matters only if you publish MCP servers.

Checked 2026-09-30 against Agent-Readiness Grade 1.3.0. HTML version: https://grade.agentexchange.work/fix/mcp-registry-auth

## What the grade checks

- `GET https://example.com/.well-known/mcp-registry-auth` with a 7-second timeout. It counts when the answer is HTTP 200, text (not HTML and not a binary content type) and not empty; a value starting with `v=MCPv1` is reported as an MCPv1 record.
- Any one of mcp-registry-auth, agent-card.json, openapi.json or /.well-known/x402 earns the agent-surface point.

The agent-surface point of the machine-readable surfaces area (shared with three other files).

## Why it matters for AI agents and crawlers

The [MCP Registry authentication guide](https://modelcontextprotocol.io/registry/authentication) says server names under your own domain must use its reverse-DNS form (`com.example/*`) and are proven by a DNS TXT record or by the HTTP file this check reads. The registry is in preview; the guide warns that breaking changes or data resets may happen before general availability.

The file holds one line with a public key, `v=MCPv1; k=ed25519; p=<base64 public key>` (or `k=ecdsap384`). The matching private key never goes on the web server.

## How to fix it

### 1. Create the file

Generate the key pair and the file with the commands in the [official authentication guide](https://modelcontextprotocol.io/registry/authentication) (Ed25519, ECDSA P-384, or a key held in Google Cloud KMS or Azure Key Vault). The guide notes that the Ed25519 commands need OpenSSL 3, which macOS does not ship by default. The result is a one-line file named `mcp-registry-auth`:

mcp-registry-auth (format):

```text
v=MCPv1; k=ed25519; p=<base64 public key>
```

### 2. Serve it as text at /.well-known/mcp-registry-auth

The file has no extension, so set `text/plain` explicitly; otherwise many hosts send `application/octet-stream`, which the grade does not count as text.

#### Static site

Save the file as `.well-known/mcp-registry-auth` in the web root and set the type:

nginx, or Apache .htaccess in .well-known:

```nginx
# nginx
location = /.well-known/mcp-registry-auth { default_type text/plain; }

# Apache (.htaccess inside the .well-known folder)
<Files "mcp-registry-auth">
  ForceType text/plain
</Files>
```

#### WordPress

Upload the file to `.well-known/mcp-registry-auth` in the WordPress root folder and add the server rule above (or ask your host to).

#### Next.js

Save it as `public/.well-known/mcp-registry-auth` and set the type in `next.config.js`:

next.config.js:

```js
module.exports = {
  async headers() {
    return [
      { source: '/.well-known/mcp-registry-auth', headers: [{ key: 'Content-Type', value: 'text/plain; charset=utf-8' }] },
    ]
  },
}
```

#### Cloudflare

With static assets or Pages, add the rule to a [`_headers` file](https://developers.cloudflare.com/workers/static-assets/headers/):

_headers:

```text
/.well-known/mcp-registry-auth
  Content-Type: text/plain; charset=utf-8
```

### 3. Log in and publish

With the file live, log in with the `mcp-publisher` CLI's HTTP method for `example.com` as the official guide shows, then publish your `server.json`.

## How to verify

Check the content type and the record.

```sh
curl -s -o /dev/null -w "%{http_code} %{content_type}\n" https://example.com/.well-known/mcp-registry-auth
curl -s https://example.com/.well-known/mcp-registry-auth
```

`200 text/plain` and one line starting with `v=MCPv1; k=`.

Re-grade: https://grade.agentexchange.work/grade?url=example.com&fresh=1

## Questions

### Do I need this file if I don't publish MCP servers?

No. It exists only to prove domain ownership to the MCP Registry.

### DNS or HTTP: which method should I use?

Both prove the same thing: DNS uses a TXT record with the same v=MCPv1 value, HTTP uses this file. Only the HTTP file is visible to this check.

### Is it safe to publish?

Yes. The file carries a public key only; the private key stays off the server.

## Sources

- [How to Authenticate When Publishing to the Official MCP Registry](https://modelcontextprotocol.io/registry/authentication) (Model Context Protocol)
- [Official MCP Registry](https://registry.modelcontextprotocol.io/) (Model Context Protocol)
- [headers in next.config.js](https://nextjs.org/docs/app/api-reference/config/next-config-js/headers) (Next.js)
- [Workers static assets: headers and the _headers file](https://developers.cloudflare.com/workers/static-assets/headers/) (Cloudflare)

## Related

- [MCP endpoint and census](https://grade.agentexchange.work/fix/mcp-endpoint.md): An MCP endpoint at /mcp, and a listing among hosts that sell to agents through x402.
- [agent-card.json](https://grade.agentexchange.work/fix/agent-card-json.md): The A2A agent card at /.well-known/agent-card.json; one of four files for the agent-surface point.
- [All fix guides](https://grade.agentexchange.work/fix)
