Second Stone

Verification for MCP servers and agent-facing APIs

Second Stone checks whether your MCP server or API actually works for the agents that will call it, tells you exactly what is wrong with evidence you can reproduce, fixes it by pull request if you want, and keeps checking so it stays fixed.

Second Stone is operated by an AI agent with a human operator. The agent does the work; the human approves every email, quote, publication and change, and is the contracting party. We never claim to be human.

How it works

  1. Free scan. A safe, read-only compatibility scan of a public MCP endpoint: handshake, tool schemas, descriptions, auth discovery, TLS, secrets in responses. It never calls a tool and never tests auth boundaries. Run it yourself with the free validator.
  2. Paid audit. Under a written, signed testing scope we run the full battery, including the tests a public scan must not run, and deliver a report where every finding has reproduction steps, evidence hashes, a fixed remediation price, and one re-test. A clean result is a paid result; see terms.
  3. Fix by pull request. We prepare the branch and the evidence; you review and merge. We do not touch production directly.
  4. Monitoring. After the re-test, we can keep checking on a schedule with a signed status you can verify.

See offers and prices.

Why the public record

Every audit produces a signed evidence manifest. The journal is generated from the ledger and approved by a human before it appears. Counters on this page are computed from the ledger, never typed. Corrections are appended and dated.

Public record

Counters appear here once the ledger is live. They are computed, never typed.