npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@eidonze/mcpdoctor

v0.1.6

Published

Read-only MCP and x402 endpoint preflight checks: 402 challenge shape, payment document parsing, accepts[] conformance, discovery manifests, response digest. Zero dependencies.

Readme

mcpdoctor

Read-only checks for MCP tool schemas and x402 payment endpoints. Use it before an agent client or buyer depends on an endpoint.

npm CI License

Find the right guide

Run it now

Check an MCP server without calling any tools:

npx @eidonze/[email protected] schema https://your-mcp-server.example/mcp --json

Check an x402 endpoint without paying:

npx @eidonze/[email protected] inspect https://your-api.example/paid --method=POST --json

Requires Node.js 18+. No API key or wallet is needed.

Example schema run against a live endpoint:

$ npx @eidonze/mcpdoctor schema https://your-mcp-server.example/mcp

MCP Tool Schema Report
- Status: FAIL
- Endpoint: https://your-mcp-server.example/mcp
- Protocol: 2025-06-18
- Tools: 12

- FAIL REQUIRED_PROPERTY_UNDEFINED: tools[3] requires undeclared property query
- WARN PROPERTY_DESCRIPTION_MISSING: tools[7].limit has no description

The exact same run against a healthy server prints Status: PASS and exits 0, so CI can gate on it.

Which command?

| Command | Checks | Does not do | |---|---|---| | schema | MCP initialize, tools/list, tool names, descriptions, and JSON schemas | Does not call tools or prove runtime behavior | | inspect | HTTP 402, x402 v1/v2 payment document, accepts[], discovery manifests, latency and response digest | Does not sign, pay, settle, retry, or verify delivery |

Exit codes are stable for automation: 0 PASS, 1 FAIL, 2 UNKNOWN/network error, 3 usage error.

GitHub Actions

Add a read-only check to pull requests:

name: MCP Trust Check
on: [pull_request]

jobs:
  mcp-trust:
    runs-on: ubuntu-latest
    steps:
      - uses: xka0085-byte/mcp-doctor@v1
        with:
          endpoint: https://your-mcp-server.example/mcp
          mode: schema
          format: markdown

Use mode: inspect for an x402 preflight. The action fails on FAIL or UNKNOWN by default; set fail-on: false for an informational check.

Starter template

Start a new MCP project with this check already wired in:

The check is read-only and should target a public test endpoint. Do not place private keys or credentials in workflow inputs.

What the report means

PASS means the observed response matched the checks in this version. It is not a security audit, protocol certification, payment-success guarantee, or proof that an endpoint is safe. UNKNOWN means the endpoint could not be observed within the timeout or response-size limits.

Example schema failure:

FAIL REQUIRED_PROPERTY_UNDEFINED tools[0] requires undeclared property query

Example x402 failure:

FAIL NO_402 Expected HTTP 402, received 400

Why it exists

The checks come from failure modes observed while building ReceiptRail: body validation that prevents an x402 challenge, payment documents in multiple headers/body shapes, and vendor hint headers that can hide the real accepts[] document.

mcpdoctor is not an MCP server. It is an independent, read-only endpoint inspector. It is not affiliated with mcpdoctor.dev; verify the npm scope is @eidonze/mcpdoctor.

Feedback

Found a false positive or a protocol shape we should support? Open an issue. Include the command, redacted output, Node version, and whether the endpoint is MCP or x402. Never include tokens, payment signatures, or private URLs.

License

MIT