Codex Marketplace
codex plugin marketplace add ozandikici/sitelemetry-plugins && codex plugin add sitelemetry@sitelemetryRemote MCP / Authorized web assurance
Choose the setup for your MCP client below. Sitelemetry audit calls are OAuth-protected, limited by your plan and read-only against the target website.
Sitelemetry gives compatible AI clients seven focused web-audit tools. The client sends a tool name, an explicit target and supported audit settings; Sitelemetry returns the full available audit evidence, prioritized findings and remediation guidance. Audit calls record usage and audit data in Sitelemetry without changing the target website.
Connecting MCP does not give an agent access to your hosting account, CMS, source code or Google account. The hosted tools inspect publicly reachable web signals and do not change the target.
Use the general endpoint for Codex, Claude Code, Cursor and other compatible MCP clients, or connect through the Sitelemetry listing in ChatGPT or Claude.ai.
Sign in to Sitelemetry and approve the audit scope in your browser.
For Codex and Claude Code, public audits can use public targets; protected scans need workspace verification. For Claude.ai, every audit needs the exact verified HTTPS target.
Choose the source-private plugin for Cloud plus Local Agent, or keep the remote-only OAuth setup below.
One source-private plugin registers Sitelemetry Cloud, a loopback-only Local Agent, and the audit/fix/re-test workflow.
codex plugin marketplace add ozandikici/sitelemetry-plugins && codex plugin add sitelemetry@sitelemetryclaude plugin marketplace add ozandikici/sitelemetry-plugins && claude plugin install sitelemetry@sitelemetryThe Local Agent connects only to localhost, 127.0.0.1 or ::1 and consumes no Sitelemetry Cloud scan quota. It does not send site data to Sitelemetry Cloud; audit requests and results return to your MCP client and may be processed by its model provider under your client/provider settings.
Long hosted audits continue in the background. Your assistant automatically checks the same job until the full result is ready, without starting another scan. The timeout settings below are optional.
Add the server, then start the browser authorization flow once.
codex mcp add sitelemetry --url https://sitelemetry.com/mcp
codex mcp login sitelemetryOptional: allow 900 seconds (15 minutes) per tool call. Merge this into the existing Sitelemetry section in ~/.codex/config.toml, then restart Codex.
[mcp_servers.sitelemetry]
url = "https://sitelemetry.com/mcp"
tool_timeout_sec = 900Add the HTTP server, open /mcp in Claude Code and choose Authenticate for Sitelemetry.
claude mcp add --transport http sitelemetry https://sitelemetry.com/mcpUse a current Claude Code version. The optional timeout allows 900000 milliseconds (15 minutes) per tool call. If Sitelemetry is already configured, add timeout: 900000 to its existing server entry, then restart Claude Code.
Claude Code MCP documentationAdd this entry to .cursor/mcp.json in your project, or ~/.cursor/mcp.json for all projects. Merge it with any existing mcpServers entries.
{
"mcpServers": {
"sitelemetry": {
"url": "https://sitelemetry.com/mcp"
}
}
}In Cursor's MCP settings, connect Sitelemetry. Sign in or create your Sitelemetry account in the browser, then approve access. OAuth handles sign-in; no API key is needed.
Cursor setup documentationOptional: if your client supports tool timeout settings, allow 15 minutes for long calls. Available settings and limits depend on the client version.
Add a remote MCP server named Sitelemetry with the URL below. Select Streamable HTTP and OAuth if your client asks.
https://sitelemetry.com/mcpUse a client that supports remote HTTP MCP and browser-based OAuth. Connect, sign in or create a Sitelemetry account, and approve access; the client then loads the available tools.
Open the Sitelemetry listing in Claude.ai and connect your account. Complete Sitelemetry authorization in your browser.
If you need a custom connector, add the Claude endpoint below in Claude.ai's connector settings and complete authorization.
https://claude-mcp.sitelemetry.com/mcpOpen the Sitelemetry listing in ChatGPT, connect your account, and complete Sitelemetry authorization in your browser.
Connect in ChatGPTOAuth clients receive a short-lived, audience-bound access token—not your Sitelemetry password, account API key or stored Google integration credentials.
Every tool requires a target. Optional inputs are deliberately narrow and results are returned as concise text plus structured audit data.
audit_securityChecks DNS, email DNS, RDAP registration, TLS, HTTP security headers, HTTPS/MITM posture, technology fingerprinting and transport delivery by default. Target verification follows your client's rules; additional modules remain subject to your plan and hosted-scan policy.
audit_seoCrawls public pages for indexation, metadata, headings, canonicals, structured data, internal-link failures, redirects and AI-crawler policy.
audit_ai_visibilityAssesses entity clarity, answerability, source signals, prompt coverage, llms.txt and crawler policy for AI search and answer engines.
audit_integrationsDetects analytics, tag managers, marketing pixels, site-verification signals, consent systems and potential PII exposure in public data-layer output.
audit_accessibilityRuns a static WCAG 2.2-oriented review of alternative text, labels, headings, landmarks, contrast signals, language declarations, duplicate IDs and iframe titles.
audit_performanceUses Google PageSpeed Insights, which fetches the requested public URL independently. Sitelemetry preflights the current redirect chain and accepts Lighthouse/CrUX metrics only when PSI's reported inspected/final URL remains inside the same safe host and port boundary.
audit_fullRuns all six pillars in parallel, returns one blended score and summarizes every pillar. Use individual tools afterward when you need the full finding list for one discipline.
A compatible client can choose the right Sitelemetry tool from your request.
Run a full Sitelemetry audit of example.com in English. Prioritize critical and high findings, then give me a sequenced remediation plan.
Audit the technical SEO of example.com across 12 pages. Group fixes into crawlability, metadata, structured data and internal links.
Check example.com for WCAG-oriented accessibility issues. Show the evidence for each high-impact problem and propose acceptance criteria.
Evaluate whether example.com is easy for answer engines to understand and cite. Turn the top five AI-visibility gaps into implementation tasks.
Review the analytics and consent stack on example.com. Flag missing verification, duplicate tags and any public data-layer fields that may contain personal data.
Sitelemetry is a defensive assurance service, not an open scanning proxy.
Codex, Claude Code and ChatGPT protected scans need workspace ownership verification. Claude.ai needs current proof for the exact HTTPS target on every audit. A new verified site gets a monitoring project if a slot is available; it can still be audited when slots are full, within your plan's allowance. Verify ownership through Sitelemetry DNS or HTTP, or Google Search Console with siteOwner permission.
Codex and Claude Code support public targets for eight public security checks, SEO, AI Visibility, Integrations, Accessibility and Performance. Protected security modules and Full Audit need workspace verification. Claude.ai requires target verification for all these audits.
The seven tools make observation requests and return evidence. They do not sign in to, create, edit or delete content in the audited website or its connected accounts.
Every successful call records Sitelemetry usage and audit/security state and consumes the applicable plan quota. Subscription entitlements, rate limits, concurrency controls and timeouts apply to remote calls; Sitelemetry-originated web requests also use server-side SSRF and redirect controls. PageSpeed's independent fetch and returned-result boundary are disclosed above.
Sitelemetry receives MCP protocol traffic and the tool arguments your client sends: the requested tool, target, report language and any supported audit setting. It processes public technical responses and returns audit evidence to that client. It does not independently access the rest of your AI conversation.
Your chosen AI client provider receives the tool request and returned results as part of your conversation and handles them under its own terms and privacy policy. Sitelemetry may retain account, usage, security and audit records as described in the Privacy Policy; it does not sell personal information.
Any active, verified Sitelemetry account can connect through Remote MCP. Claude.ai lists all seven audit tools. Execution depends on the connected account's plan and remaining quota. Free supports audit_security within its low monthly security allowance; other audits require an eligible plan. Codex and Claude Code public audits do not require workspace target verification when available; protected security modules and audit_full do. Claude.ai requires the exact verified HTTPS target for every audit. Account, usage and workspace limits apply to every call.
Verified domains define which targets are authorized. Monitoring projects store sites for ongoing tracking; project capacity is separate from domain verification. A full project slot does not by itself prevent audits of other verified sites. Audit permissions and remaining usage allowances still apply.
In Sitelemetry, open My account and Connected MCP applications to revoke an application's access. This revokes all authorizations for that application at the selected MCP address; other applications are unaffected. You can also remove Sitelemetry from your client settings. Reconnecting requires authorization again.