Sitelemetry

OpenAI-compatible remote MCP

Web-audit evidence for your AI workflow.

Sitelemetry gives OpenAI clients a focused set of target-safe tools for security, discoverability, accessibility and performance checks. Every remote call is protected by OAuth.

OAuth 2.1 PKCE S256 Non-mutating Streamable HTTP
7focused audit tools
0write or delete actions
1protected endpoint
2.1OAuth authorization

01 / Capabilities

Seven narrow tools, structured for agents.

Each tool accepts an explicit target and returns prioritized findings, compact evidence and remediation guidance. The service does not change the target website.

02

SEO

Reviews crawlability, metadata, content structure, indexing signals and technical search health.

audit_seo
03

AI Visibility

Checks machine-readable content, answer readiness and signals used by AI discovery systems.

audit_ai_visibility
04

Integrations

Inspects analytics, search, tag and platform integration signals exposed by the target.

audit_integrations
05

Accessibility

Identifies accessibility barriers and returns evidence with practical remediation steps.

audit_accessibility
06

Performance

Reviews delivery, rendering and resource signals that affect speed and resilience.

audit_performance
07

Full Audit

Runs the available categories as one coordinated assessment for a verified target.

audit_full

02 / Access

OAuth first. Exact scope. Clear consent.

Compatible clients discover the authorization service, open a browser consent flow and exchange an authorization code using PKCE S256. Access tokens are scoped to the remote audit service.

01

Discover

The client reads protected-resource and authorization metadata from Sitelemetry.

02

Authenticate

The user signs in on Sitelemetry and reviews the requested audit access.

03

Exchange

The client exchanges its short-lived code with its PKCE verifier.

04

Invoke

Authorized tool calls return structured, non-mutating audit results.

03 / Safeguards

Target access follows the evidence.

Public signals can be inspected for publicly reachable websites. Protected security work and Full Audit require target verification connected to the user's workspace.

Public signals

These checks use information already exposed to ordinary internet clients.

  • DNS resolution
  • SPF, DMARC, MX, CAA, MTA-STS
  • WHOIS / RDAP
  • TLS certificate and protocol
  • HTTP security headers
  • HTTPS redirect and interception signals
  • Technology fingerprint
  • Compression, cache and CDN

Verified targets

Deeper security modules and Full Audit run only when the target is covered by workspace verification.

Google Search ConsoleA matching verified property establishes control.
SitelemetryDNS or HTTP well-known verification establishes control.

Non-mutating tools

No hosted tool writes to, deletes from or reconfigures the audited target.

Network boundaries

Private, loopback and unsafe destinations are blocked from the remote service.

Usage controls

Monthly request limits protect service stability. When a limit is reached, the tool returns a neutral notice and performs no further target request.

Data minimization

Tool inputs are limited to the requested target and audit settings; results contain only audit evidence needed by the client.