ZeroLeaks MCP server
Connect agents to public ZeroLeaks developer documentation and OpenAPI resources over MCP Streamable HTTP.
The public ZeroLeaks MCP endpoint is https://zeroleaks.ai/mcp. /api/mcp is an alias. It exposes documentation resources without an API key. Use the authenticated REST API or @zeroleaks/sdk to create scans and read private results.
The server implements MCP 2025-11-25 Streamable HTTP with the official TypeScript SDK. It is stateless: it returns JSON responses and no Mcp-Session-Id. Standalone SSE streams, subscriptions, and resource-change notifications are not supported. A GET to the endpoint returns 405; use POST for JSON-RPC messages.
Connect and list resources
Configure your MCP client's Streamable HTTP transport with the endpoint URL. The client sends initialize, notifications/initialized, then resources/list or resources/read. HTTP POSTs must advertise both application/json and text/event-stream in Accept. Include the negotiated MCP-Protocol-Version header after initialization.
curl https://zeroleaks.ai/mcp \
-H 'Content-Type: application/json' \
-H 'Accept: application/json, text/event-stream' \
-d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-11-25","capabilities":{},"clientInfo":{"name":"docs-reader","version":"1.0.0"}}}'Initialization advertises resources: {}. The initialized notification is acknowledged with 202 Accepted and an empty body. The server also accepts the SDK's compatible earlier protocol versions.
curl https://zeroleaks.ai/mcp \
-H 'Content-Type: application/json' \
-H 'Accept: application/json, text/event-stream' \
-H 'MCP-Protocol-Version: 2025-11-25' \
-d '{"jsonrpc":"2.0","id":2,"method":"resources/list"}'Available resources
| Resource URI | MIME type | Content |
|---|---|---|
https://zeroleaks.ai/agent-instructions.md | text/markdown | When to use ZeroLeaks, scan selection, and recovery |
https://zeroleaks.ai/llms.txt | text/plain | Developer resource index |
https://zeroleaks.ai/llms-full.txt | text/plain | Scan workflows and report interpretation |
https://zeroleaks.ai/openapi.json | application/json | OpenAPI 3.1 schema |
Pass an exact resource URI in resources/read with params: {"uri":"https://zeroleaks.ai/agent-instructions.md"}. Resource content matches its public HTTP representation. Unknown resources return JSON-RPC error -32002; unsupported methods return -32601. Requests with an untrusted Origin are rejected with 403.