ZeroLeaksDocs
API Reference

ZeroLeaks MCP server

Connect agents to public ZeroLeaks developer documentation and OpenAPI resources over MCP Streamable HTTP.

The public ZeroLeaks MCP endpoint is https://zeroleaks.ai/mcp. /api/mcp is an alias. It exposes documentation resources without an API key. Use the authenticated REST API or @zeroleaks/sdk to create scans and read private results.

The server implements MCP 2025-11-25 Streamable HTTP with the official TypeScript SDK. It is stateless: it returns JSON responses and no Mcp-Session-Id. Standalone SSE streams, subscriptions, and resource-change notifications are not supported. A GET to the endpoint returns 405; use POST for JSON-RPC messages.

Connect and list resources

Configure your MCP client's Streamable HTTP transport with the endpoint URL. The client sends initialize, notifications/initialized, then resources/list or resources/read. HTTP POSTs must advertise both application/json and text/event-stream in Accept. Include the negotiated MCP-Protocol-Version header after initialization.

curl https://zeroleaks.ai/mcp \
  -H 'Content-Type: application/json' \
  -H 'Accept: application/json, text/event-stream' \
  -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-11-25","capabilities":{},"clientInfo":{"name":"docs-reader","version":"1.0.0"}}}'

Initialization advertises resources: {}. The initialized notification is acknowledged with 202 Accepted and an empty body. The server also accepts the SDK's compatible earlier protocol versions.

curl https://zeroleaks.ai/mcp \
  -H 'Content-Type: application/json' \
  -H 'Accept: application/json, text/event-stream' \
  -H 'MCP-Protocol-Version: 2025-11-25' \
  -d '{"jsonrpc":"2.0","id":2,"method":"resources/list"}'

Available resources

Resource URIMIME typeContent
https://zeroleaks.ai/agent-instructions.mdtext/markdownWhen to use ZeroLeaks, scan selection, and recovery
https://zeroleaks.ai/llms.txttext/plainDeveloper resource index
https://zeroleaks.ai/llms-full.txttext/plainScan workflows and report interpretation
https://zeroleaks.ai/openapi.jsonapplication/jsonOpenAPI 3.1 schema

Pass an exact resource URI in resources/read with params: {"uri":"https://zeroleaks.ai/agent-instructions.md"}. Resource content matches its public HTTP representation. Unknown resources return JSON-RPC error -32002; unsupported methods return -32601. Requests with an untrusted Origin are rejected with 403.

On this page