Rule-based site audits: accessibility, SEO, security headers, performance. Metered per call.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Machine-payable site compliance audits. WCAG 2.1 A/AA, SEO, security headers, and performance β deterministic rules against the real rendered page, priced per call, payable by software with no account and no human in the loop.
Live: https://hubvibe-831480473793.us-south1.run.app
Every check is a deterministic rule run against the live page. Nothing here is a language model judging whether a site looks compliant, and a check that could not run is returned as an error, never as a passing result.
There are two ways in. Both take under a minute.
That is the entire integration. Every pull request now runs the full compliance bundle against your deployed preview and fails the build on the regression that caused it β not in an audit six months later.
fail-on-error: false keeps our outage from ever blocking your deploy;
your real regressions still gate it.Gate a promotion on it:
Keys come from /billing/checkout.
Or skip the key entirely β see the second way in.
An unauthenticated call is not an error here. It is the price sheet:
An agent reads the 402, signs an x402 payment (USDC on Base), retries with
X-PAYMENT, and gets the audit. Payment is verified before the audit runs
and settled only after it produces a result β a failed audit is never
charged, on any rail.
For Python agents and swarms, the bundled tollbooth client does the whole loop β challenge, budget check, signing, retry β with two hard spending limits enforced before anything is signed:
accepts lists only the payment rails that can genuinely settle on this
deployment. A rail that is not configured is omitted rather than advertised
with a null recipient, so a paying agent never builds a payment that cannot
land.
How machines find this node without being told the URL: every 402
carries x402 Bazaar discovery data, so facilitators index it by capability
and price; the MCP endpoint at /mcp
is listed in the official registry as io.github.Its-fortunatefolly/hubvibe;
and /.well-known/agent.json
is generated from the same catalog the routes charge from, so the advertised
price is the charged price by construction.
| Route | Price | Checks |
|---|---|---|
POST /audit/wcag | $0.03 | WCAG 2.1 A/AA via axe-core, against the rendered page |
POST /audit/seo | $0.03 | Title, meta description, H1s, canonical, OpenGraph, structured data, lang |
POST /audit/security | $0.03 | HTTPS, HSTS, CSP, X-Content-Type-Options, clickjacking, Referrer-Policy, CORS |
POST /audit/performance | $0.03 | DOM nodes, transferred bytes, request count from one real page load |
POST /audit/bundle | $0.10 | All four against one URL, billed once |
Body is {"url": "..."}; wcag and seo also accept raw {"html": "..."}.
Three rails, all fail-closed β no valid credential means no audit runs:
X-API-Key β subscription key from /billing/checkoutX-PAYMENT β x402Authorization: Payment ... β MPP (Stripe Shared Payment Tokens for
fiat, or Tempo for crypto)Which are live is deployment-specific. Read accepts in any 402, or
payment.methods in the agent manifest β both list only what actually works.
Only an audit that produced a result.
Retry-After, checked before any
payment is touched, so it costs nothing.Agents shouldn't have to read documentation to use this:
/.well-known/agent.json | Full manifest β pricing, live rails, limits, per-endpoint examples |
/openapi.json | OpenAPI 3.1 |
/mcp.json | MCP tool definitions |
/llms.txt | Plain-text summary |
/docs | Interactive reference |
In wcag-audit-engine/integrations/:
mcp_server.py β MCP server exposing all five audits as tools, built on
the official SDK. Standalone, with its own mcp_requirements.txt: the mcp
package needs a newer Starlette than the deployed service pins for FastAPI,
so it is deliberately kept out of the service's dependency tree.langchain_tool.py β LangChain tool wrapper. Subscription key only; it
raises on a 402 rather than paying.hubvibe_tollbooth.py β the client for agents running unattended. Same
audits, but it settles the 402 itself from an EVM wallet via x402, so no
human has to go get a key. Enforces a per-call cap and a
process-lifetime budget, both before anything is signed β an autonomous
loop with an unbounded wallet is a drained wallet. Exposes LangChain/CrewAI
tools via hubvibe_tools().github_action.yml β a complete, copyable workflow file. It calls the
published action rather than curl-ing the API: a hand-rolled HTTP step has
to re-implement the retry policy, the 4xx no-retry rule and the JSON
encoding of the target URL, and then be maintained against the API by
whoever pasted it. One file, one URL to edit, on: push and
on: pull_request.At the repo root:
action.yml β the composite GitHub Action, and the single copy of it.
It retries transient failures but never a 4xx (repeating a 402 on a metered
endpoint risks paying twice for one answer), renders findings into the job
summary via scripts/render_audit_summary.py, and can be adopted with
fail-on-error: false so an outage in this service cannot block someone
else's deploys.scripts/publish-action-repo.sh β generates the standalone repo the
Marketplace listing needs (see below).glama.json β listing metadata for the Glama MCP directory.The machine API is the product. There is also a website for humans who want a report rather than an integration β priced per site watched, not per scan. There is deliberately no free scan: an audit costs a real browser page load, so giving them away funds strangers' compute and invites abuse.
Two separate things, with different rules:
Direct use works today. An action.yml at a public repo's root is usable
as-is, no Marketplace involved:
A Marketplace listing needs a different repo. GitHub requires an action
repository to contain a single root action.yml and no workflow files at
all. This repo has .github/workflows/, so it can never be listed itself β
moving action.yml around does not help. Generate the clean standalone repo
instead:
It copies action.yml and the summary renderer verbatim (so the published
action cannot drift from the one in this repo), writes a listing README, and
prints the exact push/tag/publish steps.
server.json in this repo root registers the live /mcp endpoint as a
remote server, so no package needs publishing anywhere.
mcp-publisher is a Go binary from the registry's GitHub releases β it is
not on npm (the mcp-publisher package on npm is an unrelated
browser-automation tool):
The name field is io.github.its-fortunatefolly/hubvibe, which the GitHub
login authenticates against. server.json is validated against the official
schema (note: description is capped at 100 characters).
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/hubvibe-site-audits)<a href="https://allmcps.com/mcp/hubvibe-site-audits"><img src="https://allmcps.com/api/badge/hubvibe-site-audits?style=directory" alt="HubVibe Site Audits on AllMCPs" /></a>