Universal resolver for the agentic web: give a domain, get one normalized discovery answer.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
Give NessGate a domain and your client's capabilities, and it tells you how that client can connect β and what's still missing. One call turns "here's a domain" into a concrete, sourced connection plan: which protocol to use, at which endpoint, over which transport, and exactly what authentication the service published β or, if it can't be done yet, the precise field the service is missing.
Four honest outcomes, never a guess: ready (connect now, no credentials), credentials-required
(everything's known β bring your own secret), incomplete (the service under-published β NessGate
names the exact missing field), no-compatible-method (nothing your client speaks). Prefer the
per-resource view? Add ?readiness=1 to /explore. Prefer the raw list of what a domain publishes?
That's the original resolver, GET /discover/{domain} β unchanged and still here.
You can β it's not impossible, just permanent. To turn a domain into a working connection you'd have
to read and track every discovery standard (ARD, A2A, llms.txt, api-catalog, OpenAPI, ORD, host-meta,
ANP, UCP, AID, MCP, GB/Z 185.4β¦), follow each one's auth story (OpenAPI security schemes, the MCP OAuth
metadata chain RFC 9728 β RFC 8414, A2A card schemes), handle server quirks, timeouts, redirects, and
SSRF safety on every hop, normalize it all into one shape, and keep doing that as the protocols change.
NessGate does exactly that, reads on demand, stores nothing, and stays neutral β so you write your
agent, not a compatibility layer. It's free, open (Apache-2.0), and independently implementable; if
nessgate.com vanished, every domain's files would still stand on the domain itself.
Live at https://nessgate.com Β· Specification Β· Charter Β· API
NessGate reads the standards a domain already publishes; it defines none of them and stores nothing. The domain is always the authority.
Embeddable library β dependency-free, fetches the target domain directly (no runtime
dependency on nessgate.com), runs anywhere with fetch β Node, Deno, Workers, and agent runtimes.
(It runs in a browser too, but a browser can only read other domains that send CORS headers, and
most .well-known files don't β so from a browser, resolve arbitrary domains via the hosted
endpoint below, which sends open CORS.) Published as
@nessgate/resolver:
Hosted endpoint β open CORS, no auth:
MCP β the same lookup as a tool (discover_domain) at https://nessgate.com/mcp. Listed in the
official MCP Registry
as com.nessgate/nessgate (domain-verified remote server), so MCP-aware clients can install it directly.
Give an agent a domain, get back what to use β no per-standard code. Drop this into a tool, a retrieval step, or an onboarding flow:
No SDK? The hosted endpoint is one HTTP GET (GET https://nessgate.com/discover/{domain}, open
CORS, no auth), and the MCP tool discover_domain returns the same shape. Adding a new standard
is a new adapter upstream β integrations don't change.
Full integration guide β library, HTTP, and MCP client config (including the mcp-remote bridge
for stdio-only clients): docs/integrations.md.
NessGate is free, neutral infrastructure β see the Charter. It never charges to use or to be read, never sells ranking or placement (there is none), keeps no accounts, and stores no domain data. It reads a domain on demand (answers are cached at the edge for up to 10 minutes), never crawls or indexes, and makes no ownership or safety claim β it reports what a domain serves and links back to each source. The specification is open and the reference implementation is Apache-2.0 licensed: anyone may run their own resolver, and if nessgate.com disappeared, every domain's files would still stand on the domain itself.
One stateless Cloudflare Worker (src/worker.js) serves the static site
(public/, via the assets binding with run_worker_first), the resolver API, the MCP
server, the per-domain pages, and the sitemap. There is no database.
The resolver (GET /discover/{domain}, and the embeddable public/resolver.mjs) reads
what a domain publishes, normalizes it into one answer, fetches the domain directly, and stores
nothing. Answers are computed fresh and cached at the edge for 10 minutes. A parity test keeps
the worker's and the library's normalization byte-identical, and keeps
packages/resolver/index.mjs (the npm package) byte-identical to public/resolver.mjs.
Adapter architecture β four discovery channels. Each supported standard is a small, independent adapter, and every adapter uses one of four channels to locate its document:
llms.txt, ard-catalog
(ARD / ai-catalog), a2a-agent-card (A2A), api-catalog (RFC 9727), ai-info.json,
openapi, ord (Open Resource Discovery), awp (draft), host-meta (RFC 6415),
anp (Agent Network Protocol /.well-known/agent-descriptions), and ucp (Universal
Commerce Protocol /.well-known/ucp).<link rel="ard"> in the homepage, then GET the target (ard-link).Agentmap: directive in /robots.txt, then GET the target
(ard-agentmap)._agent.<domain> (aid: v=aid1;u=<uri>;p=<proto>;a=<auth>).ARD: NessGate implements ARD's normative domain resolution β it fetches
/.well-known/ard.json and honours the <link rel="ard"> relation (both MUST in ARD v0.91
Β§5.1) β plus the robots Agentmap: surface. ARD's optional in-page JSON-LD is found only by
general web crawling, which NessGate does not do; ARD's DNS mechanism is described in Β§5.1 but
not yet normatively specified (no record type or parameters). Neither is implemented β publishing
a guessed record would be fake conformance. ANP and UCP are emerging; the AID TXT record (v=aid1
at _agent) and AWP are drafts, read as-is with no adoption claim. Note: the aid adapter is
the AID TXT mechanism, not the IETF DNS-AID draft (SVCB at _agents.<domain> β a separate,
unimplemented mechanism).
GB/Z 185 (China, ζΊθ½δ½δΊθ) β 185.4 yes, 185.5 gated. NessGate normalizes GB/Z 185.4
agent descriptions ("ACS"): an ACS is an A2A-family card with GB/Z extensions (an agent
identity code aic, an mTLS scheme, a certificate block), recognized by content and
labelled gbz-185-4, preserving those fields and provenance. Recognition is domain-first: an
ACS served at the agent-description location NessGate already reads is normalized β no
GB/Z-specific .well-known path is guessed. GB/Z 185.5 discovery is a federated gateway
service with no domain-native location, so it is not part of the hosted resolver and is
never auto-discovered. The embeddable library exposes it as an opt-in, Node-only call
(resolve(domain, { gbz: { gatewayUrl, fetch, query } })) that POSTs to the reference
implementation's real β¦/acps-adp-v2/discover endpoint with a caller-supplied authenticated
fetch (bring-your-own mTLS/OIDC β NessGate embeds no credentials) and normalizes the ACS
records it returns. No guessed endpoints, no fake conformance.
Cloudflare KV (NESSGATE_KV) holds only approximate, IP-keyed hourly rate-limit counters
that expire within the hour. Nothing else is stored.
Rate limiting: a Cloudflare-native edge limiter (burst, per-colo and eventually consistent β approximate by design) in front of an approximate KV hourly cap. Abuse protection, not exact global accounting.
SSRF protections: DoH pre-check against private/reserved IPs, on-domain redirects only
(β€ 3), 1 MB caps, 8 s timeouts, HTTPS-only. Probes are read-only GETs of public well-known
paths; the DNS-rebinding TOCTOU window is documented in src/worker.js and is immaterial
here (Worker egress has no private network behind it, and probes assert nothing).
No accounts, no emails, no stored domain data.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/nessgate)<a href="https://allmcps.com/mcp/nessgate"><img src="https://allmcps.com/api/badge/nessgate?style=directory" alt="NessGate on AllMCPs" /></a>