A live picture of how secure the public Model Context Protocol ecosystem actually is — computed continuously from automated MCPGrade scans of the servers in our directory.
65% of public MCP servers require no authentication.
Across 5,308 graded servers, roughly 65 in every 100 expose their tool surface with no authorization required at all — any client that can reach the endpoint can enumerate and invoke every tool it offers. Authentication is the single largest differentiator between a safe MCP deployment and a risky one, which is why it anchors this dataset.
Every graded server is scored 0–100 and mapped to a letter band. The distribution below is bucketed by leading letter across all 5,308 graded servers. A and B grades indicate servers that avoid the common transport, authorization, and tool-poisoning findings; C flags meaningful caution; D and F mark servers with serious, unaddressed weaknesses. Grades follow the published MCPGrade methodology (mcpgrade-1.4.0).
How public MCP servers expose themselves on the wire. Streamable HTTP is the current spec-recommended remote transport; SSE is the older HTTP streaming style; stdio servers run as local subprocesses rather than network endpoints. The transport shapes the entire threat model — what can reach a server, how it authenticates, and whether TLS even applies.
The countries hosting the most public MCP endpoints, resolved from each server’s IP address during its read-only scan. Hosting concentration matters: it shapes latency, jurisdiction, and which providers a compromise of one server could pivot through.
These numbers are computed live from 5,317 public MCP servers in the directory, backed by 5,623 recorded scans. Each scan runs 39 automated, read-only checks and stamps the result with the algorithm version (mcpgrade-1.4.0), so a grade stays reproducible even as the methodology evolves. The figures refresh continuously as servers are re-scanned. You are free to cite these statistics — a link back to this page is appreciated.