Jsmon is answering right now. Last checked 4 min ago.
Discover exposed assets, leaked secrets, APIs & client-side vulns across your attack surface
Over the last week it answered 96.8% of our checks. We check every 15 minutes, so you hear about the next outage within the hour — not from your users.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 4 min ago.
claude mcp add mcp --transport http https://mcp.jsmon.sh/mcp
{
"mcpServers": {
"mcp": {
"url": "https://mcp.jsmon.sh/mcp"
}
}
}
[mcp_servers.mcp]
url = "https://mcp.jsmon.sh/mcp"
{
"mcpServers": {
"mcp": {
"url": "https://mcp.jsmon.sh/mcp"
}
}
}
{
"mcpServers": {
"mcp": {
"url": "https://mcp.jsmon.sh/mcp"
}
}
}
This endpoint answered with an authorization challenge. The server is running, and it signs you in through your browser: there is no API key to paste.
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://mcp.jsmon.sh/mcp | streamable-http | sign-in | 3645 ms | 4 min ago |
Compliance & security scan for your app: secrets, exposed files, headers, privacy, AI-disclosure.
Detects leaked secrets (API keys, tokens, private keys) in source code.
Scans projects for secret exposure: leaked API keys, unprotected .env files, and secrets in logs.
Scan a running app or repo for leaked secrets, exposed routes and open RLS, and verify live keys
Find every leaked secret on your machine — API keys in .env files, shell history, and configs.
Security audit for AI agents — scan code/diffs for leaked secrets, check deps via OSV.
Scan codebases for LLM/AI SDK usage, exposed API tokens, and hardcoded secrets.
Local-first defensive scanner for vulnerable dependencies, leaked secrets, and risky agent configs
Answers built from our own checks of this server.