> Demo

A small server, tested end to end.

I keep a small demo server to show how a finished MCP server behaves. It uses made-up data, never calls a real service, and is not affiliated with any company.

What the demo has

  • One read-only tool with safety labels: read-only, not destructive, safe to repeat.
  • Strict inputs. Only a fixed example value is accepted, and extra fields are refused.
  • A bearer-token check, and a refusal of requests from other websites.
  • A verification route that directories such as ChatGPT’s can use to confirm who runs a server.

What I test on it

All checks run locally with the internet switched off, apart from a stand-in service on the same machine. Latest full run: 2 October 2026, every check passed.

  1. The server starts and completes the MCP handshake.
  2. The tool list appears with all four safety labels.
  3. A tool call reaches the stand-in service exactly once.
  4. Invalid or extra arguments are rejected before anything is sent upstream.
  5. A missing or wrong token gets a 401 response.
  6. A request from another website gets a 403 response.
  7. The verification route returns the configured text and refuses other methods.

What the demo does not prove

The demo has not been deployed, and it says nothing about how a real API will behave. A client build is tested against the client’s own sandbox, and I report anything I could not test.

Want a walk-through of the demo, or a pilot on your own API? Send a request below.