Walkthrough

Servers that need a token

Many remote servers need a token. You pass it through a config file, in the same format your MCP client already uses.

Without a token

mcpsight scan http://127.0.0.1:8931/auth/clean; echo "exit $?"
✗ http://127.0.0.1:8931/auth/clean: probing http://127.0.0.1:8931/auth/clean: initialize: http 401: missing or wrong bearer token
exit 2

Exit code 2 means the scan could not run. It is never reported as clean.

With a token

Describe the server in a config file with its headers:

{
  "mcpServers": {
    "docs-with-token": {
      "url": "http://127.0.0.1:8931/auth/clean",
      "headers": { "Authorization": "Bearer fixture-token" }
    }
  }
}
mcpsight scan --from servers.json
  benign-docs
  Server        benign-docs  (1.2.0, via remote)
  Grade         B  (80/100)  rubric v1

  Context cost  ~229 tokens  (2 tools)   ~$0.001 per request @ Claude Sonnet  (est.)
  Capabilities  none declared
  Drift         baseline recorded (first scan)

  Findings
  HIGH      Server is served over plaintext HTTP [authposture.plaintext_http]
      The endpoint uses http://, so tool traffic and any credentials travel
      unencrypted.
      fix: Serve the MCP endpoint over HTTPS.

  Report: .mcpsight/report.json  |  SARIF: .mcpsight/report.sarif

The grade rises to B. MCPsight scanned once with your token, then once without. The second attempt was refused, so the server does not list its tools to strangers, and that finding is gone. Plain HTTP is still flagged.

Your secrets stay out of reports.

MCPsight writes header and environment values as [redacted] in report.json and report.sarif, and keeps only their names.