Walkthrough
Servers that need a token
Many remote servers need a token. You pass it through a config file, in the same format your MCP client already uses.
Without a token
mcpsight scan http://127.0.0.1:8931/auth/clean; echo "exit $?"
✗ http://127.0.0.1:8931/auth/clean: probing http://127.0.0.1:8931/auth/clean: initialize: http 401: missing or wrong bearer token exit 2
Exit code 2 means the scan could not run. It is never reported as clean.
With a token
Describe the server in a config file with its headers:
{
"mcpServers": {
"docs-with-token": {
"url": "http://127.0.0.1:8931/auth/clean",
"headers": { "Authorization": "Bearer fixture-token" }
}
}
}
mcpsight scan --from servers.json
benign-docs
Server benign-docs (1.2.0, via remote)
Grade B (80/100) rubric v1
Context cost ~229 tokens (2 tools) ~$0.001 per request @ Claude Sonnet (est.)
Capabilities none declared
Drift baseline recorded (first scan)
Findings
HIGH Server is served over plaintext HTTP [authposture.plaintext_http]
The endpoint uses http://, so tool traffic and any credentials travel
unencrypted.
fix: Serve the MCP endpoint over HTTPS.
Report: .mcpsight/report.json | SARIF: .mcpsight/report.sarif
The grade rises to B. MCPsight scanned once with your token, then once without. The second attempt was refused, so the server does not list its tools to strangers, and that finding is gone. Plain HTTP is still flagged.
Your secrets stay out of reports.
MCPsight writes header and environment values as [redacted] in report.json and report.sarif, and keeps only their names.