Sample report · Claude Connectors Directory readiness

MCP server readiness report: Microsoft Learn MCP

Server URL
https://learn.microsoft.com/api/mcp
Server reported
Microsoft Learn MCP Server 1.0.0
Check run
28 September 2026, 04:49:33 UTC · took 19.9 s
Checker version
1.0.0 · 27 checks · 7 HTTP requests

Summary

13passed
0warnings
0failed

Every automated check that applies to this server passed. The 14 skipped checks cover sign-in (the server needs none) and MCP Apps screenshots (the server declares no app interface). A clean result is not an approval: Anthropic's reviewers make that decision and also judge things no script can, such as whether each tool does what its description says.

Microsoft Learn MCP is a public server run by Microsoft. It was chosen for this sample because anyone can connect to it without an account. This report is not affiliated with or endorsed by Microsoft.

Findings

Each row shows the check, the published rule it comes from, the evidence recorded during the run (verbatim), and what it means in plain language.

Transport
PassServer URL uses HTTPShttps-urlRule: claude.com · pre submission checklist for connectors

The URL uses https://.

What this means: Anthropic's submission portal only accepts https:// addresses, and this one qualifies.

PassAnswers MCP over Streamable HTTPmcp-endpointRule: modelcontextprotocol.io · sending messages

initialize answered in 3.4 s as text/event-stream; negotiated protocol 2025-06-18; session id issued. Server: Microsoft Learn MCP Server 1.0.0. (The 2026-07-28 probe got JSON-RPC error -32601, so the legacy handshake was used, as the spec describes.)

What this means: An MCP client can open a session at this URL over Streamable HTTP. The server does not answer the 2026-07-28 discovery call, so the checker fell back to the older initialize handshake, which the specification allows.

PassAccepts notifications with 202notification-202Rule: modelcontextprotocol.io · sending messages to the server

202 Accepted in 1.4 s.

What this means: The server acknowledges client notifications the way the transport specification requires: 202 with an empty body.

Authentication
PassAuthentication type Claude can useauth-modeRule: claude.com · supported authentication types

No authentication (type none, supported by default). If your tools act on a user’s account, Anthropic expects OAuth 2.0.

What this means: No sign-in is needed. That is accepted for public data; Anthropic expects OAuth 2.0 when tools act on a user's account.

Skipped401 carries a resource_metadata pointerauth-challengeRule: claude.com · serve discovery metadata

Not applicable: no sign-in is required.

What this means: Nothing to fix. These checks apply only to servers that ask users to sign in with OAuth.

Skipped401 challenge names the scopes to requestauth-scopeRule: claude.com · pkce and requested scopes

Not applicable: no sign-in is required.

What this means: Nothing to fix. These checks apply only to servers that ask users to sign in with OAuth.

SkippedProtected resource metadata is reachableprm-documentRule: modelcontextprotocol.io · protected resource metadata discovery requirements

Not applicable: no sign-in is required.

What this means: Nothing to fix. These checks apply only to servers that ask users to sign in with OAuth.

Skipped`resource` equals the server URL exactlyprm-resourceRule: claude.com · serve discovery metadata

Not applicable: no sign-in is required.

What this means: Nothing to fix. These checks apply only to servers that ask users to sign in with OAuth.

SkippedPrimary issuer is listed firstprm-auth-serversRule: claude.com · serve discovery metadata

Not applicable: no sign-in is required.

What this means: Nothing to fix. These checks apply only to servers that ask users to sign in with OAuth.

SkippedAuthorization server metadata is discoverableas-metadataRule: modelcontextprotocol.io · authorization server metadata discovery

Not applicable: no sign-in is required.

What this means: Nothing to fix. These checks apply only to servers that ask users to sign in with OAuth.

SkippedMetadata `issuer` matches the issuer URLas-issuerRule: modelcontextprotocol.io · authorization server metadata discovery

Not applicable: no sign-in is required.

What this means: Nothing to fix. These checks apply only to servers that ask users to sign in with OAuth.

SkippedClaude can register itself (DCR or CIMD)client-registrationRule: claude.com · dcr and cimd details

Not applicable: no sign-in is required.

What this means: Nothing to fix. These checks apply only to servers that ask users to sign in with OAuth.

SkippedCIMD: token endpoint accepts public clientscimd-public-clientRule: claude.com · dcr and cimd details

Not applicable: no sign-in is required.

What this means: Nothing to fix. These checks apply only to servers that ask users to sign in with OAuth.

SkippedPKCE S256 is advertisedpkce-s256Rule: claude.com · pkce and requested scopes

Not applicable: no sign-in is required.

What this means: Nothing to fix. These checks apply only to servers that ask users to sign in with OAuth.

SkippedDiscovery endpoints answer within 10 sdiscovery-latencyRule: claude.com · endpoint latency

Not applicable: no sign-in is required.

What this means: Nothing to fix. These checks apply only to servers that ask users to sign in with OAuth.

SkippedCallback URLs for Claude and Claude Code (manual)callback-urlsRule: claude.com · callback urls

Only relevant for OAuth servers.

What this means: Manual OAuth check. Not needed for a server without sign-in.

SkippedToken endpoint behaviour (manual)token-endpointRule: claude.com · token refresh

Only relevant for OAuth servers.

What this means: Manual OAuth check. Not needed for a server without sign-in.

Tools
PassTool list receivedtools-listRule: claude.com · pre submission checklist for connectors

3 tools listed without sign-in.

What this means: The tool list is readable without signing in, so the tool checks below ran on the live definitions.

PassEvery tool has a titletool-titlesRule: claude.com · provide tool annotations

All 3 tools have a title.

What this means: Anthropic's review criteria ask for a human-readable title on every tool. All three have one.

PassEvery tool has readOnlyHint or destructiveHinttool-hintsRule: claude.com · provide tool annotations

All 3 tools declare readOnlyHint: true or a destructiveHint.

What this means: Each tool says whether it only reads data or can change it, which the review criteria require.

PassTool names are 64 characters or fewertool-name-lengthRule: claude.com · keep tool names short

All names are 64 characters or fewer (longest: 28).

What this means: Well inside the 64-character limit in the review criteria.

PassEvery tool has a descriptiontool-descriptionsRule: claude.com · write narrow accurate descriptions

All 3 tools have a description. Reviewers also check that each one matches what the tool does.

What this means: Every tool is described. Whether each description is accurate and narrow is for Anthropic's reviewers to judge, not this check.

PassNo catch-all tool with an HTTP method parametertool-no-catchallRule: claude.com · separate read and write tools

No tool takes an HTTP method parameter.

What this means: No tool mixes read and write HTTP methods in one call, a pattern reviewers reject.

PassCustom query tools name their APItool-custom-query-docsRule: claude.com · reference api docs in custom query tools

No parameters that look like free-form endpoint paths, query strings or raw request bodies.

What this means: There are no free-form query tools, so the rule about naming the target API does not apply.

PassNo prompt-injection patterns in tool texttool-injection-patternsRule: claude.com · avoid prompt injection patterns

No known injection phrases, hidden characters or encoded strings found. This is an automated scan; reviewers read the descriptions themselves.

What this means: The automated scan found none of the listed patterns. Reviewers still read every description themselves.

Apps & listing
PassUI metadata is MCP Apps, not ChatGPT-onlytool-chatgpt-uiRule: claude.com · migrate from the openai apps sdk

No ChatGPT-only UI metadata found.

What this means: No ChatGPT-only widget metadata that would need moving to MCP Apps.

SkippedMCP App listing screenshotsmcp-app-screenshotsRule: claude.com · carousel screenshots for mcp apps

No MCP Apps UI declared, so carousel screenshots are not required.

What this means: The server declares no MCP Apps interface, so a listing would not need carousel screenshots.

Requests made during the run

StepMethodURLStatusTime
server/discover (2026-07-28)POSThttps://learn.microsoft.com/api/mcp2003.4 s
initialize (2025-11-25)POSThttps://learn.microsoft.com/api/mcp2003.4 s
notifications/initializedPOSThttps://learn.microsoft.com/api/mcp2021.4 s
tools/listPOSThttps://learn.microsoft.com/api/mcp2001.9 s
protected resource metadata (lazy-auth probe)GEThttps://learn.microsoft.com/en-us/.well-known/oauth-protected-resource/api/mcp4044.8 s
protected resource metadata (lazy-auth probe)GEThttps://learn.microsoft.com/en-us/.well-known/oauth-protected-resource4043.1 s
end session (DELETE)DELETEhttps://learn.microsoft.com/api/mcp4051.9 s

The 2026-07-28 probe returned HTTP 200 with JSON-RPC error -32601, as recorded in the transport evidence above. The two metadata lookups were sent to /.well-known/… on learn.microsoft.com; the URLs shown are the ones the server redirected them to, and both returned 404, which is expected for a server without sign-in. The closing DELETE got 405; the MCP transport specification says a server may answer 405 when it does not let clients end sessions, and no check is graded on it.

Limits of this check