Sample report · Claude Connectors Directory readiness
MCP server readiness report: Microsoft Learn MCP
Summary
Every automated check that applies to this server passed. The 14 skipped checks cover sign-in (the server needs none) and MCP Apps screenshots (the server declares no app interface). A clean result is not an approval: Anthropic's reviewers make that decision and also judge things no script can, such as whether each tool does what its description says.
Microsoft Learn MCP is a public server run by Microsoft. It was chosen for this sample because anyone can connect to it without an account. This report is not affiliated with or endorsed by Microsoft.
Findings
Each row shows the check, the published rule it comes from, the evidence recorded during the run (verbatim), and what it means in plain language.
| Transport | ||
|---|---|---|
| Pass | Server URL uses HTTPShttps-urlRule: claude.com · pre submission checklist for connectors | The URL uses https://. What this means: Anthropic's submission portal only accepts https:// addresses, and this one qualifies. |
| Pass | Answers MCP over Streamable HTTPmcp-endpointRule: modelcontextprotocol.io · sending messages | initialize answered in 3.4 s as text/event-stream; negotiated protocol 2025-06-18; session id issued. Server: Microsoft Learn MCP Server 1.0.0. (The 2026-07-28 probe got JSON-RPC error -32601, so the legacy handshake was used, as the spec describes.) What this means: An MCP client can open a session at this URL over Streamable HTTP. The server does not answer the 2026-07-28 discovery call, so the checker fell back to the older initialize handshake, which the specification allows. |
| Pass | Accepts notifications with 202notification-202Rule: modelcontextprotocol.io · sending messages to the server | 202 Accepted in 1.4 s. What this means: The server acknowledges client notifications the way the transport specification requires: 202 with an empty body. |
| Authentication | ||
| Pass | Authentication type Claude can useauth-modeRule: claude.com · supported authentication types | No authentication (type none, supported by default). If your tools act on a user’s account, Anthropic expects OAuth 2.0. What this means: No sign-in is needed. That is accepted for public data; Anthropic expects OAuth 2.0 when tools act on a user's account. |
| Skipped | 401 carries a resource_metadata pointerauth-challengeRule: claude.com · serve discovery metadata | Not applicable: no sign-in is required. What this means: Nothing to fix. These checks apply only to servers that ask users to sign in with OAuth. |
| Skipped | 401 challenge names the scopes to requestauth-scopeRule: claude.com · pkce and requested scopes | Not applicable: no sign-in is required. What this means: Nothing to fix. These checks apply only to servers that ask users to sign in with OAuth. |
| Skipped | Protected resource metadata is reachableprm-documentRule: modelcontextprotocol.io · protected resource metadata discovery requirements | Not applicable: no sign-in is required. What this means: Nothing to fix. These checks apply only to servers that ask users to sign in with OAuth. |
| Skipped | `resource` equals the server URL exactlyprm-resourceRule: claude.com · serve discovery metadata | Not applicable: no sign-in is required. What this means: Nothing to fix. These checks apply only to servers that ask users to sign in with OAuth. |
| Skipped | Primary issuer is listed firstprm-auth-serversRule: claude.com · serve discovery metadata | Not applicable: no sign-in is required. What this means: Nothing to fix. These checks apply only to servers that ask users to sign in with OAuth. |
| Skipped | Authorization server metadata is discoverableas-metadataRule: modelcontextprotocol.io · authorization server metadata discovery | Not applicable: no sign-in is required. What this means: Nothing to fix. These checks apply only to servers that ask users to sign in with OAuth. |
| Skipped | Metadata `issuer` matches the issuer URLas-issuerRule: modelcontextprotocol.io · authorization server metadata discovery | Not applicable: no sign-in is required. What this means: Nothing to fix. These checks apply only to servers that ask users to sign in with OAuth. |
| Skipped | Claude can register itself (DCR or CIMD)client-registrationRule: claude.com · dcr and cimd details | Not applicable: no sign-in is required. What this means: Nothing to fix. These checks apply only to servers that ask users to sign in with OAuth. |
| Skipped | CIMD: token endpoint accepts public clientscimd-public-clientRule: claude.com · dcr and cimd details | Not applicable: no sign-in is required. What this means: Nothing to fix. These checks apply only to servers that ask users to sign in with OAuth. |
| Skipped | PKCE S256 is advertisedpkce-s256Rule: claude.com · pkce and requested scopes | Not applicable: no sign-in is required. What this means: Nothing to fix. These checks apply only to servers that ask users to sign in with OAuth. |
| Skipped | Discovery endpoints answer within 10 sdiscovery-latencyRule: claude.com · endpoint latency | Not applicable: no sign-in is required. What this means: Nothing to fix. These checks apply only to servers that ask users to sign in with OAuth. |
| Skipped | Callback URLs for Claude and Claude Code (manual)callback-urlsRule: claude.com · callback urls | Only relevant for OAuth servers. What this means: Manual OAuth check. Not needed for a server without sign-in. |
| Skipped | Token endpoint behaviour (manual)token-endpointRule: claude.com · token refresh | Only relevant for OAuth servers. What this means: Manual OAuth check. Not needed for a server without sign-in. |
| Tools | ||
| Pass | Tool list receivedtools-listRule: claude.com · pre submission checklist for connectors | 3 tools listed without sign-in. What this means: The tool list is readable without signing in, so the tool checks below ran on the live definitions. |
| Pass | Every tool has a titletool-titlesRule: claude.com · provide tool annotations | All 3 tools have a title. What this means: Anthropic's review criteria ask for a human-readable title on every tool. All three have one. |
| Pass | Every tool has readOnlyHint or destructiveHinttool-hintsRule: claude.com · provide tool annotations | All 3 tools declare readOnlyHint: true or a destructiveHint. What this means: Each tool says whether it only reads data or can change it, which the review criteria require. |
| Pass | Tool names are 64 characters or fewertool-name-lengthRule: claude.com · keep tool names short | All names are 64 characters or fewer (longest: 28). What this means: Well inside the 64-character limit in the review criteria. |
| Pass | Every tool has a descriptiontool-descriptionsRule: claude.com · write narrow accurate descriptions | All 3 tools have a description. Reviewers also check that each one matches what the tool does. What this means: Every tool is described. Whether each description is accurate and narrow is for Anthropic's reviewers to judge, not this check. |
| Pass | No catch-all tool with an HTTP method parametertool-no-catchallRule: claude.com · separate read and write tools | No tool takes an HTTP method parameter. What this means: No tool mixes read and write HTTP methods in one call, a pattern reviewers reject. |
| Pass | Custom query tools name their APItool-custom-query-docsRule: claude.com · reference api docs in custom query tools | No parameters that look like free-form endpoint paths, query strings or raw request bodies. What this means: There are no free-form query tools, so the rule about naming the target API does not apply. |
| Pass | No prompt-injection patterns in tool texttool-injection-patternsRule: claude.com · avoid prompt injection patterns | No known injection phrases, hidden characters or encoded strings found. This is an automated scan; reviewers read the descriptions themselves. What this means: The automated scan found none of the listed patterns. Reviewers still read every description themselves. |
| Apps & listing | ||
| Pass | UI metadata is MCP Apps, not ChatGPT-onlytool-chatgpt-uiRule: claude.com · migrate from the openai apps sdk | No ChatGPT-only UI metadata found. What this means: No ChatGPT-only widget metadata that would need moving to MCP Apps. |
| Skipped | MCP App listing screenshotsmcp-app-screenshotsRule: claude.com · carousel screenshots for mcp apps | No MCP Apps UI declared, so carousel screenshots are not required. What this means: The server declares no MCP Apps interface, so a listing would not need carousel screenshots. |
Requests made during the run
| Step | Method | URL | Status | Time |
|---|---|---|---|---|
| server/discover (2026-07-28) | POST | https://learn.microsoft.com/api/mcp | 200 | 3.4 s |
| initialize (2025-11-25) | POST | https://learn.microsoft.com/api/mcp | 200 | 3.4 s |
| notifications/initialized | POST | https://learn.microsoft.com/api/mcp | 202 | 1.4 s |
| tools/list | POST | https://learn.microsoft.com/api/mcp | 200 | 1.9 s |
| protected resource metadata (lazy-auth probe) | GET | https://learn.microsoft.com/en-us/.well-known/oauth-protected-resource/api/mcp | 404 | 4.8 s |
| protected resource metadata (lazy-auth probe) | GET | https://learn.microsoft.com/en-us/.well-known/oauth-protected-resource | 404 | 3.1 s |
| end session (DELETE) | DELETE | https://learn.microsoft.com/api/mcp | 405 | 1.9 s |
The 2026-07-28 probe returned HTTP 200 with JSON-RPC error -32601, as recorded in the transport evidence above. The two metadata lookups were sent to /.well-known/… on learn.microsoft.com; the URLs shown are the ones the server redirected them to, and both returned 404, which is expected for a server without sign-in. The closing DELETE got 405; the MCP transport specification says a server may answer 405 when it does not let clients end sessions, and no check is graded on it.
Limits of this check
- It is an outside-in, automated check. It sends only what an MCP client sends before doing any work: the protocol probe, the handshake, tools/list and GET requests for OAuth discovery documents. No tool was called, no client was registered, no token was requested and no credentials were sent.
- The 27 checks come from Anthropic's connector documentation (authentication, review criteria, submission, MCP Apps) and the MCP specification, as read on 27 September 2026. Those documents can change after that date.
- Passing is not approval. Reviewers also judge the accuracy of tool descriptions, how tools behave, and everything entered in the submission portal. None of that is covered here.
- The prompt-injection check is a scan for known phrases, hidden characters and encoded strings. It is not a full security review.
- Timings come from a single run over one network path, not from Anthropic's own infrastructure. The checker allows 10 seconds per request and 25 seconds for the whole run.
- A server can change at any time. This report describes the server as it answered at the time shown above; run the check again before a submission.