Skip to setup
AWS Marketplace · MCP LightFree access

A clearer view of
website privacy.

Give your AI assistant the tools to scan public websites, explain privacy signals and show the evidence behind each finding.

CertScore account + Marketplace API key. Shared usage limits apply.

From a question to evidence

“What should I know about this website's privacy?”

  • Cookies, trackers and third parties
  • Consent controls and privacy disclosures
  • Supporting evidence and coverage limitations
  • A public report you can revisit

Step 1 · Your access

One connection. More websites to explore.

Sign in here to manage your subscription and keys. Your assistant uses the API key for scan requests; you do not need to sign in for each scan.

Already subscribed?

Sign in or create your CertScore account. Then confirm your AWS subscription and create your API key.

Sign in or create an account

New to Marketplace Light?

Subscribe to the free offering in AWS Marketplace, then choose Set up your account to return here.

Open AWS Marketplace ↗

Keys expire after 90 days. Replacing or revoking a key stops new requests using it. Manage subscription cancellation in AWS Marketplace; public reports remain public.

Step 2 · Connect once

Bring CertScore into your assistant

MCP connects your assistant to CertScore's scanning tools. Once connected, you can ask questions in plain language.

In your assistant's MCP settings, add a remote server using Streamable HTTP. Your client must support a custom Authorization header or bearer-token authentication.

Server URL

https://mcp.certscore.ai/mcp/marketplace/light

If asked for a bearer token, enter your key. For a custom header, use Authorization with the value Bearer YOUR_API_KEY. Replace the placeholder with your key; keep it out of chat messages.

Check the connection before scanning

Start or restart the server in your client's MCP settings. Check its discovered tool list for certscore_scan_site, certscore_get_scan_status, certscore_get_scan_bundle and certscore_get_report_evidence_page, then enable them.

Tool discovery does not start a scan. An assistant's text saying it is connected is not enough to verify the connection. Once the tools appear, continue with a scan prompt.

Step 3 · Scan & explore

Your next website starts here

Choose a website and a question. We'll prepare a prompt that asks your connected assistant for evidence, context and a report link.

Public pages only. Reports are public. Do not include private links, access tokens or personal data.

Choose a focus

This builds a prompt in your browser. A scan starts only when you send it to your connected assistant.

What happens next?

Your assistant starts or reuses a scan, checks progress and retrieves the results. Ask follow-up questions about the evidence. A partial preview is not the final report.

Keep the conversation going

One scan is a starting point.

Save your report link. Come back when you add a vendor, update your website or have another site to review. Bookmark this page for prompts and connection settings.

Understand a finding

Turn a summary into something you can review.

Read the prompt

Explain the most important finding from this CertScore report. Show the retained evidence, explain its limitations, and suggest what a human should verify next.

Review a site after a change

Updated your banner, tags or privacy policy? Check again.

Read the prompt

Use CertScore to scan this website again. Tell me the scan date and whether the result was reused. If I provide an earlier report, compare only supported observations with comparable coverage. Do not claim a change from reused or incomplete evidence.

Explore another website

Bring the same questions to your next public site.

Read the prompt

Help me review another public website with CertScore. Ask me for its URL, scan it, and summarize the privacy signals, supporting evidence, coverage limitations and report link.

Light may reuse a recent result and shares a public scan allowance. It does not include scheduled monitoring or private workspace history.

A little help, when you need it.

For setup or scanning questions, email [email protected]. Include the error, time and timezone, client name/version and scan ID if available. Never send your API key or AWS setup token.

My client says unauthorized (401).

Check that you used the Marketplace endpoint and supplied Authorization: Bearer followed by your API key. The key must be unexpired and not revoked, and its subscription must be active. After replacing a key, update your client and start a new MCP session.

I received a rate limit (429) or temporary error (503).

Honor the returned Retry-After interval. Marketplace Light shares the public Light allowance; subscribing does not add a dedicated allowance. If the service is temporarily unavailable, retry later. Avoid repeatedly starting the same scan.

Which assistants can connect?

Use a remote MCP client that supports Streamable HTTP and a custom Authorization header or bearer token. An OAuth-only connector cannot use this API-key endpoint directly. See the setup choices above and your client's documentation.

Are my scans private?

No. Light is for public websites and public reports. Do not submit private URLs or sensitive data. Your API key is private and belongs only in your client's authentication settings. Revoking access does not remove independently public reports.

Does a finding prove a compliance violation?

No. Results describe automated observations with evidence and coverage limitations. Missing evidence does not establish compliance or absence of risk. Use the findings to guide human review.