Skip to quick start
← Back to your scanning hub

AWS Marketplace · MCP Light

From setup to your first privacy report.

Connect once, then ask your assistant to scan public websites and explain the evidence. Return to your scanning hub whenever you need another prompt or a replacement key.

Free Marketplace access. A CertScore account and Marketplace API key are required. Shared usage limits apply; your assistant may have its own fees.

Before you begin

  • Use the AWS account that holds your subscription and a CertScore account you can sign in to.
  • Your MCP client must support remote Streamable HTTP and a custom Authorization header or bearer token. An OAuth-only connector cannot connect to this API-key endpoint directly.
  • Choose a public website. Reports are public; do not submit private links, access tokens or personal data.

Step 1

Subscribe, then return through AWS

  1. Open CertScore MCP Light in AWS Marketplace, review the free offer and complete your subscription.
  2. Choose Set up your account in AWS Marketplace. This securely brings your subscription to CertScore.
  3. Sign in or create your CertScore account. Continue in the same browser so the AWS setup handoff is available when you return.

Already subscribed? Start with Set up your account again. Opening the scanning hub alone does not import an AWS subscription. The CertScore handoff expires after 30 minutes; restarting it does not require another purchase.

Sign in and continue setup

Step 2

Confirm your account and save your key

  1. Check the AWS account number and signed-in CertScore email. Only confirm a subscription you are authorized to link.
  2. Choose Confirm and link subscription. If activation is pending, use Check activation status. A key becomes available after AWS confirms activation.
  3. Choose Create API key and save it securely. The full key cannot be shown again after you leave the page.

A created key is not yet a connected assistant. Add it to your client in the next step. You sign in here to manage access; MCP requests use your key without an interactive login for each scan.

Open your subscription and keys

Step 3

Connect and check the tools

In your assistant's MCP settings, add a remote server using Streamable HTTP. Your client must support a custom Authorization header or bearer-token authentication.

Server URL

https://mcp.certscore.ai/mcp/marketplace/light

If asked for a bearer token, enter your key. For a custom header, use Authorization with the value Bearer YOUR_API_KEY. Replace the placeholder with your key; keep it out of chat messages.

Check the connection before scanning

Start or restart the server in your client's MCP settings. Check its discovered tool list for certscore_scan_site, certscore_get_scan_status, certscore_get_scan_bundle and certscore_get_report_evidence_page, then enable them.

Tool discovery does not start a scan. An assistant's text saying it is connected is not enough to verify the connection. Once the tools appear, continue with a scan prompt.

certscore_scan_site
Start a public website scan or reuse a recent result.
certscore_get_scan_status
Check progress using the returned scan ID.
certscore_get_scan_bundle
Retrieve the completed findings and report link.
certscore_get_report_evidence_page
Read additional pages of supporting evidence.

Step 4

Ask your first question

Copy this prompt into your connected assistant. Replace example.com with your chosen public website and approve the tool calls your client requests. Copying the prompt does not start a scan.

Use CertScore to scan https://example.com/. Summarize the main privacy risk signals and the next checks a human should make. Start with certscore_scan_site. If a scan ID is returned and the scan is pending, check certscore_get_scan_status at the returned interval until terminal. If a retryable response has no scan ID, wait for its retry interval before retrying the scan. Retrieve certscore_get_scan_bundle and follow certscore_get_report_evidence_page pagination when needed. Include the report link, scan date, whether the result was reused, supporting evidence and coverage limitations. Do not present partial previews as final findings or automated observations as legal conclusions.

What a finished scan should give you

  • A completed result, its scan date and whether it was reused.
  • Findings with evidence, coverage limitations and a public report link.
  • Clear disclosure of any failed or incomplete capture. A partial preview is not the final report, and missing evidence is not proof of safety.

Save the report link to revisit it. For another website or a follow-up question, return to the scan prompt builder. Light may reuse recent results and does not include scheduled monitoring or private workspace history.

Get back on track

No subscription appears after sign-in

Use the same browser as your AWS handoff. In AWS Marketplace, open the subscribed product and choose Set up your account again. Check the CertScore email shown before linking. If the subscription was linked to a different CertScore account, sign in to that account or contact support.

Activation is still pending

Choose Check activation status in the scanning hub. If it remains pending, contact support with the time you subscribed and your AWS account number. Do not repeatedly subscribe or create more accounts.

Your key was lost, expired or replaced (401)

Create a replacement in My access, update every client using the old key, then restart the MCP connection. Keys expire after 90 days. Check that the subscription is active and the server URL ends in /mcp/marketplace/light. A bearer-token field takes the key alone; a custom Authorization header takes Bearer followed by the key.

The client opens an OAuth login or shows no tools

Check that the client supports bearer tokens or custom headers and uses the Marketplace endpoint. Restart the server connection and inspect its tool list. Check client or organization restrictions if tools are disabled. An assistant saying it is connected is not proof: confirm the four tools in the client's MCP settings.

Rate limit (429) or service unavailable (503)

Wait for the returned Retry-After interval when present. Light shares its public allowance; a subscription does not reserve a separate quota. Retry later for a temporary dependency failure. Avoid repeated scan requests while an existing scan is running.

The scan is incomplete or the answer has no evidence

Keep the returned scan ID and ask the assistant to retrieve status and the result bundle. Read the reported limitations. Stop polling when the scan is terminal, including a failed scan. Do not treat partial output as a complete review.

Email [email protected] with the step that failed, client name/version, error text, time and timezone, and scan ID if available. For subscription issues, include your AWS account number and the subscription details shown in My access. Never send API keys, passwords or AWS setup tokens. Remove them from screenshots too.

Your access and your data

Account identity. Your Marketplace subscription and key are linked to your signed-in CertScore account. The email comes from CertScore sign-in. A shared key identifies that access credential, not which person is using it.

Public scan results. Light scans public websites and returns public reports. Keep private URLs and sensitive data out of scan requests. Your assistant also handles the prompts and results under its own terms and privacy settings.

Stopping access. Replace or revoke a key in My access. Cancel the subscription in AWS Marketplace. Revoking a key does not cancel the subscription, and cancellation does not remove independently public reports.

Privacy questions. Read our privacy policy and security information. For retention, deletion or other personal-data requests, use the privacy request page or contact support.

CertScore provides automated observations of public websites, not legal advice, certification or a compliance determination. Review the evidence and coverage limitations before relying on a result.