Connect your agent to your CertScore.ai workspace with Hosted MCP OAuth
Connect an MCP-capable agent to your CertScore.ai workspace to scan public websites, retrieve reports, and access previous scans.
MCP Light gave agents account-free access to CertScore.ai public-website scanning. Accept and Reject Path testing expanded the evidence CertScore.ai can collect around visitor consent choices. Hosted MCP now connects an agent securely to your CertScore.ai workspace for an authenticated, continuing workflow.
You can ask an agent to scan a public website, retrieve the resulting report, and return to previous scans through your workspace connection. OAuth enables that access without manually copying an API key into the agent’s configuration.
What is new
Hosted MCP brings your CertScore.ai workspace into your agent workflow. Connect from an OAuth-capable MCP client, sign in to CertScore.ai when prompted, and use your authorized workspace access for public website reviews.
The connection gives the agent a way to work with your reports across review sessions. You can return to a prior result, inspect its findings and evidence references, or request another scan when you need fresh observations.
Why workspace access matters
A website review rarely ends with one answer. A developer may need to revisit evidence before a release. A privacy reviewer may want to inspect the basis for a finding. An agency may need to return to a report while discussing next steps with a client.
Hosted MCP keeps those requests connected to your authorized workspace. Ask the agent to access previous scans instead of treating every question as a reason to start new work. The agent should identify when it is using an existing result and keep its timestamp and coverage limitations visible.
What an agent can do through Hosted MCP
For example: “Use CertScore.ai to review this public website. Reuse a suitable previous scan if available, then summarize the findings, evidence, limitations and report link.”
The connection carries existing CertScore.ai results into your workflow. It does not change the scanner’s methodology, finding policy or scoring. Ask the agent to preserve the distinction between observed evidence and anything that remains unknown.
- Start a scan of an eligible public website or reuse a suitable completed result.
- Check progress while a scan is active, then retrieve its completed findings bundle.
- Access previous scans available to your workspace.
- Review findings alongside supporting evidence references, coverage limitations and the full report link.
Hosted OAuth versus MCP Light
MCP Light remains the anonymous, account-free entry point for low-volume public website scanning. It is useful when you want to try the workflow without connecting a workspace.
Choose Hosted OAuth when you want an authenticated connection to your CertScore.ai workspace and access to previous scans available there. Both routes scan eligible public websites; signing in to CertScore.ai does not allow the scanner to sign in to login-protected target websites.
How to connect
Use your existing connector when returning to the workflow. The setup guide explains access requirements, reconnecting and what to do when permissions or usage limits prevent a request.
- 1Open the Hosted OAuth setup guide and add the hosted endpoint to your MCP client.
- 2Start the client’s connection flow and sign in to your CertScore.ai account if prompted. Follow any connection or tool-approval prompts shown by your client.
- 3Ask the agent to review a public URL, follow an active scan to completion, and retrieve the findings with their report link.
Availability and limitations
Hosted OAuth requires a CertScore.ai account. Members of active workspaces can receive scan creation access through registered OAuth clients across workspace plans, without a manual CertScore access grant. Existing usage limits, authorized workspace boundaries and public-target restrictions continue to apply. Consult the current setup guide for verified client availability.
Reports describe automated public-web observations for human and agentic review. Findings and evidence depend on the captured result, and incomplete or unavailable observations remain limited coverage. They are not legal advice, certification or a compliance determination.
Try it
Connect your workspace
Follow the Hosted OAuth setup guide to connect your agent and start a website review.
