Sitelemetry

エージェントからの認可済みウェブサイト監査:セキュリティ体制、技術的SEO、AI可視性(GEO/AEO)、アナリティクス統合、WCAG 2.2アクセシビリティとパフォーマンスを評価し、証拠に基づく発見事項と修正策を9言語で返します。リモートのStreamable HTTP MCPサーバーで、ブラウザOAuth(PKCE+動的クライアント登録)に対応。貼り付けるAPIキーは不要です。所有しているサイト、またはテストの認可を受けたサイトのみを監査します。

ホスト型 MCP サーバー

npx add-mcp 'https://sitelemetry.com/mcp'

Claude Code、Codex、Cursor などにインストールできます

ドキュメント

7 audit tools

9 report languages

0 write or delete tools

6 client setup options

Setup

Connect in minutes.

Sitelemetry gives compatible AI clients seven focused web-audit tools. The client sends a tool name, an explicit target and supported audit settings; Sitelemetry returns the full available audit evidence, prioritized findings and remediation guidance. Audit calls record usage and audit data in Sitelemetry without changing the target website.

  1. 01 Choose your client Use the general endpoint for Codex, Claude Code, Cursor and other compatible MCP clients, or connect through the Sitelemetry listing in ChatGPT or Claude.ai.
  2. 02 Approve access Sign in to Sitelemetry and approve the audit scope in your browser.
  3. 03 Ask for evidence For Codex and Claude Code, public audits can use public targets; protected scans need workspace verification. Claude.ai requires current ownership proof for the exact HTTPS target, except for the seven public security checks included in Free.

Long hosted audits continue in the background. Your assistant automatically checks the same job until the full result is ready, without starting another scan. The timeout settings below are optional.

Choose the source-private plugin for Cloud plus Local Agent, or keep the remote-only OAuth setup below.

codex plugin marketplace add ozandikici/sitelemetry-plugins && codex plugin add sitelemetry@sitelemetry

Add the server, then start the browser authorization flow once.

codex mcp add sitelemetry --url https://sitelemetry.com/mcp
codex mcp login sitelemetry

Optional timeout for long audits

Optional: allow 900 seconds (15 minutes) per tool call. Merge this into the existing Sitelemetry section in ~/.codex/config.toml, then restart Codex.

[mcp_servers.sitelemetry]
url = "https://sitelemetry.com/mcp"
tool_timeout_sec = 900

Codex MCP documentation

Choose the source-private plugin for Cloud plus Local Agent, or keep the remote-only OAuth setup below.

claude plugin marketplace add ozandikici/sitelemetry-plugins && claude plugin install sitelemetry@sitelemetry

Add the HTTP server, open /mcp in Claude Code and choose Authenticate for Sitelemetry.

claude mcp add --transport http sitelemetry https://sitelemetry.com/mcp

Add this entry to.cursor/mcp.json in your project, or ~/.cursor/mcp.json for all projects. Merge it with any existing mcpServers entries.

{
  "mcpServers": {
    "sitelemetry": {
      "url": "https://sitelemetry.com/mcp"
    }
  }
}

In Cursor's MCP settings, connect Sitelemetry. Sign in or create your Sitelemetry account in the browser, then approve access. OAuth handles sign-in; no API key is needed.

Cursor setup documentation

Open the Sitelemetry listing in Claude.ai and connect your account. Complete Sitelemetry authorization in your browser.

Custom connector setup

If you need a custom connector, add the Claude endpoint below in Claude.ai's connector settings and complete authorization.

https://claude-mcp.sitelemetry.com/mcp

Open the Sitelemetry listing in ChatGPT, connect your account, and complete Sitelemetry authorization in your browser.

Connect in ChatGPT

Add a remote MCP server named Sitelemetry with the URL below. Select Streamable HTTP and OAuth if your client asks.

https://sitelemetry.com/mcp

Use a client that supports remote HTTP MCP and browser-based OAuth. Connect, sign in or create a Sitelemetry account, and approve access; the client then loads the available tools.

Good to know

OAuth clients receive a short-lived, audience-bound access token—not your Sitelemetry password, account API key or stored Google integration credentials.

API-key and CI use (for example the Sitelemetry GitHub Action) requires accepting the MCP authorization declaration once: open MCP in your Sitelemetry account, review the declaration next to the API key and accept it. OAuth connections record the same declaration when you approve access.

What it does

What the website audit MCP server does.

Sitelemetry is a website audit MCP server. Connect it once, then ask your AI assistant to audit a site in plain language. The assistant calls the matching tool for security, technical SEO, AI visibility, accessibility, performance or integrations, or audit_full to run all six in one call.

What is MCP? A plain-language guide

Findings with evidence and a fix

Each result lists findings with a severity, the evidence behind them, why they matter and a recommended fix, plus a score when the area could be measured.

OAuth sign-in, no API key

The clients in this guide connect with OAuth 2.1 and PKCE: you sign in to Sitelemetry in your browser and approve access. No API key goes into the client configuration.

Long audits stay one job

A long audit returns a job instead of a final result. The client checks that same job until the result is ready, without starting a second scan.

Reports in nine languages

Every tool takes a report language: English, Turkish, Spanish, German, French, Portuguese, Italian, Japanese or Chinese. Name the language in your prompt.

Limits

The Free plan covers security checks only. All six audit areas start at $49/month on the Starter plan.

Sitelemetry is not a penetration test. Hosted security audits run a fixed, non-intrusive baseline of public checks by default.

Protected security modules depend on your plan. These modules and a six-area audit_full need the site to be verified in your Sitelemetry workspace. Claude.ai needs ownership proof for the exact HTTPS target, except for the public security checks included in Free.

SEO, AI visibility, accessibility and integrations audits read static HTML. Pages are not rendered in a browser, so content or tags that only JavaScript adds are not checked.

AI visibility scores how ready the pages are for AI answer engines. It does not query AI assistants and does not track mentions or citations.

Performance data comes from Google PageSpeed Insights, which fetches the public URL itself.

Tools

Seven audit tools: one per area, plus a full audit.

Every tool requires a target. Optional inputs are deliberately narrow and results are returned as concise text plus structured audit data.

audit_security

Security audit

Checks DNS, email DNS, RDAP registration, TLS, HTTP security headers, HTTPS/MITM posture, technology fingerprinting and transport delivery by default. Target verification follows your client's rules; additional modules remain subject to your plan and hosted-scan policy.

audit_seo

Technical SEO

Crawls public pages for indexation, metadata, headings, canonicals, structured data, internal-link failures, redirects and AI-crawler policy.

audit_ai_visibility

AI visibility

Assesses entity clarity, answerability, source signals, prompt coverage, llms.txt and crawler policy for AI search and answer engines.

audit_integrations

Analytics and tracking

Detects analytics, tag managers, marketing pixels, site-verification signals, consent systems and potential PII exposure in public data-layer output.

audit_accessibility

Accessibility

Runs a static WCAG 2.2-oriented review of alternative text, labels, headings, landmarks, contrast signals, language declarations, duplicate IDs and iframe titles.

audit_performance

Performance

Uses Google PageSpeed Insights, which fetches the requested public URL independently. Sitelemetry preflights the current redirect chain and accepts Lighthouse/CrUX metrics only when PSI's reported inspected/final URL remains inside the same safe host and port boundary.

audit_full

Full audit

Runs all six pillars in parallel, returns one blended score and summarizes every pillar. Use individual tools afterward when you need the full finding list for one discipline.

Prompts

Ask for an outcome, not a tool name.

A compatible client can choose the right Sitelemetry tool from your request.

One short prompt per area, plus a full audit. Replace example.com with a site you own or are authorized to audit.

01

Run a Sitelemetry security audit of example.com and list the findings by severity, each with its fix.

Security audit guide

02

Audit the technical SEO of example.com and group the fixes into crawlability, metadata, structured data and internal links.

Technical SEO audit guide

03

Check how easily AI answer engines can understand and cite example.com, then turn the top five gaps into tasks.

AI visibility guide

04

Check the home page of example.com for accessibility issues and show the evidence for each one.

Accessibility check guide

05

Measure the Core Web Vitals of example.com and list the three improvements with the biggest impact.

Performance and Core Web Vitals guide

06

Review the analytics, tag and consent setup on example.com and flag gaps or personal data in the data layer.

Integrations audit guide

07

Run a full Sitelemetry audit of example.com, prioritize critical and high findings and give me a fix plan in English.

Website audit guide: all six areas

Safety

Target verification by client.

Sitelemetry is a defensive assurance service, not an open scanning proxy.

Connecting MCP does not give an agent access to your hosting account, CMS, source code or Google account. The hosted tools inspect publicly reachable web signals and do not change the target.

Workspace verification

Codex, Claude Code and ChatGPT protected scans need workspace ownership verification. Claude.ai requires current ownership proof for the exact HTTPS target, except for the seven public security checks included in Free. A new verified site gets a monitoring project if a slot is available; it can still be audited when slots are full, within your plan's allowance. Verify ownership through Sitelemetry DNS or HTTP, or Google Search Console with siteOwner permission.

Bounded and accounted operation

Every successful call records Sitelemetry usage and audit/security state and consumes the applicable plan quota. Subscription entitlements, rate limits, concurrency controls and timeouts apply to remote calls; Sitelemetry-originated web requests also use server-side SSRF and redirect controls. PageSpeed's independent fetch and returned-result boundary are disclosed above.

Public audits and protected scans

Codex and Claude Code support public targets for eight public security checks, SEO, AI Visibility, Integrations, Accessibility and Performance. Protected security modules and Full Audit need workspace verification. Claude.ai requires current ownership proof for the exact HTTPS target, except for the seven public security checks included in Free.

No target mutation

The seven tools make observation requests and return evidence. They do not sign in to, create, edit or delete content in the audited website or its connected accounts.

Data

Know what crosses the connection.

Sitelemetry receives MCP protocol traffic and the tool arguments your client sends: the requested tool, target, report language and any supported audit setting. It processes public technical responses and returns audit evidence to that client. It does not independently access the rest of your AI conversation.

Your chosen AI client provider receives the tool request and returned results as part of your conversation and handles them under its own terms and privacy policy. Sitelemetry may retain account, usage, security and audit records as described in the Privacy Policy; it does not sell personal information.

FAQ

Website audit MCP server: common questions.

Verified sites, monitoring and usage

Verified domains define which targets are authorized. Monitoring projects store sites for ongoing tracking; project capacity is separate from domain verification. A full project slot does not by itself prevent audits of other verified sites. Audit permissions and remaining usage allowances still apply.

Understanding Sitelemetry access