Base URLs
Each URL is a complete registry implementing the official MCP Registry API v0.1. Point a client at the base URL; it appends /v0.1/servers itself.
| Base URL | Admits | Servers |
|---|---|---|
https://hvtracker.net/registry/grade-a | Grade A only | 78 |
https://hvtracker.net/registry/grade-b | Grade A or B | 305 |
https://hvtracker.net/registry/grade-c | Grade A to C | 702 |
https://hvtracker.net/registry/all | Every entry we score, any grade | 978 |
The graded lists admit an entry only when its publisher is tied to the repository we scored: an io.github.<owner> namespace that matches the repository owner (the registry verifies it by GitHub login), or a domain namespace (verified by DNS) that matches the repository's homepage or its owner's GitHub profile website, both of which only the owner can set. An entry anyone else publishes pointing at a well-scored repository doesn't inherit its grade. Provisional and review-flagged projects are left out too. all keeps every entry and says which check each one passed.
Use it with GitHub Copilot
Enterprise: Settings → AI controls → MCP → MCP Registry URL. Organization: Settings → Copilot → Policies → MCP Registry URL. Paste a base URL above with no /v0.1 suffix, then choose Registry only to admit just that list, or Allow all to show it as recommendations. Copilot matches servers by their registry name, so a developer's locally configured server must use the same name as its registry entry. See GitHub's guide.
curl -s "https://hvtracker.net/registry/grade-b/v0.1/servers?limit=3"
curl -s "https://hvtracker.net/registry/all/v0.1/servers/io.github.github%2Fgithub-mcp-server/versions/latest"
What each entry carries
The official registry entry unchanged, plus server._meta["net.hvtracker/trust"]: trust_score, grade, coverage_grade, rank, board, provisional, scored_repo, publisher_verified and publisher_check, known_advisory (worst unfixed severity), package_source (does the package link back to the repository), and links to the profile and the signed credential.
Limits: the score is the source repository's provenance (who ships it and whether that changed), not a scan of what the server does, so pair it with a content scanner. Servers that share one repository share its score. We mirror each server's latest version. Registry entries refresh daily (last pull: 2026-10-03T09:17:12Z); scores refresh every 4 hours. Copilot's own enforcement matches names only, which GitHub documents as bypassable by editing local configuration.