Back to Browse

Viewport Witness MCP Server

Developer ToolsLow Risk9.1MCP RegistryRemote
Free

Server data from the Official MCP Registry

Agent website testing: browser QA, visual regression, Markdown extraction, and security checks.

About

Agent website testing: browser QA, visual regression, Markdown extraction, and security checks.

Remote endpoints: streamable-http: https://qa.honeygate.app/mcp

Security Report

9.1
Low Risk9.1Low Risk

Valid MCP server (2 strong, 2 medium validity signals). 3 known CVEs in dependencies Imported from the Official MCP Registry.

6 tools verified · Open access · 3 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Found in Source Code

Found by scanning the linked source code. This listing connects to a hosted endpoint, so none of this runs on your machine: it describes what the server software does where it is hosted.

file_system

Applies to the server that hosts this plugin, not to your machine.

HTTP Network Access

Connects to external APIs or services over the internet.

How to Connect

Remote Plugin

No local installation needed. Your AI client connects to the remote endpoint directly.

Add this to your MCP configuration to connect:

{
  "mcpServers": {
    "io-github-baffles78-viewport-witness": {
      "url": "https://qa.honeygate.app/mcp"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

ViewportWitness by Apex Labs

Two low-resource paid agent tools complement browser QA: extract_page converts one public HTML page to deterministic Markdown for $0.005 USDC, and web_release_gate passively checks one public page's release security controls for $0.05 USDC. Both share the Base/Solana x402 rails, idempotency protection, single-worker queue, and seven-day report lifecycle. They do not accept caller-supplied HTML, credentials, cookies, custom headers, uploads, or private-network targets.

Remote MCP server and x402 API for AI-agent browser QA. Submit a public HTTPS URL and receive screenshots, accessibility findings, layout analysis, and structured JSON across phone and desktop viewports.

The live service is at https://qa.honeygate.app. A standard report costs $0.08 USDC, read-only assertions cost $0.10, and a baseline comparison costs $0.12. Local instances can run in test mode without payment.


Live service

# Probe the live service (returns 402 with payment requirements)
curl -s -X POST https://qa.honeygate.app/v1/checks \
  -H 'Content-Type: application/json' \
  -d '{"url": "https://example.com"}'

# Payment discovery
curl -s https://qa.honeygate.app/.well-known/x402 | jq .

# Agent skill manifest
curl -s https://qa.honeygate.app/skill.md

Use an x402-aware client (e.g. @x402/fetch with a funded wallet) for paid requests. See llms.txt for the full agent usage guide.


Paid product examples

An ordinary HTTP request to any paid endpoint returns HTTP 402 — an x402 challenge containing the network, asset, amount, and destination address. An x402-aware client (such as @x402/fetch with a funded wallet) pays the challenge and retries automatically; your code receives the successful JSON result. The examples below show the request shape only — do not call the live service or send payment during development; use PAYMENT_MODE=test locally (see Local development).

POST /v1/checks — 0.08 USDC

Submit a public HTTPS URL and receive screenshots, accessibility findings, layout analysis, and browser errors across phone and desktop viewports.

// x402-aware client pays the 402 challenge and retries automatically
const { id, pollUrl } = await fetch402('https://qa.honeygate.app/v1/checks', {
  method: 'POST',
  headers: { 'Content-Type': 'application/json' },
  body: JSON.stringify({ url: 'https://example.com' }),
}).then(r => r.json())
// Poll GET pollUrl until { status: 'complete' }

POST /v1/verify — 0.10 USDC

Run explicit read-only assertions against a live public HTTPS URL. The worker performs only non-mutating checks — no forms are submitted, no purchase or delete controls are clicked.

const { id, pollUrl } = await fetch402('https://qa.honeygate.app/v1/verify', {
  method: 'POST',
  headers: { 'Content-Type': 'application/json' },
  body: JSON.stringify({
    url: 'https://example.com',
    assertions: [
      { type: 'selectorVisible', selector: 'h1' },
      { type: 'titleIncludes', value: 'Example Domain' },
    ],
  }),
}).then(r => r.json())

POST /v1/compare — 0.12 USDC

Diff the current render against a baseline job. baselineJobId must identify a completed, unexpired ViewportWitness check that has screenshots for all three viewports (phonePortrait, phoneLandscape, desktop). Baselines expire after seven days. The request is rejected if the baseline job is pending, failed, or missing any viewport screenshot.

const { id, pollUrl } = await fetch402('https://qa.honeygate.app/v1/compare', {
  method: 'POST',
  headers: { 'Content-Type': 'application/json' },
  body: JSON.stringify({
    url: 'https://example.com',
    baselineJobId: 'JOB_ID_FROM_PREVIOUS_CHECKS',
  }),
}).then(r => r.json())

Safety: Only public HTTPS URLs are accepted. Loopback, private, link-local, and metadata addresses are blocked at every hop. The browser worker is non-mutating — no forms are submitted and no state-changing interactions are performed.


Local development

npm install
npx playwright install chromium
cp .env.example .env
npm run dev
# Create a check (test mode — no payment required)
curl -s -X POST http://localhost:3000/v1/checks \
  -H 'Content-Type: application/json' \
  -d '{"url": "https://example.com"}' | jq .

# Poll result
curl -s http://localhost:3000/v1/checks/JOB_ID | jq .status

# Get screenshot
curl -o desktop.png http://localhost:3000/v1/checks/JOB_ID/screenshots/desktop

Local defaults to PAYMENT_MODE=test. No CDP keys needed for test mode. Results are labeled paymentMode: "test" and do not represent real payment settlements.


API

MethodPathDescription
GET/Service info
GET/healthLiveness probe
GET/readyReadiness probe (DB + worker)
GET/openapi.jsonOpenAPI 3.1 spec
GET/llms.txtAgent usage guide
GET/skill.mdConcise agent skill manifest
GET/privacyPrivacy policy
GET/termsTerms of service
GET/logo.pngDirectory and integration logo
GET/.well-known/x402Payment discovery
POST/v1/checksCreate a QA check job
POST/v1/verifyCheck explicit read-only assertions
POST/v1/compareCompare against an unexpired baseline job
POST/mcpRemote MCP interface with x402-paid tools
GET/v1/checks/:idPoll job status / get report
GET/v1/checks/:id/screenshots/:viewportDownload screenshot PNG
GET/v1/checks/:id/diffs/:viewportDownload comparison diff PNG

Viewports: phonePortrait (375×812), phoneLandscape (812×375), desktop (1440×900)


Payment modes

ModePayment requiredNetwork
testNo— (local dev only)
testnetYes (x402)Base Sepolia; optional Solana Devnet
productionYes (x402, $0.08 USDC)Base mainnet; optional Solana mainnet

Production mode requires ENABLE_MAINNET_PAYMENTS=true and a reviewed release. Solana is separately off by default. Enabling it requires ENABLE_SOLANA_PAYMENTS=true, the public test and revenue destinations, facilitator capability confirmation, and its own settlement test. The application selects the correct destination from PAYMENT_MODE. Paid modes also require a private CUSTOMER_HASH_SECRET of at least 32 characters. It creates a stable, one-way customer label for repeat-use measurements; raw payer wallet addresses are not stored. Attribution is best-effort and never blocks delivery after a verified payment. Changing this secret starts a new measurement series and does not rewrite old jobs. See docs/RUNBOOK.md for activation steps.


Run tests

npm test              # unit tests (no browser required)
npm run test:e2e      # local e2e (requires Playwright Chromium)
npm run typecheck     # TypeScript strict check

Docker

docker compose build
docker compose up -d
curl http://localhost:3000/health

Further reading


MIT License

Reviews

No reviews yet

Be the first to review this server!