agentic safety · trust layer · 2,644 servers scored

The trust layerfor AI agents.

Security scoring, agent identity, payment verification, and data lineage tracking for the agentic economy. Know what your agents are connecting to, who they are, and where your data goes.

50 lifetime spots at $100 — 47 remaining

Know what’s connected.

Block what’s dangerous.

Prove what happened.

How it works

three steps · no configuration required

01

Connect

Add the MCP server to any client — point your client at https://usestrata.dev/mcp with an x-api-key header — or install the TypeScript SDK and call strata.verify() directly. REST API also available — no lock-in.

02

Score

Every MCP server gets two trust signals: security_score (repo health) and runtime_score (live endpoint probing + static analysis). Per-tool scoring exposes which specific tools are dangerous — not just the server.

03

Ship safely

Block dangerous servers before your agent connects. Define policies — "no shell_exec in production" — enforced at the Strata layer. Get real-time alerts when connected servers change risk profile.

see it in action

Six ways to use Strata.

Scan your agent config, verify servers and payments, issue agent identities, enforce policies, or query the directory from inside Claude Code or Cursor.

terminal — strata
$

Phases 3 & 4 — Now Live

Policy Engine

Define rules that govern what your agents are allowed to do. "No shell_exec in production." Enforced before any tool call executes.

open →

Compliance Reporting

One-click SOC 2 and ISO 27001 audit evidence packages. Tamper-evident ledger with HMAC verification. JSON and CSV export.

open →

Real-Time Threat Feed

Push alerts when connected servers change risk profile, gain dangerous capabilities, or get quarantined. Turn alerts into policies in one click.

open →

Circuit Breaker

Automatic disconnection when connected servers cross critical risk thresholds. Agents continue in degraded-safe mode. No human intervention required.

open →

Dependency Graph

Visual map of every MCP server your agents depend on. Risk scores, capability flags, circuit breaker status, and data flow relationships in one view.

open →

Behavioral Anomaly Detection

Baseline normal agent behavior. Alert when volume spikes, high-risk server usage surges, or net-egress floods deviate from the baseline. Hourly detection.

open →

Ecosystems we track

22 AI ecosystems · 2,644 MCP servers scored · continuously updated

Claude

live

ChatGPT

live

Gemini

live

LangChain

live

Ollama

live

Developer tools

sdk · github action · mcp server

TypeScript SDK

@strata-ai/sdk

Zero-dependency. Works in Node, browser, Bun, and Cloudflare Workers.

npm install @strata-ai/sdkSDK docs →

GitHub Action

Gate every PR

Scans MCP configs, posts a trust report comment, fails on critical risk.

uses: PThrower/strata-mcp-check@v1Marketplace →

Native MCP Server

Connect once

Add to Claude Desktop, Cursor, or any MCP client — all 10 tools available instantly. MCP server verification, agent identity, payment trust, data lineage, real-time threat alerts, and behavioral anomaly detection in one connection.

{ "url": "https://usestrata.dev/mcp", "headers": { "x-api-key": "sk_..." } }MCP docs →

One MCP server. Ten tools.

api/v1 · rest + mcp
get_best_practices()structured[]
Canonical patterns and anti-patterns per ecosystem, ranked by recency and adoption.
{ ecosystem, topic? }
REST + MCP
get_latest_news()news[]
Releases, deprecations, and changelog deltas — sourced and dated, never paraphrased.
{ since, limit? }
REST + MCP
get_top_integrations()ranked[]
Tools, SDKs, and providers ordered by signal — usage, mentions, sustained activity.
{ ecosystem, surface? }
REST + MCP
search_ecosystem()results[]
Free-form semantic search across the indexed corpus, scoped to one ecosystem or all 22.
{ q, scope?, k? }
REST + MCP
list_ecosystems()ecosystems[]
List all AI ecosystems available on your tier. Call first to discover valid slugs.
{}
REST + MCP
find_mcp_servers()server[]
Search 2,179+ scored MCP servers by capability, risk level, or use case.
{ query, filters? }
REST + MCP
verify_payment_endpoint()trust
Trust scores for x402 payment endpoints before your agent pays anything.
{ url }
REST + MCP
verify_agent_credential()claims
Verify Ed25519-signed agent JWTs. Live revocation check against the Strata identity registry.
{ credential }
MCP
track_data_flow()flow
Record data flows between MCP servers. See which net_egress endpoints touched your data.
{ source, dest }
REST + MCP
get_threat_feed()events[]
Poll the real-time threat feed. Get alerts when MCP servers change risk profile, gain dangerous capabilities, or are quarantined.
{ since?, severity?, affected_only? }
REST + MCP
MCP READYAlso available as a native MCP server — connect once, access all tools automatically.view docs →

community

Trust signals that get
sharper every day.

Every MCP server is continuously re-scored as repos evolve, runtime behavior changes, and new capability flags are detected. The directory never goes stale.

22

ecosystems tracked

2,644

mcp servers scored

Daily

index updates

submit a contribution

Know what’s connected.

Block what’s dangerous.

Prove what happened.

Pricing

no card · cancel anytime
Free
$0/ forever

Everything you need to wire up a prototype agent.

  • 100 calls / month
  • 5 core ecosystems
  • 24-hour news lag
  • Weekly index refresh
start free
Pro
$29/ month

Production-grade access for teams shipping real agents.

  • 10,000 calls / month
  • All ecosystems
  • News updated every 12 hours
  • Daily index refresh
get pro access

Founder Offer

Limited · 47 spots left
$100one-time

Lifetime Pro Access

Lock in everything Strata becomes. Forever.

Claim Founder Access →

47 of 50 spots remaining

  • Everything in Pro, forever
  • All future features included
  • Founding member badge
  • Direct access to the builder

Now live — Policy Engine · Compliance Reporting · Threat Feed · Circuit Breaker · Dependency Graph · Behavioral Anomaly Detection  ·  Coming in Phase 5 — Multi-Agent Trust