Skip to main content

Model Context Protocol

An MCP server for uptime monitoring in Claude Code, Cursor and VS Code

HostTracker's MCP server for uptime monitoring puts 65 tools in front of your AI assistant - run a synchronous check from 300+ locations, list what is down, pause a monitor or open a status-page incident, all from a chat with Claude Code, Claude Desktop, Cursor, VS Code or Windsurf.

Sign in with OAuth from Claude, or use the same API token as the REST API, SDKs, ht-cli and Terraform · 30-day trial · no credit card

Reference:connect your account(sign in required - there is no public MCP setup page) ·Terraform providerfor infrastructure as code
  • Trusted since 2004
  • 500,000+ websites monitored
  • 300+ checkpoints worldwide

How a prompt becomes a tool call, from the assistant to the checkpoints and back

Ask, do not clickDescribe what you want in Claude Code, Claude Desktop, Cursor, VS Code or Windsurf; the assistant picks the tool.
A live check from inside the chatrun_instant_check dispatches to 300+ checkpoints when the assistant calls it and returns the per-location result in the same turn.
OAuth or one tokenSign in from Claude, or paste the same API token the REST API, SDKs and ht-cli use. Account writes are refused by design.
Getting started

Add the MCP server to Claude Code or Cursor: two routes in, three steps

OAuth from Claude, or a token for everything else.

Sign in with OAuth (Claude Code, Claude Desktop, claude.ai)

No token to mint. In Claude Code run claude mcp add --transport http hosttracker https://mcp.host-tracker.com/mcp, open /mcp and complete the browser sign-in; in Claude Desktop or claude.ai open Settings, Connectors, Add custom connector and paste the same URL. You approve the scopes on the consent page, and the connector can be revoked later from the Connected apps card on Integrations - API. Skip to step 3.

Or mint a token and paste the config (Cursor, VS Code, Windsurf, mcp-remote)

On Integrations - API, create a token and tick the scopes the assistant should use - check for instant checks, monitor:read/monitor:write to see or change monitors, and so on. There is no reason to grant account:write: the server refuses every account write regardless. Then add an http-transport MCP server entry pointing at https://mcp.host-tracker.com/mcp with an Authorization: Bearer header carrying the token:

{
  "mcpServers": {
    "hosttracker": {
      "type": "http",
      "url": "https://mcp.host-tracker.com/mcp",
      "headers": { "Authorization": "Bearer YOUR_TOKEN" }
    }
  }
}

For a client that can only launch a local command, use the mcp-remote shim instead:

npx mcp-remote https://mcp.host-tracker.com/mcp --header "Authorization: Bearer YOUR_TOKEN"
Ask

Restart the client so it discovers the tools, then just describe what you want: "which of my monitors are down", "run an http check on example.com from Europe and Asia", "pause staging for an hour". The assistant picks the tool.

65 tools, 9 groups

MCP server vs API: everything the REST API v2 can do, in chat

Every tool call is one v2 operation, scoped by the token's own permissions. Full detail: the API reference.

The difference

The part nobody else markets: a synchronous check, from inside the chat

Most monitoring vendors that ship an MCP server hand the assistant a way to read what a background job already recorded - yesterday's uptime, the last scheduled result. HostTracker's run_instant_check tool actually dispatches a live check to 300+ checkpoints when the assistant calls it, waits for the replies, and returns the per-location result in the same turn: no monitor to create first, no polling loop, no dashboard tab to switch to. Ask "is example.com up from Europe and Asia right now" and the answer comes back with real, fresh numbers - not a cached figure from the last scheduled run.

Checks

Run a check right now

run_instant_check, get_check_result, list_check_types - a synchronous check from 300+ locations, no monitor required.

Monitors

Create and manage monitors

12 tools: list, get, create, update, delete, pause/resume, copy, three bulk operations and list_monitor_types.

Results & incidents

Uptime, results and incidents

5 tools: get_uptime_summary, list_monitor_results, list_incidents, get_incident, comment_incident.

Maintenance

Schedule maintenance windows

4 tools to list, create, update and delete maintenance windows, so a planned change does not page anyone.

Contacts

Contacts and groups

12 tools: create, edit, delete and test contacts and contact groups; send and confirm confirmation codes.

Subscriptions

Who gets alerted

list_subscriptions, subscribe_contact, unsubscribe_contact - the alert and report legs.

Webhooks

Wire your own systems

7 tools: create, edit, delete and test webhooks; list deliveries and redeliver a failed one.

Status pages

Publish incidents

7 tools: manage status pages and open or update an incident on one, straight from a chat.

Reports

Generate a report

generate_report (returns a job) and list_report_types.

Account, jobs, locations

Diagnose and pin locations

Read-only get_account/get_account_quota/get_account_usage; 4 job tools to poll async work; list_locations for pools and agents.

Generic door

Everything else in the API

describe_api explains a v2 operation and api_request calls it - validated against the live operation list, with the same safety rules as every named tool.

What people actually ask

Plain-language prompts, real tool calls

You do not need to know the tool names - describe what you want and the assistant picks the right one (or chains a few). The mapping below is what actually runs behind eight questions people ask most.

The assistant runs

run_instant_check(url, type: "http", pools: [...])
get_check_result(dbId, id)   // if the first call comes back partial
list_monitors(state: "down")
pause_monitor(id)
// or, for a scheduled window instead of an immediate pause:
create_maintenance(monitorIds: [...], start, end)
create_status_page_incident(statusPageId, title, status)
list_subscriptions(monitorId)
create_contact(type: "telegram", address)
subscribe_contact(contactId, monitorIds: [...])
get_uptime_summary(monitorId, from, to)
list_webhook_deliveries(webhookId, status: "failed")
redeliver_webhook(webhookId, deliveryId)
You ask

"Run a check on example.com from Europe and Asia."

You ask

"Which of my monitors are down?"

You ask

"Pause staging for an hour."

You ask

"Open a status-page incident for the outage."

You ask

"Who gets alerted if this monitor goes down?"

You ask

"Add a Telegram contact and subscribe it to my monitors."

You ask

"What was my uptime last week?"

You ask

"Redeliver the webhook that failed."

Clients

Pick your client

The server speaks one protocol, streamable HTTP, and accepts either an OAuth sign-in or a bearer token, so every supported client uses the same endpoint with a different config shape.

Client
Config shape
Notes
Claude Code
claude mcp add --transport http hosttracker https://mcp.host-tracker.com/mcp, or .mcp.json / ~/.claude.json
OAuth: sign in from /mcp. Or type: "http", url, headers.Authorization with a token. Tools appear as hosttracker_*.
Claude Desktop / claude.ai
Settings → Connectors → Add custom connector
Paste https://mcp.host-tracker.com/mcp and sign in when prompted (OAuth 2.1, no token). Available on every Claude plan; a Free account is limited to one custom connector.
Cursor
~/.cursor/mcp.json or .cursor/mcp.json
Same mcpServers shape as Claude Code.
VS Code
.vscode/mcp.json
Same http-transport shape with a header for the bearer token.
Windsurf
mcp_config.json
Same mcpServers shape.
mcp-remote (any stdio client)
CLI command
npx mcp-remote https://mcp.host-tracker.com/mcp --header "Authorization: Bearer YOUR_TOKEN" - for a client that can only launch a local process.

If your assistant is not in the list, it likely still works: any MCP client that supports the http transport with an OAuth flow or custom headers can point at https://mcp.host-tracker.com/mcp directly, and mcp-remote bridges anything that only launches a local stdio process. The server itself does not care which client is asking - it is the client's config format that differs, not the protocol.

Where it is listed. The server is published in the official MCP Registry as io.github.HostTracker/hosttracker, on Smithery (whose gateway lets you paste the token once instead of editing config files) and on Glama; the connection metadata, per-client guide and security policy live in the public HostTracker/mcp repository.

By the numbers

Tools65Across 9 groups, plus the generic api_request door.
Instant-check types10Http, Ping, Port, Trace, Dns, DNSBL, Whois, WebRisk, Crawl, Waterfall.
Checkpoints300+Across 158 cities worldwide.
TransportStreamable HTTPOne endpoint, no local server to run.
AuthOAuth or tokenSign in from Claude, or reuse the REST API token elsewhere.
Since2004HostTracker's monitoring network, now reachable from your assistant.
Access, limits and safety

One token. Stated limits. Nothing hidden behind "generous".

The same personal API token authenticates the REST API v2, every official SDK, the ht-cli command line client and the MCP server. Mint it once on your HostTracker profile, pick the scopes it may use, and point any of the four at it.

Plan
API access
Reads
Writes
Free, Personal, Webmaster
Not included
-
-
30-day trial
Included
10 per minute, 10,000 per month
5 per minute, 500 per month
Business
Included
60 per minute, 100,000 per month
30 per minute, 20,000 per month
Enterprise
Included
120 per minute, 1,000,000 per month
60 per minute, 100,000 per month

Scoped tokens

A token carries only the scopes you tick - monitor, contact, webhook, check, status page, report, incident, maintenance, job, account - each as read or write. Grant what the integration needs and nothing else.

Long-lived, not revocable

Tokens are JWTs with a lifetime you choose (10 years by default) and cannot be revoked before they expire; an account-wide API switch disables every token at once. Treat a token like a password: keep it out of source control, and add an IP allow-list and a per-token request cap when you mint it.

Limits you can read

Every response carries RateLimit-Limit, RateLimit-Remaining, RateLimit-Reset and RateLimit-Policy; a 429 carries Retry-After. Current usage is on the Integrations - API page and at GET /account/quota.

Safe retries

Writes accept an Idempotency-Key, so a retried request is never a duplicate; long operations return a job you can poll or have delivered to a webhook.

Guard rails

The server refuses account-profile writes (POST/PUT/PATCH/DELETE on /account) - reading the account, its quota and usage is allowed; every other tool does exactly what the token's scopes allow, so a read-only token gives a read-only assistant.

Full details: authentication and limits in the docs. Plans and prices: pricing.

Read on

The MCP server, explained

Every chapter opens in place, so the page stays short.

Key takeaways

Key takeaways

  • The HostTracker MCP server exposes a monitoring account to AI assistants over MCP (Model Context Protocol), so an assistant can create monitors, read results and run instant checks inside a conversation.
  • It publishes 65 tools over the REST API's 182 operations and is reached at mcp.host-tracker.com over streamable HTTP.
  • Authorization is OAuth 2.1 with dynamic client registration, so a client connects without a pre-shared key and holds only the scopes you approve.
  • Instant checks run from more than 300 monitoring locations and can be run against any URL without creating a monitor first.
  • API access, and with it the MCP server, is included in the 30-day trial (100 monitors, no credit card) and on the Business plan and above; paid plans start at $14 per month.

Every layer of your stack, monitored

Websites, servers, APIs, certificates. One check type per page, the same locations, alerts and reports behind all of them.

Trusted by teams at

Microsoft Panasonic OTP Bank OneProvider Worldmate

Frequently Asked Questions

The Model Context Protocol (MCP) is an open standard that lets AI assistants call external tools in a uniform way, instead of every vendor inventing its own plugin format. HostTracker's MCP server exposes the same REST API v2 that powers the dashboard, the SDKs and ht-cli as 65 MCP tools, authenticated with your own HostTracker API token. Point a supported client at it and the assistant can run a live check, list what is down, pause a monitor or open a status-page incident - inside the conversation, without you opening a browser.

Two routes. Clients with an OAuth flow connect with just the URL and a browser sign-in: Claude Code (claude mcp add --transport http, then sign in from /mcp) and the Claude.ai / Claude Desktop custom connector. Clients that send a static Authorization header - Cursor, VS Code, Windsurf, and the mcp-remote shim for anything that can only launch a local process - use a HostTracker API token instead. The endpoint speaks streamable HTTP at a single URL, so the configuration is a few lines in each client - see the client table below.

Within the scopes your token carries, the assistant can do almost everything the REST API v2 can: run instant checks from 300+ locations, create and manage monitors, subscribe and test contacts, wire webhooks, publish status-page incidents, schedule maintenance and pull reports - 9 tool groups plus a generic api_request door for anything not covered by a named tool. It cannot touch your account profile, email, password, package or payments: those are not on the API v2 surface at all, and the server additionally refuses every write under /account regardless of what the token allows.

Give it a token scoped to only what the assistant needs - the same scope families as the REST API v2 (monitor, contact, webhook, check, status page, report, incident, maintenance, job, account), each as read or write. There is no reason to grant account:write: the MCP server refuses every account write on its own, so that scope buys nothing. Remember tokens are long-lived and not revocable before they expire - add an IP allow-list and a short expiration when you mint one for an assistant, and disable API access account-wide if you ever need to cut it off immediately.

No separate charge - it rides the same API access and quota as the REST API v2, SDKs and ht-cli. That means it is included in the 30-day trial and in the Business and Enterprise plans; Free, Personal and Webmaster plans do not include API access, so the MCP server has nothing to authenticate against on those plans. Every tool call counts against your account's normal request quota, visible with get_account_quota or on the Integrations - API page.

Yes. The server implements OAuth 2.1 with dynamic client registration, so in Claude Desktop or claude.ai open Settings, Connectors, Add custom connector, paste https://mcp.host-tracker.com/mcp and sign in to your HostTracker account when prompted; the connector holds only the scopes you approve, and you can revoke it from the Connected apps card on Integrations - API at any time. No token is pasted anywhere. The same sign-in works in Claude Code from the /mcp command. The bearer-token config remains the route for clients without an OAuth flow, such as Cursor, VS Code, Windsurf and mcp-remote.

Yes - that is the lead capability. run_instant_check runs a synchronous, ad-hoc check from 300+ checkpoints against any URL you give it, with no monitor, no dashboard visit and no setup: ask for an HTTP check from a couple of regions and the tool waits for the result and hands it back in the same turn. Saved monitors are a separate, persistent thing the assistant can also create and manage (create_monitor, list_monitors and friends) once you want the check to keep running on a schedule.

In Claude Code, run claude mcp add --transport http hosttracker https://mcp.host-tracker.com/mcp, then open /mcp and complete the browser sign-in; no token is needed. In Cursor, VS Code or Windsurf, mint a token on Integrations - API and add an http-transport server entry for https://mcp.host-tracker.com/mcp with an Authorization: Bearer header carrying it. Restart the client so it discovers the 65 tools.

The same 10 types the rest of HostTracker supports: Http, Ping, Port, Trace, Dns, DNSBL, Whois, WebRisk, Crawl and Waterfall (a full-page load timing check - pageSpeed is accepted as an alias for it). list_check_types reads the live catalogue, so the assistant always sees exactly what the API currently accepts rather than a list that can go stale.

30-day free trial - API access included

Ask your assistant, not your dashboard

Add one URL, sign in, and HostTracker's 300+ checkpoints answer inside Claude Code, Claude Desktop, Cursor, VS Code or Windsurf.

30-day free trial - 100 monitors - no credit card
  • Trusted since 2004
  • 500,000+ websites monitored
  • 300+ checkpoints worldwide

Part of HostTracker's website monitoring software.