New:Socket for Asana Is Now Available.Learn more
Get Started

@wcagc/mcp

Package Overview
Dependencies
Maintainers
1
Versions
17
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@wcagc/mcp

wcagc MCP server — a thin, stateless adapter that translates MCP tool calls into wcagc-api HTTP calls. No database, no secrets beyond WCAGC_API_BASE_URL (+ WCAGC_MCP_KEY for local stdio mode). Open-source: this package holds no business logic or credentia

Source
npmnpm
Version
0.2.7
Version published
Weekly downloads
147
-27.23%
Maintainers
1
Weekly downloads
 
Created
Source

wcagc-mcp

WCAG-Compliance/wcagc-mcp MCP server smithery badge

An MCP server that lets an AI assistant (Claude, ChatGPT, or any MCP-compatible client) run real, deterministic accessibility scans through wcagc — axe-core under the hood, not an LLM guess. Every scan result carries an explicit coverage disclaimer and never claims "compliant": automated testing finds only a portion of accessibility barriers, and this tool says so in every response.

This package is a thin, stateless adapter. It holds no database, no scan logic, and no secrets beyond the wcagc API base URL — it translates MCP tool calls into HTTP calls against the wcagc API and forwards the caller's own API key. All authentication, entitlements, quotas, and scan orchestration live in the API; this code is safe to read end to end.

Two ways to run it

Local (stdio) — for Claude Desktop, Cursor, or any MCP client that spawns a local process:

npx @wcagc/mcp

Configure your MCP client with:

{
  "mcpServers": {
    "wcagc": {
      "command": "npx",
      "args": ["-y", "@wcagc/mcp"],
      "env": {
        "WCAGC_MCP_KEY": "<your mcp:scan API key>"
      }
    }
  }
}

Mint an mcp:scan key from your wcagc account under Settings → API keys — available on every plan, with a daily quota on Free/Starter and unlimited on Pro/Agency.

Hosted (Streamable HTTP) — what Claude web/desktop/mobile connectors and ChatGPT use, since neither runs a local process for you. Add this as a remote MCP connector and paste the same API key as the bearer token:

https://mcp.wcagc.com/mcp

In ChatGPT, full tool access currently requires a Business, Enterprise, or Edu workspace; on Plus you can use the read-only Custom GPT Action instead. See wcagc.com/integrations/mcp.

Tools

ToolPlanWhat it does
scan_urlallScan any public URL, or a registered site for full tracking (Pro+).
check_pdfallRun a PDF/UA-1 structure check on a public PDF.
get_scan · get_findingsallRead a scan's status, severity counts, and findings.
list_sitesPro+List the account's registered sites.
scan_sitePro+Crawl and scan every reachable page of a registered site.
get_run · get_run_findingsPro+Read a full-site run.
run_journeyPro+Replay a saved multi-step journey and check each step.
get_trendsPro+Read a site's violation-count history over time.

Every scan-producing tool returns the coverage disclaimer in both the text content and the structured content. There is no score, grade, or conformance verdict — automated testing finds roughly 30–57% of accessibility issues, and the remainder needs manual review.

Configuration

Env varUsed byMeaning
WCAGC_API_BASE_URLbothThe wcagc API to call. Defaults to https://api.wcagc.com; set it only when self-hosting.
WCAGC_MCP_KEYstdioYour mcp:scan API key.
PORThostedPort to listen on (default 8080).
WCAGC_MCP_ALLOWED_HOSTShostedComma-separated Host-header allowlist (DNS-rebinding protection when bound to 0.0.0.0).
WCAGC_MCP_INTROSPECT_TTL_SECONDShostedHow long a verified bearer is cached before re-checking with the API (default 60).

Development

npm install
npm run dev        # hosted, watch mode
npm run start:stdio # stdio mode
npm run typecheck
npm run verify      # node:test against a local fixture API

License

MIT — see LICENSE.

Keywords

mcp

FAQs

Package last updated on 25 Jul 2026

Related posts