ai-discovery-and-registry · prepared

Official MCP Registry publication and discovery lifecycle

Official-source facts separating package publication, metadata validation, namespace authentication, registry listing, downstream aggregation, installation, security assessment, and actual MCP use.

version 1.0.0freshness currentobserved 2026-08-26T15:20:00Z

resource.discovery.mcp-registry-lifecycle
sha256:f45bb909ea7d8c9e777e458f4edaa04feb2abeb638dd6ae9a156deb3b1bc5cea

Open canonical machine JSON →

Evidence-backed facts

  1. The official MCP Registry hosts standardized server metadata and points to public packages or remote servers; it does not host the implementation artifacts themselves. informative
  2. Publishing uses a server.json record and the mcp-publisher workflow; package metadata is validated before publication, and a successful listing can be checked independently through the Registry API. informative
  3. Namespace authentication ties a server name to a GitHub identity or domain, while the official Registry relies on the wider ecosystem for security scanning of server code; namespace verification is not a security audit. informative
  4. The Registry is a primary metadata source for downstream aggregators, and host applications commonly consume downstream registries; publication or aggregation is not evidence of installation, successful initialization, tool calls, or repeat use. informative