# Sourcegraph MCP Server > Sourcegraph's official MCP server gives AI agents code search, file reading, code navigation and commit and diff search across the repositories indexed by a company's Sourcegraph instance. It is built into Enterprise instances at /.api/mcp. - Canonical: https://www.anchorterminal.com/tools/sourcegraph-mcp - Markdown: https://www.anchorterminal.com/tools/sourcegraph-mcp.md (~7,450 tokens) - Slim: https://www.anchorterminal.com/tools/sourcegraph-mcp.min.md (~1,830 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/sourcegraph-mcp.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade C · 57.5/100 · rank #473 of 722 · #6 in Code & developer platforms · not agent-ready · confidence medium** ## Assessment Sixteen read-only tools search and navigate code across every repository an instance indexes, with OAuth limited to an `mcp` scope and repository permissions enforced on each call. Access needs an Enterprise contract, priced from $16,000 a year, and no request rate limits were found in the reviewed documentation. ## Facts | Field | Value | | --- | --- | | Vendor | Sourcegraph, Inc. (https://sourcegraph.com) | | Kind | MCP server | | Category | Code & developer platforms (https://www.anchorterminal.com/categories/code) | | Transport | Streamable HTTP | | Auth | OAuth or key · An admin of a Sourcegraph Enterprise instance must exist first, and access starts with a sales contract or an approved trial. On the instance, MCP clients use OAuth 2.0 with PKCE and register themselves through dynamic client registration, which is on by default and limited to the `mcp` scope. A user approves the grant in a browser. Admins can disable registration and pre-register public clients. Clients without OAuth send a Sourcegraph access token as `Authorization: token `, and the token can carry the `mcp` scope. Users need the `MCP#ACCESS` permission, granted to the User role by default. | | Pricing | Paid (Paid) · Enterprise plans only. The pricing page lists one plan, starting at a $16K minimum annual contract that scales with team size, bought through sales. No per-user or per-call price is published. The plan includes credits for AI tools, and `code_finder` and Deep Search draw on that entitlement. A Sourcegraph Cloud trial is available on request and subject to eligibility, with no sandbox or free tier found (checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the MCP docs, the authentication docs or the pricing page (checked 2026-10-08). | | Licence | Proprietary. The server is part of the Sourcegraph Enterprise product under the Sourcegraph Terms of Service | | Tools exposed | 16 | | MCP registry name | `io.github.sourcegraph/mcp` | | Docs | https://sourcegraph.com/docs/api/mcp | | llms.txt | not found | | Last release | 2026-09-17 | | Endpoints | https:///.api/mcp (core), /.api/mcp/all (full suite), /.api/mcp/deepsearch (Deep Search only). Streamable HTTP. `mcp.enabled` defaults to true, and when false the paths return 404 | | Tools | read_file, list_files, list_repos, list_refs, keyword_search, nls_search, evaluator, go_to_definition, find_references, commit_search, diff_search, compare_revisions, get_contributor_repos, code_finder, deepsearch, deepsearch_read | | Credentials | OAuth 2.0 authorisation code with PKCE (S256), dynamic client registration (RFC 7591), device flow and a revocation endpoint. Access tokens last 3,600 seconds per the OAuth docs. Sourcegraph access tokens in `Authorization: token ...` can carry the `mcp` scope, with a default expiry of 90 days | | Access control | Repository permissions apply to every read. The `MCP#ACCESS` RBAC permission is granted to the built-in User role by default. `mcp.tools.disabled` removes named tools from all endpoints | | Result limits | list_files 1,000 entries. list_repos default 50, maximum 10,000. list_refs default 100, maximum 500. commit_search default 50, maximum 100. diff_search default 20, maximum 50. compare_revisions default 50 file diffs, maximum 100, with an `after` cursor. find_references default 10 | | Metered tools | `code_finder` is metered against the instance's entitlement and returns an error when the quota is exhausted. The pricing page says the plan includes credits for AI tools | | Plan | Enterprise only. Starting at a $16K minimum annual contract with single-tenant Cloud or self-hosted deployment, sold through sales (https://sourcegraph.com/pricing) | | SLA | 99.5 per cent monthly uptime commitment for Sourcegraph Cloud on Enterprise plans, measured per customer instance, with at most 10 hours of scheduled downtime a quarter (https://sourcegraph.com/docs/sla) | | Releases | Self-hosted 8.0.0 on 17 September 2026, 7.7.359 on 27 August, 7.7.0 on 26 August and 7.6.0 on 6 August, each with MCP entries. Weekly Cloud update notes, the latest dated 5 October 2026 | | Certifications | SOC 2 and ISO/IEC 27001:2022 listed on security.sourcegraph.com, with reports behind an access request. Annual third-party penetration tests per sourcegraph.com/security | | Sub-processors | List last modified 21 August 2026, all located in the USA. Hosting on Google Cloud. Anthropic, Fireworks AI, Google and OpenAI process queries and code snippets sent to the AI tools (https://sourcegraph.com/terms/subprocessors) | | Clients documented | Claude Code, Codex, Cursor, Copilot, OpenCode, Amp, Gemini Code Assist, VS Code, Antigravity and Windsurf (https://sourcegraph.com/docs/api/mcp/client-integrations) | | Capabilities | code.repo, code.git | | Tags | official, mcp, hosted, self-hosted, enterprise, oauth, read-only, code-search, sales-led, soc2 | | JSON | https://www.anchorterminal.com/api/v1/tools/sourcegraph-mcp.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 25 | 5.0 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 71 | 11.5 | | Agent ergonomics | 13% | 16.2 | 72 | 11.7 | | Security & auth | 14% | 17.5 | 76 | 13.3 | | Payments & pricing | 10% | 12.5 | 15 | 1.9 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 83 | 7.3 | | Transparency & trust (editorial 65, provenance 90) | 7% | 8.8 | 78 | 6.8 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **57.5 → C** | ### Why each score - Reliability 25: Scored with the hosted lines, because the server is an HTTP endpoint on a Sourcegraph Cloud or self-hosted instance. The site links a status page at sourcegraphstatus.com, but the host did not resolve from our network on 8 October 2026, so the page and its history are unread and scored as absent (0 + 0). This is our fetch failure, not an established gap. No request rate limits for the MCP endpoints were found in the reviewed documentation, only result limits per tool (0). No 429 or backoff guidance was found. Release 8.0.0 says search tools now separate incomplete searches from empty results and recommend a retry, and every tool reads, so retries are safe (5). The SLA page commits to 99.5 per cent monthly uptime for Sourcegraph Cloud on Enterprise plans (10). The server carries no beta label, and Code Finder became generally available on 20 August 2026 (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 71: The docs list each tool's parameters with required and optional marks, defaults and maximums. We could not read the tool definitions themselves, because every endpoint needs an Enterprise instance and sourcegraph.com answered 401, so the machine-readable contract earns partial credit (15). /llms.txt and /docs/llms.txt return 404, but every docs page is served as Markdown at its URL plus .md (10). Tool entries state use cases, `code_finder` has best practices and a contrast with `deepsearch`, and a matrix shows which endpoint carries which tool (14). Required fields, defaults and bounds are documented, while search filters travel inside one query string and `evaluator` takes a free Lua script (9). `list_refs` has JSON examples and the authentication page has a troubleshooting table for `invalid_scope`, 401, 403 and 404, with no catalogue of tool errors (8). Versioned releases with dated MCP entries in the changelog (15). - Agent ergonomics 72: Sixteen documented tools on /.api/mcp/all, nine on the default endpoint and two on /.api/mcp/deepsearch, and admins can remove tools with `mcp.tools.disabled`. Definition sizes are unread (23). Result limits on every list and search tool, an `after` cursor on `compare_revisions`, `count` on searches and line ranges on `read_file` (17). Search tools report incomplete results with retry advice per the 8.0.0 notes, and HTTP 401, 403 and 404 causes are documented, but no tool error list was found (10). No tool writes to a repository, so repeating a call is safe. `deepsearch` creates a conversation each time, and we could not read the readOnlyHint or destructiveHint annotations (10). Most tools need one to three parameters with stated defaults. There is no SDK to count, as the surface is MCP only (12). - Security & auth 76: OAuth 2.0 with PKCE, dynamic client registration held to the `mcp` scope, one-hour access tokens, a revocation endpoint and bearer tokens in the header only. Access tokens can also carry the `mcp` scope and default to a 90-day expiry (30). Every documented tool reads, repository permissions apply to each call, and admins can gate MCP by RBAC role or disable single tools. There is no per-repository grant narrower than the user's own access (18). The tools return repository content, which is untrusted input. The consent screen warns that the `mcp` scope grants read access to private code, and no prompt-injection guidance was found (4). The audit log records access token use, repository access and API requests as structured logs for a SIEM. No MCP-specific call log is documented (9). SOC 2 and ISO/IEC 27001:2022 on the security portal, annual third-party penetration tests, CVE fixes named in release notes and an invite-only HackerOne programme reached through security@sourcegraph.com. security.txt returns 404 (15). - Payments & pricing 15: No x402, MPP or L402 (0). The pricing page publishes a starting figure, a $16K minimum annual contract, with no per-user or per-call price and a contact-sales button, so half of the plan-pricing credit (5). A free Sourcegraph Cloud trial exists by request, with eligibility reviewed and a wait of up to an hour in business hours. No card is mentioned, so half credit (10). An agent cannot gain access alone. A company needs a contract or an approved trial, and a user approves OAuth in a browser (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 83: The latest Cloud update notes are dated 5 October 2026, and self-hosted 8.0.0 shipped on 17 September 2026 with a new `list_refs` tool (30). Four self-hosted releases since 10 July 2026 (7.6.0, 7.7.0, 7.7.359, 8.0.0) plus weekly update notes (20). A closed service with a public changelog, support at support@sourcegraph.com and published response times from two business hours for Enterprise. No public issue tracker for the server was found (12). Listed in the official MCP registry as io.github.sourcegraph/mcp (15). Release 7.6.0 moved to the MCP Go SDK v1.7.0 and protocol version 2026-07-28, and releases name the CVEs they fix. No public CI to read (6). - Transparency & trust 78: Closed source under the Sourcegraph Terms of Service, last modified 22 July 2026, with supplemental terms listed in one index (15). The terms, the DPA, the security page and the privacy policy describe data handling. Cloud logs are kept up to 365 days, partner LLMs keep inputs only for abuse detection, and the privacy policy excludes customer code, which falls under the customer agreement. No retention period for code or search queries on Cloud was found (22). The current and previous major versions are supported, and release notes date removals such as the end of GitHub Enterprise Server 3.3 support, but no deprecation policy with a notice period for MCP tools was found (10). Sub-processors are listed with locations and purposes, last modified 21 August 2026, with email notice of changes, and instance telemetry is documented (18). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (15 items): https://www.anchorterminal.com/fixes/sourcegraph-mcp.md (JSON https://www.anchorterminal.com/fixes/sourcegraph-mcp.json) ### What we couldn't check - unchecked: sourcegraphstatus.com did not resolve from our network (WebFetch and curl both failed), so the status page and its incident history are unread and scored as absent. - unchecked: the MCP tool definitions (JSON Schema inputs, description text, readOnlyHint and destructiveHint annotations, total size). Every endpoint needs an Enterprise instance, and sourcegraph.com/.api/mcp answered 401. - unchecked: the answers in the pricing page FAQ, among them the one on a free trial, are loaded on click and were not in the page we read. The trial facts come from the Cloud docs. - unchecked: the credit rate card for `code_finder` and Deep Search, which the changelog places in the Enterprise Portal. - The registry entry io.github.sourcegraph/mcp points at a repository under github.com/sourcegraph-community, which we did not open. - No request rate limit for the MCP endpoints was found. The security page says Cloudflare rate limiting protects Cloud domains, without numbers. - The lead was right on the endpoint, the authentication methods and the Enterprise-only restriction. ### Sources - MCP server docs, tools and endpoint matrix: (seen 2026-10-08) - MCP authentication: (seen 2026-10-08) - client setup: (seen 2026-10-08) - OAuth apps, scopes and token lifetimes: (seen 2026-10-08) - OAuth protected-resource metadata, and the 401 from the endpoint: (seen 2026-10-08) - pricing: (seen 2026-10-08) - Cloud trial and regions: (seen 2026-10-08) - SLA and support response times: (seen 2026-10-08) - release notes: (seen 2026-10-08) - changelog: (seen 2026-10-08) - site configuration defaults (mcp.enabled, access token expiry): (seen 2026-10-08) - audit log: (seen 2026-10-08) - telemetry and pings: (seen 2026-10-08) - security page: (seen 2026-10-08) - security portal: (seen 2026-10-08) - Terms of Service: (seen 2026-10-08) - Privacy Policy: (seen 2026-10-08) - sub-processors: (seen 2026-10-08) - DPA: (seen 2026-10-08) - official MCP registry entry: (seen 2026-10-08) - RDAP record: (seen 2026-10-08) ## Who's behind it (provenance 90/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Sourcegraph, Inc. | 20/20 | | Domain age | sourcegraph.com, registered 2012-11-25 (13 years) | 15/15 | | Endpoint on the vendor's domain | sourcegraph.com | 15/15 | | Terms of service | read, states 7 of the 7 things a reader expects | 10/10 | | Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 | | Status page | sourcegraphstatus.com | 10/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | The Terms of Service (last modified 22 July 2026) name Sourcegraph, Inc., 548 Market St PMB 20739, San Francisco, CA 94104-5401, and govern all Sourcegraph products. Enterprise licences are bought with an order form under these terms. The Privacy Policy (last modified 12 June 2026) says it does not cover user content such as customer code, which Sourcegraph processes as a data processor under the customer agreement and the DPA at sourcegraph.com/terms/dpa. The endpoint is on the customer's own instance. Sourcegraph Cloud instances are single-tenant, and the terms describe trial instances at .sourcegraph.com. A self-hosted instance answers on the customer's domain. sourcegraph.com/.well-known/security.txt and /security.txt both returned 404 on 2026-10-08. The security portal sends reports to security@sourcegraph.com. The site footer links System status to https://sourcegraphstatus.com. The host did not resolve from our network on 2026-10-08, so the page is unread. RDAP for sourcegraph.com gives a registration date of 2012-11-25. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://sourcegraph.com/terms/tos), read 2026-10-08, dated 2026-07-22, states 7 of the 7 things a reader expects. - To know. Says it may use customer content to train or improve models, and gives an opt-out. "You further agree that, unless you opt out, AI User Content may be used to improve and support" - To know. Says access can be ended without notice or for any reason. "If we discover that an Account is being used by a user under thirteen (13) years old, we will terminate that Account immediately without notice to you." - To know. Requires arbitration or waives class actions. "THE AGREEMENT CONTAINS A MANDATORY INDIVIDUAL ARBITRATION AND CLASS ACTION/JURY TRIAL WAIVER PROVISION THAT REQUIRES THE USE OF ARBITRATION ON AN INDIVIDUAL BASIS TO RESOLVE DISPUTES, RATHER THAN JURY TRIALS OR CLASS ACTIONS." - Gives the date it was last updated. Last updated 2026-07-22. - Names the governing law or courts. Disputes go to the courts of San Francisco, California. - Says how changes to the terms are announced. Says it gives notice of a change. - Also in the text (2026-10-08). Subscriptions signed on an Order Form renew for one year terms at the then-current fees unless 45 days' written notice of non-renewal is given. "shall renew for one (1) year terms at the then-current fees and your payment method will be charged" - Also in the text (2026-10-08). Sourcegraph may use an organisation's name and logo to identify it as a customer unless an Order Form says otherwise. "Organization, we may use your name and logo to identify you as a customer and use product testimonials" - Also in the text (2026-10-08). Customers agree not to store sensitive data in the services, a category the terms define to include passwords, private encryption keys and other credentials. "designed to store Sensitive Data (as defined below), and (ii) you will not use the Services to store" **Privacy policy** (https://sourcegraph.com/terms/privacy), read 2026-10-08, dated 2026-06-12, states 8 of the 8 things a reader expects. - Gives the date it was last updated. Last updated 2026-06-12. - Says how long data is kept. For as long as needed, with no period named. - Says whether personal data is sold or shared for advertising. Says it does not sell personal data. - Gives a privacy contact. privacy@sourcegraph.com. - Says where data is transferred or stored. Relies on standard contractual clauses. - Also in the text (2026-10-08). When an integration is enabled, including an AI coding agent connected through Sourcegraph's MCP, personal data may be shared with that third party under its own privacy practices. "organization enable an integration, personal data may be shared with that third party under their" - Also in the text (2026-10-08). Usage data that has been aggregated or de-identified may be used or disclosed by Sourcegraph for any purpose. "longer personal data under applicable privacy laws, and we may use or disclose it for any purpose," ## Live (updated 2026-10-08 19:51 UTC) - Vendor status page: none, All Systems Operational - Watching changelog - Watching privacy - Watching terms - Always current: https://www.anchorterminal.com/api/v1/live/sourcegraph-mcp.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Strengths - All 16 documented tools read and none writes to a repository, with three endpoints so a client can load 9, 16 or 2 tools - OAuth 2.0 with PKCE and dynamic client registration, registered clients held to the `mcp` scope, and access tokens that can carry the same scope - Repository permissions apply to every call, and admins can gate MCP by role (`MCP#ACCESS`) or switch off single tools with `mcp.tools.disabled` - Result limits and defaults are documented per tool, such as 1,000 directory entries, 100 commits and 200 lines for files over 128KB - Listed in the official MCP registry as io.github.sourcegraph/mcp, with MCP changes in dated release notes through 2026 ## Weaknesses - Enterprise plans only, from a $16,000 minimum annual contract through sales. A Cloud trial is by request and subject to eligibility - No request rate limits, 429 behaviour or tool error catalogue found in the reviewed documentation - `code_finder` and Deep Search draw on the instance's credit entitlement and return an error once the quota is used up - No guidance on prompt injection from repository content was found, although every search and file tool returns such content - sourcegraph.com/.well-known/security.txt returns 404, and the bug bounty on HackerOne is invite-only ## Before you call it (notes for agents) 1. Connect to https:///.api/mcp for the nine core tools. Use /.api/mcp/all for `go_to_definition`, `find_references`, `nls_search` and `compare_revisions` 2. Request only the `mcp` scope in OAuth. Any other scope on the MCP resource fails with `invalid_scope` 3. Without OAuth, send `Authorization: token ` and create the token with the `mcp` scope and an expiry 4. Call `list_repos` first and name the repository in every `code_finder` task. It declines broad searches across repositories 5. Read large files with `startLine` and `endLine`. Files over 128KB return only the first 200 lines ## Connect Claude Code: ```bash claude mcp add --transport http sourcegraph https://sourcegraph.example.com/.api/mcp ``` MCP client configuration: ```json { "mcpServers": { "sourcegraph": { "type": "http", "url": "https://sourcegraph.example.com/.api/mcp" } } } ``` Headless / CI: ```json { "mcpServers": { "sourcegraph": { "headers": { "Authorization": "token ${SOURCEGRAPH_ACCESS_TOKEN}" }, "type": "http", "url": "https://sourcegraph.example.com/.api/mcp" } } } ``` Through letme (picks today, calling later): https://letme.dev/sourcegraph-mcp (letme picks it for code.git, the top-graded tool for the job). letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | GitHub MCP Server | BB | 70.3 | 138 | code.repo | no | https://www.anchorterminal.com/tools/github-mcp-server.md | | Azure DevOps MCP Server | B | 66.3 | 238 | code.repo | no | https://www.anchorterminal.com/tools/azure-devops-mcp.md | | Atlassian Rovo MCP Server | C | 57.9 | 461 | code.repo | no | https://www.anchorterminal.com/tools/atlassian-rovo-mcp.md | | Git (MCP reference server) | D | 51.9 | 570 | code.git | no | https://www.anchorterminal.com/tools/git-reference-server.md | | Context7 | BB | 73 | 81 | same category (Code & developer platforms) | no | https://www.anchorterminal.com/tools/context7.md | | Salesforce DX MCP Server | C | 59.5 | 426 | same category (Code & developer platforms) | no | https://www.anchorterminal.com/tools/salesforce-dx-mcp.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - Three endpoints on each instance. /.api/mcp carries nine core tools, /.api/mcp/all carries all 16 and /.api/mcp/deepsearch carries the two Deep Search tools (source: ) - The docs mark the MCP server as supported on Enterprise plans, and the pricing page lists the Enterprise plan as starting at a $16K minimum annual contract (source: ) - Clients registered through dynamic client registration are restricted to the `mcp` scope, and admins can turn registration off and pre-register clients (source: ) - An unauthenticated request to https://sourcegraph.com/.api/mcp answered 401 with a `WWW-Authenticate` header naming the protected-resource metadata and `scope="mcp"` (checked 2026-10-08) - Code Finder, an agentic search tool exposed as `code_finder`, went to beta on 20 July 2026 and general availability on 20 August 2026, and is metered against the instance's entitlement (source: ) - The 7.6.0 release of 6 August 2026 moved the server to MCP protocol version 2026-07-28 and added the `mcp.tools.disabled` setting (source: ) - Listed in the official MCP registry as io.github.sourcegraph/mcp, version 0.1.0, published 26 March 2026 (source: ) ## Compare - [Azure DevOps MCP Server vs Sourcegraph MCP Server](https://www.anchorterminal.com/compare/azure-devops-mcp-vs-sourcegraph-mcp.md): B 66.3 vs C 57.5 - [GitHub MCP Server vs Sourcegraph MCP Server](https://www.anchorterminal.com/compare/github-mcp-server-vs-sourcegraph-mcp.md): BB 70.3 vs C 57.5 - [Git (MCP reference server) vs Sourcegraph MCP Server](https://www.anchorterminal.com/compare/git-reference-server-vs-sourcegraph-mcp.md): D 51.9 vs C 57.5 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on sourcegraph.com or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "sourcegraph-mcp", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Sourcegraph MCP Server on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Sourcegraph MCP Server on Anchor Terminal](https://www.anchorterminal.com/badges/sourcegraph-mcp.svg)](https://www.anchorterminal.com/tools/sourcegraph-mcp) ``` Plain link: ```html Sourcegraph MCP Server on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Sourcegraph MCP Server is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/sourcegraph-mcp-dark.png - Light: https://www.anchorterminal.com/assets/share/sourcegraph-mcp-light.png