> ## Documentation Index
> Fetch the complete documentation index at: https://docs.validate.al/llms.txt
> Use this file to discover all available pages before exploring further.

# MCP Server

> Use validate.al email validation and security scanning as tools in AI agents.

validate.al runs a hosted MCP (Model Context Protocol) server at `https://mcp.validate.al/mcp` that gives AI agents such as Claude Code or OpenCode the validate.al API as tools. There is nothing to install: your agent connects over Streamable HTTP and sends your API key on every request.

## Tools

| Tool | Description |
| - | - |
| `validate_email` | Check whether an email address can receive mail. |
| `request_scan` | Request a security scan (`webapp`, `dns-auth` or `ip`). |
| `list_scans` | List your scans and their status. |
| `get_scan_report` | Get the full JSON report for a scan. |
| `scan_types` | List the scan types and what each one checks. |

## Connect your agent

Send your API key in the `X-API-Key` header (or `Authorization: Bearer <key>`). Your key is in the [portal](https://portal.validate.al) under **Settings → API Key**.

<CodeGroup>
  ```bash Claude Code theme={null}
  claude mcp add --transport http validate-al https://mcp.validate.al/mcp \
    --header "X-API-Key: your-api-key"
  ```

  ```json MCP client config theme={null}
  {
    "mcpServers": {
      "validate-al": {
        "type": "http",
        "url": "https://mcp.validate.al/mcp",
        "headers": { "X-API-Key": "your-api-key" }
      }
    }
  }
  ```
</CodeGroup>

Requests without a key get `401`; an invalid or revoked key gets `403`.

## What the server can do

The MCP server acts with your key only, so it sees and does exactly what that key can through the [API](/api-reference/introduction): your own scans and reports, and checks counted against your plan. It keeps no keys or results of its own.

## Example prompts

Once connected, ask your agent in plain language:

* "Check whether [jane@acme.com](mailto:jane@acme.com) can receive mail."
* "Run a dns-auth scan on acme.com and tell me when it's done."
* "List my scans and summarise the high-severity findings from the latest webapp report."
* "Which scan type should I use for 203.0.113.10?"


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.