Skip to content

MCP servers › io.github.KeyID-AI › keyid

MCP server · registry snapshot 2026-10-04 · last tested 2026-10-08

io.github.KeyID-AI/keyid

Signup sessions, browser continuity, email, SMS, and OTP/TOTP infrastructure for AI agents. — the publisher's description

Topic: security · AI-classifiedversion 0.4.1MITstandard input/output, streamable HTTP64 tools

Summary

io.github.KeyID-AI/keyid is a remote and local MCP server listed in the official MCP registry at version 0.4.1. On 2026-10-08 ProtocolProbe started its published package in an isolated sandbox in read-only mode and read its inventory: 64 tools, 7 resources and 8 prompts. This test round was read-only, so its tools were not called. 4 of the 13 checks that apply to it were exercised. Results of the checks are published only after we have verified them and told the publisher.

Not probed (read-only run)

We started the package in an isolated sandbox and read what it declares, but this test round was read-only, so its tools were not called. No security score is given; a check we did not run is never counted as passed.

Key facts

Runs
remote and local package
Transport
standard input/output, streamable HTTP
Package
npm · listed version current
License
MIT
Dependencies
no known high or critical advisories
Repository
link does not open publicly
Topic
securityAI-classified
Last tested
2026-10-08
The 18 checks at a glanceour test · 2026-10-08
  1. Inventory: exercised
  2. Hidden instructions: exercised
  3. Real execution: not run · our policy
  4. Secret leak: not run · nothing to check it against
  5. Internal addresses: not run · our policy
  6. Unconfirmed changes: not run · our policy
  7. Bad input: not run · our policy
  8. Model requests: not run · nothing to check it against
  9. Sensitive questions: not run · nothing to check it against
  10. Folder boundary: not run · our policy
  11. Log leaks: not run · nothing to check it against
  12. Hidden content: exercised
  13. Fake assistant turns: exercised
  14. Token passthrough: not applicable
  15. Token audience: not applicable
  16. Sign-in redirect: not applicable
  17. Consent handling: not applicable
  18. Sign-in metadata: not applicable

4 exercised9 not run (reason given)5 not applicable

Worth knowing before you connect it

  • 22 tools have a name or declaration suggesting they change data (send_email, update_message, save_browser_state and 19 more). We did not call them.
  • The linked repository does not open publicly, so the code cannot be reviewed through it.

Each line comes from a section below, with its source and date.

How fresh this is

Live-tested
yes, a real session (not a text-only review)
Last tested
2026-10-08
Mode
read-only (no tool calls)
Registry data
snapshot 2026-10-04
Package and repository
checked 2026-10-06
Engine
mcp-runtime-engine@0.1.0 · sdk@1.32.0

Security testing

What did we test, and what did we leave out?

18 checks · features #1, #2

Each check ends in exactly one state: exercised, not run (with the reason), or not applicable (with the reason). 4 of the 13 checks that apply to it were exercised. Results of the checks are published only after we have verified them and told the publisher.

Exercised · 4
  • 1Inventory
    tool-list
    Reads the declared tools, resources and prompts.exercised
  • 2Hidden instructions
    description-poisoning
    Looks for hidden instructions in tool descriptions.exercised
  • 12Hidden content
    audience-hiding
    Checks resources that hide content from the user.exercised
  • 13Fake assistant turns
    fake-assistant-turn
    Checks prompts that pose as the assistant's own words.exercised
Not run, with the reason · 9
  • 3Real execution
    real-execution
    Calls a tool and checks what really happens.This check calls the package's tools. This test round was read-only, so no tool was called; tools can act on outside services with the publisher's or a user's account.not run · our policy
  • 4Secret leak
    canary-leak
    Plants a fake secret and checks whether it leaks.This check needs at least one successful tool call to have something to check, and no tool was called.not run · nothing to check it against
  • 5Internal addresses
    ssrf
    Checks whether a tool can be steered to internal addresses.This check calls the package's tools. This test round was read-only, so no tool was called; tools can act on outside services with the publisher's or a user's account.not run · our policy
  • 6Unconfirmed changes
    write-without-confirmation
    Checks whether tools that change data act without asking.This check calls the package's tools. This test round was read-only, so no tool was called; tools can act on outside services with the publisher's or a user's account.not run · our policy
  • 7Bad input
    error-handling
    Sends bad input and watches how the server answers.This check calls the package's tools. This test round was read-only, so no tool was called; tools can act on outside services with the publisher's or a user's account.not run · our policy
  • 8Model requests
    sampling
    Checks whether the server asks the client's model to act for it.This check needs at least one successful tool call to have something to check, and no tool was called.not run · nothing to check it against
  • 9Sensitive questions
    elicitation-sensitive-data
    Checks whether the server asks users for sensitive data.This check needs at least one successful tool call to have something to check, and no tool was called.not run · nothing to check it against
  • 10Folder boundary
    root-boundary
    Checks whether the server reaches outside the folders it was given.This check calls the package's tools. This test round was read-only, so no tool was called; tools can act on outside services with the publisher's or a user's account.not run · our policy
  • 11Log leaks
    logging-side-channel
    Checks whether log messages carry data they should not.This check needs at least one successful tool call to have something to check, and no tool was called.not run · nothing to check it against
Does not apply to this server · 5
  • 14Token passthrough
    token-passthrough
    Checks whether the server forwards a user's token to other services.The server runs locally over standard input/output, so there is no sign-in flow to check.not applicable
  • 15Token audience
    token-audience-validation
    Checks whether tokens meant for another service are accepted.The server runs locally over standard input/output, so there is no sign-in flow to check.not applicable
  • 16Sign-in redirect
    open-redirect
    Checks the sign-in redirect for abuse.The server runs locally over standard input/output, so there is no sign-in flow to check.not applicable
  • 17Consent handling
    confused-deputy
    Checks consent handling when one service acts for another.The server runs locally over standard input/output, so there is no sign-in flow to check.not applicable
  • 18Sign-in metadata
    oauth-url-scheme
    Checks the published sign-in metadata for unsafe URLs.The server runs locally over standard input/output, so there is no sign-in flow to check.not applicable

Source: our own test in an isolated sandbox, 2026-10-08, mcp-runtime-engine@0.1.0. Which checks count and why follows our published scoring model. This server also has a remote test (1 of 18 applicable checks exercised).

What happened during the test?

Feature #8

The steps in order, as the test record holds them.

  1. 0 msStarted the published package in an isolated sandbox (read-only mode)
  2. 7,682 msConnected after 0 redirects.
  3. Read the inventory: 64 tools, 7 resources, 8 prompts.
  4. 18,332 msFinished: 4 checks exercised.

What it is

What does this server offer?

Observed inventory
64tools
7resources
8prompts
  • provision_identity
  • get_identity
  • request_phone_number
  • list_messages
  • wait_for_message
  • get_message
  • send_email
  • reply_to_message
  • update_message
  • list_threads
  • get_thread
  • get_verification_codes
  • follow_verification_link
  • start_registration_session
  • list_registration_sessions
  • get_registration_session
  • wait_for_registration_artifact
  • get_registration_artifacts
  • save_browser_state
  • load_browser_state
  • complete_registration_session
  • block_registration_session
  • list_totp_entries
  • get_totp_code
  • get_persona
  • create_or_update_persona
  • save_registration
  • list_registrations
  • get_registration
  • list_secrets
  • get_secret
  • put_secret
  • delete_secret
  • web_search
  • list_files
  • store_file
  • get_file
  • delete_file
  • list_crons
  • create_cron
  • update_cron
  • delete_cron
  • list_pages
  • create_page
  • get_page
  • update_page
  • delete_page
  • upload_page_file
  • list_page_files
  • delete_page_file
  • get_auto_reply
  • set_auto_reply
  • get_forwarding
  • set_forwarding
  • get_signature
  • set_signature
  • list_contacts
  • upsert_contact
  • delete_contact
  • list_webhooks
  • create_webhook
  • get_webhook_deliveries
  • get_metrics
  • get_reputation

Tool names are chosen by the publisher. Highlighted names suggest a change to data, by their name or the server's own declaration; that is our reading, since we did not call them.

Does the registry listing match what we found?

Feature #6

The registry verifies a package once, when it is published, and does not re-check it. A difference below is about the listing, not a judgement of the publisher.

Registry saysWe foundResultSource · date
Remote endpoint keyid.ai/mcpEndpoint answered and asked for sign-inmatchesour test · 2026-10-08
No credential declared as requiredRequired sign-indiffersour test · 2026-10-08
Published package can be startedStarted and answeredmatchesour test · 2026-10-08
Version 0.4.1 on npmExists and can be installedmatchesnpm · 2026-10-06
Repository github.com/KeyID-AI/KeyIDDoes not open (not found or private)differsapi.github.com · 2026-10-06

Can it be installed, and is it up to date?

Version pin · advisories

Listed version

Registry lists
0.4.1
Latest stable
0.4.1
Status
current
Withdrawn
no

Source: registry.npmjs.org · 2026-10-06. About the version the registry lists; a manual install may resolve to a different one.

Dependency advisories

critical0high0moderate0low0

Counted in the full dependency tree as resolved on 2026-10-08 (npm audit). Bars share one scale. The package itself has no known vulnerability (OSV.dev).

Integrity, provenance, license

Integrity
sha512-FE5qw5bv2O/DQHU6P…
Signature
signed
License
MIT

Source: the package registry · 2026-10-06.

Usage

Downloads
299 in the last month

Source: api.npmjs.org · 2026-10-06.

Who made it?

Feature #7 · lineage

Facts about the publisher. We do not turn them into a trust score.

Namespace
io.github.KeyID-AI
Repository
github.com/KeyID-AI/KeyID — does not open publicly

Source: the registry entry and api.github.com · 2026-10-06.

Choosing

Common questions about io.github.KeyID-AI/keyid

Answered from the data above

Has io.github.KeyID-AI/keyid been security tested?

Partly. 4 of the 13 checks that apply to it were exercised. We started the package in an isolated sandbox and read what it declares, but this test round was read-only, so its tools were not called. No security verdict is published before verification.

Is the listed version current?

Yes. The registry lists 0.4.1, the latest stable release on npm.

Where is the source code of io.github.KeyID-AI/keyid?

The registry links to github.com/KeyID-AI/KeyID, but that link does not open publicly, so the code cannot be inspected through it.

Reference

How is it classified?

18 fields

One value per field, each with its source. Fields written by AI models are marked. A field with no value says why.

TopicAI-classified
security
AI-classified · 2026-10-08
Pricing modelAI-classified
no value
The pages we read do not state how the product is priced.
Programming language
does not apply
no existing GitHub repository
Hosting type
remote and local package
registry · 2026-10-04
MCP capability
logging, prompts, resources, tools
our test · 2026-10-08
Transport
standard input/output, streamable HTTP
registry · 2026-10-04
Required credentials
none declared
registry · no declaration is not a guarantee
Package registry
npm
registry · 2026-10-04
Freshness
31–90 days
registry updatedAt · 2026-10-04
Lifecycle status
active
registry · 2026-10-04
License class
permissive
package registry · 2026-10-06
Integrity hash
declared (sri)
package registry · 2026-10-06
Signature / provenance
signed
package registry · 2026-10-06
Dependency advisories
none known
npm audit · 2026-10-08
Popularity
299 downloads a month
package registry · 2026-10-06
Publisher signals
not stated
no readable GitHub owner to describe
Maintenance
not stated
repository link is dead (HTTP 404), so activity cannot be read
Environment
either (remote or your machine)
where it runs, from the hosting type

“Not stated” means the source did not state it; “does not apply” means it does not apply to this kind of server; “our limit” means our own lookup failed.

Cite or correct this page

Sources and corrections

Suggested citation

ProtocolProbe. “io.github.KeyID-AI/keyid: MCP server record.” Data checked 2026-10-08. https://protocolprobe.com/mcp/servers/io.github.KeyID-AI/keyid

Quoting is welcome with a link and the check date. Figures are valid for the date shown.

Something wrong, or is this yours?

If a fact here is wrong, tell us and we will re-check it. If you operate this server, you can authorize a full test.

Write to hello@protocolprobe.com · corrections log · methodology