squirrelscan.com
squirrelscan is a website auditing service focused on SEO, performance, security, and AI-agent readiness checks. It can run audits locally via CLI and adds cloud features such as hosted crawling, reports, credits, and MCP access.
squirrelscan exposes three developer integration surfaces on its own domain: a REST API at `https://api.squirrelscan.com` with OpenAPI, a hosted streamable-HTTP MCP server at `https://mcp.squirrelscan.com/mcp`, and the `squirrel` CLI; authentication uses org API keys, CLI login tokens, and MCP OAuth sign-in depending on surface.
- squirrelscan MCPdetected
- squirrelscan APIdetected
- squirrel CLIdeclared
Create a key in Settings → API Keys, or run `squirrel auth login` and then `squirrel keys create`. Pick scopes and expiry, copy the key when shown (it is shown once), then supply it as Authorization: Bearer sq_... or set SQUIRRELSCAN_API_KEY for CLI/headless use. The legacy env alias SQUIRREL_API_TOKEN is also accepted by the CLI.
$ squirrel auth loginAcquired by the CLI — running squirrel auth login opens the auth flow and stores the credential.
For the hosted MCP server, add https://mcp.squirrelscan.com/mcp to your MCP client with no auth header and let the client handle OAuth discovery from the authorization-server metadata. No pre-registration is needed: the client registers itself dynamically, runs authorization code + PKCE (S256), and you just sign in in the browser, choose an organization, and approve access.
Create a key at https://app.squirrelscan.com/settings/api-keys (or run squirrel keys create after squirrel auth login). Set it as SQUIRRELSCAN_API_KEY, or send it as Authorization: Bearer sq_... on any request. Local, unauthenticated audits are always free; a key is only needed for cloud features such as hosted crawling, publishing, and credits.
MCP clients discover OAuth automatically via https://mcp.squirrelscan.com/.well-known/oauth-authorization-server. No pre-registration needed: dynamic client registration and client id metadata documents (client.dev) are both supported. Authorization code + PKCE (S256).
conventions · 6/8 published
- integrations.json✓https://squirrelscan.com/.well-known/integrations.json
- llms.txt✓https://squirrelscan.com/llms.txt
- API catalog✓https://squirrelscan.com/.well-known/api-catalog
- OpenAPI document✓https://squirrelscan.com/openapi.json
- MCP server card✓https://mcp.squirrelscan.com/mcp
- OAuth protected resource✗
/.well-known/oauth-protected-resource - Agent card✗
/.well-known/agent-card.json - Agent skills✓https://squirrelscan.com/.well-known/agent-skills/index.json
Publish these signals → /publishing