Docs · the prodready MCP server

One endpoint. Two products. Every tool.

The readiness scan is free. The SDLC is licensed. Both run through the same MCP server, in the coding agent you already use. You talk in plain language; your agent calls the tools. This page is the whole manual.

Endpointhttps://mcp.prodready.si/mcpstreamable HTTP · sign-in by email
Contents

01Install

One line per host. The endpoint speaks MCP over streamable HTTP and needs no key: the first call opens a sign-in page, you type your email and click the link we send. No password, no card.

Claude Codeterminal
claude mcp add --transport http prodready https://mcp.prodready.si/mcp --scope user

Drop --scope user to add it to the current project only. Check it with /mcp inside Claude Code.

OpenAI — Codex CLIterminal
codex mcp add prodready --url https://mcp.prodready.si/mcp

Or, in ~/.codex/config.toml: [mcp_servers.prodready] then url = "https://mcp.prodready.si/mcp"

Cursor~/.cursor/mcp.json
{"mcpServers":{"prodready":{"url":"https://mcp.prodready.si/mcp"}}}

Project-local instead: .cursor/mcp.json in the repository root, same shape.

Windsurfmcp_config.json
{"mcpServers":{"prodready":{"serverUrl":"https://mcp.prodready.si/mcp"}}}

Windsurf names the key serverUrl for remote servers, not url. Open it from Cascade → MCP servers → Manage → View raw config.

Clinecline_mcp_settings.json
{"mcpServers":{"prodready":{"type":"streamableHttp","url":"https://mcp.prodready.si/mcp"}}}

Set type explicitly — Cline will otherwise guess the transport.

Claude Desktopconnector

Settings → Connectors → Add custom connector, name it prodready, paste https://mcp.prodready.si/mcp, Add. In a chat, open the tools menu (the +) and switch prodready on. The first call opens the sign-in page.

claude.ai — web and mobileconnector

Settings → Connectors → Add custom connector, name it prodready, paste https://mcp.prodready.si/mcp, Add; then enable it in the chat's tools menu. Available on Pro, Max, Team and Enterprise plans.

A claude.ai chat cannot run commands in your repository, so the scan itself needs a coding agent (Claude Code, Codex, Cursor). From claude.ai you can ask for help, the licence, the status of an SDLC project and its report.

Claude for Work — Team & Enterpriseorganisation connector

An Owner or Admin adds it once for everyone: Admin settings → Connectors → Add custom connector, paste https://mcp.prodready.si/mcp. Each member then switches it on under their own Settings → Connectors and signs in with their work email — that email is the licence holder for the SDLC.

Claude Code — desktop app & VS Code / JetBrains.mcp.json
{"mcpServers":{"prodready":{"type":"http","url":"https://mcp.prodready.si/mcp"}}}

Put it in .mcp.json at the root of the repository and every teammate's Claude Code picks it up (approve once when asked). The one-line claude mcp add above works in the app's terminal too; /mcp shows the connection and lets you sign in again.

Settings → Connectors → Add custom connector, then paste the address: https://mcp.prodready.si/mcp

OpenAI — Responses APItools[] entry
{"type":"mcp","server_label":"prodready","server_url":"https://mcp.prodready.si/mcp","require_approval":"never"}

Add it to the tools array of a Responses call. Leave require_approval off if you want to see each tool call before it runs.

Anything that only speaks stdiofallback
npx -y mcp-remote https://mcp.prodready.si/mcp

Older hosts without remote transport — and Cursor, Windsurf or Cline builds that do not take a URL — bridge through this as a normal stdio command.

Once it is installed you do not call the tools by name. Ask in plain language — is my app production-ready? — and your host picks them up on its own. The tool names on this page are what your agent calls, not what you type.

02Sign in

The first tool call opens a browser tab. That tab is the whole account: an email address, and nothing to remember.

  1. Type your email on the sign-in page. The page is good for ten minutes.
  2. Open the email. It carries a one-time link and a 6-digit code. Both are good for fifteen minutes.
  3. Click the link in the same browser where the sign-in started. The link is bound to that browser, so a link someone else asked for cannot connect their app to your account. Reading the mail on another device? Type the 6-digit code into the sign-in page instead. Five wrong codes close the sign-in; start again from your host.
  4. Approve the connection. The consent page shows the name the app gave itself, marked not verified, and — large — where access goes. Approve only if that is the app you just started from. Otherwise press Cancel.
  5. Back in your host. It receives an access token (24 hours) and a refresh token (90 days, replaced on every use). No password, no card.

The contact record

Connecting creates a contact record at Innovate d.o.o.: your email, the time and the host name. Nothing else. The same email is the account the SDLC licence and your projects are bound to.

Revoking access

Remove the server from your host (claude mcp remove prodready in Claude Code, or the host's own settings). The host drops its tokens, and hosts that support it revoke them at /oauth/revoke. An access token already issued stops working within 24 hours; an unused refresh token is dead after 90 days. To connect again, add the server again and sign in.

Limits: five sign-in links per email per hour, thirty per network address. Past that the page says “Too many links requested. Try again in an hour.”

03The free scan

Say it in plain words:

is my app production-ready?is this safe to launch?what breaks when real users arrive?

In Claude Code you can also type /prodready:scan. Then, in order:

  1. Your agent calls prodready_probe and gets back the read-only commands for your stack.
  2. It runs them in your repository, on your machine.
  3. It hands the counts and paths to prodready_assess.
  4. You get a 0–100 score with a grade, the findings with their consequences, what could not be evaluated, and a link to the report page.

The server is remote and cannot see your disk, so it does not guess and it does not ask for your code. Nothing leaves your machine but counts, file paths and identifier names.

Then the due diligence — 18 dimensions, free

The scan is the first half of the end-to-end due diligence. The second half is the technical review our own team runs: eighteen dimensions — architecture, code quality, security posture, data architecture, infrastructure, API design, frontend, dependencies, scalability, load performance, technical debt, observability, documentation, accessibility, release management, compliance signals and cost — each scored 1 to 5 against its checklist, every finding with a file and line.

Say it in plain words:

due diligencedeep reviewaudit the architecturedubinska analiza

In Claude Code: /prodready:dd. Then, in order:

  1. If the scan has not run in this session, your agent runs it first.
  2. It calls prodready_dd_brief per dimension and gets the rubric, the checklist with item ids and the files to read.
  3. It reads the code on your machine and answers every item — a finding is an item id, a path and line, a severity and a short note. No file contents, no secrets.
  4. It hands the answers to prodready_dd_assess: the server validates them (a dimension with under 60% of its checklist answered is capped at 3; load performance is scored only from load-test results you supply, otherwise it stays “not evaluated”), computes the weighted score, the risk heatmap, the compound risks and the top ten risks, and writes the report page.
  5. You get the link and its access code. The page: cover with the 1–5 gauge, executive summary, critical risks, strengths, dimension scores with the weighting, top 10 risks by probability × impact, compound risks, the detail per dimension with every finding, what could not be evaluated, the method, the comparison with a prior run, and the next step. It prints to a clean PDF.

What it does not contain: remedies. The report names each gap, where it is and what it costs. Fixing it is the SDLC.

prodready_probe — the plan

Takes an optional stack (e.g. ["next","supabase","multi-tenant"]) and an optional depth:

depthWhat comes back
stackOnly the commands that work out what the app is built on.
core (default)Every scoring probe plus the critical and high-severity checks — the ones that decide whether it is safe to put real users on.
fullThe whole catalogue, medium and low checks included. A much longer plan.

The plan is text. It opens with the contract — the read-only command vocabulary (grep, rg, find, ls, wc, head, cat, git and their usual companions), what never to run and what never to send. Without a stack it starts with the detection commands. Then a legend, once:

MarkMeaning
$A read-only shell command.
SQL>A read-only query against the database's own catalogue. Runs only on a connection you hand your agent; no check depends on one.
do:Work to do by reading files — not a command.
[structural]Read the files and work out the answer.
[corroborate]The detector has a documented exception: confirm before reporting it fired.
only if:The check's gate — report whether it matched under gates.

Then every check: its id, severity, the rule it belongs to, the condition under which it counts as fired, and its commands. Nothing writes, nothing installs, nothing calls the network. The credential detectors never print the line a match came from.

prodready_assess — the grade

Needs evidence.results: an object keyed by check id, exactly as the plan printed it. Per check: ran, fired, count, total, files (repo-relative paths, never contents), a short evidence quote of twelve words at most, corroborated where the plan asked for it, exempt where the documented exception applies. Optional: evidence.stack, evidence.repo counts (source files, routes, endpoints, locales, very large files) and evidence.gates. report picks the delivery: link (default), html or none.

It returns:

The report page

With report: "link" the full report is stored as an unlisted page at https://mcp.prodready.si/r/<id>, in the prodready design, marked noindex, and kept for seven days. Your agent should open it for you; it is the deliverable. html returns the same page inline to save locally; none returns text and stores nothing. One account writes at most thirty report pages an hour.

Honesty rules

The rules the scan keeps

Attested, not observed. The results are what your agent reports it ran. The server scores what it is told and says so.

Not evaluated is not a pass. A check your agent did not run is left out, and the report lists it as not evaluated. It is never scored as a pass. When too much is missing, the score is stated as a ceiling.

No remedies. Each finding names the gap and the consequence of leaving it in. It never names the fix. Do not ask the tool for a patch, a policy, a migration or a config — it has none to give, and it will not invent one.

No secrets, no people. An evidence value that carries a credential, a token, a row of data, a person's details or a suggested fix is rejected, and the finding it belonged to is dropped, not softened. Email addresses and query-string URLs are stripped on the way out.

04SDLC on

The SDLC is our delivery process — the one our developers use to build large applications — handed to your coding agent one step at a time. It runs as a team of specialised agents: your agent builds, and the three reviewers and the sprint auditor each run as a separate agent that did not take part in building. The server hands out each step, checks the gate in front of it and keeps the ledger. It needs the licence (§07).

SDLC onrun the prodready SDLC on this project/prodready:sdlc

Story states, in order:

Draft→Ready→In Development→In QA→In Review→Done·Blocked

Gates G0–G7

GateNameRecorded byPurpose
G0Refinedsdlc_refineA story is ready to be planned.
G2Preflightsdlc_story_startA story has enough detail to start building.
G3Verifysdlc_verifyThe project's own checks pass on the story.
G4Reviewsdlc_review_submit ×3Three independent reviewers clear the story.
G5Sprint auditsdlc_audit_submitThe finished sprint is audited as a whole.
G6Pushedsdlc_story_doneThe work is on the remote.
G7Integration flowssdlc_sprint_completeThe sprint's key journeys work across stories.

There is no G1. What each gate requires is sent to your agent by the server, in the briefs, at the step where it applies. A step that skips a gate is refused with the reason and the next allowed step: “…Next allowed step: …”. Every gate result is attested: your agent reports it, and the ledger records who said so (provenance: "self-attested"). The server cannot see your disk, so it does not claim your tests really ran. It checks the order.

The sequence

  1. sdlc_licence_status — is the licence active? If not, your agent offers sdlc_request_access and the free scan keeps working.
  2. sdlc_project_init — creates the project and returns its id with the discovery brief. sdlc_playbook returns the brief for any step along the way.
  3. sdlc_backlog_add — stories in the template's fields (see the tool reference). Stored as Draft, with what each still lacks.
  4. sdlc_refine — the refinement answers per story; complete → Ready (G0).
  5. sdlc_sprint_plan → sdlc_sprint_start — a goal and refined stories. Unrefined stories are refused.
  6. Per story: sdlc_story_start (G2, builder brief) → build → sdlc_verify (G3) → sdlc_review_request → three reviews → sdlc_review_submit ×3 (G4) → sdlc_story_done (G6).
  7. sdlc_decision_add / sdlc_decision_resolve — the decision register.
  8. sdlc_audit_request → sdlc_audit_submit — the sprint audit (G5).
  9. sdlc_sprint_complete — the journeys recorded (G7); the sprint closes.
  10. sdlc_status / sdlc_report — the board, the gate ledger, the open decisions and the report page.

Then it iterates, sprint after sprint, until the app scores at least 4 out of 5 on the readiness scale.

Refinement (G0)

Twelve refinement questions, R1–R12. The server sends them to your agent with sdlc_playbook (topic refinement); your agent answers them per story in sdlc_refine's answers, keyed by id, with optional updates to the story's fields. sdlc_refine is also how a Blocked story is released once a person has decided what changes.

Preflight (G2) and the builder brief

sdlc_story_start runs on a Ready story in the active sprint. Preflight fails → the story stays Ready and the problems come back; close them with sdlc_refine updates and start again. Preflight passes → In Development, and the builder brief. Lost it? Call sdlc_story_start again; nothing changes, the brief comes back.

Verify (G3) — three attempts

sdlc_verify records the project's own typecheck, lint, build and tests, exactly as they came out: pass and a one-line summary each, plus counts for tests. All four pass → In QA. Otherwise one attempt is used and the story stays In Development; the third failed attempt → Blocked.

Reviews (G4) — three reviewers, three nonces

sdlc_review_request on a story In QA returns three reviewer briefs. Each reviewer runs as a separate agent in a fresh context and submits once with sdlc_review_submit.

ReviewerWhat it gets
Architecture architectureIts own criteria and a one-time nonce from sdlc_review_request.
Security securityIts own criteria and a one-time nonce from sdlc_review_request.
Functional functionalIts own criteria and a one-time nonce from sdlc_review_request.

Decision register

When the work hits a business question nobody has answered, your agent records it with sdlc_decision_add: the question, who has to answer it, and how the behaviour ships meanwhile. You answer whenever you like — that rule is: … — and sdlc_decision_resolve records it with its date.

Sprint audit (G5)

When no started story in the sprint is still in flight, sdlc_audit_request returns the audit brief and sdlc_audit_submit records a 0–5 score on each of five dimensions, with findings:

Story fulfilmentFunctional completenessData integrityIntegration flowsBaseline integrity

An audit can block the sprint; the server tells your agent the rule. A blocked sprint is fixed and audited again.

Sprint complete (G7)

sdlc_sprint_complete takes the journeys walked — name and pass, optionally step counts and notes. All pass → the sprint is completed, and stories that did not reach Done go back to the backlog. A failing journey → the sprint stays active and the audit reopens.

Status and report

sdlc_status gives the board by state, the gate ledger summary, the open decisions and the next allowed step; call it whenever you are unsure what comes next. sdlc_report gives the project and sprint report as text and as an unlisted page on mcp.prodready.si, kept seven days.

Things to say mid-run

You sayYour agent calls
status / where are wesdlc_status
next storysdlc_story_start on the next Ready story in the sprint
verify it / run the checkssdlc_verify
review itsdlc_review_request, three fresh-context reviews, sdlc_review_submit ×3
that rule is: …sdlc_decision_resolve
audit the sprintsdlc_audit_request → sdlc_audit_submit
report / show me the pagesdlc_report
what does the playbook say about refinement / reviews / auditssdlc_playbook with the topic

05Tool reference

27 tools, generated from the server's own definitions. tools/list always lists every one, licensed or not, so your host can show what exists. Licensed tool descriptions start with [SDLC licence] (left off below). Every tool rejects unknown arguments (additionalProperties: false), and every refusal carries the reason and the next allowed step. Results over 40 KB keep their head and their tail — the next step — and say the middle was left out.

ToolTierWhat it does
prodready_helpfreeWhat prodready can do here: the flows, the phrases that start them, and — given what the user said — the one to run now.
prodready_probefreePlan a production-readiness scan
prodready_assessfreeGrade the scan and price the gap
prodready_dd_brieffreeDue diligence step one: which dimensions apply to the stack and, per dimension, the rubric, checklist and files to read.
prodready_dd_assessfreeDue diligence step two: validates the answers, scores the 18 dimensions, builds the heatmap and risks, writes the report page.
sdlc_licence_statusfreeSDLC licence status
sdlc_request_accessfreeRequest the SDLC licence
sdlc_project_initlicensedStart an SDLC project
sdlc_project_listfreeList SDLC projects
sdlc_playbooklicensedRead a process brief
sdlc_backlog_addlicensedAdd stories to the backlog
sdlc_refinelicensedRefine a story (G0)
sdlc_sprint_planlicensedPlan a sprint
sdlc_sprint_startlicensedStart a sprint
sdlc_story_startlicensedStart a story (G2)
sdlc_verifylicensedRecord verify results (G3)
sdlc_review_requestlicensedRequest the three reviews (G4)
sdlc_review_submitlicensedSubmit one review (G4)
sdlc_story_donelicensedMark a story Done (G6)
sdlc_decision_addlicensedRecord an open business decision
sdlc_decision_resolvelicensedRecord a business decision's answer
sdlc_audit_requestlicensedRequest the sprint audit (G5)
sdlc_audit_submitlicensedSubmit the sprint audit (G5)
sdlc_sprint_completelicensedComplete the sprint (G7)
sdlc_statuslicensedProject status and next step
sdlc_reportlicensedProject report page
sdlc_project_deletefreeDelete an SDLC project

prodready_help What can prodready do here?

Call it when the user asks what prodready can do, what to say, or says something the agent cannot map to a tool. Returns the flows this server offers, the plain phrases that start each, the tools they use, and — if said matched — the one flow to run now. No data leaves the machine.

Tierfree Free — signed in · read-only, idempotent
Arguments
  • said string — What the user said, as they said it, in any language (optional).
ReturnsThe matched flow (scan, dd, sdlc, status, next, report, licence, delete, off) with its tools, plus the full list of flows and the slash prompts.
RefusalsAn argument other than said.

prodready_probe Plan a production-readiness scan

Step one of a production-readiness and security review of the user's own codebase. Reach for this whenever someone asks whether the app they built is ready for real users, safe to launch, secure, safe to put customer data in, multi-tenant safe, or whether it will hold up when it gets traffic — and whenever they want a second opinion on something a coding tool generated for them.

This server is remote and cannot see the user's disk, so it does not guess and it does not ask for the code. It returns the exact read-only shell commands and file globs to run locally: one per detector in the prodready hardening catalogue — 25 numbered platform rules across wiring, configuration, multi-tenant isolation and row-level security, UI and internationalisation, operations, and compliance and lifecycle, plus the critical-rules set covering data integrity, API surface, state machines, auth and sessions, secrets, logging and tests.

Every command is read-only — grep and rg, find, ls, wc, head, cat, git, and their usual companions awk, sort and xargs. Nothing writes, nothing installs, and nothing a command does calls the network. Four checks carry a read-only query against the database's own catalogue; the plan marks those SQL> instead of $, they run only against a connection the user hands you, and no check depends on one. The credential detectors never print the line a match came from, so no secret value is read or sent.

By default the plan is every scoring probe plus the critical and high-severity detectors — the ones that decide whether the app is safe to put real users on. Pass depth:"full" for the whole catalogue, or depth:"stack" for just the commands that work out what the app is built on.

Run the steps, then hand what came back to prodready_assess for the graded report.

Tierfree Free — signed in · read-only, idempotent
Arguments
  • stack array of string or string — What the app is built on, if known — e.g. ["next","supabase","multi-tenant"]. Narrows the plan to the detectors that can apply. Omit it and the plan opens with the commands that work the stack out.
  • depth "stack" | "core" | "full" · default "core" — stack returns only the commands that identify what the app is built on. core (the default) returns every scoring probe plus the critical and high-severity checks — the ones that decide whether it is safe to put real users on. full adds the medium and low checks for a thorough pass; it is a much longer plan.
ReturnsThe scan plan as text: the read-only contract (the command vocabulary, what never to run, what never to send), the stack-detection commands when no stack was given, a legend for the line marks ($ shell, SQL> catalogue query, do: read the files, [structural], [corroborate], only if:), then every check with its id, severity, rule reference, fires when condition and commands.
RefusalsAn argument that is not stack or depth, or a depth outside the three values.

prodready_assess Grade the scan and price the gap

Step two: turn what prodready_probe's commands returned into a graded readiness report.

Gives back: findings mapped to the numbered rule each one breaks, with the evidence that proves it; a 0-100 score built from five dimensions of 20 — data, safety, tests, review, release — with a letter grade and a Green/Amber/Red standing; the checks that could not be evaluated, named rather than passed over; a link to the full report page in the prodready design (open it for the user — it is the deliverable, unlisted, kept seven days); and the next step: what closing the gaps would take, and what our SDLC covers that a scan cannot see. The scan is free.

Each finding names the gap and the consequence of leaving it in. It does not name the remedy: the diagnosis is free, the fix is the product. Do not ask this tool for a patch, a policy, a migration or a config — it has none to give, and it will not invent one.

Evidence is used for this one call and is never stored and never logged. Send counts, file paths and identifier names. Never send the contents of a .env, a key file, or any matched secret value.

Tierfree Free — signed in · read-only, idempotent
Arguments
  • evidence required object — What the probe's commands returned. Never file contents, never secret values.
    • stack array of string — Stack tags the probe's detection commands yielded.
    • repo object — Counts the findings quote as denominators.
      • source_file_count integer
      • route_count integer
      • endpoint_count integer
      • locale_count integer
      • mega_files array of string
    • results required object of object — Keyed by check id, exactly as the plan printed it. A check you did not run is left out entirely — it is recorded as not evaluated, never scored as a pass.
      • ran boolean — The command was actually run.
      • fired boolean — The check's fires-when condition held. Omit it and the count decides.
      • count integer — Matches, or files returned.
      • total integer — The denominator, when the finding is a ratio.
      • files array of string — Repo-relative paths, optionally path:line. Paths only, never contents.
      • evidence string — A short literal quote of what the command returned, or that it returned nothing — twelve words at most. A handful of findings quote it; the rest are rendered from count, total and files, and the evidence line under a finding never carries it. Never a credential, a token, a row of data or a person's details, and never a suggested fix: this report names the gap and its consequence. A value carrying any of those is rejected and the finding it belonged to is dropped, not softened.
      • corroborated boolean — Required on checks the plan marked as needing corroboration.
      • exempt boolean — The check's documented exception applies here.
      • units integer — Distinct things affected, when that differs from count.
    • gates object of boolean — Check id -> did its applies-when gate match.
  • report "link" | "html" | "none" · default "link" — How to deliver the report page. link (default): an unlisted URL on mcp.prodready.si that shows the full report in the prodready design, kept for seven days — open it for the user and share it. html: the same page returned inline to save locally. none: text only.
ReturnsFindings mapped to the rule each one breaks, with the evidence that proves it; a 0–100 score from five dimensions of 20 (data, safety, tests, review, release), a letter grade and a Green/Amber/Red standing; the checks that were not evaluated, by name; the report page link (link), the page itself (html) or nothing (none); the next step.
Refusals{}, a missing results or an unknown field — refused, no page written. Over 30 report pages in an hour on one account — refused, nothing stored; report: "none" still works. An evidence string carrying a credential, personal data or a suggested fix drops that finding.

prodready_dd_brief Due diligence: the brief

Step one of the 18-dimension technical due diligence — the deep review behind “due diligence”, “deep review”, “audit the architecture”. Returns which dimensions apply to this stack and, for one dimension (or every applicable one when dimension is omitted — large), its 1–5 rubric, its checklist with item ids, the files and areas to read, and the exact JSON shape to hand back. Read-only; nothing is stored. The agent reads the code on the user's machine and never sends file contents, environment values or secrets.

Tierfree Free — signed in · read-only, idempotent
Arguments
  • stack array of string or string — What the app is built on, the same tags prodready_probe works out.
  • dimension string — One dimension id; omit for the list plus every applicable brief.
ReturnsThe applicable dimensions with their weights; per dimension the rubric (what 1, 3 and 5 mean), the checklist items with ids, what to read, and the JSON shape for prodready_dd_assess.
RefusalsAn unknown dimension id; an argument outside stack and dimension.

prodready_dd_assess Due diligence: score and report

Step two: hand back what was established per dimension. The server validates it, computes the weighted 1–5 score and grade, per-dimension risk (probability × impact), the 5×5 risk heatmap, compound risks across dimensions, the top findings and what could not be evaluated, and leaves a report page (link + six-character access code, seven days). The report names each gap, where it is and what it costs; it does not name the remedy and refuses fields that would carry one.

Tierfree Free — signed in · writes one report page
Arguments
  • stack required — the stack tags.
  • dimensions required array — per dimension: id, score (1–5 or null = not evaluated), answered (item ids), findings (item, path, line, severity, note ≤ 200 chars), notes.
  • load_test object — k6-style results the user already has; without them load performance is “not evaluated”.
  • project string — the project's name for the cover.
  • prior — an earlier run's dimensions for the comparison.
  • report string — link (default), html or none.
ReturnsThe overall score and grade word, the per-dimension table, the heatmap, the top risks, the compound risks, what could not be evaluated, and report_url + report_access_code.
RefusalsUnknown dimension or item ids; a score outside 1–5; a finding without a path, or with an absolute path; any remedy-shaped field (recommendation, remediation, target state and the like); more than 30 report pages an hour on one account.

sdlc_licence_status SDLC licence status

Whether the signed-in account holds the prodready SDLC licence, until when, where to unlock it, and what it contains. Free, and works before the licence is paid. Call it when an sdlc_* tool refuses, or when the user asks what the SDLC is.

Tierfree Free — signed in, no licence needed · read-only, idempotent
Argumentsnone — call it with {}
ReturnsSigned in or not, the email, licence active or not, the date it runs until, the unlock link and what the licence contains.
RefusalsAny argument (“sdlc_licence_status takes no arguments”).

sdlc_request_access Request the SDLC licence

Asks for the prodready SDLC licence for the signed-in account. The payment link is emailed to that address automatically; the sdlc_* tools unlock on this account the moment it is paid. Free. Call it when the user wants the SDLC after sdlc_licence_status or a refusal, never on their behalf without asking them first.

Tierfree Free — signed in, no licence needed · writes
Arguments
  • note string · 1–1000 chars — Anything the user wants the person replying to know: the product, the team, the deadline.
  • company string · 1–120 chars — The company or product name, if the user gives one.
  • projects string · 1–40 chars — Roughly how many projects they would run through it.
Returns“Request recorded”. The payment link goes to your sign-in email; a person is told as well. The tools unlock on this account automatically once it is paid. Asking twice within a day is recorded once and mails nobody twice.
RefusalsFields other than note, company, projects. Already licensed: “Nothing to request.”

sdlc_project_init Start an SDLC project

Creates a project on the user's account and returns its id with the discovery brief: what to establish about the product before any story is written. Start here for a new app, a rebuild, or when the user wants their project run through our delivery process.

Tierlicensed Licensed — description starts with [SDLC licence] · writes
Arguments
  • name required string · 1–120 chars — The project's working name.
  • repo string · 1–300 chars — owner/name or a local path.
  • stack array of string · ≤ 20 items, each 1–40 chars — e.g. ["nextjs","postgres"].
ReturnsThe new project id (8 characters) and the discovery brief: what to establish about the product before a story is written.
RefusalsThe account's project index at its storage bound — a storage limit, not a project limit; delete finished projects. Without an active licence: the licence text (“The SDLC tools are part of the prodready SDLC licence … Request access with sdlc_request_access …”). Unknown project: “There is no project … on this account.” Two calls on one project at the same instant: “…this change was not stored” — call again.

sdlc_project_list List SDLC projects

The projects on this account, with their ids. Works without an active licence, so a lapsed account can still find what to delete.

Tierfree Free — signed in, no licence needed · read-only, idempotent
Argumentsnone — call it with {}
ReturnsEvery project on this account: id, name, created, updated.
RefusalsAny argument. Works without a licence.

sdlc_playbook Read a process brief

The structured brief for one part of our delivery process: how stories are written, refined, estimated, built, reviewed and audited, the gates between them, and how open business decisions ship. Read the relevant brief before doing that step.

Tierlicensed Licensed — description starts with [SDLC licence] · read-only, idempotent
Arguments
  • topic required "story_writing" | "refinement" | "execution" | "coding_standards" | "definition_of_done" | "review" | "audit" | "gates" | "decisions" | "estimation" | "sprint" | "discovery"
ReturnsThe structured brief for the topic: short imperative rules, never prose. Topics: story_writing, refinement, execution, coding_standards, definition_of_done, review, audit, gates, decisions, estimation, sprint, discovery.
RefusalsA topic outside the list. Without an active licence: the licence text (“The SDLC tools are part of the prodready SDLC licence … Request access with sdlc_request_access …”). Unknown project: “There is no project … on this account.” Two calls on one project at the same instant: “…this change was not stored” — call again.

sdlc_backlog_add Add stories to the backlog

Stores user stories on a project. Each is checked against the story template and stored as Draft; what it still lacks is listed. Read sdlc_playbook story_writing first.

Tierlicensed Licensed — description starts with [SDLC licence] · writes
Arguments
  • project_id required string · 8-char id — The id sdlc_project_init returned.
  • stories required array of object · ≤ 50 items
    • title required string · 1–200 chars — One short verb phrase naming what the user can do.
    • as_a string · 1–300 chars — The role this story serves.
    • i_want string · 1–500 chars — What that role can do after this story.
    • so_that string · 1–500 chars — The benefit the role gets.
    • acceptance_criteria array of string · ≤ 8 items, each 1–500 chars — Observable pass-or-fail statements; at least 3, at most 8.
    • tasks array of string · ≤ 15 items, each 1–500 chars — Technical tasks in build order; at least 2, at most 15 — a story that needs more is split.
    • estimate_points integer · 0–100 — Points on the scale 1, 2, 3, 5, 8; above 5 is split.
    • risk "low" | "medium" | "high"
    • owner string · 1–200 chars — Who builds the story and answers questions about it.
    • depends_on array of string · ≤ 20 items, each S-001 style — Stories that must be Done before this one starts.
ReturnsThe stored stories with their ids (S-001…), each Draft, each with what it still lacks against the template.
Refusalsdepends_on naming a story that does not exist — nothing is stored. Over 50 stories in one call, or a project document over 900 KB. Without an active licence: the licence text (“The SDLC tools are part of the prodready SDLC licence … Request access with sdlc_request_access …”). Unknown project: “There is no project … on this account.” Two calls on one project at the same instant: “…this change was not stored” — call again.

sdlc_refine Refine a story (G0)

Records the answers to the refinement checklist for one story, with optional field updates. When every item is answered and the story fits the template, it becomes Ready (gate G0); otherwise the open items come back. Also how a Blocked story is released after a person has re-scoped it.

Tierlicensed Licensed — description starts with [SDLC licence] · writes
Arguments
  • project_id required string · 8-char id — The id sdlc_project_init returned.
  • story_id required string · S-001 style — A story id such as S-001.
  • answers required object of string — Checklist id -> answer. Ids: R1, R2, R3, R4, R5, R6, R7, R8, R9, R10, R11, R12.
  • updates object
    • title string · 1–200 chars — One short verb phrase naming what the user can do.
    • as_a string · 1–300 chars — The role this story serves.
    • i_want string · 1–500 chars — What that role can do after this story.
    • so_that string · 1–500 chars — The benefit the role gets.
    • acceptance_criteria array of string · ≤ 8 items, each 1–500 chars — Observable pass-or-fail statements; at least 3, at most 8.
    • tasks array of string · ≤ 15 items, each 1–500 chars — Technical tasks in build order; at least 2, at most 15 — a story that needs more is split.
    • estimate_points integer · 0–100 — Points on the scale 1, 2, 3, 5, 8; above 5 is split.
    • risk "low" | "medium" | "high"
    • owner string · 1–200 chars — Who builds the story and answers questions about it.
    • depends_on array of string · ≤ 20 items, each S-001 style — Stories that must be Done before this one starts.
ReturnsAll twelve items answered and the story fits the template: refined: true, status Ready, G0 recorded. Otherwise the open items.
RefusalsNo such story; a story already In Development or later (“a story is refined before it is built”); an unknown checklist id; a dependency on itself or on a story that does not exist. Without an active licence: the licence text (“The SDLC tools are part of the prodready SDLC licence … Request access with sdlc_request_access …”). Unknown project: “There is no project … on this account.” Two calls on one project at the same instant: “…this change was not stored” — call again.

sdlc_sprint_plan Plan a sprint

Creates a sprint with one business goal and the refined stories that deliver it. Stories that have not passed refinement are refused.

Tierlicensed Licensed — description starts with [SDLC licence] · writes
Arguments
  • project_id required string · 8-char id — The id sdlc_project_init returned.
  • goal required string · 1–500 chars
  • story_ids required array of string · ≥ 1 item, ≤ 20 items, each S-001 style
ReturnsThe sprint (SP-1…) as planned, its stories and total points, plus notes: outside three to eight stories, open decisions to review.
RefusalsAny story that does not exist, is not refined (G0) or already sits in an unfinished sprint — the sprint is not planned. Without an active licence: the licence text (“The SDLC tools are part of the prodready SDLC licence … Request access with sdlc_request_access …”). Unknown project: “There is no project … on this account.” Two calls on one project at the same instant: “…this change was not stored” — call again.

sdlc_sprint_start Start a sprint

Makes a planned sprint the active one and returns the sprint brief: the goal, the stories in build order and the cycle to follow.

Tierlicensed Licensed — description starts with [SDLC licence] · writes
Arguments
  • project_id required string · 8-char id — The id sdlc_project_init returned.
  • sprint_id required string · SP-1 style — A sprint id such as SP-1.
ReturnsThe sprint made active and the sprint brief: goal, stories in build order, the cycle.
RefusalsSprint not planned; another sprint still active (“sprints run one after another”); a story lost refinement since planning. Without an active licence: the licence text (“The SDLC tools are part of the prodready SDLC licence … Request access with sdlc_request_access …”). Unknown project: “There is no project … on this account.” Two calls on one project at the same instant: “…this change was not stored” — call again.

sdlc_story_start Start a story (G2)

Runs the preflight check (G2) on a story in the active sprint and, when it passes, moves it to In Development and returns the builder brief: execution rules, coding standards, the definition of done and the story itself.

Tierlicensed Licensed — description starts with [SDLC licence] · writes
Arguments
  • project_id required string · 8-char id — The id sdlc_project_init returned.
  • story_id required string · S-001 style — A story id such as S-001.
ReturnsG2 passes: status In Development and the builder brief — execution rules, coding standards, definition of done, the story. G2 fails: the story stays Ready with the problems listed. Called again on a story In Development: the brief again, nothing changes.
RefusalsStory not in the active sprint; story not Ready. Without an active licence: the licence text (“The SDLC tools are part of the prodready SDLC licence … Request access with sdlc_request_access …”). Unknown project: “There is no project … on this account.” Two calls on one project at the same instant: “…this change was not stored” — call again.

sdlc_verify Record verify results (G3)

Records the results of the project's own typecheck, lint, build and tests for a story in development, exactly as they came out. All four pass: the story moves to In QA (gate G3). A failure counts as one attempt; the third failed attempt blocks the story.

Tierlicensed Licensed — description starts with [SDLC licence] · writes
Arguments
  • project_id required string · 8-char id — The id sdlc_project_init returned.
  • story_id required string · S-001 style — A story id such as S-001.
  • results required object
    • typecheck required object
      • pass required boolean
      • summary required string · 1–500 chars — One line: the command and what it printed.
    • lint required object
      • pass required boolean
      • summary required string · 1–500 chars — One line: the command and what it printed.
    • build required object
      • pass required boolean
      • summary required string · 1–500 chars — One line: the command and what it printed.
    • tests required object
      • pass required boolean
      • summary required string · 1–500 chars
      • passed required integer · ≥ 0
      • failed required integer · ≥ 0
      • skipped integer · ≥ 0 — Focused or skipped tests; any count fails the step.
ReturnsAll four pass: In QA, G3 recorded. Otherwise “attempt n of 3” with the failing steps; the third failed attempt sets Blocked.
RefusalsStory not In Development. Counted as a failed step, not a refusal: tests reported passing with failures, skipped or focused tests, zero tests run. Without an active licence: the licence text (“The SDLC tools are part of the prodready SDLC licence … Request access with sdlc_request_access …”). Unknown project: “There is no project … on this account.” Two calls on one project at the same instant: “…this change was not stored” — call again.

sdlc_review_request Request the three reviews (G4)

For a verified story: returns three reviewer briefs — architecture, security, functional — each with its own one-time nonce. Run each review in a fresh context (a separate sub-agent with no memory of the build), then submit each with sdlc_review_submit.

Tierlicensed Licensed — description starts with [SDLC licence] · writes
Arguments
  • project_id required string · 8-char id — The id sdlc_project_init returned.
  • story_id required string · S-001 style — A story id such as S-001.
ReturnsThe story printed once, then three reviewer sections — architecture, security, functional — each with its criteria, its reject rules and a one-time nonce, and the exact sdlc_review_submit call to make.
RefusalsStory not In QA; no passing G3 on record; a round in which a review was already submitted (“a round cannot be re-issued”). Without an active licence: the licence text (“The SDLC tools are part of the prodready SDLC licence … Request access with sdlc_request_access …”). Unknown project: “There is no project … on this account.” Two calls on one project at the same instant: “…this change was not stored” — call again.

sdlc_review_submit Submit one review (G4)

Records one reviewer's scores, findings and verdict, using the nonce issued to that reviewer for that story. When all three are in, the story is either cleared for Done (G4) or sent back to development with every finding as a task.

Tierlicensed Licensed — description starts with [SDLC licence] · writes
Arguments
  • project_id required string · 8-char id — The id sdlc_project_init returned.
  • story_id required string · S-001 style — A story id such as S-001.
  • nonce required string · 16–64 chars
  • reviewer required "architecture" | "security" | "functional"
  • scores required object of integer — Criterion id -> 0-5, one per criterion in the brief.
  • findings required array of object · ≤ 100 items
    • severity required "critical" | "high" | "medium" | "low"
    • text required string · 1–2000 chars
    • location string · 1–500 chars — file:line — a finding without a location does not count.
    • criterion string · 1–64 chars
    • dimension string · 1–64 chars
  • verdict required "approve" | "reject"
  • rationale string · 1–2000 chars — Two or three sentences.
ReturnsThe reviewer's outcome and who is still pending. With the third review in: “All three reviewers approve (G4)” and the story is cleared for Done, or the round is rejected — every finding becomes a task, the story goes back to In Development, and the third rejected round sets Blocked.
RefusalsA nonce never issued, already used, issued for another story or another reviewer; a story not waiting on that round; scores that do not match the reviewer's criteria exactly (the nonce stays unused — submit again). Without an active licence: the licence text (“The SDLC tools are part of the prodready SDLC licence … Request access with sdlc_request_access …”). Unknown project: “There is no project … on this account.” Two calls on one project at the same instant: “…this change was not stored” — call again.

sdlc_story_done Mark a story Done (G6)

Marks a story Done once verify (G3) and the three-reviewer approval (G4) are on record, and records the pushed branch or commit (G6).

Tierlicensed Licensed — description starts with [SDLC licence] · writes
Arguments
  • project_id required string · 8-char id — The id sdlc_project_init returned.
  • story_id required string · S-001 style — A story id such as S-001.
  • pushed_ref required string · 1–200 chars, no spaces — The pushed branch, tag or commit.
ReturnsStatus Done, G6 recorded with the pushed ref.
RefusalsAlready Done; no passing G3 on record; no three-reviewer approval (G4) on record. Without an active licence: the licence text (“The SDLC tools are part of the prodready SDLC licence … Request access with sdlc_request_access …”). Unknown project: “There is no project … on this account.” Two calls on one project at the same instant: “…this change was not stored” — call again.

sdlc_decision_add Record an open business decision

Adds a row to the decision register: a business question nobody has answered yet, who must answer it, and how the behaviour ships until then (switched off, or a conservative default). Returns the register.

Tierlicensed Licensed — description starts with [SDLC licence] · writes
Arguments
  • project_id required string · 8-char id — The id sdlc_project_init returned.
  • question required string · 1–1000 chars — Answerable in one line.
  • asked_by required string · 1–200 chars — Who has to answer it.
  • ships_as required string · 1–300 chars — switched off | conservative default | …
  • story_ids array of string · ≤ 20 items, each S-001 style
ReturnsThe register with the new row (D-001…), status open.
RefusalsA story_ids entry that does not exist. Without an active licence: the licence text (“The SDLC tools are part of the prodready SDLC licence … Request access with sdlc_request_access …”). Unknown project: “There is no project … on this account.” Two calls on one project at the same instant: “…this change was not stored” — call again.

sdlc_decision_resolve Record a business decision's answer

Records the owner's answer to an open decision, with its date, and returns the register. Plan a story to switch the behaviour on.

Tierlicensed Licensed — description starts with [SDLC licence] · writes
Arguments
  • project_id required string · 8-char id — The id sdlc_project_init returned.
  • decision_id required string · D-001 style
  • decision required string · 1–2000 chars
ReturnsThe register with the answer and its date.
RefusalsNo such decision; a decision already decided. Without an active licence: the licence text (“The SDLC tools are part of the prodready SDLC licence … Request access with sdlc_request_access …”). Unknown project: “There is no project … on this account.” Two calls on one project at the same instant: “…this change was not stored” — call again.

sdlc_audit_request Request the sprint audit (G5)

When no story in the active sprint is still in flight: returns the audit brief — five dimensions, what to check in each, and when the audit blocks.

Tierlicensed Licensed — description starts with [SDLC licence] · writes
Arguments
  • project_id required string · 8-char id — The id sdlc_project_init returned.
  • sprint_id required string · SP-1 style — A sprint id such as SP-1.
ReturnsThe audit brief: five dimensions, what to check in each, the scale, and when the audit blocks.
RefusalsSprint not active; a started story still in flight; no story Done; the audit already passed. Without an active licence: the licence text (“The SDLC tools are part of the prodready SDLC licence … Request access with sdlc_request_access …”). Unknown project: “There is no project … on this account.” Two calls on one project at the same instant: “…this change was not stored” — call again.

sdlc_audit_submit Submit the sprint audit (G5)

Records the audit's five scores (0-5) and findings. An audit can block the sprint; the server tells your agent the rule, and a blocked sprint is fixed and audited again.

Tierlicensed Licensed — description starts with [SDLC licence] · writes
Arguments
  • project_id required string · 8-char id — The id sdlc_project_init returned.
  • sprint_id required string · SP-1 style — A sprint id such as SP-1.
  • scores required object
    • story_fulfilment required integer · 0–5
    • functional_completeness required integer · 0–5
    • data_integrity required integer · 0–5
    • integration_flows required integer · 0–5
    • baseline_integrity required integer · 0–5
  • findings required array of object · ≤ 200 items
    • severity required "critical" | "high" | "medium" | "low"
    • text required string · 1–2000 chars
    • location string · 1–500 chars — file:line — a finding without a location does not count.
    • criterion string · 1–64 chars
    • dimension string · 1–64 chars
ReturnsPass: G5 recorded, next step sdlc_sprint_complete. Block: the blockers and the blocking findings, next step fix and sdlc_audit_request again.
RefusalsNo audit of that sprint waiting for results. Without an active licence: the licence text (“The SDLC tools are part of the prodready SDLC licence … Request access with sdlc_request_access …”). Unknown project: “There is no project … on this account.” Two calls on one project at the same instant: “…this change was not stored” — call again.

sdlc_sprint_complete Complete the sprint (G7)

Completes an audited sprint and records the critical user journeys walked end to end (G7). Stories that did not reach Done return to the backlog.

Tierlicensed Licensed — description starts with [SDLC licence] · writes
Arguments
  • project_id required string · 8-char id — The id sdlc_project_init returned.
  • sprint_id required string · SP-1 style — A sprint id such as SP-1.
  • integration_flows required array of object · ≥ 1 item, ≤ 50 items
    • name required string · 1–200 chars
    • pass required boolean
    • steps_total integer · ≥ 0
    • steps_working integer · ≥ 0
    • notes string · 1–1000 chars
ReturnsEvery journey passes: the sprint is completed, G7 recorded, delivered stories and points, stories not Done back to the backlog. A failing journey: the sprint stays active and the audit reopens.
RefusalsSprint not active; no passing G5 on record; a story started after the audit. Without an active licence: the licence text (“The SDLC tools are part of the prodready SDLC licence … Request access with sdlc_request_access …”). Unknown project: “There is no project … on this account.” Two calls on one project at the same instant: “…this change was not stored” — call again.

sdlc_status Project status and next step

The board by state, the gate ledger summary, open decisions, and the next allowed step. Call it whenever you are unsure what comes next.

Tierlicensed Licensed — description starts with [SDLC licence] · read-only, idempotent
Arguments
  • project_id required string · 8-char id — The id sdlc_project_init returned.
ReturnsThe board by state, the gate ledger summary (pass and fail per gate), open decisions and the next allowed step.
RefusalsWithout an active licence: the licence text (“The SDLC tools are part of the prodready SDLC licence … Request access with sdlc_request_access …”). Unknown project: “There is no project … on this account.” Two calls on one project at the same instant: “…this change was not stored” — call again.

sdlc_report Project report page

The project and sprint report as text, plus an unlisted page on mcp.prodready.si in the prodready design, kept for seven days. Open it for the user and give them the link.

Tierlicensed Licensed — description starts with [SDLC licence] · writes
Arguments
  • project_id required string · 8-char id — The id sdlc_project_init returned.
ReturnsThe project and sprint report as text, and an unlisted page on mcp.prodready.si/r/…, kept seven days.
RefusalsOver 30 report pages in an hour on one account. Without an active licence: the licence text (“The SDLC tools are part of the prodready SDLC licence … Request access with sdlc_request_access …”). Unknown project: “There is no project … on this account.” Two calls on one project at the same instant: “…this change was not stored” — call again.

sdlc_project_delete Delete an SDLC project

Deletes the project document, its index entry and its report pages. Cannot be undone. Works without an active licence: your data stays deletable after the licence ends.

Tierfree Free — signed in, no licence needed · writes, destructive, idempotent
Arguments
  • project_id required string · 8-char id — The id sdlc_project_init returned.
  • confirm required true — Must be true.
ReturnsConfirmation that the project document, its index entry and its report pages are gone. Cannot be undone.
Refusalsconfirm missing or not true; unknown project id. Works without a licence.

06Prompts and slash commands

The server publishes eight MCP prompts. Hosts that surface prompts show them as commands; in Claude Code they are /prodready:scan, /prodready:dd, /prodready:sdlc, /prodready:status, /prodready:next, /prodready:report, /prodready:licence and /prodready:help.

CommandWhat it does
/prodready:scanRuns the free readiness scan on the current repository and opens the report page.
/prodready:ddRuns the 18-dimension due diligence on the current repository (the scan first if it has not run), then opens the report page and gives the access code.
/prodready:sdlcTurns the SDLC on for the current project, starting with the licence check and following the next allowed step each tool names.
/prodready:statusShows the board, the gate ledger, open decisions and the next allowed step. Starts nothing.
/prodready:nextDoes exactly the next allowed step, then stops.
/prodready:reportWrites the project report page and gives the link and access code (the scan report when there is no SDLC project).
/prodready:licenceSays whether the account has the SDLC licence; requests it if you want it.
/prodready:helpExplains, in your words, what to say to get a scan, a due diligence, the SDLC, a status, a report or the licence.

Plain-language triggers

You sayWhat happens
is my app production-ready? · is this safe to launch? · what breaks when real users arrive?The free scan: prodready_probe → run → prodready_assess
due diligence · deep review · audit the architecture · dubinska analizaThe 18-dimension review: prodready_dd_brief → read → prodready_dd_assess
SDLC on · run the prodready SDLC on this project · fix it properlyThe SDLC, from sdlc_licence_status
help · what can you do · what do I sayprodready_help
next · continue · go onsdlc_status, then exactly the next allowed step
request the SDLCsdlc_request_access
status / where are wesdlc_status
next storysdlc_story_start
verify it / run the checkssdlc_verify
review itsdlc_review_request → sdlc_review_submit ×3
that rule is: …sdlc_decision_resolve
audit the sprintsdlc_audit_request → sdlc_audit_submit
report / show me the pagesdlc_report
list my projects · delete this projectsdlc_project_list · sdlc_project_delete

07Licence

The price: see pricing.

08Privacy & data

WhatLeaves your machineStored
Scan evidenceCounts, repo-relative file paths, identifier names, short quotes of command output. Never file contents, never secrets.No. Scored in memory for one call, never stored, never logged.
Scan report page—Unlisted, noindex, deleted after seven days. report: "none" stores nothing.
SDLC project documentsStories, sprints, gate results, the ledger, decisions — what your agent sends. Never code.Under your account until you delete them.
SDLC report pages—Unlisted, seven days, and removed with the project.
Contact recordYour email, the time, the host name.Yes — it is the account.
Licence requestYour email, the host name and what you type into the request.Yes, to answer it.

Deleting a project: ask your agent to delete it. It calls sdlc_project_list for the id, then sdlc_project_delete with confirm: true, which removes the document, its index entry and its report pages. It cannot be undone, and it works without a licence.

Usage is counted per day, per event and per host, without the account; analytics never receive your email or its hash. The full policy: prodready.si/privacy.

09Troubleshooting

You seeIt meansDo this
“tools fetch failed” right after sign-inThe host's first tool fetch after sign-in did not go through.Reconnect once: /mcp in Claude Code → prodready → Reconnect. The token is fine.
401 / “The access token is invalid or expired” / the host asks you to authenticate againThe access token lapsed and could not be refreshed, or was revoked.Reconnect from the host; sign in by email again if asked. Your projects are bound to the email, not the token.
“Open the link in the browser where you started.”The magic link was opened in another browser or device.Open it in the starting browser, or type the 6-digit code into the sign-in page there.
“Sign-in expired” / “Link expired”The sign-in page is older than ten minutes, the link older than fifteen, or it was already used.Start the connection again from your host.
“Unknown client”The host's registration with the server is gone.Remove the server from your host and add it again; it registers anew.
“Too many links requested. Try again in an hour.”Five links per email, thirty per address, per hour.Use the last link you received, or wait the hour.
“The SDLC tools are part of the prodready SDLC licence…”The licence is not active for the email you signed in with.Request it (§07). Signed in with another address? Remove the server, add it again and sign in with the licensed one.
“…Next allowed step: …”A step skipped a gate, or ran in the wrong state.Do that step. The server will not skip a gate for anyone. sdlc_status shows where you are.
“…this change was not stored” / “not stored, call again”Two calls changed one project at the same instant.Call the same tool again with the same arguments.
“This report link has expired or never existed.”Report pages live seven days.Run the scan or sdlc_report again for a fresh page.
“Report pages are limited to 30 an hour per account…”The hourly report-page limit.Wait, or run prodready_assess with report: "none".
“prodready_assess needs the structured results of prodready_probe”The agent called assess without results, or with fields the schema does not list.Call prodready_probe, run the commands, send evidence.results keyed by check id.
A story is BlockedThree failed verify attempts, or three rejected review rounds.A person decides what changes about the story; then sdlc_refine releases it.
HTTP 413A request body over 2 MB.Send fewer results per call.

10Protocol notes for integrators

Transport and versions

MCP over streamable HTTP at https://mcp.prodready.si/mcp. The era is chosen by method and headers, never guessed.

Protocol versionBehaviour
2025-03-26 · 2025-06-18 · 2025-11-25initialize handshake, Mcp-Session-Id, GET with Accept: text/event-stream opens an SSE stream, DELETE ends a session. A request without MCP-Protocol-Version is read as 2025-03-26; an unknown version at initialize is answered with 2025-11-25.
2026-07-28Stateless: no initialize, no session, per-request _meta, server/discover. Mcp-Method (and Mcp-Name) must match the body. GET and DELETE answer 405.

The server offers tools and prompts. The session id is protocol furniture, not a key into anything: the readiness tools keep no state beyond the report page.

Authorization

OAuth 2.1: authorization code with PKCE (S256), dynamic client registration, rotating refresh tokens, scope readiness. A call without a bearer token gets 401 with WWW-Authenticate pointing at the resource metadata; CORS exposes WWW-Authenticate, Mcp-Session-Id and MCP-Protocol-Version.

EndpointPurpose
GET /.well-known/oauth-protected-resource (also …/mcp)RFC 9728 resource metadata
GET /.well-known/oauth-authorization-server (also /.well-known/openid-configuration)RFC 8414 server metadata
POST /oauth/registerRFC 7591 dynamic client registration
GET /oauth/authorize · POST /oauth/authorizeThe sign-in page; sends the magic link and the 6-digit code
GET /oauth/verify · POST /oauth/codeThe consent page, by link or by code
POST /oauth/consentApprove or cancel; redirects back with a code
POST /oauth/tokenauthorization_code and refresh_token grants
POST /oauth/revokeRFC 7009 revocation

Other URLs

URLWhat it is
GET /healthOpen, no token. Status, version, transport, supported protocol versions, the tool names and the check count.
GET /r/<id>A report page: unlisted, noindex, no-referrer, seven days.
GET /A landing page for people who open the server in a browser.
# no token needed
curl -s https://mcp.prodready.si/health
# {"status":"ok","service":"prodready","transport":"mcp-streamable-http",
#  "protocol_versions":["2026-07-28","2025-11-25","2025-06-18","2025-03-26"],
#  "tools":[…],"stateful":false,"stores_evidence":false, …}

Bounds

Install it. Run the free scan tonight.

Sign-in is by email and free. The scan tells you what is wrong; the prodready SDLC is how your agent fixes it without skipping a step.

▶ StartSee pricing