The Reviseberg MCP server connects your AI assistant to your website's test results. Claude Code, Cursor, VS Code, claude.ai and other MCP clients can pull open accessibility issues, prioritise them by points back, look up the failing selector and affected pages, and queue a new crawl once the fix is deployed. Findings come from the latest completed crawl of your site – including the keyboard agent and a WCAG 2.2 status for every criterion.
The Model Context Protocol (MCP) is an open standard that lets AI applications use tools and data from external services [1]. Instead of copying findings from a report into your editor, your agent asks for them directly.
Tools
The server offers 7 tools. This table is the same list the server itself returns:
| Tool | What it returns |
|---|---|
list_sites | The sites your key can see, with their last crawl and accessibility score. |
get_issues | Open issues for a site, the ones worth most first: the rule, the WCAG criteria it violates, how many elements and pages, and the points back. Quality and SEO issues on request (module), 25 by default (limit). |
get_issue_detail | One issue in full: the message, a failing selector and snippet, every affected page and the help link. |
get_conformance | The WCAG 2.2 status of every success criterion in the catalogue – pass, fail, partial, not applicable or untested – including results people recorded by hand. Filterable by status. |
get_statement | The published accessibility statement for a site, its public address and what it claims. |
get_alt_text_suggestions | Alt-text suggestions for images that have none: the page, a CSS selector, the image address and the alt value to set. By default only the ones a person has accepted. |
run_scan | Queues a crawl of the site and returns the run ID. If a crawl is already queued or running, it returns that one instead of starting a second. |
Three principles apply to every tool. First, a criterion no automated check can settle is returned as "untested", never "pass" – your agent gets no false comfort. Second, no tool fixes anything. Reviseberg cannot write to your site; your agent applies the fix where the markup lives, in the repository or the CMS. Third, run_scan is the only tool that sets anything in motion, and all it starts is a crawl. How each status is derived is explained in our methodology.
Setup
- Create an API key in the Reviseberg app under Settings → API (this needs the Admin role). The key starts with
bz_and is shown exactly once. - Point your client at
https://reviseberg.com/api/mcp/– with the trailing slash – and send the key as anAuthorization: Bearerheader. - Ask your agent about your sites. When
list_sitesanswers, you are connected.
Keep the key in an environment variable, not in the repository:
export REVISEBERG_API_KEY="bz_…"
Claude Code
claude mcp add --transport http reviseberg https://reviseberg.com/api/mcp/ \
--header "Authorization: Bearer $REVISEBERG_API_KEY"
Run claude mcp list to confirm the server is connected [2].
Cursor
In .cursor/mcp.json (project) or ~/.cursor/mcp.json (global) [3]:
{
"mcpServers": {
"reviseberg": {
"url": "https://reviseberg.com/api/mcp/",
"headers": { "Authorization": "Bearer ${env:REVISEBERG_API_KEY}" }
}
}
}
VS Code (GitHub Copilot agent mode)
In .vscode/mcp.json. VS Code asks for the key on first start and stores it securely [4]:
{
"inputs": [
{ "type": "promptString", "id": "reviseberg-key", "description": "Reviseberg API key", "password": true }
],
"servers": {
"reviseberg": {
"type": "http",
"url": "https://reviseberg.com/api/mcp/",
"headers": { "Authorization": "Bearer ${input:reviseberg-key}" }
}
}
}
claude.ai
claude.ai's custom connectors take an address and nothing else – no header. Enter https://reviseberg.com/api/mcp/ there, and claude.ai signs in with OAuth: you land on a consent screen in the Reviseberg app that shows the address the access is handed back to, and only your approval creates a key. That needs what creating a key by hand needs – the Admin role and a free key in your plan. The connection ends when you revoke that key under Settings → API.
Any other client that supports remote MCP servers over HTTP follows the same pattern: the address plus an Authorization header.
Example prompts
- "Show me the five accessibility issues on our site with the most points back."
- "Get the details for
keyboard:focus-visible, find the component in the repo and add a visible focus style. Then run a new scan." - "Which WCAG criteria are still untested? Turn them into a checklist for manual testing."
- "Apply the accepted alt-text suggestions in our templates. Keep empty alt text where
decorative=true." - "What does our published accessibility statement claim, and does it match the current conformance status?"
A typical loop
- The agent calls
list_sitesand picks your site. get_issuesreturns the issues, sorted by impact. For example: "Focus not visible" (WCAG 2.4.7) with 17 occurrences is worth 3.42 points back.get_issue_detailgives the selector, snippet and every affected page. The agent finds the component and proposes the fix – you review and merge.- After deployment,
run_scanqueues a crawl. It takes a few minutes; polllist_sitesfor the new score. An issue counts as fixed when its findings stop appearing on the new crawl.
Findings from the keyboard agent carry the keyboard: prefix, such as keyboard:trap.
What the MCP server does not do
- It changes nothing on your site and injects no script. There is no tool that "fixes" anything.
- It never applies AI suggestions. By default it only returns alt text a person has accepted.
- It does not replace manual testing. Anything that needs human judgement stays "untested" until someone records it.
- It does not test HTML snippets in your editor. It reads results from crawled, rendered pages. For component tests at build time, keep axe-core in your unit or end-to-end tests as well (see API & CI).
Security and privacy
- Keys per organisation: a key only sees your organisation's sites – or only some of them, if you narrow it to particular sites when you create it. Every tool honours that.
- Only a hash is stored: Reviseberg keeps the key's SHA-256 hash and its first characters so you can recognise it, never the key itself. It does not expire and works until you revoke it.
- What a key may do: every tool except
run_scanonly reads, andrun_scanonly starts a crawl. There is no read-only key that excludesrun_scan; to limit what a key can reach, narrow it to particular sites. - Where the data lives: findings and account data are stored in a database in the EU (Frankfurt). Details in the privacy policy.
- Your AI client: what your agent does with the responses is governed by your client's provider. Findings contain URLs, selectors and code snippets from your pages – check that your agreement with that provider covers this.
Availability
The MCP server uses the same API keys as the REST API. How many keys a plan may hold at once: Starter 2, Growth 10 and Enterprise by agreement; none on the free account. Full details on the pricing page.