From our own listing run, plus MCP Marketplace (mcp-marketplace.io)'s published docs
MCP Marketplace (mcp-marketplace.io): what it takes to get approved.
MCP servers (local stdio packages on PyPI/npm or remote HTTP endpoints), free or paid one-time/monthly, where the product itself can verify a marketplace license key; not for courses, ebooks or non-MCP software.
Networks change their rules. Every point below links to its source and the date we read it; check it the day you submit.
Who it suits
Users of Claude, ChatGPT/Codex, Cursor, Windsurf, VS Code and other MCP clients (and AI agents querying its registry API/MCP server) looking for security-scored MCP tools; no affiliate/referral program was found on the site or in its Terms.
Fees
Free to list. Terms of Service (last updated February 24, 2026): 'MCP Marketplace retains a 15% commission on all revenue generated from paid Tool sales. The remaining 85% is paid to the Creator.' Payment processing by Stripe; payouts via Stripe Connect Express on Stripe's schedule; taxes may be added at checkout. No listing or activation fee found.
Becoming a seller
- Create an account (email/password or GitHub sign-in); must be 18+.
- Turn on creator mode in the account (ThreadFox run, 2026-09-25).
- Free listings need nothing more (ThreadFox's free listing was approved without payout setup).
- Your step: for paid listings, connect a Stripe Connect Express account from the creator dashboard, including Stripe's identity verification (ThreadFox run, 2026-09-25: a new Stripe Express account with identity verification is required).
- Your step: tax responsibility is the creator's; 1099 forms may be issued to U.S. creators.
Setting up the product
- Build a real MCP server (official TypeScript or Python SDK; Node.js 18+ or Python 3.10+); test with MCP Inspector (npx @modelcontextprotocol/inspector) and a real client.
- Submit form needs: GitHub repository (public, or private with a PAT) or a remote endpoint URL; server name and description; category; pricing model (free, one-time or monthly subscription) and price; use cases and tags. Paid local servers: publish to PyPI/npm and submit the package; remote servers submit the URL.
- Optional LAUNCHGUIDE.md in the repo auto-fills listing details, tags and setup requirements.
- Observed form (ThreadFox run, 2026-09-25/26): category (Marketing & Social chosen), version, changelog, description, tagline; no dependency field; editing the version requires 'Save & Re-scan'.
- Paid servers: gate tools with the mcp-marketplace-license SDK (pip install mcp-marketplace-license, with_license(mcp, slug=...) or verify_license(slug=...); TypeScript @mcp_marketplace/license); buyers set MCP_LICENSE_KEY=mcp_live_... in their MCP config.
What reviewers check on the sales page
- No separate sales page: the marketplace listing is the storefront with its own purchase button and Stripe checkout.
- Listing must accurately describe functionality, required permissions and pricing and be kept current; abandoned, broken or misrepresented servers may be delisted after notice (Community Guidelines 5).
- 'Listings that exist solely to drive traffic to external sites will be removed' (Community Guidelines 2).
- No fake or coordinated reviews, install-count inflation or ranking manipulation (Terms 7; Guidelines 3).
- Tool must be a real MCP server with MCP SDK dependencies, an existing repository and valid protocol implementation, and contain no malware (FAQ; Terms 5).
Affiliate page and affiliate info
Not applicable: no affiliate program found (Terms, FAQ, creator pages and docs read 2026-09-27 mention none).
Delivery
Local servers: buyer installs your public package (install commands shown per client) and receives a license key starting mcp_live_ after purchase; your server verifies it through the marketplace verify API via the SDK (MCP_LICENSE_KEY env var; result {valid, reason}). Remote servers: buyer adds your URL; you handle authentication and access control. First-hand: ThreadFox verifies keys server-side by POSTing {key, slug} to the verify endpoint used by mcp-marketplace-license 1.1.0 (a Supabase function behind a gateway that needs the site's public publishable key in an apikey header) and rechecks keys to close revoked/expired ones. Creator dashboard lists issued keys and can revoke them for abuse.
Reviewer access
No manual reviewer access field observed; the automated scanner installs/probes the server itself (local: multi-layer code scan of repo/package and dependencies; remote: endpoint probing and trust analysis). A private GitHub repo needs a PAT.
Approval
Submission is validated as a real MCP server; servers above the safety threshold are approved automatically, others go to manual review ('Most servers are approved within minutes' on /for-creators; 'most servers are approved within 24 hours' in the FAQ). OBSERVED (ThreadFox run, 2026-09-25): free listing showed Pending Review, approved the same day (emails 10:30 and 17:50 UTC), public at /server/<slug>. Each version edit with 'Save & Re-scan' takes the public page to 404 until the re-scan/re-review finishes (observed ~10 min on 2026-09-25 20:22-20:32 UTC); a failed re-scan ('Not Valid MCP', SECURITY 0.0) keeps the listing down (2026-09-26, two consecutive failures, cause not identified by the site; support emailed 2026-09-26 12:24 UTC). Read-back 2026-09-27: https://mcp-marketplace.io/server/threadfox-lite still returns 404 and the public registry search for 'threadfox' returns 0 results.
Affiliate approval
Not applicable (no affiliate program found).
Marketplace visibility
Approved listings are public automatically at /server/<slug>, in /browse, the registry API (/api/registry/search, /api/registry/mcps/{slug}), llms-full.txt and the site's hosted MCP server; ranking/signals include security score (0-10; above 8 excellent, below 5 caution), creator reputation grade A+ to F (uptime, reviews, response latency, security, update frequency, account age), installs and ratings. A pending re-scan or failed scan removes the listing from public view.
Refunds
No refund window published. Terms 4: for a paid Tool that 'does not function as described', buyers contact support@mcp-marketplace.io 'and we will work with you to resolve it'. Buyers who purchased keep access if the creator removes the Tool.
Why products get held or rejected
- Not a valid MCP server: missing MCP SDK dependencies, missing repository, or failed protocol validation (FAQ).
- Scan below the safety threshold (supply chain, package/source mismatch, code vulnerabilities, remote endpoint trust, transport/protocol spec compliance) -> manual review.
- We saw this: known-vulnerable dependency range flagged as three high 'known vulnerability in mcp' findings, public score 4.8 'Use Caution' (ThreadFox run, 2026-09-25; fixed by raising the floor to mcp>=1.28.1, re-scan then showed SECURITY 10.0).
- We saw this: re-scan result 'Not Valid MCP' with SECURITY 0.0 on versions that answered initialize/tools/list correctly from a clean install (ThreadFox run, 2026-09-26); listing taken down; cause unknown.
- Malware or code harmful to users; IP infringement; misrepresented functionality (Terms 5, 7; Guidelines 5).
Check your page against these rules, free.
AllyOtter Lite reads your sales page and flags what MCP Marketplace (mcp-marketplace.io)'s reviewers reject: readiness_audit(url, ["mcp-marketplace"]). The AllyOtter kit then has your AI write the MCP Marketplace (mcp-marketplace.io) version of your page and every field of the submission.
Sources
- mcp-marketplace.io · read 2026-09-27 · Creator pitch: Stripe checkout/license keys/payouts, 3-step publish, approval 'within minutes'
- mcp-marketplace.io · read 2026-09-27 · Submission requirements, auto-approve vs manual review, LAUNCHGUIDE.md, monetization, dashboard
- mcp-marketplace.io · read 2026-09-27 · 85% to creator, approval within 24 hours, scanner rejects non-MCP tools, reputation grades
- mcp-marketplace.io · read 2026-09-27 · Terms of Service last updated Feb 24 2026: 15% commission, Stripe Connect Express, prohibited conduct incl. automated access
- mcp-marketplace.io · read 2026-09-27 · Listing accuracy, no traffic-driving listings, honest reviews
- mcp-marketplace.io · read 2026-09-27 · mcp_live_ keys, MCP_LICENSE_KEY, verify_license
- mcp-marketplace.io · read 2026-09-27 · Paid models: license-key package vs remote hosted; submit flow for paid servers
- mcp-marketplace.io · read 2026-09-27 · Five scan dimensions and failure rates
- mcp-marketplace.io · read 2026-09-27 · Listing metadata fields (JSON-LD)
- mcp-marketplace.io · read 2026-09-27 · Registry API, hosted MCP server, signals
- mcp-marketplace.io · read 2026-09-27 · API endpoints and rate limits
- mcp-marketplace.io · read 2026-09-27 · Disallowed paths
- mcp-marketplace.io · read 2026-09-27 · Public read-back: HTTP 404 (listing still down); registry search for threadfox returned 0 results
- First-hand · read 2026-09-25 · Our own listing run (ThreadFox, AllyOtter): creator mode, free listing Pending Review then approved same day (10:30/17:50 UTC), score 4.8 findings, paid needs Stripe Express identity verification, verify endpoint needs publishable key
- First-hand · read 2026-09-26 · Our own listing run (ThreadFox, AllyOtter): Save & Re-scan -> 404 during scan; 0.2.3 re-scan SECURITY 10.0; 0.2.5 and 0.2.6 re-scans 'Not Valid MCP', page 404; support emailed
- First-hand · read 2026-09-25 · Our own listing run (ThreadFox, AllyOtter): key redemption code (verify-key endpoint, apikey header, recheck)