CrawlCheck

Registry · Capabilities · context7.com

Capability registry

What context7.com declares an agent can do

Measured 2026-10-01 16:39 UTC from the declarations the site publishes (record 4l955pfeky). Each capability is shown as declared, under the policy class that decides whether anything may call it, beside what a call observed.

26declared
1public read-only
0called and verified
0declared ≠ observed
agent_skill, mcp, openapiprotocols
Public read-only: 1Authenticated read-only: 5Unknown: 16Metadata: 4
Public read-only 1 · Authenticated read-only 5 · Unknown 16 · Metadata 4

Declared versus observed

CapabilityPolicy classDeclaredObserved
docs7AnalyticsPreflight
openapi · OPTIONS · https://context7.com/api/docs7/analytics
Public read-onlyHTTP OPTIONS with no declared security
auth: none · required inputs: 0
not attempted
not a GET
recordDocs7PageView
openapi · POST · https://context7.com/api/docs7/analytics
Unknown
never called automatically
POST with no declared reversibility
auth: none · required inputs: 2
not attempted
classed unknown: only read-only public actions are ever called
searchLibraries
openapi · GET · https://context7.com/api/v2/libs/search
Authenticated read-only
never called automatically
HTTP GET behind http_bearer
auth: http_bearer · required inputs: 3
not attempted
requires http_bearer: never called without the operator's own credentials
searchDocumentation
openapi · GET · https://context7.com/api/v3/search
Authenticated read-only
never called automatically
HTTP GET behind http_bearer
auth: http_bearer · required inputs: 2
not attempted
requires http_bearer: never called without the operator's own credentials
getLibraryMetrics
openapi · GET · https://context7.com/api/v2/libs/metrics
Authenticated read-only
never called automatically
HTTP GET behind http_bearer
auth: http_bearer · required inputs: 2
not attempted
requires http_bearer: never called without the operator's own credentials
getContext
openapi · GET · https://context7.com/api/v2/context
Authenticated read-only
never called automatically
HTTP GET behind http_bearer
auth: http_bearer · required inputs: 4
not attempted
requires http_bearer: never called without the operator's own credentials
refreshLibrary
openapi · POST · https://context7.com/api/v1/refresh
Unknown
never called automatically
POST with no declared reversibility
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
getPolicies
openapi · GET · https://context7.com/api/v2/policies
Authenticated read-only
never called automatically
HTTP GET behind http_bearer
auth: http_bearer · required inputs: 0
not attempted
requires http_bearer: never called without the operator's own credentials
updatePolicies
openapi · PATCH · https://context7.com/api/v2/policies
Unknown
never called automatically
PATCH with no declared reversibility
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
addGitHubRepo
openapi · POST · https://context7.com/api/v2/add/repo/github
Unknown
never called automatically
POST with no declared reversibility
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
addGitLabRepo
openapi · POST · https://context7.com/api/v2/add/repo/gitlab
Unknown
never called automatically
POST with no declared reversibility
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
addBitbucketRepo
openapi · POST · https://context7.com/api/v2/add/repo/bitbucket
Unknown
never called automatically
POST with no declared reversibility
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
addGitRepo
openapi · POST · https://context7.com/api/v2/add/repo/git
Unknown
never called automatically
POST with no declared reversibility
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
addOpenApi
openapi · POST · https://context7.com/api/v2/add/openapi
Unknown
never called automatically
POST with no declared reversibility
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
addOpenApiUpload
openapi · POST · https://context7.com/api/v2/add/openapi-upload
Unknown
never called automatically
POST with no declared reversibility
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
addPdfUpload
openapi · POST · https://context7.com/api/v2/add/pdf-upload
Unknown
never called automatically
POST with no declared reversibility
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
addFileUpload
openapi · POST · https://context7.com/api/v2/add/file-upload
Unknown
never called automatically
POST with no declared reversibility
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
addDocxUpload
openapi · POST · https://context7.com/api/v2/add/docx-upload
Unknown
never called automatically
POST with no declared reversibility
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
addLlmsTxt
openapi · POST · https://context7.com/api/v2/add/llmstxt
Unknown
never called automatically
POST with no declared reversibility
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
addWebsite
openapi · POST · https://context7.com/api/v2/add/website
Unknown
never called automatically
POST with no declared reversibility
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
addConfluence
openapi · POST · https://context7.com/api/v2/add/confluence
Unknown
never called automatically
POST with no declared reversibility
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
addNotion
openapi · POST · https://context7.com/api/v2/add/notion
Unknown
never called automatically
POST with no declared reversibility
auth: http_bearer · required inputs: 1
not attempted
requires http_bearer: never called without the operator's own credentials
server
mcp · https://mcp.context7.com/mcp
Metadata
never called automatically
a server declaration; its tools are listed only by the server itself (tools/list), which is not called
auth: unknown
not attempted
on another origin (mcp.context7.com): only the scanned origin is called
find-docs
agent_skill · https://context7.com/.well-known/agent-skills/find-docs/SKILL.md
Metadata
never called automatically
an instruction file an agent reads; not an operation
auth: none
not attempted
metadata: describes a surface, is not itself an action
context7-mcp
agent_skill · https://context7.com/.well-known/agent-skills/context7-mcp/SKILL.md
Metadata
never called automatically
an instruction file an agent reads; not an operation
auth: none
not attempted
metadata: describes a surface, is not itself an action
context7-cli
agent_skill · https://context7.com/.well-known/agent-skills/context7-cli.tar.gz
Metadata
never called automatically
an instruction file an agent reads; not an operation
auth: none
not attempted
metadata: describes a surface, is not itself an action

Where the declaration and the call disagree

None: every capability that was called answered as declared.

Signed certificate

This page’s rows, signed by the observer’s Ed25519 key: every capability’s id, endpoint, safety class, policy class and observed state, the declaration hashes and the record’s sealed manifest. The certificate is derived from the record alone, so the same record always yields the same id.

certificate_id ccap1:c4fccf96c5711c3353b18d9f3e32c08387171669ef53c74017e8f9c5d6725243
alg Ed25519 · kid hcIAczGf-8EFBnkunmZlvFWnD2nHHeHeC9cM4BTiBVo
sig b8qYSguhY8WSveLz9Ey7G0WBx7gZnFazDSOJGlUYh0NsNVRp6wRIYbRgaFvlqUDMB1DBvja6LRzmbiH46AejDw

The certificate as JSON · verify it now · the key directory · machine-readability certificate

To verify it yourself: SHA-256 the certificate object as canonical JSON (keys sorted, no whitespace); the hex digest must equal certificate_sha256 and the id; then check the Ed25519 signature over "crawlcheck-capability-certificate-v1\n" followed by that hex digest, with the key in the directory whose RFC 7638 thumbprint is the kid.

Policy classes

Policy classCalled automatically?Rule
Public read-only
public_read_only
yes, to verifyMay be called without credentials. CrawlCheck calls it only to check the declaration: GET with no input, on the scanned origin.
Authenticated read-only
authenticated_read_only
neverNever called by CrawlCheck. An agent needs the user's own credentials and consent.
Reversible write
reversible_write
neverNever invoked automatically. Needs the owner's written authorisation and a test account.
Irreversible write
irreversible_write
neverNever invoked automatically. Deletes or changes something that cannot be undone.
Financial
financial
neverNever invoked automatically. Moves money or creates a charge.
External communication
external_communication
neverNever invoked automatically. Sends a message, email or notification to someone.
Identity and accounts
identity
neverNever invoked automatically. Creates, signs in to or changes an account or credential.
Unknown
unknown
neverNever invoked. Its effect cannot be read from the declaration, so it is treated as the riskiest case.
Metadata
metadata
neverNothing to invoke: a listing, a server card or a skill file, not an operation.