Reliability

What fails open, what fails closed.

When mcpindex infrastructure fails, gate decisions do not change. The decision path runs locally on your machine and fails closed; the hosted side enriches decisions but never makes them. That is a design boundary, not a promise - each surface below states exactly what its failure does, and each claim is checkable in the shipped SDK source.

Per-surface semantics
The live test

On 2026-08-01 the hosting platform disabled this site's deployments for 3h40m (a usage-cap event; details in the incident log). Every hosted surface above was unreachable. No gate decision changed, no badge rendered a false pass, and installed SDKs kept enforcing their pins offline - the failure behaved exactly as this page says it should. Semantics on this page were last verified against the SDK source on 2026-08-01.

Live uptime at the external status page · trust model · methodology