Xelta MCP Server
Hosted, remote Model Context Protocol server — Xelta's documented agent surface, reached at a single streamable-HTTP /mcp endpoint. Probed live 2026-09-01: a JSON-RPC tools/list returns HTTP 401 invalid_token with a correct RFC 9728 WWW-Authenticate challenge, and the service root and /health both return 200. Authorization is OAuth 2.1 (authorization code + PKCE S256) with an RFC 8628 device-code fallback, RFC 7591 dynamic client registration and RFC 7009 revocation, all published through a complete RFC 8414 + RFC 9728 discovery pair. Eight tools (generate_image, create_mixboard, create_reel, generate_street_ad, build_website, get_website_history, check_balance, xelta_connection_status), whose names and parameters are known from Xelta's own published Agent Skills rather than from an authenticated tools/list. None of them maps to a REST operation. A 74-operation OpenAPI was generated for this record and REMOVED on 2026-09-01 as unverifiable. It declared servers: https://api.xelta.ai, and that host returns 404 on its root and on every one of the 67 paths the spec declares -- /api/auth/register, /api/auth/login and the rest. Their llms.txt names no API, no endpoints and no spec. Nothing traceable to a live surface was found, so the spec is not kept: a 74-op contract attached to a host that serves nothing would inflate this record against a surface that may not exist.