Use GuGuData API
Discover and use GuGuData public APIs through OpenAPI, Remote MCP, developer docs, and agent-readable API Markdown.
- OpenAPI catalog
- Remote MCP
- API details Markdown
Four public Agent Skills turn GuGuData API contracts into focused workflows for discovery, website quality, document OCR, and stock symbol integration reviews.
Each landing page explains its boundary, intended users, review outcomes, published source, and a traceable path to trial access.
Discover and use GuGuData public APIs through OpenAPI, Remote MCP, developer docs, and agent-readable API Markdown.
Review public website releases and SEO monitoring integrations with non-mutating website quality APIs.
Review OCR and document-processing integrations without exposing repository or customer documents.
Review US and Hong Kong stock symbol directory integrations as reference-data lookups.
Production discovery, exact authentication challenges, OAuth metadata and entry points, and all four published Skill artifacts passed. The release gate also covers all 52 API Markdown routes plus exact OAuth callback and token rotation behavior. Real production account invocation and third-party MCP Host interoperability were intentionally not performed.
| Area | Scenario | Scope | Result | Evidence |
|---|---|---|---|---|
| MCP 2026-07-28 | server/discover and stateless negotiation | Production OAuth challenge plus isolated authorized end-to-end | PASS | Production returned 401 with RFC 9728 resource metadata and no Mcp-Session-Id. The isolated authorized client negotiated 2026-07-28 and rediscovered tools after reconnect. |
| Initialize-based MCP | 2025-11-25 and earlier initialization handshake | Production OAuth challenge plus isolated authorized end-to-end | PASS | Production returned the same OAuth challenge for initialize traffic. SDK 2.0 legacy mode and the isolated SDK 1.8.0 probe completed discovery and reconnect checks. |
| OAuth discovery | Protected resource and authorization server metadata | Production | PASS | The protected resource is bound to https://mcp.gugudata.io/mcp. Authorization, token, registration, revocation, PKCE S256, CIMD, and authorization response issuer metadata were present. |
| OAuth client entry | Dynamic client registration and authorization redirect | Production, no account credentials submitted | PASS | A public client registered without a client secret and the authorization request redirected to the GuGuData login step with no-store caching. |
| Transport fingerprints | OAuth challenge through Node.js fetch, Python urllib, and curl | Production | PASS | All tested HTTP clients received the exact Bearer resource metadata challenge with mcp:access scope and no Mcp-Session-Id. The earlier generic urllib edge rejection was not reproduced. |
| OAuth lifecycle | PKCE code, token, refresh, resource binding, and revocation | Isolated end-to-end | PASS | The self-test covered approval and denial responses, exact issuer, token rotation, resource binding, and revocation without using production credentials. |
| OAuth callback and tokens | Exact callback URI, PKCE code exchange, access and refresh token issuance, and one-time refresh rotation | Unit and isolated end-to-end | PASS | The registered cursor://oauth-callback URI was preserved exactly through authorization, the callback carried code, state, and issuer, token responses contained the configured lifetime, and refresh rotation invalidated both prior tokens. |
| API LLM Markdown routes | Every published API identity returns its own raw Markdown document | Release build and post-deployment production gate | PASS | All 52 API identities are generated from the shared SSR Markdown builder and must return HTTP 200, text/markdown, a Markdown heading, and identity-specific demo and raw-document links; HTML fallback fails the release gate. |
| Entitlements | Account-scoped tools and non-purchased tool rejection | Isolated end-to-end | PASS | Normal and VIP fixtures exposed only the expected tool set, kept execution keys server-side, and rejected tools outside the entitlement snapshot. |
| Production account invocation | Authorized tool discovery and call with a real account | Production | NOT_RUN | No production credentials or paid API calls were used. This boundary is explicit and is not represented as a protocol failure. |
| Third-party MCP Host interoperability | Authorized discovery and tool calls from external MCP Hosts | Production | NOT_RUN | No real Cursor, Claude, ChatGPT, or other third-party Host was authorized during this refresh. Protocol SDK probes do not replace Host-specific interoperability testing. |
HTTP 200 · text/markdown
sha256:49e8c704e0451e571c2a90ca341455f90ef2abd5e63b5ba3479298e6507e3265HTTP 200 · text/markdown
sha256:117367e085068d36386681c230e6ce28bfed12a36bd01e38b460f4837474cc27HTTP 200 · text/markdown
sha256:939d78e274c5c42d3afc93498555c322a209f33c30c2d2d0754412b3a77a8d16HTTP 200 · text/markdown
sha256:9d922fd95ba3359bd894c3cc80f79f2794ec9efaa8ec08b7b62cdf9003bf2fb9Every trial link carries a stable source, medium, campaign, and Skill identifier through sign-in to trial-key creation.
view_skillbegin_skill_trialview_skill_trialgenerate_trial_keyMeasure unique users and event conversion by skill from this report date. Pre-launch historical attribution is unavailable and must remain zero or unknown, not backfilled.