
Bing Webmaster AI CLI MCP
io.github.stufentlyv0.1.2更新于 Oct 11, 2026
Read Bing Webmaster data and change it, directly or through a reviewed plan.
概览
读取你站点的 Bing 网站管理员工具数据,并可直接或经审核计划提交和更改 Bing 状态。
- 功能
- 让助手接入 Bing 网站管理员工具的 JSON API,获取流量、索引、抓取问题、反向链接和关键词数据,并支持 IndexNow 提交。它提供 34 个读取工具、一个本地只读的 IndexNow 密钥工具、计划查看工具,以及每个受支持操作对应的写入工具。写入要么以 bing_ 工具直接执行,要么生成 bing_plan_ 计划由你用 CLI 自行应用。
- 适用场景
- 当你希望助手诊断自有站点的 Bing 搜索表现、索引状态、抓取错误或反向链接,并可选地提交 URL 或更改 Bing 设置时使用。若希望每次更改都由人工批准,请选择经审核的写入路径。
- 运行要求
- 以 stdio 本地进程运行,通过 uvx 从 Git 仓库启动(该包尚未发布到 PyPI);pip 检出安装需要 Python 3.12+。需要 BING_WM_API_KEY,即在 Bing 网站管理员工具的“设置 > API 访问”中创建的 API 密钥。可选设置包括 BING_WM_ALLOW_WRITES、BING_WM_DENIED_SITES 和 BING_WM_MAX_WRITES_PER_DAY。可选的 HTTP 入口需要 BING_WM_HTTP_BEARER_TOKEN。
安装
在 SourceWeft 中
- 打开 控制台中的 Bing Webmaster AI CLI MCP,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
bing-webmaster-ai-cli-mcp
bing-webmaster-ai-cli-mcp gives an AI agent read access to what Bing knows about your sites — traffic, indexing, crawl issues, inbound links, keywords — and a write path you choose: direct by default, or reviewed plan-and-apply.
It ships a Python 3.12+ CLI and MCP server for the JSON Bing Webmaster Tools API, plus protocol-correct IndexNow submission. SOAP and POX are deliberately absent.
Choosing a write path
Read tools always execute immediately. For everything that changes Bing state, one setting picks between two paths:
If you are not sure, set it to false. The default is convenience; false is the
safe answer, and here is the reason. An agent using this server also reads pages, anchor
text, crawl issues and search queries written by strangers. A confirmation an agent can
send is a confirmation prompt injection can send, so as long as the agent can write, a
poisoned string in someone else's anchor text can reach your Bing account. With
false, nothing an agent does changes Bing until you have read the plan and run
bing-wm plan apply yourself.
Direct writes (default)
The MCP server advertises one-step bing_<operation> tools, and the CLI accepts:
A direct write is not idempotent: retrying one records a new plan and sends the change
again. If a response is lost, read audit.jsonl or bing-wm plan list before repeating
the call.
Reviewed writes (BING_WM_ALLOW_WRITES=false)
The server advertises bing_plan_<operation> instead. Those tools send nothing:
No MCP tool takes a plan ID, in either mode: a plan recorded for review is applied or rejected only at the CLI, by you. A direct write applies the plan it creates in the same call and never touches one somebody else recorded. The plan path stays available while direct writes are on, so an agent can still propose a change for review.
What both paths share
A direct write is the same code with the human step removed: it records the same durable
plan and goes through the same apply boundary. A readable plan record, an append-only
audit trail, one-shot application, expiry, Bing's own submission quota, a site denylist
(BING_WM_DENIED_SITES) and restart-persistent local limits
(BING_WM_MAX_WRITES_PER_DAY) apply to both.
If the applying process is killed and leaves a lock behind, the command
bing-wm plan unlock PLAN_ID verifies that the recorded PID is gone before recovering
it. An unfinished plan becomes unknown_outcome and cannot be applied again; the
recovery is audited.
Install
That one command starts the stdio MCP server. Every client block below runs the same
uvx command. Create an API key in Bing Webmaster Tools under Settings → API Access
and pass it as BING_WM_API_KEY. If you are not sure about writes, also set
BING_WM_ALLOW_WRITES=false — see Choosing a write path.
The package is not on PyPI yet. Until it is, uvx bing-webmaster-ai-cli-mcp (a PyPI
name, with no --from) does nothing useful. The command above is the install path.
PyPI publishing is switched off in release.yml: it is enabled by the repository
variable PYPI_PUBLISH=true once the PyPI Trusted Publisher is set up.
A checkout still installs with pip (Python 3.12+) and puts bing-wm,
bing-webmaster-ai-cli-mcp and bing-webmaster-ai-cli-mcp-http on PATH:
The supported matrix is Python 3.12, 3.13, and 3.14. Development and images use the
exact versions in constraints.txt; published dependencies remain compatible floors.
Never put a real key in the repository. See configuration for
all settings.
Example prompts
- Why did my site lose clicks last week?
- Which pages is Bing failing to crawl, and why?
- Is this URL indexed, and when did Bing last fetch it?
- Submit this new page to Bing, but let me review the change first.
Add the MCP server to your AI client
Every JSON block below runs the same uvx command as Install.
BING_WM_ALLOW_WRITES is false here, so writes are planned and you apply them.
Remove that variable for direct writes — see
Choosing a write path. Keep the key in a user-level config,
not in a project file you commit. The server exposes 34 Bing read tools, one local
read-only tool (bing_indexnow_key_plan), plan inspection, and one write tool per
supported operation — direct bing_<operation> tools by default, or
bing_plan_<operation> tools when BING_WM_ALLOW_WRITES=false. It exposes no plan
application or rejection tool. Restart the server after changing the setting so the
client refreshes its tool list.
Claude Code
Project file: .mcp.json in the project root.
Or from the terminal:
Claude Desktop
File: claude_desktop_config.json — macOS
~/Library/Application Support/Claude/claude_desktop_config.json, Windows
%APPDATA%\Claude\claude_desktop_config.json, Linux
~/.config/Claude/claude_desktop_config.json.
One click, without editing JSON: download the .mcpb from
https://github.com/stufently/bing-webmaster-ai-cli-mcp/releases/latest
and open it. Claude Desktop installs the extension and asks for the API key.
Direct writes stay off unless you turn Allow direct writes on. While they are off
the extension only records plans. Applying one needs the bing-wm CLI, which the
extension does not put on your PATH: install it with pip as in Install,
export the same key as BING_WM_API_KEY in that shell, then run bing-wm plan apply.
The release includes checksums.txt with the SHA256 of every .mcpb.
Download that file into the same directory as the bundle and check it before
opening the extension:
On macOS, filter the bundle's line and check it with shasum -a 256 -c -.
Cursor
File: ~/.cursor/mcp.json (every project) or .cursor/mcp.json (this project).
Windsurf
File: mcp_config.json — macOS and Linux ~/.config/devin/mcp_config.json
(or $XDG_CONFIG_HOME/devin/mcp_config.json), Windows
%APPDATA%\devin\mcp_config.json. Older builds read
~/.codeium/windsurf/mcp_config.json.
Zed
File: settings.json — Linux and macOS ~/.config/zed/settings.json.
An optional Streamable HTTP entry point is also available once the package is on
PATH (the pip install above; uvx does not install a lasting command):
It refuses non-loopback bind addresses and unauthenticated requests.
Common questions
Which crawl issues does my site have?
The result carries Bing's rows unchanged plus a category breakdown built from
Microsoft's UrlWithCrawlIssues.CrawlIssues flags — redirects, 4xx, 5xx, robots.txt
blocks, malware, DNS and timeout errors — with a count per category, a count per raw
HttpCode, and an other bucket so nothing Bing sends is dropped. A 4xx row is split
further into http_404 or http_403 from its own HttpCode, alongside the broad
http_4xx rather than instead of it. Bing has no noindex crawl-issue flag, so there
is no such category and this project does not invent one.
How do I check if Bing has indexed my page?
How do I submit URLs to Bing from the command line?
With writes enabled, from one URL or a newline-delimited file:
With BING_WM_ALLOW_WRITES=false, create a plan, review it, then apply it:
The planner calls GetUrlSubmissionQuota; no quota number is hardcoded. Bing's method
documentation also limits one SubmitUrlBatch call to 500 URLs.
Does IndexNow work with Google?
Google does not participate in IndexNow. The live IndexNow registry currently lists
Bing, Yandex, Seznam, Naver, Yep, Internet Archive, and Amazonbot. Submission through
api.indexnow.org fans out to participating engines.
Generate a key, host the displayed UTF-8 key file, then submit:
indexnow key — and the matching bing_indexnow_key_plan MCP tool — only computes and
checks. It talks to neither Bing nor api.indexnow.org, so it is not a write and needs
no plan. The generated key is printed once and stored nowhere: save it, serve it at the
printed URL, then submit.
Or, with BING_WM_ALLOW_WRITES=false:
The submission checks the exact key-file URL without following redirects before it sends the batch. IndexNow hosts must use multi-label DNS names rather than IP literals or single-label names, and the key file must contain only the key. Batches above 10,000 URLs, ambiguous dot-segment paths, and URLs outside the authorized host or key subpath are rejected locally. There is intentionally no unverified 2,048-character URL cap. IndexNow's protocol tells callers to resubmit a valid request after a non-success response, so an HTTP 5xx leaves the plan pending; the CLI never retries it automatically.
Output safety
Anchor text, crawl-issue URLs, titles, messages, and query strings may be controlled by
strangers. The shared operation layer removes control and bidirectional-formatting
characters, truncates extreme values, and returns these fields as
{"value": "…", "untrusted": true}. Consumers must treat them as data, never as
instructions.
Verification secrets never leave the machine by accident. GetUserSites returns
AuthenticationCode and DnsVerificationCode beside every site and GetSiteRoles
returns DelegatedCode; whoever holds one can claim the site in another Bing account.
All three are replaced with [redacted: verification secret] in every response, and the
only way to see one is --reveal-verification-codes typed by an operator on
bing-wm sites list|show|roles or bing-wm plan show|list|apply. No MCP tool takes that
argument, so no model — and no text a model read — can ask for a code.
Redaction is an exit boundary, not a step on the read path. The same filter covers a
write's result, the arguments a plan records — an add_site_roles plan holds the
authentication_code it will send, and showing the plan does not show the code — and
Bing's own error text, in case Bing quotes back the code it rejected. The literals to
hide come from the request body, so the cover does not depend on anyone predicting which
field a secret will next arrive in. The plan record on disk keeps the real value; a plan
that lost its code could not be applied.
The API key is covered at the same boundary, under its own marker
[redacted: API credential]. Microsoft documents the key only as a query-string
parameter, so every request URL carries a live credential — and a proxy naming the
address it could not reach, or Bing quoting the request back in an error, would otherwise
put that URL into the error message, the terminal and the audit trail. An error carrying
no credential reads exactly as it did before.
An empty answer is never presented as a measurement. Some of the older endpoints return
an empty collection for accounts that demonstrably have data: bing_link_counts,
bing_crawl_issues and bing_fetched_urls all came back empty for a site whose
bing_crawl_stats reported 1700 inbound links in the same minute. A read that returned
no rows carries empty_response: {rows_returned: 0, measured: false, note: …} beside
result over MCP, and prints the note on stderr at the CLI, so "Bing returned nothing"
cannot be reported as "no problems found". Reads that answer with a single record —
bing_url_info, bing_crawl_settings, the quotas, bing_keyword — are never labelled:
an array inside one record, such as CrawlRate, is a field of that record
and not a row Bing withheld. bing_url_info labels the same trap in one field:
HttpStatus: 0 means Bing reports no status, not 200, and the row says so with
http_status_reported.
Coverage and references
- Agent skill: how to drive this server
- CLI commands, MCP tools, and write operations
- Complete 62-method Microsoft interface transcription
- Product boundaries
- Configuration
The Microsoft interface contains 62 methods: 59 supported here and three obsolete deep-link methods deliberately excluded. Keyword research is standalone because its official signatures contain no site parameter. Content submission is exposed because it remains present in Microsoft's current interface; account-side eligibility can only be confirmed by Bing for a particular account.
Licence
MIT.
来源:README.md,提交 842d5dd
工具
0版本历史
1- v0.1.2最新Oct 11, 2026

