
Bing Webmaster AI CLI MCP
io.github.stufentlyv0.1.2更新於 Oct 11, 2026
Read Bing Webmaster data and change it, directly or through a reviewed plan.
概覽
讀取你網站的 Bing 網站管理員工具資料,並可直接或透過審核計畫提交與變更 Bing 狀態。
- 功能
- 讓助理介接 Bing 網站管理員工具的 JSON API,取得流量、索引、檢索問題、反向連結與關鍵字資料,並支援 IndexNow 提交。它提供 34 個讀取工具、一個本機唯讀的 IndexNow 金鑰工具、計畫檢視工具,以及每個支援操作對應的寫入工具。寫入可以 bing_ 工具直接執行,或產生 bing_plan_ 計畫,由你自行用 CLI 套用。
- 適用情境
- 當你希望助理診斷自有網站的 Bing 搜尋成效、索引狀態、檢索錯誤或反向連結,並可選擇提交 URL 或變更 Bing 設定時使用。若希望每次變更都由人工核准,請選擇經審核的寫入路徑。
- 執行需求
- 以 stdio 本機程序執行,透過 uvx 從 Git 儲存庫啟動(套件尚未發布到 PyPI);以 pip 安裝需要 Python 3.12+。需要 BING_WM_API_KEY,也就是在 Bing 網站管理員工具的「設定 > API 存取」建立的 API 金鑰。選用設定包括 BING_WM_ALLOW_WRITES、BING_WM_DENIED_SITES 與 BING_WM_MAX_WRITES_PER_DAY。選用的 HTTP 進入點需要 BING_WM_HTTP_BEARER_TOKEN。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 Bing Webmaster AI CLI MCP,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
bing-webmaster-ai-cli-mcp
bing-webmaster-ai-cli-mcp gives an AI agent read access to what Bing knows about your sites — traffic, indexing, crawl issues, inbound links, keywords — and a write path you choose: direct by default, or reviewed plan-and-apply.
It ships a Python 3.12+ CLI and MCP server for the JSON Bing Webmaster Tools API, plus protocol-correct IndexNow submission. SOAP and POX are deliberately absent.
Choosing a write path
Read tools always execute immediately. For everything that changes Bing state, one setting picks between two paths:
If you are not sure, set it to false. The default is convenience; false is the
safe answer, and here is the reason. An agent using this server also reads pages, anchor
text, crawl issues and search queries written by strangers. A confirmation an agent can
send is a confirmation prompt injection can send, so as long as the agent can write, a
poisoned string in someone else's anchor text can reach your Bing account. With
false, nothing an agent does changes Bing until you have read the plan and run
bing-wm plan apply yourself.
Direct writes (default)
The MCP server advertises one-step bing_<operation> tools, and the CLI accepts:
A direct write is not idempotent: retrying one records a new plan and sends the change
again. If a response is lost, read audit.jsonl or bing-wm plan list before repeating
the call.
Reviewed writes (BING_WM_ALLOW_WRITES=false)
The server advertises bing_plan_<operation> instead. Those tools send nothing:
No MCP tool takes a plan ID, in either mode: a plan recorded for review is applied or rejected only at the CLI, by you. A direct write applies the plan it creates in the same call and never touches one somebody else recorded. The plan path stays available while direct writes are on, so an agent can still propose a change for review.
What both paths share
A direct write is the same code with the human step removed: it records the same durable
plan and goes through the same apply boundary. A readable plan record, an append-only
audit trail, one-shot application, expiry, Bing's own submission quota, a site denylist
(BING_WM_DENIED_SITES) and restart-persistent local limits
(BING_WM_MAX_WRITES_PER_DAY) apply to both.
If the applying process is killed and leaves a lock behind, the command
bing-wm plan unlock PLAN_ID verifies that the recorded PID is gone before recovering
it. An unfinished plan becomes unknown_outcome and cannot be applied again; the
recovery is audited.
Install
That one command starts the stdio MCP server. Every client block below runs the same
uvx command. Create an API key in Bing Webmaster Tools under Settings → API Access
and pass it as BING_WM_API_KEY. If you are not sure about writes, also set
BING_WM_ALLOW_WRITES=false — see Choosing a write path.
The package is not on PyPI yet. Until it is, uvx bing-webmaster-ai-cli-mcp (a PyPI
name, with no --from) does nothing useful. The command above is the install path.
PyPI publishing is switched off in release.yml: it is enabled by the repository
variable PYPI_PUBLISH=true once the PyPI Trusted Publisher is set up.
A checkout still installs with pip (Python 3.12+) and puts bing-wm,
bing-webmaster-ai-cli-mcp and bing-webmaster-ai-cli-mcp-http on PATH:
The supported matrix is Python 3.12, 3.13, and 3.14. Development and images use the
exact versions in constraints.txt; published dependencies remain compatible floors.
Never put a real key in the repository. See configuration for
all settings.
Example prompts
- Why did my site lose clicks last week?
- Which pages is Bing failing to crawl, and why?
- Is this URL indexed, and when did Bing last fetch it?
- Submit this new page to Bing, but let me review the change first.
Add the MCP server to your AI client
Every JSON block below runs the same uvx command as Install.
BING_WM_ALLOW_WRITES is false here, so writes are planned and you apply them.
Remove that variable for direct writes — see
Choosing a write path. Keep the key in a user-level config,
not in a project file you commit. The server exposes 34 Bing read tools, one local
read-only tool (bing_indexnow_key_plan), plan inspection, and one write tool per
supported operation — direct bing_<operation> tools by default, or
bing_plan_<operation> tools when BING_WM_ALLOW_WRITES=false. It exposes no plan
application or rejection tool. Restart the server after changing the setting so the
client refreshes its tool list.
Claude Code
Project file: .mcp.json in the project root.
Or from the terminal:
Claude Desktop
File: claude_desktop_config.json — macOS
~/Library/Application Support/Claude/claude_desktop_config.json, Windows
%APPDATA%\Claude\claude_desktop_config.json, Linux
~/.config/Claude/claude_desktop_config.json.
One click, without editing JSON: download the .mcpb from
https://github.com/stufently/bing-webmaster-ai-cli-mcp/releases/latest
and open it. Claude Desktop installs the extension and asks for the API key.
Direct writes stay off unless you turn Allow direct writes on. While they are off
the extension only records plans. Applying one needs the bing-wm CLI, which the
extension does not put on your PATH: install it with pip as in Install,
export the same key as BING_WM_API_KEY in that shell, then run bing-wm plan apply.
The release includes checksums.txt with the SHA256 of every .mcpb.
Download that file into the same directory as the bundle and check it before
opening the extension:
On macOS, filter the bundle's line and check it with shasum -a 256 -c -.
Cursor
File: ~/.cursor/mcp.json (every project) or .cursor/mcp.json (this project).
Windsurf
File: mcp_config.json — macOS and Linux ~/.config/devin/mcp_config.json
(or $XDG_CONFIG_HOME/devin/mcp_config.json), Windows
%APPDATA%\devin\mcp_config.json. Older builds read
~/.codeium/windsurf/mcp_config.json.
Zed
File: settings.json — Linux and macOS ~/.config/zed/settings.json.
An optional Streamable HTTP entry point is also available once the package is on
PATH (the pip install above; uvx does not install a lasting command):
It refuses non-loopback bind addresses and unauthenticated requests.
Common questions
Which crawl issues does my site have?
The result carries Bing's rows unchanged plus a category breakdown built from
Microsoft's UrlWithCrawlIssues.CrawlIssues flags — redirects, 4xx, 5xx, robots.txt
blocks, malware, DNS and timeout errors — with a count per category, a count per raw
HttpCode, and an other bucket so nothing Bing sends is dropped. A 4xx row is split
further into http_404 or http_403 from its own HttpCode, alongside the broad
http_4xx rather than instead of it. Bing has no noindex crawl-issue flag, so there
is no such category and this project does not invent one.
How do I check if Bing has indexed my page?
How do I submit URLs to Bing from the command line?
With writes enabled, from one URL or a newline-delimited file:
With BING_WM_ALLOW_WRITES=false, create a plan, review it, then apply it:
The planner calls GetUrlSubmissionQuota; no quota number is hardcoded. Bing's method
documentation also limits one SubmitUrlBatch call to 500 URLs.
Does IndexNow work with Google?
Google does not participate in IndexNow. The live IndexNow registry currently lists
Bing, Yandex, Seznam, Naver, Yep, Internet Archive, and Amazonbot. Submission through
api.indexnow.org fans out to participating engines.
Generate a key, host the displayed UTF-8 key file, then submit:
indexnow key — and the matching bing_indexnow_key_plan MCP tool — only computes and
checks. It talks to neither Bing nor api.indexnow.org, so it is not a write and needs
no plan. The generated key is printed once and stored nowhere: save it, serve it at the
printed URL, then submit.
Or, with BING_WM_ALLOW_WRITES=false:
The submission checks the exact key-file URL without following redirects before it sends the batch. IndexNow hosts must use multi-label DNS names rather than IP literals or single-label names, and the key file must contain only the key. Batches above 10,000 URLs, ambiguous dot-segment paths, and URLs outside the authorized host or key subpath are rejected locally. There is intentionally no unverified 2,048-character URL cap. IndexNow's protocol tells callers to resubmit a valid request after a non-success response, so an HTTP 5xx leaves the plan pending; the CLI never retries it automatically.
Output safety
Anchor text, crawl-issue URLs, titles, messages, and query strings may be controlled by
strangers. The shared operation layer removes control and bidirectional-formatting
characters, truncates extreme values, and returns these fields as
{"value": "…", "untrusted": true}. Consumers must treat them as data, never as
instructions.
Verification secrets never leave the machine by accident. GetUserSites returns
AuthenticationCode and DnsVerificationCode beside every site and GetSiteRoles
returns DelegatedCode; whoever holds one can claim the site in another Bing account.
All three are replaced with [redacted: verification secret] in every response, and the
only way to see one is --reveal-verification-codes typed by an operator on
bing-wm sites list|show|roles or bing-wm plan show|list|apply. No MCP tool takes that
argument, so no model — and no text a model read — can ask for a code.
Redaction is an exit boundary, not a step on the read path. The same filter covers a
write's result, the arguments a plan records — an add_site_roles plan holds the
authentication_code it will send, and showing the plan does not show the code — and
Bing's own error text, in case Bing quotes back the code it rejected. The literals to
hide come from the request body, so the cover does not depend on anyone predicting which
field a secret will next arrive in. The plan record on disk keeps the real value; a plan
that lost its code could not be applied.
The API key is covered at the same boundary, under its own marker
[redacted: API credential]. Microsoft documents the key only as a query-string
parameter, so every request URL carries a live credential — and a proxy naming the
address it could not reach, or Bing quoting the request back in an error, would otherwise
put that URL into the error message, the terminal and the audit trail. An error carrying
no credential reads exactly as it did before.
An empty answer is never presented as a measurement. Some of the older endpoints return
an empty collection for accounts that demonstrably have data: bing_link_counts,
bing_crawl_issues and bing_fetched_urls all came back empty for a site whose
bing_crawl_stats reported 1700 inbound links in the same minute. A read that returned
no rows carries empty_response: {rows_returned: 0, measured: false, note: …} beside
result over MCP, and prints the note on stderr at the CLI, so "Bing returned nothing"
cannot be reported as "no problems found". Reads that answer with a single record —
bing_url_info, bing_crawl_settings, the quotas, bing_keyword — are never labelled:
an array inside one record, such as CrawlRate, is a field of that record
and not a row Bing withheld. bing_url_info labels the same trap in one field:
HttpStatus: 0 means Bing reports no status, not 200, and the row says so with
http_status_reported.
Coverage and references
- Agent skill: how to drive this server
- CLI commands, MCP tools, and write operations
- Complete 62-method Microsoft interface transcription
- Product boundaries
- Configuration
The Microsoft interface contains 62 methods: 59 supported here and three obsolete deep-link methods deliberately excluded. Keyword research is standalone because its official signatures contain no site parameter. Content submission is exposed because it remains present in Microsoft's current interface; account-side eligibility can only be confirmed by Bing for a particular account.
Licence
MIT.
來源:README.md,提交 842d5dd
工具
0版本歷史
1- v0.1.2最新Oct 11, 2026

