First capture: create a baseline. Later captures: compare the current tool manifest with the previous successful capture. A missing baseline or failed request is never detected drift.
Supported transport: Stateless calls and MCP initialize/session handshakes are supported; capture metadata records stateless_json, stateless_sse, session_json or session_sse. Public HTTPS endpoints returning a JSON or SSE tools/list response only. Authentication, redirects, legacy GET-only SSE, pagination and IPv6-only endpoints are unsupported. Baselines and history are public; new captures are Ed25519-signed, while legacy captures remain unsigned; a change is not proof of an attack.
UNSUPPORTED: Select capture to request a current comparison.
{
"server": "https://api.coral-well-demo.example/mcp",
"state": "UNSUPPORTED",
"supported": false,
"tracked": false,
"baseline": null,
"drift_detected": null,
"limits": "Stateless calls and MCP initialize/session handshakes are supported; capture metadata records stateless_json, stateless_sse, session_json or session_sse. Public HTTPS endpoints returning a JSON or SSE tools/list response only. Authentication, redirects, legacy GET-only SSE, pagination and IPv6-only endpoints are unsupported. Baselines and history are public; new captures are Ed25519-signed, while legacy captures remain unsigned; a change is not proof of an attack."
}
Wait at least 60 seconds between captures. The store is eventually consistent; simultaneous captures may take time to appear. Scheduled monitoring: $29/month per compatible endpoint, best-effort alerts and no guaranteed interval.