First capture: create a baseline. Later captures: compare the current tool manifest with the previous successful capture. A missing baseline or failed request is never detected drift.
Supported transport: Stateless calls and MCP initialize/session handshakes are supported; capture metadata records stateless_json, stateless_sse, session_json or session_sse. Public HTTPS endpoints returning a JSON or SSE tools/list response only. Authentication, redirects, legacy GET-only SSE, pagination and IPv6-only endpoints are unsupported. Baselines and history are public; new captures are Ed25519-signed, while legacy captures remain unsigned; a change is not proof of an attack.
BASELINE_AVAILABLE: Stored history only. Capture again to compare the current manifest.
{
"server": "https://mcp.api.coingecko.com/mcp",
"tracked": true,
"supported": true,
"state": "BASELINE_AVAILABLE",
"checked_live": false,
"baseline": {
"manifest_hash": "fe1f70f755ed96802a5ffa67c19f03ffb00b8c9917cbf6f2f1196c28bedaaa98",
"tool_count": 2,
"captured_at": "2026-10-07T12:25:23.573Z"
},
"tools": [
{
"name": "execute",
"description": "Runs JavaScript code to interact with the Coingecko API.\n\nYou are a skilled TypeScript programmer writing code to interface with the service.\nDefine an async function named \"run\" that takes a single parameter of an initialized SDK client and it will be run.\nFor example:\n\n```\nasync function run(client) {\n const price = await client.simple.price.get({ vs_currencies: 'usd', ids: 'bitcoin' });\n}\n```\n\nYou will be returned anything that your function returns, plus the results of any console.log statements.\nDo not add try-catch blocks for single API calls. The tool will handle errors for you.\nDo not add comments unless necessary for generating better code.\nCode will run in a container, and cannot interact with the network outside of the given SDK client.\nVariables will not persist between calls, so make sure to return or log any data you might need later.\nRemember that you are writing TypeScript code, so you need to be careful with your types.\nAlways type dynamic key-value stores explicitly as Record<string, YourValueType> instead of {}.",
"inputSchema": {
"properties": {
"code": {
"description": "Code to execute.",
"type": "string"
},
"intent": {
"description": "Task you are trying to perform. Used for improving the service.",
"type": "string"
}
},
"required": [
"code"
],
"type": "object"
}
},
{
"name": "search_docs",
"description": "Search SDK documentation to find methods, parameters, and usage examples for interacting with the API. Use this before writing code when you need to discover the right approach.",
"inputSchema": {
"properties": {
"detail": {
"description": "The amount of detail to return.",
"enum": [
"default",
"verbose"
],
"type": "string"
},
"language": {
"description": "The language for the SDK to search for.",
"enum": [
"http",
"python",
"go",
"typescript",
"javascript",
"terraform",
"ruby",
"java",
"kotlin"
],
"type": "string"
},
"query": {
"description": "The query to search for.",
"type": "string"
}
},
"required": [
"query",
"language"
],
"type": "object"
}
}
],
"drift_detected": null,
"drift_events": [],
"limits": "Stateless calls and MCP initialize/session handshakes are supported; capture metadata records stateless_json, stateless_sse, session_json or session_sse. Public HTTPS endpoints returning a JSON or SSE tools/list response only. Authentication, redirects, legacy GET-only SSE, pagination and IPv6-only endpoints are unsupported. Baselines and history are public; new captures are Ed25519-signed, while legacy captures remain unsigned; a change is not proof of an attack.",
"signed_capture": {
"alg": "Ed25519",
"kid": "capture-a46fe710c055398f3b6f43a1",
"payload": {
"schema": "dominion.capture.v1",
"server_url": "https://mcp.api.coingecko.com/mcp",
"captured_at": "2026-10-07T12:25:23.573Z",
"capture": {
"tools": [
{
"name": "execute",
"description": "Runs JavaScript code to interact with the Coingecko API.\n\nYou are a skilled TypeScript programmer writing code to interface with the service.\nDefine an async function named \"run\" that takes a single parameter of an initialized SDK client and it will be run.\nFor example:\n\n```\nasync function run(client) {\n const price = await client.simple.price.get({ vs_currencies: 'usd', ids: 'bitcoin' });\n}\n```\n\nYou will be returned anything that your function returns, plus the results of any console.log statements.\nDo not add try-catch blocks for single API calls. The tool will handle errors for you.\nDo not add comments unless necessary for generating better code.\nCode will run in a container, and cannot interact with the network outside of the given SDK client.\nVariables will not persist between calls, so make sure to return or log any data you might need later.\nRemember that you are writing TypeScript code, so you need to be careful with your types.\nAlways type dynamic key-value stores explicitly as Record<string, YourValueType> instead of {}.",
"inputSchema": {
"properties": {
"code": {
"description": "Code to execute.",
"type": "string"
},
"intent": {
"description": "Task you are trying to perform. Used for improving the service.",
"type": "string"
}
},
"required": [
"code"
],
"type": "object"
}
},
{
"name": "search_docs",
"description": "Search SDK documentation to find methods, parameters, and usage examples for interacting with the API. Use this before writing code when you need to discover the right approach.",
"inputSchema": {
"properties": {
"detail": {
"description": "The amount of detail to return.",
"enum": [
"default",
"verbose"
],
"type": "string"
},
"language": {
"description": "The language for the SDK to search for.",
"enum": [
"http",
"python",
"go",
"typescript",
"javascript",
"terraform",
"ruby",
"java",
"kotlin"
],
"type": "string"
},
"query": {
"description": "The query to search for.",
"type": "string"
}
},
"required": [
"query",
"language"
],
"type": "object"
}
}
],
"metadata": {
"probe_mode": "session_sse",
"protocol_version": "2025-11-25"
}
},
"tools_list_sha256": "fe1f70f755ed96802a5ffa67c19f03ffb00b8c9917cbf6f2f1196c28bedaaa98"
},
"signature": "sgxaa23Ifix-ljgyX5DY6sYhxy_1qSY2YmmFGgucGOowYDl8EWr5K9QlHAs-En8V5-3grd6kUt7iG_UDiYTjDw"
},
"note": "Stored history only. Capture again to compare the current manifest."
}
Wait at least 60 seconds between captures. The store is eventually consistent; simultaneous captures may take time to appear. Scheduled monitoring: $29/month per compatible endpoint, best-effort alerts and no guaranteed interval.