Capture and compare an MCP tool manifest

First capture: create a baseline. Later captures: compare the current tool manifest with the previous successful capture. A missing baseline or failed request is never detected drift.

Supported transport: Stateless calls and MCP initialize/session handshakes are supported; capture metadata records stateless_json, stateless_sse, session_json or session_sse. Public HTTPS endpoints returning a JSON or SSE tools/list response only. Authentication, redirects, legacy GET-only SSE, pagination and IPv6-only endpoints are unsupported. Baselines and history are public; new captures are Ed25519-signed, while legacy captures remain unsigned; a change is not proof of an attack.

  1. Enter an endpoint you are authorized to check and whose manifest may be published.
  2. Select Capture baseline / compare. The first successful capture creates a baseline, including an empty tool list.
  3. Return later and capture again. Review any differences before approving the changed tools.

Submitting publishes this endpoint's tool manifest and signed capture. Legacy history remains unsigned.

NO_BASELINE: Select capture to request a current comparison.

{
  "server": "https://northwind-weather.example.com/mcp",
  "name": "Northwind Weather Feed",
  "tracked": true,
  "state": "NO_BASELINE",
  "supported": null,
  "baseline": null,
  "tools": null,
  "signed_capture": null,
  "drift_events": [],
  "drift_detected": null,
  "checked_live": false,
  "limits": "Stateless calls and MCP initialize/session handshakes are supported; capture metadata records stateless_json, stateless_sse, session_json or session_sse. Public HTTPS endpoints returning a JSON or SSE tools/list response only. Authentication, redirects, legacy GET-only SSE, pagination and IPv6-only endpoints are unsupported. Baselines and history are public; new captures are Ed25519-signed, while legacy captures remain unsigned; a change is not proof of an attack."
}

Wait at least 60 seconds between captures. The store is eventually consistent; simultaneous captures may take time to appear. Scheduled monitoring: $29/month per compatible endpoint, best-effort alerts and no guaranteed interval.