MCP TOOL-CHANGE MONITORING

Know when your MCP
tools change.

Track changes to tool names, descriptions and input schemas. Get email or webhook alerts from scheduled checks of compatible public MCP endpoints.

New captures are Ed25519-signed. See a sample change report →

47,555
Projects indexed
311
Projects with runtime measurements
9
Endpoints previously checked

Last verified
Cached statistics; indexing and runtime measurements are separate.

Coverage and monitoring limits

Listed projects are an index only, not a monitored fleet.

47,555 indexed projects · 82 endpoint candidates · 9 endpoints previously checked ; 311 projects with runtime measurements. Listed projects are not necessarily monitored. Coverage last verified Oct 11, 2026, 4:37 AM UTC. Cached coverage; confirmed live means previously observed, not a current uptime guarantee. UNRATED means not measured.

Manifest history is public. Legacy captures remain unsigned. Detection intervals are not guaranteed, and a changed definition alone does not establish a security issue. Read the monitoring guide.

Gate risky MCP servers in CI — fail the build below your trust threshold
# Fail-closed policy: UNRATED, NOT FOUND, errors and scores below 70 block.
# Requires curl 7.76+ and jq. Set MCP_URL to the intended server URL.
: "${MCP_URL:?Set MCP_URL first}"
if ! response=$(curl --fail-with-body --silent --show-error --get   --data-urlencode "url=$MCP_URL" "https://dominionobservatory.com/api/trust"); then
  echo "Blocked: registry request failed" >&2; exit 1
fi
if ! printf '%s' "$response" | jq -e '
  type == "object" and .found == true and .runtime_measured == true
  and (.error == null) and (.trust_score | type == "number")
  and (.trust_score >= 70 and .trust_score <= 100)' >/dev/null; then
  echo "Blocked: UNRATED, missing, invalid response or below policy" >&2; exit 1
fi
echo "Measured score meets policy; this does not guarantee safety."

This example fails closed. A fail-open policy may log a warning and continue after independent review, but must never label an unknown or failed lookup as a passing trust check.

Why teams scan with Observatory

47,555 projects indexed. Behavioral scores are available only for servers with measured runtime data. Other projects are UNRATED, with a null trust score. Receipts support evidence review; they do not guarantee safety or compliance.

🛡

Trust Verification

Servers with measured runtime data can receive behavioral scores based on observed reliability. Indexed projects without measurements are UNRATED (not measured). An API error is an unavailable assessment, not a passing result.

📋

Compliance Attestation

Tamper-evident, machine-readable runtime records designed to support audit evidence, internal governance, and applicable record-keeping assessments. Legal compliance depends on your organisation, system classification, and deployment context — a Dominion receipt alone does not establish compliance.

🌐

Gateway Proxy

Route any MCP server through Observatory. Trust checks happen transparently. No code changes needed — just change the URL.

📊

Behavioral Baselines

Cross-ecosystem reliability baselines built from agent-reported telemetry. Data that ages into compounding value.

⚡

AIO Audit

Agent Information Optimization — check any MCP server's discoverability to AI agents. Scores llms.txt, agent.json, registry presence, and more. Try it free →

💳

Priced for teams, not experiments

Scan your first server free. CI/monitoring plans for platform teams, and a Compliance tier with signed attestations for audit and vendor-risk reviews. See pricing →

Works with your stack

Install a package. Add one line. Trust checks are automatic.

LangChainpip install langchain-mcp-trust-gate
CrewAIpip install crewai-dominion-trust
OpenAI Agentspip install openai-agents-trust-gate
Any MCP clientpython -m pip install dominion-trust-check

Score Changes

Trust scores that moved in the last 72 hours · Feed refreshed 2026-10-11T21:02:18.729Z

SAP MCP endpointuncategorized↑ +38.867
sg-company-lookup-mcpdata↓ -7.560
SAP MCP endpointuncategorized↓ -7.267
sg-company-lookup-mcpdata↓ -6.360
some-server.com (via gateway)uncategorized↓ -5.427
some-server.com (via gateway)uncategorized↓ -5.127
Context7 public MCP endpointuncategorized↑ +584
@watb/mcp-serverother↑ +4.934
Context7 public MCP endpointuncategorized↑ +4.684
GitHub Copilot MCPcode↑ +4.537
@impart-security/impart-mcpsecurity↑ +3.936

View all servers →

Pricing

Scan one server free. Pay when MCP trust becomes part of how your team ships.

Free
$0
  • Scan any server on demand
  • Trust score + SLA grade
  • Public report page
  • No signup required
Scan a server
Compliance
$0.10 /query
  • Everything in Team / CI
  • Signed attestations for evidence review
  • EU AI Act Art. 12 & MiCA receipts
  • Vendor-risk & audit-trail exports
Get an API key
Built an MCP server? Get it MCP Verified ✓

A signed, dated, independently-verifiable trust badge for your README — $29 one-time, self-serve, no sales call.

Get verified — $29 →

Run a registry, gateway, or marketplace? License the trust feed and show a trust score on every server you list.

Review the evidence for your MCP servers

Scan your first server free — no signup. Add it to CI when you're ready.

Scan a Server Free