MCP TOOL-CHANGE MONITORING
Know when your MCP
tools change.
Track changes to tool names, descriptions and input schemas. Get email or webhook alerts from scheduled checks of compatible public MCP endpoints.
New captures are Ed25519-signed. See a sample change report →
Last verified
Cached statistics; indexing and runtime measurements are separate.
Coverage and monitoring limits
Listed projects are an index only, not a monitored fleet.
47,555 indexed projects · 82 endpoint candidates · 9 endpoints previously checked ; 311 projects with runtime measurements. Listed projects are not necessarily monitored. Coverage last verified Oct 11, 2026, 4:37 AM UTC. Cached coverage; confirmed live means previously observed, not a current uptime guarantee. UNRATED means not measured.
Manifest history is public. Legacy captures remain unsigned. Detection intervals are not guaranteed, and a changed definition alone does not establish a security issue. Read the monitoring guide.
# Fail-closed policy: UNRATED, NOT FOUND, errors and scores below 70 block.
# Requires curl 7.76+ and jq. Set MCP_URL to the intended server URL.
: "${MCP_URL:?Set MCP_URL first}"
if ! response=$(curl --fail-with-body --silent --show-error --get --data-urlencode "url=$MCP_URL" "https://dominionobservatory.com/api/trust"); then
echo "Blocked: registry request failed" >&2; exit 1
fi
if ! printf '%s' "$response" | jq -e '
type == "object" and .found == true and .runtime_measured == true
and (.error == null) and (.trust_score | type == "number")
and (.trust_score >= 70 and .trust_score <= 100)' >/dev/null; then
echo "Blocked: UNRATED, missing, invalid response or below policy" >&2; exit 1
fi
echo "Measured score meets policy; this does not guarantee safety."
This example fails closed. A fail-open policy may log a warning and continue after independent review, but must never label an unknown or failed lookup as a passing trust check.
Why teams scan with Observatory
47,555 projects indexed. Behavioral scores are available only for servers with measured runtime data. Other projects are UNRATED, with a null trust score. Receipts support evidence review; they do not guarantee safety or compliance.
Trust Verification
Servers with measured runtime data can receive behavioral scores based on observed reliability. Indexed projects without measurements are UNRATED (not measured). An API error is an unavailable assessment, not a passing result.
Compliance Attestation
Tamper-evident, machine-readable runtime records designed to support audit evidence, internal governance, and applicable record-keeping assessments. Legal compliance depends on your organisation, system classification, and deployment context — a Dominion receipt alone does not establish compliance.
Gateway Proxy
Route any MCP server through Observatory. Trust checks happen transparently. No code changes needed — just change the URL.
Behavioral Baselines
Cross-ecosystem reliability baselines built from agent-reported telemetry. Data that ages into compounding value.
AIO Audit
Agent Information Optimization — check any MCP server's discoverability to AI agents. Scores llms.txt, agent.json, registry presence, and more. Try it free →
Priced for teams, not experiments
Scan your first server free. CI/monitoring plans for platform teams, and a Compliance tier with signed attestations for audit and vendor-risk reviews. See pricing →
Works with your stack
Install a package. Add one line. Trust checks are automatic.
pip install langchain-mcp-trust-gatepip install crewai-dominion-trustpip install openai-agents-trust-gatepython -m pip install dominion-trust-checkScore Changes
Trust scores that moved in the last 72 hours · Feed refreshed 2026-10-11T21:02:18.729Z
Pricing
Scan one server free. Pay when MCP trust becomes part of how your team ships.
- Scan any server on demand
- Trust score + SLA grade
- Public report page
- No signup required
- Unlimited scans via API
- Gate builds on a trust threshold
- Latency percentiles + history
- Monitoring & score-change alerts
- Everything in Team / CI
- Signed attestations for evidence review
- EU AI Act Art. 12 & MiCA receipts
- Vendor-risk & audit-trail exports
A signed, dated, independently-verifiable trust badge for your README — $29 one-time, self-serve, no sales call.
Get verified — $29 →Run a registry, gateway, or marketplace? License the trust feed and show a trust score on every server you list.
Review the evidence for your MCP servers
Scan your first server free — no signup. Add it to CI when you're ready.
Scan a Server Free