Every change Wellknown observed on this MCP server, newest first, with what it was before and what it became. Tool-surface changes carry the definition diff. Nothing here is edited after the fact.
Changed the definition of "accept_hook_event", "get_destination_status", "get_hook_credits" and 6 more
before
—after
Accept Hook EventEnqueueanupeventto 65536 payload bytes foryoura previously verified receiver using its delivery token. Returns a deliveryId,idempotentnotbyproof of delivery. Reuse eventId and exactbytes.bytes on retries, then poll get_hook_delivery. The free allowance is 100 events/day per verified receiver; extra admissions consume purchased credits. No arbitrary destination can be supplied here.
⟨25 unchanged words⟩ ,"type":"string"},"contentType":{"description":"Media type of the decoded payload bytes; JSON must be encoded as UTF-8 before base64 conversion.","enum":["application/json","text/plain","application/octet-stream"],"type":"string"},"eventId":{"description":"Stable caller-chosen event identifier, for example order-20261007-01. Reuse with identical payload bytes on retry; different bytes under the same ID are rejected.","pattern":"^[A-Za-z0-9][A-Za-z0-9._:-]{0, ⟨22 unchanged words⟩ string"},"token":{"description":"Private32-bytedeliverysecrettokenencodedreturnedasby64registration;lowercaseauthenticateshexadecimaleventcharacters.submission,Neverdeliveryexposelookupin
before
—after
Get Destination StatusReadverification/revocationthestatusexisting hook ownership challenge andchallenge.verification or revocation status using its management token. No activation or delivery. Use after registration or an interrupted verification; use get_hook_delivery for one accepted event.
⟨24 unchanged words⟩ string"},"managementToken":{"description":"Private32-bytemanagementsecrettoken
before
—after
Get Hook CreditsReadyourremainingextrapurchased admissioncreditcreditsbalance.for an existing hook using its management token. Free and read-only; does not purchase credits. Use purchase_hook_credits to request a quote. The daily free allowance remains separate.
⟨24 unchanged words⟩ string"},"managementToken":{"description":"Private32-bytemanagementsecrettoken
before
—after
Get Hook DeliveryRead one accepted event by its returned deliveryId and hook deliverystatetoken. Poll after accept_hook_event to distinguish queued, retried andsignedcompletedobservations.delivery. Signed observations attest relay attempts, not successful business processing by the receiver. No new delivery or payment.
⟨61 unchanged words⟩ string"},"token":{"description":"Private32-bytedeliverysecret
before
—after
Purchase Hook Credits⟨24 unchanged words⟩ string"},"managementToken":{"description":"Private32-bytemanagementsecrettokenencodedreturnedasby64registration.lowercaseRequiredhexadecimalforcharacters.status,Neveractivation,
before
—after
Register DestinationCreateRegister anisolatedHTTPSaccess.receiver you control. Returns hookId, private credentials and the ownership challenge; delivery remains inactive. Publish the exact challenge on your origin, then call verify_destination. Keep recoveryKey secret and reuse itonlywith thesameidentical targetonafterretries.interruption; do not register again with a new key.
before
—after
Revoke DestinationPermanently revokeclientthisaccess.hookPreviouslywith its management token after explicit owner approval. New submissions are rejected; previously accepted deliveries finish. This does not cancel queued events and cannot be undone. Use get_destination_status first if you only need to inspect access.
⟨24 unchanged words⟩ string"},"managementToken":{"description":"Private32-bytemanagementsecret
before
—after
Verify DestinationVerifyFetch thewell-knownownership challengefilefrom the previously registered receiver and activateyouritdestination.when valid. First publish the exact challenge returned by register_destination. Requires the management token; does not deliver an event. Use get_destination_status to inspect progress without activation.
⟨24 unchanged words⟩ string"},"managementToken":{"description":"Private
before
—after
Verify Hook ReceiptVerifyCheckaanrelayunchanged event and signed receipt returned by get_hook_delivery withinyourthe authenticated hook. Requires the delivery token; does not send an event. A valid signature attests relay observations, not business truth or exactly-once processing.
⟨6 unchanged words⟩ ":{"event":{"additionalProperties":{},"
Changed the definition of "accept_hook_event", "get_destination_status", "get_hook_credits" and 6 more
before
—after
Accept Hook EventEnqueueanupeventto 65536 payload bytes foryoura previously verified receiver using its delivery token. Returns a deliveryId,idempotentnotby
Certificate recorded, valid to 2026-12-02
Authorization not required
First tool surface recorded: 9 tools (server version 0.7.8)
https://datoka-hooks.bhazarstudio.workers.dev/mcp (mcp_streamable_http) — from mcp_registry
Changed the definition of "accept_hook_event", "get_destination_status", "get_hook_credits" and 6 more
{"$schema":"httphttps://json-schema.org/draft-07/schema#//json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"bodyBase64":{"description":"Canonical base64 payload, at most 65536 decoded bytes. Preserve exact bytes with eventId on retries.","maxLength":87384,"type":"string"},"contentType ⟨15 unchanged words⟩ ,"type":"string"},"hookId":{"description":"Hook identifier returned by registration; preserve for all subsequent operations.","pattern":"^pub-[a-f0-9]{32}$","type":"string"},"token":{"description":"Private 32-byte secret encoded as 64 lowercase hexadecimal characters. Never expose in logs.","pattern":"^[a-f0-9]{64}$"," ⟨10 unchanged words⟩
Certificate recorded, valid to 2026-12-02
Authorization not required
Added "get_hook_credits" and "purchase_hook_credits" (7 tools before, 9 now)
Read your extra admission credit balance.
Request an x402 quote without payment, or buy credits with an explicitly authorized signed payment. Reuse purchaseId and the same payment after any timeout.
Unknown → Live
First tool surface recorded: 7 tools (server version 0.4.0)
https://datoka-hooks-test.bhazarstudio.workers.dev/mcp (mcp_streamable_http) — from mcp_registry, with the record
Showing the latest 13 events. The API returns up to 500 and filters by kind: ?kind=tool_surface_changed
⟨5 unchanged words⟩ ,"properties":{"recoveryKey":{"description":"PrivateGenerate32-byte32secretrandomencodedbytes locally and encode as 64 lowercasehexadecimalhex characters.NeverSaveexposeprivatelyinbeforelogs.registration; reuse with the identical target after interruption.","pattern":"^[a-f0-9]{64}$" ⟨25 unchanged words⟩
⟨25 unchanged words⟩ ,"type":"string"},"contentType":{"description":"Media type of the decoded payload bytes; JSON must be encoded as UTF-8 before base64 conversion.","enum":["application/json","text/plain","application/octet-stream"],"type":"string"},"eventId":{"description":"Stable caller-chosen event identifier, for example order-20261007-01. Reuse with identical payload bytes on retry; different bytes under the same ID are rejected.","pattern":"^[A-Za-z0-9][A-Za-z0-9._:-]{0, ⟨22 unchanged words⟩ string"},"token":{"description":"Private32-bytedeliverysecrettokenencodedreturnedasby64registration;lowercaseauthenticateshexadecimaleventcharacters.submission,Neverdeliveryexposelookupinandlogs.receipt verification for this hook.","pattern":"^[a-f0-9]{64}$" ⟨10 unchanged words⟩
before
—after
Get Destination StatusReadverification/revocationthestatusexisting hook ownership challenge andchallenge.verification or revocation status using its management token. No activation or delivery. Use after registration or an interrupted verification; use get_hook_delivery for one accepted event.
⟨24 unchanged words⟩ string"},"managementToken":{"description":"Private32-bytemanagementsecrettokenencodedreturnedasby64registration.lowercaseRequiredhexadecimalforcharacters.status,Neveractivation,exposerevocationinandlogs.credits; not the delivery token.","pattern":"^[a-f0-9]{64}$" ⟨7 unchanged words⟩
before
—after
Get Hook CreditsReadyourremainingextrapurchased admissioncreditcreditsbalance.for an existing hook using its management token. Free and read-only; does not purchase credits. Use purchase_hook_credits to request a quote. The daily free allowance remains separate.
⟨24 unchanged words⟩ string"},"managementToken":{"description":"Private32-bytemanagementsecrettokenencodedreturnedasby64registration.lowercaseRequiredhexadecimalforcharacters.status,Neveractivation,exposerevocationinandlogs.credits; not the delivery token.","pattern":"^[a-f0-9]{64}$" ⟨7 unchanged words⟩
before
—after
Get Hook DeliveryRead one accepted event by its returned deliveryId and hook deliverystatetoken. Poll after accept_hook_event to distinguish queued, retried andsignedcompletedobservations.delivery. Signed observations attest relay attempts, not successful business processing by the receiver. No new delivery or payment.
⟨61 unchanged words⟩ string"},"token":{"description":"Private32-bytedeliverysecrettokenencodedreturnedasby64registration;lowercaseauthenticateshexadecimaleventcharacters.submission,Neverdeliveryexposelookupinandlogs.receipt verification for this hook.","pattern":"^[a-f0-9]{64}$" ⟨8 unchanged words⟩
before
—after
Purchase Hook Credits⟨24 unchanged words⟩ string"},"managementToken":{"description":"Private32-bytemanagementsecrettokenencodedreturnedasby64registration.lowercaseRequiredhexadecimalforcharacters.status,Neveractivation,exposerevocationinandlogs.credits; not the delivery token.","pattern":"^[a-f0-9]{64}$","type":"string"},"payment":{"additionalProperties":{},"description":"Original signed x402 payment payload authorized by the payer. Omit to request a quote without paying. Never fabricate or replace an uncertain authorization.","propertyNames":{"type":"string"},"type":"object"},"purchaseId":{"description":"Unique caller-chosen purchase identifier, for example credits-20261007-01. Save before requesting the quote and reuse unchanged with the same payment on retries.","pattern":"^[A-Za-z0-9][A-Za-z0-9._:-]{0 ⟨10 unchanged words⟩
before
—after
Register DestinationCreateRegister anisolatedHTTPSaccess.receiver you control. Returns hookId, private credentials and the ownership challenge; delivery remains inactive. Publish the exact challenge on your origin, then call verify_destination. Keep recoveryKey secret and reuse itonlywith thesameidentical targetonafterretries.interruption; do not register again with a new key.
⟨5 unchanged words⟩ ,"properties":{"recoveryKey":{"description":"PrivateGenerate32-byte32secretrandomencodedbytes locally and encode as 64 lowercasehexadecimalhex characters.NeverSaveexposeprivatelyinbeforelogs.registration; reuse with the identical target after interruption.","pattern":"^[a-f0-9]{64}$" ⟨25 unchanged words⟩
before
—after
Revoke DestinationPermanently revokeclientthisaccess.hookPreviouslywith its management token after explicit owner approval. New submissions are rejected; previously accepted deliveries finish. This does not cancel queued events and cannot be undone. Use get_destination_status first if you only need to inspect access.
⟨24 unchanged words⟩ string"},"managementToken":{"description":"Private32-bytemanagementsecrettokenencodedreturnedasby64registration.lowercaseRequiredhexadecimalforcharacters.status,Neveractivation,exposerevocationinandlogs.credits; not the delivery token.","pattern":"^[a-f0-9]{64}$" ⟨7 unchanged words⟩
before
—after
Verify DestinationVerifyFetch thewell-knownownership challengefilefrom the previously registered receiver and activateyouritdestination.when valid. First publish the exact challenge returned by register_destination. Requires the management token; does not deliver an event. Use get_destination_status to inspect progress without activation.
⟨24 unchanged words⟩ string"},"managementToken":{"description":"Private32-bytemanagementsecrettokenencodedreturnedasby64registration.lowercaseRequiredhexadecimalforcharacters.status,Neveractivation,exposerevocationinandlogs.credits; not the delivery token.","pattern":"^[a-f0-9]{64}$" ⟨7 unchanged words⟩
before
—after
Verify Hook ReceiptVerifyCheckaanrelayunchanged event and signed receipt returned by get_hook_delivery withinyourthe authenticated hook. Requires the delivery token; does not send an event. A valid signature attests relay observations, not business truth or exactly-once processing.
⟨6 unchanged words⟩ ":{"event":{"additionalProperties":{},"description":"Exact event object returned with the relay receipt; preserve all fields.","propertyNames":{"type":"string"},"type" ⟨20 unchanged words⟩ "},"receipt":{"additionalProperties":{},"description":"Exact signed relay receipt from delivery lookup. Do not substitute issuer keys or edit its fields.","propertyNames":{"type":"string"},"type":"object"},"token":{"description":"Private32-bytedeliverysecrettokenencodedreturnedasby64registration;lowercaseauthenticateshexadecimaleventcharacters.submission,Neverdeliveryexposelookupinandlogs.receipt verification for this hook.","pattern":"^[a-f0-9]{64}$" ⟨9 unchanged words⟩
{"$schema":"httphttps://json-schema.org/draft-07/schema#//json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"hookId":{"description":"Hook identifier returned by registration; preserve for all subsequent operations.","pattern":"^pub-[a-f0-9]{32}$","type":"string"},"managementToken":{"description":"Private 32-byte secret encoded as 64 lowercase hexadecimal characters. Never expose in logs.","pattern":"^[a-f0-9]{64}$"," ⟨7 unchanged words⟩
{"$schema":"httphttps://json-schema.org/draft-07/schema#//json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"hookId":{"description":"Hook identifier returned by registration; preserve for all subsequent operations.","pattern":"^pub-[a-f0-9]{32}$","type":"string"},"managementToken":{"description":"Private 32-byte secret encoded as 64 lowercase hexadecimal characters. Never expose in logs.","pattern":"^[a-f0-9]{64}$"," ⟨7 unchanged words⟩
{"$schema":"httphttps://json-schema.org/draft-07/schema#//json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"deliveryId":{"description":"Delivery identifier returned on event acceptance; acceptance does not mean delivered.","format":"uuid","pattern":"^([0-9a-fA-F ⟨17 unchanged words⟩ ,"type":"string"},"hookId":{"description":"Hook identifier returned by registration; preserve for all subsequent operations.","pattern":"^pub-[a-f0-9]{32}$","type":"string"},"token":{"description":"Private 32-byte secret encoded as 64 lowercase hexadecimal characters. Never expose in logs.","pattern":"^[a-f0-9]{64}$"," ⟨8 unchanged words⟩
{"$schema":"httphttps://json-schema.org/draft-07/schema#//json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"hookId":{"description":"Hook identifier returned by registration; preserve for all subsequent operations.","pattern":"^pub-[a-f0-9]{32}$","type":"string"},"managementToken":{"description":"Private 32-byte secret encoded as 64 lowercase hexadecimal characters. Never expose in logs.","pattern":"^[a-f0-9]{64}$"," ⟨26 unchanged words⟩
{"$schema":"httphttps://json-schema.org/draft-07/schema#//json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"recoveryKey":{"description":"Private 32-byte secret encoded as 64 lowercase hexadecimal characters. Never expose in logs.","pattern":"^[a-f0-9]{64}$","type":"string"},"target":{"description":"HTTPS receiver you control; ownership challenge is required before delivery.","format":"uri","maxLength":2048,"type ⟨6 unchanged words⟩
{"$schema":"httphttps://json-schema.org/draft-07/schema#//json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"hookId":{"description":"Hook identifier returned by registration; preserve for all subsequent operations.","pattern":"^pub-[a-f0-9]{32}$","type":"string"},"managementToken":{"description":"Private 32-byte secret encoded as 64 lowercase hexadecimal characters. Never expose in logs.","pattern":"^[a-f0-9]{64}$"," ⟨7 unchanged words⟩
{"$schema":"httphttps://json-schema.org/draft-07/schema#//json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"hookId":{"description":"Hook identifier returned by registration; preserve for all subsequent operations.","pattern":"^pub-[a-f0-9]{32}$","type":"string"},"managementToken":{"description":"Private 32-byte secret encoded as 64 lowercase hexadecimal characters. Never expose in logs.","pattern":"^[a-f0-9]{64}$"," ⟨7 unchanged words⟩
{"$schema":"httphttps://json-schema.org/draft-07/schema#//json-schema.org/draft/2020-12/schema","additionalProperties":false,"properties":{"event" ⟨4 unchanged words⟩ ,"type":"object"},"hookId":{"description":"Hook identifier returned by registration; preserve for all subsequent operations.","pattern":"^pub-[a-f0-9]{32}$","type ⟨6 unchanged words⟩ },"type":"object"},"token":{"description":"Private 32-byte secret encoded as 64 lowercase hexadecimal characters. Never expose in logs.","pattern":"^[a-f0-9]{64}$"," ⟨9 unchanged words⟩