Every change Wellknown observed on this MCP server, newest first, with what it was before and what it became. Tool-surface changes carry the definition diff. Nothing here is edited after the fact.
Added "identity_get_test_key" and "identity_sandbox_register"; changed the definition of "identity_get_challenge", "identity_get_nonce", "identity_jwks" and 3 more (73 tools before, 75 now)
[Wicked Identity] Request a real time-boxed liveness challengefor a registered wallet(constrained-generation task,~12s30s budget).AnswerThe clock starts when this returns: answer in ONE pass via identity_submit_response before `expires_at`.NeedsReal wallet: needs a fresh signednonce.nonce (fetch + sign the nonce for the NEXT call before calling this). Sandbox: just wallet + sandbox_token.
⟨3 unchanged words⟩ ,"properties":{"nonce":{"description":"NonceReal wallet: nonce from a FRESH identity_get_nonce call. Omit for sandbox.","type":"string"},"sandbox_token":{"description":"Sandbox identity: the sandbox_token from identity_sandbox_register. Use INSTEAD of nonce/signature.","type":"string"},"signature":{"description":"Real wallet: 0x-prefixed ECDSA signature over that nonce's message. Omit for sandbox.","type":"string"},"wallet":{"description":"Youragent's0x wallet address onBase.Base, or the sandbox wallet from identity_sandbox_register.","type":"string"}},"required":["wallet","nonce","signature"],"type":"object"}
[Wicked Identity]StepReal-wallet path, step 1: a one-time nonce + message to sign. Every signed identity call needs a fresh nonce (single-use,short5-minute TTL). Not needed for sandbox identities.
⟨3 unchanged words⟩ properties":{"wallet":{"description":"Youragent's0x wallet address onBase.Base, or the sandbox wallet from identity_sandbox_register.","type":"string"}},"required": ⟨3 unchanged words⟩
[Wicked Identity] Public RS256 keys to verify an assertion_token locally. Free. Set sandbox=true for the separate key set that signs sandbox assertions.{"$schema":"http://json-schema.org/draft-07/schema#","properties":{"sandbox":{"description":"true = the sandbox key set (issuer wicked-identity-sandbox).","type":"boolean"}},"type":"object"}
[Wicked Identity] Registeryoura REAL wallet (no stake required). Needs your signature over identity_get_nonce's message; this tool never signs. Sandbox identities are registered by identity_sandbox_register instead.
⟨24 unchanged words⟩ string"},"wallet":{"description":"Youragent's0x wallet address onBase.Base, or the sandbox wallet from identity_sandbox_register.","type":"string"}},"required": ⟨5 unchanged words⟩
⟨7 unchanged words⟩ a valid, unexpired assertion? No signature needed. Pays via x402, or pass api_key (get one free from identity_get_test_key) / set IDENTITY_API_KEY. Sandbox wallets are never `verified`; they report sandbox: true and sandbox_verified instead.
{"$schema":"http://json-schema.org/draft-07/schema#","properties":{"api_key":{"description":"Optional x-api-key, e.g. from identity_get_test_key.","type":"string"},"wallet":{"description":"The 0x wallet address. ⟨6 unchanged words⟩
⟨18 unchanged words⟩ short-lived signed assertion_token (JWT) verifiable via identity_jwks.NeedsReal wallet: needs a DIFFERENT fresh nonce than identity_get_challenge used. Sandbox: wallet + sandbox_token.
⟨11 unchanged words⟩ :"string"},"nonce":{"description":"NonceReal wallet: nonce from a FRESH identity_get_nonce call. Omit for sandbox.","type":"string"},"response_text":{"description":"Your answer exactly as the instructionsspecify.specify: raw text only.","type":"string"},"sandbox_token":{"description":"Sandbox identity: the sandbox_token from identity_sandbox_register. Use INSTEAD of nonce/signature.","type":"string"},"signature":{"description":"Real wallet: 0x-prefixed ECDSA signature over that nonce's message. Omit for sandbox.
[Wicked Identity] Get a free self-serve test API key (7-day expiry, 20 requests/min) to use as api_key on identity_status instead of paying via x402. Limit: 5 per IP per day.
[Wicked Identity] START HERE if you have no wallet or cannot sign messages. Returns a sandbox wallet + sandbox_token (no signing, no body). Then call identity_get_challenge and identity_submit_response with wallet + sandbox_token. Sandbox results are for trying the service: signed with a separate key (identity_jwks sandbox=true) and never reported as verified. Use a real wallet for an accountable identity. Limit: 10 per IP per hour.
Added "registry_create_api_key", "registry_lookup" and "registry_onboarding_message"; changed the definition of "registry_register_tool", "registry_search_tools" and "registry_tool_detail" (70 tools before, 73 now)
⟨9 unchanged words⟩ gets real synthetic checks and a live score.NeedsGetYOURthesignatureexactovermessage"WickedtoRegistrysign—fromToolregistry_onboarding_message(action=register),Registration\nname:
Certificate recorded, valid to 2026-12-29
Authorization not required
Unknown → Live
First tool surface recorded: 70 tools (server version 0.4.0)
npm:wickedapi-mcp (package_npm) — from mcp_registry, with the record
https://mcp.wickedapi.com/mcp (mcp_streamable_http) — from mcp_registry, with the record
Showing the latest 8 events. The API returns up to 500 and filters by kind: ?kind=tool_surface_changed
⟨71 unchanged words⟩ timestamp used in the signed message (within10anminuteshour of the call).","type":"string ⟨11 unchanged words⟩
⟨16 unchanged words⟩ x402 (402 carries payment instructions) or afree-tierfreeREGISTRY_API_KEY.API key (pass api_key, or set REGISTRY_API_KEY). No key yet? Call registry_onboarding_message then registry_create_api_key to get one yourself. For a quick free check of a known tool, use registry_lookup.
{"$schema":"http://json-schema.org/draft-07/schema#","properties":{"api_key":{"description":"Free Wicked Registry API key (wr_...). Overrides REGISTRY_API_KEY.","type":"string"},"category":{"description":"e.g. \"data\", ⟨53 unchanged words⟩
⟨8 unchanged words⟩ history and recent real health checks. x402 orREGISTRY_API_KEY.a free API key.
{"$schema":"http://json-schema.org/draft-07/schema#","properties":{"api_key":{"description":"Free Wicked Registry API key (wr_...). Overrides REGISTRY_API_KEY.","type":"string"},"tool_id":{"description":"Registry id from registry_lookup / registry_search_tools / registry_featured_tools.","type":"string"} ⟨4 unchanged words⟩
[Wicked Registry] Step 2 of getting a free API key. Submit the wallet, the timestamp and YOUR signature over the message from registry_onboarding_message(action=api_key). The key (wr_...) is returned once - store it and pass it as api_key to registry_search_tools / registry_tool_detail. Up to 3 active keys per wallet; past the daily cap calls fall back to x402.
[Wicked Registry] Free lookup: find a tool's id and headline reliability score by name or URL fragment (q), exact endpoint URL (endpoint) or category. No key or payment. Use it to check a tool before your agent pays it; follow with registry_tool_badge or registry_tool_detail.
[Wicked Registry] Step 1 of self-onboarding. Returns the exact message YOU must sign (EIP-191 personal_sign) plus its timestamp, valid for about an hour. action=api_key (needs wallet) for a free API key, or action=register (needs name and endpoint_url) to list your own tool. This tool never signs anything.