{"uid":"cap_wfrZ7iYlJHGrO746sXaIp","slug":"autobus-mcp-registry-drift-detector-b8a22bb9","name":"autobus MCP Registry Drift Detector","description":"Web bot auth debugging for AI agents, priced per check at $0.01. RFC 7638 keyid thumbprint verification, RFC 9421 Ed25519 signature verification, and per-verifier acceptance rules. Signed attestations, published fixtures, sources with dates.","url":"https://witness.holoweave.org/v1/mcp-registry-drift","method":"POST","headers":{},"bodySchema":null,"responseSchema":{"example":{"signature":{"alg":"ed25519","value":"base64...","key_id":"aw-attest-2026-08"},"attestation":{"verdict":"pass","endpoint":"mcp-registry-drift","evidence":{"live":{"reachable":true,"tool_count":8,"server_info":{"name":"autobus","version":"0.2.0"},"surface_digest":"b41c…","protocol_version":"2025-06-18"},"registry":{"name":"io.github.ninefiveonefive/autobus","status":"active","version":"0.2.0","remote_url":"https://witness.holoweave.org/mcp","remote_type":"streamable-http"},"comparison":{"unchanged":true,"version_matches":true}}}}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.01","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"down","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.01/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.01","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_STNjPa_szHBj-WHRsviV3","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.01","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Compares a live MCP server's current tool surface against its registry entry and returns a signed attestation indicating whether they match","exampleAgentPrompt":"Check if the MCP server io.github.ninefiveonefive/autobus has drifted from its registry entry — compare the live tool surface to what the registry says and give me a signed attestation of the result.","exampleUseCases":[{"title":"Detecting unauthorized tool changes","prompt":"Has anything changed in the io.github.example/weather MCP server compared to what the registry says? I want a signed attestation so I can prove the tool surface is still the same as last week."},{"title":"Baseline drift monitoring after deployment","prompt":"I deployed a new version of io.github.myorg/datatools — can you compare the live server to the registry and confirm the tool count and version both match, and give me the surface digest for my records?"},{"title":"Verifying registry consistency before agent handoff","prompt":"Before I hand off to a third-party MCP server io.github.vendor/payments version 1.4.2, can you check whether it matches what the registry has on record and flag any drift?"}],"resultDescription":"A JSON object containing a signed Ed25519 attestation with: a verdict (pass/fail), live server info (reachability, tool count, server name and version, surface digest, protocol version), registry metadata (status, version, remote URL, remote type), and a comparison result indicating whether the tool surface is unchanged and the version matches. The signature includes algorithm, base64 value, and key ID.","failureModes":["Server unreachable — live.reachable returns false, verdict may be fail","Registry entry not found — server name or namespace incorrect","Version mismatch — specified version does not exist in registry","Digest mismatch — expect_digest provided but surface has changed, returns CHANGED","Invalid tools array — malformed tools input causes schema validation error","Payment failure — x402 payment not accepted, returns 402 before processing"],"whenToPreferThis":"Use this endpoint when you need cryptographically signed, independently attested proof that an MCP server's tool surface matches its registry entry — especially before trusting a third-party MCP server, after a deployment, or as part of a continuous integrity monitoring workflow. Prefer this over manual inspection or unauthenticated checks when auditability and non-repudiation matter.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T14:26:52.648Z","isFirstParty":false}