PubFi MCP
REMOTE · MCP.PUBFI.AI · SCANNED SEP 20
Use MCP 2026-07-28 discovery or 2025-11-25 initialize to list and execute PubFi routes.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security92
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server supports Client ID Metadata Documents, the current MCP client-registration mechanism. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability80
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (good).Pass
- Tool/resource definitions use about 828 tokens (~39/item across 21 items; 4 tools + 17 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage87
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 53% of tool parameters carry a description.Partial
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 6 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the PubFi MCP server?
PubFi MCP is a hosted endpoint at https://mcp.pubfi.ai/, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.pubfi.ai
claude mcp add --transport http ai-pubfi-mcp 'https://mcp.pubfi.ai/'
{
"mcpServers": {
"ai-pubfi-mcp": {
"url": "https://mcp.pubfi.ai/"
}
}
} {
"servers": {
"ai-pubfi-mcp": {
"type": "http",
"url": "https://mcp.pubfi.ai/"
}
}
} [mcp_servers.ai-pubfi-mcp] url = "https://mcp.pubfi.ai/"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"ai-pubfi-mcp": {
"type": "remote",
"url": "https://mcp.pubfi.ai/",
"enabled": true
}
}
} openclaw mcp add ai-pubfi-mcp --url 'https://mcp.pubfi.ai/' --transport streamable-http
mcp_servers:
ai-pubfi-mcp:
url: "https://mcp.pubfi.ai/" {
"McpServers": {
"ai-pubfi-mcp": {
"Transport": "http",
"Url": "https://mcp.pubfi.ai/"
}
}
} assistant mcp add ai-pubfi-mcp -t streamable-http -u 'https://mcp.pubfi.ai/'
{
"mcpServers": {
"ai-pubfi-mcp": {
"type": "http",
"url": "https://mcp.pubfi.ai/"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 19 Sept 26 0
- Server version: 0.2.48 → 0.2.49 functional
- Server version: 0.2.47 → 0.2.48 functional
- 18 Sept 26 0
- Server version: 0.2.46 → 0.2.47 functional
- 17 Sept 26 0
- Resource “alternative-fng OpenAPI” now points somewhere else: pubfi://registry/openapi/alternative-fng/9120171650f00dae192b40556fe44d54f3e23a87c4e7faa893fc62f61e03a9a3 → pubfi://registry/openapi/alternative-fng/d903baed44cbb642f0ff34735b07fbb2129e31ffa22aa076b4753a4f813d474f security
- Resource “curve-v1 OpenAPI” now points somewhere else: pubfi://registry/openapi/curve-v1/bf2408b2d47406f6829a04c3244765a48e1419c098fd2fc3a2519b3a8ef31671 → pubfi://registry/openapi/curve-v1/24ef5f356c16caa61841e1f759e92d723e2bf6685b37cda439b39191392d86c4 security
- Resource “degov OpenAPI” now points somewhere else: pubfi://registry/openapi/degov/f7cbac1007b708347eca7371b2f8ab640a9f2e81dabcd26339ba32a1994b0130 → pubfi://registry/openapi/degov/f570f95cf6f56d7dd304e3f43fae22d7885361c9065b964559116723ccc30760 security
- Resource “ethereum-lists-chains OpenAPI” now points somewhere else: pubfi://registry/openapi/ethereum-lists-chains/0f39a1e1da7b260015fbc7c265577c532f53e5c8cf6a5ad3c3afe35fd10551b5 → pubfi://registry/openapi/ethereum-lists-chains/ca466ee80d512912a4f28eb81b069b1953c1b98585b0aa8b2cc9ac7459c15db7 security
- Resource “goplus-token-security OpenAPI” now points somewhere else: pubfi://registry/openapi/goplus-token-security/d6cdef30ce7df888bc36595dc70c4bafb9e106a3a3383a6591a83e4875eaaa47 → pubfi://registry/openapi/goplus-token-security/ffb664bb81e52b6ba331c5d3854f6defd1c8630ebaa6aebf1c7803494639863b security
- Resource “koios-v1 OpenAPI” now points somewhere else: pubfi://registry/openapi/koios-v1/c063537e84a906ac1cbf47c05cec1859ce63f6401710a598e950862e32788948 → pubfi://registry/openapi/koios-v1/687146edb07c813e13c604c1224154776038a9f93547ca298025d8818165938e security
- Resource “mempool-bitcoin OpenAPI” now points somewhere else: pubfi://registry/openapi/mempool-bitcoin/4e0a58f7ebc5030ef03b8d7c12985afc2cf88fe301e12d0652d47876481b1c31 → pubfi://registry/openapi/mempool-bitcoin/a703ef7de8ddb761693890bae9f2becdf84a5cd84bc6d51f6bf305cb76735a10 security
- Resource “meteora-dlmm OpenAPI” now points somewhere else: pubfi://registry/openapi/meteora-dlmm/65ed3aeab89affdfca17d925cd8fb1e3adfaa784acb98294313fd83384e12325 → pubfi://registry/openapi/meteora-dlmm/acc6633e0e1849a84d74bf05f08829a78d7468083afda5ee03ac9ec5cbfcee89 security
- Resource “orca-v2 OpenAPI” now points somewhere else: pubfi://registry/openapi/orca-v2/67daeb5ab21d596a4d82b77c72f34b57eeabf29b7338a75e994aad7cac2be425 → pubfi://registry/openapi/orca-v2/e8594d7e2c5230841298ce6a1d8608ef64d40b60c825b671a8e0dfae3a18f356 security
- Resource “raydium-v3 OpenAPI” now points somewhere else: pubfi://registry/openapi/raydium-v3/60f4a9cba7083e963699edfb5c3bc663b7bc87974ea6114ab0bf4d62d3d9a60d → pubfi://registry/openapi/raydium-v3/61fed8aa044b043fac6723a21000d410c1e639806714a6e0a9b90c33d957406c security
- Resource “sourcify-server-v2 OpenAPI” now points somewhere else: pubfi://registry/openapi/sourcify-server-v2/5c0c5ae6b779d42a189ae2af5dae7b4d0e213db4ba822488de0ba1217dd0b263 → pubfi://registry/openapi/sourcify-server-v2/0aeca49cc666775023169c6aa70f6fa80f6db22c5f9329ee7e3d86597b07d239 security
- Resource “sourcify-signatures OpenAPI” now points somewhere else: pubfi://registry/openapi/sourcify-signatures/d21137c8347fea44d0ee18df336d892f3e0d39a5f9a6a54a965adcc23e52b50e → pubfi://registry/openapi/sourcify-signatures/de117f1c35842d2f7454b53b362957e4e3e6a6524001ecb3ee840725e79e1126 security
- Resource “subscan OpenAPI” now points somewhere else: pubfi://registry/openapi/subscan/f9395a98ae731ca110dbd351c21af1e68df872c5d21f484f7db67dba603e0468 → pubfi://registry/openapi/subscan/b8d53f1cc29d89bcb174091981cffedc342c832afba2d964d8d4cda902668903 security
- Resource “thegrid-public OpenAPI” now points somewhere else: pubfi://registry/openapi/thegrid-public/30f9d381de3b00961c6c2c27d26887725f4a1c93309a2da043f0c3cb21e127f0 → pubfi://registry/openapi/thegrid-public/7367fe7953fa32d39858e382df64cb51c0682d1d4a0ab6e072467df0ac21e3ec security
- Resource “tzkt-v1 OpenAPI” now points somewhere else: pubfi://registry/openapi/tzkt-v1/415321a631d174bd860d87052d9bde0929e317d514998ac1a68b956262374cc5 → pubfi://registry/openapi/tzkt-v1/89db6fd8c6354b13221b0d7350199c25bf85f765581b14f1d4ce626e1723eeb9 security
- Resource “yearn-kong OpenAPI” now points somewhere else: pubfi://registry/openapi/yearn-kong/b90b3c530da07d69033ad68e6e1f296846390ee97f7e2cf09c3b8398c1936a1a → pubfi://registry/openapi/yearn-kong/6dc1499ac663d1fa6afa2adf727aef29d385ca94021c43f36a8ed323480294f6 security
- Resource “alternative-fng OpenAPI” now points somewhere else: pubfi://registry/openapi/alternative-fng/dda24f8545ae7adaf443b97f09b1b7652099f6b748d013a6a0e3e57a4ccd5da1 → pubfi://registry/openapi/alternative-fng/9120171650f00dae192b40556fe44d54f3e23a87c4e7faa893fc62f61e03a9a3 security
- Resource “curve-v1 OpenAPI” now points somewhere else: pubfi://registry/openapi/curve-v1/4eace59b76419a8d40608453231379c11346df2bc5ec294f06e69df336e2f775 → pubfi://registry/openapi/curve-v1/bf2408b2d47406f6829a04c3244765a48e1419c098fd2fc3a2519b3a8ef31671 security
- Resource “ethereum-lists-chains OpenAPI” now points somewhere else: pubfi://registry/openapi/ethereum-lists-chains/02ca683296317a3343f2f245e2a89e9b50a3c80433cba49793042c11d82daf7c → pubfi://registry/openapi/ethereum-lists-chains/0f39a1e1da7b260015fbc7c265577c532f53e5c8cf6a5ad3c3afe35fd10551b5 security
- Resource “koios-v1 OpenAPI” now points somewhere else: pubfi://registry/openapi/koios-v1/e904c285e855973527832810aa3be8fc69f673e64ade2938917d9fca752b25e4 → pubfi://registry/openapi/koios-v1/c063537e84a906ac1cbf47c05cec1859ce63f6401710a598e950862e32788948 security
- Resource “mempool-bitcoin OpenAPI” now points somewhere else: pubfi://registry/openapi/mempool-bitcoin/cebc8504969408a2ff610b058efc306f20c687e788383bf94c1567edc4dab14c → pubfi://registry/openapi/mempool-bitcoin/4e0a58f7ebc5030ef03b8d7c12985afc2cf88fe301e12d0652d47876481b1c31 security
- Resource “meteora-dlmm OpenAPI” now points somewhere else: pubfi://registry/openapi/meteora-dlmm/7373de3c7331c589328d40897d963f9df2183b58b01a4fb1e3c113970803f967 → pubfi://registry/openapi/meteora-dlmm/65ed3aeab89affdfca17d925cd8fb1e3adfaa784acb98294313fd83384e12325 security
- Resource “orca-v2 OpenAPI” now points somewhere else: pubfi://registry/openapi/orca-v2/cbce35da54fa2c7c8a6aa20719abea361aef60cf3c7d8d6ac2819d085f27ee19 → pubfi://registry/openapi/orca-v2/67daeb5ab21d596a4d82b77c72f34b57eeabf29b7338a75e994aad7cac2be425 security
- Resource “raydium-v3 OpenAPI” now points somewhere else: pubfi://registry/openapi/raydium-v3/b67e3d7ee35f8cae2f181fe0eb04f702e5884c143d1eececae182439edb4ff37 → pubfi://registry/openapi/raydium-v3/60f4a9cba7083e963699edfb5c3bc663b7bc87974ea6114ab0bf4d62d3d9a60d security
- Resource “subscan OpenAPI” now points somewhere else: pubfi://registry/openapi/subscan/2f32ebbea3ded0a4d1352afc009cceaf02d47313e5de8662efcf3bb86ef92608 → pubfi://registry/openapi/subscan/f9395a98ae731ca110dbd351c21af1e68df872c5d21f484f7db67dba603e0468 security
- Resource “tzkt-v1 OpenAPI” now points somewhere else: pubfi://registry/openapi/tzkt-v1/8c8b28624305797371db3016ebbf18332627eb997fe82adbab350e8925ea09af → pubfi://registry/openapi/tzkt-v1/415321a631d174bd860d87052d9bde0929e317d514998ac1a68b956262374cc5 security
- Resource “degov OpenAPI” now points somewhere else: pubfi://registry/openapi/degov/199b93969e1b8421bcacb62fd5514b4290c63b1ad143066ac2e7aff1487cd00c → pubfi://registry/openapi/degov/f7cbac1007b708347eca7371b2f8ab640a9f2e81dabcd26339ba32a1994b0130 security
- Resource “subscan OpenAPI” now points somewhere else: pubfi://registry/openapi/subscan/adba74c3ac939759c2139e87f99202ec8b926053a1f1b7ca53cfbdd3b06f87f4 → pubfi://registry/openapi/subscan/2f32ebbea3ded0a4d1352afc009cceaf02d47313e5de8662efcf3bb86ef92608 security
- Schema quality: 92 → 39 ▲ functional
- Schema quality: 92 → 40 ▲ functional
- New resource “goplus-supported-chains OpenAPI” functional
- New resource “alternative-fng OpenAPI” functional
- New resource “curve-v1 OpenAPI” functional
- New resource “ethereum-lists-chains OpenAPI” functional
- New resource “goplus-token-security OpenAPI” functional
- New resource “koios-v1 OpenAPI” functional
- New resource “mempool-bitcoin OpenAPI” functional
- New resource “meteora-dlmm OpenAPI” functional
- New resource “orca-v2 OpenAPI” functional
- New resource “raydium-v3 OpenAPI” functional
- New resource “sourcify-server-v2 OpenAPI” functional
- New resource “sourcify-signatures OpenAPI” functional
- New resource “thegrid-public OpenAPI” functional
- New resource “tzkt-v1 OpenAPI” functional
- New resource “yearn-kong OpenAPI” functional
- Server version: 0.2.44 → 0.2.46 functional
- Server version: 0.2.42 → 0.2.44 functional
- Server version: 0.2.41 → 0.2.42 functional
- Server version: 0.2.40 → 0.2.41 functional
- Server version: 0.2.38 → 0.2.40 functional
- 15 Sept 26 0
- Resource “degov OpenAPI” now points somewhere else: pubfi://registry/openapi/degov/9ac5dd5f6edc09762cc6df76a9ec8af4cbb6f33ac855ca2eae8da71548f1ba21 → pubfi://registry/openapi/degov/199b93969e1b8421bcacb62fd5514b4290c63b1ad143066ac2e7aff1487cd00c security
- Server version: 0.2.37 → 0.2.38 functional
- Server version: 0.2.36 → 0.2.37 functional
- 14 Sept 26 0
- Resource “subscan OpenAPI” now points somewhere else: pubfi://registry/openapi/subscan/02844f3cbabb037bb123bc862e124e53ae116595d8488c7ca915116127cb65bd → pubfi://registry/openapi/subscan/adba74c3ac939759c2139e87f99202ec8b926053a1f1b7ca53cfbdd3b06f87f4 security
- Resource “degov OpenAPI” now points somewhere else: pubfi://registry/openapi/degov/539bfcc49dd78a06933b1ab38231038516771207800dd7e149db5ac863d4669c → pubfi://registry/openapi/degov/9ac5dd5f6edc09762cc6df76a9ec8af4cbb6f33ac855ca2eae8da71548f1ba21 security
- Server version: 0.2.35 → 0.2.36 functional
- Server version: 0.2.34 → 0.2.35 functional
- 12 Sept 26 +1
- Authorization: partial → pass ▲ security
- Server version: 0.2.33 → 0.2.34 functional
- Server version: 0.2.32 → 0.2.33 functional
- 11 Sept 26 0
- Resource “degov OpenAPI” now points somewhere else: pubfi://registry/openapi/degov/6edf7f40cc2646be8a726997c9ec16a598d4727209a15158ea98e61bcc8e31b2 → pubfi://registry/openapi/degov/539bfcc49dd78a06933b1ab38231038516771207800dd7e149db5ac863d4669c security
- Resource “subscan OpenAPI” now points somewhere else: pubfi://registry/openapi/subscan/48cd6089a3028feb569f68b3d844b4877eff66d575bd56ec631d68f759e1be67 → pubfi://registry/openapi/subscan/02844f3cbabb037bb123bc862e124e53ae116595d8488c7ca915116127cb65bd security
- Server version: 0.2.31 → 0.2.32 functional
- 9 Sept 26 +2
- Resource “degov OpenAPI” now points somewhere else: pubfi://registry/openapi/degov/80f627fee992bccd7e28967fb5514a95e761b02dbff222f55a779e23b6d1115c → pubfi://registry/openapi/degov/6edf7f40cc2646be8a726997c9ec16a598d4727209a15158ea98e61bcc8e31b2 security
- Resource “subscan OpenAPI” now points somewhere else: pubfi://registry/openapi/subscan/0bd4e58a91f541c394fee75587c17d5f6947fd884e9b9b1c7b1ba36a682d2d12 → pubfi://registry/openapi/subscan/48cd6089a3028feb569f68b3d844b4877eff66d575bd56ec631d68f759e1be67 security
- Resource “degov OpenAPI” now points somewhere else: pubfi://registry/openapi/degov/c56a3acf1fe63da913c42d62ef5ba5414621f665b133e084a283a5e6680d1501 → pubfi://registry/openapi/degov/80f627fee992bccd7e28967fb5514a95e761b02dbff222f55a779e23b6d1115c security
- Resource “subscan OpenAPI” now points somewhere else: pubfi://registry/openapi/subscan/46b79dee39fd5977c1db281cd157c82c16491f37d7e90f114955e5b54c70f4f9 → pubfi://registry/openapi/subscan/0bd4e58a91f541c394fee75587c17d5f6947fd884e9b9b1c7b1ba36a682d2d12 security
- Schema quality: unverified → 100 ▲ functional
- Schema quality: fail → pass ▲ functional
- New resource “degov OpenAPI” functional
- New resource “subscan OpenAPI” functional
- Server version: 0.2.29 → 0.2.31 functional
- Server version: 0.2.28 → 0.2.29 functional
- Server version: 0.2.27 → 0.2.28 functional
- Server version: 0.2.26 → 0.2.27 functional
- Server version: 0.2.24 → 0.2.26 functional
- Server version: 0.2.23 → 0.2.24 functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://mcp.pubfi.ai
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=pubfi.ai | CN=YR1,O=Let's Encrypt,C=US | 26 Jul 2026 | 24 Oct 2026 | RSA 2048 | SHA256-RSA | 5d80177f7bedd5ffa22f1031a98b45d5f68 |
| SANs: *.pubfi.ai, pubfi.ai | ||||||
| CN=YR1,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | a20253f15f2691c05dc1ce13b9bcca4e |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.pubfi.ai. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| ai. | present | 3799 | 8 | Verified |
| pubfi.ai. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer resource_metadata="https://mcp.pubfi.ai/.well-known/oauth-protected-resource"
Bearer resource_metadata="https://mcp.pubfi.ai/.well-known/oauth-protected-resource" Protected resource metadata
| Document | https://mcp.pubfi.ai/.well-known/oauth-protected-resource |
|---|---|
| Retrieved | Yes |
| Resource | https://mcp.pubfi.ai |
| Authorisation server | https://mcp.pubfi.ai |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.pubfi.ai | Verified | 200 | |
| http (plaintext) | http://mcp.pubfi.ai | HTTPS enforced | 301 | https://mcp.pubfi.ai/ |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
pubfi.capabilities.get ~54
Return the full typed request, response, metering, and readiness contract for one exact capability id from the installed Registry generation.
| Name | Type | Req | Description |
|---|---|---|---|
| capability_id | string | yes | Exact capability id returned by pubfi.capabilities.list. |
| Name | Type | Req | Description |
|---|---|---|---|
| capability | object | yes | – |
| compiled_at | string | yes | – |
| generation | object | yes | – |
| manifest | object | yes | – |
| observed_at | string | yes | – |
| schema_version | – | yes | – |
No examples provided.
pubfi.capabilities.list ~99
Enumerate the complete installed Registry v2 catalog as deterministic compact pages. The server does not rank, infer intent, or choose a capability.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | Opaque generation-bound cursor returned by the preceding page. |
| limit | integer | – | Maximum compact capability summaries to return. |
| method | string | – | – |
| provider_key | string | – | Optional exact public provider key. This is a static filter, not semantic search. |
| Name | Type | Req | Description |
|---|---|---|---|
| capabilities | array | yes | – |
| compiled_at | string | yes | – |
| filters | object | yes | – |
| generation | object | yes | – |
| manifest | object | yes | – |
| matching_capability_count | integer | yes | – |
| next_cursor | string | – | – |
| observed_at | string | yes | – |
| schema_version | – | yes | – |
| total_capability_count | integer | yes | – |
No examples provided.
pubfi.route.execute ~171
Execute one exact GET or POST path through the authenticated PubFi account lane and the same Registry v2 matcher and typed executor as the HTTP gateway. Append :free only when the capability catalog publishes that exact account-scoped free variant.
| Name | Type | Req | Description |
|---|---|---|---|
| body | string | – | Exact optional ASCII request-body bytes. For JSON routes, supply one compact serialized JSON document rather than a nested MCP argument value. |
| idempotency_key | string | – | – |
| method | string | yes | – |
| query | string | – | Exact ASCII raw query string without a leading question mark. |
| raw_path | string | yes | Exact original URI path consumed by the Registry matcher. Segments use canonical unreserved ASCII only; percent escapes, dot segments, query, fragment, and backslash are forbidden. |
| request_id | string | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
pubfi.substrate.runtime_upgrade.verify ~160
Verify one reviewed Substrate System.apply_authorized_upgrade extrinsic through the authenticated account lane. Supply the expected Blake2b-256 hash of the FRAME System AuthorizedUpgrade code payload, not the active :code hash at the apply block. The server streams and discards provider runtime code, persists only a compact proof, and returns independent comparison evidence.
| Name | Type | Req | Description |
|---|---|---|---|
| expected_authorized_code_hash | string | yes | Canonical lowercase 0x-prefixed 32-byte hash. |
| extrinsic_hash | string | – | Canonical lowercase 0x-prefixed 32-byte hash. |
| extrinsic_index | string | – | – |
| idempotency_key | string | – | – |
| network | string | yes | – |
| request_id | string | – | – |
| Name | Type | Req | Description |
|---|---|---|---|
| computed_code_hash | string | yes | Canonical lowercase 0x-prefixed 32-byte hash. |
| credits_charged | integer | yes | – |
| execution_authority | – | yes | – |
| execution_status | – | yes | – |
| expected_authorized_code_hash | string | yes | Canonical lowercase 0x-prefixed 32-byte hash. |
| extrinsic_hash | string | yes | Canonical lowercase 0x-prefixed 32-byte hash. |
| extrinsic_index | string | yes | – |
| extrinsic_success | boolean | yes | – |
| generation | object | yes | – |
| matches | boolean | yes | – |
| meter_key | string | yes | – |
| ok | – | yes | – |
| provider | object | yes | – |
| provider_response_bytes | integer | yes | – |
| provider_response_sha256 | string | yes | – |
| reserved_units | integer | yes | – |
| route | object | yes | – |
| runtime_code_bytes | integer | yes | – |
| upstream | object | yes | – |
| upstream_latency_ms | integer | yes | – |
| upstream_status | – | yes | – |
No examples provided.
What is the PubFi MCP server?
PubFi MCP is listed in the public MCP registry as ai.pubfi/mcp. Use MCP 2026-07-28 discovery or 2025-11-25 initialize to list and execute PubFi routes. This page covers its hosted endpoint (https://mcp.pubfi.ai).
Is the PubFi MCP server safe to use?
PubFi MCP scores 92 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the PubFi MCP server expose?
PubFi MCP exposes 4 tools: pubfi.capabilities.list, pubfi.capabilities.get, pubfi.route.execute, pubfi.substrate.runtime_upgrade.verify. Their descriptions and schemas cost roughly 484 tokens of context every time the server is loaded.
Does the PubFi MCP server require authentication?
Yes. PubFi MCP asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the PubFi MCP server still maintained?
PubFi MCP is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.