Rokha
REMOTE · ROKHA.AI · SCANNED OCT 3
Search a registry of agent skills and MCP servers, then run them for real. No install, traced.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security94
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents. View diagnostics → Partial
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability78
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 35100 tokens (~166/item across 211 items; 211 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management12
- Stability check failed: schema churn in the 7 days we've observed: 11 tool removals, 11 breaking changes, 0 auth/transport breaks, 81 additions. See how to fix → Fail
Tool Coverage88
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 65% of tool parameters carry a description.Partial
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 11 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 212 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the Rokha MCP server?
Rokha is a hosted endpoint at https://rokha.ai/mcp/jsonrpc, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · rokha.ai
claude mcp add --transport http ai-rokha-rokha 'https://rokha.ai/mcp/jsonrpc'
{
"mcpServers": {
"ai-rokha-rokha": {
"url": "https://rokha.ai/mcp/jsonrpc"
}
}
} {
"servers": {
"ai-rokha-rokha": {
"type": "http",
"url": "https://rokha.ai/mcp/jsonrpc"
}
}
} [mcp_servers.ai-rokha-rokha] url = "https://rokha.ai/mcp/jsonrpc"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"ai-rokha-rokha": {
"type": "remote",
"url": "https://rokha.ai/mcp/jsonrpc",
"enabled": true
}
}
} openclaw mcp add ai-rokha-rokha --url 'https://rokha.ai/mcp/jsonrpc' --transport streamable-http
mcp_servers:
ai-rokha-rokha:
url: "https://rokha.ai/mcp/jsonrpc" {
"McpServers": {
"ai-rokha-rokha": {
"Transport": "http",
"Url": "https://rokha.ai/mcp/jsonrpc"
}
}
} assistant mcp add ai-rokha-rokha -t streamable-http -u 'https://rokha.ai/mcp/jsonrpc'
{
"mcpServers": {
"ai-rokha-rokha": {
"type": "http",
"url": "https://rokha.ai/mcp/jsonrpc"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Oct 26 0
- Tool “boosts_explain” rewrote its description, which is the text the model reads security
- Tool “carry_brief” rewrote its description, which is the text the model reads security
- Tool “justify_seeds” rewrote its description, which is the text the model reads security
- Tool “network_briefs” rewrote its description, which is the text the model reads security
- Tool “product_set” rewrote its description, which is the text the model reads security
- Tool “seeds_explain” rewrote its description, which is the text the model reads security
- New tool “interface_set” functional
- New tool “platform_interfaces_get” functional
- New tool “room_config_get” functional
- New tool “room_config_set” functional
- “rig_edge” reworded the description of “guard” cosmetic
- 2 Oct 26 +1
- Tool “adspace_bid” rewrote its description, which is the text the model reads security
- Tool “boosts_explain” rewrote its description, which is the text the model reads security
- Tool “carry_brief” rewrote its description, which is the text the model reads security
- Tool “page_claim” rewrote its description, which is the text the model reads security
- Tool “registry_search” rewrote its description, which is the text the model reads security
- Tool “rig_publish” rewrote its description, which is the text the model reads security
- Tool “studio_doors” rewrote its description, which is the text the model reads security
- Tool “wall_mcp_publish” rewrote its description, which is the text the model reads security
- New tool “carry_order” functional
- New tool “carry_order_check” functional
- New tool “creator_earnings” functional
- New tool “fuel_boost” functional
- New tool “fuel_boost_menu” functional
- New tool “fuel_tanks” functional
- New tool “network_brief_get” functional
- New tool “network_brief_set” functional
- New tool “network_briefs” functional
- New tool “network_join” functional
- New tool “network_join_status” functional
- New tool “network_me” functional
- New tool “network_member_report” functional
- New tool “network_members” functional
- New tool “network_my_picks” functional
- New tool “network_pick” functional
- New tool “network_plans” functional
- New tool “network_pot” functional
- New tool “network_referral” functional
- New tool “network_unpick” functional
- New tool “product_checkout” functional
- New tool “product_get” functional
- New tool “product_set” functional
- New tool “purchases_mine” functional
- “registry_search” added an optional parameter “proven” cosmetic
- “registry_search” added an optional parameter “type” cosmetic
- “registry_search” made “query” optional cosmetic
- 1 Oct 26 0
- New tool “fuel_menu” functional
- New tool “fuel_price” functional
- New tool “fuel_spend” functional
- New tool “fuel_status” functional
- 30 Sept 26 0
- New tool “agent_desk” functional
- New tool “signal_feed” functional
- 29 Sept 26 0
- A breaking change shipped without a version bump: still 0.1.0 ▼ security
- New tool “signet_paper_reset”, which the server declares destructive security
- Tool “trace_get” rewrote its description, which is the text the model reads security
- Tool “trace_search” rewrote its description, which is the text the model reads security
- “trace_get” dropped the required parameter “wallet_address” ▼ functional
- New tool “signet_paper_buy” functional
- New tool “signet_paper_positions” functional
- New tool “signet_paper_sell” functional
- New tool “signet_wallet_activity” functional
- “trace_get” added an optional parameter “run_id” cosmetic
- “trace_search” added an optional parameter “node_id” cosmetic
- “trace_search” added an optional parameter “run_id” cosmetic
- “trace_get” reworded the description of “id” cosmetic
- “trace_get” made “id” optional cosmetic
- 28 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Sept 26 0
- Stability: unverified → fail ▼ security
- A breaking change shipped without a version bump: still 0.1.0 ▼ security
- Tool “bounty_create” was removed ▼ security
- Tool “bounty_list” was removed ▼ security
- Tool “bounty_submit” was removed ▼ security
- Tool “hood_oracle” was removed ▼ security
- Tool “playground_state” was removed ▼ security
- Tool “playground_act” was removed ▼ security
- Tool “playground_join” was removed ▼ security
- Tool “stream_join” was removed ▼ security
- Tool “stream_say” was removed ▼ security
- Tool “aasagenticawesomeskills__compose_stack” rewrote its description, which is the text the model reads security
- Tool “aasagenticawesomeskills__diff_stack” rewrote its description, which is the text the model reads security
- Tool “aasagenticawesomeskills__export_selection_evidence” rewrote its description, which is the text the model reads security
- Tool “aasagenticawesomeskills__get_skill” rewrote its description, which is the text the model reads security
- Tool “aasagenticawesomeskills__inspect_selection_evidence” rewrote its description, which is the text the model reads security
- Tool “aasagenticawesomeskills__inspect_stack” rewrote its description, which is the text the model reads security
- Tool “aasagenticawesomeskills__list_skill_files” rewrote its description, which is the text the model reads security
- Tool “aasagenticawesomeskills__read_skill_file” rewrote its description, which is the text the model reads security
- Tool “aasagenticawesomeskills__search_skills” rewrote its description, which is the text the model reads security
- Tool “orbitx__fetch” rewrote its description, which is the text the model reads security
- Tool “orbitx__orbitx_crypto_scan” rewrote its description, which is the text the model reads security
- Tool “orbitx__orbitx_dex_chart” rewrote its description, which is the text the model reads security
- Tool “orbitx__orbitx_get_ath” rewrote its description, which is the text the model reads security
- Tool “orbitx__orbitx_get_balance” rewrote its description, which is the text the model reads security
- Tool “orbitx__orbitx_get_chart” rewrote its description, which is the text the model reads security
- Tool “orbitx__orbitx_get_forensics” rewrote its description, which is the text the model reads security
- Tool “orbitx__orbitx_get_kols” rewrote its description, which is the text the model reads security
- Tool “orbitx__orbitx_get_safety” rewrote its description, which is the text the model reads security
- Tool “orbitx__orbitx_get_signals” rewrote its description, which is the text the model reads security
- Tool “orbitx__orbitx_get_token” rewrote its description, which is the text the model reads security
- Tool “orbitx__orbitx_get_wallet” rewrote its description, which is the text the model reads security
- Tool “orbitx__orbitx_menu” rewrote its description, which is the text the model reads security
- Tool “orbitx__orbitx_screen_tokens” rewrote its description, which is the text the model reads security
- Tool “orbitx__orbitx_search” rewrote its description, which is the text the model reads security
- Tool “orbitx__orbitx_whoami” rewrote its description, which is the text the model reads security
- Tool “orbitx__search” rewrote its description, which is the text the model reads security
- Schema quality: 157 → 179 ▼ functional
- “orbitx__fetch” added a required parameter “id”, so existing callers break ▼ functional
- “orbitx__orbitx_crypto_scan” added a required parameter “mint”, so existing callers break ▼ functional
- “orbitx__orbitx_get_ath” added a required parameter “mint”, so existing callers break ▼ functional
- “orbitx__orbitx_get_chart” added a required parameter “mint”, so existing callers break ▼ functional
- “orbitx__orbitx_get_forensics” added a required parameter “mint”, so existing callers break ▼ functional
- “orbitx__orbitx_get_safety” added a required parameter “mint”, so existing callers break ▼ functional
- “orbitx__orbitx_get_token” added a required parameter “mint”, so existing callers break ▼ functional
- “orbitx__orbitx_screen_tokens” added a required parameter “type”, so existing callers break ▼ functional
- “orbitx__orbitx_search” added a required parameter “q”, so existing callers break ▼ functional
- “orbitx__search” added a required parameter “query”, so existing callers break ▼ functional
- New tool “orbitx__orbitx_dex_listings” functional
- New tool “orbitx__orbitx_gc_focus” functional
- New tool “orbitx__orbitx_gc_history” functional
- New tool “orbitx__orbitx_gc_list” functional
- New tool “orbitx__orbitx_leaderboard” functional
- New tool “orbitx__orbitx_life_account” functional
- New tool “orbitx__orbitx_life_city” functional
- New tool “orbitx__orbitx_life_files” functional
- New tool “orbitx__orbitx_life_list” functional
- New tool “orbitx__orbitx_life_timeline” functional
- New tool “orbitx__orbitx_nft_collections” functional
- New tool “orbitx__orbitx_nft_items” functional
- New tool “orbitx__orbitx_nft_listings” functional
- New tool “orbitx__orbitx_research” functional
- New tool “orbitx__orbitx_social_communities” functional
- New tool “orbitx__orbitx_social_feed” functional
- New tool “orbitx__orbitx_telegram_cmds” functional
- New tool “orbitx__orbitx_telegram_status” functional
- New tool “orbitx__orbitx_vc_link” functional
- New tool “orbitx__orbitx_vc_list” functional
- New tool “orbitx__orbitx_x_connect” functional
- New tool “orbitx__orbitx_x_status” functional
- New tool “orbitx__orbitx_xray” functional
- New tool “rig_publish” functional
- New tool “singularityagent__balance” functional
- New tool “singularityagent__chain_liveness” functional
- New tool “singularityagent__chains” functional
- New tool “singularityagent__decode” functional
- New tool “singularityagent__fees” functional
- New tool “singularityagent__history” functional
- New tool “singularityagent__inspect_exit” functional
- New tool “singularityagent__inspect_payment” functional
- New tool “singularityagent__mesh” functional
- New tool “singularityagent__mint_audit” functional
- New tool “singularityagent__portfolio” functional
- New tool “singularityagent__prove_payment” functional
- New tool “singularityagent__read_contract” functional
- New tool “singularityagent__receipt_art” functional
- New tool “singularityagent__resolve” functional
- New tool “singularityagent__token_identity” functional
- New tool “singularityagent__transaction” functional
- New tool “singularityagent__verify_burn” functional
- “orbitx__orbitx_crypto_scan” added an optional parameter “authCode” cosmetic
- “orbitx__orbitx_dex_chart” added an optional parameter “authCode” cosmetic
- “orbitx__orbitx_dex_chart” added an optional parameter “ca” cosmetic
- “orbitx__orbitx_dex_chart” added an optional parameter “chain” cosmetic
- “orbitx__orbitx_dex_chart” added an optional parameter “iframe” cosmetic
- “orbitx__orbitx_dex_chart” added an optional parameter “interval” cosmetic
- “orbitx__orbitx_dex_chart” added an optional parameter “mint” cosmetic
- “orbitx__orbitx_dex_chart” added an optional parameter “theme” cosmetic
- “orbitx__orbitx_get_ath” added an optional parameter “authCode” cosmetic
- “orbitx__orbitx_get_balance” added an optional parameter “address” cosmetic
- “orbitx__orbitx_get_balance” added an optional parameter “authCode” cosmetic
- “orbitx__orbitx_get_balance” added an optional parameter “mint” cosmetic
- “orbitx__orbitx_get_chart” added an optional parameter “authCode” cosmetic
- “orbitx__orbitx_get_chart” added an optional parameter “chain” cosmetic
- “orbitx__orbitx_get_chart” added an optional parameter “interval” cosmetic
- “orbitx__orbitx_get_chart” added an optional parameter “limit” cosmetic
- “orbitx__orbitx_get_forensics” added an optional parameter “authCode” cosmetic
- “orbitx__orbitx_get_kols” added an optional parameter “authCode” cosmetic
- “orbitx__orbitx_get_kols” added an optional parameter “limit” cosmetic
- “orbitx__orbitx_get_safety” added an optional parameter “authCode” cosmetic
- “orbitx__orbitx_get_signals” added an optional parameter “authCode” cosmetic
- “orbitx__orbitx_get_signals” added an optional parameter “limit” cosmetic
- “orbitx__orbitx_get_token” added an optional parameter “authCode” cosmetic
- “orbitx__orbitx_get_token” added an optional parameter “chain” cosmetic
- “orbitx__orbitx_get_wallet” added an optional parameter “address” cosmetic
- “orbitx__orbitx_get_wallet” added an optional parameter “authCode” cosmetic
- “orbitx__orbitx_menu” added an optional parameter “authCode” cosmetic
- “orbitx__orbitx_screen_tokens” added an optional parameter “authCode” cosmetic
- “orbitx__orbitx_screen_tokens” added an optional parameter “chain” cosmetic
- “orbitx__orbitx_screen_tokens” added an optional parameter “interval” cosmetic
- “orbitx__orbitx_screen_tokens” added an optional parameter “limit” cosmetic
- “orbitx__orbitx_search” added an optional parameter “authCode” cosmetic
- “orbitx__orbitx_whoami” added an optional parameter “authCode” cosmetic
- “orbitx__orbitx_whoami” added an optional parameter “publicKey” cosmetic
- “rig_run” added an optional parameter “wait” cosmetic
- 26 Sept 26 79
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Oct 2026 · Probed https://rokha.ai/mcp/jsonrpc
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=rokha.ai | CN=Amazon RSA 2048 M01,O=Amazon,C=US | 16 May 2026 | 29 Nov 2026 | RSA 2048 | SHA256-RSA | ae3696b36a503029f15142d977f374d |
| SANs: rokha.ai, *.rokha.ai | ||||||
| CN=Amazon RSA 2048 M01,O=Amazon,C=US (CA) | CN=Amazon Root CA 1,O=Amazon,C=US | 23 Aug 2022 | 23 Aug 2030 | RSA 2048 | SHA256-RSA | 77312380b9d6688a33b1ed9bf9ccda68e0e0f |
| CN=Amazon Root CA 1,O=Amazon,C=US (CA) | CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies\, Inc.,L=Scottsdale,ST=Arizona,C=US | 25 May 2015 | 31 Dec 2037 | RSA 2048 | SHA256-RSA | 67f944a2a27cdf3fac2ae2b01f908eeb9c4c6 |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of rokha.ai. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| ai. | present | 3799 | 8 | Verified |
| rokha.ai. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer resource_metadata="https://rokha.ai/.well-known/oauth-protected-resource"
Bearer resource_metadata="https://rokha.ai/.well-known/oauth-protected-resource" | Header | Value |
|---|---|
| strict-transport-security | max-age=31536000 |
| content-security-policy | frame-ancestors 'self' |
| x-content-type-options | nosniff |
| x-frame-options | SAMEORIGIN |
| referrer-policy | strict-origin-when-cross-origin |
Protected resource metadata
| Document | https://rokha.ai/.well-known/oauth-protected-resource |
|---|---|
| Retrieved | Yes |
| Resource | https://rokha.ai/mcp/jsonrpc |
| Authorisation server | https://rokha.ai |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://rokha.ai/mcp/jsonrpc | Verified | 200 | |
| http (plaintext) | http://rokha.ai/mcp/jsonrpc | HTTPS enforced | 301 | https://rokha.ai:443/mcp/jsonrpc |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
singularityagent__transaction Look up a transaction ~239
Fetch and normalize a transaction, with EVM calldata decoded where the selector is recognized. If no chain is given, searches the chains the hash format allows and reports every chain it was found on. Read `finality` alongside `status`, because they answer different questions: `status` says the chain executed the transaction and it did not revert, while `finality` says whether the block holding it can still be discarded. `final` is the only kind that licenses an irreversible decision. `reversible` means it sits at or near the head and a reorganization would erase it. `probabilistic` is proof-of-work settlement — it carries a confirmation count and never becomes `final` at any depth, because the chain offers no point past which reversal is disallowed, only one past which it is expensive; how many confirmations are enough is the caller’s decision. `unknown` means the endpoint would not say, which is not evidence that it is settled.
| Name | Type | Req | Description |
|---|---|---|---|
| chain | string | – | Chain id, to skip the cross-chain search. |
| hash | string | yes | Transaction hash, txid, or Solana signature. |
No output schema declared.
No examples provided.
singularityagent__verify_burn Confirm a burn from its signature ~287
Confirm that a Solana transaction really burned a token: which mint, which owner, how much, at finalized commitment. Pass `mint` (and optionally `owner` and a `minimum` amount) to check the burn against a claim rather than just describing it — a transaction that burned a different mint is refused by name. Reports whether the signature has already been redeemed, and never spends it. A signature is public the moment it lands, so this proves a burn happened and proves nothing about who quoted it; what binds a burn to a claimant is the memo the burner signed into it, which is returned when there is one.
| Name | Type | Req | Description |
|---|---|---|---|
| chain | string | – | Solana chain id or alias. Defaults to "solana". |
| expectMemo | string | – | Text the burn's memo must contain. The memo is the only part of the transaction the burner wrote and signed, so it is what makes a burn attributable to a claimant rather than to whoever quotes the si… |
| minimum | string | – | The least that must have been destroyed, as a human decimal amount, e.g. "1000". |
| mint | string | – | The mint the burn must be of. Matched by address, never by symbol. |
| owner | string | – | The wallet that must have signed the burn. |
| signature | string | yes | The transaction signature of the burn. |
No output schema declared.
No examples provided.
skill_author Author an Agent Skill (SKILL.md) ~443
Author a standard agentskills.io Agent Skill and get back its SKILL.md. A strong skill has: a `name` in kebab-case (lowercase letters, numbers, single hyphens, ≤64 chars); a `description` stating WHAT it does AND WHEN to use it, third person, with concrete trigger words (the field agents read to decide whether to load it); and `instructions` (the Markdown body), specific + imperative, ideally shaped When-to-use → Instructions → Examples → Guidelines. Optional `compatibility` (runtime/environment requirements, ≤500 chars — set when the skill needs system packages, a language version, network access, or scripts; omit for pure-instruction skills), `allowed_tools` (a SPACE-separated, least-privilege allowlist with optional scoping, e.g. 'Bash(git:*) Read'), `license` (a license name or file reference), and `metadata` (an object of string→string pairs). Returns the assembled SKILL.md to save as SKILL.md in a folder named after the skill. (In the Rokha UI the same tool fills the human's live builder form.)
| Name | Type | Req | Description |
|---|---|---|---|
| allowed_tools | string | – | Optional. SPACE-separated, least-privilege tool allowlist with optional scoping (e.g. 'Bash(git:*) Read'). Experimental. |
| compatibility | string | – | Optional, ≤500 chars. Runtime/environment requirements (e.g. 'Requires Python 3.14+ and uv'). Omit for pure-instruction skills. |
| description | string | yes | What it does + when to use it. Third person, with trigger words. ≤1024 chars. |
| instructions | string | yes | The Markdown body. Specific + imperative. When-to-use → Instructions → Examples → Guidelines. |
| license | string | – | Optional. A license name or bundled-file reference (e.g. 'MIT'). |
| metadata | object | – | Optional. Arbitrary string→string metadata (e.g. {"author":"example-org","version":"1.0"}). |
| name | string | yes | Skill id + folder name. kebab-case, ≤64 chars. |
No output schema declared.
No examples provided.
studio_doors Studio Doors ~211
WHAT ROKHA COSTS — the plans and the license. Rokha is the AI studio and launchpad: build in the Studio, launch on the Rokha Network, and the Network carries it. NETWORK (monthly): a member profile + directory listing, your MCP/brand listing recalled by agents, Rokha's posts + raids on the member cadence, a monthly report of what the Network did for you. NETWORK + STUDIO (monthly): all of that plus the full Studio — build, run and publish rigs (earn 25% of others' paid runs on them), create agents, Signet, fuel. THE STUDIO LICENSE: buy it outright, once (opens after the current round of testing). Card or USDC. Free: chat and two real runs a day, and earning on the Tailwind from a linked X account. Rank is earned (runs, usage, activity, tenure), never bought. Returns the live prices — never quote one from memory. Public, no auth.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
trace_get Trace Get ~171
READ one trace in full (input, result, status, timing) by `id`, or a whole run by `run_id` (status, steps with their trace ids, output, every trace). Signed in (Authorization: Bearer <token>): your own traces. No token: a PUBLIC rig's run is readable by anyone holding its trace id or run id — the runner's identity is stripped. Anything else answers not-found. REST twins: GET /api/traces/<id> · GET /api/rigs/runs/<run_id>.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | – | A trace UUID (every trace row shows it). |
| run_id | string | – | A run UUID — the id rig_run / POST /api/rigs/run hand back. Pass this OR id. |
No output schema declared.
No examples provided.
trace_search Read what a run actually did ~358
List your Traces — the durable record of what a run DID, newest first. This is the other half of rig_run: a run reports that it started, and the trace is where the answer lands. Without it an agent can run a rig and never learn whether it worked, which makes the run untestable. Filter by `rig_id` (this rig's runs), `parent_trace_id` (the STEPS under one run — this is how you see which steps ran and which were skipped by a guard), `trace_kind` ('run' for the containers, 'atomic' for individual steps), `run_id` (every trace ONE run wrote — the id rig_run and POST /api/rigs/run return), `node_id` or `status`. Signed in: your own traces. Anonymous: pass `run_id` to read a PUBLIC rig's run (anyone holding the id may; the runner's identity is stripped). A private run answers not-found, never forbidden.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Newest N (default modest). |
| node_id | string | – | One graph node's passes within a run. |
| parent_trace_id | string | – | The atomic step traces under one run — how you see which steps actually ran. |
| rig_id | string | – | Only traces from this rig. |
| run_id | string | – | One run's traces — the run id rig_run / POST /api/rigs/run hand back. Works anonymously for a PUBLIC rig's run. |
| status | string | – | e.g. success, error, partial. |
| trace_kind | string | – | 'run' (containers) or 'atomic' (steps). |
No output schema declared.
No examples provided.
update_harness Update Harness ~115
Update an existing harness's content or metadata. For a rig-step harness, content is the FULL config object — keep `skill` intact and set `instruction`/`endpoint`/`tool`/`params`/`model`/`model_policy` (see create_harness for the model-pin semantics).
| Name | Type | Req | Description |
|---|---|---|---|
| content | string | – | New content for the harness (optional) |
| harness_id | string | yes | UUID of the harness to update |
| metadata | object | – | New metadata for the harness (optional) |
No output schema declared.
No examples provided.
wall_mcp_publish Link your MCP server → your registry listing ~330
A live-seat perk on The Network (rokha.ai/network): link your own remote MCP server and Rokha publishes your registry listing from it — you as the source, credited to your seat. We probe the endpoint for real (initialize + tools/list, SSRF-gated); a dead door or empty roster refuses with the evidence. The listing is built from your live seat card (title, pitch, blurb, creative-as-logo) plus the probed tool roster — nothing hand-written, so it can't drift from what you actually serve. Idempotent per slug (<your-title>-seat-mcp); re-running refreshes the roster. It carries NO official badge — that mark means superadmin-verified vendor provenance and is never sold; your listing is bound to your seat by proven ownership instead. Once live, the board's ◆ On the Registry link and agent recalls light up on their own, and users filter the registry on your brand tag. Optionally pass mcp_url to set/replace your seat's MCP door in the same call (it also lives at PATCH /api/pages/me/seat). Seat sales are retired (2026-10-01) — this door serves the Founding Members' seats; new members join the Rokha Network at rokha.ai/network. Requires Authorization: Bearer <JWT> from the seat's claimed owner (or the account whose page X handle matches the seat's sponsor).
| Name | Type | Req | Description |
|---|---|---|---|
| mcp_url | string | – | your MCP server's streamable-http endpoint (https://…/mcp) — optional if your seat already carries one |
No output schema declared.
No examples provided.
x_account_audit Audit an X account — is the following real? ~227
Rokha's account auditor: give it any X @handle and get an organic-ness audit — 0–100 score, ORGANIC/MIXED/SMOKE verdict, and the promotional-worth anchor in X-algorithm engagement units (reply 13.5 · quote 1.5 · repost 1.0 · like 0.5). Hard metrics from X's own numbers: engagement rate vs follower count, reply share (the hardest signal to buy), engagement variance across posts (bought engagement is flat), account age vs follower velocity. `deep: true` (paid plans) also returns a bounded reply_sample for judging reply QUALITY — generic bot-isms vs real human reaction. Honest scope: declared limits on what a public-API sample can prove. Daily caps per caller (free taste; more on paid plans). Public, no auth for the basic audit.
| Name | Type | Req | Description |
|---|---|---|---|
| deep | boolean | – | also pull the reply sample for a quality read (Builder/Pro) |
| handle | string | yes | the X handle to audit, with or without the @ |
No output schema declared.
No examples provided.
x_link_start Prove you control an X account (no browser) ~120
Start a headless X link. Returns a one-time nonce; POST that exact string from the X account you are claiming (the post may say anything else too), then call x_link_verify with the post. This is the agent path — it needs no browser and no OAuth consent screen. Linking X is what makes your posts earn seeds on the Tailwind. The nonce lasts 30 minutes, is single-use, and one X account links to one Rokha account. Claim your page handle first (page_claim). Requires Authorization: Bearer <JWT>.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
x_link_verify Finish the X link with your posted nonce ~114
Finish a headless X link: give the id or link of the post carrying the nonce from x_link_start. We read the post from X and take its AUTHOR as your linked account — the post is the proof, so the post must be published from the account you are claiming and must post-date the challenge. On success your X handle is stamped on your page and your posts start earning seeds. Requires Authorization: Bearer <JWT>.
| Name | Type | Req | Description |
|---|---|---|---|
| post | string | yes | The post id, or its full x.com link |
No output schema declared.
No examples provided.
What is the Rokha MCP server?
Rokha is an MCP server listed in the public MCP registry as ai.rokha/rokha. Search a registry of agent skills and MCP servers, then run them for real. No install, traced. This page covers its hosted endpoint (https://rokha.ai/mcp/jsonrpc).
Is the Rokha MCP server safe to use?
Rokha scores 80 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Rokha MCP server expose?
Rokha exposes 211 tools: send_agent_message, create_task, get_task_status, list_harnesses, get_harness, and 206 more. Their descriptions and schemas cost roughly 34,806 tokens of context every time the server is loaded.
Does the Rokha MCP server require authentication?
Yes. Rokha asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the Rokha MCP server still maintained?
Rokha is still listed as active in the MCP registry. We last reached this channel on 3 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.