{
  "$schema": "https://verifymcp.io/schemas/changelog.json",
  "server": "cash-flat-flatcash",
  "component": "api-mcp",
  "generated_at": "2026-09-20T20:22:19.238Z",
  "tracking_since": "2026-07-26",
  "counts": {
    "critical": 0,
    "security": 24,
    "functional": 0,
    "cosmetic": 0
  },
  "events": [
    {
      "id": "chg_01a08530-a2c6-737f-bacb-951020ec9aba",
      "kind": "check.reverified",
      "family": "auth-oauth",
      "subject_kind": "check",
      "subject": "auth-oauth",
      "subject_child": "",
      "from_code": "auth.none_unlisted",
      "to_code": "auth.challenge_only",
      "from_value": "unverified",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-09",
      "occurred_at": "2026-09-09 08:02:32.199085+00",
      "observed_since": "2026-09-08",
      "source": "scan",
      "summary": "Authorization (unverified → fail)",
      "link": "https://verifymcp.io/servers/cash-flat-flatcash/api-mcp#chg-chg_01a08530-a2c6-737f-bacb-951020ec9aba"
    },
    {
      "id": "chg_01a08530-a2c7-74ec-8cbc-1f1a4de10fbb",
      "kind": "check.unverifiable",
      "family": "transport",
      "subject_kind": "check",
      "subject": "transport",
      "subject_child": "",
      "from_code": "transport.http_error",
      "to_code": "transport.auth_gated",
      "from_value": "fail",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "transport": "streamable-http"
      },
      "occurred_on": "2026-09-09",
      "occurred_at": "2026-09-09 08:02:32.199085+00",
      "observed_since": "2026-09-08",
      "source": "scan",
      "summary": "Transport (fail → unverified)",
      "link": "https://verifymcp.io/servers/cash-flat-flatcash/api-mcp#chg-chg_01a08530-a2c7-74ec-8cbc-1f1a4de10fbb"
    },
    {
      "id": "chg_01a08530-a2c7-7b2f-a269-48609f98e2a5",
      "kind": "check.reason",
      "family": "tool-safety-injection",
      "subject_kind": "check",
      "subject": "tool-safety-injection",
      "subject_child": "",
      "from_code": "toolsafety.unreachable",
      "to_code": "toolsafety.auth_gated",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-09",
      "occurred_at": "2026-09-09 08:02:32.199085+00",
      "observed_since": "2026-09-08",
      "source": "scan",
      "summary": "Tool safety (Tool safety blocked by authentication: the endpoint requires auth we don't have to read its tools.)",
      "link": "https://verifymcp.io/servers/cash-flat-flatcash/api-mcp#chg-chg_01a08530-a2c7-7b2f-a269-48609f98e2a5"
    },
    {
      "id": "chg_01a08530-a2c9-7301-b007-832b832e5301",
      "kind": "capture.status_changed",
      "family": "",
      "subject_kind": "server",
      "subject": "capture",
      "subject_child": "",
      "from_code": null,
      "to_code": null,
      "from_value": "not_mcp",
      "to_value": "auth_gated",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "to": "auth_gated",
        "from": "not_mcp"
      },
      "occurred_on": "2026-09-09",
      "occurred_at": "2026-09-09 08:02:32.199085+00",
      "observed_since": "2026-09-08",
      "source": "scan",
      "summary": "Endpoint reachability (not serving MCP → behind authorisation)",
      "link": "https://verifymcp.io/servers/cash-flat-flatcash/api-mcp#chg-chg_01a08530-a2c9-7301-b007-832b832e5301"
    },
    {
      "id": "chg_01a06124-eb16-71df-bc53-115cc5ee1d6b",
      "kind": "check.verdict",
      "family": "https",
      "subject_kind": "check",
      "subject": "https",
      "subject_child": "",
      "from_code": "https.plaintext",
      "to_code": "https.enforced",
      "from_value": "fail",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-02",
      "occurred_at": "2026-09-02 08:03:24.40494+00",
      "observed_since": "2026-09-01",
      "source": "scan",
      "summary": "HTTPS (fail → pass)",
      "link": "https://verifymcp.io/servers/cash-flat-flatcash/api-mcp#chg-chg_01a06124-eb16-71df-bc53-115cc5ee1d6b"
    },
    {
      "id": "chg_01a06124-eb17-76cc-8bb4-6c78691bf92e",
      "kind": "check.reverified",
      "family": "tls",
      "subject_kind": "check",
      "subject": "tls",
      "subject_child": "",
      "from_code": "tls.unreachable",
      "to_code": "tls.valid",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-02",
      "occurred_at": "2026-09-02 08:03:24.40494+00",
      "observed_since": "2026-09-01",
      "source": "scan",
      "summary": "TLS certificate (unverified → pass)",
      "link": "https://verifymcp.io/servers/cash-flat-flatcash/api-mcp#chg-chg_01a06124-eb17-76cc-8bb4-6c78691bf92e"
    },
    {
      "id": "chg_01a06124-eb18-71d4-af07-284052cf19f1",
      "kind": "check.reverified",
      "family": "hsts",
      "subject_kind": "check",
      "subject": "hsts",
      "subject_child": "",
      "from_code": "headers.inconclusive",
      "to_code": "headers.hsts_present",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-02",
      "occurred_at": "2026-09-02 08:03:24.40494+00",
      "observed_since": "2026-09-01",
      "source": "scan",
      "summary": "HSTS header (unverified → pass)",
      "link": "https://verifymcp.io/servers/cash-flat-flatcash/api-mcp#chg-chg_01a06124-eb18-71d4-af07-284052cf19f1"
    },
    {
      "id": "chg_01a06124-eb19-72ba-8ece-f4a392053047",
      "kind": "check.reason",
      "family": "transport",
      "subject_kind": "check",
      "subject": "transport",
      "subject_child": "",
      "from_code": "transport.unreachable",
      "to_code": "transport.http_error",
      "from_value": "fail",
      "to_value": "fail",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "status": "501",
        "transport": "streamable-http"
      },
      "occurred_on": "2026-09-02",
      "occurred_at": "2026-09-02 08:03:24.40494+00",
      "observed_since": "2026-09-01",
      "source": "scan",
      "summary": "Transport (Transport check failed: declared streamable-http, but the endpoint returned HTTP 501.)",
      "link": "https://verifymcp.io/servers/cash-flat-flatcash/api-mcp#chg-chg_01a06124-eb19-72ba-8ece-f4a392053047"
    },
    {
      "id": "chg_01a06124-eb19-78a4-9559-6ab9ea48a0e9",
      "kind": "check.reason",
      "family": "auth-oauth",
      "subject_kind": "check",
      "subject": "auth-oauth",
      "subject_child": "",
      "from_code": "auth.unreachable",
      "to_code": "auth.none_unlisted",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-02",
      "occurred_at": "2026-09-02 08:03:24.40494+00",
      "observed_since": "2026-09-01",
      "source": "scan",
      "summary": "Authorization (Authorisation not fully verified: no authorisation is required to connect, but we couldn't read the tool list to see what that exposes.)",
      "link": "https://verifymcp.io/servers/cash-flat-flatcash/api-mcp#chg-chg_01a06124-eb19-78a4-9559-6ab9ea48a0e9"
    },
    {
      "id": "chg_01a06124-eb19-7e7d-8177-e0955731f6ca",
      "kind": "capture.status_changed",
      "family": "",
      "subject_kind": "server",
      "subject": "capture",
      "subject_child": "",
      "from_code": null,
      "to_code": null,
      "from_value": "unreachable",
      "to_value": "not_mcp",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "to": "not_mcp",
        "from": "unreachable"
      },
      "occurred_on": "2026-09-02",
      "occurred_at": "2026-09-02 08:03:24.40494+00",
      "observed_since": "2026-09-01",
      "source": "scan",
      "summary": "Endpoint reachability (unreachable → not serving MCP)",
      "link": "https://verifymcp.io/servers/cash-flat-flatcash/api-mcp#chg-chg_01a06124-eb19-7e7d-8177-e0955731f6ca"
    },
    {
      "id": "chg_01a051b2-0969-75e8-821f-79ae11c03031",
      "kind": "check.verdict",
      "family": "https",
      "subject_kind": "check",
      "subject": "https",
      "subject_child": "",
      "from_code": "https.enforced",
      "to_code": "https.plaintext",
      "from_value": "pass",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-30",
      "occurred_at": "2026-08-30 08:03:37.287945+00",
      "observed_since": "2026-08-29",
      "source": "scan",
      "summary": "HTTPS (pass → fail)",
      "link": "https://verifymcp.io/servers/cash-flat-flatcash/api-mcp#chg-chg_01a051b2-0969-75e8-821f-79ae11c03031"
    },
    {
      "id": "chg_01a051b2-096a-7569-b6ff-dc03c569db31",
      "kind": "check.unverifiable",
      "family": "tls",
      "subject_kind": "check",
      "subject": "tls",
      "subject_child": "",
      "from_code": "tls.valid",
      "to_code": "tls.unreachable",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-30",
      "occurred_at": "2026-08-30 08:03:37.287945+00",
      "observed_since": "2026-08-29",
      "source": "scan",
      "summary": "TLS certificate (pass → unverified)",
      "link": "https://verifymcp.io/servers/cash-flat-flatcash/api-mcp#chg-chg_01a051b2-096a-7569-b6ff-dc03c569db31"
    },
    {
      "id": "chg_01a051b2-096a-7aa2-b56d-401ba5227690",
      "kind": "check.unverifiable",
      "family": "hsts",
      "subject_kind": "check",
      "subject": "hsts",
      "subject_child": "",
      "from_code": "headers.hsts_present",
      "to_code": "headers.inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-30",
      "occurred_at": "2026-08-30 08:03:37.287945+00",
      "observed_since": "2026-08-29",
      "source": "scan",
      "summary": "HSTS header (pass → unverified)",
      "link": "https://verifymcp.io/servers/cash-flat-flatcash/api-mcp#chg-chg_01a051b2-096a-7aa2-b56d-401ba5227690"
    },
    {
      "id": "chg_01a051b2-096b-7161-a80f-7a9f321945c5",
      "kind": "check.reason",
      "family": "auth-oauth",
      "subject_kind": "check",
      "subject": "auth-oauth",
      "subject_child": "",
      "from_code": "auth.none_unlisted",
      "to_code": "auth.unreachable",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-30",
      "occurred_at": "2026-08-30 08:03:37.287945+00",
      "observed_since": "2026-08-29",
      "source": "scan",
      "summary": "Authorization (Authorisation not yet verified: we couldn't confirm whether this endpoint requires it.)",
      "link": "https://verifymcp.io/servers/cash-flat-flatcash/api-mcp#chg-chg_01a051b2-096b-7161-a80f-7a9f321945c5"
    },
    {
      "id": "chg_01a051b2-096b-77c9-b64d-23ff0a38d201",
      "kind": "check.reason",
      "family": "transport",
      "subject_kind": "check",
      "subject": "transport",
      "subject_child": "",
      "from_code": "transport.http_error",
      "to_code": "transport.unreachable",
      "from_value": "fail",
      "to_value": "fail",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "transport": "streamable-http"
      },
      "occurred_on": "2026-08-30",
      "occurred_at": "2026-08-30 08:03:37.287945+00",
      "observed_since": "2026-08-29",
      "source": "scan",
      "summary": "Transport (Transport check failed: declared streamable-http, but we couldn't connect to verify it.)",
      "link": "https://verifymcp.io/servers/cash-flat-flatcash/api-mcp#chg-chg_01a051b2-096b-77c9-b64d-23ff0a38d201"
    },
    {
      "id": "chg_01a051b2-096b-7f04-94ed-d5186d8860ee",
      "kind": "capture.status_changed",
      "family": "",
      "subject_kind": "server",
      "subject": "capture",
      "subject_child": "",
      "from_code": null,
      "to_code": null,
      "from_value": "not_mcp",
      "to_value": "unreachable",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "to": "unreachable",
        "from": "not_mcp"
      },
      "occurred_on": "2026-08-30",
      "occurred_at": "2026-08-30 08:03:37.287945+00",
      "observed_since": "2026-08-29",
      "source": "scan",
      "summary": "Endpoint reachability (not serving MCP → unreachable)",
      "link": "https://verifymcp.io/servers/cash-flat-flatcash/api-mcp#chg-chg_01a051b2-096b-7f04-94ed-d5186d8860ee"
    },
    {
      "id": "chg_01a02da5-0618-7957-9c09-94e44da495d6",
      "kind": "check.unverifiable",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.churn",
      "to_code": "stability.insufficient_history",
      "from_value": "fail",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-23",
      "occurred_at": "2026-08-23 08:03:04.756657+00",
      "observed_since": "2026-08-22",
      "source": "scan",
      "summary": "Stability (fail → unverified)",
      "link": "https://verifymcp.io/servers/cash-flat-flatcash/api-mcp#chg-chg_01a02da5-0618-7957-9c09-94e44da495d6"
    },
    {
      "id": "chg_01a02da5-0619-7818-83c1-2a3c8f565867",
      "kind": "check.unverifiable",
      "family": "auth-oauth",
      "subject_kind": "check",
      "subject": "auth-oauth",
      "subject_child": "",
      "from_code": "auth.none_destructive",
      "to_code": "auth.none_unlisted",
      "from_value": "fail",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-23",
      "occurred_at": "2026-08-23 08:03:04.756657+00",
      "observed_since": "2026-08-22",
      "source": "scan",
      "summary": "Authorization (fail → unverified)",
      "link": "https://verifymcp.io/servers/cash-flat-flatcash/api-mcp#chg-chg_01a02da5-0619-7818-83c1-2a3c8f565867"
    },
    {
      "id": "chg_01a02da5-0619-7d7d-b5b8-a691eb282e84",
      "kind": "check.verdict",
      "family": "transport",
      "subject_kind": "check",
      "subject": "transport",
      "subject_child": "",
      "from_code": "transport.verified",
      "to_code": "transport.http_error",
      "from_value": "pass",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "status": "404",
        "transport": "streamable-http"
      },
      "occurred_on": "2026-08-23",
      "occurred_at": "2026-08-23 08:03:04.756657+00",
      "observed_since": "2026-08-22",
      "source": "scan",
      "summary": "Transport (pass → fail)",
      "link": "https://verifymcp.io/servers/cash-flat-flatcash/api-mcp#chg-chg_01a02da5-0619-7d7d-b5b8-a691eb282e84"
    },
    {
      "id": "chg_01a02da5-061b-7ab6-b636-8a6a4493e5b1",
      "kind": "capture.status_changed",
      "family": "",
      "subject_kind": "server",
      "subject": "capture",
      "subject_child": "",
      "from_code": null,
      "to_code": null,
      "from_value": "verified",
      "to_value": "not_mcp",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "to": "not_mcp",
        "from": "verified"
      },
      "occurred_on": "2026-08-23",
      "occurred_at": "2026-08-23 08:03:04.756657+00",
      "observed_since": "2026-08-22",
      "source": "scan",
      "summary": "Endpoint reachability (reachable → not serving MCP)",
      "link": "https://verifymcp.io/servers/cash-flat-flatcash/api-mcp#chg-chg_01a02da5-061b-7ab6-b636-8a6a4493e5b1"
    },
    {
      "id": "chg_01a01e32-6ab0-77b4-b7fe-55d1fe0775c2",
      "kind": "tool.description_changed",
      "family": "",
      "subject_kind": "tool",
      "subject": "flat_pay",
      "subject_child": "",
      "from_code": null,
      "to_code": null,
      "from_value": null,
      "to_value": null,
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "tool": "flat_pay"
      },
      "occurred_on": "2026-08-20",
      "occurred_at": "2026-08-20 08:03:35.664088+00",
      "observed_since": "2026-08-19",
      "source": "scan",
      "summary": "Tool “flat_pay” rewrote its description, which is the text the model reads",
      "link": "https://verifymcp.io/servers/cash-flat-flatcash/api-mcp#chg-chg_01a01e32-6ab0-77b4-b7fe-55d1fe0775c2"
    },
    {
      "id": "chg_01a00ebf-6efd-7a50-8dc0-f98a83960433",
      "kind": "tool.description_changed",
      "family": "",
      "subject_kind": "tool",
      "subject": "flat_earn",
      "subject_child": "",
      "from_code": null,
      "to_code": null,
      "from_value": null,
      "to_value": null,
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "tool": "flat_earn"
      },
      "occurred_on": "2026-08-17",
      "occurred_at": "2026-08-17 08:03:41.760359+00",
      "observed_since": "2026-08-16",
      "source": "scan",
      "summary": "Tool “flat_earn” rewrote its description, which is the text the model reads",
      "link": "https://verifymcp.io/servers/cash-flat-flatcash/api-mcp#chg-chg_01a00ebf-6efd-7a50-8dc0-f98a83960433"
    },
    {
      "id": "chg_019fcbca-b8d0-75ae-a75b-66d49c6e2987",
      "kind": "tool.description_changed",
      "family": "",
      "subject_kind": "tool",
      "subject": "flat_pay",
      "subject_child": "",
      "from_code": null,
      "to_code": null,
      "from_value": null,
      "to_value": null,
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "tool": "flat_pay"
      },
      "occurred_on": "2026-08-04",
      "occurred_at": "2026-08-04 08:01:27.955674+00",
      "observed_since": "2026-08-03",
      "source": "scan",
      "summary": "Tool “flat_pay” rewrote its description, which is the text the model reads",
      "link": "https://verifymcp.io/servers/cash-flat-flatcash/api-mcp#chg-chg_019fcbca-b8d0-75ae-a75b-66d49c6e2987"
    },
    {
      "id": "chg_019fcbca-b8e0-705d-94a9-40111d825031",
      "kind": "tool.description_changed",
      "family": "",
      "subject_kind": "tool",
      "subject": "flat_read",
      "subject_child": "",
      "from_code": null,
      "to_code": null,
      "from_value": null,
      "to_value": null,
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "tool": "flat_read"
      },
      "occurred_on": "2026-08-04",
      "occurred_at": "2026-08-04 08:01:27.955674+00",
      "observed_since": "2026-08-03",
      "source": "scan",
      "summary": "Tool “flat_read” rewrote its description, which is the text the model reads",
      "link": "https://verifymcp.io/servers/cash-flat-flatcash/api-mcp#chg-chg_019fcbca-b8e0-705d-94a9-40111d825031"
    }
  ],
  "days": [
    {
      "date": "2026-09-09",
      "total": 36,
      "delta": 11,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 7
    },
    {
      "date": "2026-09-02",
      "total": 25,
      "delta": 5,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 6
    },
    {
      "date": "2026-09-01",
      "total": 20,
      "delta": -5,
      "tracked": true,
      "explained": false,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 0
    },
    {
      "date": "2026-08-30",
      "total": 25,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 6
    },
    {
      "date": "2026-08-26",
      "total": 25,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-08-23",
      "total": 25,
      "delta": -37,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 7
    },
    {
      "date": "2026-08-20",
      "total": 0,
      "delta": null,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 3
    },
    {
      "date": "2026-08-17",
      "total": 0,
      "delta": null,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 5
    }
  ]
}