Wicked MCP
REMOTE · MCP.WICKEDAPI.COM · 2 COMPONENTS · SCANNED OCT 7
The whole Wicked suite for agents: trading, DeFi/token risk, identity, reputation, memory. x402.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security60
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 70 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability83
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 8282 tokens (~108/item across 76 items; 70 tools + 6 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
- Stability check failed: schema churn in the 5 days we've observed: 3 tool removals, 27 breaking changes, 0 auth/transport breaks, 43 additions. See how to fix → Fail
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 99% of tool parameters carry a description.Partial
Tool Safety75
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 0 of 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "memory_delete" implies "delete" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
- An AI judge read all 71 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the Wicked MCP server?
Wicked MCP is a hosted endpoint at https://mcp.wickedapi.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.wickedapi.com
claude mcp add --transport http choaticpixels-wicked-mcp 'https://mcp.wickedapi.com/mcp'
{
"mcpServers": {
"choaticpixels-wicked-mcp": {
"url": "https://mcp.wickedapi.com/mcp"
}
}
} {
"servers": {
"choaticpixels-wicked-mcp": {
"type": "http",
"url": "https://mcp.wickedapi.com/mcp"
}
}
} [mcp_servers.choaticpixels-wicked-mcp] url = "https://mcp.wickedapi.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"choaticpixels-wicked-mcp": {
"type": "remote",
"url": "https://mcp.wickedapi.com/mcp",
"enabled": true
}
}
} openclaw mcp add choaticpixels-wicked-mcp --url 'https://mcp.wickedapi.com/mcp' --transport streamable-http
mcp_servers:
choaticpixels-wicked-mcp:
url: "https://mcp.wickedapi.com/mcp" {
"McpServers": {
"choaticpixels-wicked-mcp": {
"Transport": "http",
"Url": "https://mcp.wickedapi.com/mcp"
}
}
} assistant mcp add choaticpixels-wicked-mcp -t streamable-http -u 'https://mcp.wickedapi.com/mcp'
{
"mcpServers": {
"choaticpixels-wicked-mcp": {
"type": "http",
"url": "https://mcp.wickedapi.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Oct 26 +5
We did not load change detail this far back for this component, so this day may have recorded more than is shown.
- Stability: unverified → fail ▼ security
- Tool “wickedapi_momentum” was removed ▼ security
- Tool “wickedapi_funding_oi” was removed ▼ security
- Tool “wickedapi_price” was removed ▼ security
- The server rewrote its instructions, which are the text every model session reads security
- The server changed its declared name: wicked-reputation → wickedapi security
- Tool “memory_store” rewrote its description, which is the text the model reads security
- Tool “reputation_transparency” rewrote its description, which is the text the model reads security
- Tool “registry_featured_tools” rewrote its description, which is the text the model reads security
- Tool “reputation_tiers” rewrote its description, which is the text the model reads security
- Tool “memory_prepare” rewrote its description, which is the text the model reads security
- Tool “registry_tool_detail” rewrote its description, which is the text the model reads security
- Tool “memory_delete” rewrote its description, which is the text the model reads security
- Tool “reputation_status” rewrote its description, which is the text the model reads security
- Tool “memory_search” rewrote its description, which is the text the model reads security
- Tool “registry_search_tools” rewrote its description, which is the text the model reads security
- Tool “reputation_query” rewrote its description, which is the text the model reads security
- Tool “registry_register_tool” rewrote its description, which is the text the model reads security
- Tool “identity_jwks” rewrote its description, which is the text the model reads security
- Tool “identity_status” rewrote its description, which is the text the model reads security
- Tool “registry_report_tool” rewrote its description, which is the text the model reads security
- Tool “reputation_statement” rewrote its description, which is the text the model reads security
- Tool “identity_register” rewrote its description, which is the text the model reads security
- Tool “memory_get” rewrote its description, which is the text the model reads security
- Tool “identity_get_challenge” rewrote its description, which is the text the model reads security
- Tool “sanity_check” rewrote its description, which is the text the model reads security
- Tool “identity_get_nonce” rewrote its description, which is the text the model reads security
- Tool “memory_deletions” rewrote its description, which is the text the model reads security
- Tool “memory_history” rewrote its description, which is the text the model reads security
- Tool “memory_update” rewrote its description, which is the text the model reads security
- Tool “registry_tool_badge” rewrote its description, which is the text the model reads security
- Tool “identity_submit_response” rewrote its description, which is the text the model reads security
- Tool “sanity_check_batch” rewrote its description, which is the text the model reads security
- “reputation_query” changed the type of “limit”: integer → number ▼ functional
- “registry_search_tools” changed the type of “limit”: integer → number ▼ functional
- Tool “memory_delete” dropped its output schema ▼ functional
- Tool “registry_search_tools” dropped its output schema ▼ functional
- Tool “memory_history” dropped its output schema ▼ functional
- Tool “memory_search” dropped its output schema ▼ functional
- Tool “reputation_statement” dropped its output schema ▼ functional
- Tool “identity_get_nonce” dropped its output schema ▼ functional
- Tool “reputation_status” dropped its output schema ▼ functional
- Tool “sanity_check_batch” dropped its output schema ▼ functional
- Tool “registry_tool_detail” dropped its output schema ▼ functional
- Tool “memory_store” dropped its output schema ▼ functional
- Tool “sanity_check” dropped its output schema ▼ functional
- Tool “registry_featured_tools” dropped its output schema ▼ functional
- Tool “identity_status” dropped its output schema ▼ functional
- Tool “memory_deletions” dropped its output schema ▼ functional
- Tool “memory_update” dropped its output schema ▼ functional
- Tool “memory_prepare” dropped its output schema ▼ functional
- Tool “memory_get” dropped its output schema ▼ functional
- Tool “registry_register_tool” dropped its output schema ▼ functional
- Tool “registry_tool_badge” dropped its output schema ▼ functional
- Tool “reputation_transparency” dropped its output schema ▼ functional
- Tool “reputation_query” dropped its output schema ▼ functional
- Tool “registry_report_tool” dropped its output schema ▼ functional
- Tool “identity_get_challenge” dropped its output schema ▼ functional
- Tool “identity_submit_response” dropped its output schema ▼ functional
- Tool “identity_jwks” dropped its output schema ▼ functional
- Tool “identity_register” dropped its output schema ▼ functional
- Tool “reputation_tiers” dropped its output schema ▼ functional
- Schema quality: 193 → 108 ▲ functional
- Tool coverage: 0% → 99% ▲ functional
- First check of Schema quality: 100 functional
- Schema quality: excellent → good functional
- MCP protocol: Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28. functional
- New prompt “verify_agent” functional
- New prompt “find_reliable_tool” functional
- New prompt “agent_memory_guide” functional
- New prompt “fact_check” functional
- New prompt “rug_check” functional
- New prompt “morning_briefing” functional
- New prompt “vet_dependency” functional
- MCP protocol version: 2026-07-28 → 2025-11-25 functional
- New resource “platform-services” functional
- New resource “token_risk-status” functional
- New resource “trading-status” functional
- New resource “broker_sync-status” functional
- New resource “protocol_health-status” functional
- New resource “platform-llms-txt” functional
- Server version: 0.3.1 → 0.4.0 functional
- New tool “defi_tvl” functional
- New tool “basis” functional
- New tool “broker_sync_prop_firms” functional
- New tool “orderbook” functional
- New tool “gas” functional
- New tool “long_short_ratio” functional
- New tool “protocol_health_refresh_all” functional
- New tool “macro_calendar” functional
- New tool “market_overview” functional
- New tool “kalshi_probability” functional
- New tool “protocol_health_sync_universe” functional
- New tool “paywall_list_settlements” functional
- New tool “atr” functional
- New tool “paywall_import_routes” functional
- New tool “ohlcv” functional
- New tool “earnings_calendar” functional
- New tool “broker_sync_transactions” functional
- New tool “protocol_health_track_protocol” functional
- New tool “broker_sync_register_user” functional
- New tool “protocol_health_scoreboard” functional
- New tool “token_risk” functional
- New tool “momentum_score” functional
- New tool “paywall_update_route” functional
- New tool “broker_sync_connections” functional
- New tool “protocol_health_list_protocols” functional
- New tool “kalshi_market” functional
- New tool “hyperliquid” functional
- New tool “paywall_signup” functional
- New tool “market_clock” functional
- New tool “paywall_delete_route” functional
- New tool “liquidity_levels” functional
- New tool “funding_oi” functional
- New tool “broker_sync_balances” functional
- New tool “price” functional
- New tool “broker_sync_positions” functional
- New tool “sentiment” functional
- New tool “paywall_get_tenant” functional
- New tool “protocol_health_score” functional
- New tool “rates” functional
- New tool “paywall_create_route” functional
- New tool “volatility” functional
- New tool “fvg” functional
- New tool “paywall_list_routes” functional
- “memory_store” reworded the description of “metadata” cosmetic
- “memory_store” reworded the description of “signature” cosmetic
- “memory_search” reworded the description of “limit” cosmetic
- “memory_history” reworded the description of “nonce” cosmetic
- “identity_get_challenge” reworded the description of “wallet” cosmetic
- “reputation_query” reworded the description of “sort” cosmetic
- “reputation_query” reworded the description of “max_stake” cosmetic
- “registry_search_tools” reworded the description of “protocol” cosmetic
- “reputation_query” reworded the description of “min_stake” cosmetic
- “memory_delete” reworded the description of “timestamp” cosmetic
- “memory_search” reworded the description of “wallet” cosmetic
- “memory_update” reworded the description of “tags” cosmetic
- “memory_update” reworded the description of “memory_id” cosmetic
- “memory_history” reworded the description of “timestamp” cosmetic
- “identity_submit_response” reworded the description of “response_text” cosmetic
- “memory_search” reworded the description of “payment_signature” cosmetic
- “identity_get_challenge” reworded the description of “signature” cosmetic
- “memory_update” reworded the description of “source” cosmetic
- “registry_tool_detail” reworded the description of “tool_id” cosmetic
- “memory_search” reworded the description of “q” cosmetic
- “memory_update” reworded the description of “timestamp” cosmetic
- “registry_report_tool” reworded the description of “evidence” cosmetic
- “sanity_check_batch” reworded the description of “mode” cosmetic
- “identity_register” reworded the description of “nonce” cosmetic
- “sanity_check_batch” reworded the description of “context” cosmetic
- “memory_delete” reworded the description of “wallet” cosmetic
- “registry_register_tool” reworded the description of “endpoint_url” cosmetic
- “memory_delete” reworded the description of “nonce” cosmetic
- “memory_history” reworded the description of “signature” cosmetic
- “memory_get” reworded the description of “signature” cosmetic
- “memory_prepare” reworded the description of “params” cosmetic
- “memory_prepare” reworded the description of “wallet” cosmetic
- “memory_get” reworded the description of “timestamp” cosmetic
- “memory_delete” reworded the description of “reason” cosmetic
- “memory_history” reworded the description of “memory_id” cosmetic
- “registry_register_tool” reworded the description of “owner_wallet” cosmetic
- “memory_update” reworded the description of “wallet” cosmetic
- “memory_search” reworded the description of “created_before” cosmetic
- “identity_register” reworded the description of “wallet” cosmetic
- “memory_delete” reworded the description of “memory_id” cosmetic
- “memory_get” reworded the description of “memory_id” cosmetic
- “memory_store” reworded the description of “timestamp” cosmetic
- “memory_delete” reworded the description of “scope” cosmetic
- “reputation_query” reworded the description of “min_reputation” cosmetic
- “memory_prepare” reworded the description of “operation” cosmetic
- “registry_register_tool” reworded the description of “signature” cosmetic
- “identity_register” reworded the description of “signature” cosmetic
- “registry_search_tools” reworded the description of “category” cosmetic
- “memory_store” reworded the description of “wallet” cosmetic
- “registry_search_tools” reworded the description of “limit” cosmetic
- “registry_search_tools” reworded the description of “sort” cosmetic
- “memory_search” reworded the description of “timestamp” cosmetic
- “memory_search” reworded the description of “created_after” cosmetic
- “memory_store” reworded the description of “tags” cosmetic
- “memory_deletions” reworded the description of “wallet” cosmetic
- “memory_get” reworded the description of “nonce” cosmetic
- “memory_update” reworded the description of “signature” cosmetic
- “reputation_status” reworded the description of “wallet” cosmetic
- “memory_store” reworded the description of “content” cosmetic
- “memory_delete” reworded the description of “signature” cosmetic
- “memory_deletions” reworded the description of “nonce” cosmetic
- “registry_report_tool” reworded the description of “reason” cosmetic
- “registry_report_tool” reworded the description of “tool_id” cosmetic
- “identity_get_nonce” reworded the description of “wallet” cosmetic
- “identity_status” reworded the description of “wallet” cosmetic
- “memory_history” reworded the description of “wallet” cosmetic
- “memory_search” reworded the description of “nonce” cosmetic
- “reputation_query” reworded the description of “min_slash_count” cosmetic
- “identity_get_challenge” reworded the description of “nonce” cosmetic
- “identity_submit_response” reworded the description of “challenge_id” cosmetic
- “reputation_query” reworded the description of “limit” cosmetic
- “memory_store” reworded the description of “source” cosmetic
- “registry_register_tool” reworded the description of “protocol” cosmetic
- “registry_tool_badge” reworded the description of “tool_id” cosmetic
- 2 Oct 26 60
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 8 Oct 2026 · Probed https://mcp.wickedapi.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=mcp.wickedapi.com | CN=YE1,O=Let's Encrypt,C=US | 30 Sept 2026 | 29 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 6b1e7ec523588f6e69ebab54e88a87683e4 |
| SANs: mcp.wickedapi.com | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC secure
Validation of mcp.wickedapi.com. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| wickedapi.com. | present | 2371 | 13 | Verified |
| mcp.wickedapi.com. | Verified address RRset verified with the apex keys |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.wickedapi.com/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.wickedapi.com/mcp | HTTPS enforced | 301 | https://mcp.wickedapi.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
atr ~192
[Trading Data API] Average True Range (Wilder's) + volatility-regime classification (low/normal/high/extreme by historical percentile) — Average True Range (Wilder's) + volatility-regime classification (low/normal/high/extreme by historical percentile). Crypto or stocks. **Example:** `/v1/atr?symbol=BTC&timeframe=1h&period=14`
| Name | Type | Req | Description |
|---|---|---|---|
| class | string | – | Optional. stock|crypto for non-curated symbols. |
| period | number | – | Optional. ATR period (default 14). |
| symbol | string | yes | Required. e.g. BTC, NVDA, SPY (or any with &class=). |
| timeframe | string | – | Optional. 1m,5m,15m,30m,1h,2h,4h,6h,12h,1D,1W (default 1h). |
No output schema declared.
No examples provided.
basis ~88
[Trading Data API] Spot-vs-perp basis (premium %) with funding-implied annualized carry — Spot-vs-perp basis (premium %) with funding-implied annualized carry. Spot from Coinbase; perp marks from Binance + Bybit. **Example:** `/v1/basis?symbol=BTC`
| Name | Type | Req | Description |
|---|---|---|---|
| symbol | string | yes | Required. Base crypto symbol (e.g. BTC). |
No output schema declared.
No examples provided.
broker_sync_balances ~45
[Broker Sync API] Cash & buying power per connected account (normalized). — Cash & buying power per connected account (normalized).
| Name | Type | Req | Description |
|---|---|---|---|
| user_id | string | yes | Required. |
No output schema declared.
No examples provided.
broker_sync_connections ~42
[Broker Sync API] List a user's connected brokerage accounts (normalized). — List a user's connected brokerage accounts (normalized).
| Name | Type | Req | Description |
|---|---|---|---|
| user_id | string | yes | Required. |
No output schema declared.
No examples provided.
broker_sync_positions ~62
[Broker Sync API] Real positions across all of a user's connected brokerages, one normalized schema, stamped as_of. — Real positions across all of a user's connected brokerages, one normalized schema, stamped as_of.
| Name | Type | Req | Description |
|---|---|---|---|
| user_id | string | yes | Required. |
No output schema declared.
No examples provided.
broker_sync_prop_firms ~73
[Broker Sync API] Prop-firm platform integration registry — live-verified methods (Topstep ProjectX API, FTMO MatchTrader bridge) and connection status. — Prop-firm platform integration registry — live-verified methods (Topstep ProjectX API, FTMO MatchTrader bridge) and connection status.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
broker_sync_register_user ~62
[Broker Sync API] Register a user with SnapTrade and get a brokerage connection-portal URL. — Register a user with SnapTrade and get a brokerage connection-portal URL.
| Name | Type | Req | Description |
|---|---|---|---|
| user_id | string | yes | Your application's stable identifier for this end user. |
No output schema declared.
No examples provided.
broker_sync_transactions ~62
[Broker Sync API] Transaction/activity history across brokerages. — Transaction/activity history across brokerages.
| Name | Type | Req | Description |
|---|---|---|---|
| from | string | – | Optional. YYYY-MM-DD. |
| to | string | – | Optional. YYYY-MM-DD. |
| user_id | string | yes | Required. |
No output schema declared.
No examples provided.
defi_tvl ~156
[Trading Data API] DefiLlama data: TVL by chain, stablecoin circulating supply, or yield pools. — DefiLlama data: TVL by chain, stablecoin circulating supply, or yield pools. **Example:** `/v1/defi-tvl?view=chains`
| Name | Type | Req | Description |
|---|---|---|---|
| chain | string | – | Optional (yields view). Filter pools by chain, e.g. Ethereum. |
| limit | number | – | Optional. Rows to return (default 20, max 100). |
| project | string | – | Optional (yields view). Filter pools by project, e.g. aave-v3. |
| view | string | – | Optional. chains (default), stablecoins, or yields. |
No output schema declared.
No examples provided.
earnings_calendar ~164
[Trading Data API] US equity earnings announcement calendar: report date, before/after-market timing, analyst EPS estimate + count, market cap, and prior-year actual EPS — US equity earnings announcement calendar: report date, before/after-market timing, analyst EPS estimate + count, market cap, and prior-year actual EPS. Sourced live from Nasdaq's public calendar. **Example:** `/v1/earnings-calendar?date=2026-07-14&days=3`
| Name | Type | Req | Description |
|---|---|---|---|
| date | string | – | Optional. Start date YYYY-MM-DD (default: today). |
| days | number | – | Optional. Days to scan forward from date (default 1, max 7). |
| symbol | string | – | Optional. Filter to one ticker within the scanned range. |
No output schema declared.
No examples provided.
funding_oi ~145
[Trading Data API] Aggregated perpetual-futures funding rate & open interest from Binance + Bybit, with 7-day average funding, 24h OI change, and a long/short bias signal. — Aggregated perpetual-futures funding rate & open interest from Binance + Bybit, with 7-day average funding, 24h OI change, and a long/short bias signal. **Example:** `/v1/funding-oi?symbol=BTC`
| Name | Type | Req | Description |
|---|---|---|---|
| symbol | string | yes | Required. Base crypto symbol (e.g. BTC, ETH, SOL). Mapped to the <SYMBOL>USDT perpetual ticker on Binance/Bybit. |
No output schema declared.
No examples provided.
fvg ~268
[Trading Data API] Fair Value Gap zones (standard ICT/LuxAlgo) with CE (50%), gap size, age, fill status, distance from price — Fair Value Gap zones (standard ICT/LuxAlgo) with CE (50%), gap size, age, fill status, distance from price. Standard timeframes match TradingView candles. Crypto or stocks. **Example:** `/v1/fvg?symbol=BTC&timeframe=1h`
| Name | Type | Req | Description |
|---|---|---|---|
| class | string | – | Optional. stock|crypto for non-curated symbols. |
| include_filled | boolean | – | Optional. true to include filled FVGs (default false = active only). |
| lookback | number | – | Optional. Timeframe candles to analyze (default 120, max 500). |
| min_gap_pct | number | – | Optional. Filter out gaps smaller than this % of price (default 0 = all). |
| symbol | string | yes | Required. e.g. BTC, NVDA, SPY (or any with &class=). |
| timeframe | string | – | Optional. 1m,5m,15m,30m,1h,2h,4h,6h,12h,1D,1W (default 1h). Matches TradingView candles. |
No output schema declared.
No examples provided.
gas ~57
[Trading Data API] Free, no signup required — Free, no signup required. Ethereum gas oracle (safe/propose/fast gas prices + base fee, in gwei), via Etherscan. **Example:** `/v1/gas`
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
hyperliquid ~113
[Trading Data API] Hyperliquid perpetual context: funding (hourly), open interest, mark/oracle/mid price, premium, 24h volume — Hyperliquid perpetual context: funding (hourly), open interest, mark/oracle/mid price, premium, 24h volume. Not geo-blocked. **Example:** `/v1/hyperliquid?symbol=BTC`
| Name | Type | Req | Description |
|---|---|---|---|
| symbol | string | yes | Required. Hyperliquid coin name (e.g. BTC, ETH, SOL). |
No output schema declared.
No examples provided.
identity_get_challenge ~191
[Wicked Identity] Request a real time-boxed liveness challenge (constrained-generation task, 30s budget). The clock starts when this returns: answer in ONE pass via identity_submit_response before `expires_at`. Real wallet: needs a fresh signed nonce (fetch + sign the nonce for the NEXT call before calling this). Sandbox: just wallet + sandbox_token.
| Name | Type | Req | Description |
|---|---|---|---|
| nonce | string | – | Real wallet: nonce from a FRESH identity_get_nonce call. Omit for sandbox. |
| sandbox_token | string | – | Sandbox identity: the sandbox_token from identity_sandbox_register. Use INSTEAD of nonce/signature. |
| signature | string | – | Real wallet: 0x-prefixed ECDSA signature over that nonce's message. Omit for sandbox. |
| wallet | string | yes | Your 0x wallet address on Base, or the sandbox wallet from identity_sandbox_register. |
No output schema declared.
No examples provided.
identity_get_nonce ~79
[Wicked Identity] Real-wallet path, step 1: a one-time nonce + message to sign. Every signed identity call needs a fresh nonce (single-use, 5-minute TTL). Not needed for sandbox identities.
| Name | Type | Req | Description |
|---|---|---|---|
| wallet | string | yes | Your 0x wallet address on Base, or the sandbox wallet from identity_sandbox_register. |
No output schema declared.
No examples provided.
identity_get_test_key ~70
[Wicked Identity] Get a free self-serve test API key (7-day expiry, 20 requests/min) to use as api_key on identity_status instead of paying via x402. Limit: 5 per IP per day.
| Name | Type | Req | Description |
|---|---|---|---|
| label | string | – | Optional name for this key. |
No output schema declared.
No examples provided.
identity_jwks ~61
[Wicked Identity] Public RS256 keys to verify an assertion_token locally. Free. Set sandbox=true for the separate key set that signs sandbox assertions.
| Name | Type | Req | Description |
|---|---|---|---|
| sandbox | boolean | – | true = the sandbox key set (issuer wicked-identity-sandbox). |
No output schema declared.
No examples provided.
identity_register ~111
[Wicked Identity] Register a REAL wallet (no stake required). Needs your signature over identity_get_nonce's message; this tool never signs. Sandbox identities are registered by identity_sandbox_register instead.
| Name | Type | Req | Description |
|---|---|---|---|
| nonce | string | yes | Nonce from a FRESH identity_get_nonce call. |
| signature | string | yes | 0x-prefixed ECDSA signature over that nonce's message. |
| wallet | string | yes | Your 0x wallet address on Base, or the sandbox wallet from identity_sandbox_register. |
No output schema declared.
No examples provided.
identity_sandbox_register ~102
[Wicked Identity] START HERE if you have no wallet or cannot sign messages. Returns a sandbox wallet + sandbox_token (no signing, no body). Then call identity_get_challenge and identity_submit_response with wallet + sandbox_token. Sandbox results are for trying the service: signed with a separate key (identity_jwks sandbox=true) and never reported as verified. Use a real wallet for an accountable identity. Limit: 10 per IP per hour.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
identity_status ~106
[Wicked Identity] Does a wallet currently hold a valid, unexpired assertion? No signature needed. Pays via x402, or pass api_key (get one free from identity_get_test_key) / set IDENTITY_API_KEY. Sandbox wallets are never `verified`; they report sandbox: true and sandbox_verified instead.
| Name | Type | Req | Description |
|---|---|---|---|
| api_key | string | – | Optional x-api-key, e.g. from identity_get_test_key. |
| wallet | string | yes | The 0x wallet address. |
No output schema declared.
No examples provided.
identity_submit_response ~213
[Wicked Identity] Submit your answer to a challenge; scored pass / fail / inconclusive. A pass returns a short-lived signed assertion_token (JWT) verifiable via identity_jwks. Real wallet: needs a DIFFERENT fresh nonce than identity_get_challenge used. Sandbox: wallet + sandbox_token.
| Name | Type | Req | Description |
|---|---|---|---|
| challenge_id | string | yes | The challenge_id from identity_get_challenge. |
| nonce | string | – | Real wallet: nonce from a FRESH identity_get_nonce call. Omit for sandbox. |
| response_text | string | yes | Your answer exactly as the instructions specify: raw text only. |
| sandbox_token | string | – | Sandbox identity: the sandbox_token from identity_sandbox_register. Use INSTEAD of nonce/signature. |
| signature | string | – | Real wallet: 0x-prefixed ECDSA signature over that nonce's message. Omit for sandbox. |
| wallet | string | yes | Your 0x wallet address on Base, or the sandbox wallet from identity_sandbox_register. |
No output schema declared.
No examples provided.
kalshi_market ~162
[Trading Data API] Single Kalshi market depth: orderbook (yes/no levels) + recent trades for a specific ticker. — Single Kalshi market depth: orderbook (yes/no levels) + recent trades for a specific ticker. **Example:** `/v1/kalshi-market?ticker=KXBTCD-26JUN1315-T64099.99`
| Name | Type | Req | Description |
|---|---|---|---|
| depth | number | – | Optional. Orderbook depth per side (default 10, max 100). |
| ticker | string | yes | Required. A Kalshi market ticker (e.g. KXBTCD-26JUN1315-T64099.99). |
| trades | string | – | Optional. Recent trades to return (default 20, max 100). |
No output schema declared.
No examples provided.
kalshi_probability ~162
[Trading Data API] Free, no signup required — Free, no signup required. Kalshi prediction-market probabilities. Query by category (returns the most active open markets) or a specific market ticker. **Example:** `/v1/kalshi-probability?category=crypto`
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | Optional. One of: crypto, macro, fed-rate, financials, politics, sports, world, companies, climate, science, health, entertainment, elections. Either category or ticker is required. |
| limit | number | – | Optional. Max markets to return for a category query (default 25, max 100). |
| ticker | string | – | Optional. A specific Kalshi market ticker (e.g. KXBTCD-...). |
No output schema declared.
No examples provided.
liquidity_levels ~263
[Trading Data API] ICT liquidity levels: buy-side liquidity (above swing highs) & sell-side (below swing lows), sweep/taken status, relative-equal pools, and nearest untaken targets — ICT liquidity levels: buy-side liquidity (above swing highs) & sell-side (below swing lows), sweep/taken status, relative-equal pools, and nearest untaken targets. Crypto or stocks. **Example:** `/v1/liquidity-levels?symbol=TQQQ&timeframe=1h`
| Name | Type | Req | Description |
|---|---|---|---|
| equal_threshold_pct | number | – | Optional. Group swings within this % as relative-equal pools (default 0.1). |
| include_swept | boolean | – | Optional. true to include already-taken levels (default false = resting only). |
| lookback | number | – | Optional. Candles to analyze (default 300, max 500). |
| swing_length | number | – | Optional. Pivot strength — bars each side of a swing (default 5). Tune to match your chart indicator. |
| symbol | string | yes | Required. e.g. BTC, NVDA, TQQQ (or any with &class=). |
| timeframe | string | – | Optional. 1m..1W (default 1h). |
No output schema declared.
No examples provided.
long_short_ratio ~162
[Trading Data API] Binance long/short ratios: global account, top-trader account, top-trader position, and taker buy/sell — Binance long/short ratios: global account, top-trader account, top-trader position, and taker buy/sell. Companion to funding-oi. **Example:** `/v1/long-short-ratio?symbol=BTC&period=1h`
| Name | Type | Req | Description |
|---|---|---|---|
| period | number | – | Optional. One of 5m,15m,30m,1h,2h,4h,6h,12h,1d (default 5m). |
| symbol | string | yes | Required. Base crypto symbol (e.g. BTC). Mapped to <SYMBOL>USDT. |
No output schema declared.
No examples provided.
macro_calendar ~118
[Trading Data API] Free, no signup required — Free, no signup required. Upcoming US macro events (FOMC rate decisions, CPI, jobs report) with verified Fed/BLS dates, days-until, and Kalshi rate-decision odds (cut/hold/hike) for FOMC meetings. **Example:** `/v1/macro-calendar`
| Name | Type | Req | Description |
|---|---|---|---|
| days | number | – | Optional. Only events within the next N days. |
| type | string | – | Optional. Filter to FOMC, CPI, or NFP. |
No output schema declared.
No examples provided.
market_clock ~102
[Trading Data API] US equities market clock (is_open, next_open/close) + upcoming sessions, via Alpaca — US equities market clock (is_open, next_open/close) + upcoming sessions, via Alpaca. Crypto endpoints are 24/7 and unaffected. **Example:** `/v1/market-clock`
| Name | Type | Req | Description |
|---|---|---|---|
| days | number | – | Optional. Upcoming session days to include (default 3, max 30; 0 to omit). |
No output schema declared.
No examples provided.
market_overview ~103
[Trading Data API] Free, no signup required — Free, no signup required. CoinGecko global crypto stats (total market cap, 24h volume, BTC/ETH dominance) or top coins by market cap. **Example:** `/v1/market-overview`
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | Optional (coins view). Number of coins (default 20, max 100). |
| view | string | – | Optional. global (default) or coins. |
No output schema declared.
No examples provided.
memory_delete ~162
[Wicked Memory] PERMANENTLY hard-delete a memory (right-to-be-forgotten). Default scope "chain" removes every version; "version" only this one. Only an audit row (no content) is kept.
| Name | Type | Req | Description |
|---|---|---|---|
| memory_id | string | yes | UUID of any version in the chain. |
| nonce | string | yes | From memory_prepare (single use). |
| reason | string | – | Optional audit-log note (max 200 chars). |
| scope | string | – | "chain" (all versions, default) or "version". |
| signature | string | yes | Your wallet's signature over memory_prepare's message_to_sign. |
| timestamp | string | yes | From memory_prepare. |
| wallet | string | yes | Your agent's 0x wallet address. |
No output schema declared.
No examples provided.
memory_deletions ~85
[Wicked Memory] Your deletion audit log (ids, times, reasons; never content).
| Name | Type | Req | Description |
|---|---|---|---|
| nonce | string | yes | From memory_prepare (single use). |
| signature | string | yes | Your wallet's signature over memory_prepare's message_to_sign. |
| timestamp | string | yes | From memory_prepare. |
| wallet | string | yes | Your agent's 0x wallet address. |
No output schema declared.
No examples provided.
memory_get ~102
[Wicked Memory] Fetch one of your memories by id (another wallet's or a deleted id returns the same 404).
| Name | Type | Req | Description |
|---|---|---|---|
| memory_id | string | yes | The memory's UUID. |
| nonce | string | yes | From memory_prepare (single use). |
| signature | string | yes | Your wallet's signature over memory_prepare's message_to_sign. |
| timestamp | string | yes | From memory_prepare. |
| wallet | string | yes | Your agent's 0x wallet address. |
No output schema declared.
No examples provided.
memory_history ~112
[Wicked Memory] Full version chain for a memory, oldest first, with valid_from / valid_until / superseded_by. Works from any version's id.
| Name | Type | Req | Description |
|---|---|---|---|
| memory_id | string | yes | UUID of any version in the chain. |
| nonce | string | yes | From memory_prepare (single use). |
| signature | string | yes | Your wallet's signature over memory_prepare's message_to_sign. |
| timestamp | string | yes | From memory_prepare. |
| wallet | string | yes | Your agent's 0x wallet address. |
No output schema declared.
No examples provided.
memory_prepare ~173
Wicked Memory step 1 of every call: returns the exact `message_to_sign`. Sign it with your own wallet (EIP-191 personal_sign), then call the matching memory_* tool with the SAME arguments plus the returned timestamp, nonce and your signature. Timestamp must be within 5 minutes; nonce is single-use, so prepare again for every call.
| Name | Type | Req | Description |
|---|---|---|---|
| operation | string | yes | "store", "search", "get", "update", "history", "delete" or "deletions". |
| params | object | – | The arguments you will pass to the tool, by name, e.g. {"content":"...","tags":["a"]} or {"memory_id":"<uuid>"}. |
| wallet | string | yes | Your agent's 0x wallet address (memories are scoped to it). |
No output schema declared.
No examples provided.
memory_search ~273
[Wicked Memory] Semantic search over YOUR memories only, ranked by real cosine similarity. The one metered call: free with MEMORY_API_KEY, otherwise http_status 402 with x402 v2 instructions under `payment_required` (0.001 USDC on Base) — pay, then call again with the SAME arguments (a 402 does not consume the nonce) plus payment_signature.
| Name | Type | Req | Description |
|---|---|---|---|
| as_of | string | – | ISO-8601 instant; search memory as it stood then. |
| created_after | string | – | ISO-8601 lower bound. |
| created_before | string | – | ISO-8601 upper bound. |
| include_superseded | boolean | – | Also search old, superseded versions. |
| limit | number | – | 1-50, default 10. |
| nonce | string | yes | From memory_prepare (single use). |
| payment_signature | string | – | x402 payment payload (base64) for the keyless path. |
| q | string | yes | What to look for, in natural language. |
| signature | string | yes | Your wallet's signature over memory_prepare's message_to_sign. |
| tags | array | – | Only memories having ALL of these tags. |
| timestamp | string | yes | From memory_prepare. |
| wallet | string | yes | Your agent's 0x wallet address. |
No output schema declared.
No examples provided.
memory_store ~159
[Wicked Memory] Store a memory (free, fair-use rate limited). A real embedding is computed at write time. Run memory_prepare with operation 'store' and these same arguments first.
| Name | Type | Req | Description |
|---|---|---|---|
| content | string | yes | Text to remember (max 16 KB). |
| metadata | object | – | Free-form JSON object (max 8 KB). |
| nonce | string | yes | From memory_prepare (single use). |
| signature | string | yes | Your wallet's signature over memory_prepare's message_to_sign. |
| source | string | – | Which agent/session wrote this. |
| tags | array | – | Up to 20 short tags. |
| timestamp | string | yes | From memory_prepare. |
| wallet | string | yes | Your agent's 0x wallet address. |
No output schema declared.
No examples provided.
memory_update ~178
[Wicked Memory] Update without overwriting: creates a new version and closes the old one (valid_until / superseded_by). Omitted fields carry over; only the current version can be updated (409 otherwise).
| Name | Type | Req | Description |
|---|---|---|---|
| content | string | – | New text (re-embedded). Provide at least one of content/tags/metadata/source. |
| memory_id | string | yes | UUID of the CURRENT version to supersede. |
| metadata | object | – | Replacement metadata object. |
| nonce | string | yes | From memory_prepare (single use). |
| signature | string | yes | Your wallet's signature over memory_prepare's message_to_sign. |
| source | string | – | New source label. |
| tags | array | – | Replacement tags. |
| timestamp | string | yes | From memory_prepare. |
| wallet | string | yes | Your agent's 0x wallet address. |
No output schema declared.
No examples provided.
momentum_score ~178
[Trading Data API] Multi-asset momentum verdict (bias, confidence, thesis, entry/invalidation/targets, signal readings) from the oracle.py pipeline, run on a separate Python service — Multi-asset momentum verdict (bias, confidence, thesis, entry/invalidation/targets, signal readings) from the oracle.py pipeline, run on a separate Python service. Scoped to 10 assets. **Example:** `/v1/momentum-score?symbol=BTC&timeframe=1h`
| Name | Type | Req | Description |
|---|---|---|---|
| symbol | string | yes | Required. One of: BTC, ETH, SOL, SUI, NVDA, IBIT, COIN, QQQ, TQQQ, DIA. |
| timeframe | string | – | Optional. 15m, 1h, 4h, 1D, 1W (default 1h). |
No output schema declared.
No examples provided.
ohlcv ~184
[Trading Data API] OHLCV candles (oldest-first) for crypto or stocks — OHLCV candles (oldest-first) for crypto or stocks. Routes to Alpaca SIP / Alpaca-crypto / Coinbase. **Example:** `/v1/ohlcv?symbol=NVDA&timeframe=1h&limit=100`
| Name | Type | Req | Description |
|---|---|---|---|
| class | string | – | Optional. stock|crypto for non-curated symbols. |
| limit | number | – | Optional. Candles to return (default 100, max 300). |
| symbol | string | yes | Required. e.g. BTC, NVDA, SPY. |
| timeframe | string | – | Optional. 1m,5m,15m,30m,1h,2h,4h,6h,12h,1D,1W (default 1h). |
No output schema declared.
No examples provided.
orderbook ~134
[Trading Data API] Top-of-book depth + spread (bps) from Binance, Bybit, or Hyperliquid. — Top-of-book depth + spread (bps) from Binance, Bybit, or Hyperliquid. **Example:** `/v1/orderbook?symbol=BTC&exchange=binance&depth=10`
| Name | Type | Req | Description |
|---|---|---|---|
| depth | number | – | Optional. Levels per side (default 10, max 50). |
| exchange | string | – | Optional. binance (default), bybit, or hyperliquid. |
| symbol | string | yes | Required. Base crypto symbol (e.g. BTC). |
No output schema declared.
No examples provided.
paywall_create_route ~225
[x402 Paywall] Paywall a new endpoint with x402 pay-per-call, settled in USDC straight to payTo. With upstreamUrl, paid requests are proxied to your backend. Applies live within ~20s (needs PAYWALL_API_KEY).
| Name | Type | Req | Description |
|---|---|---|---|
| asset | string | – | Payment token contract; defaults to USDC on the network. |
| description | string | – | Up to 200 chars: letters, digits, space . _ - |
| method | string | – | Default GET. |
| network | string | yes | CAIP-2 id: Base mainnet eip155:8453, Base Sepolia eip155:84532. |
| path | string | – | Route path, e.g. "/weather". |
| payTo | string | yes | Your payout wallet (0x…). Settlement pays here directly; nothing is custodied. |
| price | string | yes | Decimal USD amount, e.g. "0.01" or "$0.01". |
| upstreamUrl | string | – | Your https backend. Omit for the demo confirmation payload. |
No output schema declared.
No examples provided.
paywall_delete_route ~50
[x402 Paywall] Remove a paywalled route; applies within ~20s (needs PAYWALL_API_KEY).
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Route id from paywall_list_routes. |
No output schema declared.
No examples provided.
paywall_get_tenant ~28
[x402 Paywall] Your tenant record (needs PAYWALL_API_KEY).
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
paywall_import_routes ~61
[x402 Paywall] Bulk upsert routes keyed on (method, path) — paywall a whole API in one call (needs PAYWALL_API_KEY).
| Name | Type | Req | Description |
|---|---|---|---|
| routes | array | yes | Route objects, same fields as paywall_create_route. |
No output schema declared.
No examples provided.
paywall_list_routes ~30
[x402 Paywall] List your paywalled routes (needs PAYWALL_API_KEY).
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
paywall_list_settlements ~51
[x402 Paywall] Your real on-chain USDC settlements (earnings) (needs PAYWALL_API_KEY).
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | Default 50, max 200. |
No output schema declared.
No examples provided.
paywall_signup ~101
[x402 Paywall] Create a tenant account. Returns a Bearer apiKey ONCE — store it and set PAYWALL_API_KEY. Rate-limited to 5/hour per IP.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Letters, digits, space . _ - (max 100). |
| slug | string | yes | Lowercase a-z0-9 and hyphens, 2-40 chars; becomes your mount path prefix /{slug}. |
No output schema declared.
No examples provided.
paywall_update_route ~220
[x402 Paywall] Partial update of a route (e.g. change price or payout wallet); applies live within ~20s (needs PAYWALL_API_KEY).
| Name | Type | Req | Description |
|---|---|---|---|
| asset | string | – | Payment token contract; defaults to USDC on the network. |
| description | string | – | Up to 200 chars: letters, digits, space . _ - |
| id | string | yes | Route id from paywall_list_routes. |
| method | string | – | Default GET. |
| network | string | – | CAIP-2 id: Base mainnet eip155:8453, Base Sepolia eip155:84532. |
| path | string | – | Route path, e.g. "/weather". |
| payTo | string | – | Your payout wallet (0x…). Settlement pays here directly; nothing is custodied. |
| price | string | – | Decimal USD amount, e.g. "0.01" or "$0.01". |
| upstreamUrl | string | – | Your https backend. Omit for the demo confirmation payload. |
No output schema declared.
No examples provided.
price ~124
[Trading Data API] Current spot price for crypto (Coinbase) or US equities/ETFs (Alpaca SIP), via the shared routing layer. — Current spot price for crypto (Coinbase) or US equities/ETFs (Alpaca SIP), via the shared routing layer. **Example:** `/v1/price?symbol=BTC`
| Name | Type | Req | Description |
|---|---|---|---|
| class | string | yes | Optional. stock|crypto — required for symbols outside the curated list. |
| symbol | string | yes | Required. e.g. BTC, ETH, SUI, NVDA, SPY. |
No output schema declared.
No examples provided.
protocol_health_list_protocols ~111
[Protocol Health Oracle] All tracked protocols with their latest health score and verdict. — All tracked protocols with their latest health score and verdict.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | – | Optional. Filter by DefiLlama category. |
| limit | number | – | Optional. Rows to return (default 100, max 2000). |
| min_tvl | string | – | Optional. Only protocols with TVL >= this USD amount. |
| offset | string | – | Optional. Pagination offset (default 0). |
No output schema declared.
No examples provided.
What is the Wicked MCP server?
Wicked MCP is listed in the public MCP registry as io.github.choaticpixels/wicked-mcp. The whole Wicked suite for agents: trading, DeFi/token risk, identity, reputation, memory. x402. This page covers its hosted endpoint (https://mcp.wickedapi.com/mcp).
Is the Wicked MCP server safe to use?
Wicked MCP scores 65 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Wicked MCP server expose?
Wicked MCP exposes 75 tools: kalshi_probability, kalshi_market, funding_oi, long_short_ratio, orderbook, and 70 more. Their descriptions and schemas cost roughly 9,038 tokens of context every time the server is loaded.
Does the Wicked MCP server require authentication?
No. We connected to Wicked MCP without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Wicked MCP server still maintained?
Wicked MCP is still listed as active in the MCP registry. We last reached this channel on 7 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.