Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Taproot: AT Protocol MCP

REMOTE · MCP.ATPROTO.AT · SCANNED SEP 20

Read public AT Protocol profiles, records, threads, backlinks and lexicons. No API key required.

Available components

+3 this week 70 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security63
Transport & Reachability100
Schema Quality & AI Usability83
  • 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 4847 tokens (~179/item across 27 items; 27 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management23
  • Stability observed for 7 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • We read all 27 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
  • An AI judge read all 28 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
  • Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
Install

How do I install the Taproot: AT Protocol MCP server?

Taproot: AT Protocol MCP is a hosted endpoint at https://mcp.atproto.at/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · mcp.atproto.at

# add to Claude Code
claude mcp add --transport http com-atproto-mcp-taproot 'https://mcp.atproto.at/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "com-atproto-mcp-taproot": {
      "url": "https://mcp.atproto.at/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "com-atproto-mcp-taproot": {
      "type": "http",
      "url": "https://mcp.atproto.at/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.com-atproto-mcp-taproot]
url = "https://mcp.atproto.at/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-atproto-mcp-taproot": {
      "type": "remote",
      "url": "https://mcp.atproto.at/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add com-atproto-mcp-taproot --url 'https://mcp.atproto.at/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  com-atproto-mcp-taproot:
    url: "https://mcp.atproto.at/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "com-atproto-mcp-taproot": {
      "Transport": "http",
      "Url": "https://mcp.atproto.at/mcp"
    }
  }
}
# add to Vellum
assistant mcp add com-atproto-mcp-taproot -t streamable-http -u 'https://mcp.atproto.at/mcp'
// mcp.json
{
  "mcpServers": {
    "com-atproto-mcp-taproot": {
      "type": "http",
      "url": "https://mcp.atproto.at/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 20 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.

  • 18 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 13 to 17. That category is still filling its 30-day observation window: 4 days of observed history at the previous scan, 5 at this one. The score rises as the window fills, whether or not the server changes.

  • 15 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.

  • 14 Sept 26 0
    • Stability: unverified → 0.03 functional
  • 13 Sept 26 67

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 20 Sept 2026 · Probed https://mcp.atproto.at/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=mcp.atproto.at CN=WE1,O=Google Trust Services,C=US 31 Aug 2026 29 Nov 2026 ECDSA 256 ECDSA-SHA256 5c83789f71b47fbe1386acee5ed554c1
SANs: mcp.atproto.at
CN=WE1,O=Google Trust Services,C=US (CA) CN=GTS Root R4,O=Google Trust Services LLC,C=US 13 Dec 2023 20 Feb 2029 ECDSA 256 ECDSA-SHA384 7ff31977972c224a76155d13b6d685e3
CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE 15 Nov 2023 28 Jan 2028 ECDSA 384 SHA256-RSA 7fe530bf331343bedd821610493d8a1b

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of mcp.atproto.at. Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
at. present 1253, 60960 13, 13 Verified
atproto.at. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200
Header Value
strict-transport-security max-age=63072000; includeSubDomains; preload
content-security-policy default-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; object-src 'none'; script-src 'self' 'unsafe-inline' https://static.cloudflareinsights.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: blob: https:; media-src 'self' blob: https:; font-src 'self' data: https://fonts.gstatic.com; frame-src 'self' https://www.youtube-nocookie.com https://www.youtube.com; connect-src 'self' https: wss:
x-content-type-options nosniff
x-frame-options DENY
referrer-policy strict-origin-when-cross-origin
permissions-policy camera=(), microphone=(), geolocation=()

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://mcp.atproto.at/mcp Verified 200
http (plaintext) http://mcp.atproto.at/mcp HTTPS enforced 301 https://mcp.atproto.at/mcp
MCP tools · 27 exposed · ~3,960 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
count_records ~141

Count the total records in an account's collection (e.g. how many likes a user has given). Scans server-side so you don't page manually. AT Protocol has no cheap exact count, so for very large collections this returns exact:false with a lower-bound count and a cursor,call again with that cursor and ADD the counts to keep going.

NameTypeReqDescription
collectionstringyesCollection NSID, e.g. app.bsky.feed.like.
cursorstringResume cursor from a prior capped (exact:false) count. The new count covers records AFTER it,add it to your previous total.
repostringyesA handle or DID.

Structured output declared, but exposes no named fields.

No examples provided.

count_repos_by_collection ~177

Count how many accounts across the network publish a given collection/lexicon,e.g. 'how many accounts have an at.glean.subscription?'. Walks a relay's com.atproto.sync.listReposByCollection with NO per-account handle resolution, so it's cheap and returns an exact total for typical collections. For very large collections it returns exact:false with a cursor,call again with that cursor and ADD the counts (like count_records). Relay-served (defaults to the public Bluesky relay; pass `relay` for another).

NameTypeReqDescription
collectionstringyesA collection NSID, e.g. app.bsky.feed.generator.
cursorstringResume cursor from a previous exact:false response.
relaystringOptional relay origin to query instead of the default, e.g. https://relay.example.com.

Structured output declared, but exposes no named fields.

No examples provided.

describe_pds ~89

Describe a Personal Data Server: its DID, whether registration requires an invite, the handle domains you can register there, and ToS/contact links. Works for any PDS, not just Bluesky. Input is the PDS origin (e.g. https://pds.example.com).

NameTypeReqDescription
pdsstringyesA PDS origin URL, e.g. https://pds.example.com.

Structured output declared, but exposes no named fields.

No examples provided.

get_account_history ~71

An account's history from its PLC audit log: handle changes, PDS migrations, signing-key rotations, and creation time. did:plc accounts only (did:web has no PLC log). Input is a handle or DID.

NameTypeReqDescription
actorstringyesA handle or DID (did:plc).

Structured output declared, but exposes no named fields.

No examples provided.

get_app_link ~76

Turn an at:// URI (or handle/DID) into shareable web links,a Bluesky/Blacksky app URL to open in a browser, plus the canonical PDS getRecord URL. Use when the user wants a clickable/pasteable link.

NameTypeReqDescription
uristringyesAn at:// URI, handle, or DID.

Structured output declared, but exposes no named fields.

No examples provided.

get_backlinks ~121

Index of who/what references a target,the inbound likes, reposts, quotes, replies, and follows,as COUNTS per category, via the Constellation backlink index. Target is a record's at:// URI or an account DID. This returns aggregate counts only; each category also includes a `source` string. To list the actual records and their author DIDs for one category (e.g. WHO liked a post), call list_backlink_records with that `source`.

NameTypeReqDescription
targetstringyesA record at:// URI or a DID.

Structured output declared, but exposes no named fields.

No examples provided.

get_blob_info ~128

Get metadata for a single blob: its canonical PDS getBlob URL plus a best-effort content-type and byte size (via a HEAD request). Returns the URL, never the bytes. Use to turn a blob ref (CID) found in a record into a downloadable link and learn what it is. Input is the owning repo (handle or DID) and the blob CID.

NameTypeReqDescription
cidstringyesThe blob CID (e.g. bafkrei...), as found in a record's blob ref.
repostringyesA handle or DID (the blob's owning repo).

Structured output declared, but exposes no named fields.

No examples provided.

get_did_document ~77

Fetch the raw DID document for any DID or handle: all aliases (alsoKnownAs), every service entry (PDS, labeler, custom AppView), and verification methods. Broader than get_profile, and works for did:web accounts. Input is a handle or DID.

NameTypeReqDescription
actorstringyesA handle or DID.

Structured output declared, but exposes no named fields.

No examples provided.

get_latest_commit ~88

The current head commit of an account's repository (com.atproto.sync.getLatestCommit): its commit CID and revision. The cheapest way to fingerprint a repo or detect whether it changed since you last looked, without downloading data. Complements get_repo_status (which has the rev but not the commit CID). Input is a handle or DID.

NameTypeReqDescription
repostringyesA handle or DID.

Structured output declared, but exposes no named fields.

No examples provided.

get_pds_directory_info ~91

A cached health card for a PDS from pds.directory: version, DID, approximate user count, reachability, last-checked time, available domains, and which relays index it. Input is the PDS hostname (e.g. pds.example.com). Best-effort/cached data.

NameTypeReqDescription
hostnamestringyesA PDS hostname, e.g. pds.example.com.

Structured output declared, but exposes no named fields.

No examples provided.

get_profile ~107

Get an account's repository overview (handle, DID, PDS, and the list of collections it contains). Input is a handle or DID.

NameTypeReqDescription
actorstringyesA handle (alice.bsky.social) or DID (did:plc:...).
includearrayOptional enrichments: 'schema' resolves the collection's lexicon; 'backlinks' lists who referenced the target; 'profile' adds the repo owner's display name, bio, and avatar URL.

Structured output declared, but exposes no named fields.

No examples provided.

get_record ~108

Fetch a single record by its full at:// URI (must include collection and rkey). Returns the record's value, CID, and resolved identity.

NameTypeReqDescription
includearrayOptional enrichments: 'schema' resolves the collection's lexicon; 'backlinks' lists who referenced the target; 'profile' adds the repo owner's display name, bio, and avatar URL.
uristringyesFull at:// URI: at://<did-or-handle>/<collection>/<rkey>.

Structured output declared, but exposes no named fields.

No examples provided.

get_relay_directory_info ~79

A cached overview of a relay from firehose.directory: counts of PDSes it indexes (total/active/offline/banned) and total accounts. Input is the relay hostname (e.g. bsky.network). Best-effort/cached data.

NameTypeReqDescription
hostnamestringyesA relay hostname, e.g. bsky.network.

Structured output declared, but exposes no named fields.

No examples provided.

get_repo_status ~75

Liveness/moderation status of an account's repository: whether it is active, its current revision, and any takedown/suspended/deactivated/deleted state. Answers 'has @alice been taken down?' which get_profile can't. Input is a handle or DID.

NameTypeReqDescription
repostringyesA handle or DID.

Structured output declared, but exposes no named fields.

No examples provided.

get_thread ~194

Reconstruct the conversation around a post: its ancestor chain up to the thread root (following reply.parent, root-first) PLUS a bounded descendant reply TREE,replies, replies-to-replies, and so on, each tagged with its depth and parent,walked breadth-first and capped for cost. NOTE: descendant expansion assumes the Bluesky reply model (app.bsky.feed.post with reply.parent); ancestor walking follows reply.parent generically, but the reply tree is specific to that lexicon and will be empty for record types that model replies differently. Answers 'show me this whole conversation / what is this replying to?'. If the tree is truncated, use list_backlink_records on a specific post's URI to expand it further. Input is a post's at:// URI.

NameTypeReqDescription
uristringyesA post's full at:// URI: at://<did-or-handle>/app.bsky.feed.post/<rkey>.

Structured output declared, but exposes no named fields.

No examples provided.

list_backlink_records ~213

List the actual records (author DID + verified handle + at:// URI, newest first) that reference a target for ONE category,i.e. WHO liked, reposted, quoted, replied to, mentioned, or follows it. Workflow: call get_backlinks first to get a category `source`, then pass it here. To read WHAT a referencing record says (e.g. the text of a mention or reply), call get_record on its at:// URI. Author handles are resolved via identity resolution (verified), not search.

NameTypeReqDescription
cursorstringPagination cursor returned by a previous call (to get the next page).
limitintegerPage size (1-25, default 25). Use the returned cursor for the next page.
sourcestringyesA category `source` from get_backlinks, e.g. app.bsky.feed.like:subject.uri.
targetstringyesThe referenced record at:// URI or account DID (same target passed to get_backlinks).

Structured output declared, but exposes no named fields.

No examples provided.

list_blobs ~160

List the blobs (uploaded media/attachments,images, video, etc.) hosted in an account's repository, via com.atproto.sync.listBlobs. Returns each blob's CID and its canonical PDS getBlob URL (PDS-native, works for any PDS,not a CDN). Answers 'what media does this account host?'. Records reference blobs by CID; use this (or get_blob_info) to turn a CID into a fetchable URL. Input is a handle or DID.

NameTypeReqDescription
cursorstringPagination cursor from a previous call.
limitintegerPage size (1-100, default 50). A cursor in the response means more pages exist.
repostringyesA handle or DID.

Structured output declared, but exposes no named fields.

No examples provided.

list_labelers ~118

List the labeler (moderation) services known to the labeler relay,each labeler's DID, resolved handle, and service endpoint. The discovery step BEFORE query_labels, which needs a labeler DID/handle up front: use this to find moderation.bsky.app and any third-party/regional labelers, then pass one to query_labels.

NameTypeReqDescription
cursorstringPagination cursor from a previous call.
limitintegerPage size (1-20, default 20). Use the returned cursor for the next page.

Structured output declared, but exposes no named fields.

No examples provided.

list_records ~113

List records in a collection for an account, with pagination. Provide the repo (handle or DID) and the collection NSID (e.g. app.bsky.feed.post).

NameTypeReqDescription
collectionstringyesCollection NSID, e.g. app.bsky.feed.post.
cursorstringPagination cursor from a previous page.
limitintegerPage size (1-100, default 50). A cursor in the response means more pages exist.
repostringyesA handle or DID.

Structured output declared, but exposes no named fields.

No examples provided.

list_repos ~252

List the accounts (repositories) hosted on a PDS, via com.atproto.sync.listRepos: each repo's DID and active/takedown status, paginated. Answers 'who is hosted on this PDS?' / 'how many accounts does this PDS have?'. By default returns DIDs only (one request, large page — best for counting); pass enrich=true to also resolve handles (slower, smaller page). Input is the PDS origin (e.g. https://pds.example.com). Works for any PDS.

NameTypeReqDescription
cursorstringPagination cursor from a previous call.
enrichbooleanResolve each DID to its handle. Default false — returns DIDs only in ONE request (large page, the fast path for listing/counting). Set true only when you need handles (slower, smaller page).
limitintegerPage size (1-1000, default 1000). With enrich=true the effective page is capped near 20 (each DID is resolved to a handle). Use the returned cursor for the next page.
pdsstringyesA PDS origin URL, e.g. https://pds.example.com.

Structured output declared, but exposes no named fields.

No examples provided.

list_repos_by_collection ~301

Network-wide: which accounts publish a given collection/lexicon,e.g. 'who has an app.bsky.feed.generator (a custom feed)?' or who uses a custom lexicon. Via a relay's com.atproto.sync.listReposByCollection (anonymous). By default returns DIDs only (one request, large page); pass enrich=true to also resolve handles (slower, smaller page). For just a total, use count_repos_by_collection. NOTE: relay-served (defaults to the public Bluesky relay; pass `relay` to query another), not the account's own PDS. Pairs with search_lexicons / resolve_lexicon.

NameTypeReqDescription
collectionstringyesA collection NSID, e.g. app.bsky.feed.generator.
cursorstringPagination cursor from a previous call.
enrichbooleanResolve each DID to its handle. Default false — returns DIDs only in ONE request (large page, the fast path for listing/counting). Set true only when you need handles (slower, smaller page).
limitintegerPage size (1-1000, default 1000). With enrich=true the effective page is capped near 20 (each DID is resolved to a handle). Use the returned cursor for the next page.
relaystringOptional relay origin to query instead of the default, e.g. https://relay.example.com.

Structured output declared, but exposes no named fields.

No examples provided.

query_labels ~209

What moderation labels a labeler has applied to a subject (com.atproto.label.queryLabels),e.g. 'has @alice or this post been labeled spam/nsfw/hidden by labeler X?'. Anonymous and service-agnostic: the labeler's own service endpoint is found from its DID document (no hardcoded aggregator). Subject is a DID/handle (account labels) or an at:// URI (record labels); labeler is the handle or DID of a labeler service (e.g. moderation.bsky.app).

NameTypeReqDescription
cursorstringPagination cursor from a previous call.
labelerstringyesThe labeler service to ask,a handle or DID, e.g. moderation.bsky.app.
limitintegerPage size (1-100, default 50). A cursor in the response means more pages exist.
subjectstringyesWhat to check: a DID/handle (account-level labels) or an at:// URI (record-level).

Structured output declared, but exposes no named fields.

No examples provided.

resolve ~198

Resolve any AT Protocol identifier to JSON. Accepts an at:// URI (at://<did-or-handle>/<collection>/<rkey>), a bare handle (alice.bsky.social), or a DID (did:plc:...). Returns a profile, a collection page, or a single record depending on how specific the input is. PDS-agnostic: works for any AT Protocol PDS, not just Bluesky.

NameTypeReqDescription
cursorstringPagination cursor (collections only).
includearrayOptional enrichments: 'schema' resolves the collection's lexicon; 'backlinks' lists who referenced the target; 'profile' adds the repo owner's display name, bio, and avatar URL.
limitintegerPage size (1-100, default 50). A cursor in the response means more pages exist.
uristringyesAn at:// URI, a bare handle, or a DID.

Structured output declared, but exposes no named fields.

No examples provided.

resolve_lexicon ~68

Explain what a record type means by resolving its lexicon schema. Input is a collection NSID (e.g. app.bsky.feed.post). Returns the schema's description and definition.

NameTypeReqDescription
nsidstringyesA collection NSID, e.g. app.bsky.feed.post.

Structured output declared, but exposes no named fields.

No examples provided.

search_accounts ~166

Search for AT Protocol accounts by handle or display name (paginated, via the Bluesky AppView app.bsky.actor.searchActors, so accounts unknown to that index may be missing). Returns candidate accounts with DID + handle, to turn a name into a DID. Results are search CANDIDATES, not verified handle-to-DID mappings: call verify_handle before trusting that a handle really belongs to a DID (resolve/get_profile only confirm an account exists, not that the handle is authentic).

NameTypeReqDescription
cursorstringPagination cursor from a previous call.
limitintegerPage size (1-100, default 50). A cursor in the response means more pages exist.
querystringyesA handle fragment or display name, e.g. "alice".

Structured output declared, but exposes no named fields.

No examples provided.

search_lexicons ~462

Browse or search the registry of published AT Protocol lexicon schemas. The response's `total` field is the exact registry size and `matched` is the exact match count. Substring matches the NSID or description (query 'profile' → anything containing 'profile'); prefix the query with a DOT for a suffix match (query '.profile' → only NSIDs ENDING in .profile, i.e. profile record types). Filter by schema kind with `type` — 'give me every space lexicon' is type='space' with NO query, since an NSID does not imply its type (space.saebyeok.permissionSet is a permission set; app.kimbia.circle is a space). Types: the spec's primary types are record, query, procedure, subscription, and permission-set; a main def may also be a non-primary type (object, token, string); space comes from proposal 0016 (permissioned data), which is not in the ratified spec; defs-only marks a schema file with no main definition. Every response carries a `typeCounts` breakdown of the returned matches (it sums to `matched`), so one call with no arguments shows which kinds exist and how many; when you filter by type, `otherTypes` reports what the filter excluded, so a too-narrow or misspelled type still shows you the real options. Without a query or type, returns the total plus a sample. Results are paginated by `limit`; to see matches beyond the first page, call again with the `offset` printed at the end of the list. Use resolve_lexicon for a specific schema's full definition.

NameTypeReqDescription
limitintegerPage size (1-100, default 50). A cursor in the response means more pages exist.
offsetintegerSkip this many matches (pagination). Use the offset value printed after a truncated list.
querystringOptional substring to filter by, e.g. "profile" or "app.bsky".
typeKeep only these schema kinds, e.g. "space" for permissioned space declarations, or ["record","procedure"]. Case-insensitive. Combine with query to search within a kind.

Structured output declared, but exposes no named fields.

No examples provided.

verify_handle ~78

Bidirectionally verify that a handle is really owned by its DID, via DNS TXT and HTTPS well-known. Returns whether each method passed. Use this to check for impersonation/spoofing,search results and resolve give candidates, this gives cryptographic binding.

NameTypeReqDescription
handlestringyesA handle, e.g. alice.bsky.social.

Structured output declared, but exposes no named fields.

No examples provided.

Common questions

What is the Taproot: AT Protocol MCP server?

Taproot: AT Protocol MCP is listed in the public MCP registry as com.atproto-mcp/taproot. Read public AT Protocol profiles, records, threads, backlinks and lexicons. No API key required. This page covers its hosted endpoint (https://mcp.atproto.at/mcp).

Is the Taproot: AT Protocol MCP server safe to use?

Taproot: AT Protocol MCP scores 70 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Taproot: AT Protocol MCP server expose?

Taproot: AT Protocol MCP exposes 27 tools: resolve, get_profile, get_record, list_records, get_backlinks, and 22 more. Their descriptions and schemas cost roughly 3,960 tokens of context every time the server is loaded.

Does the Taproot: AT Protocol MCP server require authentication?

No. We connected to Taproot: AT Protocol MCP without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the Taproot: AT Protocol MCP server still maintained?

Taproot: AT Protocol MCP is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.