Taproot: AT Protocol MCP
REMOTE · MCP.ATPROTO.AT · SCANNED SEP 20
Read public AT Protocol profiles, records, threads, backlinks and lexicons. No API key required.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 27 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability83
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 4847 tokens (~179/item across 27 items; 27 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management23
- Stability observed for 7 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 27 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 28 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
- Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
How do I install the Taproot: AT Protocol MCP server?
Taproot: AT Protocol MCP is a hosted endpoint at https://mcp.atproto.at/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.atproto.at
claude mcp add --transport http com-atproto-mcp-taproot 'https://mcp.atproto.at/mcp'
{
"mcpServers": {
"com-atproto-mcp-taproot": {
"url": "https://mcp.atproto.at/mcp"
}
}
} {
"servers": {
"com-atproto-mcp-taproot": {
"type": "http",
"url": "https://mcp.atproto.at/mcp"
}
}
} [mcp_servers.com-atproto-mcp-taproot] url = "https://mcp.atproto.at/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-atproto-mcp-taproot": {
"type": "remote",
"url": "https://mcp.atproto.at/mcp",
"enabled": true
}
}
} openclaw mcp add com-atproto-mcp-taproot --url 'https://mcp.atproto.at/mcp' --transport streamable-http
mcp_servers:
com-atproto-mcp-taproot:
url: "https://mcp.atproto.at/mcp" {
"McpServers": {
"com-atproto-mcp-taproot": {
"Transport": "http",
"Url": "https://mcp.atproto.at/mcp"
}
}
} assistant mcp add com-atproto-mcp-taproot -t streamable-http -u 'https://mcp.atproto.at/mcp'
{
"mcpServers": {
"com-atproto-mcp-taproot": {
"type": "http",
"url": "https://mcp.atproto.at/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.
- 18 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 13 to 17. That category is still filling its 30-day observation window: 4 days of observed history at the previous scan, 5 at this one. The score rises as the window fills, whether or not the server changes.
- 15 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 14 Sept 26 0
- Stability: unverified → 0.03 ▲ functional
- 13 Sept 26 67
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://mcp.atproto.at/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=mcp.atproto.at | CN=WE1,O=Google Trust Services,C=US | 31 Aug 2026 | 29 Nov 2026 | ECDSA 256 | ECDSA-SHA256 | 5c83789f71b47fbe1386acee5ed554c1 |
| SANs: mcp.atproto.at | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.atproto.at. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| at. | present | 1253, 60960 | 13, 13 | Verified |
| atproto.at. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
| content-security-policy | default-src 'self'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; object-src 'none'; script-src 'self' 'unsafe-inline' https://static.cloudflareinsights.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; img-src 'self' data: blob: https:; media-src 'self' blob: https:; font-src 'self' data: https://fonts.gstatic.com; frame-src 'self' https://www.youtube-nocookie.com https://www.youtube.com; connect-src 'self' https: wss: |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(), geolocation=() |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.atproto.at/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.atproto.at/mcp | HTTPS enforced | 301 | https://mcp.atproto.at/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
count_records ~141
Count the total records in an account's collection (e.g. how many likes a user has given). Scans server-side so you don't page manually. AT Protocol has no cheap exact count, so for very large collections this returns exact:false with a lower-bound count and a cursor,call again with that cursor and ADD the counts to keep going.
| Name | Type | Req | Description |
|---|---|---|---|
| collection | string | yes | Collection NSID, e.g. app.bsky.feed.like. |
| cursor | string | – | Resume cursor from a prior capped (exact:false) count. The new count covers records AFTER it,add it to your previous total. |
| repo | string | yes | A handle or DID. |
Structured output declared, but exposes no named fields.
No examples provided.
count_repos_by_collection ~177
Count how many accounts across the network publish a given collection/lexicon,e.g. 'how many accounts have an at.glean.subscription?'. Walks a relay's com.atproto.sync.listReposByCollection with NO per-account handle resolution, so it's cheap and returns an exact total for typical collections. For very large collections it returns exact:false with a cursor,call again with that cursor and ADD the counts (like count_records). Relay-served (defaults to the public Bluesky relay; pass `relay` for another).
| Name | Type | Req | Description |
|---|---|---|---|
| collection | string | yes | A collection NSID, e.g. app.bsky.feed.generator. |
| cursor | string | – | Resume cursor from a previous exact:false response. |
| relay | string | – | Optional relay origin to query instead of the default, e.g. https://relay.example.com. |
Structured output declared, but exposes no named fields.
No examples provided.
describe_pds ~89
Describe a Personal Data Server: its DID, whether registration requires an invite, the handle domains you can register there, and ToS/contact links. Works for any PDS, not just Bluesky. Input is the PDS origin (e.g. https://pds.example.com).
| Name | Type | Req | Description |
|---|---|---|---|
| pds | string | yes | A PDS origin URL, e.g. https://pds.example.com. |
Structured output declared, but exposes no named fields.
No examples provided.
get_account_history ~71
An account's history from its PLC audit log: handle changes, PDS migrations, signing-key rotations, and creation time. did:plc accounts only (did:web has no PLC log). Input is a handle or DID.
| Name | Type | Req | Description |
|---|---|---|---|
| actor | string | yes | A handle or DID (did:plc). |
Structured output declared, but exposes no named fields.
No examples provided.
get_app_link ~76
Turn an at:// URI (or handle/DID) into shareable web links,a Bluesky/Blacksky app URL to open in a browser, plus the canonical PDS getRecord URL. Use when the user wants a clickable/pasteable link.
| Name | Type | Req | Description |
|---|---|---|---|
| uri | string | yes | An at:// URI, handle, or DID. |
Structured output declared, but exposes no named fields.
No examples provided.
get_backlinks ~121
Index of who/what references a target,the inbound likes, reposts, quotes, replies, and follows,as COUNTS per category, via the Constellation backlink index. Target is a record's at:// URI or an account DID. This returns aggregate counts only; each category also includes a `source` string. To list the actual records and their author DIDs for one category (e.g. WHO liked a post), call list_backlink_records with that `source`.
| Name | Type | Req | Description |
|---|---|---|---|
| target | string | yes | A record at:// URI or a DID. |
Structured output declared, but exposes no named fields.
No examples provided.
get_blob_info ~128
Get metadata for a single blob: its canonical PDS getBlob URL plus a best-effort content-type and byte size (via a HEAD request). Returns the URL, never the bytes. Use to turn a blob ref (CID) found in a record into a downloadable link and learn what it is. Input is the owning repo (handle or DID) and the blob CID.
| Name | Type | Req | Description |
|---|---|---|---|
| cid | string | yes | The blob CID (e.g. bafkrei...), as found in a record's blob ref. |
| repo | string | yes | A handle or DID (the blob's owning repo). |
Structured output declared, but exposes no named fields.
No examples provided.
get_did_document ~77
Fetch the raw DID document for any DID or handle: all aliases (alsoKnownAs), every service entry (PDS, labeler, custom AppView), and verification methods. Broader than get_profile, and works for did:web accounts. Input is a handle or DID.
| Name | Type | Req | Description |
|---|---|---|---|
| actor | string | yes | A handle or DID. |
Structured output declared, but exposes no named fields.
No examples provided.
get_latest_commit ~88
The current head commit of an account's repository (com.atproto.sync.getLatestCommit): its commit CID and revision. The cheapest way to fingerprint a repo or detect whether it changed since you last looked, without downloading data. Complements get_repo_status (which has the rev but not the commit CID). Input is a handle or DID.
| Name | Type | Req | Description |
|---|---|---|---|
| repo | string | yes | A handle or DID. |
Structured output declared, but exposes no named fields.
No examples provided.
get_pds_directory_info ~91
A cached health card for a PDS from pds.directory: version, DID, approximate user count, reachability, last-checked time, available domains, and which relays index it. Input is the PDS hostname (e.g. pds.example.com). Best-effort/cached data.
| Name | Type | Req | Description |
|---|---|---|---|
| hostname | string | yes | A PDS hostname, e.g. pds.example.com. |
Structured output declared, but exposes no named fields.
No examples provided.
get_profile ~107
Get an account's repository overview (handle, DID, PDS, and the list of collections it contains). Input is a handle or DID.
| Name | Type | Req | Description |
|---|---|---|---|
| actor | string | yes | A handle (alice.bsky.social) or DID (did:plc:...). |
| include | array | – | Optional enrichments: 'schema' resolves the collection's lexicon; 'backlinks' lists who referenced the target; 'profile' adds the repo owner's display name, bio, and avatar URL. |
Structured output declared, but exposes no named fields.
No examples provided.
get_record ~108
Fetch a single record by its full at:// URI (must include collection and rkey). Returns the record's value, CID, and resolved identity.
| Name | Type | Req | Description |
|---|---|---|---|
| include | array | – | Optional enrichments: 'schema' resolves the collection's lexicon; 'backlinks' lists who referenced the target; 'profile' adds the repo owner's display name, bio, and avatar URL. |
| uri | string | yes | Full at:// URI: at://<did-or-handle>/<collection>/<rkey>. |
Structured output declared, but exposes no named fields.
No examples provided.
get_relay_directory_info ~79
A cached overview of a relay from firehose.directory: counts of PDSes it indexes (total/active/offline/banned) and total accounts. Input is the relay hostname (e.g. bsky.network). Best-effort/cached data.
| Name | Type | Req | Description |
|---|---|---|---|
| hostname | string | yes | A relay hostname, e.g. bsky.network. |
Structured output declared, but exposes no named fields.
No examples provided.
get_repo_status ~75
Liveness/moderation status of an account's repository: whether it is active, its current revision, and any takedown/suspended/deactivated/deleted state. Answers 'has @alice been taken down?' which get_profile can't. Input is a handle or DID.
| Name | Type | Req | Description |
|---|---|---|---|
| repo | string | yes | A handle or DID. |
Structured output declared, but exposes no named fields.
No examples provided.
get_thread ~194
Reconstruct the conversation around a post: its ancestor chain up to the thread root (following reply.parent, root-first) PLUS a bounded descendant reply TREE,replies, replies-to-replies, and so on, each tagged with its depth and parent,walked breadth-first and capped for cost. NOTE: descendant expansion assumes the Bluesky reply model (app.bsky.feed.post with reply.parent); ancestor walking follows reply.parent generically, but the reply tree is specific to that lexicon and will be empty for record types that model replies differently. Answers 'show me this whole conversation / what is this replying to?'. If the tree is truncated, use list_backlink_records on a specific post's URI to expand it further. Input is a post's at:// URI.
| Name | Type | Req | Description |
|---|---|---|---|
| uri | string | yes | A post's full at:// URI: at://<did-or-handle>/app.bsky.feed.post/<rkey>. |
Structured output declared, but exposes no named fields.
No examples provided.
list_backlink_records ~213
List the actual records (author DID + verified handle + at:// URI, newest first) that reference a target for ONE category,i.e. WHO liked, reposted, quoted, replied to, mentioned, or follows it. Workflow: call get_backlinks first to get a category `source`, then pass it here. To read WHAT a referencing record says (e.g. the text of a mention or reply), call get_record on its at:// URI. Author handles are resolved via identity resolution (verified), not search.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | Pagination cursor returned by a previous call (to get the next page). |
| limit | integer | – | Page size (1-25, default 25). Use the returned cursor for the next page. |
| source | string | yes | A category `source` from get_backlinks, e.g. app.bsky.feed.like:subject.uri. |
| target | string | yes | The referenced record at:// URI or account DID (same target passed to get_backlinks). |
Structured output declared, but exposes no named fields.
No examples provided.
list_blobs ~160
List the blobs (uploaded media/attachments,images, video, etc.) hosted in an account's repository, via com.atproto.sync.listBlobs. Returns each blob's CID and its canonical PDS getBlob URL (PDS-native, works for any PDS,not a CDN). Answers 'what media does this account host?'. Records reference blobs by CID; use this (or get_blob_info) to turn a CID into a fetchable URL. Input is a handle or DID.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | Pagination cursor from a previous call. |
| limit | integer | – | Page size (1-100, default 50). A cursor in the response means more pages exist. |
| repo | string | yes | A handle or DID. |
Structured output declared, but exposes no named fields.
No examples provided.
list_labelers ~118
List the labeler (moderation) services known to the labeler relay,each labeler's DID, resolved handle, and service endpoint. The discovery step BEFORE query_labels, which needs a labeler DID/handle up front: use this to find moderation.bsky.app and any third-party/regional labelers, then pass one to query_labels.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | Pagination cursor from a previous call. |
| limit | integer | – | Page size (1-20, default 20). Use the returned cursor for the next page. |
Structured output declared, but exposes no named fields.
No examples provided.
list_records ~113
List records in a collection for an account, with pagination. Provide the repo (handle or DID) and the collection NSID (e.g. app.bsky.feed.post).
| Name | Type | Req | Description |
|---|---|---|---|
| collection | string | yes | Collection NSID, e.g. app.bsky.feed.post. |
| cursor | string | – | Pagination cursor from a previous page. |
| limit | integer | – | Page size (1-100, default 50). A cursor in the response means more pages exist. |
| repo | string | yes | A handle or DID. |
Structured output declared, but exposes no named fields.
No examples provided.
list_repos ~252
List the accounts (repositories) hosted on a PDS, via com.atproto.sync.listRepos: each repo's DID and active/takedown status, paginated. Answers 'who is hosted on this PDS?' / 'how many accounts does this PDS have?'. By default returns DIDs only (one request, large page — best for counting); pass enrich=true to also resolve handles (slower, smaller page). Input is the PDS origin (e.g. https://pds.example.com). Works for any PDS.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | Pagination cursor from a previous call. |
| enrich | boolean | – | Resolve each DID to its handle. Default false — returns DIDs only in ONE request (large page, the fast path for listing/counting). Set true only when you need handles (slower, smaller page). |
| limit | integer | – | Page size (1-1000, default 1000). With enrich=true the effective page is capped near 20 (each DID is resolved to a handle). Use the returned cursor for the next page. |
| pds | string | yes | A PDS origin URL, e.g. https://pds.example.com. |
Structured output declared, but exposes no named fields.
No examples provided.
list_repos_by_collection ~301
Network-wide: which accounts publish a given collection/lexicon,e.g. 'who has an app.bsky.feed.generator (a custom feed)?' or who uses a custom lexicon. Via a relay's com.atproto.sync.listReposByCollection (anonymous). By default returns DIDs only (one request, large page); pass enrich=true to also resolve handles (slower, smaller page). For just a total, use count_repos_by_collection. NOTE: relay-served (defaults to the public Bluesky relay; pass `relay` to query another), not the account's own PDS. Pairs with search_lexicons / resolve_lexicon.
| Name | Type | Req | Description |
|---|---|---|---|
| collection | string | yes | A collection NSID, e.g. app.bsky.feed.generator. |
| cursor | string | – | Pagination cursor from a previous call. |
| enrich | boolean | – | Resolve each DID to its handle. Default false — returns DIDs only in ONE request (large page, the fast path for listing/counting). Set true only when you need handles (slower, smaller page). |
| limit | integer | – | Page size (1-1000, default 1000). With enrich=true the effective page is capped near 20 (each DID is resolved to a handle). Use the returned cursor for the next page. |
| relay | string | – | Optional relay origin to query instead of the default, e.g. https://relay.example.com. |
Structured output declared, but exposes no named fields.
No examples provided.
query_labels ~209
What moderation labels a labeler has applied to a subject (com.atproto.label.queryLabels),e.g. 'has @alice or this post been labeled spam/nsfw/hidden by labeler X?'. Anonymous and service-agnostic: the labeler's own service endpoint is found from its DID document (no hardcoded aggregator). Subject is a DID/handle (account labels) or an at:// URI (record labels); labeler is the handle or DID of a labeler service (e.g. moderation.bsky.app).
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | Pagination cursor from a previous call. |
| labeler | string | yes | The labeler service to ask,a handle or DID, e.g. moderation.bsky.app. |
| limit | integer | – | Page size (1-100, default 50). A cursor in the response means more pages exist. |
| subject | string | yes | What to check: a DID/handle (account-level labels) or an at:// URI (record-level). |
Structured output declared, but exposes no named fields.
No examples provided.
resolve ~198
Resolve any AT Protocol identifier to JSON. Accepts an at:// URI (at://<did-or-handle>/<collection>/<rkey>), a bare handle (alice.bsky.social), or a DID (did:plc:...). Returns a profile, a collection page, or a single record depending on how specific the input is. PDS-agnostic: works for any AT Protocol PDS, not just Bluesky.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | Pagination cursor (collections only). |
| include | array | – | Optional enrichments: 'schema' resolves the collection's lexicon; 'backlinks' lists who referenced the target; 'profile' adds the repo owner's display name, bio, and avatar URL. |
| limit | integer | – | Page size (1-100, default 50). A cursor in the response means more pages exist. |
| uri | string | yes | An at:// URI, a bare handle, or a DID. |
Structured output declared, but exposes no named fields.
No examples provided.
resolve_lexicon ~68
Explain what a record type means by resolving its lexicon schema. Input is a collection NSID (e.g. app.bsky.feed.post). Returns the schema's description and definition.
| Name | Type | Req | Description |
|---|---|---|---|
| nsid | string | yes | A collection NSID, e.g. app.bsky.feed.post. |
Structured output declared, but exposes no named fields.
No examples provided.
search_accounts ~166
Search for AT Protocol accounts by handle or display name (paginated, via the Bluesky AppView app.bsky.actor.searchActors, so accounts unknown to that index may be missing). Returns candidate accounts with DID + handle, to turn a name into a DID. Results are search CANDIDATES, not verified handle-to-DID mappings: call verify_handle before trusting that a handle really belongs to a DID (resolve/get_profile only confirm an account exists, not that the handle is authentic).
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | Pagination cursor from a previous call. |
| limit | integer | – | Page size (1-100, default 50). A cursor in the response means more pages exist. |
| query | string | yes | A handle fragment or display name, e.g. "alice". |
Structured output declared, but exposes no named fields.
No examples provided.
search_lexicons ~462
Browse or search the registry of published AT Protocol lexicon schemas. The response's `total` field is the exact registry size and `matched` is the exact match count. Substring matches the NSID or description (query 'profile' → anything containing 'profile'); prefix the query with a DOT for a suffix match (query '.profile' → only NSIDs ENDING in .profile, i.e. profile record types). Filter by schema kind with `type` — 'give me every space lexicon' is type='space' with NO query, since an NSID does not imply its type (space.saebyeok.permissionSet is a permission set; app.kimbia.circle is a space). Types: the spec's primary types are record, query, procedure, subscription, and permission-set; a main def may also be a non-primary type (object, token, string); space comes from proposal 0016 (permissioned data), which is not in the ratified spec; defs-only marks a schema file with no main definition. Every response carries a `typeCounts` breakdown of the returned matches (it sums to `matched`), so one call with no arguments shows which kinds exist and how many; when you filter by type, `otherTypes` reports what the filter excluded, so a too-narrow or misspelled type still shows you the real options. Without a query or type, returns the total plus a sample. Results are paginated by `limit`; to see matches beyond the first page, call again with the `offset` printed at the end of the list. Use resolve_lexicon for a specific schema's full definition.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Page size (1-100, default 50). A cursor in the response means more pages exist. |
| offset | integer | – | Skip this many matches (pagination). Use the offset value printed after a truncated list. |
| query | string | – | Optional substring to filter by, e.g. "profile" or "app.bsky". |
| type | – | – | Keep only these schema kinds, e.g. "space" for permissioned space declarations, or ["record","procedure"]. Case-insensitive. Combine with query to search within a kind. |
Structured output declared, but exposes no named fields.
No examples provided.
verify_handle ~78
Bidirectionally verify that a handle is really owned by its DID, via DNS TXT and HTTPS well-known. Returns whether each method passed. Use this to check for impersonation/spoofing,search results and resolve give candidates, this gives cryptographic binding.
| Name | Type | Req | Description |
|---|---|---|---|
| handle | string | yes | A handle, e.g. alice.bsky.social. |
Structured output declared, but exposes no named fields.
No examples provided.
What is the Taproot: AT Protocol MCP server?
Taproot: AT Protocol MCP is listed in the public MCP registry as com.atproto-mcp/taproot. Read public AT Protocol profiles, records, threads, backlinks and lexicons. No API key required. This page covers its hosted endpoint (https://mcp.atproto.at/mcp).
Is the Taproot: AT Protocol MCP server safe to use?
Taproot: AT Protocol MCP scores 70 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Taproot: AT Protocol MCP server expose?
Taproot: AT Protocol MCP exposes 27 tools: resolve, get_profile, get_record, list_records, get_backlinks, and 22 more. Their descriptions and schemas cost roughly 3,960 tokens of context every time the server is loaded.
Does the Taproot: AT Protocol MCP server require authentication?
No. We connected to Taproot: AT Protocol MCP without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Taproot: AT Protocol MCP server still maintained?
Taproot: AT Protocol MCP is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.