What Led To
REMOTE · WHATLEDTO.COM · SCANNED SEP 28
Living, source-backed timelines of long-running events, with a quote and source per entry.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 7 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability70
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1388 tokens (~198/item across 7 items; 7 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management53
- Stability observed for 16 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 7 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 8 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the What Led To MCP server?
What Led To is a hosted endpoint at https://whatledto.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · whatledto.com
claude mcp add --transport http com-whatledto-whatledto 'https://whatledto.com/mcp'
{
"mcpServers": {
"com-whatledto-whatledto": {
"url": "https://whatledto.com/mcp"
}
}
} {
"servers": {
"com-whatledto-whatledto": {
"type": "http",
"url": "https://whatledto.com/mcp"
}
}
} [mcp_servers.com-whatledto-whatledto] url = "https://whatledto.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-whatledto-whatledto": {
"type": "remote",
"url": "https://whatledto.com/mcp",
"enabled": true
}
}
} openclaw mcp add com-whatledto-whatledto --url 'https://whatledto.com/mcp' --transport streamable-http
mcp_servers:
com-whatledto-whatledto:
url: "https://whatledto.com/mcp" {
"McpServers": {
"com-whatledto-whatledto": {
"Transport": "http",
"Url": "https://whatledto.com/mcp"
}
}
} assistant mcp add com-whatledto-whatledto -t streamable-http -u 'https://whatledto.com/mcp'
{
"mcpServers": {
"com-whatledto-whatledto": {
"type": "http",
"url": "https://whatledto.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 28 Sept 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 43 to 47. That category is still filling its 30-day observation window: 13 days of observed history at the previous scan, 14 at this one. The score rises as the window fills, whether or not the server changes.
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 23 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 33 to 37. That category is still filling its 30-day observation window: 10 days of observed history at the previous scan, 11 at this one. The score rises as the window fills, whether or not the server changes.
- 21 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 27 to 30. That category is still filling its 30-day observation window: 8 days of observed history at the previous scan, 9 at this one. The score rises as the window fills, whether or not the server changes.
- 19 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 13 to 17. That category is still filling its 30-day observation window: 4 days of observed history at the previous scan, 5 at this one. The score rises as the window fills, whether or not the server changes.
- 15 Sept 26 +1
- The server rewrote its instructions, which are the text every model session reads security
- Server version: 1.3.0 → 1.4.0 functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 28 Sept 2026 · Probed https://whatledto.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=whatledto.com | CN=WE1,O=Google Trust Services,C=US | 3 Sept 2026 | 2 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | 7ef9864bfb0baa9a0e4e65028dfe25a6 |
| SANs: whatledto.com, *.whatledto.com | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of whatledto.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| whatledto.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://whatledto.com/mcp | Verified | 200 | |
| http (plaintext) | http://whatledto.com/mcp | HTTPS enforced | 301 | https://whatledto.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
ask Ask a why or how question ~146
Answer a why/how question as a chain: an ordered set of dated, sourced entries from the timelines with one line on why each led to the next, written by the editor rather than generated. Returns the best-matching chain with every step's entry (URL, date, summary, sources), or, when no chain fits, the questions that do exist and how to research the answer with the other tools.
| Name | Type | Req | Description |
|---|---|---|---|
| question | string | yes | The question in plain words, e.g. "Why did Nvidia become so dominant in AI?" |
| since | string | – | Also return what changed on the chain since this day (its changelog entries after it); pass the updated_at you last saw. |
No output schema declared.
No examples provided.
get_entry Get an entry ~159
One dated entry in full: its summary, type, the parties it names, every source with the outlet, the publication date and the verbatim quote it was read from, plus the relations and cross-timeline links it takes part in. Use it after search_entries or get_timeline has found an entry and you need the exact wording and source URL to cite. Entry ids are unique within a timeline, not across the site, so pass the slug the entry came from.
| Name | Type | Req | Description |
|---|---|---|---|
| id | integer | yes | The entry's id on that timeline: the id field of a search_entries result or a get_timeline node, and the number in a page's #n<id> fragment. |
| slug | string | yes | The timeline the entry sits on. |
No output schema declared.
No examples provided.
get_party Get a company, person or regulator ~177
Everything the site records about one company, person or regulator across every timeline: its role on each, the parties it most often appears alongside, and every dated entry that names it, newest first, with sources. Use it instead of search_entries when you want one actor's whole history rather than a keyword match. Returns at most limit entries, with total_entries saying how many exist; a party is named when the editors listed it among an entry's parties, not merely when the name appears in the text.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Party id: a lowercase slug such as nvidia, jensen-huang or federal-reserve. search_entries results and timeline entities carry it, and the parties that have a page are listed under parties in /index.… |
| limit | integer | – | Entries to return, newest first (default 40). |
No output schema declared.
No examples provided.
get_timeline Get a timeline ~132
One timeline in full: TL;DR, dated entries newest first with sources and quotes, relations between entries, links to other timelines, what to watch next and open questions. Pass since=YYYY-MM-DD to get only entries dated on or after that day (what changed recently).
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Most recent entries to return (default 60). |
| since | string | – | Only entries dated on or after this day. Pass the updated_at you last saw to get what changed since. |
| slug | string | yes | Timeline slug, from list_timelines or a page URL (/events/<slug>). |
No output schema declared.
No examples provided.
list_timelines List timelines ~44
Every timeline on the site with its topic, tags, entry count, date range, last update and a short summary. Start here to find the slug for get_timeline.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
search_entries Search entries ~168
Find dated entries across every timeline by keywords, party id, timeline slug and date range. Every keyword must match (title, summary, party or timeline name); results are ranked, newest first among equals. Returns the entry text and url; call get_entry for quotes and sources.
| Name | Type | Req | Description |
|---|---|---|---|
| from | string | – | Earliest entry date to include. |
| limit | integer | – | Results to return (default 20); total says how many matched. |
| party | string | – | Only entries naming this party id. |
| query | string | – | Keywords. Every one must match, in the entry's title, summary, a party name or the timeline name; omit it to browse by filter alone. |
| timeline | – | – | Only entries on this timeline slug. |
| to | – | – | Latest entry date to include. |
No output schema declared.
No examples provided.
upcoming Upcoming dates ~135
Scheduled dates the timelines are watching — earnings, rulings, launches, rule deadlines — each with why it matters, the timeline it belongs to and a source where one exists. Use it to answer what happens next across the site, rather than reading each timeline for its own catalysts. Returns the dates from today to the horizon, oldest first, echoing back today and horizon; a date known only to the month carries precision=month and is matched on the month.
| Name | Type | Req | Description |
|---|---|---|---|
| days | integer | – | How far ahead to look, in days from today (default 90). |
| timeline | string | – | Only dates belonging to this timeline slug. |
No output schema declared.
No examples provided.
What is the What Led To MCP server?
What Led To is an MCP server listed in the public MCP registry as com.whatledto/whatledto. Living, source-backed timelines of long-running events, with a quote and source per entry. This page covers its hosted endpoint (https://whatledto.com/mcp).
Is the What Led To MCP server safe to use?
What Led To scores 71 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the What Led To MCP server expose?
What Led To exposes 7 tools: list_timelines, get_timeline, get_entry, get_party, search_entries, and 2 more. Their descriptions and schemas cost roughly 961 tokens of context every time the server is loaded.
Does the What Led To MCP server require authentication?
No. We connected to What Led To without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the What Led To MCP server still maintained?
What Led To is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.