SwarmIO
REMOTE · IOSWARM.IO · SCANNED SEP 22
AI that does real work for you: cited web research, plans, finance, horoscopes. Self-serve.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: this server exposes a tool marked destructive (runs.cancel) and its handshake is open, but we could not confirm whether a tool call is gated, so we do not assert it is callable unauthenticated. View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability82
- AI-judged instruction clarity (excellent).Pass
- Tool/resource definitions use about 1057 tokens (~88/item across 12 items; 12 tools + 0 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
- Stability check failed: schema churn in the 26 days we've observed: 8 tool removals, 0 breaking changes, 0 auth/transport breaks, 12 additions. See how to fix → Fail
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 12 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 13 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
- Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
How do I install the SwarmIO MCP server?
SwarmIO is a hosted endpoint at https://ioswarm.io/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · ioswarm.io
claude mcp add --transport http io-ioswarm-swarmio 'https://ioswarm.io/mcp'
{
"mcpServers": {
"io-ioswarm-swarmio": {
"url": "https://ioswarm.io/mcp"
}
}
} {
"servers": {
"io-ioswarm-swarmio": {
"type": "http",
"url": "https://ioswarm.io/mcp"
}
}
} [mcp_servers.io-ioswarm-swarmio] url = "https://ioswarm.io/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"io-ioswarm-swarmio": {
"type": "remote",
"url": "https://ioswarm.io/mcp",
"enabled": true
}
}
} openclaw mcp add io-ioswarm-swarmio --url 'https://ioswarm.io/mcp' --transport streamable-http
mcp_servers:
io-ioswarm-swarmio:
url: "https://ioswarm.io/mcp" {
"McpServers": {
"io-ioswarm-swarmio": {
"Transport": "http",
"Url": "https://ioswarm.io/mcp"
}
}
} assistant mcp add io-ioswarm-swarmio -t streamable-http -u 'https://ioswarm.io/mcp'
{
"mcpServers": {
"io-ioswarm-swarmio": {
"type": "http",
"url": "https://ioswarm.io/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 17 Sept 26 0
- The server rewrote its instructions, which are the text every model session reads security
- Schema quality: 69 → 88 ▼ functional
- New tool “fetch” functional
- New tool “market.pulse” functional
- New tool “runs.wait” functional
- New tool “search” functional
- 28 Aug 26 +4
- Stability: unverified → fail ▼ security
- A breaking change shipped without a version bump: still 0.1.0 ▼ security
- Tool “cancel_run” was removed ▼ security
- Tool “get_balance” was removed ▼ security
- Tool “get_report” was removed ▼ security
- Tool “get_run” was removed ▼ security
- Tool “get_topup_terms” was removed ▼ security
- Tool “launch_run” was removed ▼ security
- Tool “list_modes” was removed ▼ security
- Tool “route_prompt” was removed ▼ security
- The server rewrote its instructions, which are the text every model session reads security
- New tool “runs.cancel”, which the server declares destructive security
- Schema quality: 52 → 69 ▼ functional
- Tool coverage: 29% → 100% ▲ functional
- First check of Tool coverage: 100 functional
- Schema quality: good → excellent functional
- New tool “billing.balance” functional
- New tool “billing.topup_terms” functional
- New tool “modes.list” functional
- New tool “route.classify” functional
- New tool “runs.get” functional
- New tool “runs.launch” functional
- New tool “runs.report” functional
- 27 Aug 26 60
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 22 Sept 2026 · Probed https://ioswarm.io/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=ioswarm.io | CN=YE1,O=Let's Encrypt,C=US | 30 Jul 2026 | 28 Oct 2026 | ECDSA 256 | ECDSA-SHA384 | 50554ed406289a2c18aaee61d230d6619ea |
| SANs: ioswarm.io, www.ioswarm.io | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of ioswarm.io. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| io. | present | 57355 | 8 | Verified |
| ioswarm.io. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://ioswarm.io/mcp | Verified | 200 | |
| http (plaintext) | http://ioswarm.io/mcp | HTTPS enforced | 301 | https://ioswarm.io/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
billing.balance ~17
The caller's credit balance and plan state.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| balance | number | yes | Credits available right now. |
| currency | string | – | – |
| granted_total | number | – | Credits ever granted (welcome + top-ups). |
| plan | string | – | – |
| spent_total | number | – | Credits ever spent on runs. |
| user_id | string | – | – |
No examples provided.
billing.topup_terms ~48
How to refill credits machine-to-machine: USDC on Base to a published address, verified on-chain. Returns the pay_to address, minimum, and rate. Public — no credentials needed.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| asset | string | yes | 'USDC'. |
| chain_id | integer | – | 8453 (Base mainnet). |
| contract | string | yes | The USDC token contract to transfer. |
| credits_per_usd | number | yes | Base rate; volume bonus applies on top. |
| enabled | boolean | yes | False while the operator has published no receiving address. |
| how | string | yes | The exact top-up procedure, step by step. |
| min_confirmations | integer | yes | Confirmations required before crediting. |
| min_usd | number | yes | Smallest top-up accepted, in USD. |
| network | string | yes | 'base'. |
| pay_to | string | – | The receiving address — present when enabled is true. |
No examples provided.
fetch ~64
Read one report by the id search returned: the full markdown text with its citations and evidence header, plus title, url and metadata. Public reports need no key; a caller's own reports need theirs.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | A result id from search (a run id). |
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
| metadata | object | – | – |
| text | string | yes | The report as markdown. |
| title | string | yes | – |
| url | string | yes | – |
No examples provided.
market.pulse ~94
FREE, no key, no account: live prices for BTC, ETH, SOL, AMZN and NVDA with the session's change, plus today's news — the platform's newest published news digest parsed into stories with source links, and the market wire's latest headlines. Refreshed every minute (prices) and every ten minutes (news). Call this first to see what the swarm's data looks like before spending anything.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| as_of | string | yes | RFC 3339 time this document was rendered. |
| attribution | string | – | – |
| free | boolean | – | Always true — this call is never charged. |
| news | object | yes | – |
| next | object | – | How to get the same data over MCP and how to commission a real report. |
| prices | array | yes | One entry per symbol that priced this cycle, in list order. |
| prices_as_of | string|null | – | – |
| symbols | array | – | The fixed symbol list served. |
No examples provided.
modes.list ~29
The launchable modes with a one-line contract for each. Static; never charged, no credentials needed.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| modes | array | yes | – |
| route_first | string | – | How to classify a freeform prompt into a mode id. |
No examples provided.
route.classify ~64
Classify a freeform request into the right mode (research, news, finance, astrology, …) before spending a run. Never charged.
| Name | Type | Req | Description |
|---|---|---|---|
| prompt | string | yes | The freeform request to classify, e.g. 'compare the best espresso grinders under $300'. |
| Name | Type | Req | Description |
|---|---|---|---|
| alternates | array | – | Other plausible modes, best first. |
| confidence | number | yes | Router confidence, 0–1. |
| fields | object | – | Fields the router extracted from the prompt (mode-specific). |
| from_llm | boolean | – | True when the LLM router answered, false for the offline heuristic. |
| mode | string | yes | The chosen mode id — pass it to runs.launch. |
| rationale | string | – | Why this mode was picked. |
No examples provided.
runs.cancel ~28
Stop a running job.
| Name | Type | Req | Description |
|---|---|---|---|
| run_id | string | yes | The run_id returned by runs.launch. |
| Name | Type | Req | Description |
|---|---|---|---|
| run_id | string | yes | – |
| status | string | yes | 'cancelling' — the run unwinds itself; poll runs.get for the terminal state. |
No examples provided.
runs.get ~41
A run's status and metadata. Poll until status is completed/failed/cancelled.
| Name | Type | Req | Description |
|---|---|---|---|
| run_id | string | yes | The run_id returned by runs.launch. |
| Name | Type | Req | Description |
|---|---|---|---|
| cancelling | boolean | – | A stop was requested but the run has not unwound yet. |
| error | string|object|null | – | Failure detail when status is failed, else null. |
| finished_at | string|null | – | RFC 3339 completion time; null while running. |
| has_report | boolean | – | True once runs.report will answer with the report. |
| meta | object | – | Run metadata: id, mode, title, timing. |
| status | string | – | running | completed | failed | cancelled. |
| usage | object|null | – | Token meters for the run — null while the run is still running, an object once it settles. |
No examples provided.
runs.launch ~190
Launch a run: agents search the web, read sources, and write a cited report — real work, done for the caller. BILLED from the caller's credits. Returns the run record; poll runs.get until completed, then runs.report. Modes: research, news, product, trips, trainer, finance, astrology, horoscope (astrology/horoscope take Birth date constraint lines — see https://ioswarm.io/llms.txt).
| Name | Type | Req | Description |
|---|---|---|---|
| input | string | yes | The question or brief. astrology/horoscope take constraint lines ('- Birth date: YYYY-MM-DD', optional Birth time + Timezone, Latitude/Longitude) — contract at https://ioswarm.io/llms.txt. |
| max_workers | integer | – | Optional parallelism override (worker count). Omit for the mode default. |
| mode | string | yes | A mode id from modes.list, e.g. 'research'. |
| Name | Type | Req | Description |
|---|---|---|---|
| estimated_credits | number | – | The credit estimate reserved at launch; settled from real usage at completion. |
| run_id | string | yes | The run's id — pass to runs.get / runs.report / runs.cancel. |
| status | string | yes | 'running' on acceptance. |
No examples provided.
runs.report ~38
The finished, cited report for a completed run (report_text is markdown).
| Name | Type | Req | Description |
|---|---|---|---|
| run_id | string | yes | The run_id returned by runs.launch. |
| Name | Type | Req | Description |
|---|---|---|---|
| report_text | string | – | The full report as markdown, citations inline. |
No examples provided.
runs.wait ~120
Block until a run finishes, then return its record — and its report when it completed. Runs take 3–10 minutes; call this instead of polling runs.get in a loop. Returns early with timed_out=true after timeout_secs (default 90, max 240): call it again with the same run_id to keep waiting. Never charged.
| Name | Type | Req | Description |
|---|---|---|---|
| run_id | string | yes | The run_id returned by runs.launch. |
| timeout_secs | integer | – | How long this call may wait before returning the current status. Default 90, max 240. |
| Name | Type | Req | Description |
|---|---|---|---|
| report | object|null | – | The report (as runs.report) when status is completed, else null. |
| run | object | – | The run record (as runs.get). |
| run_id | string | yes | – |
| status | string | yes | running | completed | failed | cancelled. |
| timed_out | boolean | yes | True when the wait window elapsed first — call again. |
| waited_secs | integer | – | – |
No examples provided.
search ~114
Search the swarm's published research: the featured shelf, the operator's daily news / markets / AI digests, and — when a key is presented — the caller's own reports. Every hit is a finished, cited, evidence-graded report. Returns {results:[{id,title,url}]}; pass an id to fetch. No key needed for the public corpus. (The research-connector contract: this is what a ChatGPT or Claude connector calls.)
| Name | Type | Req | Description |
|---|---|---|---|
| query | string | yes | Words to match against report titles and text. |
| Name | Type | Req | Description |
|---|---|---|---|
| results | array | yes | – |
No examples provided.
What is the SwarmIO MCP server?
SwarmIO is an MCP server listed in the public MCP registry as io.ioswarm/swarmio. AI that does real work for you: cited web research, plans, finance, horoscopes. Self-serve. This page covers its hosted endpoint (https://ioswarm.io/mcp).
Is the SwarmIO MCP server safe to use?
SwarmIO scores 64 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the SwarmIO MCP server expose?
SwarmIO exposes 12 tools: market.pulse, search, fetch, route.classify, runs.launch, and 7 more. Their descriptions and schemas cost roughly 847 tokens of context every time the server is loaded.
Does the SwarmIO MCP server require authentication?
No. We connected to SwarmIO without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the SwarmIO MCP server still maintained?
SwarmIO is still listed as active in the MCP registry. We last reached this channel on 22 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.