Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Snapback

REMOTE · API.SNAPBACK.SH · SCANNED SEP 29

Diagnose why an AI agent failed and get the verified fix instantly. Free, no token.

Available components

+3 this week 64 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security57
Transport & Reachability100
Schema Quality & AI Usability73
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 3076 tokens (~133/item across 23 items; 23 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
  • Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage87
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 61% of tool parameters carry a description.Partial
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • We read all 23 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
  • An AI judge read all 23 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities40
  • Spec-recency check failed: implements MCP spec 2025-03-26; the latest is 2026-07-28. See how to fix → Fail
Install

How do I install the Snapback MCP server?

Snapback is a hosted endpoint at https://api.snapback.sh/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · api.snapback.sh

# add to Claude Code
claude mcp add --transport http ra1labsworkx-wq-snapback 'https://api.snapback.sh/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "ra1labsworkx-wq-snapback": {
      "url": "https://api.snapback.sh/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "ra1labsworkx-wq-snapback": {
      "type": "http",
      "url": "https://api.snapback.sh/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.ra1labsworkx-wq-snapback]
url = "https://api.snapback.sh/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "ra1labsworkx-wq-snapback": {
      "type": "remote",
      "url": "https://api.snapback.sh/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add ra1labsworkx-wq-snapback --url 'https://api.snapback.sh/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  ra1labsworkx-wq-snapback:
    url: "https://api.snapback.sh/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "ra1labsworkx-wq-snapback": {
      "Transport": "http",
      "Url": "https://api.snapback.sh/mcp"
    }
  }
}
# add to Vellum
assistant mcp add ra1labsworkx-wq-snapback -t streamable-http -u 'https://api.snapback.sh/mcp'
// mcp.json
{
  "mcpServers": {
    "ra1labsworkx-wq-snapback": {
      "type": "http",
      "url": "https://api.snapback.sh/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 28 Sept 26 +1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 26 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 13 to 17. That category is still filling its 30-day observation window: 4 days of observed history at the previous scan, 5 at this one. The score rises as the window fills, whether or not the server changes.

  • 25 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 24 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

  • 22 Sept 26 0
    • Stability: unverified → 0.03 ▲ functional
  • 21 Sept 26 61

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 29 Sept 2026 · Probed https://api.snapback.sh/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=api.snapback.sh CN=YR2,O=Let's Encrypt,C=US 18 Aug 2026 16 Nov 2026 RSA 4096 SHA256-RSA 5f22c65db8c435f0ba0997707fb1c865f4f
SANs: api.snapback.sh
CN=YR2,O=Let's Encrypt,C=US (CA) CN=Root YR,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 RSA 2048 SHA256-RSA 4ebd24947e24d394802d84a52fd5b319
CN=Root YR,O=ISRG,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 RSA 4096 SHA256-RSA f24b6d17f9d9ad7cb1c9fea78782699f

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of api.snapback.sh. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
sh. present 55297 8 Verified
snapback.sh. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://api.snapback.sh/mcp Verified 200
http (plaintext) http://api.snapback.sh/mcp HTTPS enforced 302 https://api.snapback.sh/mcp
MCP tools · 23 exposed · ~3,076 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
agent_memory ~98

See what YOU (this agent) tend to fail on — your recurring failure patterns across past diagnoses. Returns your top failure classes with counts and what share of your failures each is (e.g. 'loop_repeated_tool_call: 12 times, 40%'). Call it before a run to know what to guard against. Token-scoped to your own agent. Free.

NameTypeReqDescription
limitinteger–top N patterns (default 5)

No output schema declared.

No examples provided.

budget_guard ~226

Live MID-RUN budget check (fast, no LLM). Send whatever counters you have and get an advisory on context %, token burn, cost burn, step budget, and off-task drift - with concrete suggested_actions and the projected cost of NOT acting. Call it every few steps to catch a runaway BEFORE you hit a limit. Advisory only (never blocks). Params: step, max_steps, tokens_used, token_budget, cost_used_usd, cost_budget_usd, context_used, context_window.

NameTypeReqDescription
context_usednumber––
context_windownumber––
cost_budget_usdnumber––
cost_used_usdnumber––
formatstring–'summary' adds a one-line relayable answer (for chat/Telegram agents); 'summary_only' returns just that line. Default full.
max_stepsinteger––
recent_actionsarray––
stepinteger––
taskstring––
token_budgetnumber––
tokens_usednumber––

No output schema declared.

No examples provided.

cascade_root ~130

Given an ORDERED list of errors from a run (oldest first), find the TRUE root — the error that cascaded or shouldn't have been retried — not just the final symptom you see. E.g. a 429 that got retried and triggered a downstream 401: the root is the 429, not the 401. Each error can be a string or {error, retried, action}. Free, no token, no LLM.

NameTypeReqDescription
errorsarrayyesordered list (oldest first) of error strings or {error, retried:bool, action} objects

No output schema declared.

No examples provided.

convert_trace ~137

Turn your raw logs into a Snapback trace so you don't hand-craft JSON. Pass 'source' = a list of log/step entries, or an object with a spans/steps/messages/events/logs array (OTel spans, OpenAI/LangChain message lists, or generic {tool,input,output} arrays all work). Returns {trace} ready to pass straight to diagnose_trace. Free, no token.

NameTypeReqDescription
hintstring–optional: the framework/format, e.g. 'otel', 'openai'
source–yesyour logs: a list, or an object wrapping a spans/steps/messages array

No output schema declared.

No examples provided.

detect_loop ~130

MID-RUN loop check (fast, no LLM, free). Send your recent steps DURING a run; get back whether you're stuck repeating a tool call and a concrete next move. Call this every few steps to catch a loop BEFORE you burn your step budget — don't wait for a postmortem. Non-blocking advice, not a verdict.

NameTypeReqDescription
stepsarrayyesyour recent steps (last ~5-10), each with an action/tool and optionally inputs — same step shape as diagnose_trace
thresholdinteger–how many identical consecutive calls = a loop (default 3)

No output schema declared.

No examples provided.

diagnose_batch ~92

Diagnose SEVERAL traces in one call (up to 20). Each trace is metered like a separate diagnose_trace. Returns a verdicts array (per-trace, order preserved); a bad trace in the batch is isolated and doesn't fail the rest. Use for post-run analysis of many failures at once instead of N round-trips.

NameTypeReqDescription
tracesarrayyesarray of trace objects (max 20)

No output schema declared.

No examples provided.

diagnose_infra_error ~342

Diagnose a cryptic AGENT-INFRASTRUCTURE error — payments (x402/EIP-3009), Solana on-chain (ATA, blockhash, compute), MCP protocol, RPC/providers, EVM & Solana wallets, library of VERIFIED fixes the base model often gets wrong. Pass the error text (and optional context). Returns {matched, family, failure_class, root_cause, fix, confidence, source, action_class, auto_safe, gate} instantly from the library (no LLM) when a known pattern matches. Free and no token. GATE CONTRACT for autonomous action: auto-apply the fix ONLY when confidence>=0.85 AND source=='library' AND auto_safe==true (action_class is retry|refetch|config); NEVER auto-apply a 'mutate' or 'destructive' fix (create/change state, money, auth) — escalate those to a human. gate.auto_apply_ok gives you the verdict. Use it the moment you hit a transaction_simulation_failed, BlockhashNotFound, a -32xxx RPC code, a 4001/-32002 wallet error, an attestation failure, or any infra error you can't instantly resolve.

NameTypeReqDescription
actionstring–optional: the tool/operation that failed
contextstring–optional: what you were doing (e.g. 'paying via x402 on solana')
errorstringyesthe exact error text/message you hit
formatstring–'summary' adds a one-line relayable answer (for chat/Telegram agents); 'summary_only' returns just that line. Default full.

No output schema declared.

No examples provided.

diagnose_trace ~106

Diagnose why an AI agent run failed. Returns a structured verdict (failure_class, failed_at_step, root_cause, fix_suggestion, confidence). LATENCY: known patterns return library-instant (<1s); a NOVEL failure needs an LLM call and can take up to ~25s — set your client timeout to at least 30s, and treat this as async (don't block your agent loop on it).

NameTypeReqDescription
traceobjectyesOTel-shaped agent trace

No output schema declared.

No examples provided.

get_request_status ~66

Check what happened to a pattern you requested (from request_pattern's request_id). Returns pending / approved / rejected / in_library so you can see if your suggestion was actioned — the feedback loop isn't a black box. Free, no token.

NameTypeReqDescription
request_idstringyes–

No output schema declared.

No examples provided.

get_verdict ~42

Fetch a previously produced verdict by its id or by trace_id (your org only).

NameTypeReqDescription
trace_idstring––
verdict_idstring––

No output schema declared.

No examples provided.

my_impact ~55

See how your feedback + pattern requests have shaped the shared library — how many verdicts you've rated, patterns you've requested, and how many were approved into the library. Turns your input into visible collaboration. Token-scoped to you.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

my_usage ~67

See YOUR current usage + remaining allowance so you can self-govern spend: snapbacks (diagnoses) used/cap/remaining, guard checks used/cap/remaining, estimated spend, % used, and when it resets. Call it periodically to avoid surprises. Token-scoped, free.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

preflight ~114

BEFORE running: get known failure patterns for a given agent setup so you can avoid them. Returns a ranked list of {failure_class, root_cause, fix_suggestion} from Snapback's library. Call this before executing a plan and self-correct.

NameTypeReqDescription
agent_stackstring–e.g. openclaw, langchain (optional)
limitinteger–max cards (default 10)
tagsarray–task facets, e.g. [tool_calling, retrieval] (optional)

No output schema declared.

No examples provided.

recommend_failover ~191

Should you RETRY the same target, SWITCH provider, FALL BACK to another chain, or STOP? Pass the error + your configured topology (current_chain, available_chains, and/or current_provider, available_providers) and get deterministic routing advice with the reason — so a flaky Solana RPC doesn't get retried 5x when you should switch to Base. Free, no token, no LLM. Reads only what you tell it (no network calls).

NameTypeReqDescription
available_chainsarray–fallback chains you can use (e.g. ['base','arbitrum'])
available_providersarray–backup providers on the same chain
current_chainstring–the chain you're on (e.g. 'solana')
current_providerstring–the RPC/provider you're using (e.g. 'helius')
errorstringyesthe error you hit

No output schema declared.

No examples provided.

report_outcome ~174

Report the outcome of an auto-applied fix (the self-heal interceptor calls this after it gate-applied a fix and retried). Pass failure_class, family, fix, confidence, action_class, and succeeded (did the retry work?). TWO purposes: it's your safety telemetry (spot a fix that didn't work) AND it feeds the shared crowd view — every reported outcome makes what_others_did sharper for the next agent. Token-scoped (so we know it's your org), free.

NameTypeReqDescription
action_classstring–retry | refetch | config
confidencenumber––
failure_classstringyes–
familystring––
fixstring–the fix that was auto-applied
succeededbooleanyesdid the single retry after the fix succeed?

No output schema declared.

No examples provided.

request_pattern ~160

Leave us a message: ask us to add a failure pattern to the library, or report a problem we couldn't diagnose well. Use this when diagnose_trace didn't have a good answer, when you keep hitting a failure we don't classify, or when you want a specific kind of problem supported. It goes straight to our roadmap/backlog. Free — no token needed.

NameTypeReqDescription
contextobject–optional: the trace/error you couldn't get diagnosed (redacted server-side)
kindstring–'pattern_request' | 'problem' | 'message' (default 'message')
messagestringyeswhat you'd like added, or the problem we couldn't solve — be specific
verdict_idstring–optional: the verdict this relates to

No output schema declared.

No examples provided.

search_docs ~101

Search Snapback's documentation for how to use it — how to format a trace, what each tool does, the failure taxonomy, auth, pricing, and errors. Free and needs no token. Call this first if you're unsure how to format a request or what a verdict means.

NameTypeReqDescription
limitinteger–max sections to return (default 3)
querystringyeswhat you want to know, e.g. 'how to format a trace'

No output schema declared.

No examples provided.

session_end ~42

Close a live session and get a short run summary (total steps, duration). Frees the session. Free, no token.

NameTypeReqDescription
session_idstringyes–

No output schema declared.

No examples provided.

session_start ~82

Open a LIVE mid-run session so Snapback can watch your run step-by-step and warn you in real time (loop / token / cost / context) - the always-on guardian mode. Returns a session_id. Free, no token. Call session_step as you run, session_end when done.

NameTypeReqDescription
agent_idstring–optional label for your agent/run

No output schema declared.

No examples provided.

session_step ~151

Report ONE step of a live run and get back any warnings immediately (loop detected / budget breach). Pass the step (action + inputs) and any counters you have (step, max_steps, tokens_used, token_budget, cost_used_usd, cost_budget_usd, context_used, context_window, task, recent_actions. context_window). Warnings are advisory - act on them to self-correct mid-run. Free.

NameTypeReqDescription
countersobject–running counters (tokens/cost/context/max_steps)
loop_thresholdinteger–identical calls that count as a loop (default 3)
session_idstringyes–
stepobjectyesthe step: action/tool + inputs

No output schema declared.

No examples provided.

submit_feedback ~176

Tell Snapback whether a verdict was correct (correct=true/false), with an optional free-text note (did the fix work? what was wrong?). ONE rating per verdict — call it AFTER you act on a verdict and see the outcome. Your correction updates the SHARED pattern library (fix patterns are shared anonymized so every agent benefits; your trace content is never shared) — a right verdict comes back faster next time, a wrong one gets down-weighted. To ask for a new pattern or report an unsolved problem, use request_pattern instead.

NameTypeReqDescription
correctbooleanyestrue if the diagnosis was right, false if not
notestring–optional free-text: what worked, what was wrong, or any detail that would help us improve this verdict
verdict_idstringyesthe verdict you're rating

No output schema declared.

No examples provided.

suggest_budget_recovery ~152

Approaching a token/context/cost budget mid-run? Pass your counters and get the LEAST-DISRUPTIVE recovery ranked: truncate context | switch to a cheaper model | batch steps | wrap up — scored by speed gained, accuracy lost, cost saved. Turns budget_guard's 'you're at 94%' into 'here's what to do about it'. Free, no token, no LLM.

NameTypeReqDescription
context_usednumber––
context_windownumber––
cost_budget_usdnumber––
cost_used_usdnumber––
recent_actionsarray––
token_budgetnumber––
tokens_usednumber––

No output schema declared.

No examples provided.

what_others_did ~242

THE CROWD: for a failure_class (or pass the family/error and we'll map it), see what OTHER agents did about the same failure and whether it worked — anonymized, aggregated across everyone. Returns {total, agree_pct (community success rate), distinct_orgs, sample_fixes (fixes rated CORRECT by other agents)}. Use it when you hit a failure and want the crowd's verdict on what actually fixes it, not just the single library answer. Free, no token. Privacy-safe: only aggregate counts + a community success rate + the working fixes — never any org, agent, or trace identity. Hidden below a small min-sample so a single report can't be reverse-engineered. This is the network effect: the more agents use Snapback, the sharper this answer gets.

NameTypeReqDescription
errorstring–optional: an error string — we'll diagnose it to find the failure_class, then return the crowd outcomes for it
failure_classstring–the failure_class to look up (e.g. 'unhandled_tool_error', 'loop_repeated_tool_call'); or pass 'error' and we map it

No output schema declared.

No examples provided.

Common questions

What is the Snapback MCP server?

Snapback is an MCP server listed in the public MCP registry as io.github.ra1labsworkx-wq/snapback. Diagnose why an AI agent failed and get the verified fix instantly. Free, no token. This page covers its hosted endpoint (https://api.snapback.sh/mcp).

Is the Snapback MCP server safe to use?

Snapback scores 64 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Snapback MCP server expose?

Snapback exposes 23 tools: diagnose_trace, diagnose_batch, get_verdict, preflight, submit_feedback, and 18 more. Their descriptions and schemas cost roughly 3,076 tokens of context every time the server is loaded.

Does the Snapback MCP server require authentication?

No. We connected to Snapback without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the Snapback MCP server still maintained?

Snapback is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.