Otto Intel
REMOTE · MCP.OTTOAI.SERVICES · SCANNED SEP 20
Otto AI hosted MCP: 16 pay-per-call market-intelligence tools, USDC via x402 on Base, no API keys.
Available components
Recent critical change
Authorization (2 Sept 2026). See the changelog before you install this server.
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security60
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (otto_sponsored_account). See how to fix → View diagnostics → Fail
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability61
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 6561 tokens (~205/item across 32 items; 32 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management70
- Stability observed for 21 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage89
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 61% of tool parameters carry a description.Partial
- Structured output schemas are declared (59% of tools); any adoption earns full credit.Pass
Tool Safety88
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 1 of 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "otto_prepare_yield_withdraw" implies "withdraw" and declares readOnlyHint instead, contradicting what its own name says it does. See how to fix → Partial
- An AI judge read all 32 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the Otto Intel MCP server?
Otto Intel is a hosted endpoint at https://mcp.ottoai.services/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.ottoai.services
claude mcp add --transport http services-ottoai-otto 'https://mcp.ottoai.services/mcp'
{
"mcpServers": {
"services-ottoai-otto": {
"url": "https://mcp.ottoai.services/mcp"
}
}
} {
"servers": {
"services-ottoai-otto": {
"type": "http",
"url": "https://mcp.ottoai.services/mcp"
}
}
} [mcp_servers.services-ottoai-otto] url = "https://mcp.ottoai.services/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"services-ottoai-otto": {
"type": "remote",
"url": "https://mcp.ottoai.services/mcp",
"enabled": true
}
}
} openclaw mcp add services-ottoai-otto --url 'https://mcp.ottoai.services/mcp' --transport streamable-http
mcp_servers:
services-ottoai-otto:
url: "https://mcp.ottoai.services/mcp" {
"McpServers": {
"services-ottoai-otto": {
"Transport": "http",
"Url": "https://mcp.ottoai.services/mcp"
}
}
} assistant mcp add services-ottoai-otto -t streamable-http -u 'https://mcp.ottoai.services/mcp'
{
"mcpServers": {
"services-ottoai-otto": {
"type": "http",
"url": "https://mcp.ottoai.services/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 19 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 63 to 67. That category is still filling its 30-day observation window: 19 days of observed history at the previous scan, 20 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.
- 15 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 50 to 53. That category is still filling its 30-day observation window: 15 days of observed history at the previous scan, 16 at this one. The score rises as the window fills, whether or not the server changes.
- 14 Sept 26 0
- Tool “otto_native_yield_userop” rewrote its description, which is the text the model reads security
- Tool “otto_sponsored_account” rewrote its description, which is the text the model reads security
- Tool “otto_native_yield_userop” changed its title: Review or recover a sponsored native yield action → Review or recover an account native yield action cosmetic
- Tool “otto_sponsored_account” changed its title: Review or recover a sponsored account transaction → Review or recover an account transaction cosmetic
- 13 Sept 26 +1
- New tool “otto_lp_collect_userop”, which the server declares destructive security
- New tool “otto_native_yield_userop”, which the server declares destructive security
- New tool “otto_sponsored_account”, which the server declares destructive security
- Server version: 0.1.3 → 0.1.4 functional
- 12 Sept 26 0
- Tool “otto_prepare_yield_deposit” rewrote its description, which is the text the model reads security
- Tool “otto_prepare_yield_withdraw” rewrote its description, which is the text the model reads security
- 10 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 33 to 37. That category is still filling its 30-day observation window: 10 days of observed history at the previous scan, 11 at this one. The score rises as the window fills, whether or not the server changes.
- 9 Sept 26 0
- Tool “otto_delegation_exit” now declares an output schema ▲ functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://mcp.ottoai.services/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=mcp.ottoai.services | CN=YE2,O=Let's Encrypt,C=US | 23 Jul 2026 | 21 Oct 2026 | ECDSA 256 | ECDSA-SHA384 | 583ddd8dbcd2ee144fdb9a6669b145857e0 |
| SANs: mcp.ottoai.services | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC secure
Validation of mcp.ottoai.services. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| services. | present | 36727 | 8 | Verified |
| ottoai.services. | present | 21999 | 13 | Verified |
| mcp.ottoai.services. | Verified address RRset verified with the apex keys |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.ottoai.services/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.ottoai.services/mcp | HTTPS enforced | 301 | https://mcp.ottoai.services/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
otto_base_season Otto Base season ~98
Scan quality-screened Base tokens with current social-intelligence and trusted-KOL context. Market context only; not a pick, recommendation, or trade instruction. Hosted access: the first successful intelligence call is free; later calls cost $0.002 USDC through x402.
| Name | Type | Req | Description |
|---|---|---|---|
| x_payment | string | – | Signed x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload. |
No output schema declared.
No examples provided.
otto_catalog otto x402 catalog ~44
Return the full live otto x402 menu with endpoint paths, descriptions, prices, and Base-USDC payment instructions. Always free; does not consume the free intelligence call.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
otto_delegation_cap Reserve the expiry a delegation is minted with, record the chosen per-swap cap against it, then confirm the mint ~471
TWO PHASES, both header authed, both resolving the end user from the access token. { phase: "reserve", accessToken, perSwapCapUsd, requestedDays, mintKey } takes a generation-bound unified mint claim, picks a whole-second expiry instant at or BEFORE the requested duration that no durable row for this user already occupies, writes the chosen cap (whole USD, 1…5000) against it, and answers { expires_at, mint_expires_at, per_swap_cap_usd, recorded }. Call createDelegation with mint_expires_at EXACTLY as given — it is the reserved instant plus a one-millisecond filler, because CDP refuses an expiry ending .000 and truncates the filler away — and with mintKey as the idempotencyKey. Then { phase: "confirm", accessToken, mintKey } re-reads the grant from CDP and promotes only the exact still-current claim whose reported instant IS the reserved one. A mismatch, Stop overlap, or stale claim remains unconfirmed and authorises nothing; no confirm path issues CDP's user-wide revoke because that could delete a newer permission, so use a fresh explicit Stop to revoke whichever permission is current. Why this shape: Coinbase issues no grant id and a send can learn nothing about a live grant except its expiry, so the expiry is made an identity BY CONSTRUCTION — reserved server-side, recorded before the mint, asserted after it. Until a reservation is successfully confirmed active, otto_submit_under_delegation refuses that delegation (DELEGATION_CAP_UNCONFIRMED) rather than falling back to the 5000 USD ceiling. A reservation is IMMUTABLE per mint key — pressing again returns the same instant and cap, and an older revoke generation cannot be revived. Coinbase's engine cannot hold this number: end-user accounts are fenced by ONE project-scope policy shared by every delegated user, so a lower per-user cap is enforced by Otto's server alone. Server-to-server only: the caller presents Otto's delegation secret in the `x-otto-delegation-auth` request header (never in arguments); a call wit…
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| expires_at | string | yes | – |
| mint_expires_at | string | – | – |
| per_swap_cap_usd | integer | yes | – |
| phase | string | yes | – |
| recorded | boolean | yes | – |
| ruleset_version | integer | yes | – |
| state | string | yes | – |
| user_id | string | yes | – |
No examples provided.
otto_delegation_exit Prepare, submit, and recover an exact Base USDC exit ~161
Move an authenticated CDP end user's own Base USDC only through a server-held durable reservation. prepare returns one exact EIP-1559 transaction for client-side signing; the client must never broadcast it. submit validates and durably records the signed bytes and computed hash before the server broadcasts. status is read-only and cross-device. reconcile proves a canonical receipt without broadcasting, or returns the exact finalized sender+nonce replacement proof when another transaction consumed the reserved nonce. retry_same is explicit and can broadcast only the already-stored byte-identical transaction after reconciling first. cancel is accepted only before signed bytes were recorded. The caller presents Otto's delegation secret in x-otto-delegation-auth; user identity is always derived from accessToken.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| account | string | – | – |
| amount_atomic | string | – | – |
| broadcast_attempts | integer | – | – |
| created_at | string | – | – |
| destination | string | – | – |
| epoch | integer | – | – |
| has_exit | boolean | yes | – |
| lease_expires_at | string | – | – |
| operation_id | string | – | – |
| owner_token | string | – | – |
| phase | string | yes | – |
| receipt | object | – | – |
| replacement | object | – | – |
| state | string | – | – |
| transaction | object | – | – |
| transaction_hash | string | – | – |
| updated_at | string | – | – |
| user_id | string | yes | – |
No examples provided.
otto_delegation_fence Ensure the Model-B project policy (the delegation fence) is installed and reads back as v-current ~238
Idempotent ensure-by-digest of the ONE CDP project-scope policy that fences every delegated send, then a read-back. Writes only when no project policy exists (creates it) or when the existing one is Otto's own lineage with stale rules (updates it in place). REFUSES BY NAME if a different project-scope policy is installed — it is never overwritten or deleted. Never downgrades a newer fence. An OPS action: at most one ensure runs project-wide at a time, never during a rolling deploy, never from the dApp (the mint gate reads fence.present from otto_delegation_status). Arguments: {}. Output: the policy id, versioned name, rules digest and the per-swap cap; the tool fails unless the fence reads back present under the written id. Server-to-server only: the caller presents Otto's delegation secret in the `x-otto-delegation-auth` request header (never in arguments); a call without it is refused before anything is read. The listed input schema is intentionally permissive — the strict schema is validated after the caller is authenticated.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | – |
| per_swap_cap_usd | number | yes | – |
| policy_id | string | yes | – |
| policy_name | string | yes | – |
| rules_digest | string | yes | – |
| status | string | yes | – |
No examples provided.
otto_delegation_fence_status Read the Model-B delegation fence (public promise: present, name, rules digest, per-swap cap) ~198
PUBLIC and read-only, no header: whether the Model-B project policy that fences every delegated send is installed and v-current on this server, with its versioned name, rules digest, the per-swap cap ceiling in USD (shared by every delegated user — a person may choose any whole-dollar cap from per_swap_cap_min_usd up to it, enforced server-side and recorded against their own grant), and Otto's PUBLIC CDP project id (a UUID — the authority an agent binds its mint to). Exposes ONLY the fence's public promise — never an end user, a grant, an address or a policy's contents. An agent about to mint a delegation (otto-execute delegate) reads this first, mints to the published project_id and no other, and refuses to mint when the fence is not present; the server enforces fence-before-authority on every delegated send regardless. Arguments: {}.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| mint_enabled | boolean | yes | – |
| per_swap_cap_min_usd | number | yes | – |
| per_swap_cap_usd | number | yes | – |
| policy_name | string | yes | – |
| present | boolean | yes | – |
| project_id | string | – | – |
| reason | string | – | – |
| rules_digest | string | – | – |
| ruleset_version | integer | yes | – |
No examples provided.
otto_delegation_operations Read one end user's delegated operation history and recovery state ~150
Read the durable Base delegated-operation journal for the end user resolved from { accessToken }. Optional artifactId selects one exact own-user operation; without it, the result includes a bounded recent terminal history and every unresolved operation regardless of age. The global unresolved flag is fail-closed: it is true when the store is unavailable, journal coverage is not rollout-ready, or any operation has a prepared/submitted/unknown outcome. Stored serialized transactions and CDP idempotency keys are never returned, and this tool never submits or retries anything. Server-to-server only: the caller also presents Otto's delegation secret in the x-otto-delegation-auth request header; no userId argument is accepted.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| journal | object | yes | – |
| operations | array | yes | – |
| store_available | boolean | yes | – |
| unresolved | boolean | yes | – |
| user_id | string | yes | – |
No examples provided.
otto_delegation_reconcile Reconcile one end user's known-hash delegated operation ~142
Acquire the artifact's permanent process-liveness guard, then check Base for finalized canonical receipts of already-stored transaction hashes. Every chain transaction must match the stored chain, hash, sender, target, calldata, value, nonce, gas and EIP-1559 fee fields before its receipt is recorded. This tool never calls CDP, never retries a request, never builds or submits a later step, and leaves prepared/unknown no-hash steps unresolved. It returns the same token-bound operation snapshot as otto_delegation_operations. Server-to-server only: the caller also presents Otto's delegation secret in x-otto-delegation-auth.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| journal | object | yes | – |
| operations | array | yes | – |
| store_available | boolean | yes | – |
| unresolved | boolean | yes | – |
| user_id | string | yes | – |
No examples provided.
otto_delegation_revoke Revoke one end user's delegation, developer-side, confirmed by read-back ~171
Revoke the end user's delegation from Otto's side and confirm by read-back that it no longer exists; from then on this server submits nothing for that user (fail-closed, even if the read-back had failed). Arguments: EITHER { accessToken } (the user path — the server resolves the user from the token) OR { userId, support_reason } (the support path, for an operator holding the server secret; the reason is logged, the token never is). Server-to-server only: the caller presents Otto's delegation secret in the `x-otto-delegation-auth` request header (never in arguments); a call without it is refused before anything is read. The listed input schema is intentionally permissive — the strict schema is validated after the caller is authenticated.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| path | string | yes | – |
| reads_back | boolean | yes | – |
| revoked | boolean | yes | – |
| user_id | string | yes | – |
No examples provided.
otto_delegation_status Read one end user's delegation status (token-bound) ~227
Read back, for the end user identified by a CDP access token, their CDP accounts, whether the Model-B fence is present, and whether an active delegation reads back (with its expiry and the per-swap cap recorded for it). Arguments: { accessToken } — the server resolves the user from the token; a client-sent user id is refused. delegation.per_swap_cap_usd is the number THIS user chose at mint time; it is ABSENT when no cap is recorded for the grant, which means the delegated send will refuse it — say so rather than showing the shared ceiling. fence.per_swap_cap_usd is that shared ceiling and is never a per-user number. Output is bound to that user; nothing about any other user is returned. Server-to-server only: the caller presents Otto's delegation secret in the `x-otto-delegation-auth` request header (never in arguments); a call without it is refused before anything is read. The listed input schema is intentionally permissive — the strict schema is validated after the caller is authenticated.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| addresses | array | yes | – |
| delegation | object | yes | – |
| fence | object | yes | – |
| mint_enabled | boolean | yes | – |
| revocation_requested_here | boolean | yes | – |
| ruleset_version | integer | yes | – |
| user_id | string | yes | – |
No examples provided.
otto_equity_intel Otto equity intelligence ~145
Read SEC-EDGAR fundamentals and filings context for a US ticker: revenue and net-income trends, margins, EPS, leverage, recent 10-K/10-Q/8-K filings, and a guarded AI summary. Fundamentals scanner only; not a price feed or recommendation. Hosted access: the first successful intelligence call is free; later calls cost $0.003 USDC through x402.
| Name | Type | Req | Description |
|---|---|---|---|
| ticker | string | yes | US-listed stock ticker, for example NVDA, AAPL, or JPM. |
| x_payment | string | – | Signed x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload. |
No output schema declared.
No examples provided.
otto_equity_smart_money Otto equity smart-money scanner ~127
Read a public-domain SEC bundle for a US ticker: Form 4 insider activity plus trailing-twelve-month XBRL fundamentals. Scanner context only; not a pick or recommendation. Hosted access: the first successful intelligence call is free; later calls cost $0.006 USDC through x402.
| Name | Type | Req | Description |
|---|---|---|---|
| ticker | string | yes | US-listed stock ticker, for example NVDA, AAPL, or JPM. |
| x_payment | string | – | Signed x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload. |
No output schema declared.
No examples provided.
otto_equity_smart_money_brief Otto equity smart-money brief ~140
Read one guarded AI brief over observed SEC Form 4 flow, 13D/13G ownership events, and fundamentals for a US ticker. Filing scanner only; generation rejects buy/sell advice and the result is not a recommendation. Hosted access: the first successful intelligence call is free; later calls cost $0.10 USDC through x402.
| Name | Type | Req | Description |
|---|---|---|---|
| ticker | string | yes | US-listed stock ticker, for example NVDA, AAPL, or JPM. |
| x_payment | string | – | Signed x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload. |
No output schema declared.
No examples provided.
otto_insider_trades Otto insider trades ~128
Read parsed SEC Form 4 insider transactions for a US ticker, including purchase/sale counts, dollar values, roles, and net P/S balance. Filing scanner only; not a recommendation. Hosted access: the first successful intelligence call is free; later calls cost $0.003 USDC through x402.
| Name | Type | Req | Description |
|---|---|---|---|
| ticker | string | yes | US-listed stock ticker, for example NVDA, AAPL, or JPM. |
| x_payment | string | – | Signed x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload. |
No output schema declared.
No examples provided.
otto_institutional_holdings Otto institutional holdings ~131
Read the latest SEC 13F-HR top positions for an institutional manager by CIK or manager ticker, with amendments applied. Ownership data only; not a recommendation. Hosted access: the first successful intelligence call is free; later calls cost $0.003 USDC through x402.
| Name | Type | Req | Description |
|---|---|---|---|
| manager | string | yes | SEC manager CIK, such as 1067983, or listed manager ticker, such as BLK. |
| x_payment | string | – | Signed x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload. |
No output schema declared.
No examples provided.
otto_lp_collect_userop Review or recover sponsored LP collection ~88
Protected same-account Uniswap V3 guarded collection on Base. Read availability, prepare and explicitly confirm one operation, or read/reconcile it. May collect owed principal and fees; profit remains unknown. Account upgrade is separate. Current owner authority, reviewed guard and provider policy are required. Unknown delivery retains the original operation; no replacement is allowed. Preparation and simulation are not funded execution.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| account | string | – | – |
| action | string | – | – |
| attention | – | – | – |
| automaticExecutionEnabled | boolean | – | – |
| chainId | number | – | – |
| collection | object | – | – |
| configured | boolean | – | – |
| confirmation | string | – | – |
| envelopeCommitment | string | – | – |
| executionEnabled | boolean | – | – |
| failureCode | string | – | – |
| gas | – | – | – |
| kind | string | yes | – |
| operationId | string | – | – |
| pool | string | – | – |
| protocol | string | – | – |
| protocolActionVerified | boolean | – | – |
| reason | string | – | – |
| recoveryAvailable | boolean | – | – |
| replacementPermitted | boolean | – | – |
| requiresOperationReview | boolean | – | – |
| requiresReconciliation | boolean | – | – |
| requiresSeparateWalletUpgrade | boolean | – | – |
| retrySafe | boolean | – | – |
| reviewCommitment | string | – | – |
| reviewConsumed | boolean | – | – |
| schemaVersion | string | yes | – |
| settlement | – | – | – |
| state | string | – | – |
| status | string | – | – |
| supportedActions | array | – | – |
| supportedSameAddressChains | array | – | – |
| tokenId | string | – | – |
| transactionHash | string | – | – |
| userOpHash | string | – | – |
| validUntilMs | integer | – | – |
| walletAuthorityChangeIncluded | boolean | – | – |
No examples provided.
otto_native_yield_userop Review or recover an account native yield action ~88
Protected native protocol action. Read availability, review and confirm native scope, prepare, reviewGas for current payer and network estimate, and explicitly confirm one operation, or read/reconcile/revoke native consent. Account upgrade is separate. Source activation and current owner authority are required. Unknown delivery retains the original operation; no replacement is allowed. A preparation or simulation is not funded execution.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| account | string | – | – |
| action | string | – | – |
| attention | – | – | – |
| automaticExecutionEnabled | boolean | – | – |
| chainId | – | – | – |
| configured | boolean | – | – |
| confirmation | string | – | – |
| consent | object | – | – |
| envelopeCommitment | string | – | – |
| estimatedOttoFee | object | – | – |
| executionEnabled | boolean | – | – |
| existingOperationRequiresReconciliation | boolean | – | – |
| failureCode | string | – | – |
| gas | – | – | – |
| input | object | – | – |
| kind | string | yes | – |
| marketId | string | – | – |
| nativeConsentRevoked | boolean | – | – |
| operationId | string | – | – |
| output | object | – | – |
| perDepositCapUsd | integer | – | – |
| protocolActionVerified | boolean | – | – |
| reason | string | – | – |
| recoveryAvailable | boolean | – | – |
| replacementPermitted | boolean | – | – |
| requiresNativeConsent | boolean | – | – |
| requiresOperationReview | boolean | – | – |
| requiresReconciliation | boolean | – | – |
| requiresSeparateOperationReview | boolean | – | – |
| requiresSeparateWalletUpgrade | boolean | – | – |
| retrySafe | boolean | – | – |
| reviewCommitment | string | – | – |
| reviewConsumed | boolean | – | – |
| schemaVersion | string | yes | – |
| scope | object | – | – |
| scopeConsent | object | – | – |
| settlement | – | – | – |
| state | string | – | – |
| status | string | – | – |
| supportedSameAddressChains | array | – | – |
| transactionHash | string | – | – |
| userOpHash | string | – | – |
| validUntilMs | integer | – | – |
| walletAuthorityChangeIncluded | boolean | – | – |
No examples provided.
otto_pm_crypto Otto crypto prediction-market context ~99
Read high-volume open BTC, ETH, and crypto Polymarket markets with current outcome probabilities and market context. Event-probability data only; not a recommendation. Hosted access: the first successful intelligence call is free; later calls cost $0.001 USDC through x402.
| Name | Type | Req | Description |
|---|---|---|---|
| x_payment | string | – | Signed x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload. |
No output schema declared.
No examples provided.
otto_pm_markets Otto prediction-market context ~105
Read the highest-volume open Polymarket markets with live outcome probabilities, bid/ask context, liquidity, volume, and end dates. Event-probability context only; not a recommendation. Hosted access: the first successful intelligence call is free; later calls cost $0.001 USDC through x402.
| Name | Type | Req | Description |
|---|---|---|---|
| x_payment | string | – | Signed x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload. |
No output schema declared.
No examples provided.
otto_prepare_bridge Prepare an Otto-attributed LI.FI cross-chain USDC bridge ~319
Prepare, decode, and verify an unsigned cross-chain native-USDC bridge construction aid for the caller-owned EOA or Safe, over the enumerated v1 Circle-CCTP route set (Ethereum, Polygon, Base, Arbitrum, Avalanche); any other chain, token, or bridge route is refused by name. The envelope's valid_until bounds freshness and is committed to the artifact digest; the signer account nonce is the on-chain replay boundary, and this tool cannot guarantee single execution. Returns ordered allowance-reset, approval, and call steps on the source chain only; never signs or submits. Every envelope from this server is valid for 300 seconds from construction (valid_until); a stale envelope is refused by the verifier — request a fresh one.
| Name | Type | Req | Description |
|---|---|---|---|
| accountProfile | object | yes | – |
| client_ref | string | – | – |
| destinationRecipient | string | – | Where the destination mint lands. Optional for an EOA, whose address is identical on every EVM chain; REQUIRED for a Safe, whose address is not guaranteed to be the same contract on the destination c… |
| fromAmount | string | yes | Exact gross input amount in atomic token units. |
| fromChainId | integer | yes | – |
| fromToken | string | yes | Native USDC on the source chain; the v1 bridge route set is USDC-only. |
| slippage | object | yes | – |
| toChainId | integer | yes | – |
| toToken | string | yes | Native USDC on the destination chain; the v1 bridge route set is USDC-only. |
| Name | Type | Req | Description |
|---|---|---|---|
| account_binding | object | yes | – |
| artifact_id | string | yes | – |
| assertions | array | yes | – |
| fee_attribution | object | yes | – |
| intent_digest | string | yes | – |
| operation | string | yes | – |
| payload | – | yes | – |
| rail | string | yes | – |
| replay_disclosure | object | yes | – |
| required_capabilities | array | yes | – |
| schema_version | string | yes | – |
| submission | object | yes | – |
| valid_until | string | yes | – |
No examples provided.
otto_prepare_perp_order Prepare an unsigned Hyperliquid perp order L1 action ~606
Prepare and verify an unsigned Hyperliquid perpetuals order (limit, with optional reduce-only take-profit and stop-loss triggers bundled as normalTpsl) for the caller-owned Hyperliquid account, returned as the canonical L1 action plus the exact EIP-712 Agent domain, struct, and connectionId recipe the caller's own signer needs. The asset id, size grid, and price grid come from the live perp universe: an unknown or delisted perp, a size finer than the asset's szDecimals, or a price off the venue's 5-significant-digit / (6 - szDecimals) decimal grid is refused by name rather than rounded to a different order. There is no market order — name your own aggressive limit price with 'Ioc'. Otto's builder attribution is spec'd and valueless today, so the action carries no builder field and the envelope says so. The nonce is chosen by the signer, never here; the envelope's valid_until is committed to the artifact digest AND placed inside the signed digest as expiresAfter, so the venue itself rejects a stale action, while the Hyperliquid signer nonce remains the replay boundary and this tool cannot guarantee single execution. This tool never signs or submits, holds no key, and derives no agent wallet. Every envelope from this server is valid for 300 seconds from construction (valid_until); a stale envelope is refused by the verifier — request a fresh one.
| Name | Type | Req | Description |
|---|---|---|---|
| accountProfile | object | yes | The Hyperliquid master account. `chainId` must be 1337, the signature chain id Hyperliquid pins for every L1 action. |
| asset | string | yes | Perp symbol exactly as the venue names it, e.g. 'BTC', 'kPEPE'. Case-sensitive. |
| client_ref | string | – | – |
| limitPrice | string | yes | Limit price. Must sit on the venue grid: at most 5 significant digits unless integer, and at most (6 - szDecimals) decimals. |
| reduceOnly | boolean | – | – |
| side | string | yes | – |
| size | string | yes | Order size in base units, e.g. '0.01'. At most szDecimals fractional digits for this perp. |
| stopLossPrice | string | – | Optional reduce-only market stop-loss trigger, bundled with grouping normalTpsl. |
| takeProfitPrice | string | – | Optional reduce-only market take-profit trigger, bundled with grouping normalTpsl. |
| timeInForce | string | – | Gtc rests, Ioc fills-or-cancels, Alo posts only. There is no market order: name your own aggressive limit price with 'Ioc' instead. |
| tradingSigner | string | – | The address that will sign, when it is not the master account itself: a user-held approved API wallet. Declared, never derived. |
| vaultAddress | string | – | Trade on behalf of this vault or sub-account. A declared profile fact only. |
| Name | Type | Req | Description |
|---|---|---|---|
| account_binding | object | yes | – |
| artifact_id | string | yes | – |
| assertions | array | yes | – |
| fee_attribution | object | yes | – |
| intent_digest | string | yes | – |
| operation | string | yes | – |
| payload | object | yes | – |
| rail | string | yes | – |
| replay_disclosure | object | yes | – |
| required_capabilities | array | yes | – |
| schema_version | string | yes | – |
| submission | object | yes | – |
| valid_until | string | yes | – |
No examples provided.
otto_prepare_polymarket_order Prepare an Otto-attributed Polymarket CLOB limit order ~277
Prepare and verify an unsigned Polymarket CTF Exchange V2 limit order (GTC) for the caller-owned Polygon EOA, with Otto's builder code stamped inside the EIP-712 order struct and re-asserted on the exact digest the signer will sign. The price must be an exact multiple of the market's live minimum tick size and the size at or above its published minimum. The envelope's valid_until bounds freshness and is committed to the artifact digest; the exchange's own order hash is the replay boundary, and this tool cannot guarantee single execution. Returns order args and typed data only; never signs or submits, holds no CLOB credentials, and touches no collateral or allowance. Every envelope from this server is valid for 300 seconds from construction (valid_until); a stale envelope is refused by the verifier — request a fresh one.
| Name | Type | Req | Description |
|---|---|---|---|
| accountProfile | object | yes | – |
| client_ref | string | – | – |
| price | string | yes | Limit price as a probability, e.g. '0.045'. Must be an exact multiple of the market's minimum tick size. |
| side | string | yes | – |
| size | string | yes | Order size in outcome-token shares. |
| tokenId | string | yes | Outcome-token id (NOT the condition id): YES and NO are different token ids. |
| Name | Type | Req | Description |
|---|---|---|---|
| account_binding | object | yes | – |
| artifact_id | string | yes | – |
| assertions | array | yes | – |
| fee_attribution | object | yes | – |
| intent_digest | string | yes | – |
| operation | string | yes | – |
| payload | object | yes | – |
| rail | string | yes | – |
| replay_disclosure | object | yes | – |
| required_capabilities | array | yes | – |
| schema_version | string | yes | – |
| submission | object | yes | – |
| valid_until | string | yes | – |
No examples provided.
otto_prepare_stock_buy Prepare a tokenized-stock buy (Coinbase B20 on Base) as a delegable swap pair ~330
Prepare the EXACT otto_prepare_swap pair (envelope + prepareInput) that buys one of the executable Coinbase B20 tokenized equities on Base with USDC, as a LI.FI route through the fenced diamond whose receiver is the signing account. The token comes from the registry row named by executableEquityId and is never an input; the caller's registryCommitment must equal the commitment recomputed over the current record. The WORST PERMISSIBLE FILL (amount over the route's own floor) is checked against the equity's own Chainlink total-return mark and refused when it exceeds the pinned tolerance, or when the feed is frozen (> 24 h). Returns the pair unchanged plus a preview; never signs or submits — submit the pair through otto_submit_under_delegation under the end user's per-swap cap. Every envelope from this server is valid for 300 seconds from construction (valid_until); a stale envelope is refused by the verifier — request a fresh one.
| Name | Type | Req | Description |
|---|---|---|---|
| accountProfile | object | yes | – |
| amount | string | yes | Exact USDC amount to spend, in atomic units (6 decimals). |
| client_ref | string | – | – |
| executableEquityId | string | yes | The executable equity id the READ half served, e.g. b20-nvda (Coinbase B20 on Base only). |
| registryCommitment | string | yes | The registry commitment served with that row. It must equal the commitment this server recomputes over the CURRENT record; a stale or foreign row is refused by name. |
| slippage | object | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| envelope | object | yes | – |
| prepareInput | object | yes | – |
| preview | object | yes | – |
| registry_commitment | string | yes | – |
No examples provided.
otto_prepare_swap Prepare an Otto-attributed LI.FI swap ~209
Prepare, decode, and verify an unsigned same-chain EVM ERC20 swap construction aid for the caller-owned EOA or Safe. The envelope's valid_until bounds freshness and is committed to the artifact digest; the signer account nonce is the on-chain replay boundary, and this tool cannot guarantee single execution. Returns ordered allowance-reset, approval, and call steps only; never signs or submits. Every envelope from this server is valid for 300 seconds from construction (valid_until); a stale envelope is refused by the verifier — request a fresh one.
| Name | Type | Req | Description |
|---|---|---|---|
| accountProfile | object | yes | – |
| chainId | integer | yes | – |
| client_ref | string | – | – |
| fromAmount | string | yes | Exact input amount in atomic token units. |
| fromToken | string | yes | ERC20 input token address; native-token routes are out of v1. |
| slippage | object | yes | – |
| toToken | string | yes | ERC20 output token address; native-token routes are out of v1. |
| Name | Type | Req | Description |
|---|---|---|---|
| account_binding | object | yes | – |
| artifact_id | string | yes | – |
| assertions | array | yes | – |
| fee_attribution | object | yes | – |
| intent_digest | string | yes | – |
| operation | string | yes | – |
| payload | – | yes | – |
| rail | string | yes | – |
| replay_disclosure | object | yes | – |
| required_capabilities | array | yes | – |
| schema_version | string | yes | – |
| submission | object | yes | – |
| valid_until | string | yes | – |
No examples provided.
otto_prepare_yield_deposit Prepare a Yield Copilot vault deposit (Morpho USDC on Base) as a delegable swap pair ~345
Prepare the EXACT otto_prepare_swap pair (envelope + prepareInput) that deposits USDC into one of the executable Morpho vaults from the Yield Copilot registry, as a LI.FI position-acquisition route (which may buy shares or compose a protocol deposit) whose output token is the vault's ERC-4626 share token and whose receiver is the signing account. The vault comes from the registry row named by executableMarketId and is never an input; the caller's registryCommitment must equal the commitment recomputed over the current record. The quoted shares are checked against the vault's own previewDeposit and refused when they fall short by more than the pinned tolerance. Returns the pair unchanged plus a preview; never signs or submits — submit the pair through otto_submit_under_delegation under the end user's per-swap cap. Every envelope from this server is valid for 300 seconds from construction (valid_until); a stale envelope is refused by the verifier — request a fresh one.
| Name | Type | Req | Description |
|---|---|---|---|
| accountProfile | object | yes | – |
| amount | string | yes | Exact USDC amount to deposit, in atomic units (6 decimals). |
| client_ref | string | – | – |
| executableMarketId | string | yes | The executable market id the READ half served (`GET /api/yield-copilot` rows with deployable:true), e.g. base-usdc-morpho-gauntlet-prime. |
| registryCommitment | string | yes | The registry commitment served with that row. It must equal the commitment this server recomputes over the CURRENT record; a stale or foreign row is refused by name. |
| slippage | object | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| envelope | object | yes | – |
| prepareInput | object | yes | – |
| preview | object | yes | – |
| registry_commitment | string | yes | – |
No examples provided.
otto_prepare_yield_withdraw Prepare a Yield Copilot vault withdraw (Morpho USDC on Base) as a delegable swap pair ~306
Prepare the EXACT otto_prepare_swap pair (envelope + prepareInput) that redeems vault shares from one of the executable Morpho vaults in the Yield Copilot registry back to USDC in the signing account, as a LI.FI exit route (which may sell shares or compose a protocol redemption) whose input token is the vault's ERC-4626 share token. The vault and the asset come from the registry row named by executableMarketId and are never inputs; the caller's registryCommitment must equal the commitment recomputed over the current record. The quoted USDC is checked against the vault's own previewRedeem and refused when it falls short by more than the pinned tolerance. Returns the pair unchanged plus a preview; never signs or submits — submit the pair through otto_submit_under_delegation, which admits a withdraw only under fence v2 and a permission minted under cap ruleset v2, values it at zero against the per-swap cap (it returns the person's own assets), and bounds it by the engine's share cap. Every envelope from this server is valid for 300 seconds from construction (valid_until); a stale envelope is refused by the verifier — request a fresh one.
| Name | Type | Req | Description |
|---|---|---|---|
| accountProfile | object | yes | – |
| client_ref | string | – | – |
| executableMarketId | string | yes | – |
| registryCommitment | string | yes | – |
| shares | string | yes | – |
| slippage | object | yes | – |
| Name | Type | Req | Description |
|---|---|---|---|
| envelope | object | yes | – |
| prepareInput | object | yes | – |
| preview | object | yes | – |
| registry_commitment | string | yes | – |
No examples provided.
otto_rh_season Otto Robinhood Chain season ~105
Scan rug-screened Robinhood Chain (4663) movers with honeypot filters and per-token risk flags. Market context only; not a pick, recommendation, or trade instruction. Hosted access: the first successful intelligence call is free; later calls cost $0.001 USDC through x402.
| Name | Type | Req | Description |
|---|---|---|---|
| x_payment | string | – | Signed x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload. |
No output schema declared.
No examples provided.
otto_sponsored_account Review or recover an account transaction ~82
Protected account action: availability, prepare, reviewGas for current gas payer and estimate, explicit submit, owned read or reconcile. Gas refresh is read-only planning and requires new confirmation before any send. Wallet upgrade is separate. Sponsorship requires a reviewed source activation; current availability is authoritative. A missing submission response is unknown and must never cause a replacement submission.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| account | string | – | – |
| attention | – | – | – |
| automaticExecutionEnabled | boolean | – | – |
| chainId | – | – | – |
| configured | boolean | – | – |
| executionEnabled | boolean | – | – |
| failureCode | string | – | – |
| gas | – | – | – |
| input | object | – | – |
| operationId | string | – | – |
| ottoFee | string | – | – |
| output | object | – | – |
| reason | string | – | – |
| receipt | object | – | – |
| recoveryAvailable | boolean | – | – |
| replacementPermitted | boolean | – | – |
| requiresOperationReview | boolean | – | – |
| requiresReconciliation | boolean | – | – |
| requiresSeparateWalletUpgrade | boolean | – | – |
| reviewCommitment | string | – | – |
| reviewConsumed | boolean | – | – |
| schemaVersion | string | yes | – |
| settlement | object | – | – |
| state | string | – | – |
| status | string | – | – |
| supportedSameAddressChains | array | – | – |
| terms | object | – | – |
| transactionHash | string | – | – |
| userOpHash | string | – | – |
| validUntilMs | integer | – | – |
| walletAuthorityChangeIncluded | boolean | – | – |
No examples provided.
otto_stock_pools Otto tokenized-stock pool discovery ~352
Find the DEX pools a tokenized US stock is actually a member of, on Robinhood Chain, Base, BNB Chain or Solana. Returns each pool id (Uniswap v4 pool ids kept distinct from v3 pool addresses), DEX and version, which side the stock is on, the counterpart token with an evidence-backed classification (verified stock, verified stablecoin, or unclassified), reported USD liquidity and 24h volume, 24h transaction count, pool creation time, and the source coverage limits. Membership discovery only: a provider-covered observation rather than a complete census, no APR and no execution support, and the stock’s own 24h return is reported only from pools where the stock is the base token. Identify the stock by address when a ticker names two deployments on one chain (eight Solana tickers exist on both xStocks and Backpack) — that spelling is refused rather than resolved to one of them. Not a pairing recommendation. Hosted access: the first successful intelligence call is free; later calls cost $0.001 USDC through x402.
| Name | Type | Req | Description |
|---|---|---|---|
| stock | string | yes | Network-qualified tokenized-stock identity: "<network>:<TICKER>" or "<network>:<token address>", where network is robinhood, base, bsc or solana. Example: robinhood:MU. A bare ticker is rejected, and… |
| x_payment | string | – | Signed x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload. |
No output schema declared.
No examples provided.
otto_submit_under_delegation Submit an Otto-prepared swap under a CDP end-user delegation ~405
Submit a verified otto_prepare_swap envelope on Base under the end user's CDP delegation. Arguments: { userId, envelope (the otto_prepare_swap result), prepareInput (the exact otto_prepare_swap request, with slippage.minAmountOut) } — validated strictly AFTER the caller is authenticated, so the listed input schema is intentionally permissive. Server-to-server only: the caller presents Otto's delegation secret in the `x-otto-delegation-auth` request header (never in arguments); a call without it is refused before anything is read. Before any send the server confirms, in this order: the Model-B project policy is installed and reads back by name and rules digest; the user's grant is active past the envelope's valid_until; the account is one of that end user's own CDP accounts as CDP reports them; the envelope passes the 13-check verifier for exactly the request that produced it; the plan is inside the fence (allow-listed input token, reviewed spender, gross at or below the 5000 USD engine ceiling); and the plan is at or below the per-swap cap THIS user chose when they minted, which is recorded against their grant on this server. A delegation with no recorded cap is REFUSED (DELEGATION_CAP_UNRECORDED) rather than defaulted to the ceiling — mint the permission again to set one. Then the three steps (allowance reset, approval, swap) are submitted in order under the delegation, each waited to a sealed canonical block; a halt clears the allowance and reports the read-back. One delegated plan at a time per user. Coinbase's engine bounds the delegated key to Model-B swap shapes through LI.FI up to the 5000 USD ceiling, which is shared by every delegated user and cannot be narrowed per user by the engine; the user's own lower cap and the receiver binding are Otto's server-side checks, and the user can revoke at any time.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | – |
| artifact_id | string | yes | – |
| chain_id | number | yes | – |
| delegation | object | yes | – |
| fence | object | yes | – |
| replayed | boolean | – | – |
| status | string | yes | – |
| steps | array | yes | – |
| user_id | string | yes | – |
| verification | object | yes | – |
No examples provided.
otto_tokenized_equities Otto tokenized equities ~165
Scan the live registry of US equities and ETFs tokenized on Robinhood Chain (4663): symbol, canonical token address, decimals, the executable buy price a live route returns, the catalog reference price and the deviation between them, plus a verifiable tradability signal. An optional thesis returns a relevance-ranked shortlist with a match reason per row. Data only; not a recommendation or executable quote. Hosted access: the first successful intelligence call is free; later calls cost $0.001 USDC through x402.
| Name | Type | Req | Description |
|---|---|---|---|
| thesis | string | – | Natural-language screening thesis, for example "AI infrastructure chips". |
| x_payment | string | – | Signed x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload. |
No output schema declared.
No examples provided.
otto_x_recipes otto x layer recipes ~109
Return Otto X's live X Layer recipe menu — each recipe's path, price, and the X Layer (eip155:196) payment requirement decoded from its unpaid 402 challenge: token asset, issuer name/version, payTo, and a copy-paste curl. Settles in USD₮0 / USD Coin / Global Dollar on X Layer via the PAYMENT-SIGNATURE header. Always free and read-only; never signs or pays and does not consume the free intelligence call.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
What is the Otto Intel MCP server?
Otto Intel is an MCP server listed in the public MCP registry as services.ottoai/otto. Otto AI hosted MCP: 16 pay-per-call market-intelligence tools, USDC via x402 on Base, no API keys. This page covers its hosted endpoint (https://mcp.ottoai.services/mcp).
Is the Otto Intel MCP server safe to use?
Otto Intel scores 71 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Otto Intel MCP server expose?
Otto Intel exposes 32 tools: otto_tokenized_equities, otto_rh_season, otto_equity_intel, otto_insider_trades, otto_institutional_holdings, and 27 more. Their descriptions and schemas cost roughly 6,561 tokens of context every time the server is loaded.
Does the Otto Intel MCP server require authentication?
No. We connected to Otto Intel without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Otto Intel MCP server still maintained?
Otto Intel is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.