Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Otto Intel

REMOTE · MCP.OTTOAI.SERVICES · SCANNED SEP 20

Otto AI hosted MCP: 16 pay-per-call market-intelligence tools, USDC via x402 on Base, no API keys.

+3 this week 71 Trust /100

Recent critical change

Authorization (2 Sept 2026). See the changelog before you install this server.

Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security60
Transport & Reachability100
Schema Quality & AI Usability61
  • AI-judged instruction clarity (good).Pass
  • Context-footprint check failed: tool/resource definitions use about 6561 tokens (~205/item across 32 items; 32 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management70
  • Stability observed for 21 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage89
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 61% of tool parameters carry a description.Partial
  • Structured output schemas are declared (59% of tools); any adoption earns full credit.Pass
Tool Safety88
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • 1 of 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "otto_prepare_yield_withdraw" implies "withdraw" and declares readOnlyHint instead, contradicting what its own name says it does. See how to fix → Partial
  • An AI judge read all 32 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

How do I install the Otto Intel MCP server?

Otto Intel is a hosted endpoint at https://mcp.ottoai.services/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · mcp.ottoai.services

# add to Claude Code
claude mcp add --transport http services-ottoai-otto 'https://mcp.ottoai.services/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "services-ottoai-otto": {
      "url": "https://mcp.ottoai.services/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "services-ottoai-otto": {
      "type": "http",
      "url": "https://mcp.ottoai.services/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.services-ottoai-otto]
url = "https://mcp.ottoai.services/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "services-ottoai-otto": {
      "type": "remote",
      "url": "https://mcp.ottoai.services/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add services-ottoai-otto --url 'https://mcp.ottoai.services/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  services-ottoai-otto:
    url: "https://mcp.ottoai.services/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "services-ottoai-otto": {
      "Transport": "http",
      "Url": "https://mcp.ottoai.services/mcp"
    }
  }
}
# add to Vellum
assistant mcp add services-ottoai-otto -t streamable-http -u 'https://mcp.ottoai.services/mcp'
// mcp.json
{
  "mcpServers": {
    "services-ottoai-otto": {
      "type": "http",
      "url": "https://mcp.ottoai.services/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 19 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 63 to 67. That category is still filling its 30-day observation window: 19 days of observed history at the previous scan, 20 at this one. The score rises as the window fills, whether or not the server changes.

  • 17 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.

  • 15 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 50 to 53. That category is still filling its 30-day observation window: 15 days of observed history at the previous scan, 16 at this one. The score rises as the window fills, whether or not the server changes.

  • 14 Sept 26 0
    • Tool “otto_native_yield_userop” rewrote its description, which is the text the model reads security
    • Tool “otto_sponsored_account” rewrote its description, which is the text the model reads security
    • Tool “otto_native_yield_userop” changed its title: Review or recover a sponsored native yield action → Review or recover an account native yield action cosmetic
    • Tool “otto_sponsored_account” changed its title: Review or recover a sponsored account transaction → Review or recover an account transaction cosmetic
  • 13 Sept 26 +1
    • New tool “otto_lp_collect_userop”, which the server declares destructive security
    • New tool “otto_native_yield_userop”, which the server declares destructive security
    • New tool “otto_sponsored_account”, which the server declares destructive security
    • Server version: 0.1.3 → 0.1.4 functional
  • 12 Sept 26 0
    • Tool “otto_prepare_yield_deposit” rewrote its description, which is the text the model reads security
    • Tool “otto_prepare_yield_withdraw” rewrote its description, which is the text the model reads security
  • 10 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 33 to 37. That category is still filling its 30-day observation window: 10 days of observed history at the previous scan, 11 at this one. The score rises as the window fills, whether or not the server changes.

  • 9 Sept 26 0
    • Tool “otto_delegation_exit” now declares an output schema functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 20 Sept 2026 · Probed https://mcp.ottoai.services/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=mcp.ottoai.services CN=YE2,O=Let's Encrypt,C=US 23 Jul 2026 21 Oct 2026 ECDSA 256 ECDSA-SHA384 583ddd8dbcd2ee144fdb9a6669b145857e0
SANs: mcp.ottoai.services
CN=YE2,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 4df3b15dd6c0784c507cd37b58e6f115
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd

Background: What to check on a remote MCP endpoint →

DNSSEC secure

Validation of mcp.ottoai.services. Secure

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
services. present 36727 8 Verified
ottoai.services. present 21999 13 Verified
mcp.ottoai.services. Verified address RRset verified with the apex keys
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://mcp.ottoai.services/mcp Verified 200
http (plaintext) http://mcp.ottoai.services/mcp HTTPS enforced 301 https://mcp.ottoai.services/mcp
MCP tools · 32 exposed · ~6,561 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
otto_base_season ~98

Scan quality-screened Base tokens with current social-intelligence and trusted-KOL context. Market context only; not a pick, recommendation, or trade instruction. Hosted access: the first successful intelligence call is free; later calls cost $0.002 USDC through x402.

NameTypeReqDescription
x_paymentstringSigned x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload.

No output schema declared.

No examples provided.

otto_catalog ~44

Return the full live otto x402 menu with endpoint paths, descriptions, prices, and Base-USDC payment instructions. Always free; does not consume the free intelligence call.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

otto_delegation_cap ~471

TWO PHASES, both header authed, both resolving the end user from the access token. { phase: "reserve", accessToken, perSwapCapUsd, requestedDays, mintKey } takes a generation-bound unified mint claim, picks a whole-second expiry instant at or BEFORE the requested duration that no durable row for this user already occupies, writes the chosen cap (whole USD, 1…5000) against it, and answers { expires_at, mint_expires_at, per_swap_cap_usd, recorded }. Call createDelegation with mint_expires_at EXACTLY as given — it is the reserved instant plus a one-millisecond filler, because CDP refuses an expiry ending .000 and truncates the filler away — and with mintKey as the idempotencyKey. Then { phase: "confirm", accessToken, mintKey } re-reads the grant from CDP and promotes only the exact still-current claim whose reported instant IS the reserved one. A mismatch, Stop overlap, or stale claim remains unconfirmed and authorises nothing; no confirm path issues CDP's user-wide revoke because that could delete a newer permission, so use a fresh explicit Stop to revoke whichever permission is current. Why this shape: Coinbase issues no grant id and a send can learn nothing about a live grant except its expiry, so the expiry is made an identity BY CONSTRUCTION — reserved server-side, recorded before the mint, asserted after it. Until a reservation is successfully confirmed active, otto_submit_under_delegation refuses that delegation (DELEGATION_CAP_UNCONFIRMED) rather than falling back to the 5000 USD ceiling. A reservation is IMMUTABLE per mint key — pressing again returns the same instant and cap, and an older revoke generation cannot be revived. Coinbase's engine cannot hold this number: end-user accounts are fenced by ONE project-scope policy shared by every delegated user, so a lower per-user cap is enforced by Otto's server alone. Server-to-server only: the caller presents Otto's delegation secret in the `x-otto-delegation-auth` request header (never in arguments); a call wit…

Input schema present but exposes no named parameters.

NameTypeReqDescription
expires_atstringyes
mint_expires_atstring
per_swap_cap_usdintegeryes
phasestringyes
recordedbooleanyes
ruleset_versionintegeryes
statestringyes
user_idstringyes

No examples provided.

otto_delegation_exit ~161

Move an authenticated CDP end user's own Base USDC only through a server-held durable reservation. prepare returns one exact EIP-1559 transaction for client-side signing; the client must never broadcast it. submit validates and durably records the signed bytes and computed hash before the server broadcasts. status is read-only and cross-device. reconcile proves a canonical receipt without broadcasting, or returns the exact finalized sender+nonce replacement proof when another transaction consumed the reserved nonce. retry_same is explicit and can broadcast only the already-stored byte-identical transaction after reconciling first. cancel is accepted only before signed bytes were recorded. The caller presents Otto's delegation secret in x-otto-delegation-auth; user identity is always derived from accessToken.

Input schema present but exposes no named parameters.

NameTypeReqDescription
accountstring
amount_atomicstring
broadcast_attemptsinteger
created_atstring
destinationstring
epochinteger
has_exitbooleanyes
lease_expires_atstring
operation_idstring
owner_tokenstring
phasestringyes
receiptobject
replacementobject
statestring
transactionobject
transaction_hashstring
updated_atstring
user_idstringyes

No examples provided.

otto_delegation_fence ~238

Idempotent ensure-by-digest of the ONE CDP project-scope policy that fences every delegated send, then a read-back. Writes only when no project policy exists (creates it) or when the existing one is Otto's own lineage with stale rules (updates it in place). REFUSES BY NAME if a different project-scope policy is installed — it is never overwritten or deleted. Never downgrades a newer fence. An OPS action: at most one ensure runs project-wide at a time, never during a rolling deploy, never from the dApp (the mint gate reads fence.present from otto_delegation_status). Arguments: {}. Output: the policy id, versioned name, rules digest and the per-swap cap; the tool fails unless the fence reads back present under the written id. Server-to-server only: the caller presents Otto's delegation secret in the `x-otto-delegation-auth` request header (never in arguments); a call without it is refused before anything is read. The listed input schema is intentionally permissive — the strict schema is validated after the caller is authenticated.

Input schema present but exposes no named parameters.

NameTypeReqDescription
actionstringyes
per_swap_cap_usdnumberyes
policy_idstringyes
policy_namestringyes
rules_digeststringyes
statusstringyes

No examples provided.

otto_delegation_fence_status ~198

PUBLIC and read-only, no header: whether the Model-B project policy that fences every delegated send is installed and v-current on this server, with its versioned name, rules digest, the per-swap cap ceiling in USD (shared by every delegated user — a person may choose any whole-dollar cap from per_swap_cap_min_usd up to it, enforced server-side and recorded against their own grant), and Otto's PUBLIC CDP project id (a UUID — the authority an agent binds its mint to). Exposes ONLY the fence's public promise — never an end user, a grant, an address or a policy's contents. An agent about to mint a delegation (otto-execute delegate) reads this first, mints to the published project_id and no other, and refuses to mint when the fence is not present; the server enforces fence-before-authority on every delegated send regardless. Arguments: {}.

Input schema present but exposes no named parameters.

NameTypeReqDescription
mint_enabledbooleanyes
per_swap_cap_min_usdnumberyes
per_swap_cap_usdnumberyes
policy_namestringyes
presentbooleanyes
project_idstring
reasonstring
rules_digeststring
ruleset_versionintegeryes

No examples provided.

otto_delegation_operations ~150

Read the durable Base delegated-operation journal for the end user resolved from { accessToken }. Optional artifactId selects one exact own-user operation; without it, the result includes a bounded recent terminal history and every unresolved operation regardless of age. The global unresolved flag is fail-closed: it is true when the store is unavailable, journal coverage is not rollout-ready, or any operation has a prepared/submitted/unknown outcome. Stored serialized transactions and CDP idempotency keys are never returned, and this tool never submits or retries anything. Server-to-server only: the caller also presents Otto's delegation secret in the x-otto-delegation-auth request header; no userId argument is accepted.

Input schema present but exposes no named parameters.

NameTypeReqDescription
journalobjectyes
operationsarrayyes
store_availablebooleanyes
unresolvedbooleanyes
user_idstringyes

No examples provided.

otto_delegation_reconcile ~142

Acquire the artifact's permanent process-liveness guard, then check Base for finalized canonical receipts of already-stored transaction hashes. Every chain transaction must match the stored chain, hash, sender, target, calldata, value, nonce, gas and EIP-1559 fee fields before its receipt is recorded. This tool never calls CDP, never retries a request, never builds or submits a later step, and leaves prepared/unknown no-hash steps unresolved. It returns the same token-bound operation snapshot as otto_delegation_operations. Server-to-server only: the caller also presents Otto's delegation secret in x-otto-delegation-auth.

Input schema present but exposes no named parameters.

NameTypeReqDescription
journalobjectyes
operationsarrayyes
store_availablebooleanyes
unresolvedbooleanyes
user_idstringyes

No examples provided.

otto_delegation_revoke ~171

Revoke the end user's delegation from Otto's side and confirm by read-back that it no longer exists; from then on this server submits nothing for that user (fail-closed, even if the read-back had failed). Arguments: EITHER { accessToken } (the user path — the server resolves the user from the token) OR { userId, support_reason } (the support path, for an operator holding the server secret; the reason is logged, the token never is). Server-to-server only: the caller presents Otto's delegation secret in the `x-otto-delegation-auth` request header (never in arguments); a call without it is refused before anything is read. The listed input schema is intentionally permissive — the strict schema is validated after the caller is authenticated.

Input schema present but exposes no named parameters.

NameTypeReqDescription
pathstringyes
reads_backbooleanyes
revokedbooleanyes
user_idstringyes

No examples provided.

otto_delegation_status ~227

Read back, for the end user identified by a CDP access token, their CDP accounts, whether the Model-B fence is present, and whether an active delegation reads back (with its expiry and the per-swap cap recorded for it). Arguments: { accessToken } — the server resolves the user from the token; a client-sent user id is refused. delegation.per_swap_cap_usd is the number THIS user chose at mint time; it is ABSENT when no cap is recorded for the grant, which means the delegated send will refuse it — say so rather than showing the shared ceiling. fence.per_swap_cap_usd is that shared ceiling and is never a per-user number. Output is bound to that user; nothing about any other user is returned. Server-to-server only: the caller presents Otto's delegation secret in the `x-otto-delegation-auth` request header (never in arguments); a call without it is refused before anything is read. The listed input schema is intentionally permissive — the strict schema is validated after the caller is authenticated.

Input schema present but exposes no named parameters.

NameTypeReqDescription
addressesarrayyes
delegationobjectyes
fenceobjectyes
mint_enabledbooleanyes
revocation_requested_herebooleanyes
ruleset_versionintegeryes
user_idstringyes

No examples provided.

otto_equity_intel ~145

Read SEC-EDGAR fundamentals and filings context for a US ticker: revenue and net-income trends, margins, EPS, leverage, recent 10-K/10-Q/8-K filings, and a guarded AI summary. Fundamentals scanner only; not a price feed or recommendation. Hosted access: the first successful intelligence call is free; later calls cost $0.003 USDC through x402.

NameTypeReqDescription
tickerstringyesUS-listed stock ticker, for example NVDA, AAPL, or JPM.
x_paymentstringSigned x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload.

No output schema declared.

No examples provided.

otto_equity_smart_money ~127

Read a public-domain SEC bundle for a US ticker: Form 4 insider activity plus trailing-twelve-month XBRL fundamentals. Scanner context only; not a pick or recommendation. Hosted access: the first successful intelligence call is free; later calls cost $0.006 USDC through x402.

NameTypeReqDescription
tickerstringyesUS-listed stock ticker, for example NVDA, AAPL, or JPM.
x_paymentstringSigned x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload.

No output schema declared.

No examples provided.

otto_equity_smart_money_brief ~140

Read one guarded AI brief over observed SEC Form 4 flow, 13D/13G ownership events, and fundamentals for a US ticker. Filing scanner only; generation rejects buy/sell advice and the result is not a recommendation. Hosted access: the first successful intelligence call is free; later calls cost $0.10 USDC through x402.

NameTypeReqDescription
tickerstringyesUS-listed stock ticker, for example NVDA, AAPL, or JPM.
x_paymentstringSigned x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload.

No output schema declared.

No examples provided.

otto_insider_trades ~128

Read parsed SEC Form 4 insider transactions for a US ticker, including purchase/sale counts, dollar values, roles, and net P/S balance. Filing scanner only; not a recommendation. Hosted access: the first successful intelligence call is free; later calls cost $0.003 USDC through x402.

NameTypeReqDescription
tickerstringyesUS-listed stock ticker, for example NVDA, AAPL, or JPM.
x_paymentstringSigned x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload.

No output schema declared.

No examples provided.

otto_institutional_holdings ~131

Read the latest SEC 13F-HR top positions for an institutional manager by CIK or manager ticker, with amendments applied. Ownership data only; not a recommendation. Hosted access: the first successful intelligence call is free; later calls cost $0.003 USDC through x402.

NameTypeReqDescription
managerstringyesSEC manager CIK, such as 1067983, or listed manager ticker, such as BLK.
x_paymentstringSigned x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload.

No output schema declared.

No examples provided.

otto_lp_collect_userop ~88

Protected same-account Uniswap V3 guarded collection on Base. Read availability, prepare and explicitly confirm one operation, or read/reconcile it. May collect owed principal and fees; profit remains unknown. Account upgrade is separate. Current owner authority, reviewed guard and provider policy are required. Unknown delivery retains the original operation; no replacement is allowed. Preparation and simulation are not funded execution.

Input schema present but exposes no named parameters.

NameTypeReqDescription
accountstring
actionstring
attention
automaticExecutionEnabledboolean
chainIdnumber
collectionobject
configuredboolean
confirmationstring
envelopeCommitmentstring
executionEnabledboolean
failureCodestring
gas
kindstringyes
operationIdstring
poolstring
protocolstring
protocolActionVerifiedboolean
reasonstring
recoveryAvailableboolean
replacementPermittedboolean
requiresOperationReviewboolean
requiresReconciliationboolean
requiresSeparateWalletUpgradeboolean
retrySafeboolean
reviewCommitmentstring
reviewConsumedboolean
schemaVersionstringyes
settlement
statestring
statusstring
supportedActionsarray
supportedSameAddressChainsarray
tokenIdstring
transactionHashstring
userOpHashstring
validUntilMsinteger
walletAuthorityChangeIncludedboolean

No examples provided.

otto_native_yield_userop ~88

Protected native protocol action. Read availability, review and confirm native scope, prepare, reviewGas for current payer and network estimate, and explicitly confirm one operation, or read/reconcile/revoke native consent. Account upgrade is separate. Source activation and current owner authority are required. Unknown delivery retains the original operation; no replacement is allowed. A preparation or simulation is not funded execution.

Input schema present but exposes no named parameters.

NameTypeReqDescription
accountstring
actionstring
attention
automaticExecutionEnabledboolean
chainId
configuredboolean
confirmationstring
consentobject
envelopeCommitmentstring
estimatedOttoFeeobject
executionEnabledboolean
existingOperationRequiresReconciliationboolean
failureCodestring
gas
inputobject
kindstringyes
marketIdstring
nativeConsentRevokedboolean
operationIdstring
outputobject
perDepositCapUsdinteger
protocolActionVerifiedboolean
reasonstring
recoveryAvailableboolean
replacementPermittedboolean
requiresNativeConsentboolean
requiresOperationReviewboolean
requiresReconciliationboolean
requiresSeparateOperationReviewboolean
requiresSeparateWalletUpgradeboolean
retrySafeboolean
reviewCommitmentstring
reviewConsumedboolean
schemaVersionstringyes
scopeobject
scopeConsentobject
settlement
statestring
statusstring
supportedSameAddressChainsarray
transactionHashstring
userOpHashstring
validUntilMsinteger
walletAuthorityChangeIncludedboolean

No examples provided.

otto_pm_crypto ~99

Read high-volume open BTC, ETH, and crypto Polymarket markets with current outcome probabilities and market context. Event-probability data only; not a recommendation. Hosted access: the first successful intelligence call is free; later calls cost $0.001 USDC through x402.

NameTypeReqDescription
x_paymentstringSigned x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload.

No output schema declared.

No examples provided.

otto_pm_markets ~105

Read the highest-volume open Polymarket markets with live outcome probabilities, bid/ask context, liquidity, volume, and end dates. Event-probability context only; not a recommendation. Hosted access: the first successful intelligence call is free; later calls cost $0.001 USDC through x402.

NameTypeReqDescription
x_paymentstringSigned x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload.

No output schema declared.

No examples provided.

otto_prepare_bridge ~319

Prepare, decode, and verify an unsigned cross-chain native-USDC bridge construction aid for the caller-owned EOA or Safe, over the enumerated v1 Circle-CCTP route set (Ethereum, Polygon, Base, Arbitrum, Avalanche); any other chain, token, or bridge route is refused by name. The envelope's valid_until bounds freshness and is committed to the artifact digest; the signer account nonce is the on-chain replay boundary, and this tool cannot guarantee single execution. Returns ordered allowance-reset, approval, and call steps on the source chain only; never signs or submits. Every envelope from this server is valid for 300 seconds from construction (valid_until); a stale envelope is refused by the verifier — request a fresh one.

NameTypeReqDescription
accountProfileobjectyes
client_refstring
destinationRecipientstringWhere the destination mint lands. Optional for an EOA, whose address is identical on every EVM chain; REQUIRED for a Safe, whose address is not guaranteed to be the same contract on the destination c…
fromAmountstringyesExact gross input amount in atomic token units.
fromChainIdintegeryes
fromTokenstringyesNative USDC on the source chain; the v1 bridge route set is USDC-only.
slippageobjectyes
toChainIdintegeryes
toTokenstringyesNative USDC on the destination chain; the v1 bridge route set is USDC-only.
NameTypeReqDescription
account_bindingobjectyes
artifact_idstringyes
assertionsarrayyes
fee_attributionobjectyes
intent_digeststringyes
operationstringyes
payloadyes
railstringyes
replay_disclosureobjectyes
required_capabilitiesarrayyes
schema_versionstringyes
submissionobjectyes
valid_untilstringyes

No examples provided.

otto_prepare_perp_order ~606

Prepare and verify an unsigned Hyperliquid perpetuals order (limit, with optional reduce-only take-profit and stop-loss triggers bundled as normalTpsl) for the caller-owned Hyperliquid account, returned as the canonical L1 action plus the exact EIP-712 Agent domain, struct, and connectionId recipe the caller's own signer needs. The asset id, size grid, and price grid come from the live perp universe: an unknown or delisted perp, a size finer than the asset's szDecimals, or a price off the venue's 5-significant-digit / (6 - szDecimals) decimal grid is refused by name rather than rounded to a different order. There is no market order — name your own aggressive limit price with 'Ioc'. Otto's builder attribution is spec'd and valueless today, so the action carries no builder field and the envelope says so. The nonce is chosen by the signer, never here; the envelope's valid_until is committed to the artifact digest AND placed inside the signed digest as expiresAfter, so the venue itself rejects a stale action, while the Hyperliquid signer nonce remains the replay boundary and this tool cannot guarantee single execution. This tool never signs or submits, holds no key, and derives no agent wallet. Every envelope from this server is valid for 300 seconds from construction (valid_until); a stale envelope is refused by the verifier — request a fresh one.

NameTypeReqDescription
accountProfileobjectyesThe Hyperliquid master account. `chainId` must be 1337, the signature chain id Hyperliquid pins for every L1 action.
assetstringyesPerp symbol exactly as the venue names it, e.g. 'BTC', 'kPEPE'. Case-sensitive.
client_refstring
limitPricestringyesLimit price. Must sit on the venue grid: at most 5 significant digits unless integer, and at most (6 - szDecimals) decimals.
reduceOnlyboolean
sidestringyes
sizestringyesOrder size in base units, e.g. '0.01'. At most szDecimals fractional digits for this perp.
stopLossPricestringOptional reduce-only market stop-loss trigger, bundled with grouping normalTpsl.
takeProfitPricestringOptional reduce-only market take-profit trigger, bundled with grouping normalTpsl.
timeInForcestringGtc rests, Ioc fills-or-cancels, Alo posts only. There is no market order: name your own aggressive limit price with 'Ioc' instead.
tradingSignerstringThe address that will sign, when it is not the master account itself: a user-held approved API wallet. Declared, never derived.
vaultAddressstringTrade on behalf of this vault or sub-account. A declared profile fact only.
NameTypeReqDescription
account_bindingobjectyes
artifact_idstringyes
assertionsarrayyes
fee_attributionobjectyes
intent_digeststringyes
operationstringyes
payloadobjectyes
railstringyes
replay_disclosureobjectyes
required_capabilitiesarrayyes
schema_versionstringyes
submissionobjectyes
valid_untilstringyes

No examples provided.

otto_prepare_polymarket_order ~277

Prepare and verify an unsigned Polymarket CTF Exchange V2 limit order (GTC) for the caller-owned Polygon EOA, with Otto's builder code stamped inside the EIP-712 order struct and re-asserted on the exact digest the signer will sign. The price must be an exact multiple of the market's live minimum tick size and the size at or above its published minimum. The envelope's valid_until bounds freshness and is committed to the artifact digest; the exchange's own order hash is the replay boundary, and this tool cannot guarantee single execution. Returns order args and typed data only; never signs or submits, holds no CLOB credentials, and touches no collateral or allowance. Every envelope from this server is valid for 300 seconds from construction (valid_until); a stale envelope is refused by the verifier — request a fresh one.

NameTypeReqDescription
accountProfileobjectyes
client_refstring
pricestringyesLimit price as a probability, e.g. '0.045'. Must be an exact multiple of the market's minimum tick size.
sidestringyes
sizestringyesOrder size in outcome-token shares.
tokenIdstringyesOutcome-token id (NOT the condition id): YES and NO are different token ids.
NameTypeReqDescription
account_bindingobjectyes
artifact_idstringyes
assertionsarrayyes
fee_attributionobjectyes
intent_digeststringyes
operationstringyes
payloadobjectyes
railstringyes
replay_disclosureobjectyes
required_capabilitiesarrayyes
schema_versionstringyes
submissionobjectyes
valid_untilstringyes

No examples provided.

otto_prepare_stock_buy ~330

Prepare the EXACT otto_prepare_swap pair (envelope + prepareInput) that buys one of the executable Coinbase B20 tokenized equities on Base with USDC, as a LI.FI route through the fenced diamond whose receiver is the signing account. The token comes from the registry row named by executableEquityId and is never an input; the caller's registryCommitment must equal the commitment recomputed over the current record. The WORST PERMISSIBLE FILL (amount over the route's own floor) is checked against the equity's own Chainlink total-return mark and refused when it exceeds the pinned tolerance, or when the feed is frozen (> 24 h). Returns the pair unchanged plus a preview; never signs or submits — submit the pair through otto_submit_under_delegation under the end user's per-swap cap. Every envelope from this server is valid for 300 seconds from construction (valid_until); a stale envelope is refused by the verifier — request a fresh one.

NameTypeReqDescription
accountProfileobjectyes
amountstringyesExact USDC amount to spend, in atomic units (6 decimals).
client_refstring
executableEquityIdstringyesThe executable equity id the READ half served, e.g. b20-nvda (Coinbase B20 on Base only).
registryCommitmentstringyesThe registry commitment served with that row. It must equal the commitment this server recomputes over the CURRENT record; a stale or foreign row is refused by name.
slippageobjectyes
NameTypeReqDescription
envelopeobjectyes
prepareInputobjectyes
previewobjectyes
registry_commitmentstringyes

No examples provided.

otto_prepare_swap ~209

Prepare, decode, and verify an unsigned same-chain EVM ERC20 swap construction aid for the caller-owned EOA or Safe. The envelope's valid_until bounds freshness and is committed to the artifact digest; the signer account nonce is the on-chain replay boundary, and this tool cannot guarantee single execution. Returns ordered allowance-reset, approval, and call steps only; never signs or submits. Every envelope from this server is valid for 300 seconds from construction (valid_until); a stale envelope is refused by the verifier — request a fresh one.

NameTypeReqDescription
accountProfileobjectyes
chainIdintegeryes
client_refstring
fromAmountstringyesExact input amount in atomic token units.
fromTokenstringyesERC20 input token address; native-token routes are out of v1.
slippageobjectyes
toTokenstringyesERC20 output token address; native-token routes are out of v1.
NameTypeReqDescription
account_bindingobjectyes
artifact_idstringyes
assertionsarrayyes
fee_attributionobjectyes
intent_digeststringyes
operationstringyes
payloadyes
railstringyes
replay_disclosureobjectyes
required_capabilitiesarrayyes
schema_versionstringyes
submissionobjectyes
valid_untilstringyes

No examples provided.

otto_prepare_yield_deposit ~345

Prepare the EXACT otto_prepare_swap pair (envelope + prepareInput) that deposits USDC into one of the executable Morpho vaults from the Yield Copilot registry, as a LI.FI position-acquisition route (which may buy shares or compose a protocol deposit) whose output token is the vault's ERC-4626 share token and whose receiver is the signing account. The vault comes from the registry row named by executableMarketId and is never an input; the caller's registryCommitment must equal the commitment recomputed over the current record. The quoted shares are checked against the vault's own previewDeposit and refused when they fall short by more than the pinned tolerance. Returns the pair unchanged plus a preview; never signs or submits — submit the pair through otto_submit_under_delegation under the end user's per-swap cap. Every envelope from this server is valid for 300 seconds from construction (valid_until); a stale envelope is refused by the verifier — request a fresh one.

NameTypeReqDescription
accountProfileobjectyes
amountstringyesExact USDC amount to deposit, in atomic units (6 decimals).
client_refstring
executableMarketIdstringyesThe executable market id the READ half served (`GET /api/yield-copilot` rows with deployable:true), e.g. base-usdc-morpho-gauntlet-prime.
registryCommitmentstringyesThe registry commitment served with that row. It must equal the commitment this server recomputes over the CURRENT record; a stale or foreign row is refused by name.
slippageobjectyes
NameTypeReqDescription
envelopeobjectyes
prepareInputobjectyes
previewobjectyes
registry_commitmentstringyes

No examples provided.

otto_prepare_yield_withdraw ~306

Prepare the EXACT otto_prepare_swap pair (envelope + prepareInput) that redeems vault shares from one of the executable Morpho vaults in the Yield Copilot registry back to USDC in the signing account, as a LI.FI exit route (which may sell shares or compose a protocol redemption) whose input token is the vault's ERC-4626 share token. The vault and the asset come from the registry row named by executableMarketId and are never inputs; the caller's registryCommitment must equal the commitment recomputed over the current record. The quoted USDC is checked against the vault's own previewRedeem and refused when it falls short by more than the pinned tolerance. Returns the pair unchanged plus a preview; never signs or submits — submit the pair through otto_submit_under_delegation, which admits a withdraw only under fence v2 and a permission minted under cap ruleset v2, values it at zero against the per-swap cap (it returns the person's own assets), and bounds it by the engine's share cap. Every envelope from this server is valid for 300 seconds from construction (valid_until); a stale envelope is refused by the verifier — request a fresh one.

NameTypeReqDescription
accountProfileobjectyes
client_refstring
executableMarketIdstringyes
registryCommitmentstringyes
sharesstringyes
slippageobjectyes
NameTypeReqDescription
envelopeobjectyes
prepareInputobjectyes
previewobjectyes
registry_commitmentstringyes

No examples provided.

otto_rh_season ~105

Scan rug-screened Robinhood Chain (4663) movers with honeypot filters and per-token risk flags. Market context only; not a pick, recommendation, or trade instruction. Hosted access: the first successful intelligence call is free; later calls cost $0.001 USDC through x402.

NameTypeReqDescription
x_paymentstringSigned x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload.

No output schema declared.

No examples provided.

otto_sponsored_account ~82

Protected account action: availability, prepare, reviewGas for current gas payer and estimate, explicit submit, owned read or reconcile. Gas refresh is read-only planning and requires new confirmation before any send. Wallet upgrade is separate. Sponsorship requires a reviewed source activation; current availability is authoritative. A missing submission response is unknown and must never cause a replacement submission.

Input schema present but exposes no named parameters.

NameTypeReqDescription
accountstring
attention
automaticExecutionEnabledboolean
chainId
configuredboolean
executionEnabledboolean
failureCodestring
gas
inputobject
operationIdstring
ottoFeestring
outputobject
reasonstring
receiptobject
recoveryAvailableboolean
replacementPermittedboolean
requiresOperationReviewboolean
requiresReconciliationboolean
requiresSeparateWalletUpgradeboolean
reviewCommitmentstring
reviewConsumedboolean
schemaVersionstringyes
settlementobject
statestring
statusstring
supportedSameAddressChainsarray
termsobject
transactionHashstring
userOpHashstring
validUntilMsinteger
walletAuthorityChangeIncludedboolean

No examples provided.

otto_stock_pools ~352

Find the DEX pools a tokenized US stock is actually a member of, on Robinhood Chain, Base, BNB Chain or Solana. Returns each pool id (Uniswap v4 pool ids kept distinct from v3 pool addresses), DEX and version, which side the stock is on, the counterpart token with an evidence-backed classification (verified stock, verified stablecoin, or unclassified), reported USD liquidity and 24h volume, 24h transaction count, pool creation time, and the source coverage limits. Membership discovery only: a provider-covered observation rather than a complete census, no APR and no execution support, and the stock’s own 24h return is reported only from pools where the stock is the base token. Identify the stock by address when a ticker names two deployments on one chain (eight Solana tickers exist on both xStocks and Backpack) — that spelling is refused rather than resolved to one of them. Not a pairing recommendation. Hosted access: the first successful intelligence call is free; later calls cost $0.001 USDC through x402.

NameTypeReqDescription
stockstringyesNetwork-qualified tokenized-stock identity: "<network>:<TICKER>" or "<network>:<token address>", where network is robinhood, base, bsc or solana. Example: robinhood:MU. A bare ticker is rejected, and…
x_paymentstringSigned x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload.

No output schema declared.

No examples provided.

otto_submit_under_delegation ~405

Submit a verified otto_prepare_swap envelope on Base under the end user's CDP delegation. Arguments: { userId, envelope (the otto_prepare_swap result), prepareInput (the exact otto_prepare_swap request, with slippage.minAmountOut) } — validated strictly AFTER the caller is authenticated, so the listed input schema is intentionally permissive. Server-to-server only: the caller presents Otto's delegation secret in the `x-otto-delegation-auth` request header (never in arguments); a call without it is refused before anything is read. Before any send the server confirms, in this order: the Model-B project policy is installed and reads back by name and rules digest; the user's grant is active past the envelope's valid_until; the account is one of that end user's own CDP accounts as CDP reports them; the envelope passes the 13-check verifier for exactly the request that produced it; the plan is inside the fence (allow-listed input token, reviewed spender, gross at or below the 5000 USD engine ceiling); and the plan is at or below the per-swap cap THIS user chose when they minted, which is recorded against their grant on this server. A delegation with no recorded cap is REFUSED (DELEGATION_CAP_UNRECORDED) rather than defaulted to the ceiling — mint the permission again to set one. Then the three steps (allowance reset, approval, swap) are submitted in order under the delegation, each waited to a sealed canonical block; a halt clears the allowance and reports the read-back. One delegated plan at a time per user. Coinbase's engine bounds the delegated key to Model-B swap shapes through LI.FI up to the 5000 USD ceiling, which is shared by every delegated user and cannot be narrowed per user by the engine; the user's own lower cap and the receiver binding are Otto's server-side checks, and the user can revoke at any time.

Input schema present but exposes no named parameters.

NameTypeReqDescription
addressstringyes
artifact_idstringyes
chain_idnumberyes
delegationobjectyes
fenceobjectyes
replayedboolean
statusstringyes
stepsarrayyes
user_idstringyes
verificationobjectyes

No examples provided.

otto_tokenized_equities ~165

Scan the live registry of US equities and ETFs tokenized on Robinhood Chain (4663): symbol, canonical token address, decimals, the executable buy price a live route returns, the catalog reference price and the deviation between them, plus a verifiable tradability signal. An optional thesis returns a relevance-ranked shortlist with a match reason per row. Data only; not a recommendation or executable quote. Hosted access: the first successful intelligence call is free; later calls cost $0.001 USDC through x402.

NameTypeReqDescription
thesisstringNatural-language screening thesis, for example "AI infrastructure chips".
x_paymentstringSigned x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload.

No output schema declared.

No examples provided.

otto_x_recipes ~109

Return Otto X's live X Layer recipe menu — each recipe's path, price, and the X Layer (eip155:196) payment requirement decoded from its unpaid 402 challenge: token asset, issuer name/version, payTo, and a copy-paste curl. Settles in USD₮0 / USD Coin / Global Dollar on X Layer via the PAYMENT-SIGNATURE header. Always free and read-only; never signs or pays and does not consume the free intelligence call.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

Common questions

What is the Otto Intel MCP server?

Otto Intel is an MCP server listed in the public MCP registry as services.ottoai/otto. Otto AI hosted MCP: 16 pay-per-call market-intelligence tools, USDC via x402 on Base, no API keys. This page covers its hosted endpoint (https://mcp.ottoai.services/mcp).

Is the Otto Intel MCP server safe to use?

Otto Intel scores 71 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Otto Intel MCP server expose?

Otto Intel exposes 32 tools: otto_tokenized_equities, otto_rh_season, otto_equity_intel, otto_insider_trades, otto_institutional_holdings, and 27 more. Their descriptions and schemas cost roughly 6,561 tokens of context every time the server is loaded.

Does the Otto Intel MCP server require authentication?

No. We connected to Otto Intel without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the Otto Intel MCP server still maintained?

Otto Intel is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.