# Otto Intel (remote · mcp.ottoai.services)

Otto AI hosted MCP: 16 pay-per-call market-intelligence tools, USDC via x402 on Base, no API keys.

- Trust score: 71/100 (medium)
- Change this week: +3
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-20

> **Recent critical change**: Authorization (2026-09-02). See the changelog below before you install this server.

## Components

- remote · `mcp.ottoai.services`: 71/100 (this document), [markdown](https://verifymcp.io/servers/services-ottoai-otto/mcp.md), [page](https://verifymcp.io/servers/services-ottoai-otto/mcp)

## Channel facts

- Endpoint: `https://mcp.ottoai.services/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `0.1.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-20.

- **Endpoint Security**: 60/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (otto_sponsored_account).
  - HTTPS is enforced; there's no plaintext access path.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC is configured correctly; the domain's records validate against the full chain to the root.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 61/100
  - AI-judged instruction clarity (good).
  - Context-footprint check failed: tool/resource definitions use about 6561 tokens (~205/item across 32 items; 32 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 70/100
  - Stability observed for 21 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 89/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 61% of tool parameters carry a description.
  - Structured output schemas are declared (59% of tools); any adoption earns full credit.
- **Tool Safety**: 88/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - 1 of 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "otto_prepare_yield_withdraw" implies "withdraw" and declares readOnlyHint instead, contradicting what its own name says it does.
  - An AI judge read all 32 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### How do I install the Otto Intel MCP server?

Otto Intel is a hosted endpoint at https://mcp.ottoai.services/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http services-ottoai-otto 'https://mcp.ottoai.services/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "services-ottoai-otto": {
      "url": "https://mcp.ottoai.services/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "services-ottoai-otto": {
      "type": "http",
      "url": "https://mcp.ottoai.services/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.services-ottoai-otto]
url = "https://mcp.ottoai.services/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "services-ottoai-otto": {
      "type": "remote",
      "url": "https://mcp.ottoai.services/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add services-ottoai-otto --url 'https://mcp.ottoai.services/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  services-ottoai-otto:
    url: "https://mcp.ottoai.services/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "services-ottoai-otto": {
      "Transport": "http",
      "Url": "https://mcp.ottoai.services/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add services-ottoai-otto -t streamable-http -u 'https://mcp.ottoai.services/mcp'
```

### Other

```json
{
  "mcpServers": {
    "services-ottoai-otto": {
      "type": "http",
      "url": "https://mcp.ottoai.services/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-19 (score 71, +1)

No change was recorded against any check on this day. Stability & Change Management went from 63 to 67. That category is still filling its 30-day observation window: 19 days of observed history at the previous scan, 20 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-17 (score 70, +1)

No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-15 (score 69, +1)

No change was recorded against any check on this day. Stability & Change Management went from 50 to 53. That category is still filling its 30-day observation window: 15 days of observed history at the previous scan, 16 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-14 (score 68, 0)

- [security] Tool “otto_native_yield_userop” rewrote its description, which is the text the model reads
- [security] Tool “otto_sponsored_account” rewrote its description, which is the text the model reads
- [cosmetic] Tool “otto_native_yield_userop” changed its title: Review or recover a sponsored native yield action → Review or recover an account native yield action
- [cosmetic] Tool “otto_sponsored_account” changed its title: Review or recover a sponsored account transaction → Review or recover an account transaction

### 2026-09-13 (score 68, +1)

- [security] New tool “otto_lp_collect_userop”, which the server declares destructive
- [security] New tool “otto_native_yield_userop”, which the server declares destructive
- [security] New tool “otto_sponsored_account”, which the server declares destructive
- [functional] Server version: 0.1.3 → 0.1.4

### 2026-09-12 (score 67, 0)

- [security] Tool “otto_prepare_yield_deposit” rewrote its description, which is the text the model reads
- [security] Tool “otto_prepare_yield_withdraw” rewrote its description, which is the text the model reads

### 2026-09-10 (score 67, +1)

No change was recorded against any check on this day. Stability & Change Management went from 33 to 37. That category is still filling its 30-day observation window: 10 days of observed history at the previous scan, 11 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-09 (score 66, 0)

- [functional improvement] Tool “otto_delegation_exit” now declares an output schema

## MCP tools (32)

### `otto_tokenized_equities` (~165 tokens)

Otto tokenized equities

Scan the live registry of US equities and ETFs tokenized on Robinhood Chain (4663): symbol, canonical token address, decimals, the executable buy price a live route returns, the catalog reference price and the deviation between them, plus a verifiable tradability signal. An optional thesis returns a relevance-ranked shortlist with a match reason per row. Data only; not a recommendation or executable quote. Hosted access: the first successful intelligence call is free; later calls cost $0.001 USDC through x402.

Input parameters:

- `thesis` (string): Natural-language screening thesis, for example "AI infrastructure chips".
- `x_payment` (string): Signed x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload.

### `otto_rh_season` (~105 tokens)

Otto Robinhood Chain season

Scan rug-screened Robinhood Chain (4663) movers with honeypot filters and per-token risk flags. Market context only; not a pick, recommendation, or trade instruction. Hosted access: the first successful intelligence call is free; later calls cost $0.001 USDC through x402.

Input parameters:

- `x_payment` (string): Signed x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload.

### `otto_equity_intel` (~145 tokens)

Otto equity intelligence

Read SEC-EDGAR fundamentals and filings context for a US ticker: revenue and net-income trends, margins, EPS, leverage, recent 10-K/10-Q/8-K filings, and a guarded AI summary. Fundamentals scanner only; not a price feed or recommendation. Hosted access: the first successful intelligence call is free; later calls cost $0.003 USDC through x402.

Input parameters:

- `ticker` (string, required): US-listed stock ticker, for example NVDA, AAPL, or JPM.
- `x_payment` (string): Signed x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload.

### `otto_insider_trades` (~128 tokens)

Otto insider trades

Read parsed SEC Form 4 insider transactions for a US ticker, including purchase/sale counts, dollar values, roles, and net P/S balance. Filing scanner only; not a recommendation. Hosted access: the first successful intelligence call is free; later calls cost $0.003 USDC through x402.

Input parameters:

- `ticker` (string, required): US-listed stock ticker, for example NVDA, AAPL, or JPM.
- `x_payment` (string): Signed x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload.

### `otto_institutional_holdings` (~131 tokens)

Otto institutional holdings

Read the latest SEC 13F-HR top positions for an institutional manager by CIK or manager ticker, with amendments applied. Ownership data only; not a recommendation. Hosted access: the first successful intelligence call is free; later calls cost $0.003 USDC through x402.

Input parameters:

- `manager` (string, required): SEC manager CIK, such as 1067983, or listed manager ticker, such as BLK.
- `x_payment` (string): Signed x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload.

### `otto_equity_smart_money` (~127 tokens)

Otto equity smart-money scanner

Read a public-domain SEC bundle for a US ticker: Form 4 insider activity plus trailing-twelve-month XBRL fundamentals. Scanner context only; not a pick or recommendation. Hosted access: the first successful intelligence call is free; later calls cost $0.006 USDC through x402.

Input parameters:

- `ticker` (string, required): US-listed stock ticker, for example NVDA, AAPL, or JPM.
- `x_payment` (string): Signed x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload.

### `otto_equity_smart_money_brief` (~140 tokens)

Otto equity smart-money brief

Read one guarded AI brief over observed SEC Form 4 flow, 13D/13G ownership events, and fundamentals for a US ticker. Filing scanner only; generation rejects buy/sell advice and the result is not a recommendation. Hosted access: the first successful intelligence call is free; later calls cost $0.10 USDC through x402.

Input parameters:

- `ticker` (string, required): US-listed stock ticker, for example NVDA, AAPL, or JPM.
- `x_payment` (string): Signed x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload.

### `otto_base_season` (~98 tokens)

Otto Base season

Scan quality-screened Base tokens with current social-intelligence and trusted-KOL context. Market context only; not a pick, recommendation, or trade instruction. Hosted access: the first successful intelligence call is free; later calls cost $0.002 USDC through x402.

Input parameters:

- `x_payment` (string): Signed x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload.

### `otto_pm_markets` (~105 tokens)

Otto prediction-market context

Read the highest-volume open Polymarket markets with live outcome probabilities, bid/ask context, liquidity, volume, and end dates. Event-probability context only; not a recommendation. Hosted access: the first successful intelligence call is free; later calls cost $0.001 USDC through x402.

Input parameters:

- `x_payment` (string): Signed x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload.

### `otto_pm_crypto` (~99 tokens)

Otto crypto prediction-market context

Read high-volume open BTC, ETH, and crypto Polymarket markets with current outcome probabilities and market context. Event-probability data only; not a recommendation. Hosted access: the first successful intelligence call is free; later calls cost $0.001 USDC through x402.

Input parameters:

- `x_payment` (string): Signed x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload.

### `otto_stock_pools` (~352 tokens)

Otto tokenized-stock pool discovery

Find the DEX pools a tokenized US stock is actually a member of, on Robinhood Chain, Base, BNB Chain or Solana. Returns each pool id (Uniswap v4 pool ids kept distinct from v3 pool addresses), DEX and version, which side the stock is on, the counterpart token with an evidence-backed classification (verified stock, verified stablecoin, or unclassified), reported USD liquidity and 24h volume, 24h transaction count, pool creation time, and the source coverage limits. Membership discovery only: a provider-covered observation rather than a complete census, no APR and no execution support, and the stock’s own 24h return is reported only from pools where the stock is the base token. Identify the stock by address when a ticker names two deployments on one chain (eight Solana tickers exist on both xStocks and Backpack) — that spelling is refused rather than resolved to one of them. Not a pairing recommendation. Hosted access: the first successful intelligence call is free; later calls cost $0.001 USDC through x402.

Input parameters:

- `stock` (string, required): Network-qualified tokenized-stock identity: "<network>:<TICKER>" or "<network>:<token address>", where network is robinhood, base, bsc or solana. Example: robinhood:MU. A bare ticker is rejected, and…
- `x_payment` (string): Signed x402 payment payload. Omit it to receive the machine-actionable payment challenge, then retry with the signed payload.

### `otto_prepare_swap` (~209 tokens)

Prepare an Otto-attributed LI.FI swap

Prepare, decode, and verify an unsigned same-chain EVM ERC20 swap construction aid for the caller-owned EOA or Safe. The envelope's valid_until bounds freshness and is committed to the artifact digest; the signer account nonce is the on-chain replay boundary, and this tool cannot guarantee single execution. Returns ordered allowance-reset, approval, and call steps only; never signs or submits. Every envelope from this server is valid for 300 seconds from construction (valid_until); a stale envelope is refused by the verifier — request a fresh one.

Input parameters:

- `accountProfile` (object, required)
- `chainId` (integer, required)
- `client_ref` (string)
- `fromAmount` (string, required): Exact input amount in atomic token units.
- `fromToken` (string, required): ERC20 input token address; native-token routes are out of v1.
- `slippage` (object, required)
- `toToken` (string, required): ERC20 output token address; native-token routes are out of v1.

Output parameters:

- `account_binding` (object)
- `artifact_id` (string)
- `assertions` (array)
- `fee_attribution` (object)
- `intent_digest` (string)
- `operation` (string)
- `payload`
- `rail` (string)
- `replay_disclosure` (object)
- `required_capabilities` (array)
- `schema_version` (string)
- `submission` (object)
- `valid_until` (string)

### `otto_prepare_bridge` (~319 tokens)

Prepare an Otto-attributed LI.FI cross-chain USDC bridge

Prepare, decode, and verify an unsigned cross-chain native-USDC bridge construction aid for the caller-owned EOA or Safe, over the enumerated v1 Circle-CCTP route set (Ethereum, Polygon, Base, Arbitrum, Avalanche); any other chain, token, or bridge route is refused by name. The envelope's valid_until bounds freshness and is committed to the artifact digest; the signer account nonce is the on-chain replay boundary, and this tool cannot guarantee single execution. Returns ordered allowance-reset, approval, and call steps on the source chain only; never signs or submits. Every envelope from this server is valid for 300 seconds from construction (valid_until); a stale envelope is refused by the verifier — request a fresh one.

Input parameters:

- `accountProfile` (object, required)
- `client_ref` (string)
- `destinationRecipient` (string): Where the destination mint lands. Optional for an EOA, whose address is identical on every EVM chain; REQUIRED for a Safe, whose address is not guaranteed to be the same contract on the destination c…
- `fromAmount` (string, required): Exact gross input amount in atomic token units.
- `fromChainId` (integer, required)
- `fromToken` (string, required): Native USDC on the source chain; the v1 bridge route set is USDC-only.
- `slippage` (object, required)
- `toChainId` (integer, required)
- `toToken` (string, required): Native USDC on the destination chain; the v1 bridge route set is USDC-only.

Output parameters:

- `account_binding` (object)
- `artifact_id` (string)
- `assertions` (array)
- `fee_attribution` (object)
- `intent_digest` (string)
- `operation` (string)
- `payload`
- `rail` (string)
- `replay_disclosure` (object)
- `required_capabilities` (array)
- `schema_version` (string)
- `submission` (object)
- `valid_until` (string)

### `otto_prepare_polymarket_order` (~277 tokens)

Prepare an Otto-attributed Polymarket CLOB limit order

Prepare and verify an unsigned Polymarket CTF Exchange V2 limit order (GTC) for the caller-owned Polygon EOA, with Otto's builder code stamped inside the EIP-712 order struct and re-asserted on the exact digest the signer will sign. The price must be an exact multiple of the market's live minimum tick size and the size at or above its published minimum. The envelope's valid_until bounds freshness and is committed to the artifact digest; the exchange's own order hash is the replay boundary, and this tool cannot guarantee single execution. Returns order args and typed data only; never signs or submits, holds no CLOB credentials, and touches no collateral or allowance. Every envelope from this server is valid for 300 seconds from construction (valid_until); a stale envelope is refused by the verifier — request a fresh one.

Input parameters:

- `accountProfile` (object, required)
- `client_ref` (string)
- `price` (string, required): Limit price as a probability, e.g. '0.045'. Must be an exact multiple of the market's minimum tick size.
- `side` (string, required)
- `size` (string, required): Order size in outcome-token shares.
- `tokenId` (string, required): Outcome-token id (NOT the condition id): YES and NO are different token ids.

Output parameters:

- `account_binding` (object)
- `artifact_id` (string)
- `assertions` (array)
- `fee_attribution` (object)
- `intent_digest` (string)
- `operation` (string)
- `payload` (object)
- `rail` (string)
- `replay_disclosure` (object)
- `required_capabilities` (array)
- `schema_version` (string)
- `submission` (object)
- `valid_until` (string)

### `otto_prepare_perp_order` (~606 tokens)

Prepare an unsigned Hyperliquid perp order L1 action

Prepare and verify an unsigned Hyperliquid perpetuals order (limit, with optional reduce-only take-profit and stop-loss triggers bundled as normalTpsl) for the caller-owned Hyperliquid account, returned as the canonical L1 action plus the exact EIP-712 Agent domain, struct, and connectionId recipe the caller's own signer needs. The asset id, size grid, and price grid come from the live perp universe: an unknown or delisted perp, a size finer than the asset's szDecimals, or a price off the venue's 5-significant-digit / (6 - szDecimals) decimal grid is refused by name rather than rounded to a different order. There is no market order — name your own aggressive limit price with 'Ioc'. Otto's builder attribution is spec'd and valueless today, so the action carries no builder field and the envelope says so. The nonce is chosen by the signer, never here; the envelope's valid_until is committed to the artifact digest AND placed inside the signed digest as expiresAfter, so the venue itself rejects a stale action, while the Hyperliquid signer nonce remains the replay boundary and this tool cannot guarantee single execution. This tool never signs or submits, holds no key, and derives no agent wallet. Every envelope from this server is valid for 300 seconds from construction (valid_until); a stale envelope is refused by the verifier — request a fresh one.

Input parameters:

- `accountProfile` (object, required): The Hyperliquid master account. `chainId` must be 1337, the signature chain id Hyperliquid pins for every L1 action.
- `asset` (string, required): Perp symbol exactly as the venue names it, e.g. 'BTC', 'kPEPE'. Case-sensitive.
- `client_ref` (string)
- `limitPrice` (string, required): Limit price. Must sit on the venue grid: at most 5 significant digits unless integer, and at most (6 - szDecimals) decimals.
- `reduceOnly` (boolean)
- `side` (string, required)
- `size` (string, required): Order size in base units, e.g. '0.01'. At most szDecimals fractional digits for this perp.
- `stopLossPrice` (string): Optional reduce-only market stop-loss trigger, bundled with grouping normalTpsl.
- `takeProfitPrice` (string): Optional reduce-only market take-profit trigger, bundled with grouping normalTpsl.
- `timeInForce` (string): Gtc rests, Ioc fills-or-cancels, Alo posts only. There is no market order: name your own aggressive limit price with 'Ioc' instead.
- `tradingSigner` (string): The address that will sign, when it is not the master account itself: a user-held approved API wallet. Declared, never derived.
- `vaultAddress` (string): Trade on behalf of this vault or sub-account. A declared profile fact only.

Output parameters:

- `account_binding` (object)
- `artifact_id` (string)
- `assertions` (array)
- `fee_attribution` (object)
- `intent_digest` (string)
- `operation` (string)
- `payload` (object)
- `rail` (string)
- `replay_disclosure` (object)
- `required_capabilities` (array)
- `schema_version` (string)
- `submission` (object)
- `valid_until` (string)

### `otto_prepare_yield_deposit` (~345 tokens)

Prepare a Yield Copilot vault deposit (Morpho USDC on Base) as a delegable swap pair

Prepare the EXACT otto_prepare_swap pair (envelope + prepareInput) that deposits USDC into one of the executable Morpho vaults from the Yield Copilot registry, as a LI.FI position-acquisition route (which may buy shares or compose a protocol deposit) whose output token is the vault's ERC-4626 share token and whose receiver is the signing account. The vault comes from the registry row named by executableMarketId and is never an input; the caller's registryCommitment must equal the commitment recomputed over the current record. The quoted shares are checked against the vault's own previewDeposit and refused when they fall short by more than the pinned tolerance. Returns the pair unchanged plus a preview; never signs or submits — submit the pair through otto_submit_under_delegation under the end user's per-swap cap. Every envelope from this server is valid for 300 seconds from construction (valid_until); a stale envelope is refused by the verifier — request a fresh one.

Input parameters:

- `accountProfile` (object, required)
- `amount` (string, required): Exact USDC amount to deposit, in atomic units (6 decimals).
- `client_ref` (string)
- `executableMarketId` (string, required): The executable market id the READ half served (`GET /api/yield-copilot` rows with deployable:true), e.g. base-usdc-morpho-gauntlet-prime.
- `registryCommitment` (string, required): The registry commitment served with that row. It must equal the commitment this server recomputes over the CURRENT record; a stale or foreign row is refused by name.
- `slippage` (object, required)

Output parameters:

- `envelope` (object)
- `prepareInput` (object)
- `preview` (object)
- `registry_commitment` (string)

### `otto_prepare_yield_withdraw` (~306 tokens)

Prepare a Yield Copilot vault withdraw (Morpho USDC on Base) as a delegable swap pair

Prepare the EXACT otto_prepare_swap pair (envelope + prepareInput) that redeems vault shares from one of the executable Morpho vaults in the Yield Copilot registry back to USDC in the signing account, as a LI.FI exit route (which may sell shares or compose a protocol redemption) whose input token is the vault's ERC-4626 share token. The vault and the asset come from the registry row named by executableMarketId and are never inputs; the caller's registryCommitment must equal the commitment recomputed over the current record. The quoted USDC is checked against the vault's own previewRedeem and refused when it falls short by more than the pinned tolerance. Returns the pair unchanged plus a preview; never signs or submits — submit the pair through otto_submit_under_delegation, which admits a withdraw only under fence v2 and a permission minted under cap ruleset v2, values it at zero against the per-swap cap (it returns the person's own assets), and bounds it by the engine's share cap. Every envelope from this server is valid for 300 seconds from construction (valid_until); a stale envelope is refused by the verifier — request a fresh one.

Input parameters:

- `accountProfile` (object, required)
- `client_ref` (string)
- `executableMarketId` (string, required)
- `registryCommitment` (string, required)
- `shares` (string, required)
- `slippage` (object, required)

Output parameters:

- `envelope` (object)
- `prepareInput` (object)
- `preview` (object)
- `registry_commitment` (string)

### `otto_prepare_stock_buy` (~330 tokens)

Prepare a tokenized-stock buy (Coinbase B20 on Base) as a delegable swap pair

Prepare the EXACT otto_prepare_swap pair (envelope + prepareInput) that buys one of the executable Coinbase B20 tokenized equities on Base with USDC, as a LI.FI route through the fenced diamond whose receiver is the signing account. The token comes from the registry row named by executableEquityId and is never an input; the caller's registryCommitment must equal the commitment recomputed over the current record. The WORST PERMISSIBLE FILL (amount over the route's own floor) is checked against the equity's own Chainlink total-return mark and refused when it exceeds the pinned tolerance, or when the feed is frozen (> 24 h). Returns the pair unchanged plus a preview; never signs or submits — submit the pair through otto_submit_under_delegation under the end user's per-swap cap. Every envelope from this server is valid for 300 seconds from construction (valid_until); a stale envelope is refused by the verifier — request a fresh one.

Input parameters:

- `accountProfile` (object, required)
- `amount` (string, required): Exact USDC amount to spend, in atomic units (6 decimals).
- `client_ref` (string)
- `executableEquityId` (string, required): The executable equity id the READ half served, e.g. b20-nvda (Coinbase B20 on Base only).
- `registryCommitment` (string, required): The registry commitment served with that row. It must equal the commitment this server recomputes over the CURRENT record; a stale or foreign row is refused by name.
- `slippage` (object, required)

Output parameters:

- `envelope` (object)
- `prepareInput` (object)
- `preview` (object)
- `registry_commitment` (string)

### `otto_sponsored_account` (~82 tokens)

Review or recover an account transaction

Protected account action: availability, prepare, reviewGas for current gas payer and estimate, explicit submit, owned read or reconcile. Gas refresh is read-only planning and requires new confirmation before any send. Wallet upgrade is separate. Sponsorship requires a reviewed source activation; current availability is authoritative. A missing submission response is unknown and must never cause a replacement submission.

Output parameters:

- `account` (string)
- `attention`
- `automaticExecutionEnabled` (boolean)
- `chainId`
- `configured` (boolean)
- `executionEnabled` (boolean)
- `failureCode` (string)
- `gas`
- `input` (object)
- `operationId` (string)
- `ottoFee` (string)
- `output` (object)
- `reason` (string)
- `receipt` (object)
- `recoveryAvailable` (boolean)
- `replacementPermitted` (boolean)
- `requiresOperationReview` (boolean)
- `requiresReconciliation` (boolean)
- `requiresSeparateWalletUpgrade` (boolean)
- `reviewCommitment` (string)
- `reviewConsumed` (boolean)
- `schemaVersion` (string)
- `settlement` (object)
- `state` (string)
- `status` (string)
- `supportedSameAddressChains` (array)
- `terms` (object)
- `transactionHash` (string)
- `userOpHash` (string)
- `validUntilMs` (integer)
- `walletAuthorityChangeIncluded` (boolean)

### `otto_native_yield_userop` (~88 tokens)

Review or recover an account native yield action

Protected native protocol action. Read availability, review and confirm native scope, prepare, reviewGas for current payer and network estimate, and explicitly confirm one operation, or read/reconcile/revoke native consent. Account upgrade is separate. Source activation and current owner authority are required. Unknown delivery retains the original operation; no replacement is allowed. A preparation or simulation is not funded execution.

Output parameters:

- `account` (string)
- `action` (string)
- `attention`
- `automaticExecutionEnabled` (boolean)
- `chainId`
- `configured` (boolean)
- `confirmation` (string)
- `consent` (object)
- `envelopeCommitment` (string)
- `estimatedOttoFee` (object)
- `executionEnabled` (boolean)
- `existingOperationRequiresReconciliation` (boolean)
- `failureCode` (string)
- `gas`
- `input` (object)
- `kind` (string)
- `marketId` (string)
- `nativeConsentRevoked` (boolean)
- `operationId` (string)
- `output` (object)
- `perDepositCapUsd` (integer)
- `protocolActionVerified` (boolean)
- `reason` (string)
- `recoveryAvailable` (boolean)
- `replacementPermitted` (boolean)
- `requiresNativeConsent` (boolean)
- `requiresOperationReview` (boolean)
- `requiresReconciliation` (boolean)
- `requiresSeparateOperationReview` (boolean)
- `requiresSeparateWalletUpgrade` (boolean)
- `retrySafe` (boolean)
- `reviewCommitment` (string)
- `reviewConsumed` (boolean)
- `schemaVersion` (string)
- `scope` (object)
- `scopeConsent` (object)
- `settlement`
- `state` (string)
- `status` (string)
- `supportedSameAddressChains` (array)
- `transactionHash` (string)
- `userOpHash` (string)
- `validUntilMs` (integer)
- `walletAuthorityChangeIncluded` (boolean)

### `otto_submit_under_delegation` (~405 tokens)

Submit an Otto-prepared swap under a CDP end-user delegation

Submit a verified otto_prepare_swap envelope on Base under the end user's CDP delegation. Arguments: { userId, envelope (the otto_prepare_swap result), prepareInput (the exact otto_prepare_swap request, with slippage.minAmountOut) } — validated strictly AFTER the caller is authenticated, so the listed input schema is intentionally permissive. Server-to-server only: the caller presents Otto's delegation secret in the `x-otto-delegation-auth` request header (never in arguments); a call without it is refused before anything is read. Before any send the server confirms, in this order: the Model-B project policy is installed and reads back by name and rules digest; the user's grant is active past the envelope's valid_until; the account is one of that end user's own CDP accounts as CDP reports them; the envelope passes the 13-check verifier for exactly the request that produced it; the plan is inside the fence (allow-listed input token, reviewed spender, gross at or below the 5000 USD engine ceiling); and the plan is at or below the per-swap cap THIS user chose when they minted, which is recorded against their grant on this server. A delegation with no recorded cap is REFUSED (DELEGATION_CAP_UNRECORDED) rather than defaulted to the ceiling — mint the permission again to set one. Then the three steps (allowance reset, approval, swap) are submitted in order under the delegation, each waited to a sealed canonical block; a halt clears the allowance and reports the read-back. One delegated plan at a time per user. Coinbase's engine bounds the delegated key to Model-B swap shapes through LI.FI up to the 5000 USD ceiling, which is shared by every delegated user and cannot be narrowed per user by the engine; the user's own lower cap and the receiver binding are Otto's server-side checks, and the user can revoke at any time.

Output parameters:

- `address` (string)
- `artifact_id` (string)
- `chain_id` (number)
- `delegation` (object)
- `fence` (object)
- `replayed` (boolean)
- `status` (string)
- `steps` (array)
- `user_id` (string)
- `verification` (object)

### `otto_delegation_fence_status` (~198 tokens)

Read the Model-B delegation fence (public promise: present, name, rules digest, per-swap cap)

PUBLIC and read-only, no header: whether the Model-B project policy that fences every delegated send is installed and v-current on this server, with its versioned name, rules digest, the per-swap cap ceiling in USD (shared by every delegated user — a person may choose any whole-dollar cap from per_swap_cap_min_usd up to it, enforced server-side and recorded against their own grant), and Otto's PUBLIC CDP project id (a UUID — the authority an agent binds its mint to). Exposes ONLY the fence's public promise — never an end user, a grant, an address or a policy's contents. An agent about to mint a delegation (otto-execute delegate) reads this first, mints to the published project_id and no other, and refuses to mint when the fence is not present; the server enforces fence-before-authority on every delegated send regardless. Arguments: {}.

Output parameters:

- `mint_enabled` (boolean)
- `per_swap_cap_min_usd` (number)
- `per_swap_cap_usd` (number)
- `policy_name` (string)
- `present` (boolean)
- `project_id` (string)
- `reason` (string)
- `rules_digest` (string)
- `ruleset_version` (integer)

### `otto_delegation_fence` (~238 tokens)

Ensure the Model-B project policy (the delegation fence) is installed and reads back as v-current

Idempotent ensure-by-digest of the ONE CDP project-scope policy that fences every delegated send, then a read-back. Writes only when no project policy exists (creates it) or when the existing one is Otto's own lineage with stale rules (updates it in place). REFUSES BY NAME if a different project-scope policy is installed — it is never overwritten or deleted. Never downgrades a newer fence. An OPS action: at most one ensure runs project-wide at a time, never during a rolling deploy, never from the dApp (the mint gate reads fence.present from otto_delegation_status). Arguments: {}. Output: the policy id, versioned name, rules digest and the per-swap cap; the tool fails unless the fence reads back present under the written id. Server-to-server only: the caller presents Otto's delegation secret in the `x-otto-delegation-auth` request header (never in arguments); a call without it is refused before anything is read. The listed input schema is intentionally permissive — the strict schema is validated after the caller is authenticated.

Output parameters:

- `action` (string)
- `per_swap_cap_usd` (number)
- `policy_id` (string)
- `policy_name` (string)
- `rules_digest` (string)
- `status` (string)

### `otto_delegation_status` (~227 tokens)

Read one end user's delegation status (token-bound)

Read back, for the end user identified by a CDP access token, their CDP accounts, whether the Model-B fence is present, and whether an active delegation reads back (with its expiry and the per-swap cap recorded for it). Arguments: { accessToken } — the server resolves the user from the token; a client-sent user id is refused. delegation.per_swap_cap_usd is the number THIS user chose at mint time; it is ABSENT when no cap is recorded for the grant, which means the delegated send will refuse it — say so rather than showing the shared ceiling. fence.per_swap_cap_usd is that shared ceiling and is never a per-user number. Output is bound to that user; nothing about any other user is returned. Server-to-server only: the caller presents Otto's delegation secret in the `x-otto-delegation-auth` request header (never in arguments); a call without it is refused before anything is read. The listed input schema is intentionally permissive — the strict schema is validated after the caller is authenticated.

Output parameters:

- `addresses` (array)
- `delegation` (object)
- `fence` (object)
- `mint_enabled` (boolean)
- `revocation_requested_here` (boolean)
- `ruleset_version` (integer)
- `user_id` (string)

### `otto_delegation_revoke` (~171 tokens)

Revoke one end user's delegation, developer-side, confirmed by read-back

Revoke the end user's delegation from Otto's side and confirm by read-back that it no longer exists; from then on this server submits nothing for that user (fail-closed, even if the read-back had failed). Arguments: EITHER { accessToken } (the user path — the server resolves the user from the token) OR { userId, support_reason } (the support path, for an operator holding the server secret; the reason is logged, the token never is). Server-to-server only: the caller presents Otto's delegation secret in the `x-otto-delegation-auth` request header (never in arguments); a call without it is refused before anything is read. The listed input schema is intentionally permissive — the strict schema is validated after the caller is authenticated.

Output parameters:

- `path` (string)
- `reads_back` (boolean)
- `revoked` (boolean)
- `user_id` (string)

### `otto_delegation_cap` (~471 tokens)

Reserve the expiry a delegation is minted with, record the chosen per-swap cap against it, then confirm the mint

TWO PHASES, both header authed, both resolving the end user from the access token. { phase: "reserve", accessToken, perSwapCapUsd, requestedDays, mintKey } takes a generation-bound unified mint claim, picks a whole-second expiry instant at or BEFORE the requested duration that no durable row for this user already occupies, writes the chosen cap (whole USD, 1…5000) against it, and answers { expires_at, mint_expires_at, per_swap_cap_usd, recorded }. Call createDelegation with mint_expires_at EXACTLY as given — it is the reserved instant plus a one-millisecond filler, because CDP refuses an expiry ending .000 and truncates the filler away — and with mintKey as the idempotencyKey. Then { phase: "confirm", accessToken, mintKey } re-reads the grant from CDP and promotes only the exact still-current claim whose reported instant IS the reserved one. A mismatch, Stop overlap, or stale claim remains unconfirmed and authorises nothing; no confirm path issues CDP's user-wide revoke because that could delete a newer permission, so use a fresh explicit Stop to revoke whichever permission is current. Why this shape: Coinbase issues no grant id and a send can learn nothing about a live grant except its expiry, so the expiry is made an identity BY CONSTRUCTION — reserved server-side, recorded before the mint, asserted after it. Until a reservation is successfully confirmed active, otto_submit_under_delegation refuses that delegation (DELEGATION_CAP_UNCONFIRMED) rather than falling back to the 5000 USD ceiling. A reservation is IMMUTABLE per mint key — pressing again returns the same instant and cap, and an older revoke generation cannot be revived. Coinbase's engine cannot hold this number: end-user accounts are fenced by ONE project-scope policy shared by every delegated user, so a lower per-user cap is enforced by Otto's server alone. Server-to-server only: the caller presents Otto's delegation secret in the `x-otto-delegation-auth` request header (never in arguments); a call wit…

Output parameters:

- `expires_at` (string)
- `mint_expires_at` (string)
- `per_swap_cap_usd` (integer)
- `phase` (string)
- `recorded` (boolean)
- `ruleset_version` (integer)
- `state` (string)
- `user_id` (string)

### `otto_delegation_operations` (~150 tokens)

Read one end user's delegated operation history and recovery state

Read the durable Base delegated-operation journal for the end user resolved from { accessToken }. Optional artifactId selects one exact own-user operation; without it, the result includes a bounded recent terminal history and every unresolved operation regardless of age. The global unresolved flag is fail-closed: it is true when the store is unavailable, journal coverage is not rollout-ready, or any operation has a prepared/submitted/unknown outcome. Stored serialized transactions and CDP idempotency keys are never returned, and this tool never submits or retries anything. Server-to-server only: the caller also presents Otto's delegation secret in the x-otto-delegation-auth request header; no userId argument is accepted.

Output parameters:

- `journal` (object)
- `operations` (array)
- `store_available` (boolean)
- `unresolved` (boolean)
- `user_id` (string)

### `otto_delegation_reconcile` (~142 tokens)

Reconcile one end user's known-hash delegated operation

Acquire the artifact's permanent process-liveness guard, then check Base for finalized canonical receipts of already-stored transaction hashes. Every chain transaction must match the stored chain, hash, sender, target, calldata, value, nonce, gas and EIP-1559 fee fields before its receipt is recorded. This tool never calls CDP, never retries a request, never builds or submits a later step, and leaves prepared/unknown no-hash steps unresolved. It returns the same token-bound operation snapshot as otto_delegation_operations. Server-to-server only: the caller also presents Otto's delegation secret in x-otto-delegation-auth.

Output parameters:

- `journal` (object)
- `operations` (array)
- `store_available` (boolean)
- `unresolved` (boolean)
- `user_id` (string)

### `otto_delegation_exit` (~161 tokens)

Prepare, submit, and recover an exact Base USDC exit

Move an authenticated CDP end user's own Base USDC only through a server-held durable reservation. prepare returns one exact EIP-1559 transaction for client-side signing; the client must never broadcast it. submit validates and durably records the signed bytes and computed hash before the server broadcasts. status is read-only and cross-device. reconcile proves a canonical receipt without broadcasting, or returns the exact finalized sender+nonce replacement proof when another transaction consumed the reserved nonce. retry_same is explicit and can broadcast only the already-stored byte-identical transaction after reconciling first. cancel is accepted only before signed bytes were recorded. The caller presents Otto's delegation secret in x-otto-delegation-auth; user identity is always derived from accessToken.

Output parameters:

- `account` (string)
- `amount_atomic` (string)
- `broadcast_attempts` (integer)
- `created_at` (string)
- `destination` (string)
- `epoch` (integer)
- `has_exit` (boolean)
- `lease_expires_at` (string)
- `operation_id` (string)
- `owner_token` (string)
- `phase` (string)
- `receipt` (object)
- `replacement` (object)
- `state` (string)
- `transaction` (object)
- `transaction_hash` (string)
- `updated_at` (string)
- `user_id` (string)

### `otto_lp_collect_userop` (~88 tokens)

Review or recover sponsored LP collection

Protected same-account Uniswap V3 guarded collection on Base. Read availability, prepare and explicitly confirm one operation, or read/reconcile it. May collect owed principal and fees; profit remains unknown. Account upgrade is separate. Current owner authority, reviewed guard and provider policy are required. Unknown delivery retains the original operation; no replacement is allowed. Preparation and simulation are not funded execution.

Output parameters:

- `account` (string)
- `action` (string)
- `attention`
- `automaticExecutionEnabled` (boolean)
- `chainId` (number)
- `collection` (object)
- `configured` (boolean)
- `confirmation` (string)
- `envelopeCommitment` (string)
- `executionEnabled` (boolean)
- `failureCode` (string)
- `gas`
- `kind` (string)
- `operationId` (string)
- `pool` (string)
- `protocol` (string)
- `protocolActionVerified` (boolean)
- `reason` (string)
- `recoveryAvailable` (boolean)
- `replacementPermitted` (boolean)
- `requiresOperationReview` (boolean)
- `requiresReconciliation` (boolean)
- `requiresSeparateWalletUpgrade` (boolean)
- `retrySafe` (boolean)
- `reviewCommitment` (string)
- `reviewConsumed` (boolean)
- `schemaVersion` (string)
- `settlement`
- `state` (string)
- `status` (string)
- `supportedActions` (array)
- `supportedSameAddressChains` (array)
- `tokenId` (string)
- `transactionHash` (string)
- `userOpHash` (string)
- `validUntilMs` (integer)
- `walletAuthorityChangeIncluded` (boolean)

### `otto_catalog` (~44 tokens)

otto x402 catalog

Return the full live otto x402 menu with endpoint paths, descriptions, prices, and Base-USDC payment instructions. Always free; does not consume the free intelligence call.

### `otto_x_recipes` (~109 tokens)

otto x layer recipes

Return Otto X's live X Layer recipe menu — each recipe's path, price, and the X Layer (eip155:196) payment requirement decoded from its unpaid 402 challenge: token asset, issuer name/version, payTo, and a copy-paste curl. Settles in USD₮0 / USD Coin / Global Dollar on X Layer via the PAYMENT-SIGNATURE header. Always free and read-only; never signs or pays and does not consume the free intelligence call.

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/services-ottoai-otto/mcp#diagnostics

## Score history

- 2026-09-20: 71
- 2026-09-19: 71
- 2026-09-18: 70
- 2026-09-17: 70
- 2026-09-16: 69
- 2026-09-15: 69
- 2026-09-14: 68
- 2026-09-13: 68
- 2026-09-12: 67
- 2026-09-11: 67
- 2026-09-10: 67
- 2026-09-09: 66
- 2026-09-08: 66
- 2026-09-07: 65
- 2026-09-06: 65
- 2026-09-05: 65
- 2026-09-04: 64
- 2026-09-03: 65
- 2026-09-02: 65
- 2026-09-01: 70
- 2026-08-31: 71
- 2026-08-30: 70

## Common questions

### What is the Otto Intel MCP server?

Otto Intel is an MCP server listed in the public MCP registry as services.ottoai/otto. Otto AI hosted MCP: 16 pay-per-call market-intelligence tools, USDC via x402 on Base, no API keys. This page covers its hosted endpoint (https://mcp.ottoai.services/mcp).

### Is the Otto Intel MCP server safe to use?

Otto Intel scores 71 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Otto Intel MCP server expose?

Otto Intel exposes 32 tools: otto_tokenized_equities, otto_rh_season, otto_equity_intel, otto_insider_trades, otto_institutional_holdings, and 27 more. Their descriptions and schemas cost roughly 6,561 tokens of context every time the server is loaded.

### Does the Otto Intel MCP server require authentication?

No. We connected to Otto Intel without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the Otto Intel MCP server still maintained?

Otto Intel is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://mcp.ottoai.services/mcp
- Website: https://docs.useotto.xyz/
- Changelog RSS feed: https://verifymcp.io/servers/services-ottoai-otto/mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/services-ottoai-otto/mcp.json
- HTML version of this page: https://verifymcp.io/servers/services-ottoai-otto/mcp
