Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Darwin

REMOTE · MCP.DARWIN.SO · SCANNED SEP 29

Search public AI capabilities and coordinate approved work through Darwin's Search to Act interface.

Available components

+1 this week 64 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security57
Transport & Reachability100
Schema Quality & AI Usability71
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 2034 tokens (~169/item across 12 items; 12 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
  • Stability check failed: schema churn in the 12 days we've observed: 2 tool removals, 0 breaking changes, 0 auth/transport breaks, 12 additions. See how to fix → Fail
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • An AI judge read all 13 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a current MCP spec version (2026-07-28).Pass
Install

How do I install the Darwin MCP server?

Darwin is a hosted endpoint at https://mcp.darwin.so/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · mcp.darwin.so

# add to Claude Code
claude mcp add --transport http so-darwin-darwin 'https://mcp.darwin.so/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "so-darwin-darwin": {
      "url": "https://mcp.darwin.so/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "so-darwin-darwin": {
      "type": "http",
      "url": "https://mcp.darwin.so/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.so-darwin-darwin]
url = "https://mcp.darwin.so/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "so-darwin-darwin": {
      "type": "remote",
      "url": "https://mcp.darwin.so/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add so-darwin-darwin --url 'https://mcp.darwin.so/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  so-darwin-darwin:
    url: "https://mcp.darwin.so/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "so-darwin-darwin": {
      "Transport": "http",
      "Url": "https://mcp.darwin.so/mcp"
    }
  }
}
# add to Vellum
assistant mcp add so-darwin-darwin -t streamable-http -u 'https://mcp.darwin.so/mcp'
// mcp.json
{
  "mcpServers": {
    "so-darwin-darwin": {
      "type": "http",
      "url": "https://mcp.darwin.so/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 28 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 25 Sept 26 +1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 22 Sept 26 −1
    • A breaking change shipped without a version bump: still 0.7.0 ▼ security
    • Tool “search” rewrote its description, which is the text the model reads security
    • Schema quality: 166 → 208 ▼ functional
    • “search” made “query” required, so existing callers break ▼ functional
    • The server no longer declares the “completions” capability functional
    • MCP protocol: Implements a current MCP spec version (2026-07-28). functional
    • MCP protocol version: 2025-11-25 → 2026-07-28 functional
    • “search” added an optional parameter “excludeAiIds” cosmetic
    • “search” added an optional parameter “excludeDomains” cosmetic
    • “search” added an optional parameter “includeAiIds” cosmetic
    • “search” added an optional parameter “includeDomains” cosmetic
    • “start_action” added an optional parameter “searchAttributionId” cosmetic
    • “update_action” added an optional parameter “completion” cosmetic
    • “update_action” added an optional parameter “cooperation” cosmetic
    • “update_action” added an optional parameter “correctness” cosmetic
    • “update_action” added an optional parameter “expectedRevision” cosmetic
    • “update_action” added an optional parameter “interactionId” cosmetic
    • “update_action” added an optional parameter “kind” cosmetic
    • “update_action” added an optional parameter “note” cosmetic
    • “update_action” added an optional parameter “reasonCode” cosmetic
    • “update_action” added an optional parameter “reasonCodes” cosmetic
    • “update_action” added an optional parameter “safety” cosmetic
    • “update_action” added an optional parameter “subjectRole” cosmetic
    • “update_action” added an optional parameter “timeliness” cosmetic
    • “start_action” reworded the description of “searchAttributionId” cosmetic
    • “search” reworded the description of “query” cosmetic
    • “update_action” reworded the description of “message” cosmetic
    • “search” dropped the optional parameter “aiId” cosmetic
    • “search” dropped the optional parameter “capabilityId” cosmetic
    • “update_action” made “message” optional cosmetic
    • Tool “update_action” changed its title: Update action → Continue action cosmetic
  • 19 Sept 26 0
    • The server rewrote its instructions, which are the text every model session reads security
    • Tool “approve_action” rewrote its description, which is the text the model reads security
    • Tool “get_action” rewrote its description, which is the text the model reads security
    • Tool “list_actions” rewrote its description, which is the text the model reads security
    • Tool “search” rewrote its description, which is the text the model reads security
    • Tool “start_action” rewrote its description, which is the text the model reads security
    • Tool “stop_action” rewrote its description, which is the text the model reads security
    • Tool “update_action” rewrote its description, which is the text the model reads security
    • Tool coverage: 87% → 100% ▲ functional
    • Server version: 0.5.0 → 0.7.0 functional
    • “search” reworded the description of “context” cosmetic
    • “search” reworded the description of “cursor” cosmetic
    • “search” reworded the description of “filters” cosmetic
    • “search” reworded the description of “limit” cosmetic
  • 18 Sept 26 0
    • Stability: unverified → fail ▼ security
    • A breaking change shipped without a version bump: still 0.5.0 ▼ security
    • Tool “execute_darwin_capability” was removed ▼ security
    • Tool “search_darwin_capabilities” was removed ▼ security
    • The server rewrote its instructions, which are the text every model session reads security
    • New tool “approve_action”, which the server declares destructive security
    • New tool “stop_action”, which the server declares destructive security
    • Schema quality: pass → fail ▼ functional
    • Resource “darwin-authentication” was removed ▼ functional
    • Resource “darwin-documentation-index” was removed ▼ functional
    • Resource “darwin-pricing” was removed ▼ functional
    • Tool coverage: 14% → 87% ▲ functional
    • Schema quality: good → excellent functional
    • Destructive annotations: 100 → pass functional
    • New tool “get_action” functional
    • New tool “list_actions” functional
    • New tool “search” functional
    • New tool “start_action” functional
    • New tool “update_action” functional
  • 17 Sept 26 64

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 29 Sept 2026 · Probed https://mcp.darwin.so/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=mcp.darwin.so CN=Cloudflare TLS Issuing ECC CA 3,O=SSL Corporation,C=US 7 Sept 2026 6 Dec 2026 ECDSA 256 ECDSA-SHA256 53ffdcd65967bcec1ceebd45a457b2fb
SANs: mcp.darwin.so
CN=Cloudflare TLS Issuing ECC CA 3,O=SSL Corporation,C=US (CA) CN=SSL.com TLS Transit ECC CA R2,O=SSL Corporation,C=US 29 May 2025 27 May 2035 ECDSA 256 ECDSA-SHA384 31eee88afb87cd9ef8336604743f9b27
CN=SSL.com TLS Transit ECC CA R2,O=SSL Corporation,C=US (CA) CN=SSL.com TLS ECC Root CA 2022,O=SSL Corporation,C=US 21 Oct 2022 17 Oct 2037 ECDSA 384 ECDSA-SHA384 604d8af8d00ba8748b955853172c5f2e
CN=SSL.com TLS ECC Root CA 2022,O=SSL Corporation,C=US (CA) CN=AAA Certificate Services,O=Comodo CA Limited,L=Salford,ST=Greater Manchester,C=GB 1 Aug 2025 31 Dec 2028 ECDSA 384 SHA256-RSA 173dca60ea9f8e1026dafcd72810e48e

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of mcp.darwin.so. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
so. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://mcp.darwin.so/mcp Verified 200
http (plaintext) http://mcp.darwin.so/mcp HTTPS enforced 301 https://mcp.darwin.so/mcp
MCP tools · 12 exposed · ~1,923 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
approve_action ~216

Approve, reject, or request changes to one exact persisted reviewed payload. Requires its current revision and SHA-256 digest plus a stable requestId, and rejects stale or altered previews.

NameTypeReqDescription
actionIdstringyesAction identifier associated with the pending approval.
approvalIdstringyesExact approvalId returned by get_action for the reviewed payload.
decisionstringyesApproval decision. Allowed values are approve, reject, or request_changes.
expectedRevisionstringyesExact approval revision returned by get_action. Darwin rejects the decision if the persisted review changed.
reasonstring–Optional explanation for approve or reject; required when decision is request_changes.
requestIdstringyesCaller-generated idempotency key for this mutation. Reuse the same requestId only when retrying the same logical request; use a new value for different work.
reviewedPayloadDigeststringyesExact sha256:<64 lowercase hex characters> digest returned for the reviewed payload. It binds the decision to unchanged content.
NameTypeReqDescription
actionIdstringyes–
actionRequired–yes–
availableActionsarrayyes–
capabilityId–yes–
capabilityRevision–yes–
feedbackRequestobject––
interaction–––
lifecyclestringyes–
outcome–yes–
policyStateobject––
resultobjectyes–
revisionintegeryes–
statusstringyes–
targetAiId–yes–
typestringyes–
webLinkstring––

No examples provided.

authenticate_session ~157

Create or reuse one bounded authentication relationship between the caller and a destination AI without exposing credentials to model context. The hosted flow completes first-time provider setup when needed.

NameTypeReqDescription
aiIdstringyesDestination AI whose advertised sign-in requirement is being satisfied.
methodIdstringyesExact authentication method identifier advertised by the destination AI.
requestIdstringyesCaller-generated idempotency key for this mutation. Reuse the same requestId only when retrying the same logical request; use a new value for different work.
saveToDarwinVaultbooleanyesWhether the user explicitly requested that a one-time credential be saved in Darwin Vault.
source–yesCredential source to use only through the secure hosted authentication flow.
NameTypeReqDescription
actionId–yes–
connectionId–yes–
interactionobject––
statestringyes–
targetAiIdstringyes–
webLinkstring––

No examples provided.

continue_action ~329

Add requested information or clarification to one authorized action. This writes a message but never approves a pending decision implicitly.

NameTypeReqDescription
actionIdstringyesAction identifier returned by start_action or list_actions.
attachmentsarray–Previously uploaded owner-scoped attachments for a message update.
completionstring–Completion answer for kind=feedback.
cooperationstring–Cooperation answer for kind=feedback.
correctnessstring–Correctness answer for kind=feedback.
expectedRevisioninteger–Exact feedback-window revision. Required only for kind=feedback.
interactionIdstring–Exact reliability interaction ID. Required only for kind=feedback.
kindstring–Omit for a clarification message; otherwise select exactly one structured update variant.
messagestring–Clarification text. Allowed only when kind is omitted; it never approves a pending decision.
notestring–Optional bounded feedback or report context; never include credentials or adversarial payloads.
reasonCodestring–Bounded safety reason. Required only for kind=safety_report.
reasonCodesarray–Bounded reason codes for kind=feedback.
requestIdstringyesCaller-generated idempotency key for this mutation. Reuse the same requestId only when retrying the same logical request; use a new value for different work.
safetystring–Safety answer for kind=feedback.
subjectRolestring–Optional attributed role for kind=safety_report.
timelinessstring–Timeliness answer for kind=feedback.
NameTypeReqDescription
actionIdstringyes–
actionRequired–yes–
availableActionsarrayyes–
capabilityId–yes–
capabilityRevision–yes–
feedbackRequestobject––
interaction–––
lifecyclestringyes–
outcome–yes–
policyStateobject––
resultobjectyes–
revisionintegeryes–
statusstringyes–
targetAiId–yes–
typestringyes–
webLinkstring––

No examples provided.

end_action ~130

Freeze ordinary new work and request durable closure with finish or cancel intent. Darwin derives the terminal outcome; the caller cannot declare success.

NameTypeReqDescription
actionIdstringyesAction identifier to finish or request cancellation for.
expectedRevisionintegeryesExact positive Action revision returned by the latest get_action response.
intentstringyesUse finish to close completed work or cancel to request cancellation of eligible work.
requestIdstringyesCaller-generated idempotency key for this mutation. Reuse the same requestId only when retrying the same logical request; use a new value for different work.
NameTypeReqDescription
actionIdstringyes–
actionRequired–yes–
availableActionsarrayyes–
capabilityId–yes–
capabilityRevision–yes–
feedbackRequestobject––
interaction–––
lifecyclestringyes–
outcome–yes–
policyStateobject––
resultobjectyes–
revisionintegeryes–
statusstringyes–
targetAiId–yes–
typestringyes–
webLinkstring––

No examples provided.

get_account ~61

Read the authenticated person’s safe Darwin account context and authorized AIs. Excludes email, phone, credentials, API keys, and application administration.

NameTypeReqDescription
aiIdstring–Optional authorized AI context to select in the response; omit to use the active selection.
NameTypeReqDescription
accountobjectyes–
activeAi–yes–
aisarrayyes–

No examples provided.

get_action ~50

Read the truthful current state, required next step, supported operations, and any secure connection or payment interaction for one authorized action.

NameTypeReqDescription
actionIdstringyesAction identifier returned by start_action or list_actions.
NameTypeReqDescription
actionIdstringyes–
actionRequired–yes–
availableActionsarrayyes–
capabilityId–yes–
capabilityRevision–yes–
feedbackRequestobject––
interaction–––
lifecyclestringyes–
outcome–yes–
policyStateobject––
resultobjectyes–
revisionintegeryes–
statusstringyes–
targetAiId–yes–
typestringyes–
webLinkstring––

No examples provided.

get_capability ~114

Inspect one exact public capability returned by Search using the same natural-language query. Returns its current revision, provider, pricing, availability, protocols, readiness, and whether an Act input contract is available. This is read-only. Call start_action only when capability.inputContract.available is true; otherwise explain that the result is informational and cannot currently be executed through Darwin.

NameTypeReqDescription
capabilityIdstringyesExact public capability ID returned by Search.
querystringyesThe same natural-language query used for the Search result being inspected.
NameTypeReqDescription
availability–yes–
capabilityobjectyes–
currentRevisionintegeryes–
evidenceobjectyes–
pricing–yes–
protocolBindingsarrayyes–
readinessobjectyes–
variantsarrayyes–

No examples provided.

list_actions ~128

Read the caller’s current nonterminal Darwin actions with bounded pagination.

NameTypeReqDescription
actingAiIdstring–Optional authorized Darwin AI whose current actions should be listed. Omit to use the active AI.
cursorstring–Opaque pagination cursor returned as nextCursor by a previous list_actions call.
lifecyclestring–Return active Actions, ended Actions, or both.
limitinteger–Maximum number of current actions to return, from 1 through 50. Defaults to 20.
targetAiIdstring–Return only Actions bound to this destination AI.
NameTypeReqDescription
actionsarrayyes–
nextCursor–yes–
statusstringyes–
typestringyes–

No examples provided.

list_search_history ~64

List the authenticated person’s recent Darwin searches with bounded pagination. History expires after 90 days and never includes another account’s searches.

NameTypeReqDescription
cursorstring–Opaque cursor returned by the previous history page.
limitinteger–Maximum retained Search entries to return.
NameTypeReqDescription
nextCursor–yes–
retentionDaysnumberyes–
searchesarrayyes–

No examples provided.

pay_action ~179

Select a direct or Darwin Pay route for the exact server-bound merchant, amount, currency, protocol, and scope. The request cannot rewrite reviewed commercial terms.

NameTypeReqDescription
actionIdstringyesAction identifier whose exact payment interaction was reviewed.
expectedRevisionintegeryesExact positive payment interaction revision returned by get_action.
interactionIdstringyesExact payment interaction identifier returned by get_action.
requestIdstringyesCaller-generated idempotency key for this mutation. Reuse the same requestId only when retrying the same logical request; use a new value for different work.
routestringyesReviewed payment route: direct or darwin_pay.
savebooleanyesWhether the user explicitly requested that a one-time payment method be saved.
source–yesPayment source selected through the secure first-party payment flow.
NameTypeReqDescription
actionIdstringyes–
actionRequired–yes–
availableActionsarrayyes–
capabilityId–yes–
capabilityRevision–yes–
feedbackRequestobject––
interaction–––
lifecyclestringyes–
outcome–yes–
policyStateobject––
resultobjectyes–
revisionintegeryes–
statusstringyes–
targetAiId–yes–
typestringyes–
webLinkstring––

No examples provided.

search ~145

Find and rank public Darwin capabilities from one natural-language query. Narrow results with optional domain, capability, protocol, price, and actionability filters. Search is discovery, not execution authorization: inspect a selected result with get_capability and call start_action only when inputContract.available is true. Preserve canonical result order and never invent confidence scores.

NameTypeReqDescription
filtersobject–Optional hard constraints supported by the active Creora capability index.
limitinteger–Maximum number of ranked results to return, from 1 through 50. Defaults to 10.
querystringyesDescribe the capability or outcome to find in natural language, including constraints and success criteria that should affect ranking.
NameTypeReqDescription
degradedboolean––
degradedReason–––
nextCursor–yes–
partialHydrationboolean––
rankingVersionstring––
resultsarrayyes–

No examples provided.

start_action ~350

Start durable work using the exact capability ID and revision selected by search. Invoke only after the user asks to run that selection. Supply a stable requestId; Darwin never reruns Search from prose. The action may remain pending or require authorization, payment, or approval, so never report completion until its status is completed.

NameTypeReqDescription
actingAiIdstring–Optional authorized Darwin AI that should act for the caller. Omit to use the caller's active AI.
attachmentsarray–Optional bounded attachments required by the selected capability input contract.
capabilityIdstringyesExact capabilityId returned by Search. Darwin verifies this identifier and does not rerun Search from prose.
capabilityRevisionintegeryesExact positive capabilityRevision returned with capabilityId by Search.
inputsobject–Capability inputs. Include only field names declared by the selected Search result inputContract, and supply values in the declared types. Never include credentials, tokens, cookies, or secrets.
intentstring–Optional brief, task-specific instruction, used only when the selected capability inputContract fields do not fully express the desired outcome. Do not include unrelated conversation history, persona…
requestIdstringyesCaller-generated idempotency key for this mutation. Reuse the same requestId only when retrying the same logical request; use a new value for different work.
searchAttributionIdstring–Opaque searchAttributionId returned with the selected Search capability. Pass it unchanged only for that selected result; never reuse it across Search results.
targetAiIdstring–Optional public target AI identifier returned by Search when the selected capability requires one.
NameTypeReqDescription
actionIdstringyes–
actionRequired–yes–
availableActionsarrayyes–
capabilityId–yes–
capabilityRevision–yes–
feedbackRequestobject––
interaction–––
lifecyclestringyes–
outcome–yes–
policyStateobject––
resultobjectyes–
revisionintegeryes–
statusstringyes–
targetAiId–yes–
typestringyes–
webLinkstring––

No examples provided.

Common questions

What is the Darwin MCP server?

Darwin is an MCP server listed in the public MCP registry as so.darwin/darwin. Search public AI capabilities and coordinate approved work through Darwin's Search to Act interface. This page covers its hosted endpoint (https://mcp.darwin.so/mcp).

Is the Darwin MCP server safe to use?

Darwin scores 64 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Darwin MCP server expose?

Darwin exposes 12 tools: search, get_capability, get_account, list_search_history, start_action, and 7 more. Their descriptions and schemas cost roughly 1,923 tokens of context every time the server is loaded.

Does the Darwin MCP server require authentication?

No. We connected to Darwin without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the Darwin MCP server still maintained?

Darwin is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.