Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

io.github.Travisswop/swop

REMOTE · MCP.SWOPME.CO · SCANNED OCT 8

Sell to people and AI agents: create products, a storefront, and USDC payment links from chat.

Available components

+3 this week 70 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security63
Transport & Reachability100
Schema Quality & AI Usability74
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 3911 tokens (~144/item across 27 items; 27 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management23
  • Stability observed for 7 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 4 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • An AI judge read all 28 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

How do I install the io.github.Travisswop/swop MCP server?

io.github.Travisswop/swop is a hosted endpoint at https://mcp.swopme.co/mcp/commerce, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · mcp.swopme.co

# add to Claude Code
claude mcp add --transport http travisswop-swop 'https://mcp.swopme.co/mcp/commerce'
// .cursor/mcp.json
{
  "mcpServers": {
    "travisswop-swop": {
      "url": "https://mcp.swopme.co/mcp/commerce"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "travisswop-swop": {
      "type": "http",
      "url": "https://mcp.swopme.co/mcp/commerce"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.travisswop-swop]
url = "https://mcp.swopme.co/mcp/commerce"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "travisswop-swop": {
      "type": "remote",
      "url": "https://mcp.swopme.co/mcp/commerce",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add travisswop-swop --url 'https://mcp.swopme.co/mcp/commerce' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  travisswop-swop:
    url: "https://mcp.swopme.co/mcp/commerce"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "travisswop-swop": {
      "Transport": "http",
      "Url": "https://mcp.swopme.co/mcp/commerce"
    }
  }
}
# add to Vellum
assistant mcp add travisswop-swop -t streamable-http -u 'https://mcp.swopme.co/mcp/commerce'
// mcp.json
{
  "mcpServers": {
    "travisswop-swop": {
      "type": "http",
      "url": "https://mcp.swopme.co/mcp/commerce"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 8 Oct 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 17 to 23. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.

  • 6 Oct 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 10 to 17. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 5 at this one. The score rises as the window fills, whether or not the server changes.

  • 4 Oct 26 0
    • New tool “swop_get_help” functional
  • 3 Oct 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.

  • 2 Oct 26 0
    • Tool “swop_create_checkout” rewrote its description, which is the text the model reads security
    • Tool “swop_create_product” rewrote its description, which is the text the model reads security
    • Tool “swop_feature_product” rewrote its description, which is the text the model reads security
    • Tool “swop_get_my_balances” rewrote its description, which is the text the model reads security
    • Tool “swop_get_store” rewrote its description, which is the text the model reads security
    • Tool “swop_list_my_products” rewrote its description, which is the text the model reads security
    • Tool “swop_list_my_tokens” rewrote its description, which is the text the model reads security
    • Stability: unverified → 0.03 ▲ functional
    • Server version: 0.2.1 → 0.2.2 functional
  • 1 Oct 26 67

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 8 Oct 2026 · Probed https://mcp.swopme.co/mcp/commerce

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=mcp.swopme.co CN=YR2,O=Let's Encrypt,C=US 28 Aug 2026 26 Nov 2026 RSA 2048 SHA256-RSA 65c3aa643ef137fb797eab4bb3586491f12
SANs: mcp.swopme.co
CN=YR2,O=Let's Encrypt,C=US (CA) CN=Root YR,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 RSA 2048 SHA256-RSA 4ebd24947e24d394802d84a52fd5b319
CN=Root YR,O=ISRG,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 RSA 4096 SHA256-RSA f24b6d17f9d9ad7cb1c9fea78782699f

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of mcp.swopme.co. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
co. present 7786 8 Verified
swopme.co. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200
Header Value
strict-transport-security max-age=63072000

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://mcp.swopme.co/mcp/commerce Verified 200
http (plaintext) http://mcp.swopme.co/mcp/commerce HTTPS enforced 308 https://mcp.swopme.co/mcp/commerce
MCP tools · 27 exposed · ~3,830 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
swop_add_link ~291

Add a link to the linked account's SmartSite, with smart placement. TWO STEPS: (1) call with just the url — the tool detects what kind of link it is (payment like Venmo/PayPal/Cash App, social, contact, website) and returns a recommendation with a text preview of each layout: a small ICON in the icon row, a link BUTTON tile, or a full-width INFOBAR call-to-action card. Show the user the message + previews and ask which they want. (2) call again with the same url plus displayAs = 'icon' | 'button' | 'infobar' to place it. You can override title / buttonName / description / style ('solid' | 'glass') for an info bar. Returns a viewUrl to preview the result.

NameTypeReqDescription
buttonNamestring–Info-bar button text (e.g. "Pay", "Book")
descriptionstring–Info-bar description line
displayAsstring–Omit first to get a placement suggestion; then set to place it
smartsiteIdstring–Specific SmartSite id (default: primary)
stylestring–Info-bar card style (default solid)
titlestring–Override the label/title
urlstringyesThe link to add (any URL, or mailto:/tel:)

No output schema declared.

No examples provided.

swop_create_checkout ~409

Take payment on the seller's own website: creates a checkout for a cart of the linked account's OWN products, so a buyer pays there instead of being sent to Swop. For a single shareable link use swop_get_product_link instead. Prices come from the seller's catalogue and must NOT be sent — a price in the request is rejected. Shipping is charged automatically for physical products, and for those the buyer's name, email and delivery address are REQUIRED (the call is refused otherwise, naming what is missing). Rails: USDC on Solana always; set offerCard when the seller is card-enabled and every item is a physical good — then the response has cardOffered: true and paymentRequest is null until the buyer picks a rail on the seller's page via the public URLs POST /api/v5/checkout-intents/{intentId}/card-payment-intents (Stripe client secret for a Payment Element) or POST .../select-crypto (publishes the Solana Pay request). Otherwise paymentRequest is returned at once (a solana: URL the buyer's wallet opens, also fine as a QR code). Settlement is automatic once the payment lands — nothing to confirm; poll swop_get_checkout for status. Show the buyer the products, quantities and total before creating.

NameTypeReqDescription
buyerEmailstring–Buyer's email, for the receipt (required for physical items)
buyerNamestring–Buyer's name (required for physical items)
buyerPhonestring–Buyer's phone, for the courier
descriptionstring–What this checkout is for
itemsarrayyesThe cart. Ids only — prices come from the catalogue
offerCardboolean–Offer card as well as USDC. Only takes effect when the seller is card-enabled and every item is physical; otherwise the checkout is USDC-only
shippingAddressobject–Delivery address. Required when any item is a physical product

No output schema declared.

No examples provided.

swop_create_feed_post ~329

Publish a PUBLIC post to the Swop feed as the linked account's SmartSite: a caption plus up to 4 images. Each image may be an https URL, a data:image/...;base64 URI, or bare base64 (PNG/JPEG/GIF/WebP, max 5 MB; keep inline images under ~3 MB total so the request fits). TWO-STEP like swop_send: call WITHOUT confirm to get a preview — Swop hosts the images and returns who it posts as, the exact caption, the hosted image URLs and a previewId. Show the user that exact caption and every image and get an explicit yes. Then call again with the SAME caption and smartsiteId, the `images` array exactly as the preview returned it, the previewId, and confirm: true. Any change after the preview is refused — preview again. Each preview publishes at most once: re-confirming it returns the same post (duplicate: true). Never confirm before the user has seen the preview.

NameTypeReqDescription
captionstring–Post text. Hashtags and @handle.swop.id mentions work as in the app
confirmboolean–true ONLY after the user explicitly approved the preview
imagesarray–Images: https URLs, data:image/...;base64 URIs, or base64. On confirm, pass the hosted URLs from the preview
previewIdstring–From the preview step
smartsiteIdstring–Post as this SmartSite (default: primary). Ids from swop_get_my_profile

No output schema declared.

No examples provided.

swop_create_product ~339

Start selling something in one call: creates a product that people can buy on the linked account's Swop SmartSite and AI agents can buy in USDC over x402, with no store setup, payment processor, or verification needed. To change an existing product use swop_update_product instead. name, description and image are all REQUIRED by the backend. Confirm name and price with the user before creating. Then call swop_feature_product to show it on the SmartSite and swop_get_product_link to share it.

NameTypeReqDescription
descriptionstringyesProduct description (required)
digitalDeliveryNotestring–Digital goods: what the buyer receives after purchase
extraImagesarray–Additional image URLs, shown after the primary one
imagestringyesPrimary product image URL (required)
keywordsarray–Search keywords
mintLimitinteger–Inventory available, default 1
namestringyesProduct name
nftTypestring–Fine-grained type; overrides productType. phygital/menu are physical, the rest digital
priceUsdnumberyesPrice in USD (settles in USDC)
productTypestring–physical (ships), digital (default), or in_person_checkout
requiresShippingboolean–Physical goods: collect a shipping address
royaltyPercentagenumber–Resale royalty percent
royaltyRecipientstring–Wallet receiving royalties
shippingCostnumber–Flat shipping cost in USD
variantsarray–Buyer-selectable options. Replaces the existing set when given.

No output schema declared.

No examples provided.

swop_feature_product ~143

Show an existing product on the linked account's SmartSite as a tile visitors can buy from. Pass the templateId returned by swop_create_product (or the id from swop_list_my_products). Each call ADDS a new tile and never replaces existing ones, so check swop_get_my_smartsite first to avoid duplicates; remove a tile with swop_remove_link. The product must belong to the linked account.

NameTypeReqDescription
carouselTitlestring–Optional heading for the product section
smartsiteIdstring–Specific SmartSite id (default: primary)
templateIdstringyesThe product/template id from swop_create_product

No output schema declared.

No examples provided.

swop_get_checkout ~111

Read back a checkout created with swop_create_checkout: its status (active, pending_payment, paid, settled, expired, cancelled), the payment request if one is published, and the line items. Poll this after the buyer has been shown the payment to learn when it lands — paid means the buyer's money arrived; settled means the seller has been paid out. Only the linked account's own checkouts are visible.

NameTypeReqDescription
intentIdstringyesThe intentId returned by swop_create_checkout

No output schema declared.

No examples provided.

swop_get_help ~112

Look up Swop's own how-to answers on payment previews, funded claim links, Goldman AI credits, companion pairing and saved context. Use it when the user asks how a Swop feature works; for their own data use the swop_get_my_* tools instead. Returns the closest curated answer, or says the topic is not covered.

NameTypeReqDescription
querystringyesThe question in plain words, e.g. "how do claim links work" or "what are Goldman credits". Max 240 characters.

No output schema declared.

No examples provided.

swop_get_my_balances ~49

Current wallet balance snapshot for the linked Swop account (total USD and per-asset breakdown). For tokens or merchant Bucks the account has launched, use swop_list_my_tokens instead.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

swop_get_my_orders ~44

Recent marketplace orders for the linked Swop account, both sides: sales of your products and your purchases. Shows payment, escrow/settlement, and fulfillment status.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

swop_get_my_profile ~65

The linked user's own Swop account: name, email, and SmartSites (handle, bio). Use swop_lookup_identity or swop_search_identities for anyone else's profile. If no Swop account is connected, the call fails asking the user to connect it.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

swop_get_my_smartsite ~99

Get the linked account's current SmartSite so you can see it BEFORE editing: name, bio, appearance (background/theme), the links already on it (icons, buttons, info bars, with their item ids for removal), product tiles, and a viewUrl to preview it. ALWAYS call this before adding or changing things so edits stay additive.

NameTypeReqDescription
smartsiteIdstring–Specific SmartSite id (default: primary)

No output schema declared.

No examples provided.

swop_get_product_link ~102

Get one link that sells to everyone: a person who opens it sees a product page with a Buy button, and an AI agent that requests it gets an x402 USDC payment challenge. Use this to share a product in chat, a social post, or a message.

NameTypeReqDescription
handlestringyesSeller swop.id, e.g. "travis.swop.id"
skustringyesProduct sku/id from swop_get_store

No output schema declared.

No examples provided.

swop_get_store ~159

See what any swop.id sells and buy it: lists the products a swop.id sells on their SmartSite, with USDC prices and each product's x402 buyUrl (for the linked account's own catalogue use swop_list_my_products). An agent with an x402-capable wallet purchases by GETting the buyUrl: the first request returns HTTP 402 with payment instructions (exact USDC amount, network, pay-to address), and retrying with a signed X-PAYMENT header completes the purchase and returns a receipt. Always show the user the product, price, and seller and get their confirmation before paying.

NameTypeReqDescription
handlestringyesThe seller swop.id, e.g. "travis.swop.id"

No output schema declared.

No examples provided.

swop_list_embed_origins ~45

Show which websites may currently display the linked account's Swop checkout in a frame. Use before adding or removing one so the user can see what is already allowed.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

swop_list_my_products ~74

List the linked account's OWN products (each with its id, name, price, inventory, and status); to browse another seller's products use swop_get_store. Use the id with swop_update_product (to edit or unlist) or swop_feature_product (to show it on the SmartSite).

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

swop_list_my_tokens ~85

Community tokens and merchant Bucks the linked account has launched on Base, with live balances (for the overall wallet total use swop_get_my_balances). Read-only. Merchant Bucks are STORE CREDIT (isStoreCredit: true, 2 decimals) — never add them into a portfolio or cash total. An empty list means nothing has been launched yet, not an error.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

swop_list_webhooks ~78

Show the webhook endpoints Swop notifies when the linked account gets paid, and the events available. Two events: checkout.paid (the buyer's money arrived and an order exists) and payout.released (Swop released the seller's money — for a card sale that can be days later). Use before adding or removing one.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

swop_lookup_identity ~84

Resolve an exact swop.id handle (e.g. "travis.swop.id") to its profile: display name, avatar, and public EVM/Solana wallet addresses. Case-insensitive exact match; use swop_search_identities for fuzzy search.

NameTypeReqDescription
handlestringyesExact swop.id handle, e.g. "travis.swop.id"

No output schema declared.

No examples provided.

swop_register_embed_origin ~120

Allow ONE website to display the linked account's Swop checkout inside a frame. This is a security setting: only registered origins can ever frame the checkout, so a leaked API key still cannot put it on someone else's site. Give a bare origin — scheme and host only, https (http allowed for localhost), no wildcards, no path. Confirm the exact origin with the user first.

NameTypeReqDescription
labelstring–A note to recognise it later
originstringyesBare origin, e.g. https://acme.com

No output schema declared.

No examples provided.

swop_register_webhook ~176

Get notified the moment the user gets paid. Register an https URL that Swop will POST a signed JSON event to when the linked account gets paid (checkout.paid) and paid out (payout.released). Returns a signing secret ONCE — tell the user to store it now; it cannot be retrieved again. Deliveries carry a Swop-Signature header: t=<unix seconds>,v1=<hex HMAC-SHA256 of "<t>.<raw body>" with the secret>; failed deliveries retry for about 15 hours. Confirm the exact URL with the user first.

NameTypeReqDescription
eventsarray–Which events to send. Default: both
labelstring–A name for this endpoint
urlstringyeshttps URL to POST events to (http allowed for localhost only)

No output schema declared.

No examples provided.

swop_remove_embed_origin ~63

Remove a website from the list allowed to frame the linked account's checkout. Takes an id from swop_list_embed_origins. Afterwards that site can no longer display the checkout.

NameTypeReqDescription
idstringyesOrigin id from swop_list_embed_origins

No output schema declared.

No examples provided.

swop_remove_link ~121

Remove a link/icon/info-bar/product tile from the SmartSite. Get the item's id and contentType from swop_get_my_smartsite (icons → 'socialTop', buttons → 'socialLarge', info bars → 'infoBar', product tiles → 'marketPlace'). Confirm with the user first.

NameTypeReqDescription
contentTypestringyesThe kind of item to remove
itemIdstringyesThe item id from swop_get_my_smartsite
smartsiteIdstring–Specific SmartSite id (default: primary)

No output schema declared.

No examples provided.

swop_remove_webhook ~53

Stop sending events to one of the linked account's webhook URLs. Pending deliveries to it are dropped. Confirm with the user first.

NameTypeReqDescription
idstringyesWebhook id from swop_list_webhooks

No output schema declared.

No examples provided.

swop_search_identities ~96

Search Swop user identities (swop.ids) by handle or display name. Returns handle, display name, avatar, and public EVM/Solana wallet addresses. Use this to find a user or resolve a name to a wallet address.

NameTypeReqDescription
limitinteger–Max results, default 8
querystringyesHandle or name fragment, at least 2 characters (e.g. "travis")

No output schema declared.

No examples provided.

swop_test_webhook ~64

POST a signed 'ping' event to one of the linked account's webhooks right now and report the HTTP status the endpoint returned. Use to confirm an integration before relying on it.

NameTypeReqDescription
idstringyesWebhook id from swop_list_webhooks

No output schema declared.

No examples provided.

swop_update_my_smartsite ~242

Edit the linked account's SmartSite: display name, bio, and appearance (background color, a gradient of hex stops, a background image URL, theme/font color, font family, or header layout). Pass only what you want to change. For adding links/buttons/info bars use swop_add_link; for products use swop_create_product / swop_feature_product.

NameTypeReqDescription
backgroundColorstring–Solid background hex, e.g. "#0b0b0f"
backgroundGradientarray–Gradient hex stops, e.g. ["#5b3df5","#0b0b0f"] (clears the solid color)
backgroundImgstring–Background/wallpaper image URL
biostring–New bio text
fontColorstring–Primary font hex color
fontFamilystring–Font family name
headerFormatstring–Header layout style
namestring–New display name
smartsiteIdstring–Specific SmartSite id (default: primary)
themeColorstring–Accent/theme hex color

No output schema declared.

No examples provided.

swop_update_product ~277

Edit one of the linked account's products, or unlist it. Pass its productId (from swop_list_my_products) plus ONLY the fields to change — anything omitted keeps its current value. To unlist it, set status to 'archived'. Confirm price and name changes with the user first.

NameTypeReqDescription
descriptionstring–New description
digitalDeliveryNotestring–What a buyer receives
extraImagesarray–Replaces the additional images. Requires image, since the full list is rewritten
imagestring–New primary image URL
keywordsarray–Replaces the keywords
mintLimitinteger–New inventory available
namestring–New product name
priceUsdnumber–New price in USD (settles in USDC)
productIdstringyesThe product id from swop_list_my_products
requiresShippingboolean–Collect a shipping address
royaltyPercentagenumber–Resale royalty percent
royaltyRecipientstring–Wallet receiving royalties
shippingCostnumber–Flat shipping cost in USD
statusstring–Set 'archived' to unlist
variantsarray–Buyer-selectable options. Replaces the existing set when given.

No output schema declared.

No examples provided.

Common questions

What is the io.github.Travisswop/swop MCP server?

io.github.Travisswop/swop is an MCP server listed in the public MCP registry as io.github.Travisswop/swop. Sell to people and AI agents: create products, a storefront, and USDC payment links from chat. This page covers its hosted endpoint (https://mcp.swopme.co/mcp/commerce).

Is the io.github.Travisswop/swop MCP server safe to use?

io.github.Travisswop/swop scores 70 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the io.github.Travisswop/swop MCP server expose?

io.github.Travisswop/swop exposes 27 tools: swop_search_identities, swop_lookup_identity, swop_get_help, swop_get_my_profile, swop_get_my_balances, and 22 more. Their descriptions and schemas cost roughly 3,830 tokens of context every time the server is loaded.

Does the io.github.Travisswop/swop MCP server require authentication?

No. We connected to io.github.Travisswop/swop without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the io.github.Travisswop/swop MCP server still maintained?

io.github.Travisswop/swop is still listed as active in the MCP registry. We last reached this channel on 8 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.