# io.github.Travisswop/swop (remote · mcp.swopme.co)

Sell to people and AI agents: create products, a storefront, and USDC payment links from chat.

- Trust score: 70/100 (medium)
- Change this week: +3
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-08

## Components

- remote · `mcp.swopme.co`: 70/100 (this document), [markdown](https://verifymcp.io/servers/travisswop-swop/mcp-commerce.md), [page](https://verifymcp.io/servers/travisswop-swop/mcp-commerce)

## Channel facts

- Endpoint: `https://mcp.swopme.co/mcp/commerce`
- Transports: `streamable-http`
- Auth: `none`
- Version: `0.2.1`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-08.

- **Endpoint Security**: 63/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (swop_remove_link).
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 74/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 3911 tokens (~144/item across 27 items; 27 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 23/100
  - Stability observed for 7 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - All 4 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.
  - An AI judge read all 28 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### How do I install the io.github.Travisswop/swop MCP server?

io.github.Travisswop/swop is a hosted endpoint at https://mcp.swopme.co/mcp/commerce, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http travisswop-swop 'https://mcp.swopme.co/mcp/commerce'
```

### Cursor

```json
{
  "mcpServers": {
    "travisswop-swop": {
      "url": "https://mcp.swopme.co/mcp/commerce"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "travisswop-swop": {
      "type": "http",
      "url": "https://mcp.swopme.co/mcp/commerce"
    }
  }
}
```

### Codex

```toml
[mcp_servers.travisswop-swop]
url = "https://mcp.swopme.co/mcp/commerce"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "travisswop-swop": {
      "type": "remote",
      "url": "https://mcp.swopme.co/mcp/commerce",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add travisswop-swop --url 'https://mcp.swopme.co/mcp/commerce' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  travisswop-swop:
    url: "https://mcp.swopme.co/mcp/commerce"
```

### Netclaw

```json
{
  "McpServers": {
    "travisswop-swop": {
      "Transport": "http",
      "Url": "https://mcp.swopme.co/mcp/commerce"
    }
  }
}
```

### Vellum

```bash
assistant mcp add travisswop-swop -t streamable-http -u 'https://mcp.swopme.co/mcp/commerce'
```

### Other

```json
{
  "mcpServers": {
    "travisswop-swop": {
      "type": "http",
      "url": "https://mcp.swopme.co/mcp/commerce"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-10-08 (score 70, +1)

No change was recorded against any check on this day. Stability & Change Management went from 17 to 23. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-10-06 (score 69, +1)

No change was recorded against any check on this day. Stability & Change Management went from 10 to 17. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 5 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-10-04 (score 68, 0)

- [functional] New tool “swop_get_help”

### 2026-10-03 (score 68, +1)

No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-10-02 (score 67, 0)

- [security] Tool “swop_create_checkout” rewrote its description, which is the text the model reads
- [security] Tool “swop_create_product” rewrote its description, which is the text the model reads
- [security] Tool “swop_feature_product” rewrote its description, which is the text the model reads
- [security] Tool “swop_get_my_balances” rewrote its description, which is the text the model reads
- [security] Tool “swop_get_store” rewrote its description, which is the text the model reads
- [security] Tool “swop_list_my_products” rewrote its description, which is the text the model reads
- [security] Tool “swop_list_my_tokens” rewrote its description, which is the text the model reads
- [functional improvement] Stability: unverified → 0.03
- [functional] Server version: 0.2.1 → 0.2.2

### 2026-10-01 (score 67)

First indexed and scored.

## MCP tools (27)

### `swop_search_identities` (~96 tokens)

Search swop.id identities

Search Swop user identities (swop.ids) by handle or display name. Returns handle, display name, avatar, and public EVM/Solana wallet addresses. Use this to find a user or resolve a name to a wallet address.

Input parameters:

- `limit` (integer): Max results, default 8
- `query` (string, required): Handle or name fragment, at least 2 characters (e.g. "travis")

### `swop_lookup_identity` (~84 tokens)

Look up a swop.id

Resolve an exact swop.id handle (e.g. "travis.swop.id") to its profile: display name, avatar, and public EVM/Solana wallet addresses. Case-insensitive exact match; use swop_search_identities for fuzzy search.

Input parameters:

- `handle` (string, required): Exact swop.id handle, e.g. "travis.swop.id"

### `swop_get_help` (~112 tokens)

Swop help

Look up Swop's own how-to answers on payment previews, funded claim links, Goldman AI credits, companion pairing and saved context. Use it when the user asks how a Swop feature works; for their own data use the swop_get_my_* tools instead. Returns the closest curated answer, or says the topic is not covered.

Input parameters:

- `query` (string, required): The question in plain words, e.g. "how do claim links work" or "what are Goldman credits". Max 240 characters.

### `swop_get_my_profile` (~65 tokens)

Get my Swop profile

The linked user's own Swop account: name, email, and SmartSites (handle, bio). Use swop_lookup_identity or swop_search_identities for anyone else's profile. If no Swop account is connected, the call fails asking the user to connect it.

### `swop_get_my_balances` (~49 tokens)

Get my wallet balances

Current wallet balance snapshot for the linked Swop account (total USD and per-asset breakdown). For tokens or merchant Bucks the account has launched, use swop_list_my_tokens instead.

### `swop_get_my_orders` (~44 tokens)

Get my orders

Recent marketplace orders for the linked Swop account, both sides: sales of your products and your purchases. Shows payment, escrow/settlement, and fulfillment status.

### `swop_list_my_tokens` (~85 tokens)

List my Launchpad tokens

Community tokens and merchant Bucks the linked account has launched on Base, with live balances (for the overall wallet total use swop_get_my_balances). Read-only. Merchant Bucks are STORE CREDIT (isStoreCredit: true, 2 decimals) — never add them into a portfolio or cash total. An empty list means nothing has been launched yet, not an error.

### `swop_get_my_smartsite` (~99 tokens)

See my SmartSite

Get the linked account's current SmartSite so you can see it BEFORE editing: name, bio, appearance (background/theme), the links already on it (icons, buttons, info bars, with their item ids for removal), product tiles, and a viewUrl to preview it. ALWAYS call this before adding or changing things so edits stay additive.

Input parameters:

- `smartsiteId` (string): Specific SmartSite id (default: primary)

### `swop_update_my_smartsite` (~242 tokens)

Edit my SmartSite (name, bio, background)

Edit the linked account's SmartSite: display name, bio, and appearance (background color, a gradient of hex stops, a background image URL, theme/font color, font family, or header layout). Pass only what you want to change. For adding links/buttons/info bars use swop_add_link; for products use swop_create_product / swop_feature_product.

Input parameters:

- `backgroundColor` (string): Solid background hex, e.g. "#0b0b0f"
- `backgroundGradient` (array): Gradient hex stops, e.g. ["#5b3df5","#0b0b0f"] (clears the solid color)
- `backgroundImg` (string): Background/wallpaper image URL
- `bio` (string): New bio text
- `fontColor` (string): Primary font hex color
- `fontFamily` (string): Font family name
- `headerFormat` (string): Header layout style
- `name` (string): New display name
- `smartsiteId` (string): Specific SmartSite id (default: primary)
- `themeColor` (string): Accent/theme hex color

### `swop_add_link` (~291 tokens)

Add a link to my SmartSite

Add a link to the linked account's SmartSite, with smart placement. TWO STEPS: (1) call with just the url — the tool detects what kind of link it is (payment like Venmo/PayPal/Cash App, social, contact, website) and returns a recommendation with a text preview of each layout: a small ICON in the icon row, a link BUTTON tile, or a full-width INFOBAR call-to-action card. Show the user the message + previews and ask which they want. (2) call again with the same url plus displayAs = 'icon' | 'button' | 'infobar' to place it. You can override title / buttonName / description / style ('solid' | 'glass') for an info bar. Returns a viewUrl to preview the result.

Input parameters:

- `buttonName` (string): Info-bar button text (e.g. "Pay", "Book")
- `description` (string): Info-bar description line
- `displayAs` (string): Omit first to get a placement suggestion; then set to place it
- `smartsiteId` (string): Specific SmartSite id (default: primary)
- `style` (string): Info-bar card style (default solid)
- `title` (string): Override the label/title
- `url` (string, required): The link to add (any URL, or mailto:/tel:)

### `swop_remove_link` (~121 tokens)

Remove a SmartSite link

Remove a link/icon/info-bar/product tile from the SmartSite. Get the item's id and contentType from swop_get_my_smartsite (icons → 'socialTop', buttons → 'socialLarge', info bars → 'infoBar', product tiles → 'marketPlace'). Confirm with the user first.

Input parameters:

- `contentType` (string, required): The kind of item to remove
- `itemId` (string, required): The item id from swop_get_my_smartsite
- `smartsiteId` (string): Specific SmartSite id (default: primary)

### `swop_create_feed_post` (~329 tokens)

Post to my Swop feed

Publish a PUBLIC post to the Swop feed as the linked account's SmartSite: a caption plus up to 4 images. Each image may be an https URL, a data:image/...;base64 URI, or bare base64 (PNG/JPEG/GIF/WebP, max 5 MB; keep inline images under ~3 MB total so the request fits). TWO-STEP like swop_send: call WITHOUT confirm to get a preview — Swop hosts the images and returns who it posts as, the exact caption, the hosted image URLs and a previewId. Show the user that exact caption and every image and get an explicit yes. Then call again with the SAME caption and smartsiteId, the `images` array exactly as the preview returned it, the previewId, and confirm: true. Any change after the preview is refused — preview again. Each preview publishes at most once: re-confirming it returns the same post (duplicate: true). Never confirm before the user has seen the preview.

Input parameters:

- `caption` (string): Post text. Hashtags and @handle.swop.id mentions work as in the app
- `confirm` (boolean): true ONLY after the user explicitly approved the preview
- `images` (array): Images: https URLs, data:image/...;base64 URIs, or base64. On confirm, pass the hosted URLs from the preview
- `previewId` (string): From the preview step
- `smartsiteId` (string): Post as this SmartSite (default: primary). Ids from swop_get_my_profile

### `swop_create_product` (~339 tokens)

Create a product

Start selling something in one call: creates a product that people can buy on the linked account's Swop SmartSite and AI agents can buy in USDC over x402, with no store setup, payment processor, or verification needed. To change an existing product use swop_update_product instead. name, description and image are all REQUIRED by the backend. Confirm name and price with the user before creating. Then call swop_feature_product to show it on the SmartSite and swop_get_product_link to share it.

Input parameters:

- `description` (string, required): Product description (required)
- `digitalDeliveryNote` (string): Digital goods: what the buyer receives after purchase
- `extraImages` (array): Additional image URLs, shown after the primary one
- `image` (string, required): Primary product image URL (required)
- `keywords` (array): Search keywords
- `mintLimit` (integer): Inventory available, default 1
- `name` (string, required): Product name
- `nftType` (string): Fine-grained type; overrides productType. phygital/menu are physical, the rest digital
- `priceUsd` (number, required): Price in USD (settles in USDC)
- `productType` (string): physical (ships), digital (default), or in_person_checkout
- `requiresShipping` (boolean): Physical goods: collect a shipping address
- `royaltyPercentage` (number): Resale royalty percent
- `royaltyRecipient` (string): Wallet receiving royalties
- `shippingCost` (number): Flat shipping cost in USD
- `variants` (array): Buyer-selectable options. Replaces the existing set when given.

### `swop_create_checkout` (~409 tokens)

Create a checkout for a cart

Take payment on the seller's own website: creates a checkout for a cart of the linked account's OWN products, so a buyer pays there instead of being sent to Swop. For a single shareable link use swop_get_product_link instead. Prices come from the seller's catalogue and must NOT be sent — a price in the request is rejected. Shipping is charged automatically for physical products, and for those the buyer's name, email and delivery address are REQUIRED (the call is refused otherwise, naming what is missing). Rails: USDC on Solana always; set offerCard when the seller is card-enabled and every item is a physical good — then the response has cardOffered: true and paymentRequest is null until the buyer picks a rail on the seller's page via the public URLs POST /api/v5/checkout-intents/{intentId}/card-payment-intents (Stripe client secret for a Payment Element) or POST .../select-crypto (publishes the Solana Pay request). Otherwise paymentRequest is returned at once (a solana: URL the buyer's wallet opens, also fine as a QR code). Settlement is automatic once the payment lands — nothing to confirm; poll swop_get_checkout for status. Show the buyer the products, quantities and total before creating.

Input parameters:

- `buyerEmail` (string): Buyer's email, for the receipt (required for physical items)
- `buyerName` (string): Buyer's name (required for physical items)
- `buyerPhone` (string): Buyer's phone, for the courier
- `description` (string): What this checkout is for
- `items` (array, required): The cart. Ids only — prices come from the catalogue
- `offerCard` (boolean): Offer card as well as USDC. Only takes effect when the seller is card-enabled and every item is physical; otherwise the checkout is USDC-only
- `shippingAddress` (object): Delivery address. Required when any item is a physical product

### `swop_get_checkout` (~111 tokens)

Check a checkout

Read back a checkout created with swop_create_checkout: its status (active, pending_payment, paid, settled, expired, cancelled), the payment request if one is published, and the line items. Poll this after the buyer has been shown the payment to learn when it lands — paid means the buyer's money arrived; settled means the seller has been paid out. Only the linked account's own checkouts are visible.

Input parameters:

- `intentId` (string, required): The intentId returned by swop_create_checkout

### `swop_list_webhooks` (~78 tokens)

List my webhooks

Show the webhook endpoints Swop notifies when the linked account gets paid, and the events available. Two events: checkout.paid (the buyer's money arrived and an order exists) and payout.released (Swop released the seller's money — for a card sale that can be days later). Use before adding or removing one.

### `swop_register_webhook` (~176 tokens)

Add a webhook

Get notified the moment the user gets paid. Register an https URL that Swop will POST a signed JSON event to when the linked account gets paid (checkout.paid) and paid out (payout.released). Returns a signing secret ONCE — tell the user to store it now; it cannot be retrieved again. Deliveries carry a Swop-Signature header: t=<unix seconds>,v1=<hex HMAC-SHA256 of "<t>.<raw body>" with the secret>; failed deliveries retry for about 15 hours. Confirm the exact URL with the user first.

Input parameters:

- `events` (array): Which events to send. Default: both
- `label` (string): A name for this endpoint
- `url` (string, required): https URL to POST events to (http allowed for localhost only)

### `swop_test_webhook` (~64 tokens)

Send a test event to a webhook

POST a signed 'ping' event to one of the linked account's webhooks right now and report the HTTP status the endpoint returned. Use to confirm an integration before relying on it.

Input parameters:

- `id` (string, required): Webhook id from swop_list_webhooks

### `swop_remove_webhook` (~53 tokens)

Remove a webhook

Stop sending events to one of the linked account's webhook URLs. Pending deliveries to it are dropped. Confirm with the user first.

Input parameters:

- `id` (string, required): Webhook id from swop_list_webhooks

### `swop_list_embed_origins` (~45 tokens)

List sites allowed to frame my checkout

Show which websites may currently display the linked account's Swop checkout in a frame. Use before adding or removing one so the user can see what is already allowed.

### `swop_register_embed_origin` (~120 tokens)

Allow a site to frame my checkout

Allow ONE website to display the linked account's Swop checkout inside a frame. This is a security setting: only registered origins can ever frame the checkout, so a leaked API key still cannot put it on someone else's site. Give a bare origin — scheme and host only, https (http allowed for localhost), no wildcards, no path. Confirm the exact origin with the user first.

Input parameters:

- `label` (string): A note to recognise it later
- `origin` (string, required): Bare origin, e.g. https://acme.com

### `swop_remove_embed_origin` (~63 tokens)

Stop a site framing my checkout

Remove a website from the list allowed to frame the linked account's checkout. Takes an id from swop_list_embed_origins. Afterwards that site can no longer display the checkout.

Input parameters:

- `id` (string, required): Origin id from swop_list_embed_origins

### `swop_feature_product` (~143 tokens)

Feature a product on my SmartSite

Show an existing product on the linked account's SmartSite as a tile visitors can buy from. Pass the templateId returned by swop_create_product (or the id from swop_list_my_products). Each call ADDS a new tile and never replaces existing ones, so check swop_get_my_smartsite first to avoid duplicates; remove a tile with swop_remove_link. The product must belong to the linked account.

Input parameters:

- `carouselTitle` (string): Optional heading for the product section
- `smartsiteId` (string): Specific SmartSite id (default: primary)
- `templateId` (string, required): The product/template id from swop_create_product

### `swop_list_my_products` (~74 tokens)

List my products

List the linked account's OWN products (each with its id, name, price, inventory, and status); to browse another seller's products use swop_get_store. Use the id with swop_update_product (to edit or unlist) or swop_feature_product (to show it on the SmartSite).

### `swop_update_product` (~277 tokens)

Update or unlist a product

Edit one of the linked account's products, or unlist it. Pass its productId (from swop_list_my_products) plus ONLY the fields to change — anything omitted keeps its current value. To unlist it, set status to 'archived'. Confirm price and name changes with the user first.

Input parameters:

- `description` (string): New description
- `digitalDeliveryNote` (string): What a buyer receives
- `extraImages` (array): Replaces the additional images. Requires image, since the full list is rewritten
- `image` (string): New primary image URL
- `keywords` (array): Replaces the keywords
- `mintLimit` (integer): New inventory available
- `name` (string): New product name
- `priceUsd` (number): New price in USD (settles in USDC)
- `productId` (string, required): The product id from swop_list_my_products
- `requiresShipping` (boolean): Collect a shipping address
- `royaltyPercentage` (number): Resale royalty percent
- `royaltyRecipient` (string): Wallet receiving royalties
- `shippingCost` (number): Flat shipping cost in USD
- `status` (string): Set 'archived' to unlist
- `variants` (array): Buyer-selectable options. Replaces the existing set when given.

### `swop_get_product_link` (~102 tokens)

Get a shareable product link

Get one link that sells to everyone: a person who opens it sees a product page with a Buy button, and an AI agent that requests it gets an x402 USDC payment challenge. Use this to share a product in chat, a social post, or a message.

Input parameters:

- `handle` (string, required): Seller swop.id, e.g. "travis.swop.id"
- `sku` (string, required): Product sku/id from swop_get_store

### `swop_get_store` (~159 tokens)

Get a swop.id storefront

See what any swop.id sells and buy it: lists the products a swop.id sells on their SmartSite, with USDC prices and each product's x402 buyUrl (for the linked account's own catalogue use swop_list_my_products). An agent with an x402-capable wallet purchases by GETting the buyUrl: the first request returns HTTP 402 with payment instructions (exact USDC amount, network, pay-to address), and retrying with a signed X-PAYMENT header completes the purchase and returns a receipt. Always show the user the product, price, and seller and get their confirmation before paying.

Input parameters:

- `handle` (string, required): The seller swop.id, e.g. "travis.swop.id"

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/travisswop-swop/mcp-commerce#diagnostics

## Score history

- 2026-10-08: 70
- 2026-10-06: 69
- 2026-10-04: 68
- 2026-10-03: 68
- 2026-10-02: 67
- 2026-10-01: 67

## Common questions

### What is the io.github.Travisswop/swop MCP server?

io.github.Travisswop/swop is an MCP server listed in the public MCP registry as io.github.Travisswop/swop. Sell to people and AI agents: create products, a storefront, and USDC payment links from chat. This page covers its hosted endpoint (https://mcp.swopme.co/mcp/commerce).

### Is the io.github.Travisswop/swop MCP server safe to use?

io.github.Travisswop/swop scores 70 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the io.github.Travisswop/swop MCP server expose?

io.github.Travisswop/swop exposes 27 tools: swop_search_identities, swop_lookup_identity, swop_get_help, swop_get_my_profile, swop_get_my_balances, and 22 more. Their descriptions and schemas cost roughly 3,830 tokens of context every time the server is loaded.

### Does the io.github.Travisswop/swop MCP server require authentication?

No. We connected to io.github.Travisswop/swop without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the io.github.Travisswop/swop MCP server still maintained?

io.github.Travisswop/swop is still listed as active in the MCP registry. We last reached this channel on 8 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://mcp.swopme.co/mcp/commerce
- Repository: https://github.com/Travisswop/swop-mcp
- Changelog RSS feed: https://verifymcp.io/servers/travisswop-swop/mcp-commerce.xml
- Changelog JSON feed: https://verifymcp.io/servers/travisswop-swop/mcp-commerce.json
- HTML version of this page: https://verifymcp.io/servers/travisswop-swop/mcp-commerce
