Token Command Center
REMOTE · TOKEN-COMMAND-CENTER-GAMMA.VERCEL.APP · SCANNED OCT 7
Free token data: revenue, net flow after emissions, supply/unlock history, catalysts, errors marked
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security80
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability73
- AI-judged instruction clarity (good).Pass
- Tool/resource definitions use about 1547 tokens (~96/item across 16 items; 16 tools + 0 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management10
- Stability observed for 3 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage74
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 23% of tool parameters carry a description.Partial
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 16 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 17 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
- Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
How do I install the Token Command Center MCP server?
Token Command Center is a hosted endpoint at https://token-command-center-gamma.vercel.app/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · token-command-center-gamma.vercel.app
claude mcp add --transport http ysgjay-token-command-center 'https://token-command-center-gamma.vercel.app/mcp'
{
"mcpServers": {
"ysgjay-token-command-center": {
"url": "https://token-command-center-gamma.vercel.app/mcp"
}
}
} {
"servers": {
"ysgjay-token-command-center": {
"type": "http",
"url": "https://token-command-center-gamma.vercel.app/mcp"
}
}
} [mcp_servers.ysgjay-token-command-center] url = "https://token-command-center-gamma.vercel.app/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"ysgjay-token-command-center": {
"type": "remote",
"url": "https://token-command-center-gamma.vercel.app/mcp",
"enabled": true
}
}
} openclaw mcp add ysgjay-token-command-center --url 'https://token-command-center-gamma.vercel.app/mcp' --transport streamable-http
mcp_servers:
ysgjay-token-command-center:
url: "https://token-command-center-gamma.vercel.app/mcp" {
"McpServers": {
"ysgjay-token-command-center": {
"Transport": "http",
"Url": "https://token-command-center-gamma.vercel.app/mcp"
}
}
} assistant mcp add ysgjay-token-command-center -t streamable-http -u 'https://token-command-center-gamma.vercel.app/mcp'
{
"mcpServers": {
"ysgjay-token-command-center": {
"type": "http",
"url": "https://token-command-center-gamma.vercel.app/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 7 Oct 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.
- 6 Oct 26 +1
- Stability: unverified → 0.07 ▲ functional
- 4 Oct 26 69
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 8 Oct 2026 · Probed https://token-command-center-gamma.vercel.app/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=*.vercel.app | CN=WR1,O=Google Trust Services,C=US | 29 Aug 2026 | 27 Nov 2026 | RSA 2048 | SHA256-RSA | f7911168ffa7d0f4135e24792e7a52a8 |
| SANs: *.vercel.app | ||||||
| CN=WR1,O=Google Trust Services,C=US (CA) | CN=GTS Root R1,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | RSA 2048 | SHA256-RSA | 7fd9e2c2d2048a0474b627a26d0868a7 |
| CN=GTS Root R1,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 19 Jun 2020 | 28 Jan 2028 | RSA 4096 | SHA256-RSA | 77bd0d6cdb36f91aea210fc4f058d30d |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of token-command-center-gamma.vercel.app. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| app. | present | 23684 | 8 | Verified |
| vercel.app. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
| x-content-type-options | nosniff |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://token-command-center-gamma.vercel.app/mcp | Verified | 200 | |
| http (plaintext) | http://token-command-center-gamma.vercel.app/mcp | HTTPS enforced | 308 | https://token-command-center-gamma.vercel.app/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
tc_alerts ~47
Recent threshold alerts (revenue deterioration, emission acceleration, unlock cliffs, flow flips).
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | – |
| severity | string | – | – |
| token | string | – | – |
No output schema declared.
No examples provided.
tc_brief ~56
The whole Book in about 1.5 KB: freshness and caveats, verdict and lens mix, biggest 30-day revenue movers, highest health, latest high alerts, plus a plain-text version. Use for market-wide questions.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
tc_calendar ~75
Upcoming dated catalysts (unlocks, emission steps, votes, launches) across the Book, soonest first, at most 20. Optional token slug and horizon in days (default 30, max 180). Text is analyst notes.
| Name | Type | Req | Description |
|---|---|---|---|
| days | integer | – | – |
| token | string | – | Token slug to filter to. |
No output schema declared.
No examples provided.
tc_categories ~13
Token counts per category.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
tc_compare ~87
Two to six tokens side by side: price, valuation, revenue and its 7/30-day change, holders revenue, net-flow yield, P/S, unlocks, health with six pillar scores, verdict, lens, and any frozen-price or old-scorecard flags. Accepts slugs or unambiguous symbols.
| Name | Type | Req | Description |
|---|---|---|---|
| fields | array | – | – |
| tokens | array | yes | – |
No output schema declared.
No examples provided.
tc_get_report ~43
Newest markdown scorecard for a slug (clipped). Long; prefer tc_get_token unless the user asks for the write-up.
| Name | Type | Req | Description |
|---|---|---|---|
| slug | string | yes | – |
No output schema declared.
No examples provided.
tc_get_token ~107
One token's full scorecard (about 8 KB): six pillar scores, the stat grid with a provenance tag per figure, ARR change over 1D/7D/30D/1Y, 30-point history, revenue basis, analyst facts, lens, links, gaps, and this token's alerts and source conflicts. Use only when tc_get_token_digest lacks what the user asked for.
| Name | Type | Req | Description |
|---|---|---|---|
| slug | string | yes | Token slug, e.g. geodnet. |
No output schema declared.
No examples provided.
tc_get_token_digest ~80
One token in about 1 KB: latest price, valuation, revenue and flows, 7- and 30-day changes, health score with its six pillar scores and verdict, supply unlocks, lens, and data-quality counts. Prefer this over tc_get_token.
| Name | Type | Req | Description |
|---|---|---|---|
| slug | string | yes | Token slug, e.g. geodnet. |
No output schema declared.
No examples provided.
tc_ledger ~37
Prediction ledger tallies: open and graded call counts, next grading date, calls by side. Counts only; individual calls are not published.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
tc_list_tokens ~110
Page through scored tokens with optional filters. Sorts: health, mcap, revenue, net_flow, ps, unlock_30d, alerts, name.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | – | – |
| descending | boolean | – | – |
| limit | integer | – | – |
| offset | integer | – | – |
| query | string | – | Substring of slug, symbol or name. |
| sort | string | – | – |
| tier | string | – | – |
| verdict | string | – | Real, Mid or Theater. |
No output schema declared.
No examples provided.
tc_moves ~74
Biggest movers: kind=movers ranks 30-day revenue change against price change (divergence); kind=momentum ranks a 14-day composite of revenue, net-flow yield and health changes. Up to 8 up and 8 down. Rows marked base_effect started from almost zero.
| Name | Type | Req | Description |
|---|---|---|---|
| kind | string | – | – |
No output schema declared.
No examples provided.
tc_resolve ~80
Turn a symbol, $cashtag, name or slug into Token Command Center slugs. Returns exact (one slug) or ambiguous=true with every candidate when tokens share a symbol (e.g. POL); never guess between them. Call before a digest when the user names a token.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | – |
| query | string | yes | – |
No output schema declared.
No examples provided.
tc_screen ~399
Screen the whole Book (all scored tokens) and get compact ranked rows. Filters: lens (long, short, no-edge), verdict (Real, Mid, Theater), tier, category, flow_model (comma-separated for several), stale, query; numeric ranges via min/max objects, e.g. {"min": {"health": 60, "arr": 1000000}, "max": {"ps": 20}}. Fields: alerts, arr (annualized revenue, USD), arr_30d (ARR change over 30 days, %), arr_7d (ARR change over 7 days, %), category, conflicts, date, fdv, flow_model, health (0-100 health score, set when the scorecard is written), health_change, holders_rev (annualized revenue to holders, USD), lens (long, short or no-edge), mcap, name, net_flow (holders revenue minus emissions, USD/yr), nf_yield (net flow / market cap, %), pct_unlocked, price, price_frozen_days, ps (market cap / annualized revenue), scorecard_age_days, stale, symbol, tier, unlock_30d (% of supply unlocking in the next 30 days), verdict (value accrual: Real, Mid or Theater). Tokens with no value for a ranged field are excluded, never counted as zero.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | – | – |
| fields | array | – | – |
| flow_model | string | – | – |
| lens | string | – | – |
| limit | integer | – | – |
| max | object | – | Upper bounds by numeric field. |
| min | object | – | Lower bounds by numeric field. |
| order | string | – | – |
| query | string | – | Substring of slug, symbol or name. |
| sort | string | – | – |
| stale | boolean | – | – |
| tier | string | – | – |
| verdict | string | – | – |
No output schema declared.
No examples provided.
tc_search_tokens ~37
Find slugs by symbol or name before calling tc_get_token_digest.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | – |
| query | string | yes | – |
No output schema declared.
No examples provided.
tc_series ~213
One token's history as chartable series from TCC's daily snapshots (since 2026-06-09). Each metric returns `summary` {first, last, change_pct, min, max} first — answer trend questions from it — then at most 60 points (weekly by default). Frozen price feeds are null, not flat. Metrics: price, mcap, fdv, ann_fees, ann_revenue, ann_holders_rev, net_flow_usd, ps_ratio, health_score, ann_emissions_usd, circ_supply, total_supply, pct_unlocked, daily_fees, daily_revenue, daily_holders_rev, price_llama (daily_* and price_llama are DefiLlama, years deep; the rest are TCC snapshots).
| Name | Type | Req | Description |
|---|---|---|---|
| interval | string | – | – |
| metrics | array | – | – |
| range | string | – | – |
| slug | string | yes | Token slug, e.g. geodnet. Use tc_resolve first for a symbol. |
No output schema declared.
No examples provided.
tc_status ~29
Freshness, size and source-agreement stats of the token universe. Call first; quote generated_at.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
What is the Token Command Center MCP server?
Token Command Center is an MCP server listed in the public MCP registry as io.github.ysgjay/token-command-center. Free token data: revenue, net flow after emissions, supply/unlock history, catalysts, errors marked. This page covers its hosted endpoint (https://token-command-center-gamma.vercel.app/mcp).
Is the Token Command Center MCP server safe to use?
Token Command Center scores 71 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Token Command Center MCP server expose?
Token Command Center exposes 16 tools: tc_status, tc_list_tokens, tc_get_token, tc_get_token_digest, tc_search_tokens, and 11 more. Their descriptions and schemas cost roughly 1,487 tokens of context every time the server is loaded.
Does the Token Command Center MCP server require authentication?
No. We connected to Token Command Center without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Token Command Center MCP server still maintained?
Token Command Center is still listed as active in the MCP registry. We last reached this channel on 7 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.