Wicked MCP
io.github.choaticpixelsv1.0.0更新于 Oct 2, 2026
Trading data, agent reputation, tool reliability, Know-Your-Agent identity. x402-native.
概览
将 WickedAPI 交易数据、代理声誉、工具可靠性评分、Know-Your-Agent 身份、幻觉检查和钱包级代理记忆封装为 30 个 MCP 工具。
- 功能
- 提供横跨六个 Wicked 服务的 30 个工具:交易数据(价格、动量、资金费率/持仓量)、链上代理声誉与质押查询、x402/MCP 工具可靠性评分注册表、基于钱包的 Know-Your-Agent 身份(nonce 与挑战流程)、针对所提供上下文或实时网页证据的幻觉/评估检查,以及带语义搜索和版本历史的持久钱包级代理记忆。每个工具都返回上游 JSON 正文和 http_status 字段;非 2xx 响应会被返回而非抛出,因此支付指令和 404 会作为数据返回。
- 适用场景
- 当助手需要交易数据、代理或工具声誉信号、身份验证、声明核查,或与钱包绑定的持久记忆时使用。它也可用于查看 x402 支付流程,因为 402 响应正文中带有支付指令。
- 运行要求
- 可作为远程 streamable-HTTP 端点运行于 mcp.wickedapi.com/mcp,也可在本地用 Python 运行(pip install -r requirements.txt;python server.py)供 stdio 客户端使用。可选环境变量:WICKEDAPI_API_KEY、REGISTRY_API_KEY、IDENTITY_API_KEY、SANITY_API_KEY、MEMORY_API_KEY;另有用于预发布环境的 base URL 覆盖项。记忆和身份调用需要调用方生成钱包签名。需要能访问 Wicked 各服务的网络。
安装
在 SourceWeft 中
- 打开 控制台中的 Wicked MCP,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。
其他 MCP 客户端
把它添加到你客户端的 mcpServers 配置中。
{
"mcpServers": {
"wicked-mcp": {
"type": "http",
"url": "https://mcp.wickedapi.com/mcp"
}
}
}README
Wicked MCP server
An MCP server wrapping the public HTTP surface of WickedAPI
(trading data), Wicked Reputation (on-chain
agent staking/reputation), Wicked Registry
(real reliability scores for x402/MCP tools), Wicked Identity
(reverse-CAPTCHA / Know-Your-Agent verification), Wicked Sanity
(hallucination / eval check), and Wicked Memory
(persistent, wallet-scoped agent memory) — 30 tools, no new backend
logic, just a protocol-native front door onto the same endpoints each
service's own docs show calling with plain requests. Live at
mcp.wickedapi.com; the reputation/staking, registry, identity, and
sanity services and cookbooks live in separate (private) repos.
Tools
WickedAPI (works unauthenticated via x402, or with a free-tier key — see below)
wickedapi_price(symbol, asset_class?)wickedapi_momentum(symbol, timeframe?)wickedapi_funding_oi(symbol)
Wicked Reputation (all public, all free, no key needed)
reputation_status(wallet)reputation_statement(wallet)— position + full event ledgerreputation_query(tier?, min_stake?, ..., sort?, limit?)— filter/sort agentsreputation_tiers()reputation_transparency()
Wicked Registry (search/detail work unauthenticated via x402, or with a free-tier key — see below; featured/badge/report are always free)
registry_search_tools(category?, protocol?, min_score?, sort?, limit?)registry_tool_detail(tool_id)— score breakdown + real check historyregistry_featured_tools()— top scored tools, always freeregistry_tool_badge(tool_id)— a tool's current score, always freeregistry_report_tool(tool_id, reporter, reason, evidence?)— file a complaint, always freeregistry_register_tool(name, endpoint_url, protocol, category, description, owner_wallet, signature, timestamp, schema_url?)— register a tool you own; you supply a real wallet signature, this tool doesn't sign anything itself
Wicked Identity (register/challenge/response require a real wallet signature over a server-issued nonce — these tools never sign anything themselves; status is public and works unauthenticated via x402 or with a free-tier key)
identity_get_nonce(wallet)— fetch a fresh one-time nonce before every signed call belowidentity_register(wallet, nonce, signature)— lightweight identity record, no stake requiredidentity_get_challenge(wallet, nonce, signature)— issue a real, time-boxed (12s default) agent-liveness challengeidentity_submit_response(wallet, nonce, signature, challenge_id, response_text)— score it; pass issues a signed assertion tokenidentity_status(wallet)— does this wallet hold a valid, unexpired assertion? always freeidentity_jwks()— public RS256 keys to verify an assertion_token locally, always free
Wicked Sanity (hallucination / eval check — works unauthenticated via x402, or with a free-tier key; every verdict is real model inference run at request time, never cached or guessed)
sanity_check(claim, context?, mode?)— verify one claim.mode: "grounded"(default;contextrequired) checks it against source text you supply;mode: "open"checks it against live web evidence. Open mode is consistency with current web content, not objective truth, and returnsinsufficient_evidencewhen nothing relevant is found. Noteconfidence_scoreis the raw consistency score (acontradictedverdict scores near 0), not confidence-in-the-verdictsanity_check_batch(claims, context?, mode?)— up to 50 claims against one shared context in a single call; use it for a multi-sentence output rather than onesanity_checkper sentence
Wicked Memory (persistent, wallet-scoped agent memory: store, semantic search, versioned history, hard delete — only search is metered)
Every memory call needs a fresh per-request wallet signature. Like the Identity
tools, this server never signs anything or holds a key: call memory_prepare
with the operation and its arguments, sign the message_to_sign it returns
(EIP-191 personal_sign) with your own wallet, then call the matching tool
with the same arguments plus the returned timestamp, nonce and your
signature. The nonce is single-use and the timestamp must be within 5
minutes, so prepare again for every call.
memory_prepare(operation, wallet, params?)— step 1 of every call; returns the message to signmemory_store(wallet, content, …)— store a memory (free); a real embedding is computed at write timememory_search(wallet, q, …)— semantic search over your memories only, ranked by real cosine similarity. The one metered call: free withMEMORY_API_KEY, otherwise a402with x402 v2 payment instructions underpayment_required(0.001 USDC on Base); pay, then call again with the same arguments pluspayment_signature(a 402 does not consume the nonce). Supportstags, time filters,as_of(memory as it stood at a past instant) andinclude_supersededmemory_get,memory_history,memory_deletions— read one memory, its full version chain, or your deletion audit logmemory_update(wallet, memory_id, …)— supersedes: creates a new version and closes the old one (valid_until/superseded_by); nothing is overwrittenmemory_delete(wallet, memory_id, scope?, reason?)— permanent hard delete;scope: "chain"(default) removes every version,"version"just one. Only an audit row (no content) is kept
Every tool returns the upstream JSON body plus an http_status field.
Non-2xx responses are returned, not raised — a 402 from WickedAPI carries
real x402 payment instructions in the JSON body (older x402 v1); a 402 from
Wicked Registry's search/detail tools, Wicked Identity's status tool, or
Wicked Sanity's check tools carries them decoded from the PAYMENT-REQUIRED header into a
payment_required key instead (newer x402 v2); a 404 from the reputation
service just means the wallet has never registered. All of that is useful
data for whatever's calling the tool, not failures to
hide.
Run it locally (stdio — for Claude Desktop, mcp dev, etc.)
Add to Claude Desktop's config:
No WICKEDAPI_API_KEY? WickedAPI tools still work — they fall back to
x402, returning payment instructions instead of data, same as calling the
API directly with no key.
Remote deployment (streamable HTTP)
http_app.py wraps the same server with mcp.streamable_http_app() and a
per-IP rate limit (RATE_LIMIT_PER_MINUTE, default 30) — the one thing
that changes when this runs as a public endpoint instead of something each
user runs under their own control. Deployed via the Dockerfile in this
directory; Railway sets $PORT.
Live at https://mcp.wickedapi.com/mcp — point any streamable-HTTP
MCP client there directly. (https://wicked-mcp-production.up.railway.app/mcp
also works — same deployment, Railway-generated domain.)
No API key is baked into the deployed server. It authenticates
WickedAPI calls with whatever WICKEDAPI_API_KEY is set in its own
environment (optional — omit it and every caller just gets the x402
fallback), so hosting cost doesn't scale with usage. If you want free-tier
WickedAPI access through the remote endpoint, run it locally instead with
your own key — see above.
Config
来源:README.md,提交 cc784f2
工具
0版本历史
1- v1.0.0最新Oct 2, 2026