
Verified Handles
org.verifiedhandlesv1.6.0更新于 Oct 8, 2026
Look up people, organisations and things, and their verified social handles and identifiers.
概览
让助手查询、搜索并读取人物、组织和事物的条目,以及它们经过验证的社交账号和标识符。
- 功能
- 通过 Streamable HTTP 连接 Verified Handles 目录,提供 get_entry、search_entries 和 get_entry_history 等读取工具。使用 API 密钥或 OAuth 账号连接后,还会列出你的角色被允许的工具,包括修改条目的工具;所有会改动内容的工具默认以 dry run 运行,需要再次调用并设置 dry_run 为 false 才会生效,破坏性或影响全站的改动还需要 confirm 值。propose 类工具会把改动提交给审核者,而不是直接发布。
- 适用场景
- 当助手需要解析或核实某个人物、组织或事物及其社交账号和标识符,或需要搜索并读取这些条目的历史记录时使用。也适合让代理以你自己的账号和角色提议或执行目录编辑。
- 运行要求
- 远程 MCP 端点 登录则使用 Authorization 头并带上 Bearer API 密钥,或通过 OAuth 连接。Claude Desktop 扩展和 mcp-remote 桥接需要 Node.js 18 或更高版本。
安装
在 SourceWeft 中
- 打开 控制台中的 Verified Handles,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。
其他 MCP 客户端
把它添加到你客户端的 mcpServers 配置中。
{
"mcpServers": {
"verified-handles": {
"type": "http",
"url": "https://verifiedhandles.org/mcp"
}
}
}README
Verified Handles MCP server
Verified Handles lists people, organisations and things with their verified social handles and other identifiers. Its MCP server lets an AI agent look entries up, search them and read their history with no key, and, with your key or your account, do what you can do on the site.
This repository holds what you need to connect to it: the server itself runs at https://verifiedhandles.org/mcp, and its code is not here. The full guide, with every tool, is at https://verifiedhandles.org/developers/mcp.
- Version 1.6.0: what changed is in CHANGELOG.md.
- The tools, as the server lists them: with no key and with a registered account’s key, each with its input and output schemas.
- A Claude Desktop extension to install in one click: mcpb/.
- The MCP Registry listing: server.json.
- A problem or a question? Open an issue.
The guides below are the ones at https://verifiedhandles.org/developers/mcp, word for word, so “this site” and “here” in them mean verifiedhandles.org.
What MCP is here
MCP, the Model Context Protocol, is how an AI agent (Claude, Cursor, Copilot and others) uses a service through tools it can call. The Verified Handles server is at https://verifiedhandles.org/mcp, over MCP’s Streamable HTTP transport. It is stateless: each message is one POST, answered in JSON, with no session to keep.
Every tool goes through the same routes and checks as the site and the rest of the API: an agent can do nothing you could not do yourself, and with a key it acts as you. Nothing is changed by accident: every tool that changes something only shows what it would do until it is told otherwise (see dry runs).
No key, a read-only key, or a full key
A key that is sent but wrong, revoked or expired is refused with 401; it is never treated as no key. Answers are never cached, by anyone.
Getting a key
Any account can make a key: registered accounts and trusted editors may by default, and administrators hold every permission. (An administrator can take the permission away from an account.) Sign in, choose Console in the menu, then Account, then Manage API keys.
- The key is shown once, when it is made, as
vhk_<prefix>_<secret>. Keep it somewhere safe; if it leaks, revoke it on the same page and it stops working at once. - A role ceiling at or below your own role: the key never acts as more, and a role taken from you is taken from your keys too.
- Read-only, if you only read: the agent is then listed no tool that changes anything.
- An expiry of 1 to 90 days. You can keep up to 5 keys at once.
Connect with your account (OAuth)
Clients that sign in with OAuth (Claude, Claude Code, ChatGPT, VS Code) can act as you without an API key. Connect them to https://verifiedhandles.org/mcp/account: they open a Verified Handles page where you sign in and choose what they may do: a role ceiling, read only, and for how long (7, 30 or 90 days).
https://verifiedhandles.org/mcp stays as it is: with no key, the public reads; with an API key, your account. Your connected apps are on Console → Account → API keys, where you can disconnect one; you can have up to 10 at once. For clients that can’t sign in this way (Cursor, scripts), use an API key as before.
Claude Code
In a terminal
Then run /mcp in Claude Code, choose verified-handles and Authenticate: your browser opens the Verified Handles page.
claude.ai and Claude’s apps
Add a custom connector (Settings, Connectors, Add custom connector) with the address https://verifiedhandles.org/mcp/account, leaving the advanced settings empty, then choose Connect.
VS Code
.vscode/mcp.json
VS Code asks you to sign in the first time it connects.
ChatGPT
In developer mode, create a connector with the address https://verifiedhandles.org/mcp/account and OAuth as its authentication.
What the page asks
The page names the app as it describes itself, the web address its details are published at, and where it sends you back to. Only allow an app you started connecting yourself, just now. It can do what your account can do, never more than the role you pick, and never more than your own role if that changes. When its days are up it asks again; you can disconnect it sooner.
For client authors
- A request to
https://verifiedhandles.org/mcp/accountwith no token answers401withWWW-Authenticate: Bearer resource_metadata="https://verifiedhandles.org/.well-known/oauth-protected-resource/mcp/account", scope="mcp". The metadata is athttps://verifiedhandles.org/.well-known/oauth-protected-resource/mcp/account(RFC 9728) andhttps://verifiedhandles.org/.well-known/oauth-authorization-server(RFC 8414). - A client registers with a Client ID Metadata Document: its
client_idis thehttpsaddress of that document. There is no Dynamic Client Registration, and no client secret. - The authorization code flow with PKCE,
S256only. Sendresource: the address you connect to (https://verifiedhandles.org/mcp/account, orhttps://verifiedhandles.org/mcp); a token works there and nowhere else. The one scope ismcp, andisscomes back with the code. - A code works once, for 60 seconds; an access token for 1 hour. A refresh token is replaced each time it is used, and using an old one again ends the connection. Send the token as
Authorization: Bearer, never in a query string; revoke it athttps://verifiedhandles.org/oauth/revoke.
Setting up your client
Each recipe below connects with a key; for no key, leave the Authorization header (or the setting that sends it) out. Put your own key where it says vhk_<prefix>_<secret>, and keep it out of anything you share or commit: where a client can read it from an environment variable, the recipe does.
Claude Code
In a terminal
Or in a project’s .mcp.json, with the key read from your environment when Claude Code starts:
.mcp.json
Cursor
In ~/.cursor/mcp.json (every project) or a project’s .cursor/mcp.json:
mcp.json
VS Code
In a workspace’s .vscode/mcp.json. VS Code asks for the key the first time and keeps it, so it never sits in the file:
.vscode/mcp.json
Claude Desktop
Add it as a custom connector (Settings, Connectors, Add custom connector), as for claude.ai below. Or, through the mcp-remote bridge (it needs Node.js 18 or later), in claude_desktop_config.json. The key goes in env, because some clients do not pass a space inside an argument safely:
claude_desktop_config.json
claude.ai and other custom connectors
On claude.ai (and Claude’s desktop and mobile apps), add a custom connector with the address https://verifiedhandles.org/mcp. Choose No sign in: with nothing more, it reads with no key. To use your key, add a request header Authorization with the value Bearer vhk_<prefix>_<secret>. The connector calls from Anthropic’s servers, not your computer, so it shares their addresses’ rate limit; a key is the way to be counted as yourself. To sign in instead of sending a key, use the address https://verifiedhandles.org/mcp/account: see Connect with your account (OAuth).
Test the connection
curl
Dry runs, confirm and proposing
Every tool that changes something does nothing by default. Called as it is, it runs with dry_run: true: it reads the entry as it is now and answers with what it would change, the exact request it would send, and whether your account may make it. To make the change, call it again with dry_run: false.
A change that destroys something or affects the whole site also needs confirm, set to the exact target the dry run names (an entry’s VHID, say), so it is never made by accident.
To change an entry without it going live, propose it: the propose_* tools send it to a reviewer, as a suggestion on the site does, and nothing changes until a person approves it. Sending the same proposal again answers with the one already waiting. Each tool that edits live names the tool that proposes the same change instead.
Rate limits
Messages with no key are limited to 60 a minute from one IP address, shared by everyone calling from it, as everyone using an agent hosted on someone else’s servers is (a claude.ai connector calls from Anthropic’s). With a key, or connected with your account, the limit is 120 a minute for each key, wherever its messages come from. Each tool call is also counted by the request it makes, as any request to the site is: a read in the JSON reads’ limit (120 a minute), a change in the limits on changes, per address, per account and per key. Past a limit, the answer is 429 Too Many Requests with a Retry-After header: wait that many seconds, then go on.
The Claude Desktop extension
The mcpb/ folder is a Claude Desktop extension. Claude Desktop runs it with its own Node.js; it starts mcp-remote, which connects to the server for it. Its one setting is your API key, and it is optional: left empty, the extension reads with no key. Claude Desktop hides the key as you type it and stores it securely.
To build the .mcpb file from this folder (Node.js 18 or later):
About this repository
Everything here is generated from the Verified Handles source each time the server changes, so a pull request to these files would be overwritten: please open an issue instead.
This repository is MIT-licensed: see LICENSE.
来源:README.md,提交 8492cfa
工具
0版本历史
1- v1.6.0最新Oct 8, 2026
