Wicked MCP

io.github.choaticpixelsv1.0.0更新於 Oct 2, 2026

Trading data, agent reputation, tool reliability, Know-Your-Agent identity. x402-native.

已驗證Streamable HTTP可網頁執行FinanceAI & MLKnowledge & Memory

概覽

AI 產生的概覽

把 WickedAPI 交易資料、代理聲譽、工具可靠性評分、Know-Your-Agent 身分、幻覺檢查與錢包範圍的代理記憶封裝成 30 個 MCP 工具。

功能
提供橫跨六個 Wicked 服務的 30 個工具:交易資料(價格、動能、資金費率/持倉量)、鏈上代理聲譽與質押查詢、x402/MCP 工具可靠性評分登錄表、以錢包為基礎的 Know-Your-Agent 身分(nonce 與挑戰流程)、針對你提供的上下文或即時網頁證據的幻覺/評估檢查,以及具備語意搜尋與版本歷史的持久錢包範圍代理記憶。每個工具都會回傳上游 JSON 內容與 http_status 欄位;非 2xx 回應會被回傳而非拋出,因此付款指示與 404 會以資料形式回傳。
適用情境
當助理需要交易資料、代理或工具聲譽訊號、身分驗證、宣稱查核,或與錢包綁定的持久記憶時使用。它也能用來檢視 x402 付款流程,因為 402 回應內容中帶有付款指示。
執行需求
可作為遠端 streamable-HTTP 端點執行於 mcp.wickedapi.com/mcp,也可在本機以 Python 執行(pip install -r requirements.txt;python server.py)供 stdio 用戶端使用。選用環境變數:WICKEDAPI_API_KEY、REGISTRY_API_KEY、IDENTITY_API_KEY、SANITY_API_KEY、MEMORY_API_KEY;另有供測試環境使用的 base URL 覆寫項。記憶與身分呼叫需要由呼叫方產生錢包簽章。需要能連線至 Wicked 各服務的網路。
安裝前請注意
記憶與身分工具需要每次請求提供新的錢包簽章;伺服器本身從不簽章也不持有金鑰,但你要用自己的錢包簽署訊息。memory_search 是計費的:沒有 MEMORY_API_KEY 時會回傳 402 與 x402 v2 付款指示(Base 上 0.001 USDC)。memory_delete 是永久硬刪除。registry_report_tool 會提出投訴,registry_register_tool 會用你提供的簽章提交工具註冊。公開部署共用一把受限的 SANITY_API_KEY,因此 open 模式檢查有上限(每天 30 次、每分鐘 20 次請求)且所有使用者共用。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Wicked MCP,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。

其他 MCP 客戶端

把它新增到你客戶端的 mcpServers 設定中。

{
  "mcpServers": {
    "wicked-mcp": {
      "type": "http",
      "url": "https://mcp.wickedapi.com/mcp"
    }
  }
}

README

Wicked MCP server

An MCP server wrapping the public HTTP surface of WickedAPI (trading data), Wicked Reputation (on-chain agent staking/reputation), Wicked Registry (real reliability scores for x402/MCP tools), Wicked Identity (reverse-CAPTCHA / Know-Your-Agent verification), Wicked Sanity (hallucination / eval check), and Wicked Memory (persistent, wallet-scoped agent memory) — 30 tools, no new backend logic, just a protocol-native front door onto the same endpoints each service's own docs show calling with plain requests. Live at mcp.wickedapi.com; the reputation/staking, registry, identity, and sanity services and cookbooks live in separate (private) repos.

Tools

WickedAPI (works unauthenticated via x402, or with a free-tier key — see below)

  • wickedapi_price(symbol, asset_class?)
  • wickedapi_momentum(symbol, timeframe?)
  • wickedapi_funding_oi(symbol)

Wicked Reputation (all public, all free, no key needed)

  • reputation_status(wallet)
  • reputation_statement(wallet) — position + full event ledger
  • reputation_query(tier?, min_stake?, ..., sort?, limit?) — filter/sort agents
  • reputation_tiers()
  • reputation_transparency()

Wicked Registry (search/detail work unauthenticated via x402, or with a free-tier key — see below; featured/badge/report are always free)

  • registry_search_tools(category?, protocol?, min_score?, sort?, limit?)
  • registry_tool_detail(tool_id) — score breakdown + real check history
  • registry_featured_tools() — top scored tools, always free
  • registry_tool_badge(tool_id) — a tool's current score, always free
  • registry_report_tool(tool_id, reporter, reason, evidence?) — file a complaint, always free
  • registry_register_tool(name, endpoint_url, protocol, category, description, owner_wallet, signature, timestamp, schema_url?) — register a tool you own; you supply a real wallet signature, this tool doesn't sign anything itself

Wicked Identity (register/challenge/response require a real wallet signature over a server-issued nonce — these tools never sign anything themselves; status is public and works unauthenticated via x402 or with a free-tier key)

  • identity_get_nonce(wallet) — fetch a fresh one-time nonce before every signed call below
  • identity_register(wallet, nonce, signature) — lightweight identity record, no stake required
  • identity_get_challenge(wallet, nonce, signature) — issue a real, time-boxed (12s default) agent-liveness challenge
  • identity_submit_response(wallet, nonce, signature, challenge_id, response_text) — score it; pass issues a signed assertion token
  • identity_status(wallet) — does this wallet hold a valid, unexpired assertion? always free
  • identity_jwks() — public RS256 keys to verify an assertion_token locally, always free

Wicked Sanity (hallucination / eval check — works unauthenticated via x402, or with a free-tier key; every verdict is real model inference run at request time, never cached or guessed)

  • sanity_check(claim, context?, mode?) — verify one claim. mode: "grounded" (default; context required) checks it against source text you supply; mode: "open" checks it against live web evidence. Open mode is consistency with current web content, not objective truth, and returns insufficient_evidence when nothing relevant is found. Note confidence_score is the raw consistency score (a contradicted verdict scores near 0), not confidence-in-the-verdict
  • sanity_check_batch(claims, context?, mode?) — up to 50 claims against one shared context in a single call; use it for a multi-sentence output rather than one sanity_check per sentence

Wicked Memory (persistent, wallet-scoped agent memory: store, semantic search, versioned history, hard delete — only search is metered)

Every memory call needs a fresh per-request wallet signature. Like the Identity tools, this server never signs anything or holds a key: call memory_prepare with the operation and its arguments, sign the message_to_sign it returns (EIP-191 personal_sign) with your own wallet, then call the matching tool with the same arguments plus the returned timestamp, nonce and your signature. The nonce is single-use and the timestamp must be within 5 minutes, so prepare again for every call.

  • memory_prepare(operation, wallet, params?) — step 1 of every call; returns the message to sign
  • memory_store(wallet, content, …) — store a memory (free); a real embedding is computed at write time
  • memory_search(wallet, q, …) — semantic search over your memories only, ranked by real cosine similarity. The one metered call: free with MEMORY_API_KEY, otherwise a 402 with x402 v2 payment instructions under payment_required (0.001 USDC on Base); pay, then call again with the same arguments plus payment_signature (a 402 does not consume the nonce). Supports tags, time filters, as_of (memory as it stood at a past instant) and include_superseded
  • memory_get, memory_history, memory_deletions — read one memory, its full version chain, or your deletion audit log
  • memory_update(wallet, memory_id, …) — supersedes: creates a new version and closes the old one (valid_until / superseded_by); nothing is overwritten
  • memory_delete(wallet, memory_id, scope?, reason?) — permanent hard delete; scope: "chain" (default) removes every version, "version" just one. Only an audit row (no content) is kept

Every tool returns the upstream JSON body plus an http_status field. Non-2xx responses are returned, not raised — a 402 from WickedAPI carries real x402 payment instructions in the JSON body (older x402 v1); a 402 from Wicked Registry's search/detail tools, Wicked Identity's status tool, or Wicked Sanity's check tools carries them decoded from the PAYMENT-REQUIRED header into a payment_required key instead (newer x402 v2); a 404 from the reputation service just means the wallet has never registered. All of that is useful data for whatever's calling the tool, not failures to hide.

Run it locally (stdio — for Claude Desktop, mcp dev, etc.)

bash
pip install -r requirements.txtpython server.py

Add to Claude Desktop's config:

json
{  "mcpServers": {    "wicked": {      "command": "python",      "args": ["/absolute/path/to/mcp-server/server.py"],      "env": { "WICKEDAPI_API_KEY": "your-key-if-you-have-one" }    }  }}

No WICKEDAPI_API_KEY? WickedAPI tools still work — they fall back to x402, returning payment instructions instead of data, same as calling the API directly with no key.

Remote deployment (streamable HTTP)

http_app.py wraps the same server with mcp.streamable_http_app() and a per-IP rate limit (RATE_LIMIT_PER_MINUTE, default 30) — the one thing that changes when this runs as a public endpoint instead of something each user runs under their own control. Deployed via the Dockerfile in this directory; Railway sets $PORT.

bash
uvicorn http_app:app --host 0.0.0.0 --port 8080

Live at https://mcp.wickedapi.com/mcp — point any streamable-HTTP MCP client there directly. (https://wicked-mcp-production.up.railway.app/mcp also works — same deployment, Railway-generated domain.)

No API key is baked into the deployed server. It authenticates WickedAPI calls with whatever WICKEDAPI_API_KEY is set in its own environment (optional — omit it and every caller just gets the x402 fallback), so hosting cost doesn't scale with usage. If you want free-tier WickedAPI access through the remote endpoint, run it locally instead with your own key — see above.

Config

Env varDefaultNotes
WICKEDAPI_API_KEY(unset)Optional. Omit to fall back to x402 on every WickedAPI call.
REGISTRY_API_KEY(unset)Optional. Omit to fall back to x402 on every paid Wicked Registry call.
IDENTITY_API_KEY(unset)Optional. Omit to fall back to x402 on the paid identity_status call.
SANITY_API_KEY(unset)Optional. Omit to fall back to x402 on sanity_check / sanity_check_batch. Set on the public deployment to a dedicated restricted key, so public callers get real verdicts: Sanity enforces its limits (20 requests/minute and 30 open-mode checks/day, shared by all users; grounded mode is not counted against the daily cap) via its API_KEY_LIMITS setting, because every caller shares that one key and open mode spends a live web search per call. Over the limit, the tool returns http_status 429 with Retry-After.
MEMORY_API_KEY(unset)Optional. Omit to fall back to x402 on memory_search (the only metered Memory call). Memory keys are issued by the operator.
MEMORY_BASE_URLhttps://memory.wickedapi.comOverride for local/staging testing only (staging: https://memory-testnet.wickedapi.com, Base Sepolia).
WICKEDAPI_BASE_URLhttps://api.wickedapi.comOverride for local/staging testing only.
REPUTATION_BASE_URLhttps://stake.wickedapi.comOverride for local/staging testing only.
REGISTRY_BASE_URLhttps://registry.wickedapi.comOverride for local/staging testing only.
IDENTITY_BASE_URLhttps://verify.wickedapi.comOverride for local/staging testing only.
SANITY_BASE_URLhttps://sanity.wickedapi.comOverride for local/staging testing only (staging: https://wicked-sanity-staging.up.railway.app).
RATE_LIMIT_PER_MINUTE30HTTP deployment only (http_app.py), per real client IP (IPv6 grouped by /64).
TRUSTED_CLIENT_IP_HEADERx-real-ipHTTP deployment only. Header carrying the caller's real IP, set by the proxy in front (Railway sets X-Real-IP). Behind the proxy the TCP peer is always Railway's own address, so without this every caller would share one bucket. Only safe when the proxy sets the header itself; set empty to use the TCP peer instead (e.g. if run without a proxy). If the domain is ever proxied through Cloudflare, point it at cf-connecting-ip. Missing/invalid values fall back to the TCP peer.

來源:README.md,提交 cc784f2

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v1.0.0最新Oct 2, 2026