
Verified Handles
org.verifiedhandlesv1.6.0更新於 Oct 8, 2026
Look up people, organisations and things, and their verified social handles and identifiers.
概覽
讓助理查詢、搜尋並讀取人物、組織與事物的條目,以及它們經過驗證的社群帳號與識別碼。
- 功能
- 透過 Streamable HTTP 連線到 Verified Handles 目錄,提供 get_entry、search_entries 與 get_entry_history 等讀取工具。使用 API 金鑰或 OAuth 帳號連線後,還會列出你的角色被允許的工具,包括修改條目的工具;所有會變更內容的工具預設以 dry run 執行,需要再次呼叫並將 dry_run 設為 false 才會生效,破壞性或影響全站的變更還需要 confirm 值。propose 類工具會把變更送交審核者,而不是直接發布。
- 適用情境
- 當助理需要解析或查證某個人物、組織或事物及其社群帳號與識別碼,或需要搜尋並讀取這些條目的歷史記錄時使用。也適合讓代理以你自己的帳號與角色提出或執行目錄編輯。
- 執行需求
- 遠端 MCP 端點 登入則使用 Authorization 標頭並帶上 Bearer API 金鑰,或透過 OAuth 連線。Claude Desktop 擴充功能與 mcp-remote 橋接需要 Node.js 18 或以上版本。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 Verified Handles,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。
其他 MCP 客戶端
把它新增到你客戶端的 mcpServers 設定中。
{
"mcpServers": {
"verified-handles": {
"type": "http",
"url": "https://verifiedhandles.org/mcp"
}
}
}README
Verified Handles MCP server
Verified Handles lists people, organisations and things with their verified social handles and other identifiers. Its MCP server lets an AI agent look entries up, search them and read their history with no key, and, with your key or your account, do what you can do on the site.
This repository holds what you need to connect to it: the server itself runs at https://verifiedhandles.org/mcp, and its code is not here. The full guide, with every tool, is at https://verifiedhandles.org/developers/mcp.
- Version 1.6.0: what changed is in CHANGELOG.md.
- The tools, as the server lists them: with no key and with a registered account’s key, each with its input and output schemas.
- A Claude Desktop extension to install in one click: mcpb/.
- The MCP Registry listing: server.json.
- A problem or a question? Open an issue.
The guides below are the ones at https://verifiedhandles.org/developers/mcp, word for word, so “this site” and “here” in them mean verifiedhandles.org.
What MCP is here
MCP, the Model Context Protocol, is how an AI agent (Claude, Cursor, Copilot and others) uses a service through tools it can call. The Verified Handles server is at https://verifiedhandles.org/mcp, over MCP’s Streamable HTTP transport. It is stateless: each message is one POST, answered in JSON, with no session to keep.
Every tool goes through the same routes and checks as the site and the rest of the API: an agent can do nothing you could not do yourself, and with a key it acts as you. Nothing is changed by accident: every tool that changes something only shows what it would do until it is told otherwise (see dry runs).
No key, a read-only key, or a full key
A key that is sent but wrong, revoked or expired is refused with 401; it is never treated as no key. Answers are never cached, by anyone.
Getting a key
Any account can make a key: registered accounts and trusted editors may by default, and administrators hold every permission. (An administrator can take the permission away from an account.) Sign in, choose Console in the menu, then Account, then Manage API keys.
- The key is shown once, when it is made, as
vhk_<prefix>_<secret>. Keep it somewhere safe; if it leaks, revoke it on the same page and it stops working at once. - A role ceiling at or below your own role: the key never acts as more, and a role taken from you is taken from your keys too.
- Read-only, if you only read: the agent is then listed no tool that changes anything.
- An expiry of 1 to 90 days. You can keep up to 5 keys at once.
Connect with your account (OAuth)
Clients that sign in with OAuth (Claude, Claude Code, ChatGPT, VS Code) can act as you without an API key. Connect them to https://verifiedhandles.org/mcp/account: they open a Verified Handles page where you sign in and choose what they may do: a role ceiling, read only, and for how long (7, 30 or 90 days).
https://verifiedhandles.org/mcp stays as it is: with no key, the public reads; with an API key, your account. Your connected apps are on Console → Account → API keys, where you can disconnect one; you can have up to 10 at once. For clients that can’t sign in this way (Cursor, scripts), use an API key as before.
Claude Code
In a terminal
Then run /mcp in Claude Code, choose verified-handles and Authenticate: your browser opens the Verified Handles page.
claude.ai and Claude’s apps
Add a custom connector (Settings, Connectors, Add custom connector) with the address https://verifiedhandles.org/mcp/account, leaving the advanced settings empty, then choose Connect.
VS Code
.vscode/mcp.json
VS Code asks you to sign in the first time it connects.
ChatGPT
In developer mode, create a connector with the address https://verifiedhandles.org/mcp/account and OAuth as its authentication.
What the page asks
The page names the app as it describes itself, the web address its details are published at, and where it sends you back to. Only allow an app you started connecting yourself, just now. It can do what your account can do, never more than the role you pick, and never more than your own role if that changes. When its days are up it asks again; you can disconnect it sooner.
For client authors
- A request to
https://verifiedhandles.org/mcp/accountwith no token answers401withWWW-Authenticate: Bearer resource_metadata="https://verifiedhandles.org/.well-known/oauth-protected-resource/mcp/account", scope="mcp". The metadata is athttps://verifiedhandles.org/.well-known/oauth-protected-resource/mcp/account(RFC 9728) andhttps://verifiedhandles.org/.well-known/oauth-authorization-server(RFC 8414). - A client registers with a Client ID Metadata Document: its
client_idis thehttpsaddress of that document. There is no Dynamic Client Registration, and no client secret. - The authorization code flow with PKCE,
S256only. Sendresource: the address you connect to (https://verifiedhandles.org/mcp/account, orhttps://verifiedhandles.org/mcp); a token works there and nowhere else. The one scope ismcp, andisscomes back with the code. - A code works once, for 60 seconds; an access token for 1 hour. A refresh token is replaced each time it is used, and using an old one again ends the connection. Send the token as
Authorization: Bearer, never in a query string; revoke it athttps://verifiedhandles.org/oauth/revoke.
Setting up your client
Each recipe below connects with a key; for no key, leave the Authorization header (or the setting that sends it) out. Put your own key where it says vhk_<prefix>_<secret>, and keep it out of anything you share or commit: where a client can read it from an environment variable, the recipe does.
Claude Code
In a terminal
Or in a project’s .mcp.json, with the key read from your environment when Claude Code starts:
.mcp.json
Cursor
In ~/.cursor/mcp.json (every project) or a project’s .cursor/mcp.json:
mcp.json
VS Code
In a workspace’s .vscode/mcp.json. VS Code asks for the key the first time and keeps it, so it never sits in the file:
.vscode/mcp.json
Claude Desktop
Add it as a custom connector (Settings, Connectors, Add custom connector), as for claude.ai below. Or, through the mcp-remote bridge (it needs Node.js 18 or later), in claude_desktop_config.json. The key goes in env, because some clients do not pass a space inside an argument safely:
claude_desktop_config.json
claude.ai and other custom connectors
On claude.ai (and Claude’s desktop and mobile apps), add a custom connector with the address https://verifiedhandles.org/mcp. Choose No sign in: with nothing more, it reads with no key. To use your key, add a request header Authorization with the value Bearer vhk_<prefix>_<secret>. The connector calls from Anthropic’s servers, not your computer, so it shares their addresses’ rate limit; a key is the way to be counted as yourself. To sign in instead of sending a key, use the address https://verifiedhandles.org/mcp/account: see Connect with your account (OAuth).
Test the connection
curl
Dry runs, confirm and proposing
Every tool that changes something does nothing by default. Called as it is, it runs with dry_run: true: it reads the entry as it is now and answers with what it would change, the exact request it would send, and whether your account may make it. To make the change, call it again with dry_run: false.
A change that destroys something or affects the whole site also needs confirm, set to the exact target the dry run names (an entry’s VHID, say), so it is never made by accident.
To change an entry without it going live, propose it: the propose_* tools send it to a reviewer, as a suggestion on the site does, and nothing changes until a person approves it. Sending the same proposal again answers with the one already waiting. Each tool that edits live names the tool that proposes the same change instead.
Rate limits
Messages with no key are limited to 60 a minute from one IP address, shared by everyone calling from it, as everyone using an agent hosted on someone else’s servers is (a claude.ai connector calls from Anthropic’s). With a key, or connected with your account, the limit is 120 a minute for each key, wherever its messages come from. Each tool call is also counted by the request it makes, as any request to the site is: a read in the JSON reads’ limit (120 a minute), a change in the limits on changes, per address, per account and per key. Past a limit, the answer is 429 Too Many Requests with a Retry-After header: wait that many seconds, then go on.
The Claude Desktop extension
The mcpb/ folder is a Claude Desktop extension. Claude Desktop runs it with its own Node.js; it starts mcp-remote, which connects to the server for it. Its one setting is your API key, and it is optional: left empty, the extension reads with no key. Claude Desktop hides the key as you type it and stores it securely.
To build the .mcpb file from this folder (Node.js 18 or later):
About this repository
Everything here is generated from the Verified Handles source each time the server changes, so a pull request to these files would be overwritten: please open an issue instead.
This repository is MIT-licensed: see LICENSE.
來源:README.md,提交 8492cfa
工具
0版本歷史
1- v1.6.0最新Oct 8, 2026
