Official MCP RegistryListed
Otto Intel
Otto AI hosted MCP: 16 pay-per-call market-intelligence tools, USDC via x402 on Base, no API keys.
First seen 2 Oct 2026. Evidence as of 3 Oct 2026.
48
Tools
From an anonymous probe
1
Source listings
Each with its own history
0
Recorded changes
Since first seen
Tools
| Tool | Description | Behaviour |
|---|---|---|
| otto_base_season | Scan quality-screened Base tokens with current social-intelligence and trusted-KOL context. Market context only; not a pick, recommendation, or trade instruction. Hosted access: the first eligible cached intelligence result is free; otherwise calls cost $0.002 USDC through x402. | Read-only |
| otto_catalog | Return the full live otto x402 menu with endpoint paths, descriptions, prices, and Base-USDC payment instructions. Always free; does not consume the free intelligence call. | Read-only |
| otto_crypto_news | Read importance-ranked crypto headlines with source links and publication times, plus a sentiment-scored market brief. The hourly snapshot reports its analysis window and freshness; missing source links remain unknown. Paid-only, including the first call: this tool preserves the hosted free intelligence allowance. Market context only; not a recommendation. Hosted access: paid-only; each call costs $0.001 USDC through x402 and preserves the free allowance. | Read-only |
| otto_delegation_cap | Legacy Model B cap confirmation. New { phase: "reserve" } requests are retired and refused before any claim or reservation is written. { phase: "confirm", accessToken, mintKey } remains available for a permission already minted against a prior reservation: the server re-reads CDP and confirms only the exact still-current claim and reserved expiry. A mismatch or Stop overlap remains unconfirmed; a fresh explicit Stop handles the current grant. Without a confirmed per-user cap, delegated sends refuse. This tool does not issue new permissions. Server-to-server only: the caller presents Otto's delegation secret in the `x-otto-delegation-auth` request header (never in arguments); a call without it is refused before anything is read. The listed input schema is intentionally permissive — the strict schema is validated after the caller is authenticated. | Changes data |
| otto_delegation_exit | Move an authenticated CDP end user's own Base USDC only through a server-held durable reservation. prepare returns one exact EIP-1559 transaction for client-side signing; the client must never broadcast it. submit validates and durably records the signed bytes and computed hash before the server broadcasts. status is read-only and cross-device. reconcile proves a canonical receipt without broadcasting, or returns the exact finalized sender+nonce replacement proof when another transaction consumed the reserved nonce. retry_same is explicit and can broadcast only the already-stored byte-identical transaction after reconciling first. cancel is accepted only before signed bytes were recorded. The caller presents Otto's delegation secret in x-otto-delegation-auth; user identity is always derived from accessToken. | Destructive |
| otto_delegation_fence | Idempotent ensure-by-digest of the ONE CDP project-scope policy that fences every delegated send, then a read-back. Writes only when no project policy exists (creates it) or when the existing one is Otto's own lineage with stale rules (updates it in place). REFUSES BY NAME if a different project-scope policy is installed — it is never overwritten or deleted. Never downgrades a newer fence. An OPS action: at most one ensure runs project-wide at a time, never during a rolling deploy, never from the dApp (the mint gate reads fence.present from otto_delegation_status). Arguments: {}. Output: the policy id, versioned name, rules digest and the per-swap cap; the tool fails unless the fence reads back present under the written id. Server-to-server only: the caller presents Otto's delegation secret in the `x-otto-delegation-auth` request header (never in arguments); a call without it is refused before anything is read. The listed input schema is intentionally permissive — the strict schema is validated after the caller is authenticated. | Changes data |
| otto_delegation_fence_status | PUBLIC and read-only, no header: reports whether the Model B project policy still fences existing delegated sends, its name and rules digest, the shared cap ceiling, and mint_enabled for new Model B trade setup. New trade-permission creation is retired, so mint_enabled is false on the serving retirement build. Existing status, revoke and exits remain available. No user, grant, address or policy contents are exposed. Arguments: {}. | Read-only |
| otto_delegation_operations | Read the durable Base delegated-operation journal for the end user resolved from { accessToken }. Optional artifactId selects one exact own-user operation; without it, the result includes a bounded recent terminal history and every unresolved operation regardless of age. The global unresolved flag is fail-closed: it is true when the store is unavailable, journal coverage is not rollout-ready, or any operation has a prepared/submitted/unknown outcome. Stored serialized transactions and CDP idempotency keys are never returned, and this tool never submits or retries anything. Server-to-server only: the caller also presents Otto's delegation secret in the x-otto-delegation-auth request header; no userId argument is accepted. | Read-only |
| otto_delegation_reconcile | Acquire the artifact's permanent process-liveness guard, then check Base for finalized canonical receipts of already-stored transaction hashes. Every chain transaction must match the stored chain, hash, sender, target, calldata, value, nonce, gas and EIP-1559 fee fields before its receipt is recorded. This tool never calls CDP, never retries a request, never builds or submits a later step, and leaves prepared/unknown no-hash steps unresolved. It returns the same token-bound operation snapshot as otto_delegation_operations. Server-to-server only: the caller also presents Otto's delegation secret in x-otto-delegation-auth. | Changes data |
| otto_delegation_revoke | Revoke the end user's delegation from Otto's side and confirm by read-back that it no longer exists; from then on this server submits nothing for that user (fail-closed, even if the read-back had failed). Arguments: EITHER { accessToken } (the user path — the server resolves the user from the token) OR { userId, support_reason } (the support path, for an operator holding the server secret; the reason is logged, the token never is). Server-to-server only: the caller presents Otto's delegation secret in the `x-otto-delegation-auth` request header (never in arguments); a call without it is refused before anything is read. The listed input schema is intentionally permissive — the strict schema is validated after the caller is authenticated. | Destructive |
| otto_delegation_status | Read back, for the end user identified by a CDP access token, their CDP accounts, whether the Model-B fence is present, and whether an active delegation reads back (with its expiry and the per-swap cap recorded for it). Arguments: { accessToken } — the server resolves the user from the token; a client-sent user id is refused. delegation.per_swap_cap_usd is the number THIS user chose at mint time; it is ABSENT when no cap is recorded for the grant, which means the delegated send will refuse it — say so rather than showing the shared ceiling. fence.per_swap_cap_usd is that shared ceiling and is never a per-user number. Output is bound to that user; nothing about any other user is returned. Server-to-server only: the caller presents Otto's delegation secret in the `x-otto-delegation-auth` request header (never in arguments); a call without it is refused before anything is read. The listed input schema is intentionally permissive — the strict schema is validated after the caller is authenticated. | Read-only |
| otto_earnings_calendar | Read the earnings calendar and surprise history for a ticker: the next report date and session with EPS and revenue estimates (null when none is scheduled), the latest reported EPS against its estimate with the surprise percentage, and up to four quarters of history, which may be fewer. Funds and ETFs have no earnings coverage. Estimates keep the vendor’s units because the Finnhub feed does not name a currency, and event-window price drift is reported as unavailable rather than inferred. Paid-only, including the first call: licensed vendor data is not part of the hosted free allowance. Not a recommendation. Hosted access: paid-only; each call costs $0.003 USDC through x402 and preserves the free allowance. | Read-only |
| otto_equity_intel | Read SEC-EDGAR fundamentals and filings context for a US ticker: revenue and net-income trends, margins, EPS, leverage, recent 10-K/10-Q/8-K filings, and a guarded AI summary. Fundamentals scanner only; not a price feed or recommendation. Hosted access: the first eligible cached intelligence result is free; otherwise calls cost $0.003 USDC through x402. | Read-only |
| otto_equity_news | Read licensed Finnhub company headlines for a ticker from the trailing seven days, each with publication time, source and summary. Only articles that name the company are served, labelled `primary` when the headline names it and `mentioned` when only the summary does; a ticker that is also an English word (for example ON or IT) can still match an unrelated upper-case headline. A week with no articles naming the company is refused as `no_recent_news` and nothing is charged. Redirect URLs are withheld and no sentiment is generated. Paid-only, including the first call: licensed vendor data is not part of the hosted free allowance. News context only; not a recommendation. Hosted access: paid-only; each call costs $0.003 USDC through x402 and preserves the free allowance. | Read-only |
| otto_equity_smart_money | Read a public-domain SEC bundle for a US ticker: Form 4 insider activity plus trailing-twelve-month XBRL fundamentals. Scanner context only; not a pick or recommendation. Hosted access: the first eligible cached intelligence result is free; otherwise calls cost $0.006 USDC through x402. | Read-only |
| otto_equity_smart_money_brief | Read one guarded AI brief over observed SEC Form 4 flow, 13D/13G ownership events, and fundamentals for a US ticker. Filing scanner only; generation rejects buy/sell advice and the result is not a recommendation. Hosted access: the first eligible cached intelligence result is free; otherwise calls cost $0.10 USDC through x402. | Read-only |
| otto_financial_statements | Read the SEC statement set for a US-listed company: income statement, balance sheet and cash flow, up to five fiscal periods on both an annual and a quarterly basis. Each figure names the XBRL concept it was filed under, the filing and date it came from, and whether it was filed, reconstructed from year-to-date figures or computed from named lines; a restated period is flagged with the earlier value, and a period the filer did not tag is an explicit null, never carried forward. Includes the 10-K, 10-Q and 8-K filing index with 8-K item codes and EDGAR links. A fund vehicle or a filer that reports only in a non-USD currency has no statements: that is refused as `not_applicable` and nothing is charged. Public-domain SEC EDGAR data; not a recommendation. Hosted access: the first eligible cached intelligence result is free; otherwise calls cost $0.003 USDC through x402. | Read-only |
| otto_holder_analytics | Read holder analytics for a Base ERC-20 token: total holders with 24h, 3d, 7d and 30d holder-count change, whale-tier distribution, the acquisition mix (swap, transfer or airdrop), top-10, 25, 50 and 100 supply share, labelled top holders with top-1, 5, 10 and 20 concentration and the contract-held share, and an AI concentration-risk read. Holder data only; not a recommendation. Hosted access: the first eligible cached intelligence result is free; otherwise calls cost $0.03 USDC through x402. | Read-only |
| otto_insider_trades | Read parsed SEC Form 4 insider transactions for a US ticker, including purchase/sale counts, dollar values, roles, and net P/S balance. Filing scanner only; not a recommendation. Hosted access: the first eligible cached intelligence result is free; otherwise calls cost $0.003 USDC through x402. | Read-only |
| otto_institutional_holdings | Read the latest SEC 13F-HR top positions for an institutional manager by CIK or manager ticker, with amendments applied. Ownership data only; not a recommendation. Hosted access: the first eligible cached intelligence result is free; otherwise calls cost $0.003 USDC through x402. | Read-only |
| otto_lp_collect_userop | Protected same-account Uniswap V3 guarded collection on Base. Read availability, prepare and explicitly confirm one operation, or read/reconcile it. May collect owed principal and fees; profit remains unknown. Account upgrade is separate. Current owner authority, reviewed guard and provider policy are required. Unknown delivery retains the original operation; no replacement is allowed. Preparation and simulation are not funded execution. | Destructive |
| otto_material_events | Read up to 20 Form 8-K material events a US-listed company filed in the last 90 days (flagged `truncated` when there were more), each tagged with the SEC’s own numbered item codes and titles, for example 1.01 material agreement, 1.05 cybersecurity incident, 2.06 impairment, 3.01 delisting notice and 5.02 officer or director change. The event date and the filing date are kept separate, amendments are labelled, and EDGAR links are included; earnings-only filings are excluded and counted. The list may be empty when there were no material filings in the window; that answer is charged. Public-domain SEC EDGAR data; not a recommendation. Hosted access: the first eligible cached intelligence result is free; otherwise calls cost $0.003 USDC through x402. | Read-only |
| otto_muse_autopay_availability | Manage same-wallet research autopay. Enrollment needs a CDP-authenticated pending reservation; capability is returned once. Secret-bearing input/output must not be logged. | Read-only |
| otto_muse_autopay_enroll | Manage same-wallet research autopay. Enrollment needs a CDP-authenticated pending reservation; capability is returned once. Secret-bearing input/output must not be logged. | Changes data |
| otto_muse_autopay_prepare | Manage same-wallet research autopay. Enrollment needs a CDP-authenticated pending reservation; capability is returned once. Secret-bearing input/output must not be logged. | Changes data |
| otto_muse_autopay_revoke | Manage same-wallet research autopay. Enrollment needs a CDP-authenticated pending reservation; capability is returned once. Secret-bearing input/output must not be logged. | Changes data |
| otto_muse_autopay_sign | Sign one exact allowlisted Base-USDC research payment under an existing bounded capability. Never sends it. Never retry an uncertain signing attempt with a new nonce. | Changes data |
| otto_muse_autopay_status | Manage same-wallet research autopay. Enrollment needs a CDP-authenticated pending reservation; capability is returned once. Secret-bearing input/output must not be logged. | Read-only |
| otto_native_yield_userop | Protected native protocol action. Read availability, review and confirm native scope, prepare, reviewGas for current payer and network estimate, and explicitly confirm one operation, or read/reconcile/revoke native consent. Account upgrade is separate. Source activation and current owner authority are required. Unknown delivery retains the original operation; no replacement is allowed. A preparation or simulation is not funded execution. | Destructive |
| otto_news_recaps | Read a concise crypto market recap with ranked stories, source links where available, analysis window and freshness. A cached result can use the hosted free allowance; a cold or unavailable read returns a payment challenge without generating a recap for free. Stale-but-servable cached results retain their upstream freshness and degraded indicators. Market context only; not a recommendation. Hosted access: the first eligible cached intelligence result is free; otherwise calls cost $0.003 USDC through x402. | Read-only |
| otto_pm_crypto | Read high-volume open BTC, ETH, and crypto Polymarket markets with current outcome probabilities and market context. Event-probability data only; not a recommendation. Hosted access: the first eligible cached intelligence result is free; otherwise calls cost $0.001 USDC through x402. | Read-only |
| otto_pm_markets | Read the highest-volume open Polymarket markets with live outcome probabilities, bid/ask context, liquidity, volume, and end dates. Event-probability context only; not a recommendation. Hosted access: the first eligible cached intelligence result is free; otherwise calls cost $0.001 USDC through x402. | Read-only |
| otto_pools_search | Search DEX pools on Base, Ethereum, Solana, Polygon, BSC, Arbitrum, Optimism and Avalanche by token symbol, name or contract address. Returns each pool address, DEX, USD price, 24h volume, liquidity (TVL), FDV, 24h price change and 24h transaction count as flat numbers. The list may be empty when nothing matches; that answer is charged. Pool discovery only; not a recommendation. Hosted access: the first eligible cached intelligence result is free; otherwise calls cost $0.001 USDC through x402. | Read-only |
| otto_prepare_bridge | Prepare, decode, and verify an unsigned cross-chain native-USDC bridge construction aid for the caller-owned EOA or Safe, over the enumerated v1 Circle-CCTP route set (Ethereum, Polygon, Base, Arbitrum, Avalanche); any other chain, token, or bridge route is refused by name. The envelope's valid_until bounds freshness and is committed to the artifact digest; the signer account nonce is the on-chain replay boundary, and this tool cannot guarantee single execution. Returns ordered allowance-reset, approval, and call steps on the source chain only; never signs or submits. Every envelope from this server is valid for 300 seconds from construction (valid_until); a stale envelope is refused by the verifier — request a fresh one. | Read-only |
| otto_prepare_polymarket_order | Prepare and verify an unsigned Polymarket CTF Exchange V2 limit order (GTC) for the caller-owned Polygon EOA, with Otto's builder code stamped inside the EIP-712 order struct and re-asserted on the exact digest the signer will sign. The price must be an exact multiple of the market's live minimum tick size and the size at or above its published minimum. The envelope's valid_until bounds freshness and is committed to the artifact digest; the exchange's own order hash is the replay boundary, and this tool cannot guarantee single execution. Returns order args and typed data only; never signs or submits, holds no CLOB credentials, and touches no collateral or allowance. Every envelope from this server is valid for 300 seconds from construction (valid_until); a stale envelope is refused by the verifier — request a fresh one. | Read-only |
| otto_prepare_stock_buy | Prepare the EXACT otto_prepare_swap pair (envelope + prepareInput) that buys one of the executable Coinbase B20 tokenized equities on Base with USDC, as a LI.FI route through the fenced diamond whose receiver is the signing account. The token comes from the registry row named by executableEquityId and is never an input; the caller's registryCommitment must equal the commitment recomputed over the current record. The WORST PERMISSIBLE FILL (amount over the route's own floor) is checked against the equity's own Chainlink total-return mark and refused when it exceeds the pinned tolerance, or when the feed is frozen (> 24 h). Returns the pair unchanged plus a preview; never signs or submits. New Model B delegated trading is retired, including under existing grants: otto_submit_under_delegation refuses this pair. Preparation does not authorize execution. Every envelope from this server is valid for 300 seconds from construction (valid_until); a stale envelope is refused by the verifier — request a fresh one. | Read-only |
| otto_prepare_swap | Prepare, decode, and verify an unsigned same-chain EVM ERC20 swap construction aid for the caller-owned EOA or Safe. The envelope's valid_until bounds freshness and is committed to the artifact digest; the signer account nonce is the on-chain replay boundary, and this tool cannot guarantee single execution. Returns ordered allowance-reset, approval, and call steps only; never signs or submits. Every envelope from this server is valid for 300 seconds from construction (valid_until); a stale envelope is refused by the verifier — request a fresh one. | Read-only |
| otto_prepare_yield_deposit | Prepare the EXACT otto_prepare_swap pair (envelope + prepareInput) that deposits USDC into one of the executable Morpho vaults from the Yield Copilot registry, as a LI.FI position-acquisition route (which may buy shares or compose a protocol deposit) whose output token is the vault's ERC-4626 share token and whose receiver is the signing account. The vault comes from the registry row named by executableMarketId and is never an input; the caller's registryCommitment must equal the commitment recomputed over the current record. The quoted shares are checked against the vault's own previewDeposit and refused when they fall short by more than the pinned tolerance. Returns the pair unchanged plus a preview; never signs or submits. New Model B delegated trading is retired, including under existing grants: otto_submit_under_delegation refuses this pair. Preparation does not authorize execution. Every envelope from this server is valid for 300 seconds from construction (valid_until); a stale envelope is refused by the verifier — request a fresh one. | Read-only |
| otto_prepare_yield_withdraw | Prepare the EXACT otto_prepare_swap pair (envelope + prepareInput) that redeems vault shares from one of the executable Morpho vaults in the Yield Copilot registry back to USDC in the signing account, as a LI.FI exit route (which may sell shares or compose a protocol redemption) whose input token is the vault's ERC-4626 share token. The vault and the asset come from the registry row named by executableMarketId and are never inputs; the caller's registryCommitment must equal the commitment recomputed over the current record. The quoted USDC is checked against the vault's own previewRedeem and refused when it falls short by more than the pinned tolerance. Returns the pair unchanged plus a preview; never signs or submits — submit the pair through otto_submit_under_delegation, which admits a withdraw only under fence v2 and a permission minted under cap ruleset v2, values it at zero against the per-swap cap (it returns the person's own assets), and bounds it by the engine's share cap. Every envelope from this server is valid for 300 seconds from construction (valid_until); a stale envelope is refused by the verifier — request a fresh one. | Read-only |
| otto_proposed_insider_sales | Read the SEC Form 144 notices of proposed insider sales for a US ticker, which are filed before the Form 4 that reports an executed trade: who intends to sell, the units, the filer’s own market-value estimate, the broker, the approximate sale date and any Rule 10b5-1 plan dates. Up to the latest 20 notices in a 90-day lookback, which may be fewer. The list may be empty when no notices were filed in the window; that answer is charged. A notice is not a completed trade and may never be executed. Public-domain SEC EDGAR data; not a recommendation. Hosted access: the first eligible cached intelligence result is free; otherwise calls cost $0.005 USDC through x402. | Read-only |
| otto_rh_season | Scan rug-screened Robinhood Chain (4663) movers with honeypot filters and per-token risk flags. Market context only; not a pick, recommendation, or trade instruction. Hosted access: the first eligible cached intelligence result is free; otherwise calls cost $0.001 USDC through x402. | Read-only |
| otto_sponsored_account | Protected account action: availability, prepare, reviewGas for current gas payer and estimate, explicit submit, owned read or reconcile. Gas refresh is read-only planning and requires new confirmation before any send. Wallet upgrade is separate. Sponsorship requires a reviewed source activation; current availability is authoritative. A missing submission response is unknown and must never cause a replacement submission. | Destructive |
| otto_stock_pools | Find the DEX pools a tokenized US stock or ETF is actually a member of, on Robinhood Chain, Base, BNB Chain or Solana. Returns each pool id (Uniswap v4 pool ids kept distinct from v3 pool addresses), DEX and version, which side the asset is on, the counterpart token with an evidence-backed classification (verified stock, verified stablecoin, or unclassified), reported USD liquidity and 24h volume, 24h transaction count, pool creation time, and the source coverage limits. Membership discovery only: a provider-covered observation rather than a complete census, no APR and no execution support, and the asset’s own 24h return is reported only from pools where it is the base token. Identify the asset by address when a ticker names two deployments on one chain — that spelling is refused rather than resolved to one of them. Not a pairing recommendation. Hosted access: the first eligible cached intelligence result is free; otherwise calls cost $0.001 USDC through x402. | Read-only |
| otto_submit_under_delegation | New Model B delegated trading is retired: swaps, stock buys and yield deposits are refused with DELEGATION_TRADING_RETIRED, including under old grants. The prepare-only tools remain available. This retained tool can submit a qualified vault withdrawal and replay an existing terminal result. Arguments: { userId, envelope, prepareInput (with slippage.minAmountOut) }, validated after caller authentication using the `x-otto-delegation-auth` header. Withdrawal identity comes from the fully verified plan's registered share input, never a caller operation label: output must be USDC, spender and share amount must satisfy the withdrawal fence, receiver must be the user's CDP account, and both fence v2 and confirmed ruleset-v2 consent are required. All existing grant, expiry, cap-record, replay-binding, journal and worker-guard checks remain. No new trading plan is signed, funded or submitted. The withdrawal's reset, approval and call are submitted sequentially with canonical receipts and allowance clearing on halt. Uncertain prior operations are never retried here: use delegation operations/reconciliation. Status, revoke and independently qualifying exits remain available. Shared Muse permissions use their separate tools. | Destructive |
| otto_token_security | Screen a token contract with GoPlus across 8 chains for honeypot, rug-pull and scam signals: can’t-sell traps, hidden mint functions, malicious buy and sell taxes, and holder concentration. The chain defaults to Base (8453). Paid-only, including the first call: this read has no warm cache behind the hosted free allowance. A screen of known risk signals, not a guarantee that a token is safe and not a recommendation. Hosted access: paid-only; each call costs $0.001 USDC through x402 and preserves the free allowance. | Read-only |
| otto_tokenized_equities | Scan the live registry of US equities and ETFs tokenized on Robinhood Chain (4663): symbol, canonical token address, decimals, the executable buy price a live route returns, the catalog reference price and the deviation between them, plus a verifiable tradability signal. An optional thesis returns a relevance-ranked shortlist with a match reason per row. Data only; not a recommendation or executable quote. Hosted access: the first eligible cached intelligence result is free; otherwise calls cost $0.001 USDC through x402. | Read-only |
| otto_tokenized_stock_movers | Read the day movers among tokenized US stocks and ETFs on two rails in one call: Robinhood Chain (4663) and the Coinbase-issued Base B20 tokens, keyed by token address. Gainers and losers are ranked by the underlying stock’s real day-over-day change against the prior NYSE close, with per-rail coverage counts. A token with no listing is named with its reason under `excluded`; a token that cannot be quoted at the time is counted as uncovered, not named. Off-hours values freeze, and a tokenized share can trade at a premium or discount to the underlying. Refreshed every 15 minutes. Paid-only, including the first call: the movers are built from licensed Finnhub quote data. Market context only; not a recommendation. Hosted access: paid-only; each call costs $0.003 USDC through x402 and preserves the free allowance. | Read-only |
| otto_x_recipes | Return Otto X's live X Layer recipe menu — each recipe's path, price, and the X Layer (eip155:196) payment requirement decoded from its unpaid 402 challenge: token asset, issuer name/version, payTo, and a copy-paste curl. Settles in USD₮0 / USD Coin / Global Dollar on X Layer via the PAYMENT-SIGNATURE header. Always free and read-only; never signs or pays and does not consume the free intelligence call. | Read-only |
Change history
No changes since the first observation. The first snapshot is the baseline.
| Source | Listing | First seen | Last seen | Versions |
|---|---|---|---|---|
| Official MCP Registry | services.ottoai/otto | 2 Oct 2026 | 3 Oct 2026 | 1 |