Changelog
Every change to the MCP server at /mcp - tools, inputs, results, keys and limits - newest first. What counts as a breaking change is set out in its policies.
A 401 from /mcp now carries WWW-Authenticate: ApiKey realm="mcp" instead of Bearer realm="mcp", error="invalid_token", which had sent some clients looking for an OAuth server. Keys are still accepted as Authorization: Bearer or X-API-Key.
Successful tool calls return structuredContent next to the unchanged JSON text, and tools/list publishes an outputSchema for each tool whose response is documented in the OpenAPI contract. Errors stay plain isError text.
tools/list returned 15 tools per page with a nextCursor, so clients that ignore the cursor never saw get_coin_markets, get_coin_technicals, get_liquidations_summary or calculate_dca. All 19 tools now come on one page.
get_exchange and get_exchange_trust_score had returned an internal error for every exchange since launch. Both now answer; inputs and result fields are unchanged.
Since 6 September, a tool that is switched off answered server_error (HTTP 500). It now returns endpoint_unavailable (HTTP 503): This endpoint is temporarily unavailable. again.
days was advertised with a default and minimum of 0, but 0 was always rejected. It is now 1-365 with no default; omit it for the current reading. The get_global_history description now states the point shape ({time, marketcap} or {time, volume}).
New unauthenticated /.well-known/mcp/server-card.json with serverInfo and the full tool definitions, cached for an hour, for registries that cannot scan a keyed server. It and /.well-known/mcp.json can now be read cross-origin.
/mcp now also accepts the MCP key as X-API-Key: YOUR_API_KEY, for clients and gateways that reserve Authorization for their own sign-in. When that header is sent it is the only key checked, and a pasted Bearer prefix is tolerated.
Failed authentication used to be capped at 30 attempts a minute per IP, after which every key behind that IP was refused. Now one key may fail 30 times a minute from one IP and one IP 300 times, and keys that authenticated in roughly the last 15 minutes are not blocked by the IP cap.
get_fear_greed (the headline reading and every interval) and get_global_market (fear_greed) now include index - the 0-100 index shown on Bitculator - next to the raw score, and the tool descriptions tell the model to quote index.
get_coin returned a fully diluted valuation of 0 for coins without a capped max supply. It now falls back to the total supply and is null when neither is known.
get_top_movers now ranks by the change itself (it was effectively by market cap) and its losers exclude coins flat at 0.00. get_prices with symbols returns one coin per symbol, the highest-ranked active one, and get_global_market reports BTC and ETH dominance as null rather than 0 when there is no market cap.
The initialize instructions now say market caps and volumes are JSON numbers (they had said decimal strings), the list_exchanges sort description gives the real default -volume, and get_exchange_trust_score notes that an unranked exchange has a null score and breakdown.
The server is listed in /apis.json and /.well-known/api-catalog, /.well-known/mcp.json gained status and changelog links, and /status.json reports an mcp component.
Breaking: /mcp accepts only keys created in the MCP console; Data API and widget keys get 401. MCP has its own Free (2,500 tool calls a month), Starter (50,000) and Pro (250,000) plans with 2, 5 and 10 key slots, its own billing and its own per-tool plan gates, and every account starts on Free. Quota and plan errors now name the MCP plan.
Every JSON-RPC request to /mcp - initialize, tools/list, ping and tool calls - now counts against the plan's burst limit of 30, 60 or 120 a minute, and going over returns HTTP 429. Only tool calls count toward the monthly quota.
Tool server errors included the internal error message. They now read server_error (HTTP 500): Internal server error.
From launch until this fix, every tool call in production returned server_error, because the server rejected its own internal data request as coming from an untrusted host.
/mcp went live over Streamable HTTP (POST only) with 19 read-only tools for Claude, Cursor, VS Code and any MCP client, from search_coins and get_coin to calculate_dca, returning the same data as the REST API. It used Data API keys, plans and quota, one tool call counting as one request, and /.well-known/mcp.json described it.
Removing or renaming a tool or an input is announced here at least six months ahead - see the deprecation policy. The server card at /.well-known/mcp.json links to this changelog.