← All servers

~Alter Identity

warnings

mcp.truealter.com

Identity infrastructure for the AI economy. Confirms if someone is known; returns inferred traits.

https://mcp.truealter.com/api/v1/mcpWebsiteOAuthMCP 2025-11-25v0.5.10last checked 24 Aug 2026spoke MCP on 4 of 4 checks (30 days)initialize in 564 ms

How to authenticate

Checked against the endpoint by our probe on 24 Aug 2026. These are the capabilities the server advertises, not a prediction about any particular client.

Scheme
OAuth
Issuer
https://truealter.com
Dynamic client registration
Advertised (RFC 7591)
Client ID Metadata Document
Not advertised
PKCE
S256
Grant types
authorization_code, refresh_token, client_credentials, urn:ietf:params:oauth:grant-type:device_code
Scopes
alter:level, assessment, earnings, email, identity_read, identity_write, matching, openid, profile
Protected-resource metadata
Published (RFC 9728)
Anonymous access
Handshake succeeds; 16 tools listable
Credentials demanded in prose
hello_agent, get_started, list_archetypes, alter_resolve_handle, register_autonomous_challenge, register_autonomous, describe_traits, describe_competencies, get_network_stats, alter_whoami

These tools are listed anonymously and their own descriptions ask for an account or key, but no challenge is issued — so a client has nothing to act on and the refusal arrives as a tool error.

Documentation
https://truealter.com/build

What the probe found

warningTools needing credentials are listed without a challenge

10 of the 16 tools listed anonymously say in their own descriptions that they need an account or a key (hello_agent, get_started, list_archetypes, alter_resolve_handle, register_autonomous_challenge, register_autonomous, describe_traits, describe_competencies, get_network_stats, alter_whoami), but the endpoint issued no WWW-Authenticate challenge. The requirement is stated only in prose, so a call reaches the tool and comes back as a tool error instead of an authorization step.

No CORS headers for browser-based clients

A cross-origin preflight came back without Access-Control-Allow-Origin, so the endpoint is reachable from native clients only — code running in a web page is stopped by the browser before a request is ever sent.

16 tools usable without signing in

The server exposes a public surface before authorization: hello_agent, get_started, list_archetypes, alter_resolve_handle, alter_presence_read, register_autonomous_challenge, register_autonomous, describe_traits, describe_competencies, get_network_stats, recommend_tool, golden_thread_status, thread_census, alter_whoami, alter_login_status, alter_verify.

Tools

alter_login_statusalter_presence_readalter_resolve_handlealter_verifyalter_whoamidescribe_competenciesdescribe_traitsget_network_statsget_startedgolden_thread_statushello_agentlist_archetypesrecommend_toolregister_autonomousregister_autonomous_challengethread_census

Contract history

24 Aug 2026v0.5.10first recorded contract

Get alerted when this contract changes

Depend on this server? Leave an email and get a message when a probe records a change — a tool removed, an argument newly required, an enum narrowed. Alerts are being built; signing up is what tells us to hurry.

Prefer a feed reader? This page's contract changes are also an Atom feed.

Status badge

Status for a README, from the last probe — cached an hour, so up to seven hours behind the endpoint. Links back to this page.

MCP status badge for ~Alter Identity
[![MCP status](https://mcpi.app/servers/alter-identity/badge.svg)](https://mcpi.app/servers/alter-identity)

Own this server?

Sign in to claim this listing by proving control of the endpoint.