gateway
warningsapp.duvera.ai
Governed AI actions with signed, verifiable receipts: free keyless reads, human-approved writes.
https://app.duvera.ai/mcpWebsiteNo authMCP 2025-03-26v1.0last checked 24 Aug 2026spoke MCP on 2 of 2 checks (30 days)initialize in 497 msHow to authenticate
Checked against the endpoint by our probe on 24 Aug 2026. These are the capabilities the server advertises, not a prediction about any particular client.
| Scheme | No auth |
|---|---|
| Protected-resource metadata | ✕Not found Without it a client has to guess where the authorization server lives. |
| Anonymous access | Handshake succeeds; 52 tools listable |
| Credentials demanded in prose | ✕bluesky__trending_get, duvera__dev_npm_package, duvera__dev_pypi_package, duvera__dev_stackoverflow_search, duvera__finance_crypto_price, duvera__finance_exchange_rates, duvera__food_recipe_search, duvera__food_restaurant_search, duvera__geo_geocode, duvera__news_search, duvera__news_top_stories, duvera__reference_dictionary, duvera__reference_public_holidays, duvera__time_now, duvera__travel_flight_search, duvera__weather_air_quality, duvera__weather_current, duvera__wiki_search, duvera__wiki_summary, hackernews__stories_top These tools are listed anonymously and their own descriptions ask for an account or key, but no challenge is issued — so a client has nothing to act on and the refusal arrives as a tool error. |
What the probe found
20 of the 52 tools listed anonymously say in their own descriptions that they need an account or a key (bluesky__trending_get, duvera__dev_npm_package, duvera__dev_pypi_package, duvera__dev_stackoverflow_search, duvera__finance_crypto_price, duvera__finance_exchange_rates, duvera__food_recipe_search, duvera__food_restaurant_search, duvera__geo_geocode, duvera__news_search, duvera__news_top_stories, duvera__reference_dictionary, duvera__reference_public_holidays, duvera__time_now, duvera__travel_flight_search, duvera__weather_air_quality, duvera__weather_current, duvera__wiki_search, duvera__wiki_summary, hackernews__stories_top), but the endpoint issued no WWW-Authenticate challenge. The requirement is stated only in prose, so a call reaches the tool and comes back as a tool error instead of an authorization step.
A cross-origin preflight came back without Access-Control-Allow-Origin, so the endpoint is reachable from native clients only — code running in a web page is stopped by the browser before a request is ever sent.
Tools
Contract history
Get alerted when this contract changes
Depend on this server? Leave an email and get a message when a probe records a change — a tool removed, an argument newly required, an enum narrowed. Alerts are being built; signing up is what tells us to hurry.
Prefer a feed reader? This page's contract changes are also an Atom feed.
Status badge
Status for a README, from the last probe — cached an hour, so up to seven hours behind the endpoint. Links back to this page.
[](https://mcpi.app/servers/gateway)Own this server?
Sign in to claim this listing by proving control of the endpoint.