deployed_code_history
Changelog
What changed in mcp.daisycon.com, newest first.
Added
- Launched the beta of the Advertiser, Publisher, and Campaigns MCP servers.
Added
- Each hosted server now publishes its own official MCP registry entry live, at `/<slug>/server.json`, including its icon.
- A new `/.well-known/ai-catalog.json` document lists every hosted server for AI Catalog crawlers, alongside the existing `llms.txt` and `/mcp.json`.
Added
- Published a security contact and vulnerability disclosure policy at `/.well-known/security.txt`.
Fixed
- Fixed the error page sometimes ignoring a request for JSON and returning an HTML page instead.
Fixed
- Fixed an authorization failure showing as raw text in your browser instead of returning you to the app that requested it.
Security
- Fixed an issue where using an old sign-in link could have signed you out of your other active sessions too.
- Closing a way a malicious redirect address could impersonate a trusted local address to bypass a security check.
Fixed
- Server names on the home page are no longer marked as top-level headings, so screen readers and search engines read the page's outline correctly.
- Home page styling validated for Firefox.
Security
- Closing a way an attacker could have tricked someone into granting access without seeing the consent screen.
- A tool call could reach a different piece of data than the one it named, but never another account's data.
- A server could stop responding to every request, depending on how its own upstream API is described.
Changed
- The home page now shows each hosted server as its own card instead of a plain list.
Added
- Visiting the changelog with a .md ending now leads straight to the changelog instead of a page-not-found error.
Changed
- Each changelog entry now shows a colored label for its kind of change (added, changed, fixed, and so on), making the list easier to scan.
- Server pages that list a server's available tools got a cleaner look, making tools easier to browse and filter.
Changed
- The machine-readable server list at /mcp.json is now shaped as ready-to-use MCP client configuration, so it can be added directly instead of being retyped by hand.
- The robots.txt file now states that this site's content may be used for search and by AI assistants answering questions, but not for training AI models.
Added
- Clients can now sign in with a Client ID Metadata Document (CIMD), a document they publish about themselves, instead of having to register first.
Changed
- Apps that sign in through a callback on your own computer now work whichever port they happen to use, instead of only the one they first registered.
- The authorization screen now names who is asking for access, and names the server the same way your MCP client does, so there is one label to recognise instead of two.
- Server names on the website and in server listings now end with "(MCP server)" instead of "MCP", making clearer that this describes a kind of service rather than being part of the name.
Fixed
- Tool lists are sent compressed again on servers where that had quietly stopped, so they download much faster there too.
- A client that sends several requests together now gets an answer to each one, instead of the whole group being turned down.
Changed
- When the Daisycon API asks for a pause (rate limit) and says how long, the assistant is now told the wait rather than retrying straight into another refusal.
- Each server now carries both a short machine name, such as `daisycon-publisher`, and a readable title, `Daisycon | Publisher`. Pages, documents show the readable one, and MCP clients receive the short one to identify the MCP server.
- The machine-readable server index now lives at /mcp.json; /.well-known/mcp.json redirects there instead of the other way around.
Fixed
- When the Daisycon API turns a request down, the assistant now reads the reason and can correct the call itself, instead of the request simply failing.
- Approving access on the authorization screen now always continues to Daisycon sign-in on the first try, instead of sometimes doing nothing and then showing an error on a second attempt.
- Each server now identifies itself to a client with a short name the client accepts, instead of one carrying the spaces and punctuation of its display title. The display title is unchanged.
Security
- A tool call carrying a parameter that was never declared, missing one it required, or of the wrong type is now refused with a clear error instead of being silently accepted or partly ignored.
Changed
- The servers now explain how to search by category, locale, and similar campaigns, and note that "program" and "campaign" mean the same thing.
- Campaign search now lists the common locale identifiers, so a client can narrow by language and country without first fetching a campaign to find one.
- Campaign search now states how filters combine: a campaign matches any one of the values given for a single filter, and must satisfy every filter given.
- A tool's parameters now reflect the API's parameter names right away if renamed, instead of showing the old name for up to a day.
- The advertiser server now states how to retrieve the advertiser identifier, the way the publisher server already does, so a client no longer has to ask for the account number before it can do anything.
- Campaign search now says that a search term of digits alone matches a campaign number exactly, where it used to describe every search term as a partial match.
- The publisher server now states that advertiser-side data lives on the advertiser server and needs its own sign-in, which the other servers already did.
- Every campaign found through campaign search now comes with three links that lead somewhere: its public page, the link a publisher signs up through, and the campaign inside the publisher portal. Before there was one link, to the campaign overview.
Fixed
- The earnings digest returns its summary again, where every request for one used to fail.
- Narrowing program opportunities to a category now returns that category, instead of ignoring the choice and ranking every program.
- A newly installed campaign search server now offers its search tool. The example settings it ships with named tools that do not exist, so it started with none.
- Turning the page on a filtered or category search no longer silently drops the filter and switches to the full unfiltered list; a page fetched without carrying its filters forward is refused instead.
- A pagination cursor is refused, rather than honored, once the tool it belonged to no longer looks the way it did when the cursor was issued.
Security
- A session interrupted while it was being saved could keep working without appearing in session_list or being revocable from it. That gap is closed.
Changed
- Tool lists and tool calls are faster, most of all on the biggest MCP servers.
- Tool lists are sent compressed to clients that accept them, so they download much faster.
- A call a client has no permission for is refused right away, instead of after a trip to Daisycon.
- Every published llms.txt now follows the standard llms.txt format, so agents find what they expect: one entry per server, and a page per server listing its permissions and its tools.
Fixed
- Clients using Model Context Protocol 2025-11-25, 2025-06-18, 2025-03-26 or 2024-11-05 can see that those versions still work. Only 2026-07-28 was listed before.
- A tool no longer disappears from the list because another user lacked permission for it.
- A call refused for lack of permission is no longer reported as a missing resource, so the client shows the reason and the permission to grant.
Security
- Only public pages may be cached, so one user's reply can never be handed to another.
- A reply from Daisycon that is too large is dropped instead of slowing the server down for everyone.
- Calls to Daisycon only go to addresses that were checked first.
Added
- Support for Model Context Protocol 2026-07-28. Clients on that version connect without a handshake and can ask a server what it offers in one request.
- Clients can skip downloading a tool list they already have when nothing in it changed.
Changed
- The servers speak Model Context Protocol 2026-07-28, 2025-11-25, 2025-06-18, 2025-03-26 and 2024-11-05, and pick a version per client. Clients on any of them keep working.
- A client asking for a version these servers do not speak is told which versions they do.
- Tool lists at /llms.txt and /llms-full.txt group tools by category instead of one long list.
Added
- One server can serve the tools of every other server here, so a single connection reaches them all.
- Those tools keep the permissions and the API of the server they come from, and carry that server's name in front, so nothing extra becomes reachable.
Changed
- Sign-in asks for the permissions of every server involved.
Added
- A public changelog: a page at /changelog, and plain text at /changelog.txt for agents.
- Active sessions can be listed and cancelled from the MCP client itself.
Added
- An icon and a tool overview page for every server.
- A machine-readable list of servers at /.well-known/mcp.json.
Changed
- The sign-in screen was refreshed and now explains what each permission means.
- Every server has its own permissions instead of sharing one list, and asks only for the ones it can use.
Added
- Hosting for several MCP servers at once, each with its own identity, credentials and tokens. Publisher now runs alongside an Advertiser server.
- A server type that works without signing in.
- A public list of every server, at the root, at /llms.txt and at /llms-full.txt.
Fixed
- Cancelling a sign-in now gives a clear answer instead of leaving the connection stuck.
Added
- A name, title and icon for every server.
Changed
- Account credentials are stored in a new, safer way.
Added
- A machine-readable list of servers at /llms.txt, so AI clients can find them and connect on their own.
Added
- Finer-grained permissions per tool.
- The permissions each server supports are published with its sign-in details.
Security
- Sign-in was strengthened with PKCE and stricter handling of credentials.
Added
- Paging for large result sets.
- More tools for the Publisher API.
Security
- Security headers on every response.
Added
- The Publisher MCP server, connecting to the Daisycon Publisher API with secure sign-in.