Changelog

Changelog

Product updates from 0200project, newest first.

The impersonation check now says how far it reaches

A risk flag warns you when a token wears a known token’s ticker from the wrong address. It was checking against a list of 19 tokens and the page describing it never said so — which meant a token outside that list came back with no flag, and no flag reads like innocence.

  • The list is now 116 tokens, our own 19 plus the Base entries of the published Uniswap token list.
  • It is a union, not a swap, and that was the whole decision. Moving wholesale to the published list would have added 97 tokens and quietly dropped 9 that only we carried: USDS, sUSDS, GHO, wstETH, weETH, rETH, ezETH, tBTC and LBTC. Two of those are Bitcoin wrappers, which is the exact category the problem was found in. That would have been a regression wearing the shape of an upgrade.
  • Each list keeps its own date. When the flag fires it names which list matched and when that list was read — the published one on September 9, ours verified on August 19. Averaging two dates into one would be a freshness claim we cannot support.
  • The bound is now written on the page. A token whose symbol is not on the list is not checked, and the absence of this flag is not a statement that a token is genuine. That sentence is the actual change; the extra 97 tokens are the smaller half.

Found while measuring how many tokens the check covered. A coverage number cannot be computed without naming what it is coverage of, and the missing disclosure fell out of the arithmetic.

The health check now reports whether our safety feeds are current

Our drainer-address check merges two public blocklists. The health endpoint reported both as healthy because both answered when asked — and one of them had not changed since November 2020.

  • Reachable and current are different properties, and only the first was being measured. A frozen file returns HTTP 200 exactly like a maintained one.
  • Each feed now reports its own last change on /healthz, as current, stale or unknown, with the commit it was read at so anyone can check the same bytes.
  • Unknown is its own answer. If we cannot read a feed’s date, it does not quietly count as fresh.
  • One stale feed makes the set stale, because a current feed does not supply the addresses a frozen one is missing.

base-tx-explain is now base-transaction-decoder

Same tool, same endpoint, same schema. Only the name changed, and only so that it can be found.

  • Nothing you have configured breaks. Clients connect by URL, and the URL is unchanged: https://api.0200project.com/mcp. The name in your own config is a label you chose; it keeps working exactly as it is.
  • Why rename at all, the MCP registry matches search terms against the server name only, not its description or title. Ours was base-tx-explain, so the only words that could find us were “base”, “tx” and “explain”. A search for “transaction” or “decoder”, what this actually is, returned us nowhere at all.
  • The registry entry is now io.github.0200project/base-transaction-decoder. The old listing has been retired rather than left to rot.
  • The repository keeps its name at github.com/0200project/base-tx-explain, so existing links, clones and forks are untouched.

A bigger free tier, and one that resets

The free tier went from 10 calls per IP address ever to 50 calls per IP address every day.

  • 50 free calls, not 10, one person’s curiosity no longer spends a whole office’s trial.
  • A 24-hour rolling window, not 30 days: free calls are metered per IP (IPv6 collapses to the /64), so a household, office, VPN exit or mobile carrier NAT shares one counter. Under the old window a shared address that ran out stayed walled for a month; now it recovers the next day.
  • Why it changed, a genuine first-time visitor could be refused their very first call because someone else on the same address had already used the allowance. Someone who has never seen the product work does not learn that it is limited; they learn that it is broken.

REST rail and the $9 pass

Two new ways to call and pay for the same deterministic decode, plus a metering fix.

  • REST endpoint: POST /explain with a transaction hash returns the explanation as plain JSON. Same decode as MCP, standard x402 flow, shared free tier.
  • The $9 pass: 30 days, up to 10,000 calls, 60 calls/minute: one x402 payment via POST /pass or the buy_pass tool returns a bearer token. No account; not a subscription, nothing can auto-renew, and expiry returns calls to the standard pay-per-call flow.
  • Free-tier persistence: free-call counts now survive server restarts, so the free tier meters correctly across deploys.

v0.1.1: live playground, usage ledger, agent discovery

  • Persistent usage ledger with lifetime counters, published on /healthz and a token-protected /stats.
  • CORS enabled on the endpoint, so the playground and status page now call production live from the browser.
  • Agent discovery surface: llms.txt, robots.txt, a sitemap, and an OpenAPI document with a servers block.
  • Free-tier hardening: spoofed-IP fix, batch-request guard, and free calls refunded on server-fault errors.
  • Paid-call settlement is now cancelled when a call errors, buyers never pay for failures.

base-tx-explain v0.1.0

Our first tool is live: deterministic Base transaction decoding for AI agents. One MCP tool, explain_transaction(tx_hash), returns a strict JSON explanation of any Base mainnet transaction, same input, same output, no LLM in the response path.

  • Base mainnet transaction decoding across ~40 builtin event formats, ERC-20/721/1155, Uniswap V2/V3/V4, Seaport, Aave V3, OP-stack bridges, ERC-4337, EAS, and more.
  • MCP streamable-HTTP endpoint at api.0200project.com/mcp.
  • x402 pay-per-call support, $0.02 in USDC on Base, 10 free calls per client.
  • Risk flags backed by Sourcify verification and public drainer blocklists.
  • Listed in the official MCP registry as io.github.0200project/base-tx-explain.
  • Validated against 100 random live Base transactions before release, 95 decoded to a specific action type, zero crashes.

Follow the repository on GitHub for release notifications.