Volante
Routes to the best predicted fit from configured metadata/evidence after hard-capability filtering.
The current version, v0.10.0, was published to the official MCP registry on 2026-08-15. It is distributed as volante on PyPI, filed under Other by this index, and declares 85 environment variables. Removals and unreachable sources are measured across every server this index tracks, contract drift across the servers that answer in consecutive snapshots; the index's current counts put this record in context.
Using Volante in Claude, Cursor, Gemini CLI, Cline, or Zed?
MCP tool contracts can change remotely with no version bump. The mcpindex gate pins each contract and HOLDs the call when it drifts-before your agent acts. Zero credentials. This is not the package install for this server itself (use Install this server for that).
Rewrites your MCP host config so each server launches behind the gate. Inspect first: curl -fsSL https://mcpindex.ai/install.sh | less
uv tool install mcpindex-gate && mcpindex-config-wireSemantic screen found no manipulation pattern in the description. Conformance probe not yet run.
mcpindex.integrity.descriptionpassINFOevidence“No malicious instructions found”via static_description
- - Semantic screen only - the deterministic conformance probe has not run on this server
- - Confidence is reported but not yet calibrated (v1)
- - Screen reads the tool description, not the live behavior
- - advisory
- - registry description only no input schema
- - screen model 8b
- - Still current: the description we screened is unchanged, re-checked against the registry
- - The registry listing (version, packages, links) changed after this screen ran - the description we assessed did not
Semantic screen: an LLM judge reads the tool description for hidden instructions (status PARTIAL). A pass means the description is not lying, not that the tool is safe: a high-capability tool with an honest description still warrants caution. The deterministic conformance probe has not been run on this server yet, so the screen here is semantic-only. Posture: advisory. Confidences are reported but not yet calibrated (calibrated=false at v1). Full verdict history is not shown on this page.
Own this server? Screen its description →
That verdict was true at screening time (snapshot 2026-09-10).
Contracts can change after screening, with no version bump. The gate pins Volante’s tool contracts on first sight and holds any silent change before your agent acts - the check that keeps being true on Tuesday.
See your first HOLD in 2 minutes →
Related: how to trust an MCP server · screen before install · silent contract drift
People vet a server before wiring it in. One line on your project site or docs answers that with an independent record: screening verdict, registry provenance, contract drift history. It stays current as new screens and drift events land.
[Independent trust record for Volante](https://mcpindex.ai/server/io-github-ribato22-volante) - screening verdict, registry provenance, and contract drift monitoring.<a href="https://mcpindex.ai/server/io-github-ribato22-volante">Independent trust record for Volante</a> - screening verdict, registry provenance, and contract drift monitoring.A live verdict badge for your README or listing. It reflects the current screen, links back here, and updates when the verdict does.
[](https://mcpindex.ai/server/io-github-ribato22-volante)<a href="https://mcpindex.ai/server/io-github-ribato22-volante"><img src="https://mcpindex.ai/api/v1/badge/io-github-ribato22-volante" alt="mcpindex verdict" height="20" /></a>ANTHROPIC_API_KEYAnthropic API key.
ANTHROPIC_MODELSComma-separated Anthropic wire model ids.
ANTHROPIC_NAMESOptional comma-separated canonical model ids.
ANTHROPIC_STRENGTHSShared comma-separated routing strengths.
ANTHROPIC_CONTEXTShared context-window tokens.
ANTHROPIC_MAX_OUTPUTShared maximum output tokens.
ANTHROPIC_TOOLSDeclare tool-call support (1 or 0).
ANTHROPIC_COST_INShared USD per 1k input tokens.
ANTHROPIC_COST_OUTShared USD per 1k output tokens.
ANTHROPIC_TIERShared capability tier from 1 to 4.
MOONSHOT_API_KEYMoonshot API key.
MOONSHOT_BASE_URLMoonshot OpenAI-compatible base URL.
MOONSHOT_MODELSComma-separated Moonshot wire model ids.
MOONSHOT_NAMESOptional comma-separated canonical model ids.
MOONSHOT_STRENGTHSShared comma-separated routing strengths.
MOONSHOT_CONTEXTShared context-window tokens.
MOONSHOT_MAX_OUTPUTShared maximum output tokens.
MOONSHOT_TOOLSDeclare tool-call support (1 or 0).
MOONSHOT_COST_INShared USD per 1k input tokens.
MOONSHOT_COST_OUTShared USD per 1k output tokens.
MOONSHOT_TIERShared capability tier from 1 to 4.
OLLAMA_BASE_URLLocal Ollama OpenAI-compatible base URL.
OLLAMA_API_KEYOptional credential for the Ollama endpoint.
OLLAMA_MODELSComma-separated Ollama wire model ids.
OLLAMA_NAMESOptional comma-separated canonical model ids.
OLLAMA_STRENGTHSShared comma-separated routing strengths.
OLLAMA_CONTEXTShared context-window tokens.
OLLAMA_MAX_OUTPUTShared maximum output tokens.
OLLAMA_TOOLSDeclare tool-call support (1 or 0).
OLLAMA_COST_INShared USD per 1k input tokens.
OLLAMA_COST_OUTShared USD per 1k output tokens.
OLLAMA_TIERShared capability tier from 1 to 4.
CLAUDE_CODE_ENABLEDSet to 1 to enable the logged-in Claude Code CLI.
CLAUDE_CODE_MODELSComma-separated Claude Code model ids.
CLAUDE_CODE_TIERShared capability tier from 1 to 4.
CLAUDE_CODE_MAX_OUTPUTShared maximum output tokens.
CLAUDE_CODE_TIMEOUTPer-call timeout in seconds.
CLAUDE_CODE_SYSTEM_PROMPT_MODESystem-prompt mode: replace or append.
CODEX_ENABLEDSet to 1 to enable the logged-in Codex CLI.
CODEX_MODELSComma-separated Codex model ids.
CODEX_TIERRequired capability tier from 1 to 4 when enabled.
CODEX_CONTEXTShared context-window tokens.
CODEX_MAX_OUTPUTShared maximum output tokens.
CODEX_COST_INShared API-equivalent input valuation.
CODEX_COST_OUTShared API-equivalent output valuation.
CODEX_TIMEOUTPer-call timeout in seconds.
OPENAI_COMPAT_BASE_URLCompatible slot 1 base URL.
OPENAI_COMPAT_KEYCompatible slot 1 API key.
OPENAI_COMPAT_MODELCompatible slot 1 wire model id.
OPENAI_COMPAT_NAMECompatible slot 1 canonical model id.
OPENAI_COMPAT_STRENGTHSCompatible slot 1 comma-separated strengths.
OPENAI_COMPAT_CONTEXTCompatible slot 1 context-window tokens.
OPENAI_COMPAT_MAX_OUTPUTCompatible slot 1 maximum output tokens.
OPENAI_COMPAT_TOOLSCompatible slot 1 tool-call support (1 or 0).
OPENAI_COMPAT_COST_INCompatible slot 1 input cost.
OPENAI_COMPAT_COST_OUTCompatible slot 1 output cost.
OPENAI_COMPAT_TIERCompatible slot 1 capability tier.
OPENAI_COMPAT_2_BASE_URLCompatible slot 2 base URL.
OPENAI_COMPAT_2_KEYCompatible slot 2 API key.
OPENAI_COMPAT_2_MODELCompatible slot 2 wire model id.
OPENAI_COMPAT_2_NAMECompatible slot 2 canonical model id.
OPENAI_COMPAT_2_STRENGTHSCompatible slot 2 comma-separated strengths.
OPENAI_COMPAT_2_CONTEXTCompatible slot 2 context-window tokens.
OPENAI_COMPAT_2_MAX_OUTPUTCompatible slot 2 maximum output tokens.
OPENAI_COMPAT_2_TOOLSCompatible slot 2 tool-call support (1 or 0).
OPENAI_COMPAT_2_COST_INCompatible slot 2 input cost.
OPENAI_COMPAT_2_COST_OUTCompatible slot 2 output cost.
OPENAI_COMPAT_2_TIERCompatible slot 2 capability tier.
OPENAI_COMPAT_3_BASE_URLCompatible slot 3 base URL.
OPENAI_COMPAT_3_KEYCompatible slot 3 API key.
OPENAI_COMPAT_3_MODELCompatible slot 3 wire model id.
OPENAI_COMPAT_3_NAMECompatible slot 3 canonical model id.
OPENAI_COMPAT_3_STRENGTHSCompatible slot 3 comma-separated strengths.
OPENAI_COMPAT_3_CONTEXTCompatible slot 3 context-window tokens.
OPENAI_COMPAT_3_MAX_OUTPUTCompatible slot 3 maximum output tokens.
OPENAI_COMPAT_3_TOOLSCompatible slot 3 tool-call support (1 or 0).
OPENAI_COMPAT_3_COST_INCompatible slot 3 input cost.
OPENAI_COMPAT_3_COST_OUTCompatible slot 3 output cost.
OPENAI_COMPAT_3_TIERCompatible slot 3 capability tier.
VOLANTE_QUALITY_PROFILES_FILELocal strict-JSON quality-evidence file.
VOLANTE_MODEL_OVERRIDES_FILELocal strict-JSON per-model metadata override file.
VOLANTE_FETCH_ALLOWLISTComma-separated domains that enable fetch_url.
VOLANTE_READ_ROOTRoot directory that enables confined read_file.
VOLANTE_SANDBOXAgentic execution sandbox. Unset auto-selects docker when available and otherwise disables code execution; subprocess opts in to unisolated execution.
VOLANTE_MAX_SUBSCRIPTION_CALLSPhysical subscription calls allowed per run.
Buy travel eSIMs, gift cards and mobile top-ups with crypto — user confirms before any order.
Give your AI agent a spending limit: approval controls and single-use virtual cards.
Condition watcher for AI assistants — wait for ports, files, URLs, processes, and more