Skip to main content
Glama

Audit another XRPL x402 origin

t54_peer_origin_verify
Idempotent

Audit another XRPL x402 origin

Read-only HTTP + XRPL RPC audit of a third-party origin (Domain, DID, Credential, catalog hash). Settlement is Hub/peer inbound to ASM payTo — not operator ignition. GET url must be https on a public host.

HTTP GET /x402/v1/peer-origin-verify (operationId peerOriginVerify). Paid routes may return HTTP 402 until the x402 broker settles on the configured rail.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
urlYesOther merchant origin or well-known URL (https only).
pay_toNoOptional T54 payTo r-address to pin.
identityNoOptional identity r-address to pin (otherwise discovered).
credential_typeNoQuery parameter `credentialType` for operation `peerOriginVerify` (GET /x402/v1/peer-origin-verify). max length 64; default: 'ASM-T54-PayTo'.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Added

TDQS

A3.9/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=false, idempotentHint=true, destructiveHint=false. The description adds meaningful behavioral context: it is a read-only audit, settlement is Hub/peer inbound to ASM payTo, and paid routes may return HTTP 402 until the x402 broker settles. This goes beyond the annotations and helps the agent anticipate non-success responses. No contradiction with annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is compact and front-loaded with the core purpose. The first sentence states the tool's function, and subsequent sentences add essential constraints (https, public host, endpoint path, 402 behavior). It is slightly dense with domain-specific terms but every sentence earns its place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a read-only audit tool with 100% schema coverage and no output schema, the description covers the key operational details: endpoint, method, settlement rail, and 402 behavior. It does not explain what the audit result contains, but without an output schema and with a read-only audit purpose, the description is reasonably complete. Minor gap: no mention of what 'audit' verifies beyond Domain, DID, Credential, catalog hash.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents all four parameters. The description adds a little context by mentioning the GET endpoint and operationId, and clarifies the url must be https on a public host, but it does not add substantial meaning beyond the schema. Baseline 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb ('Audit') and resource ('another XRPL x402 origin'), and clarifies it is a read-only HTTP + XRPL RPC audit of a third-party origin. It distinguishes itself from operator ignition by noting settlement is Hub/peer inbound to ASM payTo, which helps separate it from sibling tools like t54_x402_request or contract_audit, though it does not explicitly name a sibling.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives clear context: it is for auditing a third-party origin, not operator ignition, and requires an https public host. It also notes paid routes may return HTTP 402 until settlement, which is a useful when-to-expect behavior. It does not explicitly state when not to use this tool versus alternatives, but the third-party vs operator distinction provides usable guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources