booklint
Server Details
Checks an agent's trades, spend, bookings and offers against its owner's limits. Facts, not advice.
- Status
- Healthy
- Last Tested
- Transport
- Streamable HTTP · MCP 2025-06-18
- URL
TDQS
Scored across 2 tools
check_book (run rule checks) and get_sample (fetch example payloads) are mostly distinct, but check_book's sample=true parameter duplicates get_sample's purpose, creating a minor overlap that could confuse an agent about which to call.
Both tools use a clean verb_noun snake_case pattern (check_book, get_sample) with no inconsistent casing or verb styles.
Only 2 tools for a narrow check-a-book-against-rules service; each earns its place, but the surface is on the thin side and leans on one large multi-purpose check_book rather than a small set of focused tools.
check_book covers the core lifecycle (multiple input modes, verdicts, flags, coverage) and get_sample supplies testable examples, but there are no tools for managing or listing rulebooks/limits, leaving rule curation outside the surface.
Available Tools
2 toolscheck_bookCheck an agent's actions against its owner's limitsARead-onlyInspect
Deterministic rule checks of any agent's actions against the limits its owner wrote, the same as POST /v1/check. Send a trading book (snapshot and rulebook, optionally broker and journal) or an actions list with limits (per-transaction and daily spend caps, merchant allow and deny lists, refundability), or, BEFORE booking or subscribing, one offer with limits (Fine-Print Check: total price cap, mandatory fees over the headline price, refundability, free-cancellation window, auto-renewal, renewal price, trial length, and an optional page_text consistency scan; each rule answers MATCH, WARN, STOP or NOT_CHECKED with the figure found). Send plain text you already have. Do not send a URL; booklint will not fetch one. Returns verdict (FLAGGED, CLEAN, NOT_VERIFIED, REFUSED), coverage and flags. Each rule reports passed, failed or not checked; missing data is not checked, never assumed, and a result with zero flags is not a pass. Pass sample=true (sample 1, trading), sample="spend" (sample 2, purchasing and booking), sample="booking" (sample 3) or sample="subscription" (sample 4) with no key, never counted against the free caps, to see a full result. Without api_key the keyless free plan and its daily cap apply. Not advice; nothing is executed.
| Name | Required | Description | Default |
|---|---|---|---|
| as_of | No | The current UTC time (ISO 8601). Time rules use it; the server clock is never used. | |
| offer | No | One offer, as structured fields your agent extracted: merchant, currency, headline_price, line_items [{label, amount, mandatory}], refund {refundable, free_cancel_until}, subscription {auto_renews, renewal_price, renewal_interval, trial_ends}. Send with limits. | |
| broker | No | Optional broker export (desk checks). | |
| limits | No | The owner's limits: a rulebook (version, declared, rules). | |
| sample | No | true runs sample 1 (trading); "spend", "booking" or "subscription" runs sample 2, 3 or 4 instead. | |
| actions | No | An agent's actions: each {id, time (ISO 8601; days are UTC), amount, currency, merchant, refundable, kind}. Send with limits. | |
| api_key | No | Optional key (vdk_...). Same as the Bearer header. | |
| journal | No | Optional journal of claims (desk checks). | |
| rulebook | No | The agent's own rules. | |
| snapshot | No | The book: positions, cash, as_of (ISO 8601). | |
| page_text | No | Optional plain text copied from the offer page, at most 64 KB. Scanned for amounts and refund or renewal phrases. Send plain text you already have. Do not send a URL; booklint will not fetch one. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Goes well beyond the annotations: the keyless free plan has a daily cap, missing data is 'not checked, never assumed', 'a result with zero flags is not a pass', the verdict vocabulary is disclosed, and it states nothing is executed and that it will not fetch URLs. This is exactly the kind of behavioral framing readOnlyHint alone cannot convey.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loaded with purpose and well organized around the three input modes, and nearly every sentence carries information. It is a dense wall of text with some overlap between the sample guidance and the description body, so it is not maximally tight.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For an 11-parameter, nested-object, no-output-schema tool, the description compensates by explaining the return shape (verdict, coverage, flags and per-rule passed/failed/not-checked statuses). An agent has enough to call it correctly and interpret the result.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so baseline is 3, but the description adds real semantics: what each input shape means, which offer fields are evaluated (mandatory fees over headline price, free-cancellation window, auto-renewal, renewal price, trial length), that page_text must be text you already have rather than a URL, and that as_of is used instead of the server clock.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource ('deterministic rule checks of any agent's actions against the limits its owner wrote') and ties itself to a known endpoint (POST /v1/check). It also enumerates the three distinct input modes (book, actions+limits, offer+limits), so an agent can tell exactly what this tool does without reading the schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives explicit when-to-use guidance per mode: send a book or an actions list for post-hoc checks, or 'BEFORE booking or subscribing' send one offer for the Fine-Print Check. It names the alternative path (pass sample=... to see a full result) and the fallback behavior without api_key, so selection reasoning is complete.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_sampleGet a public sampleARead-onlyIdempotentInspect
Returns a public sample, the same as GET /v1/sample. name "trading" (the default) is sample 1, a trading agent's book (snapshot, rulebook, broker, journal), stamped now. name "spend" is sample 2, a purchasing and booking agent's actions and the limits its owner wrote. "booking" (sample 3, a hotel offer) and "subscription" (sample 4, a subscription checkout) are Fine-Print Check requests: an offer, limits, as_of and page text. Edit it and pass it to check_book.
| Name | Required | Description | Default |
|---|---|---|---|
| name | No | trading (default, sample 1), spend (sample 2), booking (sample 3) or subscription (sample 4). |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already declare readOnlyHint, idempotentHint and openWorldHint=false, so safety is covered; the description adds meaningful behavioral context by disclosing the concrete contents of each sample and that data is 'stamped now' (timestamped at request time). It does not describe how check_book consumes the edited payload or any size/pagination concerns.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loaded with the core statement and the sibling hand-off, then enumerates samples efficiently. It is dense with quoted literals and slightly long, but every clause carries information about a distinct sample.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
There is no output schema, and the description partially compensates by describing the shape of the returned data per sample. Combined with the annotations covering the read-only/idempotent profile, an agent has enough to call it correctly, though a brief note on the response envelope would make it fully complete.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is already 100% with an enum, but the description goes well beyond the schema by explaining what each value actually contains (trading = snapshot/rulebook/broker/journal; spend = actions and owner-written limits; booking/subscription = offer, limits, as_of, page text). This semantic mapping is exactly the value the schema cannot carry.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource ('Returns a public sample, the same as GET /v1/sample') and immediately disambiguates from the only sibling by naming it: 'Edit it and pass it to check_book.' An agent can distinguish this from check_book without opening either schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Clearly implies the use case (fetching seeded sample data, then editing it and feeding it to check_book for Fine-Print Check requests on booking/subscription), naming the downstream alternative. It lacks an explicit 'when not to use this' statement or default-name guidance beyond '(the default)', so it stops short of a 5.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
2 tool updates
- Changed
check_book5 fields changed- added
Input schema / properties / as_ofAdded value: +{ + "description": "The current UTC time (ISO 8601). Time rules use it; the server clock is never used.", + "type": "string" +} - added
Input schema / properties / offerAdded value: +{ + "description": "One offer, as structured fields your agent extracted: merchant, currency, headline_price, line_items [{label, amount, mandatory}], refund {refundable, free_cancel_until}, subscription {auto_renews, renewal_price, renewal_interval, trial_ends}. Send with limits.", + "type": "object" +} - added
Input schema / properties / page_textAdded value: +{ + "description": "Optional plain text copied from the offer page, at most 64 KB. Scanned for amounts and refund or renewal phrases. Send plain text you already have. Do not send a URL; booklint will not fetch one.", + "type": "string" +} - changed
Input schema / properties / sample / descriptionPrevious value: -"true runs sample 1 (trading); \"spend\" runs sample 2 instead."New value: +"true runs sample 1 (trading); \"spend\", \"booking\" or \"subscription\" runs sample 2, 3 or 4 instead." - changed
Input schema / properties / sample / oneOfPrevious value: -[ - { - "type": "boolean" - }, - { - "enum": [ - "spend" - ], - "type": "string" - } -]New value: +[ + { + "type": "boolean" + }, + { + "enum": [ + "spend", + "booking", + "subscription" + ], + "type": "string" + } +]
- Changed
get_sample2 fields changed- changed
Input schema / properties / name / descriptionPrevious value: -"trading (default, sample 1) or spend (sample 2)."New value: +"trading (default, sample 1), spend (sample 2), booking (sample 3) or subscription (sample 4)." - changed
Input schema / properties / name / enumPrevious value: -[ - "trading", - "spend" -]New value: +[ + "trading", + "spend", + "booking", + "subscription" +]
2 tool updates
- First observed
check_book - First observed
get_sample
Related MCP Connectors
Agent payments, API key vaulting, and governed mandates. Agents spend within user-defined limits.
Read-only checks for proposed orders against evidence and policy; no trading or payment authority.
Pre-sign, token and approval checks for agents: green/orange/red for signatures, tokens, wallets.
OFAC, LEI, EU VAT, AI Act, and company compliance preflight for agents.
Related MCP Servers
- FlicenseNot gradedqualityBmaintenanceEnforces autonomous merchant checkout token and velocity limits for Agentcard/Stripe transactions.7-
- AlicenseNot gradedqualityAmaintenanceLets a coding agent inspect its own account's subscription limit windows, usage, and cost history, and decide whether to pause and sleep until a limit resets rather than failing mid-task. Supports multiple accounts and providers such as Claude Code and Codex.MIT
- AlicenseNot gradedqualityAmaintenanceEnables agents and developers to check x402 endpoints, assess scores and wallet risks, authorize payments with spending rules, and report outcomes before an agent pays.MIT
- AlicenseAqualityDmaintenanceSpending limits for AI agents. Create budgets, enforce limits, track spend across x402, cards, MPP, or any payment rail.79 npmApache 2.0
Glama MCP Gateway
Add one secure layer between your agents and this server.