Skip to main content
Glama

Quote Verification

quote_verify_evidence
Idempotent

Obtain a free bound quote for deterministic checks on supplied JSON before deciding to purchase. After a successful free precheck at POST /validate-request, supply the unchanged intent and its precheck_receipt.receipt_digest. Creates or reuses a persisted quote and records observability events; no payment, signing or paid verification is performed. The bound quote ties request/evidence digests, precheck digest, spend policy, quoted amount, network, asset, recipient and expiry together. Server availability, fresh cost basis and conservative contribution-margin thresholds must pass. Returns the quote as JSON text and structuredContent: quote_id, request_hash, price (atomic USDC, 6 decimals), expires_at, economic_guard, purchase instructions and paid_verification_binding in state quoted, not a paid receipt. Application failures return isError=true with JSON error.code, message, retryable and optional details (for example PRECHECK_STALE, PRICE_CAP_EXCEEDED, IDEMPOTENCY_KEY_CONFLICT, IDEMPOTENCY_KEY_EXPIRED or UNPROFITABLE_TRANSACTION); invalid argument shapes are rejected by MCP schema validation. Re-run precheck after request/policy changes; do not pay on refusal. Next use prepare_verify_evidence_purchase with the same key and intent for the HTTP purchase request, or explicitly authorize the separate paid verify_evidence flow.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
intentYesRequired prechecked purchase intent: request, spend_policy and precheck_receipt_digest are all required, with no defaults or optional fields. Preserve the request and policy used in the successful free POST /validate-request.
idempotency_keyYesRequired 16-128 characters from A-Z, a-z, 0-9, underscore or hyphen. Reuse with the unchanged intent to reuse an unexpired quote; changed bindings return IDEMPOTENCY_KEY_CONFLICT. An expired key returns IDEMPOTENCY_KEY_EXPIRED; use a new key.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed16 schema fields changed
    • addedInput schema / properties / idempotency_key / description
      Added value: +"Required 16-128 characters from A-Z, a-z, 0-9, underscore or hyphen. Reuse with the unchanged intent to reuse an unexpired quote; changed bindings return IDEMPOTENCY_KEY_CONFLICT. An expired key returns IDEMPOTENCY_KEY_EXPIRED; use a new key."
    • addedInput schema / properties / intent / description
      Added value: +"Required prechecked purchase intent: request, spend_policy and precheck_receipt_digest are all required, with no defaults or optional fields. Preserve the request and policy used in the successful free POST /validate-request."
    • addedInput schema / properties / intent / properties / precheck_receipt_digest / description
      Added value: +"Required sha256: followed by 64 lowercase hex characters, copied from precheck_receipt.receipt_digest of the successful free precheck. Recomputed against request, policy and current discovery contract; mismatches return PRECHECK_STALE."
    • addedInput schema / properties / intent / properties / request / description
      Added value: +"Required complete bounded verification request, unchanged from precheck; no optional fields or defaults."
    • addedInput schema / properties / intent / properties / request / properties / assertions / description
      Added value: +"Required 1-16 deterministic assertions. Each operation accepts only its documented fields. Precheck validates input, not assertion truth."
    • changedInput schema / properties / intent / properties / request / properties / assertions / items / oneOf
      Previous value: -[
      -  {
      -    "additionalProperties": false,
      -    "properties": {
      -      "expected_hex": {
      -        "pattern": "^[a-f0-9]{64}$",
      -        "type": "string"
      -      },
      -      "op": {
      -        "const": "sha256_equals",
      -        "type": "string"
      -      }
      -    },
      -    "required": [
      -      "op",
      -      "expected_hex"
      -    ],
      -    "type": "object"
      -  },
      -  {
      -    "additionalProperties": false,
      -    "properties": {
      -      "op": {
      -        "const": "json_pointer_exists",
      -        "type": "string"
      -      },
      -      "path": {
      -        "maxLength": 512,
      -        "type": "string"
      -      }
      -    },
      -    "required": [
      -      "op",
      -      "path"
      -    ],
      -    "type": "object"
      -  },
      -  {
      -    "additionalProperties": false,
      -    "properties": {
      -      "expected": {},
      -      "op": {
      -        "const": "json_pointer_equals",
      -        "type": "string"
      -      },
      -      "path": {
      -        "maxLength": 512,
      -        "type": "string"
      -      }
      -    },
      -    "required": [
      -      "op",
      -      "path",
      -      "expected"
      -    ],
      -    "type": "object"
      -  },
      -  {
      -    "additionalProperties": false,
      -    "properties": {
      -      "expected_type": {
      -        "enum": [
      -          "null",
      -          "boolean",
      -          "number",
      -          "string",
      -          "array",
      -          "object"
      -        ],
      -        "type": "string"
      -      },
      -      "op": {
      -        "const": "json_type_is",
      -        "type": "string"
      -      },
      -      "path": {
      -        "maxLength": 512,
      -        "type": "string"
      -      }
      -    },
      -    "required": [
      -      "op",
      -      "path",
      -      "expected_type"
      -    ],
      -    "type": "object"
      -  }
      -]New value: +[
      +  {
      +    "additionalProperties": false,
      +    "properties": {
      +      "expected_hex": {
      +        "description": "Required expected digest as exactly 64 lowercase hex characters, without sha256: prefix.",
      +        "pattern": "^[a-f0-9]{64}$",
      +        "type": "string"
      +      },
      +      "op": {
      +        "const": "sha256_equals",
      +        "description": "Compare SHA-256 of the raw decoded evidence bytes.",
      +        "type": "string"
      +      }
      +    },
      +    "required": [
      +      "op",
      +      "expected_hex"
      +    ],
      +    "type": "object"
      +  },
      +  {
      +    "additionalProperties": false,
      +    "properties": {
      +      "op": {
      +        "const": "json_pointer_exists",
      +        "description": "Check whether the JSON Pointer resolves.",
      +        "type": "string"
      +      },
      +      "path": {
      +        "description": "Required RFC 6901 JSON Pointer, at most 512 characters; empty string selects the document root. Escape tilde as ~0 and slash as ~1.",
      +        "maxLength": 512,
      +        "type": "string"
      +      }
      +    },
      +    "required": [
      +      "op",
      +      "path"
      +    ],
      +    "type": "object"
      +  },
      +  {
      +    "additionalProperties": false,
      +    "properties": {
      +      "expected": {
      +        "description": "Required expected JSON value, including null; JSON depth/key/value and safe-integer limits apply."
      +      },
      +      "op": {
      +        "const": "json_pointer_equals",
      +        "description": "Compare the selected JSON value with expected.",
      +        "type": "string"
      +      },
      +      "path": {
      +        "description": "Required RFC 6901 JSON Pointer, at most 512 characters; empty string selects the document root. Escape tilde as ~0 and slash as ~1.",
      +        "maxLength": 512,
      +        "type": "string"
      +      }
      +    },
      +    "required": [
      +      "op",
      +      "path",
      +      "expected"
      +    ],
      +    "type": "object"
      +  },
      +  {
      +    "additionalProperties": false,
      +    "properties": {
      +      "expected_type": {
      +        "description": "Required JSON type: null, boolean, number, string, array or object.",
      +        "enum": [
      +          "null",
      +          "boolean",
      +          "number",
      +          "string",
      +          "array",
      +          "object"
      +        ],
      +        "type": "string"
      +      },
      +      "op": {
      +        "const": "json_type_is",
      +        "description": "Check the selected JSON value type.",
      +        "type": "string"
      +      },
      +      "path": {
      +        "description": "Required RFC 6901 JSON Pointer, at most 512 characters; empty string selects the document root. Escape tilde as ~0 and slash as ~1.",
      +        "maxLength": 512,
      +        "type": "string"
      +      }
      +    },
      +    "required": [
      +      "op",
      +      "path",
      +      "expected_type"
      +    ],
      +    "type": "object"
      +  }
      +]
    • addedInput schema / properties / intent / properties / request / properties / client_request_id / description
      Added value: +"Required caller request identifier, 1-64 characters from A-Z, a-z, 0-9, dot, underscore, colon or hyphen; included in the request hash."
    • addedInput schema / properties / intent / properties / request / properties / evidence / description
      Added value: +"Required caller-supplied JSON bytes; no remote evidence is fetched."
    • addedInput schema / properties / intent / properties / request / properties / evidence / properties / content_base64 / description
      Added value: +"Required strict standard Base64 of UTF-8 JSON; 4-87384 encoded characters and at most 65536 decoded bytes. JSON limits: depth 32, object keys 2048, values 8192; integers must be JavaScript safe integers."
    • addedInput schema / properties / intent / properties / request / properties / evidence / properties / media_type / description
      Added value: +"Required literal application/json."
    • addedInput schema / properties / intent / properties / spend_policy / description
      Added value: +"Required caller spending limits and allowed terms; preserve from precheck. All five fields required; no defaults."
    • addedInput schema / properties / intent / properties / spend_policy / properties / asset / description
      Added value: +"Required USDC contract address, 0x plus 40 hex characters; must match current advertised asset."
    • addedInput schema / properties / intent / properties / spend_policy / properties / max_amount_atomic / description
      Added value: +"Required positive decimal integer string in atomic USDC units (1000000 = 1 USDC), at most 16 digits and within JavaScript safe-integer range. No leading zero; must cover the current quoted price."
    • addedInput schema / properties / intent / properties / spend_policy / properties / network / description
      Added value: +"Required eip155:8453 (Base) or eip155:84532 (Base Sepolia); must match current advertised terms."
    • addedInput schema / properties / intent / properties / spend_policy / properties / pay_to / description
      Added value: +"Required allowed payment recipient, 0x plus 40 hex characters; must match current advertised payTo."
    • addedInput schema / properties / intent / properties / spend_policy / properties / policy_version / description
      Added value: +"Required literal agent-economy/precheck-policy/2.0."
  2. First observed

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Adds substantial context beyond the annotations: it creates or reuses a persisted quote, records observability events, performs no payment/signing/paid verification, and specifies the failure contract (isError=true with error.code, message, retryable, and named codes like PRECHECK_STALE and IDEMPOTENCY_KEY_CONFLICT). It also enumerates the quote binding and its state ('quoted', not a paid receipt).

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the core action and scope, and every sentence carries real information. It is dense and lengthy, folding return-value detail and error codes into one paragraph, but with no output schema that content largely earns its place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description fully covers the return contract (quote_id, request_hash, price, expires_at, economic_guard, purchase instructions, binding) and the failure contract. For a quote-creating tool whose annotations already declare non-destructive/idempotent behavior, nothing needed to call it correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the schema already documents intent, spend_policy, precheck_receipt_digest and idempotency_key semantics, including the conflict/expiry codes. The description corroborates the precheck flow and the unchanged-intent requirement but adds little syntax or meaning beyond what the schema descriptions already provide; baseline 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource (obtain a free bound quote), establishes scope (deterministic checks on supplied JSON, no payment or paid verification), and implicitly separates itself from verify_evidence and prepare_verify_evidence_purchase by naming both later. An agent can tell this is the quote step, not the verification step.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly gates the call on a prior successful free precheck, requires supplying the unchanged intent and its receipt_digest, states when to re-run precheck (after request/policy changes), warns 'do not pay on refusal', and names the next tool (prepare_verify_evidence_purchase) versus the separate paid flow. When/when-not/alternatives are all present.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources