Skip to main content
Glama

Server Details

Inspect and validate an x402 endpoint before an autonomous agent spends USDC.

If you are the author of this connector, you can claim ownership by verifying the domain or GitHub account it belongs to. Claimed connector authors can inspect health checks, view analytics, and manage their listing.
Status
Healthy
Uptime
100.0% over 41 days
Last Tested
Transport
Streamable HTTP · MCP 2025-11-25
URL
Server Listing
x402 Preflight

TDQS

B3.3/5.0

Scored across 3 tools

Disambiguation4/5

Audit and inspect both examine an x402 endpoint, but descriptions clearly distinguish paid deep evidence vs free live check without credentials. Order remediation is distinct in creating an asynchronous report order, though it also requires an authorized purchase like audit, which could cause minor confusion.

Naming Consistency5/5

All tool names follow a consistent verb_x402_object pattern: audit_x402_endpoint, inspect_x402_endpoint, order_x402_remediation. The object differs but the structure is predictable and readable.

Tool Count5/5

Three tools are well-scoped for a focused preflight server: free inspection, paid deep audit, and remediation ordering. Each covers a distinct step with no redundant operations.

Completeness2/5

The set lacks a way to retrieve the asynchronous remediation report or check order status after ordering, creating a dead end. No tool lists past orders or fetched reports, which will cause agent failures for follow-up.

Available Tools

3 tools
audit_x402_endpointx402 Technical AuditA
Read-onlyIdempotent
Inspect

Technical audit for API developers launching or debugging x402. Returns deeper read-only evidence of payment configuration, schemas, redirects, CORS, cache behavior, OpenAPI, llms.txt, agent metadata, and x402 discovery consistency. Requires an explicitly authorized x402 purchase; does not test settlement, paid delivery, or actual marketplace indexing.

ParametersJSON Schema
NameRequiredDescriptionDefault
methodNoGET
resource_urlYesPublic HTTPS x402 resource to inspect without payment credentials.
max_price_usdNo
expected_networkNo

Output Schema

ParametersJSON Schema
NameRequiredDescription
corsYes
scoreYes
checksYes
issuesYes
paymentYes
profileYes
decisionYes
evidenceYes
resourceYes
discoveryYes
expiresAtYes
requestIdYes
observedAtYes
operationalYes
claimBoundaryYes

TDQS

A3.6/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already cover the safety profile (readOnly, idempotent, non-destructive, openWorld). The description adds meaningful context: it requires an explicitly authorized x402 purchase, returns read-only evidence, and does not test settlement, paid delivery, or marketplace indexing — useful scope boundaries an agent cannot derive from annotations alone.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three tight sentences, front-loaded with purpose before the evidence list and constraints. The middle sentence is a dense enumeration but each item earns its place by telling the agent what is returned.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists, so return values need not be spelled out, and the description does summarize the covered domains. However, for a 4-parameter tool with 25% schema coverage, the missing parameter guidance on method, max_price_usd, and expected_network leaves a real gap.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is only 25%, with just resource_url documented. The description never explains method, max_price_usd, or expected_network, so it fails to compensate for the undocumented parameters. There is even mild tension with the schema, which says the resource can be inspected without payment credentials while the description mentions an authorized purchase.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Technical audit for API developers launching or debugging x402') and enumerates the evidence domains it returns. The word 'deeper' implicitly positions it against the sibling inspect_x402_endpoint, but the distinction is not made explicit.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives clear context for when to reach for it (launching or debugging x402) and states exclusions ('does not test settlement, paid delivery, or actual marketplace indexing'). It stops short of naming the alternative tool or a concrete when-not condition relative to inspect_x402_endpoint.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

inspect_x402_endpointFree x402 Endpoint CheckB
Read-onlyIdempotent
Inspect

Free endpoint check for API developers launching or debugging x402. Inspect your live payment challenge and caller-selected comparison policy without sending payment credentials. ALLOW and BLOCK are policy decisions, not launch certification; a price-limit BLOCK does not establish a broken integration. Buyer-side inspection remains available.

ParametersJSON Schema
NameRequiredDescriptionDefault
methodNoGET
resource_urlYesPublic HTTPS x402 resource to inspect without payment credentials.
max_price_usdNo
expected_networkNo

Output Schema

ParametersJSON Schema
NameRequiredDescription
corsYes
scoreYes
checksYes
issuesYes
paymentYes
profileYes
decisionYes
evidenceYes
resourceYes
discoveryYes
expiresAtYes
requestIdYes
observedAtYes
operationalYes
claimBoundaryYes

TDQS

B3.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already cover the safe/idempotent/open-world profile, but the description adds genuine behavioral context: no payment credentials are sent, and a price-limit BLOCK does not imply a broken integration. That result-semantics guidance is valuable beyond the structured hints.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The first sentence is well front-loaded, but the two middle sentences about ALLOW/BLOCK are defensive and read as caveats rather than actionable guidance. Every sentence is relevant but the caveats could be tightened.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With an output schema present, return values needn't be explained, and annotations carry the safety profile. The description covers the essential semantics (what it inspects, credentials not required, how to read results), leaving only minor parameter documentation gaps.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is only 25% with 4 parameters, so the description must compensate and largely does not. The phrase 'caller-selected comparison policy' loosely gestures at max_price_usd/expected_network, but method, formats, and the meaning of the comparison fields are undocumented anywhere.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (inspect) and resource (x402 payment challenge / endpoint) with clear scope: 'Free endpoint check for API developers launching or debugging x402.' It implicitly distinguishes itself from the audit sibling by framing ALLOW/BLOCK as policy decisions rather than 'launch certification,' but never names audit_x402_endpoint outright.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Names the audience use case (launching or debugging) and clarifies that buyer-side inspection is available, implying usage context. However, it never explicitly states when to use this instead of audit_x402_endpoint or order_x402_remediation, leaving the routing to the reader.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

order_x402_remediationOrder x402 Diagnostic ReportCInspect

Diagnostic report for API developers launching or debugging x402. An explicitly authorized x402 purchase creates a durable order for asynchronous findings, evidence, and prioritized fix recommendations in JSON/Markdown. The receipt is not the completed report. No implementation, human consultation, target payment, deployment, or guaranteed marketplace indexing.

ParametersJSON Schema
NameRequiredDescriptionDefault
goalYes
contactNo
languageNoen
constraintsNo
callback_urlNo
resource_urlYes
response_formatNoboth

Output Schema

ParametersJSON Schema
NameRequiredDescription
reviewYes
statusYes
orderIdYes
paymentYes
requestYes
serviceYes
acceptedAtYes
capabilityYes
persistenceYes
claimBoundaryYes

TDQS

C2.6/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already disclose the safety profile (readOnlyHint=false, destructiveHint=false, openWorldHint=true, non-idempotent). The description adds genuinely useful behavioral context that annotations cannot: the operation is asynchronous, the receipt is not the finished report, and no implementation/payment/deployment follows. The phrasing is muddled, so the disclosure is present but not crisp.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The text is dense and somewhat front-loaded, but the long negation list reads as legal disclaimers rather than actionable specification, and the key ordering behavior is buried behind the 'Diagnostic report' lead. Sentences are grammatically efficient but not maximally informative per word.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

An output schema exists so return values need not be explained, but for a 7-parameter, non-idempotent, open-world mutation with 0% schema coverage the description should define the parameters and the async delivery/callback contract. As written, an agent lacks enough to call it correctly beyond guessing from names.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0% across 7 parameters, so the description carries the full burden of explaining goal, resource_url, callback_url, constraints, response_format, contact, and language. It explains none of them, leaving an agent to infer semantics from bare property names and constraints alone.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose3/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description conveys a specific verb+resource: it creates a durable order that yields an asynchronous diagnostic report for x402 endpoints. However, it leads with 'Diagnostic report' rather than the ordering action, and it never distinguishes this from siblings audit_x402_endpoint and inspect_x402_endpoint, so an agent cannot easily tell which of the three to pick.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

There is a hint of a prerequisite ('An explicitly authorized x402 purchase creates a durable order'), but no explicit statement of when to use this tool versus the audit/inspect siblings. The closing negative list ('No implementation, human consultation, target payment, deployment...') describes scope exclusions, not selection guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 3 tool updates
    • First observedaudit_x402_endpoint
    • First observedinspect_x402_endpoint
    • First observedorder_x402_remediation

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    B
    maintenance
    Before an AI agent pays an x402 endpoint, checks whether it's safe to pay: liveness, scam/anomaly scan (payTo hijack, bait-and-switch, honeypot), and on-chain receiver verification. ~70% of x402 endpoints are dead or scams.
    3
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    Verify x402 endpoints before your agent spends. Three tools: verify (SPEND/CAUTION/INVESTIGATE/DO NOT SPEND backed by 50K+ services), passport (full trust identity), risk_check (deep assessment). No API keys, no signup.
    12 npm
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Checks token contract safety for honeypot, tax, proxy, blacklist, ownership risks, and returns a risk score, enabling rug-pull protection for agents via pay-per-call x402 micropayments.
    MIT
Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources