x402 Preflight
Server Details
Inspect and validate an x402 endpoint before an autonomous agent spends USDC.
- Status
- Healthy
- Uptime
- 100.0% over 41 days
- Last Tested
- Transport
- Streamable HTTP · MCP 2025-11-25
- URL
- Server Listing
- x402 Preflight
TDQS
Scored across 3 tools
Audit and inspect both examine an x402 endpoint, but descriptions clearly distinguish paid deep evidence vs free live check without credentials. Order remediation is distinct in creating an asynchronous report order, though it also requires an authorized purchase like audit, which could cause minor confusion.
All tool names follow a consistent verb_x402_object pattern: audit_x402_endpoint, inspect_x402_endpoint, order_x402_remediation. The object differs but the structure is predictable and readable.
Three tools are well-scoped for a focused preflight server: free inspection, paid deep audit, and remediation ordering. Each covers a distinct step with no redundant operations.
The set lacks a way to retrieve the asynchronous remediation report or check order status after ordering, creating a dead end. No tool lists past orders or fetched reports, which will cause agent failures for follow-up.
Available Tools
3 toolsaudit_x402_endpointx402 Technical AuditARead-onlyIdempotentInspect
Technical audit for API developers launching or debugging x402. Returns deeper read-only evidence of payment configuration, schemas, redirects, CORS, cache behavior, OpenAPI, llms.txt, agent metadata, and x402 discovery consistency. Requires an explicitly authorized x402 purchase; does not test settlement, paid delivery, or actual marketplace indexing.
| Name | Required | Description | Default |
|---|---|---|---|
| method | No | GET | |
| resource_url | Yes | Public HTTPS x402 resource to inspect without payment credentials. | |
| max_price_usd | No | ||
| expected_network | No |
Output Schema
| Name | Required | Description |
|---|---|---|
| cors | Yes | |
| score | Yes | |
| checks | Yes | |
| issues | Yes | |
| payment | Yes | |
| profile | Yes | |
| decision | Yes | |
| evidence | Yes | |
| resource | Yes | |
| discovery | Yes | |
| expiresAt | Yes | |
| requestId | Yes | |
| observedAt | Yes | |
| operational | Yes | |
| claimBoundary | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already cover the safety profile (readOnly, idempotent, non-destructive, openWorld). The description adds meaningful context: it requires an explicitly authorized x402 purchase, returns read-only evidence, and does not test settlement, paid delivery, or marketplace indexing — useful scope boundaries an agent cannot derive from annotations alone.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Three tight sentences, front-loaded with purpose before the evidence list and constraints. The middle sentence is a dense enumeration but each item earns its place by telling the agent what is returned.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists, so return values need not be spelled out, and the description does summarize the covered domains. However, for a 4-parameter tool with 25% schema coverage, the missing parameter guidance on method, max_price_usd, and expected_network leaves a real gap.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is only 25%, with just resource_url documented. The description never explains method, max_price_usd, or expected_network, so it fails to compensate for the undocumented parameters. There is even mild tension with the schema, which says the resource can be inspected without payment credentials while the description mentions an authorized purchase.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource ('Technical audit for API developers launching or debugging x402') and enumerates the evidence domains it returns. The word 'deeper' implicitly positions it against the sibling inspect_x402_endpoint, but the distinction is not made explicit.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives clear context for when to reach for it (launching or debugging x402) and states exclusions ('does not test settlement, paid delivery, or actual marketplace indexing'). It stops short of naming the alternative tool or a concrete when-not condition relative to inspect_x402_endpoint.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
inspect_x402_endpointFree x402 Endpoint CheckBRead-onlyIdempotentInspect
Free endpoint check for API developers launching or debugging x402. Inspect your live payment challenge and caller-selected comparison policy without sending payment credentials. ALLOW and BLOCK are policy decisions, not launch certification; a price-limit BLOCK does not establish a broken integration. Buyer-side inspection remains available.
| Name | Required | Description | Default |
|---|---|---|---|
| method | No | GET | |
| resource_url | Yes | Public HTTPS x402 resource to inspect without payment credentials. | |
| max_price_usd | No | ||
| expected_network | No |
Output Schema
| Name | Required | Description |
|---|---|---|
| cors | Yes | |
| score | Yes | |
| checks | Yes | |
| issues | Yes | |
| payment | Yes | |
| profile | Yes | |
| decision | Yes | |
| evidence | Yes | |
| resource | Yes | |
| discovery | Yes | |
| expiresAt | Yes | |
| requestId | Yes | |
| observedAt | Yes | |
| operational | Yes | |
| claimBoundary | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already cover the safe/idempotent/open-world profile, but the description adds genuine behavioral context: no payment credentials are sent, and a price-limit BLOCK does not imply a broken integration. That result-semantics guidance is valuable beyond the structured hints.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The first sentence is well front-loaded, but the two middle sentences about ALLOW/BLOCK are defensive and read as caveats rather than actionable guidance. Every sentence is relevant but the caveats could be tightened.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With an output schema present, return values needn't be explained, and annotations carry the safety profile. The description covers the essential semantics (what it inspects, credentials not required, how to read results), leaving only minor parameter documentation gaps.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is only 25% with 4 parameters, so the description must compensate and largely does not. The phrase 'caller-selected comparison policy' loosely gestures at max_price_usd/expected_network, but method, formats, and the meaning of the comparison fields are undocumented anywhere.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (inspect) and resource (x402 payment challenge / endpoint) with clear scope: 'Free endpoint check for API developers launching or debugging x402.' It implicitly distinguishes itself from the audit sibling by framing ALLOW/BLOCK as policy decisions rather than 'launch certification,' but never names audit_x402_endpoint outright.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Names the audience use case (launching or debugging) and clarifies that buyer-side inspection is available, implying usage context. However, it never explicitly states when to use this instead of audit_x402_endpoint or order_x402_remediation, leaving the routing to the reader.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
order_x402_remediationOrder x402 Diagnostic ReportCInspect
Diagnostic report for API developers launching or debugging x402. An explicitly authorized x402 purchase creates a durable order for asynchronous findings, evidence, and prioritized fix recommendations in JSON/Markdown. The receipt is not the completed report. No implementation, human consultation, target payment, deployment, or guaranteed marketplace indexing.
| Name | Required | Description | Default |
|---|---|---|---|
| goal | Yes | ||
| contact | No | ||
| language | No | en | |
| constraints | No | ||
| callback_url | No | ||
| resource_url | Yes | ||
| response_format | No | both |
Output Schema
| Name | Required | Description |
|---|---|---|
| review | Yes | |
| status | Yes | |
| orderId | Yes | |
| payment | Yes | |
| request | Yes | |
| service | Yes | |
| acceptedAt | Yes | |
| capability | Yes | |
| persistence | Yes | |
| claimBoundary | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already disclose the safety profile (readOnlyHint=false, destructiveHint=false, openWorldHint=true, non-idempotent). The description adds genuinely useful behavioral context that annotations cannot: the operation is asynchronous, the receipt is not the finished report, and no implementation/payment/deployment follows. The phrasing is muddled, so the disclosure is present but not crisp.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The text is dense and somewhat front-loaded, but the long negation list reads as legal disclaimers rather than actionable specification, and the key ordering behavior is buried behind the 'Diagnostic report' lead. Sentences are grammatically efficient but not maximally informative per word.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists so return values need not be explained, but for a 7-parameter, non-idempotent, open-world mutation with 0% schema coverage the description should define the parameters and the async delivery/callback contract. As written, an agent lacks enough to call it correctly beyond guessing from names.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 0% across 7 parameters, so the description carries the full burden of explaining goal, resource_url, callback_url, constraints, response_format, contact, and language. It explains none of them, leaving an agent to infer semantics from bare property names and constraints alone.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description conveys a specific verb+resource: it creates a durable order that yields an asynchronous diagnostic report for x402 endpoints. However, it leads with 'Diagnostic report' rather than the ordering action, and it never distinguishes this from siblings audit_x402_endpoint and inspect_x402_endpoint, so an agent cannot easily tell which of the three to pick.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
There is a hint of a prerequisite ('An explicitly authorized x402 purchase creates a durable order'), but no explicit statement of when to use this tool versus the audit/inspect siblings. The closing negative list ('No implementation, human consultation, target payment, deployment...') describes scope exclusions, not selection guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
3 tool updates
- First observed
audit_x402_endpoint - First observed
inspect_x402_endpoint - First observed
order_x402_remediation
Related MCP Connectors
Check an x402 endpoint before your agent pays it: avoid / caution / ok, proven on-chain.
Check any x402 endpoint before your AI agent pays it: trust grade, verdict, and hijack checks.
Verify x402 payment endpoints before an AI agent pays: scam scan, on-chain checks, trust scores.
We buy from x402 endpoints with real USDC and publish delivery outcomes. Check before you spend.
Related MCP Servers
- AlicenseAqualityBmaintenanceBefore an AI agent pays an x402 endpoint, checks whether it's safe to pay: liveness, scam/anomaly scan (payTo hijack, bait-and-switch, honeypot), and on-chain receiver verification. ~70% of x402 endpoints are dead or scams.3MIT
- AlicenseNot gradedqualityBmaintenanceChecks wash-traffic risk of Algorand x402 endpoints using on-chain analysis, helping agents decide whether to pay USDC.60 npmMIT
- AlicenseNot gradedqualityDmaintenanceVerify x402 endpoints before your agent spends. Three tools: verify (SPEND/CAUTION/INVESTIGATE/DO NOT SPEND backed by 50K+ services), passport (full trust identity), risk_check (deep assessment). No API keys, no signup.12 npmMIT
- AlicenseNot gradedqualityBmaintenanceChecks token contract safety for honeypot, tax, proxy, blacklist, ownership risks, and returns a risk score, enabling rug-pull protection for agents via pay-per-call x402 micropayments.MIT
Glama MCP Gateway
Add one secure layer between your agents and this server.