Skip to main content
Glama

Preflight an x402 Endpoint

preflight_endpoint

Endpoint inspection and x402 endpoint preflight, free. The inspection block separates observed protocols, unverified advertised terms, structural checks and gaps; no signature, settlement or delivery verification is performed. The top-level verdict remains x402-specific. For a buyer about to pay a door it has not paid before, and for a seller checking their own. Check any x402 endpoint's door before paying it: one unpaid probe answering whether the URL serves a well-formed x402 v2 payment challenge right now — 402 status, parseable PAYMENT-REQUIRED, signable accepts, testnet catch. Returns the verdict with reached_level on the L0-L6 evidence ladder, the tri-state checks vector, and what this single probe cannot tell you. A shape check at one moment, NEVER an uptime or delivery claim — a passing preflight quoted as either is a misquote. An evidence instrument: the reading is written to be handed to the human behind you, gaps at full weight. Rate limited; the result carries the stated ceiling. For a signed, servable version of this same look, buy_observation with item_id service_audit.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
urlYesThe https endpoint a buyer would GET expecting a 402 challenge.
modelNoOptional. The model running you, as you would name it: claude-opus-5, gpt-5.6, a local model. Counted, never printed on the certificate.
clientNoOptional. The harness or framework you run in: claude-code, cursor, openai-agents, langgraph, custom. Counted, never on the certificate.
operatorNoOptional. Who runs you: a name, handle, company or URL. Stored as your claim, marked unverified, never published, never on the certificate.
came_fromNoOptional. Where you learned this door exists: a URL, a directory, a skill name, memory, another agent. Referrers never reach us; this does.
operator_kindNoOptional. solo: one person runs you. company: a team does. research: a study. self: you act for yourself.
prior_cert_idNoOptional. A cert_ id from an earlier purchase here. A payer match with this payment marks you a returning buyer; no account needed.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
verdictYesx402-specific: ready | not_ready | unreachable | method_unresolved.
inspectionNoOne unpaid response, with observed protocols, unverified advertised term summaries, existing structural findings and coverage gaps. The x402 verdict retains its meaning. No artifact signature verification, payment signing, payment submission, settlement or delivery check.
reached_levelYesHow far the probe got on the evidence ladder: none | L1 | L2 | L3a.
single_probe_noteNoOne moment — the standing caveat. Two requests only where a door refuses the first verb.
reached_level_meaningNoWhat that rung does and does not claim.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed2 schema fields changed
    • addedOutput schema / properties / inspection
      Added value: +{
      +  "description": "One unpaid response, with observed protocols, unverified advertised term summaries, existing structural findings and coverage gaps. The x402 verdict retains its meaning. No artifact signature verification, payment signing, payment submission, settlement or delivery check.",
      +  "properties": {
      +    "coverage": {
      +      "description": "Body read / over_limit / unobserved and MPP core read / absent / unmeasured.",
      +      "type": "object"
      +    },
      +    "gaps": {
      +      "items": {
      +        "type": "string"
      +      },
      +      "type": "array"
      +    },
      +    "observed_at": {
      +      "format": "date-time",
      +      "type": "string"
      +    },
      +    "protocols": {
      +      "properties": {
      +        "observed": {
      +          "items": {
      +            "enum": [
      +              "x402",
      +              "mpp"
      +            ],
      +            "type": "string"
      +          },
      +          "type": "array",
      +          "uniqueItems": true
      +        },
      +        "scope": {
      +          "type": "string"
      +        },
      +        "state": {
      +          "enum": [
      +            "read",
      +            "partial",
      +            "unobserved"
      +          ],
      +          "type": "string"
      +        }
      +      },
      +      "type": "object"
      +    },
      +    "reachability": {
      +      "properties": {
      +        "http_status": {
      +          "type": [
      +            "integer",
      +            "null"
      +          ]
      +        },
      +        "method": {
      +          "type": [
      +            "string",
      +            "null"
      +          ]
      +        },
      +        "state": {
      +          "enum": [
      +            "responded",
      +            "unreachable",
      +            "method_unresolved"
      +          ],
      +          "type": "string"
      +        }
      +      },
      +      "type": "object"
      +    },
      +    "signatures": {
      +      "properties": {
      +        "reason": {
      +          "type": "string"
      +        },
      +        "state": {
      +          "enum": [
      +            "not_checked"
      +          ],
      +          "type": "string"
      +        }
      +      },
      +      "type": "object"
      +    },
      +    "structure": {
      +      "description": "Existing x402, frozen MPP and MPP core batteries, checked counts and failed check names. MPP core also names unmeasured checks; no global readiness verdict.",
      +      "type": "object"
      +    },
      +    "subject_url": {
      +      "type": "string"
      +    },
      +    "terms": {
      +      "description": "Unverified summaries, at most 32 entries per protocol, each with state, entries, total and omitted. Not complete payment instructions.",
      +      "type": "object"
      +    },
      +    "unperformed": {
      +      "items": {
      +        "type": "string"
      +      },
      +      "type": "array"
      +    },
      +    "version": {
      +      "enum": [
      +        "inspection-v1"
      +      ],
      +      "type": "string"
      +    }
      +  },
      +  "type": "object"
      +}
    • changedOutput schema / properties / verdict / description
      Previous value: -"ready | not_ready | unreachable."New value: +"x402-specific: ready | not_ready | unreachable | method_unresolved."
  2. Changed6 schema fields changed
    • addedInput schema / properties / came_from
      Added value: +{
      +  "description": "Optional. Where you learned this door exists: a URL, a directory, a skill name, memory, another agent. Referrers never reach us; this does.",
      +  "maxLength": 160,
      +  "type": "string"
      +}
    • addedInput schema / properties / client
      Added value: +{
      +  "description": "Optional. The harness or framework you run in: claude-code, cursor, openai-agents, langgraph, custom. Counted, never on the certificate.",
      +  "maxLength": 64,
      +  "type": "string"
      +}
    • addedInput schema / properties / model
      Added value: +{
      +  "description": "Optional. The model running you, as you would name it: claude-opus-5, gpt-5.6, a local model. Counted, never printed on the certificate.",
      +  "maxLength": 64,
      +  "type": "string"
      +}
    • addedInput schema / properties / operator
      Added value: +{
      +  "description": "Optional. Who runs you: a name, handle, company or URL. Stored as your claim, marked unverified, never published, never on the certificate.",
      +  "maxLength": 120,
      +  "type": "string"
      +}
    • addedInput schema / properties / operator_kind
      Added value: +{
      +  "description": "Optional. solo: one person runs you. company: a team does. research: a study. self: you act for yourself.",
      +  "enum": [
      +    "solo",
      +    "company",
      +    "research",
      +    "self"
      +  ],
      +  "type": "string"
      +}
    • addedInput schema / properties / prior_cert_id
      Added value: +{
      +  "description": "Optional. A cert_ id from an earlier purchase here. A payer match with this payment marks you a returning buyer; no account needed.",
      +  "maxLength": 64,
      +  "type": "string"
      +}
  3. Changed1 schema field changed
    • changedOutput schema / properties / single_probe_note / description
      Previous value: -"One request, one moment — the standing caveat."New value: +"One moment — the standing caveat. Two requests only where a door refuses the first verb."
  4. First observed

TDQS

A4.5/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations give only the generic read/write/idempotency profile, and the description goes well beyond them: it discloses that no signature, settlement or delivery verification occurs, that the result is rate limited with the ceiling carried in the response, that model/client/operator are counted but never printed on the certificate, and that the reading is a single-moment shape check. That is exactly the behavioral context an agent needs before invoking.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The opening sentence is front-loaded and the alternative is placed late where it belongs, but the prose is heavily aphoristic and repetitive — 'preflight' is restated three times, and lines like 'An evidence instrument: the reading is written to be handed to the human behind you, gaps at full weight' are rhetorical rather than informative. Several sentences could be merged without losing content.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With an output schema present, return values need not be explained, and the description still adds the interpretive frame (L0-L6 evidence ladder, tri-state checks vector, what a single probe cannot tell you). For a free, non-destructive inspection tool with one required parameter, nothing an agent needs to call it correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so all seven parameters (url, model, client, operator, came_from, operator_kind, prior_cert_id) are already documented in the schema itself. The description adds no parameter-level syntax, format or ordering detail beyond that, so the baseline 3 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('one unpaid probe answering whether the URL serves a well-formed x402 v2 payment challenge right now') and enumerates the exact checks: 402 status, parseable PAYMENT-REQUIRED, signable accepts, testnet catch. This is unmistakably distinct from sibling probes like look_at_door or check_before_you_pay.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Names both audiences explicitly ('a buyer about to pay a door it has not paid before, and for a seller checking their own') and routes to the alternative for a different need ('For a signed, servable version of this same look, buy_observation with item_id service_audit'). It also states the boundary condition — this is not an uptime or delivery check.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.