Skip to main content
Glama
Nikoble1926

nsgoods workbench MCP

What it answers

A hosted Model Context Protocol server over our weekly full scan of the x402 catalogue: is this endpoint payable, what does it cost, which host is gone, which endpoints match a keyword, and whether a signed nsgoods response verifies offline.

Hosted endpoint: https://mcp.nsgoods.org/mcp (Streamable HTTP, no sign in, 300 tool calls per IP per day). Landing and docs: https://mcp.nsgoods.org/ · Health: https://mcp.nsgoods.org/health

Data is point in time from the last full scan. Every answer carries as_of and the scan id. For a live check of one endpoint before paying, use the paid /payable oracle on the hub. This server is the index.

Related MCP server: GPT55 x402 Gateway

Connect

Claude (web or desktop)

  1. Settings, then Connectors, then Add custom connector

  2. Name: nsgoods. URL: https://mcp.nsgoods.org/mcp. No sign in.

  3. New conversation, then ask for example: Using nsgoods, find the cheapest payable endpoint for sanctions screening on Base

Cursor: add to mcp.json

{"mcpServers":{"nsgoods":{"url":"https://mcp.nsgoods.org/mcp"}}}

Smithery: https://smithery.ai/servers/nikosble1926/nsgoods-workbench

Any MCP client that supports Streamable HTTP works the same way.

Tools

tool

what it answers

find_endpoints

search the catalogue by host or keyword, with the latest verdict and the observed price per endpoint, optional sort by price

payability_verdict

verdict, history, remediation hint and price for one exact URL

catalogue_stats

size of the catalogue, verdict counts, payable endpoints per network, median price

host_summary

per host verdict mix, first and last seen, gone since

drift_status

verdict changes between scans

x401_status

current x401 emitter count

verify_signature

verify any nsgoods signed response offline against our manifest

reports

links to the weekly payability reports

All tools are read only and idempotent (declared through MCP tool annotations).

Verdicts: PAYABLE, NOT_PAYABLE, MALFORMED_402, CANNOT_PAY_EITHER_VERB, UNREACHABLE, SKIPPED, UNKNOWN.

Example

A live find_endpoints("erc20-balance", 2) call, trimmed to two rows:

{
  "query": "erc20-balance",
  "total_matches": 6,
  "returned": 2,
  "endpoints": [
    {
      "resource": "https://api.onesource.io/api/chain/erc20-balance",
      "host": "api.onesource.io",
      "last_verdict": "PAYABLE",
      "host_gone_since": null,
      "price": "0.003 USDC on eip155:8453"
    },
    {
      "resource": "https://app.heinrichstech.com/v1/cdp/chain/erc20-balance",
      "host": "app.heinrichstech.com",
      "last_verdict": "PAYABLE",
      "host_gone_since": null,
      "price": "0.003 USDC on eip155:8453"
    }
  ],
  "as_of": "2026-09-13",
  "index_scan_id": "scan-20260913T050332Z"
}

Data and freshness

Index is rebuilt after each weekly full scan (14,652 resources, 1,971 hosts, 13,146 payable as of 13 September 2026). Prices come from a sweep of the 402 challenges (10,958 endpoints priced, median 0.01 USDC, 16 September 2026). A per endpoint sample with a GET only re-probe outcome per row is published under CC BY 4.0: https://x402.nsgoods.org/proof/payability-sample-2026-09-13.json

Resources that are no longer in the latest full CDP Bazaar scan are re-probed weekly in a separate reprobe scan: only non-PAYABLE rows, oldest first, up to 1,500 per week. Those rows keep in_latest_scan=false and carry their own last_checked_at and verdict_since; the latest full scan numbers (catalogue_stats, /health) do not include them.

Run your own

python -m venv venv && venv/bin/pip install -r requirements.txt

Put your own scans.jsonl (one JSON line per probe, see build_index.py for the fields) next to the scripts, then:

venv/bin/python build_index.py
venv/bin/python server.py   # listens on 127.0.0.1:4036, path /mcp

Docker:

docker build -t nsgoods-workbench-mcp . && docker run -p 4036:4036 nsgoods-workbench-mcp

Docker image is untested (built without a Docker host). Set WORKBENCH_HOST=0.0.0.0 inside containers. Feedback welcome.

Environment variables:

var

default

meaning

WORKBENCH_DIR

.

base directory for the index and data files

WORKBENCH_DATA_DIR

WORKBENCH_DIR

directory for scans.jsonl and watch state

WORKBENCH_HOST

127.0.0.1

bind address

The server creates an empty index on first run if none is present, so tools/list works before you load any data.

Privacy and logging

This server needs no wallet and no sign in. It keeps a minimal record of tool usage so we can operate and rate limit the service.

  • Per tool call we store: timestamp, tool name, the names and lengths of the arguments, and ip_h, a daily keyed hash of the caller IP. We do not store argument values, and we do not store the raw IP or the MCP session id.

  • ip_h is HMAC-SHA256(daily_secret, ip) truncated to 16 hex characters. The secret is random, held only in memory, replaced at each UTC day change and never written down, so after the day ends the hash cannot be linked back to an IP.

  • The same ip_h drives the free limit of 300 tool calls per caller per day. If the server restarts during a UTC day, a new secret is generated, so the counter restarts for everyone for the rest of that day.

  • Records are deleted after 30 days. Records written before 26 September 2026 used a fuller format (caller IP, session id and the first 80 characters of each argument); they are deleted on the same schedule, the last of them by 26 October 2026.

The current field list and retention are also reported live at GET /health under tool_log.

Verification

Signed nsgoods responses use EIP-191 over canonical JSON (sorted keys, compact separators, ASCII escaped, signature and signed_by removed before hashing). The verify_signature tool checks the recovered address against the signers in https://x402.nsgoods.org/proof/index.json

Verifying what runs. python3 scripts/pin_verify_signature.py server.py prints the line range, byte range and sha256 of the verify_signature function body (def to end, decorators excluded, LF line endings, no trailing newline) and the sha256 of the whole file. A matching hash is repo evidence only: it shows that the published source is the one described. It is not deployment evidence. The stronger evidence for what the server runs is behavioural: calling the live tools and checking that the results match what this source produces.

Landing https://mcp.nsgoods.org/ · Hub https://x402.nsgoods.org · MCP section https://x402.nsgoods.org/#mcp Weekly report https://x402.nsgoods.org/proof/payability-report-2026-09-13.html Methodology https://x402.nsgoods.org/ata-audit/payability_index.json (method field)

MIT license.

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    F
    maintenance
    Enables agents to search and inspect live service offerings, generate x402 payment snippets, and understand blockchain-only balance policies.
    4
    40 npm
    3
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Provides a read-only MCP gateway and quote-first buyer client for the GPT55 x402 service, enabling service discovery, catalog access, and safe payment quote checking without signing transactions.
    MIT
  • F
    license
    Not graded
    quality
    B
    maintenance
    Provides access to measured x402 ecosystem data, allowing users to query which merchants actually accept payment (verified by real on-chain settlements) and explore market concentration and health statistics.
    -
  • A
    license
    Not graded
    quality
    B
    maintenance
    Lets agents discover, verify, and inspect x402/B402 payment endpoints on BNB Chain, with read-only tools to list skills, check live counter behavior, and review the settlement tape.
    4 npm
    MIT