Skip to main content
Glama

PulseFeed — open-source x402 client tools

Client-side, MIT-licensed tools for PulseFeed — the independent trust & safety layer for the x402 agent-payment economy.

Before an AI agent pays an x402 endpoint, it should know whether that endpoint is safe to pay — ~70% of x402 endpoints are dead, invalid, or scams, and only about half of what catalogs call "healthy" actually work. PulseFeed independently probes every x402 service, scans for scams (payTo hijack, bait-and-switch, honeypot), verifies the receiver on-chain, and publishes an open Trust Score.

This repo holds the open-source client packages. They talk to PulseFeed's public API (free /verify, live /status, paid /trust). The crawler, scoring engine, and dataset are the service itself at pulsefeed.dev.

Packages

Package

What it does

Install

pulsefeed-x402-ai-tools

Drop-in tools for the Vercel AI SDK and LangChain: verify an x402 endpoint before your agent pays + discover working services

npm i pulsefeed-x402-ai-tools

pulsefeed-x402-guard

Wrap your paying fetch — every payment is verified first; dead/scam endpoints are blocked automatically (zero deps)

npm i pulsefeed-x402-guard

pulsefeed-x402-mcp

MCP server: gives Claude Desktop / Cursor / Cline tools to find live x402 services and verify endpoints before paying

npx -y pulsefeed-x402-mcp

Related MCP server: BlueAgent x402 Services

Quick example

import { verifyX402Endpoint } from "pulsefeed-x402-ai-tools";

const v = await verifyX402Endpoint("https://api.some-x402-service.com/data");
if (v.verdict === "avoid") throw new Error("don't pay this endpoint");

MCP config

{ "mcpServers": { "pulsefeed": { "command": "npx", "args": ["-y", "pulsefeed-x402-mcp"] } } }

MCP server safety

Beyond x402, PulseFeed applies the same independent-audit playbook to the MCP server ecosystem — because a bad MCP server can run arbitrary code on your machine the moment you install it, and most people connect one without ever checking.

  • 🔎 MCP Observatory — independent safety audit of the MCP server ecosystem (install-script / code-execution risk, abandonment, provenance, license, liveness)

  • 📊 State of MCP Security — daily report. Right now ~10% of ~800 audited MCP servers run an install script (arbitrary code at npm i), and dozens ship no repo to review. (Install scripts aren't always malicious — native builds use them — but each is an unreviewed code-execution vector.)

  • ✅ Check any server free: GET https://pulsefeed.dev/mcp/verify?package=<npm-name> — verdict + flags before you connect it

Security Disclosures & Data API

  • 🚨 Security Disclosures — a live feed of real threats caught in the x402 economy (receiver hijacks, bait-and-switch pricing, honeypots, unverified receivers), each with on-chain proof you can verify yourself. Machine feed: /incidents.json · RSS

  • 📦 Data API — the wholesale trust backbone for agentic commerce: every x402 service’s moat profile + every audited MCP server + ecosystem aggregates + live incidents in one call ($1 over x402). Free preview + full schema: /data.json

MIT © PulseFeed

Install Server
A
license - permissive license
A
quality
B
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/Nikolife2016/pulsefeed-x402'

If you have feedback or need assistance with the MCP directory API, please join our Discord server