Skip to main content
Glama
waxsway

io.github.waxsway/agentresolver

by waxsway

AgentResolver

Continuous API, MCP, and x402 compatibility monitoring for services used by AI agents.

AgentResolver answers a production question ordinary uptime monitors miss: can an AI agent still discover, call, and pay this service right now?

Production: https://agentresolver.vercel.app
Free browser check: https://agentresolver.vercel.app/monitor

x402 Reliability Router

Existing x402 resource servers can route their standard facilitator traffic through AgentResolver without changing the merchant payTo address:

import { HTTPFacilitatorClient } from "@x402/core/server";

const facilitator = new HTTPFacilitatorClient({
  url: "https://agentresolver.vercel.app",
  timeoutMs: 10_000
});

Standard facilitator surface:

GET  /supported
POST /verify
POST /settle

Verification is read-only and may use an explicitly configured secondary. Settlement is submitted to exactly one upstream facilitator; ambiguous timeout/5xx outcomes are marked non-retry-safe instead of being blindly failed over. Full integration guide: x402 Reliability Router.

Related MCP server: wayforth-mcp

Free recurring monitoring with GitHub Actions

Run the public-service check on your own GitHub schedule. No AgentResolver account, API key, wallet, or secret is required.

name: Agent commerce health
on:
  workflow_dispatch:
  schedule:
    - cron: "17 8 * * *"
jobs:
  health:
    runs-on: ubuntu-latest
    steps:
      - uses: waxsway/agentresolver/.github/actions/agent-commerce-health@main
        with:
          origin: https://api.example.com
          # Optional deeper checks:
          # mcp-endpoint: https://api.example.com/mcp
          # x402-endpoint: https://api.example.com/paid

The free Action reports current machine-readiness, optional live MCP initialize + tools/list compatibility, and optional GET-safe x402 payment-contract health. The hosted managed monitor is the $19 / 30-day option when you want AgentResolver to own the hourly schedule and durable status.

Full setup: free GitHub monitoring.

Buyer-side Guard

AgentResolver Guard remains the pre-sign safety check for autonomous x402 payments. Before a target wallet signs, Guard reads the live payment challenge, validates the payment contract, and returns a fail-closed decision plus evidence the caller can bind to its own policy.

What Guard checks

Guard performs one bounded HTTPS preflight against the target and verifies the live x402 contract before the caller authorizes spend:

  • endpoint reachability and HTTPS/TLS evidence

  • PAYMENT-REQUIRED structure

  • x402 version and payment scheme

  • quoted USDC amount

  • optional maxPriceUsd ceiling

  • network

  • asset

  • payTo recipient

  • optional expectedPayTo and expectedNetwork assertions

  • resource/payment binding

  • stable evidence fingerprints for change detection

Guard blocks private/reserved network targets, does not follow redirects, uses bounded timeouts, and fails closed when required evidence is missing or mismatched.

Guard never receives the target-payment private key, signs the target payment, authorizes the target spend, or custodies/forwards target funds. The calling runtime keeps spending authority.

Price

Canonical Guard:

POST or GET https://agentresolver.vercel.app/api/x402-payment-preflight
$0.001 USDC per successful Guard check
Base or Solana where advertised

The compatibility alias /api/payment-guard uses the same Guard product. A Coinbase-CDP-specific Base route is available at /api/cdp-payment-guard for $0.002 USDC because that rail has a higher observed settlement floor.

The intended transaction path

target request
  -> target returns 402
  -> AgentResolver Guard
  -> validate amount / asset / network / payTo / scheme / resource binding
  -> Guard returns eligible or blocked + evidence
  -> caller policy decides
  -> caller-owned wallet may sign the target payment

Guard is evidence for a payment decision, not permission to spend.

Install as a pre-sign hook

The official x402 client exposes onBeforePaymentCreation. Use two x402 clients: one hooked client for the target payment and one hook-free client dedicated to the separate Guard payment. This prevents recursive Guard payments.

The framework-neutral client package now exports the reusable pre-sign hook directly:

import { createAgentResolverX402GuardHook } from "agentresolver-client";

targetClient.onBeforePaymentCreation(
  createAgentResolverX402GuardHook({
    maxTargetPriceUsd: 0.05,
    guardFetch // separate payment-enabled fetch used only for the Guard fee
  })
);

Until registry publication, build packages/agentresolver-client directly from this repository. The hook fails closed and binds AgentResolver evidence back to the exact selected scheme, network, asset, amount, payee, x402 version, and resource before the x402 client can proceed to signing.

Three maintained integration guides:

Install as an Agent Skill

npx skills add waxsway/agentresolver --skill agentresolver-payment-guard

Direct skill source:

https://agentresolver.vercel.app/.well-known/agent-skills/agentresolver-payment-guard/SKILL.md

The skill tells a wallet-capable agent to run Guard before each unfamiliar or changed autonomous x402 spend.

Example Guard request

Guard supports a target URL plus optional caller assertions:

{
  "url": "https://target.example/api",
  "method": "GET",
  "maxPriceUsd": 1.00,
  "expectedPayTo": "0x...",
  "expectedNetwork": "eip155:8453"
}

The unpaid request returns AgentResolver's own x402 challenge. After the caller authorizes and settles the Guard fee, the response contains the observed target-payment terms, reason codes, eligibility decision, and evidence receipt.

What Guard is — and is not

Guard is a transaction-path control for x402 buyers. It is designed to answer a narrow question immediately before signing:

Does the live payment challenge still match the payment contract my agent is willing to authorize?

Guard does not claim that a provider is honest, that a wallet has a particular legal owner, or that future fulfillment is guaranteed. It validates live payment-contract evidence and caller-supplied policy assertions.

Wallet-risk, reputation, AML, and other third-party evidence can be added later through explicit evidence-provider interfaces if real users require them. They are not bundled into Guard by default.

Supporting infrastructure

AgentResolver still exposes supporting infrastructure used by integrations, testing, and open-world fallback workflows. These surfaces are not the primary product:

  • free procure / resolve capability discovery

  • remote MCP control plane: https://agentresolver.vercel.app/mcp/control

  • x402 settlement canaries and compatibility routes

  • machine-readable manifests, OpenAPI, skills, and discovery metadata

  • legacy deterministic utilities retained for compatibility and evidence

New utility endpoints, passive directory submissions, and speculative marketplace-specific builds are not product strategy. Guard is the product; supporting infrastructure exists to help agents reach and use it safely.

Machine-readable surfaces

https://agentresolver.vercel.app/.well-known/x402
https://agentresolver.vercel.app/openapi.json
https://agentresolver.vercel.app/llms.txt
https://agentresolver.vercel.app/.well-known/agentresolver-trust.json

Security

AgentResolver is non-custodial. Never provide it with wallet private keys or seed phrases.

Please report vulnerabilities privately through this repository's GitHub Security Advisories. The production security contact is also published at:

https://agentresolver.vercel.app/.well-known/security.txt

Local development

npm install
npm run dev

License

MIT

Related MCP Connectors

Related MCP Servers