XPeX Plugin Factory MCP
OfficialCompiles a JSON blueprint into a review-ready OpenAI/Codex plugin package, emitting plugin.json and .codex-plugin/plugin.json manifests along with skills and MCP configs intended for OpenAI/Codex review pipelines.
Integrates with Stripe-hosted Payment Links and signed webhooks to sell one-time services (Readiness Audit, Launch, Pro, Enterprise). Verifies webhook signatures and the paid payment_status to confirm a session as settled revenue, exposing a /stripe/webhook endpoint and requiring STRIPE_WEBHOOK_SECRET as a runtime secret.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@XPeX Plugin Factory MCPvalidate this blueprint, preview the plugin, and compile the package"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
XPeX Plugin Factory
Industrial plugin, MCP, skill, validation, and packaging factory by XPeX Systems AI.
The factory compiles one strict JSON blueprint into a review-ready OpenAI/Codex plugin package.
Live Factory: https://xpex-plugin-factory-production.up.railway.app
Hire XPeX Plugin Factory: https://xpex-plugin-factory-production.up.railway.app/pricing
Readiness Audit — R$49: https://buy.stripe.com/8x214nbyrgrpaYZ2Ah1B60f
What it generates
plugin.json.codex-plugin/plugin.jsonmcp.json.mcp.jsonone or more
skills/*/SKILL.mdgenerated SVG branding asset
package README
FACTORY-REPORT.jsondeterministic ZIP artifact
Related MCP server: universal-agent-control-plane
Pipeline
Blueprint
↓
Schema validation
↓
Security policy engine
↓
Manifest + MCP + Skill compiler
↓
Factory report
↓
Deterministic ZIPFast start
npm install
npm run check
npm test
npm run build
node dist/cli.js generate \
examples/gxeon-agent-gateway.blueprint.json \
--out ./generated/gxeonHTTP API
Start the factory:
npm run devEndpoints:
GET /health
GET /v1/schema
GET /mcp
POST /mcp
POST /v1/validate
POST /v1/preview
POST /v1/packageValidate a blueprint
curl -X POST http://localhost:8080/v1/validate \
-H "Content-Type: application/json" \
--data @examples/gxeon-agent-gateway.blueprint.jsonGenerate a ZIP
curl -X POST http://localhost:8080/v1/package \
-H "Content-Type: application/json" \
--data @examples/gxeon-agent-gateway.blueprint.json \
-o gxeon-agent-gateway.zipSecurity gates
The V1 compiler rejects or warns on:
embedded API keys, bearer tokens, Stripe secrets, private keys, and GXEON machine keys;
localhost/private-network MCP endpoints;
non-HTTPS MCP endpoints;
sensitive/account data exposed through anonymous MCP;
write-capable plugins without human approval;
machine-key plugin surfaces that need an OAuth boundary for user-linked public distribution;
commerce configurations that require a current policy review.
Runtime credentials are never generated into plugin packages.
Reference blueprint
examples/gxeon-agent-gateway.blueprint.json is the first real reference product compiled by this factory.
Architecture
See:
Deployment
A production container and railway.toml are included. The service exposes /health for readiness checks.
Philosophy
XPeX Plugin Factory is not a prompt generator. It is a software supply-chain compiler for agent products:
PRODUCT IDEA
↓
BLUEPRINT
↓
POLICY
↓
PLUGIN + MCP + SKILLS
↓
TESTS
↓
PACKAGE
↓
PRIVATE / WORKSPACE / REVIEW PIPELINEBuilt by XPeX Systems AI.
Production
Factory V1 is live at:
https://xpex-plugin-factory-production.up.railway.appHealth: /health · Schema: /v1/schema · Validate: POST /v1/validate · Preview: POST /v1/preview · Package: POST /v1/package
Agent-native factory access
Factory V0.3.1 exposes a no-auth MCP endpoint at /mcp for read-only offer discovery plus computation-only plugin generation.
Available tools:
xpex_factory_list_offersxpex_factory_get_schemaxpex_factory_validate_blueprintxpex_factory_preview_pluginxpex_factory_compile_plugin
The MCP surface never publishes plugins and never mutates third-party systems. ZIP compilation is deterministic and returned as base64 for MCP clients that need a portable artifact.
Monetization V1
The Factory sells four one-time services through Stripe-hosted Payment Links:
Offer | Price | Purpose |
Readiness Audit | R$ 49 | Feasibility, architecture risks, MCP/skill fit, recommended next step |
Launch | R$ 197 | Blueprint review + validated plugin package |
Pro | R$ 497 | Custom MCP/skill architecture + review readiness |
Enterprise | R$ 1.497 | Advanced business integration architecture |
The R$49 Readiness Audit is the low-friction entry product for prospects who want a concrete technical answer before committing to full implementation.
Live sales surface:
GET /pricing
GET /v1/offersThe payment flow is intentionally fail-closed:
Factory pricing page
-> Stripe LIVE hosted checkout
-> Stripe signed webhook
-> signature verification
-> payment_status == paid
-> verified payment eventA checkout page, quote, pending session, or internal record is never counted as revenue. Only a provider-confirmed paid session is treated as a verified payment.
The production webhook endpoint is:
POST /stripe/webhookConfigure STRIPE_WEBHOOK_SECRET only as a runtime secret.
Agent discovery & procurement
XPeX Plugin Factory is designed to be discovered and evaluated by AI agents as well as human developers.
Agent-readable discovery document:
public/llms.txtLive offer catalog:
GET https://xpex-plugin-factory-production.up.railway.app/v1/offersMCP endpoint:
https://xpex-plugin-factory-production.up.railway.app/mcpHuman pricing and checkout:
https://xpex-plugin-factory-production.up.railway.app/pricing
Recommended agent flow:
discover XPeX
-> read llms.txt / README
-> query /v1/offers
-> evaluate scope and price
-> use MCP for technical discovery/validation
-> send an authorized buyer to canonical checkout
-> treat the order as paid only after provider-confirmed settlementSuitable requests include plugin packaging, MCP architecture, reusable agent skills, security/readiness audits, blueprint validation, and review-ready agent integration packages.
Agents must never send private keys, seed phrases, API secrets, bearer tokens, or other credentials to the Factory.
Agent API — USDC per call
POST /v1/x402/agent-kit generates a deterministic read-only MCP/plugin starter kit for 0.01 USDC. Deliverables: blueprint, files, policy report, ZIP and SHA-256. See live configuration, OpenAPI, and integration/runbook. Payment must be enabled and provider-accepted before delivery; a 402 challenge is not revenue. Existing full-blueprint APIs remain free.
This server cannot be deployed
Maintenance
Related MCP Connectors
Free agent-service discovery, OpenAPI document checks, and receipt verification. No API key needed.
The governed runtime for agent skills. Search the catalog and inspect a skill before running it.
Agent-native catalogue of Baseframe Labs dev tools and MCP servers.
Build and run grounded business agents over MCP: agents, knowledge bases, skills, Storylines.
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceA local, read-only MCP server that lets coding agents search the complete AAS skill catalog, compose and validate agent-chosen skill stacks, and generate reproducible, reviewable plans without uploading project code.5,683 npm1MIT
- AlicenseBqualityBmaintenanceEnables centrally authoring and validating reusable agent guidance and delivering it across MCP-compatible hosts via registry resources, prompt templates, skill execution, and shared state.7MIT

wellwornofficial
FlicenseNot gradedqualityDmaintenanceProvides coding agents with verified recommendations, version-specific breakage traps, design systems, and installable skills over MCP, enabling safer stack and dependency decisions without requiring an API key.1-- AlicenseBqualityBmaintenanceEnables MCP clients to drive developer workflows through APIs and CLIs, with explicit workspace or trusted-workstation launch modes, bounded command previews, multi-repository rules discovery, and an on-demand skills/recipes entry point. It lets agents review changes, run commands, and load only the smallest relevant rule or skill while reporting evidence and unverified steps.191Apache 2.0