XPeX Plugin Factory MCP
OfficialREADME.md
# XPeX Plugin Factory
Industrial plugin, MCP, skill, validation, and packaging factory by **XPeX Systems AI**.
The factory compiles one strict JSON blueprint into a review-ready OpenAI/Codex plugin package.
**Live Factory:** https://xpex-plugin-factory-production.up.railway.app
**Hire XPeX Plugin Factory:** https://xpex-plugin-factory-production.up.railway.app/pricing
**Readiness Audit — R$49:** https://buy.stripe.com/8x214nbyrgrpaYZ2Ah1B60f
## What it generates
- `plugin.json`
- `.codex-plugin/plugin.json`
- `mcp.json`
- `.mcp.json`
- one or more `skills/*/SKILL.md`
- generated SVG branding asset
- package README
- `FACTORY-REPORT.json`
- deterministic ZIP artifact
## Pipeline
```text
Blueprint
↓
Schema validation
↓
Security policy engine
↓
Manifest + MCP + Skill compiler
↓
Factory report
↓
Deterministic ZIP
```
## Fast start
```bash
npm install
npm run check
npm test
npm run build
node dist/cli.js generate \
examples/gxeon-agent-gateway.blueprint.json \
--out ./generated/gxeon
```
## HTTP API
Start the factory:
```bash
npm run dev
```
Endpoints:
```text
GET /health
GET /v1/schema
GET /mcp
POST /mcp
POST /v1/validate
POST /v1/preview
POST /v1/package
```
### Validate a blueprint
```bash
curl -X POST http://localhost:8080/v1/validate \
-H "Content-Type: application/json" \
--data @examples/gxeon-agent-gateway.blueprint.json
```
### Generate a ZIP
```bash
curl -X POST http://localhost:8080/v1/package \
-H "Content-Type: application/json" \
--data @examples/gxeon-agent-gateway.blueprint.json \
-o gxeon-agent-gateway.zip
```
## Security gates
The V1 compiler rejects or warns on:
- embedded API keys, bearer tokens, Stripe secrets, private keys, and GXEON machine keys;
- localhost/private-network MCP endpoints;
- non-HTTPS MCP endpoints;
- sensitive/account data exposed through anonymous MCP;
- write-capable plugins without human approval;
- machine-key plugin surfaces that need an OAuth boundary for user-linked public distribution;
- commerce configurations that require a current policy review.
Runtime credentials are never generated into plugin packages.
## Reference blueprint
`examples/gxeon-agent-gateway.blueprint.json` is the first real reference product compiled by this factory.
## Architecture
See:
- [Architecture](docs/ARCHITECTURE.md)
- [Security](docs/SECURITY.md)
- [Roadmap](docs/ROADMAP.md)
## Deployment
A production container and `railway.toml` are included. The service exposes `/health` for readiness checks.
## Philosophy
XPeX Plugin Factory is not a prompt generator. It is a software supply-chain compiler for agent products:
```text
PRODUCT IDEA
↓
BLUEPRINT
↓
POLICY
↓
PLUGIN + MCP + SKILLS
↓
TESTS
↓
PACKAGE
↓
PRIVATE / WORKSPACE / REVIEW PIPELINE
```
Built by **XPeX Systems AI**.
## Production
Factory V1 is live at:
```text
https://xpex-plugin-factory-production.up.railway.app
```
Health: `/health` · Schema: `/v1/schema` · Validate: `POST /v1/validate` · Preview: `POST /v1/preview` · Package: `POST /v1/package`
## Agent-native factory access
Factory V0.3.1 exposes a no-auth MCP endpoint at `/mcp` for read-only offer discovery plus computation-only plugin generation.
Available tools:
- `xpex_factory_list_offers`
- `xpex_factory_get_schema`
- `xpex_factory_validate_blueprint`
- `xpex_factory_preview_plugin`
- `xpex_factory_compile_plugin`
The MCP surface never publishes plugins and never mutates third-party systems. ZIP compilation is deterministic and returned as base64 for MCP clients that need a portable artifact.
## Monetization V1
The Factory sells four one-time services through Stripe-hosted Payment Links:
| Offer | Price | Purpose |
| --- | ---: | --- |
| Readiness Audit | R$ 49 | Feasibility, architecture risks, MCP/skill fit, recommended next step |
| Launch | R$ 197 | Blueprint review + validated plugin package |
| Pro | R$ 497 | Custom MCP/skill architecture + review readiness |
| Enterprise | R$ 1.497 | Advanced business integration architecture |
The R$49 Readiness Audit is the low-friction entry product for prospects who want a concrete technical answer before committing to full implementation.
Live sales surface:
```text
GET /pricing
GET /v1/offers
```
The payment flow is intentionally fail-closed:
```text
Factory pricing page
-> Stripe LIVE hosted checkout
-> Stripe signed webhook
-> signature verification
-> payment_status == paid
-> verified payment event
```
A checkout page, quote, pending session, or internal record is never counted as revenue. Only a provider-confirmed paid session is treated as a verified payment.
The production webhook endpoint is:
```text
POST /stripe/webhook
```
Configure `STRIPE_WEBHOOK_SECRET` only as a runtime secret.
## Agent discovery & procurement
XPeX Plugin Factory is designed to be discovered and evaluated by AI agents as well as human developers.
- Agent-readable discovery document: [`public/llms.txt`](public/llms.txt)
- Live offer catalog: `GET https://xpex-plugin-factory-production.up.railway.app/v1/offers`
- MCP endpoint: `https://xpex-plugin-factory-production.up.railway.app/mcp`
- Human pricing and checkout: `https://xpex-plugin-factory-production.up.railway.app/pricing`
Recommended agent flow:
```text
discover XPeX
-> read llms.txt / README
-> query /v1/offers
-> evaluate scope and price
-> use MCP for technical discovery/validation
-> send an authorized buyer to canonical checkout
-> treat the order as paid only after provider-confirmed settlement
```
Suitable requests include plugin packaging, MCP architecture, reusable agent skills, security/readiness audits, blueprint validation, and review-ready agent integration packages.
Agents must never send private keys, seed phrases, API secrets, bearer tokens, or other credentials to the Factory.
## Agent API — USDC per call
`POST /v1/x402/agent-kit` generates a deterministic read-only MCP/plugin starter kit for **0.01 USDC**. Deliverables: blueprint, files, policy report, ZIP and SHA-256. See [live configuration](https://xpex-plugin-factory-production.up.railway.app/v1/x402), [OpenAPI](https://xpex-plugin-factory-production.up.railway.app/openapi.json), and [integration/runbook](docs/AGENT-PAYMENTS.md). Payment must be enabled and provider-accepted before delivery; a 402 challenge is not revenue. Existing full-blueprint APIs remain free.
This server cannot be deployed
Maintenance
ActivityMaintained
ResponsivenessNo issues