Connect an x402 MCP client
Add the endpoint to an MCP client that supports x402 v2 payments on Base mainnet. Discovering tools is free; payment is requested only when a paid tool is called.
Services for AI agents
These are our separate products on the same MCP endpoint. Each service card lists its purpose and tools; the prices below update from the same service catalog.
Invoice Preflight
Checks invoice fields and calculations against expected purchase details, then returns evidence and a clear review signal.
For UBL XML invoices or complete PDF/image invoices. OCR tiers check the full document up to the selected page limit.
invoice_preflight_quoteFreeinvoice_preflight$0.065 USDCinvoice_preflight_10_pages$0.13 USDCinvoice_preflight_50_pages$0.475 USDC
MCP Server Inspector
Checks whether a public MCP endpoint responds and summarizes its advertised tools, input schemas, and basic risk flags.
Read-only inspection: it does not run the target server's tools and does not use Mistral or OCR.
mcp_server_inspect$0.01 USDC
Agent Preflight · URL Safety Gate
Checks an unknown URL before an agent opens or relies on it, returning a structured allow, caution, or block signal.
Uses deterministic URL, host/IP, pattern, and HTTPS redirect checks. It never loads page content or uses an LLM. Without an optional threat-intelligence key, results are marked heuristic-only and degraded.
check_url$0.005 USDC
Prompt-Injection Firewall
Scans untrusted content before an agent adds it to context, follows its instructions, or acts on it.
Deterministic local analysis returns a structured risk report and sanitized plain text where possible; it does not call an LLM or store raw content.
scan_content$0.005 USDC
Transaction Preflight
Simulates an unsigned Base transaction before signing and returns gas estimates, decoded top-level calls, approval warnings, and a machine-readable risk signal.
Read-only RPC simulation only. It never signs, holds keys, or broadcasts; internal token state changes are not exposed by standard RPC and are not claimed as decoded movements.
simulate_transaction$0.02 USDC
Wallet Risk Check
Checks a Base wallet or contract as a counterparty before an agent sends funds, accepts payment, grants approval, or interacts with it.
Reads basic on-chain metadata and, on Base mainnet, queries GoPlus Address Security for public reputation flags. Unsupported categories remain unknown; only the checked public address is sent to the provider.
check_wallet$0.02 USDCtoken_security_audit$0.01 USDC
Package Safety Gate
Checks an npm dependency version for known vulnerabilities, malware advisories, typosquatting, and risky install scripts before installation.
Reads public npm metadata and OSV vulnerability advisories. Package scripts and source code are analyzed as text only and are never executed; direct dependency trees and maintainer history are not recursively assessed in this MVP.
check_package$0.005 USDC
Agent Tool Router + Trust Layer
Finds and ranks machine-payable MCP tools and x402 endpoints by capability, price, observed performance, trust, and agent constraints.
Returns a recommendation only; it never calls or pays the selected provider. External Bazaar discovery is optional and configured separately; local results have cold-start confidence.
route_tool$0.002 USDC
Live Product Quote
Retrieves current structured product price and availability before an agent buys.
Uses public HTTPS pages and static JSON-LD/product metadata only. Shipping and tax remain unknown unless page data explicitly provides them.
get_live_quote$0.01 USDC
Fresh Structured Extract
Turns public webpage data into schema-shaped JSON with field provenance and explicit missing values.
Static JSON-LD, metadata, and visible text only; no browser JavaScript or LLM. Arbitrary private-network URLs are blocked.
extract_structured$0.01 USDC
Change / Diff Check
Compares a page's normalized text with a previous hash and returns a compact diff when a prior snapshot is available.
Stateless hash comparison with short-lived in-memory snapshots. Authenticated pages are not supported.
check_change$0.001 USDC
Freshness / Claim Verifier
Checks a factual claim against fresh web search evidence and reports support, conflict, staleness, or insufficient evidence.
Requires Tavily Search API key for evidence retrieval. If it is not configured, the tool returns a provider-unavailable error before requesting payment. No model knowledge is used as evidence.
verify_claim$0.02 USDC
Trade Execution Quote
Estimates a swap output and route using a configured aggregator quote before an agent trades.
Read-only quote only. Solana uses Jupiter and EVM chains use 0x when their API keys are configured. This is not an execution guarantee; gas USD and account-specific fees may be unknown.
estimate_trade_execution$0.01 USDC
Whale Intelligence
Summarizes large indexed DEX trades around a token and marks size-based wallet labels as heuristic.
Asset mode uses GeckoTerminal public pool/trade data; it is not a chain-wide transfer feed. Wallet mode uses Helius on Solana or Etherscan API V2 for supported EVM chains when configured; it reports recent indexed transactions only, not a complete portfolio valuation.
analyze_whale_activity$0.02 USDC
Arbitrage Intelligence
Compares Binance and Coinbase order books at a requested trade size after configurable taker-fee assumptions.
Public order-book snapshots only. It excludes deposits, withdrawals, inventory rebalancing, and guaranteed execution; stale or incomplete books are rejected.
scan_arbitrage$0.03 USDC
Strategy Backtest
Backtests built-in long-only spot strategies against public Binance candles with next-candle execution.
No user code is executed. Includes configurable fees/slippage and bounded historical data; results are historical simulations, not predictions.
backtest_strategy$0.10 USDC
1. Connect
Use this Streamable HTTP MCP endpoint:
https://mcp.dropenginehq.com/api/paid-mcp
Discover available tools with tools/list. The endpoint advertises payment requirements when a paid tool is called without a valid payment.
2. A guarded agent call
This Node.js example gets a free quote first, then permits payment only for the quoted tier, the published seller address, Base mainnet USDC, and a per-call ceiling of $0.475. A human must approve the exact charge in the terminal. Keep the buyer key in a secret manager or local environment variable; never put it in agent prompts or source control.
import { createInterface } from "node:readline/promises";
import { stdin, stdout } from "node:process";
import { Client } from "@modelcontextprotocol/sdk/client/index.js";
import { StreamableHTTPClientTransport } from "@modelcontextprotocol/sdk/client/streamableHttp.js";
import { x402Client } from "@x402/core/client";
import { ExactEvmScheme } from "@x402/evm/exact/client";
import { wrapMCPClientWithPayment } from "@x402/mcp";
import { privateKeyToAccount } from "viem/accounts";
const endpoint = "https://mcp.dropenginehq.com/api/paid-mcp";
const usdc = "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913";
const network = "eip155:8453";
const seller = process.env.INVOICE_PREFLIGHT_SELLER?.toLowerCase();
const key = process.env.AGENT_WALLET_PRIVATE_KEY;
if (!seller || !key) throw new Error("Set the verified seller address and buyer key in your secret manager.");
const mcp = new Client({ name: "invoice-agent", version: "1.0.0" });
const paymentClient = new x402Client().register(network, new ExactEvmScheme(
privateKeyToAccount(key as `0x${string}`),
));
let expectedAmount;
const paid = wrapMCPClientWithPayment(mcp, paymentClient, {
autoPayment: true,
onPaymentRequested: async ({ toolName, paymentRequired }) => {
const req = paymentRequired.accepts.find((item) =>
item.network === network && item.asset.toLowerCase() === usdc.toLowerCase() &&
item.payTo.toLowerCase() === seller && BigInt(item.amount) === expectedAmount);
if (!req || !["invoice_preflight", "invoice_preflight_10_pages", "invoice_preflight_50_pages"].includes(toolName)) return false;
const rl = createInterface({ input: stdin, output: stdout });
try {
const usd = (Number(req.amount) / 1_000_000).toFixed(6);
return (await rl.question(`Approve $${usd} USDC for ${toolName}? Type YES: `)).trim() === "YES";
} finally { rl.close(); }
},
});
await paid.connect(new StreamableHTTPClientTransport(new URL(endpoint)));
try {
const quoteResult = await paid.callTool("invoice_preflight_quote", { document_type: "pdf", page_count: 8 });
const quote = JSON.parse(quoteResult.content?.[0]?.text ?? "{}");
if (quote.status !== "ready" || quote.network !== network || !quote.recommended_tool || !quote.price_usdc) {
throw new Error(quote.reason ?? "No supported paid tier was quoted.");
}
const [whole, fraction = ""] = String(quote.price_usdc).split(".");
expectedAmount = BigInt(whole) * 1_000_000n + BigInt((fraction + "000000").slice(0, 6));
if (expectedAmount <= 0n || expectedAmount > 475_000n) throw new Error("Quoted price exceeds the $0.475 per-call limit.");
const result = await paid.callTool(quote.recommended_tool, {
document_url: process.env.INVOICE_PDF_URL,
expected: { purchase_order: "PO-8841", currency: "USD", total: "124.00" },
});
console.log(result.content?.[0]?.text);
} finally { await mcp.close(); }Set INVOICE_PREFLIGHT_SELLER to the full seller receive address shown in the product’s verified listing and INVOICE_PDF_URL to a public HTTPS PDF URL. The example aborts if the quote or payment challenge differs from the expected chain, token, seller, amount, or tool.
3. Choose a tool
Call invoice_preflight_quote first if the price tier is uncertain. It is free, needs no wallet or document, and returns the cheapest supported tool for a stated document type and PDF page count. For example, send {"document_type":"pdf","page_count":8} to select the 10-page tier. The paid call still validates the actual file.
invoice_preflight_quoteDocument type, optional file size and PDF page countFreeinvoice_preflightUBL XML or PDF/image up to 3 pages$0.065 USDCinvoice_preflight_10_pagesPDF/image up to 10 pages$0.13 USDCinvoice_preflight_50_pagesPDF/image up to 50 pages$0.475 USDCmcp_server_inspectPublic, unauthenticated MCP endpoint over HTTPS$0.01 USDCcheck_urlOne HTTP or HTTPS URL, up to 4096 characters$0.005 USDCscan_contentText, HTML, email, document text, API response, or tool output up to 100,000 characters by default$0.005 USDCsimulate_transactionUnsigned Base or Base Sepolia transaction fields (from, to, value in wei, calldata)$0.02 USDCcheck_walletBase or Base Sepolia chain and one public EVM address$0.02 USDCtoken_security_auditSupported EVM chain and public token contract address$0.01 USDCcheck_packagenpm package name and optional exact semantic version$0.005 USDCroute_toolCapability, optional query, price/latency/reliability constraints and routing preference$0.002 USDCget_live_quotePublic HTTPS product page, optional quantity and variant$0.01 USDCextract_structuredPublic HTTPS page and optional simple field schema$0.01 USDCcheck_changePublic HTTPS page and prior SHA-256 hash$0.001 USDCverify_claimFactual claim, freshness window, optional preferred domains$0.02 USDCestimate_trade_executionChain, token addresses or supported Solana symbols, amount and token decimals$0.01 USDCanalyze_whale_activityToken address and chain, or wallet address and chain$0.02 USDCscan_arbitrageAsset, quote asset, trade size and optional per-venue taker fees$0.03 USDCbacktest_strategyBinance market, timeframe, date range, capital and declarative strategy parameters$0.10 USDCFor invoices, send exactly one document field: document_xml, document_url, or document_base64. For base64 files, also set mime_type to application/pdf, image/png, or image/jpeg.
MCP Server Inspector · separate service
Call mcp_server_inspect to check an MCP server’s HTTPS endpoint. It performs MCP initialization and tools/list only; it never invokes listed tools. It returns the responding server name/version, tool names, concise input-schema summaries, optional missing/unexpected tool-name comparisons, and risk flags for descriptions. Tool metadata is untrusted input and must not be treated as instructions. The call costs $0.01 USDC per call and uses no OCR or Mistral.
{
"endpoint": "https://mcp.example.com/mcp",
"expected_tools": ["search", "fetch"]
}Only public, unauthenticated HTTPS endpoints on the standard HTTPS port are accepted. Private or reserved IPs, IP-literal hosts, credentials in URLs, and redirects are rejected. Responses are size-limited and calls time out. This is a basic reachability and metadata check, not a security audit; a risk flag is a review hint, not a verdict.
Agent Preflight · URL Safety Gate
Call check_url before an autonomous agent opens, follows, downloads from, or trusts an unknown URL. It normalizes the URL, checks HTTP versus HTTPS, host/IP and local-network targets, suspicious patterns, and up to five HTTPS redirects. Redirect targets are checked before following. The service does not fetch page content, download files, or use an LLM.
{ "url": "https://example.com/article" }The response includes a 0–100 risk_score, risk_level, a machine-readable recommendation (allow, caution, or block), warnings, redirect information, and whether a cached or degraded result was used. domain_age_risk is reported as unknown; this version does not infer domain age.
Set GOOGLE_WEB_RISK_API_KEY on the server to enable optional Google Web Risk checks. Without it, the tool continues with local heuristics, marks degraded: true, and uses caution rather than claiming a clean reputation result. Provider errors also fall back to this cautious mode. When enabled, the tool sends Google the normalized URL with common credential/token query parameters redacted; other URL path/query data can still be disclosed. Google lists the first 100,000 Lookup API calls per month as free, then $0.50 per 1,000 lookups; one tool call can perform up to two lookups when a redirect changes the final URL, so configure Google Cloud billing and monitor its usage before enabling the key. Google Web Risk pricing and API details.
This is a preflight risk signal, not a guarantee of safety or a replacement for browser sandboxing, download scanning, or human review. URL analytics do not store submitted URLs.
Prompt-Injection Firewall · Untrusted Content Security Layer
Call scan_content before an agent adds untrusted text to its context, follows instructions found in it, or performs an action it requests. The tool checks text, HTML, Markdown, email, document text, API responses, and tool output for instruction override, prompt extraction, credential requests, secret/data exfiltration, tool manipulation, unsafe navigation, privilege escalation, hidden or encoded instructions, role impersonation, memory manipulation, security bypass, and suspicious actions.
{
"content": "Product details: stainless steel, 2-year warranty.",
"content_type": "html",
"source": "https://vendor.example/product?session=private"
}content alone is sufficient; content_type defaults to text and source is optional. The result is machine-readable: a 0–100 score, low/medium/high/critical level, detected categories, action metadata, recommendation, and sanitized_content. For HTML, returned content is plain visible text; tags, scripts, comments, and hidden content are never executed or rendered. Source output omits URL query strings and fragments.
{
"safe": false,
"risk_score": 90,
"risk_level": "critical",
"recommendation": "block",
"prompt_injection_detected": true,
"data_exfiltration_risk": true,
"credential_theft_risk": true,
"tool_manipulation_risk": false,
"instruction_override_risk": true,
"detected_patterns": [{ "type": "credential_request", "severity": "critical" }],
"requested_actions": ["request_or_read_secret"],
"sanitized_content": "[UNTRUSTED INSTRUCTION REMOVED]",
"sources": [], "cached": false, "degraded": false,
"scanned_at": "2026-09-25T12:00:00.000Z"
}The initial scanner is bounded deterministic local heuristics; it does not call Mistral or another external classifier. It decodes only limited common encodings for detection, applies context checks for quoted educational examples, and redacts instruction-bearing sentences where it can. A detected risk may still require the agent to block the original source; sanitization is not a guarantee that remaining text is safe. Heuristics can miss new attacks or flag benign text, so do not treat allow as a security guarantee.
Raw content is not logged or persisted. An in-memory cache stores only derived risk metadata, keyed by a normalized SHA-256 hash; the current request’s sanitized text is regenerated and is not cached. Cache TTL and input limit are configurable using SCAN_CONTENT_CACHE_TTL_SECONDS (default 300; set 0 to disable) and SCAN_CONTENT_MAX_CHARS (default 100,000; bounded to 1,000–1,000,000). Price is configured with SCAN_CONTENT_PRICE_USD and defaults to $0.005 USDC per call. Payment is required before scanning begins.
Transaction Preflight · Simulate before you sign
Call simulate_transaction with unsigned transaction fields before your agent signs or broadcasts a Base transaction. The tool uses read-only JSON-RPC calls (eth_chainId, eth_call, eth_estimateGas) and reports execution/revert status, simulated block, gas estimates, recognized top-level method selectors, direct ERC-20 transfer/approval calldata, unlimited approvals, and a conservative risk recommendation. It never accepts signing keys, signs, holds keys, or broadcasts.
{
"chain": "base-sepolia",
"from": "0x1111111111111111111111111111111111111111",
"to": "0x2222222222222222222222222222222222222222",
"value": "0",
"data": "0x"
}Use chain: "base" for Base mainnet or chain: "base-sepolia" for test simulation. Configure server-side BASE_RPC_URL and BASE_SEPOLIA_RPC_URL; they default to the public Base RPC endpoints. Values and estimated gas costs are returned in wei; USD estimates are null without a price provider.
Analysis limit: standard RPC simulation does not provide a complete state diff or internal ERC-20 movements. Transfer and approval details are decoded only from top-level calldata and are not proof of final asset movements. Nested calls, proxy behavior, contract reputation, and malicious-contract intelligence require a trace-capable simulation/reputation provider and are outside this MVP. Unknown selectors remain unknown. Treat allow as a preflight signal, not a guarantee; verify recipient, chain, and amount independently.
Unlimited approvals produce a high-risk caution. Reverts, RPC mismatch, or provider failures never return allow. The tool costs $0.02 USDC per call by default; configure it with SIMULATE_TRANSACTION_PRICE_USD. RPC timeout and short cache TTL use SIMULATE_TRANSACTION_RPC_TIMEOUT_MS and SIMULATE_TRANSACTION_CACHE_TTL_SECONDS (default 8 seconds and 3 seconds). Payment is required before simulation starts.
Wallet Risk Check · Check the counterparty before value moves
Call check_wallet before sending funds to, accepting value from, granting an approval to, or interacting with an unfamiliar EVM address. It supports Base and Base Sepolia, validates and normalizes the public address, checks wallet versus contract using bytecode, and reads native balance, EOA transaction nonce, current block, and chain ID. It never accepts signing credentials or performs a transfer.
{ "chain": "base-sepolia", "address": "0x1111111111111111111111111111111111111111" }{
"success": true, "chain": "base-sepolia", "address_type": "wallet",
"risk_score": 25, "risk_level": "medium", "risk_confidence": "low",
"recommendation": "caution", "reputation": "unknown",
"sanctions_match": null, "known_malicious": null, "scam_risk": null, "drainer_risk": null,
"mixer_exposure": { "level": "unknown", "direct": null },
"sources": ["local_onchain_analysis"], "degraded": false, "cached": false
}RPC-derived facts are limited to chain ID, code existence/size, native balance, EOA transaction count (nonce), and current block. Nonce is not total incoming/outgoing activity. On Base mainnet, GoPlus Address Security supplies public reputation flags by default; only the checked public address is sent, and the local adapter caps traffic at 25 requests/minute. Set GOPLUS_API_ENABLED=0 to disable it. It is not called on Base Sepolia. The result does not claim complete wallet history, stolen-funds graph exposure, or a dedicated drainer assessment; unsupported findings remain null. Missing coverage stays unknown and results remain cautious rather than certifying that an address is safe. Provider failures mark the result degraded. Cache TTL defaults to 120 seconds and is configurable with CHECK_WALLET_CACHE_TTL_SECONDS; RPC and optional intelligence-provider timeouts use WALLET_RISK_RPC_TIMEOUT_MS and WALLET_RISK_PROVIDER_TIMEOUT_MS (default 8 seconds). Price is configured by CHECK_WALLET_PRICE_USD and defaults to $0.02 USDC per call. Use this as one risk signal, not proof that an address is safe.
Package Safety Gate · Check before install
Call check_package before an autonomous coding agent installs, imports, or adds an unfamiliar dependency. MVP supports public npm packages only. It resolves latest when version is omitted; otherwise use an exact semantic version such as 1.7.0. Registry metadata and OSV vulnerability/malware advisories are checked, package names are compared against a curated popular-package list for likely typosquats, and lifecycle scripts are inspected as plain text. Package code and tarballs are never downloaded, installed, imported, or executed.
{ "ecosystem": "npm", "package": "is-number" }{
"success": true, "ecosystem": "npm", "package": "is-number",
"requested_version": null, "resolved_version": "7.0.0",
"risk_score": 0, "risk_level": "low", "risk_confidence": "medium",
"recommendation": "allow", "known_malicious": false,
"known_vulnerabilities": [], "typosquat_risk": "low",
"install_script_risk": "low", "dependency_risk": "low",
"dependency_count": 0, "dependencies_analyzed": 0, "dependency_findings": [],
"maintainer_risk": "unknown", "deprecated": false,
"sources": ["npm_registry", "local_heuristics", "osv"],
"degraded": false, "cached": false
}Up to 10 direct dependencies with exact pinned versions are checked against OSV in parallel; version ranges, transitive dependencies, and maintainer history are not assessed, so incomplete results stay cautious. Typosquat and install-script checks are deterministic heuristics, not proof of malicious intent. OSV advisories do not constitute complete malware intelligence. Registry metadata and the package name/version are sent to the public npm registry and OSV. Cache TTL defaults to 300 seconds and can be changed with CHECK_PACKAGE_CACHE_TTL_SECONDS; request timeout uses PACKAGE_CHECK_TIMEOUT_MS. Price defaults to $0.005 USDC per call via CHECK_PACKAGE_PRICE_USD. Payment is verified before registry or OSV requests begin. Use the response as a pre-install signal and review warnings before installation.
Agent Tool Router + Trust Layer · Find before paying
Call route_tool when an agent needs to choose a machine-payable MCP service or x402 HTTP endpoint. It matches structured capability metadata, applies price/latency/reliability constraints as hard filters, and ranks remaining candidates by the requested preference. It returns the endpoint only; the agent calls and pays that provider separately. It does not perform web search or execute a provider.
{
"capability": "wallet_risk",
"constraints": { "max_price_usd": 0.03 },
"preferences": { "optimize_for": "balanced" }
}Optimize modes: cheapest, fastest, quality, reliability, and balanced. Observed latency and success-rate history are not yet persisted, so they return as unknown and trust remains a neutral 50 with low confidence (cold start); self-reported metrics are not treated as observations. Without X402_BAZAAR_DISCOVERY_URLS, only our local tools appear and the result is marked degraded. Configure one or more trusted facilitator Bazaar base URLs (or full /discovery/resources URLs) to add external HTTP services. Bazaar MCP entries that publish only a mcp:// resource identifier are excluded because they do not disclose a callable transport endpoint. Prices are converted only for Base mainnet USDC; unknown price candidates are never recommended. Candidate URLs must be public HTTPS and are never fetched by the router. Set ROUTE_TOOL_PRICE_USD (default $0.002 USDC) and ROUTE_TOOL_CACHE_TTL_SECONDS (default 30).
Crypto Intelligence Tools · read-only market and token signals
These tools return structured market data and estimates. They do not sign, execute, broadcast, hold assets, or promise a profitable trade. Each has its own x402 price in the service directory above.
estimate_trade_execution · $0.01 USDC per call
Requests indicative Jupiter (Solana) or 0x (EVM) quotes. Configure JUPITER_API_KEY or ZEROX_API_KEY. If the required key is missing, the request is rejected before payment. The amount is always the exact-input quantity of from_asset (sold) into to_asset (bought). Supply token addresses; built-in Solana symbols are SOL, USDC and USDT. For EVM assets, provide both token decimals. Results omit USD network costs when no trusted pricing source exists. Jupiter and 0x each require their API key; quotes do not execute swaps. Jupiter Swap API · 0x Swap API.
{ "chain": "solana", "from_asset": "USDC", "to_asset": "SOL", "amount": 100, "max_slippage_bps": 100 }analyze_whale_activity · $0.02 USDC per call
Asset mode aggregates recent large trades from up to three indexed GeckoTerminal pools. Its “large participant” label is a size heuristic, not a verified whale identity, and the feed is not chain-wide. Wallet mode returns at most 20 indexed transactions via Helius (Solana) or Etherscan API V2 (EVM); configure HELIUS_API_KEY or ETHERSCAN_API_KEY. Wallet mode rejects before payment if the needed key is absent. Portfolio values, holdings, and verified wallet labels are not inferred. GeckoTerminal public API data is cached briefly and is subject to its public rate limits. GeckoTerminal API · Helius docs · Etherscan API V2.
{ "mode": "asset", "chain": "base", "asset": "0x…", "window": "1h", "min_transaction_usd": 100000 }scan_arbitrage · $0.03 USDC per call
Compares public Binance and Coinbase spot order books and simulates the requested notional against available depth. Depth-based price impact is included; configurable/default taker fee assumptions are applied. Deposit/withdrawal, transfer, rebalancing, and inventory costs remain unknown, so a positive spread is only a candidate signal. Book cache defaults to 3 seconds; source timestamps/freshness are reported conservatively. The implementation currently supports these two venues only. Binance Spot API.
{ "asset": "ETH", "quote_asset": "USDT", "trade_size_usd": 1000, "min_net_spread_bps": 10 }backtest_strategy · $0.10 USDC per call
Fetches Binance public OHLCV and runs a bounded long-only spot strategy from a fixed registry: moving-average crossover, RSI mean reversion, momentum, breakout, or buy-and-hold. Signals use candle close and execute at the next candle open; fee and slippage assumptions are inputs. Maximum history is 5,000 candles. Historical results are not forecasts. Data is cached for 24 hours by default.
{ "market": "BTCUSDT", "timeframe": "1d", "start": "2025-01-01", "end": "2025-03-01", "initial_capital": 10000, "strategy": { "type": "moving_average_crossover", "parameters": { "fast": 10, "slow": 30 } } }token_security_audit · $0.01 USDC per call
This is a callable extension of Wallet Risk Check, not a new numbered catalog service. It normalizes GoPlus token-security flags and supplements them with public RPC contract metadata. Configure GOPLUS_ACCESS_TOKEN; without it the request fails before payment. The internal rule score and the provider's fields are returned separately. Internal scoring is deterministic: honeypot/unsellable signal starts at 90; mintability adds 25, hidden owner 45, owner balance control 35, sell tax above 5% adds a capped tax-weighted amount, and blacklist capability adds 25 (capped at 100). Scores map to low 0–19, medium 20–49, high 50–79, critical 80–100; honeypot/unsellable yields block. Provider flags and internal scoring remain separate. This MVP does not verify liquidity locks, does not audit full source code, and does not guarantee safety; unavailable fields remain unknown. Results are cached for 5 minutes. GoPlus Token Security API.
{ "chain": "base", "token_address": "0x1111111111111111111111111111111111111111" }Set exchange fees and cache periods on the server with BINANCE_TAKER_FEE_BPS, COINBASE_TAKER_FEE_BPS, CRYPTO_QUOTE_CACHE_TTL_SECONDS, ARBITRAGE_CACHE_TTL_SECONDS, WHALE_POOL_CACHE_TTL_SECONDS, WHALE_TRADES_CACHE_TTL_SECONDS, WHALE_WALLET_CACHE_TTL_SECONDS, BACKTEST_CACHE_TTL_SECONDS, and TOKEN_SECURITY_CACHE_TTL_SECONDS. No endpoint accepts private keys or user-supplied fetch URLs.
4. Provide expected values
Expected purchase data is optional. Include only fields the agent can compare against an independent source; omitted fields are not treated as verified. Provide line_items to compare descriptions and amounts without relying on row order. Missing, extra, or changed invoice lines appear in checks.
{
"document_url": "https://supplier.example/invoice.pdf",
"expected": {
"supplier_name": "Northwind Parts",
"purchase_order": "PO-8841",
"currency": "USD",
"total": "124.00",
"line_items": [{ "description": "Replacement filters", "amount": "100.00" }]
}
}5. Branch on the response
Successful results include both JSON text and MCP structured content. Read decision first, then inspect checks, evidence, and warnings.
{
"decision": "match",
"invoice": {
"number": "INV-1042",
"supplier_name": "Northwind Parts",
"purchase_order": "PO-8841",
"currency": "USD",
"subtotal": "100.00",
"tax": "24.00",
"total": "124.00",
"line_items": [{ "description": "Replacement filters", "amount": "100.00" }]
},
"checks": [{ "field": "total", "status": "match", "expected": "124.00", "actual": "124.00" }],
"evidence": [{ "field": "total", "source": "Invoice/LegalMonetaryTotal/PayableAmount", "text": "124.00" }],
"source_sha256": "document-content-hash",
"warnings": []
}decision is match, discrepancy, or needs_review. OCR results also include pages_processed.
6. Pay only when the tool is invoked
The x402 client reads the payment challenge, pays the displayed amount in USDC on the advertised network, and retries the MCP request with the payment proof. Tool discovery and these docs are free. Your client must support x402 v2 and the selected chain.
Limits and intended use
Documents are limited to 10 MB. A PDF’s page count is checked before OCR; a document above the selected page tier is rejected before the OCR provider is called. The result helps reconcile invoice data but does not authenticate a supplier, detect fraud, certify tax compliance, or authorize payment. Use independent purchase data and route uncertain cases for review.