x402 toolkit for AI agents: paid web, AI, and Base chain tools per call in USDC. Free tools too.
Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read from a real MCP initialize → tools/list handshake against the declared endpoint. No tool was ever invoked — tools/list is the read-only introspection call the protocol defines for this. It reflects what the server advertised at that moment; a hosted endpoint is not pinned to any version and can change without notice.
https://quartermaster.surewhynot.app/mcp49 tools · 1154msx402_routerSTART HERE. One tool for anything x402, Base chain, or web/AI: describe your goal in plain English (q) and Quartermaster picks and runs the right underlying tool, returning the answer plus which tool it used. Examples: 'audit https://api.example.com/paid', 'price of eth', 'is 0x… a contract', 'veri…START HERE. One tool for anything x402, Base chain, or web/AI: describe your goal in plain English (q) and Quartermaster picks and runs the right underlying tool, returning the answer plus which tool it used. Examples: 'audit https://api.example.com/paid', 'price of eth', 'is 0x… a contract', 'veri…
| Parameter | Type | Description |
|---|---|---|
| q* | string | Your goal in plain English |
web_extract[Web] Extract clean readable text and metadata from a public webpage as structured JSON. Costs $0.005 (USDC via x402).[Web] Extract clean readable text and metadata from a public webpage as structured JSON. Costs $0.005 (USDC via x402).
| Parameter | Type | Description |
|---|---|---|
| url* | string | Public webpage URL |
page_meta[Web] Get page metadata: title, description, Open Graph, canonical URL, favicon, language. Costs $0.002.[Web] Get page metadata: title, description, Open Graph, canonical URL, favicon, language. Costs $0.002.
| Parameter | Type | Description |
|---|---|---|
| url* | string | — |
qr_generate[Web] Generate a QR code as SVG (or terminal text with format=text). Costs $0.002.[Web] Generate a QR code as SVG (or terminal text with format=text). Costs $0.002.
| Parameter | Type | Description |
|---|---|---|
| data* | string | — |
| format | string | — |
| ecc | string | — |
dns_lookup[Web] Resolve DNS records over DNS-over-HTTPS (A, AAAA, CNAME, MX, NS, TXT, and more). Costs $0.001.[Web] Resolve DNS records over DNS-over-HTTPS (A, AAAA, CNAME, MX, NS, TXT, and more). Costs $0.001.
| Parameter | Type | Description |
|---|---|---|
| name* | string | — |
| type | string | — |
http_error_explain[Web] Explain an HTTP status code: meaning, common causes, fixes, retry guidance. Costs $0.001.[Web] Explain an HTTP status code: meaning, common causes, fixes, retry guidance. Costs $0.001.
| Parameter | Type | Description |
|---|---|---|
| code* | integer | — |
tx_status[Crypto/Base] Check a Base transaction: success/reverted/pending, confirmations, gas, explorer link. Costs $0.002. Choose this for a quick raw status; use payment_receipt for decoded transfers, or settlement_assurance to PROVE an x402 payment settled to the right wallet/amount.[Crypto/Base] Check a Base transaction: success/reverted/pending, confirmations, gas, explorer link. Costs $0.002. Choose this for a quick raw status; use payment_receipt for decoded transfers, or settlement_assurance to PROVE an x402 payment settled to the right wallet/amount.
| Parameter | Type | Description |
|---|---|---|
| hash* | string | — |
wallet_balance[Crypto/Base] ETH and USDC (or any ERC-20) balance for an address on Base. Costs $0.001.[Crypto/Base] ETH and USDC (or any ERC-20) balance for an address on Base. Costs $0.001.
| Parameter | Type | Description |
|---|---|---|
| address* | string | — |
| token | string | — |
gas_prices[Crypto/Base] Current Base gas prices with a simple-transfer cost estimate. Costs $0.001.[Crypto/Base] Current Base gas prices with a simple-transfer cost estimate. Costs $0.001.
No input schema was published for this tool.
summarize_url[AI] AI summary of a public webpage (fetch + extract + summarize). length: short|medium|long. Costs $0.01.[AI] AI summary of a public webpage (fetch + extract + summarize). length: short|medium|long. Costs $0.01.
| Parameter | Type | Description |
|---|---|---|
| url* | string | — |
| length | string | — |
translate_text[AI] AI translation into any target language; source auto-detected. Costs $0.005.[AI] AI translation into any target language; source auto-detected. Costs $0.005.
| Parameter | Type | Description |
|---|---|---|
| text* | string | — |
| to* | string | — |
tldr_text[AI] Summarize raw text you pass in directly (not a URL). length: short|medium|long. Costs $0.005. Use summarize_url when you have a URL instead.[AI] Summarize raw text you pass in directly (not a URL). length: short|medium|long. Costs $0.005. Use summarize_url when you have a URL instead.
| Parameter | Type | Description |
|---|---|---|
| text* | string | — |
| length | string | — |
classify_text[AI] Zero-shot classification of text into caller-supplied labels; the result is validated back into your label set so you can route on it. Costs $0.002.[AI] Zero-shot classification of text into caller-supplied labels; the result is validated back into your label set so you can route on it. Costs $0.002.
| Parameter | Type | Description |
|---|---|---|
| text* | string | — |
| labels* | string | Comma-separated candidate labels (2-20) |
unshorten_url[Web] Expand a shortened/redirecting URL: follow the redirect chain and return every hop plus the final destination. Each hop is SSRF-validated. Costs $0.002. Safe way to see where an untrusted link goes.[Web] Expand a shortened/redirecting URL: follow the redirect chain and return every hop plus the final destination. Each hop is SSRF-validated. Costs $0.002. Safe way to see where an untrusted link goes.
| Parameter | Type | Description |
|---|---|---|
| url* | string | — |
regex_test[Dev] Test a regular expression against text; returns every match with numbered and named capture groups. Deterministic. Costs $0.001.[Dev] Test a regular expression against text; returns every match with numbered and named capture groups. Deterministic. Costs $0.001.
| Parameter | Type | Description |
|---|---|---|
| pattern* | string | — |
| text* | string | — |
| flags | string | — |
random_numbers[Dev] Cryptographically-secure random integers in a range (CSPRNG, unbiased) — real entropy an LLM cannot produce itself. Costs $0.001.[Dev] Cryptographically-secure random integers in a range (CSPRNG, unbiased) — real entropy an LLM cannot produce itself. Costs $0.001.
| Parameter | Type | Description |
|---|---|---|
| min | integer | — |
| max | integer | — |
| count | integer | — |
random_pick[Dev] Pick one or several options at random from a caller-supplied list (CSPRNG), optionally without replacement. Costs $0.001.[Dev] Pick one or several options at random from a caller-supplied list (CSPRNG), optionally without replacement. Costs $0.001.
| Parameter | Type | Description |
|---|---|---|
| options* | string | Comma-separated options |
| count | integer | — |
| unique | boolean | — |
http_check[Web] Liveness/latency pre-flight for a URL: is it up, HTTP status and class, response latency in ms, whether it redirects and where, content-type and server. Costs $0.001. Use before relying on a dependency.[Web] Liveness/latency pre-flight for a URL: is it up, HTTP status and class, response latency in ms, whether it redirects and where, content-type and server. Costs $0.001. Use before relying on a dependency.
| Parameter | Type | Description |
|---|---|---|
| url* | string | — |
public_holiday[Dev] Is a date a public holiday in a country (2-letter ISO code)? Returns the holiday name, its types, and the next upcoming holiday. Costs $0.001. Useful for scheduling.[Dev] Is a date a public holiday in a country (2-letter ISO code)? Returns the holiday name, its types, and the next upcoming holiday. Costs $0.001. Useful for scheduling.
| Parameter | Type | Description |
|---|---|---|
| country* | string | — |
| date | string | YYYY-MM-DD (defaults to today) |
x402_inspect[x402] Inspect and lint any x402 paid endpoint: decode the 402 challenge, identify network/asset, flag misconfigurations and Bazaar-readiness. Costs $0.002. Choose this for a quick one-shot decode+lint; use x402_audit for a full 0-100 scored report with origin discovery probes and recommended fixes.[x402] Inspect and lint any x402 paid endpoint: decode the 402 challenge, identify network/asset, flag misconfigurations and Bazaar-readiness. Costs $0.002. Choose this for a quick one-shot decode+lint; use x402_audit for a full 0-100 scored report with origin discovery probes and recommended fixes.
| Parameter | Type | Description |
|---|---|---|
| url* | string | — |
x402_simulate[x402] Pre-flight a payment BEFORE you spend: decode an endpoint's 402 challenge, report the cost on every rail (Base and Solana) and the cheapest, and — with an optional payer address — verify the wallet can afford the call on Base. Costs $0.003. Use this before paying an unfamiliar endpoint; use…[x402] Pre-flight a payment BEFORE you spend: decode an endpoint's 402 challenge, report the cost on every rail (Base and Solana) and the cheapest, and — with an optional payer address — verify the wallet can afford the call on Base. Costs $0.003. Use this before paying an unfamiliar endpoint; use…
| Parameter | Type | Description |
|---|---|---|
| url* | string | The x402 endpoint to pre-flight |
| address | string | Optional payer wallet (0x…) for a Base affordability check |
tx_decode[Crypto/Base] Decode a Base transaction's calldata into the function it called and its arguments — ERC-20 transfer/approve and the EIP-3009 transferWithAuthorization used by x402 settlements. Recognizes x402 settlement transactions and formats USDC amounts. Costs $0.003. Use tx_status for pass/fail…[Crypto/Base] Decode a Base transaction's calldata into the function it called and its arguments — ERC-20 transfer/approve and the EIP-3009 transferWithAuthorization used by x402 settlements. Recognizes x402 settlement transactions and formats USDC amounts. Costs $0.003. Use tx_status for pass/fail…
| Parameter | Type | Description |
|---|---|---|
| hash* | string | — |
embed_text[AI] Text embeddings (1024-dim vector) for semantic search and RAG. Costs $0.002.[AI] Text embeddings (1024-dim vector) for semantic search and RAG. Costs $0.002.
| Parameter | Type | Description |
|---|---|---|
| text* | string | — |
extract_structuredStructured extraction: JSON Schema plus a URL or raw text in, matching JSON out. Costs $0.005.Structured extraction: JSON Schema plus a URL or raw text in, matching JSON out. Costs $0.005.
| Parameter | Type | Description |
|---|---|---|
| schema* | string | JSON Schema as a JSON string |
| url | string | — |
| text | string | — |
moderate_text[AI] Content-safety classification (Llama Guard): safe flag plus category codes. Costs $0.002.[AI] Content-safety classification (Llama Guard): safe flag plus category codes. Costs $0.002.
| Parameter | Type | Description |
|---|---|---|
| text* | string | — |
describe_image[AI] AI vision: describe a public image URL, including visible text. Costs $0.005.[AI] AI vision: describe a public image URL, including visible text. Costs $0.005.
| Parameter | Type | Description |
|---|---|---|
| url* | string | — |
| prompt | string | — |
token_price[Crypto/Base] USD price for major tokens by symbol or any Base ERC-20 by address. Costs $0.001.[Crypto/Base] USD price for major tokens by symbol or any Base ERC-20 by address. Costs $0.001.
| Parameter | Type | Description |
|---|---|---|
| token* | string | — |
payment_receipt[x402] Formatted settlement receipt for a Base transaction (0x hash) or Solana settlement (base58 signature): timestamp, decoded transfers, explorer link. Costs $0.002. Choose this for a human-readable record; use payment_proof to ASSERT a specific payTo/amount, or settlement_assurance for a full s…[x402] Formatted settlement receipt for a Base transaction (0x hash) or Solana settlement (base58 signature): timestamp, decoded transfers, explorer link. Costs $0.002. Choose this for a human-readable record; use payment_proof to ASSERT a specific payTo/amount, or settlement_assurance for a full s…
| Parameter | Type | Description |
|---|---|---|
| hash* | string | 0x Base tx hash or base58 Solana signature |
resolve_basenameResolve a Basename (.base.eth) to a wallet address on Base. Costs $0.001.Resolve a Basename (.base.eth) to a wallet address on Base. Costs $0.001.
| Parameter | Type | Description |
|---|---|---|
| name* | string | — |
x402_audit[x402] WORKFLOW: full scored audit of an x402 SELLER endpoint (a URL) in one call - verifies the 402 challenge, payment fields, Bazaar discovery metadata, and the origin's discovery surfaces; returns a 0-100 score, checks with evidence, and recommended fixes. Costs $0.01. Use this to grade an endpo…[x402] WORKFLOW: full scored audit of an x402 SELLER endpoint (a URL) in one call - verifies the 402 challenge, payment fields, Bazaar discovery metadata, and the origin's discovery surfaces; returns a 0-100 score, checks with evidence, and recommended fixes. Costs $0.01. Use this to grade an endpo…
| Parameter | Type | Description |
|---|---|---|
| url* | string | x402 paid endpoint to audit |
payment_proof[x402] Verify an x402 settlement on Base OR Solana from a tx id (0x hash or base58 signature): confirm it succeeded, decode its USDC transfers, optionally assert payTo/amount - returns a single verdict. Costs $0.003. Choose this when you only need the yes/no did-it-land answer; use settlement_assur…[x402] Verify an x402 settlement on Base OR Solana from a tx id (0x hash or base58 signature): confirm it succeeded, decode its USDC transfers, optionally assert payTo/amount - returns a single verdict. Costs $0.003. Choose this when you only need the yes/no did-it-land answer; use settlement_assur…
| Parameter | Type | Description |
|---|---|---|
| hash* | string | 0x Base tx hash or base58 Solana signature |
| payTo | string | expected recipient: 0x address (Base) or base58 wallet (Solana) |
| amount | string | — |
settlement_assurance[x402] FLAGSHIP: from a tx id on Base (0x hash) or Solana (base58 signature), prove a completed x402 payment is real and sound - onchain success, USDC transfer match to an expected wallet/amount, a receipt, and an optional audit of the issuing endpoint - as one 0-100 scored report with a verdict. C…[x402] FLAGSHIP: from a tx id on Base (0x hash) or Solana (base58 signature), prove a completed x402 payment is real and sound - onchain success, USDC transfer match to an expected wallet/amount, a receipt, and an optional audit of the issuing endpoint - as one 0-100 scored report with a verdict. C…
| Parameter | Type | Description |
|---|---|---|
| hash* | string | 0x Base tx hash or base58 Solana signature |
| payTo | string | expected recipient: 0x address (Base) or base58 wallet (Solana) |
| amount | string | — |
| resource | string | — |
x402_discover[x402] Search the Coinbase x402 Bazaar for paid resources by natural-language query. Costs $0.001.[x402] Search the Coinbase x402 Bazaar for paid resources by natural-language query. Costs $0.001.
| Parameter | Type | Description |
|---|---|---|
| query* | string | — |
| limit | integer | — |
x402_merchant[x402] List all x402 Bazaar resources under a merchant payTo wallet. Costs $0.001.[x402] List all x402 Bazaar resources under a merchant payTo wallet. Costs $0.001.
| Parameter | Type | Description |
|---|---|---|
| payTo* | string | — |
| limit | integer | — |
usdc_normalizeConvert USDC amounts between atomic units and human decimals. Costs $0.001.Convert USDC amounts between atomic units and human decimals. Costs $0.001.
| Parameter | Type | Description |
|---|---|---|
| amount* | string | — |
| decimals | integer | — |
| direction | string | — |
base_token_infoERC-20 name, symbol, decimals, total supply for a token on Base. Costs $0.001.ERC-20 name, symbol, decimals, total supply for a token on Base. Costs $0.001.
| Parameter | Type | Description |
|---|---|---|
| address* | string | — |
base_allowanceCheck an ERC-20 spending allowance on Base; flags unlimited approvals. Costs $0.001.Check an ERC-20 spending allowance on Base; flags unlimited approvals. Costs $0.001.
| Parameter | Type | Description |
|---|---|---|
| owner* | string | — |
| spender* | string | — |
| token | string | — |
base_contractDetermine whether a Base address is a contract or an EOA. Costs $0.001.Determine whether a Base address is a contract or an EOA. Costs $0.001.
| Parameter | Type | Description |
|---|---|---|
| address* | string | — |
base_usdc_transfersRecent USDC transfers (in and out) for an address on Base. Costs $0.002.Recent USDC transfers (in and out) for an address on Base. Costs $0.002.
| Parameter | Type | Description |
|---|---|---|
| address* | string | — |
| limit | integer | — |
jwt_decode[Dev] Decode a JWT header and payload (signature NOT verified). Costs $0.001.[Dev] Decode a JWT header and payload (signature NOT verified). Costs $0.001.
| Parameter | Type | Description |
|---|---|---|
| token* | string | — |
base64[Dev] Base64 encode or decode a string. Costs $0.001.[Dev] Base64 encode or decode a string. Costs $0.001.
| Parameter | Type | Description |
|---|---|---|
| op | string | — |
| data* | string | — |
text_stats[Dev] Word/sentence counts, reading time, and readability score for text. Costs $0.001.[Dev] Word/sentence counts, reading time, and readability score for text. Costs $0.001.
| Parameter | Type | Description |
|---|---|---|
| text* | string | — |
text_diff[Dev] Compact line-level diff between two texts. Costs $0.001.[Dev] Compact line-level diff between two texts. Costs $0.001.
| Parameter | Type | Description |
|---|---|---|
| before* | string | — |
| after* | string | — |
x402_test_vector[x402] Free: example x402 payment-requirement objects with field explanations.[x402] Free: example x402 payment-requirement objects with field explanations.
No input schema was published for this tool.
current_timeFREE (no wallet needed): current time as ISO, unix, UTC, and optional local time for an IANA timezone.FREE (no wallet needed): current time as ISO, unix, UTC, and optional local time for an IANA timezone.
| Parameter | Type | Description |
|---|---|---|
| tz | string | Optional IANA timezone, e.g. America/Chicago |
generate_uuidFREE (no wallet needed): generate UUID v4 values, up to 100 at once.FREE (no wallet needed): generate UUID v4 values, up to 100 at once.
| Parameter | Type | Description |
|---|---|---|
| count | integer | How many, 1-100 |
hash_stringFREE (no wallet needed): SHA-1/256/384/512 hex digest of a string.FREE (no wallet needed): SHA-1/256/384/512 hex digest of a string.
| Parameter | Type | Description |
|---|---|---|
| data* | string | — |
| algo | string | — |
http_errors_listFREE (no wallet needed): index of documented HTTP status codes (use http_error_explain for a paid detailed explanation).FREE (no wallet needed): index of documented HTTP status codes (use http_error_explain for a paid detailed explanation).
No input schema was published for this tool.
quartermaster_infoFree: catalog, prices, and payment instructions for this server.Free: catalog, prices, and payment instructions for this server.
No input schema was published for this tool.
49 of 49 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
x402 toolkit for AI agents: paid web, AI, and Base chain tools per call in USDC. Free tools too.
+ 9 more observed on this entry.
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.