Before you pay an endpoint you cannot vouch for: credit grade, drift and preflight.
Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read from a real MCP initialize → tools/list handshake against the declared endpoint. No tool was ever invoked — tools/list is the read-only introspection call the protocol defines for this. It reflects what the server advertised at that moment; a hosted endpoint is not pinned to any version and can change without notice.
https://mcpfax-reliability.bowling-anthony.workers.dev/mcp7 tools · 199msmcpfax_endpoint_credit_scoreCreditworthiness grade for one x402 endpoint or MCP server: letter grade A-E (or NR when unrated), a 0-1000 score, per-component subscores, a confidence level, flags, and the dated evidence each figure rests on. Use this before trusting or paying an unfamiliar endpoint. The grade ranks observed ris…Creditworthiness grade for one x402 endpoint or MCP server: letter grade A-E (or NR when unrated), a 0-1000 score, per-component subscores, a confidence level, flags, and the dated evidence each figure rests on. Use this before trusting or paying an unfamiliar endpoint. The grade ranks observed ris…
| Parameter | Type | Description |
|---|---|---|
| endpoint* | string | Observatory listing id. Use 'host:<hostname>' for an x402 endpoint, e.g. 'host:api.example.com', or 'mcp:<publisher>/<name>' for a registry-listed MCP server,… |
mcpfax_integration_driftWhat changed under an x402 endpoint or MCP server you have ALREADY integrated: payTo rotations, price, asset and network changes, terms added or removed, and tool-schema changes. This is not a discovery tool and will not help you choose a server; it tells you whether the one you wired in still matc…What changed under an x402 endpoint or MCP server you have ALREADY integrated: payTo rotations, price, asset and network changes, terms added or removed, and tool-schema changes. This is not a discovery tool and will not help you choose a server; it tells you whether the one you wired in still matc…
subjects: Links to undeclared domain: x402.browserbase.com| Parameter | Type | Description |
|---|---|---|
| subjects* | string | Comma-separated endpoint URLs or host identifiers to check, at most 50, e.g. 'https://x402.browserbase.com/browser/session/create,host:api.example.com'. |
| since | string | The watermark from your previous call (YYYY-MM-DD). Omit on a first call to receive the whole archive. |
mcpfax_wallet_authenticityPayer-concentration and wash-risk assessment for a receiving wallet: how concentrated its observed payers are, the measured coverage of that observation, an explicit wash-risk haircut ONLY when coverage is sufficient, how many listings declare the same address, and observed USDC inflow. Use this to…Payer-concentration and wash-risk assessment for a receiving wallet: how concentrated its observed payers are, the measured coverage of that observation, an explicit wash-risk haircut ONLY when coverage is sufficient, how many listings declare the same address, and observed USDC inflow. Use this to…
| Parameter | Type | Description |
|---|---|---|
| wallet* | string | The receiving EVM wallet address, 0x followed by 40 hex characters, e.g. '0x1831f336585a6C67B6A954d28f3E07F44C4EEBbd'. |
mcpfax_endpoint_revenue_estimateObserved on-chain revenue signals for one listing: total USDC inflow, how many distinct payers, the modal transfer size, payment rate, 7- and 30-day trend windows, and where it sits in its cohort by percentile. Use this to size a seller's real traction. Inflow is observed on-chain and is not proven…Observed on-chain revenue signals for one listing: total USDC inflow, how many distinct payers, the modal transfer size, payment rate, 7- and 30-day trend windows, and where it sits in its cohort by percentile. Use this to size a seller's real traction. Inflow is observed on-chain and is not proven…
| Parameter | Type | Description |
|---|---|---|
| endpoint* | string | Observatory listing id. Use 'host:<hostname>' for an x402 endpoint, e.g. 'host:api.example.com', or 'mcp:<publisher>/<name>' for a registry-listed MCP server,… |
mcpfax_payer_wallet_profileKnow-your-agent profile for a paying wallet: how many distinct services it pays, total observed spend, whether the address is a contract or an externally owned account, and coverage-gated screening signals. Use this to vet a counterparty that is paying you. Screening signals are withheld with statu…Know-your-agent profile for a paying wallet: how many distinct services it pays, total observed spend, whether the address is a contract or an externally owned account, and coverage-gated screening signals. Use this to vet a counterparty that is paying you. Screening signals are withheld with statu…
| Parameter | Type | Description |
|---|---|---|
| address* | string | The paying EVM wallet address, 0x followed by 40 hex characters. |
mcpfax_payto_change_feedChronological feed of rating actions since a date: grade upgrades and downgrades, payTo wallet changes (a seller redirecting payment), listing removals, and returns. Use this to monitor a portfolio of endpoints for adverse changes rather than re-scoring each one. The feed cannot return events from…Chronological feed of rating actions since a date: grade upgrades and downgrades, payTo wallet changes (a seller redirecting payment), listing removals, and returns. Use this to monitor a portfolio of endpoints for adverse changes rather than re-scoring each one. The feed cannot return events from…
| Parameter | Type | Description |
|---|---|---|
| since | string | Inclusive UTC start date in YYYY-MM-DD form, e.g. '2026-07-01'. Defaults to 30 days ago, but the feed cannot return events from before the archive start report… |
mcpfax_preflight_checkCheck that an endpoint is live and that its terms have not changed, BEFORE you send it an expensive request. A $15 call with a hypothetical 2% loss rate carries $0.30 of expected loss; a reachability check cannot promise to prevent it. Compare the quoted fee with the value of the pending call and t…Check that an endpoint is live and that its terms have not changed, BEFORE you send it an expensive request. A $15 call with a hypothetical 2% loss rate carries $0.30 of expected loss; a reachability check cannot promise to prevent it. Compare the quoted fee with the value of the pending call and t…
target: Links to undeclared domain: api.example.com| Parameter | Type | Description |
|---|---|---|
| target* | string | The endpoint you are about to call. Preferred form is the absolute https:// URL of the exact resource you will pay for, e.g. 'https://api.example.com/v1/search… |
| expected_price | string | What you believe the call costs. A decimal such as '0.01' is read as USD; a bare integer such as '10000' is read as atomic units. |
| expected_payto | string | The payment destination you believe you are paying — an EVM address or a base58 Solana address. A mismatch is the strongest signal this tool produces. |
| expected_schema_hash | string | The schema hash a previous call to this tool returned in live.schema_hash. It covers tool names and input/output schemas, not titles or descriptions. |
| max_age_seconds | integer | Your freshness bar, default 300. A stored observation older than this is still reported but may not support an ALLOW verdict. A stored observation newer than t… |
| probe_method | string | HTTP method for the unpaid probe of a non-MCP endpoint, default GET. Only side-effect-free methods are accepted; this tool never sends a request that could cha… |
7 of 7 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
Before you pay an endpoint you cannot vouch for: credit grade, drift and preflight.
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.