MCP tools for x402 readiness, paid-path probes, launch packs, and trust receipts.
Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read from a real MCP initialize → tools/list handshake against the declared endpoint. No tool was ever invoked — tools/list is the read-only introspection call the protocol defines for this. It reflects what the server advertised at that moment; a hosted endpoint is not pinned to any version and can change without notice.
https://x402-resource-scanner.vercel.app/mcp6 tools · 125msboundary_guard_checkCreate a deterministic, read-only pre-action receipt from request, policy, and optional result evidence. Use before an agent posts, spends, lists, or writes so the decision can be audited; no external action is executed.Create a deterministic, read-only pre-action receipt from request, policy, and optional result evidence. Use before an agent posts, spends, lists, or writes so the decision can be audited; no external action is executed.
| Parameter | Type | Description |
|---|---|---|
| nextStep | string | Optional guidance stored in the receipt. |
| policy | object | Decision object, e.g. allow/retry/review/block and reason. |
| request* | object | Action metadata the agent is about to perform. |
| result | object | Optional result or dry-run summary to hash into evidence. |
scan_x402_resourceRead-only scan of a public API/provider URL for x402, OpenAPI, pricing, and agent-discovery metadata. Pass url, and optionally marketplace_url plus expected_resources, to get a readiness score, issues, and fixes; no private endpoints are called.Read-only scan of a public API/provider URL for x402, OpenAPI, pricing, and agent-discovery metadata. Pass url, and optionally marketplace_url plus expected_resources, to get a readiness score, issues, and fixes; no private endpoints are called.
| Parameter | Type | Description |
|---|---|---|
| expected_resources | integer | Optional expected resource count. |
| marketplace_url | string | Optional marketplace/listing URL to compare against public metadata. |
| url* | string | Target API/provider base URL to scan. |
probe_x402_paid_pathProbe a public x402 paid endpoint without signing or paying, then parse the HTTP 402 challenge. Pass target plus optional expected network/asset/price to verify payment metadata and receive a deterministic health receipt.Probe a public x402 paid endpoint without signing or paying, then parse the HTTP 402 challenge. Pass target plus optional expected network/asset/price to verify payment metadata and receive a deterministic health receipt.
| Parameter | Type | Description |
|---|---|---|
| expected | object | Optional expected x402 metadata such as network, asset, and priceUsd. |
| method | string | Safe unpaid probe method. Defaults to GET. |
| mode | string | Probe mode for v1. Defaults to unpaid_402. |
| target* | string | Specific paid endpoint URL to probe without payment. |
check_agent_tool_readinessGateCheck readiness: check whether an x402/agent-facing tool is ready for agent routing, marketplace listing, and paid-path monitoring, including public agent discovery surfaces (/llms.txt, /agents.txt, /.well-known/mcp.json, /mcp). Pass target plus optional tier, marketplace_url, expected_resource…GateCheck readiness: check whether an x402/agent-facing tool is ready for agent routing, marketplace listing, and paid-path monitoring, including public agent discovery surfaces (/llms.txt, /agents.txt, /.well-known/mcp.json, /mcp). Pass target plus optional tier, marketplace_url, expected_resource…
| Parameter | Type | Description |
|---|---|---|
| expected | object | Optional expected x402 network/asset/price metadata for paid_path probes. |
| expected_resources | integer | Optional expected resource count. |
| marketplace_url | string | Optional marketplace/listing URL to compare against public metadata. |
| method | string | Safe unpaid probe method when paid_path is supplied. Defaults to GET. |
| paid_path | string | Optional specific paid endpoint to probe without payment for deep/report tiers. |
| target* | string | Target API/provider base URL to scan. |
| tier | string | Readiness depth. quick=$1, deep=$5, report=$10. Defaults to quick. |
generate_x402_launch_packGenerate marketplace-safe launch assets for an x402/MCP seller: listing copy, buyer FAQ, checklist, approval packet, and claim boundaries. Pass target plus optional product_name, audience, primary_use_case, marketplace_url, and paid_path; service/premium tiers include readiness evidence. Tiers: sin…Generate marketplace-safe launch assets for an x402/MCP seller: listing copy, buyer FAQ, checklist, approval packet, and claim boundaries. Pass target plus optional product_name, audience, primary_use_case, marketplace_url, and paid_path; service/premium tiers include readiness evidence. Tiers: sin…
| Parameter | Type | Description |
|---|---|---|
| audience | string | Primary buyer/audience for listing copy. |
| desired_marketplaces | array | Optional marketplace names to include in launch planning. |
| expected | object | Optional expected x402 network/asset/price metadata for paid_path probes. |
| expected_resources | integer | Optional expected resource count. |
| marketplace_url | string | Optional marketplace/listing URL to compare against public metadata. |
| method | string | Safe unpaid probe method when paid_path is supplied. Defaults to GET. |
| paid_path | string | Optional paid endpoint to validate via unpaid 402 challenge for service/premium packs. |
| primary_use_case | string | Primary buyer outcome/use case. |
| product_name | string | Buyer-facing product title. |
| target* | string | Target API/provider base URL to package for launch. |
| tier | string | Launch pack depth. single=$9, service=$29, premium=$49. Defaults to single. |
generate_trust_receiptGenerate a deterministic trust receipt from sanitized request/policy/result/payment summaries. Do not submit raw auth headers, cookies, API keys, private keys, payment signatures, payment response headers, customer prompts, customer documents, or payer-identifying evidence.Generate a deterministic trust receipt from sanitized request/policy/result/payment summaries. Do not submit raw auth headers, cookies, API keys, private keys, payment signatures, payment response headers, customer prompts, customer documents, or payer-identifying evidence.
| Parameter | Type | Description |
|---|---|---|
| nextStep | string | Optional receipt next-step guidance. |
| payment | object | Optional sanitized payment summary or caller-provided hashes only; do not include raw payment signatures, raw payment response headers, private keys, API keys,… |
| policy | object | Sanitized policy or decision summary to hash. |
| request* | object | Sanitized request/action summary to hash; omit raw prompts, documents, credentials, cookies, auth headers, signatures, and secrets. |
| result | object | Sanitized outcome/result summary to hash; omit customer data and secret-like values. |
6 of 6 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
MCP tools for x402 readiness, paid-path probes, launch packs, and trust receipts.
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.