# io.github.ivaavimusic/singularity

MCP for Singularity Layer - discover listings, manage assets, run payment flows, and use agents

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the content rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.14.0
- **Author:** io.github.ivaavimusic
- **License:** Unknown
- **Endpoints:** streamable-http https://mcp.x402layer.cc/mcp
- **Source:** https://studio.x402layer.cc/docs/agentic-access/mcp-server
- **Endpoint health:** reachable (last checked 2026-09-26T13:02:24.567Z, 5 samples) — uptime is not a security property and is not part of the trust score
- **Compatible clients:** claude-code, cursor, copilot, chatgpt, gemini (basis: transport)

## Trust

60/100 (B), scored on the content rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: clean
- Obfuscation scan: clean
- Evidence age: 34 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-01T16:55:46.022Z
- **Version scanned:** live
- **CVEs:** no coverage — this entry has no package coordinates to query OSV against, so "no known CVEs" is NOT asserted for it.

## Tools

48 declared. Observed from a live `tools/list` probe.
- `vault_usage` — Agent Vault storage usage and plan for the wallet behind a compute API key: bytes used/reserved, free vs pro plan, caps, and Vault Pro pricing.
- `vault_list_agents` — List the agents registered in Agent Vault for this wallet (OpenClaw, Hermes, pods, and custom --path lineages).
- `vault_list_snapshots` — List completed Agent Vault snapshots (encrypted backups) for this wallet, optionally filtered to one agent. Use this to check WHEN an agent was last backed up.
- `vault_delete_snapshot` — Permanently delete one Agent Vault snapshot and free its storage. Irreversible — confirm with the user before calling.
- `vault_subscribe_pro` — Change the wallet’s Agent Vault plan, charged from platform credits. pro = 10 GB + the last 10 snapshots of each agent ($3/month, $30/year); max = 50 GB + unlim
- `vault_how_to_backup` — How to actually CREATE or RESTORE an encrypted backup. Encryption is zero-knowledge and must run on the machine where the agent lives — this returns the exact C
- `list_dataset_pricing` — What a generated training dataset costs and which models can generate it: per-100-example rates for each managed tier plus the decentralized grid, the maximum s
- `request_dataset_payment` — Step 1 of buying a training dataset: submit the job and get back an x402 payment challenge with the exact price. Nothing is charged and nothing is generated yet
- `create_dataset_with_payment` — Step 2 of buying a training dataset: submit the job again with the signed X-Payment payload and the quote id. Returns in seconds with a dataset id and a claim t
- `get_dataset_status` — How a purchased dataset is coming along, and the download link once it is ready. Returns rows done vs target while generating, a presigned JSONL download URL (v
- `browse_marketplace` — Browse and search the Singularity Marketplace with various filters. Returns listings of endpoints, products, and agentic services.
- `get_listing` — Get detailed information about a specific marketplace listing by its slug.
- `get_featured` — Get featured marketplace listings (endpoints and products highlighted by the platform).
- `get_top_rated` — Get top-rated marketplace listings sorted by average rating.
- `get_agent` — Get details for a specific ERC-8004 or Solana-8004 agent by network and identifier.
- `list_categories` — List all available marketplace categories.
- `list_networks` — List all supported blockchain networks.
- `list_agents` — List all registered ERC-8004 and Solana-8004 agents.
- `list_my_endpoints` — List the endpoints accessible to the dashboard owner behind your MCP access token or endpoint API key. PATs are preferred for owner-wide inventory and require m
- `list_my_campaigns` — List fundraiser campaigns owned by the dashboard user behind your MCP personal access token. Requires mcp:read or mcp:*.
- `create_campaign` — Create a fundraiser campaign owned by the dashboard user behind your MCP personal access token. Requires mcp:campaigns:write or mcp:*.
- `update_campaign` — Update allowlisted fundraiser campaign fields such as title, description, x handle, images, and links. Requires mcp:campaigns:write or mcp:*.
- `update_endpoint` — Update allowlisted endpoint fields such as metadata, pricing, listing flags, imagery, wallet, payment options, slug, and webhook settings. PATs are preferred an
- `list_my_products` — List the products owned by the same dashboard user as your MCP access token or endpoint API key. PATs are preferred and require mcp:read or mcp:*.
- `update_product` — Update allowlisted product fields including metadata, pricing, listing state, payment options, wallet, branding, and slug. PATs are preferred and require mcp:pr
- `get_endpoint_details` — Get full details for an endpoint you own, including credit balance, pricing config, and wallet address. PATs are preferred and require mcp:read or mcp:*.
- `get_endpoint_stats` — Get usage analytics for an endpoint: total requests, monthly requests, revenue, and success rate. PATs or endpoint API keys improve accuracy. PATs require mcp:r
- `set_webhook` — Set or update the webhook URL for an endpoint. Returns a signing secret that must be saved. PATs are preferred and require mcp:endpoints:write or mcp:*.
- `remove_webhook` — Remove the webhook URL from an endpoint. PATs are preferred and require mcp:endpoints:write or mcp:*.
- `delete_endpoint` — ⚠️ DESTRUCTIVE: Permanently delete an endpoint. Cannot be undone. Only works for agent-created endpoints. PATs are preferred and require mcp:endpoints:write or 
- `request_endpoint_creation_payment` — Return the x402 payment challenge needed to create a new agent endpoint. Requires a dashboard PAT with mcp:endpoints:write or mcp:*.
- `create_endpoint_with_payment` — Create a new agent endpoint after you have obtained a valid X-Payment payload for the creation challenge. Requires a dashboard PAT with mcp:endpoints:write or m
- `request_endpoint_topup_payment` — Return the x402 payment challenge needed to top up credits for an existing agent endpoint. Accepts either a dashboard PAT with mcp:endpoints:write or mcp:* or a
- `topup_endpoint_with_payment` — Complete an endpoint credit top-up after you have obtained a valid X-Payment payload. Accepts either a dashboard PAT with mcp:endpoints:write or mcp:* or a lega
- `request_product_purchase_payment` — Return the x402 payment challenge for purchasing a public product. This wraps the existing public /p/:id-or-slug flow and does not require owner credentials.
- `purchase_product_with_payment` — Complete a public product purchase after you have obtained a valid X-Payment payload for that product challenge.
- `request_endpoint_credit_purchase_payment` — Return the x402 payment challenge for purchasing a public credit pack from an endpoint that exposes /e/:slug?action=purchase.
- `purchase_endpoint_credits_with_payment` — Complete a public endpoint credit-pack purchase after you have obtained a valid X-Payment payload for the purchase challenge.
- `get_agent_registry_info` — Get public ERC-8004 / Solana-8004 registry information, supported networks, worker routes, and wallet-first notes.
- `request_agent_wallet_challenge` — Create a wallet-auth challenge for ERC-8004 agent registration or management. The wallet owner must sign the returned message locally; MCP does not sign with th
- …and 8 more

## Install

**Verdict: review** — Installable, but 2 things to check first: No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
**Cautions** (coverage gaps and advisories — never blocking)
- No CVE coverage: this entry has no npm/PyPI coordinates to query OSV against, so "no known vulnerabilities" is not a claim that can be made about it.
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"singularity\": {\n      \"type\": \"http\",\n      \"url\": \"https://mcp.x402layer.cc/mcp\"\n    }\n  }\n}"
```

## Blast radius

Extensive blast radius — deletes data; runs on someone else's infrastructure.
- Floor 34, ceiling 58 (tier: extensive)
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/io.github.ivaavimusic%2Fsingularity
- Install plan: https://forgeregistry.com/api/v1/packages/io.github.ivaavimusic%2Fsingularity/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/io.github.ivaavimusic%2Fsingularity
- HTML page: https://forgeregistry.com/registry/io.github.ivaavimusic%2Fsingularity
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
