Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

AgentRoam

REMOTE · AGENTROAM.AI · SCANNED SEP 21

Buy travel eSIMs, gift cards and mobile top-ups with crypto — user confirms before any order.

Available components

+3 this week 81 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security63
Transport & Reachability100
Schema Quality & AI Usability86
  • 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
  • AI-judged instruction clarity (excellent).Pass
  • Tool/resource definitions use about 1402 tokens (~100/item across 14 items; 11 tools + 3 resources), lean.Pass
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
  • No destabilizing schema changes in the last 30 days.Pass
Tool Coverage98
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 94% of tool parameters carry a description.Partial
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • We read all 11 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
  • An AI judge read all 13 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
  • Spec-recency check failed: implements MCP spec 2025-03-26; the latest is 2026-07-28. See how to fix → Fail
  • Supports UI / widget rendering.Pass
Install

How do I install the AgentRoam MCP server?

AgentRoam is a hosted endpoint at https://agentroam.ai/api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · agentroam.ai

# add to Claude Code
claude mcp add --transport http ai-agentroam-agentroam 'https://agentroam.ai/api/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "ai-agentroam-agentroam": {
      "url": "https://agentroam.ai/api/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "ai-agentroam-agentroam": {
      "type": "http",
      "url": "https://agentroam.ai/api/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.ai-agentroam-agentroam]
url = "https://agentroam.ai/api/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "ai-agentroam-agentroam": {
      "type": "remote",
      "url": "https://agentroam.ai/api/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add ai-agentroam-agentroam --url 'https://agentroam.ai/api/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  ai-agentroam-agentroam:
    url: "https://agentroam.ai/api/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "ai-agentroam-agentroam": {
      "Transport": "http",
      "Url": "https://agentroam.ai/api/mcp"
    }
  }
}
# add to Vellum
assistant mcp add ai-agentroam-agentroam -t streamable-http -u 'https://agentroam.ai/api/mcp'
// mcp.json
{
  "mcpServers": {
    "ai-agentroam-agentroam": {
      "type": "http",
      "url": "https://agentroam.ai/api/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 21 Sept 26 0
    • Stability: 0.97 → pass security
  • 20 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.

  • 18 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.

  • 16 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.

  • 14 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 73 to 77. That category is still filling its 30-day observation window: 22 days of observed history at the previous scan, 23 at this one. The score rises as the window fills, whether or not the server changes.

  • 12 Sept 26 +1
    • Tool “create_order” changed its title: Place order cosmetic
    • Tool “get_currencies” changed its title: List payment coins cosmetic
    • Tool “get_order_status” changed its title: Check order status cosmetic
    • Tool “get_payment_methods” changed its title: List payment networks cosmetic
    • Tool “get_price” changed its title: Get crypto price cosmetic
    • Tool “list_brands” changed its title: List brands by country cosmetic
    • Tool “list_esim_plans” changed its title: List eSIM plans cosmetic
    • Tool “list_products” changed its title: List brand products cosmetic
    • Tool “purchase_wizard” changed its title: Guided purchase (text) cosmetic
    • Tool “search_products” changed its title: Search catalog cosmetic
    • Tool “validate_order” changed its title: Prepare order for approval cosmetic

    11 cosmetic changes on this day. Switch on “Show cosmetic changes” to see them.

  • 10 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 60 to 63. That category is still filling its 30-day observation window: 18 days of observed history at the previous scan, 19 at this one. The score rises as the window fills, whether or not the server changes.

  • 8 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 53 to 57. That category is still filling its 30-day observation window: 16 days of observed history at the previous scan, 17 at this one. The score rises as the window fills, whether or not the server changes.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 21 Sept 2026 · Probed https://agentroam.ai/api/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=agentroam.ai CN=YE1,O=Let's Encrypt,C=US 5 Sept 2026 4 Dec 2026 ECDSA 256 ECDSA-SHA384 692edc160c20418f0161e80503d8a3fcee4
SANs: agentroam.ai, www.agentroam.ai
CN=YE1,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 5ddd70dd31f801c85c186a7a04b80afe
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of agentroam.ai. Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
ai. present 3799 8 Verified
agentroam.ai. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200
Header Value
strict-transport-security max-age=31536000
x-content-type-options nosniff
x-frame-options SAMEORIGIN
referrer-policy strict-origin-when-cross-origin
permissions-policy camera=(), microphone=(), geolocation=()

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://agentroam.ai/api/mcp Verified 200
http (plaintext) http://agentroam.ai/api/mcp HTTPS enforced 301 https://agentroam.ai/api/mcp
MCP tools · 11 exposed · ~1,237 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
create_order ~109

Create the real order (requires confirm_token from validate_order, after user approval). Returns the payment wallet address, exact crypto amount, 30-minute expiry, and an order-status URL. The purchased code/QR is emailed by Cryptorefills to the buyer — it is never returned here.

NameTypeReqDescription
confirm_tokenstringyesOne-time token returned by validate_order (valid 10 minutes)
full_namestringBuyer full legal name — only if a previous attempt returned FULLNAME_MISSING
NameTypeReqDescription
coinstring
errorstringPresent on failure: KYC_MISSING | FULLNAME_MISSING | PHONE_MISSING | CONFIRM_TOKEN_*
external_order_idstring
instructionsstring
kyc_urlstringHosted verification link when error=KYC_MISSING
networkstringExact network — funds sent elsewhere are lost
network_labelstring
pay_amountnumberEXACT amount to send
pay_to_addressstringWallet address to send funds to
payment_expires_atstringISO timestamp; 30-minute window
payment_urlstringPayment page with QR
qr_urlstringQR code PNG of the address
statestringCREATED | WAITING_FOR_PAYMENT | PARTIAL | COMPLETED | CANCELED | EXPIRED
status_tokenstring
status_urlstringLive order-status page

No examples provided.

get_currencies ~22

List all supported payment cryptocurrencies (the response carries the current set).

Input schema present but exposes no named parameters.

NameTypeReqDescription
currenciesarrayyes

No examples provided.

get_order_status ~63

Poll order state (WAITING_FOR_PAYMENT → PARTIAL → COMPLETED, or CANCELED/EXPIRED). Requires the status_token from create_order.

NameTypeReqDescription
external_order_idstringyes
status_tokenstringyesstatusToken returned by create_order
NameTypeReqDescription
brandstring
coinstring
denominationstring
errorstringnot_found when id/token mismatch
external_order_idstring
networkstring
payment_expires_atstring
statestringWAITING_FOR_PAYMENT | PARTIAL | COMPLETED | CANCELED | EXPIRED | REFUNDED
status_urlstring

No examples provided.

get_payment_methods ~45

Full payment matrix: every supported coin × network combination currently available, with the exact network strings orders require. The response includes live totals — report those, never a memorized count.

Input schema present but exposes no named parameters.

NameTypeReqDescription
combinationsarrayyes
payment_viastring

No examples provided.

get_price ~215

Live crypto price for one product/denomination. Payment coins include USDT, USDC, BTC (incl. Lightning), ETH, SOL, DAI, PYUSD, LTC, TRX, TON, DOGE and SUI across many networks — call get_payment_methods for the current list. Never creates an order.

NameTypeReqDescription
amount_usdnumberyesUSD amount (for dynamic-range products)
brand_slugstringyesbrandSlug from search_products
coinstringyesPayment coin, e.g. USDC, USDT, BTC, SOL
country_codestringyescountryCode from search_products
denomination_labelstringyesExact denomination label (e.g. "100 USD", "60 UC", "1 GB 7 days")
dynamicbooleanyestrue for dynamic-range amounts, false for fixed denomination labels
networkstringyesExact network string from get_price/networks, e.g. "Solana", "Tron", "ETH Mainnet"
NameTypeReqDescription
coinstringyes
estimatebooleantrue = indicative only; exact amount fixed at order creation
faceValueUsdnumber
feePctnumberFee percent over USD face value (0 for volatile coins)
networkstringyes
payAmountnumberyesAmount to pay in the chosen coin

No examples provided.

list_brands ~73

Browse all available brands/carriers for a country: gift cards (500+ US brands) and mobile top-up carriers (100+ countries). Never creates an order.

NameTypeReqDescription
country_codestringyesISO country code, e.g. "us", "mx"
kindstringFilter by product type
NameTypeReqDescription
brandsarray
countnumber
countrystring

No examples provided.

list_esim_plans ~134

PREFERRED for any eSIM request: live eSIM data plans for a destination (110+ countries, plus "eu" Europe and "ww" Global multi-country plans) with USD prices and crypto amounts. Renders an interactive plan-picker widget where the user can complete the purchase directly. Never creates an order by itself.

NameTypeReqDescription
coinstringCoin for live pricing (default USDC)
destinationstringyesDestination: 2-letter country code (e.g. "il", "jp", "fr"), or "eu" (Europe region plan) / "ww" (Global plan)
NameTypeReqDescription
brandstring
coinstring
countrystringDestination code — pass as country_code to validate_order
destination_namestring
errorstring
flagstring
productsarray
urlstring

No examples provided.

list_products ~90

List a brand's live products/denominations with prices in the chosen coin — exact labels to use with get_price/validate_order (for eSIM use list_esim_plans instead). Never creates an order.

NameTypeReqDescription
brand_slugstringyesbrandSlug from list_brands/search_products
coinstringCoin for live pricing (default USDC)
country_codestringyes
NameTypeReqDescription
brandstring
brand_slugstring
coinstring
countrystring
country_namestring
destination_namestring
errorstringproduct_not_found
flagstring
is_esimboolean
kindstringgiftcard | esim | topup
logoUrlstring
productsarray
urlstringProduct page on the AgentRoam site

No examples provided.

purchase_wizard ~134

Text-only fallback purchase flow for clients WITHOUT widget support. In ChatGPT prefer list_esim_plans / list_products + validate_order + create_order instead. Stateful: call repeatedly with the same session_token, answering one question at a time, until status is "complete". First call: empty arguments. The final "confirm" answer creates a REAL order — get explicit user approval first.

NameTypeReqDescription
actionstring"back" to return to the previous step
answerstringAnswer to the current question
session_tokenstringOmit on the first call — a new session is minted
NameTypeReqDescription
errorstring
hintstring
optionsarray
questionstringAsk the user this
resultobject
session_tokenstringyesPass back on every call of this session
statusstringyesin_progress | complete | error
stepstring
summarystring

No examples provided.

search_products ~123

Search the AgentRoam travel-crypto catalog: gift cards (Airbnb, Uber, airlines, 500+ US brands), eSIM data plans (110+ destinations incl. Europe/Global region plans) and mobile top-ups (carriers in 100+ countries). Returns product handles for get_price/validate_order. Never creates an order.

NameTypeReqDescription
countrystringISO country code filter (e.g. "us", "mx")
kindstringProduct type filter
querystringyesBrand, carrier or destination to search for
NameTypeReqDescription
hintstring
resultsarray

No examples provided.

validate_order ~229

Dry-run an order and mint a one-time confirm_token (valid 10 minutes). Returns a human-readable summary that MUST be shown to the user for approval before calling create_order. Does NOT create the order or reserve funds.

NameTypeReqDescription
amount_usdnumberyesUSD amount (for dynamic-range products)
brand_slugstringyesbrandSlug from search_products
coinstringyesPayment coin, e.g. USDC, USDT, BTC, SOL
country_codestringyescountryCode from search_products
denomination_labelstringyesExact denomination label (e.g. "100 USD", "60 UC", "1 GB 7 days")
dynamicbooleanyestrue for dynamic-range amounts, false for fixed denomination labels
emailstringyesDelivery email for the buyer
networkstringyesExact network string from get_price/networks, e.g. "Solana", "Tron", "ETH Mainnet"
phonestringPhone number to recharge (REQUIRED for mobile top-ups, with country code)
NameTypeReqDescription
confirm_tokenstringOne-time token for create_order, valid 10 minutes
errorstringproduct_not_found | out_of_stock | PHONE_MISSING
expires_in_secondsnumber
instructionsstring
messagestring
priceobject
summarystringHuman-readable purchase summary — show to the user for approval
validboolean

No examples provided.

Common questions

What is the AgentRoam MCP server?

AgentRoam is an MCP server listed in the public MCP registry as ai.agentroam/agentroam. Buy travel eSIMs, gift cards and mobile top-ups with crypto, user confirms before any order. This page covers its hosted endpoint (https://agentroam.ai/api/mcp).

Is the AgentRoam MCP server safe to use?

AgentRoam scores 81 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the AgentRoam MCP server expose?

AgentRoam exposes 11 tools: search_products, get_price, validate_order, create_order, list_esim_plans, and 6 more. Their descriptions and schemas cost roughly 1,237 tokens of context every time the server is loaded.

Does the AgentRoam MCP server require authentication?

No. We connected to AgentRoam without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the AgentRoam MCP server still maintained?

AgentRoam is still listed as active in the MCP registry. We last reached this channel on 21 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.