# Lumière PayCheck (remote · lumierepaycheck.org)

Check any x402 endpoint before your AI agent pays it: trust grade, verdict, and hijack checks.

- Trust score: 76/100 (medium)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-07

## Components

- remote · `lumierepaycheck.org`: 76/100 (this document), [markdown](https://verifymcp.io/servers/book0feli-paycheck/lumierepaycheck-2.md), [page](https://verifymcp.io/servers/book0feli-paycheck/lumierepaycheck-2)

## Channel facts

- Endpoint: `https://lumierepaycheck.org/mcp?plans=1`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.8.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-07.

- **Endpoint Security**: 83/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one.
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC is configured correctly; the domain's records validate against the full chain to the root.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 78/100
  - 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 1741 tokens (~217/item across 8 items; 6 tools + 2 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 10/100
  - Stability observed for 3 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 98/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 95% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 6 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 8 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### How do I install the Lumière PayCheck MCP server?

Lumière PayCheck is a hosted endpoint at https://lumierepaycheck.org/mcp?plans=1, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http book0feli-paycheck 'https://lumierepaycheck.org/mcp?plans=1'
```

### Cursor

```json
{
  "mcpServers": {
    "book0feli-paycheck": {
      "url": "https://lumierepaycheck.org/mcp?plans=1"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "book0feli-paycheck": {
      "type": "http",
      "url": "https://lumierepaycheck.org/mcp?plans=1"
    }
  }
}
```

### Codex

```toml
[mcp_servers.book0feli-paycheck]
url = "https://lumierepaycheck.org/mcp?plans=1"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "book0feli-paycheck": {
      "type": "remote",
      "url": "https://lumierepaycheck.org/mcp?plans=1",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add book0feli-paycheck --url 'https://lumierepaycheck.org/mcp?plans=1' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  book0feli-paycheck:
    url: "https://lumierepaycheck.org/mcp?plans=1"
```

### Netclaw

```json
{
  "McpServers": {
    "book0feli-paycheck": {
      "Transport": "http",
      "Url": "https://lumierepaycheck.org/mcp?plans=1"
    }
  }
}
```

### Vellum

```bash
assistant mcp add book0feli-paycheck -t streamable-http -u 'https://lumierepaycheck.org/mcp?plans=1'
```

### Other

```json
{
  "mcpServers": {
    "book0feli-paycheck": {
      "type": "http",
      "url": "https://lumierepaycheck.org/mcp?plans=1"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-10-07 (score 76, 0)

- [functional regression] Tool coverage: 100% → 95%
- [functional regression] Schema quality: 190 → 217
- [functional improvement] Stability: unverified → 0.10

### 2026-10-04 (score 76)

First indexed and scored.

## MCP tools (6)

### `check_endpoint` (~248 tokens)

Check an x402 endpoint

Get the trust verdict for one x402 endpoint: score (0-100), grade (A-F), and verdict (proceed, caution, avoid, free, or insufficient_data), plus uptime, delivery-test status, payout-wallet incidents, and how many independent buyers stand behind the seller's buyer wallets (we count customers, not wallets). Use it when you're deciding whether an endpoint is trustworthy at all, before you have a price quote. When you already have the 402 quote (amount and payTo) and are about to pay, use check_payment instead: it runs this same check and also verifies the price and wallet. To discover good endpoints rather than check a known one, use top_endpoints. Read-only and free; reflects monitoring every 30 minutes and real test payments, so a brand-new endpoint may return insufficient_data. Endpoints not in the catalog return monitored: false. API docs: https://github.com/Book0fEli/lumiere-paycheck/blob/main/docs/api.md

Input parameters:

- `url` (string, required): Full URL of the x402 endpoint including path, exactly as the agent will call it, e.g. https://api.example.com/v1/price.

Output parameters:

- `advice` (string): What the verdict means for paying it
- `auth` (object): Present when our paid test was refused for want of the seller's own sign-in (no money was taken). Have access? Send hasAccess: true to check_payment.
- `buyerReports` (object): What real buyers reported after paying. Never changes the grade; confirmations move the endpoint up our paid-test queue.
- `buyers` (object): Who is really behind the seller's buyers. Never changes the grade.
- `delivery` (string): verified = a real test payment was delivered; failing (see advice: an error after payment that didn't collect the money is D/caution; taking the money and failing is F/avoid); or unverified
- `exampleInput` (object): Present when the listing's own example input got 'not found' when we paid (no money taken): use real input.
- `forTeams` (object): Short note about team plans (per-agent keys, spend limits, audit trail)
- `grade` (string): A delivered cleanly; B delivered with a caveat; C unconfirmed; D doesn't work as listed, no money lost; F costs money or unsafe; ? with too little data
- `listing` (object): Present only when the latest paid response differs from the listing's example or schema. The data is delivered.
- `monitored` (boolean): false if the endpoint isn't in the monitored catalog
- `page` (string): Public page with the full history
- `payToMode` (string): fixed, or per_request when the seller issues a new payout address per request
- `probes` (number): Checks counted in the last 7 days
- `requiredInput` (object): Present when our paid test was refused for want of a header or input the listing doesn't document (no money taken).
- `score` (number|null): 0-100; null for free resources
- `testedWith` (object): Present when the latest passing paid test needed a sign-in or extra input: a seller-provided test account, a wallet sign-in, or the seller's declared test request.
- `uptimePct` (number): Share of checks in the last 7 days that returned a valid payment quote
- `url` (string): The endpoint checked
- `values` (object): Automatic value checks on the latest paid response. A warning caps the grade at B, never avoid.
- `valuesChecked` (boolean): Latest paid check also passed known-answer value tests
- `verdict` (string): proceed | caution | avoid | free | insufficient_data
- `walletIncidents` (number): Unexplained payout-wallet changes
- `walletUnconfirmed` (number): Recent wallet changes nobody could confirm yet
- `withdrawn` (object): Present when the endpoint was withdrawn by its seller or is gone from the Bazaar: no longer for sale, don't pay it.

### `check_payment` (~474 tokens)

Check an x402 payment before paying

Decide whether a specific x402 payment should go through: returns allow true/false with reasons. Checks the endpoint's trust verdict, that the amount is within your cap and not above the monitored price, and that the payTo wallet matches the one we've observed (catches swapped or hijacked wallets). Optionally (minOrganicShare) it also requires that enough of the seller's volume comes from independent buyers. Intended for right before a payment, with the amount, payTo, and network from the endpoint's 402 quote; allow is true only when every rule passes. Use check_endpoint instead if you only want an endpoint's grade without a quote in hand. Read-only and free; it doesn't make or block the payment itself. When allow is false, the reasons list explains why. API docs: https://github.com/Book0fEli/lumiere-paycheck/blob/main/docs/api.md

Input parameters:

- `allowCaution` (boolean): false = deny endpoints with a caution verdict too, not just avoid (default true)
- `amount` (string): Amount about to be paid, atomic units (USDC has 6 decimals: 10000 = $0.01)
- `hasAccess` (boolean): true if you have your own account, API key or sign-in with this seller. For endpoints that need the seller's sign-in on top of x402, allowCaution/requireVerified then don't block (we couldn't confirm…
- `maxAmount` (string): Your hard cap for this payment in atomic units (USDC: 1000000 = $1). Payments above it are denied.
- `minOrganicShare` (number): Optional, 0-1: deny sellers where less than this share of 30-day volume comes from independent buyers (e.g. 0.5). Not applied to sellers whose buyers haven't been reviewed yet.
- `network` (string): Network from the quote, e.g. eip155:8453
- `payTo` (string): Wallet address from the endpoint's 402 quote
- `requireVerified` (boolean): true = only allow endpoints that delivered on a real test payment (default false)
- `url` (string, required): Full URL of the x402 endpoint you are about to pay, including path

Output parameters:

- `afterPaying` (string): How to report the outcome after paying (free, verified on-chain)
- `allow` (boolean): Pay only when true
- `authRequired` (boolean): true: the seller needs its own sign-in on top of x402; send hasAccess: true if you have it
- `buyerReports` (object): What real buyers reported after paying. Never changes the grade; confirmations move the endpoint up our paid-test queue.
- `buyers` (object): Who is really behind the seller's buyers. Never changes the grade.
- `declaredPayTo` (array): Payout wallets the seller declared itself
- `delivery` (string)
- `forTeams` (object): Short note about team plans (per-agent keys, spend limits, audit trail)
- `grade` (string)
- `listing` (object): Present only when the latest paid response differs from the listing's example or schema. The data is delivered.
- `monitored` (boolean): Whether the endpoint is in the monitored catalog
- `notes` (array)
- `observed`: The latest payment quote our monitor saw
- `payToMode` (string)
- `reasons` (array): Why it was allowed or denied
- `reviewable` (boolean): Denied only for reasons a person may approve
- `score` (number|null)
- `url` (string)
- `values` (object): Automatic value checks on the latest paid response
- `verdict` (string|null): proceed | caution | avoid | free | insufficient_data
- `walletUnconfirmed` (number)

### `report_outcome` (~339 tokens)

Report how a paid x402 call went

After paying an x402 endpoint, report whether you got what you paid for. Free, optional, and open to every agent: send the receipt from a Lumière PayCheck allow decision (paid plans), or the endpoint url plus the payment's transaction hash (anyone; we verify the payment on-chain, Base or Solana, within 24 hours). Answer the short questions in answers: gotResponse, matchedListing (yes/partly/no), charged (as_quoted/more/twice), dataUsable (yes/unsure/no), wouldPayAgain. Reports never change a grade by themselves: confirmations from independent buyers move the endpoint up our paid-test queue, and serious problems (nothing came back, charged more or twice) trigger a re-test; only our own paid test changes the grade. One report per payment; the seller's own wallet can't report on itself.

Input parameters:

- `answers` (object)
- `httpStatus` (integer): HTTP status the endpoint returned after payment, e.g. 200 or 500
- `outcome` (string): Optional shortcut instead of answers: delivered = usable; problem = error, empty, wrong or overcharged
- `problems` (array): Short descriptions, e.g. 'missing field price', 'HTTP 500'
- `receipt` (string): The receipt from a Lumière PayCheck 'allow' decision (paid plans). Or send url + tx instead.
- `tx` (string): The payment's transaction hash (Base 0x...) or Solana signature
- `url` (string): The endpoint you paid (with tx, when you have no receipt)

Output parameters:

- `accepted` (boolean): Whether the report was recorded
- `flagged` (string): no_response, overcharged or double_charged: sent privately to the operator for an immediate re-test
- `forTeams` (object): Short note about team plans (per-agent keys, spend limits, audit trail)
- `network` (string)
- `ourTestQueued` (boolean): Our own paid test of this endpoint is queued (buyer confirmations or problem reports moved it up)
- `outcome` (string)
- `overcharge` (string): Present when the on-chain payment was higher than any quote we saw
- `paid` (string): Amount paid on-chain, atomic units
- `reason` (string): Why it wasn't accepted
- `retestQueued` (boolean): A paid re-test was queued because of reports
- `thanks` (string)
- `url` (string)
- `verifiedOnChain` (boolean): The payment was found on-chain (reports sent with tx instead of a receipt)

### `top_endpoints` (~116 tokens)

Most trustworthy x402 endpoints

List the x402 endpoints that are currently safest to pay (verdict proceed or caution, no payout-wallet incidents), best first, with score, grade, verdict, and whether a real test payment was delivered. Use it to discover reliable endpoints or pick between providers. To evaluate one specific endpoint use check_endpoint; to approve a payment use check_payment. Read-only and free; rankings update as monitoring runs (every 30 minutes).

Input parameters:

- `limit` (integer): How many endpoints to return, 1-50 (default 10)

Output parameters:

- `count` (number)
- `endpoints` (array): Best first
- `forTeams` (object): Short note about team plans (per-agent keys, spend limits, audit trail)

### `catalog_stats` (~111 tokens)

x402 catalog statistics

Get an overview of the whole monitored x402 catalog: how many endpoints are monitored, how many fall into each verdict (proceed, caution, avoid, free, insufficient_data), and when scores were last computed. Use it for context or reporting, for example to tell a user how much of the x402 ecosystem passes checks. It says nothing about any single endpoint: use check_endpoint for one endpoint, top_endpoints for a ranked list, or check_payment before paying. Read-only, free, no parameters.

Output parameters:

- `byVerdict` (object): Endpoint count per verdict
- `endpoints` (number): Endpoints monitored
- `forTeams` (object): Short note about team plans (per-agent keys, spend limits, audit trail)
- `scoredAt` (string|null): When scores were last computed

### `get_full_report` (~181 tokens)

How to get a full trust report

Get instructions for buying the detailed paid report on one x402 endpoint (score breakdown, current price quote, wallet and price history, test-payment results). Returns the report URL, price, and network; it doesn't buy the report itself. The report is an x402 endpoint that your agent pays with any x402 client. Use it only when the free check_endpoint result isn't enough and the user wants the full history. The response also lists the other paid x402 checks (wallet risk, batch grades, watch alerts), paid the same way. Endpoints we don't monitor return 404 on the report URL and are never charged. API docs: https://github.com/Book0fEli/lumiere-paycheck/blob/main/docs/api.md

Input parameters:

- `url` (string, required): Full URL of the x402 endpoint you want the paid report for, including path

Output parameters:

- `available` (boolean): false when paid reports aren't enabled
- `forTeams` (object): Short note about team plans (per-agent keys, spend limits, audit trail)
- `network` (string)
- `note` (string)
- `otherPaidChecks` (array): Other pay-per-call x402 checks, paid the same way
- `payment` (string)
- `price` (string)
- `reportUrl` (string): Request this URL with an x402 client to buy the report

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/book0feli-paycheck/lumierepaycheck-2#diagnostics

## Score history

- 2026-10-07: 76
- 2026-10-04: 76

## Common questions

### What is the Lumière PayCheck MCP server?

Lumière PayCheck is an MCP server listed in the public MCP registry as io.github.Book0fEli/paycheck. Check any x402 endpoint before your AI agent pays it: trust grade, verdict, and hijack checks. This page covers its hosted endpoint (https://lumierepaycheck.org/mcp?plans=1).

### Is the Lumière PayCheck MCP server safe to use?

Lumière PayCheck scores 76 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Lumière PayCheck MCP server expose?

Lumière PayCheck exposes 6 tools: check_endpoint, check_payment, report_outcome, top_endpoints, catalog_stats, get_full_report. Their descriptions and schemas cost roughly 1,469 tokens of context every time the server is loaded.

### Does the Lumière PayCheck MCP server require authentication?

No. We connected to Lumière PayCheck without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the Lumière PayCheck MCP server still maintained?

Lumière PayCheck is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://lumierepaycheck.org/mcp?plans=1
- Repository: https://github.com/Book0fEli/lumiere-paycheck
- Website: https://lumierepaycheck.org/
- Changelog RSS feed: https://verifymcp.io/servers/book0feli-paycheck/lumierepaycheck-2.xml
- Changelog JSON feed: https://verifymcp.io/servers/book0feli-paycheck/lumierepaycheck-2.json
- HTML version of this page: https://verifymcp.io/servers/book0feli-paycheck/lumierepaycheck-2
