Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Wever Labs Agent Products

REMOTE · WEVERLABS.COM · SCANNED OCT 1

Agent commerce: 27 tools, 10 production services, signed authority, planning, Base USDC x402.

Available components

59 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security63
Transport & Reachability100
Schema Quality & AI Usability49
  • AI-judged instruction clarity (good).Pass
  • Context-footprint check failed: tool/resource definitions use about 6384 tokens (~236/item across 27 items; 27 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
  • Stability check failed: schema churn in the 2 days we've observed: 0 tool removals, 6 breaking changes, 0 auth/transport breaks, 0 additions. See how to fix → Fail
Tool Coverage68
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 3% of tool parameters carry a description.Partial
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • We read all 27 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
  • An AI judge read all 28 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

How do I install the Wever Labs Agent Products MCP server?

Wever Labs Agent Products is a hosted endpoint at https://weverlabs.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · weverlabs.com

# add to Claude Code
claude mcp add --transport http codewever-wever-labs-products 'https://weverlabs.com/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "codewever-wever-labs-products": {
      "url": "https://weverlabs.com/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "codewever-wever-labs-products": {
      "type": "http",
      "url": "https://weverlabs.com/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.codewever-wever-labs-products]
url = "https://weverlabs.com/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "codewever-wever-labs-products": {
      "type": "remote",
      "url": "https://weverlabs.com/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add codewever-wever-labs-products --url 'https://weverlabs.com/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  codewever-wever-labs-products:
    url: "https://weverlabs.com/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "codewever-wever-labs-products": {
      "Transport": "http",
      "Url": "https://weverlabs.com/mcp"
    }
  }
}
# add to Vellum
assistant mcp add codewever-wever-labs-products -t streamable-http -u 'https://weverlabs.com/mcp'
// mcp.json
{
  "mcpServers": {
    "codewever-wever-labs-products": {
      "type": "http",
      "url": "https://weverlabs.com/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 1 Oct 26 0
    • The server rewrote its instructions, which are the text every model session reads security
    • Tool “wever_ap2-mandate-gateway” rewrote its description, which is the text the model reads security
    • Tool “wever_delegated-authority” rewrote its description, which is the text the model reads security
    • “wever_ap2-mandate-gateway” added a required parameter “challenge_token”, so existing callers break ▼ functional
    • “wever_ap2-mandate-gateway” added a required parameter “presentation”, so existing callers break ▼ functional
    • “wever_ap2-mandate-gateway” made “mode” required, so existing callers break ▼ functional
    • Server version: 0.7.0 → 0.8.0 functional
  • 30 Sept 26 −1
    • Stability: unverified → fail ▼ security
    • The server rewrote its instructions, which are the text every model session reads security
    • Tool “wever_agent-allowance-console” rewrote its description, which is the text the model reads security
    • Tool “wever_agent-budget-guard” rewrote its description, which is the text the model reads security
    • Tool “wever_agent-daily-operator-brief” rewrote its description, which is the text the model reads security
    • Tool “wever_agent-escrow-lite” rewrote its description, which is the text the model reads security
    • Tool “wever_agent-invoice-rail” rewrote its description, which is the text the model reads security
    • Tool “wever_agent-paid-workflow” rewrote its description, which is the text the model reads security
    • Tool “wever_agent-work-order-exchange” rewrote its description, which is the text the model reads security
    • Tool “wever_agent-work-order-rail” rewrote its description, which is the text the model reads security
    • Tool “wever_delegated-authority” rewrote its description, which is the text the model reads security
    • Tool “wever_diligenceops-paid-run” rewrote its description, which is the text the model reads security
    • Tool “wever_mcp-diligence-rail” rewrote its description, which is the text the model reads security
    • Tool “wever_payment-authority-inspector” rewrote its description, which is the text the model reads security
    • Tool “wever_proof-relay” rewrote its description, which is the text the model reads security
    • Tool “wever_unified-agent-checkout” rewrote its description, which is the text the model reads security
    • Tool “wever_x402-payment-gateway” rewrote its description, which is the text the model reads security
    • Tool “wever_agent-budget-guard” no longer declares itself destructive security
    • Tool “wever_payment-authority-inspector” no longer declares itself destructive security
    • Tool “wever_x402-payment-gateway” no longer declares itself destructive security
    • Schema quality: 197 → 230 ▼ functional
    • “wever_agent-budget-guard” added a required parameter “agent_id”, so existing callers break ▼ functional
    • “wever_agent-budget-guard” added a required parameter “policy”, so existing callers break ▼ functional
    • “wever_agent-budget-guard” added a required parameter “request”, so existing callers break ▼ functional
    • “wever_agent-budget-guard” added a required parameter “usage”, so existing callers break ▼ functional
    • “wever_agent-invoice-rail” added a required parameter “schema_version”, so existing callers break ▼ functional
    • “wever_payment-authority-inspector” added a required parameter “amount_atomic”, so existing callers break ▼ functional
    • “wever_payment-authority-inspector” added a required parameter “authorization_nonce”, so existing callers break ▼ functional
    • “wever_payment-authority-inspector” added a required parameter “min_confirmations”, so existing callers break ▼ functional
    • “wever_payment-authority-inspector” added a required parameter “payee”, so existing callers break ▼ functional
    • “wever_payment-authority-inspector” added a required parameter “payer”, so existing callers break ▼ functional
    • “wever_payment-authority-inspector” added a required parameter “transaction_hash”, so existing callers break ▼ functional
    • “wever_x402-payment-gateway” added a required parameter “payment”, so existing callers break ▼ functional
    • “wever_x402-payment-gateway” added a required parameter “target_product”, so existing callers break ▼ functional
    • “wever_agent-budget-guard” made “mode” required, so existing callers break ▼ functional
    • “wever_agent-escrow-lite” made “mode” required, so existing callers break ▼ functional
    • “wever_agent-invoice-rail” made “mode” required, so existing callers break ▼ functional
    • “wever_payment-authority-inspector” made “mode” required, so existing callers break ▼ functional
    • “wever_x402-payment-gateway” made “mode” required, so existing callers break ▼ functional
    • Server version: 0.4.0 → 0.7.0 functional
    • “wever_agent-escrow-lite” added an optional parameter “escrow_id” cosmetic
    • “wever_agent-escrow-lite” added an optional parameter “funding_payment” cosmetic
    • “wever_agent-escrow-lite” added an optional parameter “idempotency_key” cosmetic
    • “wever_agent-escrow-lite” added an optional parameter “mandate” cosmetic
    • “wever_agent-escrow-lite” added an optional parameter “payer_terms_signature” cosmetic
    • “wever_agent-escrow-lite” added an optional parameter “terms” cosmetic
    • “wever_agent-invoice-rail” added an optional parameter “amount_atomic” cosmetic
    • “wever_agent-invoice-rail” added an optional parameter “buyer_reference” cosmetic
    • “wever_agent-invoice-rail” added an optional parameter “buyer_wallet” cosmetic
    • “wever_agent-invoice-rail” added an optional parameter “decision” cosmetic
    • “wever_agent-invoice-rail” added an optional parameter “description” cosmetic
    • “wever_agent-invoice-rail” added an optional parameter “expected_version” cosmetic
    • “wever_agent-invoice-rail” added an optional parameter “expires_at” cosmetic
    • “wever_agent-invoice-rail” added an optional parameter “idempotency_key” cosmetic
    • “wever_agent-invoice-rail” added an optional parameter “invoice_id” cosmetic
    • “wever_agent-invoice-rail” added an optional parameter “note” cosmetic
    • “wever_agent-invoice-rail” added an optional parameter “rail_key” cosmetic
    • “wever_agent-invoice-rail” added an optional parameter “run_binding” cosmetic
    • “wever_agent-invoice-rail” added an optional parameter “usage” cosmetic
  • 29 Sept 26 60

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 1 Oct 2026 · Probed https://weverlabs.com/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=distributionops.com CN=YE1,O=Let's Encrypt,C=US 26 Sept 2026 25 Dec 2026 ECDSA 256 ECDSA-SHA384 501881397357ad8a68fe2cc2f722f3812f9
SANs: *.distributionops.com, *.weverlabs.com, distributionops.com, weverlabs.com
CN=YE1,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 5ddd70dd31f801c85c186a7a04b80afe
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of weverlabs.com. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
weverlabs.com. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200
Header Value
strict-transport-security max-age=63072000; includeSubDomains; preload
content-security-policy default-src 'self'; base-uri 'self'; connect-src 'self' https://wever-pay-agent-mesh-phase5-staging.quiet-salad-e96e.workers.dev https://agents.weverlabs.com; font-src 'self' data:; frame-ancestors 'none'; img-src 'self' data: https:; object-src 'none'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; upgrade-insecure-requests
x-content-type-options nosniff
x-frame-options DENY
referrer-policy strict-origin-when-cross-origin
permissions-policy camera=(), microphone=(), geolocation=(), payment=()

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://weverlabs.com/mcp Verified 200
http (plaintext) http://weverlabs.com/mcp HTTPS enforced 301 https://weverlabs.com/mcp
MCP tools · 27 exposed · ~6,301 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
wever_agent-allowance-console ~303

Paid URL: 0.10 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Read the backend 402 body for x402 terms. Evaluate explicit caller-reported scope, budget, usage, expiry and per-action fee limits. Returns a would-allow or would-deny preview; creates no authority and verifies no account balance. Operating boundary: Direct access uses x402 Base USDC settlement or the verified-wallet free tier. The prepared computation uses caller-supplied data and creates no execution authority, proof verification, delivery or provider action. Payment access records are durable; existing credentials and signed grants remain required for separate consequential actions. POST /api/agent-allowance-console. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This current operation is a bounded computation on caller-supplied data.

NameTypeReqDescription
agent_idstringyes–
allowed_product_keysarrayyes–
as_ofstringyes–
budget_minorintegeryes–
currency–yes–
expires_atstringyes–
max_fee_minorintegeryes–
max_runsintegeryes–
mode–yes–
requested_fee_minorintegeryes–
requested_product_keystringyes–
spent_minorintegeryes–
used_runsintegeryes–

No output schema declared.

No examples provided.

wever_agent-budget-guard ~269

Paid URL: 0.10 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Read the backend 402 body for x402 terms. Evaluates caller-supplied policy, usage and request values only. No live allowance or balance is read, no destination is contacted, no budget or run is reserved, and no permission or execution authority is granted. Operating boundary: Direct access uses x402 Base USDC settlement or the verified-wallet free tier. Evaluates caller-supplied policy, usage and request values only. No live allowance or balance is read, no destination is contacted, no budget or run is reserved, and no permission or execution authority is granted. The API access fee is separate from any inspected payment or recorded invoice amount. POST /api/agent-budget-guard. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This current money service follows its published inspection, policy evaluation or private invoice contract. Payment is an API access fee and grants no spending authority.

NameTypeReqDescription
agent_idstringyes–
mode–yes–
policyobjectyes–
requestobjectyes–
usageobjectyes–

No output schema declared.

No examples provided.

wever_agent-daily-operator-brief ~248

Paid URL: 0.25 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Free computation: /api/mcp or /api/service-resolver. Read the backend 402 body for x402 terms. Summarize supplied service health and queue observations into deterministic priorities. No private records are fetched and no activity is invented. Operating boundary: The computation uses supplied data only and performs no provider work, callbacks, document retrieval or signed attestations. Direct access uses x402 Base USDC settlement or the verified-wallet free tier; the Labs MCP and resolver computation paths remain free. POST /api/agent-daily-operator-brief. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This current operation is a bounded computation on caller-supplied data.

NameTypeReqDescription
as_ofstringyesA valid UTC calendar timestamp with whole seconds, supplied by the caller.
queuesarrayyesUnique queue names. Empty queues must have a null or zero oldest age.
servicesarrayyesUnique service_id values.

No output schema declared.

No examples provided.

wever_agent-decision-packet-rail ~188

Unavailable historical backend. Sandbox/demo: builds a decision-packet template with fixed rationale and ranks options in submitted order, recommending the first option. It does not evaluate the supplied constraints or establish which option is best. Turn messy options into a decision packet with pros, cons, risks, unknowns, constraints, recommendation, and human decision point. Operating boundary: Prepares decisions for review. It does not make binding decisions, approve spending, or take final action. POST /api/agent-decision-packet-rail. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This is a catalog proxy entry, not a guarantee of backend availability. Backend status and JSON errors are surfaced; unavailable or non-JSON backends produce tool errors.

NameTypeReqDescription
modestring––

No output schema declared.

No examples provided.

wever_agent-escrow-lite ~327

Paid URL: 0.10 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Read the backend 402 body for x402 terms. Escrow principal and API-fee wallet: 0x69255FeaC86268C0D0bD0CBd128da7B9aB44b1c4. Principal funding is separate, and every call requires a signed wallet ownership proof. Managed Base USDC custody with verified funding, immutable parties, EIP-712 release policies, expiry refunds to the payer and a durable public release log. Operating boundary: The separate custody wallet accepts bounded USDC principal. A verified release pays only the immutable payee; an expiry refund pays only the immutable payer. API fees are separate, manual sweeps are required, and work-order grants are not payment authority. POST /api/agent-escrow-lite. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This managed custody service uses immutable escrow parties and EIP-712 release policies. Releases pay only the payee; expiry refunds pay only the payer. Public logs report durable state and transaction evidence. Work-order grants do not authorize payment.

NameTypeReqDescription
escrow_idstring––
funding_payment–––
idempotency_keystring––
mandateobject––
mode–yes–
payer_terms_signaturestring––
termsobject––

No output schema declared.

No examples provided.

wever_agent-file-desk-rail ~190

Unavailable historical backend. Sandbox/demo: classifies supplied filenames using invoice and contract substrings and flags names containing copy. This bounded filename heuristic does not inspect file contents, verify duplicate content, move or delete files, or perform the cleanup implied by its generated receipt identifier. Classify files, extract document metadata, detect duplicates, suggest destinations, and create a cleanup review queue. Operating boundary: Prepares file organization recommendations and review queues. Destructive moves or deletions require outside approval. POST /api/agent-file-desk-rail. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This is a catalog proxy entry, not a guarantee of backend availability. Backend status and JSON errors are surfaced; unavailable or non-JSON backends produce tool errors.

NameTypeReqDescription
modestring––

No output schema declared.

No examples provided.

wever_agent-invoice-rail ~346

Paid URL: 0.10 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Read the backend 402 body for x402 terms. Private issuer-wallet invoice ledger, immutable face amount and parties, run-reference binding and recorded issuer review. References are not independently verified. No bill delivery, payment collection or spending authority. Operating boundary: Direct access uses x402 Base USDC settlement or the verified-wallet free tier. Private issuer-wallet invoice ledger, immutable face amount and parties, run-reference binding and recorded issuer review. References are not independently verified. No bill delivery, payment collection or spending authority. Every invoice operation also requires a signed issuer-wallet ownership proof. The API access fee is separate from any inspected payment or recorded invoice amount. POST /api/agent-invoice-rail. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This current money service follows its published inspection, policy evaluation or private invoice contract. Payment is an API access fee and grants no spending authority.

NameTypeReqDescription
amount_atomicstring––
buyer_referencestring––
buyer_walletstring––
decision–––
descriptionstring––
expected_versioninteger––
expires_atinteger––
idempotency_keystring––
invoice_idstring––
modestringyes–
notestring––
rail_keystring––
run_bindingobject––
schema_version–yes–
usage–––

No output schema declared.

No examples provided.

wever_agent-paid-workflow ~221

Paid URL: 0.10 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Read the backend 402 body for x402 terms. Prepare an ordered sequence of supported planning and computation steps with explicit required fields. No step is executed, no quote obtained, and no payment, authority or delivery is performed. Operating boundary: Direct access uses x402 Base USDC settlement or the verified-wallet free tier. The prepared computation uses caller-supplied data and creates no execution authority, proof verification, delivery or provider action. Payment access records are durable; existing credentials and signed grants remain required for separate consequential actions. POST /api/agent-paid-workflow. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This current operation is a bounded computation on caller-supplied data.

NameTypeReqDescription
agent_idstringyes–
constraintsobjectyes–
mode–yes–
product_key–yes–

No output schema declared.

No examples provided.

wever_agent-permission-ledger ~183

Unavailable historical backend. Sandbox/demo: previews a permission decision using caller-supplied allowed actions and a fixed list of consequential actions. It does not authenticate a principal, read a ledger, persist permissions or grant execution authority. Track what an agent is allowed to do, what requires approval, what changed, and what must be denied before action. Operating boundary: Records and evaluates bounded agent permissions. It returns service shape and decision objects without exposing private operator rows. POST /api/agent-permission-ledger. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This is a catalog proxy entry, not a guarantee of backend availability. Backend status and JSON errors are surfaced; unavailable or non-JSON backends produce tool errors.

NameTypeReqDescription
modestring––

No output schema declared.

No examples provided.

wever_agent-sla-rail ~182

Unavailable historical backend. Sandbox/demo: prepares an SLA policy template from supplied values or defaults. It does not record an agreement, monitor a service, schedule retries or enforce a response deadline. Create an operational promise around a rail run: response expectation, callback requirement, retry count, proof requirements, and failure behavior. Operating boundary: Records the operating terms for a rail run: response expectation, retry count, callback requirement, proof requirements, and failure behavior. POST /api/agent-sla-rail. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This is a catalog proxy entry, not a guarantee of backend availability. Backend status and JSON errors are surfaced; unavailable or non-JSON backends produce tool errors.

NameTypeReqDescription
modestring––

No output schema declared.

No examples provided.

wever_agent-to-agent-handoff-pack ~199

Unavailable historical backend. Sandbox/demo: assembles a handoff envelope and hash from supplied data, with sample package and receipt identifiers when omitted. It does not verify the referenced proof, deliver the handoff or authorize the receiving agent. Package completed work so another agent can pick it up: task summary, return package, exception object, receipt passport, callback target, and next action. Operating boundary: Packages completed paid work for another agent to continue, including proof, receipt passport, callback target, exception state, and next action. POST /api/agent-to-agent-handoff-pack. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This is a catalog proxy entry, not a guarantee of backend availability. Backend status and JSON errors are surfaced; unavailable or non-JSON backends produce tool errors.

NameTypeReqDescription
modestring––

No output schema declared.

No examples provided.

wever_agent-trust-scorecard ~190

Unavailable historical backend. Sandbox/demo: returns supplied or default example statistics and calculates a sample callback rate. It does not read operational records or verify reputation. Default counts and generated last-seen timestamps are not observations of agent activity. Show proof-based trust signals for an agent or provider: completed runs, verified receipts, callback success, denied attempts, supported rails, and last seen. Operating boundary: Returns operational trust signals from proof events so agents can choose counterparties with facts, not profile claims. POST /api/agent-trust-scorecard. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This is a catalog proxy entry, not a guarantee of backend availability. Backend status and JSON errors are surfaced; unavailable or non-JSON backends produce tool errors.

NameTypeReqDescription
modestring––

No output schema declared.

No examples provided.

wever_agent-work-order-exchange ~233

Paid URL: 0.10 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Read the backend 402 body for x402 terms. Validate a task against a supported computation and prepare its fixed POST request. Semantic validation uses a local deterministic dry run. No request is submitted, worker assigned or result delivered. Operating boundary: Direct access uses x402 Base USDC settlement or the verified-wallet free tier. The prepared computation uses caller-supplied data and creates no execution authority, proof verification, delivery or provider action. Payment access records are durable; existing credentials and signed grants remain required for separate consequential actions. POST /api/agent-work-order-exchange. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This current operation is a bounded computation on caller-supplied data.

NameTypeReqDescription
mode–yes–
product_key–yes–
requested_outcomestringyes–
requesting_agent_idstringyes–
taskobjectyes–

No output schema declared.

No examples provided.

wever_agent-work-order-rail ~223

Paid URL: 0.10 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Free computation: /api/mcp or /api/service-resolver. Read the backend 402 body for x402 terms. Prepare a validated DiligenceOps task for a specific Connect recipient. Submission, recipient permission and execution remain separate steps. Operating boundary: The computation uses supplied data only and performs no provider work, callbacks, document retrieval or signed attestations. Direct access uses x402 Base USDC settlement or the verified-wallet free tier; the Labs MCP and resolver computation paths remain free. POST /api/agent-work-order-rail. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This current operation is a bounded computation on caller-supplied data.

NameTypeReqDescription
available_evidencearrayyes–
expected_evidencearrayyes–
recipient_idstringyes–
service_id–yes–

No output schema declared.

No examples provided.

wever_ap2-mandate-gateway ~239

Paid URL: 0.10 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Read the backend 402 body for x402 terms. Verifies allowlisted AP2 direct closed-checkout mandates, binds the presenter to the holder wallet, rejects expiry and replay, and durably consumes each mandate once. Operating boundary: Wever trusted-provider direct closed-checkout profile only. No open mandates, delegation chains, checkout execution, payment execution or fund transfers. Signed wallet proof is required even for paid calls. POST /api/ap2-mandate-gateway. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This gateway verifies only its published AP2 direct closed-checkout profile, requires a trusted issuer and holder wallet proof, and consumes the mandate once. It does not execute the checkout or transfer funds. Start at /api/ap2-contract and /api/ap2-challenge.

NameTypeReqDescription
challenge_tokenstringyes–
mode–yes–
presentationstringyes–

No output schema declared.

No examples provided.

wever_callback-health-monitor ~174

Unavailable historical backend. Sandbox/demo: checks whether a callback URL starts with HTTPS and returns an example health response. It does not contact the receiver or verify an acknowledgment, availability or delivery. Check whether a callback receiver is alive, accepts proof payloads, and returns an acknowledgment shape an agent can trust. Operating boundary: Validates callback receivers before paid work is delivered so proof can be sent, acknowledged, retried, and audited. POST /api/callback-health-monitor. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This is a catalog proxy entry, not a guarantee of backend availability. Backend status and JSON errors are surfaced; unavailable or non-JSON backends produce tool errors.

NameTypeReqDescription
modestring––

No output schema declared.

No examples provided.

wever_delegated-authority ~480

Paid URL: 2.00 USDC per mandate on Base; 10 signed-wallet free calls shared over rolling 30 days. Only issue_mandate is billed; GET, contract reads, drafts and all other modes have no x402 fee. Credentials and grants remain required for their existing operations. Read the backend 402 body for x402 terms. Issue signed mandates and operator-approved action grants, then let credentialed agents consume them to create immutable work-order records. Records do not perform work, deliver results or authorize payment. Operating boundary: Operators issue mandates and approve each exact action grant with an issuance idempotency key. Only the bound credentialed agent may consume a grant; each action grant atomically reserves one nonfinancial work_order unit. Usage and attribution are credential-bound. Signed authority permits only immutable record creation, never work execution, delivery or payment. Public drafts remain unsigned_dev and cannot execute. The access fee applies only to issue_mandate and never authorizes downstream spending. GET, contract reads, drafts and all other authority modes have no x402 fee; their existing credential checks remain. POST /api/delegated-authority. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This current operation is a credentialed authority control plane for immutable work-order record creation. It does not execute the recorded work, deliver results, or authorize payment. Operator issuance and grant approval require X-Wever-Operator-Key and Idempotency-Key; consumption requires the target agent's X-Wever-Agent-Key. Usage and attribution come from validated credentials and durable authority records. AP2 issuance also accepts issue_mandate with mandate.profile com.weverlabs.ap2.direct-checkout.1, the holder public key, signed checkout challenge, consent digest and bounded expiry. It requires a dedicated AP2 i…

NameTypeReqDescription
mode–yes–

No output schema declared.

No examples provided.

wever_diligenceops-paid-run ~208

Paid URL: 1.00 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Free computation: /api/mcp or /api/service-resolver. Read the backend 402 body for x402 terms. Compare explicit submitted evidence labels and return exact matched and missing items. This does not read or verify document contents. Operating boundary: The computation uses supplied data only and performs no provider work, callbacks, document retrieval or signed attestations. Direct access uses x402 Base USDC settlement or the verified-wallet free tier; the Labs MCP and resolver computation paths remain free. POST /api/diligenceops-paid-run. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This current operation is a bounded computation on caller-supplied data.

NameTypeReqDescription
available_evidencearrayyes–
expected_evidencearrayyes–

No output schema declared.

No examples provided.

wever_mcp-diligence-rail ~200

Paid URL: 0.10 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Free computation: /api/mcp or /api/service-resolver. Read the backend 402 body for x402 terms. Inventory submitted MCP tool declarations and flag missing or consequential annotations. This does not connect to a server or grant authority. Operating boundary: The computation uses supplied data only and performs no provider work, callbacks, document retrieval or signed attestations. Direct access uses x402 Base USDC settlement or the verified-wallet free tier; the Labs MCP and resolver computation paths remain free. POST /api/mcp-diligence-rail. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This current operation is a bounded computation on caller-supplied data.

NameTypeReqDescription
toolsarrayyes–

No output schema declared.

No examples provided.

wever_payment-authority-inspector ~257

Paid URL: 0.10 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Read the backend 402 body for x402 terms. Read-only canonical Base USDC receipt inspection for the configured Wever recipient. Settlement evidence grants no mandate, resource permission or execution authority. Operating boundary: Direct access uses x402 Base USDC settlement or the verified-wallet free tier. Read-only canonical Base USDC receipt inspection for the configured Wever recipient. Settlement evidence grants no mandate, resource permission or execution authority. The API access fee is separate from any inspected payment or recorded invoice amount. POST /api/payment-authority-inspector. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This current money service follows its published inspection, policy evaluation or private invoice contract. Payment is an API access fee and grants no spending authority.

NameTypeReqDescription
amount_atomicstringyes–
authorization_noncestringyes–
min_confirmationsintegeryes–
mode–yes–
payeestringyes–
payerstringyes–
transaction_hashstringyes–

No output schema declared.

No examples provided.

wever_proof-inbox ~182

Unavailable historical backend. Sandbox/demo: generates five example proof-event categories with new identifiers and timestamps. It does not read or write an inbox. Its completed, recorded and acknowledged states are sample events, not operational evidence. Read a single view of completed runs, receipts, callback events, exceptions, handoffs, and status events. Operating boundary: Shows proof events from live agent work: completed runs, receipts, callbacks, exceptions, handoffs, and directory status events. POST /api/proof-inbox. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This is a catalog proxy entry, not a guarantee of backend availability. Backend status and JSON errors are surfaced; unavailable or non-JSON backends produce tool errors.

NameTypeReqDescription
modestring––

No output schema declared.

No examples provided.

wever_proof-relay ~225

Paid URL: 0.10 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Read the backend 402 body for x402 terms. Prepare a reference envelope and deterministic source/destination binding digest. References and supplied hashes remain unverified. No destination is contacted, no acknowledgment is obtained, and nothing is delivered or persisted. Operating boundary: Direct access uses x402 Base USDC settlement or the verified-wallet free tier. The prepared computation uses caller-supplied data and creates no execution authority, proof verification, delivery or provider action. Payment access records are durable; existing credentials and signed grants remain required for separate consequential actions. POST /api/proof-relay. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This current operation is a bounded computation on caller-supplied data.

NameTypeReqDescription
destination–yes–
mode–yes–
proof_referencesarrayyes–
source_agent_idstringyes–

No output schema declared.

No examples provided.

wever_rail-playground ~182

Unavailable historical backend. Sandbox/demo: generates an example rail package, receipt and transcript locally. No external rail work runs. Its passed state and repeatability score describe generated sample output and are not measured production results. Test PacketOps and DiligenceOps with sample data, then start a agent run with the same rail shape. Operating boundary: Lets agents test rail shape with sample data, then move directly into paid PacketOps or DiligenceOps runs when ready. POST /api/rail-playground. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This is a catalog proxy entry, not a guarantee of backend availability. Backend status and JSON errors are surfaced; unavailable or non-JSON backends produce tool errors.

NameTypeReqDescription
modestring––

No output schema declared.

No examples provided.

wever_receipt-passport ~202

Unavailable historical backend. Sandbox/demo: builds a receipt-passport envelope from supplied fields and a locally generated sample run. It does not retrieve or verify completed work or supplied proof. Generated receipt, verification and handoff fields are not evidence of production execution. Create a short, portable proof object for a completed rail run. Agents use it to verify receipt state without carrying the full run payload. Operating boundary: Creates a portable proof passport for a paid or authority-bound rail run. Use it after a completed run to verify receipt, return package, callback, and transcript linkage. POST /api/receipt-passport. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This is a catalog proxy entry, not a guarantee of backend availability. Backend status and JSON errors are surfaced; unavailable or non-JSON backends produce tool errors.

NameTypeReqDescription
modestring––

No output schema declared.

No examples provided.

wever_return-package-viewer ~187

Unavailable historical backend. Sandbox/demo: renders a generated example return package and receipt status using supplied or generated identifiers. It does not retrieve a stored package or establish that work completed. Read a rail return package in a clean shape. Agents get JSON. Humans get the same facts in a page that shows what was checked, what is missing, and what proof was issued. Operating boundary: Reads completed return packages and presents the same proof facts to agents and humans without changing the source rail output. POST /api/return-package-viewer. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This is a catalog proxy entry, not a guarantee of backend availability. Backend status and JSON errors are surfaced; unavailable or non-JSON backends produce tool errors.

NameTypeReqDescription
modestring––

No output schema declared.

No examples provided.

wever_unified-agent-checkout ~229

Paid URL: 0.10 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Read the backend 402 body for x402 terms. Itemize and total caller-supplied USD estimates for supported computations. This is not a provider quote, checkout session, payment request or authority grant. Operating boundary: Direct access uses x402 Base USDC settlement or the verified-wallet free tier. The prepared computation uses caller-supplied data and creates no execution authority, proof verification, delivery or provider action. Payment access records are durable; existing credentials and signed grants remain required for separate consequential actions. POST /api/unified-agent-checkout. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This current operation is a bounded computation on caller-supplied data.

NameTypeReqDescription
agent_idstringyes–
allowance_reference–yes–
currency–yes–
itemsarrayyes–
mode–yes–
payment_reference–yes–

No output schema declared.

No examples provided.

wever_x402-payment-gateway ~234

Paid URL: 0.10 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Read the backend 402 body for x402 terms. Verifies an EOA payment signature and observes Base USDC nonce, balance and chain time. Does not simulate, submit, settle, reserve or authorize resource access. Operating boundary: Direct access uses x402 Base USDC settlement or the verified-wallet free tier. Verifies an EOA payment signature and observes Base USDC nonce, balance and chain time. Does not simulate, submit, settle, reserve or authorize resource access. The API access fee is separate from any inspected payment or recorded invoice amount. POST /api/x402-payment-gateway. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This current money service follows its published inspection, policy evaluation or private invoice contract. Payment is an API access fee and grants no spending authority.

NameTypeReqDescription
mode–yes–
paymentobjectyes–
target_product–yes–

No output schema declared.

No examples provided.

Common questions

What is the Wever Labs Agent Products MCP server?

Wever Labs Agent Products is an MCP server listed in the public MCP registry as io.github.CodeWever/wever-labs-products. Agent commerce: 27 tools, 10 production services, signed authority, planning, Base USDC x402. This page covers its hosted endpoint (https://weverlabs.com/mcp).

Is the Wever Labs Agent Products MCP server safe to use?

Wever Labs Agent Products scores 59 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Wever Labs Agent Products MCP server expose?

Wever Labs Agent Products exposes 27 tools: wever_delegated-authority, wever_agent-paid-workflow, wever_unified-agent-checkout, wever_diligenceops-paid-run, wever_receipt-passport, and 22 more. Their descriptions and schemas cost roughly 6,301 tokens of context every time the server is loaded.

Does the Wever Labs Agent Products MCP server require authentication?

No. We connected to Wever Labs Agent Products without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the Wever Labs Agent Products MCP server still maintained?

Wever Labs Agent Products is still listed as active in the MCP registry. We last reached this channel on 1 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.