# Wever Labs Agent Products (remote · weverlabs.com)

Agent commerce: 27 tools, 10 production services, signed authority, planning, Base USDC x402.

- Trust score: 59/100 (low)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-01

## Components

- remote · `weverlabs.com`: 59/100 (this document), [markdown](https://verifymcp.io/servers/codewever-wever-labs-products/weverlabs.md), [page](https://verifymcp.io/servers/codewever-wever-labs-products/weverlabs)

## Channel facts

- Endpoint: `https://weverlabs.com/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `0.4.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-01.

- **Endpoint Security**: 63/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (wever_delegated-authority).
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 49/100
  - AI-judged instruction clarity (good).
  - Context-footprint check failed: tool/resource definitions use about 6384 tokens (~236/item across 27 items; 27 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 0/100
  - Stability check failed: schema churn in the 2 days we've observed: 0 tool removals, 6 breaking changes, 0 auth/transport breaks, 0 additions.
- **Tool Coverage**: 68/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 3% of tool parameters carry a description.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 27 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 28 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### How do I install the Wever Labs Agent Products MCP server?

Wever Labs Agent Products is a hosted endpoint at https://weverlabs.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http codewever-wever-labs-products 'https://weverlabs.com/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "codewever-wever-labs-products": {
      "url": "https://weverlabs.com/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "codewever-wever-labs-products": {
      "type": "http",
      "url": "https://weverlabs.com/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.codewever-wever-labs-products]
url = "https://weverlabs.com/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "codewever-wever-labs-products": {
      "type": "remote",
      "url": "https://weverlabs.com/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add codewever-wever-labs-products --url 'https://weverlabs.com/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  codewever-wever-labs-products:
    url: "https://weverlabs.com/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "codewever-wever-labs-products": {
      "Transport": "http",
      "Url": "https://weverlabs.com/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add codewever-wever-labs-products -t streamable-http -u 'https://weverlabs.com/mcp'
```

### Other

```json
{
  "mcpServers": {
    "codewever-wever-labs-products": {
      "type": "http",
      "url": "https://weverlabs.com/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-10-01 (score 59, 0)

- [security] The server rewrote its instructions, which are the text every model session reads
- [security] Tool “wever_ap2-mandate-gateway” rewrote its description, which is the text the model reads
- [security] Tool “wever_delegated-authority” rewrote its description, which is the text the model reads
- [functional regression] “wever_ap2-mandate-gateway” added a required parameter “challenge_token”, so existing callers break
- [functional regression] “wever_ap2-mandate-gateway” added a required parameter “presentation”, so existing callers break
- [functional regression] “wever_ap2-mandate-gateway” made “mode” required, so existing callers break
- [functional] Server version: 0.7.0 → 0.8.0

### 2026-09-30 (score 59, −1)

- [security regression] Stability: unverified → fail
- [security] The server rewrote its instructions, which are the text every model session reads
- [security] Tool “wever_agent-allowance-console” rewrote its description, which is the text the model reads
- [security] Tool “wever_agent-budget-guard” rewrote its description, which is the text the model reads
- [security] Tool “wever_agent-daily-operator-brief” rewrote its description, which is the text the model reads
- [security] Tool “wever_agent-escrow-lite” rewrote its description, which is the text the model reads
- [security] Tool “wever_agent-invoice-rail” rewrote its description, which is the text the model reads
- [security] Tool “wever_agent-paid-workflow” rewrote its description, which is the text the model reads
- [security] Tool “wever_agent-work-order-exchange” rewrote its description, which is the text the model reads
- [security] Tool “wever_agent-work-order-rail” rewrote its description, which is the text the model reads
- [security] Tool “wever_delegated-authority” rewrote its description, which is the text the model reads
- [security] Tool “wever_diligenceops-paid-run” rewrote its description, which is the text the model reads
- [security] Tool “wever_mcp-diligence-rail” rewrote its description, which is the text the model reads
- [security] Tool “wever_payment-authority-inspector” rewrote its description, which is the text the model reads
- [security] Tool “wever_proof-relay” rewrote its description, which is the text the model reads
- [security] Tool “wever_unified-agent-checkout” rewrote its description, which is the text the model reads
- [security] Tool “wever_x402-payment-gateway” rewrote its description, which is the text the model reads
- [security] Tool “wever_agent-budget-guard” no longer declares itself destructive
- [security] Tool “wever_payment-authority-inspector” no longer declares itself destructive
- [security] Tool “wever_x402-payment-gateway” no longer declares itself destructive
- [functional regression] Schema quality: 197 → 230
- [functional regression] “wever_agent-budget-guard” added a required parameter “agent_id”, so existing callers break
- [functional regression] “wever_agent-budget-guard” added a required parameter “policy”, so existing callers break
- [functional regression] “wever_agent-budget-guard” added a required parameter “request”, so existing callers break
- [functional regression] “wever_agent-budget-guard” added a required parameter “usage”, so existing callers break
- [functional regression] “wever_agent-invoice-rail” added a required parameter “schema_version”, so existing callers break
- [functional regression] “wever_payment-authority-inspector” added a required parameter “amount_atomic”, so existing callers break
- [functional regression] “wever_payment-authority-inspector” added a required parameter “authorization_nonce”, so existing callers break
- [functional regression] “wever_payment-authority-inspector” added a required parameter “min_confirmations”, so existing callers break
- [functional regression] “wever_payment-authority-inspector” added a required parameter “payee”, so existing callers break
- [functional regression] “wever_payment-authority-inspector” added a required parameter “payer”, so existing callers break
- [functional regression] “wever_payment-authority-inspector” added a required parameter “transaction_hash”, so existing callers break
- [functional regression] “wever_x402-payment-gateway” added a required parameter “payment”, so existing callers break
- [functional regression] “wever_x402-payment-gateway” added a required parameter “target_product”, so existing callers break
- [functional regression] “wever_agent-budget-guard” made “mode” required, so existing callers break
- [functional regression] “wever_agent-escrow-lite” made “mode” required, so existing callers break
- [functional regression] “wever_agent-invoice-rail” made “mode” required, so existing callers break
- [functional regression] “wever_payment-authority-inspector” made “mode” required, so existing callers break
- [functional regression] “wever_x402-payment-gateway” made “mode” required, so existing callers break
- [functional] Server version: 0.4.0 → 0.7.0
- [cosmetic] “wever_agent-escrow-lite” added an optional parameter “escrow_id”
- [cosmetic] “wever_agent-escrow-lite” added an optional parameter “funding_payment”
- [cosmetic] “wever_agent-escrow-lite” added an optional parameter “idempotency_key”
- [cosmetic] “wever_agent-escrow-lite” added an optional parameter “mandate”
- [cosmetic] “wever_agent-escrow-lite” added an optional parameter “payer_terms_signature”
- [cosmetic] “wever_agent-escrow-lite” added an optional parameter “terms”
- [cosmetic] “wever_agent-invoice-rail” added an optional parameter “amount_atomic”
- [cosmetic] “wever_agent-invoice-rail” added an optional parameter “buyer_reference”
- [cosmetic] “wever_agent-invoice-rail” added an optional parameter “buyer_wallet”
- [cosmetic] “wever_agent-invoice-rail” added an optional parameter “decision”
- [cosmetic] “wever_agent-invoice-rail” added an optional parameter “description”
- [cosmetic] “wever_agent-invoice-rail” added an optional parameter “expected_version”
- [cosmetic] “wever_agent-invoice-rail” added an optional parameter “expires_at”
- [cosmetic] “wever_agent-invoice-rail” added an optional parameter “idempotency_key”
- [cosmetic] “wever_agent-invoice-rail” added an optional parameter “invoice_id”
- [cosmetic] “wever_agent-invoice-rail” added an optional parameter “note”
- [cosmetic] “wever_agent-invoice-rail” added an optional parameter “rail_key”
- [cosmetic] “wever_agent-invoice-rail” added an optional parameter “run_binding”
- [cosmetic] “wever_agent-invoice-rail” added an optional parameter “usage”

### 2026-09-29 (score 60)

First indexed and scored.

## MCP tools (27)

### `wever_delegated-authority` (~480 tokens)

Wever Labs Delegated Authority

Paid URL: 2.00 USDC per mandate on Base; 10 signed-wallet free calls shared over rolling 30 days. Only issue_mandate is billed; GET, contract reads, drafts and all other modes have no x402 fee. Credentials and grants remain required for their existing operations. Read the backend 402 body for x402 terms. Issue signed mandates and operator-approved action grants, then let credentialed agents consume them to create immutable work-order records. Records do not perform work, deliver results or authorize payment.
Operating boundary: Operators issue mandates and approve each exact action grant with an issuance idempotency key. Only the bound credentialed agent may consume a grant; each action grant atomically reserves one nonfinancial work_order unit. Usage and attribution are credential-bound. Signed authority permits only immutable record creation, never work execution, delivery or payment. Public drafts remain unsigned_dev and cannot execute. The access fee applies only to issue_mandate and never authorizes downstream spending. GET, contract reads, drafts and all other authority modes have no x402 fee; their existing credential checks remain.
POST /api/delegated-authority. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This current operation is a credentialed authority control plane for immutable work-order record creation. It does not execute the recorded work, deliver results, or authorize payment. Operator issuance and grant approval require X-Wever-Operator-Key and Idempotency-Key; consumption requires the target agent's X-Wever-Agent-Key. Usage and attribution come from validated credentials and durable authority records. AP2 issuance also accepts issue_mandate with mandate.profile com.weverlabs.ap2.direct-checkout.1, the holder public key, signed checkout challenge, consent digest and bounded expiry. It requires a dedicated AP2 i…

Input parameters:

- `mode` (required)

### `wever_agent-paid-workflow` (~221 tokens)

Agent Workflow

Paid URL: 0.10 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Read the backend 402 body for x402 terms. Prepare an ordered sequence of supported planning and computation steps with explicit required fields. No step is executed, no quote obtained, and no payment, authority or delivery is performed.
Operating boundary: Direct access uses x402 Base USDC settlement or the verified-wallet free tier. The prepared computation uses caller-supplied data and creates no execution authority, proof verification, delivery or provider action. Payment access records are durable; existing credentials and signed grants remain required for separate consequential actions.
POST /api/agent-paid-workflow. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This current operation is a bounded computation on caller-supplied data.

Input parameters:

- `agent_id` (string, required)
- `constraints` (object, required)
- `mode` (required)
- `product_key` (required)

### `wever_unified-agent-checkout` (~229 tokens)

Unified Agent Checkout

Paid URL: 0.10 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Read the backend 402 body for x402 terms. Itemize and total caller-supplied USD estimates for supported computations. This is not a provider quote, checkout session, payment request or authority grant.
Operating boundary: Direct access uses x402 Base USDC settlement or the verified-wallet free tier. The prepared computation uses caller-supplied data and creates no execution authority, proof verification, delivery or provider action. Payment access records are durable; existing credentials and signed grants remain required for separate consequential actions.
POST /api/unified-agent-checkout. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This current operation is a bounded computation on caller-supplied data.

Input parameters:

- `agent_id` (string, required)
- `allowance_reference` (required)
- `currency` (required)
- `items` (array, required)
- `mode` (required)
- `payment_reference` (required)

### `wever_diligenceops-paid-run` (~208 tokens)

DiligenceOps Run

Paid URL: 1.00 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Free computation: /api/mcp or /api/service-resolver. Read the backend 402 body for x402 terms. Compare explicit submitted evidence labels and return exact matched and missing items. This does not read or verify document contents.
Operating boundary: The computation uses supplied data only and performs no provider work, callbacks, document retrieval or signed attestations. Direct access uses x402 Base USDC settlement or the verified-wallet free tier; the Labs MCP and resolver computation paths remain free.
POST /api/diligenceops-paid-run. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This current operation is a bounded computation on caller-supplied data.

Input parameters:

- `available_evidence` (array, required)
- `expected_evidence` (array, required)

### `wever_receipt-passport` (~202 tokens)

Receipt Passport

Unavailable historical backend. Sandbox/demo: builds a receipt-passport envelope from supplied fields and a locally generated sample run. It does not retrieve or verify completed work or supplied proof. Generated receipt, verification and handoff fields are not evidence of production execution.
Create a short, portable proof object for a completed rail run. Agents use it to verify receipt state without carrying the full run payload.
Operating boundary: Creates a portable proof passport for a paid or authority-bound rail run. Use it after a completed run to verify receipt, return package, callback, and transcript linkage.
POST /api/receipt-passport. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This is a catalog proxy entry, not a guarantee of backend availability. Backend status and JSON errors are surfaced; unavailable or non-JSON backends produce tool errors.

Input parameters:

- `mode` (string)

### `wever_return-package-viewer` (~187 tokens)

Return Package Viewer

Unavailable historical backend. Sandbox/demo: renders a generated example return package and receipt status using supplied or generated identifiers. It does not retrieve a stored package or establish that work completed.
Read a rail return package in a clean shape. Agents get JSON. Humans get the same facts in a page that shows what was checked, what is missing, and what proof was issued.
Operating boundary: Reads completed return packages and presents the same proof facts to agents and humans without changing the source rail output.
POST /api/return-package-viewer. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This is a catalog proxy entry, not a guarantee of backend availability. Backend status and JSON errors are surfaced; unavailable or non-JSON backends produce tool errors.

Input parameters:

- `mode` (string)

### `wever_agent-allowance-console` (~303 tokens)

Agent Allowance Console

Paid URL: 0.10 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Read the backend 402 body for x402 terms. Evaluate explicit caller-reported scope, budget, usage, expiry and per-action fee limits. Returns a would-allow or would-deny preview; creates no authority and verifies no account balance.
Operating boundary: Direct access uses x402 Base USDC settlement or the verified-wallet free tier. The prepared computation uses caller-supplied data and creates no execution authority, proof verification, delivery or provider action. Payment access records are durable; existing credentials and signed grants remain required for separate consequential actions.
POST /api/agent-allowance-console. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This current operation is a bounded computation on caller-supplied data.

Input parameters:

- `agent_id` (string, required)
- `allowed_product_keys` (array, required)
- `as_of` (string, required)
- `budget_minor` (integer, required)
- `currency` (required)
- `expires_at` (string, required)
- `max_fee_minor` (integer, required)
- `max_runs` (integer, required)
- `mode` (required)
- `requested_fee_minor` (integer, required)
- `requested_product_key` (string, required)
- `spent_minor` (integer, required)
- `used_runs` (integer, required)

### `wever_callback-health-monitor` (~174 tokens)

Callback Health Monitor

Unavailable historical backend. Sandbox/demo: checks whether a callback URL starts with HTTPS and returns an example health response. It does not contact the receiver or verify an acknowledgment, availability or delivery.
Check whether a callback receiver is alive, accepts proof payloads, and returns an acknowledgment shape an agent can trust.
Operating boundary: Validates callback receivers before paid work is delivered so proof can be sent, acknowledged, retried, and audited.
POST /api/callback-health-monitor. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This is a catalog proxy entry, not a guarantee of backend availability. Backend status and JSON errors are surfaced; unavailable or non-JSON backends produce tool errors.

Input parameters:

- `mode` (string)

### `wever_agent-work-order-exchange` (~233 tokens)

Agent Work Order Exchange

Paid URL: 0.10 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Read the backend 402 body for x402 terms. Validate a task against a supported computation and prepare its fixed POST request. Semantic validation uses a local deterministic dry run. No request is submitted, worker assigned or result delivered.
Operating boundary: Direct access uses x402 Base USDC settlement or the verified-wallet free tier. The prepared computation uses caller-supplied data and creates no execution authority, proof verification, delivery or provider action. Payment access records are durable; existing credentials and signed grants remain required for separate consequential actions.
POST /api/agent-work-order-exchange. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This current operation is a bounded computation on caller-supplied data.

Input parameters:

- `mode` (required)
- `product_key` (required)
- `requested_outcome` (string, required)
- `requesting_agent_id` (string, required)
- `task` (object, required)

### `wever_agent-budget-guard` (~269 tokens)

Agent Budget Guard

Paid URL: 0.10 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Read the backend 402 body for x402 terms. Evaluates caller-supplied policy, usage and request values only. No live allowance or balance is read, no destination is contacted, no budget or run is reserved, and no permission or execution authority is granted.
Operating boundary: Direct access uses x402 Base USDC settlement or the verified-wallet free tier. Evaluates caller-supplied policy, usage and request values only. No live allowance or balance is read, no destination is contacted, no budget or run is reserved, and no permission or execution authority is granted. The API access fee is separate from any inspected payment or recorded invoice amount.
POST /api/agent-budget-guard. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This current money service follows its published inspection, policy evaluation or private invoice contract. Payment is an API access fee and grants no spending authority.

Input parameters:

- `agent_id` (string, required)
- `mode` (required)
- `policy` (object, required)
- `request` (object, required)
- `usage` (object, required)

### `wever_agent-sla-rail` (~182 tokens)

Agent SLA Rail

Unavailable historical backend. Sandbox/demo: prepares an SLA policy template from supplied values or defaults. It does not record an agreement, monitor a service, schedule retries or enforce a response deadline.
Create an operational promise around a rail run: response expectation, callback requirement, retry count, proof requirements, and failure behavior.
Operating boundary: Records the operating terms for a rail run: response expectation, retry count, callback requirement, proof requirements, and failure behavior.
POST /api/agent-sla-rail. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This is a catalog proxy entry, not a guarantee of backend availability. Backend status and JSON errors are surfaced; unavailable or non-JSON backends produce tool errors.

Input parameters:

- `mode` (string)

### `wever_agent-trust-scorecard` (~190 tokens)

Agent Trust Scorecard

Unavailable historical backend. Sandbox/demo: returns supplied or default example statistics and calculates a sample callback rate. It does not read operational records or verify reputation. Default counts and generated last-seen timestamps are not observations of agent activity.
Show proof-based trust signals for an agent or provider: completed runs, verified receipts, callback success, denied attempts, supported rails, and last seen.
Operating boundary: Returns operational trust signals from proof events so agents can choose counterparties with facts, not profile claims.
POST /api/agent-trust-scorecard. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This is a catalog proxy entry, not a guarantee of backend availability. Backend status and JSON errors are surfaced; unavailable or non-JSON backends produce tool errors.

Input parameters:

- `mode` (string)

### `wever_payment-authority-inspector` (~257 tokens)

Payment Authority Inspector

Paid URL: 0.10 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Read the backend 402 body for x402 terms. Read-only canonical Base USDC receipt inspection for the configured Wever recipient. Settlement evidence grants no mandate, resource permission or execution authority.
Operating boundary: Direct access uses x402 Base USDC settlement or the verified-wallet free tier. Read-only canonical Base USDC receipt inspection for the configured Wever recipient. Settlement evidence grants no mandate, resource permission or execution authority. The API access fee is separate from any inspected payment or recorded invoice amount.
POST /api/payment-authority-inspector. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This current money service follows its published inspection, policy evaluation or private invoice contract. Payment is an API access fee and grants no spending authority.

Input parameters:

- `amount_atomic` (string, required)
- `authorization_nonce` (string, required)
- `min_confirmations` (integer, required)
- `mode` (required)
- `payee` (string, required)
- `payer` (string, required)
- `transaction_hash` (string, required)

### `wever_x402-payment-gateway` (~234 tokens)

x402 Payment Gateway

Paid URL: 0.10 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Read the backend 402 body for x402 terms. Verifies an EOA payment signature and observes Base USDC nonce, balance and chain time. Does not simulate, submit, settle, reserve or authorize resource access.
Operating boundary: Direct access uses x402 Base USDC settlement or the verified-wallet free tier. Verifies an EOA payment signature and observes Base USDC nonce, balance and chain time. Does not simulate, submit, settle, reserve or authorize resource access. The API access fee is separate from any inspected payment or recorded invoice amount.
POST /api/x402-payment-gateway. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This current money service follows its published inspection, policy evaluation or private invoice contract. Payment is an API access fee and grants no spending authority.

Input parameters:

- `mode` (required)
- `payment` (object, required)
- `target_product` (required)

### `wever_ap2-mandate-gateway` (~239 tokens)

AP2 Mandate Gateway

Paid URL: 0.10 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Read the backend 402 body for x402 terms. Verifies allowlisted AP2 direct closed-checkout mandates, binds the presenter to the holder wallet, rejects expiry and replay, and durably consumes each mandate once.
Operating boundary: Wever trusted-provider direct closed-checkout profile only. No open mandates, delegation chains, checkout execution, payment execution or fund transfers. Signed wallet proof is required even for paid calls.
POST /api/ap2-mandate-gateway. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This gateway verifies only its published AP2 direct closed-checkout profile, requires a trusted issuer and holder wallet proof, and consumes the mandate once. It does not execute the checkout or transfer funds. Start at /api/ap2-contract and /api/ap2-challenge.

Input parameters:

- `challenge_token` (string, required)
- `mode` (required)
- `presentation` (string, required)

### `wever_agent-to-agent-handoff-pack` (~199 tokens)

Agent-to-Agent Handoff Pack

Unavailable historical backend. Sandbox/demo: assembles a handoff envelope and hash from supplied data, with sample package and receipt identifiers when omitted. It does not verify the referenced proof, deliver the handoff or authorize the receiving agent.
Package completed work so another agent can pick it up: task summary, return package, exception object, receipt passport, callback target, and next action.
Operating boundary: Packages completed paid work for another agent to continue, including proof, receipt passport, callback target, exception state, and next action.
POST /api/agent-to-agent-handoff-pack. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This is a catalog proxy entry, not a guarantee of backend availability. Backend status and JSON errors are surfaced; unavailable or non-JSON backends produce tool errors.

Input parameters:

- `mode` (string)

### `wever_proof-inbox` (~182 tokens)

Proof Inbox

Unavailable historical backend. Sandbox/demo: generates five example proof-event categories with new identifiers and timestamps. It does not read or write an inbox. Its completed, recorded and acknowledged states are sample events, not operational evidence.
Read a single view of completed runs, receipts, callback events, exceptions, handoffs, and status events.
Operating boundary: Shows proof events from live agent work: completed runs, receipts, callbacks, exceptions, handoffs, and directory status events.
POST /api/proof-inbox. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This is a catalog proxy entry, not a guarantee of backend availability. Backend status and JSON errors are surfaced; unavailable or non-JSON backends produce tool errors.

Input parameters:

- `mode` (string)

### `wever_rail-playground` (~182 tokens)

Rail Playground

Unavailable historical backend. Sandbox/demo: generates an example rail package, receipt and transcript locally. No external rail work runs. Its passed state and repeatability score describe generated sample output and are not measured production results.
Test PacketOps and DiligenceOps with sample data, then start a agent run with the same rail shape.
Operating boundary: Lets agents test rail shape with sample data, then move directly into paid PacketOps or DiligenceOps runs when ready.
POST /api/rail-playground. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This is a catalog proxy entry, not a guarantee of backend availability. Backend status and JSON errors are surfaced; unavailable or non-JSON backends produce tool errors.

Input parameters:

- `mode` (string)

### `wever_agent-escrow-lite` (~327 tokens)

Agent Escrow Lite

Paid URL: 0.10 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Read the backend 402 body for x402 terms. Escrow principal and API-fee wallet: 0x69255FeaC86268C0D0bD0CBd128da7B9aB44b1c4. Principal funding is separate, and every call requires a signed wallet ownership proof. Managed Base USDC custody with verified funding, immutable parties, EIP-712 release policies, expiry refunds to the payer and a durable public release log.
Operating boundary: The separate custody wallet accepts bounded USDC principal. A verified release pays only the immutable payee; an expiry refund pays only the immutable payer. API fees are separate, manual sweeps are required, and work-order grants are not payment authority.
POST /api/agent-escrow-lite. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This managed custody service uses immutable escrow parties and EIP-712 release policies. Releases pay only the payee; expiry refunds pay only the payer. Public logs report durable state and transaction evidence. Work-order grants do not authorize payment.

Input parameters:

- `escrow_id` (string)
- `funding_payment`
- `idempotency_key` (string)
- `mandate` (object)
- `mode` (required)
- `payer_terms_signature` (string)
- `terms` (object)

### `wever_agent-invoice-rail` (~346 tokens)

Agent Invoice Rail

Paid URL: 0.10 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Read the backend 402 body for x402 terms. Private issuer-wallet invoice ledger, immutable face amount and parties, run-reference binding and recorded issuer review. References are not independently verified. No bill delivery, payment collection or spending authority.
Operating boundary: Direct access uses x402 Base USDC settlement or the verified-wallet free tier. Private issuer-wallet invoice ledger, immutable face amount and parties, run-reference binding and recorded issuer review. References are not independently verified. No bill delivery, payment collection or spending authority. Every invoice operation also requires a signed issuer-wallet ownership proof. The API access fee is separate from any inspected payment or recorded invoice amount.
POST /api/agent-invoice-rail. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This current money service follows its published inspection, policy evaluation or private invoice contract. Payment is an API access fee and grants no spending authority.

Input parameters:

- `amount_atomic` (string)
- `buyer_reference` (string)
- `buyer_wallet` (string)
- `decision`
- `description` (string)
- `expected_version` (integer)
- `expires_at` (integer)
- `idempotency_key` (string)
- `invoice_id` (string)
- `mode` (string, required)
- `note` (string)
- `rail_key` (string)
- `run_binding` (object)
- `schema_version` (required)
- `usage`

### `wever_agent-permission-ledger` (~183 tokens)

Agent Permission Ledger

Unavailable historical backend. Sandbox/demo: previews a permission decision using caller-supplied allowed actions and a fixed list of consequential actions. It does not authenticate a principal, read a ledger, persist permissions or grant execution authority.
Track what an agent is allowed to do, what requires approval, what changed, and what must be denied before action.
Operating boundary: Records and evaluates bounded agent permissions. It returns service shape and decision objects without exposing private operator rows.
POST /api/agent-permission-ledger. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This is a catalog proxy entry, not a guarantee of backend availability. Backend status and JSON errors are surfaced; unavailable or non-JSON backends produce tool errors.

Input parameters:

- `mode` (string)

### `wever_agent-work-order-rail` (~223 tokens)

Agent Work Order Rail

Paid URL: 0.10 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Free computation: /api/mcp or /api/service-resolver. Read the backend 402 body for x402 terms. Prepare a validated DiligenceOps task for a specific Connect recipient. Submission, recipient permission and execution remain separate steps.
Operating boundary: The computation uses supplied data only and performs no provider work, callbacks, document retrieval or signed attestations. Direct access uses x402 Base USDC settlement or the verified-wallet free tier; the Labs MCP and resolver computation paths remain free.
POST /api/agent-work-order-rail. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This current operation is a bounded computation on caller-supplied data.

Input parameters:

- `available_evidence` (array, required)
- `expected_evidence` (array, required)
- `recipient_id` (string, required)
- `service_id` (required)

### `wever_agent-decision-packet-rail` (~188 tokens)

Agent Decision Packet Rail

Unavailable historical backend. Sandbox/demo: builds a decision-packet template with fixed rationale and ranks options in submitted order, recommending the first option. It does not evaluate the supplied constraints or establish which option is best.
Turn messy options into a decision packet with pros, cons, risks, unknowns, constraints, recommendation, and human decision point.
Operating boundary: Prepares decisions for review. It does not make binding decisions, approve spending, or take final action.
POST /api/agent-decision-packet-rail. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This is a catalog proxy entry, not a guarantee of backend availability. Backend status and JSON errors are surfaced; unavailable or non-JSON backends produce tool errors.

Input parameters:

- `mode` (string)

### `wever_agent-file-desk-rail` (~190 tokens)

Agent File Desk Rail

Unavailable historical backend. Sandbox/demo: classifies supplied filenames using invoice and contract substrings and flags names containing copy. This bounded filename heuristic does not inspect file contents, verify duplicate content, move or delete files, or perform the cleanup implied by its generated receipt identifier.
Classify files, extract document metadata, detect duplicates, suggest destinations, and create a cleanup review queue.
Operating boundary: Prepares file organization recommendations and review queues. Destructive moves or deletions require outside approval.
POST /api/agent-file-desk-rail. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This is a catalog proxy entry, not a guarantee of backend availability. Backend status and JSON errors are surfaced; unavailable or non-JSON backends produce tool errors.

Input parameters:

- `mode` (string)

### `wever_mcp-diligence-rail` (~200 tokens)

MCP Diligence Rail

Paid URL: 0.10 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Free computation: /api/mcp or /api/service-resolver. Read the backend 402 body for x402 terms. Inventory submitted MCP tool declarations and flag missing or consequential annotations. This does not connect to a server or grant authority.
Operating boundary: The computation uses supplied data only and performs no provider work, callbacks, document retrieval or signed attestations. Direct access uses x402 Base USDC settlement or the verified-wallet free tier; the Labs MCP and resolver computation paths remain free.
POST /api/mcp-diligence-rail. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This current operation is a bounded computation on caller-supplied data.

Input parameters:

- `tools` (array, required)

### `wever_agent-daily-operator-brief` (~248 tokens)

Agent Daily Operator Brief

Paid URL: 0.25 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Free computation: /api/mcp or /api/service-resolver. Read the backend 402 body for x402 terms. Summarize supplied service health and queue observations into deterministic priorities. No private records are fetched and no activity is invented.
Operating boundary: The computation uses supplied data only and performs no provider work, callbacks, document retrieval or signed attestations. Direct access uses x402 Base USDC settlement or the verified-wallet free tier; the Labs MCP and resolver computation paths remain free.
POST /api/agent-daily-operator-brief. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This current operation is a bounded computation on caller-supplied data.

Input parameters:

- `as_of` (string, required): A valid UTC calendar timestamp with whole seconds, supplied by the caller.
- `queues` (array, required): Unique queue names. Empty queues must have a null or zero oldest age.
- `services` (array, required): Unique service_id values.

### `wever_proof-relay` (~225 tokens)

Proof Relay

Paid URL: 0.10 USDC per call on Base; 10 signed-wallet free calls shared over rolling 30 days. Read the backend 402 body for x402 terms. Prepare a reference envelope and deterministic source/destination binding digest. References and supplied hashes remain unverified. No destination is contacted, no acknowledgment is obtained, and nothing is delivered or persisted.
Operating boundary: Direct access uses x402 Base USDC settlement or the verified-wallet free tier. The prepared computation uses caller-supplied data and creates no execution authority, proof verification, delivery or provider action. Payment access records are durable; existing credentials and signed grants remain required for separate consequential actions.
POST /api/proof-relay. Existing product credentials, signed mandates, and single-use action grants remain required where applicable. This adapter grants no authority and never supplies server credentials. This current operation is a bounded computation on caller-supplied data.

Input parameters:

- `destination` (required)
- `mode` (required)
- `proof_references` (array, required)
- `source_agent_id` (string, required)

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/codewever-wever-labs-products/weverlabs#diagnostics

## Score history

- 2026-10-01: 59
- 2026-09-30: 59
- 2026-09-29: 60

## Common questions

### What is the Wever Labs Agent Products MCP server?

Wever Labs Agent Products is an MCP server listed in the public MCP registry as io.github.CodeWever/wever-labs-products. Agent commerce: 27 tools, 10 production services, signed authority, planning, Base USDC x402. This page covers its hosted endpoint (https://weverlabs.com/mcp).

### Is the Wever Labs Agent Products MCP server safe to use?

Wever Labs Agent Products scores 59 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Wever Labs Agent Products MCP server expose?

Wever Labs Agent Products exposes 27 tools: wever_delegated-authority, wever_agent-paid-workflow, wever_unified-agent-checkout, wever_diligenceops-paid-run, wever_receipt-passport, and 22 more. Their descriptions and schemas cost roughly 6,301 tokens of context every time the server is loaded.

### Does the Wever Labs Agent Products MCP server require authentication?

No. We connected to Wever Labs Agent Products without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the Wever Labs Agent Products MCP server still maintained?

Wever Labs Agent Products is still listed as active in the MCP registry. We last reached this channel on 1 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://weverlabs.com/mcp
- Repository: https://github.com/CodeWever/wever-labs-mcp-registry
- Website: https://weverlabs.com/
- Changelog RSS feed: https://verifymcp.io/servers/codewever-wever-labs-products/weverlabs.xml
- Changelog JSON feed: https://verifymcp.io/servers/codewever-wever-labs-products/weverlabs.json
- HTML version of this page: https://verifymcp.io/servers/codewever-wever-labs-products/weverlabs
