com.jpyc-service/ec-storefront
REMOTE · EC.JPYC-SERVICE.COM · SCANNED AUG 3
JPYC (JPY stablecoin) EC platform MCP: product search, x402 gasless checkout, order status.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 8 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability71
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1125 tokens (~140/item across 8 items; 8 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
- Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · ec.jpyc-service.com
claude mcp add --transport http com-jpyc-service-ec-storefront https://ec.jpyc-service.com/mcp
[mcp_servers.com-jpyc-service-ec-storefront] url = "https://ec.jpyc-service.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-jpyc-service-ec-storefront": {
"type": "remote",
"url": "https://ec.jpyc-service.com/mcp",
"enabled": true
}
}
} openclaw mcp add com-jpyc-service-ec-storefront --url https://ec.jpyc-service.com/mcp --transport streamable-http
mcp_servers:
com-jpyc-service-ec-storefront:
url: "https://ec.jpyc-service.com/mcp" {
"mcpServers": {
"com-jpyc-service-ec-storefront": {
"type": "http",
"url": "https://ec.jpyc-service.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 2 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.
- 31 Jul 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 29 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.
- 28 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 64
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://ec.jpyc-service.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=ec.jpyc-service.com | CN=YR1,O=Let's Encrypt,C=US | 13 Jul 2026 | 11 Oct 2026 | RSA 2048 | SHA256-RSA | 52d9b2da3f5717a3a21cd5b6750e3c4ec4c |
| SANs: ec.jpyc-service.com | ||||||
| CN=YR1,O=Let's Encrypt,C=US (CA) | CN=Root YR,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | RSA 2048 | SHA256-RSA | a20253f15f2691c05dc1ce13b9bcca4e |
| CN=Root YR,O=ISRG,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | RSA 4096 | SHA256-RSA | f24b6d17f9d9ad7cb1c9fea78782699f |
DNSSEC insecure
Validation of ec.jpyc-service.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| jpyc-service.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains |
| content-security-policy | default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' 'wasm-unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob: https:; font-src 'self' data:; connect-src 'self' https: wss:; frame-src 'self' https:; worker-src 'self' blob:; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'self' |
| x-content-type-options | nosniff |
| x-frame-options | SAMEORIGIN |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(), geolocation=() |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://ec.jpyc-service.com/mcp | Verified | 200 | |
| http (plaintext) | http://ec.jpyc-service.com/mcp | HTTPS enforced | 308 | https://ec.jpyc-service.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
get_order_status 注文状況の確認 ~77
ウォレットアドレスの注文履歴を新しい順で返す。x402 で購入した注文は即時に order_status=3(決済完了)となり tx_hash を持つ。
| Name | Type | Req | Description |
|---|---|---|---|
| customer_address | string | yes | 顧客のウォレットアドレス(0x...) |
No output schema declared.
No examples provided.
get_product 商品詳細 ~99
1 つの商品の詳細を product_id で取得する。価格(JPYC 建て)・在庫・SKU・バリエーション・配送要否・対応チェーンを返す。購入の前に必ず呼んで、requires_shipping(配送先が必要か)と has_variants(オプション選択が必要か)を確認すること。
| Name | Type | Req | Description |
|---|---|---|---|
| product_id | string | yes | 商品 ID |
No output schema declared.
No examples provided.
get_shop ショップ詳細 ~80
1 つのショップ(生産者・職人)の詳細を slug で取得する。ショップのストーリーや説明、対応ブロックチェーン、x402 決済が有効かどうかを返す。
| Name | Type | Req | Description |
|---|---|---|---|
| shop_slug | string | yes | ショップの slug(URL 識別子) |
No output schema declared.
No examples provided.
list_products_in_shop ショップの商品一覧 ~89
1 つのショップの公開中の商品をすべて返す。価格(JPYC 建て)・在庫・バリエーション・配送要否・対応チェーンを含む。list_shops でショップを見つけたあと、その品揃えを見るのに使う。
| Name | Type | Req | Description |
|---|---|---|---|
| shop_slug | string | yes | ショップの slug |
No output schema declared.
No examples provided.
list_shops ショップ一覧 ~94
JPYC EC Platform に出店している公開ショップの一覧を返す。減農薬の農産物・地酒・伝統工芸品など、生産者から直接買えるショップが中心。各ショップの name / slug / 説明 / 対応チェーン / 商品点数を含む。商品を探す起点として最初に呼ぶとよい。
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
quote_checkout チェックアウト見積もり(x402 1回目) ~301
カートの内容で x402 チェックアウトの 1 回目を実行する。在庫を 5 分間仮押さえし、小計・割引・送料・合計(JPYC)と reservation_id、および署名対象の x402 PAYMENT-REQUIRED チャレンジ(base64url)を返す。エージェントはこのチャレンジを自分のウォレットで EIP-3009 TransferWithAuthorization 署名し、submit_payment に渡す。全 item は同一ショップである必要がある。配送が必要な商品があれば shipping を、贈答なら gift_recipient を必ず渡すこと。
| Name | Type | Req | Description |
|---|---|---|---|
| customer_email | string | yes | 注文確認メールの送信先(必須) |
| customer_note | string | — | 注文メモ |
| gift_recipient | object | — | 贈り先(is_gift が true なら必須) |
| is_gift | boolean | — | 贈答かどうか |
| items | array | yes | 購入する商品 |
| preferred_chain_id | integer | — | 希望チェーン(任意。商品の対応チェーンから選ばれる) |
| shipping | object | — | 配送先(配送が必要な商品がある場合は必須) |
| shop_id | string | yes | ショップ ID(全 item 共通) |
No output schema declared.
No examples provided.
search_products 商品検索 ~246
JPYC EC Platform 上の公開商品を横断検索する。減農薬米・地酒・伝統工芸品など、生産者から直接 JPYC で購入できる商品が対象。text は自然言語のキーワード(例: 『丹波 米』)で、商品名と説明に部分一致する。category / tag(産地・認証種別など)、価格帯(min_price / max_price、JPYC)、shop_slug で絞り込める。売上順で最大 50 件返す。
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | — | 商品カテゴリーの完全一致 |
| limit | integer | — | 最大件数(1-50、既定 20) |
| max_price | number | — | 最高価格(JPYC) |
| min_price | number | — | 最低価格(JPYC) |
| shop_slug | string | — | 特定ショップに絞り込む |
| tag | string | — | 商品タグ(産地・認証種別など)の完全一致 |
| text | string | — | 自然言語のキーワード(商品名・説明に部分一致) |
No output schema declared.
No examples provided.
submit_payment 決済の確定(x402 2回目) ~139
quote_checkout で得た reservation_id と、エージェントが署名した x402 PaymentPayload(base64url)を渡して決済を確定する。サーバは facilitator 経由で on-chain settle し、確定した注文(order_number / tx_hash)を返す。署名は quote_checkout が返した payment_required の 内容に対する EIP-3009 TransferWithAuthorization であること。
| Name | Type | Req | Description |
|---|---|---|---|
| payment_signature | string | yes | 署名済み x402 PaymentPayload(base64url JSON) |
| reservation_id | string | yes | quote_checkout が返した reservation_id |
No output schema declared.
No examples provided.