Ontario Protocol
REMOTE · ONTARIOPROTOCOL.COM · SCANNED AUG 3
Verify x402 endpoints before payment or publish service profiles for agent discovery.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security80
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability46
- AI-judged instruction clarity (fair).Partial
- Context-footprint check failed: tool/resource definitions use about 1710 tokens (~213/item across 8 items; 8 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management2
- Stability check failed: schema churn in the 8 days we've observed: 1 tool removals, 1 breaking changes, 0 auth/transport breaks, 3 additions. See how to fix → Fail
Tool Coverage83
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 40% of tool parameters carry a description.Partial
- Structured output schemas are declared (75% of tools); any adoption earns full credit.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · ontarioprotocol.com
claude mcp add --transport http com-ontarioprotocol-ontario-protocol https://ontarioprotocol.com/mcp
[mcp_servers.com-ontarioprotocol-ontario-protocol] url = "https://ontarioprotocol.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-ontarioprotocol-ontario-protocol": {
"type": "remote",
"url": "https://ontarioprotocol.com/mcp",
"enabled": true
}
}
} openclaw mcp add com-ontarioprotocol-ontario-protocol --url https://ontarioprotocol.com/mcp --transport streamable-http
mcp_servers:
com-ontarioprotocol-ontario-protocol:
url: "https://ontarioprotocol.com/mcp" {
"mcpServers": {
"com-ontarioprotocol-ontario-protocol": {
"type": "http",
"url": "https://ontarioprotocol.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 31 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.
- 28 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 27 Jul 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 62
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://ontarioprotocol.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=kamathventures.com | CN=WR3,O=Google Trust Services,C=US | 28 Jun 2026 | 26 Sept 2026 | RSA 2048 | SHA256-RSA | 4466b4f18bd459d50a380fc90ac6d1e5 |
| SANs: kamathventures.com, r4rfitness.impactwrap.com, eye4events.com.au, buffwindowreplacement.com, dragomanager.com, cotaremedio.com, artemisbi.com, prototype.turborad.com, teamlifting.com, links.stephenashurst.com, hundredthousandloaves.com, shadow.waw.pl and 88 more | ||||||
| CN=WR3,O=Google Trust Services,C=US (CA) | CN=GTS Root R1,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | RSA 2048 | SHA256-RSA | 7ff005a91568d63abc22861684aa4b5a |
| CN=GTS Root R1,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 19 Jun 2020 | 28 Jan 2028 | RSA 4096 | SHA256-RSA | 77bd0d6cdb36f91aea210fc4f058d30d |
| CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 1 Sept 1998 | 28 Jan 2028 | RSA 2048 | SHA1-RSA | 40000000001154b5ac394 |
DNSSEC insecure
Validation of ontarioprotocol.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| ontarioprotocol.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31556926 |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://ontarioprotocol.com/mcp | Verified | 200 | |
| http (plaintext) | http://ontarioprotocol.com/mcp | HTTPS enforced | 301 | https://ontarioprotocol.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
agent_can_pay Agent Payment Preflight ~59
Free pre-payment policy decision. Agents ask whether an x402 endpoint should be paid under strict, standard, or permissive policy.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_policy | string | — | — |
| endpoint | string | yes | — |
| max_usdc | string | — | — |
| Name | Type | Req | Description |
|---|---|---|---|
| decision | string | yes | — |
| decision_code | string | yes | — |
| decision_schema_version | string | yes | — |
| declared_price_usdc | number | — | — |
| endpoint | string | — | — |
| max_usdc | number | — | — |
| reasons | array | — | — |
| recommendations | array | — | — |
| report | object | — | — |
| report_integrity_ok | boolean | — | — |
| verification_age_hours | number | — | — |
No examples provided.
find_x402_tool Find a task-matched x402 tool ~206
Free buyer-side search across Ontario's fresh strict-ready paid profiles, Agentic Market, and Coinbase CDP Bazaar. Rank public, credential-free endpoint candidates by task relevance plus bounded source-reported recent activity, with optional Base/USDC budget filtering. Paid Ontario publication adds no ranking score. This is discovery, not a safety certification; run readiness and can-pay before spending. When the query is provider-side publication intent, skip buyer marketplace search and return the free listing validator followed by the gated 0.50 USDC publication workflow.
| Name | Type | Req | Description |
|---|---|---|---|
| active_only | boolean | — | When true, require recent source-reported activity or fresh strict-ready Ontario profile evidence. |
| limit | integer | — | — |
| max_usdc | string | — | Optional hard USDC price ceiling for returned candidates. |
| network | string | — | Optional network filter, for example eip155:8453 or base. |
| query | string | yes | Public task text only; never include credentials or private customer data. |
| Name | Type | Req | Description |
|---|---|---|---|
| agent_next_step | string | — | — |
| candidates | array | yes | — |
| count | integer | yes | — |
| intent | string | — | provider_publication when provider-side listing intent is routed to the free-first publication workflow. |
| provider_path | object | — | Machine-actionable free validation, optional pending submission, and gated paid publication sequence. |
| query | string | yes | — |
| schema | — | yes | — |
| selection_method | string | — | — |
| trust_boundary | string | yes | — |
No examples provided.
ontario_agent-pay-query-v2 Live x402 Endpoint Readiness Check ~360
Live x402 endpoint readiness check before payment. This x402 paid API verification service helps verify an x402 endpoint before an AI agent pays: probe one public paid API and inspect the HTTP 402 challenge, payTo address, price, Base USDC network and asset, manifest freshness, buyer budget, and spend policy. Returns ALLOW or DENY with reasons, readiness score, report ID, settlement metadata, and a settlement-backed SHA-256 evidence receipt. Run free can-pay and readiness checks first. Readiness evidence is not a safety guarantee. Agent payment guidance: run free can-pay and readiness checks first; pay only when policy allows base 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 and 0.002 USDC is inside the agent budget. [PAID: 0.002 USDC via x402 on Base. Two-step flow: call without _x402_payment to receive the x402 payment requirements, then call again with _x402_payment set to a base64 x402 PaymentPayload to settle and receive the result.]
| Name | Type | Req | Description |
|---|---|---|---|
| _x402_payment | string | — | base64 x402 PaymentPayload (USDC on Base); obtain the requirements by calling this tool without it first. |
| agent_policy | string | — | Policy posture used to produce the allow or deny decision. |
| endpoint | string | yes | Public x402 paid API URL to probe and verify before an autonomous agent pays. |
| max_usdc | string | — | Optional maximum endpoint price allowed by the buyer policy. |
| query | string | — | Optional task context for the payment decision. When omitted, Ontario performs a general live x402 endpoint readiness check. |
Structured output declared, but exposes no named fields.
No examples provided.
ontario_list-service Publish an x402 Service Profile ~346
Use only when the caller owns an x402 endpoint and wants a public provider profile, live readiness scan, evidence link, and conditional fresh ready-grade eligibility in strict /discover and Ontario's task-to-tool buyer search, with a privacy-safe 30-day profile request receipt. A paid profile supersedes an older free preview for the same endpoint and method in public catalogs. Validate and run readiness first; payment does not guarantee a ready grade, traffic, ranking, purchases, or safety. Agent payment guidance: run free can-pay and readiness checks first; pay only when policy allows base 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 and 0.50 USDC is inside the agent budget. [PAID: 0.50 USDC via x402 on Base. Two-step flow: call without _x402_payment to receive the x402 payment requirements, then call again with _x402_payment set to a base64 x402 PaymentPayload to settle and receive the result.]
| Name | Type | Req | Description |
|---|---|---|---|
| _x402_payment | string | — | base64 x402 PaymentPayload (USDC on Base); obtain the requirements by calling this tool without it first. |
| asset | string | — | — |
| category | string | — | — |
| description | string | yes | — |
| endpoint | string | yes | — |
| method | string | — | — |
| name | string | yes | — |
| network | string | — | — |
| owner_contact | string | — | — |
| owner_url | string | — | — |
| price_atomic | integer | — | — |
| price_usdc | string | yes | — |
| tags | array | — | — |
| Name | Type | Req | Description |
|---|---|---|---|
| listing | object | yes | — |
| payment | object | — | — |
| provider_next_steps | object | yes | — |
No examples provided.
ontario_purchase_router Ontario Free/Paid Purchase Router ~212
Free deterministic pre-purchase routing across Ontario tools. Use this before any paid Ontario tool to decide whether the task is free-only, needs free preflight, or is eligible for a paid result after wallet, Base network, and explicit budget gates. Provider jobs such as publishing, registering, or making an x402 endpoint discoverable can route to the self-serve 0.50 USDC publication product after preflight. This tool never invokes another tool, signs a payload, or spends funds.
| Name | Type | Req | Description |
|---|---|---|---|
| free_preflight_complete | boolean | — | True only after the recommended free check has completed for this task. |
| max_usdc | string | — | Optional explicit per-call USDC ceiling. The router never increases it. |
| network | string | — | Wallet policy network; Ontario paid tools currently require Base mainnet. |
| task | string | yes | Public task description only; never include credentials or private customer data. |
| wallet_enabled | boolean | — | True only when the caller can locally sign an x402 PaymentPayload. |
| Name | Type | Req | Description |
|---|---|---|---|
| decision | string | yes | — |
| free_tool | object | — | — |
| gates | object | yes | — |
| next_action | string | yes | — |
| paid_candidate | object|null | — | — |
| payment_flow | object | — | — |
| privacy | string | — | — |
| provider_publication_path | object | — | Present for provider-publication intent. Gives the free launch-kit and validator followed by the gated paid publisher. |
| reasons | array | — | — |
| schema | — | yes | — |
| selected_tool | object | yes | — |
| status | — | yes | — |
| task_category | string | yes | — |
| trust_boundary | string | yes | — |
No examples provided.
ontario_refresh-listing Refresh an x402 Service Profile ~245
Use only for an existing paid Ontario provider profile when the caller wants a fresh live readiness observation attached to its canonical HTML, JSON twin, and badge. This tool cannot edit provider metadata, improve a grade by payment, or buy ranking or traffic. Agent payment guidance: run free can-pay and readiness checks first; pay only when policy allows base 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913 and 0.10 USDC is inside the agent budget. [PAID: 0.10 USDC via x402 on Base. Two-step flow: call without _x402_payment to receive the x402 payment requirements, then call again with _x402_payment set to a base64 x402 PaymentPayload to settle and receive the result.]
| Name | Type | Req | Description |
|---|---|---|---|
| _x402_payment | string | — | base64 x402 PaymentPayload (USDC on Base); obtain the requirements by calling this tool without it first. |
| listing_id | string | yes | Existing paid provider profile id. |
| paid_refresh_tx | string | — | One-use retry reference only when a settled refresh could not complete. |
No output schema declared.
No examples provided.
x402_launch_kit X402 Launch Kit ~115
Generate a validated listing payload, x402 resource draft, MCP descriptor, GitHub readiness workflow, README snippet, and registry copy for one paid endpoint.
| Name | Type | Req | Description |
|---|---|---|---|
| asset | string | — | — |
| description | string | yes | — |
| endpoint | string | yes | — |
| method | string | — | — |
| name | string | yes | — |
| network | string | — | — |
| owner_contact | string | — | — |
| owner_url | string | — | — |
| price_usdc | string | yes | — |
| tags | string | — | — |
No output schema declared.
No examples provided.
x402_readiness_verify x402 Readiness Verify ~73
Free check for whether a paid endpoint is ready for agent discovery and x402 payment. Returns a grade-aware provider handoff: validate listing metadata free before any optional 0.50 USDC publication, and do not pay for publication while the endpoint is not ready-grade.
| Name | Type | Req | Description |
|---|---|---|---|
| target_url | string | yes | — |
| Name | Type | Req | Description |
|---|---|---|---|
| grade | string | yes | — |
| provider_listing_next_step | object | — | — |
| readiness_score | number | yes | — |
| recommendations | array | — | — |
| report_id | string | yes | — |
| report_url | string | — | — |
| signals | object | — | — |
| status | string | yes | — |
| warnings | array | — | — |
No examples provided.