DeriveAI x402 APIs
REMOTE · X402-APIS-ETA.VERCEL.APP · SCANNED AUG 20
25 pay-per-request intelligence APIs for AI agents via x402 micropayments (USDC/Base)
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 25 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability80
- AI-judged instruction clarity (excellent).Pass
- Tool/resource definitions use about 2134 tokens (~85/item across 25 items; 25 tools + 0 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management3
- Stability observed for 1 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Capabilities40
- Spec-recency check failed: implements MCP spec 2025-03-26; the latest is 2026-07-28. See how to fix → Fail
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · x402-apis-eta.vercel.app
claude mcp add --transport http deriveit33z-ship-it-x402-apis https://x402-apis-eta.vercel.app/api/mcp
[mcp_servers.deriveit33z-ship-it-x402-apis] url = "https://x402-apis-eta.vercel.app/api/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"deriveit33z-ship-it-x402-apis": {
"type": "remote",
"url": "https://x402-apis-eta.vercel.app/api/mcp",
"enabled": true
}
}
} openclaw mcp add deriveit33z-ship-it-x402-apis --url https://x402-apis-eta.vercel.app/api/mcp --transport streamable-http
mcp_servers:
deriveit33z-ship-it-x402-apis:
url: "https://x402-apis-eta.vercel.app/api/mcp" {
"mcpServers": {
"deriveit33z-ship-it-x402-apis": {
"type": "http",
"url": "https://x402-apis-eta.vercel.app/api/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Aug 26 +1
- Stability: unverified → 0.03 ▲ functional
- 19 Aug 26 63
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Aug 2026 · Probed https://x402-apis-eta.vercel.app/api/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=*.vercel.app | CN=WR1,O=Google Trust Services,C=US | 28 Jun 2026 | 26 Sept 2026 | RSA 2048 | SHA256-RSA | b1c2b607df94f28513779ae26fecf92f |
| SANs: *.vercel.app | ||||||
| CN=WR1,O=Google Trust Services,C=US (CA) | CN=GTS Root R1,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | RSA 2048 | SHA256-RSA | 7fd9e2c2d2048a0474b627a26d0868a7 |
| CN=GTS Root R1,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 19 Jun 2020 | 28 Jan 2028 | RSA 4096 | SHA256-RSA | 77bd0d6cdb36f91aea210fc4f058d30d |
DNSSEC insecure
Validation of x402-apis-eta.vercel.app. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| app. | present | 23684 | 8 | Verified |
| vercel.app. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://x402-apis-eta.vercel.app/api/mcp | Verified | 200 | |
| http (plaintext) | http://x402-apis-eta.vercel.app/api/mcp | HTTPS enforced | 308 | https://x402-apis-eta.vercel.app/api/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
arabic_sentiment ~92
Analyze sentiment in Arabic text. Supports Gulf/Khaleeji, Egyptian, Levantine, and MSA dialects. Returns sentiment (positive/negative/neutral), confidence score, detected dialect, and keywords. Global LLMs hit ~45% accuracy on Gulf dialect — this tool is purpose-built for it.
| Name | Type | Req | Description |
|---|---|---|---|
| text | string | yes | Arabic text to analyze (max 10,000 characters) |
No output schema declared.
No examples provided.
arabizi_translate ~102
Convert Arabizi (Latin-script Arabic like '7abibi', 'shlonk', '3aysh') to Arabic script (حبيبي، شلونك، عايش). Gulf dialect optimized. Handles number-to-letter mappings (3=ع, 7=ح, 5=خ, 8=ق, 9=ص).
| Name | Type | Req | Description |
|---|---|---|---|
| text | string | yes | Arabizi text to transliterate (max 5,000 characters) |
No output schema declared.
No examples provided.
brand_scout ~60
Brand availability scout. Checks domain availability across 12 TLDs, social handle availability on 15+ platforms, trademark conflicts, and alternative name suggestions. Scored report (0-100).
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Brand/business name to check |
No output schema declared.
No examples provided.
company_report ~116
Full company report ($1.00). The mega-report: 25+ parallel checks in one call. WHOIS/domain age, SSL certificate, sanctions screening, web archive history, security headers (7 types), email infrastructure (SPF/DKIM/DMARC/blacklists), full DNS records, CDN detection, subdomain discovery, SEO analysis, social presence, tech stack, Lighthouse performance, legal pages. Returns scored verdict (0-100).
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Company domain to investigate (e.g., stripe.com) |
No output schema declared.
No examples provided.
competitor_analysis ~107
Competitive analysis report ($1.00). Pass two domains, get a head-to-head comparison across 8 dimensions: security headers, SEO quality, Lighthouse performance, SSL health, email security (SPF/DMARC), social presence, infrastructure (CDN/IPv6), and domain maturity. Returns winner per category and overall verdict.
| Name | Type | Req | Description |
|---|---|---|---|
| domain1 | string | yes | First domain (e.g., google.com) |
| domain2 | string | yes | Second domain (e.g., bing.com) |
No output schema declared.
No examples provided.
crypto_data ~78
Real-time cryptocurrency market data: price, 24h volume, market cap, and 24h price change percentage. Supports thousands of coins via CoinGecko IDs.
| Name | Type | Req | Description |
|---|---|---|---|
| coin | string | yes | CoinGecko coin ID (e.g., bitcoin, ethereum, solana) |
| currency | string | – | Fiat currency code (default: usd) |
No output schema declared.
No examples provided.
currency_convert ~100
Currency conversion with real-time rates. Supports 150+ currencies including fiat (USD, EUR, GBP, AED, SAR, INR, PKR, PHP) and crypto (BTC, ETH). Returns rate, converted amount, and inverse rate.
| Name | Type | Req | Description |
|---|---|---|---|
| amount | string | – | Amount to convert (default: 1) |
| from | string | yes | Source currency code (default: USD) |
| to | string | yes | Target currency code (default: AED) |
No output schema declared.
No examples provided.
detect_language ~81
Detects language, script type, and Arabic dialect from any text. Supports Arabic (MSA, Gulf, Egyptian, Levantine, Maghrebi), English, French, Spanish, Turkish, Hindi. Also detects Arabizi (Latin-script Arabic) and mixed-language text.
| Name | Type | Req | Description |
|---|---|---|---|
| text | string | yes | Text to analyze (max 10,000 chars) |
No output schema declared.
No examples provided.
domain_enrich ~75
Domain enrichment: returns company name, description, detected tech stack (React, WordPress, Shopify, etc.), social media links (Twitter, LinkedIn, GitHub), email addresses, and redirect info for any domain.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain name to enrich (e.g., google.com, aramco.com) |
No output schema declared.
No examples provided.
domain_infra ~71
Domain infrastructure map. Full DNS records (A, AAAA, MX, NS, TXT, SOA, CAA), hosting provider, CDN detection, subdomain discovery via DNS brute-force and Certificate Transparency, IP geolocation.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to map (e.g., google.com) |
No output schema declared.
No examples provided.
due_diligence ~131
Entity due diligence report. One call replaces 10+ separate lookups. Pass a domain or company name, get: WHOIS data, SSL certificate analysis, sanctions screening (OpenSanctions), web archive history, web presence audit, social links, contact info, risk signals, and a confidence-scored trust verdict (0-100). Costs $0.50 because it runs 5+ parallel checks and cross-references the results.
| Name | Type | Req | Description |
|---|---|---|---|
| company | string | – | Company name to screen (e.g., Google LLC) |
| domain | string | – | Domain to investigate (e.g., google.com) |
No output schema declared.
No examples provided.
email_audit ~73
Email infrastructure audit. Checks SPF, DKIM (10 selectors), DMARC, MX records, blacklist status (8 DNSBLs), and DNSSEC. Returns deliverability score (0-100). All DNS-based, zero API keys.
| Name | Type | Req | Description |
|---|---|---|---|
| domain | string | yes | Domain to audit (e.g., gmail.com) |
No output schema declared.
No examples provided.
gold_price ~131
Current retail gold prices per gram in 24K/22K/21K/18K across 10 currencies (USD, AED, EUR, GBP, INR, SAR, PKR, PHP, BDT, EGP). Consumer retail pricing.
| Name | Type | Req | Description |
|---|---|---|---|
| currency | string | – | Currency code: USD, AED, EUR, GBP, INR, SAR, PKR, PHP, BDT, EGP (default: USD) |
| karat | string | – | Gold karat: 24K, 22K, 21K, 18K, or 'all' (default: all) |
No output schema declared.
No examples provided.
ip_intel ~74
IP address threat intelligence. Geolocation, ASN/ISP, reverse DNS, blacklist status (8 DNSBLs), VPN/proxy/Tor detection, abuse history. Cross-referenced risk score (0-100).
| Name | Type | Req | Description |
|---|---|---|---|
| ip | string | yes | IPv4 address (e.g., 8.8.8.8) |
No output schema declared.
No examples provided.
legal_simplifier ~68
Legal jargon simplifier. Takes contract clauses, terms of service, or privacy policy text and returns: plain English explanations of legal terms, red flags, key obligations, complexity score, and risk level.
| Name | Type | Req | Description |
|---|---|---|---|
| text | string | yes | Legal text to analyze (max 20,000 chars) |
No output schema declared.
No examples provided.
prayer_times ~106
Islamic prayer times for any city worldwide: Fajr, Dhuhr, Asr, Maghrib, Isha. Includes sunrise, Hijri date, and multiple calculation methods (Umm Al-Qura, ISNA, MWL).
| Name | Type | Req | Description |
|---|---|---|---|
| city | string | yes | City name (e.g., Dubai, London, Jakarta) |
| country | string | – | Country name (optional) |
| date | string | – | Date in DD-MM-YYYY format (optional, defaults to today) |
No output schema declared.
No examples provided.
profanity_filter ~98
Multilingual profanity and toxicity detection. Supports English, Arabic (Gulf dialect aware), Spanish, and French. Returns toxicity score, flagged words with categories (hate/sexual/violence/slur), severity rating, and cleaned text.
| Name | Type | Req | Description |
|---|---|---|---|
| language | string | – | Language code: en, ar, es, fr (auto-detected if not provided) |
| text | string | yes | Text to check for profanity (max 10,000 chars) |
No output schema declared.
No examples provided.
scrape_structured ~72
Smart structured web scraper. Unlike basic scrapers that return raw text, this extracts and LABELS structured data: emails, phone numbers, prices, dates, tables, links, headings, and metadata. Returns agent-ready JSON — no further parsing needed.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | Full URL to scrape and structure |
No output schema declared.
No examples provided.
screenshot ~80
Captures a website screenshot as PNG/JPEG with performance metrics. Returns base64 image, Lighthouse performance score, First Contentful Paint, Largest Contentful Paint, and Total Blocking Time.
| Name | Type | Req | Description |
|---|---|---|---|
| format | string | – | 'json' for base64+metrics, 'image' for raw image (default: json) |
| url | string | yes | URL to screenshot |
No output schema declared.
No examples provided.
site_audit ~103
Website security and SEO audit. Runs 5 parallel checks: security headers (HSTS, CSP, X-Frame-Options), SSL certificate grade, DNS configuration (DNSSEC, SPF), SEO analysis (title, meta, OG tags, headings, images), and Lighthouse performance metrics. Returns scored report (0-100) with actionable findings. $0.50 per audit.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | URL to audit (e.g., https://example.com) |
No output schema declared.
No examples provided.
text_summarize ~74
Extractive text summarization. Scores sentences by keyword frequency and returns the most important ones in original order, plus top 10 keywords.
| Name | Type | Req | Description |
|---|---|---|---|
| max_sentences | number | – | Number of key sentences to extract (default: 5) |
| text | string | yes | Text to summarize (max 50,000 characters) |
No output schema declared.
No examples provided.
username_osint ~64
Username OSINT report. Checks 25+ platforms (GitHub, Reddit, Twitter, Instagram, npm, Steam, etc.) for a username. Categorizes by type, enriches GitHub profile, checks domain availability.
| Name | Type | Req | Description |
|---|---|---|---|
| username | string | yes | Username to investigate |
No output schema declared.
No examples provided.
verify_email ~60
Email verification: validates format, checks domain exists, verifies MX records, detects disposable emails, free providers (Gmail, Yahoo), and role-based addresses (info@, admin@). Returns risk score.
| Name | Type | Req | Description |
|---|---|---|---|
| string | yes | Email address to verify |
No output schema declared.
No examples provided.
weather_data ~55
Current weather conditions for any city worldwide. Returns temperature, feels-like, humidity, precipitation, wind speed/direction, and weather condition description.
| Name | Type | Req | Description |
|---|---|---|---|
| city | string | yes | City name (e.g., Dubai, Abu Dhabi, London) |
No output schema declared.
No examples provided.
web_scrape ~63
Extract text content, links, title, and metadata from any URL. Returns cleaned text (scripts/styles removed), page title, meta description, and up to 50 links.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | Full URL to scrape (e.g., https://example.com) |
No output schema declared.
No examples provided.