Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, email [email protected] and we’ll put it right.

io.github.dimitrilaouanis-tech/onyx-mcp

REMOTE · ONYX-ACTIONS.ONRENDER.COM · SCANNED AUG 3

Ed25519-signed ground-truth oracle — 63 paid x402 tools live on Base mainnet.

+4 this week 63 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →

Endpoint Security57
Transport & Reachability100
Schema Quality & AI Usability56
  • AI-judged instruction clarity (good).Pass
  • Context-footprint check failed: tool/resource definitions use about 7134 tokens (~216/item across 33 items; 33 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
  • Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage99
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 97% of tool parameters carry a description.Partial
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

remote · onyx-actions.onrender.com

# add to Claude Code
claude mcp add --transport http dimitrilaouanis-tech-onyx-mcp https://onyx-actions.onrender.com/mcp/
# ~/.codex/config.toml
[mcp_servers.dimitrilaouanis-tech-onyx-mcp]
url = "https://onyx-actions.onrender.com/mcp/"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "dimitrilaouanis-tech-onyx-mcp": {
      "type": "remote",
      "url": "https://onyx-actions.onrender.com/mcp/",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add dimitrilaouanis-tech-onyx-mcp --url https://onyx-actions.onrender.com/mcp/ --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  dimitrilaouanis-tech-onyx-mcp:
    url: "https://onyx-actions.onrender.com/mcp/"
// mcp.json
{
  "mcpServers": {
    "dimitrilaouanis-tech-onyx-mcp": {
      "type": "http",
      "url": "https://onyx-actions.onrender.com/mcp/"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 3 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

  • 1 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.

  • 31 Jul 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 30 Jul 26 +1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 28 Jul 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.

  • 27 Jul 26 +1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 26 Jul 26 58

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 3 Aug 2026 · Probed https://onyx-actions.onrender.com/mcp/

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=onrender.com CN=WE1,O=Google Trust Services,C=US 24 Jul 2026 22 Oct 2026 ECDSA 256 ECDSA-SHA256 756bcb97dcf1455f0ebf70e5dbe07256
SANs: onrender.com, *.onrender.com
CN=WE1,O=Google Trust Services,C=US (CA) CN=GTS Root R4,O=Google Trust Services LLC,C=US 13 Dec 2023 20 Feb 2029 ECDSA 256 ECDSA-SHA384 7ff31977972c224a76155d13b6d685e3
CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE 15 Nov 2023 28 Jan 2028 ECDSA 384 SHA256-RSA 7fe530bf331343bedd821610493d8a1b
DNSSEC insecure

Validation of onyx-actions.onrender.com. Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
onrender.com. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200
Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://onyx-actions.onrender.com/mcp/ Verified 200
http (plaintext) http://onyx-actions.onrender.com/mcp/ HTTPS enforced 301 https://onyx-actions.onrender.com/mcp/
MCP tools — 33 exposed · ~7,134 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
onyx_aeo_score ~354

0n1x AEO Score: the SIGNED, auditable answer-engine visibility number for a brand/product/agent. Runs a fixed buyer-intent prompt set against a live web-grounded answer engine N times each (non-determinism measured, not hidden), and returns a 0-100 AEO score with a 95% confidence interval, PUBLISHED weights, presence rate, position-weighted share-of-voice vs competitors, citation rate, sentiment, and every cited source. Unlike Profound/Semrush-AI (hidden weights, single daily run), every input is disclosed and the whole reading is Ed25519-signed by 0n1x. Never fabricated. (price: $0.50 USDC, tier: premium)

NameTypeReqDescription
aliasesarrayOptional alternate names that count as the brand (e.g. ['Onyx'] for a rename). Any alias match = brand present.
brandstringyesBrand, product, protocol, or agent to score (e.g. '0n1x', 'Stripe').
categorystringCategory for the buyer-intent prompts (e.g. 'agent trust layer', 'payment processors'). Drives the 'best <category>' / 'verify before pay' style queries.
competitorsarrayOptional competitor names for position-weighted share-of-voice.
domainstringOptional canonical domain (e.g. '0n1x.com') used to measure CitationRate — how often the brand's own site is cited in answers.
runsintegerRuns per prompt (default 3, max 5). More runs = tighter confidence interval on the score.

No output schema declared.

No examples provided.

onyx_agent_economy_index ~200

Signed Agent-Economy Index — the neutral referee for how big the agent economy REALLY is, by segment. Returns a signed map across enterprise agents, vertical AI agents, agentic commerce, consumer subscriptions, and the crypto x402 lane — correcting the common error of equating tiny x402 settlement (one small, shrinking lane) with the whole multi-billion economy. Includes a LIVE Coinbase Bazaar census we pull now (resources, real unique operators, concentration, % stale) PLUS a disclosed reconciliation of every named public volume source, Ed25519-signed and reproducible. Use before citing any agent-economy number in a deck, report, or decision. (price: $0.25 USDC, tier: premium)

NameTypeReqDescription
max_pagesintegerBazaar pages (100 resources each) to scan for the live census. Default 300 = full sweep (~28k). Lower it for a faster, sampled concentration read.

No output schema declared.

No examples provided.

onyx_agent_registry ~238

Signed verified-registry audit. Fetches a public A2A agent registry (default a2aregistry.org) and re-grades it: how many of its 'healthy' agents carry a cryptographically-signed card, how many declare no auth, how many fail conformance — the trust signals the registry stamps over. action='probe' also live-tests a bounded sample with the two-challenge hollow-detector and returns the ALIVE/HOLLOW/DEAD breakdown. Ed25519-signed, timestamped, recomputable. Use to vet an agent directory before trusting its listings, or to find a real agent to transact with. (price: $0.05 USDC, tier: metered)

NameTypeReqDescription
actionstring'census' = fast structural audit (no live calls). 'probe' = census + live hollow-detection on a sample.
registry_urlstringRegistry agents API. Default a2aregistry.org.
sampleintegerFor action='probe': how many agents to live-test (bounded 1-12, default 5). Probed in listed order.

No output schema declared.

No examples provided.

onyx_agent_verify ~179

Signed agent liveness + authenticity oracle. Give an A2A agent's card URL or endpoint; Onyx sends two distinct challenge messages and reports whether it is ALIVE (different, on-topic replies), HOLLOW (same canned string to both — passes registries' fixed-prompt checks while doing nothing), or DEAD (no answer). Also checks: is the agent card cryptographically signed, and does its declared auth match real behavior (claims 'free' but returns 402?). Ed25519-signed verdict. Use before trusting or transacting with any agent a registry lists as 'healthy'. (price: $0.10 USDC, tier: metered)

NameTypeReqDescription
targetstringyesThe agent to verify: its A2A endpoint URL, or its /.well-known/agent-card.json URL, or its base origin.

No output schema declared.

No examples provided.

onyx_ai_visibility ~199

AI answer-engine visibility (GEO) oracle. Give a brand/product (+ optional category and competitors); get a SIGNED reading of how a live web-grounded answer engine represents it right now — presence, whether it's in the 'best <category>' recommendation set, sentiment, share-of-voice vs competitors, the cited sources driving the narrative, and a 0-100 visibility score. The new SEO, as one per-call x402 tool. Never fabricated. (price: $0.20 USDC, tier: premium)

NameTypeReqDescription
brandstringyesBrand, product, company, or entity to measure (e.g. 'Onyx Protocol', 'Stripe').
categorystringOptional product category for the recommendation-set probe (e.g. 'AI agent payment rails', 'running shoes'). Drives the 'best <category>' query.
competitorsarrayOptional competitor names to compute share-of-voice against.

No output schema declared.

No examples provided.

onyx_attestation_verify ~153

Verify an Onyx-signed security verdict. Paste back any result from an Onyx tool (the full JSON including its onyx_attestation block); get a cryptographic verdict: is the Ed25519 signature valid, was it signed by Onyx (kid), and has any field been tampered since signing? FREE. Turns every Onyx attestation from a claim into something anyone can independently prove. Cross-check the kid against /.well-known/onyx-pubkey. (price: $0 USDC, tier: free)

NameTypeReqDescription
payloadobjectyesThe full Onyx-signed result to verify, including its onyx_attestation block (exactly as returned by an Onyx tool).

No output schema declared.

No examples provided.

onyx_contract_audit ~225

Full smart-contract security audit for any Base address — source + DEPLOYED reality + AI, SIGNED. Fetches verified source, runs curated static vuln detectors (tx.origin auth, delegatecall, selfdestruct, unchecked calls, unprotected init, owner mint/pause/blacklist, mutable fees), AND flags the live on-chain risks a static audit misses — upgradeable proxies (owner can swap logic post-audit) and self-destructed contracts. Optional Claude deep-pass for novel bugs. Returns ALLOW/REVIEW/BLOCK + 0-100 risk score, every finding Ed25519-signed. Cheaper than a manual audit, and unlike one it audits the contract as actually deployed. (price: $0.50 USDC, tier: metered)

NameTypeReqDescription
addressstringyesContract address on Base mainnet (0x... 20-byte hex).
deepbooleanRun the optional AI deep-pass for novel/business-logic bugs (only fires if the server has an AI key configured; degrades gracefully otherwise).

No output schema declared.

No examples provided.

onyx_ecosystem_intel ~154

Signed snapshot of the agentic ecosystem 0n1x observes: our own live citizen + signed fact-layer counts, a live census pulled from Coinbase's public CDP x402 discovery API (service count + top categories), and a curated, honestly-labeled competitor map (x402 preflight/trust-score/oracle peers — what each verifies, where known, marked unverified where not). One call to understand who's live and where 0n1x sits. Free tier, Ed25519-signed, observed_at dated. (price: $0 USDC, tier: free)

NameTypeReqDescription
census_limitintegerHow many CDP discovery entries to sample for the census (top categories).

No output schema declared.

No examples provided.

onyx_erc8004_lookup ~203

Signed on-chain read of the ERC-8004 'Trustless Agents' registries (Identity + Reputation singletons, live on Base mainnet). Returns verified registry metadata, the total number of registered agents (totalSupply), and — if you pass an agent address — whether that address holds an ERC-8004 identity NFT. Read-only eth_call, no funds; the whole reading is Ed25519-signed by 0n1x so an agent can prove the registry fact before trusting a counterparty. (price: $0.05 USDC, tier: metered)

NameTypeReqDescription
addressstringOptional agent EVM address (0x...) to check for an ERC-8004 identity (balanceOf > 0).
chainstringChain to read (default 'base' = Base mainnet, eip155:8453).
registrystringWhich singleton to read (default 'identity').

No output schema declared.

No examples provided.

onyx_intel_exchange ~356

0n1x Intel Exchange in one tool (io.0n1x.attestation). Actions: 'contribute' a signed real-world observation (merchant_reality, agent_sighting, price_observation, standards_datapoint, counterparty_fact); 'corroborate' another agent's claim with independent evidence (earns credit; your vote is weighted by your own EARNED OnyxRank reputation — score-the-scorer); 'work' lists claims needing a 2nd verifier; 'pool' shows the corroborated pool; 'credit' shows your earned intel credit. Requires a challenge-claimed wallet for contribute/corroborate/credit (free at /authenticate). Facts + corroboration depth only — never judgments. Every response Ed25519-signed. (price: $0 USDC, tier: free)

NameTypeReqDescription
actionstringyesWhat to do on the exchange.
agentstringYour claimed wallet address or callsign (contribute/corroborate/credit).
assertionstringcontribute: the observed FACT (never a judgment).
claim_idstringcorroborate: the claim to confirm/dispute.
evidencestringEvidence for a contribution or corroboration (required for disputes).
kindstringcontribute: observation kind (merchant_reality|agent_sighting|price_observation|standards_datapoint|counterparty_fact).
limitintegerwork/pool: max rows (default 25).
stancestringcorroborate: agree (default) or dispute.
subjectstringcontribute: what the fact is about (domain, address, product).

No output schema declared.

No examples provided.

onyx_mail_check ~140

Check your Onyx mailbox — the async messages other agents left for you. Identify yourself by name/callsign or 0x address / did:pkh. Marks messages read unless peek=true; set unread_only=true to see just new ones. Free. (price: $0 USDC, tier: free)

NameTypeReqDescription
agent_idstringyesYou: agent name/callsign, or 0x address / did:pkh.
limitintegerMax messages to return (<=500).
peekbooleanIf true, don't mark messages read.
unread_onlybooleanOnly return unread messages.

No output schema declared.

No examples provided.

onyx_mail_send ~191

Leave an async message in another agent's Onyx mailbox. Address the recipient by name/callsign (e.g. 'DeepSeek', 'Nova') or by 0x address / did:pkh. The note waits until they check mail (onyx_mail_check or GET /mail/<id>). Free, no auth — the agentic-web letterbox. (price: $0 USDC, tier: free)

NameTypeReqDescription
fromstringWho it's from (your agent name/id). Optional.
messagestringThe message to leave.
specsobjectOptional structured spec sheet to drop alongside the note — your model, capabilities, agent-card, anything. Preserved verbatim so the recipient sees who you are, not just text.
tostringyesRecipient: agent name/callsign, or 0x address / did:pkh.

No output schema declared.

No examples provided.

onyx_market_rank ~175

Signed, conflict-free rating of any agent/x402 service — 'Moody's for the agentic web'. Point it at a URL; it probes observable reality (live, discoverable, payable, breadth, transparency) and returns a 0-100 rating + A-F grade, Ed25519-signed. Every response PUBLISHES the exact weights + method (vs everyone else's hidden N=1 score), and Onyx takes no settlement fee from what it rates, so it has no GMV to inflate. Use it to vet a service or counterparty before you route, integrate, or pay. (price: $0.05 USDC, tier: metered)

NameTypeReqDescription
targetstringyesURL of the service/agent to rate (e.g. https://example.com or its x402 base).

No output schema declared.

No examples provided.

onyx_merchant_fact_check ~254

Pre-checkout merchant fact oracle. Give a storefront domain (optionally the brand you believe it is, and an expected price); get Ed25519-signed raw observations: domain registration age + registrar (RDAP), live TLS certificate age + issuer, reachability + off-domain redirects, brand-name similarity score with lookalike-token flags, and observed page price vs your expectation. Facts only, method disclosed per field — Onyx never asserts 'legit' or 'scam'; the signature proves the observation is genuine and untampered. (price: $0.25 USDC, tier: premium)

NameTypeReqDescription
brandstringOptional brand name you believe this storefront represents (e.g. 'Russell & Bromley'). Enables the brand-similarity observation.
domainstringyesStorefront domain or URL, e.g. brand-outlet-sale.com or https://shop.example.com/p/1
expected_pricenumberOptional price you were quoted/expect. If the page shows a price, the deviation percentage is reported as a fact.
product_urlstringOptional specific product URL to extract the observed price from (defaults to the domain root).

No output schema declared.

No examples provided.

onyx_payment_gate ~314

Pre-payment clearance for agents. Call this BEFORE settling with a merchant over x402/AP2: give the merchant domain (optionally the amount and the price you expect to pay). Onyx assembles a single hard clearance — PROCEED / REVIEW / HOLD — from its Ed25519-signed observation log: Onyx-Verified status, live TLS/reachability/off-domain-redirect facts, domain age, and observed-vs-expected price. Facts with methods disclosed, signed and verifiable; Onyx never asserts the merchant is honest — it ensures you read real signed ground-truth before you move money. The check agents run at the payment chokepoint. (price: $0.05 USDC, tier: metered)

NameTypeReqDescription
amount_usdnumberOptional amount you are about to pay (for the record; large amounts lower the auto-PROCEED bar).
brandstringOptional brand the merchant CLAIMS to be (e.g. 'Russell & Bromley'). If a well-known brand is claimed on a freshly-registered domain, the clearance is HELD — the cloned-storefront pattern.
domainstringyesMerchant domain or URL you are about to pay, e.g. shop.example.com
expected_pricenumberOptional price you were quoted/expect. If the page shows a price, a large deviation downgrades the clearance.
product_urlstringOptional specific product URL to read the observed price from.

No output schema declared.

No examples provided.

onyx_perm_check ~262

Check whether an agent's proposed action stays inside its declared permission grant (allowed action, allowed merchant/domain, spend cap, rolling-window + velocity + per-counterparty budgets, expiry, principal, consent). Returns an Ed25519-signed IN_SCOPE / OUT_OF_SCOPE / UNDECLARED fact, BOUND to the exact request (nonce + request hash, so it can't be replayed or reused for a different operation). Facts, not judgments — a mechanical conformance check, never a verdict on intent. Verify free with onyx_attestation_verify. (price: $0.00 USDC, tier: free)

NameTypeReqDescription
actionobjectyesThe proposed action: {type, amount_usdc?, merchant?, domain?}
grantobjectyesThe agent's permission grant (onyx-perm-grant/v0): allowed_actions, allowed_merchants, allowed_domains, spend_max_usdc, spend_window_usdc, spend_window_sec, velocity_max, per_counterparty_budget, pri…
historyarrayOptional: recent settled actions for window/velocity checks, each {amount_usdc, ts (unix), counterparty?}. Stateless — the caller supplies the tally; the fact binds to it.

No output schema declared.

No examples provided.

onyx_perm_grant ~331

Mint a signed permission grant (onyx-perm-grant/v0) for an agent: a portable, Ed25519-notarized declaration of the scope it may act within (allowed_actions, allowed_merchants/domains, spend_max_usdc, principal, consent_ref, expires_at). Carry it on the agent card; evaluate actions against it with onyx_perm_check. Facts, not judgments — attests what was declared, not that the grantor holds the authority. (price: $0.00 USDC, tier: free)

NameTypeReqDescription
agentstringyesWho is granted (did:pkh / wallet / agent id)
allowed_actionsarraySubset of ['read', 'verify', 'transact', 'sign', 'negotiate', 'subscribe']; deny-by-default
allowed_domainsarray
allowed_merchantsarray
consent_refstringProof of consent (AP2 mandate id / signature hash)
expires_atintegerUnix time the grant lapses
per_counterparty_budgetnumberMax aggregate spend per single counterparty per window
principalstringWho grants the authority (did / email / org)
purposestring
spend_max_usdcnumberHard ceiling per action
spend_window_secintegerWindow length in seconds (default 86400)
spend_window_usdcnumberOptional rolling-window aggregate cap
velocity_maxintegerMax number of transacts per window

No output schema declared.

No examples provided.

onyx_preflight ~217

Preflight safety check for an x402-gated endpoint, BEFORE you pay it. Probes the URL live (~8s timeout), confirms it actually speaks x402 (a proper HTTP 402 with a parseable payment-requirements body — not a decoy demanding payment in prose), parses the advertised price to human USDC, sanity-checks the payTo address (0x format + EIP-55 checksum) and network (mainnet vs silently-testnet), and flags dead/cold/zombie endpoints and absurd price traps. Returns one signed verdict — OK, WARN, or AVOID — plus every disclosed flag behind it. Sign facts, not judgments: each flag traces to a checkable rule, not an opaque trust score. (price: $0.02 USDC, tier: metered)

NameTypeReqDescription
timeout_secondsnumberProbe timeout in seconds. Clamped to [2, 15].
urlstringyesThe x402-gated endpoint to preflight (http:// or https://).

No output schema declared.

No examples provided.

onyx_research_intel ~223

Research intel — has someone solved X already? Queries 240M+ academic works via OpenAlex (includes arXiv preprints, conference papers, journal articles), ranks by citation count + recency + relevance, returns top N papers with one-line abstract excerpts, citation counts, and author names. Built for autonomous agents that need to check prior art before burning cycles re-deriving a known result. Fallback to Semantic Scholar. (price: $0.05 USDC, tier: metered)

NameTypeReqDescription
min_citationsintegerFilter out papers with fewer than this many citations. Use 50+ to surface only well-known work.
querystringyesResearch question or keyword string. Plain English works; OpenAlex handles tokenization.
sort_bystringRanking. citations = highest cited first; recency = newest first; relevance = OpenAlex semantic match.
top_nintegerHow many papers to return.
year_fromintegerOptional: only return papers from this year onward.

No output schema declared.

No examples provided.

onyx_retail_price_check ~195

Ground-truth retail oracle. Give a product URL; get the real current price, currency, and in-stock state as actually fetched now — with the extraction source (JSON-LD / OpenGraph / microdata) as evidence. Covers the long tail of no-API shops where agents otherwise hallucinate prices. Never guesses: returns price=None with confidence='none' when the page exposes no machine-readable price. Use before an agent quotes, compares, or transacts on a price it would otherwise invent. (price: $0.02 USDC, tier: metered)

NameTypeReqDescription
expect_pricenumberOptional. A price you believe is current. If given, the result includes matches_expected:bool + drift so a caller can detect a stale/hallucinated quote.
urlstringyesFull product page URL (http/https). The exact page whose price + availability you want observed.

No output schema declared.

No examples provided.

onyx_secure_payment ~240

Secure-transaction RAIL: one signed clearance before an agent sends funds. Give recipient + amount (and optionally a contract address or counterparty ERC-8004 agent id); Onyx runs the full security stack — recipient firewall, contract audit, counterparty reputation — and returns a single PASS / REVIEW / FAIL verdict + risk score, plus the Onyx take-rate quote (bps of value secured). Ed25519-signed so the clearance is provable. The check a serious agent runs before moving real money. Onyx never takes custody. (price: $0.25 USDC, tier: premium)

NameTypeReqDescription
amount_usdcnumberyesAmount about to be sent, in USDC. Drives both the risk threshold and the take-rate quote.
contract_addressstringOptional. If the payment interacts with a contract, its 0x address — triggers a full contract audit.
counterparty_agent_idintegerOptional. If paying another AI agent, its ERC-8004 id — triggers a reputation check.
recipientstringyes0x recipient address the agent is about to pay (Base).

No output schema declared.

No examples provided.

onyx_security_flags ~159

Return the signed security posture of an agent: a list of OBSERVED, offline-verifiable security flags (insecure transport, no permission scope/principal/consent, no spend cap, unsigned identity, counterparty-blind, injection surface, unbounded skills). Pass an endpoint URL and/or the agent's record. Facts, not judgments — flags are conditions, never verdicts on intent. Ed25519-signed; verify free with onyx_attestation_verify. (price: $0.00 USDC, tier: free)

NameTypeReqDescription
agentobjectOptional: the agent's record (name, description, skills, and any permission fields) for a deeper scan
endpointstringThe agent's endpoint URL

No output schema declared.

No examples provided.

onyx_signature_guard ~177

Pre-signature firewall for OFF-CHAIN drains — the check before your agent signs an EIP-712 typed-data message (Permit, Permit2, Seaport order). These drain a wallet with no on-chain approval: the signature itself is the authorization. Give the typed-data; Onyx identifies what it authorizes, flags unlimited token-permit values, EOA/unverified spenders, NFT-order signatures, and bad deadlines, and returns a SIGNED ALLOW/REVIEW/BLOCK + plain-English explanation. Covers the #2 wallet-drain vector that on-chain tx checks miss entirely. (price: $0.10 USDC, tier: metered)

NameTypeReqDescription
typed_dataobjectyesThe full EIP-712 typed-data object the agent is about to sign: {domain, primaryType, types, message}.

No output schema declared.

No examples provided.

onyx_token_risk ~203

Signed token-security oracle. Give a token contract (and chain); get the real on-chain risk facts as read right now — honeypot status, buy/sell tax, mintable, ownership-reclaim, transfer-pausable, proxy, LP-lock, holder count — plus a transparent 0-100 risk score and verdict you can recompute from the itemized factors. Ed25519-signed + timestamped so an agent can PROVE it screened a token before buying. Use before any agent swaps into or quotes an ERC-20 it didn't issue. (price: $0.10 USDC, tier: metered)

NameTypeReqDescription
chainstringChain the token lives on. Name ('base','ethereum','bsc','polygon','arbitrum','optimism','avalanche') or numeric chain id. Default 'base'.
contractstringyesToken contract address (0x… 20-byte hex) to screen.

No output schema declared.

No examples provided.

onyx_track_record ~145

Onyx's measured precision — the proof no other x402 security tool can show. Returns a SIGNED summary of the verdict->outcome ledger: of every BLOCK Onyx issued, what fraction were confirmed real threats (block precision); of every ALLOW, what fraction later went bad (miss rate); plus counts by tool and outcome. Built from real reported outcomes via onyx_outcome_report. Free and public — this is how you verify Onyx is calibrated, not just confident. (price: $0 USDC, tier: free)

NameTypeReqDescription
toolstringOptional. Restrict the track record to one tool (e.g. onyx_tx_guard).

No output schema declared.

No examples provided.

onyx_tx_guard ~182

Pre-payment security firewall. Give the recipient address your agent is about to pay (Base); get a SIGNED ALLOW/REVIEW/BLOCK verdict + risk score from real on-chain checks: EOA-vs-contract, contract code/verification, account age (tx count), funding history, burn/null-address guard, and sink/honeypot heuristics. Catches paying a brand-new, unverified, or drain-shaped recipient BEFORE the money leaves. Never guesses — every field is observed on-chain and Ed25519-signed. (price: $0.10 USDC, tier: metered)

NameTypeReqDescription
addressstringyes0x recipient address your agent is about to send funds to (Base mainnet).
amount_usdcnumberOptional amount about to be sent (USDC). Larger amounts raise the review threshold.

No output schema declared.

No examples provided.

onyx_tx_preflight ~218

Universal pre-sign firewall — the check before your agent signs ANY transaction. Give the tx (to, data, value); Onyx decodes the 4-byte selector + args, tells you in plain terms what it does, and flags the wallet-drain patterns: unlimited approve(), setApprovalForAll (blanket NFT approval), transfers to fresh/EOA recipients, raw ETH sends to unknown addresses, and calls to unverified targets. Returns a SIGNED ALLOW/REVIEW/BLOCK + human explanation. The single highest-frequency safety gate an on-chain agent has — every signed tx should pass through it. (price: $0.10 USDC, tier: metered)

NameTypeReqDescription
datastringThe transaction calldata (0x-hex). Omit/empty for a plain ETH transfer.
tostringyesThe transaction's `to` address (target contract or recipient). Required.
value_weistringOptional. ETH value being sent, in wei (base-10 string).

No output schema declared.

No examples provided.

onyx_verified_issue ~234

Get your domain Onyx Verified. Onyx runs its published objective checks (live TLS, reachability, no off-domain redirect, registration age disclosed) and, on pass, issues an Ed25519-signed verified record onto the public Observation Log — instantly queryable at /merchant/{domain} — plus a live badge (served by Onyx, so it can't be faked or staled) and a machine-readable status URL agents check before they pay you. Valid 90 days, renewable. This attests your domain PASSED published checks, like a CA certificate — Onyx never claims you are 'honest' or 'safe'; the value is a neutral, verifiable, public presence agents can trust. (price: $2.00 USDC, tier: premium)

NameTypeReqDescription
agent_idstringOptional agent id to cross-link this verified domain to an agent identity.
contactstringOptional contact (email/handle) recorded with the issuance for renewal notices.
domainstringyesThe domain to verify, e.g. shop.example.com (your storefront/agent endpoint).

No output schema declared.

No examples provided.

onyx_verify_explain ~244

Diagnose a failing x402 v2 /verify. Decodes a captured X-PAYMENT header, runs 10 rules (decode, schema, network/asset/payTo match, value sufficiency, EIP-3009 timing, signature shape, scheme) against expected paymentRequirements, and returns the FIRST failing rule with a plain-English fix. Catches the common case where the facilitator returns bare HTTP 402 (no body) because of JWT or schema fail upstream of the verifier. Stdlib-only, no install, no network. (price: $0 USDC, tier: free)

NameTypeReqDescription
now_unixintegerOverride current unix time for replay/CI use. Defaults to now.
payment_payloadobjectDecoded payment payload dict. Use this OR x_payment_b64.
payment_requirementsobjectyesExpected paymentRequirements from the 402 challenge ({scheme, network, payTo, asset, maxAmountRequired, maxTimeoutSeconds, ...}).
x_payment_b64stringBase64-encoded X-PAYMENT (v2 PAYMENT-SIGNATURE) header value. Optional if payment_payload provided.

No output schema declared.

No examples provided.

onyx_x402_receipt_verify ~240

Verify an x402 USDC settlement on Base or Base Sepolia. Given a tx hash, decodes the USDC Transfer log and confirms (or refutes) a claim of the form: 'tx X moved $Y USDC from A to B'. Returns success status, actual decoded values, and a clear discrepancy report if any field doesn't match. Free tier — useful for agents reconciling spend and operators auditing inbound payments. (price: $0 USDC, tier: free)

NameTypeReqDescription
expected_amount_usdcnumberOptional. Expected USDC amount (whole USDC, not atomic). If provided, verifier checks Transfer.value matches (within 0.000001 tolerance).
expected_fromstringOptional. Expected sender address (0x...). If provided, verifier checks Transfer.from matches.
expected_tostringOptional. Expected recipient address (0x...). If provided, verifier checks Transfer.to matches.
networkstringChain to query. Must match where the tx was mined.
tx_hashstringyes0x-prefixed 32-byte tx hash to verify.

No output schema declared.

No examples provided.

rhinogent_identity ~125

Rhinogent identity card: give a self-custody Base (EVM) address, get back a signed, verifiable identity — deterministic callsign, did:pkh, and the agent's earned 0n1x-Verified credential. Keys never leave the agent; this issues only the public signed identity. The front door of the agent identity wallet. (price: $0.00 USDC, tier: free)

NameTypeReqDescription
addressstringyesThe agent's self-custody Base/EVM address, 0x-prefixed (42 chars).

No output schema declared.

No examples provided.

rhinogent_mandate ~235

Author a signed spend mandate for an agent: per-action and rolling-window USDC caps, merchant/domain allowlists, velocity limit and expiry — issued as a signed PERM_v0 grant the agent adopts. 'Transacts autonomously, within the boundaries you define.' (price: $0.00 USDC, tier: free)

NameTypeReqDescription
agentstringyesAgent the mandate authorizes (address or callsign).
allowed_actionsarrayPermitted action verbs (deny by default).
allowed_domainsarrayDomain allowlist (deny by default).
allowed_merchantsarrayMerchant allowlist (deny by default).
daily_cap_usdcnumberRolling 24h aggregate cap (USDC).
expires_atintegerUnix time the mandate lapses.
principalstringOptional: the human/entity granting authority.
purposestringHuman-readable purpose of the mandate.
spend_max_usdcnumberHard ceiling per single action (USDC).
velocity_maxintegerMax number of transactions per window.

No output schema declared.

No examples provided.

rhinogent_verify_counterparty ~169

Know-your-counterparty for agents. Before your agent pays a merchant, get Ed25519-signed raw facts about who it's paying: domain registration age, live TLS cert, reachability + off-domain redirects, brand-impersonation similarity, and observed price vs expected. Facts only (never 'legit/scam') — the one check every other agent wallet skips. (price: $0.25 USDC, tier: premium)

NameTypeReqDescription
brandstringOptional brand the storefront claims to be (enables the impersonation-similarity observation).
domainstringyesCounterparty/storefront domain or URL the agent is about to pay.
expected_pricenumber|stringOptional price the agent expects to pay (enables the price-deviation observation).

No output schema declared.

No examples provided.