# io.github.dimitrilaouanis-tech/onyx-mcp (remote · onyx-actions.onrender.com)

Ed25519-signed ground-truth oracle — 63 paid x402 tools live on Base mainnet.

- Trust score: 63/100 (medium)
- Change this week: +4
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- remote · `onyx-actions.onrender.com`: 63/100 (this document), [markdown](https://verifymcp.io/servers/dimitrilaouanis-tech-onyx-mcp/onyx-actions.md), [page](https://verifymcp.io/servers/dimitrilaouanis-tech-onyx-mcp/onyx-actions)

## Channel facts

- Endpoint: `https://onyx-actions.onrender.com/mcp/`
- Transports: `streamable-http`
- Auth: `none`
- Version: `0.4.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Endpoint Security**: 57/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation not fully verified: no authorisation is required to call this server, and 33 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe.
  - HTTPS is enforced; there's no plaintext access path.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 56/100
  - AI-judged instruction clarity (good).
  - Context-footprint check failed: tool/resource definitions use about 7134 tokens (~216/item across 33 items; 33 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 27/100
  - Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 99/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 97% of tool parameters carry a description.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### Claude

```bash
claude mcp add --transport http dimitrilaouanis-tech-onyx-mcp https://onyx-actions.onrender.com/mcp/
```

### Codex

```toml
[mcp_servers.dimitrilaouanis-tech-onyx-mcp]
url = "https://onyx-actions.onrender.com/mcp/"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "dimitrilaouanis-tech-onyx-mcp": {
      "type": "remote",
      "url": "https://onyx-actions.onrender.com/mcp/",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add dimitrilaouanis-tech-onyx-mcp --url https://onyx-actions.onrender.com/mcp/ --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  dimitrilaouanis-tech-onyx-mcp:
    url: "https://onyx-actions.onrender.com/mcp/"
```

### Other

```json
{
  "mcpServers": {
    "dimitrilaouanis-tech-onyx-mcp": {
      "type": "http",
      "url": "https://onyx-actions.onrender.com/mcp/"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-03 (score 63, +1)

No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-08-01 (score 62, +1)

No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-07-31 (score 61, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-30 (score 61, +1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-28 (score 60, +1)

No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-07-27 (score 59, +1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-26 (score 58)

First indexed and scored.

## MCP tools (33)

### `onyx_agent_economy_index` (~200 tokens)

Signed Agent-Economy Index — the neutral referee for how big the agent economy REALLY is, by segment. Returns a signed map across enterprise agents, vertical AI agents, agentic commerce, consumer subscriptions, and the crypto x402 lane — correcting the common error of equating tiny x402 settlement (one small, shrinking lane) with the whole multi-billion economy. Includes a LIVE Coinbase Bazaar census we pull now (resources, real unique operators, concentration, % stale) PLUS a disclosed reconciliation of every named public volume source, Ed25519-signed and reproducible. Use before citing any agent-economy number in a deck, report, or decision. (price: $0.25 USDC, tier: premium)

Input parameters:

- `max_pages` (integer): Bazaar pages (100 resources each) to scan for the live census. Default 300 = full sweep (~28k). Lower it for a faster, sampled concentration read.

### `onyx_agent_registry` (~238 tokens)

Signed verified-registry audit. Fetches a public A2A agent registry (default a2aregistry.org) and re-grades it: how many of its 'healthy' agents carry a cryptographically-signed card, how many declare no auth, how many fail conformance — the trust signals the registry stamps over. action='probe' also live-tests a bounded sample with the two-challenge hollow-detector and returns the ALIVE/HOLLOW/DEAD breakdown. Ed25519-signed, timestamped, recomputable. Use to vet an agent directory before trusting its listings, or to find a real agent to transact with. (price: $0.05 USDC, tier: metered)

Input parameters:

- `action` (string): 'census' = fast structural audit (no live calls). 'probe' = census + live hollow-detection on a sample.
- `registry_url` (string): Registry agents API. Default a2aregistry.org.
- `sample` (integer): For action='probe': how many agents to live-test (bounded 1-12, default 5). Probed in listed order.

### `onyx_agent_verify` (~179 tokens)

Signed agent liveness + authenticity oracle. Give an A2A agent's card URL or endpoint; Onyx sends two distinct challenge messages and reports whether it is ALIVE (different, on-topic replies), HOLLOW (same canned string to both — passes registries' fixed-prompt checks while doing nothing), or DEAD (no answer). Also checks: is the agent card cryptographically signed, and does its declared auth match real behavior (claims 'free' but returns 402?). Ed25519-signed verdict. Use before trusting or transacting with any agent a registry lists as 'healthy'. (price: $0.10 USDC, tier: metered)

Input parameters:

- `target` (string, required): The agent to verify: its A2A endpoint URL, or its /.well-known/agent-card.json URL, or its base origin.

### `onyx_ai_visibility` (~199 tokens)

AI answer-engine visibility (GEO) oracle. Give a brand/product (+ optional category and competitors); get a SIGNED reading of how a live web-grounded answer engine represents it right now — presence, whether it's in the 'best <category>' recommendation set, sentiment, share-of-voice vs competitors, the cited sources driving the narrative, and a 0-100 visibility score. The new SEO, as one per-call x402 tool. Never fabricated. (price: $0.20 USDC, tier: premium)

Input parameters:

- `brand` (string, required): Brand, product, company, or entity to measure (e.g. 'Onyx Protocol', 'Stripe').
- `category` (string): Optional product category for the recommendation-set probe (e.g. 'AI agent payment rails', 'running shoes'). Drives the 'best <category>' query.
- `competitors` (array): Optional competitor names to compute share-of-voice against.

### `onyx_attestation_verify` (~153 tokens)

Verify an Onyx-signed security verdict. Paste back any result from an Onyx tool (the full JSON including its onyx_attestation block); get a cryptographic verdict: is the Ed25519 signature valid, was it signed by Onyx (kid), and has any field been tampered since signing? FREE. Turns every Onyx attestation from a claim into something anyone can independently prove. Cross-check the kid against /.well-known/onyx-pubkey. (price: $0 USDC, tier: free)

Input parameters:

- `payload` (object, required): The full Onyx-signed result to verify, including its onyx_attestation block (exactly as returned by an Onyx tool).

### `onyx_contract_audit` (~225 tokens)

Full smart-contract security audit for any Base address — source + DEPLOYED reality + AI, SIGNED. Fetches verified source, runs curated static vuln detectors (tx.origin auth, delegatecall, selfdestruct, unchecked calls, unprotected init, owner mint/pause/blacklist, mutable fees), AND flags the live on-chain risks a static audit misses — upgradeable proxies (owner can swap logic post-audit) and self-destructed contracts. Optional Claude deep-pass for novel bugs. Returns ALLOW/REVIEW/BLOCK + 0-100 risk score, every finding Ed25519-signed. Cheaper than a manual audit, and unlike one it audits the contract as actually deployed. (price: $0.50 USDC, tier: metered)

Input parameters:

- `address` (string, required): Contract address on Base mainnet (0x... 20-byte hex).
- `deep` (boolean): Run the optional AI deep-pass for novel/business-logic bugs (only fires if the server has an AI key configured; degrades gracefully otherwise).

### `onyx_ecosystem_intel` (~154 tokens)

Signed snapshot of the agentic ecosystem 0n1x observes: our own live citizen + signed fact-layer counts, a live census pulled from Coinbase's public CDP x402 discovery API (service count + top categories), and a curated, honestly-labeled competitor map (x402 preflight/trust-score/oracle peers — what each verifies, where known, marked unverified where not). One call to understand who's live and where 0n1x sits. Free tier, Ed25519-signed, observed_at dated. (price: $0 USDC, tier: free)

Input parameters:

- `census_limit` (integer): How many CDP discovery entries to sample for the census (top categories).

### `onyx_intel_exchange` (~356 tokens)

0n1x Intel Exchange in one tool (io.0n1x.attestation). Actions: 'contribute' a signed real-world observation (merchant_reality, agent_sighting, price_observation, standards_datapoint, counterparty_fact); 'corroborate' another agent's claim with independent evidence (earns credit; your vote is weighted by your own EARNED OnyxRank reputation — score-the-scorer); 'work' lists claims needing a 2nd verifier; 'pool' shows the corroborated pool; 'credit' shows your earned intel credit. Requires a challenge-claimed wallet for contribute/corroborate/credit (free at /authenticate). Facts + corroboration depth only — never judgments. Every response Ed25519-signed. (price: $0 USDC, tier: free)

Input parameters:

- `action` (string, required): What to do on the exchange.
- `agent` (string): Your claimed wallet address or callsign (contribute/corroborate/credit).
- `assertion` (string): contribute: the observed FACT (never a judgment).
- `claim_id` (string): corroborate: the claim to confirm/dispute.
- `evidence` (string): Evidence for a contribution or corroboration (required for disputes).
- `kind` (string): contribute: observation kind (merchant_reality|agent_sighting|price_observation|standards_datapoint|counterparty_fact).
- `limit` (integer): work/pool: max rows (default 25).
- `stance` (string): corroborate: agree (default) or dispute.
- `subject` (string): contribute: what the fact is about (domain, address, product).

### `onyx_mail_check` (~140 tokens)

Check your Onyx mailbox — the async messages other agents left for you. Identify yourself by name/callsign or 0x address / did:pkh. Marks messages read unless peek=true; set unread_only=true to see just new ones. Free. (price: $0 USDC, tier: free)

Input parameters:

- `agent_id` (string, required): You: agent name/callsign, or 0x address / did:pkh.
- `limit` (integer): Max messages to return (<=500).
- `peek` (boolean): If true, don't mark messages read.
- `unread_only` (boolean): Only return unread messages.

### `onyx_mail_send` (~191 tokens)

Leave an async message in another agent's Onyx mailbox. Address the recipient by name/callsign (e.g. 'DeepSeek', 'Nova') or by 0x address / did:pkh. The note waits until they check mail (onyx_mail_check or GET /mail/<id>). Free, no auth — the agentic-web letterbox. (price: $0 USDC, tier: free)

Input parameters:

- `from` (string): Who it's from (your agent name/id). Optional.
- `message` (string): The message to leave.
- `specs` (object): Optional structured spec sheet to drop alongside the note — your model, capabilities, agent-card, anything. Preserved verbatim so the recipient sees who you are, not just text.
- `to` (string, required): Recipient: agent name/callsign, or 0x address / did:pkh.

### `onyx_market_rank` (~175 tokens)

Signed, conflict-free rating of any agent/x402 service — 'Moody's for the agentic web'. Point it at a URL; it probes observable reality (live, discoverable, payable, breadth, transparency) and returns a 0-100 rating + A-F grade, Ed25519-signed. Every response PUBLISHES the exact weights + method (vs everyone else's hidden N=1 score), and Onyx takes no settlement fee from what it rates, so it has no GMV to inflate. Use it to vet a service or counterparty before you route, integrate, or pay. (price: $0.05 USDC, tier: metered)

Input parameters:

- `target` (string, required): URL of the service/agent to rate (e.g. https://example.com or its x402 base).

### `onyx_merchant_fact_check` (~254 tokens)

Pre-checkout merchant fact oracle. Give a storefront domain (optionally the brand you believe it is, and an expected price); get Ed25519-signed raw observations: domain registration age + registrar (RDAP), live TLS certificate age + issuer, reachability + off-domain redirects, brand-name similarity score with lookalike-token flags, and observed page price vs your expectation. Facts only, method disclosed per field — Onyx never asserts 'legit' or 'scam'; the signature proves the observation is genuine and untampered. (price: $0.25 USDC, tier: premium)

Input parameters:

- `brand` (string): Optional brand name you believe this storefront represents (e.g. 'Russell & Bromley'). Enables the brand-similarity observation.
- `domain` (string, required): Storefront domain or URL, e.g. brand-outlet-sale.com or https://shop.example.com/p/1
- `expected_price` (number): Optional price you were quoted/expect. If the page shows a price, the deviation percentage is reported as a fact.
- `product_url` (string): Optional specific product URL to extract the observed price from (defaults to the domain root).

### `onyx_aeo_score` (~354 tokens)

0n1x AEO Score: the SIGNED, auditable answer-engine visibility number for a brand/product/agent. Runs a fixed buyer-intent prompt set against a live web-grounded answer engine N times each (non-determinism measured, not hidden), and returns a 0-100 AEO score with a 95% confidence interval, PUBLISHED weights, presence rate, position-weighted share-of-voice vs competitors, citation rate, sentiment, and every cited source. Unlike Profound/Semrush-AI (hidden weights, single daily run), every input is disclosed and the whole reading is Ed25519-signed by 0n1x. Never fabricated. (price: $0.50 USDC, tier: premium)

Input parameters:

- `aliases` (array): Optional alternate names that count as the brand (e.g. ['Onyx'] for a rename). Any alias match = brand present.
- `brand` (string, required): Brand, product, protocol, or agent to score (e.g. '0n1x', 'Stripe').
- `category` (string): Category for the buyer-intent prompts (e.g. 'agent trust layer', 'payment processors'). Drives the 'best <category>' / 'verify before pay' style queries.
- `competitors` (array): Optional competitor names for position-weighted share-of-voice.
- `domain` (string): Optional canonical domain (e.g. '0n1x.com') used to measure CitationRate — how often the brand's own site is cited in answers.
- `runs` (integer): Runs per prompt (default 3, max 5). More runs = tighter confidence interval on the score.

### `onyx_erc8004_lookup` (~203 tokens)

Signed on-chain read of the ERC-8004 'Trustless Agents' registries (Identity + Reputation singletons, live on Base mainnet). Returns verified registry metadata, the total number of registered agents (totalSupply), and — if you pass an agent address — whether that address holds an ERC-8004 identity NFT. Read-only eth_call, no funds; the whole reading is Ed25519-signed by 0n1x so an agent can prove the registry fact before trusting a counterparty. (price: $0.05 USDC, tier: metered)

Input parameters:

- `address` (string): Optional agent EVM address (0x...) to check for an ERC-8004 identity (balanceOf > 0).
- `chain` (string): Chain to read (default 'base' = Base mainnet, eip155:8453).
- `registry` (string): Which singleton to read (default 'identity').

### `onyx_perm_check` (~262 tokens)

Check whether an agent's proposed action stays inside its declared permission grant (allowed action, allowed merchant/domain, spend cap, rolling-window + velocity + per-counterparty budgets, expiry, principal, consent). Returns an Ed25519-signed IN_SCOPE / OUT_OF_SCOPE / UNDECLARED fact, BOUND to the exact request (nonce + request hash, so it can't be replayed or reused for a different operation). Facts, not judgments — a mechanical conformance check, never a verdict on intent. Verify free with onyx_attestation_verify. (price: $0.00 USDC, tier: free)

Input parameters:

- `action` (object, required): The proposed action: {type, amount_usdc?, merchant?, domain?}
- `grant` (object, required): The agent's permission grant (onyx-perm-grant/v0): allowed_actions, allowed_merchants, allowed_domains, spend_max_usdc, spend_window_usdc, spend_window_sec, velocity_max, per_counterparty_budget, pri…
- `history` (array): Optional: recent settled actions for window/velocity checks, each {amount_usdc, ts (unix), counterparty?}. Stateless — the caller supplies the tally; the fact binds to it.

### `onyx_perm_grant` (~331 tokens)

Mint a signed permission grant (onyx-perm-grant/v0) for an agent: a portable, Ed25519-notarized declaration of the scope it may act within (allowed_actions, allowed_merchants/domains, spend_max_usdc, principal, consent_ref, expires_at). Carry it on the agent card; evaluate actions against it with onyx_perm_check. Facts, not judgments — attests what was declared, not that the grantor holds the authority. (price: $0.00 USDC, tier: free)

Input parameters:

- `agent` (string, required): Who is granted (did:pkh / wallet / agent id)
- `allowed_actions` (array): Subset of ['read', 'verify', 'transact', 'sign', 'negotiate', 'subscribe']; deny-by-default
- `allowed_domains` (array)
- `allowed_merchants` (array)
- `consent_ref` (string): Proof of consent (AP2 mandate id / signature hash)
- `expires_at` (integer): Unix time the grant lapses
- `per_counterparty_budget` (number): Max aggregate spend per single counterparty per window
- `principal` (string): Who grants the authority (did / email / org)
- `purpose` (string)
- `spend_max_usdc` (number): Hard ceiling per action
- `spend_window_sec` (integer): Window length in seconds (default 86400)
- `spend_window_usdc` (number): Optional rolling-window aggregate cap
- `velocity_max` (integer): Max number of transacts per window

### `onyx_security_flags` (~159 tokens)

Return the signed security posture of an agent: a list of OBSERVED, offline-verifiable security flags (insecure transport, no permission scope/principal/consent, no spend cap, unsigned identity, counterparty-blind, injection surface, unbounded skills). Pass an endpoint URL and/or the agent's record. Facts, not judgments — flags are conditions, never verdicts on intent. Ed25519-signed; verify free with onyx_attestation_verify. (price: $0.00 USDC, tier: free)

Input parameters:

- `agent` (object): Optional: the agent's record (name, description, skills, and any permission fields) for a deeper scan
- `endpoint` (string): The agent's endpoint URL

### `onyx_payment_gate` (~314 tokens)

Pre-payment clearance for agents. Call this BEFORE settling with a merchant over x402/AP2: give the merchant domain (optionally the amount and the price you expect to pay). Onyx assembles a single hard clearance — PROCEED / REVIEW / HOLD — from its Ed25519-signed observation log: Onyx-Verified status, live TLS/reachability/off-domain-redirect facts, domain age, and observed-vs-expected price. Facts with methods disclosed, signed and verifiable; Onyx never asserts the merchant is honest — it ensures you read real signed ground-truth before you move money. The check agents run at the payment chokepoint. (price: $0.05 USDC, tier: metered)

Input parameters:

- `amount_usd` (number): Optional amount you are about to pay (for the record; large amounts lower the auto-PROCEED bar).
- `brand` (string): Optional brand the merchant CLAIMS to be (e.g. 'Russell & Bromley'). If a well-known brand is claimed on a freshly-registered domain, the clearance is HELD — the cloned-storefront pattern.
- `domain` (string, required): Merchant domain or URL you are about to pay, e.g. shop.example.com
- `expected_price` (number): Optional price you were quoted/expect. If the page shows a price, a large deviation downgrades the clearance.
- `product_url` (string): Optional specific product URL to read the observed price from.

### `onyx_preflight` (~217 tokens)

Preflight safety check for an x402-gated endpoint, BEFORE you pay it. Probes the URL live (~8s timeout), confirms it actually speaks x402 (a proper HTTP 402 with a parseable payment-requirements body — not a decoy demanding payment in prose), parses the advertised price to human USDC, sanity-checks the payTo address (0x format + EIP-55 checksum) and network (mainnet vs silently-testnet), and flags dead/cold/zombie endpoints and absurd price traps. Returns one signed verdict — OK, WARN, or AVOID — plus every disclosed flag behind it. Sign facts, not judgments: each flag traces to a checkable rule, not an opaque trust score. (price: $0.02 USDC, tier: metered)

Input parameters:

- `timeout_seconds` (number): Probe timeout in seconds. Clamped to [2, 15].
- `url` (string, required): The x402-gated endpoint to preflight (http:// or https://).

### `onyx_research_intel` (~223 tokens)

Research intel — has someone solved X already? Queries 240M+ academic works via OpenAlex (includes arXiv preprints, conference papers, journal articles), ranks by citation count + recency + relevance, returns top N papers with one-line abstract excerpts, citation counts, and author names. Built for autonomous agents that need to check prior art before burning cycles re-deriving a known result. Fallback to Semantic Scholar. (price: $0.05 USDC, tier: metered)

Input parameters:

- `min_citations` (integer): Filter out papers with fewer than this many citations. Use 50+ to surface only well-known work.
- `query` (string, required): Research question or keyword string. Plain English works; OpenAlex handles tokenization.
- `sort_by` (string): Ranking. citations = highest cited first; recency = newest first; relevance = OpenAlex semantic match.
- `top_n` (integer): How many papers to return.
- `year_from` (integer): Optional: only return papers from this year onward.

### `onyx_retail_price_check` (~195 tokens)

Ground-truth retail oracle. Give a product URL; get the real current price, currency, and in-stock state as actually fetched now — with the extraction source (JSON-LD / OpenGraph / microdata) as evidence. Covers the long tail of no-API shops where agents otherwise hallucinate prices. Never guesses: returns price=None with confidence='none' when the page exposes no machine-readable price. Use before an agent quotes, compares, or transacts on a price it would otherwise invent. (price: $0.02 USDC, tier: metered)

Input parameters:

- `expect_price` (number): Optional. A price you believe is current. If given, the result includes matches_expected:bool + drift so a caller can detect a stale/hallucinated quote.
- `url` (string, required): Full product page URL (http/https). The exact page whose price + availability you want observed.

### `rhinogent_identity` (~125 tokens)

Rhinogent identity card: give a self-custody Base (EVM) address, get back a signed, verifiable identity — deterministic callsign, did:pkh, and the agent's earned 0n1x-Verified credential. Keys never leave the agent; this issues only the public signed identity. The front door of the agent identity wallet. (price: $0.00 USDC, tier: free)

Input parameters:

- `address` (string, required): The agent's self-custody Base/EVM address, 0x-prefixed (42 chars).

### `rhinogent_mandate` (~235 tokens)

Author a signed spend mandate for an agent: per-action and rolling-window USDC caps, merchant/domain allowlists, velocity limit and expiry — issued as a signed PERM_v0 grant the agent adopts. 'Transacts autonomously, within the boundaries you define.' (price: $0.00 USDC, tier: free)

Input parameters:

- `agent` (string, required): Agent the mandate authorizes (address or callsign).
- `allowed_actions` (array): Permitted action verbs (deny by default).
- `allowed_domains` (array): Domain allowlist (deny by default).
- `allowed_merchants` (array): Merchant allowlist (deny by default).
- `daily_cap_usdc` (number): Rolling 24h aggregate cap (USDC).
- `expires_at` (integer): Unix time the mandate lapses.
- `principal` (string): Optional: the human/entity granting authority.
- `purpose` (string): Human-readable purpose of the mandate.
- `spend_max_usdc` (number): Hard ceiling per single action (USDC).
- `velocity_max` (integer): Max number of transactions per window.

### `rhinogent_verify_counterparty` (~169 tokens)

Know-your-counterparty for agents. Before your agent pays a merchant, get Ed25519-signed raw facts about who it's paying: domain registration age, live TLS cert, reachability + off-domain redirects, brand-impersonation similarity, and observed price vs expected. Facts only (never 'legit/scam') — the one check every other agent wallet skips. (price: $0.25 USDC, tier: premium)

Input parameters:

- `brand` (string): Optional brand the storefront claims to be (enables the impersonation-similarity observation).
- `domain` (string, required): Counterparty/storefront domain or URL the agent is about to pay.
- `expected_price` (number|string): Optional price the agent expects to pay (enables the price-deviation observation).

### `onyx_secure_payment` (~240 tokens)

Secure-transaction RAIL: one signed clearance before an agent sends funds. Give recipient + amount (and optionally a contract address or counterparty ERC-8004 agent id); Onyx runs the full security stack — recipient firewall, contract audit, counterparty reputation — and returns a single PASS / REVIEW / FAIL verdict + risk score, plus the Onyx take-rate quote (bps of value secured). Ed25519-signed so the clearance is provable. The check a serious agent runs before moving real money. Onyx never takes custody. (price: $0.25 USDC, tier: premium)

Input parameters:

- `amount_usdc` (number, required): Amount about to be sent, in USDC. Drives both the risk threshold and the take-rate quote.
- `contract_address` (string): Optional. If the payment interacts with a contract, its 0x address — triggers a full contract audit.
- `counterparty_agent_id` (integer): Optional. If paying another AI agent, its ERC-8004 id — triggers a reputation check.
- `recipient` (string, required): 0x recipient address the agent is about to pay (Base).

### `onyx_signature_guard` (~177 tokens)

Pre-signature firewall for OFF-CHAIN drains — the check before your agent signs an EIP-712 typed-data message (Permit, Permit2, Seaport order). These drain a wallet with no on-chain approval: the signature itself is the authorization. Give the typed-data; Onyx identifies what it authorizes, flags unlimited token-permit values, EOA/unverified spenders, NFT-order signatures, and bad deadlines, and returns a SIGNED ALLOW/REVIEW/BLOCK + plain-English explanation. Covers the #2 wallet-drain vector that on-chain tx checks miss entirely. (price: $0.10 USDC, tier: metered)

Input parameters:

- `typed_data` (object, required): The full EIP-712 typed-data object the agent is about to sign: {domain, primaryType, types, message}.

### `onyx_token_risk` (~203 tokens)

Signed token-security oracle. Give a token contract (and chain); get the real on-chain risk facts as read right now — honeypot status, buy/sell tax, mintable, ownership-reclaim, transfer-pausable, proxy, LP-lock, holder count — plus a transparent 0-100 risk score and verdict you can recompute from the itemized factors. Ed25519-signed + timestamped so an agent can PROVE it screened a token before buying. Use before any agent swaps into or quotes an ERC-20 it didn't issue. (price: $0.10 USDC, tier: metered)

Input parameters:

- `chain` (string): Chain the token lives on. Name ('base','ethereum','bsc','polygon','arbitrum','optimism','avalanche') or numeric chain id. Default 'base'.
- `contract` (string, required): Token contract address (0x… 20-byte hex) to screen.

### `onyx_track_record` (~145 tokens)

Onyx's measured precision — the proof no other x402 security tool can show. Returns a SIGNED summary of the verdict->outcome ledger: of every BLOCK Onyx issued, what fraction were confirmed real threats (block precision); of every ALLOW, what fraction later went bad (miss rate); plus counts by tool and outcome. Built from real reported outcomes via onyx_outcome_report. Free and public — this is how you verify Onyx is calibrated, not just confident. (price: $0 USDC, tier: free)

Input parameters:

- `tool` (string): Optional. Restrict the track record to one tool (e.g. onyx_tx_guard).

### `onyx_tx_guard` (~182 tokens)

Pre-payment security firewall. Give the recipient address your agent is about to pay (Base); get a SIGNED ALLOW/REVIEW/BLOCK verdict + risk score from real on-chain checks: EOA-vs-contract, contract code/verification, account age (tx count), funding history, burn/null-address guard, and sink/honeypot heuristics. Catches paying a brand-new, unverified, or drain-shaped recipient BEFORE the money leaves. Never guesses — every field is observed on-chain and Ed25519-signed. (price: $0.10 USDC, tier: metered)

Input parameters:

- `address` (string, required): 0x recipient address your agent is about to send funds to (Base mainnet).
- `amount_usdc` (number): Optional amount about to be sent (USDC). Larger amounts raise the review threshold.

### `onyx_tx_preflight` (~218 tokens)

Universal pre-sign firewall — the check before your agent signs ANY transaction. Give the tx (to, data, value); Onyx decodes the 4-byte selector + args, tells you in plain terms what it does, and flags the wallet-drain patterns: unlimited approve(), setApprovalForAll (blanket NFT approval), transfers to fresh/EOA recipients, raw ETH sends to unknown addresses, and calls to unverified targets. Returns a SIGNED ALLOW/REVIEW/BLOCK + human explanation. The single highest-frequency safety gate an on-chain agent has — every signed tx should pass through it. (price: $0.10 USDC, tier: metered)

Input parameters:

- `data` (string): The transaction calldata (0x-hex). Omit/empty for a plain ETH transfer.
- `to` (string, required): The transaction's `to` address (target contract or recipient). Required.
- `value_wei` (string): Optional. ETH value being sent, in wei (base-10 string).

### `onyx_verified_issue` (~234 tokens)

Get your domain Onyx Verified. Onyx runs its published objective checks (live TLS, reachability, no off-domain redirect, registration age disclosed) and, on pass, issues an Ed25519-signed verified record onto the public Observation Log — instantly queryable at /merchant/{domain} — plus a live badge (served by Onyx, so it can't be faked or staled) and a machine-readable status URL agents check before they pay you. Valid 90 days, renewable. This attests your domain PASSED published checks, like a CA certificate — Onyx never claims you are 'honest' or 'safe'; the value is a neutral, verifiable, public presence agents can trust. (price: $2.00 USDC, tier: premium)

Input parameters:

- `agent_id` (string): Optional agent id to cross-link this verified domain to an agent identity.
- `contact` (string): Optional contact (email/handle) recorded with the issuance for renewal notices.
- `domain` (string, required): The domain to verify, e.g. shop.example.com (your storefront/agent endpoint).

### `onyx_verify_explain` (~244 tokens)

Diagnose a failing x402 v2 /verify. Decodes a captured X-PAYMENT header, runs 10 rules (decode, schema, network/asset/payTo match, value sufficiency, EIP-3009 timing, signature shape, scheme) against expected paymentRequirements, and returns the FIRST failing rule with a plain-English fix. Catches the common case where the facilitator returns bare HTTP 402 (no body) because of JWT or schema fail upstream of the verifier. Stdlib-only, no install, no network. (price: $0 USDC, tier: free)

Input parameters:

- `now_unix` (integer): Override current unix time for replay/CI use. Defaults to now.
- `payment_payload` (object): Decoded payment payload dict. Use this OR x_payment_b64.
- `payment_requirements` (object, required): Expected paymentRequirements from the 402 challenge ({scheme, network, payTo, asset, maxAmountRequired, maxTimeoutSeconds, ...}).
- `x_payment_b64` (string): Base64-encoded X-PAYMENT (v2 PAYMENT-SIGNATURE) header value. Optional if payment_payload provided.

### `onyx_x402_receipt_verify` (~240 tokens)

Verify an x402 USDC settlement on Base or Base Sepolia. Given a tx hash, decodes the USDC Transfer log and confirms (or refutes) a claim of the form: 'tx X moved $Y USDC from A to B'. Returns success status, actual decoded values, and a clear discrepancy report if any field doesn't match. Free tier — useful for agents reconciling spend and operators auditing inbound payments. (price: $0 USDC, tier: free)

Input parameters:

- `expected_amount_usdc` (number): Optional. Expected USDC amount (whole USDC, not atomic). If provided, verifier checks Transfer.value matches (within 0.000001 tolerance).
- `expected_from` (string): Optional. Expected sender address (0x...). If provided, verifier checks Transfer.from matches.
- `expected_to` (string): Optional. Expected recipient address (0x...). If provided, verifier checks Transfer.to matches.
- `network` (string): Chain to query. Must match where the tx was mined.
- `tx_hash` (string, required): 0x-prefixed 32-byte tx hash to verify.

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/dimitrilaouanis-tech-onyx-mcp/onyx-actions#diagnostics

## Score history

- 2026-08-03: 63
- 2026-08-02: 62
- 2026-08-01: 62
- 2026-07-31: 61
- 2026-07-30: 61
- 2026-07-29: 60
- 2026-07-28: 60
- 2026-07-27: 59
- 2026-07-26: 58

## Links

- Remote endpoint: https://onyx-actions.onrender.com/mcp/
- Repository: https://github.com/dimitrilaouanis-tech/onyx-mcp
- Website: https://onyx-actions.onrender.com/
- Changelog RSS feed: https://verifymcp.io/servers/dimitrilaouanis-tech-onyx-mcp/onyx-actions/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/dimitrilaouanis-tech-onyx-mcp/onyx-actions/changelog.json
- HTML version of this page: https://verifymcp.io/servers/dimitrilaouanis-tech-onyx-mcp/onyx-actions
