Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

io.github.epistemedeus/x402-data-gateway

REMOTE · AGENTS.SAMEDAYDESK.COM · SCANNED OCT 4

Paid x402 and MPP tools for agent discovery, payment safety, data, and DeFi.

0 this week 77 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security57
Transport & Reachability100
Schema Quality & AI Usability68
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 4776 tokens (~191/item across 25 items; 25 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
  • No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
  • Structured output schemas are declared (56% of tools); any adoption earns full credit.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • We read all 25 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
  • An AI judge read all 25 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

How do I install the io.github.epistemedeus/x402-data-gateway MCP server?

io.github.epistemedeus/x402-data-gateway is a hosted endpoint at https://agents.samedaydesk.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · agents.samedaydesk.com

# add to Claude Code
claude mcp add --transport http epistemedeus-x402-data-gateway 'https://agents.samedaydesk.com/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "epistemedeus-x402-data-gateway": {
      "url": "https://agents.samedaydesk.com/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "epistemedeus-x402-data-gateway": {
      "type": "http",
      "url": "https://agents.samedaydesk.com/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.epistemedeus-x402-data-gateway]
url = "https://agents.samedaydesk.com/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "epistemedeus-x402-data-gateway": {
      "type": "remote",
      "url": "https://agents.samedaydesk.com/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add epistemedeus-x402-data-gateway --url 'https://agents.samedaydesk.com/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  epistemedeus-x402-data-gateway:
    url: "https://agents.samedaydesk.com/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "epistemedeus-x402-data-gateway": {
      "Transport": "http",
      "Url": "https://agents.samedaydesk.com/mcp"
    }
  }
}
# add to Vellum
assistant mcp add epistemedeus-x402-data-gateway -t streamable-http -u 'https://agents.samedaydesk.com/mcp'
// mcp.json
{
  "mcpServers": {
    "epistemedeus-x402-data-gateway": {
      "type": "http",
      "url": "https://agents.samedaydesk.com/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 28 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 25 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 24 Sept 26 0
    • New tool “page_change” functional
  • 13 Sept 26 +11
    • Judged manipulation: unverified → pass ▲ security
    • Schema quality: unverified → excellent ▲ functional
  • 12 Sept 26 −11
    • Judged manipulation: pass → unverified ▼ security
    • Schema quality: excellent → unverified ▼ functional
    • Server version: 1.23.46 → 1.23.49 functional
    • New tool “lockfile_pin_delta” functional
  • 10 Sept 26 0
    • Tool coverage: 52% → 57% ▲ functional
    • Tool “read” now declares an output schema ▲ functional
    • Server version: 1.23.45 → 1.23.46 functional
    • “extract” reworded the description of “url” cosmetic
    • “read” reworded the description of “url” cosmetic
  • 8 Sept 26 0
    • Stability: 0.97 → pass security
    • Server version: 1.23.44 → 1.23.45 functional
  • 7 Sept 26 +1
    • Tool coverage: 45% → 52% ▲ functional
    • Tool coverage: 45% → 50% ▲ functional
    • Tool “extract” now declares an output schema ▲ functional
    • Server version: 1.23.43 → 1.23.44 functional
    • Server version: 1.23.40 → 1.23.43 functional
    • New tool “extract_batch” functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 4 Oct 2026 · Probed https://agents.samedaydesk.com/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=agents.samedaydesk.com CN=YE1,O=Let's Encrypt,C=US 8 Aug 2026 6 Nov 2026 ECDSA 256 ECDSA-SHA384 6e161b2ed50c5cc8f41c850c1ef098d4dfc
SANs: agents.samedaydesk.com
CN=YE1,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 5ddd70dd31f801c85c186a7a04b80afe
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of agents.samedaydesk.com. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
samedaydesk.com. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://agents.samedaydesk.com/mcp Verified 200
http (plaintext) http://agents.samedaydesk.com/mcp HTTPS enforced 301 https://agents.samedaydesk.com/mcp
MCP tools · 25 exposed · ~4,776 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
agent_discoverability_audit ~391

Measure one service's brand-blind rank, source-family coverage, expected-route presence, canonical-vs-alias listing identity, duplicate records, competitors, and exact-price drift across ten public machine-service discovery views. Supply `runtimeUrl` with an exact GET route to derive the comparison price from one coherent live unsigned x402 or MPP offer; otherwise `expectedPriceUsd` remains caller-supplied. Set `surfaceAudit` to check the target's public Agent Card, ERC-8004 registration document, and action catalog. Set `materializationAudit` with an exact GET or POST route to distinguish Coinbase seller ineligibility from provider acceptance without exact-resource Bazaar materialization. Catalog queries use no credentials or payments. Results are point-in-time provider and catalog evidence, not demand, seller trust, settlement, or future-rank proof.

NameTypeReqDescription
expectedPriceUsd––Optional exact route price expected by the caller. A coherent runtimeUrl offer takes precedence and caller drift is reported.
intentstringyesBrand-blind capability description
materializationAuditboolean–When true with route and method, distinguish Coinbase seller ineligibility from provider acceptance without exact-resource Bazaar materialization.
methodstring–Exact route method for the optional Coinbase materialization audit. Defaults to GET; runtimeUrl is GET-only.
originstringyesPublic HTTPS service origin
payTostring–Optional EVM payTo for alias matching
routestring–Optional expected exact path
runtimeUrlstring–Optional exact same-origin HTTPS GET URL whose unpaid x402 or MPP offer supplies the runtime price reference. Requires route and an exactly matching pathname.
surfaceAuditboolean–When true, inspect the target's public Agent Card, ERC-8004 registration document, and action catalog for the expected route through bounded same-origin fetches.

No output schema declared.

No examples provided.

agent_surface_budget_audit ~251

Measure one public service's credential-free MCP tools/list, OpenAPI, or both declared discovery surfaces before any tool call or target payment. Use `agent_discoverability_audit` for catalog reach and rank, `seller_integrity_audit` for one exact operation's response contract, or this tool for byte budgets, heaviest definitions, missing selection contracts, and progressive-discovery fixes. Unselected surfaces are not fetched or judged. It follows no redirect, calls no target tool, sends no credential or target payment, and returns no target schema, response body, or session identifier.

NameTypeReqDescription
mcpBudgetBytesinteger–Maximum preferred raw MCP tools/list response size in bytes.
mcpPathstring–Exact root-relative MCP streamable-HTTP path.
openApiBudgetBytesinteger–Maximum preferred raw OpenAPI document size in bytes.
openApiPathstring–Exact root-relative OpenAPI JSON path.
originstringyesCredential-free public HTTPS service origin on port 443, with no path or query.
surfaceModestring–Audit MCP only, OpenAPI only, or both. Unselected surfaces are not fetched or judged.
NameTypeReqDescription
actionsarrayyes–
boundaryobjectyes–
checkedAtstringyes–
decisionstringyes–
mcp–yes–
okbooleanyes–
openapi–yes–
productstringyes–
requestobjectyes–
versionstringyes–

No examples provided.

contract_qualified_search ~226

Search Agent402 and the official MPP catalog for paid machine services that both match a capability intent and guarantee buyer-required JSON response paths. Use `agent_discoverability_audit` when you are measuring one known seller's catalog reach or rank, `seller_integrity_audit` when you already know the exact seller route to inspect, or `payment_offer_preflight` when you already have one exact callable GET URL. This search excludes SameDayDesk-owned supply and unresolved routes before audit, uses no credential or wallet, sends no seller POST or target payment, reads no paid response body, and returns only a query digest.

NameTypeReqDescription
limitinteger–Maximum candidates audited and returned across Agent402 and MPP.
maxPriceDisplayUnitsnumber–Maximum advertised per-call price in each source's display currency.
querystringyesCapability intent sent to Agent402 and used locally to rank MPP catalog metadata. Do not include credentials or private values.
requiredPathsarrayyesBuyer-required dotted success-response paths that every returned seller schema must guarantee recursively.
NameTypeReqDescription
boundaryobjectyes–
checkedAtstringyes–
decisionstringyes–
okbooleanyes–
productstringyes–
qualifiedarrayyes–
rejectedarrayyes–
requestobjectyes–
sourcesobjectyes–
versionstringyes–

No examples provided.

deep_audit ~187

Run one read-only AI-search-readiness audit for a public business domain: company, technology, contact, and DNS/email evidence from `enrich`, plus the live structured-data gap analysis and paste-ready JSON-LD template from `schemaforge`. Use `enrich` for company facts only or `schemaforge` for structured-data remediation only. The template contains placeholders for real data; the score is diagnostic, no site changes are made, and it does not guarantee AI citations.

NameTypeReqDescription
citystring–Optional city the business serves; used only to contextualize the generated structured-data template.
domainstringyesPublic business domain or URL. The hostname is normalized and the audit starts at its HTTPS homepage; any supplied path or query is ignored.
verticalstring–Optional structured-data template profile. med-spas is currently specialized; unsupported values fall back to it.

No output schema declared.

No examples provided.

enrich ~110

Inspect a public company domain and return structured identity, technology, social, contact, DNS, email-infrastructure, and AI-readiness evidence. Use `schemaforge` instead for a paste-ready JSON-LD template and remediation diff, or `deep_audit` when both outputs are required together. Public data only; this tool makes no site changes.

NameTypeReqDescription
domainstringyesPublic company domain or URL, for example stripe.com. Use enrich for company evidence; use wallet_enrich for an EVM address.

No output schema declared.

No examples provided.

extract ~161

Fetch a public HTTP(S) page and return compact extraction signals for programmatic inspection: title, meta description, Open Graph/Twitter metadata, JSON-LD, headings, links, text excerpt, and AI-readiness flags. Use `read` instead when you need the page body as LLM-ready Markdown rather than metadata or a link inventory. Does not execute JavaScript; follows redirects and applies SSRF, timeout, and response-size guards.

NameTypeReqDescription
urlstringyesPublic HTTP(S) URL. Choose extract for metadata, JSON-LD, headings, links, and a bounded text excerpt; use read for longer bounded Markdown. Content is fetched without JavaScript rendering. Check sta…
NameTypeReqDescription
aiReadinessobjectyes–
canonicalstring|nullyes–
captureobjectyes–
contentTypestring|nullyes–
descriptionstring|nullyes–
error–yes–
fetchedAtstringyes–
finalUrlstringyes–
headingsobjectyes–
jsonLdarrayyes–
langstring|nullyes–
linksarrayyes–
okbooleanyes–
openGraphobjectyes–
requestedUrlstringyes–
sourceOkbooleanyes–
statusintegeryes–
textstringyes–
titlestringyes–
twitterobjectyes–
urlstringyes–

No examples provided.

extract_batch ~175

Fetch one to five public HTTPS URLs and return bounded structured fields for each source in one paid attempt. Supply `urls` as a JSON array and optional unique `fields`. Use `extract` for a single URL when you do not need batch accounting. Charge is one flat introductory 0.01 USDC quote for the bounded attempt, not a guarantee that every URL succeeds. Automatic retries are disabled; unknown outcomes must not be re-paid automatically. Payment challenge and credentials are bound to https://agents.samedaydesk.com/extract/batch, not mcp://. Retry the identical authorized arguments and credential.

NameTypeReqDescription
fieldsarray–Optional unique bounded subset of structured extraction fields.
urlsarrayyesOne to five public HTTPS URLs as a JSON array. Charge is one flat introductory attempt, not per-URL success.
NameTypeReqDescription
accountingobjectyes–
boundaryobjectyes–
chargedbooleanyes–
costInputsobjectyes–
errorstring––
jobIdstringyes–
jobStatusstringyes–
okbooleanyes–
partialbooleanyes–
productstringyes–
quoteobjectyes–
schemaVersionstringyes–
sourcesarrayyes–
stopReasonstring|nullyes–

No examples provided.

lockfile_pin_delta ~234

Inspect two caller-supplied npm package-lock.json objects and return added, removed, and changed name+version+integrity+resolved pins. Supply JSON `before` and `after` lockfile objects, not filesystem paths, URLs, or commands. An identical pin set is informational, not a failure. HTML, package.json, and unsupported lockfileVersion values are refused before payment. This is not an npm install, audit, or purchase. Ordinary wallets sign through examples/customer-x402 (inspect, explicit approve, attempt-receipt, read-only reconcile), not a precomputed signature. Initial live release accepts x402 only. Payment challenge and credentials are bound to https://agents.samedaydesk.com/lockfile-pin-delta, not mcp://. Retry the identical authorized arguments and credential.

NameTypeReqDescription
afterobjectyesnpm package-lock.json object (lockfileVersion 2 or 3). Not a filesystem path, URL, or command.
beforeobjectyesnpm package-lock.json object (lockfileVersion 2 or 3). Not a filesystem path, URL, or command.
NameTypeReqDescription
analysisstringyes–
boundaryobjectyes–
chargedbooleanyes–
costInputsobjectyes–
digeststring|nullyes–
engine–yes–
engineProvenanceobjectyes–
errorstring––
limitsobjectyes–
markdownstring|null––
markdownOmittedboolean––
okbooleanyes–
owedDeliveryboolean––
productstringyes–
quoteobjectyes–
schemaVersionstringyes–
transportstringyes–

No examples provided.

morpho_market_underwrite ~133

Underwrite one Base Morpho market with independent GraphQL, REST, and direct-RPC evidence for configuration integrity, liquidity, utilization, concentration, borrower health bands, recent history, bad debt, and PreLiquidation availability. Use `morpho_position` or `morpho_protection` for one borrower's current position or protection plan, and `morpho_preliquidation_replay` for the economics of one completed historical event. Read-only evidence with explicit disagreements; no opaque risk score or transaction action.

NameTypeReqDescription
marketIdstringyesMorpho market ID on Base mainnet

No output schema declared.

No examples provided.

morpho_position ~142

Inspect one Base borrower across Morpho markets and return position balances, LTV, health factor, liquidation headroom, direct-RPC verification, and caller-selected collateral-price stress scenarios. Use `morpho_protection` when you need exact repay or add-collateral amounts and unsigned transaction templates, `morpho_market_underwrite` for market-wide risk, or `morpho_preliquidation_replay` for one completed historical event. Read-only; no wallet, signing, broadcast, or custody.

NameTypeReqDescription
addressstringyesBorrower EVM address on Base mainnet
shocksarray–Collateral price shocks in percent

No output schema declared.

No examples provided.

morpho_preliquidation_replay ~135

Reconstruct one successful Base Morpho PreLiquidation transaction from its receipt and the exact block state, returning repaid and seized assets, protocol-oracle valuation, gross incentive, configured health window, and transaction gas before off-chain costs. Use `morpho_market_underwrite` for current market risk, `morpho_position` for a current borrower, or `morpho_protection` for a future protection plan. Historical read-only evidence; no transaction simulation, wallet, signing, or broadcast.

NameTypeReqDescription
transactionHashstringyesSuccessful Base transaction containing a Morpho PreLiquidate event
NameTypeReqDescription
boundarystringyes–
chainobjectyes–
eventCountintegeryes–
eventsarrayyes–
okbooleanyes–
productstringyes–
transactionobjectyes–
verificationobjectyes–
versionstringyes–

No examples provided.

morpho_protection ~242

Calculate two alternative protection plans for one Base Morpho borrower under a selected collateral-price shock and target health factor: partial repayment or added collateral. Each plan includes the bounded asset amount, expected stressed health factor, evidence basis, and unsigned ERC-20 approval plus Morpho call templates. Use `morpho_position` for diagnosis without an action plan, `morpho_market_underwrite` for market-wide risk, or `morpho_preliquidation_replay` for a completed historical event. Read-only; no wallet, signing, broadcast, or custody.

NameTypeReqDescription
addressstringyesBorrower EVM address on Base mainnet.
executionBufferBpsinteger–Additional repayment or collateral amount buffer in basis points for debt accrual and integer rounding; 25 means 0.25%.
protectAgainstShockPctnumber–Collateral-price shock percentage to withstand, from -99 through 0; for example -10 models a 10% price decline.
targetHealthFactornumber–Target Morpho health factor after the selected collateral-price shock; must be greater than 1 and at most 5.
NameTypeReqDescription
actionableCountintegeryes–
addressstringyes–
boundarystringyes–
chainobjectyes–
fetchedAtstringyes–
inputsobjectyes–
invariantsobjectyes–
latestIndexedAt–yes–
okbooleanyes–
positionCountintegeryes–
productstringyes–
quotesarrayyes–
sourceobjectyes–
unverifiedCountintegeryes–
versionstringyes–

No examples provided.

opportunity_preflight ~369

Agent work opportunity -> deterministic attempt, verify-first, or abandon preflight using caller-supplied cost and selection assumptions plus dated platform evidence. Returns break-even probability, expected surplus, hard gates, and source-linked evidence. No claim, bid, payment, or submission.

NameTypeReqDescription
acceptancestring–How completion is accepted: deterministic proof, machine score, review deadline, discretionary judgment, or unknown.
agentAccessstring–Whether the platform explicitly allows agent participation, is agent-only, mixes agents and humans, is human-only, or remains unknown.
competitioninteger–Known number of competing submissions or workers; use 0 when unknown.
computeUsdnumber–Expected model, API, hosting, and compute spend in USD for one attempt.
hourlyCostUsdnumberyesInternal opportunity cost per hour in USD.
hoursnumberyesEstimated human and agent work time in hours for one complete attempt.
mandatorySpendUsdnumber–Non-recoverable cash spend in USD required before the opportunity can settle.
platformstring–Optional platform slug used to attach dated platform-health evidence when a matching card exists.
reusableValueUsdnumber–Conservative USD value of reusable code, research, distribution, or other assets created by the attempt.
rewardUsdnumberyesMaximum gross reward in USD if the opportunity is selected and paid.
selectionProbabilityPctnumber–Caller-supplied probability, from 0 to 100, of receiving the reward; omit to receive a verify-first decision.
settlementstring–How the reward is funded and paid: direct, escrow, platform balance, discretionary, unfunded, or unknown.
slotsinteger–Number of independently paid winner or worker slots.
NameTypeReqDescription
boundarystringyes–
decisionstringyes–
economicsobjectyes–
gatesobjectyes–
inputobjectyes–
okbooleanyes–
platformEvidence–yes–
productstringyes–
versionstringyes–

No examples provided.

page_change ~113

Compare two already-held extract-batch JSON artifacts on caller-named fields. This tool is free: charged is false, it does not fetch, and it does not accept payment. Use extract_batch when you still need a paid observation. Do not add a second paid diff.

NameTypeReqDescription
afterobjectyesAlready delivered batch JSON object. Not a URL or filesystem path.
beforeobjectyesAlready delivered batch JSON object. Not a URL or filesystem path.
fieldsarrayyesExplicit field names to compare.

No output schema declared.

No examples provided.

payment_offer_preflight ~245

Compare x402 and MPP payment challenges, terms, and seller-declared JSON success-response readiness for one exact public HTTPS GET route before buyer authorization, including URL and realm binding, expiry, cross-protocol economic parity, and exact-route OpenAPI evidence. Use `agent_discoverability_audit` instead when you need to know whether catalogs rank or expose a service. This tool uses no target credential, signature, or target payment, follows no redirect, never reads the paid target body, and reads only the same-origin public OpenAPI document under a strict size cap. A seller declaration is advisory and does not establish runtime validity, seller trust, utility, or settlement reliability.

NameTypeReqDescription
catalogobject–Optional caller-supplied catalog candidate. When present, the tool compares it with every live unsigned offer across request, protocol, amount, network, asset, recipient, and expiry.
urlstringyesExact public HTTPS GET route whose unpaid x402 and MPP challenge headers and same-origin OpenAPI success-response declaration should be inspected before buyer authorization. Credential-like query key…
NameTypeReqDescription
boundaryobjectyes–
catalogCoherencearrayyes–
checkedAtstringyes–
decisionstringyes–
findingsarrayyes–
offerCountintegeryes–
offersarrayyes–
okbooleanyes–
parityobjectyes–
productstringyes–
protocolsarrayyes–
responseContractobjectyes–
responseContractAcquisitionobjectyes–
targetobjectyes–
versionstringyes–

No examples provided.

read ~150

Fetch a public HTTP(S) page and return its readable body as cleaned Markdown for LLM context, preserving headings, links, and lists while dropping navigation, ads, scripts, headers, footers, asides, and forms. Use `extract` instead when you need metadata, JSON-LD, Open Graph/Twitter tags, or a link inventory. Markdown is capped at 40,000 characters and no JavaScript is executed.

NameTypeReqDescription
urlstringyesPublic HTTP(S) URL whose readable body is needed as Markdown. Content is fetched without JavaScript rendering and may be truncated at 40,000 characters. Check status/sourceOk/error/truncated/capture;…
NameTypeReqDescription
captureobjectyes–
error–yes–
fetchedAtstringyes–
finalUrlstringyes–
markdownstringyes–
okbooleanyes–
requestedUrlstringyes–
sourceOkbooleanyes–
statusintegeryes–
titlestringyes–
truncatedbooleanyes–
urlstringyes–
wordCountintegeryes–

No examples provided.

scan ~71

Static supply-chain security scan of a public GitHub repo before an agent installs/runs it. Flags exfil sinks, obfuscation, credential reads, install-time curl|bash. risk=clean|suspicious|dangerous.

NameTypeReqDescription
repostringyesPublic GitHub repo: owner/name or URL
NameTypeReqDescription
branchstringyes–
disclaimerstringyes–
filesScannedintegeryes–
findingsarrayyes–
okbooleanyes–
repostringyes–
riskstringyes–
scannedAtstringyes–
summarystringyes–

No examples provided.

schemaforge ~165

Analyze a public business site and return a deterministic, paste-ready JSON-LD template plus the live structured-data gap diff and ranked fixes. Use `deep_audit` instead when the same call must also return company, technology, contact, and DNS/email evidence. Generated markup contains placeholders that must be replaced with real business values; this tool makes no site changes and does not guarantee AI citations.

NameTypeReqDescription
citystring–Optional city the business serves; used to contextualize the generated structured-data template.
sitestringyesPublic business homepage or representative landing-page URL. Live HTML must be directly fetchable; JavaScript is not executed.
verticalstring–Optional structured-data template profile. med-spas is currently the specialized profile; unsupported values fall back to it.

No output schema declared.

No examples provided.

seller_integrity_audit ~283

Use this after a buyer integration fails, a seller changes a paid route, or before the next paid retry or release. Audit one exact paid GET or POST seller route against buyer-required JSON success paths. GET verifies constructible non-secret input, exact request binding, live x402 and MPP economics, and optional Bazaar eligibility; POST performs static-safe OpenAPI contract analysis and sends no target request. Use `payment_offer_preflight` instead when you already have one exact callable GET URL and only need its current unpaid offer before buyer authorization, or `agent_discoverability_audit` for catalog rank and identity. Uses no target credential, signature, or target payment and retains no seller schema, body, or query values.

NameTypeReqDescription
methodstring–POST receives static OpenAPI response-contract analysis without sending a target request.
originstringyesCredential-free public HTTPS seller origin on port 443.
referralstring–Optional x402 receipt-derived acquisition label. It cannot change payment or delivery.
requireBazaarboolean–When true, missing Bazaar discovery metadata becomes a repair finding for live-probed GET routes.
requiredPathsarray–Buyer-required dotted success-response paths that the seller schema must guarantee recursively.
routestringyesExact paid GET or POST path declared by the seller, without query or template parameters.

No output schema declared.

No examples provided.

settlement_proof ~158

Verify one claimed canonical Base USDC settlement after execution by matching a successful transaction receipt to the exact recipient, atomic amount, and optional payer. Use `payment_offer_preflight` before authorization when you need to inspect an unpaid x402 or MPP offer instead. This tool reads only public Base receipt and log data; it reads no merchant ledger and performs no wallet, signing, broadcast, custody, or execution action.

NameTypeReqDescription
amountAtomicstringyesExpected positive USDC amount in six-decimal atomic units.
payerstring–Optional expected canonical Base USDC payer.
recipientstringyesExpected canonical Base USDC recipient.
transactionHashstringyesBase mainnet transaction hash containing the claimed canonical USDC transfer.
NameTypeReqDescription
assetobjectyes–
boundaryobjectyes–
chainobjectyes–
checkedAtstringyes–
decisionstringyes–
findingsarrayyes–
okbooleanyes–
productstringyes–
requestobjectyes–
settlementobjectyes–
transactionobjectyes–
versionstringyes–

No examples provided.

solana_transaction_receipt ~183

Inspect one finalized Solana mainnet transaction signature and return normalized success or failure status, slot, block time, fee, SPL-token owner deltas, and canonical USDC deltas. Supply recipient, amount, and optional payer when an exact settlement claim must be verified; use `transaction_receipt` for Base or Ethereum. Raw instructions and logs are excluded, and this tool performs no wallet, signing, broadcast, custody, or execution action.

NameTypeReqDescription
amountAtomicstring–Optional expected positive token amount in atomic units; requires recipient.
mintstring–Optional SPL-token mint; defaults to canonical Solana USDC.
payerstring–Optional expected token payer owner; requires recipient and amountAtomic.
recipientstring–Optional expected token recipient owner.
signaturestringyesFinalized Solana mainnet transaction signature.

No output schema declared.

No examples provided.

stateful_wallet_policy_conformance ~220

Evaluate safe standardized observations from wallet policies that track prior or concurrent requests. Use `wallet_policy_conformance` instead for one-request action shape, method, chain, token, recipient, amount, and function controls. This tool separately tests sequential cumulative limits, signed-but-unbroadcast accounting, ABI extraction, concurrent oversubscription, counter-reference failure, and application serialization. It accepts no credentials, counter values, wallet or resource IDs, signatures, transactions, or raw provider responses and does not run the provider tests itself.

NameTypeReqDescription
networkstringyesNetwork identifier used by the tested stateful profile.
observationsarrayyesUnique standardized stateful observations. Raw provider responses, signatures, transactions, counter values, credentials, wallet IDs, and resource IDs are rejected.
profileIdstringyesCaller-defined stateful policy profile identifier with no credential, wallet, or counter secret.
protocolstringyesPayment or execution protocol bound by the tested stateful profile.
providerstringyesWallet or delegated-signer provider name.
NameTypeReqDescription
applicationVerifiedarrayyes–
boundaryobjectyes–
completebooleanyes–
decisionstringyes–
evaluatedAtstringyes–
inconclusiveCasesarrayyes–
missingRequiredCasesarrayyes–
productstringyes–
profileobjectyes–
providerNativeUnverifiedarrayyes–
providerNativeVerifiedarrayyes–
resultsarrayyes–
schemaVersionstringyes–
standardSchemaVersionstringyes–
strictBudgetPassedbooleanyes–
unsafeCasesarrayyes–

No examples provided.

transaction_receipt ~129

Inspect one Base or Ethereum transaction hash and return normalized success or revert status, block time, gas and fee fields, decoded ERC-20 Transfer events, and canonical USDC transfers. Use `settlement_proof` instead when you must verify an exact canonical Base USDC recipient, amount, and optional payer claim. Raw logs are excluded; this tool performs no wallet, signing, broadcast, custody, or execution action.

NameTypeReqDescription
networkstring–Receipt network. Defaults to Base mainnet.
transactionHashstringyesMined Base or Ethereum transaction hash whose normalized receipt should be returned.

No output schema declared.

No examples provided.

wallet_enrich ~119

Inspect a public Base or EVM address and return an agent-ready on-chain profile: EOA or contract type, native and curated token holdings, token/NFT metadata, proxy evidence, activity, and a derived profile label. Use `enrich` for a company domain; the two tools accept different identifiers and return different evidence. Read-only public chain data; no wallet action or custody.

NameTypeReqDescription
addressstringyesPublic Base or EVM 0x address. Use wallet_enrich for on-chain evidence; use enrich for a company domain.

No output schema declared.

No examples provided.

wallet_policy_conformance ~184

Evaluate safe standardized allow, deny, and error observations from an agent wallet or delegated signer. Use this after running a bounded provider policy test matrix to distinguish explicit provider-policy enforcement from validation or generic provider failures and to test exact execution shape separately from operation allowlisting. Accepts no credentials, wallet IDs, signatures, transactions, or raw provider responses; it evaluates caller-supplied observations and does not run the provider tests itself.

NameTypeReqDescription
networkstringyesNetwork identifier used by the tested profile.
observationsarrayyesUnique standardized observations. Raw provider responses, signatures, transactions, credentials, and wallet IDs are rejected.
profileIdstringyesCaller-defined policy profile identifier with no credential or wallet secret.
protocolstringyesPayment or execution protocol bound by the tested profile.
providerstringyesWallet or delegated-signer provider name.
NameTypeReqDescription
boundaryobjectyes–
completebooleanyes–
decisionstringyes–
evaluatedAtstringyes–
exactShapePassedbooleanyes–
inconclusiveCasesarrayyes–
missingRequiredCasesarrayyes–
notEvaluatedByWalletPolicyarrayyes–
productstringyes–
profileobjectyes–
providerNativeUnverifiedarrayyes–
providerNativeVerifiedarrayyes–
resultsarrayyes–
schemaVersionstringyes–
standardSchemaVersionstringyes–
unsafeCasesarrayyes–

No examples provided.

Common questions

What is the io.github.epistemedeus/x402-data-gateway MCP server?

io.github.epistemedeus/x402-data-gateway is an MCP server listed in the public MCP registry as io.github.epistemedeus/x402-data-gateway. Paid x402 and MPP tools for agent discovery, payment safety, data, and DeFi. This page covers its hosted endpoint (https://agents.samedaydesk.com/mcp).

Is the io.github.epistemedeus/x402-data-gateway MCP server safe to use?

io.github.epistemedeus/x402-data-gateway scores 77 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the io.github.epistemedeus/x402-data-gateway MCP server expose?

io.github.epistemedeus/x402-data-gateway exposes 25 tools: extract, extract_batch, lockfile_pin_delta, read, scan, and 20 more. Their descriptions and schemas cost roughly 4,776 tokens of context every time the server is loaded.

Does the io.github.epistemedeus/x402-data-gateway MCP server require authentication?

No. We connected to io.github.epistemedeus/x402-data-gateway without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the io.github.epistemedeus/x402-data-gateway MCP server still maintained?

io.github.epistemedeus/x402-data-gateway is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.