Hermes Plant — Agent Commerce Assurance
REMOTE · MCP.HERMESPLANT.COM · SCANNED AUG 3
Preflight, approve, and prove consequential agent actions with signed evidence and x402 tools.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security66
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 6 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability42
- AI-judged instruction clarity (fair).Partial
- Context-footprint check failed: tool/resource definitions use about 7012 tokens (~280/item across 25 items; 25 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
- Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · mcp.hermesplant.com
claude mcp add --transport http jessegdotio-hermes-plant https://mcp.hermesplant.com/mcp
[mcp_servers.jessegdotio-hermes-plant] url = "https://mcp.hermesplant.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"jessegdotio-hermes-plant": {
"type": "remote",
"url": "https://mcp.hermesplant.com/mcp",
"enabled": true
}
}
} openclaw mcp add jessegdotio-hermes-plant --url https://mcp.hermesplant.com/mcp --transport streamable-http
mcp_servers:
jessegdotio-hermes-plant:
url: "https://mcp.hermesplant.com/mcp" {
"mcpServers": {
"jessegdotio-hermes-plant": {
"type": "http",
"url": "https://mcp.hermesplant.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.
- 1 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.
- 31 Jul 26 +2
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 10 to 13. That category is still filling its 30-day observation window: 3 days of observed history at the previous scan, 4 at this one. The score rises as the window fills, whether or not the server changes.
- 29 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.
- 28 Jul 26 0
- Server version: 2.0.1 → 2.0.2 functional
- 27 Jul 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 57
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://mcp.hermesplant.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=hermesplant.com | CN=WE1,O=Google Trust Services,C=US | 30 Jun 2026 | 28 Sept 2026 | ECDSA 256 | ECDSA-SHA256 | 200747b8b9ef136e13541517349220ae |
| SANs: hermesplant.com, mcp.hermesplant.com, *.mcp.hermesplant.com | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
DNSSEC secure
Validation of mcp.hermesplant.com. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| hermesplant.com. | present | 2371 | 13 | Verified |
| mcp.hermesplant.com. | Verified address RRset verified with the apex keys |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains |
| x-content-type-options | nosniff |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.hermesplant.com/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.hermesplant.com/mcp | HTTPS enforced | 301 | https://mcp.hermesplant.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
action_safety_quick_gate Action Safety - one-cent preflight ~372
AI agent action safety quick gate ($0.01 over x402 or free-tier quota). Deterministically scores a consequential action and returns the exact next call: proceed, request full DestructGuard evidence, or run the complete Action Safety workflow.
| Name | Type | Req | Description |
|---|---|---|---|
| actor | string | — | Agent or tool requesting the action |
| actorType | string | — | Caller type for analytics: agent, human, synthetic, system, or unknown |
| apiKey | string | — | Free-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr… |
| branch | string | — | Branch or environment context |
| campaign | string | — | Campaign tag for downstream telemetry |
| channel | string | — | Discovery channel or source tag |
| command | string | yes | Shell, SQL, Git, deploy, or infrastructure action to preflight |
| cwd | string | — | Working directory or execution context |
| diffStat | string | — | Optional git diff --stat or change summary |
| intent | string | — | Why the action is being requested |
| payer | string | — | Optional wallet/account identifier; stored only as a hash |
| paymentIdentifier | string | — | Optional x402 payment identifier for idempotency/retry correlation |
| paymentSignature | string | — | x402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry |
| repo | string | — | Repository or project context |
| synthetic | boolean | — | Mark this paid retry as an internal test/probe for analytics exclusion |
| xPayment | string | — | Raw X-PAYMENT proof from an x402-compatible wallet/client |
| Name | Type | Req | Description |
|---|---|---|---|
| httpStatus | number | yes | Upstream HTTP status code |
| ok | boolean | yes | True when the upstream storefront call returned a 2xx response |
| paymentRequired | boolean | — | True when the response is an x402 HTTP 402 payment challenge |
No examples provided.
action_safety_run Action Safety - complete workflow ~377
Complete AI agent action safety workflow ($0.25 over x402 or free-tier quota): DestructGuard evidence, conditional ReviewQueue triage for high or critical risk, an honest decision, signed receipt, and 30-day status record. Triage does not imply human approval.
| Name | Type | Req | Description |
|---|---|---|---|
| actor | string | — | Agent or tool requesting the action |
| actorType | string | — | Caller type for analytics: agent, human, synthetic, system, or unknown |
| apiKey | string | — | Free-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr… |
| branch | string | — | Branch or environment context |
| campaign | string | — | Campaign tag for downstream telemetry |
| channel | string | — | Discovery channel or source tag |
| command | string | yes | Shell, SQL, Git, deploy, or infrastructure action to preflight |
| cwd | string | — | Working directory or execution context |
| diffStat | string | — | Optional git diff --stat or change summary |
| intent | string | — | Why the action is being requested |
| payer | string | — | Optional wallet/account identifier; stored only as a hash |
| paymentIdentifier | string | — | Optional x402 payment identifier for idempotency/retry correlation |
| paymentSignature | string | — | x402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry |
| repo | string | — | Repository or project context |
| synthetic | boolean | — | Mark this paid retry as an internal test/probe for analytics exclusion |
| xPayment | string | — | Raw X-PAYMENT proof from an x402-compatible wallet/client |
| Name | Type | Req | Description |
|---|---|---|---|
| httpStatus | number | yes | Upstream HTTP status code |
| ok | boolean | yes | True when the upstream storefront call returned a 2xx response |
| paymentRequired | boolean | — | True when the response is an x402 HTTP 402 payment challenge |
No examples provided.
assurance_attest Assurance Attest — signed receipt for an agent action ~433
Assurance Attest (x402-paid, $0.05): bind one x402 payment intent or MCP tool call to a canonical HMAC-signed record (binding hash, policy verdict, findings, optional settlement outcome). Loop it after every payment or tool call to build a tamper-evident audit trail a third party can check at the free verify endpoint.
| Name | Type | Req | Description |
|---|---|---|---|
| actorType | string | — | Caller type for analytics: agent, human, synthetic, system, or unknown |
| apiKey | string | — | Free-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr… |
| campaign | string | — | Campaign tag for downstream telemetry |
| channel | string | — | Discovery channel or source tag |
| intent | object | yes | x402: resourceUrl+method (+scheme/network/asset/amountUnits/payTo/settlement fields). mcp: serverId+toolName (+toolArguments or toolArgumentsHash). |
| outcome | object | — | Optional settlement outcome: {outcome: fulfilled|failed|rejected, settlementId, responseStatus, evidenceHashes[]} |
| payer | string | — | Optional wallet/account identifier; stored only as a hash |
| paymentIdentifier | string | — | Optional x402 payment identifier for idempotency/retry correlation |
| paymentSignature | string | — | x402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry |
| policy | object | — | Optional buyer policy (policyId+version, caps, allow-lists); omit for binding-only attestation |
| protocol | string | yes | "x402" for a payment, "mcp" for a tool call |
| subject | object | yes | Who acted and why |
| synthetic | boolean | — | Mark this paid retry as an internal test/probe for analytics exclusion |
| xPayment | string | — | Raw X-PAYMENT proof from an x402-compatible wallet/client |
| Name | Type | Req | Description |
|---|---|---|---|
| httpStatus | number | yes | Upstream HTTP status code |
| ok | boolean | yes | True when the upstream storefront call returned a 2xx response |
| paymentRequired | boolean | — | True when the response is an x402 HTTP 402 payment challenge |
No examples provided.
assurance_verify Assurance Verify — check a signed record (free) ~109
Verify a Hermes-signed assurance record for free: recomputes the canonical hash (hermes-stable-json-v1 + SHA-256) and HMAC signature server-side and reports recordHashValid / signatureValid. Use it to audit attestations produced by assurance_attest without trusting the agent that produced them.
| Name | Type | Req | Description |
|---|---|---|---|
| integrity | object | yes | The integrity object returned with the record (recordHash, signature, keyId) |
| record | object | yes | The attestation/decision/receipt record object |
| Name | Type | Req | Description |
|---|---|---|---|
| httpStatus | number | yes | Upstream HTTP status code |
| ok | boolean | yes | True when the upstream storefront call returned a 2xx response |
| paymentRequired | boolean | — | True when the response is an x402 HTTP 402 payment challenge |
No examples provided.
bond_analyze BondLens — bond & loan analytics ~410
BondLens (x402-paid, $0.25): deterministic fixed-income and loan analytics. Bond mode solves price<->yield-to-maturity, duration, and convexity; loan mode (send principal+annualRate+termMonths) returns an amortization schedule.
| Name | Type | Req | Description |
|---|---|---|---|
| actorType | string | — | Caller type for analytics: agent, human, synthetic, system, or unknown |
| annualRate | number | — | Loan annual rate, e.g. 0.06 |
| apiKey | string | — | Free-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr… |
| campaign | string | — | Campaign tag for downstream telemetry |
| channel | string | — | Discovery channel or source tag |
| couponRate | number | — | Annual coupon rate, e.g. 0.05 |
| faceValue | number | — | Bond face value (default 1000) |
| frequency | number | — | Coupons per year (default 2) |
| payer | string | — | Optional wallet/account identifier; stored only as a hash |
| paymentIdentifier | string | — | Optional x402 payment identifier for idempotency/retry correlation |
| paymentSignature | string | — | x402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry |
| periods | number | — | Periods to maturity |
| price | number | — | Bond price; supply to solve yield |
| principal | number | — | Loan principal (selects loan mode) |
| synthetic | boolean | — | Mark this paid retry as an internal test/probe for analytics exclusion |
| termMonths | number | — | Loan term in months |
| xPayment | string | — | Raw X-PAYMENT proof from an x402-compatible wallet/client |
| yield | number | — | Annual yield; supply to solve price |
| Name | Type | Req | Description |
|---|---|---|---|
| httpStatus | number | yes | Upstream HTTP status code |
| ok | boolean | yes | True when the upstream storefront call returned a 2xx response |
| paymentRequired | boolean | — | True when the response is an x402 HTTP 402 payment challenge |
No examples provided.
cashflowlens_analyze CashflowLens — DCF, IRR & cashflow returns ~399
CashflowLens (x402-paid, $0.20): deterministic NPV, IRR, XIRR, DCF valuation, MOIC/DPI/TVPI, and payback period from a cashflow series. Use for valuation and return analysis instead of letting the model estimate.
| Name | Type | Req | Description |
|---|---|---|---|
| actorType | string | — | Caller type for analytics: agent, human, synthetic, system, or unknown |
| apiKey | string | — | Free-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr… |
| campaign | string | — | Campaign tag for downstream telemetry |
| cashflows | array | yes | Cashflows: numbers for periodic, or {amount,date} objects for dated XIRR. Outflows negative. |
| channel | string | — | Discovery channel or source tag |
| dcf | object | — | Optional DCF valuation inputs (projected FCFs, discount rate, terminal value, net debt, shares) |
| discountRate | number | — | Annual rate for NPV, e.g. 0.08 |
| nav | number | — | Residual value, for TVPI |
| payer | string | — | Optional wallet/account identifier; stored only as a hash |
| paymentIdentifier | string | — | Optional x402 payment identifier for idempotency/retry correlation |
| paymentSignature | string | — | x402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry |
| periodsPerYear | number | — | Periods per year to annualize a periodic IRR |
| synthetic | boolean | — | Mark this paid retry as an internal test/probe for analytics exclusion |
| xPayment | string | — | Raw X-PAYMENT proof from an x402-compatible wallet/client |
| Name | Type | Req | Description |
|---|---|---|---|
| httpStatus | number | yes | Upstream HTTP status code |
| ok | boolean | yes | True when the upstream storefront call returned a 2xx response |
| paymentRequired | boolean | — | True when the response is an x402 HTTP 402 payment challenge |
No examples provided.
dealanalyzer_analyze DealAnalyzer — full deal underwriting in one call ~351
DealAnalyzer (x402-paid, $2.00): the flagship. Deterministic full deal underwrite in a single call — DCF valuation (EV, equity value, implied share price), fund returns (IRR/MOIC), and the LP/GP distribution waterfall, plus sensitivity. Combines what CashflowLens + WaterfallLens do, cross-checked.
| Name | Type | Req | Description |
|---|---|---|---|
| actorType | string | — | Caller type for analytics: agent, human, synthetic, system, or unknown |
| apiKey | string | — | Free-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr… |
| campaign | string | — | Campaign tag for downstream telemetry |
| channel | string | — | Discovery channel or source tag |
| dcf | object | yes | Required. DCF valuation inputs. |
| payer | string | — | Optional wallet/account identifier; stored only as a hash |
| paymentIdentifier | string | — | Optional x402 payment identifier for idempotency/retry correlation |
| paymentSignature | string | — | x402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry |
| returns | object | — | Optional fund/deal return inputs (IRR, MOIC, NPV). |
| synthetic | boolean | — | Mark this paid retry as an internal test/probe for analytics exclusion |
| waterfall | object | — | Optional LP/GP distribution waterfall inputs. |
| xPayment | string | — | Raw X-PAYMENT proof from an x402-compatible wallet/client |
| Name | Type | Req | Description |
|---|---|---|---|
| httpStatus | number | yes | Upstream HTTP status code |
| ok | boolean | yes | True when the upstream storefront call returned a 2xx response |
| paymentRequired | boolean | — | True when the response is an x402 HTTP 402 payment challenge |
No examples provided.
emailguard_validate EmailGuard — email validation ~317
EmailGuard (x402-paid, $0.02): deterministic email/contact quality scorer — validity, deliverability score, disposable/role/free classification, typo suggestion. Pure function, no DNS.
| Name | Type | Req | Description |
|---|---|---|---|
| actorType | string | — | Caller type for analytics: agent, human, synthetic, system, or unknown |
| apiKey | string | — | Free-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr… |
| campaign | string | — | Campaign tag for downstream telemetry |
| channel | string | — | Discovery channel or source tag |
| domain | string | — | Optional explicit domain hint (usually derived from email) |
| string | yes | Email address to validate | |
| mxPresent | boolean | — | Caller-supplied MX hint |
| name | string | — | Optional contact name associated with the email |
| payer | string | — | Optional wallet/account identifier; stored only as a hash |
| paymentIdentifier | string | — | Optional x402 payment identifier for idempotency/retry correlation |
| paymentSignature | string | — | x402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry |
| synthetic | boolean | — | Mark this paid retry as an internal test/probe for analytics exclusion |
| xPayment | string | — | Raw X-PAYMENT proof from an x402-compatible wallet/client |
| Name | Type | Req | Description |
|---|---|---|---|
| httpStatus | number | yes | Upstream HTTP status code |
| ok | boolean | yes | True when the upstream storefront call returned a 2xx response |
| paymentRequired | boolean | — | True when the response is an x402 HTTP 402 payment challenge |
No examples provided.
emailguard_validate_batch EmailGuard — validate a whole contact list ~342
Validate up to 20 emails in one tool call — one deterministic verdict per record (validity, deliverability score, disposable/role/free classification, typo suggestion, canonical normalization). Pass your free apiKey (250 records/mo, no wallet — https://hermesplant.com/pricing) and each record serves from quota. Results preserve input order; the batch stops at the first 402 (quota exhausted) and marks the rest skipped so you can upgrade and resume.
| Name | Type | Req | Description |
|---|---|---|---|
| actorType | string | — | Caller type for analytics: agent, human, synthetic, system, or unknown |
| apiKey | string | — | Free-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr… |
| campaign | string | — | Campaign tag for downstream telemetry |
| channel | string | — | Discovery channel or source tag |
| payer | string | — | Optional wallet/account identifier; stored only as a hash |
| paymentIdentifier | string | — | Optional x402 payment identifier for idempotency/retry correlation |
| paymentSignature | string | — | x402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry |
| records | array | yes | Contact records to validate — one storefront call per record (max 20 per tool call) |
| synthetic | boolean | — | Mark this paid retry as an internal test/probe for analytics exclusion |
| xPayment | string | — | Raw X-PAYMENT proof from an x402-compatible wallet/client |
| Name | Type | Req | Description |
|---|---|---|---|
| httpStatus | number | yes | Upstream HTTP status code |
| ok | boolean | yes | True when the upstream storefront call returned a 2xx response |
| paymentRequired | boolean | — | True when the response is an x402 HTTP 402 payment challenge |
No examples provided.
evidence_verify Evidence Verify — check a paid result's evidence bundle ~366
Evidence Verification (x402-paid, $0.05): verify an agent-commerce evidence bundle before trusting a paid result — x402 challenge/receipt/policy-decision/service-response artifacts, endpoint and price binding, freshness, hashes, synthetic-proof leakage. Returns verified / needs_review / rejected / insufficient_evidence with per-rule evidence.
| Name | Type | Req | Description |
|---|---|---|---|
| actorType | string | — | Caller type for analytics: agent, human, synthetic, system, or unknown |
| apiKey | string | — | Free-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr… |
| artifacts | array | yes | Evidence artifacts (Hermes contract): x402_challenge, x402_receipt, payment_policy_decision, service_response, ... |
| campaign | string | — | Campaign tag for downstream telemetry |
| channel | string | — | Discovery channel or source tag |
| payer | string | — | Optional wallet/account identifier; stored only as a hash |
| paymentIdentifier | string | — | Optional x402 payment identifier for idempotency/retry correlation |
| paymentSignature | string | — | x402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry |
| policy | object | — | Verification policy: expected serviceId/endpoint/network/priceCents, require* flags |
| subject | object | — | Optional run subject: kind, serviceId, endpoint, method, runId |
| synthetic | boolean | — | Mark this paid retry as an internal test/probe for analytics exclusion |
| xPayment | string | — | Raw X-PAYMENT proof from an x402-compatible wallet/client |
| Name | Type | Req | Description |
|---|---|---|---|
| httpStatus | number | yes | Upstream HTTP status code |
| ok | boolean | yes | True when the upstream storefront call returned a 2xx response |
| paymentRequired | boolean | — | True when the response is an x402 HTTP 402 payment challenge |
No examples provided.
freetier_status Free-tier key status ~79
Check a free API key's remaining monthly quota, reset date, and upgrade path. Pass your hp_free_ key as apiKey. No key yet? POST an email to https://hermesplant.com/api/keys/free (250 calls/mo, no wallet).
| Name | Type | Req | Description |
|---|---|---|---|
| apiKey | string | yes | Your free-tier key (hp_free_...) |
| Name | Type | Req | Description |
|---|---|---|---|
| httpStatus | number | yes | Upstream HTTP status code |
| ok | boolean | yes | True when the upstream storefront call returned a 2xx response |
| paymentRequired | boolean | — | True when the response is an x402 HTTP 402 payment challenge |
No examples provided.
get_checkout_policies Get checkout policies ~18
Return legal policy URLs required before checkout
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| httpStatus | number | yes | Upstream HTTP status code |
| ok | boolean | yes | True when the upstream storefront call returned a 2xx response |
| paymentRequired | boolean | — | True when the response is an x402 HTTP 402 payment challenge |
No examples provided.
get_product Get product ~27
Get a single product by slug
| Name | Type | Req | Description |
|---|---|---|---|
| slug | string | yes | Product slug from the catalog |
| Name | Type | Req | Description |
|---|---|---|---|
| httpStatus | number | yes | Upstream HTTP status code |
| ok | boolean | yes | True when the upstream storefront call returned a 2xx response |
| paymentRequired | boolean | — | True when the response is an x402 HTTP 402 payment challenge |
No examples provided.
get_x402_manifest Get x402 manifest ~29
Return the live x402 manifest with paid endpoint prices, Bazaar metadata, and buyer policy checks
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| httpStatus | number | yes | Upstream HTTP status code |
| ok | boolean | yes | True when the upstream storefront call returned a 2xx response |
| paymentRequired | boolean | — | True when the response is an x402 HTTP 402 payment challenge |
No examples provided.
list_products List products ~17
List active products from the Hermes Plant catalog
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| httpStatus | number | yes | Upstream HTTP status code |
| ok | boolean | yes | True when the upstream storefront call returned a 2xx response |
| paymentRequired | boolean | — | True when the response is an x402 HTTP 402 payment challenge |
No examples provided.
mcp_risk_score MCP Server Risk Analyzer ~326
MCP Server Risk Analyzer (x402-paid, $0.05): score an MCP server manifest for security risk before install — destructive tools, over-broad scopes, weak auth, egress — with per-tool findings and fixes.
| Name | Type | Req | Description |
|---|---|---|---|
| actorType | string | — | Caller type for analytics: agent, human, synthetic, system, or unknown |
| apiKey | string | — | Free-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr… |
| authModel | string | — | e.g. oauth, token, none |
| campaign | string | — | Campaign tag for downstream telemetry |
| channel | string | — | Discovery channel or source tag |
| payer | string | — | Optional wallet/account identifier; stored only as a hash |
| paymentIdentifier | string | — | Optional x402 payment identifier for idempotency/retry correlation |
| paymentSignature | string | — | x402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry |
| priorTools | array | — | Prior tool names to diff capability growth |
| server | string | — | Server name/URL |
| synthetic | boolean | — | Mark this paid retry as an internal test/probe for analytics exclusion |
| tools | array | yes | The MCP server's tool manifest |
| xPayment | string | — | Raw X-PAYMENT proof from an x402-compatible wallet/client |
| Name | Type | Req | Description |
|---|---|---|---|
| httpStatus | number | yes | Upstream HTTP status code |
| ok | boolean | yes | True when the upstream storefront call returned a 2xx response |
| paymentRequired | boolean | — | True when the response is an x402 HTTP 402 payment challenge |
No examples provided.
options_price OptionLens — Black-Scholes price & Greeks ~389
OptionLens (x402-paid, $0.30): deterministic Black-Scholes price and full Greeks (delta, gamma, vega, theta, rho) for European calls/puts, with dividend yield, intrinsic/time value, and moneyness.
| Name | Type | Req | Description |
|---|---|---|---|
| actorType | string | — | Caller type for analytics: agent, human, synthetic, system, or unknown |
| apiKey | string | — | Free-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr… |
| campaign | string | — | Campaign tag for downstream telemetry |
| channel | string | — | Discovery channel or source tag |
| dividendYield | number | — | Continuous dividend yield, default 0 |
| optionType | string | — | Option type, 'call' or 'put' (default call) |
| payer | string | — | Optional wallet/account identifier; stored only as a hash |
| paymentIdentifier | string | — | Optional x402 payment identifier for idempotency/retry correlation |
| paymentSignature | string | — | x402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry |
| riskFreeRate | number | — | Annual risk-free rate, default 0 |
| spot | number | yes | Underlying price (> 0) |
| strike | number | yes | Strike price (> 0) |
| synthetic | boolean | — | Mark this paid retry as an internal test/probe for analytics exclusion |
| timeToExpiry | number | yes | Years to expiry, e.g. 0.5 |
| volatility | number | yes | Annualized volatility, e.g. 0.2 |
| xPayment | string | — | Raw X-PAYMENT proof from an x402-compatible wallet/client |
| Name | Type | Req | Description |
|---|---|---|---|
| httpStatus | number | yes | Upstream HTTP status code |
| ok | boolean | yes | True when the upstream storefront call returned a 2xx response |
| paymentRequired | boolean | — | True when the response is an x402 HTTP 402 payment challenge |
No examples provided.
payment_policy_decide Payment Policy — preflight an x402 payment ~508
Payment Policy Decision (x402-paid, $0.05): deterministic allow / deny / needs_review before your agent signs an x402 payment — checks resource binding, amount vs expected price, network, payTo, facilitator, replay readiness, PII leakage, and buyer spend limits, with evidence-backed findings. Loop it over every payment; pair with assurance_attest for a signed record.
| Name | Type | Req | Description |
|---|---|---|---|
| actorType | string | — | Caller type for analytics: agent, human, synthetic, system, or unknown |
| amountUnits | string | — | Raw x402 amount units (USDC = 6 decimals) |
| apiKey | string | — | Free-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr… |
| asset | string | — | Payment asset address |
| buyerPolicy | object | — | Buyer guardrails: maxUsdPerCall, allowedNetworks, allowedPayTo, allowedHosts, requireExactScheme, requireHttps, ... |
| campaign | string | — | Campaign tag for downstream telemetry |
| channel | string | — | Discovery channel or source tag |
| facilitatorUrl | string | — | Facilitator URL used to settle |
| maxTimeoutSeconds | number | — | Challenge timeout window |
| method | string | — | HTTP method the agent intends to call |
| network | string | — | Payment network, e.g. eip155:8453 |
| payTo | string | — | Payment recipient from the challenge |
| payer | string | — | Optional wallet/account identifier; stored only as a hash |
| paymentIdentifier | string | — | Optional x402 payment identifier for idempotency/retry correlation |
| paymentSignature | string | — | x402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry |
| resourceUrl | string | yes | Absolute resource URL from the x402 challenge or Bazaar listing |
| scheme | string | — | x402 payment scheme (exact expected) |
| serviceRisk | object | — | Optional upstream service-risk result (e.g. from mcp_risk_score) |
| synthetic | boolean | — | Mark this paid retry as an internal test/probe for analytics exclusion |
| tags | array | — | Bazaar/service tags for sensitive-category detection |
| xPayment | string | — | Raw X-PAYMENT proof from an x402-compatible wallet/client |
| Name | Type | Req | Description |
|---|---|---|---|
| httpStatus | number | yes | Upstream HTTP status code |
| ok | boolean | yes | True when the upstream storefront call returned a 2xx response |
| paymentRequired | boolean | — | True when the response is an x402 HTTP 402 payment challenge |
No examples provided.
portfolioguard_score PortfolioGuard — portfolio risk ~323
PortfolioGuard (x402-paid, $0.15): deterministic portfolio risk scoring from holdings — volatility, Sharpe, max drawdown, concentration (HHI), diversification, plus per-rule findings.
| Name | Type | Req | Description |
|---|---|---|---|
| actorType | string | — | Caller type for analytics: agent, human, synthetic, system, or unknown |
| apiKey | string | — | Free-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr… |
| campaign | string | — | Campaign tag for downstream telemetry |
| channel | string | — | Discovery channel or source tag |
| holdings | array | yes | Positions with symbol, weight (0-1), optional returns[], sector |
| payer | string | — | Optional wallet/account identifier; stored only as a hash |
| paymentIdentifier | string | — | Optional x402 payment identifier for idempotency/retry correlation |
| paymentSignature | string | — | x402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry |
| periodReturns | array | — | Optional portfolio/market return series |
| riskFreeRate | number | — | Optional risk-free rate for the Sharpe ratio (default 0) |
| synthetic | boolean | — | Mark this paid retry as an internal test/probe for analytics exclusion |
| xPayment | string | — | Raw X-PAYMENT proof from an x402-compatible wallet/client |
| Name | Type | Req | Description |
|---|---|---|---|
| httpStatus | number | yes | Upstream HTTP status code |
| ok | boolean | yes | True when the upstream storefront call returned a 2xx response |
| paymentRequired | boolean | — | True when the response is an x402 HTTP 402 payment challenge |
No examples provided.
purchase_with_x402 Purchase with x402 ~298
Purchase a one-time product via x402 (returns 402 challenge or fulfillment JSON). Call get_x402_manifest first, verify method/path/network/amount/payTo, then sign and retry with PAYMENT-SIGNATURE.
| Name | Type | Req | Description |
|---|---|---|---|
| actorType | string | — | Caller type for analytics: agent, human, synthetic, system, or unknown |
| apiKey | string | — | Free-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr… |
| campaign | string | — | Campaign tag for downstream telemetry |
| channel | string | — | Discovery channel or source tag |
| string | — | Optional email for the order record | |
| payer | string | — | Optional wallet/account identifier; stored only as a hash |
| paymentIdentifier | string | — | Optional x402 payment identifier for idempotency/retry correlation |
| paymentSignature | string | — | x402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry |
| slug | string | yes | One-time product slug (e.g. destructguard-pro) |
| synthetic | boolean | — | Mark this paid retry as an internal test/probe for analytics exclusion |
| xPayment | string | — | Raw X-PAYMENT proof from an x402-compatible wallet/client |
| Name | Type | Req | Description |
|---|---|---|---|
| httpStatus | number | yes | Upstream HTTP status code |
| ok | boolean | yes | True when the upstream storefront call returned a 2xx response |
| paymentRequired | boolean | — | True when the response is an x402 HTTP 402 payment challenge |
No examples provided.
score_destructguard_command DestructGuard — score command risk ~346
Score a command/action with the x402-paid DestructGuard service. Call get_x402_manifest first, verify the DestructGuard price and buyer policy, then retry the 402 challenge with an x402 payment signature.
| Name | Type | Req | Description |
|---|---|---|---|
| actor | string | — | Agent/tool requesting the action |
| actorType | string | — | Caller type for analytics: agent, human, synthetic, system, or unknown |
| apiKey | string | — | Free-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr… |
| campaign | string | — | Campaign tag for downstream telemetry |
| channel | string | — | Discovery channel or source tag |
| command | string | yes | Command or agent action to score |
| cwd | string | — | Working directory or execution context |
| diffStat | string | — | Optional git diff --stat or change summary |
| intent | string | — | Why the command is being requested |
| payer | string | — | Optional wallet/account identifier; stored only as a hash |
| paymentIdentifier | string | — | Optional x402 payment identifier for idempotency/retry correlation |
| paymentSignature | string | — | x402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry |
| repo | string | — | Repository or project context |
| synthetic | boolean | — | Mark this paid retry as an internal test/probe for analytics exclusion |
| xPayment | string | — | Raw X-PAYMENT proof from an x402-compatible wallet/client |
| Name | Type | Req | Description |
|---|---|---|---|
| httpStatus | number | yes | Upstream HTTP status code |
| ok | boolean | yes | True when the upstream storefront call returned a 2xx response |
| paymentRequired | boolean | — | True when the response is an x402 HTTP 402 payment challenge |
No examples provided.
start_checkout Start checkout ~29
Start a Stripe checkout session for a product slug
| Name | Type | Req | Description |
|---|---|---|---|
| slug | string | yes | Product slug to purchase |
| Name | Type | Req | Description |
|---|---|---|---|
| httpStatus | number | yes | Upstream HTTP status code |
| ok | boolean | yes | True when the upstream storefront call returned a 2xx response |
| paymentRequired | boolean | — | True when the response is an x402 HTTP 402 payment challenge |
No examples provided.
submit_reviewqueue_request ReviewQueue — submit for risk triage ~343
Submit a command/action to the x402-paid ReviewQueue agent service. Call get_x402_manifest first, verify the ReviewQueue price and buyer policy, then retry the 402 challenge with an x402 payment signature.
| Name | Type | Req | Description |
|---|---|---|---|
| actor | string | — | Agent/tool requesting the action |
| actorType | string | — | Caller type for analytics: agent, human, synthetic, system, or unknown |
| apiKey | string | — | Free-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr… |
| branch | string | — | Branch or environment context |
| campaign | string | — | Campaign tag for downstream telemetry |
| channel | string | — | Discovery channel or source tag |
| command | string | yes | Command or agent action being requested |
| diffStat | string | — | Optional git diff --stat or change summary |
| payer | string | — | Optional wallet/account identifier; stored only as a hash |
| paymentIdentifier | string | — | Optional x402 payment identifier for idempotency/retry correlation |
| paymentSignature | string | — | x402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry |
| reason | string | — | Why the action is being requested |
| repo | string | — | Repository or project context |
| synthetic | boolean | — | Mark this paid retry as an internal test/probe for analytics exclusion |
| xPayment | string | — | Raw X-PAYMENT proof from an x402-compatible wallet/client |
| Name | Type | Req | Description |
|---|---|---|---|
| httpStatus | number | yes | Upstream HTTP status code |
| ok | boolean | yes | True when the upstream storefront call returned a 2xx response |
| paymentRequired | boolean | — | True when the response is an x402 HTTP 402 payment challenge |
No examples provided.
walletguard_score WalletGuard — wallet AML risk ~384
WalletGuard (x402-paid, $0.10): deterministic wallet AML/compliance risk scorer. From caller-provided context (sanctions, exposures, labels, fund sources) returns a 0-100 risk score, level, and evidence-backed findings.
| Name | Type | Req | Description |
|---|---|---|---|
| actorType | string | — | Caller type for analytics: agent, human, synthetic, system, or unknown |
| apiKey | string | — | Free-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr… |
| campaign | string | — | Campaign tag for downstream telemetry |
| channel | string | — | Discovery channel or source tag |
| exposures | array | — | Signals e.g. mixer:tornado, sanctions:ofac |
| fundingSources | array | — | Optional fund-source breakdown (source, share 0-1, verified) |
| labels | array | — | Address labels, e.g. exchange:binance, contract:..., sanctions:... |
| payer | string | — | Optional wallet/account identifier; stored only as a hash |
| paymentIdentifier | string | — | Optional x402 payment identifier for idempotency/retry correlation |
| paymentSignature | string | — | x402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry |
| sanctionsHits | array | — | Sanctions / OFAC / blacklist hit identifiers |
| synthetic | boolean | — | Mark this paid retry as an internal test/probe for analytics exclusion |
| transfers | array | — | Optional transfer summaries (direction, value, counterparty, tags) |
| wallet | string | yes | Wallet address |
| xPayment | string | — | Raw X-PAYMENT proof from an x402-compatible wallet/client |
| Name | Type | Req | Description |
|---|---|---|---|
| httpStatus | number | yes | Upstream HTTP status code |
| ok | boolean | yes | True when the upstream storefront call returned a 2xx response |
| paymentRequired | boolean | — | True when the response is an x402 HTTP 402 payment challenge |
No examples provided.
waterfall_distribute WaterfallLens — LP/GP distribution waterfall ~420
WaterfallLens (x402-paid, $0.30): deterministic LP/GP distribution waterfall (return of capital, preferred, GP catch-up, carried-interest split) with the exact split, per-tier breakdown, LP MOIC, and effective carry %.
| Name | Type | Req | Description |
|---|---|---|---|
| actorType | string | — | Caller type for analytics: agent, human, synthetic, system, or unknown |
| apiKey | string | — | Free-tier / plan API key (hp_free_… or a pass key). Forwarded as X-API-Key so paid tools serve from your monthly quota with NO x402 wallet. Get a free key (250 calls/mo) at https://hermesplant.com/pr… |
| campaign | string | — | Campaign tag for downstream telemetry |
| carryPercentage | number | — | GP carry, e.g. 0.20 (default 0.20) |
| catchUpPercentage | number | — | GP catch-up share, 1.0 = full (default) |
| channel | string | — | Discovery channel or source tag |
| compounding | string | — | Preferred-return accrual basis: 'simple' or 'compounded' (default compounded) |
| contributedCapital | number | yes | Total LP capital to return in tier 1 |
| distributable | number | yes | Total cash to distribute |
| payer | string | — | Optional wallet/account identifier; stored only as a hash |
| paymentIdentifier | string | — | Optional x402 payment identifier for idempotency/retry correlation |
| paymentSignature | string | — | x402 payment proof to forward as PAYMENT-SIGNATURE and X-PAYMENT on retry |
| preferredRate | number | — | Annual preferred rate, e.g. 0.08 |
| preferredReturnAmount | number | — | Explicit preferred return amount |
| synthetic | boolean | — | Mark this paid retry as an internal test/probe for analytics exclusion |
| xPayment | string | — | Raw X-PAYMENT proof from an x402-compatible wallet/client |
| years | number | — | Holding period for preferred accrual |
| Name | Type | Req | Description |
|---|---|---|---|
| httpStatus | number | yes | Upstream HTTP status code |
| ok | boolean | yes | True when the upstream storefront call returned a 2xx response |
| paymentRequired | boolean | — | True when the response is an x402 HTTP 402 payment challenge |
No examples provided.