Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

io.github.JonasFuchss/x402-trust-mcp

NPM · X402-TRUST-MCP · SCANNED SEP 20

Trust & reliability data for x402 endpoints before your agent pays them.

Available components

+15 this week 81 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →

Supply Chain Security98
  • No malware found by supply-chain analysis.Pass
  • No known CVEs affecting this package version or its production dependencies.Pass
  • No install/post-install scripts declared.Pass
  • 31 of 111 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency45
Schema Quality & AI Usability65
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 3591 tokens (~276/item across 13 items; 13 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management93
  • Stability observed for 28 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • We read all 13 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
  • An AI judge read all 13 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

How do I install the io.github.JonasFuchss/x402-trust-mcp server?

io.github.JonasFuchss/x402-trust-mcp runs locally as an npm package, launched with npx -y x402-trust-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

npm · x402-trust-mcp

# add to Claude Code
claude mcp add jonasfuchss-x402-trust-mcp -- npx -y x402-trust-mcp
// .cursor/mcp.json
{
  "mcpServers": {
    "jonasfuchss-x402-trust-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "x402-trust-mcp"
      ]
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "jonasfuchss-x402-trust-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "x402-trust-mcp"
      ]
    }
  }
}
# add to Codex CLI
codex mcp add jonasfuchss-x402-trust-mcp -- npx -y x402-trust-mcp
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "jonasfuchss-x402-trust-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "x402-trust-mcp"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add jonasfuchss-x402-trust-mcp --command npx --arg -y --arg x402-trust-mcp
# ~/.hermes/config.yaml
mcp_servers:
  jonasfuchss-x402-trust-mcp:
    command: "npx"
    args: ["-y", "x402-trust-mcp"]
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "jonasfuchss-x402-trust-mcp": {
      "Transport": "stdio",
      "Command": "npx",
      "Arguments": [
        "-y",
        "x402-trust-mcp"
      ]
    }
  }
}
# add to Vellum
assistant mcp add jonasfuchss-x402-trust-mcp -t stdio -c npx -a -y x402-trust-mcp
// mcp.json
{
  "mcpServers": {
    "jonasfuchss-x402-trust-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "x402-trust-mcp"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 19 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.

  • 17 Sept 26 +16
    • Malware scan: unverified → pass security
  • 16 Sept 26 −18
    • Stability: pass → unverified security
    • Malware scan: pass → unverified security
    • Tool safety: pass → unverified security
    • Capabilities: pass → unverified functional
    • Tool coverage: 100 → unverified functional
    • Stability: pass → 0.80 functional
    • Package version: 1.12.0 → 1.13.0 functional
  • 15 Sept 26 0
    • Stability: 0.97 → pass security
  • 14 Sept 26 +16
    • Malware scan: unverified → pass security
  • 13 Sept 26 −15
    • Malware scan: pass → unverified security
    • Schema quality: 203 → 269 functional
    • Package version: 1.7.1 → 1.12.0 functional
  • 11 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.

  • 10 Sept 26 0
    • Security disclosure: unverified → fail functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 20 Sept 2026 · Analysed npm/x402-trust-mcp@1.13.0

Provenance No attestation

The registry publishes no build provenance for this version, so there is nothing to verify.

Result No attestation
Ecosystem npm

Background: How many MCP packages publish verified provenance →

Dependencies 111 packages
Packages resolved 111
Stale 31
Tree resolution Complete

Background: SBOMs and build attestations, explained →

MCP tools · 13 exposed · ~3,591 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
x402_ecosystem_stats ~77

Free aggregate snapshot of the entire x402 ecosystem (Base + Solana): how many endpoints are listed/active/delisted, what fraction are reachable and spec-compliant, and real on-chain USDC settlement volume / receivers / payers over the last 30 days. Use this to gauge market health before transacting.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

x402_endpoint_history ~134

Raw observation time-series for a SPECIFIC x402 endpoint: listing/delisting/relisting events, advertised price changes, payTo changes, and probe results (uptime, latency, quoted amount) over the requested window (1-90 days). Per-probe 'latencyMs' is measured from a single EU vantage point and includes network distance to the endpoint. Pay-per-call over x402; auto-pays if a wallet is configured, otherwise returns the price quote.

NameTypeReqDescription
daysintegerLookback window in days (default 30)
resourcestringyesFull x402 resource URL

No output schema declared.

No examples provided.

x402_find_alternatives ~300

Given an x402 endpoint URL, returns the top semantically-similar endpoints (matched on advertised purpose via description embeddings) that currently OUT-SCORE it on the deterministic trust score. Use this to route away from a mediocre/dead/expensive endpoint toward a more reliable, better-settled one serving the SAME function — e.g. before paying, check if a higher-graded equivalent exists. Each alternative carries its trust 'score', 'grade', 'recommendation', cosine 'similarity' (0-1), 'amountUsd' price, 'priceCeiling' (true when amountUsd is an x402 'upto' authorization ceiling, not a fixed per-call price), and a free 'endpointPage' URL. Same-host siblings and 'avoid'-flagged endpoints are excluded. An empty 'alternatives' array is a valid answer meaning nothing beats the subject. Similarity is independent of latency/geography. Pay-per-call over x402 (~$0.005); auto-pays if a wallet is configured, otherwise returns the price quote.

NameTypeReqDescription
limitintegerMax alternatives to return (1-25, default 5)
minScoreDeltanumberMinimum trust-score advantage an alternative must have over the subject (default 5)
resourcestringyesFull x402 resource URL to find better alternatives for, e.g. https://api.example.com/v1/thing

No output schema declared.

No examples provided.

x402_semantic_search ~537

Free-text SEMANTIC SEARCH across the entire monitored x402 endpoint catalog. Given a plain-language query (e.g. "weather forecast", "image generation", "EVM gas price oracle"), returns the up to 25 endpoints whose advertised purpose is semantically closest. Ranking is deterministic and fully specified: cosine similarity bucketed to whole percentage points first (80.3% and 80.5% are the same bucket, so sub-percent noise never outranks a better endpoint), then trust score (0-100), then described-before-undescribed, then endpoint id as a stable final tiebreak. Matches below a 0.5 cosine-similarity floor are dropped entirely, so a query can return fewer than the requested limit (or none). Endpoints that advertise no description are still matched: they are embedded from their service name and URL path tokens instead of a written description (host name as a last resort). The EXACT effect of a missing description: no fixed point deduction, and no direct similarity malus either; the only deterministic penalty is the described-before-undescribed tiebreak (at equal similarity bucket AND equal trust score, a described endpoint ranks first). Beyond that the effect is purely indirect: the shorter fallback text typically yields lower cosine similarity than a prose description, so undescribed endpoints tend to land in lower similarity buckets, by a query-dependent (never fixed) amount. Use this for DISCOVERY: find candidate endpoints for a capability before checking any of them in depth. Each match carries 'id', 'resource' URL, trust 'score' (0-100), 'grade' (A-F), raw cosine 'similarity' (0-1; ranking buckets it to whole percents), 'amountUsd' price (null when not advertised), 'priceCeiling' (true when amountUsd is an x402 'upto' authorization ceiling, not a fixed per-call price), 'description' when advertised, and a free 'endpointPage' URL. 'score'/'grade' are null for endpoints not yet scored. Deliberately NO verdict/recommendation or flag detail: the per-endpoint trust report…

NameTypeReqDescription
limitintegerMax matches to return (1-25, default 25)
querystringyesFree-text search query, e.g. "weather forecast". Describe the capability you need in plain words; matching is by meaning, not substrings.

No output schema declared.

No examples provided.

x402_trust_bulk ~344

Score up to 500 x402 endpoints in a SINGLE paid call. Returns the authoritative full-density trust score (0-100, grade A-F or '?' when unmeasured, recommendation proceed|caution|avoid|parameterize|unverified|not-payable|free), confidence, `probed_at`, `computed_at`, and a `recomputed` flag for each requested resource. Cache rows older than ~15 minutes are recomputed on-demand from the latest stored probes and settlements (no live network re-probe), so bulk scores typically reflect reality within minutes. Each recomputed row also refreshes that endpoint's free public snapshot (page, badge, card) immediately. Per-request recompute limits apply: at most 50 endpoints / 8 seconds are recomputed; the response includes `recompute_limit_hit` and `recompute_limit` so you know if the cap was reached. The smallest tier that fits your request is selected automatically (10/50/100/200/500 endpoints; ~$0.045/$0.20/$0.325/$0.40/$0.50). Resources not in our observation set return `found:false`; you still pay for the batch. For a fresh live probe, use `x402_trust_score`. Pay-per-call over x402; auto-pays if a wallet is configured, otherwise returns the price quote.

NameTypeReqDescription
resourcesarrayyesList of full x402 resource URLs (https://...) to score. Duplicates are ignored; max 500.
tiernumberOptional fixed tier size. If omitted, the cheapest tier that fits `resources` is used.

No output schema declared.

No examples provided.

x402_trust_leaderboard ~81

Free top-25 most trustworthy x402 endpoints, ranked by a deterministic trust score (uptime, envelope compliance, latency, age, on-chain settlement activity, price stability). Latency is measured from a single EU vantage point and includes network distance to the endpoint (so it is only lightly weighted). Use this to discover reliable paid endpoints.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

x402_trust_preview ~148

FREE showcase of what x402_trust_score returns. You do NOT choose the endpoint: this returns the COMPLETE paid-grade trust report (every field — exact score, scoreRange, full component breakdown, advertised price, on-chain settlement figures, all flags) for THREE endpoints picked from the current population — the best-scored, the median, and the worst-scored ('samples' each carry 'role', 'populationRank', and the full 'report'). Use it to see exactly what the paid output looks like across the entire quality range BEFORE paying. It cannot score an endpoint you choose — to evaluate YOUR OWN endpoint, call x402_trust_score (paid). Takes no arguments.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

x402_trust_score ~777

Trust score (0-100, grade A-F, or '?' when unmeasured) for a SPECIFIC x402 endpoint -- cataloged or not (uncataloged endpoints are live-probed on first query, auto-adopted, score carries a low-confidence first-contact flag). PLUS a machine-readable verdict ('recommendation': proceed|caution|avoid|parameterize|unverified|not-payable|free), the advertised price ('advertised.amountUsd'), a confidence-adjusted band ('scoreRange'), and structured flags ('flagsDetailed' with code/severity/message; any severity 'error' means avoid). The 'parameterize' verdict (with 'templated':true) means the resource URL still contains an unresolved template placeholder (e.g. {slug}, :slug or %7B…%7D) but we DO have a real signal (scored probes or a discovery fallback): substitute a valid value first, then the health metrics apply to the resolved URL. The 'unverified' verdict (grade '?') means we have NO measurement at all (every probe excluded and no discovery payment requirements to fall back on): it is unknown, not bad, so verify the endpoint yourself before paying. The 'not-payable' verdict (grade '?') means the URL answers a 402 with an EMPTY accepts[] (an auth/API-key gate such as sign-in-with-x), or answers a bare 401/403 with no payment envelope, so it is not an x402-payable resource at all and there is nothing to settle. The 'free' verdict (grade '?') means the endpoint answers plain requests with data (HTTP 200, no payment envelope) and has never presented a payment challenge: a free resource with no payment flow to grade, unmeasured by design, not a negative verdict. For templated per-item endpoints that ARE payable, a varying payTo/price is EXPECTED (one wallet/price per item): the report surfaces 'stats.payToVaries'+'payToDistinct30d' and 'advertised.amountRange30d' as a 'payto-varies'/'price-varies' note rather than a 'payto-changed-recently' hijack error; always pay the payTo in the live 402 quote, not a cached listing. 'stats.scoredProbes30d' vs 'stats.excluded30d' show h…

NameTypeReqDescription
resourcestringyesFull x402 resource URL to evaluate, e.g. https://api.example.com/v1/thing

No output schema declared.

No examples provided.

x402_watch_cancel ~116

Soft-cancel a watch immediately: no new events accrue, but the event log stays READABLE via x402_watch_events until the original expires_at (cancel is not a delete). Probing drops back to normal cadence as soon as no active watches cover the endpoint. Bearer-authed with the secret from x402_watch_create. Free and idempotent.

NameTypeReqDescription
secretstringyesThe one-time bearer secret returned by x402_watch_create.
watch_idstringyesWatch id returned by x402_watch_create.

No output schema declared.

No examples provided.

x402_watch_create ~491

Start monitoring ONE x402 endpoint for 30 days. Get alerted on changes that break autonomous payment: payTo changes (possible takeover/rug — but for a templated per-item endpoint a payTo move is expected variance and is delivered as severity 'warn', not 'critical'), price changes, asset/network changes, 402-spec regressions, delisting, and liveness down/recovered. A self-healing endpoint that repeatedly blips is auto-detected as `liveness_flapping` and its individual down/up alerts are coalesced into a single flapping notice (plus one 'stopped flapping' notice when it stabilizes) so you are not spammed. Returns a one-time bearer secret + poll URL + renew URL + edit URL + cancel URL + machine-readable `next_steps`. Use x402_watch_events to poll the append-only log, or configure push delivery to one or more signed HTTPS webhooks and/or Slack/Discord incoming webhooks (max 5 each). `webhook_url`/`slack_url` accept a single URL string or an array of URLs. All URLs are connection-tested BEFORE payment — unreachable URLs are rejected with no charge (retry with a corrected URL). On success the response reports per-URL delivery in `delivery.connection_test`. Webhook signature: `x-signature` = 'sha256=' + HMAC-SHA256(body) keyed by hex(sha256(secret)), NOT the raw secret. Pay-per-call over x402 (~$0.20); auto-pays if a wallet is configured, otherwise returns the price quote.

NameTypeReqDescription
endpointstringyesFull x402 resource URL to watch. It must already be in our observation set.
eventsarrayEvent types to subscribe to (default all): payto_change, price_change, asset_network_change, spec_regression, delisting, liveness_down, liveness_recovered, liveness_flapping, latency_regression.
liveness_sensitivity_nintegerConsecutive missed probes before liveness_down surfaces to you (1=paranoid … 10=relaxed; default 2).
slack_urlOptional Slack or Discord incoming webhook URL(s). Single string or array; max 5.
webhook_urlOptional signed HTTPS webhook URL(s) for push delivery. Single string or array; max 5.

No output schema declared.

No examples provided.

x402_watch_edit ~229

Edit an active watch: change webhook/Slack URLs, liveness sensitivity, or subscribed events. Bearer-authed with the secret from x402_watch_create. Newly-added URLs are connection-tested before the change is persisted; if any new URL fails, the existing config is unchanged. Delivery fields are full-replace per channel (omit to leave that channel unchanged). Returns the updated watch view.

NameTypeReqDescription
eventsarrayEvent types to subscribe to (default all). Omit to keep current events.
liveness_sensitivity_ninteger1=paranoid … 10=relaxed. Omit to keep current value.
secretstringyesThe one-time bearer secret returned by x402_watch_create.
slack_urlReplace Slack/Discord URL(s). Single string or array; max 5. Omit to keep current URL(s).
watch_idstringyesWatch id returned by x402_watch_create.
webhook_urlReplace webhook URL(s). Single string or array; max 5. Omit to keep current webhook(s).

No output schema declared.

No examples provided.

x402_watch_events ~282

Read the append-only event log for an active x402 watch. Returns two streams: `events` (endpoint changes — payTo/price/asset/spec/delisting/liveness) and `watch_events` (lifecycle feedback — created/edited/cancelled/renewed/expiring/expired). Nothing between two polls is lost. Provide the watch_id and the one-time secret from x402_watch_create. Advance `since` with the returned `next_cursor` (endpoint events) and `watch_since` with `watch_events_cursor` (lifecycle events). Cursors/ids are GLOBAL sequences shared across watches (a watch's first event id may be >1); always page by the returned cursor rather than assuming they start at 1. Cancelled watches remain READABLE until expires_at (no new events accrue). If the watch has push delivery, still poll to reconcile missed webhooks.

NameTypeReqDescription
secretstringyesThe one-time bearer secret returned by x402_watch_create.
sincestringEndpoint-event cursor: the `next_cursor` from a previous poll. Omit for the first poll.
watch_idstringyesWatch id returned by x402_watch_create.
watch_sincestringLifecycle-event cursor: the `watch_events_cursor` from a previous poll. Omit for the first poll.

No output schema declared.

No examples provided.

x402_watch_renew ~75

Extend an active x402 watch by another 30 days before it expires. The secret stays the same. Pay-per-call over x402 (~$0.20); auto-pays if a wallet is configured, otherwise returns the price quote.

NameTypeReqDescription
watch_idstringyesWatch id returned by x402_watch_create.

No output schema declared.

No examples provided.

Common questions

What is the io.github.JonasFuchss/x402-trust-mcp server?

io.github.JonasFuchss/x402-trust-mcp is listed in the public MCP registry as io.github.JonasFuchss/x402-trust-mcp. Trust & reliability data for x402 endpoints before your agent pays them. This page covers its npm package (x402-trust-mcp).

Is the io.github.JonasFuchss/x402-trust-mcp server safe to use?

io.github.JonasFuchss/x402-trust-mcp scores 81 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the io.github.JonasFuchss/x402-trust-mcp server expose?

io.github.JonasFuchss/x402-trust-mcp exposes 13 tools: x402_ecosystem_stats, x402_trust_leaderboard, x402_trust_preview, x402_trust_score, x402_endpoint_history, and 8 more. Their descriptions and schemas cost roughly 3,591 tokens of context every time the server is loaded.

Is the io.github.JonasFuchss/x402-trust-mcp server still maintained?

io.github.JonasFuchss/x402-trust-mcp is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

What licence is the io.github.JonasFuchss/x402-trust-mcp server under?

io.github.JonasFuchss/x402-trust-mcp declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.