io.github.kwizzlesurp10-ctrl/x402-mcp
REMOTE · X402-MCP.ONRENDER.COM · SCANNED SEP 28
Pay for HTTP APIs and charge for your own: x402 micropayments in USDC on Base.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security74
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability88
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Tool/resource definitions use about 2499 tokens (~99/item across 25 items; 19 tools + 6 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management95
- Stability check failed: schema churn in the 30 days we've observed: 1 tool removals, 0 breaking changes, 0 auth/transport breaks, 1 additions. See how to fix → Fail
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 21 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the io.github.kwizzlesurp10-ctrl/x402-mcp server?
io.github.kwizzlesurp10-ctrl/x402-mcp is a hosted endpoint at https://x402-mcp.onrender.com/mcp/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · x402-mcp.onrender.com
claude mcp add --transport http kwizzlesurp10-ctrl-x402-mcp 'https://x402-mcp.onrender.com/mcp/mcp'
{
"mcpServers": {
"kwizzlesurp10-ctrl-x402-mcp": {
"url": "https://x402-mcp.onrender.com/mcp/mcp"
}
}
} {
"servers": {
"kwizzlesurp10-ctrl-x402-mcp": {
"type": "http",
"url": "https://x402-mcp.onrender.com/mcp/mcp"
}
}
} [mcp_servers.kwizzlesurp10-ctrl-x402-mcp] url = "https://x402-mcp.onrender.com/mcp/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"kwizzlesurp10-ctrl-x402-mcp": {
"type": "remote",
"url": "https://x402-mcp.onrender.com/mcp/mcp",
"enabled": true
}
}
} openclaw mcp add kwizzlesurp10-ctrl-x402-mcp --url 'https://x402-mcp.onrender.com/mcp/mcp' --transport streamable-http
mcp_servers:
kwizzlesurp10-ctrl-x402-mcp:
url: "https://x402-mcp.onrender.com/mcp/mcp" {
"McpServers": {
"kwizzlesurp10-ctrl-x402-mcp": {
"Transport": "http",
"Url": "https://x402-mcp.onrender.com/mcp/mcp"
}
}
} assistant mcp add kwizzlesurp10-ctrl-x402-mcp -t streamable-http -u 'https://x402-mcp.onrender.com/mcp/mcp'
{
"mcpServers": {
"kwizzlesurp10-ctrl-x402-mcp": {
"type": "http",
"url": "https://x402-mcp.onrender.com/mcp/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 28 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Sept 26 +14
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 20 Sept 26 0
- A breaking change shipped without a version bump: still 1.30.0 ▼ security
- Tool “get_agent_card” was removed ▼ security
- Tool “mailrail.inbound” was removed ▼ security
- Tool “mailrail.send” was removed ▼ security
- Tool “mailrail.status” was removed ▼ security
- Schema quality: 2817 → 2499 ▲ functional
- New prompt “x402.sell_api” functional
- 17 Sept 26 0
- New tool “get_agent_card” functional
- 14 Sept 26 0
- A breaking change shipped without a version bump: still 1.30.0 ▼ security
- Tool “commerce.stripe_checkout” was removed ▼ security
- The server rewrote its instructions, which are the text every model session reads security
- Tool “city.check” rewrote its description, which is the text the model reads security
- 12 Sept 26 0
- Tool “swarm.revenue” rewrote its description, which is the text the model reads security
- Schema quality: fail → pass ▲ functional
- New resource “x402.agent-card” functional
- New resource “x402.pricing-table” functional
- New resource “x402.server-card” functional
- New resource “x402.tools-manifest” functional
- New tool “x402.agent_card” functional
- 11 Sept 26 0
- New tool “mailrail.inbound” functional
- New tool “mailrail.send” functional
- New tool “mailrail.status” functional
- 9 Sept 26 0
- Server version: 1.29.1 → 1.30.0 functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 28 Sept 2026 · Probed https://x402-mcp.onrender.com/mcp/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=onrender.com | CN=WE1,O=Google Trust Services,C=US | 21 Sept 2026 | 20 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | 6eb1e3fe7d0631ea1337bfa4a321c137 |
| SANs: onrender.com, *.onrender.com | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of x402-mcp.onrender.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| onrender.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://x402-mcp.onrender.com/mcp/mcp | Verified | 200 | |
| http (plaintext) | http://x402-mcp.onrender.com/mcp/mcp | HTTPS enforced | 301 | https://x402-mcp.onrender.com/mcp/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
city.check Paid US city property check ~178
Run a paid US city property compliance check via x402 on the same HTTP resource buyers use. Prefer city.sample first. Settles USDC when EVM_PRIVATE_KEY is set; otherwise returns a 402 probe. Price: $0.01 per call (x402, USDC on Base/Solana/Arbitrum).
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | Street address to check. Example: '1700 Penn Ave N' or '1 Centre St'. |
| agent_id | string | – | Optional agent identity for quota accounting. |
| city_code | string | yes | City code from city.list. Example: 'mn'. |
| max_price_usdc | number | – | Optional USDC spend ceiling. Example: 0.05. |
| preferred_network | string | – | Preferred CAIP-2 network. Example: 'eip155:8453'. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
city.list List US compliance cities ~57
List US City Open-Data Compliance Network cities with paid_url, sample_url, and price. Call first, then city.sample, then city.check for the paid address lookup.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Optional agent identity for quota accounting. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
city.sample US city property sample ~78
Get a free fixed-address property compliance sample for one US city code. Use before city.check to validate city_code and response shape without paying.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Optional agent identity for quota accounting. |
| city_code | string | yes | City code from city.list. Examples: 'mn', 'sea', 'nyc', 'chi'. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
commerce.activate_pro Activate Pro tier ~96
Verify a Pro-tier x402 payment and unlock Pro quota limits for the agent. Call after commerce.pro_requirements and a completed USDC payment.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Agent identity to grant Pro quota. Must match the requirements call. |
| payment_required | string | yes | PAYMENT-REQUIRED JSON returned by commerce.pro_requirements. |
| payment_signature | string | yes | PAYMENT-SIGNATURE from the Pro-tier USDC payment. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
commerce.credits_requirements Build tool-credit payment requirements ~84
Build x402 payment requirements to buy a pack of per-use MCP tool credits. Next: pay those terms, then commerce.purchase_credits with the signature.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Optional agent identity the credits will attach to. |
| credits | integer | – | Credit pack size to buy. Example: 100. Omit to use the server default pack. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
commerce.pro_requirements Build Pro-tier payment requirements ~53
Build x402 payment requirements to purchase the Pro quota tier. Next: pay those terms, then commerce.activate_pro with the signature.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Optional agent identity the Pro grant will attach to. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
commerce.purchase_credits Purchase tool credits ~108
Verify an x402 payment and add per-use tool credits to the agent. Call after commerce.credits_requirements and a completed USDC payment.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Agent identity to credit. |
| credits | integer | – | Credit pack size that was purchased. Must match the requirements call. |
| payment_required | string | yes | PAYMENT-REQUIRED JSON returned by commerce.credits_requirements. |
| payment_signature | string | yes | PAYMENT-SIGNATURE from the credits USDC payment. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
ops.metrics Host OS metrics ~84
Get host OS telemetry: CPU, memory, swap, disk, network, and an ok/warn/critical health verdict. Call to diagnose this MCP host; set include_processes=true for top memory processes.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Optional agent identity for quota accounting. |
| include_processes | boolean | – | If true, include top processes by memory. Default false. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
pulse.base Base network pulse ~84
Get live Base Network Pulse: base fee, EIP-1559 projection, utilization, USD settlement cost, verdict. Call before settling on Base when you need a settle-now vs hold recommendation.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Optional agent identity for quota accounting. |
| depth | integer | – | Blocks to sample. Example: 12. Omit to use the server default. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
swarm.research Run swarm research ~129
Run the swarm agency: compose a research product from free inputs and list it for resale. Pass allow_paid_inputs=true only when buying upstream x402 services is intended.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Seller agent identity that will own the listing. |
| allow_paid_inputs | boolean | – | If true, buy upstream x402 services before composing. Default false (free inputs only, unsold inventory costs nothing). |
| max_price_usdc | number | – | Optional USDC ceiling for any paid upstream inputs. |
| topic | string | yes | Research topic to compose. Example: 'Base mainnet gas window'. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
swarm.revenue Swarm revenue report ~79
Get swarm composite economics: spend, composite sales, LTV:CAC, margins, per-source scores. total_revenue_usdc is swarm listings only; storefront.revenue_usdc is the full settled ledger. Call after swarm.research or swarm.settle to inspect realized economics.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Optional agent identity for quota accounting. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
swarm.settle Settle composite sale ~108
Verify and settle a buyer's x402 payment for a listed composite product and record revenue. Call with product_id plus PAYMENT-SIGNATURE after the buyer pays.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Seller agent identity recording the sale. |
| payment_required | string | yes | PAYMENT-REQUIRED terms for this product. |
| payment_signature | string | yes | PAYMENT-SIGNATURE from the buyer. |
| product_id | string | yes | Listed composite product id. Example: the hex id from swarm.research. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
x402.agent_card A2A Agent ID Card ~85
Return the A2A Protocol v1.0 Agent ID Card and MCP server card. Optional target_id filters to a skill id, name, or tag.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Optional calling agent identifier for quota tracking. |
| target_id | string | – | Optional skill ID, tool name, or tag to inspect. Omit for the full server agent card. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
x402.build_seller Build seller payment requirements ~299
Build seller-side x402 payment requirements for your own HTTP resource. Pass resource_url plus discovery_* fields to catalog the endpoint in Bazaar.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Optional agent identity for quota accounting. |
| description | string | – | Human-readable description embedded in PAYMENT-REQUIRED. |
| discoverable | boolean | – | If true, embed the Bazaar discovery extension. Omit to use server default. |
| discovery_input_example | object | – | Optional example input object for Bazaar. Omit if none. |
| discovery_method | string | – | HTTP method advertised to Bazaar. Default GET. |
| discovery_output_example | object | – | Optional example output object for Bazaar. Omit if none. |
| mime_type | string | – | Resource MIME type. Default application/json. |
| network | string | – | CAIP-2 settlement network. Default eip155:84532 (Base Sepolia). Mainnet: eip155:8453. |
| pay_to | string | – | 0x recipient for USDC. Example: '0x67ff…'. Omit to use X402_PAY_TO_ADDRESS. |
| price | string | – | List price string. Default '$0.01'. Example: '$0.05'. |
| resource_url | string | – | Public URL of the paid resource. When set with discovery_* fields, Bazaar catalogs the endpoint after a settled payment. |
| scheme | string | – | x402 payment scheme. Default 'exact'. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
x402.discover Discover x402 services ~159
Discover paid HTTP APIs in the x402 Bazaar via the facilitator catalog. Call this first to find a resource URL, then x402.probe and x402.pay_and_fetch.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Optional agent identity for quota accounting. Example: 'agent-42'. Omit to use the anonymous free-tier id. |
| limit | integer | – | Maximum number of catalog entries to return. Default 20. Range 1–100. |
| max_price_usdc | number | – | Optional USDC price ceiling. Example: 0.05. Omit to include any listed price. |
| query | string | – | Optional Bazaar search substring. Example: 'weather' or 'image'. Omit to list recent paid HTTP services. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
x402.networks List x402 networks ~59
List supported settlement networks, facilitators, and x402 v2 header names. Call when choosing a preferred_network for x402.pay_and_fetch or x402.build_seller.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Optional agent identity for quota accounting. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
x402.pay_and_fetch Pay and fetch x402 resource ~212
Pay USDC via x402 and fetch a protected HTTP resource in one call. Requires EVM_PRIVATE_KEY on this host; otherwise use x402.probe for a no-spend 402.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Optional agent identity for quota accounting. |
| body | string | – | Optional raw request body for POST/PUT. Omit for GET. |
| headers | object | – | Optional extra request headers as a string map. Omit if none. |
| max_price_usdc | number | – | Optional spend ceiling in USDC. Example: 0.10. Calls above this are blocked. |
| method | string | – | HTTP method for the paid request. Default GET. |
| preferred_network | string | – | Preferred CAIP-2 network. Example: 'eip155:8453' (Base mainnet). Omit to use the server default. Call x402.networks to list options. |
| url | string | yes | Absolute paid HTTP URL to fetch after settling USDC. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
x402.probe Probe x402 payment requirements ~169
Probe a URL for HTTP 402 PAYMENT-REQUIRED terms using the x402 client SDK. Use before x402.pay_and_fetch to inspect price, network, and payTo without spending.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Optional agent identity for quota accounting. Omit for the anonymous free-tier id. |
| headers | object | – | Optional extra request headers as a string map. Example: {"Accept": "application/json"}. Omit if none. |
| method | string | – | HTTP method for the probe. Default GET. Example: 'GET' or 'POST'. |
| url | string | yes | Absolute HTTP URL to probe. Example: 'https://x402-mcp.onrender.com/us/mn/property-check?address=1700%20Penn%20Ave%20N'. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
x402.verify Verify x402 payment signature ~91
Verify an x402 PAYMENT-SIGNATURE against PAYMENT-REQUIRED terms via the facilitator. Call after a buyer presents a signature and before releasing paid content.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Optional agent identity for quota accounting. |
| payment_required | string | yes | PAYMENT-REQUIRED JSON/header the signature is meant to satisfy. |
| payment_signature | string | yes | PAYMENT-SIGNATURE header value from the buyer. |
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
What is the io.github.kwizzlesurp10-ctrl/x402-mcp server?
io.github.kwizzlesurp10-ctrl/x402-mcp is listed in the public MCP registry as io.github.kwizzlesurp10-ctrl/x402-mcp. Pay for HTTP APIs and charge for your own: x402 micropayments in USDC on Base. This page covers its hosted endpoint (https://x402-mcp.onrender.com/mcp/mcp).
Is the io.github.kwizzlesurp10-ctrl/x402-mcp server safe to use?
io.github.kwizzlesurp10-ctrl/x402-mcp scores 87 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.kwizzlesurp10-ctrl/x402-mcp server expose?
io.github.kwizzlesurp10-ctrl/x402-mcp exposes 19 tools: x402.agent_card, x402.discover, x402.probe, x402.pay_and_fetch, x402.build_seller, and 14 more. Their descriptions and schemas cost roughly 2,212 tokens of context every time the server is loaded.
Does the io.github.kwizzlesurp10-ctrl/x402-mcp server require authentication?
No. We connected to io.github.kwizzlesurp10-ctrl/x402-mcp without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the io.github.kwizzlesurp10-ctrl/x402-mcp server still maintained?
io.github.kwizzlesurp10-ctrl/x402-mcp is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.