# Boundary Guard x402 (remote · x402-resource-scanner.vercel.app)

MCP tools for x402 readiness, paid-path probes, launch packs, and trust receipts.

- Trust score: 72/100 (medium)
- Change this week: +9
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- remote · `x402-resource-scanner.vercel.app`: 72/100 (this document), [markdown](https://verifymcp.io/servers/larrylemonbot-boundary-guard-x402/x402-resource-scanner.md), [page](https://verifymcp.io/servers/larrylemonbot-boundary-guard-x402/x402-resource-scanner)

## Channel facts

- Endpoint: `https://x402-resource-scanner.vercel.app/mcp`
- Transports: `streamable-http`
- Auth: `required`
- Version: `0.1.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Endpoint Security**: 89/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation is enforced on tool calls, but the challenge carries no valid RFC 9728 metadata, so a client cannot discover where to get a token.
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 56/100
  - AI-judged instruction clarity (good).
  - Context-footprint check failed: tool/resource definitions use about 1048 tokens (~174/item across 6 items; 6 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 27/100
  - Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Capabilities**: 20/100
  - Spec-recency check failed: implements MCP spec 2024-11-05; the latest is 2026-07-28.

## Install

### Claude

```bash
claude mcp add --transport http larrylemonbot-boundary-guard-x402 https://x402-resource-scanner.vercel.app/mcp
```

### Codex

```toml
[mcp_servers.larrylemonbot-boundary-guard-x402]
url = "https://x402-resource-scanner.vercel.app/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "larrylemonbot-boundary-guard-x402": {
      "type": "remote",
      "url": "https://x402-resource-scanner.vercel.app/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add larrylemonbot-boundary-guard-x402 --url https://x402-resource-scanner.vercel.app/mcp --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  larrylemonbot-boundary-guard-x402:
    url: "https://x402-resource-scanner.vercel.app/mcp"
```

### Other

```json
{
  "mcpServers": {
    "larrylemonbot-boundary-guard-x402": {
      "type": "http",
      "url": "https://x402-resource-scanner.vercel.app/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-03 (score 72, +1)

No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-08-01 (score 71, +1)

No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-07-31 (score 70, +5)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-30 (score 65, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-29 (score 65, +1)

No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-07-28 (score 64, +1)

No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-07-27 (score 63, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-26 (score 63)

First indexed and scored.

## MCP tools (6)

### `boundary_guard_check` (~120 tokens)

Boundary Guard Check

Create a deterministic, read-only pre-action receipt from request, policy, and optional result evidence. Use before an agent posts, spends, lists, or writes so the decision can be audited; no external action is executed.

Input parameters:

- `nextStep` (string): Optional guidance stored in the receipt.
- `policy` (object): Decision object, e.g. allow/retry/review/block and reason.
- `request` (object, required): Action metadata the agent is about to perform.
- `result` (object): Optional result or dry-run summary to hash into evidence.

Output parameters:

- `claimBoundary` (string)
- `createdAt` (string)
- `decision` (string)
- `evidenceHash` (string)
- `marketplacePositioning` (object)
- `nextStep` (string)
- `receiptId` (string)

### `scan_x402_resource` (~106 tokens)

x402 Resource Scan

Read-only scan of a public API/provider URL for x402, OpenAPI, pricing, and agent-discovery metadata. Pass url, and optionally marketplace_url plus expected_resources, to get a readiness score, issues, and fixes; no private endpoints are called.

Input parameters:

- `expected_resources` (integer): Optional expected resource count.
- `marketplace_url` (string): Optional marketplace/listing URL to compare against public metadata.
- `url` (string, required): Target API/provider base URL to scan.

Output parameters:

- `issues` (array)
- `marketplacePositioning` (object)
- `nextSteps` (array)
- `prices` (array)
- `score` (integer)
- `target` (string)

### `probe_x402_paid_path` (~121 tokens)

x402 Paid-Path Health Probe

Probe a public x402 paid endpoint without signing or paying, then parse the HTTP 402 challenge. Pass target plus optional expected network/asset/price to verify payment metadata and receive a deterministic health receipt.

Input parameters:

- `expected` (object): Optional expected x402 metadata such as network, asset, and priceUsd.
- `method` (string): Safe unpaid probe method. Defaults to GET.
- `mode` (string): Probe mode for v1. Defaults to unpaid_402.
- `target` (string, required): Specific paid endpoint URL to probe without payment.

Output parameters:

- `checks` (object)
- `healthy` (boolean)
- `issues` (array)
- `observed` (object)
- `receipt` (object)
- `recommendedFixes` (array)
- `target` (string)

### `check_agent_tool_readiness` (~239 tokens)

GateCheck Readiness

GateCheck readiness: check whether an x402/agent-facing tool is ready for agent routing, marketplace listing, and paid-path monitoring, including public agent discovery surfaces (/llms.txt, /agents.txt, /.well-known/mcp.json, /mcp). Pass target plus optional tier, marketplace_url, expected_resources, and paid_path; deep/report tiers add unpaid 402 probing when paid_path is supplied. Tiers: quick $1, deep $5, report $10.

Input parameters:

- `expected` (object): Optional expected x402 network/asset/price metadata for paid_path probes.
- `expected_resources` (integer): Optional expected resource count.
- `marketplace_url` (string): Optional marketplace/listing URL to compare against public metadata.
- `method` (string): Safe unpaid probe method when paid_path is supplied. Defaults to GET.
- `paid_path` (string): Optional specific paid endpoint to probe without payment for deep/report tiers.
- `target` (string, required): Target API/provider base URL to scan.
- `tier` (string): Readiness depth. quick=$1, deep=$5, report=$10. Defaults to quick.

Output parameters:

- `checks` (object)
- `healthProbe` (object|null)
- `issues` (array)
- `priceUsd` (string)
- `product` (string)
- `ready` (boolean)
- `recommendedFixes` (array)
- `report` (object)
- `scan` (object)
- `score` (integer)
- `target` (string)
- `tier` (string)

### `generate_x402_launch_pack` (~275 tokens)

x402 Launch Pack Generator

Generate marketplace-safe launch assets for an x402/MCP seller: listing copy, buyer FAQ, checklist, approval packet, and claim boundaries. Pass target plus optional product_name, audience, primary_use_case, marketplace_url, and paid_path; service/premium tiers include readiness evidence. Tiers: single $9, service $29, premium $49.

Input parameters:

- `audience` (string): Primary buyer/audience for listing copy.
- `desired_marketplaces` (array): Optional marketplace names to include in launch planning.
- `expected` (object): Optional expected x402 network/asset/price metadata for paid_path probes.
- `expected_resources` (integer): Optional expected resource count.
- `marketplace_url` (string): Optional marketplace/listing URL to compare against public metadata.
- `method` (string): Safe unpaid probe method when paid_path is supplied. Defaults to GET.
- `paid_path` (string): Optional paid endpoint to validate via unpaid 402 challenge for service/premium packs.
- `primary_use_case` (string): Primary buyer outcome/use case.
- `product_name` (string): Buyer-facing product title.
- `target` (string, required): Target API/provider base URL to package for launch.
- `tier` (string): Launch pack depth. single=$9, service=$29, premium=$49. Defaults to single.

Output parameters:

- `approvalRequiredBeforeDistribution` (boolean)
- `claimBoundary` (string)
- `launchPack` (object)
- `priceUsd` (string)
- `product` (string)
- `productName` (string)
- `readiness` (object)
- `readinessScore` (integer)
- `readyForDistribution` (boolean)
- `report` (object)
- `target` (string)
- `tier` (string)

### `generate_trust_receipt` (~187 tokens)

Generate Trust Receipt

Generate a deterministic trust receipt from sanitized request/policy/result/payment summaries. Do not submit raw auth headers, cookies, API keys, private keys, payment signatures, payment response headers, customer prompts, customer documents, or payer-identifying evidence.

Input parameters:

- `nextStep` (string): Optional receipt next-step guidance.
- `payment` (object): Optional sanitized payment summary or caller-provided hashes only; do not include raw payment signatures, raw payment response headers, private keys, API keys, cookies, payer-identifying evidence, or…
- `policy` (object): Sanitized policy or decision summary to hash.
- `request` (object, required): Sanitized request/action summary to hash; omit raw prompts, documents, credentials, cookies, auth headers, signatures, and secrets.
- `result` (object): Sanitized outcome/result summary to hash; omit customer data and secret-like values.

Output parameters:

- `claimBoundary` (string)
- `createdAt` (string)
- `decision` (string)
- `evidenceHash` (string)
- `marketplacePositioning` (object)
- `nextStep` (string)
- `receiptId` (string)

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/larrylemonbot-boundary-guard-x402/x402-resource-scanner#diagnostics

## Score history

- 2026-08-03: 72
- 2026-08-02: 71
- 2026-08-01: 71
- 2026-07-31: 70
- 2026-07-30: 65
- 2026-07-29: 65
- 2026-07-28: 64
- 2026-07-27: 63
- 2026-07-26: 63

## Links

- Remote endpoint: https://x402-resource-scanner.vercel.app/mcp
- Authorisation metadata: https://x402-resource-scanner.vercel.app/.well-known/oauth-protected-resource/mcp
- Website: https://x402-resource-scanner.vercel.app/
- Changelog RSS feed: https://verifymcp.io/servers/larrylemonbot-boundary-guard-x402/x402-resource-scanner/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/larrylemonbot-boundary-guard-x402/x402-resource-scanner/changelog.json
- HTML version of this page: https://verifymcp.io/servers/larrylemonbot-boundary-guard-x402/x402-resource-scanner
