Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, email [email protected] and we’ll put it right.

AXIS Toolbox — Agentic Commerce Codebase Intelligence

REMOTE · AXIS-API-6C7Z.ONRENDER.COM · SCANNED AUG 3

Generate AGENTS.md, AP2 compliance docs, checkout rules, debug playbook & MCP configs from any repo.

+6 this week 56 Trust /100

Recent critical change

Authorization (29 Jul 2026). See the changelog before you install this server.

Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →

Endpoint Security63
Transport & Reachability100
Schema Quality & AI Usability24
  • AI-judged instruction clarity (poor).Fail
  • Context-footprint check failed: tool/resource definitions use about 10781 tokens (~291/item across 37 items; 37 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
  • Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Capabilities40
  • Spec-recency check failed: implements MCP spec 2025-03-26; the latest is 2026-07-28. See how to fix → Fail
Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

remote · axis-api-6c7z.onrender.com

# add to Claude Code
claude mcp add --transport http lastmanupinc-hub-axis-toolbox https://axis-api-6c7z.onrender.com/mcp
# ~/.codex/config.toml
[mcp_servers.lastmanupinc-hub-axis-toolbox]
url = "https://axis-api-6c7z.onrender.com/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "lastmanupinc-hub-axis-toolbox": {
      "type": "remote",
      "url": "https://axis-api-6c7z.onrender.com/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add lastmanupinc-hub-axis-toolbox --url https://axis-api-6c7z.onrender.com/mcp --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  lastmanupinc-hub-axis-toolbox:
    url: "https://axis-api-6c7z.onrender.com/mcp"
// mcp.json
{
  "mcpServers": {
    "lastmanupinc-hub-axis-toolbox": {
      "type": "http",
      "url": "https://axis-api-6c7z.onrender.com/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 3 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

  • 31 Jul 26 +41
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 30 Jul 26 −37
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 29 Jul 26 0
    • Authorization: unverified → fail critical
  • 28 Jul 26 +1
    • Authorization: fail → unverified security
  • 27 Jul 26 +1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 26 Jul 26 49

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 3 Aug 2026 · Probed https://axis-api-6c7z.onrender.com/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=onrender.com CN=WE1,O=Google Trust Services,C=US 24 Jul 2026 22 Oct 2026 ECDSA 256 ECDSA-SHA256 756bcb97dcf1455f0ebf70e5dbe07256
SANs: onrender.com, *.onrender.com
CN=WE1,O=Google Trust Services,C=US (CA) CN=GTS Root R4,O=Google Trust Services LLC,C=US 13 Dec 2023 20 Feb 2029 ECDSA 256 ECDSA-SHA384 7ff31977972c224a76155d13b6d685e3
CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE 15 Nov 2023 28 Jan 2028 ECDSA 384 SHA256-RSA 7fe530bf331343bedd821610493d8a1b
DNSSEC insecure

Validation of axis-api-6c7z.onrender.com. Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
onrender.com. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200
Header Value
strict-transport-security max-age=31536000; includeSubDomains
x-content-type-options nosniff
x-frame-options DENY
referrer-policy strict-origin-when-cross-origin
permissions-policy camera=(), microphone=(), geolocation=()
Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://axis-api-6c7z.onrender.com/mcp Verified 200
http (plaintext) http://axis-api-6c7z.onrender.com/mcp HTTPS enforced 301 https://axis-api-6c7z.onrender.com/mcp
MCP tools — 37 exposed · ~10,734 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
analyze_files ~189

Analyze source files directly and generate the full 142-artifact AXIS bundle without using GitHub. Returns snapshot_id plus artifact listing; use this for local, generated, or unsaved code. Requires Authorization: Bearer <api_key>. Pricing: $0.50 standard, $0.15 lite budget mode, $25 engineer per run (same tiers as analyze_repo). Can return authentication, quota, payment-required, file-limit, or validation errors. Use analyze_repo for GitHub URLs or improve_my_agent_with_axis for recommendation-first agent hardening.

NameTypeReqDescription
filesarrayyesSource files to analyze
frameworksarrayyesDetected or known frameworks
goalsarrayyesAnalysis goals
project_namestringyesName of the project
project_typestringyesProject type (web_application, api_service, cli_tool, library, monorepo)
NameTypeReqDescription
artifact_countnumberyes
artifactsarrayyes
content_discarded_atstring|nullISO timestamp if this snapshot's source content was discarded after the owning account's web session logged out (R5.7), null if content is still live.
programs_executedarray
project_idstringyes
snapshot_idstringyes
statusstringyes

No examples provided.

analyze_repo ~226

Analyze a GitHub repository and generate 142 structured AXIS artifacts across 20 programs. Returns snapshot_id plus an artifacts listing; use get_artifact to read files and get_snapshot to re-enumerate outputs without re-running analysis. Requires Authorization: Bearer <api_key>. Use this when the source of truth is a GitHub repo URL. Pricing: $0.50 standard, $0.15 lite budget mode, $25 engineer per repo. Engineer mode (X-Agent-Mode: engineer — Living Architecture) adds a verified LLM specificity pass: a living-architecture.md whose every architectural claim is grounded in the repo's extracted facts or dropped. This is the paid path for full repo analysis and can return authentication, quota, payment-required, invalid-URL, or GitHub-fetch errors. private repos require a stored GitHub token. Use analyze_files instead for inline file payloads or list_programs/search_and_discover_tools when you are still selecting a workflow.

NameTypeReqDescription
github_urlstringyesGitHub repository URL (https://github.com/owner/repo)
NameTypeReqDescription
artifact_countnumberyes
artifactsarrayyes
content_discarded_atstring|nullISO timestamp if this snapshot's source content was discarded after the owning account's web session logged out (R5.7), null if content is still live.
programs_executedarray
project_idstringyes
snapshot_idstringyes
statusstringyes

No examples provided.

assemble_ce3_evidence ~306

Assemble a Visa Compelling Evidence 3.0 packet + eligibility verdict for a disputed card-absent-fraud (reason code 10.4) transaction using the real assembleCe3 engine: finds prior undisputed transactions in the caller-supplied history that share >=2 qualified data elements (device_id / ip_address / email / shipping_address / login_id) and fall 120-365 days before the disputed transaction, per CE 3.0 rules. Returns {eligible, qualifying_priors, matched_element_union, rejection_reason?, evidence_packet, caveat} plus a sha256 reproducibility proof. Free, no auth, deterministic, no side effects. HONESTY: CE 3.0 applies to reason code 10.4 ONLY (10.2/10.3 are card-present conditions), and this is ASSEMBLY ONLY — not a submission to VROL/Verifi (use assemble_representment for the Stripe representment path). AXIS does not publish win-rate estimates.

NameTypeReqDescription
disputeobjectyes{txn: {id, amount_minor, currency, created_at, disputed, device_id?, ip_address?, email?, shipping_address?, login_id?}, reason_code: string (CE 3.0 requires '10.4'), disputed_at: ISO timestamp}
transaction_historyarrayCandidate prior transactions (same Txn shape, max 500). Undisputed priors sharing >=2 qualified elements qualify.
NameTypeReqDescription
caveatstringyes'assembly only; not a submission to VROL/Verifi'.
eligiblebooleanyesTrue when >=2 qualifying priors were found under the CE 3.0 rules.
evidence_packetobjectyesThe structured, submission-ready CE 3.0 packet (assembly only).
matched_element_unionarrayyesUnion of matched qualified data elements across priors, canonical order.
proofobjectyes{algo:'sha256', digest, over[]} reproducibility proof.
qualifying_priorsarrayyes[{txn_id, matched_elements[], age_days}] most-matching first, deterministic order.
reason_codestringyesAlways '10.4' — the only CE 3.0 reason code.
rejection_reasonstringPresent iff eligible=false — why the packet did not qualify.

No examples provided.

assemble_representment ~386

Turn a webhook-ingested dispute (charge.dispute.* events persist DisputeRecords server-side) into a Stripe representment: qualifies CE 3.0 priors from your supplied transaction history (assembleCe3), builds the Stripe `evidence` hash (buildStripeRepresentment), walks the dispute state machine (needs_response → evidence_assembling → evidence_submitted) with a full transition ledger, and — when submit=true and Stripe is configured — submits the evidence through the live Stripe disputes API. Requires Authorization: Bearer <api_key>; metered ($0.50 standard, $0.25 lite) through the standard authorize/capture path — a failed assembly never charges. Returns {dispute, evidence, ce3, ce3_eligible, submitted, disclaimer}. HONESTY: the dispute lifecycle is LIVE on the Stripe rail only; VROL/RDR/CDRN (Verifi/Ethoca) is integration-ready code gated on acquirer provisioning (AXIS_ENABLE_VROL) and never fakes a submission. AXIS does not publish win-rate estimates.

NameTypeReqDescription
dispute_idstringyesProvider dispute id (Stripe dp_...) previously ingested by the charge.dispute.created webhook.
disputed_txnobjectOptional CE 3.0 data elements of the disputed transaction: {device_id?, ip_address?, email?, shipping_address?, login_id?}.
evidence_inputsobject{customerEmail?, shippingAddress?, billingAddress?, serviceDate?, productDescription?, deliveryTracking?, threeDsAuthenticated?} — merchant-supplied evidence fields.
submitbooleantrue → submit the built evidence to the Stripe disputes API (requires STRIPE_SECRET_KEY server-side). Default false (assemble only).
transaction_historyarrayCandidate prior transactions for CE 3.0 qualification (Txn shape, max 500).
NameTypeReqDescription
ce3objectyesFull assembleCe3 result (eligible, qualifying_priors, evidence_packet, caveat).
ce3_eligiblebooleanyes
disclaimerstringyesStripe-rail-live / VROL-gated honesty split + no-win-rate stance.
disputeobjectyesThe DisputeRecord after state-machine bookkeeping (state, dueBy, representmentId, ...).
evidenceobjectyesStripe `evidence` hash: uncategorized_text (CE 3.0 narrative) + customer_email_address/shipping_address/... from evidence_inputs.
submit_notestringPresent when submit was requested but skipped (e.g. Stripe not configured).
submittedbooleanyesTrue only when the evidence was actually submitted through the dispute client.

No examples provided.

build_ap2_mandate ~350

Validate, canonically encode, and optionally Ed25519-sign an AP2 mandate (Intent / Cart / Payment) using the real @axis/ap2 codecs — schema validation (including cart-total arithmetic and intent cross-references), RFC 8785 JCS-style canonical JSON encoding, and detached-JWS EdDSA signing over node:crypto. Pass seed_hex (64 hex chars = 32 bytes) to sign deterministically client-side-supplied key material — AXIS stores no keys; omit it for an unsigned template with encoding only. The signed envelope round-trips through verifyMandate before it is returned. Free, no auth, deterministic (Ed25519 signatures are deterministic per RFC 8032), no side effects. SCOPE HONESTY: conformant to AXIS's TypeScript encoding of the public AP2 mandate schema, verified against self-authored golden vectors — NOT certified against an official AP2 conformance suite or a live network counterparty.

NameTypeReqDescription
intent_contextobjectOptional IntentMandate to cross-reference a cart's intent_ref against.
mandateobjectyesAn AP2 mandate object: {kind: 'intent'|'cart'|'payment', version: 'ap2/1', id, created_at, ...kind-specific fields (intent: user_id/description/constraints.max_amount/expires_at; cart: intent_ref/mer…
seed_hexstringOptional 64-char hex (32-byte) Ed25519 seed to sign with. Caller-supplied key material — AXIS stores no keys. Omit for an unsigned template.
NameTypeReqDescription
encodedstringyesCanonical (JCS-style) JSON wire encoding — null when invalid.
issuesarrayyes[{path, message}] validation issues (empty when valid).
mandateobjectEcho of the validated mandate.
notestringyesSigned vs 'unsigned template — sign client-side' + trust-model caveat.
proofobjectyes{algo:'sha256', digest, over[]} reproducibility proof.
signedobjectWhen seed_hex supplied: {jws: {protected, signature}, public_key} — a SignedMandate envelope, verified before return.
validbooleanyesStructural validation verdict (validateMandate).
verifiedbooleanverifyMandate result for the signed envelope (null when unsigned).

No examples provided.

closer ~172

Package an existing AXIS snapshot (create one first via analyze_repo, analyze_files, or prepare_agentic_purchasing) into complete professional packaging + marketplace certification artifacts so a 70-80%-complete project is ready to ship and sell. Requires a paid plan or entitlement. Pricing: $0.50 standard, $0.25 lite budget mode.

NameTypeReqDescription
product_namestringOptional branding override for product name
project_rootstringOptional local project root path hint (metadata only in remote MCP mode)
snapshot_idstringyesExisting AXIS snapshot_id to package into a distributable product
taglinestringOptional branding tagline
target_marketplacesarrayOptional marketplaces list (e.g. npm, unreal, vscode, dockerhub, github-marketplace)
NameTypeReqDescription
artifact_countnumberyes
artifactsarrayyes
programstringyes
project_idstringyes
snapshot_idstringyes

No examples provided.

deploy ~151

Generate a zero-pipeline-minutes deploy bundle: stack-aware Dockerfile, .dockerignore, dev compose, render.yaml (Render existing-image), wrangler.pages.toml + wrangler.containers.toml + worker.ts (Cloudflare), bash/PowerShell push scripts, and a qualification report. The project builds locally in VSCode, pushes images to GHCR or via wrangler, and Render/Cloudflare just pulls — no GitHub Actions minutes, no Render build pipeline minutes, no CF build minutes. Requires a paid plan or entitlement. Pricing: $0.50 standard, $0.25 lite budget mode.

NameTypeReqDescription
snapshot_idstringyesExisting AXIS snapshot_id to package into deploy artifacts
NameTypeReqDescription
artifact_countnumberyes
artifactsarrayyes
programstringyes
project_idstringyes
snapshot_idstringyes

No examples provided.

discover_agentic_purchasing_needs ~136

Discover the best AXIS workflow for a purchasing or compliance task. Free, no auth, and logs lightweight task metadata for intent analytics. Example: task_description='prepare for autonomous Visa checkout'. Use this when you need commerce-specific triage and next-step guidance. Use search_and_discover_tools instead for non-commerce keyword routing across all programs.

NameTypeReqDescription
current_readinessnumberOptional: current Purchasing Readiness Score (0-100) if known
focus_areasarrayOptional: specific areas to focus on
task_descriptionstringWhat the agent is trying to accomplish
NameTypeReqDescription
matched_capabilitiesarrayyes
readinessobjectyes
recommended_next_stepobjectyes
task_descriptionstringyes

No examples provided.

discover_commerce_tools ~93

Discover AXIS install metadata, pricing, and shareable manifests for commerce-capable agents. Free, no auth, and no mutation beyond read access. Example: call before wiring AXIS into Claude Desktop, Cursor, or VS Code. Use this when you need onboarding and ecosystem setup details. Use search_and_discover_tools instead for keyword routing or discover_agentic_purchasing_needs for purchasing-task triage.

Input schema present but exposes no named parameters.

NameTypeReqDescription
axis_iliadobjectyes
free_toolsarrayyes
installobjectyes
shareable_manifestobjectyes
toolsarrayyes

No examples provided.

get_artifact ~105

Read one generated artifact by snapshot_id and path. Requires access to the snapshot and may return snapshot-not-found, invalid-path, or artifact-not-found errors. Example: snapshot_id=abc-123, path=AGENTS.md. Use this when you need the full text of one artifact. Use get_snapshot instead when you first need the artifact list.

NameTypeReqDescription
pathstringyesArtifact file path as returned in the artifacts list
snapshot_idstringyesSnapshot ID

Structured output declared, but exposes no named fields.

No examples provided.

get_referral_code ~91

Get or create the caller's AXIS referral token. Requires Authorization: Bearer <api_key>, has no usage charge, and may persist a new referral code if one does not exist yet. Example: call before sharing AXIS with another agent or workspace. Use this when you need the shareable token itself. Use get_referral_credits instead when you need balances, milestones, and discount status.

Input schema present but exposes no named parameters.

NameTypeReqDescription
coststringyes
current_earningsobjectyes
next_milestonestringyes
referral_tokenstringyes
share_instructionstringyes

No examples provided.

get_referral_credits ~87

Get the caller's referral earnings, milestones, and free-call status. Requires Authorization: Bearer <api_key>, has no usage charge, and returns the current discount ledger without creating a new analysis. Example: call after a referral campaign to inspect earned credits. Use this when you need balances and milestones. Use get_referral_code instead when you only need the shareable token.

Input schema present but exposes no named parameters.

NameTypeReqDescription
coststringyes
discount_activebooleanyes
earned_credits_millicentsnumberyes
earned_discountstringyes
free_calls_remainingnumberyes
lifetime_referralsnumberyes
next_milestonestringyes
paid_call_countnumberyes
persistence_credits_remainingnumberyes
referral_tokenstringyes
tierstringyes

No examples provided.

get_snapshot ~175

Retrieve status and the full artifact listing for a prior analysis by snapshot_id. Use this to re-enumerate artifact paths without re-running analysis. Snapshots created with an API key are scoped to that same account — pass the same Authorization: Bearer <api_key> used to create it, or retrieval fails with a not-found error. Only anonymous (never-authenticated) snapshots are freely retrievable by any caller. The response's content_discarded_at is non-null if the owning account's web session has since logged out — source content is gone (closer/deploy/skills/search_index calls on this snapshot will fail with content_discarded until it's re-uploaded), though this call itself still succeeds and generated artifacts remain listable.

NameTypeReqDescription
snapshot_idstringyesSnapshot ID returned by analyze_repo or analyze_files
NameTypeReqDescription
artifact_countnumberyes
artifactsarrayyes
content_discarded_atstring|nullISO timestamp if this snapshot's source content was discarded after the owning account's web session logged out (R5.7), null if content is still live.
programs_executedarray
project_idstringyes
snapshot_idstringyes
statusstringyes

No examples provided.

grade_compliance ~230

Run the real 8-check AP2/Visa compliance grading engine (gradeCompliance — the same engine behind computeComplianceGrade and the commerce registry's verified_decisions block) over an inline file set. Each of the 8 validators (SCA/3DS2 readiness, AP2 mandate validity, tokenization posture, CE 3.0 readiness, dispute rail wiring, idempotency/receipt hygiene, budget negotiation, refund/cancel path) is a multi-signal check with weight, evidence trail, and remediation. Returns grade A-D, score, checks_passed/8, the full checks[] detail, detected commerce signals, and a sha256 reproducibility proof. Free, no auth, deterministic, no snapshot persisted. Hard caps: 25 files / 50KB per file / 1MB total. HONESTY: deterministic static source-signal analysis — a checklist starting point, NOT a certification, audit, PCI assessment, or card-network certification.

NameTypeReqDescription
filesarrayyesSource files to grade (max 25 files, 50KB each, 1MB total)
NameTypeReqDescription
checksarrayyesPer-check {name, title, status, weight, score, evidence[], remediation}.
checks_passednumberyes
checks_totalnumberyesAlways 8.
gradestringyesA | B | C | D (score >= 85 / 65 / 40 / below).
methodologystringyesThe engine's own honesty statement (static analysis, not a certification).
proofobjectyes{algo:'sha256', digest, over[]} reproducibility proof.
scorenumberyesWeighted 0-100 score across the 8 checks.
signalsobjectyesdetectCommerceSignals(files) — providers + capability booleans the grade was derived from.

No examples provided.

iliad_analytics ~312

AXIS-owned product analytics. Two operations: `capture` (insert events) and `query` (aggregations). Capture accepts a single `event` or a batch via `events[]` (max 500). Query kinds: `count` (total events), `count_by_event` (top events by frequency), `distinct_users` (unique user_id count), `count_by_bucket` (time-series with minute/hour/day buckets). All queries support optional `event`, `from_ts`, `to_ts`, and `property_filter` filters. Namespaces are account-scoped server-side (`acct:<account_id>:<namespace>`). Persistent across restarts via Postgres (the shared @axis/snapshots database). Pricing: $0.01 standard, free in lite mode. Requires Authorization: Bearer <api_key>. Best for funnels, cohorts, and retention on workloads up to ~1M events per account.

NameTypeReqDescription
eventobjectSingle event payload {event, user_id?, properties?, timestamp?} — used in capture mode.
eventsarrayBatch of event payloads (max 500). Transactional — partial inserts never persist.
namespacestringLogical isolation key. Defaults to 'default'. Account id is always prepended server-side.
operationstringyescapture or query.
queryobject{kind, event?, from_ts?, to_ts?, property_filter?, bucket?, limit?} — used in query mode.
NameTypeReqDescription
capturednumberEvents written (capture mode only).
namespacestringScoped namespace the call wrote to or queried.
operationstringEcho of the operation that ran.
resultobjectAggregation result shape depending on query.kind (query mode only).

No examples provided.

iliad_code_sandbox ~461

AXIS-owned secure code execution. Each call spawns a fresh ephemeral Docker container with hardened isolation: no network, read-only root filesystem, all Linux capabilities dropped, no-new-privileges, PID/memory/CPU limits, tmpfs /tmp only, runs as nobody:nobody. Container is force-removed after each call. Supports python | node | bash via the multi-runtime image `nikolaik/python-nodejs:python3.12-nodejs22-slim` (operator can override via AXIS_CODE_SANDBOX_IMAGE). Returns stdout/stderr/exit_code/timed_out/duration_ms/image. Wall-clock timeout enforced via SIGKILL + force-remove. Source is fed via stdin (no fs write to the read-only root). Code body capped at 256 KiB; stdin at 1 MiB; timeout 1-600 seconds (default 30); stdout/stderr each capped at 1 MiB output. Pricing: $0.05 standard, $0.02 lite — billed whenever a container actually ran, including a timeout or non-zero exit code. Not billed when the call instead returns `_not_configured: true`: no Docker daemon reachable (Render standard services don't expose /var/run/docker.sock), the operator has set AXIS_CODE_SANDBOX_DISABLED=1, or more than AXIS_SANDBOX_MAX_CONCURRENT (default 4) runs are already in flight (reason sandbox_busy — transient, retry shortly). Engineer mode (X-Agent-Mode: engineer — Verified Exec, $0.25): the result includes an Ed25519-signed attestation binding code-hash → output-hash + a per-account hash-chain entry, so another agent that pins AXIS's published key can verify the run without re-executing it. Requires Authorization: Bearer <api_key>.

NameTypeReqDescription
codestringyesSource code to execute. Fed via stdin to the interpreter. Max 256 KiB.
languagestringyesRuntime language.
stdinstringOptional additional stdin appended after the code body. Max 1 MiB.
timeout_secondsnumberWall-clock limit. Defaults 30, max 600. SIGKILL on overrun.
NameTypeReqDescription
_not_configuredbooleanTrue when the call didn't run (unreachable daemon, disabled, or at concurrency limit).
attestationobjectEngineer mode only: Ed25519-signed attestation binding code-hash to output-hash, plus a per-account hash-chain entry.
duration_msnumberEnd-to-end wall time including container spawn + teardown.
exit_codenumberProcess exit code (137 on SIGKILL).
imagestringContainer image actually used.
reasonstringdocker_daemon_unreachable | dockerode_import_failed | disabled | sandbox_busy (only when _not_configured=true).
remediationstringHow the operator (or, for sandbox_busy, the caller by retrying) should resolve the condition.
stderrstringCaptured stderr (UTF-8, capped at 1 MiB).
stdoutstringCaptured stdout (UTF-8, capped at 1 MiB with truncation marker).
timed_outbooleanTrue if the wall-clock timeout fired.

No examples provided.

iliad_document_parsing ~461

AXIS-owned document → Markdown extractor. Accepts either `document_url` (https fetch + 50 MiB cap + 60s timeout) or `document_base64` (inline bytes, 50 MiB decoded cap) — exactly one. Optional `mime_type` hint (application/pdf, application/vnd.openxmlformats-officedocument.wordprocessingml.document, text/html, text/markdown, text/plain); we sniff from magic bytes + URL extension when omitted. Format dispatch: PDF → pdfjs-dist text extraction (one block per page with `--- page N ---` separators); DOCX → mammoth → markdown (tables preserved); HTML → tag-strip with heading + list + entity handling (NOT a full HTML→MD converter — bring turndown if you need fancier); plain text + markdown → passthrough. Returns `{markdown, format_detected, byte_size, page_count, table_count, truncated}`. Output capped at 1 MiB markdown with a truncation marker. Pricing: $0.02 standard, $0.01 lite. Engineer mode (X-Agent-Mode: engineer — Document Intelligence, $0.10): adds an `engineer` block with retrieval chunks (heading-aware, overlapping) + extract-to-caller-schema (pass `json_schema` → a grammar-constrained, validated typed object) + image OCR (image/* via document_base64, capped at 10 MiB — smaller than the 50 MiB document cap; an OCR failure or oversized image returns a descriptive `reason` that may not match the standard-mode enum) — typed data, not just markdown. Requires Authorization: Bearer <api_key>.

NameTypeReqDescription
document_base64stringBase64-encoded document bytes. Use this OR document_url, not both.
document_urlstringhttps URL to a document. Use this OR document_base64, not both.
json_schemaobjectEngineer mode: a JSON Schema. The document is extracted into a validated object matching it (returned in engineer.extracted).
mime_typestringOptional MIME-type hint. When omitted we sniff from magic bytes + URL extension. Engineer mode: an image/* mime triggers OCR.
NameTypeReqDescription
_not_configuredbooleanTrue when a prerequisite is missing or the document was unsupported.
byte_sizenumberRaw byte size of the source document.
engineerobjectEngineer mode only: { chunk_count, chunks, extracted? } — retrieval chunks + optional schema-validated extraction.
format_detectedstringpdf | docx | html | markdown | text | unknown | image (engineer-mode OCR path only).
markdownstringExtracted text, formatted as Markdown when the source had structure.
page_countnumber|nullPage count for PDFs; null otherwise.
reasonstringdocument_download_failed | document_decode_failed | unsupported_format | parse_failed | pdf_runtime_missing | docx_runtime_missing (only when _not_configured=true).
remediationstringOperator-actionable fix.
table_countnumberNumber of tables detected in the rendered markdown (DOCX only; 0 elsewhere).
truncatedbooleanTrue when the markdown output was capped at the 1 MiB ceiling.

No examples provided.

iliad_embeddings ~398

Convert text into dense vectors. Accepts a single string or a batch (max 2048). Returns one vector per input. AXIS-owned in-process inference by default (node-llama-cpp + an embedding-capable GGUF at AXIS_EMBEDDING_MODEL_PATH — no upstream provider call); an optional OpenAI /v1/embeddings backend is available behind AXIS_EMBEDDING_BACKEND=openai (model: text-embedding-3-small by default, overridable via OPENAI_EMBEDDING_MODEL; reports token usage). Requires Authorization: Bearer <api_key> to call. Pricing: $0.05 standard, $0.02 lite. When the selected backend is not provisioned (local: GGUF file absent; openai: OPENAI_API_KEY unset), returns a structured `_not_configured: true` envelope naming the backend and remediation, and is not billed. Pairs natively with iliad_vector_database — feed `vectors` from this tool's output into `vector` of the vector_database upsert/query calls. Engineer mode (X-Agent-Mode: engineer — Domain Embeddings, $0.08): pass `dimensions` (Matryoshka truncation → smaller vectors) and/or `corpus_adapter: true` (mean-center the batch to sharpen retrieval on your data); returns an `engineer` block with the fitted adapter_mean for query alignment.

NameTypeReqDescription
corpus_adapterbooleanEngineer mode: mean-center the batch (all-but-the-mean) to sharpen retrieval; returns the fitted adapter_mean.
dimensionsnumberEngineer mode: truncate each vector to this many leading dims (Matryoshka) + renormalize. Smaller, cheaper vectors.
inputstring|arrayyesA single string or an array of strings to embed. Empty strings and entries > 32k chars are rejected (chunk before calling).
NameTypeReqDescription
engineerobjectEngineer mode only: { dimensions, truncated, adapter_applied, adapter_mean? } — the post-processing applied + the fitted corpus mean.
input_countnumberyesNumber of inputs submitted (matches vectors.length).
model_usedstringyesConcrete embedding model used: the GGUF filename on the local backend, or the provider model name on the openai backend.
usageobject{prompt_tokens, total_tokens} — openai backend only (the local in-process backend has no provider token report).
vectorsarrayyesArray of dense vectors. vectors[i] corresponds to input[i] (order preserved).

No examples provided.

iliad_hygiene ~381

AXIS-owned workspace hygiene grader. Analyzes an inline file set [{path,content}] and returns a letter grade (A-F) across a closed set of dimensions plus structured findings. Two modes: mode='scan' (DEFAULT, FREE) returns grade + findings (committed-secret scan, .env/secret-file detection, .gitignore gaps for build/scratch artifacts, oversized blobs, stub/placeholder markers, byte-identical duplicate files, source test-peer coverage, TODO/FIXME debt); mode='fix' (METERED, $0.05 standard / $0.02 lite) adds a prioritized remediation plan with ready-to-apply .gitignore additions and per-finding actions. Sending X-Agent-Mode: engineer always bills the fix-mode price, even if mode is 'scan' or omitted. Deterministic, dependency-free, never mutates your repo (fix returns a PLAN). Rules needing a live git checkout/toolchain (worktree pruning, build/vet, governance-source-of-truth checks, route-registration dup-handler analysis, ROI-queue coherence) are reported as repo_only_rules, not run. Engineer mode (X-Agent-Mode: engineer — Security Engineer, $5): the fix arrives as a git-applyable unified-diff patch (`patch`) + a SARIF 2.1.0 log for CI code-scanning (`sarif`). Requires Authorization: Bearer <api_key>.

NameTypeReqDescription
configobjectOptional threshold overrides: maxFileBytes, coverageA, coverageB, coverageC, todoDebtThreshold.
filesarrayyesInline files [{path, content}] to scan (non-empty; each content <= 5 MB).
modestringscan (free grade+findings, default) | fix (metered, adds remediation plan).
NameTypeReqDescription
countsobject{high, medium, low, deferredByPolicy} open-finding counts.
dimensionsarrayPer-dimension grade [{id, grade, detail}].
findingsarrayAll findings [{id, ruleId, severity, path, message, policy, recommendedAction}].
gradestringOverall hygiene grade A-F (minimum across dimensions).
modestringEcho of the mode that ran.
paid_fix_hintstringscan mode only: how to obtain the metered remediation plan.
patchstringEngineer mode only: git-apply-able unified diff of the safe auto-fixes (currently .gitignore additions only); empty string when nothing is safely auto-fixable.
reasonsarrayDimensions that capped the grade below A.
remediation_planobjectfix mode only: {ordered_steps, gitignore_additions, summary}.
repo_only_rulesarrayRules that need a live repo and were not run.
sarifobjectEngineer mode only: SARIF 2.1.0 log of all open findings for CI code-scanning.
scannedobject{files, bytes} actually analyzed.

No examples provided.

iliad_llm_inference ~558

AXIS-hosted LLM chat-completion via node-llama-cpp + a small GGUF model loaded in-process. Two input shapes accepted: `prompt` (single string) or `messages` (chat-style array of {role, content}). Sampling controls: `max_tokens` (≤2048), `temperature` (0-2), `top_k`, `top_p`, `seed` (threaded through for more deterministic output — NOT a proven byte-identical guarantee; thread count isn't pinned and GGML's multi-threaded matmul reduction order isn't guaranteed bit-exact across runs), `stop` (string[]). Inference runs in-process — no upstream LLM provider call — but this AXIS tool call is still billed: $0.02 standard, $0.01 lite. Operator sets AXIS_LLM_MODEL_PATH to point at a Phi-3-mini / TinyLlama / Llama-3.2-1B GGUF; if missing, the tool returns a `_not_configured: true` envelope and is not billed. Engineer mode (X-Agent-Mode: engineer — Constrained Inference, $0.10): pass a `json_schema` and decoding is grammar-constrained to it AND the output is validated against it (returns a `structured` block with valid + parsed + schema_errors) — guaranteed-valid structured output. Requires Authorization: Bearer <api_key>.

NameTypeReqDescription
json_schemaobjectEngineer mode (required): a JSON Schema. Decoding is grammar-constrained to it and the output is validated against it; returns a `structured` block.
max_tokensnumberMax tokens to generate. Defaults 512, hard cap 2048.
messagesarrayChat-style input. Array of {role: system|user|assistant, content: string}.
promptstringSingle-prompt completion input. Use either this OR messages, not both.
seednumberOptional seed, threaded through with temperature for more deterministic output. Not a proven byte-identical guarantee (thread count/matmul reduction order isn't pinned) — see the tool description.
stoparrayStop sequences. Generation halts when any string in the array is produced.
systemstringOptional system prompt (prompt mode only). For messages mode, use role=system entries.
temperaturenumberSampling temperature in [0, 2]. Defaults 0.7.
top_knumberTop-k sampling (positive integer). Defaults 40.
top_pnumberTop-p nucleus sampling in (0, 1]. Defaults 0.95.
NameTypeReqDescription
_not_configuredbooleanTrue when no GGUF model is present at AXIS_LLM_MODEL_PATH.
completion_tokensnumberToken count of the generated text (best-effort).
model_pathstringPath checked for the GGUF file (only present when _not_configured=true).
model_usedstringBasename of the GGUF model file used.
prompt_tokensnumberToken count of the input prompt (best-effort).
reasonstringWhy the tool returned _not_configured (only present when true).
remediationstringHow the operator should fix the missing-model condition.
structuredobjectEngineer mode only: { schema_constrained, valid, parsed, schema_errors } — the guaranteed-valid structured-output verdict.
textstringGenerated completion text.

No examples provided.

iliad_network_tokenization ~436

Network-tokenization capability. (1) `lifecycle`: an EXECUTABLE TAP-style token-lifecycle state machine (provision → activate → suspend → resume → delete; deleted is terminal; illegal transitions are rejected with an error, not silently accepted) — pure simulation, no real payment method involved. (2) `capabilities` reports which providers are configured (env-derived). (3) `read` and (4) `provision` are TEMPORARILY DISABLED: both would resolve a caller-supplied payment_method_id/pan_source against the platform's Stripe account, and this service has no way yet to verify that id belongs to the calling AXIS account — calling either always returns a structured `_not_configured: true` envelope explaining this, never real payment-method data. (For context once re-enabled: `read`'s underlying Stripe adapter is fully implemented; direct VTS/MDES `provision` is additionally capability-gated behind a network-issued Token Requestor ID — AXIS_VTS_TOKEN_REQUESTOR_ID / AXIS_MDES_TOKEN_REQUESTOR_ID — plus network onboarding, and NEVER fakes a token.) Raw PANs are never accepted even when disabled (pan_source is documented as an opaque reference only). Free (unmetered); requires Authorization: Bearer <api_key>.

NameTypeReqDescription
eventstringlifecycle: single-event shorthand for `events: [event]`.
eventsarraylifecycle: ordered TokenEvent list (provision|activate|suspend|resume|delete), max 100. Must start from provision; illegal transitions throw.
operationstringread (default, disabled) | provision (disabled) | lifecycle | capabilities.
pan_sourcestringprovision: ignored — this operation is disabled and always returns _not_configured. NEVER a raw PAN in any case.
payment_method_idstringread: ignored — this operation is disabled and always returns _not_configured.
providerstringprovision: ignored — this operation is disabled and always returns _not_configured.
NameTypeReqDescription
_not_configuredbooleanTrue for every read/provision call (disabled) and for capability-gated states.
capabilitiesobject{ stripe, vts, mdes } — which providers are configured (env-derived).
honestystringThe stripe-live / VTS-MDES-gated honesty statement (capabilities only).
lifecycleobjectlifecycle: { state, history: [{from, event, to}] } after applying every event.
operationstringThe operation that ran.
provider_checkedstringAlways 'stripe' for the disabled read/provision envelope; the real provider gate name otherwise.
reasonstringWhy the call returned _not_configured (only when true).
remediationstringWhat to use instead, or the exact env var / onboarding step required.
toolstringAlways 'iliad_network_tokenization'.

No examples provided.

iliad_object_storage ~506

AXIS-owned signed-URL minter backed by Cloudflare R2. Returns a pre-signed PUT or GET URL scoped to the calling account (keys are prefixed with `accounts/<account_id>/` server-side, so accounts can't reach each other's objects). Requires Authorization: Bearer <api_key>. Returns the URL plus expires_at (ISO 8601), bucket, and scoped_key. Returns `{_not_configured: true, ...}` when the operator has not provisioned R2_* env vars (no crash, no leaked secrets); not billed when not configured. Pricing: $0.01 standard, free in lite mode. TTL is capped at 86400 seconds (24h). Engineer mode (X-Agent-Mode: engineer — Managed Bucket, $0.05): adds delete + list + copy (server-side, no bytes through the agent) operations, content-addressed dedup keys (content_sha256), and mint-time PUT policy (pin content_type / exact content_length as signed headers R2 enforces).

NameTypeReqDescription
content_lengthnumberEngineer mode (put): pin the EXACT byte size the upload must be (signed; ≤5 GiB). Pairs with content_sha256 for verified content-addressed writes.
content_sha256stringEngineer mode: 64-char hex sha256 of the bytes you'll PUT. When set, the object lands under accounts/<id>/cas/<sha256> so identical content dedupes.
content_typestringEngineer mode (put): pin the Content-Type the upload must send (signed; R2 rejects a mismatch). Printable ASCII type/subtype, ≤255 chars. Echo via required_headers.
extstringEngineer mode: optional extension appended to the content-addressed key (e.g. 'png').
keystringyesObject key (max 1024 chars), or the prefix for operation=list. Path traversal and leading-/ are rejected.
operationstringyesput / get (standard). delete / list / copy and content-addressed put require X-Agent-Mode: engineer (Managed Bucket).
source_keystringEngineer mode (operation=copy): source object key to copy from, scoped to your account; `key` is the destination. Echo the returned required_headers on the PUT.
ttl_secondsnumberSigned-URL lifetime, 1..86400. Defaults to 3600.
NameTypeReqDescription
bucketstringyesResolved R2 bucket name.
expires_atstringyesISO-8601 expiry timestamp.
operationstringPUT or GET — what the URL was signed for.
scoped_keystringyesServer-side key after account scoping (the user-supplied key prefixed with accounts/<account_id>/).
urlstringyesPre-signed URL valid for ttl_seconds.

No examples provided.

iliad_speech_to_text ~503

AXIS-owned audio transcription via whisper.cpp + ffmpeg-static. Accepts either `audio_url` (https URL we fetch, max 100 MiB, 60s download timeout) or `audio_base64` (inline bytes, max 100 MiB decoded) — exactly one. Accepts any audio format ffmpeg can decode (mp3, wav, m4a, opus, ogg, flac); we resample to 16 kHz mono WAV internally. Optional `language` (ISO-639-1 like "en" / "fr" / "ja", or "auto" — default). Optional `initial_prompt` (≤512 chars; biases spelling of rare names). Optional `word_timestamps` boolean. Returns `{text, segments: [{start, end, text}], language_detected, duration_seconds, model_used}`. Pricing: $0.03 standard, $0.01 lite. When operator hasn't installed whisper-cli or placed the GGML model file at AXIS_WHISPER_MODEL_PATH (default `models/ggml-base.en.bin`), returns `{_not_configured: true, reason, detail, remediation}` and is not billed. Engineer mode (X-Agent-Mode: engineer — Diarization, $0.10): the response adds `diarization` — speaker turns grouped from the segments by inter-segment pause gaps (tune with diarization_gap_seconds / max_speakers; this is pause-based turn segmentation, not acoustic speaker ID). Requires Authorization: Bearer <api_key>.

NameTypeReqDescription
audio_base64stringBase64-encoded audio bytes. Use this OR audio_url, not both.
audio_urlstringhttps URL to an audio file. Use this OR audio_base64, not both.
diarization_gap_secondsnumberEngineer mode: pause (seconds) between segments that starts a new speaker turn. Defaults 0.75.
initial_promptstringOptional bias prompt (≤512 chars) — useful for spelling of rare names.
languagestringISO-639-1 language code (en, fr, ja, ...) or 'auto' to autodetect. Defaults 'auto'.
max_speakersnumberEngineer mode: max alternating speaker labels. Defaults 2.
word_timestampsbooleanEmit word-level timestamps within segments. Defaults false.
NameTypeReqDescription
_not_configuredbooleanTrue when a prerequisite is missing.
diarizationarrayEngineer mode only: speaker turns [{speaker, start, end, text}] grouped from segments by inter-segment pause gaps.
duration_secondsnumberAudio duration as inferred from the last segment end timestamp.
language_detectedstringLanguage code whisper detected (or echoed from input language).
model_usedstringBasename of the GGML model file used.
reasonstringmodel_file_not_found | whisper_cli_not_found | ffmpeg_static_missing | audio_download_failed | audio_decode_failed (only when _not_configured=true).
remediationstringOperator-actionable fix for the unconfigured prerequisite.
segmentsarray[{start: seconds, end: seconds, text}] timestamped segments.
textstringFull transcript text, joined from segments.

No examples provided.

iliad_text_to_speech ~482

AXIS-owned voice synthesis via Piper (rhasspy/piper) + ffmpeg-static. Accepts `text` (1-5000 chars), optional `voice` slug (filename without extension; defaults to AXIS_PIPER_DEFAULT_VOICE or the first available voice), optional `format` (wav | mp3 | opus; defaults wav), optional `sentence_silence` (0-5 seconds, default 0.2). Returns `{audio_base64, format, voice_used, sample_rate, duration_seconds, byte_size}`. Inference runs in-process — no upstream provider call — but this AXIS tool call is still billed: $0.02 standard, $0.01 lite. When operator hasn't installed piper or placed voice .onnx + .onnx.json files in AXIS_PIPER_VOICE_DIR (default models/piper/), returns `{_not_configured: true, reason, detail, remediation}` and is not billed. format=mp3/opus additionally requires ffmpeg-static. Engineer mode (X-Agent-Mode: engineer — Brand Voice, $0.10): requires `brand_text` (a brand / voice-and-tone artifact — the call throws without it in engineer mode) and AXIS auto-derives the voice persona (Piper voice slug + sentence pacing) and synthesizes in it; the persona is echoed in the response. Requires Authorization: Bearer <api_key>.

NameTypeReqDescription
brand_textstringRequired when X-Agent-Mode: engineer is set (the call throws without it); ignored otherwise. Brand / voice-and-tone artifact — AXIS derives a voice persona from it and synthesizes in that voice (over…
formatstringAudio codec.
genderstringEngineer mode: persona gender override.
localestringEngineer mode: persona locale override.
sentence_silencenumberPer-sentence silence in seconds (0-5). Defaults 0.2.
textstringyesText to speak. 1-5000 chars after trim.
voicestringVoice slug (filename without extension, e.g. 'en_US-amy-medium'). Defaults to first available voice or AXIS_PIPER_DEFAULT_VOICE.
NameTypeReqDescription
_not_configuredbooleanTrue when a prerequisite is missing.
audio_base64stringBase64-encoded audio bytes in the requested format.
byte_sizenumberByte length of the encoded audio (post-transcode for mp3/opus).
duration_secondsnumberAudio duration in seconds, computed from the WAV header.
formatstringEcho of the requested format.
personaobjectEngineer mode only: the derived voice persona (voice slug, sentence_silence, locale, gender, tone_tags) used for this synthesis.
reasonstringpiper_cli_not_found | voice_dir_missing | no_voices_available | voice_model_not_found | voice_config_not_found | ffmpeg_static_missing | synthesis_failed (only when _not_configured=true).
remediationstringOperator-actionable fix for the unconfigured prerequisite.
sample_ratenumberWAV sample rate parsed from the RIFF header (typically 22050 for Piper).
voice_usedstringVoice slug that was used (resolved if caller omitted `voice`).

No examples provided.

iliad_transactional_email ~426

Send a single transactional email. Requires Authorization: Bearer <api_key>. Provide either body_html, body_text, or both (Resend will pick the best variant per recipient). All emails ship from RESEND_FROM_ADDRESS — operator must verify that domain in Resend before sending. Returns the provider-assigned message_id plus the accepted recipient list. Pricing: $0.02 standard, $0.01 lite. Returns a structured _not_configured envelope when RESEND_API_KEY or RESEND_FROM_ADDRESS is missing, and is not billed. Recipients capped at 50 per call; subject capped at 998 chars; bodies capped at 1 MB. Engineer mode (X-Agent-Mode: engineer — Deliverability, $0.50): instead of sending, pass a `domain` and get a full SPF/DKIM/DMARC setup (fresh DKIM keypair) + sender warmup schedule + verification checklist — no email sent, no ESP key needed.

NameTypeReqDescription
body_htmlstringHTML body. At least one of body_html / body_text required.
body_textstringPlaintext body. At least one of body_html / body_text required.
dkim_selectorstringEngineer mode: DKIM selector (alphanumeric/hyphen, 1-32). Defaults 'axis'.
dmarc_policystringEngineer mode: DMARC policy none|quarantine|reject. Defaults none (monitoring).
domainstringEngineer mode (Deliverability): domain to generate SPF/DKIM/DMARC setup for. Replaces the send.
providerstringEngineer mode: ESP for the SPF include (resend/sendgrid/mailgun/postmark/ses/google). Defaults resend.
reply_tostringOptional Reply-To address.
subjectstringEmail subject (max 998 chars, RFC 5322).
tostring|arrayRecipient address or array of addresses (max 50). Required for a send (standard mode).
NameTypeReqDescription
delivered_toarrayyesRecipients the provider accepted.
fromstringyesRESEND_FROM_ADDRESS used as the From: header.
message_idstringyesProvider-assigned message ID.
subjectstringyesSubject sent (echo).

No examples provided.

iliad_vector_database ~360

AXIS-owned vector store. Two operations: `upsert` (insert or replace vectors) and `query` (cosine top-k nearest neighbors). Namespaces are account-scoped server-side (`acct:<account_id>:<namespace>`), so tenants cannot read each other's vectors. Persistent across restarts via Postgres. Requires Authorization: Bearer <api_key>. Pricing: $0.01 standard, free in lite mode. Best for RAG retrievers, deduplication, and similarity search. Engineer mode (X-Agent-Mode: engineer — Managed Memory, $0.05): query runs a pgvector/HNSW ANN candidate pool with optional recency-decay reranking (recency_half_life_days — managed forgetting), RRF hybrid fusion (sparse_ids), and metadata filter; upsert applies intra-batch semantic-dedup (dedup_threshold).

NameTypeReqDescription
dedup_thresholdnumberEngineer upsert: cosine threshold for intra-batch semantic-dedup (default 0.97).
namespacestringLogical isolation key. Defaults to 'default'. Account ID is always prepended server-side.
operationstringyesupsert (insert/replace) or query (top-k cosine).
queryobject{vector: number[], top_k?: number, filter?: object}. Engineer mode also reads recency_half_life_days (number — exponential recency decay) and sparse_ids (string[] — RRF hybrid fusion). Required for q…
semantic_dedupbooleanEngineer upsert: set false to disable dedup (default on).
vectorsarrayArray of {id, vector, metadata?} — required for upsert.
NameTypeReqDescription
backendstringEngineer query: 'pgvector' or 'js' — which ANN path served the query.
engineerobjectEngineer query only: { ann, recency_decay, hybrid_fusion } flags.
matchesarrayNearest neighbors sorted by score desc (query mode only).
namespacestringScoped namespace the call wrote to or queried.
operationstringEcho of the operation that ran.
semantic_dedupobjectEngineer upsert only: { dropped: [{id, duplicate_of, similarity}] } — vectors dropped as intra-batch duplicates.
total_in_namespacenumberTotal vectors in this namespace after the call (upsert mode only).
upsertednumberVectors written (upsert mode only).

No examples provided.

iliad_web_research ~196

Scrape a single URL with AXIS's owned crawler (SSRF-guarded fetch, robots.txt-aware, readability extraction — no third-party key) and return markdown-formatted content. Honest scope: fetches static HTML only, no JavaScript rendering, so client-rendered SPA pages may extract thin content. Returns markdown body, extracted metadata, and title. Best for research, documentation reading, or SEO analysis. Requires Authorization: Bearer <api_key>. Pricing: $0.10 standard, $0.05 lite per page. If the operator's backend configuration is incomplete, this call returns {_not_configured:true} instead of scraping, and is not billed. Use iliad_web_research_crawl for crawling multiple pages or link following.

NameTypeReqDescription
only_main_contentbooleanExtract only the main content (default: true)
urlstringyesThe URL to scrape (http or https)
NameTypeReqDescription
dataobject
errorstringError message if request failed
successbooleanyes

No examples provided.

iliad_web_research_crawl ~219

Crawl a domain with AXIS's owned crawler — a same-origin BFS frontier with robots.txt compliance and per-host politeness, no third-party key — and scrape multiple pages. Honest scope: static HTML only, no JavaScript rendering. Returns array of scraped pages with markdown content. Best for site mapping, content audits, or bulk research. Requires Authorization: Bearer <api_key>. Pricing: $0.01/page beyond your account's shared 100-page/month free pool (standard and lite) — a crawl fully covered by the free pool costs $0.00; a fully-paid 100-page crawl costs up to $1.00. If the operator's backend configuration is incomplete, this call returns {_not_configured:true} instead of crawling, and is not billed. Use iliad_web_research for single-page scrapes.

NameTypeReqDescription
limitnumberMaximum pages to crawl (1-100, default: 10)
urlstringyesThe domain/URL to crawl (http or https)
NameTypeReqDescription
dataobject
errorstringError message if request failed
successbooleanyes

No examples provided.

iliad_web_search ~443

AXIS-owned BM25 search engine over the corpus YOUR account has indexed. NOT a Google/Bing scraper — agents build their own searchable index by first calling operation='index' with documents (often pages fetched via iliad_web_research), then querying with operation='search'. Five operations: `index` (insert one or many documents), `search` (BM25 top-k ranked hits with snippet + score + metadata), `delete` (drop one doc), `delete_namespace` (drop all), `count`. Namespaces are account-scoped server-side (`acct:<id>:<namespace>`). Persistent across restarts via Postgres (the shared @axis/snapshots database). Search supports `max_results` (default 10, max 100) and `site` (restrict to a single URL host, case-insensitive). Only operation='search' is billed ($0.01 standard, free in lite mode) — index, delete, delete_namespace, and count are always free. Engineer mode (X-Agent-Mode: engineer — Answer Engine, $0.25): search also returns a grounded extractive answer with [n] citation spans over your corpus, reranked, refusing on weak evidence. Requires Authorization: Bearer <api_key>.

NameTypeReqDescription
doc_idstringDocument id to remove. Required in delete mode.
documentobjectSingle document {doc_id, url?, title?, content, metadata?} — used in index mode (alternative to documents[]).
documentsarrayBatch of documents (max 100). Transactional — malformed entry aborts the whole call.
max_resultsnumberCap on hits returned. Defaults 10, max 100.
namespacestringLogical isolation key. Defaults 'default'. Account id is always prepended server-side.
operationstringyesindex | search | delete | delete_namespace | count.
querystringSearch query (1-1024 chars). Required in search mode.
sitestringFilter to a single URL host (e.g. 'docs.python.org', case-insensitive).
NameTypeReqDescription
hitsarrayBM25-ranked hits [{doc_id, url, title, snippet, score, metadata}] (search mode).
indexednumberDocuments written (index mode).
namespacestringScoped namespace the call touched.
operationstringEcho of the operation that ran.
querystringEcho of the search query (search mode).
removedboolean|numberdelete: boolean; delete_namespace: count of rows removed.
totalnumberDocument count (count mode).
total_in_namespacenumberDocuments currently in the namespace (index, search modes -- count mode returns this same figure under the field name `total` instead).

No examples provided.

improve_my_agent_with_axis ~130

Analyze an agent codebase and return a prioritized AXIS hardening plan. Requires Authorization: Bearer <api_key>; this creates a snapshot and may return auth, quota, file-limit, or validation errors. Example: pass your agent source files to see missing AGENTS.md, CLAUDE.md, and MCP config gaps. Use this when you want recommendations and missing-context detection. Use analyze_files instead when you want the full artifact bundle directly.

NameTypeReqDescription
filesarrayyesSource files of the agent to analyze
project_namestringyesName of the agent/project to improve
NameTypeReqDescription
analysisobjectyes
call_againobjectyes
improvement_planobjectyes
mcp_configobjectyes
project_namestringyes
snapshot_idstringyes

No examples provided.

list_programs ~67

Inventory mode. List all 20 AXIS programs, their generators, pricing tier, and artifact paths. Free, no auth, and no side effects. Use search_and_discover_tools instead when you only have a keyword, or discover_commerce_tools when you need install and onboarding metadata.

Input schema present but exposes no named parameters.

NameTypeReqDescription
free_programsarrayyes
pro_programsarrayyes
programsarrayyes
total_generatorsnumberyes
total_programsnumberyes

No examples provided.

ping_payment ~119

Exercise the real x402 payment-flow loop at $0 — zero risk, no auth required. Call it once with no payment credential to receive a 402-style payment_required challenge (the exact same shape every real paid tool returns); retry the same tools/call carrying a payment credential in Authorization (with your API key moved to X-Axis-Key) to get a success envelope. Learn the vocabulary here before paying real money for prepare_agentic_purchasing or analyze_repo. No side effects on any other tool, no real payment rail is ever touched.

Input schema present but exposes no named parameters.

NameTypeReqDescription
_payment_requiredboolean
messagestring
okboolean
settled_centsnumber
toolstring

No examples provided.

prepare_agentic_purchasing ~455

Prepare a codebase for agentic purchasing and return a readiness score plus commerce artifacts. Requires Authorization: Bearer <api_key>; paid analysis records a new snapshot and may return auth, quota, payment, file-limit, or validation errors. Pricing: $0.50 standard, $0.25 lite budget mode, $250 engineer per run. Lite mode returns the readiness score + top 3 gaps only, with an artifacts_note pointing at standard mode for the full artifact bundle — it does NOT include the artifacts themselves. Standard and engineer modes return the full bundle. focus_areas is recorded and echoed back in the response for the caller's own bookkeeping; it does not filter which artifacts are generated. Use this when you need AP2/UCP/Visa, CE 3.0 dispute evidence, checkout, dispute, and negotiation hardening. Engineer mode (X-Agent-Mode: engineer — Commerce Integration) also emits a deployable x402/AP2/PAI'D endpoint + a runnable sandbox test + a schema-validatable CE 3.0 pack + a transparent dispute-readiness score (a working integration, not just a score), plus a deployable Stripe network-token read adapter when a stripe signal is detected. Use discover_agentic_purchasing_needs instead when you only need workflow triage.

NameTypeReqDescription
agent_typestringConsuming agent type hint
budget_per_run_centsnumberAgent budget for this call in cents
filesarrayyesArray of {path, content} objects representing source files
focusstringAnalysis focus (default: purchasing)
focus_areasarrayCompliance focus areas, recorded and echoed back in the response for the caller's own reference — does not filter which artifacts are generated.
frameworksarrayyesDetected or known frameworks
goalsarrayyesProject goals
project_namestringyesName of the project
project_typestringyesProject type (web_application, api_service, cli_tool, library, monorepo)
referral_tokenstringOptional referral token from another agent
spending_windowstringAgent spending window
NameTypeReqDescription
artifact_countnumberyes
programs_executedarrayyes
project_idstringyes
snapshot_idstringyes
statusstringyes
summaryobjectyes

No examples provided.

prepare_agentic_purchasing_preview ~217

Compute a free Purchasing Readiness Score (0-100) and gap list for a codebase without generating artifacts. No auth, no charge, no snapshot persisted. Hard caps: 25 files / 50KB per file / 1MB total. Returns score, risk_level, top gaps, frameworks detected, and which AXIS programs would close which gaps. Use this to triage 'should I pay for the full hardening bundle?' before calling prepare_agentic_purchasing. The paid version generates the full artifact bundle including CE 3.0 dispute evidence, SCA exemption matrix, and TAP interop.

NameTypeReqDescription
filesarrayyesSource files to triage (max 25 files, 50KB each, 1MB total)
frameworksarrayOptional framework hints
project_namestringyesName of the project being previewed
project_typestringOptional project type hint (web_application, api_service, cli_tool, library, monorepo)
NameTypeReqDescription
conversionobject
coststring
frameworks_detectedarray
gapsarray
interpretationstring
risk_levelstring
scorenumberCurrent Purchasing Readiness Score (0-100) for the codebase as submitted
strengthsarray
top_3_gapsarray
what_axis_would_addarray

No examples provided.

sca_exemption_decision ~442

Decide the lighter-SCA path for a single transaction using AXIS's published 7-priority PSD2 exemption matrix (the same decideScaExemption engine that renders the SCA Exemption Decision Matrix in generated artifacts). Input: amount_eur (required, PSD2 thresholds are EUR-denominated — convert before calling) plus optional context flags (secure corporate program, MIT, fixed recurring + prior SCA, trusted beneficiary + prior SCA, one-leg-out, acquirer TRA fraud rate in basis points). Returns the chosen exemption, its priority, sca_required, rationale, fallback path, all applicable candidates, the rendered priority matrix, and a sha256 reproducibility proof. Free, no auth, deterministic, no side effects. HONESTY: decision-support only, NOT an authorization oracle — final exemption eligibility is decided by the acquirer/issuer; TRA caps use published EBA RTS Art. 15 bands, not your acquirer's live fraud rate.

NameTypeReqDescription
amount_eurnumberyesTransaction amount in EUR (PSD2 thresholds are EUR-denominated).
has_prior_scabooleanA prior SCA exists — gates recurring_fixed and trusted_beneficiary.
is_merchant_initiatedbooleanMIT with stored credential + original SCA reference (out of SCA scope).
is_one_leg_outbooleanPayer or payee outside the EEA (territorial scope, not a formal exemption).
is_recurring_fixedbooleanFixed-amount subsequent collection (RTS Art. 13). Requires has_prior_sca.
is_secure_corporatebooleanDedicated/lodged corporate card program (RTS Art. 16).
is_trusted_beneficiarybooleanMerchant on the cardholder's trusted list (RTS Art. 12). Requires has_prior_sca.
tra_acquirer_fraud_bpsnumberAcquirer reference fraud rate in basis points (EBA RTS Art. 15 bands: <=1 → €500 cap, <=6 → €250, <=13 → €100).
NameTypeReqDescription
caveatstringyesDecision-support-only honesty caveat.
decisionobjectyes{exemption, priority, sca_required, rationale, fallback, candidates, tra_cap_eur?}.
matrixstringyesThe rendered 7-priority SCA Exemption Decision Matrix (markdown) this decision was taken from.
proofobjectyes{algo:'sha256', digest, over[]} — reproducibility proof over canonical input+decision.

No examples provided.

score_dispute_readiness ~339

Score how ready a disputed transaction's EVIDENCE FILE is for representment, per Visa reason-code family, using the transparent scoreWinProbability heuristic (win-prob-v0: hand-set, documented logistic coefficients — exported, inspectable, monotonic in evidence). Input: reason_code + the evidence on file (CE 3.0 eligibility, matching data elements, prior undisputed transactions, delivery proof, AVS/CVV, 3DS, signed mandate, customer communication). Returns the heuristic score, band, top missing evidence (what to capture next), recommended action, rationale, model version, and a sha256 reproducibility proof. Free, no auth, deterministic. HONESTY (read this): this scores evidence-capture readiness and is NOT a dispute-win prediction — the v0 heuristic is NOT empirically calibrated against real network outcomes, is NOT a Visa-published or Visa-endorsed win rate, and AXIS does not publish win-rate estimates. Treat it as a prioritization signal for evidence gathering only; always follow your operator's dispute policy.

NameTypeReqDescription
evidenceobjectEvidence on file: {ce3Eligible?, matchingDataElements? (0-5), priorUndisputedTransactions? (0-10), hasDeliveryProof?, hasAvsMatch?, hasCvvMatch?, has3dsAuthenticated?, hasSignedMandate?, hasCustomerC…
reason_codestringyesVisa dispute reason code (e.g. '10.4', '13.1', '12.5'). Unknown codes fall back to a documented default family.
NameTypeReqDescription
disclaimerstringyesThe NOT-a-win-prediction honesty disclaimer (always present).
proofobjectyes{algo:'sha256', digest, over[]} reproducibility proof.
readinessobjectyes{reasonCode, readiness_score (0-1 heuristic score), band, topMissingEvidence[], recommendedAction, rationale[], modelVersion}.

No examples provided.

search_and_discover_tools ~126

Search AXIS programs by keyword and return ranked matches with artifact paths. Free, no auth, and no stateful side effects. Example: q=checkout returns commerce-relevant programs first. Use this when you know the outcome you want but not the right program. Use list_programs instead for the full catalog, discover_commerce_tools for install metadata, or discover_agentic_purchasing_needs for purchasing-specific triage.

NameTypeReqDescription
programstringOptional: filter results to a specific program name
qstringSearch query — keyword or phrase
NameTypeReqDescription
program_filterstring|nullyes
querystring|nullyes
resultsarrayyes
total_matchesnumberyes

No examples provided.