Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Axis Iliad — Codebase Intelligence For Agentic Commerce

REMOTE · AXIS-API-6C7Z.ONRENDER.COM · SCANNED SEP 20

Codebase intelligence for agents: 152 structured artifacts across 21 programs, one call.

0 this week 23 Trust /100

Recent critical change

Authorization (5 Sept 2026). See the changelog before you install this server.

Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security57
Transport & Reachability0
Schema Quality & AI Usability0
  • Schema not yet verified: we couldn't read the endpoint's schema.Unverified
Stability & Change Management0
  • Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage0
  • Tool coverage not yet verified: we couldn't read the endpoint's tools.Unverified
Tool Safety0
  • Tool safety not yet verified: we couldn't read the endpoint's tools.Unverified
Capabilities0
  • Capabilities not yet verified: we couldn't read the endpoint's capabilities.Unverified

Unverified: 5 categories

Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm.

Install

How do I install the Axis Iliad — Codebase Intelligence For Agentic Commerce MCP server?

Axis Iliad — Codebase Intelligence For Agentic Commerce is a hosted endpoint at https://axis-api-6c7z.onrender.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · axis-api-6c7z.onrender.com

# add to Claude Code
claude mcp add --transport http lastmanupinc-hub-axis-toolbox 'https://axis-api-6c7z.onrender.com/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "lastmanupinc-hub-axis-toolbox": {
      "url": "https://axis-api-6c7z.onrender.com/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "lastmanupinc-hub-axis-toolbox": {
      "type": "http",
      "url": "https://axis-api-6c7z.onrender.com/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.lastmanupinc-hub-axis-toolbox]
url = "https://axis-api-6c7z.onrender.com/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "lastmanupinc-hub-axis-toolbox": {
      "type": "remote",
      "url": "https://axis-api-6c7z.onrender.com/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add lastmanupinc-hub-axis-toolbox --url 'https://axis-api-6c7z.onrender.com/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  lastmanupinc-hub-axis-toolbox:
    url: "https://axis-api-6c7z.onrender.com/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "lastmanupinc-hub-axis-toolbox": {
      "Transport": "http",
      "Url": "https://axis-api-6c7z.onrender.com/mcp"
    }
  }
}
# add to Vellum
assistant mcp add lastmanupinc-hub-axis-toolbox -t streamable-http -u 'https://axis-api-6c7z.onrender.com/mcp'
// mcp.json
{
  "mcpServers": {
    "lastmanupinc-hub-axis-toolbox": {
      "type": "http",
      "url": "https://axis-api-6c7z.onrender.com/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 11 Sept 26 −53
    • Endpoint reachability: reachable → not serving MCP security
    • Stability: fail → unverified security
    • Authorization: fail → unverified security
    • Tool safety: pass → unverified security
    • Transport: pass → fail security
    • HSTS header: pass → fail security
    • Capabilities: fail → unverified functional
    • Tool coverage: 100 → unverified functional
  • 5 Sept 26 +53
    • Authorization: unverified → fail critical
    • Stability: unverified → fail security
    • Injection markers: unverified → pass security
    • HSTS header: fail → pass security
    • Transport: fail → pass security
    • MCP protocol: unverified → fail functional
    • Endpoint reachability: not serving MCP → reachable functional
    • Tool coverage: unverified → 100 functional
  • 1 Sept 26 −53
    • Endpoint reachability: reachable → not serving MCP security
    • Stability: fail → unverified security
    • Authorization: fail → unverified security
    • Tool safety: pass → unverified security
    • Transport: pass → fail security
    • HSTS header: pass → fail security
    • Capabilities: fail → unverified functional
    • Tool coverage: 100 → unverified functional
  • 30 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 94 to 97.

  • 29 Aug 26 −1

    No change was recorded against any check on this day. Stability & Change Management went from 97 to 94.

  • 27 Aug 26 0
    • Tool “analyze_files” rewrote its description, which is the text the model reads security
    • Tool “analyze_repo” rewrote its description, which is the text the model reads security
    • Tool “assemble_representment” rewrote its description, which is the text the model reads security
    • Tool “closer” rewrote its description, which is the text the model reads security
    • Tool “deploy” rewrote its description, which is the text the model reads security
    • Tool “get_snapshot” rewrote its description, which is the text the model reads security
    • Tool “iliad_web_research” rewrote its description, which is the text the model reads security
    • Tool “improve_my_agent_with_axis” rewrote its description, which is the text the model reads security
    • Tool “prepare_agentic_purchasing” rewrote its description, which is the text the model reads security
  • 26 Aug 26 +2
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 25 Aug 26 +51
    • Authorization: unverified → fail critical
    • Stability: unverified → fail security
    • A breaking change shipped without a version bump: still 0.5.3 security
    • Tool “discover_commerce_tools” was removed security
    • Stability: unverified → pass security
    • HSTS header: fail → pass security
    • Transport: fail → pass security
    • The server rewrote its instructions, which are the text every model session reads security
    • New tool “delete_snapshot”, which the server declares destructive security
    • Tool “list_programs” rewrote its description, which is the text the model reads security
    • Tool “search_and_discover_tools” rewrote its description, which is the text the model reads security
    • Tool “analyze_files” rewrote its description, which is the text the model reads security
    • Tool “analyze_repo” rewrote its description, which is the text the model reads security
    • Tool “closer” rewrote its description, which is the text the model reads security
    • Tool “deploy” rewrote its description, which is the text the model reads security
    • Tool “iliad_document_parsing” rewrote its description, which is the text the model reads security
    • Tool “iliad_object_storage” rewrote its description, which is the text the model reads security
    • Tool “iliad_speech_to_text” rewrote its description, which is the text the model reads security
    • Tool “iliad_text_to_speech” rewrote its description, which is the text the model reads security
    • Tool “iliad_vector_database” rewrote its description, which is the text the model reads security
    • Tool “iliad_web_research” rewrote its description, which is the text the model reads security
    • Tool “iliad_web_research_crawl” rewrote its description, which is the text the model reads security
    • Tool “improve_my_agent_with_axis” rewrote its description, which is the text the model reads security
    • Tool “ping_payment” rewrote its description, which is the text the model reads security
    • MCP protocol: unverified → fail functional
    • Endpoint reachability: not serving MCP → reachable functional
    • Tool coverage: unverified → 100 functional
    • New tool “get_install_manifest” functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 20 Sept 2026 · Probed https://axis-api-6c7z.onrender.com/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=onrender.com CN=WE1,O=Google Trust Services,C=US 24 Jul 2026 22 Oct 2026 ECDSA 256 ECDSA-SHA256 756bcb97dcf1455f0ebf70e5dbe07256
SANs: onrender.com, *.onrender.com
CN=WE1,O=Google Trust Services,C=US (CA) CN=GTS Root R4,O=Google Trust Services LLC,C=US 13 Dec 2023 20 Feb 2029 ECDSA 256 ECDSA-SHA384 7ff31977972c224a76155d13b6d685e3
CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE 15 Nov 2023 28 Jan 2028 ECDSA 384 SHA256-RSA 7fe530bf331343bedd821610493d8a1b

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of axis-api-6c7z.onrender.com. Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
onrender.com. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 503

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://axis-api-6c7z.onrender.com/mcp HTTP error 503
http (plaintext) http://axis-api-6c7z.onrender.com/mcp HTTPS enforced 301 https://axis-api-6c7z.onrender.com/mcp
MCP tools · 44 exposed · ~12,112 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
analyze_files ~197

Analyze source files directly and generate the full 152-artifact AXIS bundle without using GitHub. Returns snapshot_id plus artifact listing; use this for local, generated, or unsaved code. Requires Authorization: Bearer <api_key>. Pricing: $3.00 standard, $25 engineer per run (same tiers as analyze_repo). Lite mode is retired — it now returns the free artifact set at no charge. Can return authentication, quota, payment-required, file-limit, or validation errors. Use analyze_repo for GitHub URLs or improve_my_agent_with_axis for recommendation-first agent hardening.

NameTypeReqDescription
filesarrayyesSource files to analyze
frameworksarrayyesDetected or known frameworks
goalsarrayyesAnalysis goals
project_namestringyesName of the project
project_typestringyesProject type (web_application, api_service, cli_tool, library, monorepo)
NameTypeReqDescription
artifact_countnumberyes
artifactsarrayyes
content_discarded_atstring|nullISO timestamp if this snapshot's source content was discarded after the owning account's web session logged out (R5.7), null if content is still live.
programs_executedarray
project_idstringyes
snapshot_idstringyes
statusstringyes

No examples provided.

analyze_repo ~234

Analyze a GitHub repository and generate 152 structured AXIS artifacts across 21 programs. Returns snapshot_id plus an artifacts listing; use get_artifact to read files and get_snapshot to re-enumerate outputs without re-running analysis. Requires Authorization: Bearer <api_key>. Use this when the source of truth is a GitHub repo URL. Pricing: $3.00 standard, $25 engineer per repo. Lite mode is retired — it now returns the free artifact set at no charge. Engineer mode (X-Agent-Mode: engineer — Living Architecture) adds a verified LLM specificity pass: a living-architecture.md whose every architectural claim is grounded in the repo's extracted facts or dropped. This is the paid path for full repo analysis and can return authentication, quota, payment-required, invalid-URL, or GitHub-fetch errors. private repos require a stored GitHub token. Use analyze_files instead for inline file payloads or list_programs/search_and_discover_tools when you are still selecting a workflow.

NameTypeReqDescription
github_urlstringyesGitHub repository URL (https://github.com/owner/repo)
NameTypeReqDescription
artifact_countnumberyes
artifactsarrayyes
content_discarded_atstring|nullISO timestamp if this snapshot's source content was discarded after the owning account's web session logged out (R5.7), null if content is still live.
programs_executedarray
project_idstringyes
snapshot_idstringyes
statusstringyes

No examples provided.

assemble_ce3_evidence ~306

Assemble a Visa Compelling Evidence 3.0 packet + eligibility verdict for a disputed card-absent-fraud (reason code 10.4) transaction using the real assembleCe3 engine: finds prior undisputed transactions in the caller-supplied history that share >=2 qualified data elements (device_id / ip_address / email / shipping_address / login_id) and fall 120-365 days before the disputed transaction, per CE 3.0 rules. Returns {eligible, qualifying_priors, matched_element_union, rejection_reason?, evidence_packet, caveat} plus a sha256 reproducibility proof. Free, no auth, deterministic, no side effects. HONESTY: CE 3.0 applies to reason code 10.4 ONLY (10.2/10.3 are card-present conditions), and this is ASSEMBLY ONLY — not a submission to VROL/Verifi (use assemble_representment for the Stripe representment path). AXIS does not publish win-rate estimates.

NameTypeReqDescription
disputeobjectyes{txn: {id, amount_minor, currency, created_at, disputed, device_id?, ip_address?, email?, shipping_address?, login_id?}, reason_code: string (CE 3.0 requires '10.4'), disputed_at: ISO timestamp}
transaction_historyarrayCandidate prior transactions (same Txn shape, max 500). Undisputed priors sharing >=2 qualified elements qualify.
NameTypeReqDescription
caveatstringyes'assembly only; not a submission to VROL/Verifi'.
eligiblebooleanyesTrue when >=2 qualifying priors were found under the CE 3.0 rules.
evidence_packetobjectyesThe structured, submission-ready CE 3.0 packet (assembly only).
matched_element_unionarrayyesUnion of matched qualified data elements across priors, canonical order.
proofobjectyes{algo:'sha256', digest, over[]} reproducibility proof.
qualifying_priorsarrayyes[{txn_id, matched_elements[], age_days}] most-matching first, deterministic order.
reason_codestringyesAlways '10.4' — the only CE 3.0 reason code.
rejection_reasonstringPresent iff eligible=false — why the packet did not qualify.

No examples provided.

assemble_representment ~386

Turn a webhook-ingested dispute (charge.dispute.* events persist DisputeRecords server-side) into a Stripe representment: qualifies CE 3.0 priors from your supplied transaction history (assembleCe3), builds the Stripe `evidence` hash (buildStripeRepresentment), walks the dispute state machine (needs_response → evidence_assembling → evidence_submitted) with a full transition ledger, and — when submit=true and Stripe is configured — submits the evidence through the live Stripe disputes API. Requires Authorization: Bearer <api_key>; metered ($1.00 standard, $0.50 lite) through the standard authorize/capture path — a failed assembly never charges. Returns {dispute, evidence, ce3, ce3_eligible, submitted, disclaimer}. HONESTY: the dispute lifecycle is LIVE on the Stripe rail only; VROL/RDR/CDRN (Verifi/Ethoca) is integration-ready code gated on acquirer provisioning (AXIS_ENABLE_VROL) and never fakes a submission. AXIS does not publish win-rate estimates.

NameTypeReqDescription
dispute_idstringyesProvider dispute id (Stripe dp_...) previously ingested by the charge.dispute.created webhook.
disputed_txnobjectOptional CE 3.0 data elements of the disputed transaction: {device_id?, ip_address?, email?, shipping_address?, login_id?}.
evidence_inputsobject{customerEmail?, shippingAddress?, billingAddress?, serviceDate?, productDescription?, deliveryTracking?, threeDsAuthenticated?} — merchant-supplied evidence fields.
submitbooleantrue → submit the built evidence to the Stripe disputes API (requires STRIPE_SECRET_KEY server-side). Default false (assemble only).
transaction_historyarrayCandidate prior transactions for CE 3.0 qualification (Txn shape, max 500).
NameTypeReqDescription
ce3objectyesFull assembleCe3 result (eligible, qualifying_priors, evidence_packet, caveat).
ce3_eligiblebooleanyes
disclaimerstringyesStripe-rail-live / VROL-gated honesty split + no-win-rate stance.
disputeobjectyesThe DisputeRecord after state-machine bookkeeping (state, dueBy, representmentId, ...).
evidenceobjectyesStripe `evidence` hash: uncategorized_text (CE 3.0 narrative) + customer_email_address/shipping_address/... from evidence_inputs.
submit_notestringPresent when submit was requested but skipped (e.g. Stripe not configured).
submittedbooleanyesTrue only when the evidence was actually submitted through the dispute client.

No examples provided.

axis_compare ~143

Compare two avatar contracts; returns similarity score and section-level diffs. Status: **planned_proxy** — an estate-flagged proxy is planned (see discover_estate_tools for the sibling's own direct endpoint and price today). Calls return a planned-capability envelope pointing at AXIS Foundry (https://api.avatar.jonathanarvay.com/mcp) as the recommended interim provider. When the estate proxy ships, the dispatch handler swaps in without changing this schema.

NameTypeReqDescription
file_astringyesPath to first mesh file
file_bstringyesPath to second mesh file
sectionsarrayLimit comparison to specific contract sections
NameTypeReqDescription
_plannedbooleanyesAlways true while this tool is in development.
capability_idstringCapability slug — matches capability-map.yaml for a non-estate entry, or a self-describing estate_<sibling>_<tool> slug for an estate entry.
messagestringHuman-readable status note.
recommended_providerobjectProvider to call directly today, including its price when known.
resultobjectSimilarity score and section-level diffs.
statusstringplanned_proxy or planned_owned.

No examples provided.

axis_inspect ~125

Inspect an avatar's contract state and provenance chain. Status: **planned_proxy** — an estate-flagged proxy is planned (see discover_estate_tools for the sibling's own direct endpoint and price today). Calls return a planned-capability envelope pointing at AXIS Foundry (https://api.avatar.jonathanarvay.com/mcp) as the recommended interim provider. When the estate proxy ships, the dispatch handler swaps in without changing this schema.

NameTypeReqDescription
file_pathstringyesPath to mesh file (.glb, .obj, .stl, etc.)
NameTypeReqDescription
_plannedbooleanyesAlways true while this tool is in development.
capability_idstringCapability slug — matches capability-map.yaml for a non-estate entry, or a self-describing estate_<sibling>_<tool> slug for an estate entry.
messagestringHuman-readable status note.
recommended_providerobjectProvider to call directly today, including its price when known.
resultobjectStage, bone/vertex counts, provenance step count, chain_valid + any broken links. No quality grade — use axis_validate for that.
statusstringplanned_proxy or planned_owned.

No examples provided.

axis_manifest_verify ~127

Verify an export manifest's integrity and optionally check content hash. Status: **planned_proxy** — an estate-flagged proxy is planned (see discover_estate_tools for the sibling's own direct endpoint and price today). Calls return a planned-capability envelope pointing at AXIS Foundry (https://api.avatar.jonathanarvay.com/mcp) as the recommended interim provider. When the estate proxy ships, the dispatch handler swaps in without changing this schema.

NameTypeReqDescription
expected_hashstringExpected content hash for verification
manifestobjectyesExport manifest JSON object
NameTypeReqDescription
_plannedbooleanyesAlways true while this tool is in development.
capability_idstringCapability slug — matches capability-map.yaml for a non-estate entry, or a self-describing estate_<sibling>_<tool> slug for an estate entry.
messagestringHuman-readable status note.
recommended_providerobjectProvider to call directly today, including its price when known.
resultobjectManifest integrity result, and a hash match result when expected_hash is provided.
statusstringplanned_proxy or planned_owned.

No examples provided.

axis_validate ~155

Validate an avatar mesh against 38 rules; returns pass/warn/fail counts. Status: **planned_proxy** — an estate-flagged proxy is planned (see discover_estate_tools for the sibling's own direct endpoint and price today). Calls return a planned-capability envelope pointing at AXIS Foundry (https://api.avatar.jonathanarvay.com/mcp) as the recommended interim provider. When the estate proxy ships, the dispatch handler swaps in without changing this schema.

NameTypeReqDescription
file_pathstringyesPath to mesh file (.glb, .obj, .stl, etc.)
platformstringTarget platform for platform-specific validation
profilestringValidation strictness profile
NameTypeReqDescription
_plannedbooleanyesAlways true while this tool is in development.
capability_idstringCapability slug — matches capability-map.yaml for a non-estate entry, or a self-describing estate_<sibling>_<tool> slug for an estate entry.
messagestringHuman-readable status note.
recommended_providerobjectProvider to call directly today, including its price when known.
resultobjectPass/warn/fail counts and detailed per-rule results.
statusstringplanned_proxy or planned_owned.

No examples provided.

build_ap2_mandate ~350

Validate, canonically encode, and optionally Ed25519-sign an AP2 mandate (Intent / Cart / Payment) using the real @axis/ap2 codecs — schema validation (including cart-total arithmetic and intent cross-references), RFC 8785 JCS-style canonical JSON encoding, and detached-JWS EdDSA signing over node:crypto. Pass seed_hex (64 hex chars = 32 bytes) to sign deterministically client-side-supplied key material — AXIS stores no keys; omit it for an unsigned template with encoding only. The signed envelope round-trips through verifyMandate before it is returned. Free, no auth, deterministic (Ed25519 signatures are deterministic per RFC 8032), no side effects. SCOPE HONESTY: conformant to AXIS's TypeScript encoding of the public AP2 mandate schema, verified against self-authored golden vectors — NOT certified against an official AP2 conformance suite or a live network counterparty.

NameTypeReqDescription
intent_contextobjectOptional IntentMandate to cross-reference a cart's intent_ref against.
mandateobjectyesAn AP2 mandate object: {kind: 'intent'|'cart'|'payment', version: 'ap2/1', id, created_at, ...kind-specific fields (intent: user_id/description/constraints.max_amount/expires_at; cart: intent_ref/mer…
seed_hexstringOptional 64-char hex (32-byte) Ed25519 seed to sign with. Caller-supplied key material — AXIS stores no keys. Omit for an unsigned template.
NameTypeReqDescription
encodedstringyesCanonical (JCS-style) JSON wire encoding — null when invalid.
issuesarrayyes[{path, message}] validation issues (empty when valid).
mandateobjectEcho of the validated mandate.
notestringyesSigned vs 'unsigned template — sign client-side' + trust-model caveat.
proofobjectyes{algo:'sha256', digest, over[]} reproducibility proof.
signedobjectWhen seed_hex supplied: {jws: {protected, signature}, public_key} — a SignedMandate envelope, verified before return.
validbooleanyesStructural validation verdict (validateMandate).
verifiedbooleanverifyMandate result for the signed envelope (null when unsigned).

No examples provided.

closer ~254

Package an existing AXIS snapshot (create one first via analyze_repo, analyze_files, or prepare_agentic_purchasing) into complete professional packaging + marketplace certification artifacts so a 70-80%-complete project is ready to ship and sell. Requires Authorization: Bearer <api_key> on an ALREADY-PAID Starter/Pro/Growth (or suite) account. Unlike most metered AXIS tools, a free-tier account cannot unlock this per call with an MPP payment credential — there is no pay-per-call path here, only 'upgrade at iliad.trustfabric.ai/billing'. Once unlocked, billed $1.00 per call from the account's plan credits. Lite mode carries no discount here — the bundle is identical in both modes.

NameTypeReqDescription
product_namestringOptional branding override for product name
project_rootstringOptional local project root path hint (metadata only in remote MCP mode)
snapshot_idstringyesExisting AXIS snapshot_id to package into a distributable product
taglinestringOptional branding tagline
target_marketplacesarrayOptional marketplaces list (e.g. npm, unreal, vscode, dockerhub, github-marketplace)
NameTypeReqDescription
artifact_countnumberyes
artifactsarrayyes
programstringyes
project_idstringyes
snapshot_idstringyes

No examples provided.

delete_snapshot ~150

Permanently delete a snapshot and everything derived from it (context map, repo profile, generated artifacts, search index entries). Same account scoping as get_snapshot: an anonymous (never-authenticated) snapshot is freely deletable by any caller, but an account-owned one requires the same Authorization: Bearer <api_key> used to create it — a mismatched or missing key fails with the same not-found error a nonexistent snapshot_id would, so a caller can't learn whether a snapshot they don't own even exists. This cannot be undone. MCP-layer equivalent of DELETE /v1/snapshots/:id.

NameTypeReqDescription
snapshot_idstringyesSnapshot ID returned by analyze_repo, analyze_files, or get_snapshot
NameTypeReqDescription
deletedbooleanyes
snapshot_idstringyes

No examples provided.

deploy ~233

Generate a zero-pipeline-minutes deploy bundle: stack-aware Dockerfile, .dockerignore, dev compose, render.yaml (Render existing-image), wrangler.pages.toml + wrangler.containers.toml + worker.ts (Cloudflare), bash/PowerShell push scripts, and a qualification report. The project builds locally in VSCode, pushes images to GHCR or via wrangler, and Render/Cloudflare just pulls — no GitHub Actions minutes, no Render build pipeline minutes, no CF build minutes. Requires Authorization: Bearer <api_key> on an ALREADY-PAID Starter/Pro/Growth (or suite) account. Unlike most metered AXIS tools, a free-tier account cannot unlock this per call with an MPP payment credential — there is no pay-per-call path here, only 'upgrade at iliad.trustfabric.ai/billing'. Once unlocked, billed $1.00 per call from the account's plan credits. Lite mode carries no discount here — the bundle is identical in both modes.

NameTypeReqDescription
snapshot_idstringyesExisting AXIS snapshot_id to package into deploy artifacts
NameTypeReqDescription
artifact_countnumberyes
artifactsarrayyes
programstringyes
project_idstringyes
snapshot_idstringyes

No examples provided.

discover_agentic_purchasing_needs ~136

Discover the best AXIS workflow for a purchasing or compliance task. Free, no auth, and logs lightweight task metadata for intent analytics. Example: task_description='prepare for autonomous Visa checkout'. Use this when you need commerce-specific triage and next-step guidance. Use search_and_discover_tools instead for non-commerce keyword routing across all programs.

NameTypeReqDescription
current_readinessnumberOptional: current Purchasing Readiness Score (0-100) if known
focus_areasarrayOptional: specific areas to focus on
task_descriptionstringWhat the agent is trying to accomplish
NameTypeReqDescription
matched_capabilitiesarrayyes
readinessobjectyes
recommended_next_stepobjectyes
task_descriptionstringyes

No examples provided.

discover_estate_tools ~110

List sibling AXIS properties (payments via PAI'D, 3D avatar generation via AXIS Foundry, and more) — each entry gives its own MCP endpoint, auth mode, and vendored tool prices, so you can call them directly. Free, no auth, no side effects. Same data as GET /.well-known/axis-estate.json. Use this when the task needs a capability Iliad itself does not own (e.g. payment execution, 3D asset generation).

Input schema present but exposes no named parameters.

NameTypeReqDescription
compatibilitystring
propertiesarrayyesOne entry per sibling AXIS property.
schema_versionstringyes
this_propertyobjectIliad's own id/name/mcp — so a caller can link back without a second fetch.

No examples provided.

get_artifact ~105

Read one generated artifact by snapshot_id and path. Requires access to the snapshot and may return snapshot-not-found, invalid-path, or artifact-not-found errors. Example: snapshot_id=abc-123, path=AGENTS.md. Use this when you need the full text of one artifact. Use get_snapshot instead when you first need the artifact list.

NameTypeReqDescription
pathstringyesArtifact file path as returned in the artifacts list
snapshot_idstringyesSnapshot ID

Structured output declared, but exposes no named fields.

No examples provided.

get_install_manifest ~122

Get AXIS install metadata, pricing, and a shareable manifest for onboarding a new integration — MCP endpoint, per-client config for Claude Desktop/Cursor/VS Code, and the full tool catalog with pricing. Free, no auth, and no mutation beyond read access. Example: call before wiring AXIS into an MCP client for the first time. Use this when you need setup/ecosystem details, not tool discovery. Use search_and_discover_tools instead for keyword routing across programs, or discover_agentic_purchasing_needs for purchasing-task triage.

Input schema present but exposes no named parameters.

NameTypeReqDescription
axis_iliadobjectyes
free_toolsarrayyes
installobjectyes
shareable_manifestobjectyes
toolsarrayyes

No examples provided.

get_referral_code ~91

Get or create the caller's AXIS referral token. Requires Authorization: Bearer <api_key>, has no usage charge, and may persist a new referral code if one does not exist yet. Example: call before sharing AXIS with another agent or workspace. Use this when you need the shareable token itself. Use get_referral_credits instead when you need balances, milestones, and discount status.

Input schema present but exposes no named parameters.

NameTypeReqDescription
coststringyes
current_earningsobjectyes
next_milestonestringyes
referral_tokenstringyes
share_instructionstringyes

No examples provided.

get_referral_credits ~87

Get the caller's referral earnings, milestones, and free-call status. Requires Authorization: Bearer <api_key>, has no usage charge, and returns the current discount ledger without creating a new analysis. Example: call after a referral campaign to inspect earned credits. Use this when you need balances and milestones. Use get_referral_code instead when you only need the shareable token.

Input schema present but exposes no named parameters.

NameTypeReqDescription
coststringyes
discount_activebooleanyes
earned_credits_millicentsnumberyes
earned_discountstringyes
free_calls_remainingnumberyes
lifetime_referralsnumberyes
next_milestonestringyes
paid_call_countnumberyes
persistence_credits_remainingnumberyes
referral_tokenstringyes
tierstringyes

No examples provided.

get_snapshot ~188

Retrieve status and the full artifact listing for a prior analysis by snapshot_id. Use this to re-enumerate artifact paths without re-running analysis. Snapshots created with an API key are scoped to that same account — pass the same Authorization: Bearer <api_key> used to create it, or retrieval fails with a not-found error. Only anonymous (never-authenticated) snapshots are freely retrievable by any caller. The response's content_discarded_at is non-null if the owning account's web session has since logged out — source content is gone (closer/deploy/skills/search_index calls on this snapshot will fail with content_discarded until it's re-uploaded), though this call itself still succeeds and generated artifacts remain listable. Use delete_snapshot to permanently remove a snapshot you no longer need.

NameTypeReqDescription
snapshot_idstringyesSnapshot ID returned by analyze_repo or analyze_files
NameTypeReqDescription
artifact_countnumberyes
artifactsarrayyes
content_discarded_atstring|nullISO timestamp if this snapshot's source content was discarded after the owning account's web session logged out (R5.7), null if content is still live.
programs_executedarray
project_idstringyes
snapshot_idstringyes
statusstringyes

No examples provided.

grade_compliance ~230

Run the real 8-check AP2/Visa compliance grading engine (gradeCompliance — the same engine behind computeComplianceGrade and the commerce registry's verified_decisions block) over an inline file set. Each of the 8 validators (SCA/3DS2 readiness, AP2 mandate validity, tokenization posture, CE 3.0 readiness, dispute rail wiring, idempotency/receipt hygiene, budget negotiation, refund/cancel path) is a multi-signal check with weight, evidence trail, and remediation. Returns grade A-D, score, checks_passed/8, the full checks[] detail, detected commerce signals, and a sha256 reproducibility proof. Free, no auth, deterministic, no snapshot persisted. Hard caps: 25 files / 50KB per file / 1MB total. HONESTY: deterministic static source-signal analysis — a checklist starting point, NOT a certification, audit, PCI assessment, or card-network certification.

NameTypeReqDescription
filesarrayyesSource files to grade (max 25 files, 50KB each, 1MB total)
NameTypeReqDescription
checksarrayyesPer-check {name, title, status, weight, score, evidence[], remediation}.
checks_passednumberyes
checks_totalnumberyesAlways 8.
gradestringyesA | B | C | D (score >= 85 / 65 / 40 / below).
methodologystringyesThe engine's own honesty statement (static analysis, not a certification).
proofobjectyes{algo:'sha256', digest, over[]} reproducibility proof.
scorenumberyesWeighted 0-100 score across the 8 checks.
signalsobjectyesdetectCommerceSignals(files) — providers + capability booleans the grade was derived from.

No examples provided.

iliad_analytics ~312

AXIS-owned product analytics. Two operations: `capture` (insert events) and `query` (aggregations). Capture accepts a single `event` or a batch via `events[]` (max 500). Query kinds: `count` (total events), `count_by_event` (top events by frequency), `distinct_users` (unique user_id count), `count_by_bucket` (time-series with minute/hour/day buckets). All queries support optional `event`, `from_ts`, `to_ts`, and `property_filter` filters. Namespaces are account-scoped server-side (`acct:<account_id>:<namespace>`). Persistent across restarts via Postgres (the shared @axis/snapshots database). Pricing: $0.01 standard, free in lite mode. Requires Authorization: Bearer <api_key>. Best for funnels, cohorts, and retention on workloads up to ~1M events per account.

NameTypeReqDescription
eventobjectSingle event payload {event, user_id?, properties?, timestamp?} — used in capture mode.
eventsarrayBatch of event payloads (max 500). Transactional — partial inserts never persist.
namespacestringLogical isolation key. Defaults to 'default'. Account id is always prepended server-side.
operationstringyescapture or query.
queryobject{kind, event?, from_ts?, to_ts?, property_filter?, bucket?, limit?} — used in query mode.
NameTypeReqDescription
capturednumberEvents written (capture mode only).
namespacestringScoped namespace the call wrote to or queried.
operationstringEcho of the operation that ran.
resultobjectAggregation result shape depending on query.kind (query mode only).

No examples provided.

iliad_code_sandbox ~461

AXIS-owned secure code execution. Each call spawns a fresh ephemeral Docker container with hardened isolation: no network, read-only root filesystem, all Linux capabilities dropped, no-new-privileges, PID/memory/CPU limits, tmpfs /tmp only, runs as nobody:nobody. Container is force-removed after each call. Supports python | node | bash via the multi-runtime image `nikolaik/python-nodejs:python3.12-nodejs22-slim` (operator can override via AXIS_CODE_SANDBOX_IMAGE). Returns stdout/stderr/exit_code/timed_out/duration_ms/image. Wall-clock timeout enforced via SIGKILL + force-remove. Source is fed via stdin (no fs write to the read-only root). Code body capped at 256 KiB; stdin at 1 MiB; timeout 1-600 seconds (default 30); stdout/stderr each capped at 1 MiB output. Pricing: $0.05 standard, $0.02 lite — billed whenever a container actually ran, including a timeout or non-zero exit code. Not billed when the call instead returns `_not_configured: true`: no Docker daemon reachable (Render standard services don't expose /var/run/docker.sock), the operator has set AXIS_CODE_SANDBOX_DISABLED=1, or more than AXIS_SANDBOX_MAX_CONCURRENT (default 4) runs are already in flight (reason sandbox_busy — transient, retry shortly). Engineer mode (X-Agent-Mode: engineer — Verified Exec, $0.25): the result includes an Ed25519-signed attestation binding code-hash → output-hash + a per-account hash-chain entry, so another agent that pins AXIS's published key can verify the run without re-executing it. Requires Authorization: Bearer <api_key>.

NameTypeReqDescription
codestringyesSource code to execute. Fed via stdin to the interpreter. Max 256 KiB.
languagestringyesRuntime language.
stdinstringOptional additional stdin appended after the code body. Max 1 MiB.
timeout_secondsnumberWall-clock limit. Defaults 30, max 600. SIGKILL on overrun.
NameTypeReqDescription
_not_configuredbooleanTrue when the call didn't run (unreachable daemon, disabled, or at concurrency limit).
attestationobjectEngineer mode only: Ed25519-signed attestation binding code-hash to output-hash, plus a per-account hash-chain entry.
duration_msnumberEnd-to-end wall time including container spawn + teardown.
exit_codenumberProcess exit code (137 on SIGKILL).
imagestringContainer image actually used.
reasonstringdocker_daemon_unreachable | dockerode_import_failed | disabled | sandbox_busy (only when _not_configured=true).
remediationstringHow the operator (or, for sandbox_busy, the caller by retrying) should resolve the condition.
stderrstringCaptured stderr (UTF-8, capped at 1 MiB).
stdoutstringCaptured stdout (UTF-8, capped at 1 MiB with truncation marker).
timed_outbooleanTrue if the wall-clock timeout fired.

No examples provided.

iliad_document_parsing ~495

AXIS-owned document → Markdown extractor. Accepts either `document_url` (https fetch + 50 MiB cap + 60s timeout) or `document_base64` (inline bytes, 50 MiB decoded cap) — exactly one. Optional `mime_type` hint (application/pdf, application/vnd.openxmlformats-officedocument.wordprocessingml.document, text/html, text/markdown, text/plain); we sniff from magic bytes + URL extension when omitted. Format dispatch: PDF → pdfjs-dist text extraction (one block per page with `--- page N ---` separators); DOCX → mammoth → markdown (tables preserved); HTML → tag-strip with heading + list + entity handling (NOT a full HTML→MD converter — bring turndown if you need fancier); plain text + markdown → passthrough. Returns `{markdown, format_detected, byte_size, page_count, table_count, truncated}`. Output capped at 1 MiB markdown with a truncation marker. Pricing: $0.02 standard, $0.01 lite. Engineer mode (X-Agent-Mode: engineer — Document Intelligence, $0.10): adds an `engineer` block with retrieval chunks (heading-aware, overlapping) + extract-to-caller-schema (pass `json_schema` → a grammar-constrained, validated typed object) + image OCR (image/* via document_base64, capped at 10 MiB — smaller than the 50 MiB document cap; an OCR failure or oversized image returns a descriptive `reason` that may not match the standard-mode enum) — typed data, not just markdown. document_url accepts a signed GET URL minted by iliad_object_storage; chain the extracted markdown into iliad_embeddings + iliad_vector_database to build a RAG index. Requires Authorization: Bearer <api_key>.

NameTypeReqDescription
document_base64stringBase64-encoded document bytes. Use this OR document_url, not both.
document_urlstringhttps URL to a document. Use this OR document_base64, not both.
json_schemaobjectEngineer mode: a JSON Schema. The document is extracted into a validated object matching it (returned in engineer.extracted).
mime_typestringOptional MIME-type hint. When omitted we sniff from magic bytes + URL extension. Engineer mode: an image/* mime triggers OCR.
NameTypeReqDescription
_not_configuredbooleanTrue when a prerequisite is missing or the document was unsupported.
byte_sizenumberRaw byte size of the source document.
engineerobjectEngineer mode only: { chunk_count, chunks, extracted? } — retrieval chunks + optional schema-validated extraction.
format_detectedstringpdf | docx | html | markdown | text | unknown | image (engineer-mode OCR path only).
markdownstringExtracted text, formatted as Markdown when the source had structure.
page_countnumber|nullPage count for PDFs; null otherwise.
reasonstringdocument_download_failed | document_decode_failed | unsupported_format | parse_failed | pdf_runtime_missing | docx_runtime_missing (only when _not_configured=true).
remediationstringOperator-actionable fix.
table_countnumberNumber of tables detected in the rendered markdown (DOCX only; 0 elsewhere).
truncatedbooleanTrue when the markdown output was capped at the 1 MiB ceiling.

No examples provided.

iliad_embeddings ~398

Convert text into dense vectors. Accepts a single string or a batch (max 2048). Returns one vector per input. AXIS-owned in-process inference by default (node-llama-cpp + an embedding-capable GGUF at AXIS_EMBEDDING_MODEL_PATH — no upstream provider call); an optional OpenAI /v1/embeddings backend is available behind AXIS_EMBEDDING_BACKEND=openai (model: text-embedding-3-small by default, overridable via OPENAI_EMBEDDING_MODEL; reports token usage). Requires Authorization: Bearer <api_key> to call. Pricing: $0.05 standard, $0.02 lite. When the selected backend is not provisioned (local: GGUF file absent; openai: OPENAI_API_KEY unset), returns a structured `_not_configured: true` envelope naming the backend and remediation, and is not billed. Pairs natively with iliad_vector_database — feed `vectors` from this tool's output into `vector` of the vector_database upsert/query calls. Engineer mode (X-Agent-Mode: engineer — Domain Embeddings, $0.08): pass `dimensions` (Matryoshka truncation → smaller vectors) and/or `corpus_adapter: true` (mean-center the batch to sharpen retrieval on your data); returns an `engineer` block with the fitted adapter_mean for query alignment.

NameTypeReqDescription
corpus_adapterbooleanEngineer mode: mean-center the batch (all-but-the-mean) to sharpen retrieval; returns the fitted adapter_mean.
dimensionsnumberEngineer mode: truncate each vector to this many leading dims (Matryoshka) + renormalize. Smaller, cheaper vectors.
inputstring|arrayyesA single string or an array of strings to embed. Empty strings and entries > 32k chars are rejected (chunk before calling).
NameTypeReqDescription
engineerobjectEngineer mode only: { dimensions, truncated, adapter_applied, adapter_mean? } — the post-processing applied + the fitted corpus mean.
input_countnumberyesNumber of inputs submitted (matches vectors.length).
model_usedstringyesConcrete embedding model used: the GGUF filename on the local backend, or the provider model name on the openai backend.
usageobject{prompt_tokens, total_tokens} — openai backend only (the local in-process backend has no provider token report).
vectorsarrayyesArray of dense vectors. vectors[i] corresponds to input[i] (order preserved).

No examples provided.

iliad_hygiene ~381

AXIS-owned workspace hygiene grader. Analyzes an inline file set [{path,content}] and returns a letter grade (A-F) across a closed set of dimensions plus structured findings. Two modes: mode='scan' (DEFAULT, FREE) returns grade + findings (committed-secret scan, .env/secret-file detection, .gitignore gaps for build/scratch artifacts, oversized blobs, stub/placeholder markers, byte-identical duplicate files, source test-peer coverage, TODO/FIXME debt); mode='fix' (METERED, $0.05 standard / $0.02 lite) adds a prioritized remediation plan with ready-to-apply .gitignore additions and per-finding actions. Sending X-Agent-Mode: engineer always bills the fix-mode price, even if mode is 'scan' or omitted. Deterministic, dependency-free, never mutates your repo (fix returns a PLAN). Rules needing a live git checkout/toolchain (worktree pruning, build/vet, governance-source-of-truth checks, route-registration dup-handler analysis, ROI-queue coherence) are reported as repo_only_rules, not run. Engineer mode (X-Agent-Mode: engineer — Security Engineer, $5): the fix arrives as a git-applyable unified-diff patch (`patch`) + a SARIF 2.1.0 log for CI code-scanning (`sarif`). Requires Authorization: Bearer <api_key>.

NameTypeReqDescription
configobjectOptional threshold overrides: maxFileBytes, coverageA, coverageB, coverageC, todoDebtThreshold.
filesarrayyesInline files [{path, content}] to scan (non-empty; each content <= 5 MB).
modestringscan (free grade+findings, default) | fix (metered, adds remediation plan).
NameTypeReqDescription
countsobject{high, medium, low, deferredByPolicy} open-finding counts.
dimensionsarrayPer-dimension grade [{id, grade, detail}].
findingsarrayAll findings [{id, ruleId, severity, path, message, policy, recommendedAction}].
gradestringOverall hygiene grade A-F (minimum across dimensions).
modestringEcho of the mode that ran.
paid_fix_hintstringscan mode only: how to obtain the metered remediation plan.
patchstringEngineer mode only: git-apply-able unified diff of the safe auto-fixes (currently .gitignore additions only); empty string when nothing is safely auto-fixable.
reasonsarrayDimensions that capped the grade below A.
remediation_planobjectfix mode only: {ordered_steps, gitignore_additions, summary}.
repo_only_rulesarrayRules that need a live repo and were not run.
sarifobjectEngineer mode only: SARIF 2.1.0 log of all open findings for CI code-scanning.
scannedobject{files, bytes} actually analyzed.

No examples provided.

iliad_llm_inference ~558

AXIS-hosted LLM chat-completion via node-llama-cpp + a small GGUF model loaded in-process. Two input shapes accepted: `prompt` (single string) or `messages` (chat-style array of {role, content}). Sampling controls: `max_tokens` (≤2048), `temperature` (0-2), `top_k`, `top_p`, `seed` (threaded through for more deterministic output — NOT a proven byte-identical guarantee; thread count isn't pinned and GGML's multi-threaded matmul reduction order isn't guaranteed bit-exact across runs), `stop` (string[]). Inference runs in-process — no upstream LLM provider call — but this AXIS tool call is still billed: $0.02 standard, $0.01 lite. Operator sets AXIS_LLM_MODEL_PATH to point at a Phi-3-mini / TinyLlama / Llama-3.2-1B GGUF; if missing, the tool returns a `_not_configured: true` envelope and is not billed. Engineer mode (X-Agent-Mode: engineer — Constrained Inference, $0.10): pass a `json_schema` and decoding is grammar-constrained to it AND the output is validated against it (returns a `structured` block with valid + parsed + schema_errors) — guaranteed-valid structured output. Requires Authorization: Bearer <api_key>.

NameTypeReqDescription
json_schemaobjectEngineer mode (required): a JSON Schema. Decoding is grammar-constrained to it and the output is validated against it; returns a `structured` block.
max_tokensnumberMax tokens to generate. Defaults 512, hard cap 2048.
messagesarrayChat-style input. Array of {role: system|user|assistant, content: string}.
promptstringSingle-prompt completion input. Use either this OR messages, not both.
seednumberOptional seed, threaded through with temperature for more deterministic output. Not a proven byte-identical guarantee (thread count/matmul reduction order isn't pinned) — see the tool description.
stoparrayStop sequences. Generation halts when any string in the array is produced.
systemstringOptional system prompt (prompt mode only). For messages mode, use role=system entries.
temperaturenumberSampling temperature in [0, 2]. Defaults 0.7.
top_knumberTop-k sampling (positive integer). Defaults 40.
top_pnumberTop-p nucleus sampling in (0, 1]. Defaults 0.95.
NameTypeReqDescription
_not_configuredbooleanTrue when no GGUF model is present at AXIS_LLM_MODEL_PATH.
completion_tokensnumberToken count of the generated text (best-effort).
model_pathstringPath checked for the GGUF file (only present when _not_configured=true).
model_usedstringBasename of the GGUF model file used.
prompt_tokensnumberToken count of the input prompt (best-effort).
reasonstringWhy the tool returned _not_configured (only present when true).
remediationstringHow the operator should fix the missing-model condition.
structuredobjectEngineer mode only: { schema_constrained, valid, parsed, schema_errors } — the guaranteed-valid structured-output verdict.
textstringGenerated completion text.

No examples provided.

iliad_network_tokenization ~436

Network-tokenization capability. (1) `lifecycle`: an EXECUTABLE TAP-style token-lifecycle state machine (provision → activate → suspend → resume → delete; deleted is terminal; illegal transitions are rejected with an error, not silently accepted) — pure simulation, no real payment method involved. (2) `capabilities` reports which providers are configured (env-derived). (3) `read` and (4) `provision` are TEMPORARILY DISABLED: both would resolve a caller-supplied payment_method_id/pan_source against the platform's Stripe account, and this service has no way yet to verify that id belongs to the calling AXIS account — calling either always returns a structured `_not_configured: true` envelope explaining this, never real payment-method data. (For context once re-enabled: `read`'s underlying Stripe adapter is fully implemented; direct VTS/MDES `provision` is additionally capability-gated behind a network-issued Token Requestor ID — AXIS_VTS_TOKEN_REQUESTOR_ID / AXIS_MDES_TOKEN_REQUESTOR_ID — plus network onboarding, and NEVER fakes a token.) Raw PANs are never accepted even when disabled (pan_source is documented as an opaque reference only). Free (unmetered); requires Authorization: Bearer <api_key>.

NameTypeReqDescription
eventstringlifecycle: single-event shorthand for `events: [event]`.
eventsarraylifecycle: ordered TokenEvent list (provision|activate|suspend|resume|delete), max 100. Must start from provision; illegal transitions throw.
operationstringread (default, disabled) | provision (disabled) | lifecycle | capabilities.
pan_sourcestringprovision: ignored — this operation is disabled and always returns _not_configured. NEVER a raw PAN in any case.
payment_method_idstringread: ignored — this operation is disabled and always returns _not_configured.
providerstringprovision: ignored — this operation is disabled and always returns _not_configured.
NameTypeReqDescription
_not_configuredbooleanTrue for every read/provision call (disabled) and for capability-gated states.
capabilitiesobject{ stripe, vts, mdes } — which providers are configured (env-derived).
honestystringThe stripe-live / VTS-MDES-gated honesty statement (capabilities only).
lifecycleobjectlifecycle: { state, history: [{from, event, to}] } after applying every event.
operationstringThe operation that ran.
provider_checkedstringAlways 'stripe' for the disabled read/provision envelope; the real provider gate name otherwise.
reasonstringWhy the call returned _not_configured (only when true).
remediationstringWhat to use instead, or the exact env var / onboarding step required.
toolstringAlways 'iliad_network_tokenization'.

No examples provided.

iliad_object_storage ~536

AXIS-owned signed-URL minter backed by Cloudflare R2. Returns a pre-signed PUT or GET URL scoped to the calling account (keys are prefixed with `accounts/<account_id>/` server-side, so accounts can't reach each other's objects). Requires Authorization: Bearer <api_key>. Returns the URL plus expires_at (ISO 8601), bucket, and scoped_key. Returns `{_not_configured: true, ...}` when the operator has not provisioned R2_* env vars (no crash, no leaked secrets); not billed when not configured. Pricing: $0.01 standard, free in lite mode. TTL is capped at 86400 seconds (24h). Engineer mode (X-Agent-Mode: engineer — Managed Bucket, $0.05): adds delete + list + copy (server-side, no bytes through the agent) operations, content-addressed dedup keys (content_sha256), and mint-time PUT policy (pin content_type / exact content_length as signed headers R2 enforces). A signed GET URL minted here can be passed directly as iliad_document_parsing's document_url or iliad_speech_to_text's audio_url.

NameTypeReqDescription
content_lengthnumberEngineer mode (put): pin the EXACT byte size the upload must be (signed; ≤5 GiB). Pairs with content_sha256 for verified content-addressed writes.
content_sha256stringEngineer mode: 64-char hex sha256 of the bytes you'll PUT. When set, the object lands under accounts/<id>/cas/<sha256> so identical content dedupes.
content_typestringEngineer mode (put): pin the Content-Type the upload must send (signed; R2 rejects a mismatch). Printable ASCII type/subtype, ≤255 chars. Echo via required_headers.
extstringEngineer mode: optional extension appended to the content-addressed key (e.g. 'png').
keystringyesObject key (max 1024 chars), or the prefix for operation=list. Path traversal and leading-/ are rejected.
operationstringyesput / get (standard). delete / list / copy and content-addressed put require X-Agent-Mode: engineer (Managed Bucket).
source_keystringEngineer mode (operation=copy): source object key to copy from, scoped to your account; `key` is the destination. Echo the returned required_headers on the PUT.
ttl_secondsnumberSigned-URL lifetime, 1..86400. Defaults to 3600.
NameTypeReqDescription
bucketstringyesResolved R2 bucket name.
expires_atstringyesISO-8601 expiry timestamp.
operationstringPUT or GET — what the URL was signed for.
scoped_keystringyesServer-side key after account scoping (the user-supplied key prefixed with accounts/<account_id>/).
urlstringyesPre-signed URL valid for ttl_seconds.

No examples provided.

iliad_speech_to_text ~517

AXIS-owned audio transcription via whisper.cpp + ffmpeg-static. Accepts either `audio_url` (https URL we fetch, max 100 MiB, 60s download timeout) or `audio_base64` (inline bytes, max 100 MiB decoded) — exactly one. Accepts any audio format ffmpeg can decode (mp3, wav, m4a, opus, ogg, flac); we resample to 16 kHz mono WAV internally. Optional `language` (ISO-639-1 like "en" / "fr" / "ja", or "auto" — default). Optional `initial_prompt` (≤512 chars; biases spelling of rare names). Optional `word_timestamps` boolean. Returns `{text, segments: [{start, end, text}], language_detected, duration_seconds, model_used}`. Pricing: $0.03 standard, $0.01 lite. When operator hasn't installed whisper-cli or placed the GGML model file at AXIS_WHISPER_MODEL_PATH (default `models/ggml-base.en.bin`), returns `{_not_configured: true, reason, detail, remediation}` and is not billed. Engineer mode (X-Agent-Mode: engineer — Diarization, $0.10): the response adds `diarization` — speaker turns grouped from the segments by inter-segment pause gaps (tune with diarization_gap_seconds / max_speakers; this is pause-based turn segmentation, not acoustic speaker ID). Use iliad_text_to_speech to synthesize speech from text. Requires Authorization: Bearer <api_key>.

NameTypeReqDescription
audio_base64stringBase64-encoded audio bytes. Use this OR audio_url, not both.
audio_urlstringhttps URL to an audio file. Use this OR audio_base64, not both.
diarization_gap_secondsnumberEngineer mode: pause (seconds) between segments that starts a new speaker turn. Defaults 0.75.
initial_promptstringOptional bias prompt (≤512 chars) — useful for spelling of rare names.
languagestringISO-639-1 language code (en, fr, ja, ...) or 'auto' to autodetect. Defaults 'auto'.
max_speakersnumberEngineer mode: max alternating speaker labels. Defaults 2.
word_timestampsbooleanEmit word-level timestamps within segments. Defaults false.
NameTypeReqDescription
_not_configuredbooleanTrue when a prerequisite is missing.
diarizationarrayEngineer mode only: speaker turns [{speaker, start, end, text}] grouped from segments by inter-segment pause gaps.
duration_secondsnumberAudio duration as inferred from the last segment end timestamp.
language_detectedstringLanguage code whisper detected (or echoed from input language).
model_usedstringBasename of the GGML model file used.
reasonstringmodel_file_not_found | whisper_cli_not_found | ffmpeg_static_missing | audio_download_failed | audio_decode_failed (only when _not_configured=true).
remediationstringOperator-actionable fix for the unconfigured prerequisite.
segmentsarray[{start: seconds, end: seconds, text}] timestamped segments.
textstringFull transcript text, joined from segments.

No examples provided.

iliad_text_to_speech ~497

AXIS-owned voice synthesis via Piper (rhasspy/piper) + ffmpeg-static. Accepts `text` (1-5000 chars), optional `voice` slug (filename without extension; defaults to AXIS_PIPER_DEFAULT_VOICE or the first available voice), optional `format` (wav | mp3 | opus; defaults wav), optional `sentence_silence` (0-5 seconds, default 0.2). Returns `{audio_base64, format, voice_used, sample_rate, duration_seconds, byte_size}`. Inference runs in-process — no upstream provider call — but this AXIS tool call is still billed: $0.02 standard, $0.01 lite. When operator hasn't installed piper or placed voice .onnx + .onnx.json files in AXIS_PIPER_VOICE_DIR (default models/piper/), returns `{_not_configured: true, reason, detail, remediation}` and is not billed. format=mp3/opus additionally requires ffmpeg-static. Engineer mode (X-Agent-Mode: engineer — Brand Voice, $0.10): requires `brand_text` (a brand / voice-and-tone artifact — the call throws without it in engineer mode) and AXIS auto-derives the voice persona (Piper voice slug + sentence pacing) and synthesizes in it; the persona is echoed in the response. Use iliad_speech_to_text to transcribe audio back to text. Requires Authorization: Bearer <api_key>.

NameTypeReqDescription
brand_textstringRequired when X-Agent-Mode: engineer is set (the call throws without it); ignored otherwise. Brand / voice-and-tone artifact — AXIS derives a voice persona from it and synthesizes in that voice (over…
formatstringAudio codec.
genderstringEngineer mode: persona gender override.
localestringEngineer mode: persona locale override.
sentence_silencenumberPer-sentence silence in seconds (0-5). Defaults 0.2.
textstringyesText to speak. 1-5000 chars after trim.
voicestringVoice slug (filename without extension, e.g. 'en_US-amy-medium'). Defaults to first available voice or AXIS_PIPER_DEFAULT_VOICE.
NameTypeReqDescription
_not_configuredbooleanTrue when a prerequisite is missing.
audio_base64stringBase64-encoded audio bytes in the requested format.
byte_sizenumberByte length of the encoded audio (post-transcode for mp3/opus).
duration_secondsnumberAudio duration in seconds, computed from the WAV header.
formatstringEcho of the requested format.
personaobjectEngineer mode only: the derived voice persona (voice slug, sentence_silence, locale, gender, tone_tags) used for this synthesis.
reasonstringpiper_cli_not_found | voice_dir_missing | no_voices_available | voice_model_not_found | voice_config_not_found | ffmpeg_static_missing | synthesis_failed (only when _not_configured=true).
remediationstringOperator-actionable fix for the unconfigured prerequisite.
sample_ratenumberWAV sample rate parsed from the RIFF header (typically 22050 for Piper).
voice_usedstringVoice slug that was used (resolved if caller omitted `voice`).

No examples provided.

iliad_transactional_email ~426

Send a single transactional email. Requires Authorization: Bearer <api_key>. Provide either body_html, body_text, or both (Resend will pick the best variant per recipient). All emails ship from RESEND_FROM_ADDRESS — operator must verify that domain in Resend before sending. Returns the provider-assigned message_id plus the accepted recipient list. Pricing: $0.02 standard, $0.01 lite. Returns a structured _not_configured envelope when RESEND_API_KEY or RESEND_FROM_ADDRESS is missing, and is not billed. Recipients capped at 50 per call; subject capped at 998 chars; bodies capped at 1 MB. Engineer mode (X-Agent-Mode: engineer — Deliverability, $0.50): instead of sending, pass a `domain` and get a full SPF/DKIM/DMARC setup (fresh DKIM keypair) + sender warmup schedule + verification checklist — no email sent, no ESP key needed.

NameTypeReqDescription
body_htmlstringHTML body. At least one of body_html / body_text required.
body_textstringPlaintext body. At least one of body_html / body_text required.
dkim_selectorstringEngineer mode: DKIM selector (alphanumeric/hyphen, 1-32). Defaults 'axis'.
dmarc_policystringEngineer mode: DMARC policy none|quarantine|reject. Defaults none (monitoring).
domainstringEngineer mode (Deliverability): domain to generate SPF/DKIM/DMARC setup for. Replaces the send.
providerstringEngineer mode: ESP for the SPF include (resend/sendgrid/mailgun/postmark/ses/google). Defaults resend.
reply_tostringOptional Reply-To address.
subjectstringEmail subject (max 998 chars, RFC 5322).
tostring|arrayRecipient address or array of addresses (max 50). Required for a send (standard mode).
NameTypeReqDescription
delivered_toarrayyesRecipients the provider accepted.
fromstringyesRESEND_FROM_ADDRESS used as the From: header.
message_idstringyesProvider-assigned message ID.
subjectstringyesSubject sent (echo).

No examples provided.

iliad_vector_database ~376

AXIS-owned vector store. Two operations: `upsert` (insert or replace vectors) and `query` (cosine top-k nearest neighbors). Namespaces are account-scoped server-side (`acct:<account_id>:<namespace>`), so tenants cannot read each other's vectors. Persistent across restarts via Postgres. Requires Authorization: Bearer <api_key>. Pricing: $0.01 standard, free in lite mode. Best for RAG retrievers, deduplication, and similarity search. Use iliad_embeddings to turn text into the vectors this tool stores and queries. Engineer mode (X-Agent-Mode: engineer — Managed Memory, $0.05): query runs a pgvector/HNSW ANN candidate pool with optional recency-decay reranking (recency_half_life_days — managed forgetting), RRF hybrid fusion (sparse_ids), and metadata filter; upsert applies intra-batch semantic-dedup (dedup_threshold).

NameTypeReqDescription
dedup_thresholdnumberEngineer upsert: cosine threshold for intra-batch semantic-dedup (default 0.97).
namespacestringLogical isolation key. Defaults to 'default'. Account ID is always prepended server-side.
operationstringyesupsert (insert/replace) or query (top-k cosine).
queryobject{vector: number[], top_k?: number, filter?: object}. Engineer mode also reads recency_half_life_days (number — exponential recency decay) and sparse_ids (string[] — RRF hybrid fusion). Required for q…
semantic_dedupbooleanEngineer upsert: set false to disable dedup (default on).
vectorsarrayArray of {id, vector, metadata?} — required for upsert.
NameTypeReqDescription
backendstringEngineer query: 'pgvector' or 'js' — which ANN path served the query.
engineerobjectEngineer query only: { ann, recency_decay, hybrid_fusion } flags.
matchesarrayNearest neighbors sorted by score desc (query mode only).
namespacestringScoped namespace the call wrote to or queried.
operationstringEcho of the operation that ran.
semantic_dedupobjectEngineer upsert only: { dropped: [{id, duplicate_of, similarity}] } — vectors dropped as intra-batch duplicates.
total_in_namespacenumberTotal vectors in this namespace after the call (upsert mode only).
upsertednumberVectors written (upsert mode only).

No examples provided.

iliad_web_research ~221

Scrape a single URL with AXIS's owned crawler (SSRF-guarded fetch, robots.txt-aware, readability extraction — no third-party key) and return markdown-formatted content. Honest scope: fetches static HTML only, no JavaScript rendering, so client-rendered SPA pages may extract thin content. Returns markdown body, extracted metadata, and title. Best for research, documentation reading, or SEO analysis. Requires Authorization: Bearer <api_key>. Pricing: $0.10 per page. Lite mode carries no discount here — the markdown output is identical in both modes. If the operator's backend configuration is incomplete, this call returns {_not_configured:true} instead of scraping, and is not billed. Use iliad_web_research_crawl for crawling multiple pages or link following. To make a scraped page searchable later, index it with iliad_web_search.

NameTypeReqDescription
only_main_contentbooleanExtract only the main content (default: true)
urlstringyesThe URL to scrape (http or https)
NameTypeReqDescription
dataobject
errorstringError message if request failed
successbooleanyes

No examples provided.

iliad_web_research_crawl ~235

Crawl a domain with AXIS's owned crawler — a same-origin BFS frontier with robots.txt compliance and per-host politeness, no third-party key — and scrape multiple pages. Honest scope: static HTML only, no JavaScript rendering. Returns array of scraped pages with markdown content. Best for site mapping, content audits, or bulk research. Requires Authorization: Bearer <api_key>. Pricing: $0.01/page beyond your account's shared 100-page/month free pool (standard and lite) — a crawl fully covered by the free pool costs $0.00; a fully-paid 100-page crawl costs up to $1.00. If the operator's backend configuration is incomplete, this call returns {_not_configured:true} instead of crawling, and is not billed. Use iliad_web_research for single-page scrapes. To make crawled pages searchable later, index them with iliad_web_search.

NameTypeReqDescription
limitnumberMaximum pages to crawl (1-100, default: 10)
urlstringyesThe domain/URL to crawl (http or https)
NameTypeReqDescription
dataobject
errorstringError message if request failed
successbooleanyes

No examples provided.

iliad_web_search ~443

AXIS-owned BM25 search engine over the corpus YOUR account has indexed. NOT a Google/Bing scraper — agents build their own searchable index by first calling operation='index' with documents (often pages fetched via iliad_web_research), then querying with operation='search'. Five operations: `index` (insert one or many documents), `search` (BM25 top-k ranked hits with snippet + score + metadata), `delete` (drop one doc), `delete_namespace` (drop all), `count`. Namespaces are account-scoped server-side (`acct:<id>:<namespace>`). Persistent across restarts via Postgres (the shared @axis/snapshots database). Search supports `max_results` (default 10, max 100) and `site` (restrict to a single URL host, case-insensitive). Only operation='search' is billed ($0.01 standard, free in lite mode) — index, delete, delete_namespace, and count are always free. Engineer mode (X-Agent-Mode: engineer — Answer Engine, $0.25): search also returns a grounded extractive answer with [n] citation spans over your corpus, reranked, refusing on weak evidence. Requires Authorization: Bearer <api_key>.

NameTypeReqDescription
doc_idstringDocument id to remove. Required in delete mode.
documentobjectSingle document {doc_id, url?, title?, content, metadata?} — used in index mode (alternative to documents[]).
documentsarrayBatch of documents (max 100). Transactional — malformed entry aborts the whole call.
max_resultsnumberCap on hits returned. Defaults 10, max 100.
namespacestringLogical isolation key. Defaults 'default'. Account id is always prepended server-side.
operationstringyesindex | search | delete | delete_namespace | count.
querystringSearch query (1-1024 chars). Required in search mode.
sitestringFilter to a single URL host (e.g. 'docs.python.org', case-insensitive).
NameTypeReqDescription
hitsarrayBM25-ranked hits [{doc_id, url, title, snippet, score, metadata}] (search mode).
indexednumberDocuments written (index mode).
namespacestringScoped namespace the call touched.
operationstringEcho of the operation that ran.
querystringEcho of the search query (search mode).
removedboolean|numberdelete: boolean; delete_namespace: count of rows removed.
totalnumberDocument count (count mode).
total_in_namespacenumberDocuments currently in the namespace (index, search modes -- count mode returns this same figure under the field name `total` instead).

No examples provided.

improve_my_agent_with_axis ~159

Analyze an agent codebase and return a prioritized AXIS hardening plan. Requires Authorization: Bearer <api_key> but has no usage charge on any tier — free and unmetered, unlike most AXIS tools. This creates a snapshot and may return auth, quota, file-limit, or validation errors. Example: pass your agent source files to see missing AGENTS.md, CLAUDE.md, and MCP config gaps. Use this when you want recommendations and missing-context detection. Use analyze_files instead when you want the full artifact bundle directly (paid: $3.00 standard).

NameTypeReqDescription
filesarrayyesSource files of the agent to analyze
project_namestringyesName of the agent/project to improve
NameTypeReqDescription
analysisobjectyes
call_againobjectyes
improvement_planobjectyes
mcp_configobjectyes
project_namestringyes
snapshot_idstringyes

No examples provided.

list_programs ~66

Inventory mode. List all 21 AXIS programs, their generators, pricing tier, and artifact paths. Free, no auth, and no side effects. Use search_and_discover_tools instead when you only have a keyword, or get_install_manifest when you need install and onboarding metadata.

Input schema present but exposes no named parameters.

NameTypeReqDescription
free_artifact_countnumberTotal artifacts available with no payment, across all programs.
free_programsarrayyesPrograms that are free IN FULL (no artifact behind payment).
pro_programsarrayyesPrograms with at least one artifact behind payment — each still ships free artifacts too.
programsarrayyes
programs_with_free_artifactsarrayPrograms that ship at least one free artifact — every program does.
total_generatorsnumberyes
total_programsnumberyes

No examples provided.

ping_payment ~161

Exercise the real x402 payment-flow loop at a nominal $0.01 — the cheapest metered call on this server, priced just above $0 so the probe can't be run up for free without limit. Call it once with no payment credential (no auth required) to receive a 402-style payment_required challenge (the exact same shape every real paid tool returns, and requesting it is itself free); retry the same tools/call carrying a payment credential in Authorization (with your API key moved to X-Axis-Key) to settle at $0.01 and get a success envelope. Learn the vocabulary here before paying real money for prepare_agentic_purchasing or analyze_repo. No side effects on any other tool, no real payment rail is ever touched.

Input schema present but exposes no named parameters.

NameTypeReqDescription
_payment_requiredboolean
messagestring
okboolean
price_usdstringsettled_cents formatted as a dollar string — success responses only.
settled_centsnumberAmount actually settled on a successful retry, in cents (1 = $0.01). Always 0 on the initial challenge (amount_cents), which is a separate field.
toolstring

No examples provided.

Common questions

What is the Axis Iliad — Codebase Intelligence For Agentic Commerce MCP server?

Axis Iliad — Codebase Intelligence For Agentic Commerce is an MCP server listed in the public MCP registry as io.github.lastmanupinc-hub/axis-toolbox. Codebase intelligence for agents: 152 structured artifacts across 21 programs, one call. This page covers its hosted endpoint (https://axis-api-6c7z.onrender.com/mcp).

Is the Axis Iliad — Codebase Intelligence For Agentic Commerce MCP server safe to use?

Axis Iliad — Codebase Intelligence For Agentic Commerce scores 23 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Axis Iliad — Codebase Intelligence For Agentic Commerce MCP server expose?

Axis Iliad — Codebase Intelligence For Agentic Commerce exposes 44 tools: analyze_repo, analyze_files, list_programs, get_snapshot, delete_snapshot, and 39 more. Their descriptions and schemas cost roughly 12,112 tokens of context every time the server is loaded.

Does the Axis Iliad — Codebase Intelligence For Agentic Commerce MCP server require authentication?

No. We connected to Axis Iliad — Codebase Intelligence For Agentic Commerce without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the Axis Iliad — Codebase Intelligence For Agentic Commerce MCP server still maintained?

Axis Iliad — Codebase Intelligence For Agentic Commerce is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.