Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

io.github.mercuryx402/mercury-x402-mcp

REMOTE · NETWORK.MERCURY-HQ.COM · 2 COMPONENTS · SCANNED SEP 25

Agent-payable web data over x402: 18 keyless services an agent pays per call.

0 this week 76 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security57
Transport & Reachability100
Schema Quality & AI Usability64
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 3710 tokens (~206/item across 18 items; 18 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
  • No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • We read all 18 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
  • An AI judge read all 19 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

How do I install the io.github.mercuryx402/mercury-x402-mcp server?

io.github.mercuryx402/mercury-x402-mcp is a hosted endpoint at https://network.mercury-hq.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · network.mercury-hq.com

# add to Claude Code
claude mcp add --transport http mercuryx402-mercury-x402-mcp 'https://network.mercury-hq.com/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "mercuryx402-mercury-x402-mcp": {
      "url": "https://network.mercury-hq.com/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "mercuryx402-mercury-x402-mcp": {
      "type": "http",
      "url": "https://network.mercury-hq.com/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.mercuryx402-mercury-x402-mcp]
url = "https://network.mercury-hq.com/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "mercuryx402-mercury-x402-mcp": {
      "type": "remote",
      "url": "https://network.mercury-hq.com/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add mercuryx402-mercury-x402-mcp --url 'https://network.mercury-hq.com/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  mercuryx402-mercury-x402-mcp:
    url: "https://network.mercury-hq.com/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "mercuryx402-mercury-x402-mcp": {
      "Transport": "http",
      "Url": "https://network.mercury-hq.com/mcp"
    }
  }
}
# add to Vellum
assistant mcp add mercuryx402-mercury-x402-mcp -t streamable-http -u 'https://network.mercury-hq.com/mcp'
// mcp.json
{
  "mcpServers": {
    "mercuryx402-mercury-x402-mcp": {
      "type": "http",
      "url": "https://network.mercury-hq.com/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 25 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 9 Sept 26 +43
    • Injection markers: unverified → pass ▲ security
    • Stability: unverified → pass ▲ security
    • Authorization: Authorisation not fully verified: no authorisation is required to call this server, and 18 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. security
    • Endpoint reachability: not serving MCP → reachable ▲ functional
    • Tool coverage: unverified → 100 ▲ functional
    • MCP protocol: unverified → pass ▲ functional
  • 8 Sept 26 −43
    • Endpoint reachability: reachable → not serving MCP ▼ security
    • Stability: pass → unverified ▼ security
    • Tool safety: pass → unverified ▼ security
    • Authorization: Authorisation not fully verified: no authorisation is required to connect, but we couldn't read the whole tool list to see what that exposes. security
    • Tool coverage: 100 → unverified ▼ functional
    • Capabilities: pass → unverified ▼ functional
    • First check of Schema quality: unverified functional
  • 26 Aug 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 25 Aug 26 0
    • Stability: 0.97 → pass security
  • 11 Aug 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 31 Jul 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 30 Jul 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 25 Sept 2026 · Probed https://network.mercury-hq.com/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=network.mercury-hq.com CN=YE2,O=Let's Encrypt,C=US 5 Aug 2026 3 Nov 2026 ECDSA 256 ECDSA-SHA384 600b625759f8333689a1b775a5d20554787
SANs: network.mercury-hq.com
CN=YE2,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 4df3b15dd6c0784c507cd37b58e6f115
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of network.mercury-hq.com. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
mercury-hq.com. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://network.mercury-hq.com/mcp Verified 200
http (plaintext) http://network.mercury-hq.com/mcp HTTPS enforced 301 https://network.mercury-hq.com/mcp
MCP tools · 18 exposed · ~3,649 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
availability ~110

URL → a signed uptime/status probe: up/down, HTTP status + class, reachability reason, final URL after redirects, and a measured responseMs — wrapped in an offline-verifiable provenance receipt that makes "it was up/down at T" provable SLA evidence. Deterministic verdict (responseMs is telemetry, not signed). Keyless, no LLM, no signup. — $0.005/call

NameTypeReqDescription
urlstringyesthe endpoint/page to probe for availability (http/https)

No output schema declared.

No examples provided.

batch ~175

List of URLs (≤20) → clean content for each + ONE signed receipt committing to a MERKLE ROOT over every page's contentHash. Tamper-evident multi-page snapshot with per-page membership proofs (selective disclosure). Deterministic (no LLM): same URL set + same source bytes ⇒ byte-identical root + proofs. SSRF-guarded per url; keyless x402, USDC on Base mainnet. — $0.02/call

NameTypeReqDescription
formatstring–clean text (default) or structure-preserving markdown for every page
urlsstringyescomma- OR newline-separated list of pages to snapshot (http/https), ≤20 (deduped, capped). Each is fetched through the shared SSRF-guarded engine and becomes one Merkle leaf.

No output schema declared.

No examples provided.

diff ~209

URL + prior content-hash (or prior text) -> refetch, deterministic change-proof: changed? + a NEW signed receipt binding fromHash->toHash. Stateless; receipts chain into a tamper-evident audit trail of a page's evolution. Keyless x402, Base mainnet USDC. — $0.006/call

NameTypeReqDescription
formatstring–compare cleaned text (default) or structure-preserving markdown
prevHashstring–prior content hash (0x + 64 hex sha256) from an earlier MERCURY fetch/diff receipt. Gives a hash-only change-proof (changed? true/false). Use this OR prevText.
prevTextstring–prior page text to diff against. Gives a full deterministic line-level diff (added/removed counts + unified-style hunk) on top of the change-proof. Use this OR prevHash.
urlstringyesthe page to re-fetch + diff (http/https)

No output schema declared.

No examples provided.

dns ~167

Domain → a SIGNED, timestamped DNS snapshot (A, AAAA, MX, NS, TXT, CNAME, SOA), normalised + sorted into a byte-stable record set with an offline-verifiable provenance receipt — proving exactly what the zone resolved to at that moment. Keyless, no LLM, no signup. (Normalisation is deterministic; DNS itself is mutable across time/TTL/geo — which is the very reason the snapshot is timestamped + signed.) — $0.006/call

NameTypeReqDescription
domainstring–the domain to resolve (e.g. example.com). A full URL is also accepted; its hostname is used.
urlstring–alternative to ?domain= — any http/https URL; the registrable hostname is resolved.

No output schema declared.

No examples provided.

extract ~472

TYPED structured extract for autonomous agents — URL + schema → a clean, type-safe JSON record. Where /buy/fetch returns page TEXT (and ?extract= returns string-only fields), THIS returns the schema-conformant object an LLM/RAG/trading pipeline actually consumes: pass ?url=…&schema=title,price:number,rating:number,inStock:boolean and get back { title:"…", price:19.99, rating:4.5, inStock:true } — numbers as numbers, booleans as booleans, absent fields null (honest). `schema` accepts the URL-friendly compact form (field[:type], type in string|number|integer|boolean) OR a Firecrawl/OpenAI-style JSON-Schema object ({"properties":{"price":{"type":"number"}}}). That is Firecrawl's paid 'JSON mode' headline guarantee — type-safety, 'numbers as numbers not strings' — done DETERMINISTICALLY from the page's own JSON-LD/OpenGraph/meta/microdata: keyless, NO LLM call, NO API key, NO signup, $0.004/call, paid in-band over HTTP 402 (x402, USDC on Base mainnet). The typed record is folded into the SIGNED provenance attestation too (EIP-191, ecrecoverable OFFLINE), so a buyer can prove the EXTRACTED FIELDS — not just raw bytes — are exactly what MERCURY resolved. Honest charge-per-ATTEMPT: every call returns a structured result (success OR an ok:false reason). Same SSRF guard, 5s timeout, 10MB cap, no mint. — $0.004/call

NameTypeReqDescription
formatstring–optional: text (default) or markdown for the page-text field
schemastringyesfields to extract. COMPACT: comma list of field[:type] (type in string|number|integer|boolean, default string), e.g. title,price:number,rating:number,inStock:boolean. OR a JSON-Schema string ({"prope…
urlstringyesthe page to extract from (http/https)

No output schema declared.

No examples provided.

feed ~140

RSS/Atom feed URL → a SIGNED, normalized item list [{title,link,published,summary}] unified across RSS 2.0/RDF + Atom 1.0: CDATA unwrapped, HTML stripped, entities decoded, dates → ISO-8601 (publishedRaw kept verbatim, never fabricated). Deterministic — same feed bytes ⇒ byte-identical items; no LLM. Core 4 fields only (not full-content/media/author). Receipt = EIP-191 over the canonical item list. — $0.005/call

NameTypeReqDescription
urlstringyesthe RSS/Atom feed to normalize (http/https)

No output schema declared.

No examples provided.

fetch ~646

VERIFIABLE keyless web-read for autonomous agents. Every result ships a cryptographically SIGNED provenance receipt (EIP-191 over sha256(text)+url+status+time) — the wedge a free scraper structurally CANNOT match: Jina r.jina.ai is free+keyless too, but its bytes are HEARSAY (no proof of what/where/when). MERCURY's `attestation` is ecrecoverable OFFLINE, forever, by you OR any downstream agent you forward the bytes to — proving the content is genuine + untampered (key pinned at /.well-known/mercury-attestation). For RAG, trading and agent-to-agent commerce that need provenance, that is the gap between data and evidence. Beyond that it's the keyless web-read primitive — NO API key, NO signup, NO account, NO monthly plan, the one fetch SKU a fresh agent can onboard to by itself instead of stopping to ask a human for a key. Give a ?url= and get back clean readable page text + title + status. Agent-native extras (opt-in): ?format=markdown for structure-preserving markdown, ?links=1 for an outbound-link graph (crawl frontier), and the headline wedge — STRUCTURED EXTRACT: ?extract=title,price,author,publishedAt returns a clean JSON record { title, price, author, publishedAt }, an LLM-ready row not a wall of text. That is Firecrawl's paid 'JSON mode' (they need an LLM call + an API key for it) done here DETERMINISTICALLY from the page's own JSON-LD/OpenGraph/meta/microdata — keyless, no LLM, $0.003. (?extract=1 still returns the legacy description + wordCount.) The extracted record is folded into the SIGNED attestation too, so a buyer can prove the FIELDS — not just the raw bytes — are exactly what MERCURY resolved. You pay in-band over HTTP 402 (x402, USDC on Base mainnet) — the wedge those tools can't match: they ALL gate behind a human-created API key + a credit-card plan, so an agent can't onboard itself. This one an agent finds in the x402 Bazaar and pays with zero human in the loop. Honest charge-per-ATTEMPT: every call returns a structured result (success OR an ok:…

NameTypeReqDescription
extractstring–1 = page description + wordCount; OR a comma-list of field names (e.g. title,price,author,publishedAt) to get a structured JSON record under `extract`
formatstring–text (default) or structure-preserving markdown
linksstring–1 = also return the outbound-link graph (crawl frontier)
urlstringyesthe page to fetch (http/https)

No output schema declared.

No examples provided.

headers ~96

URL → a deterministic HTTP security-headers audit (HSTS, CSP, X-Frame, X-Content-Type, Referrer-Policy, Permissions-Policy + more) with a letter grade and concrete findings, wrapped in a signed, offline-verifiable provenance receipt. Keyless, no LLM, no signup. — $0.005/call

NameTypeReqDescription
urlstringyesthe page/endpoint to audit (http/https)

No output schema declared.

No examples provided.

links ~125

URL → a SIGNED outbound/internal link graph: every <a href> as an absolute URL + anchor text, classified internal vs external against the page origin, grouped by origin with a third-party-origin histogram (privacy-audit) and same/cross-origin counts (SEO). Deterministic — same page bytes ⇒ byte-identical graph; no LLM. Covers <a> hyperlinks only (not rel/asset tags). Receipt = EIP-191 over the graph. — $0.005/call

NameTypeReqDescription
urlstringyesthe page to map (http/https)

No output schema declared.

No examples provided.

markdown ~96

URL → clean, LLM-ready markdown (boilerplate/nav/ads stripped, headings + lists + links preserved) with a signed provenance receipt pinning the markdown to its source — the RAG-ingest primitive. Deterministic (no LLM): same URL + same source bytes ⇒ byte-identical markdown. — $0.005/call

NameTypeReqDescription
urlstringyesthe page to convert to markdown (http/https)

No output schema declared.

No examples provided.

metadata ~89

URL → one typed, SIGNED metadata record (JSON-LD + OpenGraph + Twitter-card + standard <meta> + canonical + title), by source. Deterministic, keyless, no LLM — the social-card/SEO/schema.org record an agent can PROVE. — $0.006/call

NameTypeReqDescription
urlstringyesthe page to read metadata from (http/https)

No output schema declared.

No examples provided.

notarize ~176

Notarize any content (inline ?content= or a fetched ?url=) into a signed, offline-verifiable provenance receipt — sha256 contentHash + witnessed timestamp, attested by Mercury's pinned key. Deterministic, keyless, no LLM. The signed receipt is the product: it witnesses that these exact bytes existed in this exact form at this time (the one thing your own sha256() can't — a third-party witness). — $0.008/call

NameTypeReqDescription
contentstring–inline content (UTF-8, ≤256KB) to notarize directly — bytes you already hold. Provide EITHER url OR content, not both.
urlstring–a page (http/https) to fetch + notarize its cleaned text. Provide EITHER url OR content, not both.

No output schema declared.

No examples provided.

readability ~117

URL → a clean ARTICLE record { title, byline, publishedAt, article text } with boilerplate (nav/header/footer/sidebar/ads/share-bars/comment-forms) stripped via deterministic DOM density heuristics, plus a signed provenance receipt pinning the cleaned article to its source — the clean-citation primitive distinct from raw markdown. Deterministic (no LLM): same URL + same source bytes ⇒ byte-identical output. — $0.005/call

NameTypeReqDescription
urlstringyesthe article page to extract (http/https)

No output schema declared.

No examples provided.

redirect ~160

URL → a SIGNED redirect/canonical resolution: the full hop chain [{url,status}] from the link you have to where it ACTUALLY lands, the final resolved URL + status, the page's <link rel=canonical>, hop count, cross-origin flag and distinct origins traversed (affiliate-cloak / link-safety signal). Deterministic — same redirects ⇒ byte-identical resolution; no LLM. Follows HTTP 3xx only (no JS/meta-refresh execution — meta-refresh target surfaced un-followed). Receipt = EIP-191 over the resolved chain. — $0.005/call

NameTypeReqDescription
urlstringyesthe link/URL to resolve (http/https) — e.g. a shortlink or affiliate URL

No output schema declared.

No examples provided.

robots ~146

Domain → signed, timestamped per-AI-crawler allow/block audit from robots.txt + llms.txt + ai.txt (GPTBot, ClaudeBot, PerplexityBot, Google-Extended, Bytespider, …). Deterministic, no LLM. EU-AI-Act / TDM opt-out evidence: the signed verdict proves the crawler policy as it stood at fetch time. — $0.005/call

NameTypeReqDescription
domainstringyesdomain or URL to audit (e.g. example.com or https://example.com/page); only the origin is used
pathstring–optional path to evaluate the verdict for (default '/', the whole-site question)

No output schema declared.

No examples provided.

sitemap ~285

Domain/URL → a SIGNED snapshot of the site's PUBLISHED sitemap: discovers the sitemap via robots.txt Sitemap: lines then /sitemap.xml fallback, parses <urlset> + <sitemapindex> (follows up to 5 child sitemaps), returns a deduped, bounded (≤2000) URL inventory with lastmod/changefreq/priority. The receipt signs the DECLARED URL list (deterministic — same sitemap bytes ⇒ byte-identical list). Optional ?fetch=N (≤10) adds a HARD-BOUNDED same-domain liveness probe (title+status+bytes per URL) — that probe is the ONLY non-deterministic part and is NOT covered by the signature. SSRF-guarded; the crawl is bounded at every axis. — $0.01/call

NameTypeReqDescription
fetchstring–optional N (0–10): also shallow-fetch the first N same-domain sitemap URLs and report each one's live title + HTTP status + byte size (liveness sample). NOT covered by the signed receipt (it can chan…
limitstring–optional cap on URLs returned (1–2000); default returns all up to 2000
urlstringyesa domain (example.com) or any URL on the site — only its origin is used

No output schema declared.

No examples provided.

table ~153

URL in → the page's main HTML <table>(s) parsed into typed, header-keyed rows (JSON) + clean RFC-4180 CSV, with a signed provenance receipt over the exact extracted grid. Deterministic, keyless, no LLM — x402, USDC on Base mainnet. — $0.006/call

NameTypeReqDescription
formatstring–optional: which serialisations to include in `data` (default: both).
tablestring–optional: 0-based index of a SINGLE table to return (document order). Omit to return ALL tables found (up to the cap).
urlstringyesthe page to extract tables from (http/https)

No output schema declared.

No examples provided.

validate ~287

URL (a JSON/API endpoint) + a JSON Schema in → a deterministic pass/fail with per-field errors (missing/wrong-type/enum/range/pattern), plus a signed provenance receipt binding the verdict to the exact response bytes AND the exact schema. Deterministic, keyless, no LLM — x402, USDC on Base mainnet. — $0.005/call

NameTypeReqDescription
pointerstring–optional JSON-Pointer (e.g. /data or /result/0) to validate a SUB-DOCUMENT of the response instead of the whole body (for APIs that wrap the payload).
schemastringyesthe JSON Schema to validate against. THREE accepted forms: (1) COMPACT URL-native comma list of field[:type] (type in string|number|integer|boolean|array|object|null; default string), e.g. id:integer…
urlstringyesthe JSON/API endpoint to fetch + validate (http/https)

No output schema declared.

No examples provided.

Common questions

What is the io.github.mercuryx402/mercury-x402-mcp server?

io.github.mercuryx402/mercury-x402-mcp is listed in the public MCP registry as io.github.mercuryx402/mercury-x402-mcp. Agent-payable web data over x402: 18 keyless services an agent pays per call. This page covers its hosted endpoint (https://network.mercury-hq.com/mcp).

Is the io.github.mercuryx402/mercury-x402-mcp server safe to use?

io.github.mercuryx402/mercury-x402-mcp scores 76 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the io.github.mercuryx402/mercury-x402-mcp server expose?

io.github.mercuryx402/mercury-x402-mcp exposes 18 tools: fetch, extract, markdown, metadata, links, and 13 more. Their descriptions and schemas cost roughly 3,649 tokens of context every time the server is loaded.

Does the io.github.mercuryx402/mercury-x402-mcp server require authentication?

No. We connected to io.github.mercuryx402/mercury-x402-mcp without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the io.github.mercuryx402/mercury-x402-mcp server still maintained?

io.github.mercuryx402/mercury-x402-mcp is still listed as active in the MCP registry. We last reached this channel on 25 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.