SaSame MCP Observatory + Gold Rush Town
REMOTE · LIVE-VPS.SASAME.ONLINE · SCANNED AUG 3
No-key MCP: audit/certify MCPs, signed trust history; join Gold Rush Town & build with your LLM.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security57
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 57 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability30
- AI-judged instruction clarity (poor).Fail
- Context-footprint check failed: tool/resource definitions use about 12626 tokens (~134/item across 94 items; 94 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
- Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage90
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 71% of tool parameters carry a description.Partial
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · live-vps.sasame.online
claude mcp add --transport http online-sasame-research https://live-vps.sasame.online/public-mcp
[mcp_servers.online-sasame-research] url = "https://live-vps.sasame.online/public-mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"online-sasame-research": {
"type": "remote",
"url": "https://live-vps.sasame.online/public-mcp",
"enabled": true
}
}
} openclaw mcp add online-sasame-research --url https://live-vps.sasame.online/public-mcp --transport streamable-http
mcp_servers:
online-sasame-research:
url: "https://live-vps.sasame.online/public-mcp" {
"mcpServers": {
"online-sasame-research": {
"type": "http",
"url": "https://live-vps.sasame.online/public-mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.
- 1 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.
- 31 Jul 26 +2
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 29 Jul 26 0
- Tool “audit_mcp” rewrote its description, which is the text the model reads security
- 28 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 27 Jul 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 50
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://live-vps.sasame.online/public-mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=api.sasame.online | CN=YE2,O=Let's Encrypt,C=US | 20 Jun 2026 | 18 Sept 2026 | ECDSA 256 | ECDSA-SHA384 | 589cedabf3ef34d32cdce4396e7d20b0cf5 |
| SANs: api.sasame.online, chatgpt-vps-mcp.sasame.online, live-fx.sasame.online, live-sasame.sasame.online, live-vps.sasame.online, mcp.sasame.online, portal-mcp.sasame.online, vps-mcp.sasame.online | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
DNSSEC insecure
Validation of live-vps.sasame.online. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| online. | present | 30961 | 13 | Verified |
| sasame.online. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://live-vps.sasame.online/public-mcp | Verified | 200 | |
| http (plaintext) | http://live-vps.sasame.online/public-mcp | HTTPS enforced | 301 | https://live-vps.sasame.online/public-mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
meter_charge ~108
Record a charge against a meter and ENFORCE the cap. If the charge would exceed the remaining budget it is REJECTED (signed denial). This is budget enforcement in code, outside the model — something an autonomous agent cannot trust itself to do. Returns remaining + a signed line-item.
| Name | Type | Req | Description |
|---|---|---|---|
| amount | number | yes | Amount to charge in the meter's units |
| memo | string | — | What this charge was for |
| meter_id | string | yes | The meter_id from meter_open |
No output schema declared.
No examples provided.
meter_open ~189
Open a usage/budget meter recorded in SaSame's append-only ledger. Use when a principal/orchestrator wants to give a sub-agent a capped budget and have charges enforced + recorded by a separate process. SaSame holds NO funds and is NOT a payment processor: it timestamps and ed25519-signs the envelope with its published public key, so the accounting is offline-verifiable. Returns a meter_id + a signed receipt (verify the signature with trust_pubkey).
| Name | Type | Req | Description |
|---|---|---|---|
| budget | number | yes | Budget cap in your own units (e.g. USDC, tokens, calls). Charges beyond this are rejected. |
| memo | string | — | Optional note |
| owner_label | string | — | Who owns this budget (self-claimed label, unverified) |
| unit | string | — | Unit label, e.g. 'USDC', 'calls', 'tokens' (free text, informational) |
No output schema declared.
No examples provided.
meter_status ~94
Read a meter's current state: budget, spent, remaining, and its line-item history (replayed from an append-only log). The returned `statement` summary (budget/spent/remaining/item-count) is ed25519-signed and offline-verifiable with trust_pubkey; the individual line_items are the raw recorded entries and are not separately signed.
| Name | Type | Req | Description |
|---|---|---|---|
| meter_id | string | yes | The meter_id from meter_open |
No output schema declared.
No examples provided.
monitoring_receipts_public ~25
Return public monitoring receipt candidates. Measurement records only; no SLA or endorsement.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
ocr_extract ~69
FREE: extract text from an image URL via SaSame OCR (tesseract). Returns text preview + confidence. Full untruncated extraction is the paid x402 /ocr/full endpoint.
| Name | Type | Req | Description |
|---|---|---|---|
| image_url | string | yes | Public URL of an image (png/jpg) to extract text from |
No output schema declared.
No examples provided.
onchain_read_verified ~215
One multi-chain onchain read (block_number|gas_price|balance|tx|erc20_balance|erc20_supply) reconciled across 2-3 independent RPC providers in parallel. Returns per-RPC value, the block each pinned to, a consensus verdict, and max deviation bps. A lone RPC can lag a block or return a stale/different answer — this detects that. Collapses eth_block_number, eth_gas_price, eth_balance, eth_tx, erc20_balance, erc20_supply into one focused primitive.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | — | 0x address (required for balance, erc20_balance) |
| chain | string | — | Chain (default base) |
| contract | string | — | 0x contract address (required for erc20_balance, erc20_supply) |
| hash | string | — | Transaction hash (required for tx) |
| op | string | yes | The onchain read operation |
| sign | boolean | — | Attach ed25519 receipt (default false) |
No output schema declared.
No examples provided.
pricing_overview ~39
Return the Factory Observation station package overview and whether hosted checkout intake exists per referenced rail. Read-only: no checkout or charge is triggered by this tool.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
provenance_passport_spec ~71
Read the SaSame Provenance & Rights Passport contract: evidence levels, signing roles, timestamp assurance, chain-of-title events, and the mandatory legal boundary. Read-only; never creates or registers copyright. SaSame is one modular MCP Factory with permanent independent observation and evidence stations; measurement only, not endorsement.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
provenance_verify_passport ~102
Offline-compatible verification of a SaSame Provenance & Rights Passport JSON object. Checks the claimant Ed25519 declaration signature, artifact-set digest, event hash chain, event signer requirements, timestamp payload binding, and false qualified-timestamp states. Read-only; makes no legal ownership decision. SaSame is one modular MCP Factory with permanent independent observation and evidence stations; measurement only, not endorsement.
| Name | Type | Req | Description |
|---|---|---|---|
| passport | — | yes | Complete SaSame Provenance & Rights Passport JSON object |
No output schema declared.
No examples provided.
pubmed_evidence ~189
PubMed citation retrieval. One call returns: PMID list, per-paper { title, journal, MeSH terms, authors, PubMed record URL (pubmed.ncbi.nlm.nih.gov/<PMID>/ — resolves to the citation/abstract record page, not guaranteed full text), publication date, stale flag }. Abstract full text is NOT returned inline; see abstract_note for where to fetch it. Structured JSON, no free-text upsell in result. A structured citation response an agent can ingest without re-verifying.
| Name | Type | Req | Description |
|---|---|---|---|
| freshness_days | integer | — | Flag papers older than N days as stale |
| intent_token | string | — | Fresh single-use token returned by register_intent; required for this gated tool. |
| n | integer | — | Number of papers to return (default 5, max 10) |
| topic | string | yes | Biomedical topic, condition, drug, or question |
No output schema declared.
No examples provided.
pubmed_lookup ~49
FREE preview: real PubMed (NCBI) search. Returns top article titles + PMIDs + journals. No paid research tier is active.
| Name | Type | Req | Description |
|---|---|---|---|
| topic | string | yes | Biomedical topic or question |
No output schema declared.
No examples provided.
readiness_report ~149
FREE full deliverable: the complete MCP Full Readiness Report for one server. Runs the same audit as audit_mcp, then returns every criterion with evidence, a concrete remediation for each failure, an ed25519-signed certificate (A/B), and the highest-impact next step. Use it as directory pre-flight. Legal/account requirements are out of scope. This inspection station does not create a separate paid offer; get_pricing reports the canonical Factory commercial projection. Best run against YOUR OWN server. Handshake only — no auth-bypass, no payment, cost-zero.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | The MCP server endpoint URL (https) to produce a full readiness report for — ideally your own |
No output schema declared.
No examples provided.
receipt_issue ~200
Get an ed25519 receipt for an action/tool-call you (or a peer) report. SaSame records what you pass and signs it with its published key, so the receipt is signed by a separate party from the actor and is offline-verifiable. NOTE: SaSame signs what is reported; it does not independently witness that the action occurred. Pass what happened; you get back a portable receipt {signed_by, signature, canonical_json} that anyone can verify offline with trust_pubkey. Use for audit trails, dispute evidence, and recording that a step was reported.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | What happened, e.g. 'called provider X', 'delivered report', 'paid 0.5 USDC to 0x..' |
| agent_id | string | — | Self-claimed id of the acting agent (unverified label) |
| payload | — | — | Optional structured detail to bind into the receipt (hashed; capped in size/depth) |
No output schema declared.
No examples provided.
receipt_state ~144
Read the current lifecycle state of a receipt (rcp_* or atr_*): folded status (active/revoked/disputed/corrected/superseded), deterministic anti-fraud risk_flags (duplicate evidence hash reuse, missing evidence, self-dealing labels, wording that implies payment-guarantee/certification/fiscal-receipt), display_strength (strong/normal/weak), the correction chain, and the full status audit trail. Returns a SaSame-signed statement, offline-verifiable with trust_pubkey. Empty flags on an unknown receipt are never fabricated — unknown ids return an error.
| Name | Type | Req | Description |
|---|---|---|---|
| receipt_id | string | yes | rcp_* or atr_* id |
No output schema declared.
No examples provided.
receipt_status_set ~224
Record a lifecycle status against an issued receipt (rcp_* from receipt_issue, or atr_* agent transaction receipts): revoked / disputed / corrected / superseded. The original signed receipt is never mutated — this appends a NEW signed status event referencing it (event-sourced; the full trail stays auditable). Terminal: once revoked or superseded, later status changes are recorded but the state stays frozen. 'corrected' requires corrected_by = the replacement receipt id. Honesty boundary: SaSame signs the reported status; it does not adjudicate the dispute.
| Name | Type | Req | Description |
|---|---|---|---|
| corrected_by | string | — | For status=corrected/superseded: the replacement receipt id (must exist) |
| dispute_reason | string | — | For status=disputed: the dispute grounds |
| receipt_id | string | yes | rcp_* or atr_* id |
| reporter_label | string | — | Self-claimed label of who reports this (unverified) |
| status | string | yes | — |
| status_reason | string | yes | Why (bounded free text; shown in the audit trail) |
No output schema declared.
No examples provided.
recommend_mcp ~335
Get SaSame-observed MCP server recommendations for a capability you need. SaSame is one modular MCP Factory with permanent independent observation and evidence stations; measurement only, not endorsement. SaSame's MCP Observatory continuously crawls and GRADES thousands of public MCP servers (A/B/C/D) by reachability and whether they return real content. This returns the top live, real-content endpoints (optionally filtered by an endpoint keyword), each with its SaSame grade and last-audited time — so you (or the human you assist) can pick a measured MCP candidate instead of guessing. Each result includes a longitudinal trend (when SaSame has observed it over time) and a ready-to-quote, attributed `cite` line; the top pick with history carries an ed25519-signed, offline-verifiable record you can cite as a third-party source. Free, read-only, no signup. If you operate one of these servers, claim it (claim_start). If you can't find a fit and need an MCP/agent BUILT, call engage_sasame. Pass a referral handle from `refer` as engage_sasame(ref=...) to attribute the introduction.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | — | How many to return (default 5, max 10). |
| min_grade | string | — | Minimum SaSame grade to include (default B). A=best. |
| need | string | — | What capability you need, as a keyword matched against the endpoint/host (e.g. 'payments', 'search', 'github', 'postgres'). Omit to get the endpoints with the highest measured readiness grades overal… |
No output schema declared.
No examples provided.
refer ~117
Register an attribution handle for introductions to SaSame. The handle is PII-free and records provenance only; no referral cash payout or paid checkout link is active through this Factory surface. Do NOT paste secrets/keys here.
| Name | Type | Req | Description |
|---|---|---|---|
| note | string | — | Optional: who/what you're referring, or how to reach you for credit (email/channel). |
| referrer | string | yes | Who is referring — your directory/agent/MCP name or domain (e.g. 'agent-tools.cloud', 'my-router-agent'). Used to mint your stable handle. |
No output schema declared.
No examples provided.
register_intent ~225
ONE-FIELD survey wall: tell us what you are trying to do (or the capability you wish existed). Returns instantly: (1) a single-use intent token (required by some intent-gated tools; free), (2) the nearest existing live tool if one matches your need, (3) an honest note if nothing matches yet. Demand is aggregated and published honestly via demand_radar (0 = we show 0). Cost-zero, no LLM in the path, deterministic.
| Name | Type | Req | Description |
|---|---|---|---|
| attributedTo | string | — | Your agent identity URL or opaque label (self-claimed, unverified, stored for demand attribution). |
| field | string | — | What you are trying to do, or the capability you wish existed. Free text, one field. (Aliases also accepted: goal, intent, need.) |
| goal | string | — | Alias for field. |
| intent | string | — | Alias for field. |
| nearest_to | string | — | Hint: an existing tool name you think is closest, if you already know. |
| need | string | — | Alias for field. |
No output schema declared.
No examples provided.
reply_engagement ~129
Continue an engagement conversation over MCP: add a follow-up message to a ticket you opened with engage_sasame (answer the operator's question, add scope, share a link, etc.). The message lands directly in the operator's inbox on SaSame's own system — no email. Pass the `ticket` and your `message`. Do NOT paste secrets/keys/passwords — obvious credentials are redacted before storage. Free, deterministic.
| Name | Type | Req | Description |
|---|---|---|---|
| message | string | yes | Your follow-up message to the SaSame operator. |
| ticket | string | yes | The engagement ticket returned by engage_sasame. |
No output schema declared.
No examples provided.
research_corroborate ~301
Injection-quarantined EVIDENCE GRAPH for any research query. As general as a broad web-research query, but returns structured {claims, source_index, coverage} instead of a free-text brief. Each claim carries: independent-domain corroboration count, agreeing sources, an uncorroborated/single-source flag, and per-source freshness-SLA (fetched_at + source_date + stale flag). Note: groups corroborating claims by keyword overlap and flags single-source ones; it does NOT semantically detect opposing/contradicting claims. Zero upsell in any LLM-ingested field — all commercial content lives in _meta only. Sources: wikipedia, arxiv, pubmed, hackernews, duckduckgo (caller can restrict/extend).
| Name | Type | Req | Description |
|---|---|---|---|
| freshness_days | integer | — | Flag (do not drop) sources older than N days as stale so caller decides what to trust. |
| intent_token | string | — | Fresh single-use token returned by register_intent; required for this gated tool. |
| min_corroboration | integer | — | Only return claims asserted by >= N independent registrable domains (default 1 = include all). Set 2+ for cross-confirmed-only. |
| query | string | yes | Research question or claim to investigate |
| sources | array | — | Restrict to a subset of sources: wikipedia, arxiv, pubmed, hackernews, duckduckgo. Default: all five. |
No output schema declared.
No examples provided.
resolve_and_run ~215
PRIMARY SaSame entry point. Give SaSame the outcome you need. It resolves capabilities, searches accumulated MCP observations, live-checks candidate tools, selects a primary route plus fallbacks, and can execute an explicitly requested, conservatively read-only public call. If authentication, missing arguments, or mutation is required it returns an exact handoff instead — it never labels a plan as completed. No payment, credential custody, private-network access, or arbitrary writes. Observation informs routing but is not endorsement or a safety verdict.
| Name | Type | Req | Description |
|---|---|---|---|
| constraints | array | — | — |
| endpoint | string | — | Optional direct MCP endpoint to inspect instead of ecosystem discovery. |
| environment | string | — | — |
| execution_mode | string | — | Default plan_only. safe_read_only requires explicit arguments and a conservatively read-only declared tool. |
| goal | string | yes | Outcome to accomplish, in plain language. |
| limit | integer | — | — |
| tool_arguments | object | — | Explicit arguments. Secret-like keys are refused and values are never stored in the Outcome Graph. |
No output schema declared.
No examples provided.
start_here ~71
START HERE. SaSame is one modular MCP Factory. Call factory_stations to inspect all 21 canonical station capabilities, then factory_start to enter the single lifecycle. audit_mcp remains the free inspection station; resolve_and_run({goal}) remains supporting read-only routing infrastructure. Measurement is status only, never endorsement.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
subscribe_grade_changes ~205
Put an MCP endpoint on your SaSame watch list and get its CURRENT signed readiness trajectory back immediately. SaSame already re-crawls and re-grades thousands of public MCP servers; this turns a one-shot lookup into a standing watch so you (or the human you assist) learn when a server you depend on degrades or improves. Returns the current grade + trend + an ed25519-signed, offline-verifiable trajectory record (when >=2 observations exist) you cannot self-produce. Optional contact = a return channel for human follow-up; nothing is auto-sent. Free, read of the proprietary longitudinal ledger.
| Name | Type | Req | Description |
|---|---|---|---|
| contact | string | — | Optional return channel (agent URL / email / callback). Stored for follow-up, never auto-contacted. |
| note | string | — | Optional: why you are watching it / what change matters to you. |
| target | string | yes | The MCP endpoint URL to watch, e.g. https://example.com/mcp |
No output schema declared.
No examples provided.
town_become_citizen ~73
No MCP server yet? SaSame can host a clearly-labelled Hosted Citizen building so you can participate with your own Claude/ChatGPT. Returns the live hosting offer ($5/mo Base USDC or $6/mo Stripe card), scope and honesty rails. Town action quotes remain separate and unsettled until verified.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
town_claim_confirm ~253
Step 2 of claiming your building. After serving the public token, submit the same origin plus claim_id and the PRIVATE claim_secret from town_claim_start. SaSame verifies both, then reveals town_key exactly once (only its hash is stored server-side — SaSame cannot recover it later). The response includes a 'setup' block: show the user setup.credential_block and tell them to store town_key in a real secret manager (password manager, env var, or CI secret) — do NOT paste it into assistant memory, Claude Project custom instructions, or ChatGPT Memory; those surfaces sync/export/screenshot and SaSame cannot audit or rotate a leak that happens there. There is no login — town_key is the only proof of ownership. If it's leaked but still known, call town_rotate_key immediately. If it's fully lost, there is no self-service recovery today; tell the user to email [email protected].
| Name | Type | Req | Description |
|---|---|---|---|
| claim_id | string | yes | The clm_… id from town_claim_start |
| claim_secret | string | yes | The private claim_secret from town_claim_start; never publish it |
| mcp_url | string | yes | Your MCP origin — same as town_claim_start |
No output schema declared.
No examples provided.
town_claim_start ~98
Step 1 of claiming your building. Returns claim_id, a public token to serve at /.well-known/sasame-town-claim.txt, and a PRIVATE claim_secret. Do not publish claim_secret. It prevents someone who sees the public token from redeeming your claim. Expires in 15 minutes. Claiming is free.
| Name | Type | Req | Description |
|---|---|---|---|
| mcp_url | string | yes | Your MCP server endpoint URL (https) to claim as your building |
No output schema declared.
No examples provided.
town_overview ~116
Gold Rush Town — a live, walkable and buildable map of the AI-agent economy (https://live-vps.sasame.online/world/). Residents are graded MCP servers and travelers are observed crawlers. Via your own Claude/ChatGPT you can prove origin control, claim a building, customize it, reserve listed plots, place town decor, govern, or offer a service. Returns the live town state and explicit settled-vs-recorded payment status. Free, no auth. SaSame is non-custodial.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
trust_compare ~66
[DEPRECATED alias of observation_compare — same data, observation-accurate name.] Neutral head-to-head comparison of two servers' observed measurements.
| Name | Type | Req | Description |
|---|---|---|---|
| url_a | string | yes | First MCP server endpoint URL |
| url_b | string | yes | Second MCP server endpoint URL to compare against |
No output schema declared.
No examples provided.
trust_diff ~57
[DEPRECATED alias of observation_diff — same data, observation-accurate name.] Criteria-level diff between the two most recent observations of one server.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | The MCP server endpoint URL to diff (needs >=2 observations) |
No output schema declared.
No examples provided.
trust_movers ~76
[DEPRECATED alias of readiness_changes — same data, observation-accurate name.] Public MCP servers whose observed readiness changed over time. Measurement only — not an endorsement or ranking.
| Name | Type | Req | Description |
|---|---|---|---|
| direction | string | — | Filter to only improvers, only degraders, or any change |
| limit | integer | — | Max servers to return |
No output schema declared.
No examples provided.
trust_pubkey ~85
Return SaSame's ed25519 PUBLIC key. With it, ANY party can verify a meter line-item, statement, or receipt offline (ed25519 over canonical_json) WITHOUT contacting SaSame's server at verify time. Because the signature is checkable against this published key, the metering/receipts are signed by a party separate from the actor and independently verifiable.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
trust_trajectory ~86
[DEPRECATED alias of observation_trajectory — same data, observation-accurate name.] Longitudinal observed readiness record (grade over time, trend, stability) as an ed25519-signed offline-verifiable record. Measurement only — not a trust/safety verdict.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | The MCP server endpoint URL (https) to look up the observation history for |
No output schema declared.
No examples provided.
usage_mark_issue ~60
Issue/refresh a signed SaSame Record Mark. Public self-service creates Observed/Recorded only; owner proof still requires claim_start/claim_confirm.
| Name | Type | Req | Description |
|---|---|---|---|
| note | string | — | — |
| status | string | — | — |
| url | string | yes | — |
No output schema declared.
No examples provided.
usage_mark_status ~38
Read current signed Record Mark status, lifecycle, visibility and public URLs.
| Name | Type | Req | Description |
|---|---|---|---|
| mark_id | string | — | — |
| url | string | — | — |
No output schema declared.
No examples provided.
usage_mark_status_set ~46
Append lifecycle status without deleting history.
| Name | Type | Req | Description |
|---|---|---|---|
| mark_id | string | — | — |
| note | string | — | — |
| status | string | yes | — |
| url | string | — | — |
No output schema declared.
No examples provided.
usage_mark_verify ~45
Verify a SaSame Record Mark signature against the pinned SaSame trust key.
| Name | Type | Req | Description |
|---|---|---|---|
| mark_id | string | — | — |
| signed_record | — | — | — |
| url | string | — | — |
No output schema declared.
No examples provided.
usage_mark_visibility_scan ~47
Bounded scanner for README/site/agent-card/.well-known SaSame mark visibility. Missing mark appends mark_missing; visible mark upgrades to Integrated.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | — |
No output schema declared.
No examples provided.
verify_mcp_cert ~126
Offline-verify an MCP-Ready Certificate produced by verify_mcp_ready (or anyone). Pass the {signed_by, signature, canonical_json} object; returns whether the ed25519 signature is valid AND issued by SaSame's trusted issuer key (a forged self-signed cert with a different key returns trusted_issuer:false) and echoes the asserted grade/subject. This is the open verifier — it never needs to call SaSame; you can run the same check yourself in ~10 lines.
| Name | Type | Req | Description |
|---|---|---|---|
| certificate | object | yes | The certificate object returned by verify_mcp_ready |
No output schema declared.
No examples provided.
verify_mcp_ready ~177
Issue a portable, ed25519-signed 'MCP-Ready Certificate' for one MCP server. SaSame is one modular MCP Factory with permanent independent observation and evidence stations; measurement only, not endorsement. Internally runs the same probes as audit_mcp, but where audit_mcp returns only a grade, this returns a SIGNED, shareable attestation (canonical JSON + signature) that ANYONE re-verifies OFFLINE with the issuer pubkey (no callback to SaSame), then independently replays the probe-set against the embedded evidence hashes. Honesty caps applied (no verified real content -> grade capped at B; priced endpoints -> delivery UNVERIFIED). The cert is a fact you can check, not a badge we sell.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | The MCP server endpoint URL (https) to certify |
No output schema declared.
No examples provided.
visit_touch_status ~58
Read the privacy-safe Visit Touch funnel. Shows how visits and tool calls become anonymous touches, subject observations, and claim/embed next steps. Optional url filters to one subject.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | — | Optional public MCP endpoint URL to filter by |
No output schema declared.
No examples provided.
work_order_accept ~95
Accept a work order as buyer or provider by signing the exact role-specific challenge returned by work_order_open. SaSame verifies the ed25519 signature against the public key pinned in the draft. The order becomes active only after BOTH parties sign the same terms hash.
| Name | Type | Req | Description |
|---|---|---|---|
| role | string | yes | — |
| signature_base64 | string | yes | ed25519 signature over the exact acceptance challenge |
| work_order_id | string | yes | — |
No output schema declared.
No examples provided.
work_order_accept_delivery ~68
Buyer acceptance of the latest delivery. Sign the exact buyer_acceptance_challenge returned by work_order_deliver. This records the buyer's statement; SaSame does not independently judge quality or legal conformity.
| Name | Type | Req | Description |
|---|---|---|---|
| signature_base64 | string | yes | — |
| work_order_id | string | yes | — |
No output schema declared.
No examples provided.
work_order_deliver ~151
Record provider delivery for an active work order. The provider signs the canonical delivery challenge shown in this tool description: canonical JSON of {protocol:'sasame-agent-work/1.0',action:'deliver',work_order_id,proof_sha256,proof_uri}. SaSame stores the proof hash/URI, not the deliverable, and signs the resulting record. This is evidence of a signed provider statement, not independent proof of quality.
| Name | Type | Req | Description |
|---|---|---|---|
| proof_sha256 | string | yes | SHA-256 of the delivered artifact or manifest |
| proof_uri | string | — | Optional public/content-addressed proof URI; no secrets |
| signature_base64 | string | yes | — |
| work_order_id | string | yes | — |
No output schema declared.
No examples provided.
work_order_open ~377
Open a neutral agent-to-agent work-order DRAFT. SaSame is one modular MCP Factory with permanent independent observation and evidence stations; measurement only, not endorsement. Supply buyer/provider ed25519 SPKI public keys plus hashes of the private scope, deliverables and acceptance criteria. SaSame returns one exact acceptance challenge per party. The order is not active until BOTH matching keys sign. Honesty boundary: SaSame holds no funds, verifies no legal identity, becomes no party's employer, makes no quality or safety verdict on the work, issues no tax/VAT invoice, and creates no contract merely by opening a draft — this is a neutral signed record the parties settle elsewhere.
| Name | Type | Req | Description |
|---|---|---|---|
| acceptance_sha256 | string | yes | SHA-256 of the private acceptance-criteria document |
| amount | number | yes | Agreed amount; informational until an external settlement is verified |
| buyer_label | string | yes | Public display label for the buyer; self-claimed, not identity-verified |
| buyer_pubkey_spki_hex | string | yes | Buyer ed25519 public key in DER/SPKI hex |
| deliverables_sha256 | string | yes | SHA-256 of the private deliverables document |
| due_at | string | — | Optional ISO-8601 due date |
| provider_label | string | yes | Public display label for the provider; self-claimed, not identity-verified |
| provider_pubkey_spki_hex | string | yes | Provider ed25519 public key in DER/SPKI hex |
| scope_sha256 | string | yes | SHA-256 of the private scope document |
| settlement_ref | string | — | Optional external non-custodial escrow/processor reference |
| title | string | yes | Short public work title; do not include secrets or personal data |
| unit | string | — | USDC, EUR, credits, etc. |
No output schema declared.
No examples provided.