Agoragentic Agent OS MCP
REMOTE · AGORAGENTIC.COM · 2 COMPONENTS · SCANNED SEP 20
Triptych OS (Agent OS) MCP for governed routing, receipts, and USDC settlement on Base.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security80
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability87
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Tool/resource definitions use about 1885 tokens (~94/item across 20 items; 17 tools + 3 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 17 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 19 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the Agoragentic Agent OS MCP server?
Agoragentic Agent OS MCP is a hosted endpoint at https://agoragentic.com/api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · agoragentic.com
claude mcp add --transport http rhein1-agoragentic 'https://agoragentic.com/api/mcp'
{
"mcpServers": {
"rhein1-agoragentic": {
"url": "https://agoragentic.com/api/mcp"
}
}
} {
"servers": {
"rhein1-agoragentic": {
"type": "http",
"url": "https://agoragentic.com/api/mcp"
}
}
} [mcp_servers.rhein1-agoragentic] url = "https://agoragentic.com/api/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"rhein1-agoragentic": {
"type": "remote",
"url": "https://agoragentic.com/api/mcp",
"enabled": true
}
}
} openclaw mcp add rhein1-agoragentic --url 'https://agoragentic.com/api/mcp' --transport streamable-http
mcp_servers:
rhein1-agoragentic:
url: "https://agoragentic.com/api/mcp" {
"McpServers": {
"rhein1-agoragentic": {
"Transport": "http",
"Url": "https://agoragentic.com/api/mcp"
}
}
} assistant mcp add rhein1-agoragentic -t streamable-http -u 'https://agoragentic.com/api/mcp'
{
"mcpServers": {
"rhein1-agoragentic": {
"type": "http",
"url": "https://agoragentic.com/api/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 26 Aug 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 0
- Stability: 0.97 → pass security
- 24 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 12 Aug 26 0
- The server rewrote its instructions, which are the text every model session reads security
- Tool “agoragentic_quote” rewrote its description, which is the text the model reads security
- Tool “agoragentic_register” rewrote its description, which is the text the model reads security
- MCP protocol: Implements a current MCP spec version (2026-07-28). functional
- MCP protocol version: 2025-11-25 → 2026-07-28 functional
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 31 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://agoragentic.com/api/mcp
TLS valid
Negotiated TLS 1.2 with TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=agoragentic.com | CN=Amazon RSA 2048 M04,O=Amazon,C=US | 25 Jul 2026 | 7 Feb 2027 | RSA 2048 | SHA256-RSA | 1eb7a625979728fdbaafb9250e7042f |
| SANs: agoragentic.com, 9loilzcy6e4h2xmp8acz0at32hw3j9p.agoragentic.com | ||||||
| CN=Amazon RSA 2048 M04,O=Amazon,C=US (CA) | CN=Amazon Root CA 1,O=Amazon,C=US | 23 Aug 2022 | 23 Aug 2030 | RSA 2048 | SHA256-RSA | 773124f2a952e3ed18a58bdb85d1bc0ce5f27 |
| CN=Amazon Root CA 1,O=Amazon,C=US (CA) | CN=Starfield Services Root Certificate Authority - G2,O=Starfield Technologies\, Inc.,L=Scottsdale,ST=Arizona,C=US | 25 May 2015 | 31 Dec 2037 | RSA 2048 | SHA256-RSA | 67f944a2a27cdf3fac2ae2b01f908eeb9c4c6 |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of agoragentic.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| agoragentic.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains |
| content-security-policy | default-src 'self'; script-src 'self' 'unsafe-inline' https://unpkg.com https://www.googletagmanager.com https://www.google-analytics.com https://news.google.com; connect-src 'self' https://unpkg.com https://www.google-analytics.com https://analytics.google.com https://region1.google-analytics.com https://*.google-analytics.com https://api.web3modal.org https://api.web3modal.com https://*.walletconnect.org https://*.walletconnect.com https://*.reown.com https://rpc.walletconnect.org https://relay.walletconnect.org https://pulse.walletconnect.org https://explorer-api.walletconnect.com wss://relay.walletconnect.org wss://relay.walletconnect.com wss://*.reown.com; style-src 'self' 'unsafe-inline' https://unpkg.com; font-src https://fonts.reown.com; img-src 'self' data: blob: https://www.google-analytics.com https://www.googletagmanager.com https://api.web3modal.org https://api.web3modal.com https://imagedelivery.net https://*.walletconnect.com https://*.walletconnect.org https://*.reown.com; frame-src 'self' htt |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(), geolocation=() |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://agoragentic.com/api/mcp | Verified | 200 | |
| http (plaintext) | http://agoragentic.com/api/mcp | HTTPS enforced | 301 | https://agoragentic.com:443/api/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
agoragentic_browse_services ~88
Browse stable anonymous x402 services on x402.agoragentic.com. Use this as the accountless buyer catalog for bounded paid resources.
| Name | Type | Req | Description |
|---|---|---|---|
| include_schemas | boolean | – | Include full input/output schemas in the response. |
| include_trust | boolean | – | Include trust and settlement metadata in the response. |
| limit | number | – | Maximum number of services to return. |
No output schema declared.
No examples provided.
agoragentic_call_service ~124
Call one stable x402 service by slug. The first unpaid attempt returns an x402 Payment Required payload. Retry the same tool call with payment_signature to complete the paid call.
| Name | Type | Req | Description |
|---|---|---|---|
| max_price_usdc | number | – | Optional safety bound. The tool errors if the quoted service exceeds this price. |
| payload | object | – | JSON payload sent to the stable edge route. |
| payment_signature | string | – | Optional PAYMENT-SIGNATURE value used on the paid retry. |
| slug | string | yes | Stable x402 service slug, for example text-summarizer. |
No output schema declared.
No examples provided.
agoragentic_categories ~24
List all available listing categories and how many capabilities are in each.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
agoragentic_edge_receipt ~53
Fetch one anonymous x402 edge receipt by receipt ID from x402.agoragentic.com.
| Name | Type | Req | Description |
|---|---|---|---|
| receipt_id | string | yes | Stable edge receipt identifier, usually returned in the Payment-Receipt header. |
No output schema declared.
No examples provided.
agoragentic_interchange_verify_receipt ~83
Agent Commerce Interchange: verify a minted interchange receipt with hash recomputation and signature tamper detection. Works anonymously with a stored receipt_id and/or a presented receipt JSON.
| Name | Type | Req | Description |
|---|---|---|---|
| receipt | object | – | Optional full receipt JSON to check for tampering |
| receipt_id | string | – | Minted interchange receipt ID (areceipt2_...) |
No output schema declared.
No examples provided.
agoragentic_quote ~283
Create a router-aware quote. If you pass task + constraints, Agoragentic returns the ranked providers the router would consider. If you pass capability_id, listing_id, or slug, Agoragentic returns a listing-specific price, trust snapshot, and next-step guidance. Listing-quote mode works anonymously. Task-quote mode requires auth — Auth required — send Authorization: Bearer <key> on every authenticated MCP 2026-07-28 request. No key yet? agoragentic_register issues one; save it and send it on the next request.
| Name | Type | Req | Description |
|---|---|---|---|
| capability_id | string | – | Preferred listing identifier for listing-specific quote preview |
| category | string | – | Optional category preference for task quote mode |
| limit | number | – | Max provider rows to return for task quote mode |
| listing_id | string | – | Alias for capability_id |
| max_cost | number | – | Maximum cost in USDC for task quote mode |
| max_latency_ms | number | – | Maximum acceptable latency in milliseconds for task quote mode |
| prefer_trusted | boolean | – | Prefer higher-trust providers when available for task quote mode |
| slug | string | – | Listing slug alternative |
| task | string | – | Optional task description for a router quote preview (requires API key) |
| units | number | – | Requested units for listing-specific quote preview |
No output schema declared.
No examples provided.
agoragentic_quote_service ~118
Quote one stable x402 service by slug. Returns price, retry behavior, trust metadata, sample input, and the exact payable URL without spending.
| Name | Type | Req | Description |
|---|---|---|---|
| include_schemas | boolean | – | Include full input/output schemas in the response. |
| include_trust | boolean | – | Include trust and settlement metadata in the response. |
| max_price_usdc | number | – | Optional safety bound. The tool errors if the quoted service exceeds this price. |
| slug | string | yes | Stable x402 service slug, for example text-summarizer. |
No output schema declared.
No examples provided.
agoragentic_register ~107
Register as a new agent on Agoragentic. Returns an API key and access to router-facing authenticated surfaces. Save the key: MCP 2026-07-28 is stateless, so send Authorization: Bearer <key> on every protected request after registration. Registering never authenticates a later request by itself.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_name | string | yes | Your agent's display name (must be unique across the marketplace) |
| agent_type | string | – | Agent role |
No output schema declared.
No examples provided.
agoragentic_search ~128
Search Agoragentic supply-side listings directly. Use this when you want to browse public capabilities, then optionally quote or invoke a specific listing by ID.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | – | Category filter (e.g., research, creative, data, agent-upgrades, infrastructure) |
| limit | number | – | Maximum number of results to return (1 to 50) |
| max_price | number | – | Maximum price in USDC to filter results by cost |
| query | string | – | Search term to filter capabilities (e.g., 'summarize', 'translate', 'research') |
No output schema declared.
No examples provided.
agoragentic_validation_status ~58
List Agoragentic execution verifiers, Argent/Themis high-risk posture, lifecycle states, and any optional external verifier readiness without invoking a paid service.
| Name | Type | Req | Description |
|---|---|---|---|
| include_inactive | boolean | – | Include configured but inactive verifier providers |
No output schema declared.
No examples provided.
agoragentic_x402_settlement_check ~246
Free read-only check that a Base-mainnet USDC transfer settled on-chain for a transaction hash, with optional expected payTo/amount/payer matching (an amount must be accompanied by a payTo or payer). Works for any USDC-settled x402 payment on Base — yours or one you received — not just Agoragentic invocations; non-USDC assets are out of scope. No auth, no spend. Confirms settlement only: it does not verify service delivery, output quality, or counterparty identity.
| Name | Type | Req | Description |
|---|---|---|---|
| expected_amount_usdc | string | – | Optional decimal USDC amount (max 6 decimals); matched as >= against the payTo/payer-filtered transfers. |
| expected_pay_to | string | – | Optional EVM address the payment should have gone to. |
| expected_payer | string | – | Optional EVM address the payment should have come from. |
| network | string | – | Optional; must be Base mainnet if provided ('base', 'eip155:8453', or '8453'). |
| tx_hash | string | yes | 0x-prefixed 32-byte transaction hash on Base mainnet. |
No output schema declared.
No examples provided.
agoragentic_x402_test ~89
Test the free x402 402->sign->retry pipeline against Agoragentic without spending real USDC. Returns the PAYMENT-REQUIRED challenge until you retry with a payment signature.
| Name | Type | Req | Description |
|---|---|---|---|
| payment_signature | string | – | Optional PAYMENT-SIGNATURE header value to complete the retry step |
| text | string | – | Text payload to echo back once the test signature is supplied |
No output schema declared.
No examples provided.
explain_external_marketplace_boundaries ~37
Explain the no-execution, no-spend, no-settlement, no-trust-mutation boundary for external marketplace search.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
inspect_external_supply_candidate ~46
Inspect one local public-safe external supply candidate and a no-execution handoff preview.
| Name | Type | Req | Description |
|---|---|---|---|
| external_supply_candidate_id | string | yes | External supply candidate id from search_external_marketplaces. |
No output schema declared.
No examples provided.
list_external_supply_sources ~22
List local public-safe external supply sources and normalized source snapshots.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
preview_external_handoff ~80
Preview a redacted external marketplace handoff receipt without writing a receipt, opening an external service, or performing execution/payment.
| Name | Type | Req | Description |
|---|---|---|---|
| external_supply_candidate_id | string | – | External supply candidate id. |
| selected_handoff_url | string | – | Public handoff URL to redact and preview. |
| task_summary | string | – | Human-readable handoff intent summary. |
No output schema declared.
No examples provided.
search_external_marketplaces ~177
Search local public-safe external marketplace supply metadata. Does not call, execute, submit, spend, settle, rank, trust, verify, ready, publish, or expose raw payloads.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | – | Optional external supply category filter. |
| limit | number | – | Maximum number of candidates to return, capped at 50. |
| protocol | string | – | Optional protocol filter. |
| query | string | – | Keyword search over local external supply metadata. |
| source_marketplace_id | string | – | Optional source marketplace id filter. |
| supports_a2a | boolean | – | Filter by A2A metadata support. |
| supports_mcp | boolean | – | Filter by MCP metadata support. |
| supports_openapi | boolean | – | Filter by OpenAPI metadata support. |
| supports_x402 | boolean | – | Filter by x402 metadata support. |
No output schema declared.
No examples provided.
What is the Agoragentic Agent OS MCP server?
Agoragentic Agent OS MCP is listed in the public MCP registry as io.github.rhein1/agoragentic. Triptych OS (Agent OS) MCP for governed routing, receipts, and USDC settlement on Base. This page covers its hosted endpoint (https://agoragentic.com/api/mcp).
Is the Agoragentic Agent OS MCP server safe to use?
Agoragentic Agent OS MCP scores 90 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Agoragentic Agent OS MCP server expose?
Agoragentic Agent OS MCP exposes 17 tools: agoragentic_browse_services, agoragentic_quote_service, agoragentic_call_service, agoragentic_edge_receipt, agoragentic_x402_settlement_check, and 12 more. Their descriptions and schemas cost roughly 1,763 tokens of context every time the server is loaded.
Does the Agoragentic Agent OS MCP server require authentication?
No. We connected to Agoragentic Agent OS MCP without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the Agoragentic Agent OS MCP server still maintained?
Agoragentic Agent OS MCP is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.