# AANet (remote · aanet.space)

Metered coordination for agent swarms: locks, sub-keys, storage, messaging. x402 billing (USDC).

- Trust score: 67/100 (medium)
- Change this week: +3
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-28

## Components

- remote · `aanet.space`: 67/100 (this document), [markdown](https://verifymcp.io/servers/space-aanet-aanet-mcp/aanet.md), [page](https://verifymcp.io/servers/space-aanet-aanet-mcp/aanet)

## Channel facts

- Endpoint: `https://aanet.space/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `1.2.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-28.

- **Endpoint Security**: 57/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation not fully verified: no authorisation is required to call this server, and 27 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe.
  - HTTPS is enforced; there's no plaintext access path.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 67/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 7258 tokens (~268/item across 27 items; 27 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 60/100
  - Stability observed for 18 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
  - Structured output schemas are declared (22% of tools); any adoption earns full credit.
- **Tool Safety**: 25/100
  - Injection-marker check failed: the description of parameter "stamp" on tool "aanet_write_file" contains hidden, non-rendering content, an HTML comment, at byte 29 of that field.
  - 0 of 7 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "aanet_delete_workspace" implies "delete" and declares no destructiveHint at all, which the MCP spec reads as destructive by default.
  - An AI judge read all 27 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a current MCP spec version (2026-07-28).

## Install

### How do I install the AANet MCP server?

AANet is a hosted endpoint at https://aanet.space/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http space-aanet-aanet-mcp 'https://aanet.space/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "space-aanet-aanet-mcp": {
      "url": "https://aanet.space/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "space-aanet-aanet-mcp": {
      "type": "http",
      "url": "https://aanet.space/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.space-aanet-aanet-mcp]
url = "https://aanet.space/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "space-aanet-aanet-mcp": {
      "type": "remote",
      "url": "https://aanet.space/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add space-aanet-aanet-mcp --url 'https://aanet.space/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  space-aanet-aanet-mcp:
    url: "https://aanet.space/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "space-aanet-aanet-mcp": {
      "Transport": "http",
      "Url": "https://aanet.space/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add space-aanet-aanet-mcp -t streamable-http -u 'https://aanet.space/mcp'
```

### Other

```json
{
  "mcpServers": {
    "space-aanet-aanet-mcp": {
      "type": "http",
      "url": "https://aanet.space/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-28 (score 67, +1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-26 (score 66, 0)

- [security] Tool “aanet_append_file” rewrote its description, which is the text the model reads
- [security] Tool “aanet_write_file” rewrote its description, which is the text the model reads
- [functional] New tool “aanet_estimate_savings”

### 2026-09-25 (score 66, +1)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-24 (score 65, 0)

- [security] Tool “aanet_deposit” rewrote its description, which is the text the model reads

### 2026-09-23 (score 65, +1)

No change was recorded against any check on this day. Stability & Change Management went from 40 to 43. That category is still filling its 30-day observation window: 12 days of observed history at the previous scan, 13 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-21 (score 64, +1)

No change was recorded against any check on this day. Stability & Change Management went from 33 to 37. That category is still filling its 30-day observation window: 10 days of observed history at the previous scan, 11 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-19 (score 63, +1)

- [security] Tool “aanet_create_trial_workspace” rewrote its description, which is the text the model reads

### 2026-09-17 (score 62, +1)

No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.

## MCP tools (27)

### `aanet_create_workspace` (~173 tokens)

Create a real AANet workspace with a prepaid USDC balance — the entry
    point for an orchestrator agent starting a new swarm task. Use
    aanet_create_trial_workspace instead if you want to explore the API
    before paying anything.

    On success, returns {workspace_id, label, owner_key, created_at}. Store
    owner_key immediately: it is generated once, never stored in recoverable
    form, and there is no "forgot my key" recovery path — losing it means
    losing control of the workspace. The workspace starts with a balance of
    0; fund it with aanet_deposit before any metered operation will succeed.

Input parameters:

- `label` (string, required): A display name for your own reference — free text, not required to be unique.

### `aanet_create_trial_workspace` (~177 tokens)

Create a free trial workspace — no payment, no arguments, works
    immediately. Use this instead of aanet_create_workspace when you want to
    exercise the API (files, locks, sub-keys, messages) before committing
    real money.

    Pre-funded with a small fixed balance (currently 100 units = $0.001) and
    expires exactly 24 hours after creation, regardless of remaining
    balance or activity — it is then deleted permanently along with
    everything in it. Returns the same shape as aanet_create_workspace plus
    trial_expires_at. aanet_deposit and aanet_request_refund both reject a
    trial workspace outright, since no real money ever entered it. If your
    task won't fit in 24 hours, create a real workspace instead.

### `aanet_get_workspace` (~237 tokens)

Check a workspace's current balance and status — the read-only
    counterpart to every other workspace tool. Works with the owner_key or
    any sub-key issued under it (not restricted to the owner).

    Returns deposit_balance and total_spent in raw integer units ($0.00001
    each), plus is_trial/trial_expires_at (null for a non-trial workspace)
    and blocked (true if the operator has manually suspended it, in which
    case every metered call returns 403 until unblocked). Call this before a
    batch of expensive operations to confirm you won't hit a 402 partway
    through.

Input parameters:

- `api_key` (string, required): Bearer credential for this workspace: either the owner_key returned once by aanet_create_workspace/aanet_create_trial_workspace, or a sub-key returned by aanet_mint_subkey. Sent under the hood as `Au…
- `workspace_id` (string, required): The workspace_id from aanet_create_workspace or aanet_create_trial_workspace.

### `aanet_delete_workspace` (~252 tokens)

Permanently and irreversibly delete a workspace: every sub-key, all
    files, the activity log, and any registered webhooks are destroyed
    along with it — there is no undo and no trash/recycle bin. Requires the
    owner_key; a sub-key gets a 403.

    Call aanet_request_refund first if the workspace still has balance you
    want back, and wait for aanet_get_refund_status to show "paid" before
    deleting — once the workspace is gone, so is any way to claim what was
    left. Use this when a task is finished or permanently abandoned, not as
    a way to "reset" a workspace you plan to keep using.

Input parameters:

- `api_key` (string, required): Bearer credential for this workspace: either the owner_key returned once by aanet_create_workspace/aanet_create_trial_workspace, or a sub-key returned by aanet_mint_subkey. Sent under the hood as `Au…
- `workspace_id` (string, required): The workspace_id from aanet_create_workspace or aanet_create_trial_workspace.

### `aanet_deposit` (~383 tokens)

Fund a real workspace via the x402 protocol — a two-step call using
    the same tool both times. This does not accept trial workspaces (use
    aanet_create_workspace for a fundable one) and requires the owner_key.

    Step 1 — call with only api_key/workspace_id/amount_usd: returns an x402
    PaymentRequired challenge offering USDC on Base, Polygon, Arbitrum,
    Avalanche, and Solana as payment options; nothing is charged yet.
    Step 2 — sign that challenge
    with your own wallet/x402 client (this tool cannot sign for you) and
    call again with the identical amount_usd plus the resulting proof as
    payment_signature; on success this verifies and settles against the
    facilitator and returns {workspace_id, deposited_units, tx_hash,
    network}. A failed or already-used signature raises an error rather than
    silently no-op'ing.

Input parameters:

- `amount_usd` (string, required): Deposit amount in US dollars as a decimal string, e.g. "1.00". Minimum $0.25.
- `api_key` (string, required): Bearer credential for this workspace: either the owner_key returned once by aanet_create_workspace/aanet_create_trial_workspace, or a sub-key returned by aanet_mint_subkey. Sent under the hood as `Au…
- `payment_signature`: Leave unset on your first call to receive the payment challenge. Set this to the signed proof from your own x402-aware wallet client on the follow-up call with the same amount_usd, to actually settle…
- `workspace_id` (string, required): The workspace_id from aanet_create_workspace or aanet_create_trial_workspace.

### `aanet_mint_subkey` (~349 tokens)

Issue a new scoped credential for one sub-agent — the standard way to
    bring a sub-agent into an existing workspace. Requires the owner_key; a
    sub-key cannot mint another sub-key.

    Returns {subkey_id, key} where key is shown exactly once, the same as
    owner_key at workspace creation. Give each sub-agent its own sub-key
    rather than sharing one across several — that's what makes
    aanet_get_activity attributable per sub-agent and what lets you revoke
    exactly one misbehaving sub-agent (aanet_revoke_subkey) without taking
    down the rest of the swarm.

Input parameters:

- `api_key` (string, required): Bearer credential for this workspace: either the owner_key returned once by aanet_create_workspace/aanet_create_trial_workspace, or a sub-key returned by aanet_mint_subkey. Sent under the hood as `Au…
- `budget_cap`: Cap this sub-key's own cumulative spend, in the same integer units as the workspace balance ($0.00001 each), even if the workspace has more left. Leave unset for no per-key cap beyond the shared work…
- `label` (string, required): Display name for this sub-key, e.g. the sub-agent's role or id.
- `path_scope_prefix`: Restrict this sub-key to file paths and lock names under this prefix only (least-privilege). Leave unset for unrestricted access to the whole workspace.
- `workspace_id` (string, required): The workspace_id from aanet_create_workspace or aanet_create_trial_workspace.

### `aanet_list_subkeys` (~172 tokens)

List every sub-key ever issued under a workspace (including revoked
    ones), with each one's scope, budget_cap, and spent_so_far — the
    inventory view that complements aanet_get_activity's per-event log.
    Owner_key required; raw key values are never included since they're
    only ever shown once at creation.

Input parameters:

- `api_key` (string, required): Bearer credential for this workspace: either the owner_key returned once by aanet_create_workspace/aanet_create_trial_workspace, or a sub-key returned by aanet_mint_subkey. Sent under the hood as `Au…
- `workspace_id` (string, required): The workspace_id from aanet_create_workspace or aanet_create_trial_workspace.

Output parameters:

- `result` (array)

### `aanet_update_subkey` (~255 tokens)

Change a live sub-key's scope and/or budget cap without revoking and
    reissuing it — use this instead of aanet_revoke_subkey + aanet_mint_subkey
    when the sub-agent's credentials themselves should keep working (e.g.
    widening its file scope mid-task, or raising a budget cap it hit).
    Owner_key required. Fields left unset are unchanged, not cleared.

Input parameters:

- `api_key` (string, required): Bearer credential for this workspace: either the owner_key returned once by aanet_create_workspace/aanet_create_trial_workspace, or a sub-key returned by aanet_mint_subkey. Sent under the hood as `Au…
- `budget_cap`: New spending cap. Leave unset to keep the current value unchanged.
- `path_scope_prefix`: New path-scope prefix. Leave unset to keep the current value unchanged.
- `subkey_id` (string, required): The subkey_id from aanet_mint_subkey or aanet_list_subkeys.
- `workspace_id` (string, required): The workspace_id from aanet_create_workspace or aanet_create_trial_workspace.

### `aanet_revoke_subkey` (~234 tokens)

Permanently revoke one sub-agent's credentials — every subsequent call
    with that key gets a 401. Use this when a sub-agent is compromised,
    misbehaving, or simply finished, without affecting any other sub-key in
    the workspace. Owner_key required.

    Immediately releases any lock the revoked sub-key was holding (as if it
    had called aanet_release_lock itself), so a revoked sub-agent can't
    accidentally block the rest of the swarm by holding a lock forever.

Input parameters:

- `api_key` (string, required): Bearer credential for this workspace: either the owner_key returned once by aanet_create_workspace/aanet_create_trial_workspace, or a sub-key returned by aanet_mint_subkey. Sent under the hood as `Au…
- `subkey_id` (string, required): The subkey_id from aanet_mint_subkey or aanet_list_subkeys.
- `workspace_id` (string, required): The workspace_id from aanet_create_workspace or aanet_create_trial_workspace.

### `aanet_read_file` (~247 tokens)

Read a file's content, or list a directory's entries if path points
    to one — the read counterpart to aanet_write_file/aanet_append_file.
    Metered per call regardless of file size. Returns {path, content,
    is_dir, entries, etag}; for a directory, content is null and entries
    lists child names, for a file it's the reverse. Save the returned etag
    if you plan to write back — pass it as if_match on aanet_write_file to
    avoid clobbering a newer write from another sub-agent.

Input parameters:

- `api_key` (string, required): Bearer credential for this workspace: either the owner_key returned once by aanet_create_workspace/aanet_create_trial_workspace, or a sub-key returned by aanet_mint_subkey. Sent under the hood as `Au…
- `path` (string, required): Virtual file path within the workspace, e.g. "notes/progress.md".
- `workspace_id` (string, required): The workspace_id from aanet_create_workspace or aanet_create_trial_workspace.

### `aanet_write_file` (~415 tokens)

Overwrite a file's entire content, creating it if it doesn't exist —
    use aanet_append_file instead if you want to add one entry without
    replacing what's there. Fires a file_write webhook event on success
    (see aanet_register_webhook).

    Pass if_match with the file's last-known etag to make this a
    compare-and-swap: if another sub-agent wrote to the same path since you
    last read it, this raises a 409 instead of silently overwriting their
    change — re-read, resolve, and retry rather than assume your write won.
    content over 1 MiB is rejected with 413, before writing or charging —
    this service is for coordination artifacts, not bulk storage.
    Returns {path, created, etag}.

Input parameters:

- `api_key` (string, required): Bearer credential for this workspace: either the owner_key returned once by aanet_create_workspace/aanet_create_trial_workspace, or a sub-key returned by aanet_mint_subkey. Sent under the hood as `Au…
- `content` (string, required): Full new content of the file — this replaces it entirely.
- `if_match`: The file's current etag (from aanet_read_file or a prior write's response), to detect a concurrent write from another sub-agent. Omit to overwrite unconditionally.
- `path` (string, required): Virtual file path within the workspace.
- `stamp` (boolean): If true, appends a trailing `<!-- coordinated-via: aanet.space workspace_id=... -->` comment to the written content. Meant for files that will be handed off or exported outside this workspace, so a d…
- `workspace_id` (string, required): The workspace_id from aanet_create_workspace or aanet_create_trial_workspace.

### `aanet_append_file` (~296 tokens)

Append one entry to a file without touching what's already there,
    creating the file if it doesn't exist yet — use aanet_write_file instead
    when you need to replace the whole file. Typical use: a shared log or
    running notes file multiple sub-agents contribute to. Fires a
    file_write webhook event on success. Rejected with 413, before writing
    or charging, if the resulting file (existing content + this append)
    would exceed 1 MiB. Returns {path, appended, etag}.

Input parameters:

- `api_key` (string, required): Bearer credential for this workspace: either the owner_key returned once by aanet_create_workspace/aanet_create_trial_workspace, or a sub-key returned by aanet_mint_subkey. Sent under the hood as `Au…
- `content` (string, required): Text to append as a new entry — the existing content is kept.
- `if_match`: The file's current etag, for the same conflict-detection purpose as on aanet_write_file.
- `path` (string, required): Virtual file path within the workspace.
- `stamp` (boolean): Same attribution-comment option as on aanet_write_file, applied to this appended entry.
- `workspace_id` (string, required): The workspace_id from aanet_create_workspace or aanet_create_trial_workspace.

### `aanet_delete_file` (~263 tokens)

Permanently remove a file — the missing piece of the file lifecycle
    alongside aanet_read_file/aanet_write_file/aanet_append_file. There is
    no undo: to recover, a sub-agent would need its own backup of the
    content. Fires a file_delete webhook event on success (see
    aanet_register_webhook). Raises a 404 if the path doesn't exist, a 409
    if it's a directory or if_match doesn't match the current etag. Returns
    {path, deleted}.

Input parameters:

- `api_key` (string, required): Bearer credential for this workspace: either the owner_key returned once by aanet_create_workspace/aanet_create_trial_workspace, or a sub-key returned by aanet_mint_subkey. Sent under the hood as `Au…
- `if_match`: The file's current etag, for the same conflict-detection purpose as on aanet_write_file.
- `path` (string, required): Virtual file path within the workspace. Must point to a file, not a directory.
- `workspace_id` (string, required): The workspace_id from aanet_create_workspace or aanet_create_trial_workspace.

### `aanet_acquire_lock` (~305 tokens)

Claim exclusive ownership of a named unit of work so no other
    sub-agent starts the same thing — call this before starting work, not
    after. Returns {lease_expires_at} on success, or a 409 if another
    sub-agent already holds an unexpired lease on the same name (that
    conflict is free — you are not charged for losing a race).

    You do not hold the lock forever: once lease_seconds elapses, anyone can
    acquire it out from under you, even if you're still working. Call
    aanet_renew_lock periodically while still working, and
    aanet_release_lock the moment you're done so others don't wait out the
    full lease unnecessarily.

Input parameters:

- `api_key` (string, required): Bearer credential for this workspace: either the owner_key returned once by aanet_create_workspace/aanet_create_trial_workspace, or a sub-key returned by aanet_mint_subkey. Sent under the hood as `Au…
- `lease_seconds` (integer, required): How long you hold the lock before it becomes reclaimable by anyone else, 1-3600 seconds.
- `name` (string, required): Lock name identifying the unit of work, e.g. "process-batch-3".
- `workspace_id` (string, required): The workspace_id from aanet_create_workspace or aanet_create_trial_workspace.

### `aanet_renew_lock` (~218 tokens)

Extend a lock you currently hold, before its lease runs out — call
    this instead of aanet_acquire_lock again while work is still in
    progress. Fails with 404 if nobody holds the lock, or 403 if a
    different sub-key is the current holder (you can't renew someone
    else's lease). Returns {lease_expires_at}.

Input parameters:

- `api_key` (string, required): Bearer credential for this workspace: either the owner_key returned once by aanet_create_workspace/aanet_create_trial_workspace, or a sub-key returned by aanet_mint_subkey. Sent under the hood as `Au…
- `lease_seconds` (integer, required): New lease duration from now, 1-3600 seconds.
- `name` (string, required): Lock name — must match a lock you currently hold.
- `workspace_id` (string, required): The workspace_id from aanet_create_workspace or aanet_create_trial_workspace.

### `aanet_release_lock` (~246 tokens)

Voluntarily give up a lock you hold, immediately, instead of waiting
    for its lease to expire — always call this as soon as you're done with
    the unit of work, so a sub-agent waiting on it doesn't idle
    unnecessarily. Free (no charge), unlike acquire/renew. Fails with 404 if
    nobody holds it or 403 if you're not the current holder. Fires a
    lock_available webhook event on success (see aanet_register_webhook) so
    a waiting sub-agent can react immediately instead of polling
    aanet_acquire_lock in a loop.

Input parameters:

- `api_key` (string, required): Bearer credential for this workspace: either the owner_key returned once by aanet_create_workspace/aanet_create_trial_workspace, or a sub-key returned by aanet_mint_subkey. Sent under the hood as `Au…
- `name` (string, required): Lock name — must match a lock you currently hold.
- `workspace_id` (string, required): The workspace_id from aanet_create_workspace or aanet_create_trial_workspace.

### `aanet_get_activity` (~337 tokens)

Read the server-side audit log of every attempt in this workspace,
    successful or rejected — the authoritative source of what each
    sub-agent actually did, since sub-agents can't fake or skip this the
    way they could misreport their own actions. Owner_key required.

    Each entry has subkey_id, operation, path, cost_charged, status (e.g.
    OK, INSUFFICIENT_BALANCE, SCOPE_DENIED, CONFLICT), and a free-text
    detail. Use this to reconstruct what happened after the fact, or to
    check a sub-agent's spend pattern before adjusting its budget_cap via
    aanet_update_subkey.

Input parameters:

- `api_key` (string, required): Bearer credential for this workspace: either the owner_key returned once by aanet_create_workspace/aanet_create_trial_workspace, or a sub-key returned by aanet_mint_subkey. Sent under the hood as `Au…
- `limit` (integer): Maximum entries to return, newest first, up to 500.
- `operation`: Filter to one operation type, e.g. "PUT_FILE", "LOCK_ACQUIRE", "SEND_MESSAGE", "WEBHOOK_DELIVERY". Omit for all operation types.
- `since`: ISO timestamp — only return entries at or after this time.
- `subkey_id`: Filter to attempts by this sub-key only. Omit for all.
- `workspace_id` (string, required): The workspace_id from aanet_create_workspace or aanet_create_trial_workspace.

Output parameters:

- `result` (array)

### `aanet_submit_feedback` (~334 tokens)

Report a bug, request a feature, or flag that pricing feels wrong —
    this is the one feedback channel into how the operator prioritizes what
    to build next, not a support ticket that gets a reply. Any valid,
    unrevoked key can call this, owner or sub-key. Returns
    {feedback_id, status} with status always "open" initially; there is no
    tool to check its status afterward — it either got through (you got a
    result back) or it didn't (you got an error).

Input parameters:

- `api_key` (string, required): Bearer credential for this workspace: either the owner_key returned once by aanet_create_workspace/aanet_create_trial_workspace, or a sub-key returned by aanet_mint_subkey. Sent under the hood as `Au…
- `category` (string, required): One of "bug", "feature", "pricing", "other".
- `description` (string, required): Full detail — what's wrong, or what you'd want and why.
- `pledged_budget_usd` (string, required): Decimal-string USD amount you'd actually pay if this were built, e.g. "5.00". This is a declaration only — nothing is charged or reserved — but it's the only signal the operator uses to prioritize re…
- `title` (string, required): Short one-line summary of the issue or request.

### `aanet_request_refund` (~314 tokens)

Ask for a workspace's entire remaining balance back, when its task is
    done and money is left over — call this before aanet_delete_workspace,
    not after. Owner_key required; trial workspaces reject this outright
    (they never held real money).

    This reserves (zeros out) the full balance immediately, so a second call
    with nothing left to refund fails rather than double-paying out. The
    real network fee for the payout is deducted from what you receive
    (net_payout_usd in the response = gross - fee); if the balance doesn't
    even cover the estimated fee, this call fails instead of reserving
    anything. Payout is processed manually by the operator, not instantly —
    poll aanet_get_refund_status for the outcome rather than assuming
    success once this call returns.

Input parameters:

- `api_key` (string, required): Bearer credential for this workspace: either the owner_key returned once by aanet_create_workspace/aanet_create_trial_workspace, or a sub-key returned by aanet_mint_subkey. Sent under the hood as `Au…
- `destination_address` (string, required): Your own wallet address on that network to receive the payout.
- `network` (string, required): Payout network: "base" or "solana".
- `workspace_id` (string, required): The workspace_id from aanet_create_workspace or aanet_create_trial_workspace.

### `aanet_get_refund_status` (~210 tokens)

Check the status of every refund request ever made for a workspace —
    the way to find out whether an aanet_request_refund call actually got
    paid. Owner_key required. Each entry has status ("pending", "paid", or
    "rejected"), and tx_hash once paid — verify that transaction on-chain
    yourself before treating the refund as confirmed and deleting the
    workspace. A "rejected" entry means the reserved amount was credited
    back to the workspace balance, not lost.

Input parameters:

- `api_key` (string, required): Bearer credential for this workspace: either the owner_key returned once by aanet_create_workspace/aanet_create_trial_workspace, or a sub-key returned by aanet_mint_subkey. Sent under the hood as `Au…
- `workspace_id` (string, required): The workspace_id from aanet_create_workspace or aanet_create_trial_workspace.

Output parameters:

- `result` (array)

### `aanet_send_message` (~301 tokens)

Send a one-shot signal directly to another sub-agent (or to
    everyone), for things that don't belong in a file — e.g. "chunk 3
    done" or "aborting, don't wait on me". Use aanet_write_file /
    aanet_append_file instead for anything that needs to persist as durable
    state; messages are meant to be cheap and disposable, not a record of
    truth.

    Cheaper than a file write on purpose. Fires a message webhook event on
    success (see aanet_register_webhook) — pair the two instead of having
    the recipient poll aanet_get_messages in a loop. Returns
    {message_id, ts}.

Input parameters:

- `api_key` (string, required): Bearer credential for this workspace: either the owner_key returned once by aanet_create_workspace/aanet_create_trial_workspace, or a sub-key returned by aanet_mint_subkey. Sent under the hood as `Au…
- `body` (string, required): Message text.
- `to_subkey_id`: subkey_id of the specific recipient. Leave unset to broadcast to every sub-key in the workspace.
- `topic`: Optional free-text label for filtering later with aanet_get_messages.
- `workspace_id` (string, required): The workspace_id from aanet_create_workspace or aanet_create_trial_workspace.

### `aanet_get_messages` (~273 tokens)

Fetch messages sent via aanet_send_message — the pull-based fallback
    for when you haven't registered a webhook on the message event. A
    sub-key only sees messages addressed to it plus broadcasts (to_subkey_id
    was left unset by the sender); the owner_key sees every message in the
    workspace, for oversight. There's no read/unread tracking server-side —
    track your own last-seen ts and pass it as `since` on the next call,
    the same pattern as aanet_get_activity.

Input parameters:

- `api_key` (string, required): Bearer credential for this workspace: either the owner_key returned once by aanet_create_workspace/aanet_create_trial_workspace, or a sub-key returned by aanet_mint_subkey. Sent under the hood as `Au…
- `limit` (integer): Maximum messages to return, oldest first, up to 500.
- `since`: ISO timestamp — the ts of the last message you already saw, to fetch only what's new.
- `topic`: Filter to messages sent with this exact topic. Omit for all topics.
- `workspace_id` (string, required): The workspace_id from aanet_create_workspace or aanet_create_trial_workspace.

Output parameters:

- `result` (array)

### `aanet_register_webhook` (~441 tokens)

Register a push endpoint so this workspace calls you instead of you
    calling aanet_get_activity/aanet_get_messages/aanet_acquire_lock in a
    polling loop — the main alternative to polling anywhere in this API.
    Owner_key required; up to 5 active webhooks per workspace.

    Returns {webhook_id, secret} with secret shown exactly once — every
    delivery includes an X-AANet-Signature header (HMAC-SHA256 of the raw
    body, keyed by that secret); verify it before trusting a payload as
    genuinely from us. You are billed for every delivery attempt whether or
    not your endpoint responds (WEBHOOK_DELIVERY_COST per attempt, visible
    in aanet_get_activity); a webhook that fails 10 times in a row is
    auto-disabled — check aanet_get_webhook_deliveries if events stop
    arriving. Delivery is best-effort and not durable across a service
    restart, so never treat a webhook as your only source of truth — use it
    to learn something happened sooner, then confirm with the matching GET
    tool if it matters.

Input parameters:

- `api_key` (string, required): Bearer credential for this workspace: either the owner_key returned once by aanet_create_workspace/aanet_create_trial_workspace, or a sub-key returned by aanet_mint_subkey. Sent under the hood as `Au…
- `events` (array, required): Subset of ["file_write", "lock_available", "message"] — file_write fires on any successful aanet_write_file/aanet_append_file, lock_available on an explicit aanet_release_lock (not on passive lease e…
- `url` (string, required): Must be https:// and resolve to a public (non-private/loopback) address at registration time — checked once here, not re-checked on every delivery.
- `workspace_id` (string, required): The workspace_id from aanet_create_workspace or aanet_create_trial_workspace.

### `aanet_list_webhooks` (~179 tokens)

List webhooks registered on a workspace — url, subscribed events, and
    whether each is still active or auto-disabled after repeated failures.
    Owner_key required. Secrets are never included (only shown once, at
    aanet_register_webhook time); use aanet_get_webhook_deliveries for
    per-attempt delivery history on one of these.

Input parameters:

- `api_key` (string, required): Bearer credential for this workspace: either the owner_key returned once by aanet_create_workspace/aanet_create_trial_workspace, or a sub-key returned by aanet_mint_subkey. Sent under the hood as `Au…
- `workspace_id` (string, required): The workspace_id from aanet_create_workspace or aanet_create_trial_workspace.

Output parameters:

- `result` (array)

### `aanet_delete_webhook` (~194 tokens)

Permanently remove a registered webhook — no further events will be
    delivered to it, active or auto-disabled. Owner_key required. There is
    no way to temporarily pause one; delete and re-register with
    aanet_register_webhook if you want it back later (you'll get a new
    secret).

Input parameters:

- `api_key` (string, required): Bearer credential for this workspace: either the owner_key returned once by aanet_create_workspace/aanet_create_trial_workspace, or a sub-key returned by aanet_mint_subkey. Sent under the hood as `Au…
- `webhook_id` (string, required): The webhook_id from aanet_register_webhook or aanet_list_webhooks.
- `workspace_id` (string, required): The workspace_id from aanet_create_workspace or aanet_create_trial_workspace.

### `aanet_estimate_savings` (~218 tokens)

Estimate the cost of coordinating a swarm on AANet versus relaying the
    same coordination through your orchestrator's LLM context — before you
    create a workspace or spend anything. Same formula as the calculator at
    https://aanet.space/#savings.

    AANet side assumes the measured ~16 units/round (1 read + 1 write + 1
    lock cycle) at $0.00001/unit. The relay side assumes ~9,600 tokens/round
    (re-injecting another agent's update into your prompt) at a blended
    $2-$10 per million token rate. This is a rough estimate, not a quote —
    real workloads vary; see aanet_get_activity on an actual workspace for
    your own measured cost once you're running for real.

Input parameters:

- `agents` (integer, required): Number of agents in the swarm you're planning.
- `rounds_per_agent` (integer, required): Coordination rounds each agent will need (reads/writes/lock cycles).

### `aanet_get_webhook_deliveries` (~235 tokens)

Inspect one webhook's delivery history — use this to debug a webhook
    that seems to have gone quiet (check aanet_list_webhooks first to see
    if it's been auto-disabled) or to confirm an event actually fired.
    Owner_key required. Each entry has event_type, status_code (null if the
    request itself never completed, e.g. timeout or DNS failure), and
    success.

Input parameters:

- `api_key` (string, required): Bearer credential for this workspace: either the owner_key returned once by aanet_create_workspace/aanet_create_trial_workspace, or a sub-key returned by aanet_mint_subkey. Sent under the hood as `Au…
- `limit` (integer): Maximum delivery records to return, newest first, up to 200.
- `webhook_id` (string, required): The webhook_id from aanet_register_webhook or aanet_list_webhooks.
- `workspace_id` (string, required): The workspace_id from aanet_create_workspace or aanet_create_trial_workspace.

Output parameters:

- `result` (array)

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/space-aanet-aanet-mcp/aanet#diagnostics

## Score history

- 2026-09-28: 67
- 2026-09-27: 66
- 2026-09-26: 66
- 2026-09-25: 66
- 2026-09-24: 65
- 2026-09-23: 65
- 2026-09-22: 64
- 2026-09-21: 64
- 2026-09-20: 63
- 2026-09-19: 63
- 2026-09-18: 62
- 2026-09-17: 62
- 2026-09-16: 61
- 2026-09-15: 61
- 2026-09-14: 60
- 2026-09-13: 60
- 2026-09-12: 60
- 2026-09-11: 59
- 2026-09-10: 62

## Common questions

### What is the AANet MCP server?

AANet is an MCP server listed in the public MCP registry as space.aanet/aanet-mcp. Metered coordination for agent swarms: locks, sub-keys, storage, messaging. x402 billing (USDC). This page covers its hosted endpoint (https://aanet.space/mcp).

### Is the AANet MCP server safe to use?

AANet scores 67 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the AANet MCP server expose?

AANet exposes 27 tools: aanet_create_workspace, aanet_create_trial_workspace, aanet_get_workspace, aanet_delete_workspace, aanet_deposit, and 22 more. Their descriptions and schemas cost roughly 7,258 tokens of context every time the server is loaded.

### Does the AANet MCP server require authentication?

No. We connected to AANet without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the AANet MCP server still maintained?

AANet is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://aanet.space/mcp
- Website: https://aanet.space/
- Changelog RSS feed: https://verifymcp.io/servers/space-aanet-aanet-mcp/aanet.xml
- Changelog JSON feed: https://verifymcp.io/servers/space-aanet-aanet-mcp/aanet.json
- HTML version of this page: https://verifymcp.io/servers/space-aanet-aanet-mcp/aanet
