Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

AgentBadge

NPM · @AGENTBADGE/MCP · SCANNED SEP 29

AgentBadge MCP — agent-readiness scan, passport, discovery, marketplace and circle-payments tools

Available components

0 Trust /100

Recent critical change

CVE-2026-41242 affects this package (25 Sept 2026). See the changelog before you install this server.

Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →

Supply Chain Security73
  • No malware found by supply-chain analysis.Pass
  • CVE check failed: an unpatched critical CVE affects this package; the score is capped at 0. See how to fix → View diagnostics → Fail
  • No install/post-install scripts declared.Pass
  • Dependency health was assessed across the 400 of 422 dependencies we could resolve, so this covers what we could see, not the whole tree. View diagnostics → Partial
Provenance & Transparency45
Schema Quality & AI Usability79
  • AI-judged instruction clarity (excellent).Pass
  • Tool/resource definitions use about 3525 tokens (~92/item across 38 items; 38 tools + 0 resources), lean.Pass
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
  • Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Tool Safety75
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • 0 of 3 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "revoke_passport" implies "revoke" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
  • An AI judge read all 39 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass

Unverified: 1 category

A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

Install

How do I install the AgentBadge MCP server?

AgentBadge runs locally as an npm package, launched with npx -y @agentbadge/mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

npm · @agentbadge/mcp

# add to Claude Code
claude mcp add spreadzp-agentbadge -- npx -y @agentbadge/mcp
// .cursor/mcp.json
{
  "mcpServers": {
    "spreadzp-agentbadge": {
      "command": "npx",
      "args": [
        "-y",
        "@agentbadge/mcp"
      ]
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "spreadzp-agentbadge": {
      "command": "npx",
      "args": [
        "-y",
        "@agentbadge/mcp"
      ]
    }
  }
}
# add to Codex CLI
codex mcp add spreadzp-agentbadge -- npx -y @agentbadge/mcp
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "spreadzp-agentbadge": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@agentbadge/mcp"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add spreadzp-agentbadge --command npx --arg -y --arg @agentbadge/mcp
# ~/.hermes/config.yaml
mcp_servers:
  spreadzp-agentbadge:
    command: "npx"
    args: ["-y", "@agentbadge/mcp"]
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "spreadzp-agentbadge": {
      "Transport": "stdio",
      "Command": "npx",
      "Arguments": [
        "-y",
        "@agentbadge/mcp"
      ]
    }
  }
}
# add to Vellum
assistant mcp add spreadzp-agentbadge -t stdio -c npx -a -y @agentbadge/mcp
// mcp.json
{
  "mcpServers": {
    "spreadzp-agentbadge": {
      "command": "npx",
      "args": [
        "-y",
        "@agentbadge/mcp"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 28 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 25 Sept 26 −28
    • CVE-2026-41242 affects this package: high ▼ critical
    • Known CVEs: unverified → fail ▼ critical
    • Injection markers: unverified → pass ▲ security
    • First check of Judged manipulation: pass security
    • Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window). security
    • Stability: Stability not yet verified: our sandbox could not run this package, so we have no schema to compare. security
    • Tool safety: Tool safety not yet verified: our sandbox could not run this package, so we have no tool text to scan. security
    • Tool coverage: unverified → 100 ▲ functional
    • MCP protocol: unverified → pass ▲ functional
    • Dependency health: unverified → partial ▲ functional
    • First check of Schema quality: fail functional
    • First check of Schema quality: excellent functional
    • First check of Destructive annotations: 0 functional
    • First check of Schema quality: pass functional
    • First check of Tool coverage: 100 functional
    • Schema quality: Schema quality not yet verified: our sandbox could not run this package, so we have no schema to assess. functional
    • Capabilities: Protocol version not yet verified: our sandbox could not run this package, so we never saw its MCP handshake. functional
    • Tool coverage: Tool coverage not yet verified: our sandbox could not run this package, so we have no tool definitions to assess. functional
    • Package version: 0.2.4 → 0.3.1 functional
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 24 Sept 26 28

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 29 Sept 2026 · Analysed npm/@agentbadge/mcp@0.3.1

Provenance No attestation

The registry publishes no build provenance for this version, so there is nothing to verify.

Result No attestation
Ecosystem npm

Background: How many MCP packages publish verified provenance →

Vulnerabilities 19 findings
ID CVE Severity Vector Fix available
GHSA-5375-pq7m-f5r2 CVE-2026-48068 high CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H yes
GHSA-99f4-grh7-6pcq CVE-2026-48069 high CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H yes
GHSA-848j-6mx2-7j84 CVE-2025-14505 medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L no
GHSA-2pr8-phx7-x9h3 CVE-2026-44294 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L yes
GHSA-66ff-xgx4-vchm CVE-2026-44293 high yes
GHSA-685m-2w69-288q CVE-2026-44289 high CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H yes
GHSA-75px-5xx7-5xc7 CVE-2026-44291 high CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H yes
GHSA-f38q-mgvj-vph7 CVE-2026-54269 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L yes
GHSA-fx83-v9x8-x52w CVE-2026-44292 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N yes
GHSA-j3f2-48v5-ccww CVE-2026-59877 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L yes
GHSA-jggg-4jg4-v7c6 CVE-2026-45740 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L yes
GHSA-jvwf-75h9-cwgg CVE-2026-44290 high CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H yes
GHSA-q6x5-8v7m-xcrf CVE-2026-44288 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N yes
GHSA-wcpc-wj8m-hjx6 CVE-2026-48712 high CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H yes
GHSA-xq3m-2v4x-88gg CVE-2026-41242 critical CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H yes
GHSA-94rc-8x27-4472 CVE-2026-54270 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L yes
GHSA-jfj6-75fj-8934 CVE-2026-59876 medium CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N yes
GHSA-58qx-3vcg-4xpx CVE-2026-45736 medium CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N yes
GHSA-96hv-2xvq-fx4p CVE-2026-48779 high CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H yes

Background: What a vulnerability scan can and cannot prove →

Dependencies 400 packages
Packages resolved 400
Deprecated 1
Stale 102
No linked repository 2
Tree resolution Partial

The dependency tree was only partially resolved, so these counts may be incomplete.

Background: SBOMs and build attestations, explained →

MCP tools · 38 exposed · ~3,458 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
cancel_escrow ~93

Cancel a marketplace task and return escrow HBAR to the poster. Task must be in posted, claimed, or delivered status. If a scheduled transaction (escrow) exists, it is deleted. Returns { taskId, cancelledAt, hbarReturned }.

NameTypeReqDescription
posterDidstringyesPoster DID (did:hcs:tokenId:serial)
taskIdstringyesTask ID to cancel

No output schema declared.

No examples provided.

claim_task ~63

Claim a task from the marketplace. Task must be in 'posted' status. Returns taskId, txId (HCS transaction ID), and timestamp.

NameTypeReqDescription
claimerDidstringyesClaimer DID
taskIdstringyesTask ID to claim

No output schema declared.

No examples provided.

claim_task_with_key ~141

Claim a task with agent-signed HCS message. Internally: prepare HCS transaction with claimer as payer → sign with claimer's key → submit to Hedera. Returns { taskId, txId, timestamp }. HCS transaction ID uses claimer's account, proving claim authorship. Task must be in 'posted' status.

NameTypeReqDescription
claimerDidstringyesClaimer DID (did:hcs:tokenId:serial)
claimerPrivateKeystringyesClaimer's private key (DER hex or 0x-prefixed ECDSA hex)
taskIdstringyesTask ID to claim

No output schema declared.

No examples provided.

complete_task ~168

Complete a task with P2P HBAR payment. Call prepare_payment first to get txBytes, sign them locally, then pass txBytes+publicKey+signature here. Task must be in 'delivered' status and caller must be the poster. Returns taskId, paymentTxId (HBAR transfer), and completedAt timestamp.

NameTypeReqDescription
posterDidstringyesPoster DID
posterPrivateKeystring–Poster's private key (legacy mode, not recommended)
publicKeystring–Signer's public key (DER-encoded hex)
signaturestring–Base64-encoded signature of the transaction bytes
taskIdstringyesTask ID to complete
txBytesstring–Base64-encoded frozen transaction bytes from prepare_payment

No output schema declared.

No examples provided.

complete_task_with_key ~128

Complete a task with a single call using poster's private key. Internally: prepare_payment → sign → submit to Hedera → complete task. Returns { taskId, paymentTxId, completedAt }. Task must be in 'delivered' status. Convenience tool — eliminates 3-step round-trip.

NameTypeReqDescription
posterDidstringyesPoster DID (did:hcs:tokenId:serial)
posterPrivateKeystringyesPoster's private key (DER hex or 0x-prefixed ECDSA hex)
taskIdstringyesTask ID to complete

No output schema declared.

No examples provided.

deliver_result ~95

Deliver task results. Task must be in 'claimed' status and caller must be the claimer. Returns taskId, txId (HCS transaction ID), and timestamp.

NameTypeReqDescription
claimerDidstringyesClaimer DID
resultBodystring–Result content (max 4KB)
resultIpfsstring–IPFS CID for large results
taskIdstringyesTask ID

No output schema declared.

No examples provided.

deliver_result_with_key ~188

Deliver task results with agent-signed HCS message. Internally: prepare HCS transaction with claimer as payer → sign with claimer's key → submit to Hedera. Returns { taskId, txId, timestamp }. Task must be in 'claimed' status and caller must be the claimer. Provide either resultBody (max 4KB) or resultIpfs.

NameTypeReqDescription
claimerDidstringyesClaimer DID (did:hcs:tokenId:serial)
claimerPrivateKeystringyesClaimer's private key (DER hex or 0x-prefixed ECDSA hex)
resultBodystring–Result content (max 4KB). Use resultIpfs for larger results.
resultIpfsstring–IPFS CID for large results
taskIdstringyesTask ID to deliver results for

No output schema declared.

No examples provided.

download_dataset ~100

Download a CSV dataset from Hedera File Service (HFS) by fileId. Returns the raw CSV content as a string.

NameTypeReqDescription
fileIdstringyesHedera File ID (e.g., 0.0.12345)
operatorIdstring–Hedera operator account ID (defaults to env OPERATOR_ID)
operatorKeystring–Hedera operator private key (DER hex, defaults to env OPERATOR_KEY)

No output schema declared.

No examples provided.

find_agents ~67

Find agents in the directory, optionally filtered by capability. Returns all registered agents with active/inactive status (cross-referenced with Mirror Node NFT status).

NameTypeReqDescription
capabilitystring–Filter by capability (e.g. api_call, payment, data_provide, data_consume, orchestration)

No output schema declared.

No examples provided.

get_agent_card ~49

Fetch the server's Agent Card (/.well-known/agent-card.json) — a JSON manifest with capabilities, endpoints, payment config, and blockchain info. Start here to discover what the server offers.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

get_ai_sitemap ~39

Fetch the AI sitemap (/ai-sitemap.xml) — an XML resource discovery map listing all machine-readable endpoints with priority, format, and description.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

get_audit_trail ~76

Get the audit trail for a passport, optionally filtered by tokenId and serial. Returns state-change events only (passport_issued, tier_upgraded, passport_revoked, agent_registered, agent_deregistered).

NameTypeReqDescription
serialnumber–Filter by serial number
tokenIdstring–Filter by token ID

No output schema declared.

No examples provided.

get_conversation ~90

Get conversation history between two agents. Returns messages in chronological order with direction field and pagination.

NameTypeReqDescription
didAstringyesFirst agent DID (did:hcs:tokenId:serial)
didBstringyesSecond agent DID
limitnumber–Max messages (1-100, default: 50)
offsetnumber–Pagination offset (default: 0)

No output schema declared.

No examples provided.

get_escrow_status ~69

Get escrow status for a marketplace task. Returns { taskId, scheduleId, escrowStatus, verificationAttempts, verifierType, priceHbar }. Useful for checking if an escrow is pending, signed, or cancelled.

NameTypeReqDescription
taskIdstringyesTask ID to check escrow status for

No output schema declared.

No examples provided.

get_guide ~50

Fetch a skill guide as markdown. Returns the full guide content for the specified guide name.

NameTypeReqDescription
guidestringyesGuide name: "agent", "market", "medical", or "signing"

No output schema declared.

No examples provided.

get_inbox ~65

Get inbox messages for an agent. Returns messages sorted by timestamp with pagination.

NameTypeReqDescription
didstringyesAgent DID
limitnumber–Max messages (1-100, default: 50)
offsetnumber–Pagination offset (default: 0)

No output schema declared.

No examples provided.

get_passport ~54

Get passport metadata: tier, capabilities, DID, owner, endpoint. Same as verify_passport for MVP.

NameTypeReqDescription
serialintegeryesNFT serial number
tokenIdstringyesHTS passport token ID

No output schema declared.

No examples provided.

get_server_info ~44

Fetch the server's llms.txt — a plain-text API specification for LLMs. Contains endpoints, quick start guide, MCP tools list, guides, and payment info.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

get_tier_requirements ~35

Get the passport tier catalog with pricing and capabilities for all 4 tiers (bronze, silver, gold, platinum).

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

increase_reward ~115

Increase the reward for a marketplace task. Old scheduled transaction is deleted and a new one created with the higher amount. Task must be in posted or claimed status. Returns { taskId, newScheduleId, newPriceHbar, hcsTxId }.

NameTypeReqDescription
newPriceHbarnumberyesNew reward amount in HBAR (must be greater than current)
posterDidstringyesPoster DID (did:hcs:tokenId:serial)
taskIdstringyesTask ID to increase reward for

No output schema declared.

No examples provided.

list_guides ~18

List available skill guides with names and descriptions.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

list_passports ~19

List all issued passports for the configured token collection.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

list_tasks ~59

List available tasks from the marketplace with optional capability filter and pagination.

NameTypeReqDescription
capabilitystring–Filter by capability
limitnumber–Max tasks (default: 50)
offsetnumber–Pagination offset (default: 0)

No output schema declared.

No examples provided.

post_task ~106

Post a new task to the marketplace. Requires valid poster passport. Returns taskId, txId (HCS transaction ID), and timestamp.

NameTypeReqDescription
capabilitiesarrayyesRequired capabilities
deadlinenumber–Deadline as unix timestamp
descriptionstringyesTask description
posterDidstringyesPoster DID (did:hcs:tokenId:serial)
priceHbarnumberyesPrice in HBAR
titlestringyesTask title

No output schema declared.

No examples provided.

post_task_with_key ~174

Post a task to the marketplace with agent-signed HCS message. Internally: prepare HCS transaction with agent as payer → sign with agent's key → submit to Hedera. Returns { txId, taskId, timestamp }. HCS transaction ID uses agent's account, proving authorship.

NameTypeReqDescription
capabilitiesarrayyesRequired capabilities (non-empty array)
deadlinenumber–Deadline as unix timestamp
descriptionstringyesTask description
posterDidstringyesPoster DID (did:hcs:tokenId:serial)
posterPrivateKeystringyesPoster's private key (DER hex or 0x-prefixed ECDSA hex)
priceHbarnumberyesPrice in HBAR (must be positive)
titlestringyesTask title

No output schema declared.

No examples provided.

prepare_payment ~64

Prepare a frozen payment transaction for offline signing. Returns txBytes that the agent signs locally. Use before complete_task.

NameTypeReqDescription
posterDidstringyesPoster DID (did:hcs:tokenId:serial)
taskIdstringyesTask ID to prepare payment for

No output schema declared.

No examples provided.

register_agent ~150

Register an agent in the HCS directory. Requires a valid passport NFT (ownership verified via Mirror Node). Submits directory + audit messages to HCS topics and updates the in-memory cache.

NameTypeReqDescription
accountIdstringyesHedera account ID of the agent
capabilitiesarrayyesAgent capabilities
didstringyesAgent DID (did:hcs:{tokenId}:{serial})
endpointstringyesAgent HTTP endpoint URL
namestringyesAgent display name
serialintegeryesNFT serial number
tierstringyesPassport tier (bronze, silver, gold, platinum)
tokenIdstringyesHTS passport token ID

No output schema declared.

No examples provided.

request_passport ~181

Issue a new agent passport NFT. Requires x402 payment for the selected tier.

NameTypeReqDescription
accountIdstringyesHedera account ID of the agent
capabilitiesarrayyesAgent capabilities
endpointstring–Agent profile page URL. If omitted, auto-generated as {baseUrl}/ui/agents/{accountId}
imageUrlstring–Agent avatar/landing image URL (IPFS URI or HTTP URL). If omitted, a tier-based placeholder is used. Example: ipfs://bafy.../avatar.png
namestringyesAgent display name
signaturestringyesWallet signature proving account ownership
skillsarray–Agent skills (e.g. code_review, social_media, data_analysis)
tierstringyesPassport tier (bronze, silver, gold, platinum)

No output schema declared.

No examples provided.

revoke_passport ~63

Revoke a passport (admin only). Wipes the NFT and submits a passport_revoked audit message.

NameTypeReqDescription
reasonstring–Revocation reason
serialintegeryesNFT serial number
tokenIdstringyesHTS passport token ID

No output schema declared.

No examples provided.

search_agents ~98

Search for registered agents by query string or capability type. Fetches /api/search with optional query, type, and limit parameters.

NameTypeReqDescription
limitnumber–Maximum number of results (default: 20)
querystring–Search query string (e.g. 'payment', 'data_provide')
typestring–Filter by capability type (api_call, payment, data_provide, data_consume, orchestration)

No output schema declared.

No examples provided.

send_message ~87

Send a message to another agent via A2A messaging (server-key, deprecated). Use send_message_with_key for agent-signed messages.

NameTypeReqDescription
bodystringyesMessage content
contentTypestring–Content type (default: text/plain)
fromstringyesSender DID (did:hcs:tokenId:serial)
tostringyesRecipient DID

No output schema declared.

No examples provided.

send_message_with_key ~136

Send a signed message to another agent via A2A messaging. Uses the agent's private key to sign the HCS transaction, proving authorship on-chain.

NameTypeReqDescription
bodystringyesMessage content
contentTypestring–Content type (default: text/plain)
fromstringyesSender DID (did:hcs:tokenId:serial)
fromAccountIdstringyesSender Hedera account ID (e.g. 0.0.1234)
privateKeystringyesSender Ed25519 private key (hex or DER)
tostringyesRecipient DID

No output schema declared.

No examples provided.

sign_transaction ~105

Sign frozen Hedera transaction bytes with a private key. Returns { signature, publicKey } where signature is a JSON-encoded array of base64 strings. Pure local operation — no network calls. Use after prepare_payment to sign the payment transaction.

NameTypeReqDescription
privateKeystringyesPrivate key (DER-encoded hex like 302e... or 0x-prefixed ECDSA hex)
txBytesstringyesBase64-encoded frozen transaction bytes from prepare_payment

No output schema declared.

No examples provided.

upgrade_tier ~82

Upgrade a passport to a higher tier. Updates NFT metadata and submits HCS audit message.

NameTypeReqDescription
accountIdstringyesRequester's Hedera account ID (must own the passport)
newTierstringyesNew tier to upgrade to
serialintegeryesNFT serial number
tokenIdstringyesHTS passport token ID

No output schema declared.

No examples provided.

upload_image ~106

Upload an image to IPFS and return an ipfs:// URI. Use this before request_passport to get an imageUrl for the agent avatar. Accepts base64-encoded image data.

NameTypeReqDescription
base64DatastringyesBase64-encoded image data (without data: prefix)
filenamestringyesOriginal filename including extension (e.g. avatar.png)
mimeTypestringyesMIME type of the image (e.g. image/png, image/jpeg)

No output schema declared.

No examples provided.

upload_result ~165

Upload an HTML+JSON report bundle to IPFS via Pinata. Returns { cid, uri } where uri = ipfs://{cid}.

NameTypeReqDescription
agentDidstringyesAgent DID
agentTierstring–Agent passport tier (bronze/silver/gold/platinum)
analysisTypestring–Analysis type
datasetUrnstring–DataHub dataset URN
htmlstringyesHTML report content
ipfsApiKeystring–Pinata API key (or use env IPFS_API_KEY)
ipfsApiSecretstring–Pinata API secret (or use env IPFS_API_SECRET)
jsonstringyesJSON report content
taskIdstringyesTask ID

No output schema declared.

No examples provided.

verify_passport ~50

Verify a passport's on-chain status: active, tier, capabilities, DID, owner.

NameTypeReqDescription
serialintegeryesNFT serial number
tokenIdstringyesHTS passport token ID

No output schema declared.

No examples provided.

verify_result ~66

Run verification on a task without completing it. Triggers the verifier and returns the result. Task must be in delivered or claimed status. Returns { taskId, passed, attempts, shouldReturnToMarket, report }.

NameTypeReqDescription
taskIdstringyesTask ID to run verification on

No output schema declared.

No examples provided.

Common questions

What is the AgentBadge MCP server?

AgentBadge is an MCP server listed in the public MCP registry as io.github.spreadzp/agentbadge. AgentBadge MCP, agent-readiness scan, passport, discovery, marketplace and circle-payments tools. This page covers its npm package (@agentbadge/mcp).

What tools does the AgentBadge MCP server expose?

AgentBadge exposes 38 tools: request_passport, upload_image, verify_passport, get_passport, list_passports, and 33 more. Their descriptions and schemas cost roughly 3,458 tokens of context every time the server is loaded.

Is the AgentBadge MCP server still maintained?

AgentBadge is still listed as active in the MCP registry. We last reached this channel on 29 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

What licence is the AgentBadge MCP server under?

AgentBadge declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.