Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

io.github.the402ai/mcp-server

NPM · @THE402/MCP-SERVER · SCANNED OCT 3

AI agent service marketplace — browse, purchase, and manage services via x402/USDC

Available components

−2 this week 79 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →

Supply Chain Security98
  • No malware found by supply-chain analysis.Pass
  • No known CVEs affecting this package version or its production dependencies.Pass
  • No install/post-install scripts declared.Pass
  • 31 of 93 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency39
Schema Quality & AI Usability73
  • AI-judged instruction clarity (good).Pass
  • Tool/resource definitions use about 2560 tokens (~85/item across 30 items; 30 tools + 0 resources), lean.Pass
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management90
  • Stability observed for 27 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Tool Safety75
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • 0 of 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "send_message" implies "send" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
  • An AI judge read all 30 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

How do I install the io.github.the402ai/mcp-server server?

io.github.the402ai/mcp-server runs locally as an npm package, launched with npx -y @the402/mcp-server. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

npm · @the402/mcp-server

# add to Claude Code
claude mcp add the402ai-mcp-server -- npx -y @the402/mcp-server
// .cursor/mcp.json
{
  "mcpServers": {
    "the402ai-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@the402/mcp-server"
      ]
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "the402ai-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@the402/mcp-server"
      ]
    }
  }
}
# add to Codex CLI
codex mcp add the402ai-mcp-server -- npx -y @the402/mcp-server
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "the402ai-mcp-server": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@the402/mcp-server"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add the402ai-mcp-server --command npx --arg -y --arg @the402/mcp-server
# ~/.hermes/config.yaml
mcp_servers:
  the402ai-mcp-server:
    command: "npx"
    args: ["-y", "@the402/mcp-server"]
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "the402ai-mcp-server": {
      "Transport": "stdio",
      "Command": "npx",
      "Arguments": [
        "-y",
        "@the402/mcp-server"
      ]
    }
  }
}
# add to Vellum
assistant mcp add the402ai-mcp-server -t stdio -c npx -a -y @the402/mcp-server
// mcp.json
{
  "mcpServers": {
    "the402ai-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@the402/mcp-server"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 2 Oct 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.

  • 30 Sept 26 −3
    • Stability: pass → 0.80 functional
  • 29 Sept 26 +1
    • Stability: 0.97 → pass security
  • 28 Sept 26 −1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 26 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.

  • 25 Sept 26 0
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 24 Sept 26 −2
    • Stability: pass → 0.83 functional
  • 23 Sept 26 0
    • Stability: 0.97 → pass security
    • Security disclosure: unverified → fail ▼ functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 3 Oct 2026 · Analysed npm/@the402/mcp-server@1.0.1

Provenance No attestation

The registry publishes no build provenance for this version, so there is nothing to verify.

Result No attestation
Ecosystem npm

Background: How many MCP packages publish verified provenance →

Dependencies 93 packages
Packages resolved 93
Stale 31
Tree resolution Complete

Background: SBOMs and build attestations, explained →

MCP tools · 30 exposed · ~2,560 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
accept_proposal ~63

Agent accepts a provider's price proposal and pays from pre-funded balance. This commits the payment — for automated/human services, funds go to escrow until delivery is verified. Requires API key.

NameTypeReqDescription
thread_idstringyesThe thread ID with a pending price proposal

No output schema declared.

No examples provided.

balance_history ~58

View your balance transaction history on the402.ai. Shows deposits, purchases, refunds, and other balance changes. Requires API key.

NameTypeReqDescription
limitnumber–Results per page (default: 20)
offsetnumber–Pagination offset

No output schema declared.

No examples provided.

browse_products ~79

Search the digital product catalog on the402.ai. Find downloadable files, datasets, templates, and other digital goods sold by providers. Supports keyword search. No authentication required.

NameTypeReqDescription
limitnumber–Results per page (default: 20)
offsetnumber–Pagination offset
querystring–Search keywords (full-text search)

No output schema declared.

No examples provided.

check_balance ~43

Check your pre-funded USDC balance on the402.ai. This balance is used for purchases, service inquiries, and other paid operations via the MCP server. Requires API key.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

create_plan ~112

Create a subscription plan as a provider on the402.ai. Bundle one or more of your services at a recurring price. Agents can subscribe for monthly or annual access. Requires API key (provider account).

NameTypeReqDescription
billing_periodstringyesBilling frequency
descriptionstringyesWhat the plan includes
namestringyesPlan name
pricestringyesRecurring price in USD (e.g., '9.99')
service_idsarrayyesService IDs included in this plan

No output schema declared.

No examples provided.

create_service ~279

List a new service on the the402.ai marketplace as a provider. Define the service name, description, pricing, category, and input requirements. Your service will be discoverable by AI agents worldwide. Requires API key (provider account).

NameTypeReqDescription
categorystringyesService category (e.g., 'data', 'development', 'content', 'security')
descriptionstringyesDetailed description of what the service does, who it's for, and what agents will receive
estimated_deliverystring–Estimated delivery time (e.g., '< 1 minute', '24 hours', '3-5 days')
fulfillment_typestring–How the service is fulfilled
input_schemaobject–JSON Schema defining required input fields agents must provide when purchasing
namestringyesService name (clear, descriptive, max 100 chars)
pricestringyesPrice in USD (e.g., '0.50', '25.00')
pricing_modelstring–fixed = set price, quote_required = negotiate per request (default: fixed)
service_typestring–data_api = instant, automated_service = async processing, human_service = expert work
tagsarray–Tags for discoverability
webhook_urlstring–URL to receive webhook notifications for new orders

No output schema declared.

No examples provided.

decline_thread ~72

Cancel or decline a thread on the402.ai. Either the agent or provider can use this. If payment was made and work hasn't started, a refund may be issued. Requires API key.

NameTypeReqDescription
reasonstring–Optional reason for declining
thread_idstringyesThe thread ID to decline/cancel

No output schema declared.

No examples provided.

delete_service ~56

Remove a service listing from the402.ai marketplace. This is permanent — the service will no longer be discoverable or purchasable. Requires API key (service owner only).

NameTypeReqDescription
service_idstringyesThe service ID to delete

No output schema declared.

No examples provided.

get_participant ~52

View a participant's public profile on the402.ai. Shows name, description, role, and when they joined. No authentication required.

NameTypeReqDescription
participant_idstringyesParticipant ID (wallet address or participant ID)

No output schema declared.

No examples provided.

get_platform_info ~43

Get the402.ai platform health, status, available endpoints, and referral program details. Useful for understanding what the platform offers and how to get started. No authentication required.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

get_service ~66

Get full details for a specific service on the402.ai by its ID. Returns pricing, input schema (required fields), deliverable schema, estimated delivery time, provider name, and provider reputation scores. No authentication required.

NameTypeReqDescription
service_idstringyesThe service ID to look up

No output schema declared.

No examples provided.

get_thread ~58

Get full details and message history for a specific thread on the402.ai. Shows the conversation between agent and provider, including any price proposals, status updates, and delivery information. Requires API key.

NameTypeReqDescription
thread_idstringyesThe thread ID

No output schema declared.

No examples provided.

inquire_service ~95

Open a conversation thread about a service on the402.ai. Costs $0.001 from your pre-funded balance. Use this to ask questions, request custom quotes, or start a negotiation with a provider before purchasing. Requires API key.

NameTypeReqDescription
briefstringyesYour message to the provider — describe what you need, ask questions, or request a custom quote
service_idstringyesThe service ID to inquire about

No output schema declared.

No examples provided.

list_plans ~74

Browse subscription plans on the402.ai. Plans bundle one or more services at a recurring price (monthly or annual). Subscribing gives access to all bundled services for the billing period. No authentication required.

NameTypeReqDescription
limitnumber–Results per page (default: 20)
offsetnumber–Pagination offset

No output schema declared.

No examples provided.

list_purchases ~31

List your purchased digital products on the402.ai. Shows products you've bought with download status. Requires API key.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

list_threads ~84

List your conversation threads on the402.ai. Shows threads where you are the agent (buyer) or provider (seller). Filter by status to find active, completed, or disputed threads. Requires API key.

NameTypeReqDescription
limitnumber–Results per page (default: 20)
offsetnumber–Pagination offset
statusstring–Filter by thread status

No output schema declared.

No examples provided.

manage_plan ~102

Update or delete a subscription plan on the402.ai. Only the provider who created the plan can modify it. Requires API key (plan owner).

NameTypeReqDescription
actionstringyesupdate = modify plan details, delete = remove plan
descriptionstring–New description (for update)
namestring–New plan name (for update)
plan_idstringyesThe plan ID
pricestring–New price (for update)

No output schema declared.

No examples provided.

manage_product ~132

Create, update, or delete a digital product on the402.ai as a provider. Products are one-time purchasable digital goods (files, datasets, templates). Requires API key (provider account).

NameTypeReqDescription
actionstringyescreate = new product, update = modify existing, delete = remove
categorystring–Product category
descriptionstring–Product description (required for create)
namestring–Product name (required for create)
pricestring–Price in USD (required for create)
product_idstring–Product ID (required for update/delete)

No output schema declared.

No examples provided.

manage_subscription ~91

Manage your subscription on the402.ai — cancel, pause auto-renewal, or resume a paused subscription. Cancelling still gives access until the current period ends. Requires API key.

NameTypeReqDescription
actionstringyescancel = end at period end, pause = stop auto-renewal, resume = restart auto-renewal, details = view subscription info
subscription_idstringyesThe subscription ID

No output schema declared.

No examples provided.

propose_price ~105

Provider proposes a price for a thread on the402.ai. After discussing requirements with the agent, use this to set a price. The agent can then accept and pay, or continue negotiating. Free — provider action only. Requires API key.

NameTypeReqDescription
messagestring–Optional message explaining the price or scope
pricestringyesProposed price in USD (e.g., '5.00', '25.50')
thread_idstringyesThe thread ID

No output schema declared.

No examples provided.

provider_earnings ~42

View your provider earnings breakdown on the402.ai. Shows settled (paid out), held (in escrow), and pending amounts. Requires API key (provider account).

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

purchase_product ~58

Purchase a digital product on the402.ai. Payment is deducted from your pre-funded balance. After purchase, use list_purchases to find the product and download it. Requires API key.

NameTypeReqDescription
product_idstringyesThe product ID to purchase

No output schema declared.

No examples provided.

purchase_service ~100

Purchase a fixed-price service on the402.ai. Creates an async job and conversation thread. Payment is deducted from your pre-funded balance. For data_api services, results are returned immediately. For automated/human services, the provider fulfills the work asynchronously. Requires API key.

NameTypeReqDescription
briefstringyesDescription of what you need — must include all required fields defined in the service's input_schema
service_idstringyesThe service ID to purchase

No output schema declared.

No examples provided.

referrals ~105

Manage your referral program on the402.ai. Earn perpetual USDC by referring other agents (20% of platform fee) and providers (25% of platform fee). Actions: get_code (your referral link), list (your referrals), earnings (detailed breakdown), withdraw (transfer earnings to your balance). Requires API key.

NameTypeReqDescription
actionstringyesget_code = get your referral code/link, list = see who you referred, earnings = detailed breakdown, withdraw = transfer to balance

No output schema declared.

No examples provided.

search_catalog ~161

Search the the402.ai service marketplace. Find AI agent services by keyword, category, service type, or price range. Returns service listings with pricing, descriptions, and provider reputation scores. No authentication required.

NameTypeReqDescription
categorystring–Filter by category
limitnumber–Results per page (default: 20, max: 100)
min_reputationnumber–Minimum provider reputation score (0-100)
offsetnumber–Pagination offset
querystring–Search keywords (full-text search with BM25 ranking)
service_typestring–Filter by type: data_api (instant), automated_service (async), human_service (expert)
sortstring–Sort order (default: relevance)

No output schema declared.

No examples provided.

send_message ~73

Send a message in a thread on the402.ai. Works for both agents and providers. Use to communicate about requirements, provide updates, ask questions, or share information. Free — no balance deduction. Requires API key.

NameTypeReqDescription
messagestringyesYour message content
thread_idstringyesThe thread ID

No output schema declared.

No examples provided.

subscribe_to_plan ~67

Subscribe to a plan on the402.ai. Pays the first billing period from your pre-funded balance. Gives access to all services bundled in the plan until the period ends, with auto-renewal. Requires API key.

NameTypeReqDescription
plan_idstringyesThe plan ID to subscribe to

No output schema declared.

No examples provided.

update_profile ~64

Update your participant profile on the402.ai. Change your display name, description, or other profile fields. Requires API key.

NameTypeReqDescription
descriptionstring–New profile description
namestring–New display name
participant_idstringyesYour participant ID

No output schema declared.

No examples provided.

update_service ~139

Update an existing service listing on the402.ai. Change price, description, status (active/inactive), or any other field. Requires API key (service owner only).

NameTypeReqDescription
descriptionstring–New description
estimated_deliverystring–New estimated delivery time
input_schemaobject–New input schema
namestring–New service name
pricestring–New price in USD
service_idstringyesThe service ID to update
statusstring–Set active or inactive
tagsarray–New tags
webhook_urlstring–New webhook URL

No output schema declared.

No examples provided.

verify_delivery ~56

Agent confirms that delivery is satisfactory and releases the escrow payment to the provider. Costs $0.001 from balance. Only use after reviewing the delivered work. Requires API key.

NameTypeReqDescription
thread_idstringyesThe thread ID to verify

No output schema declared.

No examples provided.

Common questions

What is the io.github.the402ai/mcp-server server?

io.github.the402ai/mcp-server is listed in the public MCP registry as io.github.the402ai/mcp-server. AI agent service marketplace, browse, purchase, and manage services via x402/USDC. This page covers its npm package (@the402/mcp-server).

Is the io.github.the402ai/mcp-server server safe to use?

io.github.the402ai/mcp-server scores 79 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 3 October 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the io.github.the402ai/mcp-server server expose?

io.github.the402ai/mcp-server exposes 30 tools: search_catalog, get_service, get_platform_info, inquire_service, list_threads, and 25 more. Their descriptions and schemas cost roughly 2,560 tokens of context every time the server is loaded.

Is the io.github.the402ai/mcp-server server still maintained?

io.github.the402ai/mcp-server is still listed as active in the MCP registry. We last reached this channel on 3 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

What licence is the io.github.the402ai/mcp-server server under?

io.github.the402ai/mcp-server declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.