# Settled (remote · settled.tools)

Check x402 endpoints before your agent pays: payTo, paid test purchases, payee and buyer reports

- Trust score: 76/100 (medium)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-08

## Components

- remote · `settled.tools`: 76/100 (this document), [markdown](https://verifymcp.io/servers/tools-settled-settled/settled.md), [page](https://verifymcp.io/servers/tools-settled-settled/settled)
- npm · `settled-x402`: 34/100, [markdown](https://verifymcp.io/servers/tools-settled-settled/settled-x402.md), [page](https://verifymcp.io/servers/tools-settled-settled/settled-x402)

## Channel facts

- Endpoint: `https://settled.tools/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `0.2.1`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-08.

- **Endpoint Security**: 80/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one.
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 73/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 3415 tokens (~189/item across 18 items; 18 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 17/100
  - Stability observed for 5 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 18 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 19 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### How do I install the Settled MCP server?

Settled is a hosted endpoint at https://settled.tools/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http tools-settled-settled 'https://settled.tools/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "tools-settled-settled": {
      "url": "https://settled.tools/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "tools-settled-settled": {
      "type": "http",
      "url": "https://settled.tools/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.tools-settled-settled]
url = "https://settled.tools/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "tools-settled-settled": {
      "type": "remote",
      "url": "https://settled.tools/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add tools-settled-settled --url 'https://settled.tools/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  tools-settled-settled:
    url: "https://settled.tools/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "tools-settled-settled": {
      "Transport": "http",
      "Url": "https://settled.tools/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add tools-settled-settled -t streamable-http -u 'https://settled.tools/mcp'
```

### Other

```json
{
  "mcpServers": {
    "tools-settled-settled": {
      "type": "http",
      "url": "https://settled.tools/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-10-08 (score 76, +1)

- [functional] Server version: 0.9.45-discord → 0.9.60-buy

### 2026-10-06 (score 75, +8)

- [security improvement] Authorization: fail → partial
- [security] Tool “settled_events” rewrote its description, which is the text the model reads
- [security] Tool “settled_find_endpoints” rewrote its description, which is the text the model reads
- [security] Tool “settled_income_check” rewrote its description, which is the text the model reads
- [security] Tool “settled_income_listings” rewrote its description, which is the text the model reads
- [security] Tool “settled_income_venues” rewrote its description, which is the text the model reads
- [security] Tool “settled_peek” rewrote its description, which is the text the model reads
- [security] Tool “settled_preflight” rewrote its description, which is the text the model reads
- [security] Tool “settled_report” rewrote its description, which is the text the model reads
- [security] Tool “settled_seller_reputation” rewrote its description, which is the text the model reads
- [security] Tool “settled_sellers” rewrote its description, which is the text the model reads
- [security] Tool “settled_status” rewrote its description, which is the text the model reads
- [security] Tool “settled_submit” rewrote its description, which is the text the model reads
- [security] Tool “settled_verify” rewrote its description, which is the text the model reads
- [security] Tool “settled_watch” rewrote its description, which is the text the model reads
- [security] Tool “settled_watch_alerts” rewrote its description, which is the text the model reads
- [security] Tool “settled_weekly_report” rewrote its description, which is the text the model reads
- [security] Tool “settled_check” rewrote its description, which is the text the model reads
- [security] Tool “settled_claim” rewrote its description, which is the text the model reads
- [security] Tool “settled_claim” no longer declares itself destructive
- [functional regression] Schema quality: 145 → 189
- [functional] Server version: 0.9.21-sellerwatch → 0.9.45-discord
- [cosmetic] “settled_claim” reworded the description of “docs”
- [cosmetic] “settled_claim” reworded the description of “issued_at”
- [cosmetic] “settled_claim” reworded the description of “name”
- [cosmetic] “settled_claim” reworded the description of “signature”
- [cosmetic] “settled_claim” reworded the description of “wallet”
- [cosmetic] “settled_claim” reworded the description of “website”
- [cosmetic] “settled_income_listings” reworded the description of “min_reward”
- [cosmetic] “settled_income_listings” reworded the description of “rail”
- [cosmetic] “settled_income_listings” reworded the description of “venue”
- [cosmetic] “settled_report” reworded the description of “signature”
- [cosmetic] “settled_report” reworded the description of “tx”
- [cosmetic] “settled_seller_reputation” reworded the description of “address”
- [cosmetic] “settled_watch” reworded the description of “url”
- [cosmetic] “settled_watch” reworded the description of “watch_id”
- [cosmetic] “settled_watch” reworded the description of “webhook”
- [cosmetic] “settled_watch_alerts” reworded the description of “watch_id”
- [cosmetic] “settled_find_endpoints” reworded the description of “status”
- [cosmetic] “settled_claim” reworded the description of “contact”

### 2026-10-04 (score 67, +1)

- [functional improvement] Stability: unverified → 0.03
- [functional] Server version: 0.9.20-holds → 0.9.21-sellerwatch

### 2026-10-03 (score 66)

First indexed and scored.

## MCP tools (18)

### `settled_status` (~70 tokens)

Settled index status

Free. Size and freshness of the x402 endpoint index and the on-chain ledger. Use when: you need to know how current Settled’s data is, or what the paid routes cost, before relying on any other tool. Not for: looking up a specific endpoint (use settled_check). No input.

Output parameters:

- `attestation`: EIP-191 signature over the answer; verify it with settled_verify or any EVM library
- `attested_at`: When Settled signed this answer (ISO 8601)
- `by_status`: Endpoint counts by status (live, dead, ...)
- `docs`: Where the docs are
- `endpoints_probed`: How many have been probed
- `endpoints_tracked`: Number of x402 endpoints Settled tracks
- `error`: Present only when the call failed or needs another step: an error code such as pass_required, next to the fields that explain it
- `last_probe_at`: When the latest probe ran
- `live_share_of_probed`: Percentage of probed endpoints that are live
- `mcp`: This MCP server's URL
- `network`: Network Settled's own paid routes settle on (CAIP-2)
- `onchain_ledger`: Coverage of Settled's on-chain settlement ledger
- `prices_usd`: Prices of Settled's paid routes, in USD
- `scout`: Totals for the scout's paid test purchases
- `service`: Always Settled
- `settlement_7d`: USDC settled to tracked sellers in the last 7 days
- `sources`: Discovery sources and how far each import has got
- `total_probes`: Probes run so far
- `version`: Settled's software version

### `settled_peek` (~123 tokens)

Peek at an endpoint

Free, rate-limited. Coarse status and quality score for one x402 endpoint URL, from the index only (no fresh probe). Use when: you only need a quick yes/no on whether Settled knows the URL and its last status. Not for: deciding whether to pay — use settled_check (free, fuller) or settled_preflight (paid, fresh). If the URL is unknown, call settled_submit, then check again later.

Input parameters:

- `url` (string, required): Full URL of the x402 endpoint, e.g. https://api.example.com/search

Output parameters:

- `attestation`: EIP-191 signature over the answer; verify it with settled_verify or any EVM library
- `attested_at`: When Settled signed this answer (ISO 8601)
- `detail`: Where to get the full check
- `error`: Present only when the call failed or needs another step: an error code such as pass_required, next to the fields that explain it
- `last_probe_at`: When Settled last probed it
- `quality`: Quality score 0-100
- `seller_claimed`: Whether the seller has claimed it
- `status`: Endpoint status, e.g. live, degraded, dead, free, auth_gated, not_found or quote_invalid
- `url`: The endpoint

### `settled_submit` (~104 tokens)

Submit an endpoint

Free, rate-limited. Queue an x402 endpoint URL for indexing. Use when: settled_check or settled_peek reports the URL as unknown or not indexed. Not for: URLs already indexed (it just returns their status) or non-x402 URLs. After: wait a few minutes, then call settled_check; the first probe runs within minutes. Idempotent.

Input parameters:

- `url` (string, required): Full URL of an x402 endpoint to add to Settled's index

Output parameters:

- `already_indexed`: true when Settled already tracks it
- `attestation`: EIP-191 signature over the answer; verify it with settled_verify or any EVM library
- `attested_at`: When Settled signed this answer (ISO 8601)
- `error`: Present only when the call failed or needs another step: an error code such as pass_required, next to the fields that explain it
- `hint`: What to call next
- `next_check_at`: When it will next be probed
- `ok`: true when accepted
- `queued`: true when queued for its first probe
- `status`: Its current status, if already indexed

### `settled_report` (~243 tokens)

Report whether a paid call worked

Free. After paying an x402 endpoint on Base, tell Settled whether you got what you paid for. Use when: your agent has just made a real USDC payment and has the transaction hash. Not for: endpoints you did not pay, or payments on other chains. Flow: call without signature to get message_to_sign; sign it with the paying wallet (EIP-191 personal_sign); call again with signature. One report per payment, one vote per wallet per endpoint; Settled keeps only per-endpoint tallies.

Input parameters:

- `ok` (boolean, required): true if the call delivered what you paid for, false if it did not
- `signature` (string): EIP-191 personal_sign of message_to_sign by the wallet that paid (0x + 130 hex characters); omit on the first call to get message_to_sign
- `tx` (string, required): Transaction hash of your USDC payment to that endpoint on Base, from the last 30 days: 0x followed by 64 hex characters, e.g. 0x3f9a...c21e
- `url` (string, required): The x402 endpoint you paid

Output parameters:

- `accepted`: true once the report is recorded
- `attestation`: EIP-191 signature over the answer; verify it with settled_verify or any EVM library
- `attested_at`: When Settled signed this answer (ISO 8601)
- `error`: signature_required when no signature was given (sign message_to_sign and call again), or why the report was refused
- `message_to_sign`: The exact message to sign with the paying wallet
- `ok`: Your verdict, as recorded
- `paid_at`: When your payment was made
- `paid_usd`: What your transaction paid the endpoint, in USD
- `privacy`: What Settled keeps about you
- `reports`: This endpoint's report tallies
- `url`: The endpoint

### `settled_sellers` (~132 tokens)

Claimed sellers

Free. Sellers who proved control of the wallet their x402 endpoints are paid to, with their published profile and endpoint counts. Use when: you want a contact or docs link for a seller, or to see which sellers stand behind their endpoints. Not for: judging an endpoint’s quality (claims never change scores; use settled_check). Paged: limit (max 50) and offset, with a total.

Input parameters:

- `limit` (integer): How many sellers to return, 1-50 (default 25)
- `offset` (integer): How many sellers to skip, for paging (default 0)

Output parameters:

- `attestation`: EIP-191 signature over the answer; verify it with settled_verify or any EVM library
- `attested_at`: When Settled signed this answer (ISO 8601)
- `error`: Present only when the call failed or needs another step: an error code such as pass_required, next to the fields that explain it
- `generated_at`: When this list was built
- `limit`: Page size used
- `note`: What a claim proves
- `offset`: Offset used
- `sellers`: Claimed sellers with their profile and endpoint counts
- `total`: Total claimed sellers

### `settled_claim` (~333 tokens)

Claim your endpoints (sellers)

Free. For sellers: claim every x402 endpoint paid to your wallet with one signature, on every host, so your name, website, contact and docs show next to them (plus a 10-day Seller Watch trial). Use when: you operate x402 endpoints. Not for: buyers or third parties; only the payTo wallet can sign. Flow: call with wallet and profile to get message_to_sign and issued_at; sign with that wallet; call again with issued_at and signature. action=remove withdraws a claim (reversible by claiming again). Claims never change scores.

Input parameters:

- `action` (string): claim (default) or remove to withdraw an existing claim
- `contact` (string): How buyers can reach you, e.g. hello@example.com or @handle on X
- `docs` (string): Your API documentation, as a full https URL
- `issued_at` (string): The issued_at timestamp returned by the first call; send it back unchanged with the signature
- `name` (string): Seller name to show on your endpoints, up to 80 characters, e.g. Acme Data
- `signature` (string): Signature of message_to_sign by the wallet: EIP-191 personal_sign (0x hex) on Base, ed25519 (base58) on Solana; omit on the first call
- `wallet` (string, required): The payTo wallet your endpoints are paid to: 0x + 40 hex characters on Base, or a base58 address on Solana
- `website` (string): Your website, as a full https URL

Output parameters:

- `attestation`: EIP-191 signature over the answer; verify it with settled_verify or any EVM library
- `attested_at`: When Settled signed this answer (ISO 8601)
- `claimed`: true once the claim is recorded
- `covers`: The endpoints and hosts the claim covers
- `error`: signature_required on the first call (sign message_to_sign and call again), or why the claim was refused
- `issued_at`: Timestamp to send back with the signature
- `message_to_sign`: The exact message to sign with the wallet
- `network`: The wallet's network
- `note`: What the claim does
- `profile`: The published profile: name, website, contact, docs
- `removed`: true once a claim is withdrawn
- `wallet`: The wallet
- `would_cover`: The endpoints and hosts the claim would cover

### `settled_preflight` (~209 tokens)

Pre-spend check (pay / caution / avoid)

Pass required. The call to make right before paying an unfamiliar x402 endpoint: a fresh probe, parsed quote, payability, payTo on-chain history, seller integrity, the scout’s real-payment delivery result and a honeypot scan, as one signed answer with a recommendation (pay, caution or avoid) and reasons. Use when: real money is about to leave your wallet and settled_check was stale or not enough. Not for: browsing (settled_find_endpoints) or endpoints you already verified. After: compare pay_to and price with the 402 you receive, pay, then call settled_report.

Input parameters:

- `force` (boolean): true to probe the endpoint now instead of reusing a result up to 5 minutes old
- `pass` (string): Settled day pass token, if you did not send it as the x-settled-pass header
- `url` (string, required): Full URL of the x402 endpoint, e.g. https://api.example.com/search

Output parameters:

- `attestation`: EIP-191 signature over the answer; verify it with settled_verify or any EVM library
- `attested_at`: When Settled signed this answer (ISO 8601)
- `cached`: Whether the probe came from Settled's 5-minute cache
- `checked_at`: When this check ran
- `delivery`: The scout's last real purchase and whether it matched the listing
- `description`: The listing's description
- `error`: Present only when the call failed or needs another step: an error code such as pass_required, next to the fields that explain it
- `flags`: Risk flags
- `honeypot`: Honeypot scan of the listing text
- `liveness`: Fresh probe results
- `onchain`: Settlements and unique payers over the last 30 days
- `payability`: Payability verdict and the verb that pays
- `payee`: Whether the payTo exists on-chain, and the seller's other endpoints and settlement integrity
- `quality`: Quality score breakdown
- `quote`: The parsed 402 quote Settled sees: network, asset, price_usd, pay_to
- `reasons`: Why, in plain words
- `recommendation`: pay, caution or avoid
- `reports`: Paying agents' reports
- `seller_claim`: The seller's claim and profile, if claimed
- `url`: The endpoint

### `settled_check` (~219 tokens)

Check an x402 endpoint

Free up to 300 calls/day per client (a pass lifts the cap). Check an x402 endpoint before paying it, from Settled’s index (cached up to 5 min): status, payability, latency, parsed price/network/payTo, payee on-chain history, the scout’s last real purchase, paying agents’ reports, seller claim, quality breakdown and risk flags. Use when: deciding whether to call an endpoint, and for routine re-checks. Not for: a fresh probe right now (settled_preflight) or searching (settled_find_endpoints). If status is unknown, call settled_submit; after paying, call settled_report.

Input parameters:

- `force` (boolean): true to probe now instead of using the 5-minute cache; needs a pass
- `pass` (string): Settled day pass token: lifts the free daily cap; or send it as the x-settled-pass header
- `url` (string, required): Full URL of the x402 endpoint, e.g. https://api.example.com/search

Output parameters:

- `asset`: Asset of the cheapest option
- `attestation`: EIP-191 signature over the answer; verify it with settled_verify or any EVM library
- `attested_at`: When Settled signed this answer (ISO 8601)
- `cached`: Whether this came from Settled's 5-minute cache
- `checked_at`: When this answer was built
- `delivery_receipt`: The scout's last purchase, with its settlement transaction and checks (when the scout has bought it)
- `delivery_verified`: Whether a real payment by Settled's scout came back with content
- `description`: The listing's description
- `error`: Present only when the call failed or needs another step: an error code such as pass_required, next to the fields that explain it
- `first_seen`: When Settled first saw it
- `flags`: Risk flags
- `http_status_last`: HTTP status of the latest probe
- `last_delivery_at`: When the scout last bought it
- `last_ok_at`: When it last answered with a valid quote
- `last_probe_at`: When Settled last probed it
- `latency_ms`: Latency of the latest probe
- `network`: Network of the cheapest option (CAIP-2)
- `network_name`: Readable network name
- `onchain`: Settlements and unique payers over the last 30 days
- `pay_to`: The payTo Settled's probe sees; compare it with the quote you are about to pay
- `payability`: Payability verdict and the verb that pays
- `payee`: Whether the payTo has on-chain history
- `price_usd`: Price per call in USD (cheapest option)
- `quality`: Quality score breakdown
- `reports`: Paying agents' reports
- `scheme`: Payment scheme, e.g. exact
- `seller_claim`: The seller's claim and profile, if claimed
- `service_name`: The listing's service name
- `status`: Endpoint status, e.g. live, degraded, dead, free, auth_gated, not_found or quote_invalid
- `url`: The endpoint
- `x402_version`: x402 version of the quote

### `settled_find_endpoints` (~287 tokens)

Find live x402 endpoints

Free up to 300 calls/day per client (a pass lifts the cap). Ranked live endpoints by keyword, network and max price (sort by quality, price, latency or payers), each with payability and delivery verification. Use when: you need an x402 endpoint for a capability and want candidates that are live, payable and, where possible, proven to deliver. Not for: verifying one known URL (settled_check). After: run settled_check or settled_preflight on the one you pick before paying.

Input parameters:

- `limit` (integer): How many endpoints to return, 1-50 (default 20)
- `max_price` (number): Highest price per call in USD, e.g. 0.01
- `network` (string): Only endpoints on this network, as a CAIP-2 id, e.g. eip155:8453 for Base
- `pass` (string): Settled day pass token: lifts the free daily cap; or send it as the x-settled-pass header
- `q` (string): Keywords to match in endpoint names, descriptions and URLs, e.g. weather or gift cards
- `sort` (string): Order of results: quality (default), price, latency or payers
- `status` (string): Only endpoints with this status; live (default) or any for every status

Output parameters:

- `attestation`: EIP-191 signature over the answer; verify it with settled_verify or any EVM library
- `attested_at`: When Settled signed this answer (ISO 8601)
- `count`: Number of endpoints returned
- `error`: Present only when the call failed or needs another step: an error code such as pass_required, next to the fields that explain it
- `filters`: The filters applied
- `generated_at`: When this list was built
- `items`: Ranked endpoints, each with payability and delivery status

### `settled_seller_reputation` (~161 tokens)

Seller reputation by payTo address

Pass required. Everything Settled knows about one payTo address: the endpoints it is paid for, live/dead counts, price range, clone-farm and quote-only flags, on-chain settlements and unique payers. Use when: several endpoints share a seller and you want to judge the seller rather than one URL, or a payTo looks unfamiliar. Not for: a single endpoint’s status (settled_check). Input is the wallet address from a 402 quote.

Input parameters:

- `address` (string, required): The payTo address from a 402 quote: 0x followed by 40 hex characters (Base)
- `pass` (string): Settled day pass token, if you did not send it as the x-settled-pass header

Output parameters:

- `address`: The payTo address
- `attestation`: EIP-191 signature over the answer; verify it with settled_verify or any EVM library
- `attested_at`: When Settled signed this answer (ISO 8601)
- `claim`: The seller's claim and profile, if claimed
- `dead`: How many are dead
- `endpoints`: Endpoints paid to it
- `error`: Present only when the call failed or needs another step: an error code such as pass_required, next to the fields that explain it
- `first_seen`: When Settled first saw one
- `flags`: Seller flags such as clone_farm or quote_only
- `generated_at`: When this answer was built
- `hosts`: Hosts serving them
- `live`: How many are live
- `onchain`: On-chain settlements and unique payers
- `price_range_usd`: Lowest and highest price
- `settlement_integrity`: Whether paid activity looks organic or self-generated
- `top_endpoints`: Its main endpoints

### `settled_income_venues` (~134 tokens)

Which venues actually pay agents

Free. Scorecard of bounty boards, task markets, audit contests and the x402 sell-side: verdict (paying / paying small / measuring / no payouts seen / unmeasured / closed to agents / defunct), agent policy, gating (KYC, human claim, self-custody wallet), open listings and on-chain payouts. Use when: choosing where an agent should look for paid work, or checking whether a venue actually pays. Not for: individual listings (settled_income_listings) or x402 endpoints (settled_find_endpoints). Poll settled_events for changes instead of re-reading this.

Output parameters:

- `attestation`: EIP-191 signature over the answer; verify it with settled_verify or any EVM library
- `attested_at`: When Settled signed this answer (ISO 8601)
- `count`: Number of venues
- `error`: Present only when the call failed or needs another step: an error code such as pass_required, next to the fields that explain it
- `generated_at`: When this list was built
- `venues`: Each venue with its verdict, agent policy, gating, open listings and on-chain payouts
- `verdict_vocabulary`: The possible verdicts

### `settled_income_listings` (~306 tokens)

Verified agent-income listings

Pass required. Open bounties and tasks an agent can actually work on, from sanctioned venue APIs, each with reward, agent-access policy, gating, honeypot scan flags with reasons, a trust score and the venue’s on-chain payout record. Use when: an agent is looking for work it is allowed to do. Not for: venue-level questions (settled_income_venues). Suspected honeypots, dead and human-only listings are excluded unless include_honeypots is true. Before working one, run settled_income_check on its URL.

Input parameters:

- `agent_access` (string): allowed (default) for listings agents may take, or any to include human-only ones
- `include_honeypots` (boolean): true to include suspected honeypots and dead listings
- `limit` (integer): How many listings to return, 1-50 (default 20)
- `min_reward` (number): Smallest reward to include, in USD, e.g. 50
- `pass` (string): Settled day pass token, if you did not send it as the x-settled-pass header
- `rail` (string): Only listings paid on this rail, e.g. usdc-base
- `sort` (string): Order of results: trust (default), reward or recent
- `venue` (string): Only listings from this venue, by its slug from settled_income_venues, e.g. superteam-earn

Output parameters:

- `attestation`: EIP-191 signature over the answer; verify it with settled_verify or any EVM library
- `attested_at`: When Settled signed this answer (ISO 8601)
- `count`: Number of listings returned
- `error`: Present only when the call failed or needs another step: an error code such as pass_required, next to the fields that explain it
- `filters`: The filters applied
- `generated_at`: When this list was built
- `items`: Open bounties and tasks with reward, agent access, gating, honeypot flags, trust score and the venue's payout record
- `label_vocabulary`: The possible listing labels

### `settled_income_check` (~169 tokens)

Honeypot / trust scan of one listing

Pass required. Fetches a bounty issue, repository or listing page and scans it for patterns used to bait agents (hidden HTML-comment instructions, prompt injection, credential requests, fork/star anomalies, dead or archived repos, reward anomalies). Returns trust, label and every flag with its reason. Use when: about to work on an unfamiliar bounty or task, especially one not in settled_income_listings. Not for: x402 API endpoints (settled_check). Treat a suspected_honeypot label as do-not-work; a clean result is not a promise of payment.

Input parameters:

- `pass` (string): Settled day pass token, if you did not send it as the x-settled-pass header
- `url` (string, required): URL of the bounty issue, repository or listing page to scan

Output parameters:

- `attestation`: EIP-191 signature over the answer; verify it with settled_verify or any EVM library
- `attested_at`: When Settled signed this answer (ISO 8601)
- `error`: Present only when the call failed or needs another step: an error code such as pass_required, next to the fields that explain it
- `flags`: Every flag found, with its reason
- `indexed`: Settled's listing for this URL, if it has one
- `label`: verified_paying, unverified, gated, suspected_honeypot, dead or closed_to_agents
- `note`: How to read the result
- `repo`: Repository facts, for GitHub links
- `scanned_at`: When the scan ran
- `source`: What was scanned, e.g. page_text
- `trust`: Trust score 0-100
- `url`: The page scanned

### `settled_events` (~148 tokens)

Change feed

Free up to 300 calls/day per client. Recent changes worth acting on: venue verdict flips, new suspected honeypots, settlement-integrity changes, newest first. Use when: your agent runs on a schedule and wants to react to what changed since last time. Not for: the full picture (settled_income_venues) or endpoint-level changes (settled_watch). Poll this instead of re-reading the scorecard.

Input parameters:

- `limit` (integer): How many events to return, newest first, 1-200 (default 50)
- `pass` (string): Settled day pass token: lifts the free daily cap; or send it as the x-settled-pass header

Output parameters:

- `attestation`: EIP-191 signature over the answer; verify it with settled_verify or any EVM library
- `attested_at`: When Settled signed this answer (ISO 8601)
- `count`: Number of events returned
- `error`: Present only when the call failed or needs another step: an error code such as pass_required, next to the fields that explain it
- `events`: Changes newest first: venue verdict flips, new suspected honeypots, settlement-integrity changes
- `generated_at`: When this list was built

### `settled_watch` (~223 tokens)

Buy a Watchdog for an x402 endpoint

Paid: $1.00 USDC on Base over x402 inside MCP (the first call returns the payment requirements; @x402/mcp clients pay automatically). Buys 10 days of monitoring for one x402 endpoint: probed about every 15 minutes, with a signed alert whenever status, payability, price or payTo changes. Use when: your agent depends on one endpoint and must learn quickly if it changes. Not for: one-off checks (settled_check). Give url to start or watch_id to renew; give webhook to have alerts POSTed, else read them with settled_watch_alerts. Returns watch_id.

Input parameters:

- `url` (string): The x402 endpoint to watch, e.g. https://api.example.com/search; required unless watch_id is given
- `watch_id` (string): The watch_id of an existing watch to renew for 10 more days; give this or url, not both
- `webhook` (string): https URL that receives each alert as a signed POST; omit to poll with settled_watch_alerts

Output parameters:

- `accepts`: Present when payment is needed: the x402 payment requirements; pay one and call again with the payment in _meta
- `alert_format`: What an alert contains
- `alerts`: URL of the alerts feed
- `attestation`: EIP-191 signature over the answer; verify it with settled_verify or any EVM library
- `attested_at`: When Settled signed this answer (ISO 8601)
- `baseline`: The endpoint's state when the watch started
- `created_at`: When the watch started
- `delivery`: webhook or poll
- `error`: Present only when the call failed or needs another step: an error code such as pass_required, next to the fields that explain it
- `expires_at`: When it ends unless renewed
- `manage`: URL of the watch
- `note`: What happens next
- `renewed`: true when this call renewed an existing watch
- `status`: active or expired
- `url`: The watched endpoint
- `watch_id`: The watch's id: keep it to read alerts and to renew
- `webhook_host`: Host the alerts are POSTed to, if a webhook was given
- `x402Version`: Present when payment is needed: the x402 version of the requirements

### `settled_watch_alerts` (~172 tokens)

Read a Watchdog's alerts

Free. Everything a Watchdog has recorded for its endpoint since a given alert id: each change to status, payability, price or payTo, the endpoint’s state now, and next_since to pass on the next call. Use when: you created a watch with settled_watch and did not give a webhook. Not for: endpoints without a watch (use settled_check). Poll it whenever your agent runs; the endpoint is probed about every 15 minutes.

Input parameters:

- `limit` (integer): Most alerts to return, 1-100 (default 50)
- `since` (integer): Return alerts with an id above this; pass next_since from your last call, or 0 for all
- `watch_id` (string, required): The watch_id returned by settled_watch when the Watchdog was bought

Output parameters:

- `alerts`: Alerts since the given id, oldest first: each change to status, payability, price or payTo
- `attestation`: EIP-191 signature over the answer; verify it with settled_verify or any EVM library
- `attested_at`: When Settled signed this answer (ISO 8601)
- `delivery`: webhook or poll
- `endpoint_now`: The endpoint's state now: status, payability, price, payTo, last probe
- `error`: Present only when the call failed or needs another step: an error code such as pass_required, next to the fields that explain it
- `expires_at`: When the watch ends unless renewed
- `how`: How to poll
- `more`: true when more alerts are waiting
- `next_since`: Pass this as since on your next call
- `status`: active or expired
- `url`: The watched endpoint
- `watch_id`: The watch

### `settled_weekly_report` (~92 tokens)

Weekly Agent Income Report

Free. The latest published Agent Income Report as JSON: which venues paid agents on-chain, worker wallets, honeypots flagged, x402 index health. Use when: you want the week’s summary, for a digest or a decision about where to look for work. Not for: live numbers (settled_status, settled_income_venues). Published Mondays; the window and ledger coverage are in the body.

Output parameters:

- `attestation`: EIP-191 signature over the answer; verify it with settled_verify or any EVM library
- `attested_at`: When Settled signed this answer (ISO 8601)
- `endpoints`: x402 index health
- `error`: Present only when the call failed or needs another step: an error code such as pass_required, next to the fields that explain it
- `generated_at`: When it was built
- `key`: The report's key, e.g. weekly:2026-W40
- `kind`: Always weekly
- `links`: Where the report is published
- `listings`: Listings and honeypots
- `settlements`: On-chain settlement totals
- `venues`: Venues that paid agents on-chain
- `week`: ISO week of the report
- `window`: The 7 days covered

### `settled_verify` (~112 tokens)

Verify a signed Settled response

Free. Pass any signed Settled response (attestation included) to recompute its hash and recover the signer; tells you whether it is authentic and unaltered. Use when: a Settled answer reached you through a third party, a cache or a log and you need to trust it. Not for: answers you just received directly over this server (already signed and fresh). Use the full response object, unchanged.

Input parameters:

- `document` (object, required): A complete signed Settled answer, including its attestation block

Output parameters:

- `attested_at`: When the document was signed
- `hash`: Hash recomputed from the document
- `hash_matches`: Whether it matches the signed hash
- `reason`: Why it is not valid
- `signer_matches`: Whether the two addresses match
- `signer_published`: Settled's published signing address
- `signer_recovered`: Address recovered from the signature
- `valid`: true when the hash matches and the signer is Settled's published key

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/tools-settled-settled/settled#diagnostics

## Score history

- 2026-10-08: 76
- 2026-10-06: 75
- 2026-10-04: 67
- 2026-10-03: 66

## Common questions

### What is the Settled MCP server?

Settled is an MCP server listed in the public MCP registry as tools.settled/settled. Check x402 endpoints before your agent pays: payTo, paid test purchases, payee and buyer reports. This page covers its hosted endpoint (https://settled.tools/mcp).

### Is the Settled MCP server safe to use?

Settled scores 76 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Settled MCP server expose?

Settled exposes 18 tools: settled_status, settled_peek, settled_submit, settled_report, settled_sellers, and 13 more. Their descriptions and schemas cost roughly 3,237 tokens of context every time the server is loaded.

### Does the Settled MCP server require authentication?

No. We connected to Settled without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the Settled MCP server still maintained?

Settled is still listed as active in the MCP registry. We last reached this channel on 8 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://settled.tools/mcp
- Website: https://settled.tools/for-agents
- Changelog RSS feed: https://verifymcp.io/servers/tools-settled-settled/settled.xml
- Changelog JSON feed: https://verifymcp.io/servers/tools-settled-settled/settled.json
- HTML version of this page: https://verifymcp.io/servers/tools-settled-settled/settled
