Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Agent Utility Suite (x402)

REMOTE · X402-AGENT-API.ONRENDER.COM · SCANNED OCT 9

SEC filings, financials, insider trades; company data; web scraping; OFAC, email; HVAC calcs. x402

70 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security74
Transport & Reachability100
Schema Quality & AI Usability60
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 10114 tokens (~532/item across 19 items; 19 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management10
  • Stability observed for 3 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • We read all 19 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
  • An AI judge read all 20 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

How do I install the Agent Utility Suite (x402) MCP server?

Agent Utility Suite (x402) is a hosted endpoint at https://x402-agent-api.onrender.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · x402-agent-api.onrender.com

# add to Claude Code
claude mcp add --transport http vanakenj45-x402-agent-api 'https://x402-agent-api.onrender.com/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "vanakenj45-x402-agent-api": {
      "url": "https://x402-agent-api.onrender.com/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "vanakenj45-x402-agent-api": {
      "type": "http",
      "url": "https://x402-agent-api.onrender.com/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.vanakenj45-x402-agent-api]
url = "https://x402-agent-api.onrender.com/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "vanakenj45-x402-agent-api": {
      "type": "remote",
      "url": "https://x402-agent-api.onrender.com/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add vanakenj45-x402-agent-api --url 'https://x402-agent-api.onrender.com/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  vanakenj45-x402-agent-api:
    url: "https://x402-agent-api.onrender.com/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "vanakenj45-x402-agent-api": {
      "Transport": "http",
      "Url": "https://x402-agent-api.onrender.com/mcp"
    }
  }
}
# add to Vellum
assistant mcp add vanakenj45-x402-agent-api -t streamable-http -u 'https://x402-agent-api.onrender.com/mcp'
// mcp.json
{
  "mcpServers": {
    "vanakenj45-x402-agent-api": {
      "type": "http",
      "url": "https://x402-agent-api.onrender.com/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 9 Oct 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 3 to 10. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.

  • 7 Oct 26 69

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 9 Oct 2026 · Probed https://x402-agent-api.onrender.com/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=onrender.com CN=WE1,O=Google Trust Services,C=US 21 Sept 2026 20 Dec 2026 ECDSA 256 ECDSA-SHA256 6eb1e3fe7d0631ea1337bfa4a321c137
SANs: onrender.com, *.onrender.com
CN=WE1,O=Google Trust Services,C=US (CA) CN=GTS Root R4,O=Google Trust Services LLC,C=US 13 Dec 2023 20 Feb 2029 ECDSA 256 ECDSA-SHA384 7ff31977972c224a76155d13b6d685e3
CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE 15 Nov 2023 28 Jan 2028 ECDSA 384 SHA256-RSA 7fe530bf331343bedd821610493d8a1b

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of x402-agent-api.onrender.com. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
onrender.com. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200
Header Value
x-content-type-options nosniff
referrer-policy no-referrer

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://x402-agent-api.onrender.com/mcp Verified 200
http (plaintext) http://x402-agent-api.onrender.com/mcp HTTPS enforced 301 https://x402-agent-api.onrender.com/mcp
MCP tools · 19 exposed · ~9,206 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
company_profile ~424

Answers "Who is behind stripe.com?", "What does this company do, where is it based and who runs it?" or "Is it public, and what is its ticker?". Give a website domain (or any URL), a company name, a ticker or a CIK. Returns one profile combining: SEC EDGAR for public companies (legal name, tickers, exchanges, CIK, SIC industry, state of incorporation, fiscal year end, business address, phone, filer category, former names), Wikidata (founded, founders, CEO, headquarters, country, employees with date, industries, official website), a short Wikipedia description (with its URL for attribution), and the domain's email provider (from MX records) and registration date and registrar (RDAP). Works for private companies too (Wikidata and the domain). `sources` says which sources answered. For public companies, next_calls lead to their financials, 8-K events and insider trades. A name matching several SEC registrants returns the candidates, free; no company found is a 404, free. You are only charged when a result is returned: invalid input (400) and upstream failures (4xx/5xx) are not settled. Costs $0.01 USDC per call via x402. Paid per call with x402 inside MCP (see the server instructions).

NameTypeReqDescription
cik––SEC Central Index Key, e.g. 320193. Use this, `ticker` or `company`.
companystring–Company name, e.g. "Apple" or "Coca-Cola". Use this, `ticker` or `cik`; a name matching several companies returns their tickers, free.
domainstring–The company's website domain or any URL on it, e.g. "stripe.com". Use this, `company`, `ticker` or `cik`.
tickerstring–US stock ticker, e.g. AAPL, MSFT, BRK-B. Use this, `cik` or `company`.

No output schema declared.

No examples provided.

domain_enrich ~221

Answers "Who hosts this company's email, and is it configured properly?" and "Which SaaS tools does this company use?". Profiles a domain from live DNS and its website: MX records and the inferred email provider (Google Workspace, Microsoft 365, …), SPF and DMARC configuration and policy, services the domain has verified ownership with (from TXT records: Google, Microsoft, Stripe, Atlassian, …), whether the website is reachable over HTTPS, and stack and security headers (Server, X-Powered-By, HSTS, CSP). Use it for lead enrichment, email deliverability checks, vendor due diligence or security reviews. You are only charged when a result is returned: invalid input (400) and upstream failures (4xx/5xx) are not settled. Costs $0.004 USDC per call via x402. Paid per call with x402 inside MCP (see the server instructions).

NameTypeReqDescription
domainstringyesDomain to profile, e.g. example.com. A full URL is accepted; its hostname is used.

No output schema declared.

No examples provided.

economic_indicators ~314

Answers "What is the 10-year Treasury yield?", "Is the yield curve inverted?", "What is inflation now?", "What is the unemployment rate?" and "Where is the fed funds rate?". Returns a snapshot of key US macro indicators from official public-domain sources: the U.S. Treasury's daily par yield curve (1 month to 30 years, 10y-2y spread, inversion), the Bureau of Labor Statistics' CPI and core CPI (year-over-year %), unemployment rate and nonfarm payrolls (level and monthly change), and the New York Fed's effective federal funds rate and target range. Optionally up to 24 months of monthly history. Choose indicators to keep the answer short. Sources are cached (yields and fed funds 1 hour, BLS 12 hours); a source that does not answer is listed in `unavailable`. If none answers, you are not charged. You are only charged when a result is returned: invalid input (400) and upstream failures (4xx/5xx) are not settled. Costs $0.003 USDC per call via x402. Paid per call with x402 inside MCP (see the server instructions).

NameTypeReqDescription
history_monthsinteger–Also return this many months of monthly history (inflation, employment, month-end 10-year and 2-year yields). Default 0.
indicatorsarray–Which to return: treasury_yields, inflation, employment, fed_funds. Default: all four.

No output schema declared.

No examples provided.

email_verify ~317

Answers "Is this email address valid?", "Will mail to it bounce?" and "Is it a throwaway, a shared inbox or a typo?" before an agent sends mail or saves a lead. Checks, without sending mail: syntax, whether the domain accepts email (MX records, an A/AAAA record as implicit MX, or a null MX that refuses all mail), disposable/temporary providers (a maintained list of thousands of domains), free webmail (Gmail, Outlook, Yahoo, ...), role accounts (info@, support@, noreply@), likely misspellings of big providers with a corrected suggestion (gmial.com → gmail.com), and the domain's SPF and DMARC records and email provider. Returns a verdict (deliverable, risky, undeliverable), a 0-100 score and the reasons. The mailbox itself is not probed (no SMTP), so a catch-all domain accepts any name. An invalid address is still an answer (undeliverable); only a DNS failure is an error, not charged. You are only charged when a result is returned: invalid input (400) and upstream failures (4xx/5xx) are not settled. Costs $0.002 USDC per call via x402. Paid per call with x402 inside MCP (see the server instructions).

NameTypeReqDescription
emailstringyesThe address to check, e.g. "jane@acme.com" (a "Jane Doe <jane@acme.com>" form is accepted).

No output schema declared.

No examples provided.

hvac_coil_load ~722

Answers "What is the cooling coil load for 10,000 CFM from 80/67 °F to 55/54 °F?", "What leaves a coil that removes 270 MBH sensible and 60 MBH latent?" and "What is the mixed air with 20% outdoor air?" for AHU and RTU selection, coil schedules and design checks. Give the airflow and either the entering and leaving air (any two properties each) to get the sensible, latent and total loads, tons, sensible heat ratio, condensate rate and both full state points; or one state plus the loads to solve the other (cooling or heating). The entering air can be mixed from outdoor and return air states with an outdoor air % or airflow; or, given the mixed air, the outdoor air % is back-calculated. Standard-air equations (Qs = 1.08·CFM·ΔT, Ql = 4840·CFM·ΔW, Qt = 4.5·CFM·Δh as a cross-check), ASHRAE psychrometrics at the site elevation, IP (CFM, MBH) or SI (L/s, kW). Flags impossible (supersaturated) results. Every result includes `steps` with the equations and numbers. You are only charged when a result is returned: invalid input (400) and upstream failures (4xx/5xx) are not settled. Costs $0.002 USDC per call via x402. Paid per call with x402 inside MCP (see the server instructions).

NameTypeReqDescription
airflownumberyesTotal airflow through the coil: CFM (IP) or L/s (SI).
elevationnumber–Site elevation, ft (IP) or m (SI); sets the atmospheric pressure. Default 0 (sea level).
enteringobject–Air entering the coil: exactly two of dry_bulb, wet_bulb, dew_point, relative_humidity (%), humidity_ratio (lb/lb or g/kg), enthalpy (BTU/lb or kJ/kg), grains (gr/lb), in `units`. With outdoor_air an…
latent_loadnumber–Coil latent load, MBH or kW (default 0 when only sensible_load is given).
leavingobject–Air leaving the coil: two properties, like `entering`.
modestring–When solving a state from loads: cooling (default) removes heat, heating adds it. Detected automatically when both states are given.
outdoor_airobject–Outdoor air (two properties, like `entering`), mixed with return_air ahead of the coil.
outdoor_air_percentnumber–Outdoor air share of the total airflow, %.
outdoor_airflownumber–Outdoor airflow, CFM or L/s (instead of outdoor_air_percent).
return_airobject–Return air (two properties, like `entering`).
sensible_loadnumber–Coil sensible load, MBH (IP) or kW (SI): with one state, solves the other.
unitsstring–"IP" (°F, CFM, in, BTU) or "SI" (°C, L/s, mm, kW). Default IP. Applies to inputs and results.

No output schema declared.

No examples provided.

hvac_duct_size ~522

Answers "What size duct for 1,000 CFM at 0.08 in. w.g./100 ft?", "What is the velocity and friction in a 24×12 duct at 2,000 CFM?" and "What height do I need with a 10 in depth limit?" for duct design and checking. Give any two of a duct size (round diameter, or rectangular width × height), airflow, velocity and friction rate (equal-friction sizing); a single width or height is held as a fixed side. Returns the exact round diameter and a rectangular equivalent (ASHRAE/Huebscher equivalent diameter for equal friction, or equal area for a velocity design), the nearest standard round and rectangular sizes with the velocity and friction of each, the friction loss per 100 ft (Darcy-Weisbach with Colebrook-White, galvanized steel, standard air), velocity pressure, Reynolds number, and design checks for velocity, friction and aspect ratio. IP (in, CFM, FPM) or SI (mm, L/s, m/s, Pa/m, metric sizes). Every result includes `steps` with the equations and numbers. You are only charged when a result is returned: invalid input (400) and upstream failures (4xx/5xx) are not settled. Costs $0.002 USDC per call via x402. Paid per call with x402 inside MCP (see the server instructions).

NameTypeReqDescription
airflownumber–Airflow: CFM (IP) or L/s (SI).
diameternumber–Round duct diameter: in (IP) or mm (SI).
friction_ratenumber–Friction loss: in. w.g. per 100 ft (IP, typically 0.05-0.15) or Pa/m (SI, typically 0.4-1.2). With airflow, this is equal-friction sizing.
heightnumber–Rectangular height: in or mm.
unitsstring–"IP" (°F, CFM, in, BTU) or "SI" (°C, L/s, mm, kW). Default IP. Applies to inputs and results.
velocitynumber–Air velocity: FPM (IP) or m/s (SI).
widthnumber–Rectangular width: in or mm. With height, the duct size; alone, a fixed side (e.g. a ceiling depth) the other side is solved for.

No output schema declared.

No examples provided.

hvac_psychrometrics ~578

Answers "What is the dew point / enthalpy / humidity ratio of 95 °F air at 75 °F wet bulb?" and "What RH is 75 °F air with a 55 °F dew point in Denver?" for HVAC design, commissioning, energy and comfort work. From any two of dry bulb, wet bulb, dew point, relative humidity, humidity ratio, enthalpy or grains, returns the full state point: all seven plus specific volume, density and vapor pressure, at any site elevation (atmospheric pressure), in IP (°F, BTU/lb, gr/lb) or SI (°C, kJ/kg, g/kg). Uses the ASHRAE Handbook—Fundamentals (2021) Ch. 1 equations (Hyland-Wexler saturation pressure, ice below freezing) and is cross-checked against PsychroLib to within 0.02 °F. Every result includes `steps`: each equation with the numbers put into it and its ASHRAE reference, so the work can be checked or pasted into a calc package. Impossible states (wet bulb above dry bulb, RH over 100%) are errors and are not charged. You are only charged when a result is returned: invalid input (400) and upstream failures (4xx/5xx) are not settled. Costs $0.002 USDC per call via x402. Paid per call with x402 inside MCP (see the server instructions).

NameTypeReqDescription
dew_pointnumber–Dew-point temperature, °F or °C.
dry_bulbnumber–Dry-bulb temperature, °F (IP) or °C (SI).
elevationnumber–Site elevation, ft (IP) or m (SI); sets the atmospheric pressure. Default 0 (sea level).
enthalpynumber–Enthalpy: BTU per lb dry air (IP) or kJ/kg dry air (SI).
grainsnumber–Moisture in grains per lb dry air (gr/lb), in either unit system (7,000 gr = 1 lb).
humidity_rationumber–Humidity ratio: lb water per lb dry air (IP, e.g. 0.0100) or g/kg (SI, e.g. 10.0).
relative_humiditynumber–Relative humidity, % (0-100).
unitsstring–"IP" (°F, CFM, in, BTU) or "SI" (°C, L/s, mm, kW). Default IP. Applies to inputs and results.
wet_bulbnumber–Wet-bulb temperature, °F or °C.

No output schema declared.

No examples provided.

sanctions_screen ~409

Answers "Is this company or person sanctioned by the US?" and "Is this crypto wallet on OFAC's list?" for KYC, vendor onboarding, payments and compliance checks. Screens a name against the US Treasury OFAC Specially Designated Nationals (SDN) list and the Consolidated (non-SDN) sanctions lists, primary names and aliases, tolerant of word order ("PUTIN, Vladimir"), accents, punctuation, honorifics, legal suffixes and small typos; and a cryptocurrency address against the addresses OFAC lists (exact match). Each match has a 0-100 score, the name it matched (primary or a.k.a.), and the listing: OFAC ID, type, programs, title, aliases, addresses, date of birth, nationality, crypto addresses and remarks. Filter by type and country; set the score threshold. `clear` is true when nothing matched. Lists are refreshed from OFAC every 12 hours. A screening aid, not legal advice. You are only charged when a result is returned: invalid input (400) and upstream failures (4xx/5xx) are not settled. Costs $0.005 USDC per call via x402. Paid per call with x402 inside MCP (see the server instructions).

NameTypeReqDescription
countrystring–Only listings with an address or nationality in this country, e.g. "Iran".
crypto_addressstring–A cryptocurrency address to check against the addresses OFAC lists (exact match), e.g. a Bitcoin or Ethereum address.
limitinteger–Most matches to return, best first (default 10).
min_scoreinteger–Lowest name-match score (0-100) to report. Default 85.
namestring–Person, company, vessel or aircraft name, e.g. "Vladimir Putin" or "Rosneft".
typestring–Only this kind of listing: individual, entity, vessel or aircraft.

No output schema declared.

No examples provided.

scrape_batch ~454

Use it when an agent needs to read several web pages at once: compare competitors' pricing pages, read the top search results, or the pages a site_map call found. Reads 2-5 public URLs in one paid call (one payment round trip instead of five), each exactly like scrape_markdown: the main content as clean Markdown (or `mode: "full"`), real tables, code blocks, metadata from meta tags and JSON-LD (author, dates, language, canonical URL), PDFs as text by page, RSS feeds as item lists, optionally each page's links. Results come back in request order, each either `ok: true` with the page or `ok: false` with an error code and message (bot check, unreachable, unsupported content), so one bad URL does not spoil the batch. Each page is cut at `max_chars_per_page` (default 20,000); next_calls continue a long page with scrape_markdown. If no page at all can be read, the call fails and is not charged. JavaScript is not executed. No account or API key. Costs $0.008 USDC per call via x402 ($0.002 per page when read one by one). Paid per call with x402 inside MCP (see the server instructions).

NameTypeReqDescription
include_linksboolean–Also return each page's links as a list (url, text, internal). Default false.
max_chars_per_pageinteger–Return at most this many characters of each page (1,000-50,000, default 20,000). Read the rest of a long page with scrape_markdown and its next_offset.
modestring–main (default): each page's article or main content only. full: whole pages, including navigation and footers.
strip_link_urlsboolean–Write links as plain text in the Markdown (keeps the text, drops the URLs) to save tokens. Default false.
urlsarrayyes2-5 different public http(s) URLs to read, e.g. ["https://example.com/pricing", "https://example.com/docs"]. Results come back in the same order.

No output schema declared.

No examples provided.

scrape_markdown ~532

Use it when an agent needs to read a web page, article, documentation, PDF, blog post, product or pricing page, news story or RSS feed. Returns the main content as clean Markdown ready for an LLM: navigation, ads, footers and sidebars removed (or `mode: "full"` for the whole page), real tables as Markdown tables, code blocks with their language, math as TeX, the real (not lazy-loaded placeholder) images, absolute links without same-page anchors, and no needless escaping. Also returns metadata from meta tags and JSON-LD (description, author, published and modified time, language, site name, canonical URL, image, schema.org type), the HTTP status, word and token counts, and optionally the page's links. PDFs come back as text by page (up to 100 pages, 15 MB; no OCR), RSS/Atom feeds as item lists, JSON pretty-printed, and JavaScript-built pages that embed their content as data (JSON-LD articleBody, Next.js) are read from it. Long pages are returned in parts of up to 100,000 characters: pass `next_offset` back as `offset`; `strip_link_urls` saves tokens. Bot checks ("Just a moment...") and pages with no readable text answer 422 and are not charged; JavaScript is not executed. No account or API key. You are only charged when a result is returned: invalid input (400) and upstream failures (4xx/5xx) are not settled. Costs $0.002 USDC per call via x402. Paid per call with x402 inside MCP (see the server instructions).

NameTypeReqDescription
include_linksboolean–Also return the page's links as a list (url, text, internal). Default false.
max_charsinteger–Return at most this many characters (1,000-100,000, default 100,000).
modestring–main (default): the article or main content only. full: the whole page, including navigation and footers.
offsetinteger–Start at this character of the Markdown; pass the previous response's next_offset to read a long page in parts.
strip_link_urlsboolean–Write links as plain text in the Markdown (keeps the text, drops the URLs) to save tokens. Default false.
urlstringyesPublic http(s) URL to read: a web page, PDF, text, JSON or RSS/Atom feed, e.g. https://example.com/article.

No output schema declared.

No examples provided.

sec_filing_section ~652

Answers questions like "What are Tesla's risk factors?", "What did Apple's MD&A say about margins?" or "How has Microsoft's cybersecurity disclosure changed since 2023?". Returns exactly one section of a US public company's 10-K (annual) or 10-Q (quarterly) report from SEC EDGAR as clean text, ready for an LLM: Risk Factors (Item 1A), Management's Discussion and Analysis (MD&A), Business, Legal Proceedings, Market Risk, or Cybersecurity. Look up by stock ticker or CIK. Defaults to the latest filing; pass `fiscal_year` (2001 on) for an earlier year's report, or `accession_number` for an exact filing (the free sec_list_filings tool lists them, with the sections each one has). For several sections of one filing use sec_filing_sections; for what changed since last year, sec_section_changes. The table of contents, page numbers, hidden XBRL data and HTML are removed; tables are kept as readable rows. Includes the filing date, fiscal period, accession number and sec.gov link for citation. Use it for investment research, due diligence, competitor analysis or risk monitoring without downloading a 100-page filing. Sections up to 200,000 characters. If the filing's item only points elsewhere ("See Note 12"), you get 404 SECTION_INCORPORATED_BY_REFERENCE with that pointer, free. You are only charged when a result is returned: invalid input (400) and upstream failures (4xx/5xx) are not settled. Costs $0.01 USDC per call via x402. Paid per call with x402 inside MCP (see the server instructions).

NameTypeReqDescription
accession_numberstring–Return the section from this exact 10-K or 10-Q filing of the company, e.g. 0000320193-22-000108.
cik––SEC Central Index Key, e.g. 320193. Use this, `ticker` or `company`.
companystring–Company name, e.g. "Apple" or "Coca-Cola". Use this, `ticker` or `cik`; a name matching several companies returns their tickers, free.
fiscal_yearinteger–Return the report whose fiscal period ends in this calendar year instead of the latest one, e.g. 2022 for Apple's 10-K for the year ended September 24, 2022. For a 10-Q, the latest quarter ending in…
formstring–Annual report (10-K, the default) or quarterly report (10-Q). With `accession_number`, taken from that filing.
sectionstringyesWhich section to return: risk_factors, mda (Management's Discussion and Analysis), business, legal_proceedings, market_risk, or cybersecurity (10-K only, filings from late 2023 on).
tickerstring–US stock ticker, e.g. AAPL, MSFT, BRK-B. Use this, `cik` or `company`.

No output schema declared.

No examples provided.

sec_filing_sections ~523

Answers several questions about one report at once, e.g. "What are Nvidia's risks, and what does management say about results?". Returns 2 or 3 sections of the same 10-K or 10-Q from SEC EDGAR as clean text, in one call: Risk Factors, MD&A, Business, Legal Proceedings, Market Risk, Cybersecurity. Same inputs and output per section as sec_filing_section (latest filing, a `fiscal_year` since 2001, or an exact `accession_number`; by ticker, CIK or company name), at $0.015 for up to three sections instead of $0.01 each. Sections the filing does not contain are listed in `not_found`; if none can be read you get 404, free. You are only charged when a result is returned: invalid input (400) and upstream failures (4xx/5xx) are not settled. Costs $0.015 USDC per call via x402. Paid per call with x402 inside MCP (see the server instructions).

NameTypeReqDescription
accession_numberstring–Return the section from this exact 10-K or 10-Q filing of the company, e.g. 0000320193-22-000108.
cik––SEC Central Index Key, e.g. 320193. Use this, `ticker` or `company`.
companystring–Company name, e.g. "Apple" or "Coca-Cola". Use this, `ticker` or `cik`; a name matching several companies returns their tickers, free.
fiscal_yearinteger–Return the report whose fiscal period ends in this calendar year instead of the latest one, e.g. 2022 for Apple's 10-K for the year ended September 24, 2022. For a 10-Q, the latest quarter ending in…
formstring–Annual report (10-K, the default) or quarterly report (10-Q). With `accession_number`, taken from that filing.
sectionsarrayyes2 or 3 sections to read from the same filing: risk_factors, mda, business, legal_proceedings, market_risk, cybersecurity. Business and cybersecurity exist only in 10-Ks.
tickerstring–US stock ticker, e.g. AAPL, MSFT, BRK-B. Use this, `cik` or `company`.

No output schema declared.

No examples provided.

sec_financials ~528

Answers "What were Apple's revenue and net income over the last five years?", "Is Tesla's free cash flow positive?" or "How fast is Nvidia growing quarter over quarter?". Returns a US public company's key financial-statement figures for its latest fiscal years (annual, from 10-Ks) or single quarters (quarterly), newest first, from the XBRL data companies file with the SEC: income statement (revenue, cost of revenue, gross profit, R&D, SG&A, operating income, pretax income, tax, net income, basic and diluted EPS, diluted shares), balance sheet (cash, current and total assets and liabilities, long-term debt, equity) and cash flow (operating cash flow, capex, free cash flow, dividends, buybacks), plus gross, operating and net margins and year-over-year revenue growth. Fourth quarters and single-quarter cash flows, which companies only report as full-year or year-to-date totals, are derived and flagged in `derived`. Each period cites the latest filing that reports it, so restated figures replace original ones. Up to 20 periods per call, back to about 2009; `fiscal_year` reaches earlier years. By ticker, CIK or company name. US-GAAP filers only (not IFRS 20-F filers); values in USD. You are only charged when a result is returned: invalid input (400) and upstream failures (4xx/5xx) are not settled. Costs $0.005 USDC per call via x402. Paid per call with x402 inside MCP (see the server instructions).

NameTypeReqDescription
cik––SEC Central Index Key, e.g. 320193. Use this, `ticker` or `company`.
companystring–Company name, e.g. "Apple" or "Coca-Cola". Use this, `ticker` or `cik`; a name matching several companies returns their tickers, free.
fiscal_yearinteger–Return periods up to this fiscal year (the calendar year the fiscal year ends in) instead of the latest, e.g. 2019.
limitinteger–How many periods to return, newest first (1-20, default 5).
periodstring–Fiscal years from 10-Ks (annual, the default) or single quarters (quarterly).
tickerstring–US stock ticker, e.g. AAPL, MSFT, BRK-B. Use this, `cik` or `company`.

No output schema declared.

No examples provided.

sec_full_text_search ~591

Answers "Which companies disclosed a material weakness this year?", "Who mentions tariffs in their 10-Q risk factors?", "Which filings name this executive, product or supplier?" or "Has this company ever mentioned a going-concern doubt?". Searches the full text of SEC EDGAR filings and their exhibits since 2001 (EDGAR Full-Text Search): put exact phrases in double quotes. Filter by form (10-K, 10-Q, 8-K, S-1, DEF 14A, ...), by company (ticker, CIK or name) and by filing date. Each hit gives the company, ticker, CIK, form, document type (e.g. EX-99.1), filing date, period, accession number, document and filing-index links, 8-K items, location, and `next_call`: the paid call that reads it (a 10-K/10-Q section, the 8-K event, or the document as Markdown). Also returns the total hit count and the companies and forms with the most hits across all pages. Up to 50 results per call; page with `offset`. No match is a 404, free. You are only charged when a result is returned: invalid input (400) and upstream failures (4xx/5xx) are not settled. Costs $0.01 USDC per call via x402. Paid per call with x402 inside MCP (see the server instructions).

NameTypeReqDescription
cik––SEC Central Index Key, e.g. 320193. Use this, `ticker` or `company`.
companystring–Company name, e.g. "Apple" or "Coca-Cola". Use this, `ticker` or `cik`; a name matching several companies returns their tickers, free.
formsarray–Only these form types, e.g. ["10-K", "10-Q"] or ["8-K"], ["S-1"], ["DEF 14A"]. Default: all forms.
limitinteger–How many documents to return, most relevant first (1-50, default 20).
offsetinteger–Skip this many results; pass the previous response's next_offset to page through more.
querystringyesWhat to search for in the filings' text. Put an exact phrase in double quotes, e.g. "\"material weakness\"" or "\"going concern\" Nasdaq"; words outside quotes must all appear.
sincestring–Only documents filed on or after this date (YYYY-MM-DD). Full-text search covers 2001 on.
tickerstring–US stock ticker, e.g. AAPL, MSFT, BRK-B. Use this, `cik` or `company`.
untilstring–Only documents filed on or before this date (YYYY-MM-DD).

No output schema declared.

No examples provided.

sec_insider_trades ~502

Answers "Are Nvidia's executives selling?", "Did any Intel insider buy shares on the open market this year?" or "What did Tesla's CFO do with his vested stock?". Returns a US public company's latest Form 4 filings from SEC EDGAR, the reports officers, directors and 10% owners must file within two business days of trading its stock: who traded (name, role, title), each transaction with its date, code and plain-English meaning, shares, price, dollar value, holdings after, and direct or indirect ownership, plus footnotes. A summary totals open-market purchases and sales (shares, dollars, which insiders) and separates sales under pre-arranged Rule 10b5-1 plans and sales that only cover taxes on vesting stock, which say little about insiders' views. Filter by filing date or transaction code (e.g. ["P"] for open-market purchases), optionally with option and RSU transactions; up to 40 filings per call. By ticker, CIK or company name. If nothing matches you get 404, free. You are only charged when a result is returned: invalid input (400) and upstream failures (4xx/5xx) are not settled. Costs $0.005 USDC per call via x402. Paid per call with x402 inside MCP (see the server instructions).

NameTypeReqDescription
cik––SEC Central Index Key, e.g. 320193. Use this, `ticker` or `company`.
companystring–Company name, e.g. "Apple" or "Coca-Cola". Use this, `ticker` or `cik`; a name matching several companies returns their tickers, free.
include_derivativeboolean–Also list derivative transactions (option and RSU grants, exercises, expirations). Default false.
limitinteger–How many Form 4 filings to return, newest first (1-40, default 15).
sincestring–Only filings filed on or after this date (YYYY-MM-DD).
tickerstring–US stock ticker, e.g. AAPL, MSFT, BRK-B. Use this, `cik` or `company`.
transaction_codesarray–Only filings with these transaction codes, e.g. ["P"] for open-market purchases, ["P", "S"] for open-market buying and selling. Default: all filings.

No output schema declared.

No examples provided.

sec_list_filings ~402

Free, no payment needed. Lists a US public company's 10-K (annual), 10-Q (quarterly) and 8-K (material event) filings from SEC EDGAR, newest first: filing date, fiscal year and period, sec.gov link, the sections sec_filing_section can extract from each report (Risk Factors, MD&A, Business, Legal Proceedings, Market Risk, Cybersecurity), and the event items of each 8-K (earnings 2.02, executive changes 5.02, deals 1.01, cybersecurity incidents 1.05, …). Every filing carries `next_call`: the exact paid tool call, with arguments and price, that returns its text. Use it to check what exists before paying, to find a specific year or event, or to track new filings. Filter by form and date (back to 2001); up to 50 filings per call. Look up by stock ticker or CIK. Rate-limited per client.

NameTypeReqDescription
cik––SEC Central Index Key, e.g. 320193. Use this, `ticker` or `company`.
companystring–Company name, e.g. "Apple" or "Coca-Cola". Use this, `ticker` or `cik`; a name matching several companies returns their tickers, free.
formsarray–Which filings to list: 10-K (annual), 10-Q (quarterly), 8-K (material events). Default: all three.
limitinteger–How many filings to return, newest first (1-50, default 20).
sincestring–Only filings filed on or after this date (YYYY-MM-DD). Reaches back to 2001.
tickerstring–US stock ticker, e.g. AAPL, MSFT, BRK-B. Use this, `cik` or `company`.

No output schema declared.

No examples provided.

sec_recent_events ~580

Answers "What happened at this company lately?": did the CEO or CFO leave, what were the latest earnings, was there an acquisition, major contract or cyber incident. Returns a US public company's most recent 8-K filings from SEC EDGAR, newest first: the material events companies must report within four business days, such as earnings releases (Item 2.02), CEO, CFO and director changes (5.02), material agreements and acquisitions (1.01, 2.01), cybersecurity incidents (1.05), impairments, auditor changes and shareholder votes. Each event has its item codes with official titles, the 8-K text as clean prose, and the text of its press-release exhibits (EX-99), e.g. the full earnings release. Filter by item codes and filing date, or ask for one exact 8-K by `accession_number` (the free sec_list_filings tool lists them); up to 10 events per call. Look up by stock ticker or CIK. Use it for event monitoring, news and earnings agents, due diligence or trading research, with sec.gov links for citation. If no 8-K matches, you get 404 FILING_NOT_FOUND, free. You are only charged when a result is returned: invalid input (400) and upstream failures (4xx/5xx) are not settled. Costs $0.01 USDC per call via x402. Paid per call with x402 inside MCP (see the server instructions).

NameTypeReqDescription
accession_numberstring–Return only this 8-K, e.g. one found with the free sec_list_filings tool.
cik––SEC Central Index Key, e.g. 320193. Use this, `ticker` or `company`.
companystring–Company name, e.g. "Apple" or "Coca-Cola". Use this, `ticker` or `cik`; a name matching several companies returns their tickers, free.
include_exhibitsboolean–Include the text of press-release exhibits (EX-99), e.g. the earnings release. Default true.
itemsarray–Only events reporting one of these 8-K items, e.g. ["5.02"] for executive and director changes, ["2.02"] for earnings releases, ["1.01", "2.01"] for deals, ["1.05"] for cybersecurity incidents.
limitinteger–How many events to return, newest first (1-10, default 5).
sincestring–Only events filed on or after this date (YYYY-MM-DD).
tickerstring–US stock ticker, e.g. AAPL, MSFT, BRK-B. Use this, `cik` or `company`.

No output schema declared.

No examples provided.

sec_section_changes ~541

Answers "What changed in Tesla's risk factors this year?", "Which new risks did Apple add?" or "How did Microsoft's MD&A change since 2022?". Compares one section of a company's 10-K with the same section of an earlier 10-K from SEC EDGAR, paragraph by paragraph: paragraphs added (new risk factors appear here), removed, and edited, each edit with a word-level diff marking deletions [-like this-] and insertions {+like this+}, plus a summary (counts and the share of text unchanged). Moved but identical paragraphs count as unchanged. Defaults to the latest 10-K against the one before it; pass `fiscal_year` or `accession_number` for the newer report and `compare_to_fiscal_year` for the older one (2001 on). Sections: Risk Factors, MD&A, Business, Legal Proceedings, Market Risk, Cybersecurity (filed from late 2023 on). By ticker, CIK or company name, with sec.gov links for both filings. Use it for risk monitoring, due diligence and investment research without reading two 100-page filings. If either report lacks the section you get 404, free. You are only charged when a result is returned: invalid input (400) and upstream failures (4xx/5xx) are not settled. Costs $0.04 USDC per call via x402. Paid per call with x402 inside MCP (see the server instructions).

NameTypeReqDescription
accession_numberstring–The newer report as an exact 10-K filing, instead of `fiscal_year`.
cik––SEC Central Index Key, e.g. 320193. Use this, `ticker` or `company`.
companystring–Company name, e.g. "Apple" or "Coca-Cola". Use this, `ticker` or `cik`; a name matching several companies returns their tickers, free.
compare_to_fiscal_yearinteger–The older report to compare against: the 10-K for this fiscal year. Default: the 10-K just before the newer one.
fiscal_yearinteger–The newer report: the 10-K whose fiscal year ends in this year. Default: the latest 10-K.
sectionstringyesWhich 10-K section to compare: risk_factors, mda, business, legal_proceedings, market_risk or cybersecurity.
tickerstring–US stock ticker, e.g. AAPL, MSFT, BRK-B. Use this, `cik` or `company`.

No output schema declared.

No examples provided.

site_map ~394

Use it when an agent needs to know what pages a website has before reading them: where is the pricing page, which docs pages exist, what did the blog publish lately, which product or careers pages are there. Give any URL on the site; returns the site's page URLs with their last-modified dates, like Firecrawl's /map. Reads the sitemaps named in robots.txt, else /sitemap.xml and /sitemap_index.xml, following sitemap indexes (up to 10 child sitemaps, 20,000 URLs) and gzip (.xml.gz) sitemaps; a site with no sitemap is mapped from its home page's links on the same host. Filter with `search` (every word must appear in the URL, title or date, e.g. "pricing" or "blog 2026") and `path_prefix` (e.g. "/docs/"); `limit` up to 1,000 (default 200). next_calls read the first matches with scrape_batch. When the site cannot be reached (502) or no page matches (404), you are not charged. No account or API key. Costs $0.002 USDC per call via x402. Paid per call with x402 inside MCP (see the server instructions).

NameTypeReqDescription
limitinteger–How many URLs to return (1-1,000, default 200).
path_prefixstring–Only URLs whose path starts with this, e.g. "/blog/" or "/docs".
searchstring–Only URLs containing every word of this text (case-insensitive) in the URL, or in the title or lastmod when known, e.g. "pricing" or "blog 2026".
urlstringyesThe website, or any page on it, e.g. https://example.com. Its origin (scheme and host) is mapped.

No output schema declared.

No examples provided.

Common questions

What is the Agent Utility Suite (x402) MCP server?

Agent Utility Suite (x402) is an MCP server listed in the public MCP registry as io.github.vanakenj45/x402-agent-api. SEC filings, financials, insider trades; company data; web scraping; OFAC, email; HVAC calcs. x402. This page covers its hosted endpoint (https://x402-agent-api.onrender.com/mcp).

Is the Agent Utility Suite (x402) MCP server safe to use?

Agent Utility Suite (x402) scores 70 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Agent Utility Suite (x402) MCP server expose?

Agent Utility Suite (x402) exposes 19 tools: sec_list_filings, sec_filing_section, sec_filing_sections, sec_section_changes, sec_recent_events, and 14 more. Their descriptions and schemas cost roughly 9,206 tokens of context every time the server is loaded.

Does the Agent Utility Suite (x402) MCP server require authentication?

No. We connected to Agent Utility Suite (x402) without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the Agent Utility Suite (x402) MCP server still maintained?

Agent Utility Suite (x402) is still listed as active in the MCP registry. We last reached this channel on 9 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.