# AgentResolver Guard — Verify x402 Before Paying (remote · agentresolver.vercel.app)

Capability procurement + provider routing; $0.001 x402 verify-before-pay Guard on Base + Solana.

- Trust score: 69/100 (medium)
- Change this week: +1
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-25

## Components

- remote · `agentresolver.vercel.app`: 69/100 (this document), [markdown](https://verifymcp.io/servers/waxsway-agentresolver/agentresolver.md), [page](https://verifymcp.io/servers/waxsway-agentresolver/agentresolver)

## Channel facts

- Endpoint: `https://agentresolver.vercel.app/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `0.2.3`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-25.

- **Endpoint Security**: 80/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one.
  - HTTPS is enforced; there's no plaintext access path.
  - The HSTS (Strict-Transport-Security) header is present.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 69/100
  - AI-judged instruction clarity (good).
  - Tool/resource definitions use about 2290 tokens (~65/item across 35 items; 35 tools + 0 resources), lean.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 0/100
  - Stability check failed: schema churn in the 10 days we've observed: 1 tool removals, 0 breaking changes, 0 auth/transport breaks, 34 additions.
- **Tool Coverage**: 71/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 0% of tool parameters carry a description.
  - Structured output schemas are declared (11% of tools); any adoption earns full credit.
- **Tool Safety**: 75/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 35 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - Manipulation not yet verified: only 35 of 36 captured unit(s) of tool text has been judged so far, so we will not certify text no model has read as clean.
- **Capabilities**: 100/100
  - Implements a current MCP spec version (2026-07-28).

## Install

### How do I install the AgentResolver Guard — Verify x402 Before Paying MCP server?

AgentResolver Guard — Verify x402 Before Paying is a hosted endpoint at https://agentresolver.vercel.app/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http waxsway-agentresolver 'https://agentresolver.vercel.app/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "waxsway-agentresolver": {
      "url": "https://agentresolver.vercel.app/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "waxsway-agentresolver": {
      "type": "http",
      "url": "https://agentresolver.vercel.app/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.waxsway-agentresolver]
url = "https://agentresolver.vercel.app/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "waxsway-agentresolver": {
      "type": "remote",
      "url": "https://agentresolver.vercel.app/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add waxsway-agentresolver --url 'https://agentresolver.vercel.app/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  waxsway-agentresolver:
    url: "https://agentresolver.vercel.app/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "waxsway-agentresolver": {
      "Transport": "http",
      "Url": "https://agentresolver.vercel.app/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add waxsway-agentresolver -t streamable-http -u 'https://agentresolver.vercel.app/mcp'
```

### Other

```json
{
  "mcpServers": {
    "waxsway-agentresolver": {
      "type": "http",
      "url": "https://agentresolver.vercel.app/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-25 (score 69, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-24 (score 69, 0)

- [functional] Server version: 0.1.3 → 0.1.4

### 2026-09-21 (score 69, +1)

- [security] The server rewrote its instructions, which are the text every model session reads
- [security] Tool “resolve” rewrote its description, which is the text the model reads
- [security] Tool “verified_resolve” rewrote its description, which is the text the model reads
- [functional regression] Schema quality: 58 → 65
- [functional improvement] Tool “hash_encode” now declares an output schema
- [functional improvement] Tool “payment_guard” now declares an output schema
- [functional improvement] Tool “x402_payment_preflight” now declares an output schema
- [functional improvement] Tool “x402_ping” now declares an output schema
- [functional] First check of Tool coverage: 11
- [functional] New tool “provider_bootstrap”
- [functional] New tool “provider_launch_check”
- [functional] New tool “procure”
- [cosmetic] “verified_resolve” added an optional parameter “constraints”
- [cosmetic] “verified_resolve” added an optional parameter “providerOrigins”
- [cosmetic] Tool “resolve” changed its title: Resolve a missing capability → Explore possible capabilities
- [cosmetic] Tool “verified_resolve” changed its title: Live verified resolve — $0.02 → Verify an unresolved external capability — $0.02

### 2026-09-18 (score 68, 0)

- [functional] New tool “payment_guard”
- [cosmetic] Tool “x402_payment_preflight” changed its title: X402 preflight — verify endpoint before paying — $0.001 → X402 preflight — verify endpoint before paying — endpoint safety — USDC payment check — $0.001
- [cosmetic] Tool “x402_ping” changed its title: x402 settlement test — $0.001 → x402 settlement test — wallet facilitator payment test — $0.001

### 2026-09-17 (score 68, −2)

- [security regression] Judged manipulation: pass → unverified
- [security] The server rewrote its instructions, which are the text every model session reads
- [security] Tool “agent_readiness” rewrote its description, which is the text the model reads
- [security] Tool “batch_verified_resolve” rewrote its description, which is the text the model reads
- [security] Tool “http_inspect” rewrote its description, which is the text the model reads
- [security] Tool “mcp_preflight” rewrote its description, which is the text the model reads
- [security] Tool “openapi_select” rewrote its description, which is the text the model reads
- [security] Tool “tool_contract” rewrote its description, which is the text the model reads
- [security] Tool “verified_resolve” rewrote its description, which is the text the model reads
- [functional improvement] Schema quality: 74 → 56
- [functional] New tool “uuid_v4”
- [functional] New tool “x402_payment_preflight”
- [functional] New tool “x402_ping”
- [functional] New tool “url_parse”
- [functional] New tool “abi_decode”
- [functional] New tool “abi_encode”
- [functional] New tool “base64_decode”
- [functional] New tool “base64_encode”
- [functional] New tool “eip712_hash”
- [functional] New tool “ens_namehash”
- [functional] New tool “evm_address_checksum”
- [functional] New tool “evm_units”
- [functional] New tool “hash_encode”
- [functional] New tool “hmac_sha256”
- [functional] New tool “json_normalize”
- [functional] New tool “json_schema_validate”
- [functional] New tool “jwt_decode”
- [functional] New tool “keccak256”
- [functional] New tool “sha256”
- [functional] New tool “sha512”
- [functional] New tool “slugify”
- [functional] New tool “solidity_selector”
- [functional] New tool “sponsorship_info”
- [cosmetic] Tool “http_inspect” changed its title: HTTP inspection — $0.001 → x402 payment preflight + PayTo verification — $0.001

### 2026-09-16 (score 70, −1)

- [security regression] Stability: unverified → fail
- [security regression] Tool “list_capabilities” was removed
- [security] The server rewrote its instructions, which are the text every model session reads
- [security] Tool “resolve” rewrote its description, which is the text the model reads
- [functional regression] Schema quality: 59 → 74
- [functional] Server version: 0.1.0 → 0.1.3
- [functional] New tool “tool_contract”
- [functional] New tool “verified_resolve”
- [functional] New tool “openapi_select”
- [functional] New tool “mcp_preflight”
- [functional] New tool “http_inspect”
- [functional] New tool “batch_verified_resolve”
- [functional] New tool “agent_readiness”
- [cosmetic] Tool “resolve” changed its title: Resolve a missing capability

### 2026-09-15 (score 71)

First indexed and scored.

## MCP tools (35)

### `sponsorship_info` (~40 tokens)

Provider sponsorship information

Free read-only information for tool/API/MCP providers about AgentResolver's explicitly labeled sponsorship pilot. Organic ranking remains independent; applying creates no purchase or financial commitment.

### `resolve` (~72 tokens)

Explore possible capabilities

Free exploratory discovery. Use only when browsing possible tools/APIs/MCP services without needing a trustworthy execution choice yet. For an actual missing capability, prefer procure so required evidence fails closed and unresolved candidates can escalate to verification.

Input parameters:

- `goal` (string, required)
- `limit` (integer)
- `url` (string)

### `provider_bootstrap` (~86 tokens)

Bootstrap a domain-controlled provider

Free zero-state provider onboarding. Reads the fixed AgentResolver well-known manifest on one HTTPS origin, live-verifies selected same-origin x402 payment identities, returns an immediate providerOrigins procurement seed, and prepares caller-owned durable 402 Index registration actions. AgentResolver does not persist provider state or send the external registration.

Input parameters:

- `origin` (string, required)
- `routeIds` (array)

### `procure` (~112 tokens)

Procure a compatible capability

CALL THIS when the agent's installed tools do not clearly satisfy the current task. Free open-world procurement across APIs, MCP, x402, L402 and MPP. Required compatibility evidence fails closed: AgentResolver returns no selected provider rather than guessing. When supported unknowns remain, the response can recommend the paid $0.02 verified_resolve step. Never authorizes spend.

Input parameters:

- `constraints` (object)
- `goal` (string, required)
- `limit` (integer)
- `providerOrigins` (array)

### `abi_encode` (~48 tokens)

Ethereum ABI encode — $0.005

Paid $0.005 USDC on Base or Solana exact Ethereum ABI encoding from Solidity typed JSON values to calldata-ready hex.

Input parameters:

- `types` (array, required)
- `values` (array, required)

### `abi_decode` (~44 tokens)

Ethereum ABI decode — $0.005

Paid $0.005 USDC on Base or Solana exact Ethereum ABI decoding into JSON-safe typed values.

Input parameters:

- `data` (string, required)
- `types` (array, required)

### `eip712_hash` (~65 tokens)

EIP-712 typed-data hash — $0.005

Paid $0.005 USDC on Base or Solana exact EIP-712 typed-data digest for signing and verification workflows.

Input parameters:

- `domain` (object, required)
- `message` (object, required)
- `primaryType` (string, required)
- `types` (object, required)

### `ens_namehash` (~42 tokens)

ENS namehash — $0.01

Paid $0.01 USDC on Base or Solana ENSIP-15 normalization, exact ENS namehash and label hashes.

Input parameters:

- `name` (string, required)

### `evm_address_checksum` (~40 tokens)

EVM address checksum — $0.003

Paid $0.003 USDC on Base or Solana exact EIP-55 address validation and checksum normalization.

Input parameters:

- `address` (string, required)

### `keccak256` (~50 tokens)

Keccak-256 — $0.004

Paid $0.004 USDC on Base or Solana exact Ethereum keccak256 digest for UTF-8 text or hex bytes.

Input parameters:

- `encoding` (string)
- `input` (string, required)

### `solidity_selector` (~41 tokens)

Solidity selector — $0.01

Paid $0.01 USDC on Base or Solana exact 4-byte Solidity selector and full keccak256 signature hash.

Input parameters:

- `signature` (string, required)

### `evm_units` (~52 tokens)

EVM units convert — $0.005

Paid $0.005 USDC on Base or Solana exact decimal/base-unit conversion with arbitrary token decimals.

Input parameters:

- `decimals` (integer, required)
- `mode` (string, required)
- `value` (string, required)

### `x402_ping` (~62 tokens)

x402 settlement test — wallet facilitator payment test — $0.001

Paid $0.001 USDC on Base or Solana no-body settlement canary for funded agents. Returns a timestamped pong only after successful x402 payment to verify wallet, facilitator, payment, and delivery end-to-end.

Input parameters:

- `echo` (string)

Output parameters:

- `at` (string)
- `echo` (string|null)
- `next` (object)
- `pong` (boolean)
- `requestId` (string)
- `settledDelivery` (boolean)
- `unixMs` (integer)

### `sha256` (~38 tokens)

SHA-256 hash — $0.001

Paid $0.001 USDC on Base or Solana SHA-256 digest of bounded UTF-8 text.

Input parameters:

- `input` (string, required)

### `sha512` (~38 tokens)

SHA-512 hash — $0.001

Paid $0.001 USDC on Base or Solana SHA-512 digest of bounded UTF-8 text.

Input parameters:

- `input` (string, required)

### `hmac_sha256` (~44 tokens)

HMAC SHA-256 — $0.001

Paid $0.001 USDC on Base or Solana HMAC-SHA256 hex digest.

Input parameters:

- `input` (string, required)
- `secret` (string, required)

### `base64_encode` (~36 tokens)

Base64 encode — $0.001

Paid $0.001 USDC on Base or Solana UTF-8 to Base64 encoding.

Input parameters:

- `input` (string, required)

### `base64_decode` (~36 tokens)

Base64 decode — $0.001

Paid $0.001 USDC on Base or Solana Base64 to UTF-8 decoding.

Input parameters:

- `input` (string, required)

### `jwt_decode` (~36 tokens)

JWT decode — $0.001

Paid $0.001 USDC on Base or Solana non-verifying JWT header/payload decode.

Input parameters:

- `input` (string, required)

### `json_normalize` (~35 tokens)

JSON normalize — $0.001

Paid $0.001 USDC on Base or Solana canonical JSON normalization plus SHA-256 digest.

Input parameters:

- `value` (required)

### `json_schema_validate` (~39 tokens)

JSON Schema validate — $0.001

Paid $0.001 USDC on Base or Solana deterministic JSON Schema subset validation.

Input parameters:

- `data` (required)
- `schema` (object, required)

### `url_parse` (~31 tokens)

URL parse — $0.001

Paid $0.001 USDC on Base or Solana absolute URL parser.

Input parameters:

- `url` (string, required)

### `uuid_v4` (~39 tokens)

UUID v4 — $0.001

Paid $0.001 USDC on Base or Solana UUID v4 generation, up to 20 IDs.

Input parameters:

- `count` (integer)

### `slugify` (~38 tokens)

Slugify — $0.001

Paid $0.001 USDC on Base or Solana deterministic slug generation.

Input parameters:

- `separator` (string)
- `text` (string, required)

### `hash_encode` (~83 tokens)

Hash & encode — $0.001

Paid $0.001 USDC on Base or Solana deterministic SHA-256, SHA-512, HMAC-SHA256, Base64 encode/decode, or non-verifying JWT decode. x402-aware MCP clients can authorize and settle inside this tool call.

Input parameters:

- `input` (string, required)
- `operation` (string, required)
- `secret` (string)

### `payment_guard` (~118 tokens)

AgentResolver Guard — verify before every x402 payment — $0.001

Paid $0.001 USDC fail-closed payment authorization preflight. Use immediately before an autonomous agent signs a target x402 payment. Returns eligible/blocked, exact observed payment terms, reason codes, evidence receipt and stable fingerprints. The caller retains sole spending authority.

Input parameters:

- `allowUnpaidPostProbe` (boolean)
- `body`
- `expectedNetwork` (string)
- `expectedPayTo` (string)
- `maxPriceUsd` (number)
- `method` (string)
- `url` (string, required)

Output parameters:

- `evidenceReceipt` (object)
- `guard` (object)
- `latencyMs` (number)
- `ok` (boolean)
- `prepaymentDecision` (object)
- `status` (integer)
- `url` (string)

### `x402_payment_preflight` (~131 tokens)

X402 preflight — verify endpoint before paying — endpoint safety — USDC payment check — $0.001

Paid $0.001 USDC on Base or Solana transaction-path gate for autonomous buyers. Returns eligible/blocked, exact target payment terms, fail-closed reason codes and verifiable evidence before caller authorization. AgentResolver never requests a private key, signs the target payment, or custodies/forwards target funds.

Input parameters:

- `allowUnpaidPostProbe` (boolean)
- `body`
- `expectedNetwork` (string)
- `expectedPayTo` (string)
- `maxPriceUsd` (number)
- `method` (string)
- `url` (string, required)

Output parameters:

- `evidenceReceipt` (object)
- `guard` (object)
- `latencyMs` (number)
- `ok` (boolean)
- `prepaymentDecision` (object)
- `status` (integer)
- `url` (string)

### `http_inspect` (~77 tokens)

x402 payment preflight + PayTo verification — $0.001

Paid $0.001 USDC on Base or Solana verify-before-pay endpoint safety check: payTo verification, quote price, network, asset, resource binding and x402 challenge compliance before an agent authorizes spend. POST probes require explicit caller opt-in because an unprotected endpoint could have side effects.

Input parameters:

- `url` (string, required)

### `tool_contract` (~77 tokens)

Tool contract fit — $0.005

Paid $0.005 USDC on Base or Solana deterministic JSON-schema compatibility check between one tool output and the next tool input. Returns exact incompatibility reasons and conservative normalized mappings. x402-aware MCP clients can authorize and settle inside this tool call.

Input parameters:

- `consumerInputSchema` (object, required)
- `producerOutputSchema` (object, required)

### `openapi_select` (~74 tokens)

OpenAPI operation selection — $0.005

Paid $0.005 USDC on Base or Solana selection of the best operation from one public JSON OpenAPI spec for a stated goal. Returns a compact execution-ready contract. x402-aware MCP clients can authorize and settle inside this tool call.

Input parameters:

- `goal` (string, required)
- `specUrl` (string, required)

### `mcp_preflight` (~62 tokens)

MCP live preflight — $0.001

Paid $0.001 USDC on Base or Solana live MCP endpoint preflight for reachability, compatibility, latency, server metadata and tool inventory. x402-aware MCP clients can authorize and settle inside this tool call.

Input parameters:

- `endpoint` (string, required)

### `agent_readiness` (~57 tokens)

Agent-readiness audit — $0.005

Paid $0.005 USDC on Base or Solana audit of a public website for agent discoverability and machine-readable integration signals. x402-aware MCP clients can authorize and settle inside this tool call.

Input parameters:

- `url` (string, required)

### `provider_launch_check` (~120 tokens)

Provider launch check — $0.05

Paid $0.05 USDC seller-side readiness and x402 contract verification before AgentResolver provider-network review.

Input parameters:

- `capabilityId` (string, required)
- `description` (string, required)
- `endpoint` (string, required)
- `method` (string)
- `name` (string, required)
- `network` (string)
- `origin` (string, required)
- `priceUsd` (number, required)
- `probeUrl` (string)
- `providerId` (string, required)
- `providerName` (string, required)
- `tags` (array)

### `verified_resolve` (~109 tokens)

Verify an unresolved external capability — $0.02

PAID $0.02 USDC verification step. Use after procure returns no proven selection / eligible_with_unknowns, or immediately before trusting an unfamiliar external candidate when live evidence is required. Re-checks supported endpoint, MCP, x402 and contract evidence and returns a fail-closed recommendation. Call only when the host independently authorizes the displayed spend.

Input parameters:

- `constraints` (object)
- `goal` (string, required)
- `providerOrigins` (array)
- `url` (string)

### `batch_verified_resolve` (~63 tokens)

Batch verified resolve — $0.05

Paid $0.05 USDC on Base or Solana batch live verification for 2–4 capability decisions using unpaid MCP and x402/HTTP evidence. x402-aware MCP clients can authorize and settle inside this tool call.

Input parameters:

- `items` (array, required)

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/waxsway-agentresolver/agentresolver#diagnostics

## Score history

- 2026-09-25: 69
- 2026-09-24: 69
- 2026-09-23: 69
- 2026-09-22: 69
- 2026-09-21: 69
- 2026-09-18: 68
- 2026-09-17: 68
- 2026-09-16: 70
- 2026-09-15: 71

## Common questions

### What is the AgentResolver Guard — Verify x402 Before Paying MCP server?

AgentResolver Guard — Verify x402 Before Paying is an MCP server listed in the public MCP registry as io.github.waxsway/agentresolver. Capability procurement + provider routing; $0.001 x402 verify-before-pay Guard on Base + Solana. This page covers its hosted endpoint (https://agentresolver.vercel.app/mcp).

### Is the AgentResolver Guard — Verify x402 Before Paying MCP server safe to use?

AgentResolver Guard — Verify x402 Before Paying scores 69 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the AgentResolver Guard — Verify x402 Before Paying MCP server expose?

AgentResolver Guard — Verify x402 Before Paying exposes 35 tools: sponsorship_info, resolve, provider_bootstrap, procure, abi_encode, and 30 more. Their descriptions and schemas cost roughly 2,135 tokens of context every time the server is loaded.

### Does the AgentResolver Guard — Verify x402 Before Paying MCP server require authentication?

No. We connected to AgentResolver Guard — Verify x402 Before Paying without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the AgentResolver Guard — Verify x402 Before Paying MCP server still maintained?

AgentResolver Guard — Verify x402 Before Paying is still listed as active in the MCP registry. We last reached this channel on 25 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://agentresolver.vercel.app/mcp
- Repository: https://github.com/waxsway/agentresolver
- Changelog RSS feed: https://verifymcp.io/servers/waxsway-agentresolver/agentresolver.xml
- Changelog JSON feed: https://verifymcp.io/servers/waxsway-agentresolver/agentresolver.json
- HTML version of this page: https://verifymcp.io/servers/waxsway-agentresolver/agentresolver
