GhostKey — Route Paid APIs with x402

Find paid APIs, check access policy and price, and route x402 requests. No autonomous spending.

Should I use this

Quality & Safety

B
Description quality
97%
Schema completeness
63%
Naming quality
80%
Poisoning risk
100%
Permission match
100%
Protocol compliance
100%

Findings (1)

  • LOWTool 'ghostkey_device_pairing_status' description lacks action verbin ghostkey_device_pairing_status

Based on automated analysis of tool definitions and protocol compliance.

Context Cost

~1,066Tokens (tool definitions)
~696 BTypical response size
Moderate attention impact (0.83% of 128k context)

This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.

Install

One-Click Install

Add this to your `claude_desktop_config.json` file:

{
  "mcpServers": {
    "ghostkey": {
      "url": "https://ghostkey-mcp.onrender.com/mcp"
    }
  }
}

Remote endpoints

https://ghostkey-mcp.onrender.com/mcpstreamable-http
https://squeezeos-api.onrender.com/mcp/ghostkeystreamable-http

What it can do

Tool inventory

Tools (10)

🟢 Read-only🟡 Write🔴 Delete⚪ Unknown
🟢ghostkey_status

Report GhostKey server status and check whether configured ScriptMasterLabs authorities are reachable. Unknown stays unknown; no health result is fabricated.

Input Schema

{
  "type": "object",
  "properties": {},
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢ghostkey_catalog

List the capabilities actually exposed by this GhostKey MCP server and identify staged families without pretending they are callable.

Input Schema

{
  "type": "object",
  "properties": {},
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢ghostkey_quote(capability)

Explain how to obtain authoritative pricing for a GhostKey/SML paid capability. Pricing and settlement destination come from the fresh live HTTP 402 challenge, never a copied wallet or stale fixed price.

Input Schema

{
  "type": "object",
  "properties": {
    "capability": {
      "type": "string",
      "minLength": 1
    }
  },
  "additionalProperties": false,
  "$schema": "http://json-schema.org/draft-07/schema#"
}
⚪ghostkey_policy

Return GhostKey's operating, payment, upstream-rights, browser-session, and trusted-device policy for autonomous agents.

Input Schema

{
  "type": "object",
  "properties": {},
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟡ghostkey_device_pairing_create(label)

Create a one-time trusted-device enrollment capability. Requires GhostKey persistent trusted-device storage to be configured. The browser generates its own non-exportable P-256 private key; only the public key is uploaded.

Input Schema

{
  "type": "object",
  "properties": {
    "label": {
      "type": "string",
      "minLength": 1,
      "maxLength": 80
    }
  },
  "additionalProperties": false,
  "$schema": "http://json-schema.org/draft-07/schema#"
}
⚪ghostkey_device_pairing_status(pairing_id, pairing_code)

Resolve a one-time trusted-device pairing after the browser has enrolled. Requires the original pairing ID and pairing code and is available only until that pairing capability expires.

Input Schema

{
  "type": "object",
  "properties": {
    "pairing_id": {
      "type": "string",
      "format": "uuid"
    },
    "pairing_code": {
      "type": "string",
      "minLength": 20,
      "maxLength": 200
    }
  },
  "required": [
    "pairing_id",
    "pairing_code"
  ],
  "additionalProperties": false,
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟡ghostkey_session_create(allowed_origins, ttl_seconds, trusted_device_id)

Create a short-lived, origin-scoped browser delegation session. Optionally target a previously enrolled trusted device using its private 256-bit routing capability so its extension can claim the session automatically. The user still handles login/CAPTCHA and any new browser-origin permission themselves.

Input Schema

{
  "type": "object",
  "properties": {
    "allowed_origins": {
      "type": "array",
      "items": {
        "type": "string",
        "format": "uri"
      },
      "minItems": 1,
      "maxItems": 12
    },
    "ttl_seconds": {
      "type": "integer",
      "minimum": 60,
      "maximum": 3600
    },
    "trusted_device_id": {
      "type": "string",
      "pattern": "^[A-Za-z0-9_-]{43}$"
    }
  },
  "required": [
    "allowed_origins"
  ],
  "additionalProperties": false,
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🟢ghostkey_session_status(session_id, agent_token)

Check whether a scoped GhostKey browser session is alive and whether its user-controlled browser bridge has a fresh heartbeat.

Input Schema

{
  "type": "object",
  "properties": {
    "session_id": {
      "type": "string",
      "format": "uuid"
    },
    "agent_token": {
      "type": "string",
      "minLength": 20
    }
  },
  "required": [
    "session_id",
    "agent_token"
  ],
  "additionalProperties": false,
  "$schema": "http://json-schema.org/draft-07/schema#"
}
⚪ghostkey_session_action(session_id, agent_token, action, url, selector, ...)

Relay one authorized browser action into the user's already-authenticated browser. Actions: navigate, inspect, click, input, select, read, wait. Password/hidden fields and off-allowlist navigation are denied.

Input Schema

{
  "type": "object",
  "properties": {
    "session_id": {
      "type": "string",
      "format": "uuid"
    },
    "agent_token": {
      "type": "string",
      "minLength": 20
    },
    "action": {
      "type": "string",
      "enum": [
        "navigate",
        "inspect",
        "click",
        "input",
        "select",
        "read",
        "wait"
      ]
    },
    "url": {
      "type": "string",
      "format": "uri"
    },
    "selector": {
      "type": "string",
      "minLength": 1,
      "maxLength": 500
    },
    "text": {
      "type": "string",
      "maxLength": 4000
    },
    "attribute": {
      "type": "string",
      "maxLength": 100
    },
    "timeout_ms": {
      "type": "integer",
      "minimum": 1000,
      "maximum": 30000
    }
  },
  "required": [
    "session_id",
    "agent_token",
    "action"
  ],
  "additionalProperties": false,
  "$schema": "http://json-schema.org/draft-07/schema#"
}
🔴ghostkey_session_revoke(session_id, agent_token)

Immediately revoke a GhostKey browser delegation session and cancel queued work.

Input Schema

{
  "type": "object",
  "properties": {
    "session_id": {
      "type": "string",
      "format": "uuid"
    },
    "agent_token": {
      "type": "string",
      "minLength": 20
    }
  },
  "required": [
    "session_id",
    "agent_token"
  ],
  "additionalProperties": false,
  "$schema": "http://json-schema.org/draft-07/schema#"
}

Community

Rate this Server

Evidence

Recent observations

verifiedversion not recorded10 tools
verifiedversion not recorded4 tools
verifiedversion not recorded10 tools
verifiedversion not recorded4 tools