GhostKey — Route Paid APIs with x402
Find paid APIs, check access policy and price, and route x402 requests. No autonomous spending.
Should I use this
Quality & Safety
Findings (1)
- LOWin ghostkey_device_pairing_status
Based on automated analysis of tool definitions and protocol compliance.
Context Cost
This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.
Install
One-Click Install
Add this to your `claude_desktop_config.json` file:
{
"mcpServers": {
"ghostkey": {
"url": "https://ghostkey-mcp.onrender.com/mcp"
}
}
}Remote endpoints
https://ghostkey-mcp.onrender.com/mcpstreamable-httphttps://squeezeos-api.onrender.com/mcp/ghostkeystreamable-httpWhat it can do
Tool inventory
Tools (10)
🟢ghostkey_status
Report GhostKey server status and check whether configured ScriptMasterLabs authorities are reachable. Unknown stays unknown; no health result is fabricated.
Input Schema
{
"type": "object",
"properties": {},
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢ghostkey_catalog
List the capabilities actually exposed by this GhostKey MCP server and identify staged families without pretending they are callable.
Input Schema
{
"type": "object",
"properties": {},
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢ghostkey_quote(capability)
Explain how to obtain authoritative pricing for a GhostKey/SML paid capability. Pricing and settlement destination come from the fresh live HTTP 402 challenge, never a copied wallet or stale fixed price.
Input Schema
{
"type": "object",
"properties": {
"capability": {
"type": "string",
"minLength": 1
}
},
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}⚪ghostkey_policy
Return GhostKey's operating, payment, upstream-rights, browser-session, and trusted-device policy for autonomous agents.
Input Schema
{
"type": "object",
"properties": {},
"$schema": "http://json-schema.org/draft-07/schema#"
}🟡ghostkey_device_pairing_create(label)
Create a one-time trusted-device enrollment capability. Requires GhostKey persistent trusted-device storage to be configured. The browser generates its own non-exportable P-256 private key; only the public key is uploaded.
Input Schema
{
"type": "object",
"properties": {
"label": {
"type": "string",
"minLength": 1,
"maxLength": 80
}
},
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}⚪ghostkey_device_pairing_status(pairing_id, pairing_code)
Resolve a one-time trusted-device pairing after the browser has enrolled. Requires the original pairing ID and pairing code and is available only until that pairing capability expires.
Input Schema
{
"type": "object",
"properties": {
"pairing_id": {
"type": "string",
"format": "uuid"
},
"pairing_code": {
"type": "string",
"minLength": 20,
"maxLength": 200
}
},
"required": [
"pairing_id",
"pairing_code"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🟡ghostkey_session_create(allowed_origins, ttl_seconds, trusted_device_id)
Create a short-lived, origin-scoped browser delegation session. Optionally target a previously enrolled trusted device using its private 256-bit routing capability so its extension can claim the session automatically. The user still handles login/CAPTCHA and any new browser-origin permission themselves.
Input Schema
{
"type": "object",
"properties": {
"allowed_origins": {
"type": "array",
"items": {
"type": "string",
"format": "uri"
},
"minItems": 1,
"maxItems": 12
},
"ttl_seconds": {
"type": "integer",
"minimum": 60,
"maximum": 3600
},
"trusted_device_id": {
"type": "string",
"pattern": "^[A-Za-z0-9_-]{43}$"
}
},
"required": [
"allowed_origins"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢ghostkey_session_status(session_id, agent_token)
Check whether a scoped GhostKey browser session is alive and whether its user-controlled browser bridge has a fresh heartbeat.
Input Schema
{
"type": "object",
"properties": {
"session_id": {
"type": "string",
"format": "uuid"
},
"agent_token": {
"type": "string",
"minLength": 20
}
},
"required": [
"session_id",
"agent_token"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}⚪ghostkey_session_action(session_id, agent_token, action, url, selector, ...)
Relay one authorized browser action into the user's already-authenticated browser. Actions: navigate, inspect, click, input, select, read, wait. Password/hidden fields and off-allowlist navigation are denied.
Input Schema
{
"type": "object",
"properties": {
"session_id": {
"type": "string",
"format": "uuid"
},
"agent_token": {
"type": "string",
"minLength": 20
},
"action": {
"type": "string",
"enum": [
"navigate",
"inspect",
"click",
"input",
"select",
"read",
"wait"
]
},
"url": {
"type": "string",
"format": "uri"
},
"selector": {
"type": "string",
"minLength": 1,
"maxLength": 500
},
"text": {
"type": "string",
"maxLength": 4000
},
"attribute": {
"type": "string",
"maxLength": 100
},
"timeout_ms": {
"type": "integer",
"minimum": 1000,
"maximum": 30000
}
},
"required": [
"session_id",
"agent_token",
"action"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}🔴ghostkey_session_revoke(session_id, agent_token)
Immediately revoke a GhostKey browser delegation session and cancel queued work.
Input Schema
{
"type": "object",
"properties": {
"session_id": {
"type": "string",
"format": "uuid"
},
"agent_token": {
"type": "string",
"minLength": 20
}
},
"required": [
"session_id",
"agent_token"
],
"additionalProperties": false,
"$schema": "http://json-schema.org/draft-07/schema#"
}Community
Evidence