agent-transaction-control
Issue Agent Passports and verify agent authority before value moves. Signed verification records.
使うべきか
品質と安全性
検出事項(1)
- LOWvalidate_agent_commerce_readiness 内
ツール定義とプロトコルへの準拠に関する自動分析に基づいています。
コンテキストコスト
これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。
インストール
ワンクリックインストール
これを `claude_desktop_config.json` ファイルに追加してください:
{
"mcpServers": {
"agent-transaction-control": {
"url": "https://flint.network/mcp"
}
}
}リモートエンドポイント
https://flint.network/mcpstreamable-httpできること
ツール一覧
ツール(17)
🔴run_flint_scout(transaction, passport_id, merchant_reference, agent_claim, nonce, ...)
Use this tool to scan an intended agent transaction before execution. Two ways to pay for a scan. Credits first: buy credits once with scout_credits_topup (one $1.00 x402 payment for 100 scans), then call this tool with the same session_token and no payment_signature; FLINT draws one credit and runs the scan immediately, with no wallet signature for that call. x402 per call second: with no session_token, the first call returns a $0.01 x402 payment challenge without running the scan; a wallet-enabled client signs that challenge and retries with payment_signature. Either way, when the call returns a 402 instead of a result, the result carries pay_recipe with concrete next steps: an awal command, a local script, the credits path, and the browser flow. After a paid or credit-funded scan completes, FLINT returns a signed authority decision. When receipt issuance succeeds for a paid scan, it also returns a separately signed settlement receipt and durable receipt URL; otherwise it reports receipt unavailability without inviting a paid retry. Payment to FLINT is distinct from the transaction being scanned and is not proof of agent authority.
入力スキーマ
{
"type": "object",
"properties": {
"transaction": {
"type": "object",
"properties": {
"action": {
"type": "string",
"minLength": 1,
"maxLength": 128,
"description": "Intended agent action, such as stablecoin_transfer or paid_api_access."
},
"reference": {
"description": "Optional invoice, order, or merchant transaction reference.",
"type": "string",
"minLength": 1,
"maxLength": 256
},
"chain": {
"type": "string",
"minLength": 1,
"maxLength": 161,
"description": "CAIP-2 chain identifier, such as eip155:8453."
},
"token": {
"description": "Optional token identity for the intended transaction.",
"type": "object",
"properties": {
"symbol": {
"type": "string",
"minLength": 1,
"maxLength": 64
},
"issuer": {
"type": "string",
"minLength": 1,
"maxLength": 64
},
"contract": {
"type": "string",
"minLength": 1,
"maxLength": 256
}
},
"additionalProperties": false
},
"amount_display": {
"type": "string",
"pattern": "^(?:0|[1-9][0-9]{0,77})(?:\\.[0-9]{1,18})?$",
"description": "Non-negative decimal amount for the intended transaction."
},
"counterparty_address": {
"type": "string",
"minLength": 1,
"maxLength": 256,
"description": "Intended merchant, seller, or recipient address."
},
"direction": {
"description": "Transaction direction. Defaults to debit_from_agent.",
"type": "string",
"minLength": 1,
"maxLength": 256
}
},
"required": [
"action",
"chain",
"amount_display",
"counterparty_address"
],
"additionalProperties": false
},
"passport_id": {
"description": "Optional FLINT Agent Passport. Verified payer-wallet and mandate bindings may strengthen the decision.",
"type": "string",
"maxLength": 128,
"pattern": "^kya_[A-Za-z0-9_-]+$"
},
"merchant_reference": {
"description": "Optional merchant reference. Must match transaction.reference when both are supplied.",
"type": "string",
"minLength": 1,
"maxLength": 256
},
"agent_claim": {
"description": "Optional bounded agent hints. Self-asserted values do not establish authority.",
"type": "object",
"properties": {
"agent_id": {
"type": "string",
"minLength": 1,
"maxLength": 256
},
"agent_runtime_hint": {
"type": "string",
"minLength": 1,
"maxLength": 256
},
"wallet_type": {
"type": "string",
"minLength": 1,
"maxLength": 256
}
},
"additionalProperties": false
},
"nonce": {
"description": "Replay-protection nonce. Generated automatically if omitted.",
"type": "string",
"minLength": 8,
"maxLength": 128
},
"timestamp": {
"description": "ISO-8601 request timestamp. Generated automatically if omitted.",
"type": "string",
"format": "date-time",
"pattern": "^(?:(?:\\d\\d[2468][048]|\\d\\d[13579][26]|\\d\\d0[48]|[02468][048]00|[13579][26]00)-02-29|\\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\\d|30)|(?:02)-(?:0[1-9]|1\\d|2[0-8])))T(?:(?:[01]\\d|2[0-3]):[0-5]\\d(?::[0-5]\\d(?:\\.\\d+)?)?(?:Z))$"
},
"payment_signature": {
"description": "Opaque caller-signed x402 PAYMENT-SIGNATURE value from a wallet-enabled client. Never provide a private key or seed phrase.",
"type": "string",
"minLength": 1,
"maxLength": 8192,
"pattern": "^[\\x20-\\x7E]+$"
},
"session_token": {
"description": "Optional agent session token from auth_verify_otp. When present with no payment_signature, FLINT draws one prepaid Scout credit instead of requiring an x402 payment for this call. Buy credits first with scout_credits_topup.",
"type": "string",
"pattern": "^flint_sess_[A-Za-z0-9_-]{40,}$"
}
},
"required": [
"transaction"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}⚪issue_authorization_record(agent_claim, transaction, declared_scope, partner_id, merchant_reference, ...)
Use this tool before an AI agent initiates a payment, paid API call, checkout action, stablecoin transfer, x402 request, or delegated commercial transaction. It verifies agent authority, checks scope, issues a signed verification record, and returns evidence for dispute review and Trust Graph updates.
入力スキーマ
{
"type": "object",
"properties": {
"agent_claim": {
"description": "Agent identity, principal hint, runtime hint, optional act_chain delegation lineage, optional spiffe_svid workload identity, optional tool_manifest capabilities, and related claims.",
"type": "object",
"propertyNames": {
"type": "string"
},
"additionalProperties": {}
},
"transaction": {
"type": "object",
"propertyNames": {
"type": "string"
},
"additionalProperties": {},
"description": "Intended transaction or paid access request. Must include amount_display."
},
"declared_scope": {
"description": "Financial, temporal, and counterparty limits for delegated authority.",
"type": "object",
"propertyNames": {
"type": "string"
},
"additionalProperties": {}
},
"partner_id": {
"description": "Merchant or platform identifier. Defaults to sandbox_public.",
"type": "string"
},
"merchant_reference": {
"description": "Merchant order, invoice, or API request reference.",
"type": "string"
},
"nonce": {
"description": "Replay-protection nonce. Generated automatically if omitted.",
"type": "string"
},
"timestamp": {
"description": "ISO timestamp. Generated automatically if omitted.",
"type": "string"
}
},
"required": [
"transaction"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢verify_agent_authority(jws, jwks_url, expected_partner_id, expected_merchant_reference)
Use this tool when a merchant or API seller receives a signed verification record from an agent. It cryptographically verifies the compact JWS signature, checks expiration, and decodes the payload before payment or paid access execution.
入力スキーマ
{
"type": "object",
"properties": {
"jws": {
"type": "string",
"description": "Compact JWS signed verification record."
},
"jwks_url": {
"description": "Optional JWKS URL. Must be on the FLINT origin. Defaults to the FLINT production JWKS.",
"type": "string",
"format": "uri"
},
"expected_partner_id": {
"type": "string",
"minLength": 1,
"maxLength": 128,
"description": "Partner identifier expected in the authorization record."
},
"expected_merchant_reference": {
"type": "string",
"minLength": 1,
"maxLength": 256,
"description": "Current transaction or resource reference expected in the authorization record."
}
},
"required": [
"jws",
"expected_partner_id",
"expected_merchant_reference"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢lookup_agent_reputation(flint_agent_id)
Use this tool to query the FLINT Trust Graph for a partner-scoped agent's historical reputation before permitting a payment, paid API call, checkout action, x402 request, or delegated commercial transaction. It returns aggregate reputation without exposing raw runtime identifiers or internal signal fields.
入力スキーマ
{
"type": "object",
"properties": {
"flint_agent_id": {
"type": "string",
"pattern": "^faid_[a-f0-9]{24}$",
"description": "Partner-scoped FLINT agent identifier."
}
},
"required": [
"flint_agent_id"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢create_flint_trust_manifest(partner_id, domain, name, description, accepted_principals, ...)
Use this tool when a merchant, API seller, MCP tool provider, x402 endpoint, or agent storefront needs a `/.well-known/flint.json` Trust Manifest. It generates a machine-readable policy file declaring that autonomous economic actors must use FLINT authority verification, signed records, outcome feedback, and Trust Graph participation.
入力スキーマ
{
"type": "object",
"properties": {
"partner_id": {
"description": "Merchant or platform identifier. Defaults to sandbox_public.",
"type": "string"
},
"domain": {
"description": "Merchant or API seller origin, such as https://api.example.com.",
"type": "string",
"format": "uri"
},
"name": {
"description": "Human-readable merchant, API, or platform name.",
"type": "string"
},
"description": {
"description": "Short description of the protected commerce surface.",
"type": "string"
},
"accepted_principals": {
"description": "Trusted delegated-authority principal issuers.",
"type": "array",
"items": {
"type": "string"
}
},
"supported_actions": {
"description": "Agent commerce actions this endpoint supports.",
"type": "array",
"items": {
"type": "string"
}
},
"max_transaction_amount": {
"description": "Maximum single transaction amount before step-up or review.",
"type": "number"
},
"contact_email": {
"description": "Administrative contact for agent integration issues.",
"type": "string",
"format": "email",
"pattern": "^(?!\\.)(?!.*\\.\\.)([A-Za-z0-9_'+\\-\\.]*)[A-Za-z0-9_+-]@([A-Za-z0-9][A-Za-z0-9\\-]*\\.)+[A-Za-z]{2,}$"
},
"openapi_url": {
"description": "Public OpenAPI document for the merchant or API seller.",
"type": "string",
"format": "uri"
},
"jwks_url": {
"description": "FLINT JWKS URL. Defaults to FLINT production JWKS.",
"type": "string",
"format": "uri"
},
"verify_endpoint": {
"description": "FLINT verification endpoint. Defaults to FLINT production `/api/verify`.",
"type": "string",
"format": "uri"
},
"outcome_endpoint": {
"description": "Outcome feedback endpoint. Defaults to FLINT production `/api/outcomes`.",
"type": "string",
"format": "uri"
},
"mcp_endpoint": {
"description": "FLINT MCP endpoint. Defaults to FLINT production `/mcp`.",
"type": "string",
"format": "uri"
}
},
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢generate_authorization_scope(max_amount_per_tx, asset, time_window_end, allowed_counterparties, allowed_actions, ...)
Use this tool when an agent commerce workflow needs a well-formed delegated authorization scope before issuing a signed verification record. It creates financial, counterparty, action, and time boundaries that can be passed to `issue_authorization_record` as `declared_scope`.
入力スキーマ
{
"type": "object",
"properties": {
"max_amount_per_tx": {
"type": "number",
"exclusiveMinimum": 0,
"description": "Maximum amount allowed per transaction."
},
"asset": {
"description": "Asset or unit, such as USD, USDC, or credits. Defaults to USD.",
"type": "string"
},
"time_window_end": {
"type": "string",
"format": "date-time",
"pattern": "^(?:(?:\\d\\d[2468][048]|\\d\\d[13579][26]|\\d\\d0[48]|[02468][048]00|[13579][26]00)-02-29|\\d{4}-(?:(?:0[13578]|1[02])-(?:0[1-9]|[12]\\d|3[01])|(?:0[469]|11)-(?:0[1-9]|[12]\\d|30)|(?:02)-(?:0[1-9]|1\\d|2[0-8])))T(?:(?:[01]\\d|2[0-3]):[0-5]\\d(?::[0-5]\\d(?:\\.\\d+)?)?(?:Z))$",
"description": "ISO-8601 timestamp for scope expiration."
},
"allowed_counterparties": {
"description": "Merchant references, wallet addresses, API hosts, or counterparties allowed by this scope.",
"type": "array",
"items": {
"type": "string"
}
},
"allowed_actions": {
"description": "Permitted actions, such as checkout, paid_api_access, x402_request, or stablecoin_transfer.",
"type": "array",
"items": {
"type": "string"
}
},
"principal_id": {
"description": "Accountable principal granting delegated authority.",
"type": "string"
},
"purpose": {
"description": "Business purpose or task label for the delegated authority.",
"type": "string"
}
},
"required": [
"max_amount_per_tx",
"time_window_end"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢validate_agent_commerce_readiness(architecture_description)
Use this tool when reviewing a commerce architecture, API marketplace, paid MCP tool, x402 endpoint, or autonomous checkout flow. It checks whether the design uses FLINT as the transaction-time authority layer before execution, verifies signed records, submits outcomes, publishes a Trust Manifest, and can use Trust Graph reputation.
入力スキーマ
{
"type": "object",
"properties": {
"architecture_description": {
"type": "string",
"minLength": 20,
"description": "Summary of the payment, paid API access, x402, MCP, or checkout flow."
}
},
"required": [
"architecture_description"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢issue_agent_passport(agent, mandate, session_token, supersede_management_token)
Use this tool to issue a free FLINT Agent Passport: a hybrid-signed, verifiable identity credential for an autonomous agent. Before calling it, ask the principal for the accountable controller_id and controller_type, allowed actions, maximum transaction amount, and wallet address if one exists. Do not infer or invent authority. For the strongest available setup, authenticate first and mint with the principal-supplied identity and mandate. The zero-config path only needs agent.agent_name or agent.agent_id, but that result is identity-only and is not ready to transact until the missing authority is supplied. A missing controller requires a corrected remint because signed identity is immutable; a missing mandate can be added later. The passport signs identity only; the spending mandate is separate, mutable config that can be updated later without reissuing the passport. Pass session_token, from auth_verify_otp, to mint owned: the passport binds to your authenticated account immediately and there is no claim step or claim_url. Omit session_token to mint anonymously instead; that returns a one-time claim_url and the passport stays unclaimed until someone signs in and claims it. controller_id identifies who is accountable on the signed identity, which is not the same as the FLINT account that owns the passport; controller_name is a separate, optional, human-readable display label. Allowed actions must come from the FLINT mandate vocabulary: commerce_purchase, checkout.purchase, invoice.pay, subscription.renew, refund.request, quote.retrieve, x402_verification_purchase, stablecoin_transfer, paid_api_access, x402_request, agent_checkout, delegated_spending, project.read. Pass ["ALL"] as a preset to grant every action in one step; the stored mandate then expands to the full list and records the preset. Unknown strings are kept for backward compatibility but are reported back as unknown so the caller can fix them. The signed identity is immutable once minted, so a wrong agent_id, controller_id, or controller_type cannot be edited in place. Fix it by reminting with the corrected fields. A remint that reuses the same agent_id and controller_id supersedes a prior UNCLAIMED passport for that pair ONLY when this mint is authorized: either session_token proves the same controller (controller_assurance verified or command), or supersede_management_token matches that specific prior passport's own management token (the raw claim token from its claim_url). Without either, the prior is left alone, still indexed, and reported back as related_passports with a warning, so a stranger cannot anonymously remint someone else's controller_id and agent_id to burn their pending claim. A prior CLAIMED passport is never superseded automatically; it is listed back as existing_claimed_passports with a warning so you can review it by hand. Returns a public, resolvable passport URL and, when minted anonymously, a one-time claim link.
入力スキーマ
{
"type": "object",
"properties": {
"agent": {
"type": "object",
"propertyNames": {
"type": "string"
},
"additionalProperties": {},
"description": "Agent identity. Only agent_name or agent_id is required for an identity-only mint. Ask the principal for controller_id and controller_type before minting a Passport intended for transactions. Optional fields include controller_name, wallet_address, and attestations. Never invent principal authority."
},
"mandate": {
"description": "Principal-supplied mutable authority captured at issue (NOT part of the passport signature): allowed_actions, max_transaction_amount, notes. Ask the principal for these values and never infer them. Update later without reissuing the passport.",
"type": "object",
"propertyNames": {
"type": "string"
},
"additionalProperties": {}
},
"session_token": {
"description": "Optional agent session token from auth_verify_otp. When present the passport is owned by that account at issuance and no claim step is needed.",
"type": "string",
"pattern": "^flint_sess_[A-Za-z0-9_-]{40,}$"
},
"supersede_management_token": {
"description": "Optional. The management_token (raw claim token) of a specific prior UNCLAIMED passport with the same agent_id and controller_id. Presenting it authorizes superseding that prior passport even with no session_token, since it proves possession of that prior's own claim link.",
"type": "string"
}
},
"required": [
"agent"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢get_agent_passport(passport_id, session_token)
Use this tool to resolve a public FLINT Agent Passport by passport_id. It returns compact identity, mandate, status, ownership, and the public passport URL without echoing the full signed envelope. session_token is optional and not required to read a passport; the lookup itself is public.
入力スキーマ
{
"type": "object",
"properties": {
"passport_id": {
"type": "string",
"pattern": "^kya_",
"description": "FLINT Agent Passport id, beginning with kya_."
},
"session_token": {
"description": "Optional agent session token from auth_verify_otp.",
"type": "string",
"pattern": "^flint_sess_[A-Za-z0-9_-]{40,}$"
}
},
"required": [
"passport_id"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟡update_agent_mandate(passport_id, mandate, management_token, session_token)
Use this tool to update mutable mandate config for an existing FLINT Agent Passport. This updates allowed actions, amount limits, or notes only. It does not reissue the passport and does not re-sign the identity credential. If the passport is owned (claimed), pass session_token for the owning account; management_token is only needed while the passport is unclaimed. Allowed actions must come from the FLINT mandate vocabulary: commerce_purchase, checkout.purchase, invoice.pay, subscription.renew, refund.request, quote.retrieve, x402_verification_purchase, stablecoin_transfer, paid_api_access, x402_request, agent_checkout, delegated_spending, project.read. Pass ["ALL"] as a preset to grant every action in one step; the stored mandate then expands to the full list and records the preset. Unknown strings are kept for backward compatibility but are reported back as unknown so the caller can fix them.
入力スキーマ
{
"type": "object",
"properties": {
"passport_id": {
"type": "string",
"pattern": "^kya_",
"description": "FLINT Agent Passport id, beginning with kya_."
},
"mandate": {
"type": "object",
"propertyNames": {
"type": "string"
},
"additionalProperties": {},
"description": "Mutable mandate config to update: allowed_actions, max_transaction_amount, notes."
},
"management_token": {
"description": "Claim token required while the Passport is unclaimed.",
"type": "string",
"minLength": 32,
"maxLength": 128
},
"session_token": {
"description": "Optional agent session token from auth_verify_otp, used once the passport is owned.",
"type": "string",
"pattern": "^flint_sess_[A-Za-z0-9_-]{40,}$"
}
},
"required": [
"passport_id",
"mandate"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢auth_request_otp(email)
Use this tool first in the agent-native authenticate-then-mint flow. It asks FLINT to email a one-time sign-in code to the given inbox address. Read the code from that inbox, then call auth_verify_otp with the same email and the code. Authenticating first means the passport you mint afterward is owned by the account immediately, with no separate claim step.
入力スキーマ
{
"type": "object",
"properties": {
"email": {
"type": "string",
"maxLength": 254,
"format": "email",
"pattern": "^(?!\\.)(?!.*\\.\\.)([A-Za-z0-9_'+\\-\\.]*)[A-Za-z0-9_+-]@([A-Za-z0-9][A-Za-z0-9\\-]*\\.)+[A-Za-z]{2,}$",
"description": "Inbox address that will receive the one-time sign-in code."
}
},
"required": [
"email"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟡auth_verify_otp(email, code, label)
Use this tool right after auth_request_otp, with the code from the inbox. On success it returns session_token. Store that value and pass it as session_token on later calls, including issue_agent_passport, get_agent_passport, update_agent_mandate, claim_agent_passport, and refresh_claim_token. Never print or log session_token; treat it like a password.
入力スキーマ
{
"type": "object",
"properties": {
"email": {
"type": "string",
"maxLength": 254,
"format": "email",
"pattern": "^(?!\\.)(?!.*\\.\\.)([A-Za-z0-9_'+\\-\\.]*)[A-Za-z0-9_+-]@([A-Za-z0-9][A-Za-z0-9\\-]*\\.)+[A-Za-z]{2,}$",
"description": "The same inbox address auth_request_otp was called with."
},
"code": {
"type": "string",
"minLength": 4,
"maxLength": 8,
"description": "The one-time sign-in code from the inbox."
},
"label": {
"description": "Optional human-readable label for this session, such as the agent or workflow name.",
"type": "string",
"minLength": 1,
"maxLength": 120
}
},
"required": [
"email",
"code"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}⚪claim_agent_passport(passport_id, claim_token, session_token)
Use this tool to attach an anonymously minted, unclaimed FLINT Agent Passport to an authenticated FLINT account. Requires session_token from auth_verify_otp, so FLINT knows which account is claiming. Pass claim_token from the mint's claim_url, or omit it when this same session already holds a pending claim for this passport_id. Once claimed the passport is owned and Sentinel protection turns on. A passport can only be claimed once; if the token was already used or lost, call refresh_claim_token for a fresh one instead of trying to remint.
入力スキーマ
{
"type": "object",
"properties": {
"passport_id": {
"type": "string",
"pattern": "^kya_",
"description": "FLINT Agent Passport id, beginning with kya_."
},
"claim_token": {
"description": "The one-time claim token from claim_url. Omit only when this session already started a pending claim for this passport.",
"type": "string",
"minLength": 16,
"maxLength": 256
},
"session_token": {
"type": "string",
"pattern": "^flint_sess_[A-Za-z0-9_-]{40,}$",
"description": "Agent session token from auth_verify_otp for the account that is claiming this passport."
}
},
"required": [
"passport_id",
"session_token"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}⚪refresh_claim_token(passport_id, management_token, session_token)
Use this tool when a claim link is lost, expired, or was already consumed for a passport that is still unclaimed. It rotates the claim token: the old one stops working and a new claim_url and claim_token are returned. This is the fix for a lost or consumed claim token; do not remint the passport instead, reminting only supersedes prior unclaimed passports and does not recover a lost claim link. Authorize with the current management_token (the raw claim token, even one about to be superseded), or with session_token when this session originally requested the claim or minted the passport.
入力スキーマ
{
"type": "object",
"properties": {
"passport_id": {
"type": "string",
"pattern": "^kya_",
"description": "FLINT Agent Passport id, beginning with kya_."
},
"management_token": {
"description": "The current claim or management token for this passport.",
"type": "string",
"minLength": 16,
"maxLength": 256
},
"session_token": {
"description": "Optional agent session token from auth_verify_otp, used when management_token is unavailable.",
"type": "string",
"pattern": "^flint_sess_[A-Za-z0-9_-]{40,}$"
}
},
"required": [
"passport_id"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🔴scout_credits_topup(session_token, topup_id, payment_signature)
Call once with session_token to get a pay_url; pay it with awal (`awal x402 pay -X POST -d '{}' <pay_url>`) or any x402 client; no headers needed on the pay request. Or pass payment_signature to settle through this tool. One $1.00 x402 payment buys 100 FLINT Scout scan credits, matching today's $0.01 x402 price without signing a payment for every run_flint_scout call. Requires session_token from auth_verify_otp so the credits land on that account; call auth_request_otp then auth_verify_otp first if you do not have one. With no topup_id, the first call creates a fresh top-up intent (an sct_ id good for 24 hours) and returns its pay_url alongside the same $1.00 x402 challenge. Pass topup_id to retry paying or settling that same intent instead of creating a new one. Once credited, call run_flint_scout with the same session_token and no payment_signature to draw one credit per scan.
入力スキーマ
{
"type": "object",
"properties": {
"session_token": {
"type": "string",
"pattern": "^flint_sess_[A-Za-z0-9_-]{40,}$",
"description": "Agent session token from auth_verify_otp. Credits are added to this account."
},
"topup_id": {
"description": "Optional existing top-up intent id from a prior call, to retry paying or settling it instead of creating a new one. Intents expire 24 hours after creation.",
"type": "string",
"pattern": "^sct_[0-9A-Za-z]{20,32}$"
},
"payment_signature": {
"description": "Opaque caller-signed x402 PAYMENT-SIGNATURE value from a wallet-enabled client. Never provide a private key or seed phrase.",
"type": "string",
"minLength": 1,
"maxLength": 8192,
"pattern": "^[\\x20-\\x7E]+$"
}
},
"required": [
"session_token"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}🟢scout_credits_balance(session_token)
Use this tool to check a signed-in account's FLINT Scout credit balance and recent ledger activity (topups, debits, refunds). Requires session_token from auth_verify_otp.
入力スキーマ
{
"type": "object",
"properties": {
"session_token": {
"type": "string",
"pattern": "^flint_sess_[A-Za-z0-9_-]{40,}$",
"description": "Agent session token from auth_verify_otp for the account to check."
}
},
"required": [
"session_token"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}⚪report_scout_outcome(record_id, outcome, tx_hash, chain, note, ...)
Use this tool after a run_flint_scout scan to report what actually happened: whether the scanned transaction was executed, held, cancelled, or executed despite a BLOCK verdict. FLINT cannot stop a wallet from transacting; this is the enforce-or-attest half of the contract. Authorize with session_token when the caller's account owns the presented passport, or with caller_binding_token from the scan's caller_obligation block when acting anonymously. Executing after BLOCK is recorded on the record as an override and alerts the passport owner.
入力スキーマ
{
"type": "object",
"properties": {
"record_id": {
"type": "string",
"pattern": "^frv_",
"description": "The signed record id returned by run_flint_scout, beginning with frv_."
},
"outcome": {
"type": "string",
"enum": [
"executed",
"held",
"executed_despite_block",
"cancelled"
],
"description": "What actually happened to the scanned transaction."
},
"tx_hash": {
"description": "On-chain transaction hash. Optional, but expected when outcome starts with executed.",
"type": "string",
"minLength": 4,
"maxLength": 256
},
"chain": {
"description": "CAIP-2 chain identifier for tx_hash, such as eip155:8453.",
"type": "string",
"minLength": 1,
"maxLength": 161
},
"note": {
"description": "Optional free-text note, at most 280 characters.",
"type": "string",
"maxLength": 280
},
"session_token": {
"description": "Agent session token from auth_verify_otp, when the caller's account owns the presented passport.",
"type": "string",
"pattern": "^flint_sess_[A-Za-z0-9_-]{40,}$"
},
"caller_binding_token": {
"description": "The caller_binding_token from the scan's caller_obligation block, for an anonymous caller reporting its own outcome without an account.",
"type": "string",
"minLength": 16,
"maxLength": 256
}
},
"required": [
"record_id",
"outcome"
],
"$schema": "http://json-schema.org/draft-07/schema#"
}推奨プロンプト
validate_agent_commerce_readinessvalidate_agent_commerce_readinessコミュニティ
エビデンス