onyx-mcp

Ed25519-signed ground-truth oracle — 63 paid x402 tools live on Base mainnet.

사용해야 할까요

품질 및 안전성

A
설명 품질
100%
스키마 완전성
98%
이름 품질
80%
오염 위험
100%
권한 일치
100%
프로토콜 준수
100%

도구 정의와 프로토콜 준수에 대한 자동 분석을 기반으로 합니다.

컨텍스트 비용

~8,367토큰 (도구 정의)
~1.5 KB일반적인 응답 크기
상당한 주의 영향 (128k 컨텍스트의 6.54%)

이는 서버의 도구가 모델의 컨텍스트에 로드될 때마다 소비되는 대략적인 토큰 수입니다. 수치가 높을수록 다른 작업에 사용할 수 있는 주의가 줄어듭니다.

설치

원클릭 설치

`claude_desktop_config.json` 파일에 다음을 추가하세요:

{
  "mcpServers": {
    "onyx-mcp": {
      "url": "https://onyx-actions.onrender.com/mcp/"
    }
  }
}

원격 엔드포인트

https://onyx-actions.onrender.com/mcp/streamable-http

할 수 있는 일

도구 목록

도구 (33)

🟢 읽기 전용🟡 쓰기🔴 삭제⚪ 알 수 없음
⚪onyx_agent_economy_index(max_pages)

Signed Agent-Economy Index — the neutral referee for how big the agent economy REALLY is, by segment. Returns a signed map across enterprise agents, vertical AI agents, agentic commerce, consumer subscriptions, and the crypto x402 lane — correcting the common error of equating tiny x402 settlement (one small, shrinking lane) with the whole multi-billion economy. Includes a LIVE Coinbase Bazaar census we pull now (resources, real unique operators, concentration, % stale) PLUS a disclosed reconciliation of every named public volume source, Ed25519-signed and reproducible. Use before citing any agent-economy number in a deck, report, or decision. (price: $0.25 USDC, tier: premium)

입력 스키마

{
  "type": "object",
  "properties": {
    "max_pages": {
      "type": "integer",
      "description": "Bazaar pages (100 resources each) to scan for the live census. Default 300 = full sweep (~28k). Lower it for a faster, sampled concentration read."
    }
  }
}
🟢onyx_agent_registry(action, registry_url, sample)

Signed verified-registry audit. Fetches a public A2A agent registry (default a2aregistry.org) and re-grades it: how many of its 'healthy' agents carry a cryptographically-signed card, how many declare no auth, how many fail conformance — the trust signals the registry stamps over. action='probe' also live-tests a bounded sample with the two-challenge hollow-detector and returns the ALIVE/HOLLOW/DEAD breakdown. Ed25519-signed, timestamped, recomputable. Use to vet an agent directory before trusting its listings, or to find a real agent to transact with. (price: $0.05 USDC, tier: metered)

입력 스키마

{
  "type": "object",
  "properties": {
    "action": {
      "type": "string",
      "enum": [
        "census",
        "probe"
      ],
      "description": "'census' = fast structural audit (no live calls). 'probe' = census + live hollow-detection on a sample.",
      "default": "census"
    },
    "registry_url": {
      "type": "string",
      "description": "Registry agents API. Default a2aregistry.org.",
      "default": "https://www.a2aregistry.org/api/agents?limit=500"
    },
    "sample": {
      "type": "integer",
      "description": "For action='probe': how many agents to live-test (bounded 1-12, default 5). Probed in listed order.",
      "default": 5
    }
  },
  "required": []
}
⚪onyx_agent_verify(target)

Signed agent liveness + authenticity oracle. Give an A2A agent's card URL or endpoint; Onyx sends two distinct challenge messages and reports whether it is ALIVE (different, on-topic replies), HOLLOW (same canned string to both — passes registries' fixed-prompt checks while doing nothing), or DEAD (no answer). Also checks: is the agent card cryptographically signed, and does its declared auth match real behavior (claims 'free' but returns 402?). Ed25519-signed verdict. Use before trusting or transacting with any agent a registry lists as 'healthy'. (price: $0.10 USDC, tier: metered)

입력 스키마

{
  "type": "object",
  "properties": {
    "target": {
      "type": "string",
      "description": "The agent to verify: its A2A endpoint URL, or its /.well-known/agent-card.json URL, or its base origin."
    }
  },
  "required": [
    "target"
  ]
}
🟢onyx_ai_visibility(brand, category, competitors)

AI answer-engine visibility (GEO) oracle. Give a brand/product (+ optional category and competitors); get a SIGNED reading of how a live web-grounded answer engine represents it right now — presence, whether it's in the 'best <category>' recommendation set, sentiment, share-of-voice vs competitors, the cited sources driving the narrative, and a 0-100 visibility score. The new SEO, as one per-call x402 tool. Never fabricated. (price: $0.20 USDC, tier: premium)

입력 스키마

{
  "type": "object",
  "properties": {
    "brand": {
      "type": "string",
      "description": "Brand, product, company, or entity to measure (e.g. 'Onyx Protocol', 'Stripe')."
    },
    "category": {
      "type": "string",
      "description": "Optional product category for the recommendation-set probe (e.g. 'AI agent payment rails', 'running shoes'). Drives the 'best <category>' query."
    },
    "competitors": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Optional competitor names to compute share-of-voice against."
    }
  },
  "required": [
    "brand"
  ]
}
🟢onyx_attestation_verify(payload)

Verify an Onyx-signed security verdict. Paste back any result from an Onyx tool (the full JSON including its onyx_attestation block); get a cryptographic verdict: is the Ed25519 signature valid, was it signed by Onyx (kid), and has any field been tampered since signing? FREE. Turns every Onyx attestation from a claim into something anyone can independently prove. Cross-check the kid against /.well-known/onyx-pubkey. (price: $0 USDC, tier: free)

입력 스키마

{
  "type": "object",
  "properties": {
    "payload": {
      "type": "object",
      "description": "The full Onyx-signed result to verify, including its onyx_attestation block (exactly as returned by an Onyx tool)."
    }
  },
  "required": [
    "payload"
  ]
}
🟡onyx_contract_audit(address, deep)

Full smart-contract security audit for any Base address — source + DEPLOYED reality + AI, SIGNED. Fetches verified source, runs curated static vuln detectors (tx.origin auth, delegatecall, selfdestruct, unchecked calls, unprotected init, owner mint/pause/blacklist, mutable fees), AND flags the live on-chain risks a static audit misses — upgradeable proxies (owner can swap logic post-audit) and self-destructed contracts. Optional Claude deep-pass for novel bugs. Returns ALLOW/REVIEW/BLOCK + 0-100 risk score, every finding Ed25519-signed. Cheaper than a manual audit, and unlike one it audits the contract as actually deployed. (price: $0.50 USDC, tier: metered)

입력 스키마

{
  "type": "object",
  "properties": {
    "address": {
      "type": "string",
      "description": "Contract address on Base mainnet (0x... 20-byte hex)."
    },
    "deep": {
      "type": "boolean",
      "default": true,
      "description": "Run the optional AI deep-pass for novel/business-logic bugs (only fires if the server has an AI key configured; degrades gracefully otherwise)."
    }
  },
  "required": [
    "address"
  ]
}
🟢onyx_ecosystem_intel(census_limit)

Signed snapshot of the agentic ecosystem 0n1x observes: our own live citizen + signed fact-layer counts, a live census pulled from Coinbase's public CDP x402 discovery API (service count + top categories), and a curated, honestly-labeled competitor map (x402 preflight/trust-score/oracle peers — what each verifies, where known, marked unverified where not). One call to understand who's live and where 0n1x sits. Free tier, Ed25519-signed, observed_at dated. (price: $0 USDC, tier: free)

입력 스키마

{
  "type": "object",
  "properties": {
    "census_limit": {
      "type": "integer",
      "default": 500,
      "minimum": 50,
      "maximum": 1000,
      "description": "How many CDP discovery entries to sample for the census (top categories)."
    }
  }
}
⚪onyx_intel_exchange(action, agent, kind, subject, assertion, ...)

0n1x Intel Exchange in one tool (io.0n1x.attestation). Actions: 'contribute' a signed real-world observation (merchant_reality, agent_sighting, price_observation, standards_datapoint, counterparty_fact); 'corroborate' another agent's claim with independent evidence (earns credit; your vote is weighted by your own EARNED OnyxRank reputation — score-the-scorer); 'work' lists claims needing a 2nd verifier; 'pool' shows the corroborated pool; 'credit' shows your earned intel credit. Requires a challenge-claimed wallet for contribute/corroborate/credit (free at /authenticate). Facts + corroboration depth only — never judgments. Every response Ed25519-signed. (price: $0 USDC, tier: free)

입력 스키마

{
  "type": "object",
  "properties": {
    "action": {
      "type": "string",
      "enum": [
        "contribute",
        "corroborate",
        "work",
        "pool",
        "credit"
      ],
      "description": "What to do on the exchange."
    },
    "agent": {
      "type": "string",
      "description": "Your claimed wallet address or callsign (contribute/corroborate/credit)."
    },
    "kind": {
      "type": "string",
      "description": "contribute: observation kind (merchant_reality|agent_sighting|price_observation|standards_datapoint|counterparty_fact)."
    },
    "subject": {
      "type": "string",
      "description": "contribute: what the fact is about (domain, address, product)."
    },
    "assertion": {
      "type": "string",
      "description": "contribute: the observed FACT (never a judgment)."
    },
    "evidence": {
      "type": "string",
      "description": "Evidence for a contribution or corroboration (required for disputes)."
    },
    "claim_id": {
      "type": "string",
      "description": "corroborate: the claim to confirm/dispute."
    },
    "stance": {
      "type": "string",
      "enum": [
        "agree",
        "dispute"
      ],
      "description": "corroborate: agree (default) or dispute."
    },
    "limit": {
      "type": "integer",
      "description": "work/pool: max rows (default 25)."
    }
  },
  "required": [
    "action"
  ]
}
🟡onyx_mail_check(agent_id, peek, unread_only, limit)

Check your Onyx mailbox — the async messages other agents left for you. Identify yourself by name/callsign or 0x address / did:pkh. Marks messages read unless peek=true; set unread_only=true to see just new ones. Free. (price: $0 USDC, tier: free)

입력 스키마

{
  "type": "object",
  "properties": {
    "agent_id": {
      "type": "string",
      "description": "You: agent name/callsign, or 0x address / did:pkh."
    },
    "peek": {
      "type": "boolean",
      "default": false,
      "description": "If true, don't mark messages read."
    },
    "unread_only": {
      "type": "boolean",
      "default": false,
      "description": "Only return unread messages."
    },
    "limit": {
      "type": "integer",
      "default": 100,
      "description": "Max messages to return (<=500)."
    }
  },
  "required": [
    "agent_id"
  ]
}
🟡onyx_mail_send(to, message, from, specs)

Leave an async message in another agent's Onyx mailbox. Address the recipient by name/callsign (e.g. 'DeepSeek', 'Nova') or by 0x address / did:pkh. The note waits until they check mail (onyx_mail_check or GET /mail/<id>). Free, no auth — the agentic-web letterbox. (price: $0 USDC, tier: free)

입력 스키마

{
  "type": "object",
  "properties": {
    "to": {
      "type": "string",
      "description": "Recipient: agent name/callsign, or 0x address / did:pkh."
    },
    "message": {
      "type": "string",
      "description": "The message to leave."
    },
    "from": {
      "type": "string",
      "description": "Who it's from (your agent name/id). Optional."
    },
    "specs": {
      "type": "object",
      "description": "Optional structured spec sheet to drop alongside the note — your model, capabilities, agent-card, anything. Preserved verbatim so the recipient sees who you are, not just text."
    }
  },
  "required": [
    "to"
  ]
}
⚪onyx_market_rank(target)

Signed, conflict-free rating of any agent/x402 service — 'Moody's for the agentic web'. Point it at a URL; it probes observable reality (live, discoverable, payable, breadth, transparency) and returns a 0-100 rating + A-F grade, Ed25519-signed. Every response PUBLISHES the exact weights + method (vs everyone else's hidden N=1 score), and Onyx takes no settlement fee from what it rates, so it has no GMV to inflate. Use it to vet a service or counterparty before you route, integrate, or pay. (price: $0.05 USDC, tier: metered)

입력 스키마

{
  "type": "object",
  "properties": {
    "target": {
      "type": "string",
      "description": "URL of the service/agent to rate (e.g. https://example.com or its x402 base)."
    }
  },
  "required": [
    "target"
  ]
}
🟢onyx_merchant_fact_check(domain, brand, expected_price, product_url)

Pre-checkout merchant fact oracle. Give a storefront domain (optionally the brand you believe it is, and an expected price); get Ed25519-signed raw observations: domain registration age + registrar (RDAP), live TLS certificate age + issuer, reachability + off-domain redirects, brand-name similarity score with lookalike-token flags, and observed page price vs your expectation. Facts only, method disclosed per field — Onyx never asserts 'legit' or 'scam'; the signature proves the observation is genuine and untampered. (price: $0.25 USDC, tier: premium)

입력 스키마

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Storefront domain or URL, e.g. brand-outlet-sale.com or https://shop.example.com/p/1"
    },
    "brand": {
      "type": "string",
      "description": "Optional brand name you believe this storefront represents (e.g. 'Russell & Bromley'). Enables the brand-similarity observation."
    },
    "expected_price": {
      "type": "number",
      "description": "Optional price you were quoted/expect. If the page shows a price, the deviation percentage is reported as a fact."
    },
    "product_url": {
      "type": "string",
      "description": "Optional specific product URL to extract the observed price from (defaults to the domain root)."
    }
  },
  "required": [
    "domain"
  ]
}
🟡onyx_aeo_score(brand, category, domain, competitors, runs, ...)

0n1x AEO Score: the SIGNED, auditable answer-engine visibility number for a brand/product/agent. Runs a fixed buyer-intent prompt set against a live web-grounded answer engine N times each (non-determinism measured, not hidden), and returns a 0-100 AEO score with a 95% confidence interval, PUBLISHED weights, presence rate, position-weighted share-of-voice vs competitors, citation rate, sentiment, and every cited source. Unlike Profound/Semrush-AI (hidden weights, single daily run), every input is disclosed and the whole reading is Ed25519-signed by 0n1x. Never fabricated. (price: $0.50 USDC, tier: premium)

입력 스키마

{
  "type": "object",
  "properties": {
    "brand": {
      "type": "string",
      "description": "Brand, product, protocol, or agent to score (e.g. '0n1x', 'Stripe')."
    },
    "category": {
      "type": "string",
      "description": "Category for the buyer-intent prompts (e.g. 'agent trust layer', 'payment processors'). Drives the 'best <category>' / 'verify before pay' style queries."
    },
    "domain": {
      "type": "string",
      "description": "Optional canonical domain (e.g. '0n1x.com') used to measure CitationRate — how often the brand's own site is cited in answers."
    },
    "competitors": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Optional competitor names for position-weighted share-of-voice."
    },
    "runs": {
      "type": "integer",
      "description": "Runs per prompt (default 3, max 5). More runs = tighter confidence interval on the score."
    },
    "aliases": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Optional alternate names that count as the brand (e.g. ['Onyx'] for a rename). Any alias match = brand present."
    }
  },
  "required": [
    "brand"
  ]
}
🟢onyx_erc8004_lookup(address, registry, chain)

Signed on-chain read of the ERC-8004 'Trustless Agents' registries (Identity + Reputation singletons, live on Base mainnet). Returns verified registry metadata, the total number of registered agents (totalSupply), and — if you pass an agent address — whether that address holds an ERC-8004 identity NFT. Read-only eth_call, no funds; the whole reading is Ed25519-signed by 0n1x so an agent can prove the registry fact before trusting a counterparty. (price: $0.05 USDC, tier: metered)

입력 스키마

{
  "type": "object",
  "properties": {
    "address": {
      "type": "string",
      "description": "Optional agent EVM address (0x...) to check for an ERC-8004 identity (balanceOf > 0)."
    },
    "registry": {
      "type": "string",
      "enum": [
        "identity",
        "reputation"
      ],
      "description": "Which singleton to read (default 'identity')."
    },
    "chain": {
      "type": "string",
      "enum": [
        "base"
      ],
      "description": "Chain to read (default 'base' = Base mainnet, eip155:8453)."
    }
  },
  "required": []
}
🟢onyx_perm_check(action, grant, history)

Check whether an agent's proposed action stays inside its declared permission grant (allowed action, allowed merchant/domain, spend cap, rolling-window + velocity + per-counterparty budgets, expiry, principal, consent). Returns an Ed25519-signed IN_SCOPE / OUT_OF_SCOPE / UNDECLARED fact, BOUND to the exact request (nonce + request hash, so it can't be replayed or reused for a different operation). Facts, not judgments — a mechanical conformance check, never a verdict on intent. Verify free with onyx_attestation_verify. (price: $0.00 USDC, tier: free)

입력 스키마

{
  "type": "object",
  "properties": {
    "action": {
      "type": "object",
      "description": "The proposed action: {type, amount_usdc?, merchant?, domain?}",
      "properties": {
        "type": {
          "type": "string",
          "description": "e.g. transact, verify, read"
        },
        "amount_usdc": {
          "type": "number"
        },
        "merchant": {
          "type": "string"
        },
        "domain": {
          "type": "string"
        }
      }
    },
    "grant": {
      "type": "object",
      "description": "The agent's permission grant (onyx-perm-grant/v0): allowed_actions, allowed_merchants, allowed_domains, spend_max_usdc, spend_window_usdc, spend_window_sec, velocity_max, per_counterparty_budget, principal, consent_ref, expires_at"
    },
    "history": {
      "type": "array",
      "description": "Optional: recent settled actions for window/velocity checks, each {amount_usdc, ts (unix), counterparty?}. Stateless — the caller supplies the tally; the fact binds to it.",
      "items": {
        "type": "object"
      }
    }
  },
  "required": [
    "action",
    "grant"
  ]
}
⚪onyx_perm_grant(agent, principal, consent_ref, allowed_actions, allowed_merchants, ...)

Mint a signed permission grant (onyx-perm-grant/v0) for an agent: a portable, Ed25519-notarized declaration of the scope it may act within (allowed_actions, allowed_merchants/domains, spend_max_usdc, principal, consent_ref, expires_at). Carry it on the agent card; evaluate actions against it with onyx_perm_check. Facts, not judgments — attests what was declared, not that the grantor holds the authority. (price: $0.00 USDC, tier: free)

입력 스키마

{
  "type": "object",
  "properties": {
    "agent": {
      "type": "string",
      "description": "Who is granted (did:pkh / wallet / agent id)"
    },
    "principal": {
      "type": "string",
      "description": "Who grants the authority (did / email / org)"
    },
    "consent_ref": {
      "type": "string",
      "description": "Proof of consent (AP2 mandate id / signature hash)"
    },
    "allowed_actions": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Subset of ['read', 'verify', 'transact', 'sign', 'negotiate', 'subscribe']; deny-by-default"
    },
    "allowed_merchants": {
      "type": "array",
      "items": {
        "type": "string"
      }
    },
    "allowed_domains": {
      "type": "array",
      "items": {
        "type": "string"
      }
    },
    "spend_max_usdc": {
      "type": "number",
      "description": "Hard ceiling per action"
    },
    "spend_window_usdc": {
      "type": "number",
      "description": "Optional rolling-window aggregate cap"
    },
    "spend_window_sec": {
      "type": "integer",
      "description": "Window length in seconds (default 86400)"
    },
    "velocity_max": {
      "type": "integer",
      "description": "Max number of transacts per window"
    },
    "per_counterparty_budget": {
      "type": "number",
      "description": "Max aggregate spend per single counterparty per window"
    },
    "purpose": {
      "type": "string"
    },
    "expires_at": {
      "type": "integer",
      "description": "Unix time the grant lapses"
    }
  },
  "required": [
    "agent"
  ]
}
🟢onyx_security_flags(endpoint, agent)

Return the signed security posture of an agent: a list of OBSERVED, offline-verifiable security flags (insecure transport, no permission scope/principal/consent, no spend cap, unsigned identity, counterparty-blind, injection surface, unbounded skills). Pass an endpoint URL and/or the agent's record. Facts, not judgments — flags are conditions, never verdicts on intent. Ed25519-signed; verify free with onyx_attestation_verify. (price: $0.00 USDC, tier: free)

입력 스키마

{
  "type": "object",
  "properties": {
    "endpoint": {
      "type": "string",
      "description": "The agent's endpoint URL"
    },
    "agent": {
      "type": "object",
      "description": "Optional: the agent's record (name, description, skills, and any permission fields) for a deeper scan"
    }
  }
}
🟢onyx_payment_gate(domain, amount_usd, expected_price, product_url, brand)

Pre-payment clearance for agents. Call this BEFORE settling with a merchant over x402/AP2: give the merchant domain (optionally the amount and the price you expect to pay). Onyx assembles a single hard clearance — PROCEED / REVIEW / HOLD — from its Ed25519-signed observation log: Onyx-Verified status, live TLS/reachability/off-domain-redirect facts, domain age, and observed-vs-expected price. Facts with methods disclosed, signed and verifiable; Onyx never asserts the merchant is honest — it ensures you read real signed ground-truth before you move money. The check agents run at the payment chokepoint. (price: $0.05 USDC, tier: metered)

입력 스키마

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Merchant domain or URL you are about to pay, e.g. shop.example.com"
    },
    "amount_usd": {
      "type": "number",
      "description": "Optional amount you are about to pay (for the record; large amounts lower the auto-PROCEED bar)."
    },
    "expected_price": {
      "type": "number",
      "description": "Optional price you were quoted/expect. If the page shows a price, a large deviation downgrades the clearance."
    },
    "product_url": {
      "type": "string",
      "description": "Optional specific product URL to read the observed price from."
    },
    "brand": {
      "type": "string",
      "description": "Optional brand the merchant CLAIMS to be (e.g. 'Russell & Bromley'). If a well-known brand is claimed on a freshly-registered domain, the clearance is HELD — the cloned-storefront pattern."
    }
  },
  "required": [
    "domain"
  ]
}
🟢onyx_preflight(url, timeout_seconds)

Preflight safety check for an x402-gated endpoint, BEFORE you pay it. Probes the URL live (~8s timeout), confirms it actually speaks x402 (a proper HTTP 402 with a parseable payment-requirements body — not a decoy demanding payment in prose), parses the advertised price to human USDC, sanity-checks the payTo address (0x format + EIP-55 checksum) and network (mainnet vs silently-testnet), and flags dead/cold/zombie endpoints and absurd price traps. Returns one signed verdict — OK, WARN, or AVOID — plus every disclosed flag behind it. Sign facts, not judgments: each flag traces to a checkable rule, not an opaque trust score. (price: $0.02 USDC, tier: metered)

입력 스키마

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "The x402-gated endpoint to preflight (http:// or https://)."
    },
    "timeout_seconds": {
      "type": "number",
      "default": 8,
      "description": "Probe timeout in seconds. Clamped to [2, 15]."
    }
  },
  "required": [
    "url"
  ]
}
🟢onyx_research_intel(query, top_n, min_citations, year_from, sort_by)

Research intel — has someone solved X already? Queries 240M+ academic works via OpenAlex (includes arXiv preprints, conference papers, journal articles), ranks by citation count + recency + relevance, returns top N papers with one-line abstract excerpts, citation counts, and author names. Built for autonomous agents that need to check prior art before burning cycles re-deriving a known result. Fallback to Semantic Scholar. (price: $0.05 USDC, tier: metered)

입력 스키마

{
  "type": "object",
  "properties": {
    "query": {
      "type": "string",
      "description": "Research question or keyword string. Plain English works; OpenAlex handles tokenization."
    },
    "top_n": {
      "type": "integer",
      "minimum": 1,
      "maximum": 20,
      "default": 5,
      "description": "How many papers to return."
    },
    "min_citations": {
      "type": "integer",
      "minimum": 0,
      "default": 0,
      "description": "Filter out papers with fewer than this many citations. Use 50+ to surface only well-known work."
    },
    "year_from": {
      "type": "integer",
      "minimum": 1900,
      "maximum": 2100,
      "description": "Optional: only return papers from this year onward."
    },
    "sort_by": {
      "type": "string",
      "enum": [
        "relevance",
        "citations",
        "recency"
      ],
      "default": "relevance",
      "description": "Ranking. citations = highest cited first; recency = newest first; relevance = OpenAlex semantic match."
    }
  },
  "required": [
    "query"
  ]
}
🟢onyx_retail_price_check(url, expect_price)

Ground-truth retail oracle. Give a product URL; get the real current price, currency, and in-stock state as actually fetched now — with the extraction source (JSON-LD / OpenGraph / microdata) as evidence. Covers the long tail of no-API shops where agents otherwise hallucinate prices. Never guesses: returns price=None with confidence='none' when the page exposes no machine-readable price. Use before an agent quotes, compares, or transacts on a price it would otherwise invent. (price: $0.02 USDC, tier: metered)

입력 스키마

{
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "description": "Full product page URL (http/https). The exact page whose price + availability you want observed."
    },
    "expect_price": {
      "type": "number",
      "description": "Optional. A price you believe is current. If given, the result includes matches_expected:bool + drift so a caller can detect a stale/hallucinated quote."
    }
  },
  "required": [
    "url"
  ]
}
🟢rhinogent_identity(address)

Rhinogent identity card: give a self-custody Base (EVM) address, get back a signed, verifiable identity — deterministic callsign, did:pkh, and the agent's earned 0n1x-Verified credential. Keys never leave the agent; this issues only the public signed identity. The front door of the agent identity wallet. (price: $0.00 USDC, tier: free)

입력 스키마

{
  "type": "object",
  "properties": {
    "address": {
      "type": "string",
      "description": "The agent's self-custody Base/EVM address, 0x-prefixed (42 chars)."
    }
  },
  "required": [
    "address"
  ]
}
⚪rhinogent_mandate(agent, principal, spend_max_usdc, daily_cap_usdc, allowed_merchants, ...)

Author a signed spend mandate for an agent: per-action and rolling-window USDC caps, merchant/domain allowlists, velocity limit and expiry — issued as a signed PERM_v0 grant the agent adopts. 'Transacts autonomously, within the boundaries you define.' (price: $0.00 USDC, tier: free)

입력 스키마

{
  "type": "object",
  "properties": {
    "agent": {
      "type": "string",
      "description": "Agent the mandate authorizes (address or callsign)."
    },
    "principal": {
      "type": "string",
      "description": "Optional: the human/entity granting authority."
    },
    "spend_max_usdc": {
      "type": "number",
      "description": "Hard ceiling per single action (USDC)."
    },
    "daily_cap_usdc": {
      "type": "number",
      "description": "Rolling 24h aggregate cap (USDC)."
    },
    "allowed_merchants": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Merchant allowlist (deny by default)."
    },
    "allowed_domains": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Domain allowlist (deny by default)."
    },
    "allowed_actions": {
      "type": "array",
      "items": {
        "type": "string"
      },
      "description": "Permitted action verbs (deny by default)."
    },
    "velocity_max": {
      "type": "integer",
      "description": "Max number of transactions per window."
    },
    "expires_at": {
      "type": "integer",
      "description": "Unix time the mandate lapses."
    },
    "purpose": {
      "type": "string",
      "description": "Human-readable purpose of the mandate."
    }
  },
  "required": [
    "agent"
  ]
}
🟢rhinogent_verify_counterparty(domain, brand, expected_price)

Know-your-counterparty for agents. Before your agent pays a merchant, get Ed25519-signed raw facts about who it's paying: domain registration age, live TLS cert, reachability + off-domain redirects, brand-impersonation similarity, and observed price vs expected. Facts only (never 'legit/scam') — the one check every other agent wallet skips. (price: $0.25 USDC, tier: premium)

입력 스키마

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "Counterparty/storefront domain or URL the agent is about to pay."
    },
    "brand": {
      "type": "string",
      "description": "Optional brand the storefront claims to be (enables the impersonation-similarity observation)."
    },
    "expected_price": {
      "type": [
        "number",
        "string"
      ],
      "description": "Optional price the agent expects to pay (enables the price-deviation observation)."
    }
  },
  "required": [
    "domain"
  ]
}
🟢onyx_secure_payment(recipient, amount_usdc, contract_address, counterparty_agent_id)

Secure-transaction RAIL: one signed clearance before an agent sends funds. Give recipient + amount (and optionally a contract address or counterparty ERC-8004 agent id); Onyx runs the full security stack — recipient firewall, contract audit, counterparty reputation — and returns a single PASS / REVIEW / FAIL verdict + risk score, plus the Onyx take-rate quote (bps of value secured). Ed25519-signed so the clearance is provable. The check a serious agent runs before moving real money. Onyx never takes custody. (price: $0.25 USDC, tier: premium)

입력 스키마

{
  "type": "object",
  "properties": {
    "recipient": {
      "type": "string",
      "description": "0x recipient address the agent is about to pay (Base)."
    },
    "amount_usdc": {
      "type": "number",
      "description": "Amount about to be sent, in USDC. Drives both the risk threshold and the take-rate quote."
    },
    "contract_address": {
      "type": "string",
      "description": "Optional. If the payment interacts with a contract, its 0x address — triggers a full contract audit."
    },
    "counterparty_agent_id": {
      "type": "integer",
      "description": "Optional. If paying another AI agent, its ERC-8004 id — triggers a reputation check."
    }
  },
  "required": [
    "recipient",
    "amount_usdc"
  ]
}
🟢onyx_signature_guard(typed_data)

Pre-signature firewall for OFF-CHAIN drains — the check before your agent signs an EIP-712 typed-data message (Permit, Permit2, Seaport order). These drain a wallet with no on-chain approval: the signature itself is the authorization. Give the typed-data; Onyx identifies what it authorizes, flags unlimited token-permit values, EOA/unverified spenders, NFT-order signatures, and bad deadlines, and returns a SIGNED ALLOW/REVIEW/BLOCK + plain-English explanation. Covers the #2 wallet-drain vector that on-chain tx checks miss entirely. (price: $0.10 USDC, tier: metered)

입력 스키마

{
  "type": "object",
  "properties": {
    "typed_data": {
      "type": "object",
      "description": "The full EIP-712 typed-data object the agent is about to sign: {domain, primaryType, types, message}."
    }
  },
  "required": [
    "typed_data"
  ]
}
🟢onyx_token_risk(contract, chain)

Signed token-security oracle. Give a token contract (and chain); get the real on-chain risk facts as read right now — honeypot status, buy/sell tax, mintable, ownership-reclaim, transfer-pausable, proxy, LP-lock, holder count — plus a transparent 0-100 risk score and verdict you can recompute from the itemized factors. Ed25519-signed + timestamped so an agent can PROVE it screened a token before buying. Use before any agent swaps into or quotes an ERC-20 it didn't issue. (price: $0.10 USDC, tier: metered)

입력 스키마

{
  "type": "object",
  "properties": {
    "contract": {
      "type": "string",
      "description": "Token contract address (0x… 20-byte hex) to screen."
    },
    "chain": {
      "type": "string",
      "description": "Chain the token lives on. Name ('base','ethereum','bsc','polygon','arbitrum','optimism','avalanche') or numeric chain id. Default 'base'.",
      "default": "base"
    }
  },
  "required": [
    "contract"
  ]
}
⚪onyx_track_record(tool)

Onyx's measured precision — the proof no other x402 security tool can show. Returns a SIGNED summary of the verdict->outcome ledger: of every BLOCK Onyx issued, what fraction were confirmed real threats (block precision); of every ALLOW, what fraction later went bad (miss rate); plus counts by tool and outcome. Built from real reported outcomes via onyx_outcome_report. Free and public — this is how you verify Onyx is calibrated, not just confident. (price: $0 USDC, tier: free)

입력 스키마

{
  "type": "object",
  "properties": {
    "tool": {
      "type": "string",
      "description": "Optional. Restrict the track record to one tool (e.g. onyx_tx_guard)."
    }
  },
  "required": []
}
🟢onyx_tx_guard(address, amount_usdc)

Pre-payment security firewall. Give the recipient address your agent is about to pay (Base); get a SIGNED ALLOW/REVIEW/BLOCK verdict + risk score from real on-chain checks: EOA-vs-contract, contract code/verification, account age (tx count), funding history, burn/null-address guard, and sink/honeypot heuristics. Catches paying a brand-new, unverified, or drain-shaped recipient BEFORE the money leaves. Never guesses — every field is observed on-chain and Ed25519-signed. (price: $0.10 USDC, tier: metered)

입력 스키마

{
  "type": "object",
  "properties": {
    "address": {
      "type": "string",
      "description": "0x recipient address your agent is about to send funds to (Base mainnet)."
    },
    "amount_usdc": {
      "type": "number",
      "description": "Optional amount about to be sent (USDC). Larger amounts raise the review threshold."
    }
  },
  "required": [
    "address"
  ]
}
🟢onyx_tx_preflight(to, data, value_wei)

Universal pre-sign firewall — the check before your agent signs ANY transaction. Give the tx (to, data, value); Onyx decodes the 4-byte selector + args, tells you in plain terms what it does, and flags the wallet-drain patterns: unlimited approve(), setApprovalForAll (blanket NFT approval), transfers to fresh/EOA recipients, raw ETH sends to unknown addresses, and calls to unverified targets. Returns a SIGNED ALLOW/REVIEW/BLOCK + human explanation. The single highest-frequency safety gate an on-chain agent has — every signed tx should pass through it. (price: $0.10 USDC, tier: metered)

입력 스키마

{
  "type": "object",
  "properties": {
    "to": {
      "type": "string",
      "description": "The transaction's `to` address (target contract or recipient). Required."
    },
    "data": {
      "type": "string",
      "description": "The transaction calldata (0x-hex). Omit/empty for a plain ETH transfer."
    },
    "value_wei": {
      "type": "string",
      "description": "Optional. ETH value being sent, in wei (base-10 string)."
    }
  },
  "required": [
    "to"
  ]
}
🟢onyx_verified_issue(domain, contact, agent_id)

Get your domain Onyx Verified. Onyx runs its published objective checks (live TLS, reachability, no off-domain redirect, registration age disclosed) and, on pass, issues an Ed25519-signed verified record onto the public Observation Log — instantly queryable at /merchant/{domain} — plus a live badge (served by Onyx, so it can't be faked or staled) and a machine-readable status URL agents check before they pay you. Valid 90 days, renewable. This attests your domain PASSED published checks, like a CA certificate — Onyx never claims you are 'honest' or 'safe'; the value is a neutral, verifiable, public presence agents can trust. (price: $2.00 USDC, tier: premium)

입력 스키마

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "description": "The domain to verify, e.g. shop.example.com (your storefront/agent endpoint)."
    },
    "contact": {
      "type": "string",
      "description": "Optional contact (email/handle) recorded with the issuance for renewal notices."
    },
    "agent_id": {
      "type": "string",
      "description": "Optional agent id to cross-link this verified domain to an agent identity."
    }
  },
  "required": [
    "domain"
  ]
}
🟢onyx_verify_explain(x_payment_b64, payment_payload, payment_requirements, now_unix)

Diagnose a failing x402 v2 /verify. Decodes a captured X-PAYMENT header, runs 10 rules (decode, schema, network/asset/payTo match, value sufficiency, EIP-3009 timing, signature shape, scheme) against expected paymentRequirements, and returns the FIRST failing rule with a plain-English fix. Catches the common case where the facilitator returns bare HTTP 402 (no body) because of JWT or schema fail upstream of the verifier. Stdlib-only, no install, no network. (price: $0 USDC, tier: free)

입력 스키마

{
  "type": "object",
  "properties": {
    "x_payment_b64": {
      "type": "string",
      "description": "Base64-encoded X-PAYMENT (v2 PAYMENT-SIGNATURE) header value. Optional if payment_payload provided."
    },
    "payment_payload": {
      "type": "object",
      "description": "Decoded payment payload dict. Use this OR x_payment_b64."
    },
    "payment_requirements": {
      "type": "object",
      "description": "Expected paymentRequirements from the 402 challenge ({scheme, network, payTo, asset, maxAmountRequired, maxTimeoutSeconds, ...})."
    },
    "now_unix": {
      "type": "integer",
      "description": "Override current unix time for replay/CI use. Defaults to now."
    }
  },
  "required": [
    "payment_requirements"
  ]
}
🔴onyx_x402_receipt_verify(tx_hash, network, expected_from, expected_to, expected_amount_usdc)

Verify an x402 USDC settlement on Base or Base Sepolia. Given a tx hash, decodes the USDC Transfer log and confirms (or refutes) a claim of the form: 'tx X moved $Y USDC from A to B'. Returns success status, actual decoded values, and a clear discrepancy report if any field doesn't match. Free tier — useful for agents reconciling spend and operators auditing inbound payments. (price: $0 USDC, tier: free)

입력 스키마

{
  "type": "object",
  "properties": {
    "tx_hash": {
      "type": "string",
      "description": "0x-prefixed 32-byte tx hash to verify."
    },
    "network": {
      "type": "string",
      "enum": [
        "base",
        "base-sepolia"
      ],
      "default": "base",
      "description": "Chain to query. Must match where the tx was mined."
    },
    "expected_from": {
      "type": "string",
      "description": "Optional. Expected sender address (0x...). If provided, verifier checks Transfer.from matches."
    },
    "expected_to": {
      "type": "string",
      "description": "Optional. Expected recipient address (0x...). If provided, verifier checks Transfer.to matches."
    },
    "expected_amount_usdc": {
      "type": "number",
      "description": "Optional. Expected USDC amount (whole USDC, not atomic). If provided, verifier checks Transfer.value matches (within 0.000001 tolerance)."
    }
  },
  "required": [
    "tx_hash"
  ]
}

커뮤니티

이 서버 평가하기

증거

최근 관측

검증됨버전이 기록되지 않음도구 33개
검증됨버전이 기록되지 않음도구 33개
검증됨버전이 기록되지 않음도구 33개