Mmcp.market

MCP server

by 402.coffee·coffee.402/mcp·v0.1.1

Trust layer for agent payments (x402, Base): verify agents, risk scores, signed escrow verdicts.

C65/100grade C
What users say
No reviews yet
Be the first
Safety scan
C65/100

full report

Adoption
Not measured yet

Usage numbers are collected on the next scan

Reviews

Write one

Nobody has reviewed MCP yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

MCP tools (10)

write = sends, deletes, buys or posts

Read from the package source without running it. The installed server may list more.

  • arbiter_policy

    FREE — the published 402.coffee arbiter policy: scope (machine-verifiable categories only), verdict semantics, evidence rules, neutrality, corrections, fees, signatures, liability.

  • arbiter_verify

    PAID $0.25 ($0.60 scored) — get a SIGNED release/refund/escalate delivery verdict from the 402.coffee external arbiter for a machine-verifiable claim. Non-custodial: your escrow executes the verdict. Categories: http-delivery {url, expect_status?, expect_sha256?, min_bytes?, expect_contains?} · payload-hash {payload_text|payload_b64, expected_sha256} · ci-status {repo, commit_sha}. Scored variant

  • behavioural_test_info

    FREE — how to run the behavioural conformance tests (scam-resistance / recipient-awareness, $0.60 total each). These are ADVERSARIAL: a naive auto-paying client will sign the bait and FAIL — which is exactly what they measure — so they are not run by this MCP server's auto-payer. Returns the step-by-step flow and the one-command path.

  • certify

    PAID $0.25 (basic) / $0.75 (suite) — certify THIS wallet's x402 client by completing a real payment against 402.coffee's conformance harness. Returns a public certificate URL + README badge. The behavioural tests (scam/recipient) are multi-step and adversarial — use behavioural_test_info for those.

  • check_credential

    FREE — fetch a wallet's portable W3C-VC-shaped credential AND verify its Ed25519 signature locally against 402.coffee's published JWKS (offline-verifiable proof it was issued by 402.coffee and not altered).

  • escrow_info

    FREE — the 402.coffee full-escrow product for merchants: route x402 sales through the on-chain x402r operator, funds held in AuthCaptureEscrow until the arbiter verifies delivery (release minus 1% or refund). Contracts, fee policy, integration snippet.

  • list_tests

    FREE — the machine-readable 402.coffee menu: every conformance test, price, route, and payoff, plus the counterparty products (score, escrow, arbiter). No wallet, no spend.

  • score_batch

    PAID $0.50 — risk scores for up to 25 wallets in one payment ($0.02/wallet effective).

  • score_wallet

    PAID $0.10 — deterministic 0–100 payment-risk score for any wallet: certified behaviour (scam-resistance, recipient-awareness) + real on-chain USDC payment history, with tier A–F, itemized evidence and flags. For deciding whether to transact with an agent.

  • verify_agent

    FREE — check whether a wallet has current 402.coffee conformance certs (pays correctly, refuses scams, checks recipients) plus a free on-chain USDC payment-activity summary. The one-call trust check before you transact with an agent.

Public scan report

scanner v0.1.9 · 2026-09-26 · same rubric, same numbers if you re-run it

1 low
  • Code scan4 source files scanned25/25
  • –Live reliabilityno gateway calls yet and no remote to proben/a
  • –Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitylocal package, no credentials required12/15
  • Maintenanceno repository listed3/15
  • Maintainer identityno repository or website to verify2/10

Findings (1)

  • lowNo source repository listedmaint.no-repo
Overall 65/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install directly

Runs npx -y 402coffee-mcp on your machine. Read the scan report first; the gateway never runs local packages.

claude mcp add mcp -- npx -y 402coffee-mcp
Add to Cursor

MCP: common questions

Is MCP server safe?
With care: it is graded C, so read the findings first (65/100). Read the MCP safety report
How do I install MCP?
It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
Does MCP need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is MCP maintained?
The latest release is v0.1.1.
What can I use instead of MCP?
Servers from other publishers that do the same job: Emilia Protocol MCP server, agent-device MCP server and IWE MCP server. Compare all MCP alternatives.

Alternatives to MCP

Same job from other publishers: the closest match first, then the best rated.

All MCP alternatives →
  • Emilia Protocol
    Exact-action approval for consequential agent actions: request, track, and verify signed receipts.
    B
  • agent-device
    MCP server for mobile app automation: verify, control, and debug iOS, Android, TV, and desktop apps
    A
  • IWE
    Markdown knowledge base as agent memory. Runs against the notes directory it is started in.
    A
  • Mockserver
    Mock, record/replay, verify and chaos-test any HTTP, REST, gRPC or LLM dependency over MCP.
    A
  • Agent Recall
    Correction-first agent memory. Precision KPI tracks if agents heed warnings. 5 layers, local-only.
    A

More from 402.coffee →