Mmcp.market

X402 Data Gateway MCP server

by epistemedeus·io.github.epistemedeus/x402-data-gateway·v1.23.49

Paid x402 and MPP tools for agent discovery, payment safety, data, and DeFi.

B81/100grade B
What users say
No reviews yet
Be the first
Safety scan
B81/100

full report

Adoption
Growing

1 stars

Reviews

Write one

Nobody has reviewed X402 Data Gateway yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

X402 Data Gateway tools (24, 3 write)

write = sends, deletes, buys or posts
  • agent_discoverability_auditFree

    Measure one service's brand-blind rank, source-family coverage, expected-route presence, canonical-vs-alias listing identity, duplicate records, competitors, and exact-price drift across ten public machine-service discovery views. Supply `runtimeUrl` with an exact GET route to derive the comparison price from one coherent live unsigned x402 or MPP offer; otherwise `expectedPriceUsd` remains caller-supplied. Set `surfaceAudit` to check the target's public Agent Card, ERC-8004 registration document, and action catalog. Set `materializationAudit` with an exact GET or POST route to distinguish Coinbase seller ineligibility from provider acceptance without exact-resource Bazaar materialization. Catalog queries use no credentials or payments. Results are point-in-time provider and catalog evidence, not demand, seller trust, settlement, or future-rank proof.

  • agent_surface_budget_auditFree

    Measure one public service's credential-free MCP tools/list, OpenAPI, or both declared discovery surfaces before any tool call or target payment. Use `agent_discoverability_audit` for catalog reach and rank, `seller_integrity_audit` for one exact operation's response contract, or this tool for byte budgets, heaviest definitions, missing selection contracts, and progressive-discovery fixes. Unselected surfaces are not fetched or judged. It follows no redirect, calls no target tool, sends no credential or target payment, and returns no target schema, response body, or session identifier.

  • contract_qualified_searchFree

    Search Agent402 and the official MPP catalog for paid machine services that both match a capability intent and guarantee buyer-required JSON response paths. Use `agent_discoverability_audit` when you are measuring one known seller's catalog reach or rank, `seller_integrity_audit` when you already know the exact seller route to inspect, or `payment_offer_preflight` when you already have one exact callable GET URL. This search excludes SameDayDesk-owned supply and unresolved routes before audit, uses no credential or wallet, sends no seller POST or target payment, reads no paid response body, and returns only a query digest.

  • deep_auditwrite actionFree

    Run one read-only AI-search-readiness audit for a public business domain: company, technology, contact, and DNS/email evidence from `enrich`, plus the live structured-data gap analysis and paste-ready JSON-LD template from `schemaforge`. Use `enrich` for company facts only or `schemaforge` for structured-data remediation only. The template contains placeholders for real data; the score is diagnostic, no site changes are made, and it does not guarantee AI citations.

  • enrichwrite actionFree

    Inspect a public company domain and return structured identity, technology, social, contact, DNS, email-infrastructure, and AI-readiness evidence. Use `schemaforge` instead for a paste-ready JSON-LD template and remediation diff, or `deep_audit` when both outputs are required together. Public data only; this tool makes no site changes.

  • extractFree

    Fetch a public HTTP(S) page and return compact extraction signals for programmatic inspection: title, meta description, Open Graph/Twitter metadata, JSON-LD, headings, links, text excerpt, and AI-readiness flags. Use `read` instead when you need the page body as LLM-ready Markdown rather than metadata or a link inventory. Does not execute JavaScript; follows redirects and applies SSRF, timeout, and response-size guards.

  • extract_batchFree

    Fetch one to five public HTTPS URLs and return bounded structured fields for each source in one paid attempt. Supply `urls` as a JSON array and optional unique `fields`. Use `extract` for a single URL when you do not need batch accounting. Charge is one flat introductory 0.01 USDC quote for the bounded attempt, not a guarantee that every URL succeeds. Automatic retries are disabled; unknown outcomes must not be re-paid automatically. Payment challenge and credentials are bound to https://agents.samedaydesk.com/extract/batch, not mcp://. Retry the identical authorized arguments and credential.

  • lockfile_pin_deltaFree

    Inspect two caller-supplied npm package-lock.json objects and return added, removed, and changed name+version+integrity+resolved pins. Supply JSON `before` and `after` lockfile objects, not filesystem paths, URLs, or commands. An identical pin set is informational, not a failure. HTML, package.json, and unsupported lockfileVersion values are refused before payment. This is not an npm install, audit, or purchase. Ordinary wallets sign through examples/customer-x402 (inspect, explicit approve, attempt-receipt, read-only reconcile), not a precomputed signature. Initial live release accepts x402 only. Payment challenge and credentials are bound to https://agents.samedaydesk.com/lockfile-pin-delta, not mcp://. Retry the identical authorized arguments and credential.

  • morpho_market_underwriteFree

    Underwrite one Base Morpho market with independent GraphQL, REST, and direct-RPC evidence for configuration integrity, liquidity, utilization, concentration, borrower health bands, recent history, bad debt, and PreLiquidation availability. Use `morpho_position` or `morpho_protection` for one borrower's current position or protection plan, and `morpho_preliquidation_replay` for the economics of one completed historical event. Read-only evidence with explicit disagreements; no opaque risk score or transaction action.

  • morpho_positionFree

    Inspect one Base borrower across Morpho markets and return position balances, LTV, health factor, liquidation headroom, direct-RPC verification, and caller-selected collateral-price stress scenarios. Use `morpho_protection` when you need exact repay or add-collateral amounts and unsigned transaction templates, `morpho_market_underwrite` for market-wide risk, or `morpho_preliquidation_replay` for one completed historical event. Read-only; no wallet, signing, broadcast, or custody.

  • morpho_preliquidation_replayFree

    Reconstruct one successful Base Morpho PreLiquidation transaction from its receipt and the exact block state, returning repaid and seized assets, protocol-oracle valuation, gross incentive, configured health window, and transaction gas before off-chain costs. Use `morpho_market_underwrite` for current market risk, `morpho_position` for a current borrower, or `morpho_protection` for a future protection plan. Historical read-only evidence; no transaction simulation, wallet, signing, or broadcast.

  • morpho_protectionFree

    Calculate two alternative protection plans for one Base Morpho borrower under a selected collateral-price shock and target health factor: partial repayment or added collateral. Each plan includes the bounded asset amount, expected stressed health factor, evidence basis, and unsigned ERC-20 approval plus Morpho call templates. Use `morpho_position` for diagnosis without an action plan, `morpho_market_underwrite` for market-wide risk, or `morpho_preliquidation_replay` for a completed historical event. Read-only; no wallet, signing, broadcast, or custody.

  • opportunity_preflightFree

    Agent work opportunity -> deterministic attempt, verify-first, or abandon preflight using caller-supplied cost and selection assumptions plus dated platform evidence. Returns break-even probability, expected surplus, hard gates, and source-linked evidence. No claim, bid, payment, or submission.

  • payment_offer_preflightFree

    Compare x402 and MPP payment challenges, terms, and seller-declared JSON success-response readiness for one exact public HTTPS GET route before buyer authorization, including URL and realm binding, expiry, cross-protocol economic parity, and exact-route OpenAPI evidence. Use `agent_discoverability_audit` instead when you need to know whether catalogs rank or expose a service. This tool uses no target credential, signature, or target payment, follows no redirect, never reads the paid target body, and reads only the same-origin public OpenAPI document under a strict size cap. A seller declaration is advisory and does not establish runtime validity, seller trust, utility, or settlement reliability.

  • readFree

    Fetch a public HTTP(S) page and return its readable body as cleaned Markdown for LLM context, preserving headings, links, and lists while dropping navigation, ads, scripts, headers, footers, asides, and forms. Use `extract` instead when you need metadata, JSON-LD, Open Graph/Twitter tags, or a link inventory. Markdown is capped at 40,000 characters and no JavaScript is executed.

  • scanFree

    Static supply-chain security scan of a public GitHub repo before an agent installs/runs it. Flags exfil sinks, obfuscation, credential reads, install-time curl|bash. risk=clean|suspicious|dangerous.

  • schemaforgeFree

    Analyze a public business site and return a deterministic, paste-ready JSON-LD template plus the live structured-data gap diff and ranked fixes. Use `deep_audit` instead when the same call must also return company, technology, contact, and DNS/email evidence. Generated markup contains placeholders that must be replaced with real business values; this tool makes no site changes and does not guarantee AI citations.

  • seller_integrity_auditFree

    Use this after a buyer integration fails, a seller changes a paid route, or before the next paid retry or release. Audit one exact paid GET or POST seller route against buyer-required JSON success paths. GET verifies constructible non-secret input, exact request binding, live x402 and MPP economics, and optional Bazaar eligibility; POST performs static-safe OpenAPI contract analysis and sends no target request. Use `payment_offer_preflight` instead when you already have one exact callable GET URL and only need its current unpaid offer before buyer authorization, or `agent_discoverability_audit` for catalog rank and identity. Uses no target credential, signature, or target payment and retains no seller schema, body, or query values.

  • settlement_proofFree

    Verify one claimed canonical Base USDC settlement after execution by matching a successful transaction receipt to the exact recipient, atomic amount, and optional payer. Use `payment_offer_preflight` before authorization when you need to inspect an unpaid x402 or MPP offer instead. This tool reads only public Base receipt and log data; it reads no merchant ledger and performs no wallet, signing, broadcast, custody, or execution action.

  • solana_transaction_receiptFree

    Inspect one finalized Solana mainnet transaction signature and return normalized success or failure status, slot, block time, fee, SPL-token owner deltas, and canonical USDC deltas. Supply recipient, amount, and optional payer when an exact settlement claim must be verified; use `transaction_receipt` for Base or Ethereum. Raw instructions and logs are excluded, and this tool performs no wallet, signing, broadcast, custody, or execution action.

  • stateful_wallet_policy_conformanceFree

    Evaluate safe standardized observations from wallet policies that track prior or concurrent requests. Use `wallet_policy_conformance` instead for one-request action shape, method, chain, token, recipient, amount, and function controls. This tool separately tests sequential cumulative limits, signed-but-unbroadcast accounting, ABI extraction, concurrent oversubscription, counter-reference failure, and application serialization. It accepts no credentials, counter values, wallet or resource IDs, signatures, transactions, or raw provider responses and does not run the provider tests itself.

  • transaction_receiptwrite actionFree

    Inspect one Base or Ethereum transaction hash and return normalized success or revert status, block time, gas and fee fields, decoded ERC-20 Transfer events, and canonical USDC transfers. Use `settlement_proof` instead when you must verify an exact canonical Base USDC recipient, amount, and optional payer claim. Raw logs are excluded; this tool performs no wallet, signing, broadcast, custody, or execution action.

  • wallet_enrichFree

    Inspect a public Base or EVM address and return an agent-ready on-chain profile: EOA or contract type, native and curated token holdings, token/NFT metadata, proxy evidence, activity, and a derived profile label. Use `enrich` for a company domain; the two tools accept different identifiers and return different evidence. Read-only public chain data; no wallet action or custody.

  • wallet_policy_conformanceFree

    Evaluate safe standardized allow, deny, and error observations from an agent wallet or delegated signer. Use this after running a bounded provider policy test matrix to distinguish explicit provider-policy enforcement from validation or generic provider failures and to test exact execution shape separately from operation allowlisting. Accepts no credentials, wallet IDs, signatures, transactions, or raw provider responses; it evaluates caller-supplied observations and does not run the provider tests itself.

Public scan report

scanner v0.1.3 · 2026-09-19 · same rubric, same numbers if you re-run it

1 high
  • Code scanremote-only server, no package to scann/a
  • Live reliabilityremote reachable in 691ms20/20
  • Tool poisoning24 tool descriptions checked15/15
  • Auth qualityopen endpoint exposes 3 write-action tools with no auth3/15
  • Maintenancelast push 0 days ago15/15
  • Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10

Findings (1)

  • highWrite-action tools reachable without authenticationauth.open-write
Overall 81/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install directly

claude mcp add --transport http x402-data-gateway https://agents.samedaydesk.com/mcp
Add to Cursor

X402 Data Gateway: common questions

Is X402 Data Gateway MCP server safe?
Mostly: it is graded B (81/100). Read the X402 Data Gateway safety report
How do I install X402 Data Gateway?
It runs remotely at agents.samedaydesk.com. Add it to Claude Code, Claude Desktop or Cursor with the snippets above, or call it through the mcp.market gateway without installing anything.
Does X402 Data Gateway need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is X402 Data Gateway maintained?
The last commit was in the last day (2026-09-19). The latest release is v1.23.49.
Is X402 Data Gateway up?
100% of our last 1 checks got an answer. We check remote servers about four times a day.
What can I use instead of X402 Data Gateway?
Servers from other publishers that do the same job: Agent402.Tools: pay-per-call web tools MCP server, POPCORN MCP server and Easypaydirect MCP server. Compare all X402 Data Gateway alternatives.

Alternatives to X402 Data Gateway

Same job from other publishers: the closest match first, then the best rated.

All X402 Data Gateway alternatives →
  • Agent402.Tools: pay-per-call web tools
    Agentic Finance: 500+ agent tools, multi-chain USDC over x402 or MPP, free via PoW or card credits
    A
  • POPCORN MCP
    Signed time and SHA-256 witness receipts for agents, with offline verification and x402 payment.
    B
  • Easypaydirect
    Read-only MCP server for the Easy Pay Direct (EPD) / NMI-family payment gateway Query API.
    B
  • Losbeto
    x402-paid market intelligence: forex, stocks, Brazil macro (BCB/B3) + crypto.
    A
  • AgentIndex
    Trust scores and on-chain payment receipts for x402 services.
    B

More from epistemedeus