Every change Wellknown observed on this MCP server, newest first, with what it was before and what it became. Tool-surface changes carry the definition diff. Nothing here is edited after the fact.
Added "phion_enrich_basic"; changed the definition of "try_service" (134 tools before, 135 now)
⟨121 unchanged words⟩ multi-agent-escrow","cross-protocol-receipt","phion-inference","phion-search","phion-enrich-basic","phion-enrich","phion-intelligence"],"type":"string"} ⟨4 unchanged words⟩
PHION Basic Domain Enrichment — Observe a public company domain directly and return bounded website metadata, hashes, injection screening and signed delivery without an expensive enrichment upstream.; 0.003 USDC. Deterministic, evidence-bounded and signed.
Changed the definition of "payment_capability_preflight"
⟨5 unchanged words⟩ wallet, mandate, x402 v2, network, asset, account kind and funding readiness. Detects EVM account types incompatible with exact EIP-3009 before signature. Stores only a daily pseudonymous actor and normalized ⟨9 unchanged words⟩
{"additionalProperties":false,"properties":{"evm_account_kind":{"enum":["standard_eoa","delegated_eip7702","smart_contract","unknown"]},"funds_available":{"type":"boolean"},"intent" ⟨36 unchanged words⟩
Certificate changed, valid to 2026-12-26
Added "payment_capability_preflight"; changed the definition of "phion_discover", "phion_execute", "phion_get_service" and 4 more (133 tools before, 134 now)
before
—after
Discover PHION Servicesbefore
—after
Execute a PHION ServiceAdded "phion_discover", "phion_get_service", "phion_preflight" and 2 more (128 tools before, 133 now)
Free complete PHION service index generated from canonical inventory. Use when the agent knows a capability or wants to inspect the full network.
Retrieve one exact canonical PHION service contract by service id or MCP tool name.
Free service-specific schema, network, budget and economic preflight. It does not execute or charge.
Free provider-neutral capability resolution. Applies eligibility constraints, preserves UNKNOWN and abstains when evidence is insufficient. Advisory only: never authorizes payment or execution.
Search the complete canonical PHION inventory by task, capability, protocol or maximum advertised price without selecting or charging.
Added "phion_enrich", "phion_inference", "phion_intelligence" and 1 more; changed the definition of "try_service" (124 tools before, 128 now)
⟨119 unchanged words⟩ ,"dynamic-service-pricing","autonomous-procurement","multi-agent-escrow","cross-protocol-receipt","phion-inference","phion-search","phion-enrich","phion-intelligence"],"type":"string"}},"required": ⟨3 unchanged words⟩
PHION Enrich — Enrich a company, person or contact through an attributed provider route without hiding upstream cost.; 0.120 USDC. Deterministic, evidence-bounded and signed.
PHION Inference — Complete a bounded inference microtask and return a directly usable answer with signed delivery.; 0.001 USDC. Deterministic, evidence-bounded and signed.
Added "agent_economic_graph", "autonomous_procurement", "cross_protocol_receipt" and 6 more; changed the definition of "try_service" (115 tools before, 124 now)
⟨110 unchanged words⟩ ,"proof-of-service","automated-dispute-bundle","transaction-recovery-v2","reputation-update-receipt","agent-economic-graph","market-demand-predictor","service-gap-detector","price-discovery-engine","sla-risk-predictor","dynamic-service-pricing","autonomous-procurement","multi-agent-escrow","cross-protocol-receipt"],"type":"string"}},"required": ⟨3 unchanged words⟩
Agent Economic Graph — Build privacy-bounded economic relationships only from supplied nodes and edges.; 0.005 USDC. Deterministic, evidence-bounded and signed.
Autonomous Procurement — Recommend a verified eligible provider under a mandate without purchasing.; 0.005 USDC. Deterministic, evidence-bounded and signed.
Added "a2a_transaction_bridge", "agent_behavior_fingerprint", "agent_memory_provenance" and 27 more; changed the definition of "try_service" (85 tools before, 115 now)
⟨80 unchanged words⟩ ,"mcp-catalog-cache-guard","oauth-issuer-binding-evidence","mcp-a2a-task-bridge","quote-freshness-guard","delegated-credential-guard","agent-session-continuity","task-lease-guard","tool-result-schema-validator","agent-memory-provenance","payment-delivery-atomicity","service-failover-selector","agent-rate-limit-negotiator","execution-cost-estimator","cross-agent-receipt-bundle","capability-verification","capability-benchmark","sybil-reputation-guard","agent-behavior-fingerprint","trust-anomaly-detector","economic-loop-detector","provider-quality-predictor","transaction-risk-score","payment-optimizer","x402-v2-router","erc8004-identity-evidence","erc8004-reputation-intelligence","delegated-spend-policy","ap2-mandate-bridge","a2a-transaction-bridge","mcp-transaction-gateway","proof-of-service","automated-dispute-bundle","transaction-recovery-v2","reputation-update-receipt"],"type":"string"}},"required": ⟨3 unchanged words⟩
A2A Transaction Bridge — Bind an A2A task to a transaction without silently transferring authority.; 0.004 USDC. Deterministic, evidence-bounded and signed.
Added "agent_approval_relay", "capability_negotiation_preflight", "durable_agent_task" and 7 more; changed the definition of "try_service" (75 tools before, 85 now)
⟨70 unchanged words⟩ ,"live-data-freshness","person-enrichment-evidence","company-enrichment-evidence","contact-enrichment-evidence","mcp-2026-compatibility-gateway","durable-agent-task","task-checkpoint-evidence","task-cancel-assurance","agent-approval-relay","capability-negotiation-preflight","mcp-catalog-cache-guard","oauth-issuer-binding-evidence","mcp-a2a-task-bridge","quote-freshness-guard"],"type":"string"}},"required": ⟨3 unchanged words⟩
Agent Approval Relay — Agent Approval Relay; deterministic signed assessment over supplied input.
Capability Negotiation Preflight — Capability Negotiation Preflight; deterministic signed assessment over supplied input.
Changed the definition of "try_service"
⟨57 unchanged words⟩ ,"retention-deletion-receipt","interrupted-task-recovery","portable-observability-audit","index-feed","verified-web-extract","entity-enrichment-evidence","social-source-evidence","market-data-snapshot","onchain-evidence","verified-news-monitor","multi-source-fact-bundle","document-to-verified-json","source-backed-search","live-data-freshness","person-enrichment-evidence","company-enrichment-evidence","contact-enrichment-evidence"],"type":"string"}},"required": ⟨3 unchanged words⟩
Changed the definition of "company_enrichment_evidence", "contact_enrichment_evidence" and "person_enrichment_evidence"
Company enrichmentfrom domain, profile, tickerwithorfreenameinputwithpreflight, provider attribution and signed evidence; 0.005 USDC.
{"anyOfadditionalProperties":[true,"description":"Company identifier: pdl_id, website/domain, profile, ticker, name, company, or identifier; nested input/query/entity/company accepted. Validation occurs before payment.","minProperties":1,"properties":
Added "company_enrichment_evidence", "contact_enrichment_evidence" and "person_enrichment_evidence" (72 tools before, 75 now)
Company enrichment from domain, profile, ticker or name with provider attribution and signed evidence; 0.005 USDC.
Business-contact enrichment from strong identifiers with explicit identity limitations and a signed receipt; 0.007 USDC.
Person enrichment from strong identifiers with provider attribution, likelihood, limitations and a signed receipt; 0.006 USDC.
Added "document_to_verified_json", "entity_enrichment_evidence", "live_data_freshness" and 7 more (62 tools before, 72 now)
Public text, HTML, JSON or XML normalized to source-backed JSON; no OCR; 0.010 USDC.
Source-bounded entity field coverage with explicit missing facts; 0.008 USDC.
Evaluate live source observation against explicit maximum age; 0.002 USDC.
Timestamped public market-data snapshot with provenance; 0.005 USDC.
Independent source observations with agreement made explicit; 0.005 USDC.
Certificate recorded, valid to 2026-10-28
Authorization not required
Added "index_feed"; changed the definition of "try_service" (61 tools before, 62 now)
⟨56 unchanged words⟩ ,"purpose-bound-consent","retention-deletion-receipt","interrupted-task-recovery","portable-observability-audit","index-feed"],"type":"string"}},"required": ⟨3 unchanged words⟩
PHION Index Feed — Canonical catalog snapshot or digest-based delta with exact HTTP/MCP records, PHION Execute templates and signed evidence; 0.005 USDC.
Added "phion_execute"; changed the definition of "abandoned_tool_detector", "concurrency_guard", "conflict_resolution" and 27 more (60 tools before, 61 now)
before
—after
Abandoned Tool DetectorAssessRequiretoolstalereachabilitysuccessandplusstaleness;multiple independent failed probes before classifying likely abandonment; 0.003 USDC.
Added "abandoned_tool_detector", "agent_budget_guard", "agent_task_handoff_receipt" and 36 more; changed the definition of "try_service" (21 tools before, 60 now)
⟨18 unchanged words⟩ ,"schema-normalize","sanctions-screening-evidence","agent-reputation-evidence","counterparty-risk-preflight","tool-output-firewall","delegation-scope-guard","memory-write-guard","mcp-manifest-firewall","tool-call-policy-guard","data-egress-preflight","agent-budget-guard","idempotency-replay-guard","human-approval-policy","secret-redaction-preflight","oauth-token-audience-guard","redirect-callback-validator","tool-capability-drift-monitor","mcp-server-identity-evidence","agent-task-handoff-receipt","context-provenance-labeler","signed-result-comparator","service-sla-attestation","payment-route-selector","x402-quote-comparator","payment-receipt-reconciler","duplicate-charge-detector","subscription-spend-guard","webhook-verifier","delivery-evidence","inter-agent-policy-evaluator","concurrency-guard","resource-cycle-guard","abandoned-tool-detector","manifest-version-diff","dependency-provenance-assessment","conflict-resolution","data-freshness-certificate","domain-ownership-evidence","purpose-bound-consent","retention-deletion-receipt","interrupted-task-recovery","portable-observability-audit"],"type":"string"}},"required": ⟨3 unchanged words⟩
Unknown → Live
First tool surface recorded: 21 tools (server version 1.8.0)
https://phion.systems/mcp (mcp_streamable_http) — from mcp_registry, with the record
Showing the latest 21 events. The API returns up to 500 and filters by kind: ?kind=tool_surface_changed
before
—after
Get PHION Service Contractbefore
—after
Check PHION Service Preflightbefore
—after
Resolve an Agent Capabilitybefore
—after
Search PHION Servicesbefore
—after
Verify a PHION Receiptbefore
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}Declare Payment Capability — Free anonymous non-blocking self-report of wallet, mandate, x402 v2, network, asset and funding readiness. Stores only a daily pseudonymous actor and normalized reason; never a wallet, balance, signature or request content.
PHION Intelligence — Search, synthesize and cite evidence in one call, minimizing residual agent work.; 0.012 USDC. Deterministic, evidence-bounded and signed.
PHION Search — Search the live web and return normalized source URLs and snippets with signed delivery.; 0.006 USDC. Deterministic, evidence-bounded and signed.
Cross-Protocol Receipt — Bundle consistent transaction commitments across multiple protocols.; 0.004 USDC. Deterministic, evidence-bounded and signed.
Dynamic Service Pricing — Propose a capped shadow price without changing the live catalog.; 0.004 USDC. Deterministic, evidence-bounded and signed.
Market Demand Predictor — Forecast verified demand trends while abstaining on insufficient history.; 0.005 USDC. Deterministic, evidence-bounded and signed.
Multi-Agent Escrow — Recommend hold or release from evidence without PHION custody or fund movement.; 0.005 USDC. Deterministic, evidence-bounded and signed.
Price Discovery Engine — Derive price bands only from settled observations, never traffic or unsigned quotes.; 0.005 USDC. Deterministic, evidence-bounded and signed.
Service Gap Detector — Detect capability shortages using verified demand and verified provider supply.; 0.004 USDC. Deterministic, evidence-bounded and signed.
SLA Risk Predictor — Estimate SLA failure probability from bounded success and latency evidence.; 0.004 USDC. Deterministic, evidence-bounded and signed.
Agent Behavior Fingerprint — Create a privacy-minimized behavioral commitment without retaining payloads or raw identifiers.; 0.003 USDC. Deterministic, evidence-bounded and signed.
Agent Memory Provenance — Agent Memory Provenance; deterministic signed assessment over supplied input.
Agent Rate Limit Negotiator — Agent Rate Limit Negotiator; deterministic signed assessment over supplied input.
Agent Session Continuity — Agent Session Continuity; deterministic signed assessment over supplied input.
AP2 Mandate Bridge — Map mandate fields for review without advertising unsupported AP2 production authorization.; 0.004 USDC. Deterministic, evidence-bounded and signed.
Automated Dispute Bundle — Assemble failure evidence and recommend resolution without executing refunds.; 0.005 USDC. Deterministic, evidence-bounded and signed.
Capability Benchmark — Measure reproducible success, latency and cost from versioned evidence-bound benchmark cases.; 0.004 USDC. Deterministic, evidence-bounded and signed.
Capability Verification — Separate claimed capabilities from independently evidenced successful demonstrations.; 0.003 USDC. Deterministic, evidence-bounded and signed.
Cross-Agent Receipt Bundle — Cross-Agent Receipt Bundle; deterministic signed assessment over supplied input.
Delegated Credential Guard — Delegated Credential Guard; deterministic signed assessment over supplied input.
Delegated Spend Policy — Fail closed when delegated authority, per-call limit or remaining budget is insufficient.; 0.003 USDC. Deterministic, evidence-bounded and signed.
Economic Loop Detector — Detect self-transfer and reciprocal economic patterns without presenting correlation as fraud.; 0.004 USDC. Deterministic, evidence-bounded and signed.
ERC-8004 Identity Evidence — Bind an ERC-8004 registry identity to evidence while separating registration from ownership.; 0.004 USDC. Deterministic, evidence-bounded and signed.
ERC-8004 Reputation Intelligence — Aggregate diverse verified reputation observations with low-sample abstention.; 0.004 USDC. Deterministic, evidence-bounded and signed.
Execution Cost Estimator — Execution Cost Estimator; deterministic signed assessment over supplied input.
MCP Transaction Gateway — Bind an MCP tool call to transaction evidence without granting undeclared authority.; 0.004 USDC. Deterministic, evidence-bounded and signed.
Payment Delivery Atomicity — Payment Delivery Atomicity; deterministic signed assessment over supplied input.
Payment Optimizer — Rank only integration-tested payment routes under explicit cost and latency constraints.; 0.003 USDC. Deterministic, evidence-bounded and signed.
Proof of Service — Commit request, authority, execution, payment and delivery evidence in one proof.; 0.005 USDC. Deterministic, evidence-bounded and signed.
Provider Quality Predictor — Estimate provider success, quality, latency and cost using transparent sample-aware statistics.; 0.004 USDC. Deterministic, evidence-bounded and signed.
Reputation Update Receipt — Recommend a bounded auditable reputation update from verified outcome evidence.; 0.004 USDC. Deterministic, evidence-bounded and signed.
Service Failover Selector — Service Failover Selector; deterministic signed assessment over supplied input.
Sybil Reputation Guard — Combine multiple bounded Sybil signals while abstaining without independent evidence.; 0.004 USDC. Deterministic, evidence-bounded and signed.
Task Lease Guard — Task Lease Guard; deterministic signed assessment over supplied input.
Tool Result Schema Validator — Tool Result Schema Validator; deterministic signed assessment over supplied input.
Transaction Recovery v2 — Recommend bounded recovery and reconcile ambiguous payments before retry.; 0.005 USDC. Deterministic, evidence-bounded and signed.
Transaction Risk Score — Estimate evidence-supported loss probability without selling insurance or assuming liability.; 0.004 USDC. Deterministic, evidence-bounded and signed.
Trust Anomaly Detector — Detect material drift between comparable trust vectors without asserting misconduct.; 0.003 USDC. Deterministic, evidence-bounded and signed.
x402 v2 Router — Select an exactly compatible x402 v2 payment requirement without receiving private keys.; 0.003 USDC. Deterministic, evidence-bounded and signed.
Durable Agent Task — Durable Agent Task; deterministic signed assessment over supplied input.
MCP 2026 Compatibility Gateway — MCP 2026 Compatibility Gateway; deterministic signed assessment over supplied input.
MCP-A2A Task Bridge — MCP-A2A Task Bridge; deterministic signed assessment over supplied input.
MCP Catalog Cache Guard — MCP Catalog Cache Guard; deterministic signed assessment over supplied input.
OAuth Issuer Binding Evidence — OAuth Issuer Binding Evidence; deterministic signed assessment over supplied input.
Quote Freshness Guard — Quote Freshness Guard; deterministic signed assessment over supplied input.
Task Cancel Assurance — Task Cancel Assurance; deterministic signed assessment over supplied input.
Task Checkpoint Evidence — Task Checkpoint Evidence; deterministic signed assessment over supplied input.
Business-contact enrichmentfrom strongwithidentifiersfreewithinputexplicitpreflight, identity limitations andasigned receipt; 0.007 USDC.
{"anyOfadditionalProperties":[true,"description":"Person identifier: pdl_id, email, email_hash, phone, lid, profile, or name plus context; nested input/query/subject/person/contact accepted. Validation occurs before payment.","minProperties":1,"properties":{"requiredbirth_date":[{"type":"string"},"company":{"description":"Company name or nested input object"},"contact":{"type":"object"},"country":{"type":"string"},"email"]:{"type":"string"},"email_hash":{"requiredtype":["profilestring"]},"entity":{"requiredtype":["nameobject"},"companyfirst_name"]:{"type":"string"}],"propertiesidentifier":{"description":"Email, profile URL, phone, company domain, ticker or name; interpreted by service","type":"string"},"input":{"type":"object"},"last_name":{"type":"string"},"
Person enrichmentfromwithstrongfreeidentifiersinputwithpreflight, provider attribution, likelihood, limitations andasigned receipt; 0.006 USDC.
{"anyOfadditionalProperties":[{true,"requireddescription":["Person identifier: pdl_id, email, email_hash, phone, lid, profile, or name plus context; nested input/query/subject/person/contact accepted. Validation occurs before payment."]},"minProperties":1,"properties":{"requiredbirth_date":[{"profiletype"]:"string"},"company":{"requireddescription":["Company name or nested input object"},"companycontact"]:{"type":"object"},"country":{"requiredtype":["namestring"},"locationemail"]:{"type":"string"}],"propertiesemail_hash":{"type":"string"},"entity":{"type":"object"},"first_name":{"type":"string"},"identifier":{"description":"Email, profile URL, phone, company domain, ticker or name; interpreted by service","type":"string"},"input":{"type":"object"},"last_name":{"type":"string"},"
Public explorer or RPC response evidence with immutable hashes; 0.004 USDC.
Attributable public social-source observations with identity limitations; 0.006 USDC.
Literal search over supplied public sources with citations and hashes; 0.004 USDC.
Literal query evidence across bounded public news sources; 0.006 USDC.
Bounded public web extraction with source, timestamp and hashes; 0.003 USDC.
{"additionalProperties":false,"properties":{"policy":{"type":"object"},"tool":{"required":["last_success_at","reachable","independent_probe_count"],"type":"object"}},"required":["tool","policy"],"type":"object"}
before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}before
—after
Concurrency GuardEnforceFailconcurrentclosedslotunlesslimits;capacity counter is fresh and the request carries a lease plus idempotency binding; 0.002 USDC.
{"additionalProperties":false,"properties":{"active_slots":{"minimum":0,"type":"integer"},"counter_observed_at":{"type":"integer"},"idempotency_key":{"type":"string"},"lease_id":{"type":"string"},"lease_valid_until":{"type":"integer"},"policy":{"required":["maximum_slots"],"type":"object"},"requested_slots":{"minimum":1,"type":"integer"}},"required":["requested_slots","active_slots","lease_id","idempotency_key","lease_valid_until","counter_observed_at","policy"],"type":"object"}
before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}Resolveresultorconflictsabstain;byeveryexplicitcandidatepolicy;must bind source, value hash, observation time and bounded confidence; 0.003 USDC.
{"properties":{"candidates":{"items":{"required":["source","value_sha256","observed_at","confidence"],"type":"object"},"maxItems":100,"minItems":2,"type":"array"},"policy":{"type":"object"}},"required":["candidates","policy"],"type":"object"}
Certifydeclaredfreshnessdataonlyagewhenagainsttimestamppolicy;is bound to source URI and a 64-hex content hash; 0.002 USDC.
{"properties":{"data":{"required":["observed_at","source_uri","content_sha256"],"type":"object"},"policy":{"required":["maximum_age_seconds"],"type":"object"}},"required":["data","policy"],"type":"object"}
before
—after
Delivery EvidenceHashBind successful delivery to transaction, request andsignmatchingdelivery64-hexevidence;expected/observed content hashes without echoing content; 0.003 USDC.
{"additionalProperties":false,"properties":{"delivery":{"required":["transaction_id","status","delivered_at","content_sha256","expected_content_sha256","request_sha256"],"type":"object"}},"required":["delivery"],"type":"object"}
before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}AssessFaildeclaredclosed on empty dependencyprovenancesetscoverage;or absent registry policy; distinguish digest declarations from verified provenance; 0.003 USDC.
{"properties":{"dependencies":{"maxItems":1000,"minItems":1,"type":"array"},"policy":{"required":["allowed_registries"],"type":"object"}},"required":["dependencies","policy"],"type":"object"}
AttestRequiredeclaredadomain-controlfreshproofdomain-boundstatus;DNS-01/HTTP-01 challenge and separate control from legal ownership; 0.003 USDC.
{"properties":{"domain":{"type":"string"},"evidence":{"required":["domain","method","verified_at","challenge_sha256","independently_verified"],"type":"object"}},"required":["domain","evidence"],"type":"object"}
before
—after
Duplicate Charge DetectorDetectduplicaterepeatedchargetransactionfingerprints;hashes, payment identifiers and idempotent intents; 0.003 USDC.
{"additionalProperties":false,"properties":{"charges":{"items":{"type":"object"},"maxItems":1000,"minItems":1,"type":"array"}},"required":["charges"],"type":"object"}
before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}x402Independentlypaidfetchindependentboundedwebpublicevidence;evidence0.004withUSDCredirect/DNS/connected-addressonSSRFBase.checks, hashes and injection screening; 0.004 USDC.
before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true}Pre-payment agent inspection across x402,paidA2A,AI-agentERC-8004,dueOpenAPIdiligence;and0.009MCP;USDCfailedoninspectionsBase.are not charged; 0.009 USDC.
before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true}before
—after
Inter-Agent Policy EvaluatorCompare agentRequire policy identity, subject, action, lifetime and valid decisions; compute the restrictive cap and shared actions; 0.003 USDC.
{"additionalProperties":false,"properties":{"policies":{"items":{"required":["policy_id","subject","action","expires_at","decision"],"type":"object"},"maxItems":64,"minItems":2,"type":"array"}},"required":["policies"],"type":"object"}
before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}PlanResumeboundedonlytaskwhenresumption;task/checkpoint identity, sequence, deadline, attempt budget, idempotency and side effects are explicit; 0.003 USDC.
{"properties":{"checkpoint":{"required":["task_id","sequence","state_sha256"],"type":"object"},"policy":{"required":["max_attempts"],"type":"object"},"task":{"required":["task_id","attempts","deadline","side_effect_status"],"type":"object"}},"required":["task","checkpoint","policy"] ⟨2 unchanged words⟩
x402 paidVerifyverificationhashofcontinuity,atimestampscommerceandjourney;ordered0.010intent→quote→payment→deliveryUSDClifecycle;on0.010Base.USDC.
{"properties":{"events":{"maxItems":128,"minItems":2,"type":"array"},"expected":{"type":"object"},"journey_id":{"maxLength":128,"type":"string"}},"required":["journey_id","events","expected"],"type":"object"}
before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}x402Atomicpaidspendingatomicreservationspending-mandatewithreservation;cumulative0.004capUSDCandonconflict-safeBase.idempotency; 0.004 USDC.
{"properties":{"amount":{"pattern":"^[1-9][0-9]*$","type":"string"},"capability_token":{"maxLength":256,"minLength":32,"type":"string"},"cumulative_limit":{"pattern":"^[1-9][0-9]*$","type":"string"},"idempotency_key":{"maxLength":128,"type":"string"},"mandate_id":{"maxLength":128,"type":"string"},"ttl_seconds":{"maximum":3600,"minimum":1,"type":"integer"}},"required":[" ⟨7 unchanged words⟩
before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":false}HashRecursiveandmanifest diffmanifests;that requires explicit versions and flags sensitive changes without a version advance; 0.002 USDC.
{"properties":{"current":{"required":["version"],"type":"object"},"previous":{"required":["version"],"type":"object"}},"required":["previous","current"],"type":"object"}
Fail-closed x402paidv2deterministicfirewallpaymentforfirewall;network,0.002asset,USDCrecipient,onamount,Base.scheme, resource host and expiry; 0.002 USDC.
{"properties":{"intent_id":{"maxLength":128,"type":"string"},"payment_requirement":{"type" ⟨9 unchanged words⟩
before
—after
{"required":["decision","receipt","charged"],"type":"object"}before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}before
—after
Payment Receipt ReconcilerReconcileComparepaymentcanonical andreceiptcommonfields;x402 payment/receipt aliases, settlement state and coverage; 0.003 USDC.
{"additionalProperties":false,"properties":{"payment":{"type":"object"},"receipt":{"type":"object"}},"required":["payment","receipt"],"type":"object"}
before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}Validate event identity, timestamps, hash chain andsignW3C-compatiblealowercaseportablenonzeroeventtrace/spanchain;identifiers; 0.004 USDC.
{"properties":{"events":{"items":{"required":["event_id","observed_at","trace_id","span_id"],"type":"object"},"maxItems":1000,"minItems":1,"type":"array"}},"required":["events"],"type":"object"}
Bind declaredFail-closed consent bound to ID, subject, recipient, purpose, scope, issue/expiry andexpiry;checked revocation state; 0.003 USDC.
{"properties":{"action":{"required":["subject","recipient","purpose","scope"],"type":"object"},"consent":{"required":["consent_id","subject","recipient","purpose","scope","issued_at","expires_at","revocation_checked","revoked"],"type":"object"}},"required":["consent","action"],"type":"object"}
before
—after
Resource Cycle GuardStopRequireexecutionper-steploopsidentity, token andstepcostoverruns;counters; detect repeated nodes/edges and enforce all three hard caps; 0.002 USDC.
{"additionalProperties":false,"properties":{"policy":{"required":["max_steps","max_tokens","max_cost_atomic"],"type":"object"},"trace":{"items":{"required":["id","tokens","cost_atomic"],"type":"object"},"type":"array"}},"required":["trace","policy"],"type":"object"}
before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}SignSeparatearequested,declaredoperator-completedretentionandorevidence-verifieddeletionretention/deletionaction;states using content and evidence hashes; 0.003 USDC.
{"properties":{"action":{"required":["kind"],"type":"object"},"record":{"required":["record_id","content_sha256"],"type":"object"}},"required":["record","action"],"type":"object"}
RWAFail-closed issuer, contract, jurisdiction, custody anddocument duedocumentationdiligencecoverage withliveindependently fetched evidence; 0.019 USDC.
before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true}DeterministicFail-closed RWAeligibilitytransfer decision requiring explicit jurisdiction, KYC, allowlist, limit andtransfer-policytransfer-windowassessment;checks; 0.012 USDC.
before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":true,"readOnlyHint":true}Compare declared NAV,reservesandorreservecollateralratios with structured observed facts plus independently fetched evidence; returns discrepancies in basis points and fails closed on incomplete evidence; 0.015 USDC.
{"additionalProperties":false,"properties":{"asset":{"minProperties":1,"type":"object"},"declared_facts":{"required":["nav","reserve_ratio","as_of","unit"],"type":"object"},"observed_facts":{"required":["nav","reserve_ratio","as_of","unit"],"type":"object"},"source_urls":{"maxItems":5,"minItems":1,"type":"array"},"tolerance_bps":{"maximum":10000,"minimum":0,"type":"integer"}},"required":["asset","declared_facts","observed_facts","source_urls"],"type":"object"}
before
—after
{"required":["charged","assessment","receipt"],"type":"object"}SignedSafeschemaalias normalizationand repairthatreceipt;refuses0.001ambiguousUSDCcanonical/aliasoncollisionsBase.andNevernever changespayment-criticalpaymentvalues.values; 0.001 USDC.
before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}before
—after
Subscription Spend GuardEnforceBind one recurringspendingchargelimits;to approval, merchant, due time and per-charge/period budgets; 0.003 USDC.
{"additionalProperties":false,"properties":{"policy":{"required":["period_limit_atomic"],"type":"object"},"subscription":{"required":["next_charge_atomic"],"type":"object"},"usage":{"type":"object"}},"required":["subscription","usage","policy"] ⟨2 unchanged words⟩
before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}x402 paid end-to-end transaction assurance; 0.015 USDC on Base. Separately verifiesEnd-to-end settlement,deliverytimestamp, delivery-hash and deterministicacceptance.acceptance assurance; 0.015 USDC.
before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}x402 paid transaction failureFailure classification andsignednon-repeating recoveryclaim;plan0.010withUSDCvalidatedonattemptBase.history; 0.010 USDC.
before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}before
—after
Webhook VerifierValidateFail-closed RFC 9421-style webhooksignaturepreflight requiring trusted key, algorithm, nonce, freshness, replay status andfreshnesssignatureevidence;coverage of method, target and content; 0.003 USDC.
{"additionalProperties":false,"properties":{"event":{"required":["delivery_id","timestamp","payload"],"type":"object"},"verification":{"required":["signature_valid","trusted_key","algorithm","key_id","nonce","verified_components","replay_seen"],"type":"object"}},"required":["event","verification"],"type":"object"}
before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}before
—after
x402 Quote ComparatorNormalizeValidate x402 v2 fields and comparex402onlyquotes;quotes sharing asset and decimals; 0.002 USDC.
{"additionalProperties":false,"properties":{"quotes":{"items":{"properties":{"amount":{"type":["string","integer"]},"asset":{"type":"string"},"asset_decimals":{"type":"integer"},"expires_at":{"type":"integer"},"network":{"type":"string"},"payTo":{"type":"string"},"scheme":{"type":"string"},"x402Version":{"type":"integer"}},"required":["network","asset","asset_decimals","amount","payTo"],"type":"object"},"maxItems":64,"minItems":2,"type":"array"}},"required":["quotes"],"type":"object"}
before
—after
{"destructiveHint":false,"idempotentHint":true,"openWorldHint":false,"readOnlyHint":true}Universal PHION execution gateway: enforce a budget and persistent idempotency, execute one selected PHION service, evaluate acceptance criteria, and return a signed completion envelope. No gateway surcharge; the selected service price applies.
Assess tool reachability and staleness; 0.003 USDC.
Enforce per-call, task, session and period budgets; 0.002 USDC.
Sign a bounded agent-task handoff; 0.003 USDC.
Enforce concurrent slot limits; 0.002 USDC.
Resolve result conflicts by explicit policy; 0.003 USDC.
Hash and label context integrity, confidentiality and source; 0.002 USDC.
Inspect outbound agent data and destination before transmission; 0.002 USDC.
Certify declared data age against policy; 0.002 USDC.
Least-privilege guard for agent-to-agent delegation scope, destinations, budget and expiry; 0.003 USDC.
Hash and sign delivery evidence; 0.003 USDC.
Assess declared dependency provenance coverage; 0.003 USDC.
Attest declared domain-control proof status; 0.003 USDC.
Detect duplicate charge fingerprints; 0.003 USDC.
Classify an action as automatic, approval-required or denied; 0.002 USDC.
Detect safe replays and conflicting idempotency-key reuse; 0.002 USDC.
Compare agent policy decisions; 0.003 USDC.
Plan bounded task resumption; 0.003 USDC.
Hash and diff manifests; 0.002 USDC.
Inspect an MCP manifest before installation or trust; 0.002 USDC.
Bind MCP domain, endpoint, manifest, key and version; 0.003 USDC.
Screen persistent memory writes for poisoning, unsafe instructions and missing provenance; 0.002 USDC.
Validate declared OAuth audience and issuer; never send raw tokens; 0.002 USDC.
Free diagnosis of the exact payment-funnel stage and machine-readable recovery actions for any PHION service.
Reconcile payment and receipt fields; 0.003 USDC.
Payment Route Selector — Reject impossible x402 routes, rank safe eligible routes by policy and return the exact next payment action; read-only, deterministic, 0.002 USDC.
Validate and sign a portable event chain; 0.004 USDC.
Bind declared consent to purpose, scope and expiry; 0.003 USDC.
Validate HTTPS callbacks and redirect host allowlists; 0.002 USDC.
Stop execution loops and step overruns; 0.002 USDC.
Sign a declared retention or deletion action; 0.003 USDC.
Detect and redact common secret indicators before transmission; 0.002 USDC.
Sign availability and latency calculations from bounded samples; 0.004 USDC.
Compare agent results and sign agreement or conflict; 0.003 USDC.
Enforce recurring spending limits; 0.003 USDC.
Bind a proposed tool call to declared intent and execution policy; 0.002 USDC.
Detect tool capability or manifest drift; 0.002 USDC.
Inspect untrusted MCP/tool output before it enters agent context or triggers an action; 0.002 USDC.
Validate webhook signature status and freshness evidence; 0.003 USDC.
Normalize and compare x402 quotes; 0.002 USDC.