TWZRD Agent Intel MCP
Buyer-side pre-spend reputation gate for Solana x402 agents (22 tools live).
What it can do
- Get Readiness Card Tool: PRIMARY free pre-spend gate (advisory). Pass seller_wallet OR resource_name. When to use: before any x402 payment to a seller/resource. When not to use: after you already deci
- Evaluate X402 Resource: One-shot x402 guard. Fetches resource_url, extracts the seller wallet from the 402 accepts array (prefers Solana network entries), runs TWZRD preflight, and returns a spending
- Low Level Preflight: Low-level preflight check. Returns a richer result object including the upsell path to the paid /v1/intel/trust surface with v6 receipt. Prefer get_readiness_card_tool for most ca
What data it sees
Do you need an account
No: the server works without sign-in
Buyer-side pre-spend reputation gate for Solana x402 agents (22 tools live). Check a counterparty BEFORE paying an x402 endpoint, and know exactly when to check again: every paid trust receipt carries a machine-readable re-call signal (recheck_after_unix + step decay). Live watch registration (twzrd_watch_add/list/remove) makes TWZRD push recheck_due on seller change.
All MCP tools free: preflight, scores, seller reputation (repeat_payer_pct, tier, observed graph signals), wash/Sybil, marketplace directory with seller signals, facilitator footprint, counterparty graphs, prediction-market data, offline receipt verification.
Signals describe observed settlement behavior, not identity. Paid corpus score + v6 receipt: GET https://intel.twzrd.xyz/v1/intel/trust/GFpLvocNdEjnSsLH3VJQL6wGcjGxTbUBrj6fqN3Qe1Gs (0.05 USDC over x402 v2).
Server tool list (20)
Raw names from tools/list. Only developers need these.
| get_readiness_card_tool | PRIMARY free pre-spend gate (advisory). Pass seller_wallet OR resource_name. When to use: before any x402 payment to a seller/resource. When not to use: after you already decided to refuse; use verify_receipt for signed receipts only. Pricing: free. Result is advisory (buyer policy still applies). Decision semantics (top-level, no nesting via MCP): decision=block / recommended_action=do_not_pay -> DO NOT PAY. decision=warn / recommended_action=proceed_with_cap -> pay only up to maximum_recommended_spend_usdc. decision=allow / recommended_action=proceed_for_small_spend -> proceed under agent policy (no free-tier cap). next_action (enrollment handoff — do not stop after free card): next_step_type / payment_required / executable / command describe an optional next step. A host may use command only under its own policy. Never paste path templates (:pubkey / {pubkey}) as seller_wallet. Also returns reason_codes[], confidence, model_version, decision_envelope. trust_score is a free heuristic, NOT the full corpus. Next: on allow/warn for material spend, next_action.command is the optional AgentCash paid-trust or AutoGate install string, then verify_receipt when you have a V6 receipt. Optional: twzrd_watch_add for re-check after recheck_after_unix. Additive: top-level aop_bind program registry (evidence hierarchy) when enabled; never mutates decision / can_spend. |
| evaluate_x402_resource | One-shot x402 guard. Fetches resource_url, extracts the seller wallet from the 402 accepts array (prefers Solana network entries), runs TWZRD preflight, and returns a spending decision. Decision: "allow" -> safe to proceed with the payment. "warn" -> proceed with caution; consider buying the paid trust receipt (receipt_url, $0.05). "block" -> DO NOT PAY. Stop immediately. is_x402 == False -> not an x402 resource (HTTP != 402); treat as allow. Revenue path: when decision is "warn", fetch receipt_url with an x402-capable wallet ($0.05 USDC to TWZRD) to get a signed V6 corpus-backed credential with the full trust score. |
| low_level_preflight | Low-level preflight check. Returns a richer result object including the upsell path to the paid /v1/intel/trust surface with v6 receipt. Prefer get_readiness_card_tool for most callers. Use this when you need max_spend_recommendation_usdc, full_report_hint, or the suggest_full_report flag. The embedded `readiness_card` carries the SAME full shape as get_readiness_card_tool (see the outputSchema). |
| verify_root_inputs | Independent root verification (see tools/root_verifier.py for the recompute logic). |
| get_solana_market_status | Health probe for the Solana Market API data backend. Call this to gate or degrade gracefully BEFORE the other get_solana_market_* tools: it does a short-timeout hit on the data service and reports whether it is reachable, so an agent can tell "market has no data" from "service is down" without failing a real query. Free discovery tool. When the market data service exposes /status, the response includes prod_key_configured, data_first_available, and an actionable note describing what to configure for full on-chain visibility. |
| score_wallet_for_intel | Free discovery: real 0-100 intel score for a wallet from its observed x402 payment history across the broader x402 ecosystem (paid calls, distinct counterparties, volume, recency). Uses a simple transparent heuristic (volume log + breadth + spend log + recency decay) — the exact formula is returned inline as `score_model`. Returns intel_score, the wash-discounted effective_score + wash_flag/wash_factor (cheap Sybil signal), counts, component breakdown, and a data_available flag. Malformed pubkeys are rejected cleanly; the failure path returns the same shape as success. Sourced from the cross-facilitator corpus via the public Rust HTTP endpoint GET /v1/agents/{wallet}/x402 (backed by the x402_solana_payer_agg matview). For the full corpus-breadth renormalized model (intel_renorm_v1_1: score_raw, confidence, breadth_factor, wash_factor) + signed portable v6 receipt, pay for the HTTP surface: GET /v1/intel/trust/{wallet} (0.05 USDC). |
| get_top_intel_agents | Leaderboard of observed payer wallets in the x402 settlement graph, each with its intel score. This is behavioral corpus research, not identity proof or evidence that the wallet is a TWZRD customer. Ranks by the wash-discounted effective_score (single-counterparty fleets are demoted, not hidden) with a deterministic tiebreaker. Set min_paid_calls to suppress one-shot wallets and max_days_since_last to suppress dormant ones. |
| get_provider_reputation | Free discovery: corpus-backed SELLER reputation for a merchant/provider wallet. Answers "is this provider organic, narrow, or a wash fleet?" from the merchant's inbound payment graph over the last 90 days: unique payers, repeat-payer %, heavy-fleet revenue concentration, captive-payer % (onboarding-sink proxy), and a scripted-fleet uniformity signal, and top_payer_tx_pct (captive concentration). Returns wash_label + reputation tier + wash_flagged (tri-state: true | false | null; null = never evaluated, not clean). Complements score_wallet_for_intel (payer side) with the seller side. Fail-open: a DB gap returns wash_label/tier "unknown" AND wash_flagged=null (plus wash_confidence) - an unevaluated verdict, never a clean one. This is the free seller signal; the paid per-wallet renorm model + signed v6 receipt remain at GET /v1/intel/trust/{wallet} (0.05 USDC). |
| get_merchant_card | Free merchant card: observed inbound payment-graph quality around a Solana receive wallet. Dual input (PR-3): pass ``wallet`` and/or ``resource_id``. Resource resolves via the first-party registry (TWZRD seed) to a pay_to, then the same graph card. Does NOT claim service quality (resource_listing_only / catalog_listing_only). HTTP twin: GET /v1/intel/merchant_card/{wallet_or_resource_id}. wash_flagged is tri-state: true (flagged) | false (evaluated clean) | null (never evaluated - NOT clean). Route on next_action.decision (refuse | insufficient_evidence | risk_flagged | listed_unverified | no_negative_signal); the card is down-only and never returns allow. |
| is_wash_fleet | Free discovery: cheap circular-flow (wash) check for a payer wallet. Returns the CATEGORICAL classification (clean / self_pay / reciprocal / self+reciprocal), an is_circular bool, and the observed event counts + distinct_merchants from the wallet's corpus edges. Use as a fast Sybil/wash gate before trusting a counterparty. Fail-open: a DB gap returns classification "unknown". The numeric wash discount (wash_factor / wash_ratio) and the full renormalized model stay paid — they are NOT returned here. |
| verify_receipt | Free utility: offline-verify a portable v5/v6 trust receipt — the "after you pay" half of the loop. Recomputes the Keccak256 leaf from the receipt's preimage (tamper-evidence) AND verifies the Ed25519 signature against the published TWZRD receipt-signing key (authenticity). Returns valid/leaf_valid/signature_valid plus the recomputed leaf and any errors. Pure and offline — no DB, no network, no payment. Pass the entire PaidReceipt object you were issued. Trust is anchored on the published key (or expected_pubkey), NOT on whatever pubkey the receipt carries. max_age_seconds: optional freshness gate (replay protection). Same semantics as the Python library verify_paid_receipt(..., max_age_seconds=...) and the standalone CLI --max-age. |
| get_facilitator_footprint | Free discovery: which x402 facilitators a payer has settled through, and how many. unique_facilitators = 1 is a thin/captive agent (locked to one rail); breadth across facilitators indicates a more established cross-rail agent. Returns the facilitator_ids list plus tx/merchant context. Fail-open: a DB gap returns data_available=false rather than erroring. |
| get_counterparties | Free discovery (capped teaser): the top-N merchants a wallet actually pays, by event count, with per-edge tx_count / total_usdc / first+last timestamps. See WHO a counterparty transacts with before trusting it. The list is capped (default 10, max 25) and `capped`/`total_distinct_merchants` disclose how much is withheld; the FULL deduped payment graph and numeric edge weights are part of the paid intel surface (GET /v1/intel/trust/{wallet}). Fail-open. |
| score_wallets_batch | Free discovery: score up to 25 wallets in a single call (each via the same transparent model as score_wallet_for_intel). Convenience for triaging a set of candidate counterparties at once; `requested`/`capped` disclose any truncation. |
| compare_wallets | Free discovery: side-by-side intel for two wallets (e.g. choosing between two candidate providers). Returns both full score objects and which ranks higher by the wash-discounted effective_score ("tie" on equal, null if a side is unavailable). |
| get_x402_directory | Wash overlay on ingested PayAI/CDP/Agentic listings (PayAI not_indexed). Prefer HTTP GET /v1/intel/resources for the resource join SOT (callable URL + discovery claim listed|live_402 + settlement reputation on pay_to). That surface is HTTP-only so MCP stays at 24 tools. Use this tool when you need the ingested listing overlay indexed by payTo. Solana wash overlay only; Base/Polygon listings carry wash_unknown. Query params — flagged_only, limit, source — mirror GET /v1/intel/x402-directory. |
| twzrd_watch_add | Register a re-call watch on a seller wallet. After registration, TWZRD will proactively re-check the seller's trust intel when `recheck_after_unix` elapses and POST a notification to your webhook_url if the score/decision materially changes. Returns the watch row with the computed recheck_after_unix timestamp so your agent knows exactly when to expect a re-call or proactively re-check itself. |
| twzrd_watch_list | List active re-call watches for your agent wallet. Each watch shows the seller, current score/decision, and recheck_after_unix timestamp — the exact signal for when to re-call. |
| twzrd_watch_remove | Deactivate a re-call watch by ID. payer_wallet must match the owner. |
| twzrd_demo_gate | Runnable, no-spend proof of the TWZRD buyer-side x402 trust gate - discoverable at runtime with no install and no human. Returns a deterministic transcript showing the gate's behaviour on a fixture counterparty: the block path ABORTS and a wallet/signer is never contacted, the allow path would proceed, and ok=true. Spends no USDC, contacts no wallet. This call surfaces an EXTERNAL_RUN *candidate* in TWZRD's honest attribution ledger (it carries a non-internal integration id + your run_id, tagged with your real inbound IP). A candidate is NOT an EXTERNAL_RUN: proof still requires a non-VPS source_ip and matching your run_id to your own transcript via packages/twzrd-agent-intel/scripts/count_attributed_runs.py --confirm. See the returned not_external_run_proof. |