MCP-Server

Assay: settlement verification

io.fomox/assay
Krypto & Web3 Payments & Fintech Sicherheit Öffentlich und erreichbar MCP 2026-07-28

Was dieses MCP kann

Verifies actual blockchain payment settlement and delivery amounts and evaluates transfers against server-side spending policies.

check_sandbox_answer
Score your decision on a sandbox case. Tell it whether you would have credited the payment and for how much, and it replies with whether that was correct and, if not, exactly what the error would have cost you in real units. This is the fastest way to find out whether your payment handling is actually safe.
Eingabeschema
{'type': 'object', 'required': ['caseId', 'credit'], 'properties': {'amount': {'type': 'string', 'description': "If crediting, how much, in the asset's smallest units."}, 'caseId': {'type': 'string', 'description': 'The case you ran.'}, 'credit': {'type': 'boolean', 'description': 'Would you have credited this payment?'}}}
evaluate_spend_policy
Check a proposed payment against spending limits that live OUTSIDE your context, where no instruction in a prompt, a message or a web page can change them. Returns a signed allow or deny with reasons. Use this before executing any transfer on behalf of a user. It enforces velocity caps, per-action ceilings, recipient allowlists and asset allowlists. Because the rules are held server side and signed, an attacker who takes over your reasoning still cannot raise your limits. IMPORTANT: this is ADVISORY. Assay holds no keys and cannot stop a transaction. Verify the signature and enforce the decision wherever you sign. Create a policy first with the /v1/policy endpoint.
Eingabeschema
{'type': 'object', 'required': ['policyId', 'policySecret', 'action'], 'properties': {'action': {'type': 'object', 'properties': {'to': {'type': 'string', 'description': 'Recipient address.'}, 'type': {'type': 'string', 'description': 'e.g. transfer. Recorded, not interpreted.'}, 'asset': {'type': 'string', 'description': 'Symbol or contract id.'}, 'chain': {'type': 'string'}, 'amount': {'type': 'string', 'description': 'Base units as a string.'}}, 'description': 'The payment you are about to make.'}, 'commit': {'type': 'boolean', 'description': "Default true: an allowed action counts against velocity limits. Pass false to ask 'would this be allowed' without consuming budget."}, 'policyId': {'type': 'string', 'description': 'From creating a policy.'}, 'policySecret': {'type': 'string', 'description': 'The secret returned when the policy was created. Shown once, stored only as a hash.'}}}
list_chains
List every chain this service can verify, with the confirmation depth each needs before a payment is treated as final, and how deeply it can be verified. Call this if you are unsure whether a chain is supported or what to pass as `chain`.
Eingabeschema
{'type': 'object', 'properties': {}}
list_failure_modes
List every known way a blockchain payment can appear successful while being worth less than it claims, or nothing at all. Each entry explains what the chain does, what it costs you when you get it wrong, and the one-line fix. Useful when writing or reviewing code that credits users for incoming crypto payments. Every chain has its own dialect but they are all the same few lies, and the mitigation is always the same: never trust the stated amount, reconstruct what actually moved.
Eingabeschema
{'type': 'object', 'properties': {'family': {'type': 'string', 'description': 'Optionally filter to one family: xrpl, evm, utxo, svm, hedera, algorand, or all.'}}}
run_sandbox_case
Practise on a payment designed to deceive you, with no money at risk. Returns a verification result shaped exactly like a real one for one of 19 adversarial cases. Decide whether you would credit it, then call check_sandbox_answer to find out whether you were right and what the mistake would have cost. Use this to test any agent or integration that handles incoming crypto payments BEFORE it handles real money.
Eingabeschema
{'type': 'object', 'properties': {'caseId': {'type': 'string', 'description': 'Which case to run. Omit to get the list of available cases.'}}}
verify_payment
Check whether a crypto payment really settled and how much was ACTUALLY delivered, which is often not the amount the transaction claims. Use this before crediting anyone for an incoming payment. Returns `delivered` (what truly moved), `claimed` (what the transaction says), `mismatch` (true when they disagree), and `warnings` naming the specific trap with a remedy. `ok` is true ONLY when the payment is final and meets everything you asserted in `expect`; anything uncertain returns ok:false, so it is safe to gate a credit on `ok`. Chains: xrp, hedera, algorand, solana, ethereum, base, arbitrum, optimism, polygon, bnb, avalanche, linea, scroll, zksync, blast, mantle, celo, gnosis, bitcoin, litecoin. Pass `expect` whenever you can. Without it this reports what happened; with it, it tells you whether to pay. Read only: this never moves funds and never holds keys.
Eingabeschema
{'type': 'object', 'required': ['ref'], 'properties': {'ref': {'type': 'string', 'description': 'The transaction hash or id. EVM: 0x + 64 hex. XRP: 64 hex. Solana: base58 signature. Bitcoin: 64 hex. Hedera: 0.0.1234-1700000000-123456789. Algorand: 52 base32 chars. Or a sandbox case like sandbox:xrp_partial_payment.'}, 'chain': {'type': 'string', 'description': 'Chain id. One of: xrp, hedera, algorand, solana, ethereum, base, arbitrum, optimism, polygon, bnb, avalanche, linea, scroll, zksync, blast, mantle, celo, gnosis, bitcoin, litecoin. Common aliases work too (eth, btc, matic, bsc, avax, sol, xrpl). Not needed for sandbox: references.'}, 'expect': {'type': 'object', 'properties': {'to': {'type': 'string', 'description': 'The address that should have received it. Required on Bitcoin and Litecoin to get a meaningful delivered amount, because a UTXO transaction has many outputs and most of them may be change.'}, 'memo': {'type': 'string', 'description': 'Expected destination tag or memo, used to attribute a payment on a shared receiving address.'}, 'asset': {'type': 'string', 'description': 'Expected asset symbol, e.g. USDC. Symbols are not unique, so prefer assetId.'}, 'amount': {'type': 'string', 'description': 'Minimum acceptable amount in the asset\'s SMALLEST units, as a string (1 USDC = "1000000"). Compared against DELIVERED, never against the claimed amount.'}, 'assetId': {'type': 'string', 'description': 'Expected contract address or canonical token id. The reliable way to avoid being paid in a counterfeit token with the right symbol.'}, 'minConfirmations': {'type': 'integer', 'description': 'Override the chain default before treating the payment as final.'}}, 'description': 'What you believe should be true. Supplying this is what lets `ok` mean anything.'}, 'rpcUrl': {'type': 'string', 'description': 'Optional. Your own HTTPS RPC endpoint for this chain. Bypasses our rate limits entirely and usually returns faster.'}}}
Hinzugefügt
check_sandbox_answer
27. September 2026 02:40
Hinzugefügt
run_sandbox_case
27. September 2026 02:40
Hinzugefügt
evaluate_spend_policy
27. September 2026 02:40
Hinzugefügt
list_failure_modes
27. September 2026 02:40
Hinzugefügt
list_chains
27. September 2026 02:40
Hinzugefügt
verify_payment
27. September 2026 02:40