MCPサーバー

aspern

org.aspern/aspern
暗号資産・Web3 セキュリティ 公開・接続可能 MCP 2026-07-28

このMCPでできること

Evaluates blockchain counterparties, agents, vaults, service endpoints, and proposed payments using on-chain activity and operational evidence.

check_service_endpoint
Check a service endpoint before connecting
Call this before connecting to a service, the way preflight_payment is called before sending money. Give it the http(s) URL of an MCP or A2A endpoint and it says who declares it, whether our daily probe reached it, what it answered with, and how many of the last readings answered. It keeps three things apart and never merges them: what an identity DECLARES the endpoint offers, what a probe OBSERVED, and the readings behind that. Read `drift` where present — tools declared but not answering is the signal that an endpoint has changed under the people relying on it. It also answers the three things a buyer wants BEFORE calling a paid endpoint, as separate fields and never folded into one number: `price` is the seller’s own published amount, asset, network and payee; `handshake` says whether it answered without credentials, which is the nearest observable thing to “can I try it”; and `measured` is how many of how many days answered and how slow it was, which is what we read rather than a guarantee anybody made. `manifest` and `changes` answer the question a registry cannot: a registration says what an agent offers, and only a series of readings says what it offered LAST WEEK. Store `manifest.hash` and compare it next time to detect an endpoint that changed under you. Two things this is NOT: an unreachable endpoint is an availability fact and never evidence of bad faith (weigh `latest` against `history`, since one bad day and a dead service look identical in a single reading), and an endpoint we have never probed is outside our reading rather than absent from the world. Free.
読み取り専用 外部アクセスあり 冪等
入力スキーマ
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'description': 'The absolute http(s) URL of the service endpoint you are about to connect to.'}}}
出力スキーマ
{'type': 'object', 'required': ['says'], 'properties': {'says': {'type': 'string', 'description': 'The reading in one sentence. An endpoint we have never probed says so here: that is our gap, not evidence the service is down.'}, 'drift': {'type': ['object', 'null'], 'description': 'Declared but not observed, and the reverse. Null where either side is unknown — subtracting silence would manufacture a finding.'}, 'price': {'type': ['object', 'null'], 'description': 'The seller’s OWN published terms for this URL: `amount` in the asset’s own units with `asset` named beside it (a bare number would be read as dollars), `network` as CAIP-2, `payTo`, which catalogues list it, and `cardPriceUsd` where the registration states a price too. Null throughout is UNPRICED, which is not free. Where the card and the catalogue disagree, both are shown — two claims by the same party, and picking one would hide that.'}, 'latest': {'type': ['object', 'null'], 'description': 'The most recent probe: outcome, latency, and what it answered with.'}, 'changes': {'type': 'array', 'items': {'type': 'object'}, 'description': 'Every move we saw in what it offers, oldest first, each with `added`, `removed`, a protocol-version move where there was one, and the two hashes. `at` is the day we SAW the change, not the day it happened: we probe daily and cannot place it more precisely. An empty array where we read a list and it never moved; a tool list we could NOT read is skipped entirely rather than folded in as an empty one, which would invent a “removed everything” out of our own gap.'}, 'history': {'type': 'array', 'items': {'type': 'object'}, 'description': 'Up to fourteen readings. One bad day and a dead service look identical in a single reading.'}, 'endpoint': {'type': 'string', 'description': 'The URL as we read it back, so a typo is visible before anything is concluded from the answer.'}, 'manifest': {'type': ['object', 'null'], 'description': 'What the endpoint offers NOW, as something you can bind to: `hash` over the sorted tool names and the declared protocol version and nothing else, with `tools`, `firstSeen`, `lastSeen` and how many readings carried it. Store the hash and compare it on your next call to know whether the offering moved under you. Null where we have never read a tool list here.'}, 'measured': {'type': 'object', 'description': 'What we measured, which is NOT a guarantee: nothing on these rails publishes one. `serving` of `days`, every outcome by how often, and median and worst latency of the readings that answered. Left as counts with the denominator stated, never a rate and never a grade — 12 of 14 over two weeks means something different from the same fraction over two days, and only the caller can pick the denominator that matters to them.'}, 'outcomes': {'type': 'object', 'description': 'What each outcome word means, so a caller never has to guess.'}, 'handshake': {'enum': ['open', 'gated', 'no-answer', None], 'type': ['string', 'null'], 'description': 'Whether the protocol HANDSHAKE completed without credentials on the latest reading. `open` is the closest thing here to “you can try it” and is NOT a statement that calling its tools is free — a server can answer openly and charge for every call, and we complete a handshake rather than call a tool. `gated` means it asked for something we do not have, which is working as intended. Null where we have no reading.'}, 'declaredBy': {'type': 'array', 'items': {'type': 'object'}, 'description': 'Identities that declare this endpoint, and the tools each one claims. Their claim, not our verification.'}}}
counterparty_bulk
Check up to fifty addresses in one call (paid)
Check up to fifty addresses in one call, each with its observations: for an agent or a desk holding a list of counterparties before paying any of them. PAID, one cent a call over x402, priced per call rather than per address.
外部アクセスあり 冪等
入力スキーマ
{'type': 'object', 'required': ['addresses'], 'properties': {'addresses': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Up to 50.'}}}
出力スキーマ
{'type': 'object', 'required': ['items'], 'properties': {'items': {'type': 'array', 'items': {'type': 'object'}, 'description': 'One entry per address given, in the order given, each with its own observations and its own limits.'}, 'limits': {'type': 'string', 'description': 'What this answer cannot tell you.'}, 'checked': {'type': 'integer', 'description': 'How many addresses were read.'}, 'payment': {'type': 'object', 'description': 'What was paid and how it settled. Priced per call, not per address.'}}}
counterparty_check
What the chain records about one address
Before paying or hiring an agent: what the chain records about that address. Independent payers (counterparties that paid it and were never paid back), the ones it does pay back, how concentrated its custom is, how its ACP jobs ended, whether its advertised service answers, and when it was last paid. Free. Two limits to repeat whenever quoting it: independent means no payment BACK on the rails we read, NOT proof the payers are different parties, since one owner can fund many addresses that never pay each other; and an all-time record says nothing about whether the agent still works — 44% of agents ever paid have not been paid in 90 days. Takes an EVM address, a Cardano payment address (addr1…) or a Solana address.
読み取り専用 外部アクセスあり 冪等
入力スキーマ
{'type': 'object', 'required': ['address'], 'properties': {'address': {'type': 'string', 'description': 'The address you are about to pay or hire.'}}}
出力スキーマ
{'type': 'object', 'required': ['address', 'format', 'observations', 'limits'], 'properties': {'acp': {'type': 'object', 'description': 'How its jobs ended, where it has any.'}, 'mech': {'type': 'object', 'description': 'Deliveries on the Olas mech marketplace, and what was paid for them where we hold it. A rail many agents never touch; zero here is not a mark against an address.'}, 'x402': {'type': 'object', 'description': 'Sales and payers on the x402 rail. Payers are counted as parties, not payments: one buyer paying fifty times is one payer.'}, 'format': {'type': 'object', 'description': 'What kind of address this is and what we read for it.'}, 'limits': {'type': 'string', 'description': 'What this answer cannot tell you. Quote it with the numbers.'}, 'masumi': {'type': ['object', 'null'], 'description': 'Escrows on the Masumi rail. Null where we hold no reading for this address at all, which is not the same as zero escrows.'}, 'address': {'type': 'string', 'description': 'The address as we read it, normalised. Compare it with what you sent before acting on the answer.'}, 'paidFor': {'type': ['object', 'null'], 'description': 'What it was paid for, in the subject’s own words.'}, 'alsoHere': {'type': ['object', 'null'], 'description': 'The same address on the capital side — a vault or an operator — with the check to call. A match on the address, never an identification of the party.'}, 'dealings': {'type': 'object', 'description': 'rails, chains, counterparties, independent, largestShare, firstPaid, lastPaid. `independent` means no payment BACK on the rails we read — NOT proof the payers are different parties, since one owner can fund many addresses.'}, 'identity': {'type': 'object', 'description': 'Registrations it holds. Claims, never verification.'}, 'services': {'type': 'object', 'description': 'Callable services it declares, and how many answered our probe.'}, 'observations': {'type': 'array', 'items': {'type': 'object'}, 'description': 'The findings, each with its evidence class and its own words. Read these first.'}}}
counterparty_history
One agent’s record day by day (paid)
How one agent’s record has moved: dealings, independent payers, concentration and delivery, day by day. PAID, one cent a call over x402 — the median price of this rail. Without payment the tool answers with the price and how to pay it, and the free check remains available. The history begins the day we started keeping it; it is a record we keep, not one the chain gives away.
外部アクセスあり 冪等
入力スキーマ
{'type': 'object', 'required': ['address'], 'properties': {'days': {'type': 'number', 'description': '1 to 365, default 90. The history begins the day we started keeping it, so a longer window does not reach further back than that.'}, 'address': {'type': 'string', 'description': 'The agent whose record you want day by day. An EVM, Cardano or Solana address.'}}}
出力スキーマ
{'type': 'object', 'required': ['address'], 'properties': {'items': {'type': 'array', 'items': {'type': 'object'}, 'description': 'One entry per day: dealings, independent payers, concentration, delivery.'}, 'change': {'type': ['object', 'null'], 'description': 'What moved across the window, and over which dates.'}, 'address': {'type': 'string', 'description': 'The address this history is for, normalised and read back.'}, 'payment': {'type': 'object', 'description': 'What was paid and how it settled. Present because this call took money.'}, 'keptSince': {'type': 'string', 'format': 'date', 'description': 'The day we began keeping this. Nothing before it exists, at any window.'}}}
evaluate_action
Weigh one action against a named policy
Call this when you are about to DO something and need one answer you can act on: pay an address, connect to an MCP server, call a tool, or put capital into a vault. Unlike a reputation score, the answer depends on the AMOUNT, the ACTION, the POLICY you name and how much we actually read — so the same address can be `allow` for $5 and `abstain` for $5,000. Four decisions. `allow` means nothing we could check objects, up to `maxAmountUsd`, and is NOT a statement that the action is safe: nothing here sees what it is for or what you agreed. `review` means something we READ does not match, and `reasons` names which rule. `abstain` means we did not read enough to have an opinion — our gap, never approval. `unsupported` means the policy has no rule for this action, and inventing one would be worse than declining. Every rule id in `reasons` is published in full at the policies tool, including to the party being evaluated. Free.
読み取り専用 外部アクセスあり 冪等
入力スキーマ
{'type': 'object', 'required': ['action', 'subject'], 'properties': {'chain': {'type': 'string', 'description': 'The chain the action settles on, e.g. base, polygon, solana.'}, 'action': {'enum': ['pay', 'connect_mcp', 'call_tool', 'allocate_capital'], 'type': 'string', 'description': 'What you are about to do.'}, 'policy': {'type': 'string', 'description': 'A policy version or slug. Defaults to conservative-v1. An unknown name is REFUSED rather than silently replaced with the default.'}, 'subject': {'type': 'string', 'description': 'What you are about to do it to: an address to pay, an endpoint URL to connect to, or a vault slug.'}, 'resource': {'type': 'string', 'description': 'The http(s) endpoint being bought or connected to, where that differs from `subject`. This is what reaches the seller’s own catalogue entry, carrying their price and their payee.'}, 'amountUsd': {'type': 'number', 'description': 'What you are about to commit, in US dollars. Leave it out and the amount rules report that they did not run, rather than passing.'}}}
出力スキーマ
{'type': 'object', 'required': ['decision', 'reasons', 'coverage', 'policyVersion', 'says'], 'properties': {'says': {'type': 'string', 'description': 'The decision in one sentence, naming the rules that drove it. Written to be shown to whoever authorises the action.'}, 'rules': {'type': 'array', 'items': {'type': 'object'}, 'description': 'Every rule considered, each pass, fail or unknown. The audit trail for the decision.'}, 'limits': {'type': 'string', 'description': 'What a decision here is and is not. `allow` means no rule objected under this policy at this coverage, which is not a statement that the action is safe.'}, 'policy': {'type': 'object', 'description': 'The policy applied: its intent, its ceiling and the coverage floor below which it abstains.'}, 'reasons': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Rule ids that decided. Look them up in the policy to see the sentence each one checks.'}, 'coverage': {'enum': ['none', 'low', 'medium', 'high'], 'type': 'string', 'description': 'How much of what the policy wanted was actually there. Below the policy floor the decision is `abstain` rather than `allow`.'}, 'decision': {'enum': ['allow', 'review', 'abstain', 'unsupported'], 'type': 'string', 'description': '`allow` is not “safe” and `abstain` is not “nothing found”. Read `decisions` in the answer for what each one means.'}, 'proposal': {'type': 'object', 'description': 'What you asked about, read back, so a typo is visible before you act on the answer.'}, 'decisions': {'type': 'object', 'description': 'What each decision word means, so a caller never has to guess. Read it before treating `allow` as approval or `abstain` as a clean result.'}, 'maxAmountUsd': {'type': ['number', 'null'], 'description': 'The most this policy permits for this proposal. Null where the action moves no money, and null on anything but an `allow`, because a limit printed beside a `review` reads as permission.'}, 'policyVersion': {'type': 'string', 'description': 'Carried so an answer given today can be reproduced after the rules change.'}, 'missingEvidence': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Rule ids whose evidence we do not hold. These lower `coverage` and are NEVER counted as objections.'}}}
evidence_for
Every edge we hold about one subject
Everything we hold about one subject, as edges, each carrying where it came from. Use it when you need to explain a decision rather than just make one, or to see what is MISSING before you act. Every edge has `source`, `observedAt` (when the world was in that state), `asOf` (when we read it — a fresh read of a stale fact is not a fresh fact), a `confidence` that names what it is confident IN, its own `coverage`, and the `method` that established it. Edges come in three kinds and are NEVER summed: `declared` is the subject speaking about itself, `observed` is our reading, `derived` is arithmetic over the others. Adding them together rebuilds the reputation score this replaces. It infers NO identity: a shared host or funder is reported as exactly that, because being the same party is a conclusion no join supports. `lookedForAndMissing` lists what we searched for and did not find, so a thin subject never reads as a complete picture. Free.
読み取り専用 外部アクセスあり 冪等
入力スキーマ
{'type': 'object', 'required': ['subject'], 'properties': {'subject': {'type': 'string', 'description': 'An address, or the http(s) URL of an endpoint.'}}}
出力スキーマ
{'type': 'object', 'required': ['subject', 'edges', 'counts', 'says'], 'properties': {'says': {'type': 'string', 'description': 'What the evidence amounts to, in one sentence. Never a verdict: this tool reports edges and leaves the conclusion to the caller.'}, 'edges': {'type': 'array', 'items': {'type': 'object'}, 'description': 'Each with claim, object, kind, source, observedAt, asOf, confidence {value, in}, coverage and method.'}, 'kinds': {'type': 'object', 'description': 'What declared, observed and derived each mean.'}, 'counts': {'type': 'object', 'description': 'Edges by kind. NOT a score: the three are reported apart and never added.'}, 'limits': {'type': 'string', 'description': 'What this graph cannot contain. Declared, observed and derived are different kinds of fact and are never added together; `counts` keeps them apart for the same reason.'}, 'subject': {'type': 'string', 'description': 'What was asked about, read back. Where we resolved it to something else, this is the resolved form.'}, 'subjectKind': {'enum': ['address', 'endpoint', 'vault', 'unknown'], 'type': 'string', 'description': 'What we took the subject to BE. `unknown` means we could not classify it, so the empty edge list below is our failure to look rather than a finding about the subject.'}, 'lookedForAndMissing': {'type': 'array', 'items': {'type': 'object'}, 'description': 'What we searched for and did not find, with why. Listed rather than omitted.'}}}
find_agents
Find agents by what the record shows
Find agents to hire by what the chain records rather than what they claim: filter every address ever paid on x402, Virtuals ACP, the Olas mech marketplace or Masumi by independent payers, dealings, ACP completion, whether its declared service answers, whether it pays its own payers back, and how recently it was paid. Free. An address absent from the result was never paid on a rail we read, which is not the same as never having worked.
読み取り専用 外部アクセスあり 冪等
入力スキーマ
{'type': 'object', 'properties': {'rail': {'type': 'string', 'description': 'x402, acp, mech or masumi.'}, 'sort': {'type': 'string', 'description': 'One named dimension: independent, dealings, usd, completion, recent, paidBack, largestShare or counterparties. There is no "best" — nothing here has earned the right to rank.'}, 'limit': {'type': 'number', 'description': 'Default 25, maximum 200.'}, 'serving': {'type': 'boolean', 'description': 'Only agents whose declared service answered our last probe. An agent that declares none is excluded, not failed.'}, 'noTwoWay': {'type': 'boolean', 'description': 'Exclude agents that also pay their own payers, which can be one owner moving money between their own addresses.'}, 'activeDays': {'type': 'number', 'description': 'Paid within this many days.'}, 'registered': {'type': 'boolean', 'description': 'Only agents holding a registration in a registry we read. A registration is a claim, never a verification.'}, 'minDealings': {'type': 'number', 'description': 'Fewest dealings on the rails we read, all time.'}, 'minCompletion': {'type': 'number', 'description': 'ACP jobs completed over those that ended, 0 to 1.'}, 'minIndependent': {'type': 'number', 'description': 'Fewest counterparties that paid it and were never paid back. The closest thing here to "has real custom".'}}}
出力スキーマ
{'type': 'object', 'required': ['items'], 'properties': {'asOf': {'type': ['string', 'null'], 'format': 'date-time', 'description': 'When the record behind these rows was last rebuilt. Null means nothing in the answer carries a date, which is a gap in our reading rather than a fact about the agents.'}, 'items': {'type': 'array', 'items': {'type': 'object'}, 'description': 'Matching agents, ordered by the ONE dimension asked for, never a composite score.'}, 'filters': {'type': 'object', 'description': 'What was applied, read back, including what a floor excluded.'}}}
find_vaults
Find a vault by what it has done
Find a vault by what it has DONE rather than what it is called. Free. The filter worth knowing is `earned`: `short` returns the vaults where a holder earned LESS than the venue advertises — there are 18 — and `beating` the ones where they earned more. It matches only vaults whose realised return is COMPARABLE with an advertised one, 349 of 3,394 open vaults; a venue that quotes nothing or a share price that never moves is excluded rather than counted as in-line, so a short list here means few comparable and not few that performed. Call vault_check on a slug for the full answer.
読み取り専用 外部アクセスあり 冪等
入力スキーマ
{'type': 'object', 'properties': {'q': {'type': 'string', 'description': 'Part of a name or an address.'}, 'chain': {'type': 'string', 'description': 'e.g. base, solana, hyperliquid.'}, 'limit': {'type': 'number', 'description': 'Default 25, capped at 100.'}, 'earned': {'type': 'string', 'description': 'in-line, beating or short — realised against advertised, comparable cases only.'}, 'minTvl': {'type': 'number', 'description': 'Floor on stated size, in US dollars.'}, 'maxRisk': {'type': 'number', 'description': 'Ceiling on the published risk score. Scored for 936 of 3,394 open vaults; the unscored are excluded, which is not the same as scoring well.'}, 'platform': {'type': 'string', 'description': 'A platform id or its display name, e.g. morpho or Hyperliquid.'}, 'minOwnShare': {'type': 'number', 'description': 'Floor on the share of the vault its leader holds, 0 to 1. Readable on Hyperliquid and Drift only — 584 of 3,394 open vaults — so a floor excludes every other venue, where it is ABSENT and not zero. Evidence of alignment, never proof: the holder can be a treasury or a custodian.'}, 'agentManaged': {'type': 'boolean', 'description': 'Only vaults a machine runs.'}}}
出力スキーマ
{'type': 'object', 'required': ['data'], 'properties': {'data': {'type': 'array', 'items': {'type': 'object'}, 'description': 'Each with its slug, which vault_check takes.'}, 'fields': {'type': 'string', 'description': 'Which fields this tool kept from the endpoint’s own rows.'}, 'warnings': {'type': 'array', 'items': {'type': 'object'}, 'description': 'READ THESE: an `earned` or `minOwnShare` floor carries what it excluded, and the denominator is not visible from the rows.'}}}
identify
Identify the party behind an identifier
Call this FIRST whenever you hold something other than a wallet address. Give it a transaction hash, an http(s) URL, a hostname or an ERC-8004 registration number and it says which party that is, with the evidence for the link, so the other tools here can then be called with the address. It never picks between candidates: where a hostname or id matches several parties, `address` comes back null and every candidate is listed, because choosing one would be an identification the evidence does not support. A link through a hostname or a declared endpoint is the subject’s own claim, never proof that they control it. An identifier it cannot resolve is not evidence of anything wrong — read `says`, which distinguishes "no such thing" from "we do not read that chain". Free.
読み取り専用 外部アクセスあり 冪等
入力スキーマ
{'type': 'object', 'required': ['q'], 'properties': {'q': {'type': 'string', 'description': 'What you have: an address (returned as given), a transaction hash (the payee is read from the transfer inside it), a URL or hostname (matched against the x402 catalogue and declared agent endpoints), or an ERC-8004 registration number, optionally as `chain:id`.'}}}
出力スキーマ
{'type': 'object', 'required': ['says'], 'properties': {'says': {'type': 'string', 'description': 'The answer in words, including the difference between "no such thing" and "we do not read that chain".'}, 'check': {'type': ['string', 'null'], 'description': 'The free check to call next with the address.'}, 'given': {'type': 'string', 'description': 'What you sent, as sent.'}, 'kinds': {'type': 'object', 'description': 'What each reading would have meant, so an unrecognised identifier is not a dead end.'}, 'format': {'type': 'object', 'description': 'What kind of address it is and what we read for it.'}, 'address': {'type': ['string', 'null'], 'description': 'The party, or null where the evidence names more than one. Never a guess between candidates.'}, 'evidence': {'type': 'array', 'items': {'type': 'object'}, 'description': 'Why each link is claimed, and whether it is the subject’s own claim or something we read.'}, 'looksLike': {'type': 'string', 'description': 'What the identifier was read as: address, transaction, endpoint, host, agent-id or unrecognised.'}, 'candidates': {'type': 'array', 'items': {'type': 'object'}, 'description': 'Every party the identifier could be, where it is not one.'}}}
inspect_payment
Read the transaction you are about to sign
Call this with the CALLDATA you are about to sign, before you sign it. Every other check here asks whether an address is worth dealing with; this asks whether the transaction is the one you think it is, and the two catch different losses. No amount of reputation makes the recipient in the bytes match the recipient on your screen, and a spotless counterparty record says nothing about an UNLIMITED APPROVAL granted to it, which is not a payment at all but a standing permission that outlives the transaction. It reads three calls — transferWithAuthorization, approve, transfer — and REFUSES to guess at any other: decoding unknown calldata without the ABI means guessing where each argument begins, and a confident wrong answer about where money goes is worse than none. Amounts are atomic units, never dollars, because the token owns its decimals. Free, needs no key, stores nothing.
読み取り専用 冪等
入力スキーマ
{'type': 'object', 'required': [], 'properties': {'to': {'type': 'string', 'description': 'The contract being called, where you know it.'}, 'data': {'type': 'string', 'description': 'The calldata, 0x-prefixed. Without it nothing about the transaction is read, and the answer says so rather than passing.'}, 'expect': {'type': 'object', 'properties': {'chain': {'type': 'string'}, 'payTo': {'type': 'string', 'description': 'Who you mean to pay.'}, 'validAfter': {'type': 'string', 'description': 'Seconds since the epoch.'}, 'validBefore': {'type': 'string', 'description': 'Seconds since the epoch, as EIP-3009 writes them.'}, 'amountAtomic': {'type': 'string', 'description': 'The amount in ATOMIC units of the token, as a decimal string. Not dollars.'}}, 'description': 'What you believe you are doing. Anything you leave out is not compared, and is reported as not compared rather than as agreeing.'}}}
出力スキーマ
{'type': 'object', 'required': ['verdict', 'findings'], 'properties': {'call': {'type': ['string', 'null'], 'description': 'What the bytes actually are, or null where it is not a call this decodes.'}, 'limits': {'type': 'string', 'description': 'What decoding a payment establishes. It reads what the transaction SAYS it will do; it does not simulate it and cannot tell you the recipient is honest.'}, 'verdict': {'enum': ['read', 'mismatch', 'undecodable'], 'type': 'string', 'description': '`read` means every comparison you asked for agreed. `mismatch` means at least one did not. `undecodable` means the call is not one this reads and NOTHING was checked — it is not a pass.'}, 'findings': {'type': 'array', 'items': {'type': 'object'}, 'description': 'One per check, each carrying whether it ran: observation, mismatch, or unknown.'}, 'selector': {'type': ['string', 'null'], 'description': 'The four-byte function selector the calldata begins with, where we could read one. Null means the payload is not a call we can decode, which is not evidence that it is bad.'}, 'recipient': {'type': ['string', 'null'], 'description': 'Who the bytes pay, read from the payload rather than from a label.'}, 'amountAtomic': {'type': ['string', 'null'], 'description': 'Atomic units, as a decimal string. The token owns its decimals and this does not apply them.'}, 'unlimitedAllowance': {'type': 'boolean', 'description': 'True where this grants permission to move every token of this kind you will ever hold.'}}}
list_policies
The policies a decision can be made under
The policies evaluate_action can be run under, in full: every rule, its id and the sentence it checks. Published deliberately, including to the agents being evaluated — a rule nobody can read is a rule nobody can correct. Free.
読み取り専用 外部アクセスあり 冪等
入力スキーマ
{'type': 'object', 'properties': {}}
出力スキーマ
{'type': 'object', 'required': ['data'], 'properties': {'data': {'type': 'array', 'items': {'type': 'object'}, 'description': 'Each policy with its slug, version, intent, ceiling, coverage floor and rules.'}, 'says': {'type': 'string', 'description': 'What these policies are and are not. They are rules a decision is checked against, never a ranking of the agents evaluated under them.'}, 'default': {'type': 'string', 'description': 'The slug of the policy used when a call names none. Read it rather than assume: the default is an operator setting and can change without any tool changing.'}}}
list_vaults
Find the vault you mean
The vaults we read, so a caller holding a name rather than a slug can find the one it means. Free. Absence from this list means we do not read that vault, never that it does not exist.
読み取り専用 外部アクセスあり 冪等
入力スキーマ
{'type': 'object', 'properties': {'q': {'type': 'string', 'description': 'Part of a vault or platform name, matched as typed.'}, 'limit': {'type': 'number', 'description': 'Default 25, maximum 200.'}}}
出力スキーマ
{'type': 'object', 'required': ['data'], 'properties': {'data': {'type': 'array', 'items': {'type': 'object'}, 'description': 'Each with its slug, which is what vault_check takes.'}, 'fields': {'type': 'string', 'description': 'Which fields this tool kept from the endpoint’s own rows, and where the rest are.'}}}
monitor_subject
Be told when the answer about an address changes
Ask to be told when the answer about an address CHANGES. The dimensions are the ones the counterparty check already answers, so this is that same reading on a schedule rather than a second opinion; what it adds is the comparison. The first run records a reading and reports nothing — there is nothing yet to compare against, and a first reading dressed up as news is the thing this avoids. Idempotent per subject: calling it again edits the watch rather than creating a second. An unknown dimension or policy is REFUSED rather than dropped, because a watch that quietly ignores half of what you asked for is worse than no watch. Needs a key.
冪等
入力スキーマ
{'type': 'object', 'required': ['subject'], 'properties': {'policy': {'type': 'string', 'description': 'The policy its verdict is read against. An unknown name is refused rather than replaced with a default.'}, 'subject': {'type': 'string', 'description': 'The address to watch.'}, 'dimensions': {'type': 'array', 'items': {'enum': ['endpoint', 'counterparty', 'risk', 'vault'], 'type': 'string'}, 'description': 'What to watch. All four if you leave it out. An unknown name is refused, not ignored.'}}}
出力スキーマ
{'type': 'object', 'required': ['id', 'subject', 'dimensions'], 'properties': {'id': {'type': 'string', 'description': 'The watch, for changing or ending it later.'}, 'says': {'type': 'string', 'description': 'What this watch will and will not tell you. It reports a CHANGE in what we hold, which is not the same as a change in the world.'}, 'policy': {'type': ['string', 'null'], 'description': 'The policy its verdict is read against. Null where the watch names none and the default applies; read `says` for which that is.'}, 'subject': {'type': 'string', 'description': 'The address being watched, read back so a watch cannot be set on the wrong one.'}, 'dimensions': {'type': 'array', 'items': {'type': 'string'}, 'description': 'What is actually being watched, which is what you asked for or all four.'}, 'firstReadingAt': {'type': ['string', 'null'], 'description': 'When the comparison baseline was taken. Null means no reading yet, so nothing can be reported as a change.'}}}
operator_check
Who runs the money, and how much is theirs
The question that follows vault_check: who runs the money, and how much of it is their own. Free. Read `ownShare` with its limits, which travel inside it: the leader’s holding is readable on Hyperliquid and Drift only — 584 of 3,394 open vaults — so elsewhere it is ABSENT and not zero, the median describes the strategies we can read rather than the manager, and a large own-share is evidence of alignment and never proof, because the address running a vault can be a treasury or a custodian holding for other people. `cannotSee` names whatever of that applies here. Take the slug from vault_check’s `operator`.
読み取り専用 外部アクセスあり 冪等
入力スキーマ
{'type': 'object', 'required': ['slug'], 'properties': {'slug': {'type': 'string', 'description': 'The operator’s slug, as vault_check returns it in `operator.slug`.'}}}
出力スキーマ
{'type': 'object', 'required': ['name', 'cannotSee', 'says'], 'properties': {'name': {'type': 'string', 'description': 'The operator’s name as published. Their words, not an identity we verified.'}, 'says': {'type': 'string', 'description': 'The operator in one sentence, including what we cannot see about them — own-capital share is readable on two venues only.'}, 'ownShare': {'type': ['object', 'null'], 'description': 'Median share of the vault its leader holds, the count it is taken over, and what it does and does not mean.'}, 'cannotSee': {'type': 'array', 'items': {'type': 'string'}}, 'capitalUsd': {'type': ['number', 'null'], 'description': 'Capital across every open strategy we read for this operator. Null where none of them can be priced.'}, 'strategies': {'type': 'object', 'description': 'How many open and closed, and on which platforms.'}, 'agentManaged': {'type': 'integer', 'description': 'How many of their open strategies we have reason to call agent-managed. A COUNT of strategies, never a share of the capital.'}}}
preflight_payment
Weigh one payment before sending it
Call this immediately before sending a payment, every time — not once per counterparty. It weighs THIS payment (the amount, the chain, the endpoint) against what the address has actually done: the price the seller themselves published for that endpoint, the address that endpoint names as its payee, the largest payment this address has ever received, and whether it has ever been paid on the chain you are about to use. Answers one of three verdicts. `nothing-against-it` means every check ran and none objected — it is NOT a statement that the payment is safe, because nothing here can see what the payment is for or what you agreed. `look-first` means at least one thing we could READ does not match, and the findings say which; a check that could not run never produces it, it produces `cannot-say`. `cannot-say` means we did not read enough to have an opinion, and must never be read as the first. Free. Give as much of amountUsd, chain and resource as you have: each one left out is a check that did not run, and the answer says so rather than passing.
読み取り専用 外部アクセスあり 冪等
入力スキーマ
{'type': 'object', 'required': ['to'], 'properties': {'to': {'type': 'string', 'description': 'The address you are about to pay.'}, 'chain': {'type': 'string', 'description': 'The chain you are about to send it on, e.g. base, polygon, solana.'}, 'resource': {'type': 'string', 'description': 'The http(s) URL of the endpoint you are buying, where there is one. This is the sharpest check available: its catalogue entry carries the seller’s own price and their own payee address.'}, 'amountUsd': {'type': 'number', 'description': 'What you are about to send, in US dollars.'}}}
出力スキーマ
{'type': 'object', 'required': ['verdict', 'observations', 'says'], 'properties': {'says': {'type': 'string', 'description': 'The verdict in one sentence, naming what did not match. Written to be shown to a person deciding whether to go ahead.'}, 'check': {'type': ['string', 'null'], 'description': 'The free counterparty check for this address.'}, 'limits': {'type': 'string', 'description': 'What this check cannot establish, in full. Quote it whenever you quote the verdict: a clean answer here is the absence of an objection, never a guarantee about the payment.'}, 'listing': {'type': ['object', 'null'], 'description': 'The seller’s own catalogue entry for the resource, where there is one. The sharpest check available.'}, 'verdict': {'enum': ['nothing-against-it', 'look-first', 'cannot-say'], 'type': 'string', 'description': '`nothing-against-it` means every check ran and none objected — NOT that the payment is safe. `cannot-say` means too little was read to have an opinion, and must never be read as the first. It is also the answer when nothing contradicted the payment but a check could not run, because reporting our own gap as a clean result would be the worst of the three.'}, 'findings': {'type': 'array', 'items': {'type': 'object'}, 'description': 'Every check that ran, each with the record behind it and its own `tone` and `kind`. NOT only the ones that objected: a `tone` of `good` is a check that MATCHED, so reading this array’s length as a count of problems overstates them. Bucket on `kind` — `fact` and `signal` were established, and `unknown` means we could not see, which never counts as something standing against the payment.'}, 'proposal': {'type': ['object', 'null'], 'description': 'Your payment as we understood it: payee, amount, chain and resource. Null where too little was given to form one. Check it before reading the verdict, which is about THIS proposal and no other.'}, 'received': {'type': 'object', 'description': 'What you told us, read back, so a typo is visible.'}, 'verdicts': {'type': 'object', 'description': 'What each verdict word means, so a caller never has to guess.'}, 'observations': {'type': 'array', 'items': {'type': 'object'}, 'description': 'Every check that ran, including the ones that could not: a field you left out appears here as a check that did not run, rather than as silence.'}}}
record_receipt
Record what you did, so it can be checked later
Call this AFTER you have paid an address or called a tool, to put what you did on the record. Until now this platform answered "should I" and never heard what happened, which is the difference between a lookup and a control layer: a receipt lets the next question about this subject be asked against a record instead of a guess, and lets a verdict we gave be read back against what followed. `reference` is YOUR evidence, a transaction hash or the digest of a signed payload, and we store it WITHOUT verifying it. `outcome` comes back null and stays null until something actually reads what happened, so a receipt nobody has checked never looks like one that settled. Needs a key; a receipt is readable only by the key that wrote it.
入力スキーマ
{'type': 'object', 'required': ['subject', 'action', 'reference'], 'properties': {'chain': {'type': 'string', 'description': 'The chain it settled on, where it settled on one.'}, 'action': {'enum': ['payment', 'tool_call'], 'type': 'string', 'description': 'What you did.'}, 'policy': {'type': 'string', 'description': 'The policy you evaluated under, so a later disagreement can be read against what we said at the time.'}, 'subject': {'type': 'string', 'description': 'The address you acted on.'}, 'verdict': {'type': 'string', 'description': 'The decision we gave you before you acted, for the same reason.'}, 'deadline': {'type': 'string', 'description': 'ISO 8601 time you expected it by. A time already past is refused, because it is usually seconds where milliseconds were meant.'}, 'expected': {'type': 'string', 'description': 'What you expected to follow, in your words. Ours to store and yours to claim.'}, 'amountUsd': {'type': 'number', 'description': 'What you committed, in US dollars.'}, 'reference': {'type': 'string', 'description': 'Your evidence that it happened: a transaction hash, or the digest of a signed payload. Stored, not verified.'}}}
出力スキーマ
{'type': 'object', 'required': ['id', 'recordedAt'], 'properties': {'id': {'type': 'string', 'description': 'The receipt, for asking about it later.'}, 'says': {'type': 'string', 'description': 'What was and was not verified.'}, 'outcome': {'type': ['string', 'null'], 'description': 'Always null here. It stays null until something reads what actually happened; null is "nobody has checked", never "it failed".'}, 'subject': {'type': 'string', 'description': 'The address the receipt is about, read back, so a receipt cannot be filed against the wrong party.'}, 'recordedAt': {'type': 'string', 'description': 'When we wrote it down. Not when your action happened.'}}}
vault_check
What the record shows about one vault
Before putting capital into a vault: what the record shows about it, rather than what the venue says about itself. The headline is what a holder ACTUALLY EARNED set against the advertised rate — the one figure a depositor cannot get from the venue — with the risk band, the components that apply, and who runs it. Free. Read `earned.comparability` before quoting the ratio: a realised rate drawn from too short or too sparse a window is not a comparison with the advertised one, and `cannotSee` lists everything we could not establish for this vault rather than leaving it as an absence you have to notice. Rates are decimal fractions: 0.0432 is 4.32% a year.
読み取り専用 外部アクセスあり 冪等
入力スキーマ
{'type': 'object', 'required': ['slug'], 'properties': {'slug': {'type': 'string', 'description': 'The vault’s slug, or an address we can resolve to one. Call list_vaults first if you have only a name.'}}}
出力スキーマ
{'type': 'object', 'required': ['slug', 'cannotSee', 'says'], 'properties': {'name': {'type': ['string', 'null'], 'description': 'The vault’s name as the venue publishes it. Their words, and two venues may use the same one.'}, 'risk': {'type': 'object', 'description': 'The band, the share of components we could measure, and each applying component in its own words.'}, 'says': {'type': 'string', 'description': 'The finding in one sentence. Where we cannot say what a holder earned, it says that plainly rather than reporting the venue’s own figure as ours.'}, 'slug': {'type': 'string', 'description': 'The vault this answer is about, read back so it cannot be attached to the wrong one.'}, 'earned': {'type': ['object', 'null'], 'description': 'Advertised against realised, with the ratio, the verdict, the window and its comparability. Null where we have too few price points to say.'}, 'operator': {'type': ['object', 'null'], 'description': 'Who runs it, as the venue names them.'}, 'cannotSee': {'type': 'array', 'items': {'type': 'string'}, 'description': 'What we could not establish. Empty means every check ran.'}, 'capitalUsd': {'type': ['number', 'null'], 'description': 'What the vault holds, in US dollars, at `capitalAsOf`. Null where we cannot price the underlying — unread, never zero.'}}}
vault_exits
What actually left a vault
Before putting capital somewhere, ask what has actually LEFT it. Every liquidity figure elsewhere is a level at an instant — how much could be withdrawn right now. This is the other half: withdrawals that SETTLED, over 7, 30 and 90 days, with the largest single exit we have ever recorded and the day it happened. Measured on the largest vault we read: $52.8M declared withdrawable against $265.8M actually withdrawn over thirty days, so a holder reading only the declared figure would badly underestimate what the vault has been able to pay. A LEVEL and a FLOW are never divided by one another and this returns no ratio between them. We see withdrawals that settled and NOT an attempt that reverted, a queue somebody waited in, or a gate that refused them — so an empty register means “nobody withdrew” OR “nobody could”, and `cannotSee` says so. Free.
読み取り専用 外部アクセスあり 冪等
入力スキーマ
{'type': 'object', 'required': ['slug'], 'properties': {'slug': {'type': 'string', 'description': 'The vault slug, as list_vaults and find_vaults return it.'}}}
出力スキーマ
{'type': 'object', 'required': ['slug', 'windows', 'says', 'cannotSee'], 'properties': {'says': {'type': 'string', 'description': 'What actually left, against what the vault advertises as withdrawable, in one sentence.'}, 'slug': {'type': 'string', 'description': 'The vault this register is for, read back so an answer cannot be attached to the wrong vault.'}, 'tvlUsd': {'type': ['number', 'null'], 'description': 'What the vault holds, for scale beside the withdrawals. A LEVEL, never to be divided into the flow figures in `windows`. Null means unread, not empty.'}, 'windows': {'type': 'array', 'items': {'type': 'object'}, 'description': 'FLOWS over 7, 30 and 90 days: count, total, largest single, most recent. Never a share of the level.'}, 'cannotSee': {'type': 'array', 'items': {'type': 'string'}, 'description': 'What this register structurally cannot contain, so an empty one is never read as an easy exit.'}, 'largestEverAt': {'type': ['string', 'null'], 'format': 'date-time', 'description': 'When `largestEverUsd` was taken out. An old date beside a large figure is the whole point: it says the exit was possible then, not now.'}, 'largestEverUsd': {'type': ['number', 'null'], 'description': 'Somebody actually got this much out, on `largestEverAt`. Evidence about the past, never a promise about now.'}, 'declaredWithdrawableUsd': {'type': ['number', 'null'], 'description': 'A LEVEL at this instant. Null where we cannot read it, which is not zero.'}}}
追加
monitor_subject
2026年10月1日2:42
追加
record_receipt
2026年10月1日2:42
追加
inspect_payment
2026年10月1日2:42
変更
counterparty_history
2026年10月1日2:42
変更
find_agents
2026年10月1日2:42
変更
operator_check
2026年10月1日2:42
変更
vault_check
2026年10月1日2:42
変更
counterparty_check
2026年10月1日2:42
変更
list_policies
2026年10月1日2:42
変更
evaluate_action
2026年10月1日2:42
変更
evidence_for
2026年10月1日2:42
変更
vault_exits
2026年10月1日2:42
変更
preflight_payment
2026年10月1日2:42
変更
check_service_endpoint
2026年10月1日2:42
変更
counterparty_bulk
2026年9月29日2:49
変更
counterparty_history
2026年9月29日2:49
変更
find_agents
2026年9月29日2:49
変更
list_vaults
2026年9月29日2:49
変更
find_vaults
2026年9月29日2:49
変更
counterparty_check
2026年9月29日2:49
追加
list_policies
2026年9月29日2:49
追加
evaluate_action
2026年9月29日2:49
追加
evidence_for
2026年9月29日2:49
追加
vault_exits
2026年9月29日2:49
変更
preflight_payment
2026年9月29日2:49
変更
check_service_endpoint
2026年9月29日2:49
変更
identify
2026年9月29日2:49
変更
counterparty_bulk
2026年9月27日2:40
変更
counterparty_history
2026年9月27日2:40
変更
find_agents
2026年9月27日2:40