MCP Server

Overwing

ai.overwing/mcp
AI & Agents Security Public & reachable MCP 2025-11-25

What this MCP does

Evaluates text against configurable safety rules and provides agent policy decisions, approval workflows, compensating actions, and signed action receipts.

atlas_agents
Search the agent registry (Overwing Atlas)
Browse or search Overwing Atlas, the registry of AI crawlers, fetchers and browser agents: name, operator, user-agent tokens, Web Bot Auth key directory, robots.txt behaviour, and (with Atlas Pro or Team) purpose class, verification, evasion flags and traffic shares. Filter by free text, purpose (training, search, browser, coding), operator, or verification. Needs an organization key.
Read only
Input schema
{'type': 'object', 'properties': {'q': {'type': 'string', 'maxLength': 200, 'description': 'Free text over name, operator, user agents, description'}, 'limit': {'type': 'integer', 'default': 20, 'maximum': 100, 'minimum': 1}, 'purpose': {'type': 'string', 'maxLength': 60, 'description': 'Purpose substring, e.g. training, search, browser, fetcher, coding'}, 'operator': {'type': 'string', 'maxLength': 100}, 'verification': {'type': 'string', 'maxLength': 60, 'description': "e.g. 'Web Bot Auth', 'spoofable', 'Unattributable'"}}}
atlas_lookup
Identify a user agent (Overwing Atlas)
Say what a User-Agent string claims to be and whether the claim can be trusted, from the Overwing Atlas registry of AI crawlers, fetchers and browser agents. Returns the claimed agent, operator, purpose class, verification method (Web Bot Auth signature, user-agent string only, or unattributable) and a trust note. Works with no API key: 10 lookups a day. With a key, metered per day by Atlas tier: free 100, Pro 10,000, Team 100,000. Use it when deciding whether to serve, block, or pay-gate a request, or to understand who is hitting a site.
Read only
Input schema
{'type': 'object', 'required': ['user_agent'], 'properties': {'user_agent': {'type': 'string', 'maxLength': 2000, 'minLength': 1, 'description': 'The User-Agent header value to identify'}}}
atlas_summary
Agent traffic and spending summary (Overwing Atlas)
Public numbers from Overwing Atlas: registry counts by purpose and verification, published browser-agent traffic shares, sector field-scan headlines (e.g. how many OSINT sites carry AI-crawler rules or any agent-payable surface), and the summary of the Agent Consumers report on what agents actually spend. No key needed.
Read only
Input schema
{'type': 'object', 'properties': {}}
beacon_report
Read a reachability report (Overwing Beacon)
The report for a check started with beacon_start, once it is paid for: score (0 to 100), verdict (yes, partly, no), the find / read / use answers, every check with what was found and a fix when it did not pass, and top_fixes ranked by value. Answers 402 with the checkout link while unpaid and 202 while the check is running (ask again in a few seconds). The id is the credential: whoever holds it can read the report. No key needed.
Read only
Input schema
{'type': 'object', 'required': ['id'], 'properties': {'id': {'type': 'string', 'pattern': '^bcn_[A-Za-z0-9_-]{16}$', 'description': 'The check id from beacon_start'}}}
beacon_sample
Sample reachability report (Overwing Beacon)
A real Overwing Beacon report, free: the check of overwing.ai itself, refreshed daily. Read it to see exactly what a paid check returns before starting one. No key needed.
Read only
Input schema
{'type': 'object', 'properties': {}}
beacon_start
Start a reachability check (Overwing Beacon)
Overwing Beacon answers one question about a site: is this product reachable by agents? It checks robots.txt rules for AI agents, llms.txt, the sitemap, the MCP server card, hosted MCP endpoint and MCP Registry listing, the A2A agent card, OpenAPI discovery, and how the home page reads to a model, then returns three answers (find, read, use), a score and the fixes worth making. This tool starts a check paid by card ($5): it returns a checkout_url for a person to open and a check id. Nothing runs and nothing is charged until that payment completes; then call beacon_report with the id. An agent with a wallet can instead pay $1 in USDC over x402 and get the report in one call: GET /api/x402/beacon?url=<site>. Call beacon_sample first to see a real report. No key needed.
Input schema
{'type': 'object', 'required': ['url'], 'properties': {'url': {'type': 'string', 'maxLength': 500, 'minLength': 3, 'description': 'The site to check: a domain (example.com) or an https URL. Public sites only.'}}}
create_rule_set
Create rule set
Create a custom rule set with 1 to 25 rules. Each rule is a choice (pick one option), score (position on an ordered scale), or noul (yes/no) question with a fail condition, optional review threshold, weight, and action (block, redact, or review) that callers should take when it fails. Rule instructions may reference `context.*` fields that callers pass with each evaluation. Needs an organization key.
Input schema
{'type': 'object', 'required': ['name', 'slug', 'rules'], 'properties': {'name': {'type': 'string', 'maxLength': 100}, 'slug': {'type': 'string', 'pattern': '^[a-z0-9]+(?:-[a-z0-9]+)*$', 'maxLength': 100}, 'rules': {'type': 'array', 'items': {'type': 'object', 'required': ['name', 'question_type', 'question_config', 'fail_condition'], 'properties': {'name': {'type': 'string', 'maxLength': 100}, 'action': {'enum': ['block', 'redact', 'review'], 'type': 'string', 'description': 'What a caller should do when this rule fails: block (default), redact, or review'}, 'weight': {'type': 'number', 'maximum': 100, 'exclusiveMinimum': 0}, 'description': {'type': 'string'}, 'question_type': {'enum': ['choice', 'score', 'noul'], 'type': 'string'}, 'fail_condition': {'type': 'object', 'description': 'choice: {failOn: [options]}; noul: {failOn: boolean}; score: {failAbove: levelIndex}', 'additionalProperties': {}}, 'question_config': {'type': 'object', 'description': 'choice: {options[], instructions}; score: {levels[], instructions}; noul: {question}', 'additionalProperties': {}}, 'review_condition': {'type': 'object', 'required': ['confidenceBelow'], 'properties': {'confidenceBelow': {'type': 'number', 'maximum': 1, 'exclusiveMinimum': 0}}}}}, 'maxItems': 25, 'minItems': 1}, 'description': {'type': 'string'}}}
evaluate
Evaluate text
Works with no API key: 10 evaluations a day, inputs up to 2,000 characters, and the text is not stored. With a key: 250 a day and up, inputs up to 100,000 characters, and your own rule sets. Score any text (typically an LLM's output) against an Overwing rule set. The text can be in any language; tested in Spanish, Portuguese, French, German, Japanese, Chinese, Korean, Arabic and Hindi. Results come back in English. Returns an aggregate verdict of pass, fail, or review, a recommended_action (block, redact, review, or allow), and per-rule answers with probability, confidence, and the rule's action. Act on recommended_action: block means do not send, redact means remove the flagged content and resend, review means ask a human or a slower model, allow means proceed. Prebuilt sets: 'content-safety' (toxicity, PII, self-harm, sexual content, severity) and 'outbound-message', which also takes a context object (recipient, channel, owns_contact_info) so PII that the recipient already owns is not flagged.
Input schema
{'type': 'object', 'required': ['input'], 'properties': {'input': {'type': 'string', 'maxLength': 100000, 'minLength': 1, 'description': 'The text to evaluate, in any language'}, 'store': {'type': 'boolean', 'description': 'With a key: false runs the check without keeping the input text or the context (the verdict and metadata are still recorded). Without a key the text is never stored.'}, 'context': {'type': 'object', 'description': "Facts the rules may reference: recipient, channel, whether you own the data, sender, purpose. Sent to the model alongside the text (max 8 KB). Use the 'outbound-message' rule set to have it honoured.", 'additionalProperties': {}}, 'metadata': {'type': 'object', 'description': 'Opaque data stored with the evaluation and echoed in webhooks (max 8 KB)', 'additionalProperties': {}}, 'rule_set': {'type': 'string', 'default': 'content-safety', 'description': 'Rule set slug'}}}
evaluate_batch
Evaluate many texts
Score up to 50 texts against one rule set in a single call. Each item counts as one evaluation. Returns a summary plus per-item verdicts; items can fail independently. Needs an organization key.
Input schema
{'type': 'object', 'required': ['items'], 'properties': {'items': {'type': 'array', 'items': {'type': 'object', 'required': ['input'], 'properties': {'id': {'type': 'string', 'maxLength': 128}, 'input': {'type': 'string', 'maxLength': 100000, 'minLength': 1}, 'context': {'type': 'object', 'description': 'Per-item context; overrides the batch-level context', 'additionalProperties': {}}, 'metadata': {'type': 'object', 'additionalProperties': {}}}}, 'maxItems': 50, 'minItems': 1}, 'store': {'type': 'boolean', 'description': 'False runs every item without keeping its input text or context'}, 'context': {'type': 'object', 'description': "Facts the rules may reference: recipient, channel, whether you own the data, sender, purpose. Sent to the model alongside the text (max 8 KB). Use the 'outbound-message' rule set to have it honoured.", 'additionalProperties': {}}, 'rule_set': {'type': 'string', 'default': 'content-safety'}}}
get_evaluation
Get evaluation
Fetch a stored evaluation by id, including the original input and per-rule results. Needs an organization key.
Read only
Input schema
{'type': 'object', 'required': ['id'], 'properties': {'id': {'type': 'string', 'maxLength': 128, 'minLength': 1}}}
get_rule_set
Get rule set
Fetch a rule set with its full rule definitions. Use 'content-safety' as a worked example when writing your own. Needs an organization key.
Read only
Input schema
{'type': 'object', 'required': ['slug'], 'properties': {'slug': {'type': 'string', 'maxLength': 100, 'minLength': 1}}}
get_usage
Get usage
Daily usage, remaining quota for today, and plan limits. Needs an organization key.
Read only
Input schema
{'type': 'object', 'properties': {'days': {'type': 'integer', 'maximum': 90, 'minimum': 1}}}
list_evaluations
List evaluations
List recent evaluations, newest first, with optional verdict and rule set filters. Use next_cursor to page. Needs an organization key.
Read only
Input schema
{'type': 'object', 'properties': {'limit': {'type': 'integer', 'maximum': 100, 'minimum': 1}, 'cursor': {'type': 'string'}, 'verdict': {'enum': ['pass', 'fail', 'review'], 'type': 'string'}, 'rule_set': {'type': 'string'}}}
list_plans
List plans
Public plan catalog: prices, daily limits, and per-minute burst limits. No API key needed.
Read only
Input schema
{'type': 'object', 'properties': {}}
list_rule_sets
List rule sets
List the prebuilt and custom rule sets available to this organization. Needs an organization key.
Read only
Input schema
{'type': 'object', 'properties': {'include_inactive': {'type': 'boolean'}}}
tower_capabilities
What may I do? (Overwing Tower)
List the operations this agent is allowed to call, each with the JSON Schema its input must match and its compensating operation. Call this first; build inputs from the schema rather than guessing. Needs an agent key.
Read only
Input schema
{'type': 'object', 'properties': {}}
tower_compensate
Undo an executed action (Overwing Tower)
Run the compensating operation for an executed action, for example cancel the order that create_order made. Runs once; repeating it returns the first outcome. Needs an agent key.
Idempotent
Input schema
{'type': 'object', 'required': ['action_id'], 'properties': {'action_id': {'type': 'string', 'pattern': '^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$', 'description': "The executed action's id (a UUID)"}}}
tower_create_agent
Create an agent identity (Overwing Tower)
Create a scoped agent identity and its key. Needs an organization key. Scope it to the operations the agent needs (for example create_order) rather than * where you can. The key (ow_agent_...) is returned once, in this result, and this server does not keep it: store it, and send it as the Authorization bearer on a connection used for the agent tools (tower_capabilities, tower_decide, tower_submit_action, tower_get_action, tower_compensate, tower_get_receipt, tower_verify_receipts). Revoke with tower_revoke_agent.
Input schema
{'type': 'object', 'required': ['name', 'scopes'], 'properties': {'name': {'type': 'string', 'maxLength': 100, 'minLength': 1, 'description': 'A name a person will recognise in the review queue, e.g. order-intake-bot'}, 'scopes': {'type': 'array', 'items': {'type': 'string', 'pattern': '^(\\*|[a-z][a-z0-9_]{0,63})$'}, 'maxItems': 50, 'minItems': 1, 'description': 'Operation names this agent may call, or ["*"] for all'}, 'use_for_session': {'type': 'boolean', 'description': 'Ignored here. The hosted server has no session and never holds a key; it exists so calls written for the npm package still validate.'}}}
tower_decide
Would this be allowed? (Overwing Tower)
Ask Tower how it would rule on an operation without doing anything: auto (would execute), review (a person must approve), or reject. Returns the score, the reason, and each policy question's answer. No side effects. Needs an agent key.
Read only
Input schema
{'type': 'object', 'required': ['operation', 'input'], 'properties': {'input': {'type': 'object', 'description': "The operation's input, matching its input_schema from tower_capabilities", 'additionalProperties': {}}, 'operation': {'type': 'string', 'maxLength': 64, 'minLength': 1}}}
tower_get_action
Get an action (Overwing Tower)
Status and result of an action: pending, approved, executed, failed, compensated, or rejected. Use it to poll an action that is waiting on human review. Needs an agent key.
Read only
Input schema
{'type': 'object', 'required': ['action_id'], 'properties': {'action_id': {'type': 'string', 'pattern': '^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$', 'description': "The action's id (a UUID), from tower_submit_action"}}}
tower_get_receipt
Get a receipt (Overwing Tower)
Fetch one signed receipt by id or by sequence number: the payload, its hash, the previous link's hash, and the Ed25519 signature. Needs an agent key.
Read only
Input schema
{'type': 'object', 'required': ['id'], 'properties': {'id': {'type': 'string', 'maxLength': 64, 'minLength': 1, 'description': 'Receipt id or sequence number'}}}
tower_list_agents
List agents (Overwing Tower)
List this organization's Tower agents with scopes, status and last use. Keys are never returned. Needs an organization key.
Read only
Input schema
{'type': 'object', 'properties': {}}
tower_load_template
Load the starter workflow (Overwing Tower)
Set up Overwing Tower for this organization by loading the starter workflow: email purchase order to order entry, with create_order, update_order and cancel_order against a mock IBM i system, and a starter policy. Idempotent. Needs an organization key. Returns a sample input you can submit. Next: tower_create_agent.
Idempotent
Input schema
{'type': 'object', 'properties': {}}
tower_revoke_agent
Revoke an agent (Overwing Tower)
Revoke an agent. Its key stops working at once and cannot be restored. Needs an organization key.
Destructive Idempotent
Input schema
{'type': 'object', 'required': ['agent_id'], 'properties': {'agent_id': {'type': 'string', 'pattern': '^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$', 'description': "The agent's id (a UUID), from tower_list_agents"}}}
tower_submit_action
Request an action (Overwing Tower)
Ask Tower to perform an operation on the legacy system. Tower decides: executed (done), pending (a person must approve; poll tower_get_action, do not resubmit), or rejected (do not retry unchanged). Always send an idempotency_key that is stable for this business request, such as the source message id: repeating a key returns the original outcome instead of acting twice. Set dry_run to see the decision without executing. Needs an agent key.
Idempotent
Input schema
{'type': 'object', 'required': ['operation', 'input', 'idempotency_key'], 'properties': {'input': {'type': 'object', 'description': "The operation's input, matching its input_schema from tower_capabilities", 'additionalProperties': {}}, 'dry_run': {'type': 'boolean'}, 'operation': {'type': 'string', 'maxLength': 64, 'minLength': 1}, 'idempotency_key': {'type': 'string', 'maxLength': 128, 'minLength': 1, 'description': 'Stable per business request; reuse it on retries'}}}
tower_verify_receipts
Verify the receipt chain (Overwing Tower)
Recompute every hash and check every signature over a range of this organization's receipts. Reports the first break, if any. Defaults to the whole chain (up to 5,000 links per call). Needs an agent key.
Read only
Input schema
{'type': 'object', 'properties': {'to': {'type': 'integer', 'minimum': 1}, 'from': {'type': 'integer', 'minimum': 1}}}
whoami
Who am I
Identify the organization and plan behind the API key on this request, the key's scope, the organization's data settings (store_inputs, retention_days), and whether billing is set up. Needs an organization key.
Read only
Input schema
{'type': 'object', 'properties': {}}
Added
tower_verify_receipts
Oct. 1, 2026, 2:40 a.m.
Added
tower_get_receipt
Oct. 1, 2026, 2:40 a.m.
Added
tower_compensate
Oct. 1, 2026, 2:40 a.m.
Added
tower_get_action
Oct. 1, 2026, 2:40 a.m.
Added
tower_submit_action
Oct. 1, 2026, 2:40 a.m.
Added
tower_decide
Oct. 1, 2026, 2:40 a.m.
Added
tower_capabilities
Oct. 1, 2026, 2:40 a.m.
Added
tower_revoke_agent
Oct. 1, 2026, 2:40 a.m.
Added
tower_list_agents
Oct. 1, 2026, 2:40 a.m.
Added
tower_create_agent
Oct. 1, 2026, 2:40 a.m.
Added
tower_load_template
Oct. 1, 2026, 2:40 a.m.
Added
beacon_sample
Oct. 1, 2026, 2:40 a.m.
Added
beacon_report
Oct. 1, 2026, 2:40 a.m.
Added
beacon_start
Oct. 1, 2026, 2:40 a.m.
Added
atlas_summary
Oct. 1, 2026, 2:40 a.m.
Added
atlas_agents
Oct. 1, 2026, 2:40 a.m.
Added
atlas_lookup
Oct. 1, 2026, 2:40 a.m.
Added
list_plans
Oct. 1, 2026, 2:40 a.m.
Added
whoami
Oct. 1, 2026, 2:40 a.m.
Added
get_usage
Oct. 1, 2026, 2:40 a.m.
Added
list_evaluations
Oct. 1, 2026, 2:40 a.m.
Added
get_evaluation
Oct. 1, 2026, 2:40 a.m.
Added
create_rule_set
Oct. 1, 2026, 2:40 a.m.
Added
get_rule_set
Oct. 1, 2026, 2:40 a.m.
Added
list_rule_sets
Oct. 1, 2026, 2:40 a.m.
Added
evaluate_batch
Oct. 1, 2026, 2:40 a.m.
Added
evaluate
Oct. 1, 2026, 2:40 a.m.

GoCreative Agent API

io.github.ColinHughes2121/gocreative-agent-api

Offers pay-per-call LLM completions and data services for company intelligence, KYB, sanctions screening, threat intelligence, co…

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

DDG Agent Services

io.github.daedalusdevelopmentgroup/ddg-agent-services-mcp

Acts as a pay-per-call gateway for agent tools including LLM routes, web and market data, Ethereum RPC, security scans, service c…

mainstreet

io.github.philpof102-svg/mainstreet

Provides reputation, trust scoring, validation, consensus, routing, and payment-related tools for on-chain AI agents on Base.

xrpl-referee

io.github.eamwhite1/xrpl-referee

Supports XRPL-based agent hiring, escrow payments, job marketplaces, wallet trust scoring, sanctions and KYC checks, and AI-assis…

InsureLink

io.github.skewing1/insurelink

Manages agent reputation, insurance coverage, SLA agreements, transaction safety checks, attestations, claims, and x402-mediated …

Hermes Plant — Agent Commerce Assurance

io.github.JesseGdotIO/hermes-plant

Preflights and attests consequential agent actions, verifies signed evidence, evaluates payments and wallets, and provides determ…

mcp-server

io.github.forcedreamai/mcp-server

Discovers and invokes ForceDream agents, routes paid work, verifies cryptographic proofs, and offers document extraction, code ge…