MCP Server

Agent Verifier

guru.packet/agent-verifier
Developer Tools Security Public & reachable MCP 2025-11-25

What this MCP does

Checks Web Bot Auth signatures, key directory information, request details, and configuration errors.

self_check_web_bot_auth
Check my own Web Bot Auth setup
Reports how the request carrying this call looks from the outside: whether its Web Bot Auth (RFC 9421) signature verified, what the key directory it named publishes, the exact fault if there is one and the sentence saying what to change, plus plain facts about the address it arrived from. Sign the call the way you sign requests to anyone else. Free, anonymous, no account. Takes no arguments: an unsigned call still gets an answer about its address.
Read only Idempotent
Input schema
{'type': 'object', 'properties': {}, 'additionalProperties': False}
Output schema
{'type': 'object', 'properties': {'id': {'type': 'string', 'description': 'Identifier for this verdict, safe to quote in a support request.'}, 'ip': {'type': 'object', 'properties': {'asn': {'type': ['integer', 'null'], 'description': 'Autonomous system number of the network.'}, 'org': {'type': ['string', 'null'], 'description': 'The organisation that network is registered to.'}, 'origin': {'type': 'string', 'description': 'What kind of network the address belongs to: residential, datacenter, mobile, and so on.'}, 'hostname': {'type': ['string', 'null'], 'description': 'Reverse DNS name of the address, when it has one.'}, 'riskLevel': {'type': 'string', 'description': 'The same figure as a word: low, medium or high.'}, 'riskScore': {'type': 'integer', 'description': 'Reputation of the ADDRESS, 0 to 100, higher meaning worse. A datacenter address scores in the middle by nature: it is a statement about where you are, never about who you are or what you did.'}, 'blacklisted': {'type': 'boolean', 'description': 'Whether the address appears on the public abuse feeds this service tracks.'}}, 'description': 'Plain facts about your own address: network, operator, reputation of the address itself.', 'additionalProperties': True}, 'geo': {'type': 'object', 'properties': {'city': {'type': ['string', 'null'], 'description': 'City the address is placed in.'}, 'region': {'type': ['string', 'null'], 'description': 'First-level administrative division.'}, 'country': {'type': ['string', 'null'], 'description': 'ISO 3166-1 alpha-2 country code of the address.'}, 'timezone': {'type': ['string', 'null'], 'description': 'IANA timezone name for that place.'}}, 'description': 'Country, region, city and timezone of your address.', 'additionalProperties': True}, 'meta': {'type': 'object', 'properties': {'axes': {'type': 'array', 'items': {'type': 'string'}, 'description': 'Which sources contributed to this answer. An axis absent here contributed nothing, which is why a field can be missing without anything being wrong.'}, 'apiVersion': {'type': 'string', 'description': 'Version of this API. `v1` today.'}, 'queryTimeMs': {'type': ['integer', 'null'], 'description': 'How long the answer took to build, in milliseconds.'}}, 'description': 'Envelope: API version, how long the verdict took, which axes contributed.', 'additionalProperties': True}, 'mode': {'enum': ['direct'], 'type': 'string', 'description': 'You called this endpoint yourself, so the answer describes your own request.'}, 'signals': {'type': 'object', 'properties': {'agent': {'type': 'object', 'properties': {'card': {'type': 'object', 'description': 'Your own published card read back to you, plus the one promise a single live request can settle: the User-Agent you said you would send.', 'additionalProperties': True}, 'notes': {'type': 'array', 'description': 'Observations about your setup that are not faults.'}, 'knownBot': {'enum': ['matched', 'none'], 'type': 'string', 'description': 'The second, independent check, and the one that has nothing to do with your signature: some operators publish the address ranges their crawlers use, and those lists are read here nightly. matched means the address this request came from is inside such a published range. none is the ordinary answer and is not a fault: it means no operator publishes a list containing this address, which is true of every address that is not a large crawler, and true of most agents.'}, 'signature': {'type': 'object', 'description': 'Whether a Web Bot Auth signature was present and how it came out.', 'additionalProperties': True}, 'webBotAuthDetail': {'type': 'object', 'description': 'The specific fault, and the sentence saying what to change. Read this part first. Besides reason and fix it may carry three more members. clockDriftSec is how far the signing clock sits from this server, in seconds. directoryStatus is the HTTP status the named key directory answered with, where 403 or 429 is almost always a firewall in front of it refusing this verifier rather than anything about the keys. fromCachedDirectory appears only when true and means the answer rests on a stored copy that could not be refreshed, so a key reported as absent may simply have been published after that copy was taken.', 'additionalProperties': True}, 'refutedSignatures': {'type': 'array', 'description': 'Other signatures on the same request whose named directory does not list the key they used. You can confirm each against the published file yourself.'}, 'keyDirectoryBinding': {'enum': ['binding-proven', 'binding-key-proven', 'binding-not-provided', 'binding-failed', 'binding-not-checked'], 'type': 'string', 'description': 'Whether your directory proved it published the key set that was read. binding-key-proven means the response signature verified but did not cover the body, so possession of the key is proven and the key set is not.'}}}, 'transport': {'type': 'object', 'properties': {'provenance': {'enum': ['measured', 'unavailable'], 'type': 'string', 'description': 'measured = your request arrived directly and was read first-hand. unavailable = it did not, and no finding in this answer rests on it.'}}}, 'automation': {'type': 'object', 'properties': {'uaClient': {'type': 'string', 'description': 'What your User-Agent string alone says you are. A string, not a judgement.'}, 'clientHints': {'type': 'string', 'description': 'State of the Client Hints headers you sent.'}}}}}, 'success': {'type': 'boolean', 'description': 'Always true on a 200. Errors carry success:false and an error object.'}, 'identity': {'type': 'object', 'properties': {'bot': {'type': ['string', 'null'], 'description': 'The specific bot within that operator, when the evidence distinguishes one.'}, 'method': {'type': 'string', 'description': 'How the name was established: `signature` when your own signature verified, `range` when your address sat in a list its operator publishes.'}, 'trusted': {'type': 'boolean', 'description': 'Whether the established name is one this verifier holds a trust anchor for. A verified signature from a domain nobody knows is a verified signature from a domain nobody knows.'}, 'operator': {'type': ['string', 'null'], 'description': 'The name established for you, when one could be. Null when nothing named you.'}}, 'description': 'Who you were established to be, and on what evidence. Empty of judgement: the outcome of checking a signature you sent against a directory you published.', 'additionalProperties': True}}}
Added
self_check_web_bot_auth
Oct. 3, 2026, 2:40 a.m.

hyperion

com.thetempleofdoom.hyperion/hyperion

Acts as a paid MCP tool marketplace and utility gateway with server discovery, HTTP and JavaScript tools, research, data conversi…

Vee3

io.github.Vee3io/vee3

Manages Clerk authentication infrastructure, including users, organizations, domains, sessions, tokens, OAuth, SSO, machines, per…

IA-QA — 130+ QA & Dev Tools for AI Agents

io.github.JcJamet/ia-qa-toolbox

Provides deterministic QA, evaluation, testing, code analysis, prompt and RAG checks, model comparison, and web security diagnost…

validoria-mcp

com.validoria/validoria-mcp

Runs continuous website, API, and webshop tests covering security, SEO, performance, accessibility, browser journeys, and inciden…

HubVibe: Pay-per-Call Tools for AI Agents: Web Search, Email Verify, KYC, Stocks, Crypto, News, Data

io.github.Its-fortunatefolly/hubvibe

Offers paid utilities for web audits, HTTP fetching and extraction, BigQuery analysis, LLM processing, code execution, blockchain…

developer-tools

net.programmes/developer-tools

Provides general-purpose developer utilities for encoding, hashing, encryption, JSON, HTML, CSS, networking, and related data tra…

Qiniso

io.github.qinisolabs/qiniso

Provides deterministic formatting, parsing, holiday and tax lookups, address handling, and checksum or structure validation for i…

ContrastAPI

com.contrastcyber/api

Provides security research and assessment tools covering CVEs, IOCs, dependencies, secrets, injection risks, HTTP headers, domain…