Make x402 micropayments in USDC on Base from AI coding environments.
Do not connect
A critical issue was found. Do not connect this server as-is.
Scanned 6 days ago
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The xenarch MCP server exposes 103 tools, focused primarily on communication capabilities. Its published description reads: "Make x402 micropayments in USDC on Base from AI coding environments". It communicates over Streamable HTTP using the 2025-06-18 protocol revision, and does not require authorization to connect. MCPGrade currently rates xenarch F — a critical issue was found and the server should not be connected as-is. Its most notable findings include "Data-exfiltration parameters" and "Data-exfiltration parameters". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check xenarch's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add xenarch to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://mcp.xenarch.dev/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
Check if a URL or domain has an x402 payment gate. Returns gate status, accepted payment requirements (price, asset, network), and the seller wallet. Use this before paying to confirm pricing, when a
Pay an x402-gated URL with USDC on Base L2 and return the gated content. Signs an EIP-3009 transferWithAuthorization, settles on-chain, then re-fetches the resource with proof of payment. Returns the
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: xenarch_check_gate
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: xenarch_pay
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: xenarch_pay
A tool description tries to alter the model’s use of another tool.
ired. Use after xenarch_check_gate confirms a gate exists, or when the user asks tRecommendationDescriptions must describe only their own tool.
tool: xenarch_update_merchant_profile
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "issuer_logo_url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: xenarch_verify_domain
A tool description tries to alter the model’s use of another tool.
_site first via xenarch_update_merchant_profile.RecommendationDescriptions must describe only their own tool.
tool: xenarch_permit_collect
A tool description tries to alter the model’s use of another tool.
not-booked, use xenarch_record_collect; NEVER re-run this tool for the same cycle.RecommendationDescriptions must describe only their own tool.
tool: xenarch_metered_collect
A tool description tries to alter the model’s use of another tool.
not-booked, use xenarch_record_collect; NEVER re-run this tool for the same charges.RecommendationDescriptions must describe only their own tool.
tool: xenarch_set_link_webhook
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: xenarch_set_agent_webhook
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: xenarch_get_receipt
A tool description tries to alter the model’s use of another tool.
ipt by id (from xenarch_agent_get_receipts). Read-only.RecommendationDescriptions must describe only their own tool.
tool: xenarch_set_site_gating
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: xenarch_create_site_claim
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
ort-lived claim token so a plugin/worker/SDK can bootstrap its site tRecommendationRemove side-channel parameters; constrain tool inputs.
tool: xenarch_redeem_invite
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
count by invite token — the agent's LOCAL wallet signs SIWE and attacRecommendationRemove side-channel parameters; constrain tool inputs.
tool: xenarch_set_account_email
A tool description tries to alter the model’s use of another tool.
de (finish with xenarch_verify_account_email). Requires confirm: true.RecommendationDescriptions must describe only their own tool.
tool: xenarch_upload_asset
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "url"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: xenarch_pay_link
Tools that execute commands / write files / make arbitrary requests are exposed without annotations or guards.
xenarch_pay for arbitrary x402-gated URLs. Pays from the agent wallet (USDC only, no gasRecommendationAnnotate destructive tools and require human approval.
tool: xenarch_pay_link
A tool description tries to alter the model’s use of another tool.
<id> links; use xenarch_pay for arbitrary x402-gated URLs. Pays from the agRecommendationDescriptions must describe only their own tool.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: xenarch_check_gate
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_pay
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_wallet_status
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_get_history
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_agent_login
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_agent_status
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_agent_get_caps
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_agent_set_caps
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_agent_reset_day_cap
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_agent_get_scope
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_agent_add_scope_rule
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_agent_remove_scope_rule
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_agent_set_default_scope
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_agent_pause
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_agent_resume
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_agent_list_keys
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_agent_create_key
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_agent_rotate_key
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_agent_revoke_key
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_agent_get_receipts
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_list_links
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_get_link
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_create_link
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_revoke_link
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_list_payments
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_list_subscribers
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_get_merchant_profile
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_update_merchant_profile
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_verify_domain
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_get_subscriber
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_get_subscriber_charges
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_get_subscriber_rollup
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_cancel_subscriber
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_suspend_subscriber
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_mint_manage_link
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_set_period_cap
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_list_permit_collectable
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_list_metered_collectable
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_fire_permit_digest
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_permit_submit
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_permit_collect
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_metered_collect
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_record_collect
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_edit_link
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_get_link_events
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_get_links_rollup
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_get_links_summary
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_list_groups
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_create_group
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_update_group
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_delete_group
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_assign_link_group
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_list_orders
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_ship_order
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_export_orders
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_get_link_webhook
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_set_link_webhook
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_rotate_link_webhook_secret
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_test_link_webhook
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_get_link_webhook_deliveries
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_retry_link_webhook_delivery
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_get_agent_webhook
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_set_agent_webhook
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_rotate_agent_webhook_secret
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_test_agent_webhook
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_get_agent_webhook_deliveries
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_retry_agent_webhook_delivery
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_update_agent_profile
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_get_receipt
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_list_sites
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_add_site
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_get_site
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_delete_site
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_set_site_gating
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_set_site_pricing
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_rotate_site_token
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_get_site_stats
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_get_site_activity
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_get_site_categories
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_get_publisher_gating
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_set_publisher_gating
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_create_site_claim
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_bot_catalog
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_bot_activity
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_list_wallets
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_link_wallet
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_unlink_wallet
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_set_wallet_label
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_transfer_owner
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_list_merchant_keys
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_create_merchant_key
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_rotate_merchant_key
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_revoke_merchant_key
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_create_invite
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_list_invites
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_revoke_invite
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_preview_invite
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_redeem_invite
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_set_account_email
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_verify_account_email
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_upload_asset
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_get_earnings_summary
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
tool: xenarch_pay_link
The server advertises open-world / broadly-scoped capabilities.
annotations.openWorldHint = trueRecommendationScope tools to the minimum needed.
Vantaj uptime monitoring via MCP — manage monitors, heartbeats, incidents, and status pages.
Unified gateway to Algeria's TKAWEN ecosystem: commerce, certification, and AI tools.
Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Agentic rails for complex workflows with receipts, fees, and MCP tool access.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Show the agent's local payment wallet: its address, USDC balance on Base, and whether it's funded. Use this to find the address the user needs to top up with USDC, or to check the balance before payin
List past USDC micropayments made by this wallet through Xenarch. Returns transaction hashes, URLs, domains, amounts in USD, timestamps, total spend, and payment count. Optionally filter by domain. Us
Sign in to the agent control plane using your browser wallet — no CLI needed. First call returns a link; open it, sign in with your wallet on the dashboard, and approve. Call this tool again to finish
Show the operator's agent profile (name, paused state) and spend summary for a period. Read-only. Needs a SIWE session from `xenarch agent login`.
Read the agent's spending caps (per-transaction, daily, monthly) and remaining headroom. Read-only.
Set spending caps. Pass per_tx/daily/monthly in USD ('none' disables an axis); omit an axis to leave it unchanged. RAISING or REMOVING a cap requires confirm: true (returns needs_confirmation otherwis
Reset today's daily-spend counter back to the full daily cap (recovery from accidental mid-day exhaustion). Restores full spending headroom — requires confirm: true.
Read the agent's scope: default posture (allow/deny) and the allow/deny rule list. Read-only.
Add an allow/deny scope rule. A 'deny' rule tightens (free); an 'allow' rule loosens and requires confirm: true.
Remove a scope rule by id (full UUID or unambiguous prefix). Removing a DENY rule loosens scope and requires confirm: true.
Set the default scope posture for unmatched URLs. 'deny' tightens (free); 'allow' loosens and requires confirm: true.
Kill switch: pause the agent so all of its payments are blocked immediately. Tightening, so no confirm needed.
Lift the pause so the agent can spend again (subject to caps + scope). Requires confirm: true.
List the agent's xa_live_ API keys (id, label, last-used, revoked state). Never returns plaintext. Read-only.
Issue a new xa_live_ API key (plaintext returned once). Issues a live spending credential — requires confirm: true.
Rotate an API key by id (full UUID or prefix) — invalidates the old secret, returns a new one once. Requires confirm: true.
Permanently revoke an API key by id (full UUID or prefix). Requires confirm: true.
List the agent's payment receipts with filters (period, status, source, domain) and pagination. Read-only.
List the merchant's pay-links (newest first), with cursor pagination. Read-only. Needs a SIWE session from `xenarch agent login`.
Get one pay-link's detail (status, params, stats) by id. Read-only.
Create a pay-link. VALIDATE-FIRST: call with mode:'validate' (default) to learn which fields are missing (each missing field includes a prompt to ask the user); once valid, call again with mode:'creat
Revoke a pay-link by id so it can no longer be paid. Requires confirm: true (returns needs_confirmation otherwise).
List payments RECEIVED across the merchant's pay-links (newest first), with cursor pagination. Read-only.
List subscribers across the merchant's subscription pay-links, with optional filters (link_id, status, mode). Read-only.
Get the merchant profile (issuer identity, domain verification status). Read-only. Returns null if none is set yet.
Update the merchant profile (issuer name, site, email, address, tax id, brand color, logo, payout rhythm). Only the fields you pass change; the rest are preserved (whole-state upsert). Rewrites custom
Verify the merchant's domain via its DNS TXT record at _xenarch.<merchant_site> (XEN-394). Set merchant_site first via xenarch_update_merchant_profile.
Get one subscriber's full detail (plan, cadence, renewal dates, payer, permit/metered state) by subscription id. Read-only.
Read a metered subscriber's immutable charge ledger (booked + settled charges, totals, outstanding). Read-only, cursor over charge_seq.
Subscriber KPIs: active count, MRR (USDC), 30-day churn. Read-only.
Cancel a subscription (merchant-initiated; reminder-mode only, 409 otherwise). Permanent. Requires confirm: true.
Suspend a subscription: collection attempts and dunning stop. Any mode, idempotent, no on-chain effect. Requires confirm: true.
Mint a short-lived manage URL + token for a subscriber (hosted manage page). Anyone holding it can manage that subscription until expiry. Requires confirm: true.
Set/raise a metered-per-period subscriber's budget (new_cap_usdc). Mints the manage token behind the scenes. Requires confirm: true.
List permit subscriptions with a cycle due now (the collectable bag): amount, owner→spender transferFrom params, permit status. Read-only.
List metered subscriptions with booked charges awaiting on-chain settlement (the collectable bag). Read-only.
Dev/test: drop the throttle and immediately re-send the collectable digest email for your wallet. Requires confirm: true.
Broadcast the buyer's signed USDC.permit on-chain to set the allowance (moves NO funds; wallet pays gas). Needs the LOCAL seller wallet key + Base ETH. Broadcasting requires confirm: true. Pass tx_has
Collect one due permit cycle: preflights allowance/balance/simulation, broadcasts USDC.transferFrom from the LOCAL seller wallet (must be the permit spender, needs Base ETH gas), then books it. MOVES
Settle a metered subscriber's booked charges on-chain: preflight, broadcast USDC.transferFrom from the LOCAL seller wallet, book. MOVES REAL MONEY — requires confirm: true PLUS expected_amount_usdc pi
Recovery: book an ALREADY-broadcast transferFrom by tx hash. Never transfers — the backend dedups on tx_hash, so it is always safe to re-run.
Replace a pay-link's metadata object (whole-state; null clears). Requires confirm: true.
List a pay-link's event stream (views, payments, webhook fires…) with type filter + cursor. Read-only.
Merchant pay-link KPIs: paid 24h/total, month-to-date revenue, views, conversion. Read-only.
Revenue / paid-count / link-count summary for a period (24h, 7d, 30d, all). Read-only.
List pay-link groups (name, accent, members). Read-only.
Create a pay-link group. Requires confirm: true.
Rename / re-accent / re-position a pay-link group. Requires confirm: true.
Delete a pay-link group (member links become ungrouped). Requires confirm: true.
Move a pay-link into a group (or null to ungroup). Requires confirm: true.
List paid orders across pay-links (buyer, shipping, status, tracking) with filters + cursor. Read-only.
Mark an order shipped with a tracking number — emails the buyer. Requires confirm: true.
Export orders as CSV text (same filters as list). Read-only.
Read a pay-link's webhook config (URL, event types, enabled). Read-only.
Set a pay-link's webhook URL / event types / enabled. Requires confirm: true.
Rotate a pay-link's webhook signing secret (old secret stops verifying). Requires confirm: true.
Send a test event to a pay-link's webhook URL. Requires confirm: true.
List a pay-link's recent webhook delivery attempts (status, latency, errors). Read-only.
Re-send one failed pay-link webhook delivery. Requires confirm: true.
Read the agent's webhook config (URL, event types, enabled). Read-only.
Set the agent's webhook URL / event types / enabled. Requires confirm: true.
Rotate the agent webhook's signing secret. Requires confirm: true.
Send a test event to the agent's webhook URL. Requires confirm: true.
List the agent webhook's recent delivery attempts. Read-only.
Re-send one failed agent webhook delivery. Requires confirm: true.
Update the agent's display profile (display_name, label; null clears). Requires confirm: true.
Get one payment receipt by id (from xenarch_agent_get_receipts). Read-only.
List the signed-in identity's sites (domain, price, gating, integration). Empty if the identity isn't a publisher yet. Read-only.
Create a site (issues its site token; domain optional — the integration backfills it). Needs a verified account email. Requires confirm: true.
Full site detail: gating config, pricing rules, token hash, integration. Read-only.
Permanently delete a site — its token stops working. Requires confirm: true.
Replace a site's gating config (master switch + category map, whole-state). Changes which bot traffic is charged/blocked. Requires confirm: true.
Replace a site's pricing (default price/scope + per-path rules, whole-state). Requires confirm: true.
Rotate a site's token — the integration must be updated or gating stops. Requires confirm: true.
Site earnings stats: gates, paid count, revenue, top pages, top agents. Read-only.
Site transaction feed (paid / blocked / withdrawals) with period + status filters, paginated. Read-only.
Per-bot-category earnings breakdown for a site. Read-only.
Read the publisher-level gating defaults (category map + per-bot overrides). Read-only.
Replace the publisher-level gating defaults — affects every site set to follow them. Requires confirm: true.
Mint a short-lived claim token so a plugin/worker/SDK can bootstrap its site token without copy-paste. Requires confirm: true.
The full bot signature catalog (name, category, company). Public, no auth. Read-only.
Aggregated cross-site bot activity for the publisher (hits, sites seen, last seen per signature). Read-only.
List the account's linked wallets (owner/default flags, labels, eligibility). Read-only.
Link the agent's LOCAL wallet to your account as a co-wallet (key-held SIWE — signs with the local key). Requires confirm: true.
Unlink a wallet from the account — it loses sign-in access. Requires confirm: true.
Set/clear a linked wallet's nickname. Requires confirm: true.
Transfer account OWNERSHIP to another linked wallet. Hard to reverse. Requires confirm: true.
List the merchant's xm_live_ API keys (never returns plaintext). Read-only.
Issue a new xm_live_ merchant API key (plaintext returned once). Requires confirm: true.
Rotate a merchant API key — invalidates the old secret, returns a new one once. Requires confirm: true.
Permanently revoke a merchant API key. Requires confirm: true.
Mint a co-owner join link (viewer / operator / full_co_owner). Anyone redeeming it joins your account. Requires confirm: true.
List outstanding (unredeemed) invites. Read-only.
Revoke a live invite before it's redeemed. Requires confirm: true.
Preview a join link: which account it joins, role, expiry. Anonymous. Read-only.
Join another Xenarch account by invite token — the agent's LOCAL wallet signs SIWE and attaches to the inviter's identity. Requires confirm: true.
Set the account email and send it a verification code (finish with xenarch_verify_account_email). Requires confirm: true.
Verify the account email with the emailed code.
Upload an image (URL or base64, max 5 MB) to Xenarch's public CDN — for logos/branding. Returns the cdn.xenarch.dev URL. Requires confirm: true.
Earnings summary: today / this month / all-time (USD + payment counts). Read-only.
Pay a Xenarch pay-link by id (wrapped x402): fetches the link's payment envelope, settles EIP-3009 USDC on Base, and confirms the payment with the link. Use this for pay.xenarch.com/l/<id> links; use