CrossingKey MCP
Agent-native MCP for governed commerce, x402 payments, paid capabilities, and verifiable receipts.
- 3.0.1
- Version
- remote
- Transport
- 26
- Tools
Security review
Review passedReviewed 11h ago.
- tools: 26 tools scanned
- metadata: scanned
No findings.
Tools (26)
marketplace.describe
FREE, read-only marketplace overview. Use this first for marketplace-specific capability commerce, fee policy, creator rights, payment rails, and active catalog counts; use provider.describe for the broader CrossingKey provider and legacy offer surface.
provider.register
FREE public intake. Submit a pending marketplace provider application; this creates no credential, approval, payment, ownership transfer, or active capability. Use creator.apply instead when submitting an asset or body of work that still needs a capability model.
provider.get
FREE. Public active provider metadata. Pending applications require owner or administrator authorization.
capability.get
FREE. Use name for legacy deterministic capability metadata or capabilityId for public marketplace metadata, rights and provenance.
capability.search
FREE MARKETPLACE FILTERED DISCOVERY ONLY. Search active public marketplace capabilities when one or more filters are known: text, category, provider, delivery type, or price. Metadata is free; purchased execution and deliverables are not. Do NOT use for unfiltered browsing; use catalog.list. Do NOT use for CrossingKey digital/service offers; use offers.list. For one exact capabilityId use capability.get.
catalog.list
FREE MARKETPLACE UNFILTERED DISCOVERY ONLY. Page through active public marketplace capabilities when no search filters are needed. Metadata is free; execution, entitlement, delivery, and purchased output remain gated. Do NOT use for filtered discovery; use capability.search. Do NOT use for CrossingKey digital/service offers; use offers.list. For one exact capabilityId use capability.get.
commerce.quote
FREE MARKETPLACE PAYMENT QUOTE ONLY. After selecting an active marketplace capabilityId, return authoritative gross price, CrossingKey fee, provider share, and x402 v1/v2 payment requirements. A quote grants no entitlement and performs no execution. Do NOT use for first-party paid capabilities; use cost.estimate (first-party x402 capabilities have fixed catalog prices and no quote stage). Do NOT use for generic price lookup; use cost.estimate. Paid marketplace execution requires capability.purchase with authorization and verified payment.
creator.apply
FREE WRITE. Private creator intake for assets needing a capability model. No ownership transfer and AI training defaults false.
provider.describe
FREE read-only provider and commerce policy discovery. Use this before selecting an offer or capability.
offers.list
FREE read-only public offer and capability discovery. This tool never starts payment or execution.
requirements.check
FREE read-only requirements check. This tool never authorizes or starts payment or execution.
cost.estimate
FREE read-only cost estimate. This tool never creates checkout, reserves funds, or contacts a facilitator.
result.preview
FREE read-only result-shape preview. This tool never executes a capability or creates an entitlement or receipt.
execution.preflight
FREE read-only execution preflight. Returns READY_FOR_HUMAN_AUTHORIZATION only; it never authorizes, purchases, settles, executes, or creates records.
credits.options
FREE read-only prepaid request-credit pack options. Lists available credit packs with identifiers and credit amounts. Purchasing happens via checkout; this tool never starts payment or creates accounts.
x402.compatibility_audit
PAID $1.00 USDC on Base via x402. Audits an x402 endpoint for v1/v2 compatibility defects. Calling this MCP tool does not spend funds; it returns the exact PAYMENT-REQUIRED challenge and canonical paid execution endpoint.
mcp.schema_audit
PAID $1.00 USDC on Base via x402. Scores supplied MCP tool schemas for discoverability, descriptions, and bounded input contracts. Calling this MCP tool does not spend funds; it returns the exact PAYMENT-REQUIRED challenge and canonical paid execution endpoint.
openapi.quality_audit
PAID $1.00 USDC on Base via x402. Evaluates structural quality and required fields in an OpenAPI document. Calling this MCP tool does not spend funds; it returns the exact PAYMENT-REQUIRED challenge and canonical paid execution endpoint.
machine_commerce.readiness_audit
PAID $2.00 USDC on Base via x402. Checks machine-commerce discovery and health surfaces. Calling this MCP tool does not spend funds; it returns the exact PAYMENT-REQUIRED challenge and canonical paid execution endpoint.
artifact.integrity_manifest
PAID $0.10 USDC on Base via x402. Creates deterministic SHA-256 entries and a root manifest hash for supplied text artifacts. Calling this MCP tool does not spend funds; it returns the exact PAYMENT-REQUIRED challenge and canonical paid execution endpoint.
hash.encode
PAID $0.01 USDC on Base via x402. Computes a SHA-256 digest and UTF-8 byte count for supplied text. Calling this MCP tool returns a payment challenge and does not autonomously spend funds.
secret.scan
PAID $0.01 USDC on Base via x402. Detects selected credential patterns and returns classifications and positions, not matched values. Heuristic, not comprehensive. Calling this MCP tool returns a payment challenge and does not autonomously spend funds.
pii.scan
PAID $0.01 USDC on Base via x402. Detects selected personal-data patterns and returns classifications and positions, not matched values. Heuristic, not comprehensive. Calling this MCP tool returns a payment challenge and does not autonomously spend funds.
json.repair
PAID $0.01 USDC on Base via x402. Validates JSON and repairs a limited set of formatting errors. May return supplied content. Calling this MCP tool returns a payment challenge and does not autonomously spend funds.
prompt.audit
PAID $0.01 USDC on Base via x402. Scores selected prompt structure signals using deterministic heuristics. Calling this MCP tool returns a payment challenge and does not autonomously spend funds.
xkey.validate
PAID prepaid-credit XKEY intake validation. Requires an authenticated ck_ principal and commits one credit only on verified success. Discovery is free; execution is not.