Tracea
Tracea — legal identity (Know Your Agent) for AI agents, on-chain. ERC-8004 compatible.
- 0.1.0
- Version
- remote
- Transport
- 15
- Tools
Security review
Review passedReviewed Jan 1, 2000.
- tools: 15 tools scanned
- metadata: scanned
No findings.
Tools (15)
verify_agent
Verify an AI agent's on-chain legal identity on Tracea (Base Sepolia). Returns registration status, financial cap, permission scope, revocation status, and KYA legal identity (mandant) when available. Use this BEFORE trusting or delegating work to an agent.
get_agent_info
Get the raw Tracea registry record for an agent: owner, permission scope, financial cap, active status, timestamps.
is_agent_revoked
Check whether an agent's mandate has been revoked on Tracea (immediate, scheduled or partial revocation).
get_owner_agents
List all agent addresses registered on Tracea by a given owner address.
get_action
Read a single logged agent action from the Tracea ActionLog contract by its numeric ID. Returns agent, action type, payload and timestamp.
get_agent_actions
List all on-chain action IDs logged for a given agent on Tracea.
log_action
Log an agent action on-chain via Tracea (immutable audit trail, court-ready). Requires TRACEA_API_KEY env var. The action is signed by the account's wallet.
get_registration_file
Fetch the ERC-8004 compatible registration file for a Tracea-registered agent, including the KYA legal principal block.
report_activity
Report an action the agent just performed to its owner's Tracea activity feed (off-chain, free, instant). Call this AFTER every significant action (email sent, message posted, file modified, payment, purchase, booking...). Auth via the Tracea MCP URL (?key=...) from the agent's identity page, OR self-activate with a one-time activation code (?code=... or x-activation-code header) — the tool then receives its apiKey automatically.
get_my_identity
Get this agent's full Tracea identity (activity apiKey +, for v2 agents, its EOA private key and ERC-4337 smart account address) using a one-time activation code from the owner. The private key is returned ONLY ONCE — save it securely.
get_payment_whitelist
Get the list of owner-approved payment destination addresses for an agent (anti-injection guardrail). Non-empty list = the agent's smart account can ONLY pay these addresses. Empty = all allowed.
check_payment_allowed
Dry-run a payment BEFORE executing it: checks on-chain whether the agent's smart account would allow it (permission granted, within financial cap, destination approved if a whitelist exists). Returns { allowed, reason }.
payment_required
Create a x402 payment request (HTTP 402) for a resource you sell to another agent. Returns a paymentId, the USDC amount in units, the destination address and the TraceaPayments contract to call. The paying agent must then call TraceaPayments.payX402(destination, amount, paymentId) on-chain — the contract enforces financial cap + whitelist on-chain. Deliver the resource only after payment_incoming confirms fulfilment.
payment_incoming
Verify a x402 payment ON-CHAIN (the USDC transfer to your address, exact amount) and mark the session fulfilled. The blockchain is the ONLY source of truth — the payment_sessions table is never trusted alone. Returns { status: 'fulfilled', resource } if verified, or an error if not yet paid/expired.
payment_status
Get the status of a x402 payment session (pending | paid | fulfilled | expired), with destination, amount and tx hash. Useful to poll while waiting for the paying agent's on-chain transaction.