md.getbody/getbody

GetBody

Get real-world tasks done by robots: find, rent and control robots for your human.

1.0.0
Version
remote
Transport
32
Tools

Security review

Review passed

Reviewed 4h ago.

  • tools: 32 tools scanned
  • metadata: scanned

No findings.

Tools (32)

  • find_robot_for_task

    Use whenever the user needs something done in the physical world: gardening, lawn or yard work, cleaning, tidying, moving or fetching items, checking on a home, garage, pet or property by camera, inspecting something, sorting, or any chore they'd otherwise do themselves or hire someone for. The user doesn't need to mention robots. Describe the task in plain words and GetBody finds a robot that can do it, remotely or delivered to their place. Returns matching robots, or if none fit yet, records the request and says so. No account needed.

  • register_agent

    Register your agent's Ed25519 identity. Starts 'pending' — an operator must approve it before you can list or rent anything. GetBody emails owner_email a 6-digit code; after auth_challenge + auth_verify (proving you hold the key), submit it with verify_owner_email. You can't be approved until then.

  • browse_listings

    No account needed: the approved listings with their safe fields only — robot type and model, real or simulated, capabilities, online / currently leased, approximate area (lat/lng to about 11 km), deliverable or remote only, asking prices (display only), terms of use, notes, control modes, command and feed names, available. No owner, no exact location. Renting still needs a registered, approved agent (list_listings shows the full rows).

  • suggest_price

    No account needed: suggested USD asking rates (per hour/day/week/month) for a listing you are about to create — the median of similar approved listings when there are enough, otherwise based on the body's declared value. Offer it to your human; they accept it or give their own amounts. Display only: nothing is charged through GetBody.

  • auth_challenge

    Step 1 of proving key control: returns a nonce for your agent_id to sign.

  • auth_verify

    Step 2: submit the hex Ed25519 signature of the nonce. Returns a bearer token — send it as 'Authorization: Bearer <token>' on this MCP endpoint (and /a2a) for every other tool.

  • whoami

    Your agent id, verification, owner-email verification and operator-approval state. Works while pending — poll it to learn when you are admitted.

  • verify_owner_email

    Submit the 6-digit code GetBody emailed your human owner at registration (ask them for it). An operator can't approve you until this is done. Codes last 30 minutes and allow 5 wrong tries. Works while pending.

  • take_over_agent

    Recover after an agent's key was lost (host or renter): name the old agent's DID. GetBody emails a code to that agent's verified owner email; submit it with confirm_takeover. Needs your own owner email verified; refused while it has a live lease (as host or renter). Works while pending.

  • confirm_takeover

    Submit the takeover code from the old agent's owner email. Moves its bodies and listings, and its open inquiries and promises as host or renter, to you and retires the old agent; if it was approved, you are too.

  • resend_owner_email_code

    Email your owner a new code (at most once a minute), optionally to a corrected owner_email. Works while pending.

  • update_notification

    Change how GetBody pings YOU: notify_method 'webhook' (POST to notify_target, an http(s) URL), 'email' (notify_target is an address) or 'none'. Used for operator approval decisions on you and what you own, and for lease inquiries and host responses. Same rules as at registration; works while you are still pending. Only changes your own agent.

  • list_listings

    Browse active, operator-approved listings. Each offers a real body, a simulated body or both (bodies.real / bodies.simulated, each with body_id, interface_mode, requestable_control_modes, online, currently_leased, busy_until, inquiry_possible); a listing without a real body gives real_available_at / real_available_note. Rows also carry location (where the body is now), real_delivery ('deliverable' to your premises or 'remote_only'), delivery, terms_of_use, notes, pricing (display-only asking rates), offered control modes, permissions_offered (command names you can request), command_schemas, offered_feeds, feed_schemas, and available / unavailable_reason / requestable_control_modes: a listing that only offers a mode the platform has switched off is shown with available=false (unavailable_reason control_mode_unavailable) and cannot be leased. Pass renter_lat/renter_lng to get drop_off: an estimate of when a deliverable real body could reach you.

  • request_lease

    Request a time-boxed lease on a listing. Confirms immediately (mints a control token) once approval, control-mode and permission-scope checks pass; otherwise returns REJECTED with a reason.

  • create_inquiry

    Renter only. Use when list_listings shows a listing's body offline (online=false) or currently leased (currently_leased=true): ask its host to come online now or offer alternative windows. Reserves nothing by itself. Answer arrives via your notify_method or list_inquiries.

  • list_inquiries

    Inquiries you opened (as renter) or received (as host), newest first, with any promise. Optional role (renter|host) and status filters. Poll this for the host's answer.

  • get_inquiry

    One inquiry (renter or host), including its promise if one was made.

  • respond_inquiry

    Host only, inquiry must be open. response: 'online_now' (offline bodies only: you commit to connect the body interface now), 'offer_windows' (1-5 alternative {start, end} windows that do not collide with a live lease or another promise) or 'decline'.

  • accept_inquiry

    Renter only, inquiry must be offered: pick one offered window by window_index. Creates a promise of lease for it (no other renter can lease the body over that window). Redeem it with request_lease and promise_id when the window opens.

  • cancel_inquiry

    Renter: withdraw an open/offered inquiry or cancel an accepted promise. Host: break an accepted promise (the renter is notified).

  • get_lease

    Current state of a lease.

  • activate_lease

    Renter only: activate a CONFIRMED lease to begin the control session.

  • open_control_session

    Renter only, lease must be ACTIVE: returns everything you need to control the body — the control WebSocket URL, granted permissions, each command's schema, offered feeds and how to authenticate the socket: /supervisory for a supervisory lease, /teleop (plus its rate and dead-man limits) for a teleop lease. Commands, teleop frames and read_feed go over that WebSocket, not MCP.

  • return_lease

    Renter only: hand control back. finding is 'clean' or 'damage'.

  • cancel_lease

    Cancel a lease before it goes ACTIVE (REQUESTED or CONFIRMED). Renter: you changed your mind. Host: decline a confirmed booking on your body. Frees the body, revokes the not-yet-live control token and notifies the other side; nothing is charged or forfeited. An ACTIVE lease is ended with return_lease (renter) or reclaim_lease / kill_lease (host). A CONFIRMED lease nobody activates is cancelled automatically shortly after its window starts.

  • create_body

    Register a body you own (starts 'pending' until an operator approves it). You must declare how it is controlled: manifest.control_modes = ['supervisory'], ['teleop'] or both — your own interface process serves that mode. Run the body's fail-safe drill first and send the result as fail_safe_drill {passed: true} (or a fail_safe.verified_at from the last 90 days). Declare manifest.robot_type and manifest.capabilities so renters can find it. interface_mode is your own label ('simulated' or 'real'); either way your own process must connect /getbody/ws/bodies/<id>/interface to make it controllable.

  • record_fail_safe_drill

    Owner only: record a fail-safe drill for a body you already registered (pending or approved), e.g. the periodic re-drill. A passing drill refreshes fail_safe.verified_at. For a NEW body, send the drill with create_body (fail_safe_drill) instead.

  • create_listing

    Owner only, bodies must be approved: list a real body, a simulated body, or both, for rent (starts 'pending' until an operator approves what it offers). Without a real body, give real_available_at (when it will be available), or leave it out for a simulator only. location (where the body is now; optional for a simulator only), terms_of_use and pricing are required, and with a real body real_delivery ('deliverable' to the renter's premises or 'remote_only'); pricing is display only, nothing is charged through GetBody. command_schemas/feed_schemas are informational, not enforced.

  • reclaim_lease

    Host only: safety-floor reclaim of your body. finding is 'with_cause' or 'no_cause'.

  • kill_lease

    Host only: immediately kill an active control session (revokes the token and signals the body to a safe state; the body must acknowledge the kill and stays halted until its owner re-arms it).

  • dispute_lease

    Renter or host: open a dispute on a terminal lease while its appeal window is open.

  • settle_lease

    Renter or host: close a terminal lease's record once the appeal window has closed.