The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the LimitGuard Trust Intelligence listing page.
Trust Intelligence for AI agents. Entity verification, sanctions screening, and risk scoring via the Model Context Protocol.
Server URL: https://api.limitguard.ai/mcp
Transport: Streamable HTTP (POST)
Auth: API key (Bearer), plus an x402 micropayment per call on the free and sandbox tiers
What it is: Limitguard is a KYB, sanctions/PEP and entity-trust API for AI agents and developers: it checks a company against business registers (KVK, KBO/CBE), VIES VAT, OpenSanctions, its domain and country risk, is paid per call with x402 (USDC) or an API key, is also served as an MCP server, and is hosted in the EU.
Start here: Free sandbox key, no wallet. $0.65-0.85 fresh for entity and risk checks ($1.50 KYB); $0.10 cached ($0.25 KYB) when available.
tools/list is public — connect and read it without any credential. These are
the names it returns, and the names tools/call accepts:
| Tool | Description | Inputs |
|---|---|---|
check_entity | Full trust intelligence check on a business entity. Returns trust score (0-100), risk level, and recommendation. | entity_name (required), country (required), kvk_number, domain |
verify_wallet | Screen a wallet: OFAC SDN address match, on-chain signals (contract check, native and USDC balance, transaction count, first seen on Base) and named risk rules with up to 3 advice items. On Base, also reports any ERC-8004 agent the wallet owns and its open on-chain reputation as descriptive signals, never scored. Free ($0). Supports EVM and Solana addresses. | wallet_address (required), chain_id |
get_risk_score | Quick risk assessment without full trust check. Focuses on risk signals only. | entity_name (required), country (required) |
get_compliance_report | Per-entity report built from one real check: registry identity, sanctions and PEP screens, domain signals, risk score with the rules that fired, correlations, at most 3 findings, a per-source status table (ok / unavailable / error) and a report hash. | entity_name, country, kvk_number, cbe_number, vat_number, domain, iban, wallet_address, wallet_chain, check_id |
All tools are priced via x402 micropayments (USDC on Base or Solana):
| Endpoint | Price |
|---|---|
Entity Check (/v1/mcp/check-entity) | $0.85 |
Risk Score (/v1/mcp/risk-score) | $0.65 |
Check Agent (/v1/mcp/check-agent) | $0.00 — unimplemented / beta, placeholder data |
Trust Score (/v1/mcp/trust-score) | $0.00 — unimplemented / beta, placeholder data |
Verify Wallet (/v1/mcp/verify-wallet) | $0.00 — unimplemented / beta, placeholder data |
Two things gate a tools/call, in this order:
An API key, as Authorization: Bearer <key>. Without one every call comes
back Authentication required. Provide API key via Authorization: Bearer <lg_live_...> header. Get a free one — no payment, no card:
That returns a free-tier key, which is the key the Quick Start configs below
expect. Asking for "tier": "sandbox" instead returns a key that answers with
mock data — see the next point before you use one here.
Payment, on the free and sandbox tiers only. Send the x402 proof as
PAYMENT-SIGNATURE (x402 v2) or X-PAYMENT (v1), alongside the Bearer key.
A paid subscription (indie and up) covers usage and needs no per-call payment.
A sandbox key does not lift the payment requirement on this transport: it
owes x402 per call exactly as a free key does, and it answers with mock
data rather than a real check. Paying for one over MCP spends real USDC on a
mock answer. Where a sandbox key is worth having is the REST mirrors under
/v1/mcp/* (sent as X-API-Key, not Bearer), which serve the mock response
before the payment check — a way to exercise the request and response shapes,
not a cheap source of real checks.
The 5 tools above are what the MCP server exposes over the Model Context Protocol. Clients that
integrate directly over HTTP — instead of through an MCP client — can reach 18 x402-priced
endpoints on https://api.limitguard.ai: the 13 REST endpoints below, plus the MCP tools' own
/v1/mcp/* paths. All 18 are published in
/.well-known/x402.json; only the 5 tools above
are listed by /.well-known/mcp.json.
Most of the REST endpoints are capabilities the MCP tools do not expose, but two are the same
check reached over plain HTTP: /v1/entity/check behind check_entity — the manifest describes
/v1/mcp/check-entity as "same as /v1/entity/check with MCP-native interface" — and
/v1/risk/score behind get_risk_score, at the same $0.65.
Payment works the same way throughout: USDC on Base or Solana, pay-per-call. The 11 data endpoints
below need no API key at all. The 4 /v1/keys/upgrade/* endpoints also take payment without one,
but they act on an API key you already hold — see API key tiers.
| Endpoint | Method | Price | Description |
|---|---|---|---|
/v1/entity/check | POST | $0.85 | Full entity trust check across multiple verification layers: KVK/CBE registry, OpenSanctions, country risk (CPI/FATF), domain WHOIS, IBAN validation and EU VAT/VIES. Returns trust score 0-100 with cluster and recommendation. |
/v1/risk/score | POST | $0.65 | Quick risk score (0-100) for entity name + country. Lightweight check without full data source scan. |
/v1/entity/deep-check | POST | $0.75 | Extended screening in up to three tiers. fresh ($0.75): politically exposed person and relative/close-associate (role.pep / role.rca) matches from OpenSanctions, with the match detail the standard entity check does not return, plus a Dutch Centraal Insolventieregister screen (NL only). enhanced ($1.50): the same plus adverse media screening against a global news index. If a source of the requested tier cannot be reached the call returns 503 and is not charged. |
/v1/reports/entity | POST | $1.50 | Per-entity report built from one real check's signals: identity, sanctions and PEP screening, domain signals, risk score, correlations with the caller's earlier reports, sources and an evidence hash. A source that did not answer is shown unavailable, never clean. |
| Endpoint | Method | Price | Description |
|---|---|---|---|
/v1/reputation/score | POST | $0.65 | Reputation scoring with Bayesian trust decay analysis. Tracks entity trust over time with confidence intervals. |
/v1/reputation/history/{id} | GET | $0.10 | Historical reputation trend data. Returns trust score timeline with change events and decay curves. |
| Endpoint | Method | Price | Description |
|---|---|---|---|
/v1/wallet/balance | GET | $0.10 | ERC-8004 agent wallet balance check. Returns the on-chain USDC balance (Base mainnet) for a registered ERC-8004 agent wallet. |
| Endpoint | Method | Price | Description |
|---|---|---|---|
/v1/kyb/check | POST | $1.50 | Know Your Business verification: company registration, sanctions screening, VAT/VIES, and domain analysis in one call. |
/v1/compliance/alerts | GET | $0.10 | Daily changes to the OFAC, EU and UN sanctions lists, plus alerts when an entity or wallet this key checked is listed. Poll this route; alerts are not pushed. Filter by jurisdiction and severity. |
/v1/compliance/readiness/{id} | GET | $0.10 | EU AI Act readiness self-assessment for one AI system. Send the system_type and the checklist items you have completed (completed_items); returns the EU AI Act risk level for that system type, a readiness score and the open gaps. entity_id is your label: nothing is looked up about it. |
The 5 MCP tools are also reachable over plain HTTP at their own x402-priced paths — same capabilities and prices as the Tools table above, for clients that pay per call without opening an MCP session.
| Endpoint | Method | Price | MCP tool |
|---|---|---|---|
/v1/mcp/check-entity | POST | $0.85 | check_entity |
/v1/mcp/check-agent | POST | $0.00 | check_agent |
/v1/mcp/trust-score | POST | $0.00 | get_trust_score |
/v1/mcp/verify-wallet | POST | $0.00 | verify_wallet |
/v1/mcp/risk-score | POST | $0.65 | get_risk_score |
Limitguard accepts two forms of payment: x402 per call, or a paid-tier API key whose
subscription prepays the calls. Paying per call needs no API key on 13 of the 18 endpoints — the
9 data endpoints above and the 4 /v1/keys/upgrade/* paths. The other 5 always want a key: the
MCP transport takes Authorization: Bearer on every tools/call, and its /v1/mcp/* mirrors
take X-API-Key.
A base key is free and self-service: POST /v1/keys/create with an email address, no payment and
no existing key needed. It identifies you and tracks your usage; it does not pay for calls. A
free-tier key still owes x402 on every paid endpoint, on REST exactly as on MCP. The
monthly_limit it reports is a ceiling on how many calls it may make, not an allowance of free
ones. A sandbox key is also free and returns mock data, never a real check — over MCP it owes
x402 like any other free key, so it earns its keep only against the REST mirrors.
The endpoints below take an x402 payment to move a key onto a paid tier, which is what lifts the
per-call charge. On a paid tier monthly_limit is the number of calls the subscription covers.
The manifest prices the upgrade call itself and says nothing about what happens at the end of a
month, so confirm the renewal terms before budgeting against the figures below.
| Endpoint | Method | Price | Tier | monthly_limit |
|---|---|---|---|---|
/v1/keys/upgrade/indie | POST | $29 | Indie | 1,000 calls/mo |
/v1/keys/upgrade/starter | POST | $99 | Starter | 10,000 calls/mo |
/v1/keys/upgrade/growth | POST | $299 | Growth | 50,000 calls/mo |
/v1/keys/upgrade/pro | POST | $999 | Pro | 250,000 calls/mo |
Prices and descriptions above mirror the live x402 manifest as of 2026-09-05. The manifest is the source of truth — fetch it if you need the current schema for any endpoint.
Add to your claude_desktop_config.json:
Add to MCP settings:
Connect to https://api.limitguard.ai/mcp using Streamable HTTP transport (POST),
sending Authorization: Bearer <key> on every tools/call.
| Endpoint | URL |
|---|---|
| MCP server card | /.well-known/mcp/server-card.json |
| MCP Tools | /.well-known/mcp.json |
| x402 Pricing | /.well-known/x402.json |
| Health | /health |
The service publishes two tool cards, and they do not agree. Both list the same five
tools, taking the same required arguments, so a tools/call written against either one
works — but the descriptions and the argument wording differ between them. The Tools
table above and this repository's server.json are generated from the server card,
which is the one to read when the two disagree. Reconciling them is the service's to fix.
MIT