STIX 2.1 threat indicator feed: IPs, domains, URLs, file hashes from ThreatFox, OTX, NVD.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
Cryptographically-gated threat telemetry and IOC feeds for enterprise and autonomous nodes.
License keys: new sales are temporarily paused while data licensing is finalised. The free tier and x402 remain available.
/api/ioc β simple REST GET, returns the STIX 2.1 indicator feed directly. Best for scripts, curl, and simple integrations./api/mcp β full Model Context Protocol server, 13 tools (CVE lookups, batch operations, threat actor dossiers, wallet sanctions screening, domain age, hostname/phishing reputation, and more). Best for Claude, MCP-compatible agents, and any client speaking the MCP standard.Opt-in: /api/ioc/context?value=<indicator> β a REST mirror of the get_ioc_context MCP tool, disabled by default. The operator must set ENABLE_REST_IOC_CONTEXT=true for this route to respond; otherwise it returns 404 {"error":"not available"}. Not listed in x402 Bazaar/discovery metadata.
Both accept the same Gumroad license key via the x-api-key header, or per-call x402 micropayments ($0.01/call) via the PAYMENT-SIGNATURE header (x402 v2).
The free tier is opt-in β add x-free-tier: 1 to your request header. Without it, a request with no license key and no payment header returns 402 Payment Required by default.
Optional query parameters: ?since=<ISO timestamp>, ?type=<IPv4|domain|URL|FileHash-MD5|FileHash-SHA1|FileHash-SHA256>, ?min_score=<0-100>, ?limit=<1-1000>
Note on confidence scores: indicator confidence currently defaults to a fixed value of 50 whenever the source record has no confidence_score β it is not yet a computed/weighted score for those records.
Exception: get_ioc_context and get_ioc_batch (the pre-action safety-check tools) are always free when the result is found: false β no x-free-tier header needed for those specific "nothing on record" responses. The header is only required for the general free tier.
/api/mcp follows the x402 v2 MCP transport spec for paid tools/call requests, so a payment can be attached either as an MCP-native field or as an HTTP header β whichever your client library supports:
params._meta["x402/payment"] (recommended for MCP clients, e.g. @x402/mcp) β attach the signed x402 v2 PaymentPayload object directly to the JSON-RPC request:
PAYMENT-SIGNATURE header (or X-Payment) β the same signed payload, base64-encoded, attached at the HTTP transport level instead of inside the JSON-RPC request. This is how non-MCP-aware HTTP clients pay.
If both are present on the same request, _meta wins.
Unpaid calls don't get an HTTP 402. A tools/call for a paid tool with no license key, no free tier, and no payment returns a normal 200 OK JSON-RPC result shaped as an MCP tool error:
The same object is also sent, base64-encoded, in the PAYMENT-REQUIRED response header for backward compatibility with clients that only read headers. A verification or settlement failure returns this exact same shape (still 200 OK, isError: true), with structuredContent.error describing what went wrong.
On a successful payment, the tool result carries the facilitator's settlement receipt in result._meta["x402/payment-response"], and the PAYMENT-RESPONSE header is set as before.
To connect your autonomous agent to the PG1 API, pass your Gumroad license key in the connection request.
Run this command in your terminal, replacing the placeholder with your active key:
Call "method": "tools/list" against /api/mcp for full schemas. Summary:
| Tool | Purpose | Source(s) | Free tier applies? |
|---|---|---|---|
get_threat_indicators | Bulk STIX 2.1 indicator feed | ThreatFox, URLhaus, OTX, NVD | Yes (needs x-free-tier: 1) |
get_ioc_context | Single-indicator safety check | ThreatFox, URLhaus, OTX | Always free if not found |
get_ioc_batch | Up to 20 indicators per call | ThreatFox, URLhaus, OTX | Always free if none found |
get_cve_details | CVE lookup enriched with NVD, EPSS, CISA KEV | NVD, FIRST.org EPSS, CISA KEV | Yes (needs x-free-tier: 1) |
get_cve_batch | Up to 20 CVE IDs per call | NVD, FIRST.org EPSS, CISA KEV | Yes (needs x-free-tier: 1) |
get_cve_by_product | Discover CVEs by vendor/product | NVD | Yes (needs x-free-tier: 1) |
get_threat_actor_profile | APT/threat actor dossiers with MITRE ATT&CK | MITRE ATT&CK Enterprise | Yes (needs x-free-tier: 1) |
get_usage_status | Check your remaining free-tier quota | β | Always free, no header needed |
subscribe_alerts | Register a webhook for new matching indicators | β | No β license key required |
submit_indicator | Contribute an observed indicator for review | β | No β license key required |
check_wallet_sanctions | Screen a wallet address against sanctions | OFAC SDN List (US Treasury), synced daily | Always free |
check_domain_age | Domain registration age via RDAP | RDAP (per-TLD server, resolved via the IANA bootstrap registry) | Always free |
check_hostname_reputation | Screen a hostname for phishing/lookalike domains | MetaMask eth-phishing-detect, synced daily | Always free |
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/pg1-sovereign-threat-intelligence)<a href="https://allmcps.com/mcp/pg1-sovereign-threat-intelligence"><img src="https://allmcps.com/api/badge/pg1-sovereign-threat-intelligence?style=directory" alt="PG1 Sovereign Threat Intelligence on AllMCPs" /></a>