Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

Follow AllMCPs on X (opens in a new tab)AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI β†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE β†— (opens in a new tab)
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • X (@AllMCPs) β†— (opens in a new tab)
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ’° Finance & Fintech
  3. X402 Preflight
X
Health: Not checked yetWe have not completed a health check for this listing yet.No health check has run yet.

X402 Preflight

User RatingsBe the first to rate and review this MCP server! Enrichment pendingWe haven’t run our AI enrichment pass on this listing yet, so the overview, use cases, and FAQ below may be sparse or missing. We work through the catalog over time β€” check back soon.
View Repository

Inspect and validate an x402 endpoint before an autonomous agent spends USDC.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

Add to CursorAdd to VS Code
Manual Client & Custom JSON ConfigExpand JSON β–Ύ

Client Config & Setup

Choose your client or environment
Target File:~/Library/Application Support/Claude/claude_desktop_config.json
claude_desktop_config.json
{
  "mcpServers": {
    "x402-preflight": {
      "command": "npx",
      "args": [
        "-y",
        "x402-preflight"
      ]
    }
  }
}

πŸ’‘ Paste the JSON block into your client's configuration file under mcpServers, then restart the application.

Install Directory Badge Claim listing AlternativesπŸ’° More in Finance & Fintech

Documentation Overview

x402 Preflight

Inspect and validate an unfamiliar x402 endpoint before an autonomous agent spends USDC.

x402 Preflight performs bounded, read-only HTTPS probes. It observes the live payment challenge, price, network, asset, receiver, Bazaar discovery metadata, CORS, redirects, cache behavior, and other operational signals. It never connects a buyer wallet, forwards payment credentials, signs a payload, or spends funds.

A report is time-bound evidence, not an endorsement. It cannot prove seller identity or intent, contract safety, future availability, successful settlement, or delivery of a business outcome.

Canonical Capabilities

CapabilityInterfaceAccessUse
inspect_x402_endpointPOST /api/preflight/inspectFreeInspect an unfamiliar live challenge before payment.
audit_x402_endpointPOST /api/x402/preflight/auditx402, $0.05 defaultDeep-check schemas, discovery, CORS, redirects, cache, and policy.
order_x402_remediationPOST /api/x402/preflight/remediationx402, configurableEscalate a blocked or risky audit into a durable remediation intake.

For HTTP clients that cannot submit a JSON body during discovery, the paid audit also has a compatibility alias at GET /api/x402/preflight/audit. It requires resource_url in the query string and accepts optional method=GET|HEAD, expected_network, and max_price_usd parameters. The alias uses the same price, x402 payment, and audit report as the canonical POST, but is not a fourth capability and never audits a POST target.

Canonical remediation requires a healthy ORDER_DATABASE_URL. If durable storage is unavailable, HTTP and MCP calls fail with REMEDIATION_UNAVAILABLE before a payment challenge is served.

These are the only primary operations in OpenAPI, MCP, llms.txt, the manifest, and agent metadata. Existing wallet, market, weather, repository, marketplace, and helper routes remain available under the manifest's labs section.

Bitcoin Lightning / L402 Seller

The service also contains a gateway-only repository opportunity scanner for coding agents:

text
GET or POST https://l402.chikocorp.com/api/l402/repo-opportunity-scan

Lightning Labs Aperture presents the public L402 challenge and then forwards a private gateway credential to this backend. Direct backend requests fail closed when the credential is absent, so the public Node/Vercel route cannot bypass the Lightning paywall. The deterministic report ranks public GitHub issues, detects open-PR competition and hardware risk, and treats payout words as unverified until an authorized payer and amount are explicit.

Free machine-readable discovery lives at:

text
https://l402.chikocorp.com/.well-known/l402.json

Production setup, invoice-only LND permissions, and no-payment verification are documented in deploy/l402/README.md. Wallet seeds, passwords, admin macaroons, and backend tokens must remain outside Git.

Local Development

Requires Node.js 20 or newer.

Terminal
npm install
npm start

The API listens on http://localhost:4021 by default. The service does not auto-load .env; export variables through your process manager or shell.

Useful checks:

Terminal
npm run check
npm test
npm run validate:bazaar
npm run verify:discovery
npm run metrics:summary

HTTP and OpenAPI

Free inspection:

Terminal
curl -sS http://localhost:4021/api/preflight/inspect \
  -H 'content-type: application/json' \
  --data '{
    "resource_url": "https://example.com/api/resource",
    "method": "GET",
    "expected_network": "eip155:8453",
    "max_price_usd": 1
  }'

The same input sent to the paid audit returns HTTP 402 until a client supplies a valid x402 payment:

Terminal
curl -i http://localhost:4021/api/x402/preflight/audit \
  -H 'content-type: application/json' \
  --data '{
    "resource_url": "https://example.com/api/resource",
    "method": "GET",
    "expected_network": "eip155:8453",
    "max_price_usd": 1
  }'

An entirely empty unauthenticated POST to the paid audit also returns its 402 challenge for method probes. A request that includes a payment attempt still requires the complete input before payment processing.

The compatibility GET alias requires its target before payment and returns 400 without a challenge when resource_url is missing or query parameters are unknown, repeated, empty, non-scalar, unsafe, or invalid:

Terminal
curl -i 'http://localhost:4021/api/x402/preflight/audit?resource_url=https%3A%2F%2Fexample.com%2Fapi%2Fresource&method=GET&expected_network=eip155%3A8453&max_price_usd=1'

The runtime 402 response is authoritative for amount, network, asset, payTo, and Bazaar extensions. The static contract is available at /openapi.json. Errors use one strict envelope with a machine code, retryability, optional delay, and request ID.

Remote MCP

The stateless Streamable HTTP endpoint is:

text
https://x402.chikocorp.com/mcp

The previous Vercel origin remains an allowlisted compatibility alias, so clients that still call https://x402-wallet-readiness-service.vercel.app/mcp continue to receive challenges that name that Vercel resource.

Discover tools without payment:

Terminal
curl -sS http://localhost:4021/mcp \
  -H 'content-type: application/json' \
  -H 'accept: application/json, text/event-stream' \
  --data '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}'

tools/list returns exactly the three canonical tools and strict input/output schemas. A paid tools/call receives an x402 challenge before tool execution. The buyer's MCP client remains responsible for explicit payment authorization; the server never signs or spends automatically.

This service does not implement A2A. /.well-known/agent-card.json returns a clear A2A_NOT_IMPLEMENTED response and points clients to MCP, OpenAPI, and x402 metadata.

Registry-ready remote-server metadata lives in server.json. It is intentionally not published automatically.

Discovery and Bazaar

Primary discovery surfaces:

text
GET /manifest
GET /openapi.json
GET /llms.txt
GET /.well-known/agent.json
GET /.well-known/x402.json
POST /mcp  (initialize, tools/list, tools/call)

The x402 resource server registers the Bazaar extension and publishes strict HTTP and MCP declarations for audit and remediation, including schemas and examples. The POST audit declaration uses a JSON body; the compatibility GET declaration publishes compact Bazaar queryParams and summary-output contracts so the payment challenge remains safely below common header limits. OpenAPI documents the alias's full response schema, which is identical to the canonical audit.

Use CDP Facilitator in production:

sh
X402_USE_CDP_FACILITATOR=true
CDP_API_KEY_ID=<configured outside git>
CDP_API_KEY_SECRET=<configured outside git>

To keep a non-CDP facilitator, leave X402_USE_CDP_FACILITATOR=false and set X402_FACILITATOR_URL. npm run validate:bazaar validates local Bazaar declarations. When PUBLIC_URL is exported, it also inspects the public unpaid challenge and queries CDP's read-only merchant catalog for the configured receiver. Bazaar catalog indexing still requires a successful settlement through CDP; validation alone does not publish a listing.

URL Safety

Inspection accepts public HTTPS URLs only. It rejects credentials and sensitive query parameters, localhost, private/link-local/reserved addresses, metadata hosts, nonstandard ports, and unsafe redirects before a paid challenge is created. DNS is checked on the target and every redirect. Requests have bounded timeouts, response bytes, and redirect counts; JavaScript and target code are never executed.

Do not submit private keys, seed phrases, access tokens, authorization headers, cookies, payment signatures, or confidential repository URLs.

Runtime and Metrics

GET /health reports the public service version, commit, deployment time, network, facilitator mode, database availability, worker heartbeat, and settlement reconciler status. It does not expose wallets, orders, transaction hashes, URLs, secrets, or filesystem paths. Every response includes:

text
X-Service-Version
X-Commit-SHA
X-Request-ID

Telemetry is allowlisted, structured JSON and fail-open. Buyer addresses are recorded only as SHA-256 hashes when TELEMETRY_BUYER_PEPPER is configured. Apply 002_preflight_telemetry.sql to an existing PostgreSQL installation, then use npm run metrics:summary for 7-day and 30-day aggregates.

Deployment stamping, public smoke checks, database migration, CDP activation, and MCP Registry preparation are documented in docs/OPERATIONS.md.

Labs and Compatibility

Legacy routes have not been deleted and their existing prices remain unchanged. Representative surfaces include:

  • /api/preview, /api/readiness, and /api/agent-commerce-receipt
  • /api/market/*, /api/x402/market/*, and /api/weather/current
  • /api/dev/repo-snapshot and /api/x402/dev/repo-snapshot
  • /api/x402/services/quick-review and /api/x402/services/integration-triage
  • marketplace webhooks, /wallet-sign, and /open-frame

No sunset date is announced. The historical custom metadata documents remain at /labs/legacy-agent.json and /labs/legacy-agent-card.json with a Deprecation: true response header.

Read the full README β†’View source on GitHub β†’

Related MCP Servers

View all in Finance & Fintech View all alternatives
  • Stripe AI logoStripe AI

    MCP server integrating with Stripe - tools for customers, products, payments, and more.

    πŸ’° Finance & Fintech0 views
    Compare vs Stripe AI β†’
  • WingmanProtocol Agent Gateway logoWingmanProtocol Agent Gateway

    Async errands, artifact hosting, watches, memory + 15 calculators for AI agents. x402 on Base.

    πŸ’° Finance & Fintech1 views
    Compare vs WingmanProtocol Agent Gateway β†’
  • Provenance MCP logoProvenance MCP

    Wash-traffic risk checks for Algorand x402 endpoints before your agent trusts or pays them.

    πŸ’° Finance & Fintech1 views
    Compare vs Provenance MCP β†’
  • Hera Agent Unity logoHera Agent Unity

    Control and verify a live Unity Editor through a local, low-token MCP server.

    πŸ’° Finance & Fintech0 views
    Compare vs Hera Agent Unity β†’

Reviews

No reviews yet β€” be the first to share how this listing worked for you.

Frequently Asked Questions about X402 Preflight

Add the following block to your claude_desktop_config.json under mcpServers: "mcpServers": { "x402-preflight": { "command": "npx", "args": ["-y", "x402 Preflight"] } }

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewX402 Preflight AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/x402-preflight?style=directory)](https://allmcps.com/mcp/x402-preflight)
HTML Embed
<a href="https://allmcps.com/mcp/x402-preflight"><img src="https://allmcps.com/api/badge/x402-preflight?style=directory" alt="X402 Preflight on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ’°Finance & Fintech
More technical detailsExpand β–Ύ
TransportSTDIO
RuntimeNode.js
Last updatedSep 7, 2026
Views0
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
27Quality signal: Emerging Β· 27/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership8/20
Documentation & tools11/30
Adoption & activity1/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

β˜… FeaturedAllMCPs Server logo

AllMCPs Server

The official MCP server for AllMCPs.com - submit and manage tools directly from your AI. The open directory for MCP servers. Connect Claude, Cursor, Windsurf, and AI agents to databases, tools, files, and APIs. Explore 10,000+ servers. AllMCPs is the premier, open directory for discovering, evaluating, and installing Model Context Protocol (MCP) servers to equip AI agents and LLMs with real-world superpowers.

Explore Server β†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge and attach your website β€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it β€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ’° Finance & Fintech β†’Best MCP servers for Finance & Fintech β†’Alternatives to X402 Preflight β†’Install in Claude DesktopInstall in CursorInstall in VS Code