Check if a counterparty is safe to pay: trust/risk score for AI agents. Scam/phishing screen.
io.github.notifuturo/vouch MCP Server
This MCP server provides a per-call payment trust/risk score to help check whether a counterparty is safe to pay. It is positioned as a scam/phishing screening layer for AI agents, intended for payment-related decisions.
π οΈ Key Features
Trust/risk score for counterparty safety
Scam/phishing screen for payments
Per-call payment trust
π Use Cases
AI agents evaluating payment recipients before sending funds
Payment safety checks to reduce scam/phishing exposure
Agentic commerce workflows using risk scoring
β‘ Developer Benefits
Tooling count: 2 tools
Fits TypeScript-based stacks (topics include TypeScript)
Deploys on Cloudflare Workers; uses Hono (topics include hono, cloudflare-workers)
β οΈ Limitations
Describes only payment trust/risk scoring and scam/phishing screening; no additional capabilities are specified beyond that.
Check whether a counterparty is SAFE TO PAY before sending money. Given a URL or host, returns a 0-100 trust score and risk band (low/medium/high/critical), detecting scams, phishing, and known-malicious endpoints via threat feeds, domain risk heuristics, and a community reputation graph. Call this before paying any merchant, API, agent, or x402 resource. Free β for the full explainable reasons AND a signed, verifiable attestation (proof of the check for audit/disputes), call the paid POST /v1/check endpoint via x402.
Report a host as a scam/bad actor ('flag') or as trustworthy ('vouch'), improving Vouch's community reputation graph for everyone's future payment-trust checks. Free.
A per-call payment trust & reputation API for AI agents β monetized over x402.
When an autonomous agent is about to pay a merchant, API, or counterparty, it
asks Vouch one question first: is this safe to pay? Vouch returns an
explainable trust score, and charges a fraction of a cent per call in USDC β no
accounts, no API keys, no Stripe. Billing is the x402 protocol itself.
Why
The agentic-commerce rails (Coinbase x402, AWS, Visa, Mastercard, Agnic) are
being built by giants. The governance layer β should this agent trust this
counterparty with money? β is the named #1 blocker to autonomous spend and is
wide open. Vouch is a thin, self-serve pick-and-shovel on top of those rails.
Every call makes the product better: checks and community reports accrete into a
reputation dataset that compounds with usage β the moat a bootstrapped team can
actually build.
Scoring is a weighted average of independent signals, with a safety
override: any single hard-negative signal (e.g. a threat-feed hit) caps the
overall score so one strong red flag can't be averaged away.
Signal
Weight
Source
threat_feed
3
URLhaus host list (THREAT_FEED_URL), cached, fails open
reputation
2
Vouch's own accumulating D1 data (the moat)
transport
1.5
HTTPS / valid host
domain_heuristics
1
Punycode, raw IPs, abuse-prone TLDs, etc.
Use it from your agent
Vouch is a real MCP server, an x402-paid HTTP API, and a tiny SDK β pick whichever
fits your stack. Nothing needs an account or API key.
MCP (free tools, works in any MCP client)
Point your client at the Streamable-HTTP endpoint β it exposes vouch_score and
vouch_report, and ships model-facing instructions so the agent knows to check a
counterparty before it pays:
For clients that only speak stdio, bridge it with npx mcp-remote https://vouch.futuronoti.workers.dev/mcp.
Vouch is also listed in the official MCP registry
as io.github.notifuturo/vouch.
The paid POST /v1/check adds the explainable reasons, weighted signals, and a
signed Ed25519 attestation (keep it as proof of due diligence). See
examples/buyer.ts for the full x402 pay-and-retry loop and
sdk/ for the client.
MCP Streamable-HTTP server (vouch_score, vouch_report tools)
GET /health
free
Liveness
GET /
free
Service info (HTML landing for browsers)
CORS is open (*) and the x402 payment headers are exposed, so browser-hosted
agents can preflight and complete the pay/retry flow.
Reading /v1/report (abuse model)
POST /v1/report is free and unauthenticated by design β anyone can submit a
flag or vouch for a host, so the raw flags/vouches counts are community
signals, not ground truth. Abuse is contained by:
Rate limiting β 10 reports per 60s per client IP (Cloudflare Rate Limiting, fails closed).
Reporter-standing weighting β each counted report contributes a weighted amount
(not a flat +1) based on the reporting source's tenure: a brand-new or anonymous source
counts at 0.3, ramping to 1.0 only after ~7 days of sustained reporting. The scoring
signal uses these weighted totals, so spinning up fresh sybil identities buys far less
influence. A source can also move a given host's counter at most once per 24h (per-source
de-dup); raw counts are still logged for audit.
Poisoning resistance in scoring β community reputation is a non-authoritative
signal: it can lower a score but cannot, on its own, force a critical verdict.
Only objective signals (threat feeds, transport) can hard-cap the score. So a burst
of anonymous flags can't unilaterally brand a legitimate counterparty as unsafe.
Bounded input β target/reason/reporter are length-capped before storage.
Treat /v1/stats and report counts as a crowd-sourced prior that informs the paid
verdict, not as an authoritative blocklist.
Stack ($0 to run)
TypeScript Β· Hono Β· Cloudflare Workers (free tier) Β·
D1 (free SQLite) Β· @x402/* v2 Β· public facilitator at x402.org/facilitator.
Live on Base mainnet (X402_NETWORK=base, real USDC, $0.01/call). For local
development, set X402_NETWORK=base-sepolia and fund a throwaway wallet from the
free Circle faucet. The live network and price are
authoritatively advertised at /.well-known/x402.
Develop
bash
npm install
npm run typecheck
npm testcp .dev.vars.example .dev.vars # set PAY_TO_ADDRESS (your testnet wallet)
wrangler d1 create vouch # paste database_id into wrangler.toml
npm run db:init # apply schema locally
npm run dev # local Worker