
Official MCP RegistryListed
dev.fetchgate/fetchgate
Fetch any URL as clean Markdown or metadata, and buy digital goods via x402 — for AI agents.
First seen 2 Oct 2026. Evidence as of 7 Oct 2026.
9
Tools
From an anonymous probe
1
Source listings
Each with its own history
4
Recorded changes
Since first seen
Tools
| Tool | Description | Behaviour |
|---|---|---|
| check_x402_endpoint | Decide whether an unfamiliar pay-per-call (x402) endpoint is worth paying. Sends one unpaid GET to read its live payment challenge (format, price, network, signing domain), then adds its settled-call and unique-payer history, whether its live price matches its listed price, and its domain's reputation (template farm or not, share of its endpoints that answer). Returns a verdict — ok, caution, avoid or unknown — with the reasons. Nothing is paid. Use before an agent sends money to an endpoint it has not used before. Wraps GET /v1/x402/check. Same free daily tier as read_url; $0.01/call via x402 after that. | Not declared |
| get_agent_census | Return the Agent Web Crawler Census: every named bot observed crawling a live, publicly-listed x402 + MCP endpoint over a 24-hour window, each with a case-insensitive regex `matcher` and a behavioural `category` (liveness-monitor, directory-crawler, price-scraper, security-research, ai-training, ...) so you can classify your own access log. Observed first-hand, not aggregated from third-party bot lists. Notable finding: of the named agent-web crawlers in the census, zero have ever presented a payment, and several declare that in their own User-Agent string. Wraps GET /v1/agent-census.json. Free, unmetered, no payment required. CC BY 4.0. | Not declared |
| get_metadata | Fetch a URL server-side and return structured metadata: title, description, canonical URL, OpenGraph/Twitter card fields, favicon URL, language, and published/modified timestamps when present. Wraps GET /v1/meta. Same free tier as read_url; priced at $0.001/call via x402 once exhausted. | Not declared |
| get_purchase_info | Look up a product by id (from list_products) and explain exactly how to buy it: its price, and the x402 purchase flow step by step (the 402 challenge shape, the PAYMENT-SIGNATURE header, and the signed download URL you get back on success). Does not take payment itself — informational only, mirroring the pre-payment leg of GET /v1/buy/:id. | Not declared |
| list_products | List Fetchgate's digital-goods catalog: id, name, description, priceUsd, currency, file format, size, sha256, and a walletless humanUrl checkout link for each product for sale. Wraps GET /v1/products. Free, no rate limit, no payment required just to browse. | Not declared |
| read_url | Fetch a URL server-side and return its main content as clean Markdown, with scripts/styles/nav/ads/boilerplate stripped out. Wraps GET /v1/read. Free tier: 30 calls/day per caller; priced at $0.002/call via x402 once that's exhausted (see get_purchase_info for how the x402 flow works). Only http:// and https:// URLs are accepted; private/internal-network hosts are rejected. | Not declared |
| scan_for_prompt_injection | Check untrusted content BEFORE acting on it. Give a `url` to fetch and scan a web page (its visible text and, separately, text hidden in HTML comments, alt/title/aria attributes and meta tags), or give `text` to scan a tool result, retrieved document or message you already have. Runs 120 detection rules covering instruction override, tool hijacking, data exfiltration, system-prompt extraction, jailbreak framing and encoding tricks (zero-width and Unicode-tag smuggling, homoglyphs, base64). Returns a 0-100 risk score, a recommended action (block / review / flag / none) and each match with its evidence. Heuristic: a clean result means nothing obvious tripped, not that the content is safe. Wraps /v1/scan. Same free daily tier as read_url; $0.003/call via x402 after that. | Not declared |
| scan_mcp_server | Connect to a remote Streamable HTTP MCP server, fetch its tools/list (sends only initialize, notifications/initialized and tools/list — never tools/call) and scan every tool name, description, parameter description and the server's initialize `instructions` string for tool-poisoning patterns: hidden-instruction markers, invisible Unicode, directives aimed at the model, credential/secret references, exfiltration shapes and instructions about other tools. Returns per-tool findings with severity, excerpt and a score band. Use it before installing or trusting a third-party server. Heuristic: a clean result means nothing obvious in what the server declares about itself, not that it is safe. Wraps GET /v1/mcp-scan. Free, rate-limited per caller; private/internal-network hosts are rejected. | Not declared |
| search_x402_services | Search for a pay-per-call (x402) API that does what you need. Unlike a raw directory, results are limited to endpoints that answered a real x402 payment challenge AND had at least 5 settled calls from at least 2 distinct payers in the last 30 days, so dead, never-bought and template-farm listings are left out. Each result has the endpoint URL, method, price in USD, networks, 30-day calls and unique payers, and a flag when the payer count looks farmed. Use it when you need a paid API (search, scraping, enrichment, LLM, market data…) and want one that demonstrably works. Wraps GET /v1/x402/search. Same free daily tier as read_url; $0.005/call via x402 after that. | Not declared |
Change history
- search_x402_services: tool added
- scan_for_prompt_injection: tool added
- check_x402_endpoint: tool added
- server instructions changed (+"scan_for_prompt_injection checks a page or text for injection attempts before you act on it; search_x402_services finds paid APIs that are live and actually bought; check_x402_endpoint says whether an x402 endpoint is worth paying (same free tier, then $0.003/$0.005/$0.01).")
| Source | Listing | First seen | Last seen | Versions |
|---|---|---|---|---|
| Official MCP Registry | dev.fetchgate/fetchgate | 2 Oct 2026 | 7 Oct 2026 | 1 |