Official MCP RegistryListed
PHION Agent Trust Infrastructure
122 agent services: inference, search, enrich, intelligence, trust and x402 signed delivery.
First seen 2 Oct 2026. Evidence as of 2 Oct 2026.
134
Tools
From an anonymous probe
1
Source listings
Each with its own history
0
Recorded changes
Since first seen
Tools
| Tool | Description | Behaviour |
|---|---|---|
| a2a_transaction_bridge | Bind an A2A task to a transaction without silently transferring authority.; 0.004 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| abandoned_tool_detector | Require stale success plus multiple independent failed probes before classifying likely abandonment; 0.003 USDC. | Read-only |
| agent_approval_relay | Agent Approval Relay; deterministic signed assessment over supplied input. | Read-only |
| agent_behavior_fingerprint | Create a privacy-minimized behavioral commitment without retaining payloads or raw identifiers.; 0.003 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| agent_budget_guard | Enforce per-call, task, session and period budgets; 0.002 USDC. | Not declared |
| agent_economic_graph | Build privacy-bounded economic relationships only from supplied nodes and edges.; 0.005 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| agent_memory_provenance | Agent Memory Provenance; deterministic signed assessment over supplied input. | Read-only |
| agent_rate_limit_negotiator | Agent Rate Limit Negotiator; deterministic signed assessment over supplied input. | Read-only |
| agent_reputation_evidence | Evidence-bounded agent reputation assessment with confidence, coverage, provenance limitations and a signed receipt; 0.005 USDC. | Not declared |
| agent_session_continuity | Agent Session Continuity; deterministic signed assessment over supplied input. | Read-only |
| agent_task_handoff_receipt | Sign a bounded agent-task handoff; 0.003 USDC. | Not declared |
| ap2_mandate_bridge | Map mandate fields for review without advertising unsupported AP2 production authorization.; 0.004 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| attest | x402 paid signed JSON attestation; 0.001 USDC on Base. | Not declared |
| automated_dispute_bundle | Assemble failure evidence and recommend resolution without executing refunds.; 0.005 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| autonomous_procurement | Recommend a verified eligible provider under a mandate without purchasing.; 0.005 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| capability_benchmark | Measure reproducible success, latency and cost from versioned evidence-bound benchmark cases.; 0.004 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| capability_negotiation_preflight | Capability Negotiation Preflight; deterministic signed assessment over supplied input. | Read-only |
| capability_verification | Separate claimed capabilities from independently evidenced successful demonstrations.; 0.003 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| company_enrichment_evidence | Company enrichment with free input preflight, provider attribution and signed evidence; 0.005 USDC. | Not declared |
| concurrency_guard | Fail closed unless capacity counter is fresh and the request carries a lease plus idempotency binding; 0.002 USDC. | Read-only |
| conflict_resolution | Resolve or abstain; every candidate must bind source, value hash, observation time and bounded confidence; 0.003 USDC. | Not declared |
| contact_enrichment_evidence | Business-contact enrichment with free input preflight, identity limitations and signed receipt; 0.007 USDC. | Not declared |
| context_provenance_labeler | Hash and label context integrity, confidentiality and source; 0.002 USDC. | Not declared |
| counterparty_risk_preflight | Deterministic counterparty policy preflight using supplied reputation evidence and transaction limits; 0.003 USDC. | Not declared |
| cross_agent_receipt_bundle | Cross-Agent Receipt Bundle; deterministic signed assessment over supplied input. | Read-only |
| cross_protocol_receipt | Bundle consistent transaction commitments across multiple protocols.; 0.004 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| data_egress_preflight | Inspect outbound agent data and destination before transmission; 0.002 USDC. | Not declared |
| data_freshness_certificate | Certify freshness only when timestamp is bound to source URI and a 64-hex content hash; 0.002 USDC. | Not declared |
| delegated_credential_guard | Delegated Credential Guard; deterministic signed assessment over supplied input. | Read-only |
| delegated_spend_policy | Fail closed when delegated authority, per-call limit or remaining budget is insufficient.; 0.003 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| delegation_scope_guard | Least-privilege guard for agent-to-agent delegation scope, destinations, budget and expiry; 0.003 USDC. | Not declared |
| delivery_evidence | Bind successful delivery to transaction, request and matching 64-hex expected/observed content hashes without echoing content; 0.003 USDC. | Read-only |
| dependency_provenance_assessment | Fail closed on empty dependency sets or absent registry policy; distinguish digest declarations from verified provenance; 0.003 USDC. | Not declared |
| document_to_verified_json | Public text, HTML, JSON or XML normalized to source-backed JSON; no OCR; 0.010 USDC. | Not declared |
| domain_ownership_evidence | Require a fresh domain-bound DNS-01/HTTP-01 challenge and separate control from legal ownership; 0.003 USDC. | Not declared |
| duplicate_charge_detector | Detect repeated transaction hashes, payment identifiers and idempotent intents; 0.003 USDC. | Read-only |
| durable_agent_task | Durable Agent Task; deterministic signed assessment over supplied input. | Read-only |
| dynamic_service_pricing | Propose a capped shadow price without changing the live catalog.; 0.004 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| economic_loop_detector | Detect self-transfer and reciprocal economic patterns without presenting correlation as fraud.; 0.004 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| entity_enrichment_evidence | Source-bounded entity field coverage with explicit missing facts; 0.008 USDC. | Not declared |
| erc8004_identity_evidence | Bind an ERC-8004 registry identity to evidence while separating registration from ownership.; 0.004 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| erc8004_reputation_intelligence | Aggregate diverse verified reputation observations with low-sample abstention.; 0.004 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| execution_cost_estimator | Execution Cost Estimator; deterministic signed assessment over supplied input. | Read-only |
| fetch_evidence | Independently fetch bounded public evidence with redirect/DNS/connected-address SSRF checks, hashes and injection screening; 0.004 USDC. | Read-only |
| human_approval_policy | Classify an action as automatic, approval-required or denied; 0.002 USDC. | Not declared |
| idempotency_replay_guard | Detect safe replays and conflicting idempotency-key reuse; 0.002 USDC. | Not declared |
| index_feed | Canonical catalog snapshot or digest-based delta with exact HTTP/MCP records, PHION Execute templates and signed evidence; 0.005 USDC. | Read-only |
| inspect_agent | Pre-payment agent inspection across x402, A2A, ERC-8004, OpenAPI and MCP; failed inspections are not charged; 0.009 USDC. | Read-only |
| inter_agent_policy_evaluator | Require policy identity, subject, action, lifetime and valid decisions; compute the restrictive cap and shared actions; 0.003 USDC. | Read-only |
| interrupted_task_recovery | Resume only when task/checkpoint identity, sequence, deadline, attempt budget, idempotency and side effects are explicit; 0.003 USDC. | Not declared |
| journey_verify | Verify hash continuity, timestamps and ordered intent→quote→payment→delivery lifecycle; 0.010 USDC. | Read-only |
| live_data_freshness | Evaluate live source observation against explicit maximum age; 0.002 USDC. | Not declared |
| mandate_reserve | Atomic spending reservation with cumulative cap and conflict-safe idempotency; 0.004 USDC. | Changes data |
| manifest_version_diff | Recursive manifest diff that requires explicit versions and flags sensitive changes without a version advance; 0.002 USDC. | Not declared |
| market_data_snapshot | Timestamped public market-data snapshot with provenance; 0.005 USDC. | Not declared |
| market_demand_predictor | Forecast verified demand trends while abstaining on insufficient history.; 0.005 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| mcp_2026_compatibility_gateway | MCP 2026 Compatibility Gateway; deterministic signed assessment over supplied input. | Read-only |
| mcp_a2a_task_bridge | MCP-A2A Task Bridge; deterministic signed assessment over supplied input. | Read-only |
| mcp_catalog_cache_guard | MCP Catalog Cache Guard; deterministic signed assessment over supplied input. | Read-only |
| mcp_manifest_firewall | Inspect an MCP manifest before installation or trust; 0.002 USDC. | Not declared |
| mcp_server_identity_evidence | Bind MCP domain, endpoint, manifest, key and version; 0.003 USDC. | Not declared |
| mcp_transaction_gateway | Bind an MCP tool call to transaction evidence without granting undeclared authority.; 0.004 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| memory_write_guard | Screen persistent memory writes for poisoning, unsafe instructions and missing provenance; 0.002 USDC. | Not declared |
| multi_agent_escrow | Recommend hold or release from evidence without PHION custody or fund movement.; 0.005 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| multi_source_fact_bundle | Independent source observations with agreement made explicit; 0.005 USDC. | Not declared |
| oauth_issuer_binding_evidence | OAuth Issuer Binding Evidence; deterministic signed assessment over supplied input. | Read-only |
| oauth_token_audience_guard | Validate declared OAuth audience and issuer; never send raw tokens; 0.002 USDC. | Not declared |
| onchain_evidence | Public explorer or RPC response evidence with immutable hashes; 0.004 USDC. | Not declared |
| payment_capability_preflight | Free anonymous non-blocking self-report of wallet, mandate, x402 v2, network, asset, account kind and funding readiness. Detects EVM account types incompatible with exact EIP-3009 before signature. Stores only a daily pseudonymous actor and normalized reason; never a wallet, balance, signature or request content. | Read-only |
| payment_delivery_atomicity | Payment Delivery Atomicity; deterministic signed assessment over supplied input. | Read-only |
| payment_diagnose | Free diagnosis of the exact payment-funnel stage and machine-readable recovery actions for any PHION service. | Not declared |
| payment_optimizer | Rank only integration-tested payment routes under explicit cost and latency constraints.; 0.003 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| payment_preflight | Fail-closed x402 v2 firewall for network, asset, recipient, amount, scheme, resource host and expiry; 0.002 USDC. | Read-only |
| payment_receipt_reconciler | Compare canonical and common x402 payment/receipt aliases, settlement state and coverage; 0.003 USDC. | Read-only |
| payment_route_selector | Reject impossible x402 routes, rank safe eligible routes by policy and return the exact next payment action; read-only, deterministic, 0.002 USDC. | Read-only |
| person_enrichment_evidence | Person enrichment with free input preflight, provider attribution, likelihood, limitations and signed receipt; 0.006 USDC. | Not declared |
| phion_discover | Free complete PHION service index generated from canonical inventory. Use when the agent knows a capability or wants to inspect the full network. | Read-only |
| phion_enrich | Enrich a company, person or contact through an attributed provider route without hiding upstream cost.; 0.120 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| phion_execute | Universal PHION execution gateway: enforce a budget and persistent idempotency, execute one selected PHION service, evaluate acceptance criteria, and return a signed completion envelope. No gateway surcharge; the selected service price applies. | Changes data |
| phion_get_service | Retrieve one exact canonical PHION service contract by service id or MCP tool name. | Read-only |
| phion_inference | Complete a bounded inference microtask and return a directly usable answer with signed delivery.; 0.001 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| phion_intelligence | Search, synthesize and cite evidence in one call, minimizing residual agent work.; 0.012 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| phion_preflight | Free service-specific schema, network, budget and economic preflight. It does not execute or charge. | Read-only |
| phion_resolve | Free provider-neutral capability resolution. Applies eligibility constraints, preserves UNKNOWN and abstains when evidence is insufficient. Advisory only: never authorizes payment or execution. | Read-only |
| phion_search | Search the live web and return normalized source URLs and snippets with signed delivery.; 0.006 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| phion_search_services | Search the complete canonical PHION inventory by task, capability, protocol or maximum advertised price without selecting or charging. | Read-only |
| portable_observability_audit | Validate event identity, timestamps, hash chain and W3C-compatible lowercase nonzero trace/span identifiers; 0.004 USDC. | Not declared |
| preflight | Free URL safety and reachability check. | Not declared |
| price_discovery_engine | Derive price bands only from settled observations, never traffic or unsigned quotes.; 0.005 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| proof_of_service | Commit request, authority, execution, payment and delivery evidence in one proof.; 0.005 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| provider_quality_predictor | Estimate provider success, quality, latency and cost using transparent sample-aware statistics.; 0.004 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| purpose_bound_consent | Fail-closed consent bound to ID, subject, recipient, purpose, scope, issue/expiry and checked revocation state; 0.003 USDC. | Not declared |
| quote_freshness_guard | Quote Freshness Guard; deterministic signed assessment over supplied input. | Read-only |
| redirect_callback_validator | Validate HTTPS callbacks and redirect host allowlists; 0.002 USDC. | Not declared |
| reputation_update_receipt | Recommend a bounded auditable reputation update from verified outcome evidence.; 0.004 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| resource_cycle_guard | Require per-step identity, token and cost counters; detect repeated nodes/edges and enforce all three hard caps; 0.002 USDC. | Read-only |
| retention_deletion_receipt | Separate requested, operator-completed and evidence-verified retention/deletion states using content and evidence hashes; 0.003 USDC. | Not declared |
| rwa_asset_due_diligence | Fail-closed issuer, contract, jurisdiction, custody and documentation coverage with independently fetched evidence; 0.019 USDC. | Read-only |
| rwa_compliance | Fail-closed RWA transfer decision requiring explicit jurisdiction, KYC, allowlist, limit and transfer-window checks; 0.012 USDC. | Read-only |
| rwa_corporate_actions | Detect and sign material RWA changes in NAV, income, maturity, redemption or freeze state; 0.012 USDC. | Not declared |
| rwa_nav_reserve | Compare declared NAV and reserve ratios with structured observed facts plus independently fetched evidence; returns discrepancies in basis points and fails closed on incomplete evidence; 0.015 USDC. | Not declared |
| rwa_sanctions_screening_evidence | Evidence-based literal subject screening against observed official US/EU sanctions sources; 0.015 USDC. Not legal clearance or wallet attribution. | Not declared |
| rwa_transaction_assurance | Verify an RWA asset, payment, delivery and transfer restrictions; 0.020 USDC. | Not declared |
| schema_normalize | Safe alias normalization that refuses ambiguous canonical/alias collisions and never changes payment values; 0.001 USDC. | Read-only |
| schema_normalize_free | Free, rate-limited payload validation and safe key normalization before payment. Payment-critical values are never changed. | Not declared |
| secret_redaction_preflight | Detect and redact common secret indicators before transmission; 0.002 USDC. | Not declared |
| service_failover_selector | Service Failover Selector; deterministic signed assessment over supplied input. | Read-only |
| service_gap_detector | Detect capability shortages using verified demand and verified provider supply.; 0.004 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| service_sla_attestation | Sign availability and latency calculations from bounded samples; 0.004 USDC. | Not declared |
| signed_result_comparator | Compare agent results and sign agreement or conflict; 0.003 USDC. | Not declared |
| sla_risk_predictor | Estimate SLA failure probability from bounded success and latency evidence.; 0.004 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| social_source_evidence | Attributable public social-source observations with identity limitations; 0.006 USDC. | Not declared |
| source_backed_search | Literal search over supplied public sources with citations and hashes; 0.004 USDC. | Not declared |
| subscription_spend_guard | Bind one recurring charge to approval, merchant, due time and per-charge/period budgets; 0.003 USDC. | Read-only |
| sybil_reputation_guard | Combine multiple bounded Sybil signals while abstaining without independent evidence.; 0.004 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| task_cancel_assurance | Task Cancel Assurance; deterministic signed assessment over supplied input. | Read-only |
| task_checkpoint_evidence | Task Checkpoint Evidence; deterministic signed assessment over supplied input. | Read-only |
| task_lease_guard | Task Lease Guard; deterministic signed assessment over supplied input. | Read-only |
| tool_call_policy_guard | Bind a proposed tool call to declared intent and execution policy; 0.002 USDC. | Not declared |
| tool_capability_drift_monitor | Detect tool capability or manifest drift; 0.002 USDC. | Not declared |
| tool_output_firewall | Inspect untrusted MCP/tool output before it enters agent context or triggers an action; 0.002 USDC. | Not declared |
| tool_result_schema_validator | Tool Result Schema Validator; deterministic signed assessment over supplied input. | Read-only |
| transaction_assurance | End-to-end settlement, timestamp, delivery-hash and deterministic acceptance assurance; 0.015 USDC. | Read-only |
| transaction_recovery | Failure classification and non-repeating recovery plan with validated attempt history; 0.010 USDC. | Read-only |
| transaction_recovery_v2 | Recommend bounded recovery and reconcile ambiguous payments before retry.; 0.005 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| transaction_risk_score | Estimate evidence-supported loss probability without selling insurance or assuming liability.; 0.004 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| trust_anomaly_detector | Detect material drift between comparable trust vectors without asserting misconduct.; 0.003 USDC. Deterministic, evidence-bounded and signed. | Read-only |
| try_service | Free representative preview, exact price and upgrade instructions for any PHION paid service; no wallet required. | Not declared |
| verified_news_monitor | Literal query evidence across bounded public news sources; 0.006 USDC. | Not declared |
| verified_web_extract | Bounded public web extraction with source, timestamp and hashes; 0.003 USDC. | Not declared |
| verify | Free verification of a PHION signed receipt. | Read-only |
| webhook_verifier | Fail-closed RFC 9421-style webhook preflight requiring trusted key, algorithm, nonce, freshness, replay status and signature coverage of method, target and content; 0.003 USDC. | Read-only |
| x402_quote_comparator | Validate x402 v2 fields and compare only quotes sharing asset and decimals; 0.002 USDC. | Read-only |
| x402_v2_router | Select an exactly compatible x402 v2 payment requirement without receiving private keys.; 0.003 USDC. Deterministic, evidence-bounded and signed. | Read-only |
Change history
No changes since the first observation. The first snapshot is the baseline.
| Source | Listing | First seen | Last seen | Versions |
|---|---|---|---|---|
| Official MCP Registry | systems.phion/evidence-engine | 2 Oct 2026 | 2 Oct 2026 | 1 |