Server definition
- Hash
- sha256:f299a2f743203d1608e3b1e002880da3e449f8df708e9592341b92f202e47183
- What it is
- What a remote MCP server returned when asked what it offers: 10 tools
The blob, as servednamed by its sha256
{
"instructions": "OceanAlt AML — free, agent-callable compliance for autonomous payments. Before your agent pays, call payment_decision (allow/review/decline + evidence + a settlement attestation); use screen_address for a raw AML verdict on any address, and screen_endpoint on the URL you are about to call — a spoofed endpoint hands back a fresh address that no list has seen.",
"tools": [
{
"description": "File your operator's control-baseline attestation — the counterpart to counterparty_control_baseline. That tool asks what controls the OTHER side runs; this one publishes what YOUR side runs, so payers can see it before settling with you. No account, no key, one call. Gaps are allowed and expected: answer false where a control is not in place and describe how you plan to close it in gapPlan. A filing with declared gaps is worth far more than no filing — it lets a payer decide against a known shape instead of a blank. Get the control ids from the baseline list first. Only file for a party you are actually authorised to speak for.",
"inputSchema": {
"properties": {
"agentId": {
"description": "Optional. If this party already has an agent registered with OceanAlt, link the attestation to it.",
"type": "string"
},
"answers": {
"description": "Map of control id to boolean, e.g. {\"ACB-1.1\": true, \"ACB-2.1\": false}. Control ids come from the baseline list (see baseline_controls).",
"type": "object"
},
"contact": {
"description": "Optional contact for follow-up. Not published.",
"type": "string"
},
"entity": {
"description": "The accountable party's legal or commonly-used name, e.g. \"Acme Robotics Ltd\". This is who the attestation is about — not your agent's name.",
"type": "string"
},
"gapPlan": {
"description": "For controls answered false: how and when you plan to close them. Plain text.",
"type": "string"
}
},
"required": [
"entity",
"answers"
],
"type": "object"
},
"name": "attest_control_baseline",
"outputSchema": null
},
{
"description": "Fetch the OceanAlt Agent Control Baseline: the list of controls an agent operator is expected to run before it is allowed to move money, each answerable yes or no. Call this before attest_control_baseline so you file against real control ids. Each control carries which gate enforces it and why it exists.",
"inputSchema": {
"properties": {},
"required": [],
"type": "object"
},
"name": "baseline_controls",
"outputSchema": null
},
{
"description": "Anti blind-signing. EVM: decodes what a transaction's calldata will actually do (ERC-20 transfer/approve/permit, setApprovalForAll, ownership transfer, native transfer). Solana: decodes a whole base64 transaction (SPL Token / Token-2022 Transfer, TransferChecked, Approve, SetAuthority, CloseAccount, Burn; System Transfer / Assign; ATA creation). Compares it with what you believe you are doing. EVM: pass intent:{action:'pay', to, amount} plus contract (the transaction's to) and data (hex calldata). Solana: pass network:'solana' and transaction (base64) instead of data. decision match = does what you declared; mismatch = different recipient/amount/asset, or an approval / authority change instead of a payment — do not sign; unknown = could not decode (including address-lookup-table accounts), which is not the same as safe.",
"inputSchema": {
"properties": {
"contract": {
"description": "EVM only: the transaction's `to` field (token contract for ERC-20 payments, or the recipient for native transfers).",
"type": "string"
},
"data": {
"description": "EVM only: 0x-prefixed hex calldata.",
"type": "string"
},
"intent": {
"properties": {
"action": {
"enum": [
"pay"
],
"type": "string"
},
"amount": {
"description": "Base units (e.g. 10 USDC = 10000000).",
"type": "string"
},
"asset": {
"description": "EVM: symbol/contract (optional). Solana: mint address (optional, checked against TransferChecked).",
"type": "string"
},
"to": {
"description": "EVM: recipient address. Solana: wallet or token account.",
"type": "string"
}
},
"required": [
"action",
"to"
],
"type": "object"
},
"network": {
"description": "'solana' to decode a Solana transaction; EVM chain name or CAIP-2 id otherwise (optional).",
"type": "string"
},
"transaction": {
"description": "Solana only: base64-serialized transaction or message.",
"type": "string"
},
"value": {
"description": "EVM only: native value in wei (optional).",
"type": "string"
}
},
"type": "object"
},
"name": "check_calldata_intent",
"outputSchema": null
},
{
"description": "Answers a different question from address screening. Screening asks whether an address is risky; this asks how much damage the agent on the other side could do if it were talked into something. Returns that party's self-attestation against the OceanAlt Agent Control Baseline, split into two sets that must NOT be conflated: verified_by_oceanalt (enforced by the gateway on every payment — provable) and self_claimed (what they state about their own side — NOT verified by OceanAlt). Most parties have not attested: found:false means no information, not a bad signal.",
"inputSchema": {
"properties": {
"agentId": {
"description": "Their agent id, if you have that instead.",
"type": "string"
},
"entity": {
"description": "The counterparty's entity name.",
"type": "string"
}
},
"type": "object"
},
"name": "counterparty_control_baseline",
"outputSchema": null
},
{
"description": "\"Before your agent pays, call OceanAlt once.\" Pass the payee address the agent is about to pay; get a machine-executable decision: allow | review | decline, plus verifiable evidence and retry semantics — use it as a gate: if the decision is not \"allow\", do not pay. On allow/review it also returns a verifiable compliance attestation you can attach to the settlement so the payment carries proof it passed OceanAlt's decision. Free, no API key.",
"inputSchema": {
"properties": {
"amountUsdc": {
"description": "Amount in USDC (optional; recorded, not required for the decision).",
"type": "number"
},
"lang": {
"description": "Language for human-readable fields (signals, note, advice). Defaults to English.",
"enum": [
"en",
"zh"
],
"type": "string"
},
"maxAmountUsdc": {
"description": "Optional declared per-payment cap in USDC. amountUsdc above it → decline.",
"type": "number"
},
"network": {
"description": "EVM chain for the payee (optional; ignored for Tron).",
"enum": [
"ethereum",
"base",
"bsc",
"polygon",
"arbitrum",
"optimism",
"avalanche",
"arc"
],
"type": "string"
},
"purpose": {
"description": "Short purpose/memo (optional).",
"type": "string"
},
"reasoning": {
"description": "Optional payment intent: why this payee. Instruction-override phrases here route the payment to review.",
"type": "string"
},
"task": {
"description": "Optional payment intent: what this payment is for. Sending task, reasoning or maxAmountUsdc opts into a deterministic intent check; an empty intent is itself a finding (requires_information).",
"type": "string"
},
"to": {
"description": "Payee address the agent is about to pay. EVM: 0x + 40 hex. Tron: T + 33 base58.",
"type": "string"
}
},
"required": [
"to"
],
"type": "object"
},
"name": "payment_decision",
"outputSchema": null
},
{
"description": "Return a representative sample of addresses on OceanAlt's reviewed risk list — OFAC-sanctioned, known mixers, and community-reported scam/phishing — each with its source category and reason. Takes no arguments. Free, no API key.",
"inputSchema": {
"properties": {},
"type": "object"
},
"name": "recent_flagged",
"outputSchema": null
},
{
"description": "Resolves who stands behind a paying agent: agent -> principal -> mandate -> credential -> wallet. Each link reports whether it holds; completeness counts how many do (a factual count, not a score). Wherever the chain breaks is where accountability stops. Publication is opt-in and only posture is exposed (that a ceiling exists, never its value), so found:false means the agent has not published — absence of information, not a bad signal.",
"inputSchema": {
"properties": {
"agentId": {
"description": "The agent id to resolve.",
"type": "string"
}
},
"required": [
"agentId"
],
"type": "object"
},
"name": "resolve_agent_identity",
"outputSchema": null
},
{
"description": "Run an AML compliance screen on a single blockchain address BEFORE paying or receiving from it — the pre-payment check on a counterparty. Checks OFAC sanctions, known mixers, community scam/phishing lists, stablecoin issuer freezes, and on-chain heuristics. Returns a verdict (clear | caution | risky), a 0–100 risk score, a blocked flag, and the matching signals — receipts, not a black-box score. A clear verdict means nothing was found in the data OceanAlt holds; it is not a statement that the address is safe. Depth varies by chain (see coverage.chains at /.well-known/agent-capabilities). Supports EVM (0x…), Tron (T…), Solana (base58). Free, no API key.",
"inputSchema": {
"properties": {
"address": {
"description": "Address to screen. EVM: 0x + 40 hex. Tron: T + 33 base58. Solana: base58 public key.",
"type": "string"
},
"lang": {
"description": "Language for human-readable fields (signals, note, advice). Defaults to English.",
"enum": [
"en",
"zh"
],
"type": "string"
},
"network": {
"description": "EVM chain (optional; auto-defaults to ethereum; ignored for Tron/Solana).",
"enum": [
"ethereum",
"base",
"bsc",
"polygon",
"arbitrum",
"optimism",
"avalanche",
"arc"
],
"type": "string"
}
},
"required": [
"address"
],
"type": "object"
},
"name": "screen_address",
"outputSchema": null
},
{
"description": "Screen a payment ENDPOINT (URL or domain) before calling it — the half that address screening cannot answer. In x402 the agent discovers a URL first, receives a 402, and only then learns where to pay: if that endpoint is spoofed, the payee address it hands back is freshly generated and appears on no sanctions list. Checks the hostname and its parent domains against public phishing-domain lists plus hostname shape signals (bare IP, punycode homograph, deep subdomain nesting, free hosting). Returns clear | caution | risky | unknown with language-independent signal_keys. A clear verdict means no match was found, NOT that the endpoint is safe — freshly registered phishing hosts always precede any list. Use together with screen_address. Free, no API key.",
"inputSchema": {
"properties": {
"lang": {
"description": "Language for human-readable fields. Defaults to English.",
"enum": [
"en",
"zh"
],
"type": "string"
},
"url": {
"description": "Full URL or bare domain of the payment endpoint, e.g. https://pay.example.com/x402 or pay.example.com",
"type": "string"
}
},
"required": [
"url"
],
"type": "object"
},
"name": "screen_endpoint",
"outputSchema": null
},
{
"description": "Before paying an x402 402 response, check that its payment requirements (payTo, amount, asset, network, resource) were signed by the seller and not altered in transit by a proxy, CDN, SDK or another tool. x402 v2 carries the requirements in the PAYMENT-REQUIRED response header (base64 JSON): pass either the decoded JSON or the raw base64 value as body. Optionally pass expect:{payTo, amount} — the address and amount you are about to pay — and the tool also checks they match what was signed. verified:false with reason_code no_signature means the seller does not sign (unprotected, not necessarily malicious); digest_mismatch or signature_invalid means the response was tampered with — do not pay.",
"inputSchema": {
"properties": {
"body": {
"description": "The decoded PAYMENT-REQUIRED header JSON (object), or the raw base64 header value (string)."
},
"expect": {
"description": "What you are about to pay; checked against the signed fields.",
"properties": {
"amount": {
"type": "string"
},
"payTo": {
"type": "string"
}
},
"type": "object"
},
"keys_url": {
"description": "Override the seller's public-key URL (defaults to extensions.signedRequirements.keys_url).",
"type": "string"
}
},
"required": [
"body"
],
"type": "object"
},
"name": "verify_payment_requirements",
"outputSchema": null
}
]
}Verify it yourself
curl -s https://api.teppi.xyz/v1/evidence/sha256:f299a2f743203d1608e3b1e002880da3e449f8df708e9592341b92f202e47183 | sha256sum