MCP serverio.github.ox31461/robyn
Gasless cross-chain for AI agents: 25 nodes incl.
Read more
Gasless cross-chain for AI agents: 25 nodes incl. Solana & native Bitcoin. One signature, no gas.Overview
Score?
UNRATED 0.672
of what a free look can see, on 30 looks
Looks
35
last 17 hr ago
Tools
87
changed 17 hr ago
More info
URL
api.anygas.xyz/mcp
streamable-http
Says it is
robyn 1.6.0
protocol 2025-06-18
In the record since
32 days ago
Among servers18,413 with a card
0median 0.606 · this server 0.672 · highest on record 0.8561
Toolsfrom sha256:88b2f18dad…b9d8b4 · +0 −0 17 hr ago
| Tool | Schema |
|---|---|
| null_agent_guide One read that teaches an agent to use every NULL capability with the right privacy posture: create an identity, seal + send + scan, start forward-secret sessions, drop an anonymous |
input · no output |
| null_balance Reads an address balance through the NULL server-side RPC proxy, so YOUR IP never reaches any public RPC provider (this host queries upstream from its own address). BE HONEST ABOUT |
input · no output |
| null_calls_info What the blind call relay offers (1:1 and conference, codecs, join-token model). Media keys are sealed through the feed and never reach the relay. Calls themselves need a media-cap |
input · no output |
| null_capsule_cancel Destroys a future-dated capsule you sent with {holdMs, cancellable:true}, using its one-time cancel token. Already-released rows are untouchable. The token proves nothing about who |
input · no output |
| null_ecosystem The live NULL manifest: every product (messenger, Pay, Vault, Drop, Legacy, Agent Wire, forward secrecy), its status, its page, the wired/proposed integrations between them, the se |
input · no output |
| null_login_verify Stateless dual-signature check (secp256k1 + ML-DSA-65) of a NULLAUTH1 assertion for YOUR rp domain and the ONE-TIME challenge YOU issued; returns {ok, psid, mode, named, meta, hand |
input · no output |
| null_market_delist Relays a fresh (<10 min) self-issued card whose claim is {purpose:"delist"} - a public listing card can never be replayed to delist someone. A market moderator adds modCred (a role |
input · no output |
| null_market_list Relays a NULLCRED1 card the agent issued ABOUT ITSELF (subject = issuer = its own meta; SDK credentialIssue, or the stdio door null_market_list_me which mints it for you). One list |
input · no output |
| null_market_listings Every current listing {card, at}; identical for every reader. The registry checked only the classical half of each card when it was listed, so it is never a trust oracle: verify th |
input · no output |
| null_names_market Live listings of premium handles for sale, plus the full deal protocol: agree peer-to-peer in a sealed chat, pay stealth or via NULL Escrow 2-of-3, then finalize with the dual-sign |
input · no output |
| null_names_quote Quotes a handle: 3ch $512/yr, 4ch $128/yr, 5-6ch $4/yr (deliberately under ENS), 7+ characters FREE forever. Includes live state (available/registered/grace/premium with the 21-day |
input · no output |
| null_notarize Proof-of-existence: hash the document LOCALLY (sha256, 64 hex) and send only the hash. The issuer countersigns {h, ts} with ML-DSA-65 (post-quantum); ts is SERVER-assigned. Optiona |
input · no output |
| null_prekeys_fetch Fetches {spk, sigSpk, otk, otksLeft} for a recipient so you can start an X3DH-PQ forward-secret session (SDK: fs.startOutbound). ALWAYS fetch by META-ADDRESS: the sigSpk check veri |
input · no output |
| null_prekeys_publish Makes you reachable with forward secrecy: publishes your signed prekey bundle (medium-term spk + one-time otks) so peers can start X3DH-PQ sessions TO you. Generate and sign locall |
input · no output |
| null_prov_issuer Returns the post-quantum issuer public key that countersigns notary attestations, provenance mints and the witness-log head. Pin it once and verify everything against the pinned co |
input · no output |
| null_prov_mint Relays a provenance request you signed LOCALLY (SDK mintProvenance builds it): {meta, claim, ts, sig, bind, sig2}. A post-quantum identity MUST include sig2 (ML-DSA) or the issuer |
input · no output |
| null_transparency The signed sha256 of every crypto artifact the server hands out (SDK, bundle, workers); hash changes are witness-chained under release:<file>. Fetch an artifact, hash it, compare - |
input · no output |
| null_void_descriptor Returns a pseudonymous channel descriptor {descriptor, witness:{ts}}; the 3.3 KB ML-DSA signature and the handle-ownership proof come as separate parts (part=sig | part=proof) beca |
input · no output |
| null_void_directory Channels whose creators SIGNED themselves discoverable (dark by default). No search parameters by design: pull pages and filter by tag LOCALLY, so your interests never reach the se |
input · no output |
| null_void_publish Relays {descriptor, proof:{ts, sig}} built and signed LOCALLY (SDK voidCreate + voidSignDescriptor + the handle-ownership proof). The registry accepts only the handle owner and sto |
input · no output |
| null_witness_head ML-DSA-signed head {seq, root, sig} of the append-only log that binds every mailbox record (slot|meta|kemPub|ts). Signed by the SAME issuer key as null_prov_issuer. Keep the last h |
input · no output |
| null_witness_range Up to 20 entries {s, b, r, t} from seq `from`: b binds slot|meta|kemPub|ts, r = sha256(prevRoot + b). Replay the chain from a head you trust to prove a mailbox binding was never si |
input · no output |
| robyn_7702_check Check that a signed EIP-7702 authorization tuple recovers the expected account, and whether its nonce matches the live account nonce. Free, read-only, moves nothing. |
input · no output |
| robyn_7702_delegate The canonical Robyn EIP-7702 batch-executor delegate: its address on each of the 22 EVM chains, the ABI, and the EIP-712 scheme for executeSigned. Delegate to this and the relayer |
input · no output |
| robyn_attestation Returns a relayer-SIGNED attestation that, as of a signed timestamp, every component was up (router, signing daemons, MCP, privacy relay) AND the privacy invariants held — the adve |
input · no output |
| robyn_capability_snapshot A signed, timestamped record of current capability: which chains can actually be PAID OUT ON right now, which are merely policy-eligible, which rails are execute-ready, and whether |
input · no output |
| robyn_changelog Machine-readable API history. Pass the version your integration was built against as `since` and you get only what has changed after it, with an explicit `breaking` flag on each en |
input · no output |
| robyn_counterparty_check Your OWN payment history with a recipient address: how many times, how recently, and whether this amount is typical. Call it before paying an address you have not confirmed. THIS I |
input · no output |
| robyn_cross_chain Plan a gasless cross-chain move and get the exact payload to sign. This hosted server never holds your key: call this, sign what it returns with your own wallet, then call robyn_su |
input · no output |
| robyn_delivery_stats How long settlements ACTUALLY take, per rail and per corridor — not a single advertised constant. CHECK `basis`/`status`: below the sample threshold this returns `insufficient-data |
input · no output |
| robyn_errors The full error taxonomy: every errorCode, whether it is retryable, and the suggested recovery action. Read this once and branch on errorCode instead of parsing messages. |
input · no output |
| robyn_evidence_bundle Assembles EVERYTHING about a settled transfer in one call: the on-chain verification, the unit-by-unit fee breakdown, what the alternative route would have cost, and whether the de |
input · no output |
| robyn_fee_forensics Reconstruct a settled transfer unit by unit: destination payout gas, Robyn margin, or a Robyn SUBSIDY where Robyn absorbed a loss. Each line names who was paid and how the figure w |
input · no output |
| robyn_improve_cost Turns a price into a decision. Returns concrete, QUANTIFIED changes — a cheaper destination chain with the exact saving, the size at which a fixed payout cost stops dominating, whe |
input · no output |
| robyn_integration_lint Post the request you INTEND to make and get back what is missing or unsafe, with the concrete consequence. Run this before your first live execute. Findings marked `unsafe` can los |
input · no output |
| robyn_mandate_certificate A signed certificate listing every spend counted against a mandate, the budget, the total spent, and whether it stayed inside. Hand it to the principal at the end of a period. Ever |
input · no output |
| robyn_mandate_check Check a proposed spend against a signed spending mandate BEFORE making it. Returns WITHIN_MANDATE, EXCEEDS_MANDATE or EXPIRED plus the remaining budget. If EXCEEDS_MANDATE, do NOT |
input · no output |
| robyn_mandate_cosign_request For mandates with a co-sign threshold, check whether a specific spend needs the principal to approve it and get the exact digest they must sign. The digest binds the mandate, the t |
input · no output |
| robyn_mandate_events Poll for spend, nearly-exhausted, exhausted, approval-required and revoked events on a principal's mandates. Pass the returned `cursor` back as `since` for only what is new. Use th |
input · no output |
| robyn_mandate_list List all mandates granted by a principal address, with remaining budget, co-sign threshold, expiry and revocation state. Use this before telling a user they are safe: live mandates |
input · no output |
| robyn_mandate_status Remaining and consumed budget for a signed mandate. Consumption counts ONLY transfers verified on-chain, so the figure cannot be inflated by claiming spends that did not happen. |
input · no output |
| robyn_mesh List the Robyn gasless chains and the cross-chain route graph (22 EVM nodes + Stellar), plus the relayer/Permit2 addresses. No credentials needed. |
input · no output |
| robyn_message_anchor_proof Merkle inclusion proof for an anchored row id: leaf, path, root, the signer’s EIP-191 signature over the batch statement and the on-chain tx when enabled. Verify locally with plus- |
input · no output |
| robyn_message_directory Every published v2 mailbox. PUBLIC rows carry {address, metaAddress, kemPub}; PRIVATE rows (the default since 2026-08-28) carry {handle, metaAddress, kemPub} and deliberately NO ad |
input · no output |
| robyn_message_erasure The last purge statement (expired count, cumulative, root of purged ids) signed by the operator. Read-only. |
input · no output |
| robyn_message_feed Returns released rows {id, ephemeralPubKey, viewTag, ct, releaseAt, nextAfter}, identical for every reader. Scan locally with the SDK (inbox(identity)) — checkStealthAddress with y |
input · no output |
| robyn_message_info Sonar — PRIVATE · SEALED · POST-QUANTUM MESSENGER (broadcast to everyone, understood by one, remembered by none). Hybrid ML-KEM-768+X25519 encryption, a one-time stealth handle per |
input · no output |
| robyn_message_mailbox_of For a Robyn name or NULL handle the server must resolve it, so this reveals your intended recipient to the server — prefer robyn_message_directory when you have an address. Returns |
input · no output |
| robyn_message_publish_mailbox Registers a mailbox so others can seal to you. PRIVATE BY DEFAULT: the server stores only a salted hash of your signing address — pass `handle` to be reachable by name (agents get |
input · no output |
| robyn_message_send Relays a message you sealed locally with /svc/msg2-sdk.mjs (seal(mailbox, inner) → {ephemeralPubKey, viewTag, ct}). This tool cannot encrypt for you: sending plaintext here would e |
input · no output |
| robyn_netting_account Whether an address is enrolled (and therefore custodied), its internal balance, recent history, and `nextNonce` — which you MUST use when signing the next transfer or withdrawal. A |
input · no output |
| robyn_netting_enroll_payload Returns the EXACT message the account must sign with its OWN key to open a custodial balance. This endpoint holds no key and enrols nobody — it returns the text; the user signs it, |
input · no output |
| robyn_netting_info Explains the opt-in netting ledger: transfers between two ENROLLED accounts settle as a book entry — no chain, no gas, no fee, instant, at ANY size including amounts below every pe |
input · no output |
| robyn_netting_preview Free and read-only. Given an amount, ranks EVERY exit chain by what actually arrives after the destination payout cost is deducted. Those costs differ by more than 1000x (Avalanche |
input · no output |
| robyn_netting_reserves Publishes what Robyn OWES across all netting accounts against the real relayer float backing it, per chain. Solvency is checkable rather than asserted. Deposits are refused if they |
input · no output |
| robyn_netting_statement Internal transfers produce NO transaction hash because no transaction occurs — this append-only journal is their only record. Never truncated; page with `before` (a seq number). Us |
input · no output |
| robyn_netting_transfer_payload Returns the exact string to sign, with the correct next nonce, for a free instant transfer between two ENROLLED accounts. Signs nothing and moves nothing — the sender signs the ret |
input · no output |
| robyn_payment_request_prepare Build a canonical payment request (payee, chain, token, amount, memo, expiry) and return the digest for THE PAYEE to sign with their own wallet. Robyn does not sign these and holds |
input · no output |
| robyn_payment_request_settlement After paying, prove it: re-checks the transfer against the DESTINATION CHAIN and confirms the payee was paid at least the amount requested. Returns paid=true only on a verified on- |
input · no output |
| robyn_payment_request_verify ALWAYS run this before paying a request you received. It confirms the payee address, chain, token and amount were signed by whoever controls the payee address, and that the request |
input · no output |
| robyn_plan Validate a WHOLE multi-step workflow up front instead of one hop at a time. Fees and durations accumulate across steps. Evaluation stops at the first unroutable step rather than re |
input · no output |
| robyn_plus_claim Submit BLINDED tokens (base64, from plus-sdk blindTokens()) with the payment txHash. Payment is verified on-chain (recipient, amount, confirmation; one tx pays one invoice), then e |
input · no output |
| robyn_plus_info Plus sells capacity (rate-limit-exempt sends), funded cover rows and signed/anchored Merkle proofs — never a "more private lane" (that would be a smaller crowd). Paid in ETH (Robin |
input · no output |
| robyn_plus_invoice Creates an invoice for one bundle (500 passes, $3 quoted in the chosen asset). Returns {invoiceId, payTo, amount (base units), human, chainId, expires}. Pay from any wallet; then b |
input · no output |
| robyn_plus_invoice_status Status, remaining passes and payment details for an invoice. Read-only. |
input · no output |
| robyn_plus_trial Try Plus before paying: submit up to 20 BLINDED tokens (base64, from plus-sdk blindTokens()) and receive blind signatures — identical BLINDED passes to paid ones (the server never |
input · no output |
| robyn_preflight Run this before robyn_prepare/robyn_submit. Returns decision GO or NO_GO plus typed `blockers` (each with a `fix`) and `warnings`. It catches, for free, the failures that otherwise |
input · no output |
| robyn_preflight_full ONE call combining serviceability, routing competitiveness, cheaper alternatives, delivery basis and mandate budget into a single go/no-go. Call this before executing rather than m |
input · no output |
| robyn_prepare Turn a plain-language or structured intent into a concrete plan plus the EXACT payload to sign. Costs nothing, moves nothing, needs no key. Returns status:"sign" with signRequest, |
input · no output |
| robyn_privacy_posture ONE read that tells you, for a chain and for the lane you reached Robyn on, exactly what stays private (relay lane, PQ transport, private mempool / sequencer) and what is still pub |
input · no output |
| robyn_quote Best gasless route to move a token from one Robyn chain to another. Returns estimated output, the bridge used, duration, and the Robyn fee. Read-only — moves nothing. IMPORTANT: ch |
input · no output |
| robyn_receipt_deliver Hands a relayer-signed settlement receipt (from robyn_settle / a completed route) to the counterparty's sealed messaging-v2 mailbox, so they get verifiable proof (terms honored, au |
input · no output |
| robyn_receipt_verify Checks digest + relayer signature + signed terms of a receipt you received (e.g. opened from your v2 mailbox). Read-only. |
input · no output |
| robyn_recipes Ordered playbooks for real goals: pay-someone-safely, prove-what-i-spent, spend-within-a-budget, handle-failures-well, stay-current. CALL THIS BEFORE IMPROVISING A SEQUENCE. Each s |
input · no output |
| robyn_refusal_verify Check a signed refusal receipt. Send header `x-anygas-receipt: 1` on any request and, IF Robyn refuses it, the error response carries a signed `refusalReceipt` recording what was a |
input · no output |
| robyn_route_status Status of an in-flight route by id (BRIDGING → DONE), with the destination tx once delivered. |
input · no output |
| robyn_sandbox_do Runs the identical path end to end against the sandbox: no key, no funds, no broadcast. Use this to prove an integration works before touching real money. |
input · no output |
| robyn_settle The one-verb primitive. Say where value should go; Robyn returns the best route (all rails compared), the gasless method (no native token needed), the privacy posture that will app |
input · no output |
| robyn_spend_statement A statement of every transfer in a window with each fee broken down, SIGNED by Robyn's relayer key (EIP-191). Use this when you must PROVE to a principal what you spent — your own |
input · no output |
| robyn_sponsor_7702 Price or request an EIP-7702 sponsored transaction: Robyn submits your signed authorization as a type-4 transaction and PAYS THE GAS, so your account needs no native token. Over th |
input · no output |
| robyn_submit Relay an intent you already signed. The relayer broadcasts it and fronts all network gas; your account needs no native token. Build `permit2` from robyn_prepare: sign its signReque |
input · no output |
| robyn_verify_outcome Check what ACTUALLY happened to a settled transfer, against the destination chain rather than Robyn's own database. Optionally assert who should have been paid (`recipient`) and th |
input · no output |
| robyn_vip_status Check whether an address holds a recognised member NFT and what it gets. Members pay ZERO on cross-chain transfers of $0.10-$25 to low-cost chains, 15bps instead of 25bps routing, |
input · no output |
| robyn_why_this_route Returns the full routing decision: every rail that quoted, what each would deliver, the margin the winner won by, and which rails stayed SILENT and why. Signed, so you can archive |
input · no output |
| robyn_yield_account An agent's own Aave v3 / Moonwell position (aUSDC/mUSDC) per chain + the capped allowance it granted the relayer + live APY (best-yield auto-selected). Non-custodial: funds stay in |
input · no output |
| robyn_yield_quote Read-only JIT quote: how a spend would be fulfilled from an agent's Aave yield venue (draw <= your allowance -> Aave/Moonwell withdraw -> gasless deliver). Moves nothing. |
input · no output |
| robyn_yield_spend Spend from your yield (Aave v3 or Moonwell) with ONE EIP-712 signature: Robyn pulls only up to your on-chain aUSDC/mUSDC allowance, unwinds exactly what is needed, and delivers gas |
input · no output |
Verify it yourself
npx teppi-check https://api.anygas.xyz/mcpcurl -s https://api.teppi.xyz/v1/trust/mcp/mcs_01M1FZ2JSN0WJQ6SGWEMJCDM9K