{"_id":"smartflow-verify-mcp","_rev":"2-3f6a968dba7782161b73f68eaf1af2c4","name":"smartflow-verify-mcp","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"smartflow-verify-mcp","version":"0.1.0","keywords":["mcp","modelcontextprotocol","x402","base","usdc","payments","verification","audit","agent-commerce"],"author":{"name":"Tom Smart"},"license":"MIT","_id":"smartflow-verify-mcp@0.1.0","maintainers":[{"name":"tomsmart-ai","email":"smartflowpro.ai@gmail.com"}],"homepage":"https://verify.smartflowproai.com","bin":{"smartflow-verify-mcp":"src/server.js"},"dist":{"shasum":"5229e6d30d92fe98ada43cbef235f8b75540490e","tarball":"https://registry.npmjs.org/smartflow-verify-mcp/-/smartflow-verify-mcp-0.1.0.tgz","fileCount":4,"integrity":"sha512-YCYN7qmvVdq3CYIaaFJoZmCEU/h04MjV/JHrfIccoOxJIO+C8Ipr08gcYhHB41nm8AuNWszTYC5vuuaeDZa/9A==","signatures":[{"sig":"MEQCIC9HrjamxurESyRjLBcWEvTZXBom2n7TAHW2Iqe5irv/AiAjAycRqWP86xm5DoA6Kn2w6/ms2pbvZuK8CTq291rdfA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":20259},"type":"module","_from":"file:smartflow-verify-mcp-0.1.0.tgz","engines":{"node":">=18"},"scripts":{"start":"node src/server.js","selftest":"node selftest.js"},"_npmUser":{"name":"tomsmart-ai","email":"smartflowpro.ai@gmail.com"},"_resolved":"/private/tmp/claude-501/-Users-tomasz-Documents-Obsidian-Vault/29c37b78-190d-4bec-b9dd-ea0e7cd84415/scratchpad/smartflow-verify-mcp-0.1.0.tgz","_integrity":"sha512-YCYN7qmvVdq3CYIaaFJoZmCEU/h04MjV/JHrfIccoOxJIO+C8Ipr08gcYhHB41nm8AuNWszTYC5vuuaeDZa/9A==","repository":{"url":"https://verify.smartflowproai.com","type":"git"},"_npmVersion":"11.11.0","description":"MCP server for SmartFlow Observatory, an independent x402 observatory on Base: integrity-sealed decomposition of x402 network growth and self-serve endpoint audits paid over the x402 rail itself.","directories":{},"_nodeVersion":"24.14.1","dependencies":{"zod":"^4.4.3","@modelcontextprotocol/sdk":"^1.29.0"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/smartflow-verify-mcp_0.1.0_1783785148381_0.6903703549062341","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"smartflow-verify-mcp","version":"0.1.1","description":"MCP server for SmartFlow Observatory, an independent x402 observatory on Base: integrity-sealed decomposition of x402 network growth and self-serve endpoint audits paid over the x402 rail itself.","type":"module","bin":{"smartflow-verify-mcp":"src/server.js"},"scripts":{"start":"node src/server.js","selftest":"node selftest.js"},"keywords":["mcp","modelcontextprotocol","x402","base","usdc","payments","verification","audit","agent-commerce"],"author":{"name":"Tom Smart"},"license":"MIT","homepage":"https://verify.smartflowproai.com","repository":{"type":"git","url":"https://verify.smartflowproai.com"},"engines":{"node":">=18"},"dependencies":{"@modelcontextprotocol/sdk":"^1.29.0","zod":"^4.4.3"},"mcpName":"io.github.smartflowproai-lang/verify","_id":"smartflow-verify-mcp@0.1.1","_nodeVersion":"24.14.1","_npmVersion":"11.11.0","dist":{"integrity":"sha512-ag0fPIzQ5uMHx4pzO46DFnLuHHCUHWsGl4GebmKwCtxOguK+GDG1aW2pcqyO7Wj0JHDcB4wLw6M9EyxnL+vXtA==","shasum":"3cdd8751f6af410689abceb8fbf08b7ded34aba6","tarball":"https://registry.npmjs.org/smartflow-verify-mcp/-/smartflow-verify-mcp-0.1.1.tgz","fileCount":4,"unpackedSize":20312,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCGqfX4GSTq0WRUgMwy8QzqIwRm8kEIBCCtZYphUQIWTAIhAKXvXYi9o0GRf8HFCccBI+po9xCYbXKFklNicfWrbp53"}]},"_npmUser":{"name":"tomsmart-ai","email":"smartflowpro.ai@gmail.com"},"directories":{},"maintainers":[{"name":"tomsmart-ai","email":"smartflowpro.ai@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/smartflow-verify-mcp_0.1.1_1786285200354_0.023924884422259485"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-11T15:52:28.338Z","modified":"2026-08-09T14:20:00.618Z","0.1.0":"2026-07-11T15:52:28.521Z","0.1.1":"2026-08-09T14:20:00.484Z"},"author":{"name":"Tom Smart"},"license":"MIT","homepage":"https://verify.smartflowproai.com","keywords":["mcp","modelcontextprotocol","x402","base","usdc","payments","verification","audit","agent-commerce"],"repository":{"type":"git","url":"https://verify.smartflowproai.com"},"description":"MCP server for SmartFlow Observatory, an independent x402 observatory on Base: integrity-sealed decomposition of x402 network growth and self-serve endpoint audits paid over the x402 rail itself.","maintainers":[{"name":"tomsmart-ai","email":"smartflowpro.ai@gmail.com"}],"readme":"# smartflow-verify-mcp\n\nMCP server for [SmartFlow Observatory](https://verify.smartflowproai.com), an independent x402 observatory on Base that runs its own ledger of USDC micro-transfers. It gives any MCP-capable agent (Claude Code, Claude Desktop, Cursor, and others) two capabilities:\n\n1. **Read the integrity-sealed decomposition of x402 network growth**: how much of the headline volume is wash or self-dealing activity, how much is ERC-4337 bundler plumbing, and how large the organic core really is. Free.\n2. **Order a $199 signed, human-reviewed audit of any x402 endpoint or receiving wallet**, paid over the x402 rail itself. No human needed on the buying side.\n\nThe server is a pure HTTP client of the public observatory API. It holds no keys, stores nothing locally, and **never moves funds**. Payment, if you choose to make one, happens entirely outside this server through your own wallet or x402 client.\n\nHuman-facing verification portal: <https://verify.smartflowproai.com>\n\n## Installation\n\nRequires Node.js 18 or newer.\n\n### Claude Code\n\n```bash\nclaude mcp add smartflow-verify -- npx -y smartflow-verify-mcp\n```\n\n### Claude Desktop\n\nAdd to `claude_desktop_config.json` (Settings > Developer > Edit Config):\n\n```json\n{\n  \"mcpServers\": {\n    \"smartflow-verify\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"smartflow-verify-mcp\"]\n    }\n  }\n}\n```\n\nRestart Claude Desktop and the three tools appear under the `smartflow-verify` server.\n\n### From a local checkout\n\n```bash\nnpm install\nclaude mcp add smartflow-verify -- node /path/to/mcp/src/server.js\n```\n\n## Tools\n\n### `get_network_decomposition` (free)\n\nInput: none.\n\nOutput: the full sealed decomposition document plus fields added by this client:\n\n- `data`: the dataset (30d / 7d / previous-7d windows; universe, bundler, facilitator, wash, and `clean_core` categories with tx counts, USDC volume, and unique payers; category overlaps; concentration checks; explicit limitations).\n- `seal` and `seal_verified`: the server publishes a SHA-256 seal over the canonical JSON of `data`. This client recomputes it locally and reports whether it matches, so the numbers are tamper-evident end to end. The recipe is included in the response.\n- `data_age_hours`: how stale the snapshot is. The dataset refreshes roughly daily.\n\nUse this before trusting any headline x402 volume figure. Note the `clean_core` field is a dataset category name meaning: facilitator-settled transfers with no flagged conditions after the full 48h detection window. Figures reflect the observatory's ingest time, so the most recent hour of activity may be under-represented.\n\n### `order_endpoint_audit` (creates a $199 payable order; the call itself is free)\n\nInput:\n\n- `target` (string): an x402 endpoint URL (`https://...`) or a receiving wallet address (`0x...`).\n- `email` (string): where the signed audit report is delivered.\n\nOutput: an order id (`aud_` + 16 hex chars), plain-language payment instructions, and the raw x402 payment challenge (see payment flow below).\n\nWhat you are buying: a signed, human-reviewed audit of the target covering wash-share, payer concentration, demand dispersion, and attribution, delivered by email within 24h of payment.\n\n**Calling this tool moves no funds.** It only creates an order and returns payment instructions. Unpaid orders are harmless and expire on their own within 24h.\n\n### `get_audit_order_status` (free)\n\nInput:\n\n- `order_id` (string): the id returned by `order_endpoint_audit`.\n\nOutput: order state. `pending_payment` means the exact-amount payment has not been detected yet; `paid: true` confirms the payment was matched; a delivered state means the signed report was emailed.\n\nPayment detection reads Base USDC transfer logs and can lag a few minutes behind the chain. If you just paid, wait 2-5 minutes and poll again before assuming a problem.\n\n## Free vs paid\n\n| Tool | Cost |\n|---|---|\n| `get_network_decomposition` | free |\n| `order_endpoint_audit` | free to call; creates a $199 payable order |\n| `get_audit_order_status` | free |\n\nNothing in this package can spend money by itself. A purchase happens only if you (or your operator) send the quoted USDC amount from your own wallet.\n\n## How the x402 payment flow works\n\n1. `order_endpoint_audit` POSTs to the observatory API. The API answers **HTTP 402 Payment Required** with an x402 v2 challenge envelope. That 402 is the success path for order creation, not an error.\n2. The challenge quotes a **per-order unique amount**: $199 plus a unique micro-USDC fraction, for example `199.002732` USDC. The fraction is how the observatory matches your on-chain payment to your order. **Pay the exact amount; do not round it.**\n3. Pay in either way:\n   - **x402 client**: use the `exact` scheme entry from the `accepts` array (network `eip155:8453`, USDC asset contract, `payTo` address are all in the challenge).\n   - **Plain transfer**: send the exact USDC amount on Base to the `payTo` address from any wallet.\n4. After paying, poll `get_audit_order_status` with your order id. Detection usually completes within minutes.\n5. Once matched, the order flips to paid and the signed audit report is prepared, human-reviewed, and emailed to the address you gave, within 24h of payment.\n\nSafety rules built into the tool descriptions, worth repeating:\n\n- If a payment submission times out, **poll status before paying again**. Never pay the same order twice.\n- Unpaid orders expire within 24h and cost nothing.\n- Agents with spend policies: creating an order is free, but paying it is a real $199 purchase. Confirm with your operator if your policy requires it.\n\n## Example session\n\nA typical agent conversation:\n\n> **User:** Before I integrate with this x402 endpoint, is the network volume real? And get me an audit of https://api.example-x402-service.com/paywall\n>\n> **Agent** calls `get_network_decomposition`, checks `seal_verified: true`, and reports that a large share of headline volume carries wash flags while the organic core is far smaller, citing exact figures and the dataset's own limitations.\n>\n> **Agent** calls `order_endpoint_audit` with the target URL and the user's email, and relays the payment instructions: \"Pay exactly 199.002732 USDC on Base to 0xd779...C893. The order id is aud_a80214548a0c4276. Unpaid orders expire in 24h.\"\n>\n> **User** pays from their wallet (or approves their agent's x402 client to pay).\n>\n> **Agent** polls `get_audit_order_status` until `paid: true`, then tells the user the signed report will arrive by email within 24h.\n\n## Configuration\n\n- `SMARTFLOW_BASE_URL` (env var): overrides the API base. Default `https://verify.smartflowproai.com`.\n- HTTP timeout is 25s per request; the server reports timeouts as retryable network errors and never retries payments on its own.\n\n## Selftest (from a source checkout)\n\n```bash\nnpm run selftest\n```\n\nWrites `selftest.log` with the full JSON-RPC exchange against the live API. The selftest creates one real unpaid test order for `https://example.com`; test orders are harmless and expire in 24h. The selftest never pays anything.\n\n## License\n\nMIT. See [LICENSE](LICENSE).\n","readmeFilename":"README.md"}