How we check and score

Every number on a listing comes from a check we ran or a public source we name. Here is exactly how.

The checks

For an x402 endpoint we send one unpaid request with the example input it publishes. A correct server answers HTTP 402 with a payment challenge before running anything. We parse the challenge (v1 body or v2 PAYMENT-REQUIRED header) and record status, response time, price, token, network and pay-to address. We never pay.

For an MCP server we run the MCP handshake (initialize, then tools/list) and record the tools it exposes. Servers that require sign-in count as reachable.

Verified, featured and actively used services are checked every 30 minutes, others every few hours, and services that keep failing less often. Requests come from ToolVetProbe/1.0 (+https://toolvet.app/methodology).

The trust score

87trust

A yellow tag means the latest check passed. Grey means it failed or hasn't run yet.

x402 endpoints

Availability (30-day uptime)30 pts
Valid x402 challenge15 pts
Response time10 pts
Real paying agents (30 days)15 pts
Charges what it lists10 pts
Security scan10 pts
Verified owner10 pts

MCP servers

Availability (30-day uptime)35 pts
Response time15 pts
Security scan20 pts
Transparency (repo, homepage, docs)15 pts
Recently checked5 pts
Verified owner10 pts

The security scan

We scan names, descriptions and MCP tool definitions for patterns used to manipulate agents:

Findings are shown on the listing with the exact text that triggered them.

Ranking and sponsorship

Search ranks by text relevance (60%), trust score (30%) and real usage (10%), and pushes services that are failing right now down. Featured listings appear in separate, labelled sponsored slots; paying never changes the organic order or a score.

Corrections

If a check is wrong, contact [email protected] with the listing URL.