Cat-1 · AI & Agentic Developer Tooling · 10 Tools

Agentic Commerce & MCP Developer Hub

Browser-based tooling for the two layers of the agent stack: building MCP servers and integrating agentic payment rails. Lint tool definitions and a server.json, score spec-revision compliance, audit OAuth, scan for tool poisoning, orient across the fragmenting payment protocols (AP2, ACP, x402, Visa TAP, Mastercard Agent Pay), decode an x402 flow, and validate an A2A agent card — all deterministic, client-side, zero PII.

Zero PII · Client-Side Only 10 Tools · Cat-1 MCP · AP2 · x402 Policy Mandate Export
🔒 All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data — use synthetic or anonymised inputs only.
Build Path

From MCP server to agentic settlement — 4 stages

A path for developers shipping MCP-native, payment-capable agents: define and publish your server, then choose and integrate a payment rail. The security and spec tools span every stage.

01
Stage 1
Lint your tool definitions
T274 · Tool-Definition Linter
02
Stage 2
Validate & publish server.json
T275 · server.json Validator
03
Stage 3
Choose your payment protocol
T276 · Protocol Comparator
04
Stage 4
Integrate x402 settlement
T277 · x402 Workbench
Tool Library

10 Agentic Commerce & MCP Developer Tools

Ten deterministic, client-side tools. Each validates pasted artifacts against published specs — no live handshake, token, or network. All export a Policy Mandate JSON for agent ingestion.

T274 · MCP
LinterZero PII

MCP Tool-Definition Linter & Annotation Designer

Lint a tool definition against JSON Schema 2020-12 and the current naming, output-schema, and annotation rules. Designs a consistent readOnly/destructive/idempotent/openWorld annotation set.

Open tool →
T275 · MCP
RegistryZero PII

MCP server.json Validator & Skeleton Generator

Validate a server.json against the 2025-12-11 schema and the official registry publishing rules — reverse-DNS namespace, _meta 4KB cap, allowlisted base URLs, MCPB fileSha256 — then scaffold a compliant skeleton.

Open tool →
T276 · Payments
ComparatorZero PII

Agentic Payments Protocol Comparator & Field Crosswalk

Put AP2, ACP (Shared Payment Token), x402, Visa Trusted Agent Protocol, and Mastercard Agent Pay side by side across credential, signing, scope, rail, and audit — with a field crosswalk and scenario recommender.

Open tool →
T277 · Payments
x402Zero PII

x402 Header Decoder, Payload Linter & 402 Flow Simulator

Decode x402 PAYMENT-REQUIRED / PAYMENT-SIGNATURE headers, lint an exact-scheme PaymentPayload, walk the HTTP-402 verify/settle flow, and check the scheme×network matrix.

Open tool →
T278 · MCP
OAuth 2.1Zero PII

MCP OAuth 2.1 Authorization Auditor

Validate the RFC 9728 protected-resource-metadata document, visualize the discovery chain, check RFC 8707 audience binding, and self-assess the two cardinal sins — token passthrough and the confused deputy.

Open tool →
T279 · Identity
RFC 9421Zero PII

RFC 9421 Signature Decoder & Web Bot Auth Readiness

Decode and validate HTTP Message Signatures, lint a Web Bot Auth JWKS directory (Ed25519), and score readiness — the signature substrate under Visa's Trusted Agent Protocol.

Open tool →
T280 · MCP
SpecZero PII

MCP Spec-Revision Compliance Scorer & Stateless Migration Advisor

Score your server against a target revision (2025-06-18 / 2025-11-25 / 2026-07-28 RC) and get a breaking-change advisor for the stateless protocol core — the largest, most breaking MCP revision since launch.

Open tool →
T281 · Payments
ACPZero PII

ACP Checkout Validator & Shared Payment Token Scope Linter

Validate an Agentic Commerce Protocol checkout-session object and lint a Shared Payment Token for the four properties that keep it safe: single-use, merchant-bound, amount-capped, and short-lived.

Open tool →
T282 · Security
ASI01Zero PII

MCP Tool-Poisoning & Prompt-Injection Manifest Scanner

Scan a tool description or manifest for poisoning and injection smells — instruction overrides, hidden zero-width unicode, role-play framing, tool-shadowing, and exfiltration hints. Maps to OWASP ASI01.

Open tool →
T283 · A2A
Agent CardZero PII

A2A Agent Card Validator & Extension Checker

Validate an Agent2Agent agent-card.json against the v1.0 shape, check the signed-card signatures block, and confirm AP2 / x402 extension declarations — the discovery layer AP2 rides on.

Open tool →
⚠ The MCP specification, the MCP Registry, and the agentic payment protocols all version frequently (the MCP registry is in preview; a breaking MCP revision lands 2026-07-28; payment specs change monthly). Treat embedded rules and reference data as dated snapshots and re-verify against each primary source before relying on any output.
Audience

Who uses these tools

MCP Server Authors

Engineers shipping Model Context Protocol servers who need their tool definitions, server.json, auth, and security posture to pass review.

Agent / Platform Builders

Teams adding payment capability to agents and choosing between AP2, ACP, x402, and the card-network protocols.

Payments & Fintech Architects

Architects mapping the fragmenting agentic-commerce landscape onto their existing rails and compliance posture.

Security & DevRel

Anyone auditing tool poisoning, OAuth confused-deputy risk, or agent identity — or who needs a fast, citable orientation without infrastructure.

Quick Start

Get going in 4 steps

Related Hubs

Explore adjacent suites