Cat-1 · AI & Agentic Developer Tooling · 15 Tools

Agentic Commerce & MCP Developer Hub

Browser-based tooling for the two layers of the agent stack: building MCP servers and integrating agentic payment rails. Lint tool definitions and a server.json, audit OAuth and transport security, scan for tool poisoning, score ship-readiness, compare and build the payment protocols (AP2, ACP, x402, Visa TAP, Mastercard Agent Pay), decode an x402 flow, and validate an A2A agent card — all deterministic, client-side, zero PII.

Zero PII · Client-Side Only 15 Tools · Cat-1 MCP · AP2 · x402 Policy Mandate Export
🔒 All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data — use synthetic or anonymised inputs only.
Build Path

From MCP server to agentic settlement — 4 stages

A path for developers shipping MCP-native, payment-capable agents: define and publish your server, then choose and integrate a payment rail. The security, spec, and readiness tools span every stage.

01
Stage 1
Lint your tool definitions
T274 · Tool-Definition Linter
02
Stage 2
Validate & publish server.json
T275 · server.json Validator
03
Stage 3
Choose your payment protocol
T276 · Protocol Comparator
04
Stage 4
Ship with confidence
T288 · Readiness Scorecard
Tool Library

15 Agentic Commerce & MCP Developer Tools

Fifteen deterministic, client-side tools. Each validates pasted artifacts against published specs — no live handshake, token, or network. All export a Policy Mandate JSON for agent ingestion.

T274 · MCP
LinterZero PII

MCP Tool-Definition Linter & Annotation Designer

Lint a tool definition against JSON Schema 2020-12 and the current naming, output-schema, and annotation rules. Designs a consistent annotation set.

Open tool →
T275 · MCP
RegistryZero PII

MCP server.json Validator & Skeleton Generator

Validate a server.json against the 2025-12-11 schema and registry rules — reverse-DNS namespace, _meta 4KB cap, allowlisted base URLs, MCPB fileSha256 — then scaffold a skeleton.

Open tool →
T276 · Payments
ComparatorZero PII

Agentic Payments Protocol Comparator & Field Crosswalk

Put AP2, ACP (Shared Payment Token), x402, Visa TAP, and Mastercard Agent Pay side by side across credential, signing, scope, rail, and audit — with a crosswalk and scenario recommender.

Open tool →
T277 · Payments
x402Zero PII

x402 Header Decoder, Payload Linter & 402 Flow Simulator

Decode x402 headers, lint an exact-scheme PaymentPayload, walk the HTTP-402 verify/settle flow, and check the scheme×network matrix.

Open tool →
T278 · MCP
OAuth 2.1Zero PII

MCP OAuth 2.1 Authorization Auditor

Validate RFC 9728 protected-resource-metadata, visualize the discovery chain, check RFC 8707 audience binding, and self-assess token passthrough and the confused deputy.

Open tool →
T279 · Identity
RFC 9421Zero PII

RFC 9421 Signature Decoder & Web Bot Auth Readiness

Decode and validate HTTP Message Signatures, lint a Web Bot Auth JWKS directory (Ed25519), and score readiness — the substrate under Visa's Trusted Agent Protocol.

Open tool →
T280 · MCP
SpecZero PII

MCP Spec-Revision Compliance Scorer & Stateless Migration Advisor

Score against a target revision (2025-06-18 / 2025-11-25 / 2026-07-28 RC) and get a breaking-change advisor for the stateless protocol core.

Open tool →
T281 · Payments
ACPZero PII

ACP Checkout Validator & Shared Payment Token Scope Linter

Validate an ACP checkout-session object and lint a Shared Payment Token for the four properties that keep it safe: single-use, merchant-bound, amount-capped, short-lived.

Open tool →
T282 · Security
ASI01Zero PII

MCP Tool-Poisoning & Prompt-Injection Manifest Scanner

Scan a tool description for poisoning and injection smells — instruction overrides, hidden unicode, role-play framing, tool-shadowing, exfiltration hints. Maps to OWASP ASI01.

Open tool →
T283 · A2A
Agent CardZero PII

A2A Agent Card Validator & Extension Checker

Validate an Agent2Agent agent-card.json against the v1.0 shape, check the signed-card signatures, and confirm AP2 / x402 extension declarations — the discovery layer AP2 rides on.

Open tool →
T284 · Security
TransportZero PII

MCP Transport & DNS-Rebinding Security Auditor

Audit Streamable HTTP for Origin/Host validation, loopback binding, DNS-rebinding protection, and token passthrough — the vuln classes behind real rmcp / mcp-toolbox CVEs.

Open tool →
T285 · Payments
Google AP2Zero PII

Google AP2 Checkout/Payment Mandate (VDC) Builder & Validator

Build and validate Google's AP2 Checkout and Payment Mandate Verifiable Digital Credentials (Open/Closed) — the external Google/FIDO spec, distinct from the suite's Policy Mandate.

Open tool →
T286 · Payments
Visa TAPZero PII

Visa Trusted Agent Protocol Signature Inspector & Readiness

Parse a Visa TAP signature, surface the agent-recognition signature and replay-protection parameters, and score TAP readiness. Built on RFC 9421.

Open tool →
T287 · Payments
MC Agent PayZero PII

Mastercard Agent Pay — Agentic Token Scope & Consent-Policy Builder

Build and lint a Mastercard Agentic Token scope — agent-ID, merchant scope, and consent policy (limit, merchants, expiry, velocity) — without exposing the PAN.

Open tool →
T288 · MCP
ScorecardZero PII

MCP Developer Readiness Scorecard

One ship-readiness scorecard rolling up tool definitions, server.json, OAuth, transport, tool poisoning, and spec compliance into a graded report with per-section sub-scores and gap links.

Open tool →
⚠ The MCP specification, the MCP Registry, and the agentic payment protocols all version frequently (the MCP registry is in preview; a breaking MCP revision lands 2026-07-28; payment specs change monthly). Treat embedded rules and reference data as dated snapshots and re-verify against each primary source before relying on any output. Where a protocol's exact field names are not public (ACP, AP2 VDC, Visa TAP, Mastercard Agentic Token), tools flag those fields as illustrative.
Audience

Who uses these tools

MCP Server Authors

Engineers shipping Model Context Protocol servers who need their tool definitions, server.json, auth, transport, and security posture to pass review.

Agent / Platform Builders

Teams adding payment capability to agents and choosing or building across AP2, ACP, x402, and the card-network protocols.

Payments & Fintech Architects

Architects mapping the fragmenting agentic-commerce landscape onto their existing rails and compliance posture.

Security & DevRel

Anyone auditing tool poisoning, OAuth confused-deputy risk, transport hardening, or agent identity — or who needs a fast, citable orientation.

Quick Start

Get going in 4 steps

Related Hubs

Explore adjacent suites