{"protocolVersion":"0.3.0","name":"Sentinel402","description":"Paid tools for AI agents over x402: a PII and secret guardrail that scans outbound payloads, a prompt-injection scanner for untrusted inputs, live citable data (crypto, stocks, news, weather, GitHub, sports, FX, npm/PyPI, ENS, IP geolocation), and an RCP/1 retrieval server backed by that live data.","url":"https://pii-guardrail.chronokey.workers.dev/mcp","version":"1.3.0","preferredTransport":"JSONRPC","additionalInterfaces":[{"url":"https://pii-guardrail.chronokey.workers.dev/mcp","transport":"JSONRPC"},{"url":"https://pii-guardrail.chronokey.workers.dev/rcp","transport":"JSONRPC"},{"url":"https://pii-guardrail.chronokey.workers.dev/v1/scan","transport":"HTTP+JSON"}],"capabilities":{"streaming":false,"pushNotifications":false,"stateTransitionHistory":false},"defaultInputModes":["application/json"],"defaultOutputModes":["application/json"],"provider":{"organization":"Sentinel402","url":"https://pii-guardrail.chronokey.workers.dev"},"securitySchemes":{"x402":{"type":"apiKey","in":"header","name":"PAYMENT-SIGNATURE","description":"x402 v2 (v1 X-PAYMENT also accepted). 402 carries the exact requirements."},"mpp":{"type":"http","scheme":"Payment","description":"MPP \"Payment\" HTTP auth scheme: 402 carries WWW-Authenticate: Payment (evm/charge); retry with Authorization: Payment <credential>; receipt in Payment-Receipt."}},"security":[{"x402":[]},{"mpp":[]}],"skills":[{"id":"pii-guardrail","name":"PII & secret guardrail","description":"Scan a payload for PII and leaked credentials before it leaves your agent. Detects credit cards (Luhn-validated), SSNs, emails, phone numbers, IP and MAC addresses, IBANs, ABA routing numbers, crypto wallets, passports, national IDs, dates of birth, medical record numbers, and secrets: AWS keys, GitHub/OpenAI/Stripe/Slack/Google/Twilio tokens, JWTs, bearer tokens, PEM private key blocks, basic-auth URLs, database connection strings and password assignments. Returns a verdict, a 0-100 risk score, and in redact mode a sanitized copy that is structurally identical and safe to forward. Zero retention: payloads are scanned in memory and never logged or stored.","tags":["pii","security","guardrail","dlp","redaction","compliance"],"examples":["Scan this payload for PII before I POST it to a partner API","Redact credit card numbers and API keys from this JSON","Is it safe to send this to a third party?"],"inputModes":["application/json"],"outputModes":["application/json"]},{"id":"live-data","name":"Live structured data","description":"Live structured data from primary sources, normalized and citable: crypto spot prices with 24h change (Binance, Coinbase fallback), stock/ETF/index quotes (Yahoo Finance), current weather plus today's high/low for any place name (Open-Meteo, auto-geocoded), the 5 most recent commits for a public GitHub repo, live and final sports scores across NBA/NFL/MLB/NHL/EPL/UCL/LaLiga/Serie A/Bundesliga/MLS (ESPN), ECB daily FX reference rates, news headlines or topic search (Google News), Hacker News front page + search (Algolia), Wikipedia summaries, IP geolocation with ISP/ASN (ipwho.is), npm and PyPI package metadata, and ENS forward/reverse name resolution. Cached per collection so it is fast and cheap.","tags":["data","live","crypto","stocks","news","weather","sports","github","fx","npm","pypi","ens","geo"],"examples":["What is the BTC price?","Weather in Berlin","NBA scores today","Latest commits to cloudflare/workers-sdk"],"inputModes":["application/json"],"outputModes":["application/json"]},{"id":"rcp-retrieve","name":"RCP/1 retrieval over live data","description":"RCP/1 (Retrieval Context Protocol) server backed by live data. Speaks JSON-RPC 2.0 over POST /rcp/<method>. `retrieve` answers a natural-language query — or an explicit collection + params — by fetching from primary sources and returning spec-shaped Hits with id, score, text, citation{uri,title} and meta, so an agent can drop them straight into a RAG context window with provenance attached. initialize, info, catalog/list and ping are free. Stateless: every request is implicitly initialized, no session token needed.","tags":["rcp","rag","retrieval","citations"],"examples":["retrieve { query: \"btc price\", k: 5 }"],"inputModes":["application/json"],"outputModes":["application/json"]}],"payment":{"protocols":["x402","mpp"],"protocol":"x402","versions":[2,1],"scheme":"exact","network":"eip155:8453","asset":"USDC","assetContract":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","payTo":"0xAb59e91c7A4e280914681FA8eA2015f2e1826b4f","mpp":{"spec":"draft-httpauth-payment-01 (Machine Payments Protocol — Tempo × Stripe)","method":"evm","intent":"charge","credentialTypes":["authorization"],"challengeHeader":"WWW-Authenticate: Payment (on every 402, alongside the x402 challenges)","credentialHeader":"Authorization: Payment <base64url credential>","receiptHeader":"Payment-Receipt","nonceBinding":"EIP-3009 nonce = keccak256(challenge.id + challenge.realm)","sameWalletAsX402":true,"settlement":"Same x402 facilitator, same USDC, same recipient wallet.","discovery":"https://pii-guardrail.chronokey.workers.dev/.well-known/mpp"},"paidTools":[{"name":"scan_for_pii","priceUsd":0.02},{"name":"scan_batch","priceUsd":0.003},{"name":"audit_compliance","priceUsd":0.003},{"name":"scan_prompt_injection","priceUsd":0.003},{"name":"get_live_data","priceUsd":0.003}],"freeMethods":["initialize","tools/list","ping","service_info"],"howToPay":["Call the endpoint with no payment header -> HTTP 402 (carries BOTH x402 and MPP challenges)","x402: decode the PAYMENT-REQUIRED header (v2) or the JSON body (v1), sign an EIP-3009 transferWithAuthorization, retry with PAYMENT-SIGNATURE (v2) or X-PAYMENT (v1)","MPP: parse WWW-Authenticate: Payment, sign the same EIP-3009 authorization with nonce = keccak256(challenge.id + challenge.realm), retry with 'Authorization: Payment <base64url credential>'","200 OK, with the settlement receipt in PAYMENT-RESPONSE (x402) / Payment-Receipt (MPP)"]}}