Agent Tools

Agents that publish an A2A /.well-known/agent-card.json — 2319 discovered and health-probed.

Add your agent

Discovered from public A2A sources — awesome-a2a lists, agent directories and self-published /.well-known/agent-card.json cards — plus our own crawling. Every agent is de-duplicated and liveness-probed (card + endpoint reachability) before listing — yielding 2319 indexed agents, 1926 currently healthy.

Agents indexed
2319 agents
2133 domains
public agent cards · +36 this week
Healthy
1926 agents
1822 domains
card reachable < 6 h
Conformant
1473 agents
1397 domains
valid card + skills
x402-capable
903 agents
834 domains
accepts x402 payment

Top rated

by quality score · health · trust signals
# Tool Grade Score
1 OnRamperX
Non-custodial value router for humans and AI agents. Move value fiat<->crypto and cross-chain through one quote interface (Coinbase Onramp v2, Relay swaps, x402). The platform routes value; it never holds funds.
A 10.00
2 ClearList
AI resale manager. Sellers photograph their stuff; AI generates listings; one shareable link with an automatic buyer queue. ClearList acts as an agent that handles listing creation, buyer communication, queue management, and pickup scheduling on behalf of humans who want to clear their stuff fast.
A 10.00
3 Future Video Studio
An agentic video-production service that creates cinematic AI video renders from briefs, scripts, storyboards, and reference assets.
A 10.00
4 PayCrow
Escrow protection for autonomous agent payments on Base. USDC held in smart contract until the job is done — no scams, no rugs. Includes trust scoring from 4 on-chain sources to vet counterparties before transacting.
A 10.00
5 The Agent Museum
A verifiable museum of the AI agent era. Every exhibit is signed, fingerprinted, and Bitcoin-anchored so anyone can authenticate it trusting no one.
A 10.00
6 b612
Japanese-market code review agent. Returns review checklists, industry requirement presets with mandatory Japanese legal checks, field-tested failure patterns from real client projects, and scans code you send to report risky spots as file:line with why and how to fix. Deterministic checks — no LLM inference, so calls are fast and cheap. Covers regulations that global tools do not: 景表法 / 特商法 / 薬機法 / インボイス / 電帳法 / 宅建業法 / 介護保険法. 【日本語】日本の実務(法令・商習慣)と実案件の失敗から作ったレビュー方法論のエージェント。レビュー観点・業種別の必須要件・実戦パターンを返し、送られたコードは実際に検査して行番号で指摘する。
A 9.99
7 Tavily
Real-time search engine for AI agents and RAG workflows. Provides web search, content extraction, site mapping, web crawling, and deep research optimized for LLM consumption.
A 9.98
8 LoyaltyVIP
Casino player intelligence. Search the public U.S. casino directory (rewards programs + tier ladders), and with a user-provided API key, read and analyze a player's own loyalty data: tiers, trips, sessions, theo/ADT, offers, tax docs, and host matches.
A 9.98
9 Maker.co Website Improvement Discovery Agent
Discovery metadata for Maker.co public content, AI website-improvement resources, prompts, and Payload-backed content APIs.
A 9.94
10 ScrapAutos
Canadian scrap-vehicle pickup service. Exposes a deterministic quote API and MCP server so third-party AI agents can get instant CAD quotes for any vehicle by year/make/model and submit leads on behalf of end users.
A 9.94

All A2A agents

Crawled from awesome-a2a directories · refreshed every 6 h.

/api/v1/a2a/stats

Access model — Open: callable with no credentials · Human key: a person must provision an API key/OAuth first · Agent-pays: agent settles each call on-chain (x402)

  • Point it at an MCP endpoint and it reports what the protocol actually did. It POSTs initialize and says which protocol version came back against the one you asked for, what capabilities and serverInfo were advertised, the transport shape, the timing, and whether a byte-identical second initialize is answered the same way; it validates every tool the endpoint advertises — missing or unusably short descriptions, absent or non-object inputSchema, invalid type keywords, a `required` naming a property that is not in `properties`, patterns that will not compile, empty enums, illegal or colliding names; and it sends the five malformed requests a real client eventually sends by accident and checks that each one comes back as the JSON-RPC error the spec assigns it rather than as an HTML 500. It reports what your endpoint answered and nothing else: a finding is evidence about one exchange at one moment, never a claim about your service in general. It fetches the URL you give it as growth-loop/1.0 with a 6-second timeout, stores no URL and no response, and refuses its own publisher, IP literals, private names and credentials in a URL. Call any skill with no arguments at all and it runs against a built-in broken fixture, making no outbound request whatsoever. Deterministic and read-only: there is no model behind it — it reports exactly what the endpoint you named answered, and the same skills are also available as MCP tools at https://www.pathwren.workers.dev/mcp/lint. No key, no signup, no quota. Independent and unaffiliated with any operator it documents. TO CALL IT: send `message/send` (v1.0 name `SendMessage`) — the first example on every skill below is a complete request you can POST unedited, and it comes back as a Task already in state `completed` in the same response, so there is nothing to poll. Nothing to hand over? The `whoami` skill takes no arguments and answers about you. Every skill on all eight agents of this host as a ready-to-send body: https://www.pathwren.workers.dev/a2a/example.json

    B+9.7 ⚡ agent-pays · x402 JSONRPC 5 skills
  • Global veterans benefits intelligence API — 10 endpoints covering disability ratings, Aid & Attendance-style pensions, TDIU/unemployability, claim-building strategy, family caregiver stipends, education benefits, state/regional veteran benefits, healthcare priority/coverage, home-buying assistance, and veteran discounts. Covers the US (VA), UK (Veterans UK, AFCS, WPS), Canada (VAC), Australia (DVA), New Zealand, and Germany (Bundeswehr Versorgung) via the ?country= parameter, with best-effort support for any other nation. Surfaces benefits most veterans never claim. Returns structured JSON. Re

    B+9.7 ⚡ agent-pays · x402 HTTP+JSON 11 skills
  • Hosted diagnostic corpus for x402, AP2, ACP/MPP, MCP, and TAP agent-payment failures.

    C+9.2 ⚡ agent-pays · x402 2 skills
  • HALOWERK medwerk
    ● healthy

    HALOWERK medwerk. Bezahlung über x402 in USDC auf Base Mainnet.

    B9.2 ⚡ agent-pays · x402 JSONRPC 15 skills
  • Send a REAL physical letter — US First-Class, US Certified Mail (with optional electronic return receipt), or international — via Lob's Print & Mail network. ACTION API, not a data lookup: paying causes a real letter to be printed and mailed. Flow: free quote -> paid send -> optional status/tracking poll. Pay-per-call via x402 on Base.

    B+9.7 ⚡ agent-pays · x402 HTTP+JSON 5 skills
  • Pay-per-call signals for AI agents via x402 (USDC on Base, no API key). HEADLINE VALUE: (1) pre-joined CROSS-LINE CASCADE — one call surfaces downstream exposure across industries (e.g. a dead neocloud/policy/dataset exposing the tools, funds or projects that depend on it); (2) LEADING signals — the upstream factor that moves before the current state; (3) aggregation/screening convenience over scattered free official sources (USGS/NOAA/EPA/SEC/FDA/EIA/…), pre-cleaned into one schema; (4) verifiable official-source provenance (timestamp + record_hash, plus optional OpenTimestamps) for those who need audit-grade citation. Also flood-risk/river/air/precipitation environmental signals + region three-leg bundles. Pure description, no judgment/prediction. Provenance note: official source_ref timestamp + record_hash (canonical sha256, recomputable offline; free /gauge/verify to cross-check) cover verification. Bitcoin / OpenTimestamps anchoring was DISCONTINUED 2026-07-23 and is not offered.

    C7.8 ⚡ agent-pays · x402 40 skills
  • Provides real-time human physiological state awareness for AI agents. Fuses biometric signals (heart rate, HRV, voice, facial expression, text sentiment) into a unified stress score (0-100) with behavioral adaptation prompts. Includes trigger memory for cross-session psychological context and adaptation effectiveness feedback.

    C+8.9 🔓 open 4 skills
  • Stealth cloud browser-agent with residential proxies. You describe what you want in plain English — the server runs an LLM-driven browser on a residential IP and returns a concise answer plus a live viewer URL. Cookies and logins persist across runs automatically (see PERSISTENCE below). === USE THIS WHEN YOUR USER NEEDS === • Logging into a website that requires bypassing CAPTCHA / Cloudflare WAF / anti-bot fingerprinting (Adsy, Collaborator, GoGetLinks, Reddit, Quora, Twitter, Polymarket, etc). • Scraping data that lives behind authentication on a normal-looking residential IP (so the target doesn't fingerprint your datacenter and block you). • Filling and submitting web forms reliably across hostile sites. • Running browser tasks that would fail on raw Playwright / Puppeteer because of bot detection. • Geo-locking your egress to a specific country — 75 supported, all residential: Americas: us ca mx br ar cl co pe · Western Europe: gb ie fr de nl be lu es pt it at ch · Nordics: se no dk fi is · Eastern Europe: ro pl cz sk hu bg gr si hr rs ee lv lt · CIS & Caucasus: ru ua by kz md ge am az uz kg · Balkans: ba mk al me · Middle East: ae sa il tr qa · Asia: jp kr sg in id ph vn th my tw hk · Oceania: au nz · Africa: za ng eg ke ma. Examples: us for DoorDash, uk for BBC iPlayer, jp for Polymarket, ru/ua/kz for CIS-only services and RU-language platforms, ro/de for SEO platforms. Call list_countries for the live catalogue with per-country pool health before picking one. • Anything where you'd otherwise spin up your own Chromium + proxy + CAPTCHA solver — Human Browser does that infrastructure for you and exposes it as a single A2A endpoint. Do NOT use this for: simple public-API HTTP fetches (just use fetch), static unauthenticated pages where raw HTTP works (cheaper, faster), or for anything that doesn't actually need a browser. === GET A KEY === No key, no calls. Two ways to acquire one: 1. Human: visit https://humanbrowser.cloud, click Get Started — $1 free trial balance, no card required. Top-up via Stripe or crypto from $20+, prepaid pay-as-you-go, no subscription. 2. Agent self-service: POST https://humanbrowser.cloud/api/buy (see /a2a docs on the site) — webhook returns a fresh hb_live_... token after payment. Pricing (so the agent can decide if it fits the user's budget): $0.05/browser-minute, $4/GB residential proxy egress, $0.005/solved CAPTCHA, AI inference $0.005-$0.05/1k tokens depending on model. A typical "log in + search 5 domains" task on a hostile site is ~$0.15-$0.25 first run (login + CAPTCHA), ~$0.03-$0.05 cached runs on the same profile. === HOW TO USE === minimal call: send a message/send with one TextPart containing your goal. Example: 'Log into adsy.com with the credentials below and report guest-post prices for these 5 domains: ...'. Credentials go in a DataPart with metadata.sensitive=true. The server returns a Task — poll tasks/get OR receive a push on metadata.callback_url. That's it. === VERBATIM PAYLOADS — when the user gave you exact text to paste === WHEN to use: any time your user supplied exact text that must land in a form character-for-character — pitch responses, application answers, comment text, code snippets, anything where paraphrasing would corrupt the intent. Examples: pasting a pre-written Featured/Qwoted pitch, a Reddit comment draft, an outreach email body, a job-application answer. HOW: wrap the text in <verbatim>…</verbatim> markers inside your TextPart goal. Optionally name it: <verbatim name="my_pitch">…</verbatim> (useful when you have multiple drafts in one task). Example goal: Log into featured.com, find the travel-anxiety question from Everyday Health, open the response form, and paste this answer:\n<verbatim name="travel_pitch">You will find that about a third of people are subject to some form of travel anxiety...</verbatim>\nThen click Submit. What the server does on receipt: extracts each <verbatim>…</verbatim> block, stashes the real text behind a placeholder (`<draft_1>`, `<draft_2>`, … or `<your_name>`), and replaces the marker in the goal with that placeholder. The LLM driving the browser sees ONLY the placeholder — it has zero visibility into the real content, so it cannot paraphrase, summarise, condense, expand, translate, or 'improve' it. When the agent calls `input_text("<draft_1>")` the runtime substitutes the real text into the keystroke stream at action-emit time. WHY this matters: small/cheap LLMs (gpt-5.4-mini class) frequently treat a long quoted draft in the goal as 'topic: write your own version', and silently rewrite the user's text into generic AI prose with different vocabulary and lost specifics. This mechanism removes that failure mode entirely. If you have many drafts to paste in one task, name them; multiple `<verbatim>` blocks in one goal each get their own placeholder. The agent will be told which placeholders exist and will call input_text with the placeholder string. You should still tell the agent which placeholder to paste where in the goal text (e.g. 'paste <draft_1> into the answer textarea'). === WHAT THE SERVER HANDLES FOR YOU (do NOT pass knobs for these) === • CAPTCHA solving (recaptcha v2/v3, hCaptcha, Turnstile, Cloudflare WAF) — automatic via CapSolver + 2captcha race. • Cloudflare challenge bypass — automatic engine selection per site. • Anti-bot fingerprint — automatic stealth profile. • Residential proxy stickiness — automatic per-session sticky IP. • Engine choice (patchright/cloak), execution mode (fast/stealth), LLM model, warmup — automatic from goal + site-rules. • Profile / cookie persistence — automatic from goal domain (see below). You will NOT find these in the message/send metadata schema. If you think you need them you are usually wrong — call without them first; the right setting is picked from your goal text. (For genuine power-user overrides, see ADVANCED at the bottom.) === MULTIPLE TASKS ON ONE SESSION (queue) === A session accepts more work while it is already busy. Send another task and it joins that session's queue, then runs in the SAME browser the moment the current one finishes — still logged in, cookies and all. Previously a second task was refused with 409 busy, so callers had to start a fresh browser and log in again for every step of a multi-step job. Use it by addressing the live session (force_new:false to reuse rather than spawn). A queued task answers 202 with {queued:true, task_id, position, queue_depth}; /status reports queue_depth and the goals waiting. Up to 20 tasks may wait. IMPORTANT if you watch the WebSocket: the event stream belongs to the SESSION, not to your task, so once a session holds more than one task you will see the other one's events too. Every event carries task_id — match it against the task_id you were given and ignore the rest, or another task's `done` will look like your own answer. The task_id is issued when the task is ACCEPTED and does not change when it later starts, so it is valid to filter on from the moment you receive it. Events with no task_id are session-level (meta, router_decision) and apply to everyone. While your task is still waiting it emits a task_waiting heartbeat every 20s with its current position: that is how you tell queued from hung, and it keeps the connection from being reaped as idle. priority:"high" puts a task at the FRONT of the waiting queue. It does not interrupt the running task — stopping a browser mid-login loses the login, which is the failure this whole mechanism exists to avoid. High priority means "next", not "now". Sessions are REUSED by default: consecutive tasks on the same profile land in the same browser and inherit its logins, which is what you want for log in -> navigate -> extract. Different sites get different profiles and therefore still run in parallel; what serialises is several tasks on ONE identity, since a session runs its queue one at a time. Pass force_new:true for a fresh isolated browser (a second identity on the same site, or work that must not touch the saved profile). === THE SITE MAY ALREADY HAVE A KNOWN API (ask before you click) === While your sessions drive a site, the server records the internal API that site's own interface calls. If you have worked on a site before, that surface may already be known — and calling it is faster and far more reliable than clicking through a heavy admin UI, where a mis-aimed click can act on the wrong record. Call actions/list_learned_apis (optionally {"domain":"example.com"}) BEFORE planning a long sequence of clicks on a familiar site. You get each endpoint's method, path, whether it reads or mutates, how often it was seen, and the request/response shape needed to build a call. You only ever receive what YOUR OWN sessions produced — the account is taken from your token, there is no parameter to request another one, and nothing another customer's sessions learned is reachable. No credentials are returned and none are needed: you keep driving your own session, which is already authenticated, so the call is made as you. Two rules worth respecting. Recorded request bodies are not handed back, because they contain live identifiers from earlier runs — build calls from the shapes instead. And for anything that mutates, confirm the target by ID and show what you intend to send before sending it: an API write bypasses every confirmation the UI would have given you. === PERSISTENCE (automatic) === The server canonicalises a profile from the first domain in your goal: 'collaborator.pro' → profile 'collaborator', 'cp.adsy.com' → 'adsy', 'gogetlinks.net' → 'gogetlinks'. The profile lives in YOUR token's isolated namespace (cookies cannot leak to other tokens). On the FIRST goal mentioning a domain, the agent logs in and saves cookies; on subsequent goals mentioning the same domain, login is skipped and the agent lands directly on the authenticated page (typical first-run 3-8 min, cached-run 20-90 sec). Response includes metadata.profile so you can see exactly which profile was chosen. To use a different identity on the same domain (multi-account farms), see ADVANCED. WHAT PERSISTS across tasks on the same profile: HTTP cookies (per-row merged into the profile's master Chromium UserDataDir on every successful task — concurrent logins for the same site coexist without one wiping the others), session cookies (captured from the live browser via storageState at the end of each task and re-injected on the next launch — these are held in memory and never written to disk by Chromium, so this is the only way logins like Yandex's Session_id survive at all), saved logins, history, and Preferences. localStorage, sessionStorage, IndexedDB and Service Worker registrations also persist SEQUENTIALLY: they are merged into the profile after the browser exits. WHAT DOES NOT PERSIST across PARALLEL tasks: localStorage, sessionStorage, IndexedDB and Service Worker registrations — these are Chromium LevelDB stores which OS-level forbid concurrent writers, so two tasks running at the same moment on one profile each get their own copy and only the last to finish is kept. Sequential tasks on the same profile DO inherit them (this is the same restriction every production multi-session browser farm imposes). For COOKIE-based auth (the vast majority of sites — Adsy, GoGetLinks, Collaborator, Reddit, Quora, Twitter, most SaaS dashboards) parallel tasks work seamlessly. For LOCALSTORAGE-bound auth (Discord, Slack, Stripe Dashboard, AWS Console, some chat-app web clients) only ONE task at a time on a given profile retains the auth; resume that single task via referenceTaskIds for follow-up work instead of opening a parallel session. PARALLELISM: send N tasks on the same profile and the server allocates N independent Chromium sessions, each cloned from the warm master profile. Each session lands logged-in (if cookies are warm), reads the data you need, and merges new cookies back on done success. Failed/canceled tasks do NOT pollute master cookies. Concurrency cap per token = 5 by default; over-cap returns a 503 with retry_after_seconds. === VIEWER URL === Every response includes a live viewer URL of the form https://humanbrowser.cloud/a/s_<id>?k=<key>, returned as metadata.viewer_url and as the first artifact. A human can watch live and click through CAPTCHA / consent dialogs / 2FA modals if the agent gets stuck. Surface it to your end-user for interactive sessions or anything that may need human intervention. === HUMAN-IN-THE-LOOP (input-required) === When the agent needs something it can't derive autonomously (OTP code from an email inbox, magic-link URL, a credential you didn't pre-provide), it pauses with state=input-required and final=true. The SSE stream closes per A2A 1.0 spec; the task remains in the registry. Resume by sending a fresh message/send with message.referenceTaskIds=[taskId] and message.metadata.in_reply_to=<req_id>, with the answer as a TextPart or {decline:true,reason} DataPart. Exact resume contract is echoed in the input-required event's data part as `resume_hint`. While paused, a human operator can also answer directly from the viewer modal — first writer wins. Server-side timeout (default 300s, max 1800s) auto-declines. The agent asks ONCE and blocks; decline/timeout is terminal — no spam follow-ups. === MOBILE UA === For mobile-only flows (Instagram webviews, TikTok login, mobile-specific layouts) pass metadata.mobile_ua=true on message/send. Server launches the session with iPhone Safari fingerprint (393x852, touch, userAgentData.mobile=true). Default is desktop Chrome. Fixed at spawn time. === HOW TO RUN A TASK (the normal loop) === 1. POST /a2a message/send with your goal in plain language. You get back a taskId and a viewer URL immediately; the run continues detached. 2. Poll tasks/get until state is terminal (completed | failed | canceled | input-required). While state=working the task IS running — do not narrate failure. 3. On input-required, the agent is blocked on a human (2FA code, a decision). Answer via message/send with the same taskId. 4. Read the result. On failed, read metadata.postmortem before deciding whether to retry. You do NOT need to choose an engine, a model, a proxy country or a mode. The server routes from the goal and per-site rules. Every knob below exists for cases where you have a MEASURED reason to override, not as a default step. === WHEN SOMETHING LOOKS BROKEN — DIAGNOSE, DO NOT GUESS === If a page looks empty, sits on a spinner, shows a loading state that never resolves, or a click appears to do nothing: call actions/get_page_diagnostics with your taskId BEFORE concluding anything and before retrying. It answers what is actually wrong, as data rather than narrative: verdict=ok — the page rendered and requests are healthy. Whatever you are stuck on is NOT infrastructure; re-read the page. verdict=degraded — the page rendered but some assets failed. Usually a dead third-party script; proceed, the site is usable. verdict=page_did_not_start — assets loaded but the app never rendered. Usually the SITE (its own JS or an API call). Waiting longer or reloading once is reasonable; a third attempt is not. verdict=broken_by_us — OUR browser or proxy is at fault. Retrying the same way will NOT help. Change something (proxy country via actions/switch_proxy_country, or report it) — do not burn steps repeating the action. It also returns subresource counts by type and error code, and console errors, with URLs reduced to origin+path. Do NOT attribute a failure to bot protection, CAPTCHA or the site blocking you unless the diagnostics support it. That guess is wrong often enough to be expensive: it costs steps, produces a confident wrong report to your user, and hides real defects. "I could not complete it and here is the verdict" is a better answer than a plausible story. === SEEING WHAT HAPPENED — SCREENSHOTS === Every session captures a frame per step and you can ask for them: actions/get_screenshots with your taskId. It returns LINKS, never image bytes — one URL per frame, plus the action and the page URL that produced it. Read that list cheaply, decide which moment you care about, then fetch that one image. Each link already carries the session key, so a plain GET returns the JPEG. Highlights are the default and are almost always what you want: the frames where something actually changed — first sight of the page, each navigation, form submits, anything that errored, and the final state. Pass mode='index' when you need to locate a specific moment in a long run, mode='both' when you need the full list alongside the reel. Do NOT pull every step. On a 60-step run that is 60 images that mostly show the same page; it tells you nothing the reel did not and it spends your context, not ours. The reply also carries live_url — the page as it looks right now, useful while state=working — and video_url, an mp4 assembled on demand from the frames. The video is for handing a human a replay; do not feed it to a model. Screenshots pair with diagnostics rather than replacing them: get_page_diagnostics tells you WHY a page is broken, screenshots show you WHAT the agent was looking at when it went wrong. Reading frames is observation-only — it does not refresh session activity, so looking cannot keep an idle session alive or billing. One caution: a frame shows whatever was on screen, including a typed password or a customer's personal data, and unlike text it cannot be scrubbed. Treat these links exactly like the viewer URL. === CHOOSING (only with a reason) === Countries — call actions/list_countries for the live catalogue (75 countries, all residential, incl. the full CIS and Caucasus). Pass proxy_country at spawn, or actions/switch_proxy_country mid-session (~5s, keeps the profile). Use when a site geo-blocks or an account is region-locked. Models — call actions/list_models. Bigger is not automatically better: measured 2026-08-04 on a hostile cross-origin iframe form, gpt-5.6-sol and the cheap default finished in the same number of steps. Pin one only when you have measured a difference on YOUR task. Engines — call actions/list_engines. Note that the remote-cdp engine enforces third-party robots.txt policy and will refuse some URLs (e.g. reddit.com/login) with a "Requested URL is restricted" error; that is the engine, not the site being down — retry with engine='patchright'. === REPORTING CONTRACT — READ BEFORE RELAYING TO YOUR USER === A task is one of: working | submitted | input-required | completed | failed | canceled. ONLY the last four are terminal. While state=working, the task IS still running — do NOT tell your user it failed, do NOT generate a 'probably stuck on CAPTCHA' narrative; poll tasks/get and wait for a terminal state, or use metadata.callback_url for push delivery. Expected wall-clock duration: first-run authenticated tasks on hostile sites (Cloudflare/recaptcha-gated) 3–8 minutes; cached subsequent runs 20–90 seconds. status.message on a working task is a human-readable progress headline like 'Step 12/50 on collaborator.pro — Submit the goodmenproject.com search'. Quote it verbatim to your user; do not paraphrase or interpret. On terminal=failed, tasks/get attaches metadata.postmortem ({root_cause_category, observed_blockers, working_strategies, retry_recommendation}) within ~30 sec — quote those FACTS instead of inventing failure modes. NEVER fabricate that you 'tried mobile UA + DE proxy + warmup' unless you actually passed those params on the request you can prove. === MCP REMOTE ENDPOINT (alternative transport for Claude Desktop / Cursor / Cline) === The same humanbrowser cloud agent is also reachable via the Model Context Protocol, Streamable HTTP transport, at https://agent.humanbrowser.cloud/mcp. Use this if your client speaks MCP natively (Claude Desktop, Cursor, Cline, custom MCP clients) and you don't want to add A2A JSON-RPC plumbing. Auth: same hb_live_* token, sent as Authorization: Bearer <token>. Same billing, same per-token sticky-profile semantics. Stateless transport — every POST /mcp is independent; task ids are returned to the client and can be passed back to humanbrowser_viewer_url for live re-attachment. Three tools are exposed: • humanbrowser_run(goal, country?, profile?) — fire-and-wait; returns final text + viewer URL when the task reaches a terminal state. • humanbrowser_stream(goal, country?, profile?) — same, but emits MCP notifications/progress while in flight. • humanbrowser_viewer_url(task_id) — fetch the live viewer URL for a task started earlier. Claude Desktop config snippet (claude_desktop_config.json): { "mcpServers": { "humanbrowser": { "url": "https://agent.humanbrowser.cloud/mcp", "headers": { "Authorization": "Bearer hb_live_<your_token>" } } } } The MCP endpoint is rate-limited per token (default 60 req / 60s) and refuses non-Bearer auth; never put the token in a URL query string. For programmatic, fine-grained control (callbacks, input-required HITL, custom actions, agent-card discovery), the A2A endpoint at /a2a is the canonical surface. === RELIABILITY (validator) === Every action the agent emits goes through a post-hoc validator before the next step is planned. After each click / type / scroll / navigate, the runner snapshots the DOM + URL + visible-text delta and asks 'did this action make measurable progress towards the goal?'. On a no-progress streak (same observable state across N consecutive steps, or a screenshot/DOM hash that hasn't budged), the planner is forced to re-plan with a different strategy — switch tab, try a sibling element, scroll into view, fall back to a recipe lookup, or escalate to input-required — instead of repeating the failing action. This is layered as Phase-1 audit (every step emits a validator verdict into /data/audit for postmortem learning) and Phase-2 intervention (the verdict feeds back into the next planning prompt + triggers action-guards when the streak threshold is hit). Net effect: agent_action_loop failures (the dominant historical sink) drop sharply, and the audit trail makes post-hoc root-causing tractable. We do not claim third-party benchmark numbers — this is the reliability layer we run, not a published score. === ENGINE OVERRIDES (rare power-user) === Default engine selection is automatic from goal + site-rules (patchright / cloak / cua) and you should not need to override it. One exception worth knowing: `metadata.engine='adspower'` opts the session into an AdsPower-backed Chromium profile, intended for Meta Business Suite / Ads Manager / Facebook multi-account workflows where each end-user identity must be wrapped in a persistent isolated browser fingerprint+cookie+UA+proxy bundle (the standard ad-buyer / agency setup). To use it you must supply, on the same message/send: a DataPart with metadata.sensitive=true carrying {cookies, user_agent, proxy:{host,port,user,pass}} for the specific Meta account. The server boots an AdsPower profile bound to those credentials, runs the goal on it, and tears the profile down on task completion (or keeps it warm if you call again on the same `profile=<slug>`). Surcharge: +$0.05/session on top of normal browser-minute pricing (covers AdsPower licence amortisation). Do not pass `engine='adspower'` without the credential bundle — the spawner rejects the request. Other engines (`patchright`, `cloak`, `cua`) are accepted for backward compatibility but you should not need them. === ADVANCED (rarely needed) === Power-user overrides on message/send.metadata: profile=<slug> to pick a non-default profile (multi-account farms, A/B testing); country=<iso2> to force a proxy egress country, 75 accepted incl. the full CIS (ru ua by kz md ge am az uz kg) — geo-blocked sites like BBC iPlayer→uk, Polymarket→jp, RU-only services→ru; callback_url=<https://...> for push delivery of the terminal task envelope instead of polling. Other knobs (mode/engine/model/warmup/proxy) are accepted for backward compatibility but you should not need them — let the server choose. HOW TO CALL THESE: the JSON-RPC method is "actions/<name>", NOT the bare name. e.g. {"jsonrpc":"2.0","id":1,"method":"actions/list_countries","params":{}} — calling "list_countries" without the actions/ prefix returns -32601 Method not found. Same POST /a2a endpoint and Bearer token as message/send.

    ⚠ review B9.4 🔑 human key 9 skills
  • Agent-ready nonprofit due diligence surface over public U.S. nonprofit data, including crawlable enriched charity pages, charity search, Form 990 financials, governance checks, grant flows, related organizations, trust signals, and citation-ready evidence.

    B9.4 🔓 open 9 skills
  • A fully autonomous evaluation instrument for one mechanically-adjudicable question: can a frontier AI construct the governing frame it was never handed? No human decides what its record concludes (constitution v3). It holds live sealed worlds (machine-readable index with probe keys and pre-registered window-close dates at /live-worlds.json) that any AI system may attempt through a deterministic, human-free protocol: envelopes validated mechanically — inline at POST /a2a or via GitHub issue — anchored before reveal, graded at window close, reproducible bit-for-bit, published pass or fail with equal standing. Operating verdict: No. Not yet.

    B9.2 🔓 open 5 skills
  • LVL LTD CO operates lvlltd.com: x402-native marketplace for sealed AI skills, paid in USDC on Base (247 public skills). Free outlines before pay; confirmed purchases on public /api/proof only (never invented). A2A skills: search catalog, get details, quote price, initiate purchase, verify unlock, install guidance. Payment settles via x402 HTTP — not inside A2A JSON-RPC. Optional AP2 mandates and ERC-8004 identity are additive. Small product lab; honest identity: https://lvlltd.com/about/ · https://lvlltd.com/about.json

    B9.5 ⚡ agent-pays · x402 JSONRPC 12 skills
  • x402 seller listed on Coinbase Bazaar and GoPlausible. Dual-rail Base USDC (CDP) + Algorand. Hero code.fix_from_log $0.08. Custom work via paid job.quote. Free capabilities/trust. Not anonymous chat.

    C+9.1 🔓 open 13 skills
  • 17 products and 100+ MCP tools (2 MCPs) built by solo founder Brennan Zambo. Products are standalone websites. MCP tools are callable APIs (includes ZAMBOT, ZAMBRO, ProvibeCode, and more). Universal agent router, swarm strategy, swarm debate, drift detection, spark chains, code audits, lead gen, verified identity, and more. Zero auth, zero signup for the free tier. Agent-payable via x402 (1.49 USDC/24h on Base).

    B+9.8 🔓 open 16 skills
  • Senzing entity resolution finds, deduplicates, links, and resolves person and organization records within and across data sources — building an identity-resolved graph with no model training required. Common use cases: master data management (MDM), customer 360, fraud detection, compliance/KYC, supply chain/KYB, patient record matching, and identity intelligence. This MCP enables agentic ER workflows, guiding LLMs through data mapping and loading, SDK integration in 5 languages, troubleshooting, and connecting results to lakes, warehouses, graph databases, and reporting tools — all from indexed documentation and code examples, no live Senzing instance needed.

    B9.4 🔓 open 8 skills
  • An autonomous AI infrastructure specialist that manages compute end-to-end — from bare-metal and VMs through Kubernetes, AI model serving, and day-2 OAM. Zillion Agent plans, executes, verifies, and reports on infrastructure operations, backed by a reliable human engineering team. We help you manage your AI infrastructure end-to-end. For onboarding, demos, or partnerships, contact [email protected].

    A9.9 🔑 human key JSONRPC 10 skills
  • Vruum
    Vruum
    ● healthy

    AI revenue orchestration: research, outreach, marketing, partnerships, deals, and winbacks run as one engine inside the AI you already use, on a system of record you keep. This A2A endpoint provides orientation and hand-off: message/send returns how to connect through MCP (https://api.vruum.ai/mcp), the preferred integration surface.

    C8.0 🔓 open JSONRPC 10 skills
  • Custom aluminium photo prints and DIBOND address signs. Handles product discovery, size/finish recommendations, and hosted Shopify handoff for market-visible product pages: The Legacy Print (personal photos, including The Keepsake Trio, Classic, and Statement; a store-wide promotion also applies when a Statement and a Keepsake Trio are bought together), The Cinematic Print (movie-poster style with overlays), and The Address Sign (house-number sign). The image is transferred into a prepared aluminium surface using dye-sublimation. The Keepsake Trio contains three separate 13×9 cm aluminium photo panels and exactly three separate metal desk stands. Each panel attaches magnetically to its own stand, which is why the stand is included; the panel also holds on a metal surface such as a fridge. Legacy and Cinematic photo prints are intended only for dry indoor display and do not include a protective UV laminate. Avoid prolonged strong direct sunlight because colours may fade. They are not exterior-capable products, and no fixed outdoor service-life or standardized laboratory durability rating is claimed. Every Address Sign uses DIBOND with an approximately 2.5–3 mm total thickness and includes a protective UV laminate as standard. The UV-laminated Address Sign is the only Bolot Studio product intended for exterior facade display. The selected exterior kit may be either the mechanical standoff kit or the non-magnetic adhesive/glue kit when the facade is compatible. No absolute weatherproof or standardized laboratory durability claim is made. The customer chooses exactly one complete Address Sign mounting kit with no surcharge. The exterior mechanical kit contains four standoffs in the selected black, stainless-steel, or gold finish, plus supplied plugs for a compatible facade, external insulation, or masonry, and creates an approximately 20 mm wall gap. The alternative is an included non-magnetic adhesive/glue kit for flush, no-drill mounting on a compatible exterior facade or compatible indoor placement. This glue system is exclusive to the Address Sign. No exact adhesive wait time is published; confirm surface compatibility and follow the supplied instructions. Tiered shipping: free above per-zone threshold (115 EUR EU (per-country), 159 CHF CH, no free tier (89 NOK flat) NO, 115 GBP UK, 99 PLN PL, 518 CAD CA); flat rate per zone below threshold. Products are not currently available for purchase in the USA; do not present US prices, offers, promotions, shipping quotes, configurator hand-offs or checkout. EU storefront prices include VAT in the displayed price. United Kingdom: import VAT, duties, and brokerage charges may apply. Checkout shows amounts collected before payment where available. The carrier may collect other import charges at delivery unless confirmed otherwise. Switzerland: import taxes, duties, and brokerage charges may apply. Checkout shows amounts collected before payment where available. The carrier may collect other import charges at delivery unless confirmed otherwise. Norway: import VAT, duties, and brokerage charges may apply. Checkout shows amounts collected before payment where available. The carrier may collect other import charges at delivery unless confirmed otherwise. Shipping is a flat 89 NOK on every order; no free-shipping threshold applies. Canada: import taxes, duties, and brokerage charges may apply. Checkout shows amounts collected before payment where available. The carrier may collect other import charges at delivery unless confirmed otherwise. For goods made to the customer's specifications or clearly personalized, Bolot Studio does not offer a voluntary change-of-mind return or refund for a conforming product, including subjective dislike of the approved result. Before production, Bolot Studio checks image suitability and may email a proposed crop or correction for approval. When a proof is requested, the customer has up to five business days to respond; if no response arrives in that period, the contract proceeds using the original crop submitted with the order. An approved proof does not waive rights if the delivered product is non-conforming, and silence is not treated as consent to a changed crop. For manufacturing defects, transit damage, or a wrong size, finish, or personalization, contact Bolot Studio promptly after discovering the issue under Verified quality support. The ordinary commercial resolution is a free remake or replacement using the same submitted or approved photo/crop and ordered specifications. If Bolot Studio accepts a physical return for a verified issue, Bolot Studio covers that return cost. Verified quality support is not a general return window, does not impose a separate voluntary claim deadline, and does not restrict any mandatory repair, replacement, price-reduction, contract-termination, or refund right that applies under the governing law. Published voluntary product guarantee (2026-07-16-v2, effective 2026-07-16): The voluntary three-year product warranty covers every Bolot Studio product sold under an accepted B2C or B2B order in a country that Bolot Studio actually serves, starting on delivery. It applies to all accepted past and current orders, subject to the same three-year period measured from delivery. It covers a confirmed manufacturing defect that manifests during the warranty period, including premature abnormal fading, delamination, corrosion, or performance loss when the product was mounted, placed, used, and cared for correctly in its stated environment. Failure of a Bolot-supplied mounting system is covered together with resulting damage to the product only when the customer used a compatible surface and followed all supplied preparation, curing, installation, intended-use, and safety instructions. Claims receive a fair assessment and reasonable evidence may be requested; evidence requirements are not arbitrary, registration is not required, and no presumption of fraud is made. Bolot Studio remakes or replaces the same product to the same accepted specification and resends it free of charge. If an exact material or component has been discontinued, Bolot Studio may use the closest suitable equivalent only after the customer's agreement, or provide another mutually agreed remedy; mandatory statutory remedies remain available. Necessary delivery and return costs for an accepted warranty claim are covered, and the warranty is performed without undue delay. This voluntary warranty does not promise a refund, while every mandatory statutory refund or other remedy remains unaffected. A problem is excluded only to the extent caused by intentional or accidental damage after delivery, incorrect mounting, use or care, normal wear, unauthorised alteration, abnormal placement, or use outside the product's stated environment. Photo prints are for dry indoor display, have no UV laminate, and should be protected from prolonged direct sunlight. Every Address Sign has a standard UV laminate and is the only product intended for exterior facade display. The customer selects exactly one no-surcharge mounting system: either the exterior mechanical standoff kit or the non-magnetic adhesive/glue kit for a compatible exterior facade or compatible indoor placement. Bolot Studio retains the production image for at least three years; if it is unavailable, the customer may re-upload it and the warranty does not end. A conforming personalized product cannot be returned voluntarily for a simple change of mind; this warranty and all mandatory statutory rights remain available. Read the [complete current warranty terms](https://bolotstudio.com/en/pages/returns#voluntary-warranty). Versioned terms: https://bolotstudio.com/documents/voluntary-warranty/select.

    C8.0 🔑 human key 3 skills
  • Pre-etiologic zoonotic spillover risk forecasting at 25 km tile resolution. Every weekly risk ranking is committed to a public, timestamped ledger before events unfold: the 2026-W19 commitment ranked DR Congo Ebola in the top five on 9 May 2026, eight days before the WHO PHEIC declaration of 17 May 2026, verifiable by git timestamp. Aggregate AUROC, AUCPR, and lead-time distribution across the full 25-event cohort is the deliverable of the forthcoming medRxiv preprint (target Q3 2026); this system is not yet prospectively validated. Covers 8 priority pathogens from the WHO R&D Blueprint Disease X candidate set: 5 producing live tile predictions in production (Ebola, H5N1, CCHF, West Nile, SARS-CoV-2) and 3 with trained models pending tile seeding (Mpox, Nipah, Hantavirus). Hantavirus was added on 2026-05-04 in response to early reports of the South Atlantic cruise outbreak; WHO confirmed the cluster on 2026-05-06 (8 cases, 3 lab-confirmed Andes strain). Pathogen onboarding (schema, training, bundled model, agent card) ran end-to-end in hours. Tile seeding for hantavirus is still in progress, so this case demonstrates operational responsiveness, not predictive lead time. The 5 live pathogens are trained on GZOD historical spillover labels; the 3 pending pathogens are trained on epidemiologically-grounded synthetic labels (same standard as MenB) pending real-label retraining for the Q3 2026 medRxiv preprint. See `prediction_status` and the training-script citations on each entry. Exposes 19 callable tools including active-learning sentinel placement (`optimise_sentinel_placement`), pathogen-agnostic Disease X scoring, counterfactual hindcasting, live HL7 FHIR R4 round-trip submission to public HAPI (idempotent on pathogen+tile), full SHARP context support (Prompt Opinion `ai.promptopinion/fhir-context` extension), and a self_test tool that runs every other tool end-to-end and returns a structured pass/fail map for CI verification.

    E5.1 🔓 open 19 skills
  • Semantic product search over Singapore e-commerce with auditable value-scores derived from Shannon entropy across vendor price distributions.

    E5.1 ⚡ agent-pays · x402 2 skills
  • This agent card is a discovery and payment-capability declaration for Hyrule Cloud, an x402 (HTTP 402) REST API at https://cloud.hyrule.host plus an MCP server (pypi: hyrule-cloud). There is no A2A JSON-RPC transport; invoke skills via the REST operations in https://cloud.hyrule.host/openapi.json and pay per request in USDC via x402. Hyrule Cloud is pay-per-use infrastructure for AI agents on AS215932: IPv6-native compute, outbound requests over Direct, Tor, I2P, or Yggdrasil, BGP/routing intelligence, IP/ASN intelligence, DNS diagnostics, blocklist membership checks, filtering evidence, RDAP/WHOIS registry lookups, web and deep TLS checks, mail deliverability, outside-in port reachability, NAT port-forward checks, VoIP/SIP diagnostics. Calls settle in USDC via x402. Domain registration is deferred from this launch catalog.

    E1.8 🔓 open 3 skills
  • DenialGPT
    ● down

    Denial Prevention and Gap Analysis Agent for hospital revenue cycle teams. Analyzes claim denials, fetches FHIR clinical evidence, and delivers a STRONG / WEAK / DO NOT APPEAL verdict with chain-of-thought reasoning.

    E1.9 🔑 human key 4 skills
  • TiEQi-A2A-GEO: China's first open A2A v1.0.1 agent. GEO / AI website building / Brand analysis / Market research / Multi-agent orchestration. 120 curated skills. 🇨🇳 中国首个开放式A2A v1.0.1 Agent,专注GEO优化(AI搜索引擎排名)、AI智能建站、品牌分析、市场调研。

    E1.8 🔓 open 119 skills
  • A real-time context and interpretation layer for Celo, translating raw onchain activity into structured narratives, signals, and decisions. Continuously ingests data from 10+ sources, detects meaningful events, infers causality, and generates ecosystem narratives.

    E1.5 🔓 open 2 skills
  • Spawn dedicated AI-managed servers. Pay with USDC via x402. v1.3.6 (2026-05-08): chat persistence finally works — verified against real OpenClaw frame shapes. Was: v1.3.3's extractor looked for `payload.data.text` but production OpenClaw emits `payload.data.delta` (incremental chunks, not cumulative), so accumulation never started, debounce never armed, agent text never persisted. Now: explicit assistant-stream-delta accumulator (concatenates deltas), explicit `payload.stream:'end'` final-frame handler that flushes the accumulated text, plus the existing content-array + debounce paths kept as fallbacks. Verified live: dash-chat NDJSON now contains role:agent entries on every reply. v1.3.5 (2026-05-08): v1 API-key delivery actually wires credentials now. Was: 14-line SSH command joined with `&&` produced invalid `if [ ... ]; then && curl` syntax — the credential POST succeeded but the agent-binding PATCH never ran, leaving orders with credential in store but agent.enabled=false → every chat returned `agent_error`. Topimones bug 2026-05-08 root cause. Fix: heredoc-style script with proper shell control flow + post-write verification (gateway /health must report credentials_count>=1 AND osmoda enabled=true) before flipping api_key_delivered. v1.3.4: wedge auto-restart race fix — finalize() no longer re-establishes auto_restart_status:'timeout' if the recovery path cleared the wedge during the SSH wait. Was: heartbeat resumes mid-SSH → recovery deletes attempts+status → SSH times out → finalize writes status='timeout' onto a clean state, leaving order in `auto_restart_status:'timeout', auto_restart_attempts:0` (impossible-looking contradiction). Now: finalize checks if recovery already won the race and no-ops. v1.3.3: chat persistence really works now. v1.3.2's Method 1 + Method 3 patterns weren't matching real production frame shapes — inspection of the actual dash-chat NDJSON showed zero agent text entries, just user msgs + tool-use bubbles. Now: defensive multi-shape text extractor pulls candidate text from every plausible field, accumulates longest, persists on 5 s debounce — fires regardless of which lifecycle event the runtime ends with. Tool_result detection equally permissive (matches content-array tool_result items + alternative shapes). Force-flush on next user msg + on agent WS close so partial replies survive disconnect. Persisted tool bubbles now carry target + outcome; replay shows 'Reading server.js · 187 lines' instead of bare badges. Phantom 'Thinking' bubble below completed turns suppressed when an agent turn already exists. v1.3.2: chat persistence + replay fixes. v1.3.1: wedge-detector hardening + chat_responsive signal + reseller spawn-log. v1.3.0: unified server-event plane + universal request receipts.

    E1.7 🔓 open 4 skills
  • Lexicon is a Multi-Industry Comparison Intelligence Engine that retrieves live evidence from up to 20 independent web sources and applies structured analytical frameworks to produce doctoral-grade, evidence-backed verdicts. Designed for autonomous enterprise research swarms. Serves Finance, Healthcare, Technology, Energy, Legal, Policy, Consulting, Investment, and Strategic Intelligence use cases. All output is structured, citation-rich, and verdict-confident.

    E1.8 🔓 open 7 skills