Wash-traffic risk checks for Algorand x402 endpoints before your agent trusts or pays them.
Check the wash-traffic risk of Algorand x402 endpoints before your agent pays them.
📊 The x402 Trust Index — our free public leaderboard: weekly Bazaar Wash Report + resale-authorization audits for 38 API brands.
Roughly half of x402 "agentic payment" activity is artificial — self-dealing loops, fresh-wallet farms, metronomic bots. Provenance reads the chain and tells your agent whether an endpoint's revenue is organic or fabricated, so it can decide before sending USDC.
check_endpoint_risk(address) — free quick verdict for any Algorand endpoint
payTo address: risk level (low/medium/high/critical), 0–100 score, and the
on-chain red flags (distinct-payer count, self-dealing payout loops, wallet ages,
timing regularity, funding concentration).provenance_service_info() — service + paid-tier info.Deep forensics are x402-paid on the same API: /score $0.05 · /report $0.50
(full 8-signal grade + facilitator drift) · /diligence $5.00.
Claude Code
claude mcp add provenance -- npx -y provenance-mcp
Claude Desktop / any MCP client (mcpServers config):
{
"mcpServers": {
"provenance": {
"command": "npx",
"args": ["-y", "provenance-mcp"]
}
}
}
Then ask your agent: “check the wash risk of Algorand endpoint <ADDRESS>”.
The hosted Provenance engine indexes USDC (ASA 31566704) payments on Algorand mainnet, enriches payer wallets (age, first funder, asset diversity, rekey auth-addr), clusters them (union-find over funding + shared-key links), and runs 8 wash-detection signals. Scores are point-in-time snapshots, anchored on-chain for tamper-evidence. Methodology: signals, not accusations — a high score means the revenue pattern is consistent with self-dealing, not that the operator is guilty of anything.
PROVENANCE_API_URL to point at a different Provenance deployment.Building an agent that pays over x402? provenance-guard
wraps any x402-paying fetch and runs this same check automatically before any
money moves — one line, zero dependencies:
import { createGuard } from "provenance-guard";
const guarded = createGuard().guardedFetch(fetchWithPayment);
MIT · Provenance — the trust layer for machine-payable endpoints.
Source-derived launch command. Check the maintainer’s required arguments and credentials before running:
npx -y provenance-mcpMerge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.
{
"mcpServers": {
"io-github-apeirontrade-provenance-mcp": {
"command": "npx",
"args": [
"-y",
"provenance-mcp"
]
}
}
}Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.
Claude Desktop setup referenceprovenance-mcpnpmio.github.apeirontrade/provenance-mcp works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.
~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.~/.cursor/mcp.jsonRestart Cursor for changes to take effect..vscode/mcp.jsonReload VS Code window for changes to take effect.~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect..mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.