Live on x402 — pay per request, no signup

Security & automation for the agent economy

We scan the MCP ecosystem daily, publish what we find, and run the same engine against your fleet. AI agents pay per request over x402 (USDC on Base, no account, no signup — the HTTP 402 flow handles everything). Humans can order by email.

18
scanner rules
100
servers scanned
338
verified findings
44%
had open handshakes

For agents & APIs — pay per call with x402

Machine-to-machine pricing on the x402 rail: your agent hits the endpoint, gets a 402 with payment terms, pays USDC on Base, retries with the receipt. Zero human in the loop.

Basic security scan

$0.50
per endpoint

18-rule FlowSentry scan of any MCP or x402 endpoint: auth posture, header hygiene, transport config, known design-flaw patterns. Returns structured findings with severities.

POST https://flowsentry-agentpay2.vercel.app/v1/scan · x402 · $0.50 USDC on Base

Agent trust check

$0.05
per server

Fast trust signal before your agent talks to a third-party MCP server: live handshake test, auth gate status, header hygiene, DNS liveness. Built for pre-call gating.

GET https://flowsentry-agentpay2.vercel.app/v1/trust · 94 servers indexed

Whitelist feed

$1.00
per month

Daily machine-readable feed of vetted, scan-clean MCP endpoints for your agents to consume. JSON + RSS. Your agents only touch endpoints that passed yesterday's scan.

Delivered at a0flow.com/feed.json · order by email

Compliance report

$2.00
per server

Human-readable report: findings mapped to severity, evidence for each check, remediation steps. Suitable for vendor security reviews of AI tooling.

Custom scan + report · order by email

Bulk scan

$20.00
up to 100 endpoints

Scan your whole MCP fleet in one run: registry inventory, per-endpoint findings, fleet-level risk summary, re-scan on fix. The same pipeline behind our public reports.

Batch order · order by email

For teams — custom work

Delivered by the same team that runs the scanner. Email us with scope; everything lands with a verification artifact.

Custom n8n / automation build

$230–$380
per project

Custom workflow automation in n8n or your stack: spec to working automation in 24-48h. Security-first by default — secrets handling, least-privilege webhooks, audit trail.

24h security fix service

from $150
per incident

Found a hole in your MCP deployment or automation? We deliver a tested fix within 24 hours: patched config, verification scan, and a short postmortem.

MCP Security Report for your fleet

from $50
per engagement

We scan your whole MCP fleet the way our published research scans the public registry — and give you a prioritized fix plan.

"44% of live MCP servers accept an unauthenticated handshake — and 86% ship no Content-Security-Policy. We found placeholder entries the official registry never validated. The deployment layer is the gap nobody owns."
— from our public MCP Security Report (flowsentry.vercel.app/mcp-report), scanning 100 live registry servers

How to order

  1. Agents: call the endpoint — the 402 response carries exact terms and the payee address. Humans: email the form below with what you need.
  2. Pay in USDC on Base: automatic via x402, or send to the wallet below and include the tx hash.
  3. Scans return immediately; reports and custom builds land in your inbox within 24-48h.

Why us

Our scanner runs daily against the public MCP registry — 44% of live servers accept an unauthenticated handshake, 86% ship no Content-Security-Policy. We found placeholder entries the official registry never validated. The same engine (18 rules, Python + in-browser JS) scans your endpoints.

Security-first, self-hosted-friendly, privacy-by-design: we store what you pay for and nothing else.

Order by email — fast path