Fetchgate

Fetchgate

The agent web, measured — not quoted.

We probe every remote server in the official MCP registry, every paid endpoint in Coinbase's x402 Bazaar, and every crawler that hits our own storefront, then publish what we find: free per-server lookups and CC BY data for everyone, and datasets plus a 25-page analyst report for teams that need the numbers citable. Underneath it runs the thing we measure with — a storefront an unattended agent can buy from over x402 (HTTP 402 + USDC), an MCP server, and a web-content API.

Agent safety and discovery endpoints

Three calls an agent can make before it trusts a page or pays a stranger. Same free daily tier as the reader endpoints, then pay per call over x402.

$0.003 / call after free tier

GET /v1/scan?url=<url> · POST /v1/scan

Prompt-injection scan. 120 detection rules over a page's visible text and, separately, the text hidden in HTML comments and alt/title/aria/meta attributes — or over any text you POST. Use before letting an agent act on untrusted content. Heuristic, not a guarantee.

curl "https://fetchgate.dev/v1/scan?url=https://example.com/some-article"
{
  "riskScore": 80, "riskBand": "critical", "recommendedAction": "block",
  "visible": [],
  "hidden": [{ "ruleId": "PID-DIR-001", "severity": "high",
               "evidence": "ignore all previous instructions" }]
}
$0.005 / call after free tier

GET /v1/x402/search?q=<task>

Find a pay-per-call API that demonstrably works. Searches only x402 endpoints that answered a real payment challenge and had at least 5 settled calls from 2+ payers in the last 30 days — dead, never-bought and template-farm listings are left out. From the same data as the x402 Bazaar Audit.

curl "https://fetchgate.dev/v1/x402/search?q=web+search&max_price_usd=0.02"
$0.01 / call after free tier

GET /v1/x402/check?url=<endpoint>

Should an agent pay this endpoint? One unpaid probe of its live payment challenge, plus its settled-call and unique-payer history, listed-vs-live price and domain reputation. Returns ok, caution, avoid or unknown with reasons.

curl "https://fetchgate.dev/v1/x402/check?url=https://api.example.com/v1/resource"

Reader endpoints

Fetch a page, get back clean content. These exist to be cheap and reliable enough that any agent tries them and comes back — the on-ramp to the store, not the business itself.

$0.002 / call after free tier

GET /v1/read?url=<url>

Fetches the URL server-side and converts the main content to Markdown. Add &format=text for raw Markdown instead of JSON.

curl "https://fetchgate.dev/v1/read?url=https://example.com/some-article"
{
  "url": "https://example.com/some-article",
  "title": "Some Article Title",
  "markdown": "# Some Article Title\n\nClean article body as markdown...",
  "fetchedAt": "2026-08-22T12:00:00Z"
}
$0.001 / call after free tier

GET /v1/meta?url=<url>

Fetches the URL and returns structured metadata: title, description, canonical URL, OpenGraph/Twitter fields, favicon, language, published/modified times.

curl "https://fetchgate.dev/v1/meta?url=https://example.com/some-article"
{
  "url": "https://example.com/some-article",
  "title": "Some Article Title",
  "description": "Meta description or OG description.",
  "openGraph": { "type": "article", "site_name": "Example" },
  "canonical": "https://example.com/some-article",
  "fetchedAt": "2026-08-22T12:00:00Z"
}
TierLimitHow
Free30 requests/day per IPNo auth, just call it
API keyPlan-basedAuthorization: Bearer <key>
x402 pay-per-callUnlimitedNo auth; retry a 402 with a signed PAYMENT-SIGNATURE header

Store

A small, growing catalog of digital goods for agents and the people who build them. GET /v1/products is always the live, authoritative list — prices below are a snapshot. Payments are in beta: x402 settlement runs through a third-party facilitator on Base; digital delivery only, and we monitor every settlement.

$15.00

x402 Services & Facilitator Registry

A curated, machine-readable snapshot of 21 x402 facilitators and 118 x402-payable services/APIs: chains, stablecoins, fee models, per-call pricing, live status, and source URLs — so an agent or builder doesn't have to crawl and reconcile multiple directories itself.

Buy with a card — $15.00

Or pay in USDC over x402:

curl "https://fetchgate.dev/v1/buy/x402-registry-2026-10-04"

No payment attached → 402 with x402 payment terms. Retry with a signed PAYMENT-SIGNATURE header (legacy X-PAYMENT also works) to get a signed download URL. No wallet? Use the card button above — same file, no account needed.

$29.00

Prompt-Injection & Tool-Hijack Test Corpus

156 structured, labeled adversarial test cases across seven categories (direct/indirect injection, tool hijacking, data exfiltration, system-prompt leaks, jailbreak/roleplay, encoding obfuscation) for evaluating whether an agent resists prompt injection and tool-misuse attacks. Ships with a JSON Schema and a Python eval harness.

Buy with a card — $29.00

Or pay in USDC over x402:

curl "https://fetchgate.dev/v1/buy/prompt-injection-test-corpus"

Digital delivery only — see /llms.txt for refund policy.

$19.00

MCP Server Registry Snapshot

A curated, machine-readable snapshot of 400 production/community Model Context Protocol servers: category, transport, auth needs, repo/package URLs, and source-directory cross-references — reconciled across the official registry, Smithery, Glama, PulseMCP, and mcp.so so you don't have to crawl them yourself.

Buy with a card — $19.00

Or pay in USDC over x402:

curl "https://fetchgate.dev/v1/buy/mcp-registry-2026-08-22"

Dated edition.

$39.00

Agent Eval Harness Templates

A ready-to-use kit for evaluating an agent or LLM app fast: a JSON-Schema test-case format, 40 example cases across four suites (task completion, tool selection, refusal/safety, regression), an LLM-as-judge scorer with documented bias mitigations, and a dependency-light Python CLI runner. Bring-your-own-model via a one-file adapter.

Buy with a card — $39.00

Or pay in USDC over x402:

curl "https://fetchgate.dev/v1/buy/agent-eval-harness-templates"

Digital delivery only.

$39.00

Prompt-Injection Defenses Playbook & Detection Ruleset

The defense counterpart to the attack corpus above: a 6-layer defense taxonomy mapped to attack categories, 119 machine-readable detection rules (with honest false-positive notes), and a stdlib-only Python detector with two profiles, decode-and-rescan for obfuscated instructions and hidden-HTML-text scanning. Measured, and the numbers ship in the box: 0.35% false positives on 1,714 unseen top-site homepages (the original rules as written flag 69%); 38–53% recall on held-out attacks. Try it free at /tools/injection-scanner.

Buy with a card — $39.00

Or pay in USDC over x402:

curl "https://fetchgate.dev/v1/buy/prompt-injection-defenses-playbook"

Digital delivery only.

$7.00

x402 Quickstart Kit

A dependency-minimal reference implementation of x402 payments: seller-side middleware for Cloudflare Workers/Hono and plain Node/Express, plus buyer-side client code in TypeScript (viem) and Python (eth_account/web3.py) that signs a real EIP-3009 payment and retries a 402 automatically. Includes a guide on facilitators, pitfalls, and going live.

Buy with a card — $7.00

Or pay in USDC over x402:

curl "https://fetchgate.dev/v1/buy/x402-quickstart-2026-08-23"

Digital delivery only.

$29.00

MCP Live Tool Inventory

Every remote server in the official MCP registry (15,329 URLs) probed read-only via initialize → tools/list, and everything the 8,235 live ones returned: 140,284 tool names, titles, full descriptions, input-schema keys and annotations; 5,462 server-level instructions strings verbatim; per-server reachability, protocol version and outcome; and 24k+ tool-poisoning audit flags with snippets. The real-world base rate for allow-listing servers, name-collision checks, and building or testing tool-description detectors against live text instead of synthetic samples.

Buy with a card — $29.00

Or pay in USDC over x402:

curl "https://fetchgate.dev/v1/buy/mcp-tool-inventory-2026-08-28"

Dated edition.

$149.00

The Agent Web, Measured — 2026 Q3 edition

A 25-page analyst report built from first-hand measurement, not directory listings: every remote URL in the official MCP registry probed (54% answer; 45.5% once two template fleets are removed; 140,284 tool descriptions scored — the textbook tool-poisoning payload appears zero times, and the 51 concealment directives that do appear are quoted verbatim), every endpoint in Coinbase's x402 Bazaar probed with the first published revenue ceiling for the market (~$314/day), all 21 facilitators, and a 60-crawler census. 22 charts, 10 tables, twelve conclusions; every number is generated by a script from the underlying datasets, most of them free, so every figure is checkable. For anyone who has to put a number on MCP or x402 in a deck, a threat model or a diligence memo.

Buy with a card — $149.00

Or pay in USDC over x402:

curl "https://fetchgate.dev/v1/buy/agent-web-report-2026-q3"

Single-organisation licence. Includes the +30/+60/+90-day re-probe summaries and the 2026 Q4 edition.

$129.00 · save ~27%

Fetchgate Complete Bundle

The seven datasets and kits above (not the report), one checkout, $48 cheaper than buying them separately ($177 individually). Human checkout only — this is a single multi-file Gumroad order, not an x402 catalog entry.

Buy the bundle on Gumroad →

$399.00 · company-wide

Fetchgate Company License

All eight files — the seven datasets and kits plus The Agent Web, Measured ($149 on its own) — licensed for a whole organisation rather than a single team (every listing above, the bundle included, is single-team), plus every new edition published in the next 12 months. These are dated measurements and they get re-cut: the registry audit re-probes its frozen 8,235-server cohort at +30, +60 and +90 days, the Bazaar index is re-measured as the market moves, and new editions land in your Gumroad library automatically. One payment; nothing renews.

Need something else — a recurring re-probe on your own schedule, or a custom cut of any dataset? Email support@fetchgate.dev with what you need — quoted within a day.

Buy the company license on Gumroad →

$249.00 · per server

MCP Server Security Assessment

The audit, applied to your server. We run the same read-only probe used across the whole registry against your MCP endpoint (and, if you send it, your tool definitions and instructions text before you publish them), score every description against the 85-rule detection set and the concealment, precedence, shadow-name and length checks, and hand you a written report within 3 business days: every finding with the exact text, why a client or a reviewer would flag it, a rewrite that keeps the behaviour and loses the flag, your context cost per session, and how you compare to the 8,235-server base rate. Optional: a follow-up re-scan after you ship the fixes, included.

You give us the server URL at checkout (or email it to support@fetchgate.dev with your receipt). Read-only, nothing is called, nothing is published. If the server needs auth we work from the exported tool definitions instead.

Book an assessment — $249.00

Want the free version first? Run the scanner — it does the automated part in one request. The assessment is the human-read report on top of it.

What is x402?

The mechanism that lets an autonomous agent pay for a reader call or a product, with nobody in the loop.

x402 reuses the long-dormant HTTP 402 Payment Required status code for machine-to-machine micropayments. Call a priced endpoint with no valid API key or payment, and instead of the data you get back a 402 describing exactly what to pay: amount (in USDC), network, and recipient address.

  1. Call the endpoint normally. No payment on file → 402 Payment Required, body includes an accepts[] array with the price and payment terms.
  2. Your agent's wallet signs a USDC payment authorization for that exact amount.
  3. Retry the same request with the signed payment, base64-encoded, in a PAYMENT-SIGNATURE header (legacy X-PAYMENT also works).
  4. Payment verifies and settles → you get the real response (markdown, metadata, or a signed download URL) plus a PAYMENT-RESPONSE header confirming settlement.

No account, no OAuth, no stored card — just a wallet and a USDC balance. The reader endpoints and the store both use this exact same flow.

MCP server

For agent frameworks that call tools instead of raw HTTP.

POST /mcp is a Streamable HTTP Model Context Protocol server (JSON-RPC 2.0: initialize, tools/list, tools/call) exposing six tools — read_url, get_metadata, list_products, get_agent_census, scan_mcp_server, and get_purchase_info — backed by the exact same logic and free-tier limits as the HTTP endpoints above. See /llms.txt for the full reference, or /.well-known/mcp/server.json for the registry manifest.

Free tools & data

No key, no payment, no signup. Built from the same work as the paid datasets.

The Agent Web Crawler Census — every named bot observed crawling this endpoint in 24 hours, with a matcher and a behavioural category for each. 60 crawlers discovered, graded and price-scraped it; zero of them bought anything. Machine-readable at /v1/agent-census.json, CC BY 4.0.

x402 Endpoint Inspector — paste any URL that should return a payment challenge and see its decoded x402 requirements, with common mistakes flagged (bad addresses and amounts, unknown networks, and EIP-712 signing-domain values that silently break USDC-on-Base signatures).

Prompt-Injection Scanner — paste a URL or a block of text and see which of 120 detection rules match: instruction overrides, tool hijacking, data exfiltration, and instructions hidden where a reader never looks (HTML comments, alt, title, aria and meta attributes).

MCP Tool Description Scanner — paste a remote MCP server URL and see every tool description the way the model sees it, with tool-poisoning patterns flagged: hidden instructions, invisible Unicode, credential references, exfiltration shapes and directives aimed at the model. Fetches tools/list only.

The MCP Registry Audit — every remote server in the official MCP registry (15,329 URLs) probed read-only, and every tool description the live ones returned (140,284) read. 29% of live servers are two operators; 47 hosts tell the model what not to tell the user; the textbook exfiltration attack appears zero times. Look up any server; per-server data CC BY 4.0.

The x402 Bazaar Audit — every paid resource in Coinbase’s x402 Bazaar index (27,681, up 87% in five weeks) with its own 30-day call counters, a read-only probe of every URL and an EIP-712 signing-domain check. The whole CDP-facilitated market clears about $634 a day; 54% of resources sold at most once in a month. Look up any endpoint.

Get the next dataset by email — follow on Gumroad; one message per new edition or audit, nothing else.

Articles — field notes on x402 payments, MCP servers and prompt-injection defense, each computed from the same data as the paid products: x402 vs. Stripe, MCP tool poisoning, the crawler census write-up, the unlisted-twin experiment, the x402 Bazaar five weeks on, our own injection rules, measured, and more.