Xpex Plugin Factory

io.github.xpex-systems-aiv0.4.1Updated Oct 2, 2026

MCP plugin factory and x402 Agent Kit API for external agents, at 0.01 USDC per call.

VerifiedStreamable HTTPWeb executableAI & MLDeveloper Tools

Overview

AI-generated overview

Lets an assistant validate JSON blueprints and compile them into review-ready OpenAI/Codex plugin packages with MCP manifests, skills, and a deterministic ZIP.

What it does
The server exposes a no-auth MCP endpoint for read-only offer discovery and computation-only plugin generation. Its tools list offers, return the blueprint schema, validate a blueprint, preview a plugin, and compile a plugin package. Compilation produces plugin and MCP manifests, skill files, an SVG branding asset, a README, a factory report, and a deterministic ZIP returned as base64. A separate paid API generates a read-only starter kit for 0.01 USDC per call.
When to use it
Use it when you want an assistant to turn a structured product blueprint into a packaged agent plugin, or to check a blueprint against the factory's schema and security policy before packaging. It suits plugin packaging, MCP architecture, reusable skills, and readiness or blueprint validation work.
Requirements
The MCP endpoint is remote and needs no authentication or API keys. The paid agent-kit endpoint requires USDC payment to be enabled and accepted before delivery. The README also describes a local Node.js workflow with npm install, build, and a CLI, plus a Stripe webhook secret configured only as a runtime secret.
Before you install
The paid agent-kit call costs 0.01 USDC per call and is delivered only after provider-accepted payment. The README states agents must never send private keys, seed phrases, API secrets, bearer tokens, or other credentials to the factory. The MCP surface does not publish plugins or mutate third-party systems, but compiled packages should still be reviewed before use.

Installation

In SourceWeft

  1. Open Xpex Plugin Factory in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.

Other MCP clients

Add this to your client's mcpServers config.

{
  "mcpServers": {
    "xpex-plugin-factory": {
      "type": "http",
      "url": "https://xpex-plugin-factory-production.up.railway.app/mcp"
    }
  }
}

README

XPeX Plugin Factory

Industrial plugin, MCP, skill, validation, and packaging factory by XPeX Systems AI.

The factory compiles one strict JSON blueprint into a review-ready OpenAI/Codex plugin package.

Live Factory: https://xpex-plugin-factory-production.up.railway.app
Hire XPeX Plugin Factory: https://xpex-plugin-factory-production.up.railway.app/pricing
Readiness Audit — R$49: https://buy.stripe.com/8x214nbyrgrpaYZ2Ah1B60f

What it generates

  • plugin.json
  • .codex-plugin/plugin.json
  • mcp.json
  • .mcp.json
  • one or more skills/*/SKILL.md
  • generated SVG branding asset
  • package README
  • FACTORY-REPORT.json
  • deterministic ZIP artifact

Pipeline

text
Blueprint   ↓Schema validation   ↓Security policy engine   ↓Manifest + MCP + Skill compiler   ↓Factory report   ↓Deterministic ZIP

Fast start

bash
npm installnpm run checknpm testnpm run build
node dist/cli.js generate \  examples/gxeon-agent-gateway.blueprint.json \  --out ./generated/gxeon

HTTP API

Start the factory:

bash
npm run dev

Endpoints:

text
GET  /healthGET  /v1/schemaGET  /mcpPOST /mcpPOST /v1/validatePOST /v1/previewPOST /v1/package

Validate a blueprint

bash
curl -X POST http://localhost:8080/v1/validate \  -H "Content-Type: application/json" \  --data @examples/gxeon-agent-gateway.blueprint.json

Generate a ZIP

bash
curl -X POST http://localhost:8080/v1/package \  -H "Content-Type: application/json" \  --data @examples/gxeon-agent-gateway.blueprint.json \  -o gxeon-agent-gateway.zip

Security gates

The V1 compiler rejects or warns on:

  • embedded API keys, bearer tokens, Stripe secrets, private keys, and GXEON machine keys;
  • localhost/private-network MCP endpoints;
  • non-HTTPS MCP endpoints;
  • sensitive/account data exposed through anonymous MCP;
  • write-capable plugins without human approval;
  • machine-key plugin surfaces that need an OAuth boundary for user-linked public distribution;
  • commerce configurations that require a current policy review.

Runtime credentials are never generated into plugin packages.

Reference blueprint

examples/gxeon-agent-gateway.blueprint.json is the first real reference product compiled by this factory.

Architecture

See:

Deployment

A production container and railway.toml are included. The service exposes /health for readiness checks.

Philosophy

XPeX Plugin Factory is not a prompt generator. It is a software supply-chain compiler for agent products:

text
PRODUCT IDEA   ↓BLUEPRINT   ↓POLICY   ↓PLUGIN + MCP + SKILLS   ↓TESTS   ↓PACKAGE   ↓PRIVATE / WORKSPACE / REVIEW PIPELINE

Built by XPeX Systems AI.

Production

Factory V1 is live at:

text
https://xpex-plugin-factory-production.up.railway.app

Health: /health · Schema: /v1/schema · Validate: POST /v1/validate · Preview: POST /v1/preview · Package: POST /v1/package

Agent-native factory access

Factory V0.3.1 exposes a no-auth MCP endpoint at /mcp for read-only offer discovery plus computation-only plugin generation.

Available tools:

  • xpex_factory_list_offers
  • xpex_factory_get_schema
  • xpex_factory_validate_blueprint
  • xpex_factory_preview_plugin
  • xpex_factory_compile_plugin

The MCP surface never publishes plugins and never mutates third-party systems. ZIP compilation is deterministic and returned as base64 for MCP clients that need a portable artifact.

Monetization V1

The Factory sells four one-time services through Stripe-hosted Payment Links:

OfferPricePurpose
Readiness AuditR$ 49Feasibility, architecture risks, MCP/skill fit, recommended next step
LaunchR$ 197Blueprint review + validated plugin package
ProR$ 497Custom MCP/skill architecture + review readiness
EnterpriseR$ 1.497Advanced business integration architecture

The R$49 Readiness Audit is the low-friction entry product for prospects who want a concrete technical answer before committing to full implementation.

Live sales surface:

text
GET /pricingGET /v1/offers

The payment flow is intentionally fail-closed:

text
Factory pricing page  -> Stripe LIVE hosted checkout  -> Stripe signed webhook  -> signature verification  -> payment_status == paid  -> verified payment event

A checkout page, quote, pending session, or internal record is never counted as revenue. Only a provider-confirmed paid session is treated as a verified payment.

The production webhook endpoint is:

text
POST /stripe/webhook

Configure STRIPE_WEBHOOK_SECRET only as a runtime secret.

Agent discovery & procurement

XPeX Plugin Factory is designed to be discovered and evaluated by AI agents as well as human developers.

  • Agent-readable discovery document: public/llms.txt
  • Live offer catalog: GET https://xpex-plugin-factory-production.up.railway.app/v1/offers
  • MCP endpoint: https://xpex-plugin-factory-production.up.railway.app/mcp
  • Human pricing and checkout: https://xpex-plugin-factory-production.up.railway.app/pricing

Recommended agent flow:

text
discover XPeX  -> read llms.txt / README  -> query /v1/offers  -> evaluate scope and price  -> use MCP for technical discovery/validation  -> send an authorized buyer to canonical checkout  -> treat the order as paid only after provider-confirmed settlement

Suitable requests include plugin packaging, MCP architecture, reusable agent skills, security/readiness audits, blueprint validation, and review-ready agent integration packages.

Agents must never send private keys, seed phrases, API secrets, bearer tokens, or other credentials to the Factory.

Agent API — USDC per call

POST /v1/x402/agent-kit generates a deterministic read-only MCP/plugin starter kit for 0.01 USDC. Deliverables: blueprint, files, policy report, ZIP and SHA-256. See live configuration, OpenAPI, and integration/runbook. Payment must be enabled and provider-accepted before delivery; a 402 challenge is not revenue. Existing full-blueprint APIs remain free.

Source: README.md at commit ec20a7c

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.4.1LatestOct 2, 2026