
Agent Output Verifier
io.github.mglbagiv0.3.2更新于 Oct 1, 2026
Independently verify an agent's output before you pay.
概览
让助手按 JSON Schema 和自定义规则检查其他代理的结构化输出,返回通过/失败、评分、修复提示和签名凭证。
- 功能
- 通过托管的 Streamable HTTP 端点提供两个 MCP 工具:verify_schema 依据调用方提供的 JSON Schema 和可选规则,对结构、格式、取值范围和跨字段规则(例如各行小计之和必须等于总计)做确定性检查;get_verification_record 按 agent_id 查询某代理的信任评分。验证结果包含通过/失败、检查通过百分比、修复提示,以及可用服务公开公钥核验的 Ed25519 签名证明与凭证。compact 模式只返回摘要、凭证字段和签名。
- 适用场景
- 适合在助手或工作流收到其他代理或卖方产出的结构化数据时,在采纳或付款前做一次独立且带签名的检查。卖方也可在提交前用它校验自己的输出并附上证明。
- 运行要求
- 远程托管服务,无需本地安装、账号或注册。MCP 端点通过 Streamable HTTP 访问。每个工具每天有 3 次免费调用;超出后需以 x402 v2 在 Base 或 Solana 上支付 USDC,支付信息放在 MCP 请求的 _meta 中的 x402/payment,或在 REST 上使用标准 x402 支付头。需要能访问该服务的网络。
安装
在 SourceWeft 中
- 打开 控制台中的 Agent Output Verifier,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。
其他 MCP 客户端
把它添加到你客户端的 mcpServers 配置中。
{
"mcpServers": {
"agent-output-verifier": {
"type": "http",
"url": "https://fastapi-service-5ag4.onrender.com/mcp"
}
}
}README
Agent Output Verifier
Independently verify an agent's output before you pay.
Independent, deterministic checks of structure, formats, ranges and cross-field rules, such as "line totals must equal the total," against your own requirements, written in standard JSON Schema plus optional rules. Returns pass/fail, the percentage of checks passed, fix hints, and an Ed25519-signed attestation and receipt that anyone can verify with our public key. Sellers: check your own output before you submit it, and deliver it with a signed attestation and receipt. No signup: pay per call with x402 v2, in USDC on Base or Solana. 3 free calls a day through MCP.
This repository is documentation and public metadata for the hosted service — there is no source
code to install or run here. The service itself is a live API at
https://fastapi-service-5ag4.onrender.com.
Endpoints
Two MCP tools are exposed over the same endpoint: verify_schema (POST /verify/schema) and
get_verification_record (GET /score/{agent_id}).
Pricing and networks
Paid per call with x402 v2, in USDC, on either network below — no account or signup required:
/.well-known/x402 and the Payment-Required header of a live 402 response always carry the
exact live prices, pay-to addresses and asset addresses — treat them as the source of truth, and
this table as a quick reference.
Free trial
Each MCP tool carries its own free-trial allowance: 3 free calls per day, available over MCP.
After that, a call requires an x402 payment carried in the MCP request's _meta under
x402/payment, or a standard x402 payment header on REST.
Verifying a receipt, step by step
Every response from /verify/schema and /score/{agent_id} carries a signed verify section and
an attestation block, for example:
Nothing but the response itself and verify.public_key_url is needed:
- Fetch the public key.
GETthe agent-card atverify.public_key_url. Itscapabilities.extensionsarray has an entry whoseuristarts withurn:json-schema-verifier:extension:attestation:; itsparams.publicKeyslists every key the service has ever signed with, each{keyVersion, algorithm, publicKey}(the raw 32-byte Ed25519 public key, base64-encoded). Pick the entry whosekeyVersionequalsresponse.attestation.key_version. - Rebuild the signed document. It's a JSON object with exactly these five keys:
contextisjson-schema-verifier/verify-schema-attestation/v1for/verify/schemaresponses, orjson-schema-verifier/trust-score-attestation/v1for/score/{agent_id}responses. - Canonicalize it with RFC 8785 (JCS): UTF-8 bytes of the JSON document above, object keys
sorted recursively, no insignificant whitespace, numbers printed the way ECMAScript prints them
(
1.0becomes1). - Verify the Ed25519 signature (
response.attestation.signature, base64-decoded) over those canonical bytes, using the public key from step 1. - Check the four receipt hashes, each SHA-256 over the RFC 8785 (JCS) canonical JSON of the
named value:
output_hash(ofsubmitted_output),schema_hash(ofexpected_schema),rules_hash(of{"bounds": ..., "rules": ...}), andrequest_hash(of the whole request as parsed, full detail only). Recompute them yourself and compare — this is what binds the receipt to the exact data that was checked.
A minimal Python verifier, using only the standard library plus cryptography:
Tested against both receipts in the worked example below — both verify True.
Worked example: invoice verification
Both calls below are genuine, live, paid calls against the production service — real x402
payments on Base, settled on-chain, with the resulting signed receipts shown exactly as received.
Both are independently verifiable: fetch the agent-card above, confirm key_version: v1-2026-09c
is listed, and verify each attestation.signature with the steps above.
1. Draft invoice — fails on a cross-field rule (detail: "full")
Request:
The line items sum to 129.5, but total says 135.0. With enforce_rules: true, that rule
violation fails the result and comes with a fix hint:
Payment evidence: $0.02 USDC on Base, settled on-chain —
0x4cb755c71413ed5419215d2d7445c34e19be79d9f15b4046802656165b774897.
2. Corrected invoice — passes (detail: "compact")
Same schema and rule, total fixed to match the line items (129.5), requested with
"detail": "compact" to get back only the summary, receipt fields and signature:
The compact shape keeps the summary, receipt fields, verify and attestation; request_hash,
errors, errors_detail, flags, hints and the three scores stay in the full shape (see
detail above).
Payment evidence: $0.02 USDC on Base, settled on-chain —
0xaa9161736ac410b6ac9ccc478780aa2feaa6d2cf02af4c51855e099c14499079.
Verifying these two receipts yourself
Both responses above were checked against the live agent-card's public key for v1-2026-09c
before being included here, using the steps in Verifying a receipt.
Confirm it yourself the same way: fetch
https://fastapi-service-5ag4.onrender.com/.well-known/agent-card.json, confirm v1-2026-09c is
listed, and re-run the same five steps against the two JSON blocks above — the signatures were
computed once, over exactly this data, and will verify identically for anyone.
agent_id identifies the agent that produced the output being checked — for example, the seller;
it's an unauthenticated label the caller supplies. agent_id: "test-seller-invoice-agent" uses the
test- prefix the service reserves for examples: the verification ran for real, and its receipt is
genuine, while staying separate from that agent's trust score.
License
Documentation and examples in this repository are licensed under the MIT License. The hosted service is proprietary; this repository holds only documentation and public metadata.
来源:README.md,提交 3018261
工具
0版本历史
1- v0.3.2最新Oct 1, 2026