MCP server for AgentMetal — an AI agent can discover, pay (USDC via x402 or card), provision, SSH into, and run commands on its own Linux VPSes over HTTP 402. No signup.
AgentMetal MCP server demonstrates strong definition quality with comprehensive, well-structured tool definitions. All 14 tools have clear names following verb_noun conventions (provision_, get_, list_, extend_, destroy_, etc.), and all include detailed descriptions explaining both the what and the when/why. Input schemas are consistently defined using Zod with proper types and descriptions. However, there are notable gaps in output schema documentation, error handling guidance, and some parameter relationships lack clear interdependency documentation. Tool names are precise and action-oriented; descriptions are substantive (100-300+ chars, well above the 34-char baseline minimum). The server handles sensitive operations (financial transactions via x402, SSH access, destructive operations) with clear risk labeling. Main weaknesses: no documented output schemas in the MCP registration; missing confirmation/dry-run patterns for irreversible operations (provision, extend, destroy); limited error recovery guidance beyond basic field constraints.
Start an email claim: the API emails a one-time code to verify control of an email address and claim servers or create an account.
Permanently destroy a server RIGHT NOW, before its lease expires. IRREVERSIBLE — the VM and all its data are deleted and remaining lease time is NOT refunded. Requires an account API key (AGENTMETAL_API_KEY); without one this returns an auth error. Use to free quota or stop holding an unneeded box. To let a box expire naturally instead, simply do not extend it.
Run a command as root on a managed-key server via SSH. Requires an account API key (AGENTMETAL_API_KEY) and a server provisioned with managed_key:true. Bounded by timeout_seconds.
Extend an existing server's lease so it is not auto-destroyed at expiry. SPENDS REAL USDC — signed on-chain via x402 (Base) up to the per-call spend cap; a real charge. Adds `days` days to the current expiry and returns the new expiry (unix seconds). Use before a lease runs out to keep a box alive; check the current expiry first with get_server.
List available server plans (size + price), the regions servers can run in, and add-on pricing for bandwidth and storage. FREE — read-only, charges no money and needs no wallet or account. Call this FIRST to see what sizes, regions, and prices are on offer before provisioning a server.
Output schemas not documented in MCP tool registrations. While descriptions explain what tools return, there are no formal JSON Schema definitions for response structures, forcing LLMs to infer response shapes.
No dry-run or confirmation pattern for irreversible operations (provision_server, extend_server, destroy_server). Agents making financial or destructive mistakes cannot be easily prevented.
Parameter interdependencies not clearly documented. manage_firewall has optional protocol, port, source_ips, unclear when each is required/forbidden. verify_claim has optional wallet and wallet_signature that appear to require each other but this is not stated.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 67 | 2026-07-28+ | v2 |
Hypervisor-level diagnostics for a server: recent actions, a VNC console, and live metrics. Requires an account API key (AGENTMETAL_API_KEY) and ownership of the server.
List a server's edge-firewall rules. Requires an account API key (AGENTMETAL_API_KEY) and ownership of the server.
Look up one server's live status (provisioning | running | suspended | expired | destroyed), public IPv4, lease expiry (unix seconds), and bandwidth usage. Read-only — never charges money or changes the server. Use to confirm a box is up and reachable, or to see how long it has before auto-destroy.
List every server (the fleet) for a payer wallet, or for the whole account when an account API key is configured. Read-only — never charges or changes anything. Defaults to the wallet configured on this MCP server; pass `wallet` to list a different payer. Use to enumerate active boxes before calling extend_server or destroy_server.
Open or close a port on a server's edge firewall. Requires an account API key (AGENTMETAL_API_KEY) and ownership of the server.
Provision a brand-new Linux VPS and pay for it in a single call. SPENDS REAL USDC — the payment is signed on-chain via x402 (Base) up to this MCP server's per-call spend cap; it is a real charge, not a quote or a dry run. Returns the server id (srv_…), public IPv4, and an `ssh root@<ip>` target, usually reachable in under 60 seconds. Use when an agent needs its own compute to build, run, or host something with no human signup. Pass `ssh_key` to get inbound SSH; omit it and the box boots with no way to log in. The lease lasts `days` days, after which the server is automatically destroyed unless you extend_server first.
Soft-reboot a server (graceful ACPI restart) without destroying it or losing data. Use to recover a box that has become unresponsive or to apply changes that need a restart. Requires an account API key (AGENTMETAL_API_KEY) and ownership of the server; without one this returns an auth error. Does not charge money. Returns immediately with status "rebooting"; the box is back in well under a minute.
Generate the EIP-191 message to sign for wallet linking during claim verification. Use the result as the message to sign with an EVM wallet; pass the signature to verify_claim as wallet_signature.
Complete an email claim, receiving an account API key. Optionally link a wallet by providing a wallet_signature to prove control.
Limited error recovery guidance. Tools like exec_command, get_server lack explicit error messages guiding the LLM on retry vs. user action vs. fatal failure. E.g., exec_command timeout: should agent retry? Increase timeout? Or is the server unreachable?
list_servers lacks pagination parameters (limit, offset, cursor). If a user/agent manages hundreds of servers, this tool could return massive lists and blow the context window.