Crypto-paid, no-KYC VPS hosting that AI agents can rent and operate end-to-end over MCP: discover plans, create an account, top up with crypto, order a VPS, then control it (power, hostname, reinstall, metrics).
The EQVPS server demonstrates solid schema discipline with all 21 tools having clear input schemas and descriptions. Naming follows consistent verb_noun patterns (list_*, get_*, register_*, order_*, power_*, etc.). Most descriptions are informative and state action intent. However, there are critical gaps in parameter descriptions, missing output schema documentation, and incomplete error handling guidance. Tools like `cancel_service` and delegation tools are defined in source but missing from the published .well-known/mcp.json (only 15 of 21 tools listed). This discrepancy suggests incomplete tool registration. Parameter descriptions lack detail on constraints, formats, and ranges (e.g., `hostname` parameter has no format specification, `amount_usd` lacks min/max bounds). No tools declare output schemas or explain what fields agents should expect in responses. Error handling is minimal, no recovery guidance for common failures (e.g., 'Invoice not found' or 'Insufficient balance'). Destructive tools (reinstall_vps, cancel_service) include confirmation parameters but lack explicit dry-run or confirmation-request patterns.
Accept a delegation invite using the token from the invite link. Returns a Bearer token for the delegated account.
Cancel a VPS: 'end_of_period' (safe default — runs until the paid period ends) or 'immediate' (destroys VM + data, requires confirm=hostname).
Grant OPERATOR access to one of your VPS to another person by email (power/reinstall/console/hostname/rDNS, not billing). Sends an invite; optional time limit. Owner-only.
Return prepaid credit balance and currency.
Time-series resource metrics (CPU, memory, network, disk) for a VPS.
Full detail for one VPS: status, specs, live VM state/uptime, SSH access.
Tool registration mismatch: 6 tools (cancel_service, delegate_service, accept_delegation, list_delegations, list_delegated_to_me, revoke_delegation) are defined in source code but absent from published .well-known/mcp.json. Only 15 of 21 tools are advertised. This breaks client discovery and violates single source of truth.
No output schemas documented for any tool. LLMs cannot plan downstream calls or extract return values. Example: order_vps should document return type (service_id, status, specs, billing_cycle). Tools returning lists (list_vps, list_plans) lack pagination (limit, offset, total_count) declarations.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | B | 71 | 2026-07-28+ | v2 |
List services other owners delegated operator access to you.
List outgoing delegations you granted — who has operator access to what, and its status.
List available VPS plans with pricing, specs and OS images. Public — no auth.
List the account's VPS services (id, status, plan).
Log in with email + password; returns a Bearer token.
Order a VPS by plan slug + OS id (pays from prepaid balance).
Initiate crypto payment for an owned unpaid invoice; returns a checkout URL.
Power-control a VPS: start, stop or reboot.
Create an EQVPS account programmatically (no human/KYC/OTP step). Returns a Bearer token.
DESTRUCTIVE: wipe and reinstall the VPS with a given OS image.
Reset the VPS root password.
Revoke a delegation by id (owner revokes, or delegate declines). The other side is notified.
Set the VPS hostname (DNS label; applied on reboot/rebuild).
Create a crypto top-up invoice; returns a PayRam checkout URL. Pay in USDC/USDT on Base or Ethereum.
Return the authenticated account profile.
Parameter descriptions lack actionable constraints and formats. Examples: 'hostname' parameter (set_hostname, order_vps) has no format spec (DNS label rules); 'amount_usd' (topup_balance) has no min/max bounds; 'plan' (order_vps) references 'e.g. nano' but no enum of valid plans (should reference list_plans or declare enum); 'range' (get_vps_metrics) lacks format guidance (accepted formats: '1h', '24h', etc.). Forces LLMs to guess valid values.
Destructive operations (reinstall_vps, cancel_service with mode='immediate') use a 'confirm' parameter for hostname matching, but lack explicit dry-run support or confirmation-request pattern. No tool offers 'confirm_destructive_operation' two-step workflow. Agents cannot safely preview consequences before executing irreversible actions.
No error handling guidance. Tools lack descriptions of failure modes or recovery steps. Example: order_vps can fail with 'Insufficient balance', 'Invalid plan', 'OS not available for plan', but no tool documents these scenarios or suggests next steps (check balance via get_balance, list available plans via list_plans). Agents cannot self-correct on failures.
Authentication flow is undocumented in tool descriptions. Tools like register_account, login state they return a 'Bearer token', but nowhere do tool descriptions explain HOW to use that token in subsequent calls (Authorization header, parameter, etc.). This forces agents to infer the authentication mechanism from context.
'email' parameter in delegate_service and register_account/login lacks validation hints. No description states whether email format is validated, whether addresses must be real, or whether duplicate registrations are allowed. Agents may attempt invalid emails without guidance.
Tool composition gaps: No batch operations. Agent calling delegate_service multiple times to grant access to many users must repeat the call per user. No 'delegate_service_batch' or array parameter support. Token waste and latency impact for common workflows.