A marketplace where AI agents discover MCP services and buy them from other agents per call in USDC via x402, auto-paid from your wallet — plus a non-custodial USDC-to-bank cash-out (licensed provider), first-party Base chain data and token safety
FiatDock defines 22 tools with explicit schemas and descriptions. Naming is verb-forward (get_, create_, search_, call_) and mostly clear. Descriptions range 50 - 300+ chars and explain WHAT and WHEN. However, critical gaps: (1) Many parameter descriptions are minimal or missing context (e.g., 'Ethereum address (0x-prefixed)' lacks format/validation hints); (2) Output schemas are NOT documented, LLMs cannot infer response structure for chaining; (3) Error handling is absent, no recovery guidance, no categorization of retryable vs fatal errors; (4) Sensitive operations (create_offramp_session, create_onramp_session, call_service, call_x402) lack confirmation/dry-run patterns despite irreversible side effects (money movement, auto-payment); (5) Compliance disclaimers are embedded in descriptions rather than structured as tool metadata. Strengths: all tools have descriptions, schemas are present with types and enums, naming is consistent and action-oriented.
Address intelligence: transaction count, first/last activity, balance history.
Current Base chain block number.
Call a paid MCP service from the marketplace (auto-pays x402 fee from AGENT_PRIVATE_KEY).
Call any x402-priced endpoint (auto-pays x402 fee from AGENT_PRIVATE_KEY).
Start a USDC-to-fiat cash-out session (non-custodial, licensed provider). COMPLIANCE: own-account rule — the sending wallet and the receiving bank account must belong to the SAME person (the agent's owner); no third-party funds, no aggregation, no P2P transfers. 18+; service area: Portugal + supported EU/EEA countries (NOT the UK). Crypto is volatile; not investment advice.
Start a fiat-to-USDC buy session (non-custodial, licensed provider). COMPLIANCE: own-account rule — the sending wallet and the receiving bank account must belong to the SAME person (the agent's owner); no third-party funds, no aggregation, no P2P transfers. 18+; service area: Portugal + supported EU/EEA countries (NOT the UK). Crypto is volatile; not investment advice.
Output schemas not documented. LLMs cannot infer response structure for tool chaining (e.g., what fields does get_quote return? what does token_report include?). This forces agents to guess or make extra discovery calls.
Irreversible write operations (create_offramp_session, create_onramp_session, call_service, call_x402) lack confirmation/dry-run patterns. Agents can trigger money transfers or auto-payments without explicit user approval, risking financial loss.
No error handling guidance. Tools return HTTP status codes or API errors without recovery hints. LLMs cannot distinguish retryable (rate limit, timeout) from fatal (invalid address, insufficient balance) errors, leading to infinite retries or dead-ends.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | C | 62 | 2026-07-28+ | v2 |
Email address validation and deliverability check.
ETH balance of an address on Base chain.
Current Base chain gas price (gwei).
Free status of a FiatDock on/off-ramp order by partnerOrderId.
Free FiatDock quote: rate + all fees itemised (incl. the 1% commission). side=SELL (USDC->fiat, needs cryptoAmount) or BUY (fiat->USDC, needs fiatAmount).
Get details of a specific MCP service from the marketplace (pricing, schema, provider info).
Search the FiatDock marketplace for MCP services by keyword, category, or price.
Search the public x402 index for any priced endpoint (not just FiatDock services).
Stablecoin reserve, collateral, and issuer details (USDC, USDT, DAI, etc.).
Token metadata: name, symbol, decimals, total supply, contract creation block.
Token price on Base chain (via Uniswap, Aerodrome, or other DEX).
Comprehensive token report: price, safety, metadata, holder distribution.
Token safety report: rug-pull risk, contract audit status, holder concentration, liquidity depth.
Transaction status on Base chain (pending, confirmed, failed).
USDC balance of an address on Base chain.
Fetch and parse web page content (HTML to markdown).
Parameter descriptions lack validation context. E.g., 'Ethereum address (0x-prefixed)' does not specify length (42 chars), character set, or checksum validation. LLMs may pass invalid addresses without guidance on what makes an address valid.
Compliance disclaimers (own-account rule, 18+, service area restrictions) are embedded in tool descriptions as free text. They should be structured metadata (e.g., tool tags, scope declarations) so agents can enforce them programmatically and audit trails can track compliance.