Limitguard MCP agent

LimitGuard MCP server: KYB, sanctions and PEP screening, company registry checks (KVK, KBO, VIES) and entity trust scores for AI agents.

by jwconsultancyteam·MIT license·★ 1 Stars on the repo·GitHub ↗

Files of Limitguard MCP

jwconsultancyteam/main1 file
README.md
Show the full text257 lines
Limitguard

Limitguard MCP Server

Trust Intelligence for AI agents. Entity verification, sanctions screening, and risk scoring via the Model Context Protocol.

Server URL: https://api.limitguard.ai/mcp Transport: Streamable HTTP (POST) Auth: API key (Bearer), plus an x402 micropayment per call on the free and sandbox tiers

What it is: Limitguard is a lead validation service for lead generation agencies, B2B marketing and sales teams: it checks the company behind each lead against official business registers (full coverage in the Netherlands and Belgium), EU VAT and sanctions lists, with website age in the company check, and returns proceed, review or block with the source on every line. Developers and AI agents can use its HTTP API, MCP server and A2A service, hosted in the EU.

Start here: Free sandbox key, no wallet. The sandbox covers entity, risk and KYB checks; Lead Verify and the agent check need a live key or an x402 payment. Lead Verify $0.24 per lead and agent check $0.75 per wallet; $0.10-1.50 per call; entity and risk checks $0.65-0.85 fresh ($1.50 KYB), $0.10 cached ($0.25 KYB) when available.

Tools

tools/list is public — connect and read it without any credential. These are the names it returns, and the names tools/call accepts:

Tool Description Inputs
check_entity Full trust intelligence check on a business entity. Returns trust score (0-100), risk level, and recommendation. entity_name (required), country (required), kvk_number, domain
get_trust_score Look up your own most recent trust score for an entity you checked before, from your stored checks: score, level, when, which product, trend and how many checks are on record. Runs no new check and calls no data source. Free ($0). entity_id (required)
verify_wallet Screen a wallet: OFAC SDN address match, on-chain signals (contract check, native and USDC balance, transaction count, first seen on Base) and named risk rules with up to 3 advice items. On Base, also reports any ERC-8004 agent the wallet owns and its open on-chain reputation as descriptive signals, never scored. Free ($0). Supports EVM and Solana addresses. wallet_address (required), chain_id
get_risk_score Quick risk assessment without full trust check. Focuses on risk signals only. entity_name (required), country (required)
get_compliance_report Per-entity report built from one real check: registry identity, sanctions and PEP screens, domain signals, risk score with the rules that fired, correlations, every finding as a ranked action, a per-source status table (ok / unavailable / error) and a report hash. entity_name, country, kvk_number, cbe_number, vat_number, domain, iban, wallet_address, wallet_chain, check_id
check_agent_wallet Check a counterparty agent's EVM wallet in one call: OFAC SDN digital-currency address list match, Base USDC and ETH balance, ERC-8004 identity registration (and, given an agent id, that agent's owner and payment wallet) and open ERC-8004 feedback, which is not scored. $0.75. wallet (required), agent_id, domain
verify_lead Verify a NL/BE sales lead against the registers in one call: real and active, VAT, mail server, IBAN, sanctions; a 0-100 lead score. $0.24. country (required), company_number, name, vat_number, email, domain, address, iban, phone, target_industries, target_size

Pricing

All tools are priced via x402 micropayments (USDC on Base or Solana):

Endpoint Price
Entity Check (/v1/mcp/check-entity) $0.85
Risk Score (/v1/mcp/risk-score) $0.65
Check Agent (/v1/mcp/check-agent) $0.00 — unimplemented / beta, placeholder data
Trust Score (/v1/mcp/trust-score) $0.00 — unimplemented / beta, placeholder data
Verify Wallet (/v1/mcp/verify-wallet) $0.00 — unimplemented / beta, placeholder data

Authentication

Two things gate a tools/call, in this order:

  1. An API key, as Authorization: Bearer <key>. Without one every call comes back Authentication required. Provide API key via Authorization: Bearer <lg_live_...> header. Get a free one — no payment, no card:

    curl -X POST https://api.limitguard.ai/v1/keys/create \
      -H "Content-Type: application/json" \
      -d '{"email": "[email protected]"}'
    

    That returns a free-tier key, which is the key the Quick Start configs below expect. Asking for "tier": "sandbox" instead returns a key that answers with mock data — see the next point before you use one here.

  2. Payment, on the free and sandbox tiers only. Send the x402 proof as PAYMENT-SIGNATURE (x402 v2) or X-PAYMENT (v1), alongside the Bearer key. A paid subscription (indie and up) covers usage and needs no per-call payment.

    A sandbox key does not lift the payment requirement on this transport: it owes x402 per call exactly as a free key does, and it answers with mock data rather than a real check. Paying for one over MCP spends real USDC on a mock answer. Where a sandbox key is worth having is the REST mirrors under /v1/mcp/* (sent as X-API-Key, not Bearer), which serve the mock response before the payment check — a way to exercise the request and response shapes, not a cheap source of real checks.

Full x402 API (direct HTTP)

The 5 tools above are what the MCP server exposes over the Model Context Protocol. Clients that integrate directly over HTTP — instead of through an MCP client — can reach 18 x402-priced endpoints on https://api.limitguard.ai: the 13 REST endpoints below, plus the MCP tools' own /v1/mcp/* paths. All 18 are published in /.well-known/x402.json; only the 5 tools above are listed by /.well-known/mcp.json.

Most of the REST endpoints are capabilities the MCP tools do not expose, but two are the same check reached over plain HTTP: /v1/entity/check behind check_entity — the manifest describes /v1/mcp/check-entity as "same as /v1/entity/check with MCP-native interface" — and /v1/risk/score behind get_risk_score, at the same $0.65.

Payment works the same way throughout: USDC on Base or Solana, pay-per-call. The 11 data endpoints below need no API key at all. The 4 /v1/keys/upgrade/* endpoints also take payment without one, but they act on an API key you already hold — see API key tiers.

Trust intelligence
Endpoint Method Price Description
/v1/leads/verify POST $0.24 Lead verify for one NL or BE sales lead: is it a real, active company? Checks the KVK or KBO register (status, legal form, start date, main activity, staff, registered address) and cross-checks whatever else the lead holds: VAT number with VIES, mail server and disposable domain, IBAN country and bank (the account holder is not checked), and the company name against the OFAC, EU and UN sanctions lists. Returns a verdict, a 0-100 lead score, flags and one action per flag. An input not given is not checked and never counts against the lead.
/v1/agent/check POST $0.75 Agent wallet check in one call: screens an EVM wallet against the OFAC SDN digital-currency address list, reads its Base USDC and ETH balance, looks up its ERC-8004 identity registration (and, given an agent id, that agent's owner and payment wallet) and lists open ERC-8004 feedback, which is not scored. Returns one verdict and each part's status; a part that could not be read says so.
/v1/sanctions/screen POST $0.10 Sanctions screen of a company or person name against the OFAC SDN, EU and UN sanctions lists, held locally and refreshed daily. Returns each matched entry: list, entry id, matched name, programmes, countries, listing date and match score. Exact normalised or word-order-insensitive name match only; a name match is not a determination.
/v1/entity/check POST $0.85 Full entity trust check across multiple verification layers: KVK/CBE registry, OpenSanctions, country risk (CPI/FATF), domain WHOIS, IBAN validation and EU VAT/VIES. Returns trust score 0-100 with cluster and recommendation.
/v1/risk/score POST $0.65 Quick risk score (0-100) for entity name + country. Lightweight check without full data source scan.
/v1/entity/deep-check POST $0.75 Extended screening in up to three tiers. fresh ($0.75): politically exposed person and relative/close-associate (role.pep / role.rca) matches from OpenSanctions, with the match detail the standard entity check does not return, plus a Dutch Centraal Insolventieregister screen (NL only). enhanced ($1.50): the same plus adverse media screening against a global news index. If a source of the requested tier cannot be reached the call returns 503 and is not charged.
/v1/reports/entity POST $1.50 Per-entity report built from one real check's signals: identity, sanctions and PEP screening, domain signals, risk score, correlations with the caller's earlier reports, sources and an evidence hash. A source that did not answer is shown unavailable, never clean.
Reputation management
Endpoint Method Price Description
/v1/reputation/score POST $0.65 Reputation scoring with Bayesian trust decay analysis. Tracks entity trust over time with confidence intervals.
/v1/reputation/history/{id} GET $0.10 Historical reputation trend data. Returns trust score timeline with change events and decay curves.
Wallet services
Endpoint Method Price Description
/v1/wallet/balance GET $0.10 ERC-8004 agent wallet balance check. Returns the on-chain USDC balance (Base mainnet) for a registered ERC-8004 agent wallet.
Regulatory compliance
Endpoint Method Price Description
/v1/kyb/check POST $1.50 Know Your Business verification: company registration, sanctions screening, VAT/VIES, and domain analysis in one call.
/v1/compliance/alerts GET $0.10 Daily changes to the OFAC, EU and UN sanctions lists, plus alerts when an entity or wallet this key checked is listed. Poll this route; alerts are not pushed. Filter by jurisdiction and severity.
/v1/compliance/readiness/{id} GET $0.10 EU AI Act readiness self-assessment for one AI system. Send the system_type and the checklist items you have completed (completed_items); returns the EU AI Act risk level for that system type, a readiness score and the open gaps. entity_id is your label: nothing is looked up about it.
MCP tool paths (direct HTTP)

The 5 MCP tools are also reachable over plain HTTP at their own x402-priced paths — same capabilities and prices as the Tools table above, for clients that pay per call without opening an MCP session.

Endpoint Method Price MCP tool
/v1/mcp/check-entity POST $0.85 check_entity
/v1/mcp/check-agent POST $0.00 check_agent
/v1/mcp/trust-score POST $0.00 get_trust_score
/v1/mcp/verify-wallet POST $0.00 verify_wallet
/v1/mcp/risk-score POST $0.65 get_risk_score
API key tiers

Limitguard accepts two forms of payment: x402 per call, or a paid-tier API key whose subscription prepays the calls. Paying per call needs no API key on 13 of the 18 endpoints — the 9 data endpoints above and the 4 /v1/keys/upgrade/* paths. The other 5 always want a key: the MCP transport takes Authorization: Bearer on every tools/call, and its /v1/mcp/* mirrors take X-API-Key.

A base key is free and self-service: POST /v1/keys/create with an email address, no payment and no existing key needed. It identifies you and tracks your usage; it does not pay for calls. A free-tier key still owes x402 on every paid endpoint, on REST exactly as on MCP. The monthly_limit it reports is a ceiling on how many calls it may make, not an allowance of free ones. A sandbox key is also free and returns mock data, never a real check — over MCP it owes x402 like any other free key, so it earns its keep only against the REST mirrors.

The endpoints below take an x402 payment to move a key onto a paid tier, which is what lifts the per-call charge. On a paid tier monthly_limit is the number of calls the subscription covers. The manifest prices the upgrade call itself and says nothing about what happens at the end of a month, so confirm the renewal terms before budgeting against the figures below.

Endpoint Method Price Tier monthly_limit
/v1/keys/upgrade/indie POST $29 Indie 1,000 calls/mo
/v1/keys/upgrade/starter POST $99 Starter 10,000 calls/mo
/v1/keys/upgrade/growth POST $299 Growth 50,000 calls/mo
/v1/keys/upgrade/pro POST $999 Pro 250,000 calls/mo

Prices and descriptions above mirror the live x402 manifest as of 2026-09-05. The manifest is the source of truth — fetch it if you need the current schema for any endpoint.

Quick Start

Claude Desktop

Add to your claude_desktop_config.json:

{
  "mcpServers": {
    "limitguard": {
      "type": "url",
      "url": "https://api.limitguard.ai/mcp",
      "headers": {
        "Authorization": "Bearer YOUR_LIMITGUARD_KEY"
      }
    }
  }
}
Cursor

Add to MCP settings:

{
  "limitguard": {
    "type": "url",
    "url": "https://api.limitguard.ai/mcp",
    "headers": {
      "Authorization": "Bearer YOUR_LIMITGUARD_KEY"
    }
  }
}
Smithery
npx -y @smithery/cli install team-mehs/limitguard
Any MCP Client

Connect to https://api.limitguard.ai/mcp using Streamable HTTP transport (POST), sending Authorization: Bearer <key> on every tools/call.

Discovery Endpoints

Endpoint URL
MCP server card /.well-known/mcp/server-card.json
MCP Tools /.well-known/mcp.json
x402 Pricing /.well-known/x402.json
Health /health

The service publishes two tool cards, and they do not agree. Both list the same five tools, taking the same required arguments, so a tools/call written against either one works — but the descriptions and the argument wording differ between them. The Tools table above and this repository's server.json are generated from the server card, which is the one to read when the two disagree. Reconciling them is the service's to fix.

Use Cases

  • KYC/KYB Automation — AI agents verify business entities before transactions
  • Sanctions Screening — Check entities against OpenSanctions watchlists
  • Agent-to-Agent Trust — Verify counterparty agent reputation before collaboration
  • Wallet Verification — Check blockchain wallet risk before on-chain transactions
  • Due Diligence — Automated entity research with trust scoring

Security

  • HTTPS with TLS 1.3
  • x402 payment protocol for per-call billing (no stored payment credentials)
  • GDPR-compliant (EU-hosted, data minimization)
  • All tools are read-only (no data modification)
  • Rate limited per payment (abuse-proof)

License

MIT

1<picture>
2 <source media="(prefers-color-scheme: dark)" srcset="assets/logo-dark.svg">
3 <img src="assets/logo-light.svg" alt="Limitguard" width="220">
4</picture>
5 
6# Limitguard MCP Server
7 
8Trust Intelligence for AI agents. Entity verification, sanctions screening, and risk scoring via the [Model Context Protocol](https://modelcontextprotocol.io/).
9 
10**Server URL:** `https://api.limitguard.ai/mcp`
11**Transport:** Streamable HTTP (POST)
12**Auth:** API key (Bearer), plus an x402 micropayment per call on the free and sandbox tiers
13 
14**What it is:** Limitguard is a lead validation service for lead generation agencies, B2B marketing and sales teams: it checks the company behind each lead against official business registers (full coverage in the Netherlands and Belgium), EU VAT and sanctions lists, with website age in the company check, and returns proceed, review or block with the source on every line. Developers and AI agents can use its HTTP API, MCP server and A2A service, hosted in the EU.
15 
16**Start here:** Free sandbox key, no wallet. The sandbox covers entity, risk and KYB checks; Lead Verify and the agent check need a live key or an x402 payment. Lead Verify $0.24 per lead and agent check $0.75 per wallet; $0.10-1.50 per call; entity and risk checks $0.65-0.85 fresh ($1.50 KYB), $0.10 cached ($0.25 KYB) when available.
17 
18## Tools
19 
20`tools/list` is public — connect and read it without any credential. These are
21the names it returns, and the names `tools/call` accepts:
22 
23| Tool | Description | Inputs |
24|------|-------------|--------|
25| `check_entity` | Full trust intelligence check on a business entity. Returns trust score (0-100), risk level, and recommendation. | `entity_name` (required), `country` (required), `kvk_number`, `domain` |
26| `get_trust_score` | Look up your own most recent trust score for an entity you checked before, from your stored checks: score, level, when, which product, trend and how many checks are on record. Runs no new check and calls no data source. Free ($0). | `entity_id` (required) |
27| `verify_wallet` | Screen a wallet: OFAC SDN address match, on-chain signals (contract check, native and USDC balance, transaction count, first seen on Base) and named risk rules with up to 3 advice items. On Base, also reports any ERC-8004 agent the wallet owns and its open on-chain reputation as descriptive signals, never scored. Free ($0). Supports EVM and Solana addresses. | `wallet_address` (required), `chain_id` |
28| `get_risk_score` | Quick risk assessment without full trust check. Focuses on risk signals only. | `entity_name` (required), `country` (required) |
29| `get_compliance_report` | Per-entity report built from one real check: registry identity, sanctions and PEP screens, domain signals, risk score with the rules that fired, correlations, every finding as a ranked action, a per-source status table (ok / unavailable / error) and a report hash. | `entity_name`, `country`, `kvk_number`, `cbe_number`, `vat_number`, `domain`, `iban`, `wallet_address`, `wallet_chain`, `check_id` |
30| `check_agent_wallet` | Check a counterparty agent's EVM wallet in one call: OFAC SDN digital-currency address list match, Base USDC and ETH balance, ERC-8004 identity registration (and, given an agent id, that agent's owner and payment wallet) and open ERC-8004 feedback, which is not scored. $0.75. | `wallet` (required), `agent_id`, `domain` |
31| `verify_lead` | Verify a NL/BE sales lead against the registers in one call: real and active, VAT, mail server, IBAN, sanctions; a 0-100 lead score. $0.24. | `country` (required), `company_number`, `name`, `vat_number`, `email`, `domain`, `address`, `iban`, `phone`, `target_industries`, `target_size` |
32 
33## Pricing
34 
35All tools are priced via [x402](https://www.x402.org/) micropayments (USDC on Base or Solana):
36 
37| Endpoint | Price |
38|----------|-------|
39| Entity Check (`/v1/mcp/check-entity`) | $0.85 |
40| Risk Score (`/v1/mcp/risk-score`) | $0.65 |
41| Check Agent (`/v1/mcp/check-agent`) | $0.00 — unimplemented / beta, placeholder data |
42| Trust Score (`/v1/mcp/trust-score`) | $0.00 — unimplemented / beta, placeholder data |
43| Verify Wallet (`/v1/mcp/verify-wallet`) | $0.00 — unimplemented / beta, placeholder data |
44 
45## Authentication
46 
47Two things gate a `tools/call`, in this order:
48 
491. **An API key**, as `Authorization: Bearer <key>`. Without one every call comes
50 back `Authentication required. Provide API key via Authorization: Bearer
51 <lg_live_...> header.` Get a free one — no payment, no card:
52 
53 ```bash
54 curl -X POST https://api.limitguard.ai/v1/keys/create \
55 -H "Content-Type: application/json" \
56 -d '{"email": "[email protected]"}'
57 ```
58 
59 That returns a `free`-tier key, which is the key the Quick Start configs below
60 expect. Asking for `"tier": "sandbox"` instead returns a key that answers with
61 mock data — see the next point before you use one here.
62 
632. **Payment, on the free and sandbox tiers only.** Send the x402 proof as
64 `PAYMENT-SIGNATURE` (x402 v2) or `X-PAYMENT` (v1), alongside the Bearer key.
65 A paid subscription (indie and up) covers usage and needs no per-call payment.
66 
67 A sandbox key does *not* lift the payment requirement on this transport: it
68 owes x402 per call exactly as a `free` key does, and it answers with mock
69 data rather than a real check. Paying for one over MCP spends real USDC on a
70 mock answer. Where a sandbox key is worth having is the REST mirrors under
71 `/v1/mcp/*` (sent as `X-API-Key`, not Bearer), which serve the mock response
72 before the payment check — a way to exercise the request and response shapes,
73 not a cheap source of real checks.
74 
75## Full x402 API (direct HTTP)
76 
77The 5 tools above are what the MCP server exposes over the Model Context Protocol. Clients that
78integrate directly over HTTP — instead of through an MCP client — can reach 18 x402-priced
79endpoints on `https://api.limitguard.ai`: the 13 REST endpoints below, plus the MCP tools' own
80`/v1/mcp/*` paths. All 18 are published in
81[/.well-known/x402.json](https://api.limitguard.ai/.well-known/x402.json); only the 5 tools above
82are listed by `/.well-known/mcp.json`.
83 
84Most of the REST endpoints are capabilities the MCP tools do not expose, but two are the same
85check reached over plain HTTP: `/v1/entity/check` behind `check_entity` — the manifest describes
86`/v1/mcp/check-entity` as "same as `/v1/entity/check` with MCP-native interface" — and
87`/v1/risk/score` behind `get_risk_score`, at the same $0.65.
88 
89Payment works the same way throughout: USDC on Base or Solana, pay-per-call. The 11 data endpoints
90below need no API key at all. The 4 `/v1/keys/upgrade/*` endpoints also take payment without one,
91but they act on an API key you already hold — see [API key tiers](#api-key-tiers).
92 
93### Trust intelligence
94 
95| Endpoint | Method | Price | Description |
96|----------|--------|-------|-------------|
97| `/v1/leads/verify` | POST | $0.24 | Lead verify for one NL or BE sales lead: is it a real, active company? Checks the KVK or KBO register (status, legal form, start date, main activity, staff, registered address) and cross-checks whatever else the lead holds: VAT number with VIES, mail server and disposable domain, IBAN country and bank (the account holder is not checked), and the company name against the OFAC, EU and UN sanctions lists. Returns a verdict, a 0-100 lead score, flags and one action per flag. An input not given is not checked and never counts against the lead. |
98| `/v1/agent/check` | POST | $0.75 | Agent wallet check in one call: screens an EVM wallet against the OFAC SDN digital-currency address list, reads its Base USDC and ETH balance, looks up its ERC-8004 identity registration (and, given an agent id, that agent's owner and payment wallet) and lists open ERC-8004 feedback, which is not scored. Returns one verdict and each part's status; a part that could not be read says so. |
99| `/v1/sanctions/screen` | POST | $0.10 | Sanctions screen of a company or person name against the OFAC SDN, EU and UN sanctions lists, held locally and refreshed daily. Returns each matched entry: list, entry id, matched name, programmes, countries, listing date and match score. Exact normalised or word-order-insensitive name match only; a name match is not a determination. |
100| `/v1/entity/check` | POST | $0.85 | Full entity trust check across multiple verification layers: KVK/CBE registry, OpenSanctions, country risk (CPI/FATF), domain WHOIS, IBAN validation and EU VAT/VIES. Returns trust score 0-100 with cluster and recommendation. |
101| `/v1/risk/score` | POST | $0.65 | Quick risk score (0-100) for entity name + country. Lightweight check without full data source scan. |
102| `/v1/entity/deep-check` | POST | $0.75 | Extended screening in up to three tiers. fresh ($0.75): politically exposed person and relative/close-associate (role.pep / role.rca) matches from OpenSanctions, with the match detail the standard entity check does not return, plus a Dutch Centraal Insolventieregister screen (NL only). enhanced ($1.50): the same plus adverse media screening against a global news index. If a source of the requested tier cannot be reached the call returns 503 and is not charged. |
103| `/v1/reports/entity` | POST | $1.50 | Per-entity report built from one real check's signals: identity, sanctions and PEP screening, domain signals, risk score, correlations with the caller's earlier reports, sources and an evidence hash. A source that did not answer is shown unavailable, never clean. |
104 
105### Reputation management
106 
107| Endpoint | Method | Price | Description |
108|----------|--------|-------|-------------|
109| `/v1/reputation/score` | POST | $0.65 | Reputation scoring with Bayesian trust decay analysis. Tracks entity trust over time with confidence intervals. |
110| `/v1/reputation/history/{id}` | GET | $0.10 | Historical reputation trend data. Returns trust score timeline with change events and decay curves. |
111 
112### Wallet services
113 
114| Endpoint | Method | Price | Description |
115|----------|--------|-------|-------------|
116| `/v1/wallet/balance` | GET | $0.10 | ERC-8004 agent wallet balance check. Returns the on-chain USDC balance (Base mainnet) for a registered ERC-8004 agent wallet. |
117 
118### Regulatory compliance
119 
120| Endpoint | Method | Price | Description |
121|----------|--------|-------|-------------|
122| `/v1/kyb/check` | POST | $1.50 | Know Your Business verification: company registration, sanctions screening, VAT/VIES, and domain analysis in one call. |
123| `/v1/compliance/alerts` | GET | $0.10 | Daily changes to the OFAC, EU and UN sanctions lists, plus alerts when an entity or wallet this key checked is listed. Poll this route; alerts are not pushed. Filter by jurisdiction and severity. |
124| `/v1/compliance/readiness/{id}` | GET | $0.10 | EU AI Act readiness self-assessment for one AI system. Send the system_type and the checklist items you have completed (completed_items); returns the EU AI Act risk level for that system type, a readiness score and the open gaps. entity_id is your label: nothing is looked up about it. |
125 
126### MCP tool paths (direct HTTP)
127 
128The 5 MCP tools are also reachable over plain HTTP at their own x402-priced paths — same
129capabilities and prices as the Tools table above, for clients that pay per call without opening an
130MCP session.
131 
132| Endpoint | Method | Price | MCP tool |
133|----------|--------|-------|----------|
134| `/v1/mcp/check-entity` | POST | $0.85 | `check_entity` |
135| `/v1/mcp/check-agent` | POST | $0.00 | `check_agent` |
136| `/v1/mcp/trust-score` | POST | $0.00 | `get_trust_score` |
137| `/v1/mcp/verify-wallet` | POST | $0.00 | `verify_wallet` |
138| `/v1/mcp/risk-score` | POST | $0.65 | `get_risk_score` |
139 
140### API key tiers
141 
142Limitguard accepts two forms of payment: x402 per call, or a **paid-tier** API key whose
143subscription prepays the calls. Paying per call needs no API key on 13 of the 18 endpoints — the
1449 data endpoints above and the 4 `/v1/keys/upgrade/*` paths. The other 5 always want a key: the
145MCP transport takes `Authorization: Bearer` on every `tools/call`, and its `/v1/mcp/*` mirrors
146take `X-API-Key`.
147 
148A base key is free and self-service: `POST /v1/keys/create` with an email address, no payment and
149no existing key needed. It identifies you and tracks your usage; it does **not** pay for calls. A
150`free`-tier key still owes x402 on every paid endpoint, on REST exactly as on MCP. The
151`monthly_limit` it reports is a ceiling on how many calls it may make, not an allowance of free
152ones. A `sandbox` key is also free and returns mock data, never a real check — over MCP it owes
153x402 like any other free key, so it earns its keep only against the REST mirrors.
154 
155The endpoints below take an x402 payment to move a key onto a paid tier, which is what lifts the
156per-call charge. On a paid tier `monthly_limit` is the number of calls the subscription covers.
157The manifest prices the upgrade call itself and says nothing about what happens at the end of a
158month, so confirm the renewal terms before budgeting against the figures below.
159 
160| Endpoint | Method | Price | Tier | `monthly_limit` |
161|----------|--------|-------|------|-----------------|
162| `/v1/keys/upgrade/indie` | POST | $29 | Indie | 1,000 calls/mo |
163| `/v1/keys/upgrade/starter` | POST | $99 | Starter | 10,000 calls/mo |
164| `/v1/keys/upgrade/growth` | POST | $299 | Growth | 50,000 calls/mo |
165| `/v1/keys/upgrade/pro` | POST | $999 | Pro | 250,000 calls/mo |
166 
167Prices and descriptions above mirror the live x402 manifest as of 2026-09-05. The manifest is the
168source of truth — fetch it if you need the current schema for any endpoint.
169 
170## Quick Start
171 
172### Claude Desktop
173 
174Add to your `claude_desktop_config.json`:
175 
176```json
177{
178 "mcpServers": {
179 "limitguard": {
180 "type": "url",
181 "url": "https://api.limitguard.ai/mcp",
182 "headers": {
183 "Authorization": "Bearer YOUR_LIMITGUARD_KEY"
184 }
185 }
186 }
187}
188```
189 
190### Cursor
191 
192Add to MCP settings:
193 
194```json
195{
196 "limitguard": {
197 "type": "url",
198 "url": "https://api.limitguard.ai/mcp",
199 "headers": {
200 "Authorization": "Bearer YOUR_LIMITGUARD_KEY"
201 }
202 }
203}
204```
205 
206### Smithery
207 
208```bash
209npx -y @smithery/cli install team-mehs/limitguard
210```
211 
212### Any MCP Client
213 
214Connect to `https://api.limitguard.ai/mcp` using Streamable HTTP transport (POST),
215sending `Authorization: Bearer <key>` on every `tools/call`.
216 
217## Discovery Endpoints
218 
219| Endpoint | URL |
220|----------|-----|
221| MCP server card | [/.well-known/mcp/server-card.json](https://api.limitguard.ai/.well-known/mcp/server-card.json) |
222| MCP Tools | [/.well-known/mcp.json](https://api.limitguard.ai/.well-known/mcp.json) |
223| x402 Pricing | [/.well-known/x402.json](https://api.limitguard.ai/.well-known/x402.json) |
224| Health | [/health](https://api.limitguard.ai/health) |
225 
226The service publishes two tool cards, and they do not agree. Both list the same five
227tools, taking the same required arguments, so a `tools/call` written against either one
228works — but the descriptions and the argument wording differ between them. The Tools
229table above and this repository's `server.json` are generated from the **server card**,
230which is the one to read when the two disagree. Reconciling them is the service's to fix.
231 
232## Use Cases
233 
234- **KYC/KYB Automation** — AI agents verify business entities before transactions
235- **Sanctions Screening** — Check entities against OpenSanctions watchlists
236- **Agent-to-Agent Trust** — Verify counterparty agent reputation before collaboration
237- **Wallet Verification** — Check blockchain wallet risk before on-chain transactions
238- **Due Diligence** — Automated entity research with trust scoring
239 
240## Security
241 
242- HTTPS with TLS 1.3
243- x402 payment protocol for per-call billing (no stored payment credentials)
244- GDPR-compliant (EU-hosted, data minimization)
245- All tools are read-only (no data modification)
246- Rate limited per payment (abuse-proof)
247 
248## Links
249 
250- **Website:** [limitguard.ai](https://limitguard.ai)
251- **Status:** [status.limitguard.ai](https://status.limitguard.ai)
252- **MCP Registry:** [ai.limitguard.api/trust-intelligence](https://registry.modelcontextprotocol.io/v0/servers/ai.limitguard.api%2Ftrust-intelligence/versions/latest) (JSON; the registry has no HTML page per server)
253 
254## License
255 
256MIT
257 

Discussion

Alternatives