# XGuard

**Canonical:** https://apis.io/providers/xguardgate-com/  
**Website:** https://xguardgate.com/  
**APIs profiled:** 3

XGuard is a paid-tool and credential-brokering gateway for AI agents, operated from xguardgate.com with its API at api.xguardgate.com and its source published at github.com/moelayyan90/XGuard (Apache-2.0, Cloudflare Workers). Its canonical product, "XGuard Universal Paid AI Agent + Secretless Gateway" (v5.1.0), sells four public-source outcomes to any agent with no account or API key: a free HTML extraction preview, multi-page evidence extraction, Schema.org product-offer comparison and a deduplicated RSS/Atom feed digest, each priced per execution in USDC on Base (0.002-0.006 USDC) and settled through the x402 v2 protocol before the sources are touched, with a signed quote, a replay-safe payment identifier, a signed receipt and ES256 "ProofRail" execution evidence. A second surface, Secretless Egress, lets an operator store an upstream API credential (OpenAI, Anthropic, GitHub, Stripe, Slack, Notion, Cloudflare, Gemini or custom) and hand an agent a short-lived scoped capability instead of the secret, with a mandatory Idempotency-Key on every write. The same catalog is exposed as a 49-operation OpenAPI 3.1.0 contract, a remote Streamable HTTP MCP server at api.xguardgate.com/mcp that answers tools/list anonymously, an A2A 1.0.0 agent card at /.well-known/agent-card.json, an OpenAI plugin manifest, llms.txt and a set of x402 payment, egress and action manifests; a companion x402 settlement-reconciliation API runs at reconcile.xguardgate.com.

## Kin Score — 52.8 / 100 (developing)

Scored 2026-10-09 under rubric 0.23.0. Trend: flat (+0.5 from 52.3).

| Facet | Score |
|---|---|
| Discoverability | 80.0 |
| Contract Quality | 40.1 |
| Contract Governance | 18.2 |
| Operational Transparency | 31.6 |
| Developer Ergonomics | 57.7 |
| Access Clarity | 63.2 |

Regulatory layer — **Horizontal (data, software, accessibility, platform)**: 30.4 (matched via fallback).

## Agent readiness — 46.4 (agent-native)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | documented |
| Auth Clarity | bearer |
| Idempotency | verified |
| Error Semantics | verified |
| OpenAPI Examples | partial |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | conformant |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | documented |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## APIs (30)

- **XGuard MCP Server** — Remote Model Context Protocol server at https://api.xguardgate.com/mcp (Streamable HTTP, protocol version 2026-07-28, serverInfo xguard-universal-paid-secretless-gateway 5.1.0)....
- **XGuard A2A Agent** — Agent2Agent surface: an agent card served identically from https://api.xguardgate.com/.well-known/agent-card.json (the canonical location named in the provider's own xguard.json...
- **XGuard Actions API** — The Actions API from XGuard — 5 operation(s) for actions.
- **XGuard Agent Card.json API** — The Agent Card.json API from XGuard — 1 operation(s) for agent card.json.
- **XGuard Discovery API** — The Discovery API from XGuard — 2 operation(s) for discovery.
- **XGuard Edge API** — The Edge API from XGuard — 1 operation(s) for edge.
- **XGuard Egress API** — The Egress API from XGuard — 6 operation(s) for egress.
- **XGuard Facilitator API** — The Facilitator API from XGuard — 2 operation(s) for facilitator.
- **XGuard Health API** — The Health API from XGuard — 1 operation(s) for health.
- **XGuard Healthz API** — The Healthz API from XGuard — 1 operation(s) for healthz.
- **XGuard Inspect API** — The Inspect API from XGuard — 1 operation(s) for inspect.
- **XGuard Metrics API** — The Metrics API from XGuard — 1 operation(s) for metrics.
- **XGuard Openapi.yaml API** — The Openapi.yaml API from XGuard — 1 operation(s) for openapi.yaml.
- **XGuard Operations API** — The Operations API from XGuard — 1 operation(s) for operations.
- **XGuard Outcomes API** — Primary intent execution
- **XGuard Payment API** — The Payment API from XGuard — 1 operation(s) for payment.
- **XGuard Preflight API** — The Preflight API from XGuard — 1 operation(s) for preflight.
- **XGuard Pricing API** — The Pricing API from XGuard — 2 operation(s) for pricing.
- **XGuard Proof API** — The Proof API from XGuard — 1 operation(s) for proof.
- **XGuard Proofs API** — The Proofs API from XGuard — 1 operation(s) for proofs.
- **XGuard Protocols API** — The Protocols API from XGuard — 1 operation(s) for protocols.
- **XGuard Ready API** — The Ready API from XGuard — 1 operation(s) for ready.
- **XGuard Receipts API** — The Receipts API from XGuard — 1 operation(s) for receipts.
- **XGuard Reconcile API** — The Reconcile API from XGuard — 1 operation(s) for reconcile.
- **XGuard Settle API** — The Settle API from XGuard — 1 operation(s) for settle.
- **XGuard Supported API** — The Supported API from XGuard — 1 operation(s) for supported.
- **XGuard Test API** — The Test API from XGuard — 2 operation(s) for test.
- **XGuard Tools API** — The Tools API from XGuard — 2 operation(s) for tools.
- **XGuard Verify API** — The Verify API from XGuard — 1 operation(s) for verify.
- **XGuard .well Known API** — The .well Known API from XGuard — 3 operation(s) for .well known.

## MCP servers (1)

- **XGuard MCP Server** — XGuard operates ONE remote MCP server at https://api.xguardgate.com/mcp, on the same host as its OpenAPI, its A2A JSON-RPC endpoint and its x402 facilitator relay. It is Streama...

## Agentic access (1)

- **Xguardgate Com Agentic Access** — 50 operations · 16 acting · 2 human-in-the-loop

## Security (3)

- **Xguardgate Com Authentication** — 8 schemes
- **Xguardgate Com Domain Security** — TLSv1.2 · HSTS
- **Xguardgate Com Vulnerability Disclosure** — Hackerone · security.txt · contact published

## Plans (1)

- **Xguardgate Com Plans Pricing**

## Tags

Agents, Agentic Commerce, x402, MCP, A2A, Micropayments, Web Extraction, Feed Aggregation, Credential Broker, API Gateway, Agent Security, Agent-Native

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/xguardgate-com/). Scores are computed from the provider's own public artifacts under a published rubric.
