MCP server · XGuard

XGuard Universal Paid AI Agent + Secretless Gateway

XGuard operates ONE remote MCP server at https://api.xguardgate.com/mcp, on the same host as its OpenAPI, its A2A JSON-RPC endpoint and its x402 facilitator relay. It is Streamable HTTP, speaks MCP protocol version 2026-07-28, identifies itself as serverInfo {xguard-universal-paid-secretless-gateway, 5.1.0}, and answers initialize and tools/list anonymously with exactly three tools, each carrying a real JSON Schema inputSchema and MCP tool annotations (readOnlyHint / destructiveHint / idempotentHint / openWorldHint). The initialize instructions and the provider's README both say the live tools/list is deliberately small: the paid-outcome chokepoint is xguard_execute, and the older explicit tool names that llms-install.md still lists (xguard.web.fetch, xguard_secretless_egress, xguard_proofrail, ...) are "compatibility references, not the default catalog". A paid tool call returns an HTTP 200 JSON-RPC result with isError: true and the x402 PaymentRequired challenge in both structuredContent and content[0].text; a funded x402 MCP client retries the identical arguments with params._meta["x402/payment"] and receives settlement in result._meta["x402/payment-response"]. Authorship is not in question: the tool names, the serverInfo name, the canonical-identity block in every response header set (x-xguard-canonical-mcp) and the MCP Registry entry io.github.moelayyan90/xguard-control-plane all name this provider.

One-click install for Cursor, VS Code, Claude, and 20+ other MCP clients, powered by API Commons MCP Install — visit install.apicommons.org for more information.

Provider: XGuard Type: Hosted endpoint Transport: streamable-http Host: api.xguardgate.com

Endpoint

https://api.xguardgate.com/mcp

Hosted endpoint · transport streamable-http

Connect

This is a remote MCP server — point an MCP client at the endpoint URL. Clients with native remote support (Claude, Cursor, VS Code, …):

# mcp client config (e.g. .mcp.json / mcp settings) { "mcpServers": { "xguardgate-com": { "url": "https://api.xguardgate.com/mcp" } } }

For stdio-only clients (older Claude Desktop, etc.), bridge with mcp-remote:

# Add to claude_desktop_config.json { "mcpServers": { "xguardgate-com": { "command": "npx", "args": ["-y", "mcp-remote", "https://api.xguardgate.com/mcp"] } } }

If the server requires authentication, add the provider's token/header (e.g. an X-API-Key) per its docs. A quick reachability check:

curl -i -X POST https://api.xguardgate.com/mcp \ -H "Content-Type: application/json" -H "Accept: application/json, text/event-stream" \ -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'

Tools

About MCP

The Model Context Protocol (MCP) is an open protocol Anthropic introduced for connecting LLM-based agents to external tools and data sources. Providers publish MCP servers that expose their API surface as structured, discoverable tools — an MCP-compatible client (Claude Desktop, Cursor, Cline, Continue, etc.) can connect to the server and call its tools without any per-provider integration code.

Browse every MCP server on the APIs.io network or compare with the broader Agent Skill surfaces of the same providers.

Work with this as data

Every MCP server here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for mcp servers

4 MCP tools reach this
  • find_mcpBrowse and filter every MCP server in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This MCP server
curl "https://apis.io/api/v1/mcp/xguard-universal-paid-secretless-gateway"
All mcp servers
curl "https://apis.io/api/v1/mcp?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.