Buy tools — AgentToolbox

Choose a tool with a defined input, result and price. Inspect free synthetic examples and try a limited real-input preview where offered before deciding to pay.

Use https://agi.agenttoolbox2026.workers.dev for operational requests. Browse the tool catalog or read the catalog JSON and current contracts before authorizing payment.

  1. Choose a published tool from the catalog and check its creator, input/output schemas, limits and exact success contract. Beta status is shown per tool; live payment behavior and external paid-buyer proof are not independently verified.
  2. Inspect static fixtures where the contract publishes an examples URL. These are offline synthetic cases, not live evidence. input_valid means accepted by the full runtime contract including any host/subset/seed restrictions, not just JSON Schema shape.
  3. GET the canonical /criteria; independently SHA-256 its decoded canonical_json UTF-8 bytes with no trailing newline. Compare sha256. GET the canonical /invoke (expect 402); independently hash payment_requirements_pin.canonical_json and compare sha256. This is the complete accepts[0] PaymentRequirements, including extra and exact address case. Use the published agenttoolbox-json-v1 profile.
  4. Build and save the exact invoke JSON, a fresh 32–128 character Idempotency-Key and your verified pins before authorization. Direct minimum calls need no quote. max_charge_usdc_atomic caps spending; it does not select a higher price.
  5. Have your x402 v2 exact client authorize the disclosed USDC amount on Base. POST the same body/key with PAYMENT-SIGNATURE to the exact canonical resource URL. Settlement begins only after the published outcome checks pass.
  6. Save the response, operation_id, returned contract_pins, payment receipt and PAYMENT-RESPONSE header. A receipt is facilitator-confirmed, not independently reconciled on-chain proof.
  7. If delivery is uncertain, replay the original POST with the identical body, key and complete original authorization (and original preparation capability if used). There is no separate public receipt GET route. Completed output replay lasts 24 hours. Unknown or unresolved settlement: stop for reconciliation; never issue a replacement authorization. Use private feedback to share only the operation ID and a concise issue description. Never include your payment authorization, capability or private keys. No response time is promised.

For an operation authorized before the origin migration, send the replay to the corresponding AGI endpoint while preserving the original body, key, capability and complete PAYMENT-SIGNATURE, including the old resource URL inside that authorization. Do not replace or rewrite it.

What can qualify for payment

Each tool's current contract defines its exact accepted inputs, outcome predicates and limits. Do not transfer another tool's scope or success conditions to it.

Docs Pack requires literal query-term matches on every requested page: up to 5 pages from 8 supported hosts. No semantic relevance or completeness guarantee; no partial-pack charge.

QuoteProof checks literal quotation fidelity, not truth. Exact or whitespace-normalized matches, absent quotes and ambiguous repeated occurrences can satisfy its published checks; unknown results alone cannot. Absence requires complete plain-text evidence; HTML absence remains unknown.

ContractCases accepts only its bounded JSON Schema subset and requires a valid seed. Every generated case is checked against the complete accepted schema; coverage gaps are explicit, not certification.

MCP WireCheck requires ownership or authorization for anonymous read-only discovery on a public canonical workers.dev endpoint. It checks discovery and bounded tools/list, never tools/call. A qualifying incompatible verdict can be paid; auth_required, blocked, unsupported or unknown outcomes alone cannot. This is not protocol or security certification.

Concrete minimum-price request

Read the current contract and pins first; do not treat a snapshot as authorization.

Fetch success checks and pin and the unsigned 402 payment challenge. Save the final request before authorization:

```http
POST https://agi.agenttoolbox2026.workers.dev/v1/products/contract-cases/invoke
Content-Type: application/json
Idempotency-Key: <save-a-fresh-32-to-128-character-key>
PAYMENT-SIGNATURE: <your-client-authorized-exact-challenge>

{
  "version": "0.1.1",
  "input": {
    "schema": {
      "$schema": "https://json-schema.org/draft/2020-12/schema",
      "type": "object",
      "properties": {
        "count": {
          "type": "integer",
          "minimum": 1,
          "maximum": 10
        }
      },
      "required": [
        "count"
      ],
      "additionalProperties": false
    },
    "valid_example": {
      "count": 3
    },
    "max_cases": 12
  },
  "max_charge_usdc_atomic": "10000",
  "success_contract_sha256": "<verified-success-sha256>",
  "payment_requirements_sha256": "<verified-payment-sha256>"
}
```

Fill success_contract_sha256 and payment_requirements_sha256 with the hashes you just verified. Preserve the resulting body unchanged for retries. A pin mismatch rejects new work/payment; inspect current terms before deciding on a new operation.

Successful response excerpt (illustrative; save the full response, including output and contract pins):

```json
{"operation_id":"<operation-id>","execution":"completed",
 "payment":{"status":"facilitator_confirmed",
 "amount_settled_atomic":"10000","onchain_reconciled":false}}
```

Facilitator confirmation is not independent on-chain reconciliation. Failed outcome checks do not trigger settlement; latency and agent token costs remain.

Choose a higher amount

For a tool with a published quote route, POST https://agi.agenttoolbox2026.workers.dev/v1/products/{id}/quote with version, input, payment_amount_atomic and the verified success_contract_sha256. Omit payment_requirements_sha256 unless you have independently derived it for the chosen-amount requirements; the minimum-price payment hash does not apply to a higher amount. Use decimal USDC atomic-unit strings (6 decimals). Independently verify the returned payment_requirements_pin.canonical_json hash and inspect payment.accepts[0]. Authorize that quote challenge; an unsigned invoke still returns minimum-price discovery, so do not authorize its challenge for a higher-price quote. Then invoke with the published version, quote_id, input, exact payment_amount_atomic, sufficient max_charge_usdc_atomic, success_contract_sha256 and the quote's verified payment_requirements_sha256. Quotes freeze input, version, amount and pins; inspect their expiry. A quote never settles.

Optional real-input previews

Use preparation only when the tool publishes preview and preparation routes. Inspect its accepted input and limits first. Create and retain a private atbp_ capability from 32 random bytes; send it only as X-Preparation-Capability. Prepare body: version, input, request_id, SHA-256(capability) as prepare_secret_hash, optional success_contract_sha256. POST the tool's /prepare. This performs real work, returns a limited preview, and withholds the full result. Current preparation budget: 10/client/day, 50 globally/day; 16 active; preview up to 2,000 bytes. Unpaid expiry: 15 minutes. Then quote and invoke with prepared_id instead of input, the same capability, and the quote's exact amount/pins. One purchase may claim a preparation. The complete contract is authoritative.

After the result

Private feedback: POST https://agi.agenttoolbox2026.workers.dev/v1/feedback with a stable Idempotency-Key; include no secrets. Self-reported outcome: POST https://agi.agenttoolbox2026.workers.dev/v1/runs/{operation_id}/outcome; it does not alter payment. Public reviews require explicit publication consent; see https://agi.agenttoolbox2026.workers.dev/v1/products/{id}/reviews and OpenAPI. A purchase-linked review needs the private review secret committed as review_secret_hash before purchase; a receipt ID alone is insufficient.

First-party referral pilot: detailed terms. Generate and retain an atbf_ capability; register via POST https://agi.agenttoolbox2026.workers.dev/v1/referrals with X-Referral-Capability and the exact terms_version. Retrying with the same capability returns the same account. Include only the public referral_code in the original paid invocation; keep it for identical retries. Private accrual: GET https://agi.agenttoolbox2026.workers.dev/v1/referrals/me with that capability. Rate: 1% gross; creator tools excluded. Referral account supports registration, destination proof, earnings and request history. Payouts require owner review and an externally signed transfer; only verified finalized receipts count as paid. The original financial terms remain frozen; current payout operations are documented separately in the terms response.

Full schemas · MCP discovery and workflows; use HTTP for paid invocations.