PHION Agent Trust Infrastructure MCP Tools
PHION Agent Trust Infrastructure exposes 124 tools. Each one has its own page with the configuration for every client that can run this server.
-
phion_executephion execute
-
index_feedindex feed
-
preflightpreflight
-
try_servicetry service
-
schema_normalize_freeschema normalize free
-
payment_diagnosepayment diagnose
-
verifyverify
-
attestattest
-
payment_preflightpayment preflight
-
fetch_evidenceRead-onlyfetch evidence
-
mandate_reservemandate reserve
-
inspect_agentRead-onlyinspect agent
-
journey_verifyjourney verify
-
transaction_assurancetransaction assurance
-
transaction_recoverytransaction recovery
-
schema_normalizeschema normalize
-
agent_reputation_evidenceagent reputation evidence
-
counterparty_risk_preflightcounterparty risk preflight
-
tool_output_firewalltool output firewall
-
delegation_scope_guarddelegation scope guard
-
memory_write_guardmemory write guard
-
mcp_manifest_firewallmcp manifest firewall
-
tool_call_policy_guardtool call policy guard
-
data_egress_preflightdata egress preflight
-
agent_budget_guardagent budget guard
-
idempotency_replay_guardidempotency replay guard
-
human_approval_policyhuman approval policy
-
secret_redaction_preflightsecret redaction preflight
-
oauth_token_audience_guardoauth token audience guard
-
redirect_callback_validatorredirect callback validator
-
tool_capability_drift_monitortool capability drift monitor
-
mcp_server_identity_evidencemcp server identity evidence
-
agent_task_handoff_receiptagent task handoff receipt
-
context_provenance_labelercontext provenance labeler
-
signed_result_comparatorsigned result comparator
-
service_sla_attestationservice sla attestation
-
payment_route_selectorpayment route selector
-
x402_quote_comparatorx402 quote comparator
-
payment_receipt_reconcilerpayment receipt reconciler
-
duplicate_charge_detectorduplicate charge detector
-
subscription_spend_guardsubscription spend guard
-
webhook_verifierwebhook verifier
-
delivery_evidencedelivery evidence
-
inter_agent_policy_evaluatorinter agent policy evaluator
-
concurrency_guardconcurrency guard
-
resource_cycle_guardresource cycle guard
-
abandoned_tool_detectorabandoned tool detector
-
manifest_version_diffmanifest version diff
-
dependency_provenance_assessmentdependency provenance assessment
-
conflict_resolutionconflict resolution
-
data_freshness_certificatedata freshness certificate
-
domain_ownership_evidencedomain ownership evidence
-
purpose_bound_consentpurpose bound consent
-
retention_deletion_receiptretention deletion receipt
-
interrupted_task_recoveryinterrupted task recovery
-
portable_observability_auditportable observability audit
-
rwa_asset_due_diligencerwa asset due diligence
-
rwa_compliancerwa compliance
-
rwa_nav_reserverwa nav reserve
-
rwa_transaction_assurancerwa transaction assurance
-
rwa_corporate_actionsrwa corporate actions
-
rwa_sanctions_screening_evidencerwa sanctions screening evidence
-
verified_web_extractverified web extract
-
entity_enrichment_evidenceentity enrichment evidence
-
social_source_evidencesocial source evidence
-
market_data_snapshotmarket data snapshot
-
onchain_evidenceonchain evidence
-
verified_news_monitorverified news monitor
-
multi_source_fact_bundlemulti source fact bundle
-
document_to_verified_jsondocument to verified json
-
source_backed_searchsource backed search
-
live_data_freshnesslive data freshness
-
person_enrichment_evidenceperson enrichment evidence
-
company_enrichment_evidencecompany enrichment evidence
-
contact_enrichment_evidencecontact enrichment evidence
-
mcp_2026_compatibility_gatewaymcp 2026 compatibility gateway
-
durable_agent_taskdurable agent task
-
task_checkpoint_evidencetask checkpoint evidence
-
task_cancel_assurancetask cancel assurance
-
agent_approval_relayagent approval relay
-
capability_negotiation_preflightcapability negotiation preflight
-
mcp_catalog_cache_guardmcp catalog cache guard
-
oauth_issuer_binding_evidenceoauth issuer binding evidence
-
mcp_a2a_task_bridgemcp a2a task bridge
-
quote_freshness_guardquote freshness guard
-
delegated_credential_guarddelegated credential guard
-
agent_session_continuityagent session continuity
-
task_lease_guardtask lease guard
-
tool_result_schema_validatortool result schema validator
-
agent_memory_provenanceagent memory provenance
-
payment_delivery_atomicitypayment delivery atomicity
-
service_failover_selectorservice failover selector
-
agent_rate_limit_negotiatoragent rate limit negotiator
-
execution_cost_estimatorexecution cost estimator
-
cross_agent_receipt_bundlecross agent receipt bundle
-
capability_verificationcapability verification
-
capability_benchmarkcapability benchmark
-
sybil_reputation_guardsybil reputation guard
-
agent_behavior_fingerprintagent behavior fingerprint
-
trust_anomaly_detectortrust anomaly detector
-
economic_loop_detectoreconomic loop detector
-
provider_quality_predictorprovider quality predictor
-
transaction_risk_scoretransaction risk score
-
payment_optimizerpayment optimizer
-
x402_v2_routerx402 v2 router
-
erc8004_identity_evidenceerc8004 identity evidence
-
erc8004_reputation_intelligenceerc8004 reputation intelligence
-
delegated_spend_policydelegated spend policy
-
ap2_mandate_bridgeap2 mandate bridge
-
a2a_transaction_bridgea2a transaction bridge
-
mcp_transaction_gatewaymcp transaction gateway
-
proof_of_serviceproof of service
-
automated_dispute_bundleautomated dispute bundle
-
transaction_recovery_v2transaction recovery v2
-
reputation_update_receiptreputation update receipt
-
agent_economic_graphagent economic graph
-
market_demand_predictormarket demand predictor
-
service_gap_detectorservice gap detector
-
price_discovery_engineprice discovery engine
-
sla_risk_predictorsla risk predictor
-
dynamic_service_pricingdynamic service pricing
-
autonomous_procurementautonomous procurement
-
multi_agent_escrowmulti agent escrow
-
cross_protocol_receiptcross protocol receipt
This list was read from the server itself, by connecting to it and calling tools/list on 24 September 2026. It is what
the server actually exposes, not what its listing claims.
Mutating and Read-only are read off each tool's name, not its schema — a hint, not a guarantee. The registry stores tool names only; connect the server for its live schemas.