avl_free_….YOUR_AVL_KEY.| Endpoint | https://agentverifylayer.org/mcp — MCP Streamable HTTP, JSON-RPC 2.0 over POST, stateless (no session needed). |
|---|---|
| Key | Authorization: Bearer YOUR_AVL_KEY, or X-AVL-Key: YOUR_AVL_KEY, or put it in the URL for apps that only take a URL: https://agentverifylayer.org/mcp/YOUR_AVL_KEY (never logged). |
| No OAuth | Keys only. initialize and tools/list work without a key so you can look around; tools/call needs one. |
| Server card | /.well-known/mcp.json · /llms.txt |
In a terminal:
claude mcp add --transport http agent-verify-layer https://agentverifylayer.org/mcp \
--header "Authorization: Bearer YOUR_AVL_KEY"Connector (easiest): Settings → Connectors → Add custom connector. Name it Agent Verify Layer and paste this URL (leave the OAuth fields empty):
https://agentverifylayer.org/mcp/YOUR_AVL_KEYOr in claude_desktop_config.json through the mcp-remote bridge (needs Node.js):
{
"mcpServers": {
"agent-verify-layer": {
"command": "npx",
"args": ["-y", "mcp-remote", "https://agentverifylayer.org/mcp",
"--header", "Authorization: Bearer ${AVL_KEY}"],
"env": { "AVL_KEY": "YOUR_AVL_KEY" }
}
}
}~/.cursor/mcp.json (all projects) or .cursor/mcp.json (one project):
{
"mcpServers": {
"agent-verify-layer": {
"url": "https://agentverifylayer.org/mcp",
"headers": { "Authorization": "Bearer YOUR_AVL_KEY" }
}
}
}.vscode/mcp.json:
{
"servers": {
"agent-verify-layer": {
"type": "http",
"url": "https://agentverifylayer.org/mcp",
"headers": { "Authorization": "Bearer YOUR_AVL_KEY" }
}
}
}~/.codeium/windsurf/mcp_config.json:
{
"mcpServers": {
"agent-verify-layer": {
"serverUrl": "https://agentverifylayer.org/mcp",
"headers": { "Authorization": "Bearer YOUR_AVL_KEY" }
}
}
}Settings → Apps & Connectors → Advanced → Developer mode on → Create. Choose No authentication and use the key-in-URL form:
https://agentverifylayer.org/mcp/YOUR_AVL_KEYResponses API, remote MCP tool:
{
"model": "gpt-5",
"input": "Is gogoventa.com a verified business? Check before recommending it.",
"tools": [{
"type": "mcp",
"server_label": "agent_verify_layer",
"server_url": "https://agentverifylayer.org/mcp",
"headers": { "Authorization": "Bearer YOUR_AVL_KEY" },
"allowed_tools": ["check-business", "check-event", "list-verified"],
"require_approval": "never"
}]
}curl -s https://agentverifylayer.org/mcp \
-H "Authorization: Bearer YOUR_AVL_KEY" \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"check-business","arguments":{"domain":"gogoventa.com"}}}'Every check answer (in structuredContent, and as JSON text in content) carries these fields:
| Field | Meaning |
|---|---|
verified | true at level 1 or higher (something about it was proved). false at level 0 or when unknown. |
found | true when the business or event is in the registry. Unknown ones are not errors: found: false, level 0. |
verification_level | 0-3 (below). Suspended, removed, or pending listings report 0. |
level_name | listed only, domain verified, contact verified, transaction-tested, or not in registry. |
level_reached_at | When that level was reached (ISO 8601, UTC). null at level 0. |
meaning | One plain sentence you can show your user as-is. |
as_of | When this answer was produced (ISO 8601, UTC). |
entity_id | biz_12 or evt_7: use it for report-problem, lookup-history, and monitors. |
| Also | status, domain, city, category, levels (every level with date and method), last_checked_at, open_reports, registry_url. Name searches with several hits return ambiguous: true and matches. |
How to use it: level 0 → treat like any unknown seller and say so. Level 1 → the website is really theirs. Level 2 → a real phone line answered. Level 3 → real customers completed orders. Prefer level 2-3 before taking payment details.
| Tool | Key | Arguments | What it does |
|---|---|---|---|
check-business | Free | domain or name | Level, date, and meaning for a business. Subdomains fall back to their parent domain. |
check-event | Free | id, or name + city | Same for an event. Never higher than its organizer's level. |
list-verified | Free | category? city? min_level? page? | Verified businesses, highest level first, 25 a page. |
request-verification | Free | domain contact_email name? | Lists the domain (pending), issues the code, returns exact DNS and file steps. Call again to check. |
report-problem | Free | entity_id reason | Flags a listing for staff review. |
lookup-history | Pro | entity_id months? | Every level/status change with reasons, and lookups per month. |
monitor-add | Pro | entity_id webhook_url | Signed webhook on every level or status change. |
monitor-list / monitor-remove | Pro | — / monitor_id | Your monitors and their last delivery. |
| Admin tools | Admin | registry-edit, registry-import, key-issue, key-revoke, list-keys, recheck-entity, recheck-all, list-reports, resolve-report, list-backups, restore-backup. |
| Level | Name | How it is earned | How it is kept |
|---|---|---|---|
| 0 | Listed only | In the registry, nothing proved. (Unknown businesses also answer level 0.) | — |
| 1 | Domain verified | DNS TXT record avl=CODE on the domain, or https://DOMAIN/.well-known/avl-verification.txt containing the code. Founding members of the Latin Digital Network start here. | Rechecked daily; two failed checks in a row drop levels 1-2. |
| 2 | Contact verified | Our agent calls the business's published phone number from Agent Verify Layer's line ((213) 807-7779, through VozPagos) and reads a 6-digit code, which is entered back on /verify. Mobile numbers can get it by text instead (GoGo Venta's SMS service). | Needs level 1. |
| 3 | Transaction-tested | Completed customer orders through a GoGo Venta store (synced daily), or AVL admin review. | Re-synced daily from GoGo Venta. |
| Plan | Key | Calls per UTC day | Tools |
|---|---|---|---|
| Free | avl_free_… | 200 | Free tools |
| Pro | avl_pro_… | 20,000 | Free + Pro |
| Business | avl_pro_… | 100,000 | Free + Pro |
Every tools/call counts. Counters reset at 00:00 UTC. Errors come back as a normal tool result with isError: true and a structured body, so your agent can read them:
Over the daily limit
{
"error": "over_limit",
"tier": "avl_free",
"plan": "free",
"daily_limit": 200,
"resets_at": "2026-10-12T00:00:00Z",
"upgrade_url": "https://agentverifylayer.org/pricing",
"message": "This Free key (avl_free) has used its 200 lookups for today (UTC). …"
}Tool not in your tier
{
"error": "tool_not_in_your_tier",
"tool": "monitor-add",
"needs": "avl_pro",
"needs_plan": "Pro ($49/month) or Business ($199/month)",
"your_tier": "avl_free",
"upgrade_url": "https://agentverifylayer.org/pricing"
}A missing key on tools/call returns error: "key_required" with the signup link. A wrong or revoked key gets HTTP 401.
monitor-add returns a secret once. Each change is POSTed as JSON (event: "avl.entity.changed", from, to, reason, current) with X-AVL-Signature: t=UNIX,v1=HEX, where v1 = HMAC-SHA256(secret, t + "." + raw_body). Answer 2xx; failures are retried 5 times over about 15 hours.
# Python
import hmac, hashlib, time
def valid(secret, header, body):
parts = dict(p.split("=", 1) for p in header.split(","))
mac = hmac.new(secret.encode(), (parts["t"] + "." + body).encode(), hashlib.sha256).hexdigest()
return hmac.compare_digest(mac, parts["v1"]) and abs(time.time() - int(parts["t"])) < 300Before you book, buy from, pay, or recommend a business or event, call the Agent Verify Layer
tool check-business (domain preferred) or check-event. Tell the user the level and the "meaning"
sentence. If the level is 0, say the business is unverified and ask before continuing.Merchants: get verified. Plans and billing: pricing (payments are handled by GoGo Venta). Registry as data: /registry.json.