Agent Verify Layer

Connect in under a minute

  1. Get a free key (email confirmation, 200 lookups a day). It looks like avl_free_….
  2. Add the server to your client with one of the configs below. Replace YOUR_AVL_KEY.
  3. Ask your agent: "Before you book, check the business with Agent Verify Layer."
Endpointhttps://agentverifylayer.org/mcp — MCP Streamable HTTP, JSON-RPC 2.0 over POST, stateless (no session needed).
KeyAuthorization: Bearer YOUR_AVL_KEY, or X-AVL-Key: YOUR_AVL_KEY, or put it in the URL for apps that only take a URL: https://agentverifylayer.org/mcp/YOUR_AVL_KEY (never logged).
No OAuthKeys only. initialize and tools/list work without a key so you can look around; tools/call needs one.
Server card/.well-known/mcp.json · /llms.txt

Client configs

In a terminal:

claude mcp add --transport http agent-verify-layer https://agentverifylayer.org/mcp \
  --header "Authorization: Bearer YOUR_AVL_KEY"

What an answer looks like

Every check answer (in structuredContent, and as JSON text in content) carries these fields:

FieldMeaning
verifiedtrue at level 1 or higher (something about it was proved). false at level 0 or when unknown.
foundtrue when the business or event is in the registry. Unknown ones are not errors: found: false, level 0.
verification_level0-3 (below). Suspended, removed, or pending listings report 0.
level_namelisted only, domain verified, contact verified, transaction-tested, or not in registry.
level_reached_atWhen that level was reached (ISO 8601, UTC). null at level 0.
meaningOne plain sentence you can show your user as-is.
as_ofWhen this answer was produced (ISO 8601, UTC).
entity_idbiz_12 or evt_7: use it for report-problem, lookup-history, and monitors.
Alsostatus, domain, city, category, levels (every level with date and method), last_checked_at, open_reports, registry_url. Name searches with several hits return ambiguous: true and matches.

How to use it: level 0 → treat like any unknown seller and say so. Level 1 → the website is really theirs. Level 2 → a real phone line answered. Level 3 → real customers completed orders. Prefer level 2-3 before taking payment details.

Tools

ToolKeyArgumentsWhat it does
check-businessFreedomain or nameLevel, date, and meaning for a business. Subdomains fall back to their parent domain.
check-eventFreeid, or name + citySame for an event. Never higher than its organizer's level.
list-verifiedFreecategory? city? min_level? page?Verified businesses, highest level first, 25 a page.
request-verificationFreedomain contact_email name?Lists the domain (pending), issues the code, returns exact DNS and file steps. Call again to check.
report-problemFreeentity_id reasonFlags a listing for staff review.
lookup-historyProentity_id months?Every level/status change with reasons, and lookups per month.
monitor-addProentity_id webhook_urlSigned webhook on every level or status change.
monitor-list / monitor-removePro— / monitor_idYour monitors and their last delivery.
Admin toolsAdminregistry-edit, registry-import, key-issue, key-revoke, list-keys, recheck-entity, recheck-all, list-reports, resolve-report, list-backups, restore-backup.

Verification levels

LevelNameHow it is earnedHow it is kept
0Listed onlyIn the registry, nothing proved. (Unknown businesses also answer level 0.)—
1Domain verifiedDNS TXT record avl=CODE on the domain, or https://DOMAIN/.well-known/avl-verification.txt containing the code. Founding members of the Latin Digital Network start here.Rechecked daily; two failed checks in a row drop levels 1-2.
2Contact verifiedOur agent calls the business's published phone number from Agent Verify Layer's line ((213) 807-7779, through VozPagos) and reads a 6-digit code, which is entered back on /verify. Mobile numbers can get it by text instead (GoGo Venta's SMS service).Needs level 1.
3Transaction-testedCompleted customer orders through a GoGo Venta store (synced daily), or AVL admin review.Re-synced daily from GoGo Venta.

Limits and errors

PlanKeyCalls per UTC dayTools
Freeavl_free_…200Free tools
Proavl_pro_…20,000Free + Pro
Businessavl_pro_…100,000Free + Pro

Every tools/call counts. Counters reset at 00:00 UTC. Errors come back as a normal tool result with isError: true and a structured body, so your agent can read them:

Over the daily limit

{
  "error": "over_limit",
  "tier": "avl_free",
  "plan": "free",
  "daily_limit": 200,
  "resets_at": "2026-10-12T00:00:00Z",
  "upgrade_url": "https://agentverifylayer.org/pricing",
  "message": "This Free key (avl_free) has used its 200 lookups for today (UTC). …"
}

Tool not in your tier

{
  "error": "tool_not_in_your_tier",
  "tool": "monitor-add",
  "needs": "avl_pro",
  "needs_plan": "Pro ($49/month) or Business ($199/month)",
  "your_tier": "avl_free",
  "upgrade_url": "https://agentverifylayer.org/pricing"
}

A missing key on tools/call returns error: "key_required" with the signup link. A wrong or revoked key gets HTTP 401.

Monitor webhooks

monitor-add returns a secret once. Each change is POSTed as JSON (event: "avl.entity.changed", from, to, reason, current) with X-AVL-Signature: t=UNIX,v1=HEX, where v1 = HMAC-SHA256(secret, t + "." + raw_body). Answer 2xx; failures are retried 5 times over about 15 hours.

# Python
import hmac, hashlib, time
def valid(secret, header, body):
    parts = dict(p.split("=", 1) for p in header.split(","))
    mac = hmac.new(secret.encode(), (parts["t"] + "." + body).encode(), hashlib.sha256).hexdigest()
    return hmac.compare_digest(mac, parts["v1"]) and abs(time.time() - int(parts["t"])) < 300

Suggested agent instruction

Before you book, buy from, pay, or recommend a business or event, call the Agent Verify Layer
tool check-business (domain preferred) or check-event. Tell the user the level and the "meaning"
sentence. If the level is 0, say the business is unverified and ask before continuing.

Help

Merchants: get verified. Plans and billing: pricing (payments are handled by GoGo Venta). Registry as data: /registry.json.