
This is the missing API layer for the 60 million small businesses that don't have one. It exposes 14 operations over MCP to let agents find, verify, message, and book appointments with barbers, plumbers, and accountants through whatever channel actually reaches them: Cal.com, SMS, voice AI, email, or web form fallback. Every write operation costs USDC on Base via x402 payment rails, so agents pay per call without API keys or signup. The compliance layer is non-bypassable and blocks TCPA/GDPR violations before they go out. Reach for this when your agent needs to schedule a haircut or get a roofing quote and you don't want to scrape booking sites or cold call by voice.
Public tool metadata for what this MCP can expose to an agent.
register_agentCreate a new agent account on AgentBroker. Returns an api_key for all authenticated operations. Use mode="sandbox" to start with $10,000 virtual USDC for testing, or mode="live" for real trading.3 paramsCreate a new agent account on AgentBroker. Returns an api_key for all authenticated operations. Use mode="sandbox" to start with $10,000 virtual USDC for testing, or mode="live" for real trading.
modestringsandbox · livenamestringowner_emailstringget_pricesFetch real-time market prices for all 8 crypto pairs (BTC, ETH, SOL, AVAX, LINK, DOGE, ARB, MATIC — all vs USDC). No authentication required. Data sourced from CoinGecko, updated every 30 seconds.Fetch real-time market prices for all 8 crypto pairs (BTC, ETH, SOL, AVAX, LINK, DOGE, ARB, MATIC — all vs USDC). No authentication required. Data sourced from CoinGecko, updated every 30 seconds.
No parameter schema in public metadata yet.
get_balanceCheck your USDC balance, active trading strategy, total deposited, and trade count. Requires your api_key.1 paramsCheck your USDC balance, active trading strategy, total deposited, and trade count. Requires your api_key.
api_keystringdepositAdd USDC funds to your account. For sandbox accounts this adds virtual test funds. For live accounts, provide the transaction hash. Requires your api_key.3 paramsAdd USDC funds to your account. For sandbox accounts this adds virtual test funds. For live accounts, provide the transaction hash. Requires your api_key.
amountnumberapi_keystringtx_hashstringselect_strategyChoose a trading strategy for your agent. Must be set before placing orders. Available: momentum (trend-following), grid (range trading), mean_reversion (buy dips/sell peaks). Requires your api_key.2 paramsChoose a trading strategy for your agent. Must be set before placing orders. Available: momentum (trend-following), grid (range trading), mean_reversion (buy dips/sell peaks). Requires your api_key.
api_keystringstrategystringmomentum · grid · mean_reversionplace_orderExecute a trade. Supports market orders (immediate fill at best price) and limit orders (fill only at specified price or better). Requires api_key and an active strategy selected first.6 paramsExecute a trade. Supports market orders (immediate fill at best price) and limit orders (fill only at specified price or better). Requires api_key and an active strategy selected first.
api_keystringpairstringpricenumberquantitynumbersidestringbuy · selltypestringmarket · limitget_order_bookView the current order book for a trading pair — top 10 bids (buyers) and asks (sellers) with prices and quantities. No authentication required.1 paramsView the current order book for a trading pair — top 10 bids (buyers) and asks (sellers) with prices and quantities. No authentication required.
pairstringget_tradesView your executed trade history with fill prices, quantities, fees, and timestamps. Requires your api_key.3 paramsView your executed trade history with fill prices, quantities, fees, and timestamps. Requires your api_key.
api_keystringlimitintegeroffsetintegerwithdrawWithdraw USDC from your live account to a wallet address. Not available for sandbox accounts. Requires your api_key.3 paramsWithdraw USDC from your live account to a wallet address. Not available for sandbox accounts. Requires your api_key.
amountnumberapi_keystringdestination_addressstringAn agent-callable MCP server that lets autonomous AI agents find, verify, message, schedule with, and transact with small and mid-sized businesses (SMBs) through a single compliance-enforced tool surface.
Live endpoint: https://hatchloop.dev/mcp/agent-broker (streamable-http, always-on Cloudflare edge)
There are ~60 million long-tail small businesses in the US - barbers, plumbers, accountants, home cleaners - and they have no API surface. AI agents that need to schedule a haircut, get a quote, or send a confirmation today must either drive a browser, cold-call by voice, or give up.
This server is the missing middle layer. Agents call us; we route to the right SMB through whichever channel reaches them fastest - Cal.com -> WhatsApp -> SMS -> voice AI -> email - with full TCPA / GDPR / CASL / 10DLC compliance enforced as a non-bypassable gate.
| Capability | Status |
|---|---|
| MCP endpoint (streamable-http) | Live - https://hatchloop.dev/mcp/agent-broker |
| 23 MCP tools | Live (callable today) |
| Compliance gate (TCPA/GDPR/CASL) | Live |
| REST + A2A + OpenAI/Anthropic tool surfaces | Live |
| SMB supply network | Demo - 20+ seed SMBs; demo bookings return demo_smb_no_live_booking |
| Billing | Live - 12 utility tools free (no key, unmetered). Premium data tools (company verification, sanctions, trade screening): free up to a daily limit (500/day with a free key, 100/day anonymous), then $0.02/call via credits. Write tools: free email-verified key (100 ops/day) at hatchloop.dev/agent-broker; credit packages from $9/1,000 credits at hatchloop.dev/pricing;. |
| x402 payment rail | Offered, opt-in. Enabled on the service since the founder lifted the crypto restriction on 2026-08-29. A caller attaches a payment in params._meta["x402/payment"] and the call is served without a key (USDC on Base, proven once on mainnet, tx 0x38a0d9ec). Callers who do not attach one fall through to credits and the free quota, so nothing is gated behind it. /.well-known/x402 is still a 404 - discovery is via /.well-known/mcp.json, which lists the rail. |
| Production SMB onboarding | Planned - real businesses not yet enrolled |
The MCP server is live and callable right now. Bookings hit demo data. 12 utility tools are free (no key, unmetered). Premium data tools (verify_company_record, screen_sanctions, map_trade_restriction) are free up to a daily limit; beyond that, $0.02/call via credits. Write tools require a free email-verified key (100 ops/day) - get one at https://hatchloop.dev/agent-broker. Credit packages from $9/1,000 credits at https://hatchloop.dev/pricing.
All tools are callable via MCP, REST, OpenAI function calling, Anthropic tool_use, or A2A protocol.
| # | Tool | What it does | Auth |
|---|---|---|---|
| 1 | find_business | Search SMBs by vertical, location, and capability | free |
| 2 | verify_business | Confirm an SMB is real, operating, and capable of the requested service | free |
| 3 | get_status | Poll the current state of an async operation | free |
| 4 | get_outcome | Retrieve the final OutcomeReceipt (with cost and reason codes) | free |
| 5 | preview_cost | Estimate cost, latency, and success probability before committing | free |
| 6 | self_test | Verify service health and all claimed capabilities are responding | free |
| 7 | check_quota | Inspect your remaining daily quota and tier without consuming any ops - call at session start or after a rate_limited error | free |
| 8 | check_booking_link | Classify a URL and confirm import_booking_url will accept it - sub-100ms pre-flight | free |
| 9 | check_compliance | Preview TCPA/GDPR/CASL/10DLC gate result before spending a paid send | free |
| 10 | verify_company_record | Live GLEIF LEI registry + SEC EDGAR lookup - official legal name, status, jurisdiction, address | free up to daily limit |
| 11 | screen_sanctions | Check a name or entity against OFAC SDN, the EU Consolidated list and the UK Sanctions List | free up to daily limit |
| 12 | map_trade_restriction | OFAC country embargoes + export-control Entity List + sanctioned-party screening for a proposed shipment | free up to daily limit |
| 13 | get_conversation | Read a two-way thread you started: state, full transcript, reply count | free |
| 14 | lookup_us_contracts | Search US federal contract awards by company name via USASpending.gov - awardee, agency, amount, NAICS, period | free |
| 15 | send_message | Send WhatsApp, SMS, email, or voice with compliance pre-check enforced | key |
| 16 | capture_lead | Structured intake of a prospect into an SMB pipeline with CRM integration | key |
| 17 | schedule_appointment | Book, reschedule, or cancel - tries direct booking API, falls back to voice AI | key |
| 18 | send_transactional_confirmation | TCPA-exempt OTPs, booking confirmations, receipts | key |
| 19 | handle_inbound | Classify inbound messages: booking / cancel / opt-out / question / complaint | key |
| 20 | escalate_to_human | Hand off a stuck or ambiguous task to a human operator with full context | key |
| 21 | import_booking_url | Turn any Cal.com, Calendly, Doctolib, Booksy, OpenTable, Square, Acuity, or Fresha URL into a bookable SMB record | key |
| 22 | call_business | Place a conversational voice-AI phone call to a business on behalf of a consumer | key |
| 23 | mint_key | Issue a free-tier agent identity key via HMAC proof - no email required, no human in the loop | free |
Free key (100 write ops/day + 500 premium data calls/day): https://hatchloop.dev/agent-broker - Credits from $9/1,000 ops: https://hatchloop.dev/pricing - Premium data beyond quota: $0.02/call
{
"mcpServers": {
"agent-broker": {
"url": "https://hatchloop.dev/mcp/agent-broker"
}
}
}
12 tools require no key (find_business, verify_business, verify_company_record, screen_sanctions, map_trade_restriction, check_booking_link, check_compliance, get_conversation, get_status, get_outcome, preview_cost, self_test).
Write tools require an X-Agent-Identity bearer token:
POST https://api.hatchloop.dev/keys/mint - see Machine-mintable keys below.Add your key to the config once you have one:
{
"mcpServers": {
"agent-broker": {
"url": "https://hatchloop.dev/mcp/agent-broker",
"headers": {
"X-Agent-Identity": "Bearer YOUR_KEY_HERE"
}
}
}
}
npx agentbroker-mcp
With a key:
AGENT_BROKER_KEY=your_key npx agentbroker-mcp
curl -X POST https://hatchloop.dev/mcp/agent-broker \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}'
curl -X POST https://hatchloop.dev/mcp/agent-broker \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 2,
"method": "tools/call",
"params": {
"name": "find_business",
"arguments": {
"vertical": "personal_services",
"location": {"zip_or_city": "30309"},
"capability": "haircut"
}
}
}'
import httpx, openai
tools = httpx.get(
"https://hatchloop.dev/.well-known/openai-tools.json"
).json()["tools"]
client = openai.OpenAI()
resp = client.chat.completions.create(
model="gpt-4o",
messages=[{"role": "user", "content": "Book a haircut in Atlanta Saturday under $50"}],
tools=tools,
)
import httpx, anthropic
tools = httpx.get(
"https://hatchloop.dev/.well-known/anthropic-tools.json"
).json()["tools"]
client = anthropic.Anthropic()
msg = client.messages.create(
model="claude-opus-4-5",
max_tokens=1024,
tools=tools,
messages=[{"role": "user", "content": "Book a haircut in Atlanta Saturday under $50"}],
)
curl -X POST https://hatchloop.dev/ops/find_business \
-H "Content-Type: application/json" \
-d '{"vertical":"personal_services","location":{"zip_or_city":"30309"},"capability":"haircut"}'
AI agents that cannot receive email can self-provision a free-tier API key (100 gated ops/day) by proving identity via HMAC-SHA256.
MACHINE_MINT_SECRET from hatchloop.dev/docs/#machine-mint.signature = HMAC-SHA256(agent_id + str(timestamp) + nonce, MACHINE_MINT_SECRET)
The HMAC input is the raw concatenation of the three fields (no separators). Digest must be lowercase hex.https://api.hatchloop.dev/keys/mint:{
"agent_id": "my-agent-abc123",
"timestamp": 1725100000,
"nonce": "4f8a2c1d9e2b7c6a",
"signature": "<lowercase-hex-hmac>"
}
{
"ok": true,
"key": "<JWT - use as X-Agent-Identity header>",
"key_id": "free_machine_<hash>",
"expires_at": "2026-11-28",
"tier": "free",
"daily_limit": 100,
"usage": "Send as the X-Agent-Identity header on every call to https://hatchloop.dev/mcp/agent-broker"
}
timestamp must be within 60 seconds of server time (prevents replay attacks).nonce on every call (UUID or random hex).agent_id is a stable identifier for your agent; the issued key is tied to its SHA-256 hash.401 {error: "invalid_request"} on bad signature or stale timestamp.503 {error: "not_configured"} if the server secret has not been set (contact hello@hatchloop.dev).| Surface | URL |
|---|---|
| MCP (streamable-http) | https://hatchloop.dev/mcp/agent-broker |
| MCP descriptor | https://hatchloop.dev/.well-known/mcp.json |
| OpenAI function tools | https://hatchloop.dev/.well-known/openai-tools.json |
| Anthropic tool_use | https://hatchloop.dev/.well-known/anthropic-tools.json |
| A2A (Agent-to-Agent) | https://hatchloop.dev/.well-known/agents.json |
| OpenAI ChatGPT plugin | https://hatchloop.dev/.well-known/ai-plugin.json |
| llms.txt | https://hatchloop.dev/llms.txt |
| OpenAPI 3.1 | https://hatchloop.dev/openapi.yaml |
| npm shim (stdio) | npx agentbroker-mcp |
| Glama MCP Registry | Listed via glama.json |
| MCP Registry | Listed via server.json |
AI agent
|
v MCP / REST / A2A
Cloudflare Worker edge (hatchloop.dev)
| 300+ PoPs globally -- discovery served from edge bundle in 40-70 ms
|
+-- GET /.well-known/* /manifest /llms.txt --> embedded snapshot (40-70 ms)
+-- POST /mcp initialize / tools/list --> embedded snapshot (40-65 ms)
+-- POST /mcp tools/call /ops/* --> proxy to origin (170-190 ms)
|
v
Python FastAPI (api.hatchloop.dev)
| Cron keep-alive every 2 min (eliminates Render cold starts)
|
+-- 23 operation handlers (core/)
+-- Compliance gate (compliance/pre_check)
+-- Channel adapters (channels/ -- Twilio, Cal.com, Vapi, SendGrid)
+-- Billing + outcome store
+-- All .well-known / MCP endpoints (also served from edge bundle)
The edge worker can outlive the origin: discovery still works even if the origin is down. Idempotency is keyed by (agent_id, operation, idempotency_key) with 24h TTL. Async operations return pending_async; poll with get_status / get_outcome.
Every outbound communication passes through compliance/pre_check():
Violations surface as ComplianceViolationError and are never silently bypassed.
agentbroker/
+-- core/ # 23 operation handlers + shared Pydantic models
+-- channels/ # Twilio, SendGrid, Vapi, Bland, Cal.com, Playwright
+-- compliance/ # pre_check, jurisdiction_rules, consent_store, audit_log
+-- reliability/ # retry, circuit_breaker, channel_fallback, async_runner
+-- billing/ # meter, budget_guard, receipt_signer, pricing_tiers
+-- telemetry/ # tracer, log_redactor, metrics_emitter
+-- storage/ # outcome_store, idempotency_store
+-- supply/ # smb_directory (20+ seed/demo SMBs)
+-- onboarding/ # self_serve, verification_flow, channel_capture
+-- feedback/ # failure_classifier, attribution_engine, outcome_evaluator
+-- optimizer/ # ab_router, selection_analytics, weekly_report
+-- agent_interface/ # manifest_server, mcp_server, well_known, identity, webhooks
+-- manifest/ # manifest.json, mcp_tools.json, openapi.yaml
+-- api/ # errors.md, identity.md, async.md
+-- docs/ # mission, architecture, compliance, ADRs
+-- edge/ # Cloudflare Worker (TypeScript/Hono)
+-- deploy/ # Dockerfile, docker-compose.yml
+-- tests/ # unit, contract, compliance, fault_injection, agent_sim
+-- main.py # FastAPI entry point
+-- config.py # Centralized config from env
+-- requirements.txt
# Install dependencies
pip install -r requirements.txt
# Run tests (1173 passing at the time of writing)
python -m pytest tests/ -q
# Start the API
python main.py
# --> http://localhost:8000/docs (Swagger UI)
# --> http://localhost:8000/mcp (MCP endpoint)
# --> http://localhost:8000/manifest (capability manifest)
# Run the agent simulation harness
python -m tests.agent_sim.harness
# Self-test
python -c "import asyncio; from agent_interface.self_test import run_self_test; print(asyncio.run(run_self_test()).all_passed)"
Or with Docker:
docker compose -f deploy/docker-compose.yml up
Licensed under MIT. Issues and discussion are welcome - open a GitHub issue to report bugs or suggest features. For substantial changes, please open an issue first to discuss direction. Note: this repo is the open-source server; the hosted service at hatchloop.dev (supply index, billing rails) is operated by Hatchloop.
MIT - see LICENSE. The hosted service and its supply/billing data are operated separately by Hatchloop.
Built by Basil Al-Shukaili. Listed on the MCP Registry and Glama.