Is gate402 merchant checkout MCP server safe?
Yes, with the usual care.
Passed every safety check we run. Maintained, authenticated, reachable, clean scan.
No critical or high findings in the latest scan.
Public scan report
scanner v0.1.7 · 2026-09-19 · same rubric, same numbers if you re-run it
no findings
- –Code scanremote-only server, no package to scann/a
- Live reliabilityremote reachable in 262ms; handshake note: [ { "expected": "object", "code": "invalid_type", "path": [ "capabilities" ], "message": "In20/20
- –Tool poisoningtools not inspected (endpoint requires auth); not countedn/a
- Auth qualityopen endpoint, read-only tools10/15
- Maintenancelast push 11 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year; website matches verified namespace10/10
Overall 92/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON
Other servers that do what gate402 merchant checkout does
- AgentPayRU merchant catalog for AI agents: live price, stock, choices and controlled checkout. Not x402.not reviewedGrowingA
- PipRailBudget-bound x402 payment wallet for AI agents — pays HTTP 402 URLs, capped locally. No backend.not reviewedGrowingB
POPCORN MCPSigned time and SHA-256 witness receipts for agents, with offline verification and x402 payment.not reviewedGrowingB