Skip to content
clusters: prooflayer · edgemarket · edgefinance · synthforge · mediakit · wordmint · webprobe · locale · comppoint · rollforge · bestiary · statline · matchpoint · retail · agentops · browserworkflow · modelrouter · compose
$ man inbound-message-firewall

/inbound-message-firewall

agentutility / compose / inbound-message-firewall
PRICE / CALL
$0.06
USDC · base mainnet · scheme: exact
METHOD
POST
CLUSTER
compose
CATEGORY
uncategorized
STATUS
live
NAME
inbound-message-firewall one call an agent makes before trusting an inbound message that also carries a claimed source link: an email with a link, a dm citing a u…
SYNOPSIS
POST https://x402.agentutility.ai/inbound-message-firewall
     Content-Type: application/json
     X-PAYMENT:    <signed-transferWithAuthorization>

     { ... }
↳ first call → 402 Payment Required. Sign USDCtransferWithAuthorization, retry with theX-PAYMENT header.
DESCRIPTION

One call an agent makes before trusting an inbound message that also carries a claimed source link: an email with a link, a DM citing a URL, a tool result referencing a page. Composite: one call runs prompt-injection-detect (required, a failure fails the call), moderate-content and ai-content-detector (both degradable, the latter skips silently under its own length floor), and content-authenticity-report on source_url when given (degradable). agent-input-guard screens text only; this adds the source-URL check, so an agent can decide whether to act on 'per this report, do X' in one call. Returns one act/verify/block decision, a risk score, and per-leg detail. Use it as an inbound message firewall, agent trust gate, message-plus-source verification API, or a pre-action guardrail for autonomous agents.

INPUTrequest schema
propertytypedescriptionreq?
messagestringThe inbound message text to screen before the agent acts on it, e.g. an email body, DM, or tool result. Min 15 chars, max 20000.required
source_urlstringOptional http/https URL the message cites as its source, e.g. an article it claims to be reporting on. When given, the source's own authenticity is checked and feeds the verdict.optional
contextstringOptional note on what the agent plans to do with this message, e.g. 'transfer funds if instructed'. Max 500 chars, passed through to the injection-screen leg.optional
OUTPUTresponse shape
fieldtypedescription
verdictstring
risk_scorestring
injectionstring
moderationstring
message_ai_slopstring
source_checkstring
composed_ofstring
componentsstring
degradedstring
EXAMPLEStwo ways to call
EXAMPLE 1 · curl
curl -X POST https://x402.agentutility.ai/inbound-message-firewall \
  -H 'Content-Type: application/json' \
  -d '{ }'
first response = 402 Payment Required with payment requirements; sign + retry with X-PAYMENT.
EXAMPLE 2 · mcp
# Install the MCP package for this endpoint's cluster
npx -y @agentutility/mcp-<cluster>

# Required: EVM private key with USDC on Base
export X402_PRIVATE_KEY=0x...

# Then call the inbound-message-firewall tool from your MCP-aware agent.
MCP server handles payment automatically — your coding agent just calls the tool by name.
METADATA
tags
composeinboundmessagefirewallinbound-message-firewall
methods
POST
cluster
compose
price
$0.06 USDC per call
ADJACENTother endpoints in compose
endpointdescriptionprice
agent-run-reviewAgent run review / trace cost evals / post-run analysis / agent debugging in one call: hand it a raw agent execution trace and get a read…$0.06
authentic-sentimentAuthentic sentiment API: send a topic, brand, handle, or phrase and get back sentiment from real humans, not bots or AI astroturf.$0.06
brand-availability-sweepBrand availability sweep API for a name availability check before you commit to a startup, product, or project name: trademark signal, do…$0.06
browser-workflow-repairBrowser workflow repair / self-healing automation / dom drift fix / flow memory in one call for agents whose CSS selectors broke after a…$0.06
competitor-snapshotSnapshots a company for competitive intelligence in one call: profile, recent news, and news sentiment.$0.06
contact-golden-recordTurn 2-5 messy candidate contact records into one deduplicated golden record with per-field provenance.$0.06
content-authenticity-reportContent authenticity report: send a URL (or raw text) and find out whether a page is AI-generated slop before your agent cites, summarize…$0.06
cross-lingual-topic-monitorMonitor a topic across non-English sources in one call: search the open web and X, detect what language each hit is actually in, translat…$0.06
SEE ALSO
agentutility · compose · x402 · mcp · llms.txt · registry.json · bazaar.x402.org