Docs Leaderboard Categories How it works Free Run free audit →
The compliance layer for MCP servers Free audit · No account Docs →

One scan. 44 checks.
Fix before your users find out.

Paste your URL. Get a full compliance report in 30 seconds.

100% Free · 44 checks · Instant report · No account needed

44
checks / audit
up to 24x
daily monitoring
auto
email alerts
0–100
score + README badge
Sample report — example-api.xyz A · 85/100
x402 discovery /.well-known/x402.json ✓
Trust score endpoint 200 · 336ms
ERC-8004 identity Agent #16850
Security headers 5/5 present ✓
llms.txt encoding ⚠ fix recommended
Zero-address block ✗ fix required
CORS headers origin: * ✓
OpenAPI spec 3.0.3 · 12 paths ✓
EU AI Act disclosure ⚠ no model card
Travel Rule (FATF) ⚠ no VASP disclosure
A2A Protocol 3 skills · streaming ✓
DNSSEC validated (AD flag) ✓
Auth maturity OAuth 2.0 + x402 gate ✓
ERC-8004 on-chain ⚠ not registered
API versioning /v1/ · Sunset header ✓
Human oversight ⚠ No kill switch endpoint
Terms of Service /terms found ✓
Content-Type application/json on 3/4 paths ✓
85
Listing-ready · 2 non-critical fixes remaining
A = listing-ready, minor fixes only · B = needs work · C = will fail x402 validation · D/F = critical compliance gaps
See all 44 checks →
Built for the AI agent ecosystem
“Just had our agent run through Probe. Very helpful.”
— Quigley, Helixa
✓ 44 compliance checks — x402, EU AI Act, MCP, Voice AI, A2A, and more
✓ 100% free — no account, no credit card. Open audits, shareable reports

AI Agent Compliance Monitoring — How It Works

01
Paste your API URL
02
Get your compliance report instantly
03
Subscribe for 24/7 continuous monitoring
Validates against
MCPModel Context Protocol — Probe checks MCP endpoint discovery, tool declarations, and transport security. EU AI ActHuman oversight (Art. 14), AI disclosure, risk classification. Deadline: 2 August 2026. Voice AI NEW10 voice-specific compliance checks: voice disclosure, synthetic voice labeling, call recording consent, caller identity, operator identity, and more. GDPRPrivacy policy, data processing disclosure, DMARC/SPF email security. Security HeadersHSTS, CSP, X-Content-Type-Options, X-Frame-Options, Referrer-Policy. DNSSEC + CAADNS security extensions and Certificate Authority Authorization records. OpenAPIAPI documentation via OpenAPI/Swagger spec validation.

Who is Probe for?

Built for anyone shipping AI agents that touch payments, identity, or onchain services.

AI / Infra Engineers
Catch compliance drift before it hits production. Integrate Probe into your CI/CD pipeline for automated checks.
Compliance & Risk Teams
Continuous evidence of compliance across all agent endpoints. Audit trails and exportable PDF reports for regulators.
Founders & CTOs
Know your agent is listing-ready and compliant before Consensus, investor meetings, or directory submissions.
DevOps & Platform Teams
Real-time Slack alerts, webhook integration, and monitoring dashboards across all your endpoints.

Integrate into your pipeline

Block deploys that fail compliance. Show your score publicly.

CI/CD gate
curl -X POST getprobe.xyz/api/ci \
  -d '{"url":"$API_URL",
       "threshold":70}'

# Returns 200 if pass,
# 422 if below threshold
GitHub Actions example →
README badge
Probe badge example
![Probe](https://getprobe.xyz
  /api/badge?domain=YOUR.com)
Badge docs →

Before & After Probe

See what changes when you add automated compliance monitoring.

Without Probe
  • Manual, ad-hoc compliance checks
  • Issues found by users in production
  • No visibility into endpoint drift
  • Scramble before audits & listings
  • No proof of ongoing compliance
With Probe
  • Automated 44-check audits every 1–12h
  • Alerts before issues become incidents
  • Real-time drift detection & scoring
  • Always listing-ready with live score
  • Shareable reports & badge for README

⚠ EU AI Act enforcement starts August 2, 2026

The EU AI Act requires AI systems to declare human oversight mechanisms, risk levels, and transparency disclosures. MCP servers and AI agent APIs that operate in the EU must comply — or face fines up to €7.5M / 1% of global revenue for transparency violations (Article 50).

Probe checks the technical requirements now:
• Human oversight endpoint (Art. 14) & kill switch
• AI model disclosure & risk classification
• Privacy policy, DMARC, security headers
• Transparency & documentation endpoints

Check your compliance now →

AI Agent API Compliance Leaderboard

Top-scoring APIs from public, opt-in audits.

   
   
   
   
   
Updated in real-time after every audit View full leaderboard →
Is your API on the leaderboard? Run free audit →

x402 Audit Tool — Why Probe?

Purpose-built for AI agent compliance. Not another uptime monitor.

Probe DIY cron + scripts Uptime monitors
x402 / ERC-8004 checks
Sanctions screeningQ3 2026Manual
44 compliance checks (incl. Voice AI)Build yourselfHTTP only
Continuous monitoringEvery 1–12hYou maintain
Shareable reports
Score badge for README
Time to first report~30 secondsDays of engineeringN/A
Setup time0 — just paste URLHours / daysMinutes
Price100% FreeDev time$10–100/mo

Security & Privacy

🔍 Read-only scanning Standard GET/HEAD requests to public endpoints only. No authentication attempts.
🗑 Minimal data retention No request bodies, payloads, or API keys stored. Audit metadata deleted per plan schedule.
🌍 Edge infrastructure Cloudflare edge + Supabase PostgreSQL. All data encrypted in transit and at rest.
🛡 No third-party sharing Audit data never shared. Leaderboard is opt-in and aggregated only.

100% Free

No paid plans. No limits. No account needed. Everything included.

EVERYTHING INCLUDED
$0
No credit card · No account · No limits · Forever
✓ Unlimited audits
✓ All 44 checks
✓ 10 Voice AI checks
✓ Instant report + score
✓ Leaderboard ranking
✓ Fix guides for every check
✓ Shareable report links
✓ No signup required
Run free audit →

We're building the largest AI agent compliance dataset. That's why everything is free — we want maximum adoption.
Need enterprise features? Contact us

Frequently Asked Questions

What is AI agent API compliance monitoring?

It's automated, continuous checking of your AI agent's API endpoints against emerging standards like x402 (payment disclosure), ERC-8004 (agent identity), MCP (Model Context Protocol), Voice AI compliance (EU AI Act Article 50), and security best practices. Probe runs 44 checks and alerts you when anything drifts.

How is Probe different from uptime monitoring?

Uptime monitors only check if your server responds with HTTP 200. Probe checks compliance-specific things: x402 payment metadata, agent identity endpoints, MCP server, llms.txt, security headers, rate limiting, and more. It's purpose-built for AI agents, not generic web apps.

Is Probe free?

Yes — Probe is 100% free. Unlimited audits, all 44 checks including 10 Voice AI compliance checks. No account, no credit card, no limits. We're building the largest AI agent compliance dataset and want maximum adoption first.

Does Probe store my API data?

No. Probe only makes read-only GET/HEAD requests to public endpoints. We never store request bodies, response payloads, or API keys. Only audit metadata (score, check results) is persisted for your plan's retention period.

What is an x402 check?

x402 is an emerging standard for AI agent payment and trust disclosure. Probe checks if your API publishes a .well-known/x402.json file and whether its contents are valid — critical for agent directories and listing approvals.

Can I use Probe with any API?

Probe works with any publicly accessible HTTPS endpoint. It's optimized for AI agent APIs but can audit any API. Just paste your URL and get a report in 30 seconds.

Do you support MiCA compliance checks?

Probe's 44 checks cover the technical compliance foundations that MiCA-regulated services need (x402, identity, security, rate limiting, Voice AI). Dedicated MiCA checks including sanctions screening via Chainalysis oracle are on our roadmap for Q3 2026.

What does the "Zero-address block" check do?

This check verifies that your payment endpoint rejects the Ethereum zero address (0x0000...0000) as a recipient. Sending funds to the zero address permanently burns them. A compliant API should return an error when a client requests payment to 0x0. This is a critical safety check for any API that handles on-chain transfers.

What does "Auth maturity" mean?

Auth maturity evaluates how your API handles authentication. Probe checks for modern auth patterns: OAuth 2.0, API key rotation support, x402 payment gates, and proper 401/403 responses. A mature auth setup uses layered security rather than a single shared API key.