# l402-discover

Probe an endpoint to discover its L402 pricing without committing to payment. Returns the cost in sats, available payment methods, and credit tiers (if toll-booth server). The challenge is cached so a subsequent l402-pay can reuse it.

Agent View of the PolicyLayer registry record for `l402-discover`. HTML page: https://policylayer.com/tools/dev-forgesworn-402-mcp/l402-discover

## Facts

- Tool: `l402-discover`
- Server: 402 (`402-mcp`) — https://policylayer.com/tools/dev-forgesworn-402-mcp.md
- Install: `npx -y 402-mcp`
- Homepage: https://github.com/forgesworn/402-mcp
- Risk category: Read (Low risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 0
- Recommended policy verdict: Allowed

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "l402-discover",
    "arguments": {}
  }
}
```

## Why l402-discover is rated Low

This tool only probes and retrieves pricing/metadata information from an endpoint without making any payment or commitment. It is a read/discovery operation. The only side effect mentioned is caching the challenge locally, which is benign. Severity is low since misuse only results in information disclosure about pricing structures.

From the tool's own definition: "Probe an endpoint to discover its L402 pricing without committing to payment. Returns the cost in sats, available payment methods, and credit tiers"

## Use case

AI agents call l402-discover to retrieve information from 402 without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches 402:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "l402-discover": {}
  }
}
```

## Other tools on 402 (9)

- `l402-buy-credits` — Financial — https://policylayer.com/tools/dev-forgesworn-402-mcp/l402-buy-credits.md
- `l402-pay` — Financial — https://policylayer.com/tools/dev-forgesworn-402-mcp/l402-pay.md
- `l402-redeem-cashu` — Financial — https://policylayer.com/tools/dev-forgesworn-402-mcp/l402-redeem-cashu.md
- `l402-balance` — Read — https://policylayer.com/tools/dev-forgesworn-402-mcp/l402-balance.md
- `l402-config` — Read — https://policylayer.com/tools/dev-forgesworn-402-mcp/l402-config.md
- `l402-credentials` — Read — https://policylayer.com/tools/dev-forgesworn-402-mcp/l402-credentials.md
- `l402-fetch` — Read — https://policylayer.com/tools/dev-forgesworn-402-mcp/l402-fetch.md
- `l402-search` — Read — https://policylayer.com/tools/dev-forgesworn-402-mcp/l402-search.md
- `l402-store-token` — Write — https://policylayer.com/tools/dev-forgesworn-402-mcp/l402-store-token.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=dev-forgesworn-402-mcp · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/dev-forgesworn-402-mcp
