sap_register_agent
Deprecated raw SDK wrapper. Production registration must use sap_payments_register_agent so the local signer path confirms the account, verifies the 0.1 SOL protocol treasury fee invariant, and returns protocolComplete. Hosted accountless SAP MCP rejects this direct write before x402 payment. SAP...
This record as markdown: /tools/oobe-protocol-labs-sap-mcp-server/sap-register-agent.md
What sap_register_agent does on Sap
AI agents use sap_register_agent to commit financial operations through Sap, usually the final step of a payment, billing, or trading workflow. A call moves real money.
| Parameter | Type | Required | Description |
|---|---|---|---|
name | string | — | Required public display name for the SAP agent. Keep it stable enough for explorers and humans. |
agentId | string | — | Optional stable lowercase agent id, for example solking. This is separate from the on-chain agent PDA. |
pricing | array | — | Optional pricing tiers advertised by the agent. Use tokenType usdc + settlementMode x402 for pay.sh/x402 agent commerce. |
agentUri | string | — | Optional public HTTPS/IPFS/Arweave/Kommodo URI for the agent profile metadata or profile page. Never use local desktop file paths. |
protocols | array | — | Required protocol tags the agent supports, for example sap, mcp, jupiter, pyth, metaplex, sns, x402, payments. |
description | string | — | Required public description of what the agent does, which protocols it can use, and its safety/trust boundaries. |
metadataUri | string | — | Alias for agentUri. Prefer a public JSON metadata document containing name, description, image, external_url, attributes, sap, metaplex, sns, and x402 fields. |
capabilities | array | — | Required capability list. Prefer object form for production; strings are accepted as shorthand. |
x402Endpoint | string | — | Optional public x402 discovery/payment endpoint, usually https://host/.well-known/x402 for external agent services. |
Parameters from the server's own tool schema.
Why sap_register_agent is rated Critical
Tool involves SOL payment fees and financial protocol registration with treasury obligations.
From the tool's definition 0.1 SOL protocol treasury fee invariant, x402 payment
Risk signalsHigh parameter count (25 properties)
Attacks that exploit this kind of access
The rule that runs sap_register_agent safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Sap, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For sap_register_agent, this is the rule to start with:
Any call to sap_register_agent is blocked until a human approves it. The rest of the server keeps working.
The button opens the PolicyLayer dashboard: create your workspace, connect Sap, apply this rule, and every sap_register_agent call is checked against it from then on.
Questions about sap_register_agent
Deprecated raw SDK wrapper. Production registration must use sap_payments_register_agent so the local signer path confirms the account, verifies the 0.1 SOL protocol treasury fee invariant, and returns protocolComplete. Hosted accountless SAP MCP rejects this direct write before x402 payment. SAP MCP context: Do not use this raw SDK wrapper for production registration. The canonical registration path is sap_payments_register_agent, because it confirms the account, audits the protocol treasury fee, and fails closed when protocolComplete is false. Hosted accountless SAP MCP rejects direct registration before x402 payment because OOBE never custodies user wallet keys. Use sap_agent_identity_plan first, then sap_payments_register_agent with confirm:true. SAP MCP execution guidance: Intent: local-signer write workflow. Pricing: paid value-action; preview cost and transaction effects before user confirmation. Routing: hosted accountless write is blocked; do not call this as a paid hosted write and no x402 payment should be charged. Use sap_payments_register_agent when user signing is required. Signer boundary: user-controlled local profile or external signer; OOBE hosted MCP remains non-custodial. It is categorised as a Financial tool in the Sap MCP Server, which means it involves financial transactions. Block by default and require explicit approval.
sap_register_agent accepts 9 parameters: name, agentId, pricing, agentUri, protocols, description, metadataUri, capabilities, x402Endpoint. The full parameter table on this page comes from the server's own tool schema.
Register the Sap MCP server in PolicyLayer and add a rule for sap_register_agent: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Sap. Nothing to install.
sap_register_agent is a Financial tool with critical risk. Critical-risk tools should be blocked by default and only enabled with explicit human approval.
Yes. Add a rate_limit block to the sap_register_agent rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for sap_register_agent. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
sap_register_agent is provided by the Sap MCP server (https://mcp.sap.oobeprotocol.ai/mcp). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Sap, and thousands of servers like it.
Across the catalogue