# Palmyr

> Agent infra: email, phone, social, domains, VPS, wallets. Paid per-action via x402, no API key.

- name: ai.palmyr/palmyr
- version: 1.0.0
- connection class: R0 (autonomous)
- trust: 88/100
- quality: 79/100 (good)
- owner: not claimed
- descriptor: https://api.protogrid.dev/v1/servers/ai.palmyr%2Fpalmyr
- tools: https://api.protogrid.dev/v1/servers/ai.palmyr%2Fpalmyr/tools

**An agent can connect right now, no human step.** Remote endpoint, no authentication, reachable on the last probe.

## Connection (mcpServers)

```json
{
  "mcpServers": {
    "palmyr": {
      "type": "http",
      "url": "https://palmyr.ai/mcp"
    }
  }
}
```


## Trust

- hygiene: 100
- liveness: 97
- freshness: 65
- provenance: 85
- drivers: +repository +dns-namespace +website +reachable +uptime-92% ~updated-99d-ago
- Derived from observable signals (official registry feed and our own credential-free probes); no code audit performed.

## Quality 79/100 (good)

### protocol: 75 (weight 25)

- warn `protocol.modern`: newest supported version is 2025-11-25; 2026-07-28 not supported, older versions are deprecated until 2027-07-28
- n/a `protocol.stateless`: only applies to 2026-07-28 servers
- pass `protocol.transport`: streamable HTTP
- n/a `protocol.list_ttl`: only applies to 2026-07-28 servers

### authorization: n/a (weight 15)

- n/a `auth.prm`, `auth.as_metadata`, `auth.cimd`: no remote uses OAuth
- n/a `auth.secret_in_url`: no templated URL

### tool hygiene: 71 (weight 30)

- pass `tools.descriptions`: every tool has a description
- pass `tools.description_length`: descriptions are concise
- pass `tools.schemas`: every tool has an object input schema
- fail `tools.annotations`: no tool declares readOnlyHint or destructiveHint, so clients cannot tell safe calls from risky ones
- fail `tools.directory_hints`: no tool declares all four of readOnlyHint, destructiveHint, idempotentHint and openWorldHint; missing: email_create_temp (readOnlyHint, destructiveHint, idempotentHint, openWorldHint); email_extend_temp (readOnlyHint, destructiveHint, idempotentHint, openWorldHint); email_send (readOnlyHint, destructiveHint, idempotentHint, openWorldHint); …
- pass `tools.token_cost`: about 6,142 tokens to load every tool
- pass `tools.api_dump`: tools are not a one-to-one API dump

### stability: 100 (weight 15)

- pass `stability.changes`: no tool changes in 30 days
- pass `stability.rug_pull`: no tool changed its meaning under the same name

### dependencies: n/a (weight 15)

- n/a `deps.known_vulns`, `deps.mcp_sdk_version`, `deps.resolvable`: no npm or PyPI package

- tools: 33, about 6,142 tokens to load them all
- tool set hash: 73139faa44df873d930939a90a456e5c
- badge: [![protogrid quality](https://protogrid.dev/badge/ai.palmyr/palmyr.svg)](https://protogrid.dev/servers/ai.palmyr/palmyr)
- Checks run on what our credential-free, read-only probes observe; tools are never called and no code audit is performed.

### Tool changes

_No tool definition changes recorded._

## Remotes

- https://palmyr.ai/mcp (streamable-http, auth none, reachable true, uptime30d 0.9189189)

## Packages

_none_

## Tools (33)

- `card_buy`: Buy a USA prepaid Visa card loaded with EXACTLY the requested balance ($5–$1000). Dynamic x402 price = amount + fee (3% min 0.50 USDC) — the 402 instructions carry the exact total. Returns 202 with an operation_id: poll card_status until ready (~10s), then fetch the number with card_get. US merchants only; non-reloadable (spend across transactions until depleted); max 6 cards per agent per rolling 24h (issuer limit).
- `card_get`: Retrieve a prepaid card you own: full card number, CVV, expiry, live balance. Owner-verified (0.01 USDC ownership proof; the paying wallet must be the card's buyer).
- `card_list`: List cards owned by the paying wallet: status, last4, balance (never full numbers — those are per-card via card_get). 0.01 USDC ownership proof.
- `card_status`: Poll a card purchase started by card_buy (free). done=true when status is 'ready' (fetch details with card_get) or 'failed' (payment auto-refunded — see refund_status).
- `compute_deploy`: Deploy a cloud VPS keyed to your wallet (optionally auto-installs OpenClaw/skills). Priced per server type — the exact quote is returned in the 402 challenge, paid per-action via x402.
- `domain_check`: Check domain availability and per-TLD pricing. Pass a full domain (example.com) or a bare name to scan popular TLDs. Free — no payment required.
- `domain_register`: Register a domain to your wallet. Priced per TLD — the exact quote is returned in the 402 challenge, paid per-action via x402.
- `email_create_inbox`: Provision an email inbox at {name}@palmyr.ai (or a custom domain you own), keyed to your wallet. Costs 2.00 USDC, paid per-action via x402.
- `email_create_temp`: Provision a cheap, disposable, receive-only email inbox — ideal for receiving a one-off verification or order-confirmation email during a checkout/signup flow. The address (a natural-looking handle on a dedicated inbox domain) is returned in the response. Auto-expires (default 24h). Reads return plaintext to the owning wallet (no E2E key to manage). Costs 0.50 USDC, paid per-action via x402.
- `email_extend_temp`: Rent another 7 days on a live disposable temp inbox — each call pushes expires_at exactly 7 days further (fixed, stackable, no cap). Owner-only; expired temp inboxes cannot be revived (buy a new one via email_create_temp). Costs 0.50 USDC, paid per-action via x402.
- `email_read_messages`: Read decrypted messages from an inbox you own (payment wallet must match the inbox). Costs 0.02 USDC, paid per-action via x402.
- `email_send`: Send an email from an inbox you own. Costs 0.08 USDC, paid per-action via x402.
- `i402_plan`: State an intent, get a priced execution plan. The i402 orchestrator turns a natural-language outcome into an ordered list of x402 calls your agent signs and runs. Costs 0.10 USDC per plan, paid per-action via x402.
- `palmyr_capabilities`: List the i402 capabilities Palmyr can plan and execute (the intent-resolver catalog). Free — no payment required.
- `palmyr_pricing`: List every paid Palmyr capability and its live x402 price (USDC on Solana/Base). Free — no payment required.
- `phone_buy_number`: Provision a real phone number (SMS + voice) for your agent. Costs 3.00 USDC, paid per-action via x402.
- `phone_extend_temp`: Rent another 30 minutes on a live disposable temp number — each call pushes expires_at 30 min further (stackable up to 24h total lease). Owner-only; expired temp leases cannot be revived (lease a fresh one via phone_temp_number). Costs 0.20 USDC, paid per-action via x402.
- `phone_read_messages`: Read SMS messages received on a phone number you own. Costs 0.02 USDC, paid per-action via x402.
- `phone_send_sms`: Send an SMS from a phone number you own. Costs 0.05 USDC, paid per-action via x402.
- `phone_temp_number`: Lease a cheap, instant, receive-only US phone number from a pool to receive one SMS verification code — the phone analogue of a disposable temp email inbox. $0.20 for 30 min (ttl_seconds, clamped 300–1800), returned to the pool at expiry; call wait_for_otp to catch the code. Good for one-time SMS verification and phone-gated signups. Works with major sites like Google, X, and Discord; some (Telegram, WhatsApp, OpenAI) may reject it as a VoIP number — for strict sites, buy a dedicated number with phone_buy_number. Pool numbers are recycled after the lease, so use them for one-time codes only, not long-term 2FA. Costs 0.20 USDC, paid per-action via x402.
- `tiktok_accounts`: List the TikTok accounts the paying wallet owns, with session health (status, profile_present, hours_since_success, last_error_code) — i.e. which of your accounts are still logged in. Costs 0.001 USDC, paid per-action via x402.
- `tiktok_analytics`: Scrape per-post analytics (views, likes, comments, shares) for a TikTok account you control, and record a sample so tiktok_series can answer 'is it still growing'. Async: returns an operation to poll with tiktok_operation_status. Costs 0.005 USDC, paid per-action via x402.
- `tiktok_cancel_scheduled`: Cancel a post queued with tiktok_post(schedule_at). TikTok has no 'unschedule', so this deletes the held video — the cancellation is recorded only once that succeeded. Async: returns an operation to poll with tiktok_operation_status. Costs 0.001 USDC, paid per-action via x402.
- `tiktok_connect`: Attach a TikTok account by logging in ON THE SERVER, into that account's own persistent browser profile: returns a connect_url to hand a human, who scans the QR in the TikTok app. The recommended path — the browser that authenticates is the browser that later acts, and every other TikTok tool then works with `cookies` omitted (no jar to move). The paying wallet becomes the account's owner. Async: poll tiktok_connect_status with the returned token. Costs 0.01 USDC, paid per-action via x402.
- `tiktok_connect_status`: Poll a server-side login started by tiktok_connect (free). done=true when state is 'completed' (the account is live and usable with cookies omitted) or 'failed'.
- `tiktok_hooks`: Which caption openings actually earn views. Pass account_id or tag to measure YOUR accounts against their own median (0.001 USDC). Pass niche to report what is working in that niche across TikTok, needing no posting history — the answer for a brand-new account (0.05 USDC; tiktok_niches lists them, free). The two are never blended. Pass caption to classify a draft before posting. Paid per-action via x402 — the 402 challenge carries the exact price for the arguments you sent.
- `tiktok_niches`: List the niches tiktok_hooks can report on, with how fresh each corpus is. Free — an agent should not pay to learn what it may ask for.
- `tiktok_operation_status`: Poll an async TikTok operation started by tiktok_post / tiktok_analytics / tiktok_cancel_scheduled (free). done=true when status is 'posted' / 'done' (carries video_url or the op's result) or 'failed' (payment auto-refunded — see refund_status).
- `tiktok_post`: Post a video to a TikTok account you control (from video_base64 or video_url), immediately or scheduled. Async: returns an operation to poll with tiktok_operation_status. Costs 0.01 USDC, paid per-action via x402.
- `tiktok_scheduled`: List the posts you have queued with tiktok_post(schedule_at), and whether each is still pending, due, or confirmed published. Palmyr's own record — TikTok exposes no way to read pending posts back, so edits made directly in TikTok Studio are invisible to it. Costs 0.001 USDC, paid per-action via x402.
- `tiktok_series`: Read the stored per-post history for an account you own: the full time series for one video (video_id), per-video growth over a window (hours), or the latest sample per video (neither). Samples come from tiktok_analytics runs, so history exists only for what you have scraped. Costs 0.001 USDC, paid per-action via x402.
- `twitter_post`: Post a tweet from an X account you control (via injected session cookies). Costs 0.001 USDC, paid per-action via x402.
- `wait_for_otp`: Wait for an SMS verification code / OTP to arrive on a Palmyr phone number you own, and return the parsed code. Blocks up to timeout_s (default 60, max 90) checking every ~2s — one call replaces hand-rolled polling of phone_read_messages during account signups and 2FA flows. Messages that arrived up to lookback_s seconds (default 10) BEFORE the call also match, so a code that landed early is not missed — pass lookback_s=0 when reusing a number across signups so a stale code can't be re-served. Default extraction handles standalone 4-8 digit codes, 'code is/code:' tokens, and Google-style G-XXXXXX; pass pattern to override (max 256 chars; a pattern that blows its per-match budget is dropped mid-wait and pattern_timeout: true is reported). Returns { found: true, code, message_text } on a hit or { found: false, waited_s } on timeout (not an error — just call again). Costs 0.02 USDC, paid per-action via x402.
