Skip to main content
Glama

zkVerify

Trustless blockchain verification over x402 with Merkle proofs + ECDSA signing

Live on Railway License: MIT

Why?

When an AI agent pays for blockchain data via x402, how does it know the data is authentic? It doesn't. 99% of x402 transactions are at risk (arXiv, July 2026 — 31 vulnerabilities found).

zkVerify solves this: every API response includes a Merkle proof + ECDSA signature. The agent can verify independently — zero trust required.

Related MCP server: Tilde x402 MCP Server

Endpoints

Endpoint

Price

Returns

GET /verify/balance/:address?chain=base

$0.02

Account balance + Merkle proof + signature

GET /verify/contract/:address?chain=base

$0.02

Contract code hash + signature

GET /health

Free

Service status + signer address

GET /.well-known/x402

Free

x402 discovery (Bazaar)

Supported Chains

  • Base (L2 — fallback to eth_getBalance)

  • Ethereum (L1 — full eth_getProof / EIP-1186)

  • Polygon

How It Works

  1. Agent sends GET /verify/balance/0xABC...?chain=ethereum

  2. zkVerify returns HTTP 402 Payment Required

  3. Agent pays $0.02 USDC on Base via x402

  4. zkVerify: a. Fetches eth_getProof from RPC b. Verifies Merkle Patricia Proof against stateRoot c. Signs the result with ECDSA d. Returns: { balance, blockNumber, stateRoot, merkleProof, signature }

  5. Agent verifies: a. Signature (recoverAddress) b. Merkle proof locally (optional) c. stateRoot against block header (optional)

  6. Agent now has 100% verified on-chain data — no trust needed

Quick Start

For AI Agents (via x402)

curl https://zkverify-production.up.railway.app/verify/balance/0xd8dA6BF26964aF9D7eEd9e03E53415D37aA96045?chain=ethereum
# Returns: balance, Merkle proof (9 nodes), ECDSA signature, verified: true

SDK (Client-side verification)

import { fullVerify } from "zkverify";

const result = await fetch("https://zkverify-production.up.railway.app/verify/balance/0xABC...?chain=ethereum").then(r => r.json());
console.log(result.fullyVerified); // true = verified 100%

MCP Server

zkVerify includes an MCP server with 3 tools for Claude/Cursor:

{
  "mcpServers": {
    "zkverify": {
      "command": "npx",
      "args": ["-y", "zkverify-mcp"],
      "env": {
        "ZKVERIFY_URL": "https://zkverify-production.up.railway.app"
      }
    }
  }
}

Architecture

  • Merkle Patricia Proof: EIP-1186 eth_getProof from Ethereum L1

  • ECDSA Signing: Every response signed with secp256k1

  • x402 Payment: $0.02 USDC on Base

  • Zero Trust: Agent needs no trusted oracle — just math

Costs

  • $0 startup cost

  • Free RPC (PublicNode, Alchemy free tier)

  • x402 facilitator: free for first 1,000 transactions/day

  • Margin: 99% (after $0.001 facilitator fee)

Patent (Pending)

Title: "System and method for providing cryptographically verifiable API responses using Merkle proofs and ECDSA signatures over HTTP payment protocols"

See patent/USPTO_PROVISIONAL.md

ZK Circuit (Level 2)

A simplified circom circuit (~202 constraints) proves that verification was performed correctly without revealing proof data.

See circuits/zkverify.circom

License

MIT — free to use, modify, and distribute. Attribution appreciated.


Built with ZKForge — the first x402 service providing cryptographically verifiable blockchain data.

Available Tools

3 tools
verify_balanceA

Verify any blockchain address balance with Merkle proof and ECDSA signature. Returns cryptographically verified balance data.

ParametersJSON Schema
NameRequiredDescriptionDefault
chainNobase
addressYesEVM address to verify

TDQS

A3.6/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the burden of behavioral disclosure. It adds useful context by mentioning Merkle proof and ECDSA signature, and states that it returns 'cryptographically verified balance data.' However, it does not disclose whether the operation is read-only, any error conditions, or side effects, leaving some ambiguity.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is concise, two sentences, and front-loaded with the primary action. Every word earns its place: the first sentence states what it does, the second clarifies the return type. No wasted text.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's simplicity (2 parameters, no output schema, no annotations), the description is mostly complete but leaves gaps. It does not mention the chain parameter, default behavior, or any edge cases. The claim of returning 'verified balance data' is helpful but lacks specifics about response structure or error handling.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The schema covers 50% of parameters (address has a description, chain does not). The description does not compensate for the chain parameter's lack of meaning, nor does it explain the address format beyond what the schema already provides. It mentions 'balance' but not the parameters explicitly, adding minimal value beyond the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's purpose: 'Verify any blockchain address balance with Merkle proof and ECDSA signature.' It names a specific verb (verify), a clear resource (blockchain address balance), and adds cryptographic details (Merkle proof, ECDSA signature) that differentiate it from siblings like verify_contract or verify_signature.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies when to use the tool ('Verify any blockchain address balance') but provides no explicit guidance on when not to use it or how it compares to sibling tools. There is no mention of alternatives, prerequisites, or exclusions, so the guidance is only implicit.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

verify_contractB

Verify if an address is a smart contract and get its code hash with ECDSA signature.

ParametersJSON Schema
NameRequiredDescriptionDefault
chainNobase
addressYesEVM address to check

TDQS

B3.3/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the full burden of behavioral disclosure. It mentions the signed code hash output but does not state whether the operation is read-only, error behavior for non-contracts, chain support, or any side effects. This is insufficient.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is one concise sentence that front-loads the core purpose and adds a necessary detail about the signed hash. There is no redundancy or fluff.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The tool has two parameters, no output schema, and no annotations. The description covers the core function but omits the chain parameter, expected return format beyond a signed hash, and any caveats. It is not complete enough for the agent to use correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 50% (only address is described). The tool description does not clarify the chain parameter or the default value, and it does not compensate for the missing schema description. The description adds no parameter meaning beyond what is already in the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool verifies whether an address is a smart contract and retrieves its code hash with an ECDSA signature. This is a specific verb+resource and distinguishes from sibling tools verify_signature and verify_balance.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage through its name and sibling context, but it does not explicitly state when to use this tool versus alternatives, nor does it provide any exclusions. The guidance is only implicit.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

verify_signatureA

Verify a zkVerify ECDSA signature on a previous response. Checks signer authenticity.

ParametersJSON Schema
NameRequiredDescriptionDefault
responseYesJSON response from verify_balance or verify_contract
expectedSignerYesExpected signer address (from /health)

TDQS

A3.5/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description bears full responsibility for disclosing behavioral traits. It merely states the core verification function but does not disclose potential side effects, error behavior, return format, or safety profile (e.g., whether it is read-only). This is a significant gap for a tool that verifies authenticity.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is two concise sentences, front-loaded with the main action. Every word earns its place without redundancy or unnecessary detail. It is optimally brief and clear.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The tool is simple with full schema coverage, but there is no output schema. The description does not explain what the tool returns or what happens on success/failure, which is a gap given the absence of an output schema. It also doesn't mention prerequisites in the description itself. Overall, it is minimally complete but lacks important result-related context.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema has 100% coverage for both parameters, with clear descriptions for 'response' and 'expectedSigner'. The tool description does not add any additional meaning beyond what the schema provides, so the baseline of 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states a specific action ('Verify a zkVerify ECDSA signature') and the target resource ('on a previous response'). It also adds the purpose of the verification ('Checks signer authenticity'). This distinguishes it from sibling tools like verify_contract and verify_balance, which likely perform different verification tasks.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage context: it is used on a previous response, which indicates a prerequisite. However, it does not explicitly mention when to use this tool versus alternatives, nor does it state any exclusions or when not to use it. The context signal that parameters come from verify_balance or verify_contract is only in the schema, not the description.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. 3 tool updatesv0.3.1
    • First observedverify_balance
    • First observedverify_contract
    • First observedverify_signature

TDQS

A3.8/5.0
Disambiguation5/5

Each tool targets a distinct object: contract, signature, and balance. There is no ambiguity about which tool to use for a given verification task.

Naming Consistency5/5

All tool names follow a consistent 'verify_' prefix followed by the object being verified. This creates a predictable pattern that is easy for agents to learn and recall.

Tool Count5/5

Three tools is a well-scoped count for a specialized verification server. Each tool serves a clear purpose, and the set is neither too sparse nor bloated.

Completeness4/5

The server covers the core verification actions for contracts, signatures, and balances, which covers the most common needs. A minor gap is lack of transaction or proof verification, but the current surface is coherent and functional.

Maintenance

ActivityMaintained
ResponsivenessSyncing

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/zkarchitect/zkverify'

If you have feedback or need assistance with the MCP directory API, please join our Discord server