Back to Browse

Agentbroker MCP Server

Developer ToolsUse Caution3.9MCP RegistryRemote
Free

Server data from the Official MCP Registry

Find real businesses and book appointments. Books via Cal.com; imports 12 platforms.

About

Find real businesses and book appointments. Books via Cal.com; imports 12 platforms.

Remote endpoints: streamable-http: https://hatchloop.dev/mcp/appointment-booking

Security Report

3.9
Use Caution3.9High Risk

Valid MCP server (1 strong, 1 medium validity signals). 11 known CVEs in dependencies (0 critical, 3 high severity) Imported from the Official MCP Registry.

9 tools verified · Open access · 11 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

Unverified package source

We couldn't verify that the installable package matches the reviewed source code. Proceed with caution.

How to Connect

Remote Plugin

No local installation needed. Your AI client connects to the remote endpoint directly.

Add this to your MCP configuration to connect:

{
  "mcpServers": {
    "dev-hatchloop-appointment-booking": {
      "url": "https://hatchloop.dev/mcp/appointment-booking"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Agent Broker - SMB Transaction & Communication MCP Server

An agent-callable MCP server that lets autonomous AI agents find, verify, message, schedule with, and transact with small and mid-sized businesses (SMBs) through a single compliance-enforced tool surface.

MCP License Python Edge Registry

CI

Live endpoint: https://hatchloop.dev/mcp/agent-broker (streamable-http, always-on Cloudflare edge)


Why this exists

There are ~60 million long-tail small businesses in the US - barbers, plumbers, accountants, home cleaners - and they have no API surface. AI agents that need to schedule a haircut, get a quote, or send a confirmation today must either drive a browser, cold-call by voice, or give up.

This server is the missing middle layer. Agents call us; we route to the right SMB through whichever channel reaches them fastest - Cal.com -> WhatsApp -> SMS -> voice AI -> email - with full TCPA / GDPR / CASL / 10DLC compliance enforced as a non-bypassable gate.


Current status (honest)

CapabilityStatus
MCP endpoint (streamable-http)Live - https://hatchloop.dev/mcp/agent-broker
21 MCP toolsLive (callable today)
Compliance gate (TCPA/GDPR/CASL)Live
REST + A2A + OpenAI/Anthropic tool surfacesLive
SMB supply networkDemo - 20+ seed SMBs; demo bookings return demo_smb_no_live_booking
BillingLive - 10 utility tools free (no key, unmetered). Premium data tools (company verification, sanctions, trade screening): free up to a daily limit (500/day with a free key, 100/day anonymous), then $0.02/call via credits. Write tools: free email-verified key (100 ops/day) at hatchloop.dev/agent-broker; credit packages from $9/1,000 credits at hatchloop.dev/pricing;.
x402 payment railOffered, opt-in. Enabled on the service since the founder lifted the crypto restriction on 2026-08-29. A caller attaches a payment in params._meta["x402/payment"] and the call is served without a key (USDC on Base, proven once on mainnet, tx 0x38a0d9ec). Callers who do not attach one fall through to credits and the free quota, so nothing is gated behind it. /.well-known/x402 is still a 404 - discovery is via /.well-known/mcp.json, which lists the rail.
Production SMB onboardingPlanned - real businesses not yet enrolled

The MCP server is live and callable right now. Bookings hit demo data. 10 utility tools are free (no key, unmetered). Premium data tools (verify_company_record, screen_sanctions, map_trade_restriction) are free up to a daily limit; beyond that, $0.02/call via credits. Write tools require a free email-verified key (100 ops/day) - get one at https://hatchloop.dev/agent-broker. Credit packages from $9/1,000 credits at https://hatchloop.dev/pricing.


21 MCP Tools

All tools are callable via MCP, REST, OpenAI function calling, Anthropic tool_use, or A2A protocol.

#ToolWhat it doesAuth
1find_businessSearch SMBs by vertical, location, and capabilityfree
2verify_businessConfirm an SMB is real, operating, and capable of the requested servicefree
3get_statusPoll the current state of an async operationfree
4get_outcomeRetrieve the final OutcomeReceipt (with cost and reason codes)free
5preview_costEstimate cost, latency, and success probability before committingfree
6self_testVerify service health and all claimed capabilities are respondingfree
7check_booking_linkClassify a URL and confirm import_booking_url will accept it - sub-100ms pre-flightfree
8check_compliancePreview TCPA/GDPR/CASL/10DLC gate result before spending a paid sendfree
9verify_company_recordLive GLEIF LEI registry + SEC EDGAR lookup - official legal name, status, jurisdiction, addressfree up to daily limit
10screen_sanctionsCheck a name or entity against OFAC SDN, the EU Consolidated list and the UK Sanctions Listfree up to daily limit
11map_trade_restrictionOFAC country embargoes + export-control Entity List + sanctioned-party screening for a proposed shipmentfree up to daily limit
12get_conversationRead a two-way thread you started: state, full transcript, reply countfree
13send_messageSend WhatsApp, SMS, email, or voice with compliance pre-check enforcedkey
14capture_leadStructured intake of a prospect into an SMB pipeline with CRM integrationkey
15schedule_appointmentBook, reschedule, or cancel - tries direct booking API, falls back to voice AIkey
16send_transactional_confirmationTCPA-exempt OTPs, booking confirmations, receiptskey
17handle_inboundClassify inbound messages: booking / cancel / opt-out / question / complaintkey
18escalate_to_humanHand off a stuck or ambiguous task to a human operator with full contextkey
19import_booking_urlTurn any Cal.com, Calendly, Doctolib, Booksy, OpenTable, Square, Acuity, or Fresha URL into a bookable SMB recordkey
20call_businessPlace a conversational voice-AI phone call to a business on behalf of a consumerkey
21mint_keyIssue a free-tier agent identity key via HMAC proof - no email required, no human in the loopfree

Free key (100 write ops/day + 500 premium data calls/day): https://hatchloop.dev/agent-broker - Credits from $9/1,000 ops: https://hatchloop.dev/pricing - Premium data beyond quota: $0.02/call


Quick start

Connect via MCP (Claude Desktop, Cursor, Cline, Continue, etc.)

{
  "mcpServers": {
    "agent-broker": {
      "url": "https://hatchloop.dev/mcp/agent-broker"
    }
  }
}

12 tools require no key (find_business, verify_business, verify_company_record, screen_sanctions, map_trade_restriction, check_booking_link, check_compliance, get_conversation, get_status, get_outcome, preview_cost, self_test).

Write tools require an X-Agent-Identity bearer token:

Add your key to the config once you have one:

{
  "mcpServers": {
    "agent-broker": {
      "url": "https://hatchloop.dev/mcp/agent-broker",
      "headers": {
        "X-Agent-Identity": "Bearer YOUR_KEY_HERE"
      }
    }
  }
}

Or via npx (stdio transport)

npx agentbroker-mcp

With a key:

AGENT_BROKER_KEY=your_key npx agentbroker-mcp

Discover tools (JSON-RPC)

curl -X POST https://hatchloop.dev/mcp/agent-broker \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}'

Call a tool (JSON-RPC)

curl -X POST https://hatchloop.dev/mcp/agent-broker \
  -H "Content-Type: application/json" \
  -d '{
    "jsonrpc": "2.0",
    "id": 2,
    "method": "tools/call",
    "params": {
      "name": "find_business",
      "arguments": {
        "vertical": "personal_services",
        "location": {"zip_or_city": "30309"},
        "capability": "haircut"
      }
    }
  }'

OpenAI function calling

import httpx, openai
tools = httpx.get(
    "https://hatchloop.dev/.well-known/openai-tools.json"
).json()["tools"]
client = openai.OpenAI()
resp = client.chat.completions.create(
    model="gpt-4o",
    messages=[{"role": "user", "content": "Book a haircut in Atlanta Saturday under $50"}],
    tools=tools,
)

Anthropic tool use

import httpx, anthropic
tools = httpx.get(
    "https://hatchloop.dev/.well-known/anthropic-tools.json"
).json()["tools"]
client = anthropic.Anthropic()
msg = client.messages.create(
    model="claude-opus-4-5",
    max_tokens=1024,
    tools=tools,
    messages=[{"role": "user", "content": "Book a haircut in Atlanta Saturday under $50"}],
)

Plain REST

curl -X POST https://hatchloop.dev/ops/find_business \
  -H "Content-Type: application/json" \
  -d '{"vertical":"personal_services","location":{"zip_or_city":"30309"},"capability":"haircut"}'

Machine-mintable keys

AI agents that cannot receive email can self-provision a free-tier API key (100 gated ops/day) by proving identity via HMAC-SHA256.

How it works

  1. Obtain the MACHINE_MINT_SECRET from hatchloop.dev/docs/#machine-mint.
  2. Compute the signature:
    signature = HMAC-SHA256(agent_id + str(timestamp) + nonce, MACHINE_MINT_SECRET)
    
    The HMAC input is the raw concatenation of the three fields (no separators). Digest must be lowercase hex.
  3. POST to https://api.hatchloop.dev/keys/mint:
{
  "agent_id": "my-agent-abc123",
  "timestamp": 1725100000,
  "nonce": "4f8a2c1d9e2b7c6a",
  "signature": "<lowercase-hex-hmac>"
}

Response

{
  "ok": true,
  "key": "<JWT - use as X-Agent-Identity header>",
  "key_id": "free_machine_<hash>",
  "expires_at": "2026-11-28",
  "tier": "free",
  "daily_limit": 100,
  "usage": "Send as the X-Agent-Identity header on every call to https://hatchloop.dev/mcp/agent-broker"
}

Constraints

  • timestamp must be within 60 seconds of server time (prevents replay attacks).
  • Use a fresh nonce on every call (UUID or random hex).
  • agent_id is a stable identifier for your agent; the issued key is tied to its SHA-256 hash.
  • Returns 401 {error: "invalid_request"} on bad signature or stale timestamp.
  • Returns 503 {error: "not_configured"} if the server secret has not been set (contact hello@hatchloop.dev).

Discovery surfaces

SurfaceURL
MCP (streamable-http)https://hatchloop.dev/mcp/agent-broker
MCP descriptorhttps://hatchloop.dev/.well-known/mcp.json
OpenAI function toolshttps://hatchloop.dev/.well-known/openai-tools.json
Anthropic tool_usehttps://hatchloop.dev/.well-known/anthropic-tools.json
A2A (Agent-to-Agent)https://hatchloop.dev/.well-known/agents.json
OpenAI ChatGPT pluginhttps://hatchloop.dev/.well-known/ai-plugin.json
llms.txthttps://hatchloop.dev/llms.txt
OpenAPI 3.1https://hatchloop.dev/openapi.yaml
npm shim (stdio)npx agentbroker-mcp
Glama MCP RegistryListed via glama.json
MCP RegistryListed via server.json

Architecture

AI agent
   |
   v  MCP / REST / A2A
Cloudflare Worker edge  (hatchloop.dev)
   |  300+ PoPs globally -- discovery served from edge bundle in 40-70 ms
   |
   +-- GET /.well-known/* /manifest /llms.txt  --> embedded snapshot (40-70 ms)
   +-- POST /mcp  initialize / tools/list      --> embedded snapshot (40-65 ms)
   +-- POST /mcp  tools/call  /ops/*           --> proxy to origin  (170-190 ms)
                |
                v
        Python FastAPI  (api.hatchloop.dev)
                |  Cron keep-alive every 2 min (eliminates Render cold starts)
                |
                +-- 21 operation handlers  (core/)
                +-- Compliance gate        (compliance/pre_check)
                +-- Channel adapters       (channels/ -- Twilio, Cal.com, Vapi, SendGrid)
                +-- Billing + outcome store
                +-- All .well-known / MCP endpoints (also served from edge bundle)

The edge worker can outlive the origin: discovery still works even if the origin is down. Idempotency is keyed by (agent_id, operation, idempotency_key) with 24h TTL. Async operations return pending_async; poll with get_status / get_outcome.


Compliance

Every outbound communication passes through compliance/pre_check():

  1. Content classification - blocks restricted categories (gambling, adult, cannabis, spam)
  2. Opt-out check - TCPA STOP keyword, GDPR right-to-be-forgotten, CASL
  3. Consent check - TCPA written consent, GDPR opt-in, CASL implied/express
  4. 10DLC registry check - US SMS campaign compliance
  5. Two-party recording consent - CA, FL, IL, MD, MA, MT, NV, NH, PA, WA
  6. Audit log - PII stored as SHA-256 hash, never plaintext

Violations surface as ComplianceViolationError and are never silently bypassed.


Repo layout

agentbroker/
+-- core/                  # 21 operation handlers + shared Pydantic models
+-- channels/              # Twilio, SendGrid, Vapi, Bland, Cal.com, Playwright
+-- compliance/            # pre_check, jurisdiction_rules, consent_store, audit_log
+-- reliability/           # retry, circuit_breaker, channel_fallback, async_runner
+-- billing/               # meter, budget_guard, receipt_signer, pricing_tiers
+-- telemetry/             # tracer, log_redactor, metrics_emitter
+-- storage/               # outcome_store, idempotency_store
+-- supply/                # smb_directory (20+ seed/demo SMBs)
+-- onboarding/            # self_serve, verification_flow, channel_capture
+-- feedback/              # failure_classifier, attribution_engine, outcome_evaluator
+-- optimizer/             # ab_router, selection_analytics, weekly_report
+-- agent_interface/       # manifest_server, mcp_server, well_known, identity, webhooks
+-- manifest/              # manifest.json, mcp_tools.json, openapi.yaml
+-- api/                   # errors.md, identity.md, async.md
+-- docs/                  # mission, architecture, compliance, ADRs
+-- edge/                  # Cloudflare Worker (TypeScript/Hono)
+-- deploy/                # Dockerfile, docker-compose.yml
+-- tests/                 # unit, contract, compliance, fault_injection, agent_sim
+-- main.py                # FastAPI entry point
+-- config.py              # Centralized config from env
+-- requirements.txt

Local development

# Install dependencies
pip install -r requirements.txt

# Run tests (1173 passing at the time of writing)
python -m pytest tests/ -q

# Start the API
python main.py
# --> http://localhost:8000/docs      (Swagger UI)
# --> http://localhost:8000/mcp       (MCP endpoint)
# --> http://localhost:8000/manifest  (capability manifest)

# Run the agent simulation harness
python -m tests.agent_sim.harness

# Self-test
python -c "import asyncio; from agent_interface.self_test import run_self_test; print(asyncio.run(run_self_test()).all_passed)"

Or with Docker:

docker compose -f deploy/docker-compose.yml up

Documentation


Contributing

Licensed under MIT. Issues and discussion are welcome - open a GitHub issue to report bugs or suggest features. For substantial changes, please open an issue first to discuss direction. Note: this repo is the open-source server; the hosted service at hatchloop.dev (supply index, billing rails) is operated by Hatchloop.


License

MIT - see LICENSE. The hosted service and its supply/billing data are operated separately by Hatchloop.


Built by Basil Al-Shukaili. Listed on the MCP Registry and Glama.

Reviews

No reviews yet

Be the first to review this server!