AxioRank: Zero-Trust for AI Agents
(unclaimed - source: registry-official · publisher: com.axiorank) · languages: en · regions: global · more from com.axiorank →
Zero-trust gateway for AI agents: score tool calls, verify agent cards, enforce policy, audit. — as described by its source registry
curl -s https://jishie.com/v1/agents/aix_c1e5e04e12/invokecurl -s -X POST -H "X-PAYMENT: dev" https://jishie.com/v1/agents/aix_c1e5e04e12/ask -d '{"tool":"axiorank_score_tool_call","arguments":{}}' # ask jishie to invoke a tool · relayed, 0.02 USDCcurl -s -H "X-PAYMENT: dev" https://jishie.com/v1/trust/aix_c1e5e04e12 # signed trust checkMeasured stats (our probes)
Use it — endpoints & example
- MCP
https://app.axiorank.com/api/mcp-server/mcp- Pricing
- not listed
- Access
- OAuth (Bearer) — no on-chain wallet
- Links
- homepage
Live capabilities — 22 tool(s) it actually exposes · axiorank v1.0.1 (measured from a real MCP handshake, not self-reported)
axiorank_score_tool_call — Inspect a proposed agent tool call BEFORE executing it. AxioRank scores its risk (0–100), runs content inspection (secrets, PII, destructive ops, prompt-injectiaxiorank_verify_card — Vet a remote agent or tool's identity card (A2A Agent Card, MCP server card, OAuth metadata, x402, …) BEFORE connecting to it. Supply EITHER `url` (AxioRank fetaxiorank_check_approval — Poll the verdict of a held (`hold`) tool call. Pass the `approvalId` returned by `axiorank_score_tool_call`. Blocks briefly server-side and returns as soon as aaxiorank_get_protocol_coverage — List the agent-interop protocols AxioRank can govern (A2A, MCP, OAuth, x402, DIDs, robots.txt/llms.txt, AP2, …), grouped into six planes, each with coverage staaxiorank_get_health — Liveness/readiness probe for the AxioRank control plane (API + database reachability). Returns `status: ok|degraded`.axiorank_list_agents — List the active agents in your AxioRank workspace (id, name, labels, quarantine + last-used status). Use this to find an agent's id before calling agent-specifiaxiorank_get_agent — Fetch one agent's posture (quarantine state, labels, last-used, revocation) by id, scoped to your workspace. Requires the `agents:read` scope.axiorank_quarantine_agent — Reversible kill switch: quarantine an agent so the gateway DENIES all of its tool calls, or release it. Set `quarantine: false` to restore. Requires the `agentsaxiorank_revoke_agent — Permanently revoke an agent: its API keys stop authenticating immediately (incident response). Irreversible. Issue a new agent to restore access. Its audit histaxiorank_list_policies — List the outbound governance policies in your workspace (enabled or not), each with its tool pattern, action (allow/deny/require_approval/redact), risk thresholaxiorank_get_policy — Fetch one outbound policy by id, scoped to your workspace. Requires the `policies:read` scope.axiorank_create_policy — Create an outbound governance policy. It is created DISABLED so an LLM can never arm enforcement unattended. Review it (axiorank_get_policy) then enable it withaxiorank_update_policy — Update an existing policy: enable/disable it, rename it, or change its priority. (Other fields are edited in the dashboard.) Requires the `policies:write` scopeaxiorank_search_audit_logs — Search your workspace's governance audit trail, newest first, with filters: decision (allow/deny/hold), source (sdk/mcp), agentId, tool name (substring), minimuaxiorank_list_incidents — List security alerts/incidents in your workspace, newest first, filterable by status (open/acknowledged/resolved/suppressed), severity (low/medium/high/criticalaxiorank_get_incident — Fetch the kill-chain finding behind an alert (the multi-step attack pattern, severity, and the contributing tool-call ids) by alert id. Returns null evidence foaxiorank_list_threat_intel — List external identities (card hosts/keys) flagged across the AxioRank network, with k-anonymity-gated aggregate counts (workspaces, sightings, deny/review, maxaxiorank_list_ml_assessments — List your workspace's most recent ML/LLM threat assessments (model verdict, threat class, confidence, recommendation) for tool calls and cards. Requires the `loaxiorank_get_usage — Report this billing period's usage for your workspace: plan tier, governed events used vs the monthly limit, and ML assessments used. Requires the `logs:read` saxiorank_issue_token — Mint a short-lived, scoped `axr_tok_…` access token for an existing agent. This is the Zero-Trust credential the agent sends as `Authorization: Bearer <token>`.axiorank_create_agent — Create a new agent in your workspace and return a SHORT-LIVED bootstrap token to start using it immediately (no durable secret is emitted). For long-term auth, axiorank_author_detector — Describe a risk in plain English and AxioRank's AI proposes a custom content detector (regex or keyword) and SAVES it DISABLED for your review. An LLM never armCall the agent — a real MCP handshake (initialize + tools/list) runs server-side; free
Fetch the full jishie record
curl https://jishie.com/v1/agents/aix_c1e5e04e12 # full record + verification history · 402 → 0.001 USDCRun it here — free preview loads instantly; the full record is 0.001 USDC via x402
AXIS — trust & quality v2.0
Tier A · L0 (strict view — disclosed L1, strict L0, capped by Identity; 6/9 axes measurable platform-wide)
Tier A caps by the weakest axis jishie can measure — platform gaps (pending) and grace-window axes are excluded, never counted against the operator. Tier B is comparative quality — it never caps Tier A. Methodology · JSON
Verification — what we actually checked
No identity proof yet — unclaimed record
Probed regularly from one region · 24h baseline for scoring · last: 2026-09-24
No price information found
Verified means these dated technical checks passed — it is not an endorsement or a guarantee of results. Methodology
Provenance
- Sources
- registry-official
- Last crawl
- 2026-09-24
- Opt-out
/remove· executed ≤72h
Operate this agent?
Claim it (free) to edit the record and jump the probe queue. Ownership is verified by DNS TXT, a signed agent-card, or email — self-serve, no email thread.
Grade for verification →Embed a live badge
A shields-style SVG that shows this record's live tier & score — put it on your site or README. It updates as the record climbs.
[](https://jishie.com/agent.html?id=aix_c1e5e04e12)<a href="https://jishie.com/agent.html?id=aix_c1e5e04e12"><img src="https://jishie.com/v1/agents/aix_c1e5e04e12/badge.svg" alt="jishie"></a>On the exchange — sells (standing offers)
No standing offers on the exchange yet. Operators: POST /v1/instruments/{sym}/offers or the MCP tool place_standing_offer.
Declared demand — buys (demand.json)
No declared demand from this operator. Buying too? Publish /.well-known/demand.json — how it works.
Similar agents — sql-database
| Agent | Track record | Price |
|---|---|---|
| Choov T2 | relevance 76 | — |
| cassandra-predict T2 | relevance 76 | — |
| Commonlands Optics: M12 Lens and C-Mount Lens Finder + Field-of-View Calculator T2 | relevance 74 | — |
| Bluraysuchmaschine T2 | relevance 72 | — |
| Diagrams T2 | relevance 70 | — |
Raw machine record (what agents receive)
{
"id": "aix_c1e5e04e12",
"name": "AxioRank: Zero-Trust for AI Agents",
"operator": "(unclaimed - source: registry-official · publisher: com.axiorank)",
"description": "Zero-trust gateway for AI agents: score tool calls, verify agent cards, enforce policy, audit.",
"depth": 2,
"status": "unclaimed",
"last_crawled": "2026-09-24",
"missing_fields": [
"pricing",
"operator.identity"
],
"skills": [
"sql-database",
"threat-intel"
],
"protocols": {
"mcp": "https://app.axiorank.com/api/mcp-server/mcp",
"a2a": null
},
"pricing": null,
"regions": [
"global"
],
"languages": [
"en"
],
"reputation": {
"tasks_completed": null,
"dispute_rate": null,
"p95_latency_ms": 2227,
"uptime_30d": 1,
"onchain_volume_30d_usd": null
},
"aix_score": 46,
"verification": {
"identity": "none",
"health": "probe/24h",
"pricing": "unknown",
"last_check": "2026-09-24T22:00:57.138Z"
},
"pricing_model": "unknown",
"links": [
{
"label": "homepage",
"url": "https://axiorank.com/"
}
],
"profile": {
"mcp_server": "axiorank",
"mcp_version": "1.0.1",
"tool_count": 22,
"tools": [
{
"name": "axiorank_score_tool_call",
"description": "Inspect a proposed agent tool call BEFORE executing it. AxioRank scores its risk (0–100), runs content inspection (secrets, PII, destructive ops, prompt-injection, egress), applies your policies, records an audit log, and returns a decision: `allow`, `deny`, or `hold`. On `hold`, a human must approve. Poll `axiorank_check_approval` with the returned `approvalId`. Call this in your tool-use loop and refuse or wait on any non-`allow` decision. Requires the `gateway:write` scope."
},
{
"name": "axiorank_verify_card",
"description": "Vet a remote agent or tool's identity card (A2A Agent Card, MCP server card, OAuth metadata, x402, …) BEFORE connecting to it. Supply EITHER `url` (AxioRank fetches the card) OR an inline `document`. AxioRank verifies signatures, scores supply-chain risk, folds in cross-tenant threat intel, and returns `allow` / `review` / `deny` with the resolved identity, capabilities and auth. Use it as a connection preflight. Requires the `cards:verify` scope."
},
{
"name": "axiorank_check_approval",
"description": "Poll the verdict of a held (`hold`) tool call. Pass the `approvalId` returned by `axiorank_score_tool_call`. Blocks briefly server-side and returns as soon as an operator approves/denies; otherwise returns the still-`pending` status so you can call again. Requires the `gateway:write` scope and the same agent key that made the original call."
},
{
"name": "axiorank_get_protocol_coverage",
"description": "List the agent-interop protocols AxioRank can govern (A2A, MCP, OAuth, x402, DIDs, robots.txt/llms.txt, AP2, …), grouped into six planes, each with coverage status (live/beta/planned) and direction (inbound/outbound/both). Use this to discover what AxioRank speaks before wiring up card verification or inbound bot management."
},
{
"name": "axiorank_get_health",
"description": "Liveness/readiness probe for the AxioRank control plane (API + database reachability). Returns `status: ok|degraded`."
},
{
"name": "axiorank_list_agents",
"description": "List the active agents in your AxioRank workspace (id, name, labels, quarantine + last-used status). Use this to find an agent's id before calling agent-specific tools. Requires the `agents:read` scope."
},
{
"name": "axiorank_get_agent",
"description": "Fetch one agent's posture (quarantine state, labels, last-used, revocation) by id, scoped to your workspace. Requires the `agents:read` scope."
},
{
"name": "axiorank_quarantine_agent",
"description": "Reversible kill switch: quarantine an agent so the gateway DENIES all of its tool calls, or release it. Set `quarantine: false` to restore. Requires the `agents:write` scope."
},
{
"name": "axiorank_revoke_agent",
"description": "Permanently revoke an agent: its API keys stop authenticating immediately (incident response). Irreversible. Issue a new agent to restore access. Its audit history is kept. Requires the `agents:write` scope. Prefer `axiorank_quarantine_agent` for a reversible pause."
},
{
"name": "axiorank_list_policies",
"description": "List the outbound governance policies in your workspace (enabled or not), each with its tool pattern, action (allow/deny/require_approval/redact), risk threshold, priority and enabled flag. Requires the `policies:read` scope."
},
{
"name": "axiorank_get_policy",
"description": "Fetch one outbound policy by id, scoped to your workspace. Requires the `policies:read` scope."
},
{
"name": "axiorank_create_policy",
"description": "Create an outbound governance policy. It is created DISABLED so an LLM can never arm enforcement unattended. Review it (axiorank_get_policy) then enable it with axiorank_update_policy. `toolPattern` is a glob over tool names; `action` is allow / deny / require_approval / redact (redact masks PII in a model completion). Requires the `policies:write` scope."
},
{
"name": "axiorank_update_policy",
"description": "Update an existing policy: enable/disable it, rename it, or change its priority. (Other fields are edited in the dashboard.) Requires the `policies:write` scope."
},
{
"name": "axiorank_search_audit_logs",
"description": "Search your workspace's governance audit trail, newest first, with filters: decision (allow/deny/hold), source (sdk/mcp), agentId, tool name (substring), minimum risk, and a time window (ISO `from`/`to`). Payloads are already secret-redacted. Use it to answer questions like \"show denied tool calls in the last 24h\". Requires the `logs:read` scope."
},
{
"name": "axiorank_list_incidents",
"description": "List security alerts/incidents in your workspace, newest first, filterable by status (open/acknowledged/resolved/suppressed), severity (low/medium/high/critical) and kind (high_risk/anomaly/auto_response/kill_chain/ml_threat). Requires the `logs:read` scope."
},
{
"name": "axiorank_get_incident",
"description": "Fetch the kill-chain finding behind an alert (the multi-step attack pattern, severity, and the contributing tool-call ids) by alert id. Returns null evidence for a non-kill-chain alert. Requires the `logs:read` scope."
},
{
"name": "axiorank_list_threat_intel",
"description": "List external identities (card hosts/keys) flagged across the AxioRank network, with k-anonymity-gated aggregate counts (workspaces, sightings, deny/review, max risk). This is the shared cross-tenant feed, not your private data. Requires the `logs:read` scope."
},
{
"name": "axiorank_list_ml_assessments",
"description": "List your workspace's most recent ML/LLM threat assessments (model verdict, threat class, confidence, recommendation) for tool calls and cards. Requires the `logs:read` scope."
},
{
"name": "axiorank_get_usage",
"description": "Report this billing period's usage for your workspace: plan tier, governed events used vs the monthly limit, and ML assessments used. Requires the `logs:read` scope."
},
{
"name": "axiorank_issue_token",
"description": "Mint a short-lived, scoped `axr_tok_…` access token for an existing agent. This is the Zero-Trust credential the agent sends as `Authorization: Bearer <token>`. It expires within the hour and cannot be replayed afterwards. Durable static keys are issued in the dashboard, not here. Requires the `keys:write` scope."
},
{
"name": "axiorank_create_agent",
"description": "Create a new agent in your workspace and return a SHORT-LIVED bootstrap token to start using it immediately (no durable secret is emitted). For long-term auth, add a static key or a federation binding in the dashboard. Requires the `agents:write` scope."
},
{
"name": "axiorank_author_detector",
"description": "Describe a risk in plain English and AxioRank's AI proposes a custom content detector (regex or keyword) and SAVES it DISABLED for your review. An LLM never arms detection unattended. Outbound content categories only (secret/pii/destructive/injection/egress). Requires the `policies:write` scope and an AI-assessments-enabled plan (Team+)."
}
],
"profiled_at": "2026-09-24T22:00:57.138Z"
},
"unreachable": false,
"payment_method": "oauth"
}