# M2M Sentinel — Autonomous Agent Capabilities Manifest agent-service: M2M Sentinel service-url: https://m2msentinel.com api-url: https://api.m2msentinel.com contact: contact@m2msentinel.com primary-chain: Base (eip155:8453; chainId 8453) settlement-token: USDC (0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913) payout-address: 0x6d6C398390cfb88f1CD42715B84906a0Bd6652aa sdk-version: 1.2.7 protocols: - name: model-context-protocol current-transport: streamable-http endpoint: https://api.m2msentinel.com/mcp local-command: npx -y @m2msentinel/sdk mcp legacy-sse: https://api.m2msentinel.com/sse manifest: https://m2msentinel.com/.well-known/mcp/server.json - name: x402 version: 2 catalog: https://m2msentinel.com/.well-known/x402 network: eip155:8453 - name: rest-openapi version: 3.1.0 spec: https://m2msentinel.com/openapi.json payable-capabilities: - route: GET /v1/audit/{address} price-x402: $0.02 USDC description: Before you sign: can this Base contract be paused, frozen, or have tokens minted by its owner, self-destruct, or delegate execution somewhere you have not seen? Returns the opcodes and selectors actually present in the deployed bytecode, resolves proxies and EIP-7702 delegated accounts to what really runs, and states the trust level behind the answer. Evidence for your policy, not a safety verdict. - route: GET /v1/security/score/{address} price-x402: $0.02 USDC description: How completely could this Base contract be checked, and on what grade of evidence. Separates checked-and-clean from could-not-be-checked, which automated callers otherwise conflate. Explicitly not a safety score. - route: GET /v1/gas/fees price-x402: $0.005 USDC description: What a Base transaction costs right now, with the RPC provider and trust level behind the number, so a caller can tell a credentialed reading from a degraded one before pricing a transaction. - route: GET /v1/dex/metrics price-x402: $0.01 USDC description: How deep is liquidity for tracked Base tokens and how much is actually trading, with the source named, for sizing an order or declining one. - route: GET /v1/token/price/{symbol} price-x402: $0.005 USDC description: What a tracked Base token is worth right now, taken as the median of the deepest pools rather than one pair, returning the pools considered and the spread across them. - route: GET /v1/whales/signals price-x402: $0.02 USDC description: Who is moving size on Base right now: large ERC-20 transfers reported as observed facts with amounts and source, not as trade signals or predictions. api-key-metered-capabilities: - route: POST /v1/transaction/preflight access: API key or verified RapidAPI proxy authentication; one existing decision credit after a valid evidence response is prepared. x402: not-payable; no x402 price description: API-key/RapidAPI metered transaction-specific evidence. Accepts one strictly validated Base mainnet transaction, pins one observation block before state-bearing reads, identifies the supplied four-byte selector and resolved implementation or Diamond facet, returns bytecode hashes, capability evidence and an eth_call observation when possible. Incomplete or unsupported paths stay explicit. The caller owns policy before signing. This route is not x402-payable and has no x402 price; an unauthenticated request receives the normal protected-route 401 response. limitations: - Capability observations are static evidence, not safety, maliciousness, reachability, or exploitability guarantees. - notASafetyGuarantee is always true for contract observations. - Credentials in URL query strings are rejected; use x-api-key or Authorization headers. implementation-services: - name: Growth Integration Sprint price-usd: 299 existing-plan: GROWTH checkout: https://m2msentinel.com/checkout.html?tier=GROWTH&duration=31 rapidapi: https://rapidapi.com/ApplicationsForTheFuture/api/m2m-sentinel-api rapidapi-tier: ULTRA scope: one codebase, one Base signing boundary, one runnable proxy/EIP-7702-aware preflight patch, bounded seven-day handoff - name: Pro Production Sprint price-usd: 999 existing-plan: PRO checkout: https://m2msentinel.com/checkout.html?tier=PRO&duration=31 rapidapi: https://rapidapi.com/ApplicationsForTheFuture/api/m2m-sentinel-api rapidapi-tier: MEGA scope: up to two transaction flows, runnable integration patches, deployment and handoff documentation intake: https://m2msentinel.com/integration-sprint.html#intake note: Payment uses the existing plan rail; no new API entitlement or x402 price is introduced. Never send private keys, seed phrases, raw API keys, or wallet credentials. technical-proof-assets: - name: Openfort-compatible EIP-7702/ERC-4337 preflight page: https://m2msentinel.com/proof-openfort.html source: https://github.com/M2M-Sentinel/m2m-sentinel-sdk/blob/main/examples/proofs/openfort-7702-preflight.ts official-reference: https://github.com/openfort-xyz/openfort-7702-account demo-reference: https://7702.openfort.io/ workflow: Observe the selected execution target and apply caller policy before an Openfort-style signUserOperation callback. status: Original adapter example; not an official Openfort integration or partnership. - name: Locus-compatible standalone agent-payment preflight page: https://m2msentinel.com/proof-locus.html source: https://github.com/M2M-Sentinel/m2m-sentinel-sdk/blob/main/examples/proofs/locus-compatible-agent-payment.ts official-reference: https://docs.paywithlocus.com/ developers-reference: https://paywithlocus.com/developers workflow: Observe the dynamically selected Base payment target and apply caller policy before the payment callback. status: Original standalone adapter; no Locus SDK or partnership is claimed. note: Both proofs use hermetic mocks, require no funded wallet or executable private key, and block unresolved proxy/delegation evidence according to caller-defined policy.