AxioRank: Zero-Trust for AI Agents
com.axiorank/axiorank · 1.0.1
Zero-trust gateway for AI agents: score tool calls, verify agent cards, enforce policy, audit.
Nobody here has read this server's code, because it publishes none. The description above is the maker's own, from the registry. A connection test shows whether it answers and what tools it says it has; it never calls a tool, so it cannot show what one does with your data.
Where it sits in the directory's order
What can be seen from outside, weighed as the directory publishes.
Observable signals: 60 of 100 points (at most 60 here)
| Input | Points | What was seen |
|---|---|---|
| Source published | held at 0 | No entry here publishes source: that is what puts it in this directory. |
| Licence stated | held at 0 | With no files, there is nothing for a licence to be stated in or held against. |
| Advisory state | held at 0 | Advisory databases index packages, and these entries publish none, so there is nothing to look up. |
| Auth declared | 15 of 15 | The registry entry declares a key or a token. |
| Latest connection test reached it | 20 of 20 | The latest test had its handshake answered. |
Where it answers
https://app.axiorank.com/api/mcp-server/mcpstreamable-httpAuthorizationrequired, secret: AxioRank API key as a Bearer token (axr_live_…), required for tool calls (the handshake and tool listing are public). Create one in your AxioRank dashboard under Settings → API keys.
Connection test
The MCP handshake, then a request for the tool list, with no key and no data of yours. Run nightly, and by anyone, at most once every ten minutes per server.
It completed the handshake and listed 22 tools.
- Protocol
- 2025-06-18
- Calls itself
- axiorank 1.0.1
- Handshake time
- 75 ms
- HTTP status
- 200
The tools it lists (22, as of 4 days ago)
The tool-description rules found nothing in these descriptions. They look for instructions aimed at a model and for hidden characters; they cannot see what a tool does when it runs.
axiorank_score_tool_callInspect a proposed agent tool call BEFORE executing it. AxioRank scores its risk (0–100), runs content inspection (secrets, PII, destructive ops, prompt-injection, egress), applies your policies, records an audit log, and returns a decision: `allow`, `deny`, or `hold`. On `hold`, a human must approve. Poll `axiorank_check_approval` with the returned `approvalId`. Call this in your tool-use loop and refuse or wait on any non-`allow` decision. Requires the `gateway:write` scope.
axiorank_verify_cardVet a remote agent or tool's identity card (A2A Agent Card, MCP server card, OAuth metadata, x402, …) BEFORE connecting to it. Supply EITHER `url` (AxioRank fetches the card) OR an inline `document`. AxioRank verifies signatures, scores supply-chain risk, folds in cross-tenant threat intel, and returns `allow` / `review` / `deny` with the resolved identity, capabilities and auth. Use it as a connection preflight. Requires the `cards:verify` scope.
axiorank_check_approvalPoll the verdict of a held (`hold`) tool call. Pass the `approvalId` returned by `axiorank_score_tool_call`. Blocks briefly server-side and returns as soon as an operator approves/denies; otherwise returns the still-`pending` status so you can call again. Requires the `gateway:write` scope and the same agent key that made the original call.
axiorank_get_protocol_coverageList the agent-interop protocols AxioRank can govern (A2A, MCP, OAuth, x402, DIDs, robots.txt/llms.txt, AP2, …), grouped into six planes, each with coverage status (live/beta/planned) and direction (inbound/outbound/both). Use this to discover what AxioRank speaks before wiring up card verification or inbound bot management.
axiorank_get_healthLiveness/readiness probe for the AxioRank control plane (API + database reachability). Returns `status: ok|degraded`.
How this entry becomes a listing
For the maker. The catalogue lists what it can read, and this server publishes nothing to read yet. There are two routes, and only the first is open today.
Publish the source Open today
- Put the server's source in a public repository on github.com, with a licence.
- Keep a server.json in that repository naming this server,
com.axiorank/axiorank, and declare the repository in it:"repository": { "url": "https://github.com/owner/repo", "source": "github" }, adding"subfolder"when the server lives in a folder. - Publish that version to the official MCP registry.
- The nightly registry sweep records the declaration. This page stays, dated, and says the source is declared but not yet read.
- The catalogue reads declared repositories at a pinned commit, in batches run by hand, and lists the servers that meet the batch's rules (among them a server.json at that commit naming the server, an https endpoint and a licence). When it lists this server, this page links to the listing. There is no schedule, so no date can be promised.
List it through the maker studio Not open yet
From the official MCP registry, last updated there 69 days ago. The registry entry · axiorank.com