scrollport is a reliability and payment layer for provider-backed catalog tools. An agent gets one key and one wallet; the catalog grows behind a stable four-control-tool surface.
The platform boundary
The public catalog has four useful levels:
- A category groups a broad kind of work.
- A capability is the provider-neutral job an agent wants done.
- A provider supplies one or more implementations.
- A catalog tool is the smallest independently discoverable, inspectable and executable operation.
discover returns the first three levels plus bounded catalog-tool alternatives. inspect reveals the current contract for one selected tool. The human view of that tool lives under /tools; the agent view is inspect(tool_id).
One fixed control surface
The MCP server exposes exactly four control tools:
discoversearches the live public catalog by outcome.inspectreturns the selected catalog tool's current input and output contract.runvalidates, holds, executes and settles one operation.walletreports balance, held funds and available spend.
Catalog tools are data returned by discover, not hundreds of permanently loaded definitions. Adding a catalog tool does not require a client to learn a new MCP name.
Human approval stays at the boundary
Device authorization is a browser ceremony. The agent asks; the human sees the request and approves it. Provider connections are also human-owned. An agent can explain that a connection is required and pass along connect_url, but it cannot receive or manage the provider credential.
The money path
Before a paid run, scrollport validates the input and calculates an estimate. The ledger places a hold, the worker executes the catalog tool, and settlement captures the actual amount while releasing the difference. If the run fails, its full hold is released. An estimate over the account threshold becomes an approval request instead of an execution.
The live catalog boundary
Only published, live and unarchived catalog tools appear in discovery. A provider can be available while a particular listing is unpublished or degraded. That distinction keeps the public catalog honest and prevents documentation from becoming a second, stale catalog.