DEV Community

ScriptMasterLabs
ScriptMasterLabs

Posted on Originally published at scriptmasterlabs.com

Fund Momentum gave AI agents a pay-per-call MCP server — and deleted the confirmation step

Fund Momentum gave AI agents a pay-per-call MCP server — and deleted the confirmation step

Yesterday, Vienna's Fund Momentum opened its VC/LP fundraising database to AI agents through a remote MCP server with machine payments in USDC on Tempo. Agents self-register with one API call (no email), get 25 free credits, and pay per call through the Machine Payments Protocol: the tool answers HTTP 402 with a payment challenge, the agent pays and retries, and gets data plus a receipt.

The pricing is genuinely micropayment-native: €0.01 per search_funds/get_fund/get_changes call, €0.10 for get_fund_signals/get_gp_profile, €0.25 for match_startup. Timed-out calls re-issue the same challenge (never pay twice); wrong slugs are rejected before any challenge.

Here's the detail that should worry builders: every tool is declared read-only and idempotent "so agents can call them without a confirmation step."

Read-only describes side effects. It doesn't describe spend. At €0.25 a pop, an agent can run a 4,000-call match_startup sweep — €1,000 of machine spend — with zero confirmation and zero scored judgment between intent and settlement. Fund Momentum sets the vendor confirm band to zero and trusts idempotency. But idempotency isn't judgment.

The genuinely novel part is the provenance block: every record carries its source, the date it was last verified, and a confidence score — structured, the company says, "as much for an AI agent to evaluate trust as for a human reader." That's half of what a decision gate needs. A confidence score on the data tells the agent whether the record is trustworthy; a scored gate tells it whether this call deserves to fire. Source × freshness × confidence-in-data fused with instruction × budget × provenance-of-the-question — that's the decision.

I tested my live gate this morning against two instructions:

  • "Should the agent pay €0.01 via MPP on Tempo for one search_funds call... for a founder raising a seed round?" → 0.35, escalate/block+log
  • "Should the agent auto-fire 4,000 match_startup calls at €0.25 each (€1,000 total, no per-call review)?" → 0.35, escalate/block+log

The uncalibrated heuristic can't discriminate a €0.01 listed-price lookup from a €1,000 credit-drain sweep — fail-closed blocks both. That's eighteen runs in a row with this finding, and the upgrade is the same: a calibrated decider would green-light the €0.01 provenanced call at ≥0.80 and block the €1,000 sweep below 0.50. "Block everything" is a seatbelt, not judgment.

For builders working on pay-per-call MCP servers:

  1. Consume the provenance block — weight source × freshness × confidence before the buy.
  2. Score the call, not the server. Trust in the tool isn't trust in this invocation.
  3. Put per-call price in a per-task envelope. Fund Momentum's get_changes incremental-sync tool is the disciplined pattern — pull the diff, don't re-poll the world.
  4. Keep every 402 receipt: challenge id, amount, rail, band, decision, timestamp.
  5. Never outsource judgment to "no confirmation needed." The confirmation you skip is the payment you authorized.

Full canonical with dated receipts, claim objects, and FAQ: https://scriptmasterlabs.com/fund-momentum-mcp-pay-per-call

Top comments (0)