AGENT API · REST + MCP

Let your AI agent
order its own security audit

An agent that writes or deploys smart contracts can now ask Grisoco AI to audit them before anything goes on-chain, with no human clicking through a dashboard. One API key, a prepaid balance, and the same review the workspace runs, including the delegation and session-key review for the contracts agents use to pay. Over plain REST, or as an MCP tool in Claude, Cursor and any other MCP client.Give your agent an API key and it can quote, run and collect audits on its own, over REST or as an MCP tool. Same review as the workspace, paid from your prepaid balance.

InterfacesREST + MCP
LanguagesSolidity, DAML
PaymentPrepaid USDC
Failed auditRefunded
01 · SETUP

Get a key

  1. Sign in to the workspace and top up your balance with USDC (Buy points).
  2. Open Agent API, name a key, and set a daily cap: the most that key may spend per day, whatever your balance.
  3. Copy the key (it starts with grisoco_sk_). It is shown once; store it as a secret, never in source code.
02 · MCP

Connect an MCP client

The MCP server lives at https://grisoco.com/mcp (Streamable HTTP). Send your key as a bearer token. In Claude Code:

claude mcp add --transport http grisoco https://grisoco.com/mcp \
  --header "Authorization: Bearer grisoco_sk_..."

Or in any client that reads an mcpServers config:

{
  "mcpServers": {
    "grisoco": {
      "type": "http",
      "url": "https://grisoco.com/mcp",
      "headers": { "Authorization": "Bearer grisoco_sk_..." }
    }
  }
}

Your agent then has six tools:

03 · REST

Call the REST API

Submit. The answer comes back in about a second with an id, and the audit runs in the background:

curl https://grisoco.com/v1/audits \
  -H "Authorization: Bearer $GRISOCO_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "project_name": "Acme Vault",
    "product": "deep_review",
    "language": "solidity",
    "max_price_cents": <price_cents from /v1/audits/quote>,
    "files": [{"path": "src/Vault.sol", "content": "pragma solidity ^0.8.24; ..."}]
  }'

Poll until status is succeeded, then fetch the report:

curl https://grisoco.com/v1/audits/aud_... -H "Authorization: Bearer $GRISOCO_KEY"
curl "https://grisoco.com/v1/audits/aud_.../report?format=markdown" \
  -H "Authorization: Bearer $GRISOCO_KEY"
04 · PAYMENT

How you are charged

The same prices as the workspace (see pricing), paid from the balance you top up with USDC.

Your agent can never spend more than you prepaid, and never more per day than the key's cap.

05 · SAFETY

Keys, limits and your data

READY WHEN YOUR AGENT IS

Create a key and connect your agent

Everything an agent needs is one key and a funded balance.

Grisoco AI is an automated audit: no human security engineer reviews your code, and it is not a certification. No audit of any kind — automated or human — can prove a contract is free of vulnerabilities, and this one will miss issues, including critical ones. Have a qualified engineer review every finding, and engage a professional audit firm as well before deploying a contract that holds significant value. See the Terms of Service.