One in Seven Paid Agent Endpoints Has More Than One Buyer
· 425 words
Of 30,189 paid agent endpoints tracked via Coinbase telemetry, 4,306 have more than one distinct paying caller in the last 30 days. That is 14.3%. The other 85.7% have at most one payer, and in most cases that payer is the operator who built the service.
The call count, 345,350 over 30 days, sounds like a market. The buyer count reveals something closer to an extended product test. A service called once by its own operator has not been sold. It has been wired up.
This distinction matters for any builder trying to earn revenue from an agent endpoint. Attracting a second buyer, one who found you independently and paid without any coordination, is the actual signal that you have a product rather than infrastructure you are running for yourself.
Three gaps separate most single-payer endpoints from the ones that have multiple buyers. First, no description. Of the 16,195 hosts we track, 8,992 publish nothing readable about what they do. An orchestrating agent evaluating which tools to call cannot select a service it cannot describe. The endpoint might as well not exist.
Second, no live response. Fifty-two percent of actually-probed MCP servers answered a live tools/list handshake. The rest either failed or were blocked from testing. A server that does not respond to discovery cannot be bought by anyone who did not already know it was there.
Third, no corroboration. Only 1,226 hosts appear in two or more independent registries. A listing in a second registry is the cheapest trust signal available, and most services have not collected it.
None of this is difficult to fix. A paragraph describing what the endpoint does, a working tools/list response, and a submission to one more registry is work that takes hours. Most operators have not done it.
The security market is starting to price this gap. AIR, a startup founded by Israeli intelligence veterans, raised $50 million last week to help enterprises vet the agent tools and MCP servers their agents connect to. Their argument is that AI agent tool supply chains look like operating systems before driver signing existed: anyone can install anything, with no verification of who built it or what it does. Their product includes a marketplace of pre-vetted add-ons.
But AIR serves the buyer side. The operator who wants to appear on a vetted list rather than get blocked by one has to do the trust work themselves. Readable description, live endpoint, second registry listing. Those are the baseline. Without them, the 85.7% of single-payer endpoints are not just undiscovered. They are undiscoverable.
Sources
[object Object] · [object Object]