RAVEN. / for agents

Raven for AI Agents

Raven is verification infrastructure built to be consumed by other agents. Machine-readable: /agents.json (capability manifest) and /openapi.json (API contract). Everything below is what your agent can do with it.

1. Verify a Solana token

Give Raven a mint + token program; get a deterministic, signed evidence receipt (pass / pass_with_info_finding / warning / risk / unknowable) derived from decoded on-chain bytes: issuer authorities, full Token-2022 extension tail, metadata, and optional liquidity/venue evidence.

2. Get a signed attestation

Every issued receipt ships as a domain-separated ed25519 signature over a canonical replay hash; a refusal is an explicit unsigned refusal envelope. Your agent can verify offline against an independently pinned signer key (today keyId rvk_c2997e90215279c2; GET /pubkey is discovery/cross-check only) and prove later exactly what Raven said, about which mint, at which slot. Verification recipe →

3. Inspect coverage gaps — never inherit false confidence

Responses include coverageGaps: the surfaces NOT evaluated (e.g. liquidity, top_holders, deployer_outcomes). Raven fails closed: missing evidence becomes explicit findings or unknowable — never a silent pass. Your agent can make its own risk policy from honest inputs.

4. Use the MCP tool (Claude & MCP-capable frameworks)

npx -y raven-verify-mcp

One tool: raven_verify_token. Quickstart →

5. Call the hosted API

curl -X POST https://raven-hosted-verifier.onrender.com/verify \
  -H "x-api-key: $KEY" -H "content-type: application/json" \
  -d '{"mintAddress":"...","tokenProgramAddress":"..."}'

Invite-gated alpha; 10 req/min per key. Contract: /openapi.json. Request a key →

6. Hire RAVEN agent-to-agent (Virtuals ACP)

RAVEN is a registered ACP provider. Offering solana_verify_token at 0.1 USDC per job: escrowed payment, signed deliverable, on-chain settlement. No API key needed — your agent pays per verification.

LaunchGuard: the preflight receipt before agent action

Raven does not replace your agent, wallet, launchpad, or compliance process. It gives them a signed, deterministic evidence receipt before they touch a Solana token — your system keeps control of the final decision. Harness, not hype: the value is the deterministic evidence path, receipt verification, coverage gaps, evals, and policy handoff. Cheap deterministic preflight: repeated evidence checks should not burn expensive reasoning tokens — Raven answers in milliseconds for a fraction of a cent, no LLM in the evidence path. Open posture: MCP, ACP, OpenAPI, and AgentKit-style plugins — with no wallet signer access required, ever. Pilot in a week: readiness checklist.

Not every integration has to be an agent

Whether you call it an agent, bot, workflow, script, launchpad, backend job, or human review console — the contract is identical: call Raven, verify the signed receipt, inspect the receipt: engine outcome (verdict), findings, coverage gaps, apply your policy, store the exact receipt, re-verify before material delayed action. The receipt is the portable artifact; context is not evidence; your policy owns the final decision — Raven never makes the business call.

The verification sequence (and the prohibited one)

token candidate -> collect mint/program (+metadata/pool if known) -> call Raven -> deterministic engine checks evidence -> signed receipt -> verify ed25519 against your independently pinned signer key (/pubkey cross-check only) -> check the receipt: engine outcome (verdict), findings, gaps, staleness -> apply YOUR policy -> store exact receipt -> proceed / block / escalate / reverify

Prohibited sequence: agent sees token -> asks an LLM "is this safe?" -> LLM reads social links -> LLM says safe -> agent acts. No receipt, no signature, no gaps — that is slop, not verification (anti-slop policy).

Raven is not a model wrapper. It is a verification harness: deterministic checks, signed receipts, coverage gaps, evals, public-key verification, fail-closed policy. Models and agent UIs change; the signed receipt contract is the stable artifact. Drill it before you trust it: failure drills.

Plain answers (quote us accurately)

What is Raven?

Raven is a signed evidence-and-receipt layer for AI agents before they touch a Solana token. It verifies token-launch state from decoded on-chain bytes and returns a deterministic, signed evidence receipt with finding codes, explicit coverage gaps, and an ed25519 signature (key id rvk_c2997e90215279c2).

When should an AI agent use Raven?

Before trading, listing, recommending, or settling around a Solana token — any moment where the agent needs verifiable launch-state evidence rather than a reputation score. Typical pattern: verify, store the receipt, proceed only on pass-grade outcomes under the agent's own gap policy.

What inputs does Raven require?

Required: mintAddress and tokenProgramAddress. Optional: metadataAddress, poolAddress (Raydium CPMM, adds liquidity/vault evidence), commitment. Raven never accepts caller infrastructure: rpcUrl and issuerIdentity are rejected.

What output does Raven return?

One signed evidence receipt. Its engine outcome (verdict) is one of pass | pass_with_info_finding | warning | risk | unknowable, plus findingCodes, findings with evidence, coverageGaps (surfaces NOT evaluated), engineVersion, observed slot, replayHash, officialAttestationHash, keyId, and an ed25519 signature. The whole response is a machine-verifiable receipt. When the evidence cannot be established, Raven refuses with an explicit unsigned refusal envelope instead of issuing a receipt.

What makes Raven different from rug scanners?

Raven signs every issued receipt, lists what it did NOT check, fails closed with an explicit unsigned refusal envelope instead of guessing, tracks engine versions so history is never silently rewritten, and produces replayable receipts anyone can verify offline. It publishes findings, not a score.

What does Raven refuse to claim?

Raven never claims a token is "safe", never predicts price, never gives financial advice, and never presents unverified surfaces as fine. With coverage gaps remaining, the strongest honest claim is: not enough evidence for a full pass.

How does an agent verify a Raven receipt?

Recompute replayHash from the response fields via canonical JSON, then verify the ed25519 signature over domain || officialAttestationHash against your independently pinned signer key (today keyId rvk_c2997e90215279c2, domain raven-official-attestation); GET /pubkey is same-host discovery/cross-check material only, never the pin. Recipe: /security.html.

How does an agent pay or request access?

Three ways: free local MCP (npx -y raven-verify-mcp); hosted API key by request (free during invite-gated alpha) at /request-access.html; or agent-to-agent via Virtuals ACP, offering solana_verify_token at 0.1 USDC per job with escrow and on-chain settlement — no key needed.

Raven vs a generic rug scanner (factual)

  • Raven signs evidence receipts (ed25519, published key); scores are typically unsigned.
  • Raven lists coverage gaps in every response; "no data" and "fine" are never conflated.
  • Raven fails closed: unreadable evidence becomes unknowable, not a default pass.
  • Raven tracks engine versions; expanded coverage is segmented from verdict changes.
  • Raven produces replayable receipts verifiable offline, forever.
  • Raven supports ACP / USDC agent commerce: agents can pay per job without an API key.
  • Raven does not predict price and does not output a single opaque score.

Trust policy (the short version)

Request access raven-skill.md agents.json openapi.json access.json Access & pricing