Threat intelligence for MCP and x402.
MCP (Model Context Protocol) · x402 (an agent payment protocol)
Glimmer runs its own controlled Decoys, then publishes what it can corroborate as versioned Indicators. Customers receive signed Feeds and lookup APIs. Not a wrap, not a workspace, not a safety score — and never the telemetry behind the claim.See what you get ↕
Illustrative example — not a captured incident
- Two observations at separate Decoys shared a TLS fingerprint.
- Publication requires corroboration from at least two independent observations by default.
- Correlated observations publish only as an Anonymous Cluster — never a named actor.
What you get.
Glimmer is a commercial threat-intelligence publisher. Collection is Glimmer-owned. The customer object is an Indicator, not a log line.
- Signed FeedsA Snapshot of current Indicators and Anonymous Clusters, plus cursor Deltas.
- Lookup APIsFor Organizations, and a public x402-paid Lookup Tier for autonomous agents.
- First published objectsAfter corroboration: IP, TLS fingerprint, and wallet.
Each Indicator carries verdict, confidence, reason codes, and a provenance-safe Evidence Summary. It does not carry precise observation times, Decoy IDs, discovery locations, or raw telemetry.
What it is not.
- Not a customer-side MCP wrap or reverse-proxy on someone else's host.
- Not an investigation workspace.
- Not a customer-telemetry ingest.
- Not named attribution. Related observations publish as an Anonymous Cluster.
- Not a claim that a Decoy settled a payment. The x402 Decoy simulates validation and never moves value.
Glimmer is not what remains of a customer's interaction. It is a shared intelligence corpus collected from our Decoys and sold without exposing how we saw it.
Terms we use precisely.
Glimmer never turns an uncertain inference into a definitive claim merely because a simple score is easier to display. These are the terms that keep that promise honest:
- Decoy
- A controlled synthetic MCP or x402 endpoint used to observe hostile interaction without executing attacker input or moving value.
- Raw Telemetry
- The unmodified, immutable event record captured from a Decoy before normalization.
- Indicator
- A customer-visible, versioned intelligence assertion about an observable — a wallet, TLS fingerprint, IP, domain, or fingerprint.
- Anonymous Cluster
- A provisional grouping of related observations that does not assert a named real-world actor.
- Evidence Summary
- A provenance-safe explanation of an Indicator, safe to disclose without revealing collection sources or exact observation details.
- Feed
- The signed channel (Snapshot plus cursor-based Delta) through which corroborated Indicators and Anonymous Clusters reach customers.
- Snapshot
- A full-state Feed delivery: the complete current set of published Indicators and Anonymous Clusters.
- Delta
- A cursor-based incremental Feed update, published between Snapshots.
- Entitlement
- What a given Organization is authorized to access, tied to its usage. Never called a subscription or permission.
- Public Lookup Tier
- An x402-paid lookup API open to autonomous agents directly, alongside self-serve Organization accounts.
- Organization
- A customer account on Glimmer, created by self-serve signup. Never called a tenant.
How customers receive it.
Delivery model — MVP-confirmed, not yet publicly available
Customers receive common intelligence through signed Feeds (Snapshot and cursor-based Delta) and lookup APIs — never a customer investigation workspace, and never raw telemetry. A public, x402-paid Lookup Tier extends access to autonomous agents directly, alongside self-serve Organization accounts. Public Decoy deployment and live customer Feeds remain gated on legal and hosting-provider clearance.
Five ways Glimmer's Decoys generate evidence.
Decoy → Raw Telemetry → normalization → deterministic rules → candidate observables → correlation graph + session grouping → corroboration threshold → versioned Indicator or Anonymous Cluster.
Every derived result retains its processor, rule-set, and model version, anchored to an immutable event identifier. Two of the five paths below are design targets, not live capabilities yet; each is labeled plainly rather than folded into the others.Implemented means the engineering is complete and tested, not that a Decoy is publicly deployed today. Seewhere we are → for status.
| Path | Status | Trigger | Captured evidence | Correlation & outcome |
|---|---|---|---|---|
| MCP protocol probing and misuse | Implemented | Invalid methods, malformed or oversized requests, calls against synthetic MCP tools. | Protocol/transport metadata per exchange, timestamped, tied to the originating Decoy. | Joined by source and timing proximity; repeated patterns across Decoys become a behavior pattern or Anonymous Cluster. |
| MCP tool-poisoning / prompt-injection probes | Planned | A tool call or discovery interaction matches a known injection/poisoning pattern. | Would match normalized content against a versioned rule set — matched-rule reference and confidence only, never the raw payload. | Would correlate matching patterns across Decoys to identify campaigns that adapt over time. |
| x402 malformed-payment and protocol abuse | Implemented | Missing header prompts a challenge; malformed or synthetically-rejected header captured as an attempt. | Transport/protocol metadata per attempt, plus a cryptographic fingerprint of the payment artifact. | Matching fingerprint flags replay across sources and time — distinguishes a one-off client from scanning infrastructure. |
| Payment identity and wallet correlation | Planned | Would derive a candidate wallet from structurally valid, cryptographically verifiable payment material. | Candidate wallet identifier, same provenance and confidence model as any observable. Credentials or private material never enter Indicators. | High-value link across observations — the one cryptographically-gated exception to the two-observation corroboration threshold. |
| Shared infrastructure and campaign correlation | Implementedat the graph layer | Any suspicious event repeats an observable already seen elsewhere. | Network- and protocol-level fingerprints observed across Decoys, timestamped and linked by session. | Linked in a relationship graph, clustered only as an Anonymous Cluster — never named attribution from one shared signal. |