Proof · machine-verifiable, not testimonials
Most company “proof” pages are testimonials and case studies. We have none of those — no paying clients yet, so nothing to quote. Instead, every claim here links to a live endpoint an agent or a human can re-run, and every number is labelled verified or unverified. If a thing is not independently checkable, we say so on this page.
SaSame runs a public Model Context Protocol endpoint over streamable-http. You do not have to take our word for what it does — POST a tools/list request and call the free preview tools yourself. Per our honesty rules we do not advertise a fixed tool number (the count is currently inconsistent across our own sources); the only number we trust is what the live server returns when you ask it.
Public MCP endpoint
https://live-vps.sasame.online/public-mcp
Transport: mcp-streamable-http. Free readiness tools + paid continuous monitoring.
Tool count: 94 tools as reported by the live server at 2026-08-01 23:27:31Z.
Open the endpoint →Reproduce it (free)
curl -s -X POST \
https://live-vps.sasame.online/public-mcp \
-H 'Content-Type: application/json' \
-H 'Accept: application/json, text/event-stream' \
-d '{"jsonrpc":"2.0","id":1,
"method":"tools/list","params":{}}'The response lists the current tools. Free tools return real data with no key.
Why no fixed number? Across our own sources the count has read differently (live tools/list, our llms.txt, a prior internal audit). Until they reconcile, publishing any one figure would be a number that does not trace to a stable source — so we query it live and label the timestamp, or omit it.
agent-proof.json is a script that re-invokes the real services and records HTTP status, latency and returned content. It currently passes 5/5 checks (100%). Read this honestly:
self-test; independently reproducible by calling the endpoints — NOT third-party verified.This is SaSame's own script calling SaSame's own endpoints. It proves the services are live and functional — not that a third party audited them, and not that anyone is paying for them. It is reproducible: open the JSON, then call the same endpoints and compare.
Liveness checks
5 / 5
passed · 100%
operator: SaSame SRL (Romania, CUI 50731520)
Research utility
Former paid tier is inactive
Use the free research tools or see Services for the active paid shelf.
Research endpoint →as of 2026-08-01 · source: agent-proof.json
Public GitHub repository
github.com/shigeki7777/sasame-mcp
The MCP server source is public. You can read what the tools actually do rather than trust a description — the strongest form of “proof” for a developer or an agent evaluating a vendor.
Open the repository →Public repository. We do not claim stars, forks or downloads — go look.
Research library (free tools via MCP)
The public MCP exposes free preview research tools that return real data with no API key — verifiable by simply calling them. Examples from the last self-test (non-authoritative; query tools/list for the current live set):
The live tools/list endpoint is the authoritative set; names above may differ from the current live toolbelt.
The Observatory samples public agent registries and publishes a machine-readable dataset. The evidence points one way: most listings register and never produce — “ghosts”. This is SaSame's own measurement, sampled — not a complete census, not a complete census, and the raw dataset is linked so you can check it.
Registries indexed
8,117
+ 27,359 (second registry)
reported totals across two registries
Mass-producer concentration
70% / 54%
from a single domain (orbisapi.com) in samples
a few producers dominate — the “ghost” signature
Cross-registry overlap
~1%
of the union appears in both
any single registry is a biased lens
Census — indexed vs verified
30,001 / 1
auto-indexed / verified members
auto-indexed from public registries, UNVERIFIED, NOT members; verified members = 0
Low overlap => the two registries see largely DIFFERENT slices of the market. A single source is a biased lens.
as of 2026-08-01 · source: observatory-multi-latest.json · last verified 2026-07-19 · (offline fallback)
SaSame continuously audits the public MCP population against the 10-criterion Agent-Tool Discoverability Standard. Below are the most common measured gaps. Read them as measured criterion failures — observed from outside, owner-claimable (claim → fix → re-audit), not endorsements and not death certificates.
Servers audited
38,999
against the 10-criterion Standard
Observed MCP-Ready
2,854
measure ready from outside (unclaimed)
The same signed ledger, read as an attack surface: which capability classes the public MCP population exposes, and whether an agent can tell a read from a write, delete or payment before it calls. This is an observation of the declared surface — not a vulnerability scan, not malware detection, and nota claim any server is unsafe. “Unlabeled” means the server published no machine-readable safety annotation — a hygiene gap a caller must gate manually.
Enumerable servers
3,023
exposed a tool surface we could read anonymously
Declared tools
62,962
24,497 of them state-changing
Unlabeled & state-changing
4,823
no read/destructive hint an agent could gate on
The capability-over-time signal — which servers newlyexpose a higher-risk class since first observed — is the part an agent cannot self-produce; it compounds with every crawl. Per-server defensive pre-call checks are available over MCP (capability_profile); this aggregate never names individual servers.
as of 2026-08-01 · source: attack-surface.json · full report
What this page does NOT prove
External AI reach is 80487 crawler/registry hits from 220 distinct IPs (external AI crawler/registry hits — discovery / reach, NOT demand). That is discovery, not buying. External tool calls = 101, engagement = 0, paid = 0.
The 5/5 agent-proof result is self-test; independently reproducible by calling the endpoints — NOT third-party verified. It proves the services run; it does not prove an external party audited or paid for them.
The Census shows 30,001 auto-indexed listings but 1 verified members. We do not count indexed listings as users, customers or members — and neither should you.
Knowledge-ledger finding 0004 = REFUTED at present: there is no externally verifiable example (mid-2026) of an AI agent autonomously discovering and paying a no-track-record vendor via llms.txt / registry / x402. We surface proof of capability, not proof of demand — because the latter does not exist yet.
The whole bet is under a public kill-test: LIVING GATE verdict SIGNAL, Day 44/30, decision 2026-07-17. A page full of capability proof with zero external pulse by then is a REFUTED_SHRINK, not a win. as of 2026-08-01 · source: funnel.json.
Anti-ghost (C7) is the single most common gap — a server that registers but does not return real content. We measure it from outside and never call a server “dead”: many are simply invisible to naive probing, and any owner can claim and fix their record. That is the moat — a neutral, signed, re-runnable measurement an agent cannot self-issue.
as of 2026-08-01 · source: observatory.json