Agent card · OpenAPI 3.1 · MCP

Buy a server without a human

We removed the identity layer for privacy reasons. It turned out to produce the cleanest agent-purchasable checkout on the market as a side effect — there is no email confirmation, no card form and no captcha, because there never were any.

Answer

Incognito VPS exposes an agent card at /.well-known/agent.json, an OpenAPI 3.1 document at /openapi.json and an MCP endpoint at /mcp. Authentication is a bearer token created on first use. An autonomous agent can create an account, settle a crypto top-up and deploy a server with no human intervention at any step.

§01 Four calls

Account to running server

No human step at any point. No confirmation email, no card form, no captcha.

shell
# 1. Create a token
curl -X POST https://incognitovps.com/api/v1/account
# → {"token":"IVPS-7K2M-9QX4-1BVN-5RTZ","balance_usd":0}

# 2. Create a top-up invoice
curl -X POST https://incognitovps.com/api/v1/topup \
  -H "Authorization: Bearer IVPS-7K2M-9QX4-1BVN-5RTZ" \
  -H "Content-Type: application/json" \
  -d '{"amount_usd":50,"coin":"XMR"}'
# → {"invoice_id":"inv_...","pay_address":"8B...","pay_amount":"0.2841","expires_in":5400}

# 3. Settle on-chain, then poll
curl https://incognitovps.com/api/v1/topup/inv_... \
  -H "Authorization: Bearer IVPS-7K2M-9QX4-1BVN-5RTZ"
# → {"status":"paid","credited_usd":50}

# 4. Deploy
curl -X POST https://incognitovps.com/api/v1/orders \
  -H "Authorization: Bearer IVPS-7K2M-9QX4-1BVN-5RTZ" \
  -H "Content-Type: application/json" \
  -d '{"plan":"hv-4","region":"bulgaria","months":1,"os":"debian-13"}'
# → {"server_id":"srv_...","status":"active","ipv4":"185.132.48.77"}
§02 Reference

Endpoints

OpenAPI 3.1
API endpoints
Method Path Purpose Auth
GET /.well-known/agent.json Capability card: endpoints, auth scheme, payment model. none
GET /openapi.json Complete OpenAPI 3.1 specification. none
GET /api/v1/catalog Plans, locations and live prices. none
POST /api/v1/account Create a token. Returns it once. none
GET /api/v1/account Balance and server list. bearer
POST /api/v1/quote Price a configuration before committing. none
POST /api/v1/topup Crypto invoice to credit balance. bearer
GET /api/v1/topup/{id} Poll invoice status. bearer
POST /api/v1/orders Deploy, debiting balance. Returns server ID. bearer
GET /api/v1/servers/{id} State, address, credentials. bearer

Rate limits — 120 req/min per token on reads, 20 req/min on writes, 60 req/min per address unauthenticated.

Content built for machines

Every page has a markdown twin at the same path with .md appended, linked from the HTML head. It is a faithful rendering of the same content — no cloaking, just a cleaner format.

/llms.txt
Index of the site, structured for language models
/llms-full.txt
Full text corpus of every English page
/pricing.md
Complete price list as markdown
/pricing.json
Complete price list as JSON
/jurisdictions.json
Legal index dataset, CC BY 4.0
/servers.md
Jurisdiction dossiers as markdown
<path>.md
Markdown twin of any page on the site

Why this works here and not elsewhere

An agent that can read a pricing page but cannot complete a purchase has to hand back to a human at exactly the wrong moment. The provider whose checkout needs a card form, an email confirmation and a captcha simply loses that transaction.

Ours needs a token and a crypto payment. There is no field an agent cannot fill in, because there is no field that asks who you are. 341 configurations are purchasable this way, from $4.00 a month.

The one thing an agent must handle itself is settling the on-chain payment from a wallet it controls. Everything either side of that is a single HTTP call.

55-second deploy

An agent can buy this without asking you

No account to create, no email to confirm, no card to enter.