Agent card · OpenAPI 3.1 · MCP
Buy a server without a human
We removed the identity layer for privacy reasons. It turned out to produce the cleanest agent-purchasable checkout on the market as a side effect — there is no email confirmation, no card form and no captcha, because there never were any.
Answer
Incognito VPS exposes an agent card at /.well-known/agent.json, an OpenAPI 3.1 document at /openapi.json and an MCP endpoint at /mcp. Authentication is a bearer token created on first use. An autonomous agent can create an account, settle a crypto top-up and deploy a server with no human intervention at any step.
Account to running server
No human step at any point. No confirmation email, no card form, no captcha.
# 1. Create a token
curl -X POST https://incognitovps.com/api/v1/account
# → {"token":"IVPS-7K2M-9QX4-1BVN-5RTZ","balance_usd":0}
# 2. Create a top-up invoice
curl -X POST https://incognitovps.com/api/v1/topup \
-H "Authorization: Bearer IVPS-7K2M-9QX4-1BVN-5RTZ" \
-H "Content-Type: application/json" \
-d '{"amount_usd":50,"coin":"XMR"}'
# → {"invoice_id":"inv_...","pay_address":"8B...","pay_amount":"0.2841","expires_in":5400}
# 3. Settle on-chain, then poll
curl https://incognitovps.com/api/v1/topup/inv_... \
-H "Authorization: Bearer IVPS-7K2M-9QX4-1BVN-5RTZ"
# → {"status":"paid","credited_usd":50}
# 4. Deploy
curl -X POST https://incognitovps.com/api/v1/orders \
-H "Authorization: Bearer IVPS-7K2M-9QX4-1BVN-5RTZ" \
-H "Content-Type: application/json" \
-d '{"plan":"hv-4","region":"bulgaria","months":1,"os":"debian-13"}'
# → {"server_id":"srv_...","status":"active","ipv4":"185.132.48.77"} Endpoints
| Method | Path | Purpose | Auth |
|---|---|---|---|
| GET | /.well-known/agent.json | Capability card: endpoints, auth scheme, payment model. | none |
| GET | /openapi.json | Complete OpenAPI 3.1 specification. | none |
| GET | /api/v1/catalog | Plans, locations and live prices. | none |
| POST | /api/v1/account | Create a token. Returns it once. | none |
| GET | /api/v1/account | Balance and server list. | bearer |
| POST | /api/v1/quote | Price a configuration before committing. | none |
| POST | /api/v1/topup | Crypto invoice to credit balance. | bearer |
| GET | /api/v1/topup/{id} | Poll invoice status. | bearer |
| POST | /api/v1/orders | Deploy, debiting balance. Returns server ID. | bearer |
| GET | /api/v1/servers/{id} | State, address, credentials. | bearer |
Rate limits — 120 req/min per token on reads, 20 req/min on writes, 60 req/min per address unauthenticated.
Content built for machines
Every page has a markdown twin at the same path with .md appended, linked from the HTML head. It is a faithful rendering of the same content — no cloaking, just a cleaner format.
- /llms.txt
- Index of the site, structured for language models
- /llms-full.txt
- Full text corpus of every English page
- /pricing.md
- Complete price list as markdown
- /pricing.json
- Complete price list as JSON
- /jurisdictions.json
- Legal index dataset, CC BY 4.0
- /servers.md
- Jurisdiction dossiers as markdown
- <path>.md
- Markdown twin of any page on the site
Why this works here and not elsewhere
An agent that can read a pricing page but cannot complete a purchase has to hand back to a human at exactly the wrong moment. The provider whose checkout needs a card form, an email confirmation and a captcha simply loses that transaction.
Ours needs a token and a crypto payment. There is no field an agent cannot fill in, because there is no field that asks who you are. 341 configurations are purchasable this way, from $4.00 a month.
The one thing an agent must handle itself is settling the on-chain payment from a wallet it controls. Everything either side of that is a single HTTP call.
55-second deploy
An agent can buy this without asking you
No account to create, no email to confirm, no card to enter.