Skip to main content

The problem

Your agent’s first call is the real one. There is no rehearsal. A wrong call that errors is the cheap failure. You find out. The expensive one is quiet. Well-formed, accepted, nothing throws, and the world is now wrong. Nobody gets an alert for a call that worked and was wrong.

Watch it run

Ten questions, four programs, one landed transaction. Every command real, one take.

What Gecko is

Gecko reads an API (its spec, its docs, or for a Solana program its IDL and source) and turns it into tools your agent calls correctly the first time, every fact tagged with where it came from. For anything that costs money, it runs the call somewhere that doesn’t count first and hands back a receipt with a binding to the exact bytes. Then someone else signs.
Gecko is not the agent. It holds no key and signs nothing. The only thing it sends to a chain is signed bytes that verify against a binding it issued.

Your first call

No install, no account, no key, no spend. The flagship surface covers Solana storefronts, Orca Whirlpool swaps, find_start and program graphs:
Every other client’s wiring is in mcp-config.json, and the executable runbook is agents.md. Or let a skill do it:
For a keyless HTTP API, same shape:
Ask, in plain words:
Live answer, real production API. Your agent picked the right tool out of 28 and filled the parameter, first try.
Another client? Put the same URL in your mcp.json under mcpServers. If it only speaks SSE, use /pegana/sse: same tools, older transport.
The host serves ten surfaces. They are listed at /.well-known/gecko.json and described at catalog.md. The host root, /mcp, serves two tools: comprehend_api (point it at your own API) and list_surfaces.

”I already have an OpenAPI spec and an MCP server”

Good. Keep both. Gecko reads the spec and speaks MCP. A specification tells you what a call looks like. It cannot tell you whether it will work. That is structural, and just as true of a perfect spec as a bad one. And one thing an MCP server does: it leaves your key in mcp.json or .env, inside the agent’s context. Gecko keeps it in your OS keychain and injects it at call time. The model never sees it.

The model underneath

1

Comprehend

Read the surface. Tag every fact extracted, recovered, or flagged as genuinely unknown. Never invented. Below the retrieval floor it says “no start found” instead of guessing.
2

Plan

Turn an intent into one specific call, including the accounts the surface does not carry. Solana programs derive addresses from seeds; those recipes are often missing from the IDL, and a guess gives you a valid-looking address for the wrong thing.
3

Simulate

Run it against real chain state. $0, unsigned, nothing broadcast.
4

Receipt

Does it land, what does it cost, and if not, which class of failure. Plus a binding over the exact bytes. See The Receipt.
5

Someone else signs

Gecko hands back the plan, the receipt and the unsigned bytes. A wallet signs. verify_signed_transaction proves the signed bytes are the checked ones, and submit_transaction relays them only after that check passes. Different jobs, and we do exactly ours.

The proof

The engine repo’s ledger (docs/mainnet-ledger.jsonl) holds 50 landed mainnet transactions as of 2026-09-01. Every row that records both a prediction and a charge matches to the compute unit. The latest three were prepared by the hosted MCP and signed headless by a hosted signer against an exact binding. They are public and linked on A real transaction. Open any of them.

What is not built yet

  • A receipt is true for the state it was taken against, and the binding dies with its blockhash (about 60 seconds). Prepare when you sign. Re-running is free.
  • Nothing re-checks on a schedule. Drift is detected across runs you make.
  • Seven program configs ship (Pump.fun, Meteora, Jupiter, ORE, MetaDAO, Orca Whirlpool, let_me_buy). The catalog lists thousands. Different numbers.
  • Receipts are hosted on one surface. The orquestra surface simulates against a public mainnet RPC and returns a receipt with a binding. The other hosted surfaces give tools, not receipts. A fork is your own node.
  • Gecko does not check whether an answer is true, only that the call is right, and on-chain, that the transaction lands.

One next step

Evaluating: see it decide

The whole candidate field, not just the winner, including the accounts it flags instead of guessing.

Building: point it at your API

No OpenAPI? Give it the docs URL. Then Quickstart.
prove routes and shows provenance with no setup. A receipt additionally needs an RPC: pass --rpc-url, or see The Receipt.