# LayerCall Muse connector

From musedirectory.ai, the independent directory of Meta Muse connectors. Not affiliated with Meta.

## LayerCall

Score IP addresses, emails, phones and devices for fraud risk with detailed signals.

- Record: https://musedirectory.ai/connector/layercall
- Category: Finance & Bills
- Developer: LayerCall (https://www.layercall.com/docs/mcp)
- Muse status: Extra setup. Not in Muse's Connectors list yet. Muse can still use it: its page gives you a request to paste into Muse.
- Health: Working, 1104ms, checked 2026-09-28T08:16:02Z
- Endpoint: https://www.layercall.com/api/mcp
- Auth: Needs an access key; Pricing: unknown
- Screening: Screened, no issues found (2026-09-24T15:45:56Z)
- Source: Found in the official MCP Registry (com.layercall/trust-api) https://registry.modelcontextprotocol.io/v0/servers?search=com.layercall%2Ftrust-api

Detects fraudulent signups and transactions by analyzing IP geolocation and VPN use, email validity and age, phone number validation, domain reputation, browser fingerprints and device history. Returns risk scores and allow/review/block verdicts to help Muse protect accounts and payments.

Example request: "Check if this email and IP look suspicious before I complete a purchase."

How to connect: Not in Muse's Connectors list yet, but Muse can still use it. Paste this into Muse: "Use LayerCall to help me. It is a free service with an MCP server at https://www.layercall.com/api/mcp. It needs an API key from LayerCall; ask me to enter it through your secure credential prompt. Ask me before you share anything with it." Muse asks before it shares anything with the app's site. Meta does not review apps used this way, so only use ones you trust. We tested this in the Muse app on September 24, 2026: Muse used an app's link directly this way and returned a live answer.

Tools:
- score_ip: Risk-score an IPv4 or IPv6 address. Detects commercial VPNs (naming the provider where its own published list confirms it), proxies, Tor exit nodes and datacenter hosting, and returns geolocation, ASN and a 0-100 risk score with an allow/review/block verdict.
- verify_email: Check an email for syntax, MX records, disposable/throwaway providers, role accounts (info@, admin@), homograph lookalikes and domain age. Returns a 0-100 risk score and an allow/review/block verdict.
- lookup_phone: Validate a phone number worldwide against its national numbering plan. Returns E.164, country, line type (mobile/fixed/VoIP/toll-free/premium) and a risk score. Works globally, not US-only.
- score_domain: Profile a domain: registration date from RDAP, registrar, MX/SPF/DMARC configuration, disposable-mail and risky-TLD detection. newly_registered is null when the age genuinely could not be determined — treat that as unknown, not as 'established'.
- score_device: Judge a browser fingerprint from /fp.js: headless detection, automation frameworks (Selenium, Puppeteer, Playwright), timezone-versus-IP mismatch and repeat-device history. Note the ceiling honestly — the declared signals it relies on are the first thing stealth tooling patches, 
- verify_agent: Cryptographically verify a Web Bot Auth signature (RFC 9421) — proof of WHICH agent is calling, not a guess from the user-agent. Returns verified true/false plus the agent's identity and declared purpose. This is the only check here that proves rather than infers, so it carries n
- score_user: Score an entire signup in one call — any combination of IP, email, phone and domain — returning a single weighted risk score, a verdict, and the top contributing signals. A hard block on any component is never averaged away. This is the tool to use when judging a person rather th

Screening checks:
- MCP handshake: pass (Answered in 987ms)
- Domain against threat feeds (Cloudflare security DNS): pass (www.layercall.com not flagged)
- Published packages against the OSV malicious-package database: n/a (No npm or PyPI package published)
- Hidden instructions or invisible characters in tool text: pass (7 tools read, nothing found)
- Inputs asking for passwords, card numbers or seed phrases: pass (None found)
- Domain and redirects: pass (Domain registered 63 days ago)
- AI review of purpose and tool behavior: pass (No concerns)
