惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

SecWiki News
SecWiki News
阮一峰的网络日志
阮一峰的网络日志
WordPress大学
WordPress大学
Stack Overflow Blog
Stack Overflow Blog
Google DeepMind News
Google DeepMind News
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
T
Tailwind CSS Blog
www.infosecurity-magazine.com
www.infosecurity-magazine.com
The Last Watchdog
The Last Watchdog
S
Securelist
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
T
Tor Project blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
H
Help Net Security
Attack and Defense Labs
Attack and Defense Labs
O
OpenAI News
博客园 - 聂微东
Y
Y Combinator Blog
N
News | PayPal Newsroom
IT之家
IT之家
C
Cybersecurity and Infrastructure Security Agency CISA
Engineering at Meta
Engineering at Meta
L
LangChain Blog
L
Lohrmann on Cybersecurity
Recent Commits to openclaw:main
Recent Commits to openclaw:main
有赞技术团队
有赞技术团队
Hugging Face - Blog
Hugging Face - Blog
C
CERT Recently Published Vulnerability Notes
爱范儿
爱范儿
P
Palo Alto Networks Blog
T
Threat Research - Cisco Blogs
N
News and Events Feed by Topic
G
Google Developers Blog
PCI Perspectives
PCI Perspectives
The Register - Security
The Register - Security
H
Heimdal Security Blog
V
Visual Studio Blog
F
Fortinet All Blogs
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Jina AI
Jina AI
TaoSecurity Blog
TaoSecurity Blog
博客园 - Franky
T
The Blog of Author Tim Ferriss
AI
AI
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
博客园 - 叶小钗
The Hacker News
The Hacker News
U
Unit 42
Security Latest
Security Latest
The GitHub Blog
The GitHub Blog

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
Collection is not Callability: PubFi 为什么要为 AI Agent 建立可信的 Crypto Data Gateway
Gotomoon · 2026-06-23 · via DEV Community

不是每个 API 都应该被 Agent 调用

Collection is not Callability: PubFi 为什么要为 AI Agent 建立可信的 crypto data gateway

PubFi: https://pubfi.ai/

AI Agent 真正接入外部世界以后,一个问题会变得越来越重要:当 agent 需要一条链上数据时,它到底应该调用谁?

比如它想查一个钱包余额、一个 token price、一组 governance proposals,或者某条链上的交易活动。表面看,这只是找一个 API。实际上一点也不简单。

Crypto data 的问题不是没有数据源,而是数据源太多了。Subscan、DeFiLlama、CoinGecko、Alchemy、QuickNode、Dune、Covalent、Bitquery、The Graph 这些名字对开发者并不陌生。问题在于,每个 provider 都有自己的文档、鉴权方式、价格、限额、返回结构、覆盖范围和数据新鲜度。

人类开发者可以慢慢读文档、申请 key、试接口、看返回、做 fallback。但 agent 不应该每次都重新完成这套判断。

PubFi 的切入点就在这里。它不是再做一个 API 大全,也不是给每个 provider 包一层看起来很酷的 tool。PubFi 真正关心的是:一个数据源从“被发现”到“可被 agent 安全调用”,中间到底缺了哪些证据。

一句话概括:Collection is not Callability。收集到,不等于可调用。

API 目录解决不了 Agent 的运行时问题

传统 API directory 关心的是“有没有”。有没有文档、有没有 endpoint、有没有 pricing page、有没有 SDK、有没有 status page。

这些当然有价值。但对 agent 来说,还不够。

Agent 的问题不是“世界上是否存在某个 API”。它的问题是:

  • 这个 API 现在能不能被我调用?
  • 调用它需要什么 key?
  • 当前用户是否有权限?
  • 是否会产生费用?
  • 返回的数据是否足够新?
  • 这个 provider 是否真的覆盖我要的 chain 和 data type?
  • 如果失败,系统如何解释?
  • 如果调用成功,谁来记录这次调用发生过?

一个 API 被发现,只说明它存在。一个文档被解析,只说明它有接口描述。一个 provider 进入 corpus,只说明它有公共信息价值。这些都不能自动推出“它现在可以被 agent 调用”。

从 collected candidate 到 callable route,中间还隔着 credential、policy、freshness、adapter certification、usage accounting 和 claim safety。

这就是 PubFi 和普通 API directory 的区别。普通目录把“存在”当成终点;PubFi 把“存在”当成起点。

PubFi 的三层结构

理解 PubFi,可以先把它拆成三层:Discovery、Gateway、Route Intelligence。

Discovery 是入口。

它面向人类、搜索引擎、answer engine 和 AI agent。这里有 source pages、category hubs、chain hubs、comparison pages,也有 llms.txt、agents.md、Markdown mirrors 和 OpenAPI exports。

但 Discovery 不只是 SEO。它更像需求传感器。当有人搜索 “MCP crypto data API”、“x402 crypto data API”、“Subscan vs SubSquid”、“Polkadot data API” 时,这些 query 不只是流量入口,也是在告诉 PubFi:市场正在问什么,哪些数据源需要被解释,哪些能力缺口值得进入下一步。

Gateway 是出口。

如果一个 route 真的可以调用,它应该通过 gateway 被调用。Gateway 负责 API key、credit、provider adapter、upstream credential injection、response normalization 和 usage facts。

这意味着 PubFi 不只是把请求转发给上游。它要知道谁在调用、有没有权限、消耗了什么、上游返回了什么状态、这次调用如何被记录。

Route Intelligence 是中间的判断层。

Agent 通常不会说“请调用 provider X 的 endpoint Y”。它更可能说:“给我 BTC spot price”“查一下这个钱包的 token balances”“我要某个治理提案的数据”。

Route Intelligence 要把这种自然语言需求变成结构化 intent,然后找候选、过滤、排名,最后决定:现在是否有可调用 route;是否需要更多信息;是否只能记录一个 demand signal;是否应该进入 procurement review;是否应该拒绝调用。

真正困难的是知道什么时候不该调用

很多 agent 产品会把“智能路由”讲成一个模型能力:把用户问题丢给 embedding、reranker 或 LLM,然后选一个最像的 API。

但真实系统里,语义相似远远不够。

一个 provider 的文档和用户需求很像,不代表它有可用 credential。一个 endpoint 名字看起来正确,不代表它覆盖目标 network。一个 route 在 corpus 里出现,不代表它已经通过 adapter certification。一个 API 支持付费调用,不代表系统可以自动采购或支付。一个页面写了 MCP 或 x402,不代表今天就有 live MCP tool 或 live x402 payment execution。

所以 PubFi 的 route intelligence 不是让模型自由发挥。它的顺序应该是:

  • 先规范化需求;
  • 再找候选;
  • 先跑 hard filters;
  • 再做 ranking;
  • 模型分数只能作为透明输入;
  • 证据不足时必须 abstain。

这是一种很基础但很重要的工程伦理:不能因为 agent 想要答案,系统就假装自己有能力。

在 agent infrastructure 里,错误的 available 比普通网页上的夸张文案危险得多。因为 agent 可能真的会拿它去调用、花钱、生成判断,甚至触发下一个自动流程。

Growth Loop:把“不能调用”变成下一步

如果一个 route 现在不能调用,PubFi 不应该只是失败。它可以把失败变成产品信号。

这就是 Gateway Growth Loop 的意义:外部 API discovery、docs parsing、API corpus、integration candidate queue、adapter certification、keyword growth、SEO/GEO recommendations、issue outbox。

一个 API 被发现,先只是 collected candidate。文档解析成功,变成 endpoint facts。进入 corpus,成为 public-safe profile evidence。进入 candidate queue,才可能被评估是否值得做 adapter。通过 certification,才有机会 runtime enabled。最后,在 credential、auth、usage、claim safety 都成立时,才可能被称为 gateway available。

这条路径很克制。它没有把“收集”包装成“能力”,也没有把“研究原型”包装成“生产可用”。

PubFi 文档里反复出现类似的边界:

  • corpus inclusion 不是 gateway availability;
  • crawler hit 不是 AI citation;
  • llms.txt 不是 agent callability;
  • x402 sandbox proof 不是 live payment execution;
  • source page 存在,不代表 PubFi 可以调用这个 source;
  • candidate queue 里的 provider,不代表已经被采购或授权。

这些句子看起来像限制,实际上是产品可信度的来源。

为什么这件事在 AI Agent 时代重要

Model Context Protocol 这类标准正在让 AI 应用更容易连接外部数据、工具和工作流。官方介绍见:https://modelcontextprotocol.io/docs/getting-started/intro

x402 这类协议则把 machine-to-machine payment 和 HTTP 402 重新带回讨论中心。官方网站见:https://www.x402.org/

这些趋势会让 agent 更容易调用外部系统,也会放大一个老问题:谁来判断一次调用是否真的安全、授权、可计量、可解释?

在传统应用里,API integration 通常由开发者完成。开发者会判断接口是否靠谱,key 是否有效,价格是否合理,失败是否可恢复。

但 agent-native 应用会把这些判断往运行时推。Agent 可能临时决定需要某类数据;可能要在多个 provider 之间选择;可能要根据成本、延迟、新鲜度、权限做权衡;也可能在证据不足时选择不调用。

这时,一个普通 API directory 就不够了。Agent 需要的是一个能表达“可发现、可解释、可调用、可拒绝、可审计”的数据层。

PubFi 要卖的不是“更多 API”

如果只看表层,PubFi 像是 crypto data gateway。但更准确地说,它在做的是 agent 时代的数据可信层。

这个可信层包括几件事:

  • 让 agent 能发现数据源;
  • 让 agent 能理解哪些数据源适合什么问题;
  • 让真正可用的 route 通过统一 gateway 调用;
  • 让每次调用留下 usage facts;
  • 让不可调用的需求进入 demand 或 procurement 流程;
  • 让 public claim 不超过真实能力。

这比“我们支持 100 个 provider”更难,也更有价值。

因为 AI Agent 时代的信息获取会变得越来越便宜。真正稀缺的是判断:什么可以信,什么可以调,什么应该停下来。

PubFi 的产品气质就在这里。它不是急着告诉你所有东西都能用,而是认真区分 found、documented、requestable、contract ready、gateway available、not supported。每个状态都有价值,但不能互相冒充。

相关链接

Collection is not Callability

“Collection is not Callability” 不是一句漂亮口号。它是一条系统设计原则。

它要求 PubFi 在每个环节都回答一个问题:我们现在到底知道什么?这些证据足不足以支持一次 agent 调用?如果不够,系统应该如何诚实地表达“不够”?

这也许不是最热闹的 AI 叙事,但它是 agent 真正进入生产环境前必须补上的一环。

收集信息会越来越容易。生成接口包装会越来越容易。让模型猜一个 provider 也会越来越容易。

困难的是,在一个自动化系统里,仍然坚持:没有证据,就不要调用。不能调用,也要留下信号。能调用,就必须可解释、可审计、可追踪。

这就是 PubFi 想做的事:不是给 AI Agent 更多入口,而是给它更可靠的出口。