Agent Pay Mcp

com.deepfirstsearchv0.1.2Updated Oct 7, 2026

x402 payments in USDC on Base inside an owner-signed, on-chain budget the model can't change

VerifiedSTDIODesktop onlyDeveloper ToolsFinance

Overview

AI-generated overview

Lets an MCP agent pay x402 APIs in USDC on Base inside an owner-signed on-chain budget it cannot change.

What it does
Exposes three tools: paid_fetch fetches a URL and, on a 402 Payment Required response, pays only if the merchant, price and budget match the owner's config; list_merchants shows payable origins, prices and remaining amounts; budget_status reports remaining budget per merchant, window renewal and vault balance (R6, R7, R8, R9). The model cannot choose payee, amount, network or limit because no such arguments exist (R10). Merchants, price pins, caps and the spending plan come from the config file, keys from environment variables (R11). Responses are wrapped in a randomly tagged fence marked untrusted (R12).
When to use it
Worth adding when an agent needs to call paid x402 APIs on Base and spending must stay bounded by an owner-signed budget, even if a page or API response tries to prompt-inject the model (R2). Suited to testing on Base Sepolia or small mainnet amounts (R3). Not for agents that need to choose arbitrary payees or amounts, since no such arguments exist (R10).
Requirements
Local stdio process, desktop only, run via npx @deepfirstsearch/agent-pay-mcp with an absolute path to a config.json (R24, R28). Node.js and npm are needed; from source, npm ci and npm run build (R29). Secrets come from environment variables only: AGENT_PAY_AGENT_KEY (needed with a vault) and AGENT_PAY_BURNER_SEED (required) (R20, R21, R22). A vault and signed per-merchant budget are created once with the owner CLI, or payer addresses are funded manually (R14, R15, R16). Network access to the x4
Before you install
Beta and unaudited; use Base Sepolia or small amounts on Base mainnet (R3). It spends real USDC from payer addresses derived from AGENT_PAY_BURNER_SEED, which must never be the owner key (R22, R23). Two secrets are required: AGENT_PAY_AGENT_KEY and AGENT_PAY_BURNER_SEED (R21, R22). Payments are refused above approvalAbove and when sessionHasSensitiveData is set (R43, R44). Every decision is written to a hash-chained audit log (R45).

Installation

In SourceWeft

  1. Open Agent Pay Mcp in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

@deepfirstsearch/agent-pay-mcp

An MCP server that lets any MCP agent (Claude Desktop, Claude Code, Cursor, …) pay x402 APIs in USDC on Base without being able to overspend, even if a web page or API response prompt-injects it.

Beta, unaudited. Use Base Sepolia or small amounts on Base mainnet.

The model gets three tools and nothing else:

ToolWhat the model can do
paid_fetch(url, method?, body?, contentType?)Fetch a URL. If it answers 402 Payment Required, the payment goes through only if the merchant, price and budget match your config
list_merchants()See which origins it may pay, their prices and what's left
budget_status()Remaining budget per merchant, window renewal, vault balance

The model cannot choose a payee, an amount, a network or a limit: there is no argument for any of them. Merchants, price pins, caps and the spending plan come from your config file; keys come from environment variables. Responses are returned inside a randomly tagged fence marked as untrusted data. On-chain, the Agent Safe vault enforces your signed per-payment and per-day caps even if this machine is compromised.

Setup

  1. Budget (owner, once): create a vault and sign a budget per merchant with the owner CLI: npx @deepfirstsearch/agent-pay owner create-vault, then owner budget …, which prints the intentId and a ready-to-paste merchants[] entry. (No vault? Leave out vault, tranche and intentId and fund the payer addresses yourself.)
  2. Config: copy config.example.json and fill it in. Amounts are USDC decimal strings. Keep tranche at or below each intent's trancheCap and maxPerTx.
  3. Secrets (environment only):
    • AGENT_PAY_AGENT_KEY: the intent's agent key (needed with a vault).
    • AGENT_PAY_BURNER_SEED: the 32-byte secret the payer addresses were derived from. Never your owner key.

Claude Code

bash
claude mcp add agent-pay \  -e AGENT_PAY_AGENT_KEY=0x… -e AGENT_PAY_BURNER_SEED=0x… \  -- npx -y @deepfirstsearch/agent-pay-mcp /absolute/path/config.json

OpenClaw

bash
npm install -g @deepfirstsearch/agent-pay-mcpopenclaw mcp set agent-pay '{"command":"agent-pay-mcp","args":["/absolute/path/config.json"],"env":{"AGENT_PAY_AGENT_KEY":"${AGENT_PAY_AGENT_KEY}","AGENT_PAY_BURNER_SEED":"${AGENT_PAY_BURNER_SEED}"}}'openclaw mcp probe agent-pay   # - agent-pay: 3 tools

Full walkthrough: OpenClaw guide.

Claude Desktop / Cursor

claude_desktop_config.json (Claude Desktop) or .cursor/mcp.json (Cursor):

json
{  "mcpServers": {    "agent-pay": {      "command": "npx",      "args": ["-y", "@deepfirstsearch/agent-pay-mcp", "/absolute/path/config.json"],      "env": { "AGENT_PAY_AGENT_KEY": "0x…", "AGENT_PAY_BURNER_SEED": "0x…" }    }  }}

From source instead of npm: cd integrations/mcp && npm ci && npm run build, then use node /path/to/integrations/mcp/dist/index.js as the command.

See it work in 5 minutes (Base Sepolia)

sdk/examples/demo-merchant.ts is a tiny x402 API on Base Sepolia with an honest route (/premium, 0.01 USDC) and a hostile one (/malicious: its 402 asks for 5 USDC to an attacker address and its body carries a prompt injection).

bash
cd sdk && MERCHANT=0xYourMerchantAddress npx tsx examples/demo-merchant.ts

Point the config's merchant at http://127.0.0.1:4021 with that payTo, then ask your agent to fetch /premium and /malicious. Expected: the first is paid and settled on-chain; the second is refused before anything is signed ("payTo … is not the merchant's registered address").

Config reference

FieldMeaning
networkeip155:84532 (Base Sepolia) or eip155:8453 (Base)
vault, trancheAgent Safe vault that tops up each merchant's payer, and the top-up size
merchants[].origin, payToWho may be paid, and the only address the payment can go to
merchants[].price, tolerancePctExpected price per call; anything above price × (1 + tolerance) is refused
merchants[].maxPerTx, maxSpendHard cap per call, and per merchant per plan window
planWindowHoursThe plan is sealed from this file at start and renewed from it every window
periodBudgetTotal across merchants per period
approvalAbovePayments above this are refused (this server has no approval channel the model can't reach)
sessionHasSensitiveDataIf the agent can also read private data, every payment needs a human (Rule of Two), so all are refused
auditLogHash-chained JSONL log of every decision

Develop

bash
npm ci && npm run typecheck && npm test   # tests drive the server through an MCP client against a mock x402 merchant

Source: integrations/mcp/README.md at commit 9aee897

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.1.2LatestOct 7, 2026