
Agent Pay Mcp
com.deepfirstsearchv0.1.2Updated Oct 7, 2026
x402 payments in USDC on Base inside an owner-signed, on-chain budget the model can't change
Overview
Lets an MCP agent pay x402 APIs in USDC on Base inside an owner-signed on-chain budget it cannot change.
- What it does
- Exposes three tools: paid_fetch fetches a URL and, on a 402 Payment Required response, pays only if the merchant, price and budget match the owner's config; list_merchants shows payable origins, prices and remaining amounts; budget_status reports remaining budget per merchant, window renewal and vault balance (R6, R7, R8, R9). The model cannot choose payee, amount, network or limit because no such arguments exist (R10). Merchants, price pins, caps and the spending plan come from the config file, keys from environment variables (R11). Responses are wrapped in a randomly tagged fence marked untrusted (R12).
- When to use it
- Worth adding when an agent needs to call paid x402 APIs on Base and spending must stay bounded by an owner-signed budget, even if a page or API response tries to prompt-inject the model (R2). Suited to testing on Base Sepolia or small mainnet amounts (R3). Not for agents that need to choose arbitrary payees or amounts, since no such arguments exist (R10).
- Requirements
- Local stdio process, desktop only, run via npx @deepfirstsearch/agent-pay-mcp with an absolute path to a config.json (R24, R28). Node.js and npm are needed; from source, npm ci and npm run build (R29). Secrets come from environment variables only: AGENT_PAY_AGENT_KEY (needed with a vault) and AGENT_PAY_BURNER_SEED (required) (R20, R21, R22). A vault and signed per-merchant budget are created once with the owner CLI, or payer addresses are funded manually (R14, R15, R16). Network access to the x4
Installation
In SourceWeft
- Open Agent Pay Mcp in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
@deepfirstsearch/agent-pay-mcp
An MCP server that lets any MCP agent (Claude Desktop, Claude Code, Cursor, …) pay x402 APIs in USDC on Base without being able to overspend, even if a web page or API response prompt-injects it.
Beta, unaudited. Use Base Sepolia or small amounts on Base mainnet.
The model gets three tools and nothing else:
The model cannot choose a payee, an amount, a network or a limit: there is no argument for any of them. Merchants, price pins, caps and the spending plan come from your config file; keys come from environment variables. Responses are returned inside a randomly tagged fence marked as untrusted data. On-chain, the Agent Safe vault enforces your signed per-payment and per-day caps even if this machine is compromised.
Setup
- Budget (owner, once): create a vault and sign a budget per merchant with the owner CLI:
npx @deepfirstsearch/agent-pay owner create-vault, thenowner budget …, which prints theintentIdand a ready-to-pastemerchants[]entry. (No vault? Leave outvault,trancheandintentIdand fund the payer addresses yourself.) - Config: copy
config.example.jsonand fill it in. Amounts are USDC decimal strings. Keeptrancheat or below each intent'strancheCapandmaxPerTx. - Secrets (environment only):
AGENT_PAY_AGENT_KEY: the intent's agent key (needed with a vault).AGENT_PAY_BURNER_SEED: the 32-byte secret the payer addresses were derived from. Never your owner key.
Claude Code
OpenClaw
Full walkthrough: OpenClaw guide.
Claude Desktop / Cursor
claude_desktop_config.json (Claude Desktop) or .cursor/mcp.json (Cursor):
From source instead of npm: cd integrations/mcp && npm ci && npm run build, then use node /path/to/integrations/mcp/dist/index.js as the command.
See it work in 5 minutes (Base Sepolia)
sdk/examples/demo-merchant.ts is a tiny x402 API on Base Sepolia with an honest route (/premium, 0.01 USDC) and a hostile one (/malicious: its 402 asks for 5 USDC to an attacker address and its body carries a prompt injection).
Point the config's merchant at http://127.0.0.1:4021 with that payTo, then ask your agent to fetch /premium and /malicious. Expected: the first is paid and settled on-chain; the second is refused before anything is signed ("payTo … is not the merchant's registered address").
Config reference
Develop
Source: integrations/mcp/README.md at commit 9aee897
Tools
0Version history
1- v0.1.2LatestOct 7, 2026


