presign-guard wallet

io.github.Fizzl13v0.3.0Updated Oct 2, 2026

A wallet with spending limits for agents: pay x402 APIs, send USDC, phone approval over the limit.

VerifiedSTDIODesktop onlySecurity & MonitoringFinance

Overview

AI-generated overview

Gives an AI agent a spending-limited crypto wallet to pay x402 APIs and send USDC, with Telegram approval above set limits.

What it does
Runs a local wallet for an agent with tools to check status, pay x402 APIs that answer 402 Payment Required, send USDC, send native coins, and pause spending. Every signature is first checked by presign-guard for known drainers, sanctioned addresses and look-alike tokens; a red verdict is never signed. Payments above your per-transaction or daily limits require your approval over Telegram or a wallet server dashboard, and if the check, Telegram or the server cannot be reached, nothing is signed.
When to use it
Use it when an agent needs to pay for x402 APIs or send USDC on its own but you want hard budget caps and a human approval step above them. It fits agent workflows that spend small amounts on Base or another supported chain.
Requirements
Local process started via npx (Node.js). Requires AGENT_KEY, the private key of a separate agent wallet, plus limits or a wallet server. Optional: CHAIN, LIMIT_USDC_PER_DAY, LIMIT_USDC_PER_TX, MAX_PAYMENT_USD, RPC_URL, PRESIGN_CREDIT_KEY, and TELEGRAM_BOT_TOKEN with TELEGRAM_CHAT_ID for approvals, or WALLET_SERVER_URL with WALLET_SERVER_KEY. Network access needed.
Before you install
AGENT_KEY, WALLET_SERVER_KEY, PRESIGN_CREDIT_KEY and TELEGRAM_BOT_TOKEN are secrets; the private key stays on your machine. The wallet can move real funds: send_usdc and send_native transfer crypto, and pay_x402 spends USDC, so use a separate wallet holding only what the agent may spend, never your main wallet. Each presign-guard check costs $0.01 in USDC. Without Telegram or a wallet server, anything over a limit is refused.

Installation

In SourceWeft

  1. Open presign-guard wallet in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

presign-guard-wallet-mcp

A wallet with spending limits for AI agents, as an MCP server. Add it to Claude Desktop, Claude Code, Cursor or any other MCP client, and your agent can:

  • pay for x402 APIs;
  • send USDC.

It can only do that within the budget you set:

  • You set the limits. For example: up to 5 USDC per payment and 20 USDC a day, and the agent is free to spend within them.
  • Above a limit, you decide. You get a Telegram message with Approve / Deny, or the request shows up on your wallet server dashboard. No answer means no payment.
  • Every signature is checked first by presign-guard. It checks for known drainers, sanctioned addresses and look-alike tokens. A red verdict is never signed.
  • When in doubt, nothing is signed. If the check, Telegram or the server can't be reached, the wallet stops.

The key stays on your machine; the server only decides whether a signature is allowed. Each check costs $0.01, paid in USDC on Base from the same wallet, or from prepaid credits.

See the dashboard (demo data): https://wallet.fizzl.eu/demo

Tools

ToolWhat it does
wallet_statusAddress, balances, limits, what is left today, how approvals work
pay_x402Call an API that answers 402 Payment Required, pay it in USDC, return the response (with a price cap per call)
send_usdcSend USDC to an address
send_nativeSend ETH / POL / BNB to an address
pause_spendingThe agent stops itself when something looks wrong; nothing is signed until you restart or resume

Set up

  1. Make a separate wallet for the agent. Put only what it may spend in it: a few dollars of USDC on Base, plus a little ETH for gas if it will send transfers. Never use your main wallet.
  2. Optional: phone approvals.
  3. Add it to your MCP client. For Claude Desktop, put this in claude_desktop_config.json:
json
{  "mcpServers": {    "wallet": {      "command": "npx",      "args": ["-y", "presign-guard-wallet-mcp"],      "env": {        "AGENT_KEY": "0x…the agent wallet's private key…",        "LIMIT_USDC_PER_TX": "5",        "LIMIT_USDC_PER_DAY": "20",        "TELEGRAM_BOT_TOKEN": "123456:ABC…",        "TELEGRAM_CHAT_ID": "123456789"      }    }  }}

For Claude Code:

sh
claude mcp add wallet -e AGENT_KEY=0x… -e LIMIT_USDC_PER_TX=5 -e LIMIT_USDC_PER_DAY=20 -- npx -y presign-guard-wallet-mcp

Then ask your agent, for example: "Check my wallet, then get the BTC signal from https://ichimoku-signal.fizzl.eu/signal/BTC-USDT".

One budget for all your agents

Run the wallet server and make an agent key on its dashboard. It gives you:

  • one price rule and one daily budget for all your agents;
  • approvals on the dashboard and on Telegram;
  • an activity log.

Then use these variables instead of LIMIT_* and TELEGRAM_*:

json
"env": {  "AGENT_KEY": "0x…",  "WALLET_SERVER_URL": "https://your-wallet-server.example",  "WALLET_SERVER_KEY": "awk_…"}

Configuration

Variable
AGENT_KEYrequired: private key of the agent's own wallet
LIMIT_USDC_PER_TX, LIMIT_USDC_PER_DAYUSDC limits (payments and transfers together). Limits or a wallet server are required
LIMIT_NATIVE_PER_TX, LIMIT_NATIVE_PER_DAYlimits for the native coin; without them, sending it needs approval
TELEGRAM_BOT_TOKEN, TELEGRAM_CHAT_IDapprovals on Telegram; without them, anything over a limit is refused
WALLET_SERVER_URL, WALLET_SERVER_KEYa wallet server instead of the above
CHAINbase (default), ethereum, optimism, arbitrum, polygon or bsc
MAX_PAYMENT_USDmost one pay_x402 call may cost (default 1); a cap on top of the limits
PRESIGN_CREDIT_KEYpay the $0.01 checks from prepaid credits (pgc_…)
RPC_URLyour own RPC for the chain
AGENT_LABELthe name shown in Telegram approval messages (default mcp-agent)

One Telegram bot serves one running server at a time, and the bot must not have a webhook. To run several agents on one bot, use the wallet server.

Receipts

Every payment carries what it was for: the URL for pay_x402, and the agent's reason if it gives one. With a wallet server, that shows on the receipt for each payment, together with:

  • the amount and recipient;
  • presign-guard's signed verdict;
  • the approval;
  • the x402 settlement;
  • what the agent got back: the API's answer (up to 16,000 characters), shown in plain form on the receipt.

Telegram approval requests say what the payment is for too. See a receipt in the demo: click a purchase under "Purchases".

When something is refused

The tool returns an error the agent can read and pass on to you. Examples:

  • Not done (over_limit): 8 USDC is over the limit of 5 per transaction (denied by the owner);
  • Not done (red): not signed: red (known_drainer).

Also available

License

MIT

Source: wallet-mcp/README.md at commit 1c7a8ea

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.3.0LatestOct 2, 2026