VeilQuota

io.github.omkardongrev0.1.0Updated Oct 10, 2026

Private OCR, web search, and attested AI chat, paid with anonymous credits bought with shielded ZEC

Overview

AI-generated overview

Lets an assistant run paid private OCR, web search, and attested encrypted chat using prepaid anonymous credits from a local sealed wallet.

What it does
Provides tools for OCR of local PNG/JPG images, Brave web search excerpts for grounding, and end-to-end encrypted chat to an attested enclave. Each call is paid with prepaid anonymous credits (Privacy Pass Blind RSA tokens) bought with shielded Zcash. A wallet_balance tool reports credits and spending policy, and quote_ocr gives a price before any spend. No account or API key is used.
When to use it
Use when an assistant needs OCR, web search, or chat calls that should not be tied to an account or API key, and when paying per call with anonymous prepaid credits is acceptable. It suits privacy-focused workflows where the gateway should not link calls to one payer.
Requirements
Runs as a local process via npx @veilquota/mcp on Linux x64 (glibc) or macOS arm64; other platforms need veilquota-checkout built from source and on PATH. Requires a wallet created with setup, a passphrase typed at the native wallet terminal prompt, and credits bought with shielded ZEC or a try-link. VEILQUOTA_HOME sets the wallet directory (default ~/.veilquota).
Before you install
Unaudited capped mainnet beta; IP address and timing are not hidden. Spending real ZEC on credits is involved, though the wallet agent enforces per-request, session, and daily caps, a tool allowlist, and a pause switch, and spends above the approval threshold require the user's answer via MCP elicitation. Passphrases are typed only at the native wallet prompt, not in argv or configuration.

Installation

In SourceWeft

  1. Open VeilQuota in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.

Other MCP clients

Follow the launch instructions in the repository.

README

@veilquota/mcp

MCP server (TypeScript SDK v2, stdio, protocol 2026-07-28) for private paid tools: OCR, web search, and attested, end-to-end encrypted AI chat. Each call is paid with anonymous prepaid credits (Privacy Pass Blind RSA tokens) bought with shielded Zcash. There is no account and no API key, and the gateway cannot link two calls to one payer.

Unaudited, capped mainnet beta. IP address and timing are not hidden.

Quickstart

bash
npx -y @veilquota/mcp setup      # create a wallet; paste a try-link or credit packnpx -y @veilquota/mcp agent      # unlock it (keep this terminal open)claude mcp add veilquota -- npx -y @veilquota/mcp

Credits: buy 100 for 0.0005 ZEC at the hosted wallet with Zodl, or use a try-link someone gave you. The wallet lives in ~/.veilquota (0700), sealed with your passphrase; set VEILQUOTA_HOME to move it. Prebuilt binaries ship for Linux x64 (glibc) and macOS arm64. On other platforms, install veilquota-checkout from source and it is found on PATH.

Tools

ToolSpendsWhat it does
wallet_balancenoCredits available, plus the spending policy and what remains of it
quote_ocrnoPrice for one image, checked against the policy before any spend
run_ocr13 creditsOCR one local .png/.jpg
private_search2 creditsBrave web search excerpts for grounding
private_chat4 creditsOne chat call to an attested Tinfoil enclave, encrypted end to end

What an agent structurally cannot do

These limits come from where keys and rules live, not from instructions to the model:

  • It cannot touch money. No Zcash key, wallet passphrase, or credit token is in this process or in model context. It can spend only credits already in the wallet. Buying more needs a person paying a ZEC invoice.
  • It cannot pay anyone else. The wallet agent pins one gateway origin at startup. No tool argument names a payee or a price.
  • It cannot exceed the caps. The wallet agent, not this server, enforces a per-request ceiling, a session cap, and a daily cap. It also enforces a tool allowlist and a pause switch. The rules live in a policy file beside the wallet and are re-read before every spend.
  • It cannot approve its own spend. A spend above the approval threshold is put to the user as an MCP elicitation. Only the user's answer sets approved; no tool argument can. If the host cannot show the prompt, the spend is refused and nothing is charged.
  • It cannot be charged twice. A lost response is retried with the same arguments; the retry returns the original result.

Spending policy

bash
veilquota-mcp policy showveilquota-mcp policy pause            # stops new spends at onceveilquota-mcp policy resumeveilquota-mcp policy set daily_cap 100veilquota-mcp policy set session_cap 50veilquota-mcp policy set approval_above 4veilquota-mcp policy set tools search,chat

The defaults are: all tools allowed, session cap 50, daily cap 100, and approval for anything above 4 credits, so OCR asks first. An exact retry of a spend whose credits are already locked is never blocked, even while paused, so credits are never stranded. A refunded spend gives its credits back to the caps. Daily totals are kept on this machine in WALLET.spend-day.json, and nothing about them reaches a gateway.

Commands

bash
veilquota-mcp                 # MCP server on stdio (what `claude mcp add` runs)veilquota-mcp setup           # create a wallet, then import a try-link or credit packveilquota-mcp agent [PORT]    # unlock the wallet; with PORT, also http://127.0.0.1:PORT/v1 for OpenAI clientsveilquota-mcp policy show     # spending guardrails (pause, resume, set KEY VALUE)

Passphrases are typed only at the native wallet binary's terminal prompt, and packs are read from a hidden prompt. Neither appears in argv, shell history, or MCP configuration.

Source: packages/mcp-ocr/README.md at commit aa6fbb5

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v0.1.0LatestOct 10, 2026