Agent Pay Mcp

com.deepfirstsearchv0.1.2更新于 Oct 7, 2026

x402 payments in USDC on Base inside an owner-signed, on-chain budget the model can't change

已验证STDIO仅桌面Developer ToolsFinance

概览

AI 生成的概览

让 MCP 智能体在所有者签名、自身无法更改的链上预算内,用 Base 上的 USDC 支付 x402 API。

功能
提供三个工具:paid_fetch 获取 URL,若返回 402 Payment Required,仅当商户、价格与预算符合所有者配置时才付款;list_merchants 显示可支付的来源、价格与剩余额度;budget_status 报告每个商户的剩余预算、窗口续期与 vault 余额(R6、R7、R8、R9)。模型无法选择收款方、金额、网络或限额,因为不存在这些参数(R10)。商户、价格锁定、上限与支出计划来自配置文件,密钥来自环境变量(R11)。响应会被包在随机标签的围栏中并标记为不可信数据(R12)。
适用场景
当智能体需要调用 Base 上付费的 x402 API,且支出必须受所有者签名预算约束时值得添加,即使网页或 API 响应试图对模型进行提示注入(R2)。适合在 Base Sepolia 或主网小额资金上测试(R3)。不适合需要自行选择任意收款方或金额的智能体,因为不存在这些参数(R10)。
运行要求
本地 stdio 进程,仅限桌面端,通过 npx @deepfirstsearch/agent-pay-mcp 并传入 config.json 的绝对路径运行(R24、R28)。需要 Node.js 与 npm;从源码运行时需 npm ci 与 npm run build(R29)。密钥仅通过环境变量提供:AGENT_PAY_AGENT_KEY(配置 vault 时需要)与 AGENT_PAY_BURNER_SEED(必需)(R20、R21、R22)。需先用所有者 CLI 创建 vault 并签署每个商户的预算,或自行向付款地址充值(R14、R15、R16)。需要网络访问以调用 x402 接口。
安装前请注意
处于 Beta 且未经审计;请使用 Base Sepolia 或 Base 主网上的小额资金(R3)。它会从由 AGENT_PAY_BURNER_SEED 派生的付款地址花费真实 USDC,该种子绝不能是所有者密钥(R22、R23)。需要两个密钥:AGENT_PAY_AGENT_KEY 与 AGENT_PAY_BURNER_SEED(R21、R22)。超过 approvalAbove 的付款会被拒绝,设置 sessionHasSensitiveData 时所有付款也会被拒绝(R43、R44)。每个决定都会写入哈希链审计日志(R45)。

安装

在 SourceWeft 中

  1. 打开 控制台中的 Agent Pay Mcp,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

@deepfirstsearch/agent-pay-mcp

An MCP server that lets any MCP agent (Claude Desktop, Claude Code, Cursor, …) pay x402 APIs in USDC on Base without being able to overspend, even if a web page or API response prompt-injects it.

Beta, unaudited. Use Base Sepolia or small amounts on Base mainnet.

The model gets three tools and nothing else:

ToolWhat the model can do
paid_fetch(url, method?, body?, contentType?)Fetch a URL. If it answers 402 Payment Required, the payment goes through only if the merchant, price and budget match your config
list_merchants()See which origins it may pay, their prices and what's left
budget_status()Remaining budget per merchant, window renewal, vault balance

The model cannot choose a payee, an amount, a network or a limit: there is no argument for any of them. Merchants, price pins, caps and the spending plan come from your config file; keys come from environment variables. Responses are returned inside a randomly tagged fence marked as untrusted data. On-chain, the Agent Safe vault enforces your signed per-payment and per-day caps even if this machine is compromised.

Setup

  1. Budget (owner, once): create a vault and sign a budget per merchant with the owner CLI: npx @deepfirstsearch/agent-pay owner create-vault, then owner budget …, which prints the intentId and a ready-to-paste merchants[] entry. (No vault? Leave out vault, tranche and intentId and fund the payer addresses yourself.)
  2. Config: copy config.example.json and fill it in. Amounts are USDC decimal strings. Keep tranche at or below each intent's trancheCap and maxPerTx.
  3. Secrets (environment only):
    • AGENT_PAY_AGENT_KEY: the intent's agent key (needed with a vault).
    • AGENT_PAY_BURNER_SEED: the 32-byte secret the payer addresses were derived from. Never your owner key.

Claude Code

bash
claude mcp add agent-pay \  -e AGENT_PAY_AGENT_KEY=0x… -e AGENT_PAY_BURNER_SEED=0x… \  -- npx -y @deepfirstsearch/agent-pay-mcp /absolute/path/config.json

OpenClaw

bash
npm install -g @deepfirstsearch/agent-pay-mcpopenclaw mcp set agent-pay '{"command":"agent-pay-mcp","args":["/absolute/path/config.json"],"env":{"AGENT_PAY_AGENT_KEY":"${AGENT_PAY_AGENT_KEY}","AGENT_PAY_BURNER_SEED":"${AGENT_PAY_BURNER_SEED}"}}'openclaw mcp probe agent-pay   # - agent-pay: 3 tools

Full walkthrough: OpenClaw guide.

Claude Desktop / Cursor

claude_desktop_config.json (Claude Desktop) or .cursor/mcp.json (Cursor):

json
{  "mcpServers": {    "agent-pay": {      "command": "npx",      "args": ["-y", "@deepfirstsearch/agent-pay-mcp", "/absolute/path/config.json"],      "env": { "AGENT_PAY_AGENT_KEY": "0x…", "AGENT_PAY_BURNER_SEED": "0x…" }    }  }}

From source instead of npm: cd integrations/mcp && npm ci && npm run build, then use node /path/to/integrations/mcp/dist/index.js as the command.

See it work in 5 minutes (Base Sepolia)

sdk/examples/demo-merchant.ts is a tiny x402 API on Base Sepolia with an honest route (/premium, 0.01 USDC) and a hostile one (/malicious: its 402 asks for 5 USDC to an attacker address and its body carries a prompt injection).

bash
cd sdk && MERCHANT=0xYourMerchantAddress npx tsx examples/demo-merchant.ts

Point the config's merchant at http://127.0.0.1:4021 with that payTo, then ask your agent to fetch /premium and /malicious. Expected: the first is paid and settled on-chain; the second is refused before anything is signed ("payTo … is not the merchant's registered address").

Config reference

FieldMeaning
networkeip155:84532 (Base Sepolia) or eip155:8453 (Base)
vault, trancheAgent Safe vault that tops up each merchant's payer, and the top-up size
merchants[].origin, payToWho may be paid, and the only address the payment can go to
merchants[].price, tolerancePctExpected price per call; anything above price × (1 + tolerance) is refused
merchants[].maxPerTx, maxSpendHard cap per call, and per merchant per plan window
planWindowHoursThe plan is sealed from this file at start and renewed from it every window
periodBudgetTotal across merchants per period
approvalAbovePayments above this are refused (this server has no approval channel the model can't reach)
sessionHasSensitiveDataIf the agent can also read private data, every payment needs a human (Rule of Two), so all are refused
auditLogHash-chained JSONL log of every decision

Develop

bash
npm ci && npm run typecheck && npm test   # tests drive the server through an MCP client against a mock x402 merchant

来源:integrations/mcp/README.md,提交 9aee897

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v0.1.2最新Oct 7, 2026