ProvenPaid

com.provenpaidv0.1.0更新于 Oct 9, 2026

Check an x402 endpoint before your agent pays it: challenge validity and on-chain payer evidence.

已验证STDIO仅桌面FinanceSecurity & Monitoring

概览

AI 生成的概览

让助手对 x402 端点执行付费的付款前检查,验证其支付挑战并报告链上付款方证据。

功能
提供 check_x402_endpoint 工具,用于验证端点的 x402 支付挑战,并报告其收款地址的公开链上证据,包括独立付款方数量、重复付款方占比、付款方集中度和覆盖率。另有两个免费工具 provenpaid_methodology 和 provenpaid_status,分别说明各信号的计算方式,以及显示付款钱包地址、网络、价格上限和当日剩余付费检查次数。检查本身通过 Base 上的 USDC 自动付费,每次约 0.01 美元。
适用场景
适合在助手依赖某个不熟悉的付费 x402 端点之前使用一次,查看其支付挑战是否有效,以及是否真有钱包在付款。它并非用于每次调用前执行,且结果只是证据,并不代表对服务质量的判定。
运行要求
本地进程,需要 Python 3.11+,可通过 uvx 或 pip 安装。需要机密项 PROVENPAID_WALLET_PRIVATE_KEY,对应一个仅持有少量 Base 上 USDC 的专用钱包,并需要访问 ProvenPaid API 的网络连接。可选设置包括 PROVENPAID_DAILY_LIMIT、PROVENPAID_MAX_PRICE_USD、PROVENPAID_NETWORK、PROVENPAID_API_URL 和 PROVENPAID_STATE_DIR。
安装前请注意
该服务器要求提供 PROVENPAID_WALLET_PRIVATE_KEY,即用于签署支付授权的私钥;README 建议使用仅存少量资金的专用钱包,切勿使用存有重要资金的钱包。检查会花费真实的 Base 上 USDC,每次约 0.01 美元,受 PROVENPAID_MAX_PRICE_USD 和 PROVENPAID_DAILY_LIMIT 限制。签署后的支付授权会离开本进程,端点 URL 也会发送给 ProvenPaid API。

安装

在 SourceWeft 中

  1. 打开 控制台中的 ProvenPaid,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

provenpaid-mcp

Give your agent a pre-payment check for paid x402 endpoints. Evidence before you pay.

ProvenPaid checks an x402 endpoint before your agent relies on it: is its payment challenge valid, and do real wallets actually pay it on-chain, come back, and how concentrated are payments? This MCP server exposes that check as a tool and pays for it automatically, about $0.01 in USDC on Base per check, from a wallet you control.

Use it once before relying on an unfamiliar endpoint, not before every call.

Tools

ToolCostWhat it does
check_x402_endpoint(url)about $0.01Validates the endpoint's x402 challenge and reports public on-chain evidence for its receiving address: distinct payers, repeat-payer share, payer concentration, coverage.
provenpaid_methodology()freeHow each signal is computed, what is not verified, and when a check is charged.
provenpaid_status()freePaying wallet address, network, price cap and paid checks left today.

You are not charged when the URL is invalid or unsafe, is not an x402 endpoint, or offers no payment option in USDC on Base. Results are evidence, not a verdict: ProvenPaid does not verify service quality or that an endpoint controls its receiving address.

Install

Requires Python 3.11+. With uv:

bash
uvx provenpaid-mcp

or pip install provenpaid-mcp.

Claude Desktop / Claude Code / Cursor

json
{  "mcpServers": {    "provenpaid": {      "command": "uvx",      "args": ["provenpaid-mcp"],      "env": {        "PROVENPAID_WALLET_PRIVATE_KEY": "0x...",        "PROVENPAID_DAILY_LIMIT": "20"      }    }  }}

Wallet safety

  • Use a dedicated wallet holding only a few dollars of USDC on Base. Never use a wallet with meaningful funds.
  • The key stays on your machine, in memory only. It is never logged, returned by a tool, or sent anywhere; only signed payment authorizations leave the process.
  • No ETH is needed: the payment facilitator pays network fees.

Guardrails enforced before anything is signed:

SettingDefaultMeaning
PROVENPAID_MAX_PRICE_USD0.01Refuse any check priced above this (hard ceiling 0.10).
PROVENPAID_DAILY_LIMIT20Maximum paid checks per UTC day, persisted across restarts.
PROVENPAID_NETWORKeip155:8453Pay only on this network, only in its USDC. eip155:84532 for Base Sepolia testing.
PROVENPAID_API_URLhttps://api.provenpaid.comMust be https.
PROVENPAID_STATE_DIR~/.provenpaid-mcpWhere the daily counter is kept.

How it works

The server calls GET https://api.provenpaid.com/v1/check?url=.... The API answers HTTP 402 with x402 payment requirements; the official x402 SDK signs a single-use USDC authorization within the guardrails above and retries. Settlement happens only when the check delivers evidence. Methodology: https://api.provenpaid.com/methodology

License

MIT

来源:README.md,提交 3ba55a5

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v0.1.0最新Oct 9, 2026