presign-guard wallet

io.github.Fizzl13v0.3.0更新于 Oct 2, 2026

A wallet with spending limits for agents: pay x402 APIs, send USDC, phone approval over the limit.

已验证STDIO仅桌面FinanceSecurity & Monitoring

概览

AI 生成的概览

为 AI 代理提供一个带消费限额的加密钱包,用于支付 x402 API 和发送 USDC,超限时通过 Telegram 审批。

功能
在本地运行一个代理钱包,提供查询状态、支付返回 402 Payment Required 的 x402 API、发送 USDC、发送原生代币以及暂停消费等工具。每个签名先由 presign-guard 检查已知盗币合约、受制裁地址和仿冒代币,红色结论一律不签名。超过单笔或每日限额的支付需要你通过 Telegram 或钱包服务器面板批准;若检查、Telegram 或服务器无法访问,则不会签名。
适用场景
当代理需要自行支付 x402 API 或发送 USDC,而你希望有硬性预算上限并在超限时人工批准时使用。适合在 Base 或其他支持链上进行小额支出的代理工作流。
运行要求
通过 npx 启动的本地进程(需要 Node.js)。需要 AGENT_KEY,即独立代理钱包的私钥,并需设置限额或使用钱包服务器。可选:CHAIN、LIMIT_USDC_PER_DAY、LIMIT_USDC_PER_TX、MAX_PAYMENT_USD、RPC_URL、PRESIGN_CREDIT_KEY,以及用于审批的 TELEGRAM_BOT_TOKEN 与 TELEGRAM_CHAT_ID,或 WALLET_SERVER_URL 与 WALLET_SERVER_KEY。需要网络访问。
安装前请注意
AGENT_KEY、WALLET_SERVER_KEY、PRESIGN_CREDIT_KEY 和 TELEGRAM_BOT_TOKEN 均为机密,私钥保留在本机。该钱包可动用真实资金:send_usdc 和 send_native 会转账加密货币,pay_x402 会花费 USDC,因此请使用只存放代理可支配金额的独立钱包,切勿使用主钱包。每次 presign-guard 检查花费 0.01 USDC。若未配置 Telegram 或钱包服务器,超过限额的请求会被拒绝。

安装

在 SourceWeft 中

  1. 打开 控制台中的 presign-guard wallet,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

presign-guard-wallet-mcp

A wallet with spending limits for AI agents, as an MCP server. Add it to Claude Desktop, Claude Code, Cursor or any other MCP client, and your agent can:

  • pay for x402 APIs;
  • send USDC.

It can only do that within the budget you set:

  • You set the limits. For example: up to 5 USDC per payment and 20 USDC a day, and the agent is free to spend within them.
  • Above a limit, you decide. You get a Telegram message with Approve / Deny, or the request shows up on your wallet server dashboard. No answer means no payment.
  • Every signature is checked first by presign-guard. It checks for known drainers, sanctioned addresses and look-alike tokens. A red verdict is never signed.
  • When in doubt, nothing is signed. If the check, Telegram or the server can't be reached, the wallet stops.

The key stays on your machine; the server only decides whether a signature is allowed. Each check costs $0.01, paid in USDC on Base from the same wallet, or from prepaid credits.

See the dashboard (demo data): https://wallet.fizzl.eu/demo

Tools

ToolWhat it does
wallet_statusAddress, balances, limits, what is left today, how approvals work
pay_x402Call an API that answers 402 Payment Required, pay it in USDC, return the response (with a price cap per call)
send_usdcSend USDC to an address
send_nativeSend ETH / POL / BNB to an address
pause_spendingThe agent stops itself when something looks wrong; nothing is signed until you restart or resume

Set up

  1. Make a separate wallet for the agent. Put only what it may spend in it: a few dollars of USDC on Base, plus a little ETH for gas if it will send transfers. Never use your main wallet.
  2. Optional: phone approvals.
  3. Add it to your MCP client. For Claude Desktop, put this in claude_desktop_config.json:
json
{  "mcpServers": {    "wallet": {      "command": "npx",      "args": ["-y", "presign-guard-wallet-mcp"],      "env": {        "AGENT_KEY": "0x…the agent wallet's private key…",        "LIMIT_USDC_PER_TX": "5",        "LIMIT_USDC_PER_DAY": "20",        "TELEGRAM_BOT_TOKEN": "123456:ABC…",        "TELEGRAM_CHAT_ID": "123456789"      }    }  }}

For Claude Code:

sh
claude mcp add wallet -e AGENT_KEY=0x… -e LIMIT_USDC_PER_TX=5 -e LIMIT_USDC_PER_DAY=20 -- npx -y presign-guard-wallet-mcp

Then ask your agent, for example: "Check my wallet, then get the BTC signal from https://ichimoku-signal.fizzl.eu/signal/BTC-USDT".

One budget for all your agents

Run the wallet server and make an agent key on its dashboard. It gives you:

  • one price rule and one daily budget for all your agents;
  • approvals on the dashboard and on Telegram;
  • an activity log.

Then use these variables instead of LIMIT_* and TELEGRAM_*:

json
"env": {  "AGENT_KEY": "0x…",  "WALLET_SERVER_URL": "https://your-wallet-server.example",  "WALLET_SERVER_KEY": "awk_…"}

Configuration

Variable
AGENT_KEYrequired: private key of the agent's own wallet
LIMIT_USDC_PER_TX, LIMIT_USDC_PER_DAYUSDC limits (payments and transfers together). Limits or a wallet server are required
LIMIT_NATIVE_PER_TX, LIMIT_NATIVE_PER_DAYlimits for the native coin; without them, sending it needs approval
TELEGRAM_BOT_TOKEN, TELEGRAM_CHAT_IDapprovals on Telegram; without them, anything over a limit is refused
WALLET_SERVER_URL, WALLET_SERVER_KEYa wallet server instead of the above
CHAINbase (default), ethereum, optimism, arbitrum, polygon or bsc
MAX_PAYMENT_USDmost one pay_x402 call may cost (default 1); a cap on top of the limits
PRESIGN_CREDIT_KEYpay the $0.01 checks from prepaid credits (pgc_…)
RPC_URLyour own RPC for the chain
AGENT_LABELthe name shown in Telegram approval messages (default mcp-agent)

One Telegram bot serves one running server at a time, and the bot must not have a webhook. To run several agents on one bot, use the wallet server.

Receipts

Every payment carries what it was for: the URL for pay_x402, and the agent's reason if it gives one. With a wallet server, that shows on the receipt for each payment, together with:

  • the amount and recipient;
  • presign-guard's signed verdict;
  • the approval;
  • the x402 settlement;
  • what the agent got back: the API's answer (up to 16,000 characters), shown in plain form on the receipt.

Telegram approval requests say what the payment is for too. See a receipt in the demo: click a purchase under "Purchases".

When something is refused

The tool returns an error the agent can read and pass on to you. Examples:

  • Not done (over_limit): 8 USDC is over the limit of 5 per transaction (denied by the owner);
  • Not done (red): not signed: red (known_drainer).

Also available

License

MIT

来源:wallet-mcp/README.md,提交 1c7a8ea

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v0.3.0最新Oct 2, 2026