
Shinjuku Shielded
io.github.ShinjukuStaitionv0.1.1更新于 Oct 8, 2026
Private x402 payments on Solana: shield, pay, and unshield USDC under caps you set.
概览
一个本地 MCP 服务器,让智能体在 Solana 上从屏蔽余额进行私密的 x402 USDC 支付,并受你设定的额度限制。
- 功能
- 它提供在 Solana 上进行屏蔽 USDC 支付的工具:wallet_balance 显示屏蔽与未屏蔽余额,wallet_shield 将 USDC 转入屏蔽余额,x402_preview 在不付款的情况下检查卖家价格是否符合额度,x402_pay 支付某个 URL 并返回结果,wallet_unshield 将屏蔽 USDC 发送到公开地址,wallet_receipts 列出近期收据,wallet_cancel 释放未完成的支付。额度与单主机限额在启动时设定,工具调用只能降低而不能提高。
- 适用场景
- 当智能体需要从自托管的 Solana 钱包向支持 x402 的卖家或 API 付款,同时希望在链上隐藏付款方,并且你希望在本地强制执行单笔与会话支出上限时,适合使用。
- 运行要求
- 以 npm 包 shinjuku-shielded 通过 npx 在本地以 stdio 运行,需要 Node.js 22 或更高版本。需要由 SHIELDED_WALLET_HOME 指定的钱包目录,并在启动时通过 --passphrase-file 或 SHIELDED_WALLET_PASSPHRASE 提供口令。启动时必须提供 --max-payment 与 --max-session。可选参数可启用 Tor、shield 与 unshield 证明工具以及你自己的 Solana RPC。无需账户或 API 密钥。
安装
在 SourceWeft 中
- 打开 控制台中的 Shinjuku Shielded,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
[Shinjuku Shielded MCP: the private x402 facilitator, inside your agent]
[Solana mainnet] [x402 facilitator] [MCP] [Self-custody] [Tor]
Shinjuku Shielded MCP
The private x402 facilitator, inside your agent.
Shinjuku Shielded settles x402 payments from a shielded USDC balance on Solana: on chain, a shielded payment does not show who paid. This MCP server is how your agent uses it. It runs on your machine, under caps that only you set.
- Self-custody. The server runs on your machine. Your keys never leave it. We never run it, and we never hold your money.
- Shielded payments. Your agent pays from a shielded balance. Add
--torand no server sees your IP. - Caps that only you set.
--max-paymentand--max-sessionare required at launch. A tool call can only lower them, never raise them. - Look before you pay.
x402_previewshows the price and whether your caps allow it. It pays nothing. - Never twice. A retry with the same
request_idresumes the same payment, deposit, or unshield. It never starts a second one. - No RPC, no account, no API key. Reads go through our relay by default. Your own RPC always wins if you give one.
Every Shinjuku Shielded service joins this MCP as it ships.
The server is the mcp command of shinjuku-wallet, one file. This
repository holds the setup guide and examples. The wallet file, its SHA-256, and its
release history are in
ShinjukuStaition/shinjuku-shielded.
Talk to it in plain words
Ask your agent the way you would ask a person:
Each answer tells the agent the exact next call. The wallet reads the chain and writes an encrypted backup by itself, so you never run a command for upkeep.
Tools
SHIELD
PAY
UNSHIELD
ACCOUNT
Also: wallet_cancel closes one unfinished payment, so its reserved balance
comes back.
wallet_shield and wallet_unshield always appear in the tool list. When
one is off, it answers "error": "mcp_tool_disabled" and tells the agent
what to ask you.
What it pays: x402 scheme shielded-exact from your shielded balance, and
standard Solana exact from a ready pocket. A ready pocket pays any Solana
x402 exact seller, whichever facilitator settles it. For sellers that
offer only confidential (hidden amounts), use shinjuku-wallet laneb pay-url.
Privacy modes
Setup
You need Node.js 22 or later. The current wallet release is 1a336885.
Fastest install (npm)
The npm package [email protected] is wallet release 1a336885. It
has two commands: shinjuku-shielded and shinjuku-wallet. npx gets it
for you:
Or download the file and check it
Download the release file and check its SHA-256 before you run it. The current file and hash are also in the Releases table and in section 7b of https://shinjukustaition.com/skill.md.
With the file, replace npx -y shinjuku-shielded below with
node /abs/path/shinjuku-wallet.mjs.
Make and fund the wallet
Follow https://shinjukustaition.com/skill.md section 7b: init, the proof
tools, and funding your shielded balance. The proof tools are a separate
download with both install options (Linux, or WSL on Windows; about 144 MB,
every file hash-checked). help init and help add-funds say the same on
your machine. Your agent can also fund the shielded balance itself with
wallet_shield.
Add it to your agent
The session flags for the production pool:
Caps are in atomic USDC units: 50000 = 0.05 USDC. --proof-tools turns
wallet_shield on. --exit-proof-tools and --profile (both in the
shinjuku-proof-tools folder) turn wallet_unshield on.
Claude Code
Claude Desktop, Cursor, and other JSON-config hosts
Use absolute paths: a host starts the server from its own folder. On Windows,
write C:/Users/you/....
Claude Desktop: claude_desktop_config.json. Cursor: ~/.cursor/mcp.json.
A send to a new address needs a host that supports MCP elicitation (it shows
you the confirmation). With a host that does not, name each address with
--unshield-to.
Examples
examples/ has complete configs and a walkthrough:
- Claude Code: the
claude mcp addcommand with and without Tor, each flag explained, and how to check it works. - Claude Desktop and Cursor: complete JSON configs.
- Hermes Agent: the
config.yamlentry. - First 10 minutes: install, make the wallet, fund it, shield, pay, send, and check the balance.
- Plain requests: 10 requests, the tool each one calls, and the shape of the answer.
Caps and flags
The passphrase comes from --passphrase-file or SHIELDED_WALLET_PASSPHRASE
at start, never from a tool call. A refusal is a normal answer
({"ok": false, "error", "detail", "next"}); the agent does what next
says. A cap refusal tells the agent to ask you: only you set the caps.
An unshield is your own money, so it does not count against the payment
budget of the wallet file (init --max-payment, --max-cumulative).
Payments to sellers still count.
Upkeep is automatic. After a deposit lands, and before a payment or unshield
when the local balance is stale, the server reads the chain itself. After
each shield and unshield, the wallet writes an encrypted backup to
<SHIELDED_WALLET_HOME>/auto-backups/<pool>/. It keeps the newest 5
complete, verified backups. They are on the same disk as the wallet: copy
one to another place.
What others can see
- The seller sees your request, the price, the time, and your IP unless you
use
--tor. - Your agent host and its model provider see every URL, body, price, paid answer, amount, and unshield address the agent handles. A local model removes that observer.
- Your MCP client app (Claude Code, Claude Desktop, Cursor, ...) answers the
confirmation of a send, not the model. So a prompt-injected agent cannot
approve a send. But the wallet trusts the client app to show the dialog to
you: a malicious or modified client app could answer "accept" by itself.
For a strict setup, name your addresses with
--unshield-toand use a client without elicitation. Then any other address is refused. - Our facilitator processes your payment. It keeps no access logs.
- On chain, a
shielded-exactpayment does not show who paid. A pocketexactpayment is a normal USDC transfer from the pocket address. wallet_shieldis a public step: the chain shows USDC leave the wallet's own key, the amount, and the time.wallet_unshieldis a public step: the chain shows the amount, the address that receives it, and the time.- The UNSHIELDED line of
wallet_balancereads the wallet's own key. The RPC (our relay by default) sees which key it reads. - Privacy needs a crowd. With few users, timing can still link payments.
Status
Listed in the official MCP Registry
as io.github.ShinjukuStaition/shinjuku-mcp. npm: shinjuku-shielded,
published from this repository's workflow with npm provenance (from 0.1.1).
Live on Solana mainnet with wallet release 1a336885 (2026-10-08). Proven
with real money through this MCP server, against our production facilitator:
No unshield transaction contains the wallet that shielded; our facilitator paid every network fee of each unshield.
Full guide: https://shinjukustaition.com/skill.md · Onion: http://2kfhlfuyuwvhmibjrpxqsg4nrbcxasjgjq7kmnfzgfwzptkhhznz3dad.onion/skill.md · X: @Shin_StAItion
来源:README.md,提交 b767f54
工具
0版本历史
1- v0.1.1最新Oct 8, 2026


