
Rein
io.github.bugiiiii11v0.5.1更新于 Oct 6, 2026
Spend limits for AI agents that pay with x402: every paywall is policy-checked before a cent moves.
概览
让 AI 代理在策略校验与留痕的前提下抓取 x402 付费墙网址,并仅在支出规则允许时付款。
- 功能
- Rein 是一个本地 stdio MCP 服务器,为单个代理充当支出守卫。rein_fetch 工具抓取网址,仅在策略引擎允许时才支付 x402 付费墙;rein_status、rein_receipts 和 rein_escalations 分别报告适用规则、历史付款和等待人工批准的付款,rein_heartbeat 用于上报代理存活。被拒绝时以工具错误返回,并附带 DENIED、ESCALATED 或 ALLOWED_BUT_UNPAID 说明。
- 适用场景
- 当助手需要调用付费 x402 接口,而你希望有单次调用支出上限、收据和审计记录,而不是一个不受限制的钱包时使用。也适合需要对较大额付款进行人工审批的团队,或想先以顾问模式观察会支付哪些费用的场景。
- 运行要求
- 通过 npx @reinconsole/mcp 在本地运行(需要 Node.js)。需要 REIN_ENGINE_URL 与 REIN_AGENT_ID,或由 npx @reinconsole/init 生成的 REIN_AGENT_FILE。托管引擎可能需要 REIN_ENGINE_API_KEY。付款需要 REIN_PAYER_PRIVATE_KEY,缺少时以顾问模式运行。REIN_NETWORK_PROFILE 选择 testnet(默认)或 mainnet。需要访问引擎和被抓取网址的网络。
安装
在 SourceWeft 中
- 打开 控制台中的 Rein,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
@reinconsole/mcp
The Rein guard, as an MCP server. Point any MCP-capable harness at it and its agent gets a spend-governed fetch: every x402 paywall is policy-checked, receipted and observable before a cent moves.
Rein is non-custodial. It governs an agent's authority to spend, not the funds.
Install
The fastest start is a free testnet sandbox -- no account, no signup:
It creates an agent on the hosted engine with a starter policy (Base Sepolia, $0.004 per-call cap),
a test wallet with a little test USDC, and rein-agent.json, then prints this config with the path
filled in:
The file supplies the engine URL, agent id, API key and wallet, so keys never sit on a command line
or in the config. The sandbox lasts 7 days; npx @reinconsole/init --claim keeps it by signing in
with GitHub or an Ethereum wallet.
Your own engine
Point it at any policy engine with variables instead of the file:
That is advisory mode: paywalls are evaluated against policy and reported, and nothing is ever
paid. Add REIN_PAYER_PRIVATE_KEY to settle allowed payments.
npx -p @reinconsole/policy-engine rein-policy-engine runs an engine locally on 127.0.0.1:8787;
see @reinconsole/policy-engine for
registering an agent and writing a policy.
When the server is up it prints exactly one line to stderr. A harness shows nothing else, so if this line is missing the server is not running, and whatever preceded it is why:
Environment
Everything is fixed at startup. Nothing here is reachable from a tool call.
REIN_NETWORK_PROFILE exists because the engine cannot draw this line: it maps Base and Base
Sepolia onto the same chain, so a policy that allows one allows both, and the vendor's 402 would
otherwise choose which network the agent's key spends on. The default is testnet, which means a
0.1.x install that paid mainnet 402s will refuse them until the profile is set to mainnet on
purpose.
On a HOSTED engine, REIN_ENGINE_API_KEY should be an evaluate key issued with the org
and narrowed to this one agent:
That is the whole blast radius of the secret sitting in a desktop config file: it can submit intents for this agent and nothing else — not another agent in the same org, not policy, not keys, not other tenants' anything. Against a self-hosted single-tenant engine, omit both fields and the key behaves exactly as it always has.
Tools
rein_fetch is the only tool that can move money, and it is the only one without readOnlyHint.
The authority boundary
The client on the other end of this pipe is the agent -- the thing being governed. So a tool may do anything the agent could already do with its own fetch, and nothing that widens the agent's own authority.
There is deliberately no tool to approve an escalation, edit a policy, freeze or unfreeze an agent,
mint an API key, or register an approver. An approval in Rein is an ed25519 signature over the
decision by a registered approver key; a tool call is not a signature, and one that stood in for one
would put the authority to move money behind whatever process holds the pipe. rein_escalations is
read-only by construction, and a test asserts the whole tool surface rather than a sample of it, so
adding an authority tool has to break a test first.
One server also speaks for exactly one agent. An agent id the caller could choose would turn an agent-scoped tool surface into a cross-agent admin API.
What a blocked payment looks like
A policy refusal comes back as a tool error -- the fetch did not happen, and a model that read it as an ordinary result would treat the explanation of a refusal as the data it asked for. The detail rides along, because the useful next move depends on which refusal it was:
DENIED-- final. The same request will be refused the same way.ESCALATED-- parked for a human to sign. Pollrein_escalations, or move on. Nothing the agent can call will approve it.ALLOWED_BUT_UNPAID-- not an error: policy said yes, but this server runs in advisory mode, so the 402 is returned unpaid.
Programmatic use
createToolContext and reinTools are exported too, for embedding the same tools in a server that
carries others.
License
MIT
来源:services/mcp/README.md,提交 efbb433
工具
0版本历史
1- v0.5.1最新Oct 6, 2026


