VeilQuota

io.github.omkardongrev0.1.0更新于 Oct 10, 2026

Private OCR, web search, and attested AI chat, paid with anonymous credits bought with shielded ZEC

概览

AI 生成的概览

让助手使用本地密封钱包中的预付匿名额度,执行付费的私密 OCR、网页搜索和可验证加密聊天。

功能
提供对本地 PNG/JPG 图片进行 OCR、获取 Brave 网页搜索摘录用于依据,以及向可验证飞地发起端到端加密聊天的工具。每次调用都用预付匿名额度(Privacy Pass Blind RSA 令牌)支付,额度以屏蔽式 Zcash 购买。wallet_balance 工具报告可用额度和支出策略,quote_ocr 在支出前给出价格。不使用账户或 API 密钥。
适用场景
当助手需要 OCR、网页搜索或聊天调用,且不希望这些调用与账户或 API 密钥关联,并可以接受按次使用匿名预付额度付费时使用。适合注重隐私、不希望网关把调用关联到同一付款方的工作流。
运行要求
通过 npx @veilquota/mcp 作为本地进程运行,支持 Linux x64(glibc)和 macOS arm64;其他平台需从源码构建 veilquota-checkout 并放入 PATH。需要先用 setup 创建钱包,在原生钱包终端提示符输入口令,并用屏蔽式 ZEC 或试用链接购买额度。VEILQUOTA_HOME 设置钱包目录(默认 ~/.veilquota)。
安装前请注意
未经审计、有额度上限的主网测试版;IP 地址和时序不会被隐藏。涉及用真实 ZEC 购买额度,但钱包代理会强制执行单次请求、会话和每日上限、工具允许列表和暂停开关,超过审批阈值的支出需通过 MCP elicitation 由用户确认。口令只在原生钱包提示符输入,不会出现在 argv 或配置中。

安装

在 SourceWeft 中

  1. 打开 控制台中的 VeilQuota,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

@veilquota/mcp

MCP server (TypeScript SDK v2, stdio, protocol 2026-07-28) for private paid tools: OCR, web search, and attested, end-to-end encrypted AI chat. Each call is paid with anonymous prepaid credits (Privacy Pass Blind RSA tokens) bought with shielded Zcash. There is no account and no API key, and the gateway cannot link two calls to one payer.

Unaudited, capped mainnet beta. IP address and timing are not hidden.

Quickstart

bash
npx -y @veilquota/mcp setup      # create a wallet; paste a try-link or credit packnpx -y @veilquota/mcp agent      # unlock it (keep this terminal open)claude mcp add veilquota -- npx -y @veilquota/mcp

Credits: buy 100 for 0.0005 ZEC at the hosted wallet with Zodl, or use a try-link someone gave you. The wallet lives in ~/.veilquota (0700), sealed with your passphrase; set VEILQUOTA_HOME to move it. Prebuilt binaries ship for Linux x64 (glibc) and macOS arm64. On other platforms, install veilquota-checkout from source and it is found on PATH.

Tools

ToolSpendsWhat it does
wallet_balancenoCredits available, plus the spending policy and what remains of it
quote_ocrnoPrice for one image, checked against the policy before any spend
run_ocr13 creditsOCR one local .png/.jpg
private_search2 creditsBrave web search excerpts for grounding
private_chat4 creditsOne chat call to an attested Tinfoil enclave, encrypted end to end

What an agent structurally cannot do

These limits come from where keys and rules live, not from instructions to the model:

  • It cannot touch money. No Zcash key, wallet passphrase, or credit token is in this process or in model context. It can spend only credits already in the wallet. Buying more needs a person paying a ZEC invoice.
  • It cannot pay anyone else. The wallet agent pins one gateway origin at startup. No tool argument names a payee or a price.
  • It cannot exceed the caps. The wallet agent, not this server, enforces a per-request ceiling, a session cap, and a daily cap. It also enforces a tool allowlist and a pause switch. The rules live in a policy file beside the wallet and are re-read before every spend.
  • It cannot approve its own spend. A spend above the approval threshold is put to the user as an MCP elicitation. Only the user's answer sets approved; no tool argument can. If the host cannot show the prompt, the spend is refused and nothing is charged.
  • It cannot be charged twice. A lost response is retried with the same arguments; the retry returns the original result.

Spending policy

bash
veilquota-mcp policy showveilquota-mcp policy pause            # stops new spends at onceveilquota-mcp policy resumeveilquota-mcp policy set daily_cap 100veilquota-mcp policy set session_cap 50veilquota-mcp policy set approval_above 4veilquota-mcp policy set tools search,chat

The defaults are: all tools allowed, session cap 50, daily cap 100, and approval for anything above 4 credits, so OCR asks first. An exact retry of a spend whose credits are already locked is never blocked, even while paused, so credits are never stranded. A refunded spend gives its credits back to the caps. Daily totals are kept on this machine in WALLET.spend-day.json, and nothing about them reaches a gateway.

Commands

bash
veilquota-mcp                 # MCP server on stdio (what `claude mcp add` runs)veilquota-mcp setup           # create a wallet, then import a try-link or credit packveilquota-mcp agent [PORT]    # unlock the wallet; with PORT, also http://127.0.0.1:PORT/v1 for OpenAI clientsveilquota-mcp policy show     # spending guardrails (pause, resume, set KEY VALUE)

Passphrases are typed only at the native wallet binary's terminal prompt, and packs are read from a hidden prompt. Neither appears in argv, shell history, or MCP configuration.

来源:packages/mcp-ocr/README.md,提交 aa6fbb5

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v0.1.0最新Oct 10, 2026