
VeilQuota
io.github.omkardongrev0.1.0更新于 Oct 10, 2026
Private OCR, web search, and attested AI chat, paid with anonymous credits bought with shielded ZEC
概览
让助手使用本地密封钱包中的预付匿名额度,执行付费的私密 OCR、网页搜索和可验证加密聊天。
- 功能
- 提供对本地 PNG/JPG 图片进行 OCR、获取 Brave 网页搜索摘录用于依据,以及向可验证飞地发起端到端加密聊天的工具。每次调用都用预付匿名额度(Privacy Pass Blind RSA 令牌)支付,额度以屏蔽式 Zcash 购买。wallet_balance 工具报告可用额度和支出策略,quote_ocr 在支出前给出价格。不使用账户或 API 密钥。
- 适用场景
- 当助手需要 OCR、网页搜索或聊天调用,且不希望这些调用与账户或 API 密钥关联,并可以接受按次使用匿名预付额度付费时使用。适合注重隐私、不希望网关把调用关联到同一付款方的工作流。
- 运行要求
- 通过 npx @veilquota/mcp 作为本地进程运行,支持 Linux x64(glibc)和 macOS arm64;其他平台需从源码构建 veilquota-checkout 并放入 PATH。需要先用 setup 创建钱包,在原生钱包终端提示符输入口令,并用屏蔽式 ZEC 或试用链接购买额度。VEILQUOTA_HOME 设置钱包目录(默认 ~/.veilquota)。
安装
在 SourceWeft 中
- 打开 控制台中的 VeilQuota,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
@veilquota/mcp
MCP server (TypeScript SDK v2, stdio, protocol 2026-07-28) for private paid tools: OCR, web search, and attested, end-to-end encrypted AI chat. Each call is paid with anonymous prepaid credits (Privacy Pass Blind RSA tokens) bought with shielded Zcash. There is no account and no API key, and the gateway cannot link two calls to one payer.
Unaudited, capped mainnet beta. IP address and timing are not hidden.
Quickstart
Credits: buy 100 for 0.0005 ZEC at the hosted wallet with Zodl, or use a try-link someone gave you. The wallet lives in ~/.veilquota (0700), sealed with your passphrase; set VEILQUOTA_HOME to move it. Prebuilt binaries ship for Linux x64 (glibc) and macOS arm64. On other platforms, install veilquota-checkout from source and it is found on PATH.
Tools
What an agent structurally cannot do
These limits come from where keys and rules live, not from instructions to the model:
- It cannot touch money. No Zcash key, wallet passphrase, or credit token is in this process or in model context. It can spend only credits already in the wallet. Buying more needs a person paying a ZEC invoice.
- It cannot pay anyone else. The wallet agent pins one gateway origin at startup. No tool argument names a payee or a price.
- It cannot exceed the caps. The wallet agent, not this server, enforces a per-request ceiling, a session cap, and a daily cap. It also enforces a tool allowlist and a pause switch. The rules live in a policy file beside the wallet and are re-read before every spend.
- It cannot approve its own spend. A spend above the approval threshold is put to the user as an MCP elicitation. Only the user's answer sets
approved; no tool argument can. If the host cannot show the prompt, the spend is refused and nothing is charged. - It cannot be charged twice. A lost response is retried with the same arguments; the retry returns the original result.
Spending policy
The defaults are: all tools allowed, session cap 50, daily cap 100, and approval for anything above 4 credits, so OCR asks first. An exact retry of a spend whose credits are already locked is never blocked, even while paused, so credits are never stranded. A refunded spend gives its credits back to the caps. Daily totals are kept on this machine in WALLET.spend-day.json, and nothing about them reaches a gateway.
Commands
Passphrases are typed only at the native wallet binary's terminal prompt, and packs are read from a hidden prompt. Neither appears in argv, shell history, or MCP configuration.
来源:packages/mcp-ocr/README.md,提交 aa6fbb5
工具
0版本历史
1- v0.1.0最新Oct 10, 2026
