Agent Pay Mcp

com.deepfirstsearchv0.1.2更新於 Oct 7, 2026

x402 payments in USDC on Base inside an owner-signed, on-chain budget the model can't change

已驗證STDIO僅桌面Developer ToolsFinance

概覽

AI 產生的概覽

讓 MCP 代理在擁有者簽署、自身無法更改的鏈上預算內,用 Base 上的 USDC 支付 x402 API。

功能
提供三個工具:paid_fetch 取得 URL,若回應 402 Payment Required,僅當商家、價格與預算符合擁有者設定時才付款;list_merchants 顯示可支付的來源、價格與剩餘額度;budget_status 回報每個商家的剩餘預算、視窗續期與 vault 餘額(R6、R7、R8、R9)。模型無法選擇收款方、金額、網路或限額,因為不存在這些參數(R10)。商家、價格鎖定、上限與支出計畫來自設定檔,密鑰來自環境變數(R11)。回應會被包在隨機標籤的圍籬中並標記為不可信資料(R12)。
適用情境
當代理需要呼叫 Base 上付費的 x402 API,且支出必須受擁有者簽署預算約束時值得加入,即使網頁或 API 回應試圖對模型進行提示注入(R2)。適合在 Base Sepolia 或主網小額資金上測試(R3)。不適合需要自行選擇任意收款方或金額的代理,因為不存在這些參數(R10)。
執行需求
本機 stdio 程序,僅限桌面端,透過 npx @deepfirstsearch/agent-pay-mcp 並傳入 config.json 的絕對路徑執行(R24、R28)。需要 Node.js 與 npm;從原始碼執行時需 npm ci 與 npm run build(R29)。密鑰僅透過環境變數提供:AGENT_PAY_AGENT_KEY(設定 vault 時需要)與 AGENT_PAY_BURNER_SEED(必需)(R20、R21、R22)。需先用擁有者 CLI 建立 vault 並簽署每個商家的預算,或自行向付款位址充值(R14、R15、R16)。需要網路存取以呼叫 x402 介面。
安裝前請注意
處於 Beta 且未經審計;請使用 Base Sepolia 或 Base 主網上的小額資金(R3)。它會從由 AGENT_PAY_BURNER_SEED 衍生的付款位址花費真實 USDC,該種子絕不能是擁有者金鑰(R22、R23)。需要兩個密鑰:AGENT_PAY_AGENT_KEY 與 AGENT_PAY_BURNER_SEED(R21、R22)。超過 approvalAbove 的付款會被拒絕,設定 sessionHasSensitiveData 時所有付款也會被拒絕(R43、R44)。每個決定都會寫入雜湊鏈審計日誌(R45)。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Agent Pay Mcp,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

@deepfirstsearch/agent-pay-mcp

An MCP server that lets any MCP agent (Claude Desktop, Claude Code, Cursor, …) pay x402 APIs in USDC on Base without being able to overspend, even if a web page or API response prompt-injects it.

Beta, unaudited. Use Base Sepolia or small amounts on Base mainnet.

The model gets three tools and nothing else:

ToolWhat the model can do
paid_fetch(url, method?, body?, contentType?)Fetch a URL. If it answers 402 Payment Required, the payment goes through only if the merchant, price and budget match your config
list_merchants()See which origins it may pay, their prices and what's left
budget_status()Remaining budget per merchant, window renewal, vault balance

The model cannot choose a payee, an amount, a network or a limit: there is no argument for any of them. Merchants, price pins, caps and the spending plan come from your config file; keys come from environment variables. Responses are returned inside a randomly tagged fence marked as untrusted data. On-chain, the Agent Safe vault enforces your signed per-payment and per-day caps even if this machine is compromised.

Setup

  1. Budget (owner, once): create a vault and sign a budget per merchant with the owner CLI: npx @deepfirstsearch/agent-pay owner create-vault, then owner budget …, which prints the intentId and a ready-to-paste merchants[] entry. (No vault? Leave out vault, tranche and intentId and fund the payer addresses yourself.)
  2. Config: copy config.example.json and fill it in. Amounts are USDC decimal strings. Keep tranche at or below each intent's trancheCap and maxPerTx.
  3. Secrets (environment only):
    • AGENT_PAY_AGENT_KEY: the intent's agent key (needed with a vault).
    • AGENT_PAY_BURNER_SEED: the 32-byte secret the payer addresses were derived from. Never your owner key.

Claude Code

bash
claude mcp add agent-pay \  -e AGENT_PAY_AGENT_KEY=0x… -e AGENT_PAY_BURNER_SEED=0x… \  -- npx -y @deepfirstsearch/agent-pay-mcp /absolute/path/config.json

OpenClaw

bash
npm install -g @deepfirstsearch/agent-pay-mcpopenclaw mcp set agent-pay '{"command":"agent-pay-mcp","args":["/absolute/path/config.json"],"env":{"AGENT_PAY_AGENT_KEY":"${AGENT_PAY_AGENT_KEY}","AGENT_PAY_BURNER_SEED":"${AGENT_PAY_BURNER_SEED}"}}'openclaw mcp probe agent-pay   # - agent-pay: 3 tools

Full walkthrough: OpenClaw guide.

Claude Desktop / Cursor

claude_desktop_config.json (Claude Desktop) or .cursor/mcp.json (Cursor):

json
{  "mcpServers": {    "agent-pay": {      "command": "npx",      "args": ["-y", "@deepfirstsearch/agent-pay-mcp", "/absolute/path/config.json"],      "env": { "AGENT_PAY_AGENT_KEY": "0x…", "AGENT_PAY_BURNER_SEED": "0x…" }    }  }}

From source instead of npm: cd integrations/mcp && npm ci && npm run build, then use node /path/to/integrations/mcp/dist/index.js as the command.

See it work in 5 minutes (Base Sepolia)

sdk/examples/demo-merchant.ts is a tiny x402 API on Base Sepolia with an honest route (/premium, 0.01 USDC) and a hostile one (/malicious: its 402 asks for 5 USDC to an attacker address and its body carries a prompt injection).

bash
cd sdk && MERCHANT=0xYourMerchantAddress npx tsx examples/demo-merchant.ts

Point the config's merchant at http://127.0.0.1:4021 with that payTo, then ask your agent to fetch /premium and /malicious. Expected: the first is paid and settled on-chain; the second is refused before anything is signed ("payTo … is not the merchant's registered address").

Config reference

FieldMeaning
networkeip155:84532 (Base Sepolia) or eip155:8453 (Base)
vault, trancheAgent Safe vault that tops up each merchant's payer, and the top-up size
merchants[].origin, payToWho may be paid, and the only address the payment can go to
merchants[].price, tolerancePctExpected price per call; anything above price × (1 + tolerance) is refused
merchants[].maxPerTx, maxSpendHard cap per call, and per merchant per plan window
planWindowHoursThe plan is sealed from this file at start and renewed from it every window
periodBudgetTotal across merchants per period
approvalAbovePayments above this are refused (this server has no approval channel the model can't reach)
sessionHasSensitiveDataIf the agent can also read private data, every payment needs a human (Rule of Two), so all are refused
auditLogHash-chained JSONL log of every decision

Develop

bash
npm ci && npm run typecheck && npm test   # tests drive the server through an MCP client against a mock x402 merchant

來源:integrations/mcp/README.md,提交 9aee897

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.1.2最新Oct 7, 2026