
Agent Pay Mcp
com.deepfirstsearchv0.1.2更新於 Oct 7, 2026
x402 payments in USDC on Base inside an owner-signed, on-chain budget the model can't change
概覽
讓 MCP 代理在擁有者簽署、自身無法更改的鏈上預算內,用 Base 上的 USDC 支付 x402 API。
- 功能
- 提供三個工具:paid_fetch 取得 URL,若回應 402 Payment Required,僅當商家、價格與預算符合擁有者設定時才付款;list_merchants 顯示可支付的來源、價格與剩餘額度;budget_status 回報每個商家的剩餘預算、視窗續期與 vault 餘額(R6、R7、R8、R9)。模型無法選擇收款方、金額、網路或限額,因為不存在這些參數(R10)。商家、價格鎖定、上限與支出計畫來自設定檔,密鑰來自環境變數(R11)。回應會被包在隨機標籤的圍籬中並標記為不可信資料(R12)。
- 適用情境
- 當代理需要呼叫 Base 上付費的 x402 API,且支出必須受擁有者簽署預算約束時值得加入,即使網頁或 API 回應試圖對模型進行提示注入(R2)。適合在 Base Sepolia 或主網小額資金上測試(R3)。不適合需要自行選擇任意收款方或金額的代理,因為不存在這些參數(R10)。
- 執行需求
- 本機 stdio 程序,僅限桌面端,透過 npx @deepfirstsearch/agent-pay-mcp 並傳入 config.json 的絕對路徑執行(R24、R28)。需要 Node.js 與 npm;從原始碼執行時需 npm ci 與 npm run build(R29)。密鑰僅透過環境變數提供:AGENT_PAY_AGENT_KEY(設定 vault 時需要)與 AGENT_PAY_BURNER_SEED(必需)(R20、R21、R22)。需先用擁有者 CLI 建立 vault 並簽署每個商家的預算,或自行向付款位址充值(R14、R15、R16)。需要網路存取以呼叫 x402 介面。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 Agent Pay Mcp,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
@deepfirstsearch/agent-pay-mcp
An MCP server that lets any MCP agent (Claude Desktop, Claude Code, Cursor, …) pay x402 APIs in USDC on Base without being able to overspend, even if a web page or API response prompt-injects it.
Beta, unaudited. Use Base Sepolia or small amounts on Base mainnet.
The model gets three tools and nothing else:
The model cannot choose a payee, an amount, a network or a limit: there is no argument for any of them. Merchants, price pins, caps and the spending plan come from your config file; keys come from environment variables. Responses are returned inside a randomly tagged fence marked as untrusted data. On-chain, the Agent Safe vault enforces your signed per-payment and per-day caps even if this machine is compromised.
Setup
- Budget (owner, once): create a vault and sign a budget per merchant with the owner CLI:
npx @deepfirstsearch/agent-pay owner create-vault, thenowner budget …, which prints theintentIdand a ready-to-pastemerchants[]entry. (No vault? Leave outvault,trancheandintentIdand fund the payer addresses yourself.) - Config: copy
config.example.jsonand fill it in. Amounts are USDC decimal strings. Keeptrancheat or below each intent'strancheCapandmaxPerTx. - Secrets (environment only):
AGENT_PAY_AGENT_KEY: the intent's agent key (needed with a vault).AGENT_PAY_BURNER_SEED: the 32-byte secret the payer addresses were derived from. Never your owner key.
Claude Code
OpenClaw
Full walkthrough: OpenClaw guide.
Claude Desktop / Cursor
claude_desktop_config.json (Claude Desktop) or .cursor/mcp.json (Cursor):
From source instead of npm: cd integrations/mcp && npm ci && npm run build, then use node /path/to/integrations/mcp/dist/index.js as the command.
See it work in 5 minutes (Base Sepolia)
sdk/examples/demo-merchant.ts is a tiny x402 API on Base Sepolia with an honest route (/premium, 0.01 USDC) and a hostile one (/malicious: its 402 asks for 5 USDC to an attacker address and its body carries a prompt injection).
Point the config's merchant at http://127.0.0.1:4021 with that payTo, then ask your agent to fetch /premium and /malicious. Expected: the first is paid and settled on-chain; the second is refused before anything is signed ("payTo … is not the merchant's registered address").
Config reference
Develop
來源:integrations/mcp/README.md,提交 9aee897
工具
0版本歷史
1- v0.1.2最新Oct 7, 2026

