presign-guard wallet

io.github.Fizzl13v0.3.0更新於 Oct 2, 2026

A wallet with spending limits for agents: pay x402 APIs, send USDC, phone approval over the limit.

已驗證STDIO僅桌面Security & MonitoringFinance

概覽

AI 產生的概覽

為 AI 代理提供一個有消費上限的加密錢包,用來支付 x402 API 與發送 USDC,超額時透過 Telegram 核准。

功能
在使用者本機執行一個代理錢包,提供查詢狀態、支付回傳 402 Payment Required 的 x402 API、發送 USDC、發送原生代幣,以及暫停消費等工具。每個簽章都會先由 presign-guard 檢查已知盜幣合約、受制裁地址與仿冒代幣,紅色結論一律不簽署。超過單筆或每日上限的付款需要你透過 Telegram 或錢包伺服器儀表板核准;若檢查、Telegram 或伺服器無法連線,就不會簽署。
適用情境
當代理需要自行支付 x402 API 或發送 USDC,而你希望有硬性預算上限並在超額時人工核准時使用。適合在 Base 或其他支援鏈上進行小額支出的代理工作流程。
執行需求
透過 npx 啟動的本機程序(需要 Node.js)。需要 AGENT_KEY,也就是獨立代理錢包的私鑰,並需設定上限或使用錢包伺服器。選用:CHAIN、LIMIT_USDC_PER_DAY、LIMIT_USDC_PER_TX、MAX_PAYMENT_USD、RPC_URL、PRESIGN_CREDIT_KEY,以及用於核准的 TELEGRAM_BOT_TOKEN 與 TELEGRAM_CHAT_ID,或 WALLET_SERVER_URL 與 WALLET_SERVER_KEY。需要網路連線。
安裝前請注意
AGENT_KEY、WALLET_SERVER_KEY、PRESIGN_CREDIT_KEY 與 TELEGRAM_BOT_TOKEN 都是機密,私鑰保留在本機。這個錢包能動用真實資金:send_usdc 與 send_native 會轉帳加密貨幣,pay_x402 會花費 USDC,因此請使用只存放代理可支配金額的獨立錢包,切勿使用主錢包。每次 presign-guard 檢查花費 0.01 USDC。若未設定 Telegram 或錢包伺服器,超過上限的要求會被拒絕。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 presign-guard wallet,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

presign-guard-wallet-mcp

A wallet with spending limits for AI agents, as an MCP server. Add it to Claude Desktop, Claude Code, Cursor or any other MCP client, and your agent can:

  • pay for x402 APIs;
  • send USDC.

It can only do that within the budget you set:

  • You set the limits. For example: up to 5 USDC per payment and 20 USDC a day, and the agent is free to spend within them.
  • Above a limit, you decide. You get a Telegram message with Approve / Deny, or the request shows up on your wallet server dashboard. No answer means no payment.
  • Every signature is checked first by presign-guard. It checks for known drainers, sanctioned addresses and look-alike tokens. A red verdict is never signed.
  • When in doubt, nothing is signed. If the check, Telegram or the server can't be reached, the wallet stops.

The key stays on your machine; the server only decides whether a signature is allowed. Each check costs $0.01, paid in USDC on Base from the same wallet, or from prepaid credits.

See the dashboard (demo data): https://wallet.fizzl.eu/demo

Tools

ToolWhat it does
wallet_statusAddress, balances, limits, what is left today, how approvals work
pay_x402Call an API that answers 402 Payment Required, pay it in USDC, return the response (with a price cap per call)
send_usdcSend USDC to an address
send_nativeSend ETH / POL / BNB to an address
pause_spendingThe agent stops itself when something looks wrong; nothing is signed until you restart or resume

Set up

  1. Make a separate wallet for the agent. Put only what it may spend in it: a few dollars of USDC on Base, plus a little ETH for gas if it will send transfers. Never use your main wallet.
  2. Optional: phone approvals.
  3. Add it to your MCP client. For Claude Desktop, put this in claude_desktop_config.json:
json
{  "mcpServers": {    "wallet": {      "command": "npx",      "args": ["-y", "presign-guard-wallet-mcp"],      "env": {        "AGENT_KEY": "0x…the agent wallet's private key…",        "LIMIT_USDC_PER_TX": "5",        "LIMIT_USDC_PER_DAY": "20",        "TELEGRAM_BOT_TOKEN": "123456:ABC…",        "TELEGRAM_CHAT_ID": "123456789"      }    }  }}

For Claude Code:

sh
claude mcp add wallet -e AGENT_KEY=0x… -e LIMIT_USDC_PER_TX=5 -e LIMIT_USDC_PER_DAY=20 -- npx -y presign-guard-wallet-mcp

Then ask your agent, for example: "Check my wallet, then get the BTC signal from https://ichimoku-signal.fizzl.eu/signal/BTC-USDT".

One budget for all your agents

Run the wallet server and make an agent key on its dashboard. It gives you:

  • one price rule and one daily budget for all your agents;
  • approvals on the dashboard and on Telegram;
  • an activity log.

Then use these variables instead of LIMIT_* and TELEGRAM_*:

json
"env": {  "AGENT_KEY": "0x…",  "WALLET_SERVER_URL": "https://your-wallet-server.example",  "WALLET_SERVER_KEY": "awk_…"}

Configuration

Variable
AGENT_KEYrequired: private key of the agent's own wallet
LIMIT_USDC_PER_TX, LIMIT_USDC_PER_DAYUSDC limits (payments and transfers together). Limits or a wallet server are required
LIMIT_NATIVE_PER_TX, LIMIT_NATIVE_PER_DAYlimits for the native coin; without them, sending it needs approval
TELEGRAM_BOT_TOKEN, TELEGRAM_CHAT_IDapprovals on Telegram; without them, anything over a limit is refused
WALLET_SERVER_URL, WALLET_SERVER_KEYa wallet server instead of the above
CHAINbase (default), ethereum, optimism, arbitrum, polygon or bsc
MAX_PAYMENT_USDmost one pay_x402 call may cost (default 1); a cap on top of the limits
PRESIGN_CREDIT_KEYpay the $0.01 checks from prepaid credits (pgc_…)
RPC_URLyour own RPC for the chain
AGENT_LABELthe name shown in Telegram approval messages (default mcp-agent)

One Telegram bot serves one running server at a time, and the bot must not have a webhook. To run several agents on one bot, use the wallet server.

Receipts

Every payment carries what it was for: the URL for pay_x402, and the agent's reason if it gives one. With a wallet server, that shows on the receipt for each payment, together with:

  • the amount and recipient;
  • presign-guard's signed verdict;
  • the approval;
  • the x402 settlement;
  • what the agent got back: the API's answer (up to 16,000 characters), shown in plain form on the receipt.

Telegram approval requests say what the payment is for too. See a receipt in the demo: click a purchase under "Purchases".

When something is refused

The tool returns an error the agent can read and pass on to you. Examples:

  • Not done (over_limit): 8 USDC is over the limit of 5 per transaction (denied by the owner);
  • Not done (red): not signed: red (known_drainer).

Also available

License

MIT

來源:wallet-mcp/README.md,提交 1c7a8ea

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.3.0最新Oct 2, 2026