
Shinjuku Shielded
io.github.ShinjukuStaitionv0.1.1更新於 Oct 8, 2026
Private x402 payments on Solana: shield, pay, and unshield USDC under caps you set.
概覽
一個本機 MCP 伺服器,讓代理在 Solana 上從屏蔽餘額進行私密的 x402 USDC 付款,並受你設定的額度限制。
- 功能
- 它提供在 Solana 上進行屏蔽 USDC 付款的工具:wallet_balance 顯示屏蔽與未屏蔽餘額,wallet_shield 將 USDC 轉入屏蔽餘額,x402_preview 在不付款的情況下檢查賣家價格是否符合額度,x402_pay 支付某個 URL 並回傳結果,wallet_unshield 將屏蔽 USDC 傳送到公開地址,wallet_receipts 列出近期收據,wallet_cancel 釋放未完成的付款。額度與單一主機限額在啟動時設定,工具呼叫只能調降而不能調高。
- 適用情境
- 當代理需要從自託管的 Solana 錢包向支援 x402 的賣家或 API 付款,同時希望在鏈上隱藏付款方,而且你希望在本地強制執行單筆與工作階段支出上限時,適合使用。
- 執行需求
- 以 npm 套件 shinjuku-shielded 透過 npx 在本機以 stdio 執行,需要 Node.js 22 或以上版本。需要由 SHIELDED_WALLET_HOME 指定的錢包資料夾,並在啟動時透過 --passphrase-file 或 SHIELDED_WALLET_PASSPHRASE 提供通關密語。啟動時必須提供 --max-payment 與 --max-session。選用參數可啟用 Tor、shield 與 unshield 證明工具以及你自己的 Solana RPC。不需要帳號或 API 金鑰。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 Shinjuku Shielded,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
[Shinjuku Shielded MCP: the private x402 facilitator, inside your agent]
[Solana mainnet] [x402 facilitator] [MCP] [Self-custody] [Tor]
Shinjuku Shielded MCP
The private x402 facilitator, inside your agent.
Shinjuku Shielded settles x402 payments from a shielded USDC balance on Solana: on chain, a shielded payment does not show who paid. This MCP server is how your agent uses it. It runs on your machine, under caps that only you set.
- Self-custody. The server runs on your machine. Your keys never leave it. We never run it, and we never hold your money.
- Shielded payments. Your agent pays from a shielded balance. Add
--torand no server sees your IP. - Caps that only you set.
--max-paymentand--max-sessionare required at launch. A tool call can only lower them, never raise them. - Look before you pay.
x402_previewshows the price and whether your caps allow it. It pays nothing. - Never twice. A retry with the same
request_idresumes the same payment, deposit, or unshield. It never starts a second one. - No RPC, no account, no API key. Reads go through our relay by default. Your own RPC always wins if you give one.
Every Shinjuku Shielded service joins this MCP as it ships.
The server is the mcp command of shinjuku-wallet, one file. This
repository holds the setup guide and examples. The wallet file, its SHA-256, and its
release history are in
ShinjukuStaition/shinjuku-shielded.
Talk to it in plain words
Ask your agent the way you would ask a person:
Each answer tells the agent the exact next call. The wallet reads the chain and writes an encrypted backup by itself, so you never run a command for upkeep.
Tools
SHIELD
PAY
UNSHIELD
ACCOUNT
Also: wallet_cancel closes one unfinished payment, so its reserved balance
comes back.
wallet_shield and wallet_unshield always appear in the tool list. When
one is off, it answers "error": "mcp_tool_disabled" and tells the agent
what to ask you.
What it pays: x402 scheme shielded-exact from your shielded balance, and
standard Solana exact from a ready pocket. A ready pocket pays any Solana
x402 exact seller, whichever facilitator settles it. For sellers that
offer only confidential (hidden amounts), use shinjuku-wallet laneb pay-url.
Privacy modes
Setup
You need Node.js 22 or later. The current wallet release is 1a336885.
Fastest install (npm)
The npm package [email protected] is wallet release 1a336885. It
has two commands: shinjuku-shielded and shinjuku-wallet. npx gets it
for you:
Or download the file and check it
Download the release file and check its SHA-256 before you run it. The current file and hash are also in the Releases table and in section 7b of https://shinjukustaition.com/skill.md.
With the file, replace npx -y shinjuku-shielded below with
node /abs/path/shinjuku-wallet.mjs.
Make and fund the wallet
Follow https://shinjukustaition.com/skill.md section 7b: init, the proof
tools, and funding your shielded balance. The proof tools are a separate
download with both install options (Linux, or WSL on Windows; about 144 MB,
every file hash-checked). help init and help add-funds say the same on
your machine. Your agent can also fund the shielded balance itself with
wallet_shield.
Add it to your agent
The session flags for the production pool:
Caps are in atomic USDC units: 50000 = 0.05 USDC. --proof-tools turns
wallet_shield on. --exit-proof-tools and --profile (both in the
shinjuku-proof-tools folder) turn wallet_unshield on.
Claude Code
Claude Desktop, Cursor, and other JSON-config hosts
Use absolute paths: a host starts the server from its own folder. On Windows,
write C:/Users/you/....
Claude Desktop: claude_desktop_config.json. Cursor: ~/.cursor/mcp.json.
A send to a new address needs a host that supports MCP elicitation (it shows
you the confirmation). With a host that does not, name each address with
--unshield-to.
Examples
examples/ has complete configs and a walkthrough:
- Claude Code: the
claude mcp addcommand with and without Tor, each flag explained, and how to check it works. - Claude Desktop and Cursor: complete JSON configs.
- Hermes Agent: the
config.yamlentry. - First 10 minutes: install, make the wallet, fund it, shield, pay, send, and check the balance.
- Plain requests: 10 requests, the tool each one calls, and the shape of the answer.
Caps and flags
The passphrase comes from --passphrase-file or SHIELDED_WALLET_PASSPHRASE
at start, never from a tool call. A refusal is a normal answer
({"ok": false, "error", "detail", "next"}); the agent does what next
says. A cap refusal tells the agent to ask you: only you set the caps.
An unshield is your own money, so it does not count against the payment
budget of the wallet file (init --max-payment, --max-cumulative).
Payments to sellers still count.
Upkeep is automatic. After a deposit lands, and before a payment or unshield
when the local balance is stale, the server reads the chain itself. After
each shield and unshield, the wallet writes an encrypted backup to
<SHIELDED_WALLET_HOME>/auto-backups/<pool>/. It keeps the newest 5
complete, verified backups. They are on the same disk as the wallet: copy
one to another place.
What others can see
- The seller sees your request, the price, the time, and your IP unless you
use
--tor. - Your agent host and its model provider see every URL, body, price, paid answer, amount, and unshield address the agent handles. A local model removes that observer.
- Your MCP client app (Claude Code, Claude Desktop, Cursor, ...) answers the
confirmation of a send, not the model. So a prompt-injected agent cannot
approve a send. But the wallet trusts the client app to show the dialog to
you: a malicious or modified client app could answer "accept" by itself.
For a strict setup, name your addresses with
--unshield-toand use a client without elicitation. Then any other address is refused. - Our facilitator processes your payment. It keeps no access logs.
- On chain, a
shielded-exactpayment does not show who paid. A pocketexactpayment is a normal USDC transfer from the pocket address. wallet_shieldis a public step: the chain shows USDC leave the wallet's own key, the amount, and the time.wallet_unshieldis a public step: the chain shows the amount, the address that receives it, and the time.- The UNSHIELDED line of
wallet_balancereads the wallet's own key. The RPC (our relay by default) sees which key it reads. - Privacy needs a crowd. With few users, timing can still link payments.
Status
Listed in the official MCP Registry
as io.github.ShinjukuStaition/shinjuku-mcp. npm: shinjuku-shielded,
published from this repository's workflow with npm provenance (from 0.1.1).
Live on Solana mainnet with wallet release 1a336885 (2026-10-08). Proven
with real money through this MCP server, against our production facilitator:
No unshield transaction contains the wallet that shielded; our facilitator paid every network fee of each unshield.
Full guide: https://shinjukustaition.com/skill.md · Onion: http://2kfhlfuyuwvhmibjrpxqsg4nrbcxasjgjq7kmnfzgfwzptkhhznz3dad.onion/skill.md · X: @Shin_StAItion
來源:README.md,提交 b767f54
工具
0版本歷史
1- v0.1.1最新Oct 8, 2026


