Rein

io.github.bugiiiii11v0.5.1更新於 Oct 6, 2026

Spend limits for AI agents that pay with x402: every paywall is policy-checked before a cent moves.

已驗證STDIO僅桌面FinanceSecurity & Monitoring

概覽

AI 產生的概覽

讓 AI 代理在策略檢查與留痕的前提下抓取 x402 付費牆網址,且只在支出規則允許時付款。

功能
Rein 是本地 stdio MCP 伺服器,為單一代理扮演支出守門人。rein_fetch 工具會抓取網址,且僅在策略引擎允許時才支付 x402 付費牆;rein_status、rein_receipts 與 rein_escalations 分別回報適用規則、過往付款與等待人工核准的付款,rein_heartbeat 用來回報代理仍在運作。被拒絕時會以工具錯誤回傳,並附上 DENIED、ESCALATED 或 ALLOWED_BUT_UNPAID 說明。
適用情境
當助理需要呼叫付費 x402 端點,而你希望有單次呼叫支出上限、收據與稽核紀錄,而不是一個不受限制的錢包時使用。也適合需要對較大金額付款進行人工核准的團隊,或想先以顧問模式觀察會支付哪些費用的情境。
執行需求
透過 npx @reinconsole/mcp 在本機執行(需要 Node.js)。需要 REIN_ENGINE_URL 與 REIN_AGENT_ID,或由 npx @reinconsole/init 產生的 REIN_AGENT_FILE。託管引擎可能需要 REIN_ENGINE_API_KEY。付款需要 REIN_PAYER_PRIVATE_KEY,缺少時以顧問模式執行。REIN_NETWORK_PROFILE 選擇 testnet(預設)或 mainnet。需要連線至引擎與被抓取網址的網路。
安裝前請注意
REIN_PAYER_PRIVATE_KEY 是可動用資金的代理錢包私鑰,REIN_ENGINE_API_KEY 是引擎的 Bearer 密鑰。rein_fetch 可能花錢,且 REIN_NETWORK_PROFILE=mainnet 會允許支付真實主網 402,預設 testnet 較安全。此伺服器為非託管,治理的是支出權限而非資金本身。被抓取網址與付款意圖會傳送至所設定的引擎及付費網站。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Rein,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

@reinconsole/mcp

The Rein guard, as an MCP server. Point any MCP-capable harness at it and its agent gets a spend-governed fetch: every x402 paywall is policy-checked, receipted and observable before a cent moves.

Rein is non-custodial. It governs an agent's authority to spend, not the funds.

Install

The fastest start is a free testnet sandbox -- no account, no signup:

bash
npx @reinconsole/init

It creates an agent on the hosted engine with a starter policy (Base Sepolia, $0.004 per-call cap), a test wallet with a little test USDC, and rein-agent.json, then prints this config with the path filled in:

json
{  "mcpServers": {    "rein": {      "command": "npx",      "args": ["-y", "@reinconsole/mcp"],      "env": { "REIN_AGENT_FILE": "/path/to/rein-agent.json" }    }  }}

The file supplies the engine URL, agent id, API key and wallet, so keys never sit on a command line or in the config. The sandbox lasts 7 days; npx @reinconsole/init --claim keeps it by signing in with GitHub or an Ethereum wallet.

Your own engine

Point it at any policy engine with variables instead of the file:

json
{  "mcpServers": {    "rein": {      "command": "npx",      "args": ["-y", "@reinconsole/mcp"],      "env": {        "REIN_ENGINE_URL": "http://127.0.0.1:8787",        "REIN_AGENT_ID": "agt_01J..."      }    }  }}

That is advisory mode: paywalls are evaluated against policy and reported, and nothing is ever paid. Add REIN_PAYER_PRIVATE_KEY to settle allowed payments.

npx -p @reinconsole/policy-engine rein-policy-engine runs an engine locally on 127.0.0.1:8787; see @reinconsole/policy-engine for registering an agent and writing a policy.

When the server is up it prints exactly one line to stderr. A harness shows nothing else, so if this line is missing the server is not running, and whatever preceded it is why:

[rein-mcp] 0.2.0 ready on stdio for agt_01J... via http://127.0.0.1:8787 (advisory -- no payer configured)

Environment

VariableRequiredMeaning
REIN_AGENT_FILEnoPath to the rein-agent.json that npx @reinconsole/init writes. Supplies the four values below; any variable set explicitly overrides its field.
REIN_ENGINE_URLyes, unless the filePolicy engine base URL.
REIN_AGENT_IDyes, unless the fileThe one agent this server speaks for. Never a tool argument.
REIN_ENGINE_API_KEYif the engine has authBearer secret for the engine.
REIN_PAYER_PRIVATE_KEYnoAgent wallet key. Omit for advisory mode: policy is checked, nothing is paid.
REIN_NETWORK_PROFILEnotestnet (default) or mainnet. Which network's 402s this server will pay; the other is refused before a signature exists. An unknown value refuses to boot.
REIN_MCP_TASK_IDnoDefault task attribution, so per-task budgets can cap this agent's work.
REIN_MCP_ESCALATION_WAIT_MSnoHold a tool call open this long waiting for a signed approval. Default 0.
REIN_MCP_MAX_BODY_BYTESnoCap on the response body returned to the model. Default 65536.

Everything is fixed at startup. Nothing here is reachable from a tool call.

REIN_NETWORK_PROFILE exists because the engine cannot draw this line: it maps Base and Base Sepolia onto the same chain, so a policy that allows one allows both, and the vendor's 402 would otherwise choose which network the agent's key spends on. The default is testnet, which means a 0.1.x install that paid mainnet 402s will refuse them until the profile is set to mainnet on purpose.

On a HOSTED engine, REIN_ENGINE_API_KEY should be an evaluate key issued with the org and narrowed to this one agent:

POST /v1/keys{ "name": "claude-desktop", "scopes": ["evaluate"], "orgId": "org_01J...", "agentIds": ["agt_01J..."] }

That is the whole blast radius of the secret sitting in a desktop config file: it can submit intents for this agent and nothing else — not another agent in the same org, not policy, not keys, not other tenants' anything. Against a self-hosted single-tenant engine, omit both fields and the key behaves exactly as it always has.

Tools

ToolRead-onlyWhat it answers
rein_fetchnoFetch a URL, paying for it only if policy allows.
rein_statusyesWhat rules govern this agent, and where it stands against them.
rein_receiptsyesWhat it has paid, and whether those payments settled.
rein_escalationsyesWhich of its payments are parked awaiting a human.
rein_heartbeatnoReport the agent alive, for dead-man monitoring.

rein_fetch is the only tool that can move money, and it is the only one without readOnlyHint.

The authority boundary

The client on the other end of this pipe is the agent -- the thing being governed. So a tool may do anything the agent could already do with its own fetch, and nothing that widens the agent's own authority.

There is deliberately no tool to approve an escalation, edit a policy, freeze or unfreeze an agent, mint an API key, or register an approver. An approval in Rein is an ed25519 signature over the decision by a registered approver key; a tool call is not a signature, and one that stood in for one would put the authority to move money behind whatever process holds the pipe. rein_escalations is read-only by construction, and a test asserts the whole tool surface rather than a sample of it, so adding an authority tool has to break a test first.

One server also speaks for exactly one agent. An agent id the caller could choose would turn an agent-scoped tool surface into a cross-agent admin API.

What a blocked payment looks like

A policy refusal comes back as a tool error -- the fetch did not happen, and a model that read it as an ordinary result would treat the explanation of a refusal as the data it asked for. The detail rides along, because the useful next move depends on which refusal it was:

  • DENIED -- final. The same request will be refused the same way.
  • ESCALATED -- parked for a human to sign. Poll rein_escalations, or move on. Nothing the agent can call will approve it.
  • ALLOWED_BUT_UNPAID -- not an error: policy said yes, but this server runs in advisory mode, so the 402 is returned unpaid.

Programmatic use

ts
import { createReinMcpServer } from '@reinconsole/mcp';import { StdioServerTransport } from '@modelcontextprotocol/sdk/server/stdio.js';
const server = createReinMcpServer({ engineUrl, agentId, payer });await server.connect(new StdioServerTransport());

createToolContext and reinTools are exported too, for embedding the same tools in a server that carries others.

License

MIT

來源:services/mcp/README.md,提交 efbb433

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.5.1最新Oct 6, 2026