
VeilQuota
io.github.omkardongrev0.1.0更新於 Oct 10, 2026
Private OCR, web search, and attested AI chat, paid with anonymous credits bought with shielded ZEC
概覽
讓助理使用本機密封錢包中的預付匿名額度,執行付費的私密 OCR、網頁搜尋與可驗證加密聊天。
- 功能
- 提供對本機 PNG/JPG 圖片進行 OCR、取得 Brave 網頁搜尋摘錄作為依據,以及向可驗證飛地發起端對端加密聊天的工具。每次呼叫都以預付匿名額度(Privacy Pass Blind RSA 權杖)支付,額度以屏蔽式 Zcash 購買。wallet_balance 工具回報可用額度與支出政策,quote_ocr 在支出前提供價格。不使用帳號或 API 金鑰。
- 適用情境
- 當助理需要 OCR、網頁搜尋或聊天呼叫,且不希望這些呼叫與帳號或 API 金鑰關聯,並可接受按次以匿名預付額度付費時使用。適合注重隱私、不希望閘道把呼叫關聯到同一付款方的工作流程。
- 執行需求
- 透過 npx @veilquota/mcp 以本機程序執行,支援 Linux x64(glibc)與 macOS arm64;其他平台需從原始碼建置 veilquota-checkout 並放入 PATH。需要先用 setup 建立錢包,在原生錢包終端提示字元輸入密語,並以屏蔽式 ZEC 或試用連結購買額度。VEILQUOTA_HOME 設定錢包目錄(預設 ~/.veilquota)。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 VeilQuota,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
@veilquota/mcp
MCP server (TypeScript SDK v2, stdio, protocol 2026-07-28) for private paid tools: OCR, web search, and attested, end-to-end encrypted AI chat. Each call is paid with anonymous prepaid credits (Privacy Pass Blind RSA tokens) bought with shielded Zcash. There is no account and no API key, and the gateway cannot link two calls to one payer.
Unaudited, capped mainnet beta. IP address and timing are not hidden.
Quickstart
Credits: buy 100 for 0.0005 ZEC at the hosted wallet with Zodl, or use a try-link someone gave you. The wallet lives in ~/.veilquota (0700), sealed with your passphrase; set VEILQUOTA_HOME to move it. Prebuilt binaries ship for Linux x64 (glibc) and macOS arm64. On other platforms, install veilquota-checkout from source and it is found on PATH.
Tools
What an agent structurally cannot do
These limits come from where keys and rules live, not from instructions to the model:
- It cannot touch money. No Zcash key, wallet passphrase, or credit token is in this process or in model context. It can spend only credits already in the wallet. Buying more needs a person paying a ZEC invoice.
- It cannot pay anyone else. The wallet agent pins one gateway origin at startup. No tool argument names a payee or a price.
- It cannot exceed the caps. The wallet agent, not this server, enforces a per-request ceiling, a session cap, and a daily cap. It also enforces a tool allowlist and a pause switch. The rules live in a policy file beside the wallet and are re-read before every spend.
- It cannot approve its own spend. A spend above the approval threshold is put to the user as an MCP elicitation. Only the user's answer sets
approved; no tool argument can. If the host cannot show the prompt, the spend is refused and nothing is charged. - It cannot be charged twice. A lost response is retried with the same arguments; the retry returns the original result.
Spending policy
The defaults are: all tools allowed, session cap 50, daily cap 100, and approval for anything above 4 credits, so OCR asks first. An exact retry of a spend whose credits are already locked is never blocked, even while paused, so credits are never stranded. A refunded spend gives its credits back to the caps. Daily totals are kept on this machine in WALLET.spend-day.json, and nothing about them reaches a gateway.
Commands
Passphrases are typed only at the native wallet binary's terminal prompt, and packs are read from a hidden prompt. Neither appears in argv, shell history, or MCP configuration.
來源:packages/mcp-ocr/README.md,提交 aa6fbb5
工具
0版本歷史
1- v0.1.0最新Oct 10, 2026
