
Rail
io.github.tstockham96v0.1.1更新於 Sep 29, 2026
Budgets, propose-then-approve, and receipts for agents that buy for a human. Dry-run by default.
安裝
在 SourceWeft 中
- 開啟 儀表板中的 Rail,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
Rail MCP
Rail is a budget, approval and receipt layer that agents call when they buy something on a human's behalf, dry-run by default, wrapping Stripe Link for settlement rather than issuing cards.
It is not a marketplace, storefront, or outreach tool. Rail owns the budget, the approval gate, and the receipt ledger.
Quickstart
Requires Node.js 20+. Run the published package with npx -y rail-mcp. Default mode is dry-run: no network and no charges.
Claude Desktop and any other host that takes an mcpServers block:
Cursor: one-click install (install links). The config value is the base64 of {"command":"npx","args":["-y","rail-mcp"]}.
Install Rail in Cursor
Grok Bot: add a custom MCP with npx -y rail-mcp.
Do not put Stripe or Link secrets (STRIPE_SECRET_KEY, LINK_ACCESS_TOKEN, or live-spend flags) in this shared snippet. Real charges stay off unless those gates are set on purpose, outside the shared config. See Stripe Link seam.
Ledger files (budget.json, proposals.json, receipts.json) are written to ~/.rail in the user home directory, or to RAIL_DATA_DIR when that is set. They are local state, not part of the npm package. The default does not follow the process working directory, so a host that starts the server from / still writes under the home directory.
Example
Set a budget, propose a purchase, have a human approve it, then read the receipt. Dry-run moves no money off the machine.
set_budget→{ "amount_usd": 50, "note": "week1" }propose_purchase→{ "merchant": "Acme", "amount_usd": 12, "rationale": "need widgets" }get_budgetstill shows remaining50.00andopen_proposals: 1. The proposal is pending until a human decides.decide_proposal→{ "proposal_id": "prop_…", "decision": "approve" }get_receiptsreturns onesettled_dry_runreceipt with asettlement_ref. Remaining budget is38.00.
Rejecting spends nothing. refund_receipt reverses a dry-run settlement and restores the budget.
Tools
Permission model
Proposing a purchase is cheap. Settling one is not. An agent may record intent without moving money. The human should confirm the call that settles a purchase or reverses a receipt.
Hosts should read title, description, and annotations from tools/list. Every hint is set explicitly. The spec defaults (readOnlyHint false, destructiveHint true, openWorldHint true) would otherwise treat every tool as a destructive open-world write. Rail's ledger is local. Default mode is dry-run: no network and no charge.
destructiveHint is the confirmation signal, and it is true only for decide_proposal and refund_receipt. openWorldHint is false on every tool: dry-run never leaves the ledger, and live Link stays behind separate environment gates. Annotations are hints for the host. They do not themselves move money.
Mode defaults to RAIL_MODE=dry_run. Money is stored as integer cents; tools display USD with 2 decimals. IDs: prop_…, rcpt_…, dry-run Link refs lsrq_dry_… on settlement_ref.
Local checkout
tsx is a dev dependency for dogfood in this repo. npm run smoke runs the TypeScript sources directly and does not need a build. npm start compiles first, then runs dist/index.js (the same file the rail-mcp bin points at).
npm run smoke forces RAIL_MODE=dry_run, never enables live charge gates, and writes the ledger only under temporary directories it creates and deletes. ./data, ~/.rail, and RAIL_DATA_DIR are left untouched even when RAIL_DATA_DIR is set in the environment. One check starts the server with its working directory at / and HOME pointed at a temp directory, then calls a tool. That call succeeds, and the ledger for that check is created under the temp home rather than /data or the real ~/.rail. An explicit RAIL_DATA_DIR still overrides the default in that launch.
Stripe Link seam
Rail asks Link for a one-time credential. Rail still decides budget and policy and writes the receipt. This seam does not issue cards and does not render UI.
RAIL_MODE=dry_run(default, including when unset):createSpendRequestreturns a fake Link spend-request id and statusdry_run_pending_human. No Stripe or Link HTTP. Approve stores that id assettlement_refon asettled_dry_runreceipt and decrements remaining budget.RAIL_MODE=livewithout gates: throwslive mode not enabled — set keys and get explicit human approvalunless bothSTRIPE_SECRET_KEYandRAIL_LIVE=1are set. The proposal stays pending and no receipt is written.- Live with those two gates: the
POST https://api.link.com/spend_requestsbody is scaffolded only (seesrc/stripeLink.ts). Nothing is sent unlessRAIL_ALLOW_LIVE_CHARGE=1. RAIL_ALLOW_LIVE_CHARGE=1: the only branch allowed to call Link, and only ifLINK_ACCESS_TOKENis also set.STRIPE_SECRET_KEYis a presence gate and is never sent. There is no Stripe Issuing card create. Docs: Link CLI, link-cli, Issuing for agents.- Live spend stays off until those env vars are set on purpose. A posted Link request is stored as
link_pending_humanand does not decrement the dry-run budget. CI andnpm run smokestay on dry-run and do not charge.
Explicit non-goals
- No marketplace UI
- No outreach / messaging
- No card issuing
- No real charges in dry-run, CI, or smoke
License
MIT. Copyright 2026 Thomas Stockham.
來源:README.md,提交 7190385
工具
0版本歷史
1- v0.1.1最新Sep 29, 2026

