# scanpay [Health: Active]

**Category:** 🔒 Security  
**Repository:** https://github.com/Misterio070/scanpay  
**GitHub Stars:** 0  
**npm Downloads (last month):** 172  
**Views:** 0  
**Installs:** 0  
**Upvotes:** 0  
**Directory Page:** https://allmcps.com/mcp/scanpay

## Description
Code security scanner for AI agents. 45+ vulnerability patterns, AST analysis, Solana micropayments.

## Claude Desktop Quick Installation
Install path detected from listing signals. Uses `npx` (confidence: high):

```json
"mcpServers": {
  "scanpay": {
    "command": "npx",
    "args": ["-y","scanpay-mcp-server"],
    "env": {
      "SCANPAY_URL": "",
      "SCANPAY_PAYMENT_MODE": "",
      "SCANPAY_MERCHANT_WALLET": "",
      "SCANPAY_PRICE_LAMPORTS": "",
      "SCANPAY_RPC_URL": "",
      "SCANPAY_PORT": ""
    }
  }
}
```

**Requires environment variables:** `SCANPAY_URL`, `SCANPAY_PAYMENT_MODE`, `SCANPAY_MERCHANT_WALLET`, `SCANPAY_PRICE_LAMPORTS`, `SCANPAY_RPC_URL`, `SCANPAY_PORT` — the values above are empty placeholders; fill in real credentials before running (see the repository for what each one is for).

## Documentation

## What scanpay does

The scanpay MCP server gives AI agents a code-scanning tool for Python, JavaScript, TypeScript, and TSX source. Its analysis is rule-based and deterministic: identical input produces the same result, and the scanner does not execute submitted code or use AI inference. Findings identify matched rules, severity, messages, and source lines, along with a count by severity.

The scanner covers more than 45 vulnerability patterns. Examples include Python `eval()` and `exec()` usage, shell-enabled subprocess calls, unsafe deserialization with `pickle.loads()`, `os.system()`, SQL injection patterns, path traversal, and hardcoded credentials. JavaScript and TypeScript checks include `eval()`, `innerHTML`, `document.write()`, `new Function()`, SQL injection patterns, and prototype pollution.

## How it works

The MCP process is started with `npx` and configured with a `SCANPAY_URL` value that identifies the ScanPay HTTP API. An agent calls `scan_code`, and the MCP server forwards the source and language to the API's scan endpoint. The response contains a status, findings, and a summary with total, critical, high, medium, and low counts.

When the API requires payment, the request follows an x402 v2 flow on Solana. The API first returns HTTP 402 with payment information. A client pays 0.0007 SOL to the configured merchant wallet, then retries with an `X-PAYMENT` header containing proof of payment. The API verifies the payment before returning scan results.

## Setup and configuration

Run the MCP process with the package command shown below:

```json
{
  "mcpServers": {
    "scanpay": {
      "command": "npx",
      "args": ["-y", "scanpay-cli", "scanpay-mcp"],
      "env": {
        "SCANPAY_URL": "https://repository-nil-camcorder-divx.trycloudflare.com"
      }
    }
  }
}
```

The repository also documents self-hosting the API with Python: install the requirements, run `python main.py`, and use the resulting local address as the MCP endpoint. API configuration includes payment mode, merchant wallet, price in lamports, Solana RPC URL, and listening port. The documented default price is 700,000 lamports, equivalent to 0.0007 SOL.

## Tools and capabilities

- Calls `scan_code` to inspect source before an agent runs or uses it.
- Accepts Python and JavaScript/TypeScript-family code.
- Uses Python's AST support and tree-sitter for language parsing.
- Returns structured vulnerability findings and severity totals.
- Supports batch scanning through the underlying ScanPay service.
- Provides SARIF output as an available scan format.
- Exposes health and product-pricing endpoints through the HTTP API, although the README only documents `scan_code` as the MCP tool.

## Limitations and notes

The MCP server is a client of the ScanPay API; it does not itself establish that the API is available or free to use. Paid deployments require Solana payment handling, and the documented live flow uses mainnet pricing of 0.0007 SOL per scan. Self-hosted configurations can disable payment according to the API configuration.

Results are limited to the scanner's implemented rules and supported languages. Static analysis can report matched patterns, but the README does not claim complete vulnerability coverage. The scanner does not execute code, and its output should therefore be treated as a security-check result rather than proof that code is safe.

The repository lists MIT licensing. The live API addresses in the README are public deployment URLs and may differ between examples, so configure `SCANPAY_URL` explicitly instead of assuming one endpoint.

_Full upstream README: https://allmcps.com/mcp/scanpay/readme_

