The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Agentpay listing page.
AgentPay MCP is a stdio Model Context Protocol server for x402 payments and wallet operations. It exposes Agent Wallet SDK functions as MCP tools and loads a caller-controlled signing key from the local process environment.
The current npm package is agentpay-mcp v4.1.17.
Check the installed command without loading wallet credentials:
Use the AgentPay Wallet Starter for a no-funds verification of allowed, approval-required, and blocked policy outcomes.
Wallet tools read the following environment variables:
| Variable | Required for wallet tools | Meaning |
|---|---|---|
AGENT_PRIVATE_KEY | Yes | Local hot-wallet signing key |
AGENT_WALLET_ADDRESS | Yes | Deployed AgentAccountV2 address |
CHAIN_ID | No | 8453 or 84532; defaults to Base mainnet |
RPC_URL | No | Caller-selected Base RPC endpoint |
FACTORY_ADDRESS | For deployment | Wallet factory address |
NFT_CONTRACT_ADDRESS | For deployment | Token contract bound to a wallet |
SESSION_TTL_SECONDS | No | Local session lifetime in seconds |
Example MCP configuration:
Do not commit a real signing key. Use the client or operating system's secret mechanism where one exists. Start on Base Sepolia before using Base mainnet.
The tool registry in src/index.ts exposes these groups:
| Group | Examples |
|---|---|
| Wallet | deploy_wallet, get_wallet_info, queue_approval |
| Payments | send_payment, x402_pay, x402 session tools |
| Policy | set_spend_policy, check_budget, OTel budget tools |
| Tokens | Lookup, custom-token registration, balances, and transfers |
| Execution | Swap, USDC bridge, and mutual-stake escrow |
| Trust | ERC-8004 identity, reputation, and UAID verification |
| History | get_transaction_history for wallet contract events |
Tool schemas and handlers live under src/tools/.
These boundaries matter more than the feature list:
AGENT_PRIVATE_KEY into its local Node.js process and uses
viem for signing. Protect the process, environment, and MCP client config.set_spend_policy stores policy in the MCP server process. The same agent can
call that tool again, and a process restart clears its rolling state.AgentAccountV2. set_spend_policy does not write those contract limits.get_transaction_history reads on-chain wallet events. It is not an MCP
request log and does not record rejected pre-chain attempts or read-only
calls.src/utils/client.ts.Read docs/security-posture.md for the detailed
control map and known limitations.
The repository keeps deeper interoperability and buyer-safety evidence in versioned documents:
docs/agentpay-buyer-flow-parity.md
covers typed payment errors and buyer flow behavior.docs/paid-mcp-gateway-hardening.md
covers default-deny controls and quota envelopes.docs/agentpay-five-tool-parity-proof.md
records the five-tool parity check.docs/agentpay-escrow-reputation-boundary.md
defines the escrow and reputation boundary.docs/paid-mcp-proxy-discovery-readiness.md
records discovery readiness evidence.docs/x402-chain-neutral-gateway-profile.md
defines the packaged chain-neutral profile.docs/x402-dynamic-paid-mcp-manifest-drift.md
documents checks for stale paid-tool metadata.docs/mcp-registry-listing-proof.md
and llms.txt expose directory metadata.docs/smithery-paid-mcp-installation.md
and
examples/smithery-paid-mcp-installation
document the packaged Smithery path without asserting a live listing.docs/paid-provider-health-proof.md
defines provider-health evidence.docs/hosted-x402-proxy-verification.md
defines hosted-proxy preflight checks.docs/x402-native-vs-stripe-proxy.md
separates local spend control from hosted proxy billing.docs/dependency-pin-policy.md defines the
release gate for payment-critical packages.AgentPay pins viem exactly at 2.56.0.
The directory comparison was captured against agentpay-mcp@4.1.9; the
package version at the top of this README is the current release.
The CI workflow is separate from scheduled daily review and repair workflows. A scheduled-review failure is not a product-test result, and a repair success does not replace CI.
SECURITY.md.CONTRIBUTING.md.MIT. See LICENSE.