Lets an agent pay for x402 APIs in USDC on Arc, under a spending policy it cannot change.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
One-click editor setup isn’t available for this listing yet — we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.
Payments for AI agents on Arc, Circle's USDC-native L1. One tool call and an agent can buy an API call for a fraction of a cent: the rail reads the x402 price, applies a spending policy the model cannot change, verifies the seller, pays gas-free through Circle Gateway, and writes the receipt to a ledger.
TypeScript monorepo, npm workspaces, Node 22. Site: cra-agent.tech.
Status: the buyer agent, the seller middleware and the MCP server are built and exercised end to end on
Arc testnet. See docs/arc-verification.md for every value verified against docs.arc.io.
| Package | What it does |
|---|---|
packages/accounting | The only module allowed to do arithmetic on USDC amounts. Branded types Usdc6 (ERC-20 interface) and Usdc18 (native/gas interface), dust-preserving conversions, property tests |
packages/policy | Pure spend control: caps per payment, per day and per counterparty, rate limit, allow/deny lists, required identity, seller-bond hook. Compact syntax daily=5,per_seller=0.5,… |
packages/ledger | Every payment attempt (quoted / rejected / signed / settled / failed) with amount, counterparty, latency and transaction. MemoryLedger and PgLedger; exposure() per counterparty |
packages/identity | Signing with an explicit scheme parameter (secp256k1 today, post-quantum reserved) and ERC-8004 resolution, fail closed. registerIdentity() mints the agent identity |
packages/router | The buyer rail: rail.quote(url) and rail.fetch(url) over x402 with Circle Gateway batched settlement (gas-free) or the standard on-chain exact scheme. chooseRail() is pure: nanopayment vs escrow |
packages/escrow | The ERC-8183 rail for jobs: createJob, setBudget, fund (with USDC approval), submit, complete/reject, claimRefund. ABI taken from the verified implementation on chain; the evaluator is injected |
packages/seller | createSeller().route("GET /x", "$0.001") for Hono, createExpressSeller() for Express. Payments verified and settled by Circle Gateway; any x402 buyer can pay |
packages/collector | Block-zero collector: blocks, per-block stats by operation, contract deploys, base fee inputs, per-provider RPC observations. Optionally transactions, receipts, logs and revert reasons. Append-only Postgres with the raw JSON-RPC preserved |
packages/api | Read API over the collector database (Hono): /v1/network, /v1/fees, /v1/fees/estimate, /v1/activity, /v1/deploys, /v1/rpc, /v1/fx, /v1/token, /v1/health, plus the paid /v1/paid/* routes, described for agents and directories at /openapi.json. Also serves the website |
packages/web | The site: product landing (/), live network page (/network) and token page (/token, price, burns and payouts). Plain HTML, CSS and TypeScript, hand-drawn SVG charts |
packages/mcp | MCP server over stdio: arc_quote, arc_pay, arc_balance, arc_deposit, arc_ledger, arc_policy, plus the escrow tools arc_job_create, arc_job_fund, arc_job_status, arc_job_decide, arc_job_submit. Also a CLI |
Local Postgres (Homebrew, keg-only):
As an MCP server, for any MCP client:
The policy is read from the environment, not from the conversation: the model cannot raise its own limit, and never sees the key.
Setting SELLER_ADDRESS in .env turns on our own paid routes: the API then serves /v1/paid/*
(catalogue at /v1/paid) priced per call, described for agents at /openapi.json.
A route can also be offered on a second network at the same price. The x402 discovery catalogues are
filled by the facilitator that settles a payment, and no facilitator settles Arc except Circle's,
which does not catalogue: DISCOVERY_FACILITATOR_URL (or CDP_API_KEY_ID / CDP_API_KEY_SECRET)
adds that rail, and scripts/pay-on-network.mts <url> [network] buys a route there once so the
catalogue picks it up. The Arc rail is untouched and our own buyer keeps choosing it.
GET /v1/paid/selftest/fail, a priced
route that always answers 500, so anyone can check it: the response is 500, the receipt reads
not_charged, and the Gateway balance does not move.cra-agent verify receipt.json recovers the signer and redoes the arithmetic, with no key and no
network. Be clear about what that proves: the agent's key issued this statement and nobody altered
it since. It is the rail vouching for its own decision. The independent half is the settlement.cra-agent proof (MCP: arc_proof) matches
settled payments to the on-chain USDC transfer that carried them and stores the hash in the ledger.collector_state.parent_hash discontinuities. Never auto-fixes.latest, finalized and safe, storing
head_observations (per-provider lag and latency) and evaluating alerts.eth_call against the parent block;
runtime bytecode size and hash for deploys.TOKEN_ADDRESS is set) it
records each swap against USDC at the rate it executed. Transfers are netted per pair of
addresses, so a token that taxes transfers is priced correctly, and a hop that merely forwarded
what it was handed is skipped instead of guessed. Served at /v1/fx?symbol= and, with the size
curve and venues, at /v1/paid/fx/execution.COLLECTOR_MODE=light (default: blocks, per-block stats by operation, deploys, RPC
observations, around 0.5 GB/day) or full (also transactions, receipts, logs and reverts).GET :8790/health (JSON, 503 when lagging or stalled), GET :8790/metrics (Prometheus).Database summary: npm run status -w @cra-agent/collector.
deploy/setup.sh installs everything on an Ubuntu VPS running Caddy (Node 22, Postgres 17, systemd units
for the collector and the API, a Caddy site). See deploy/README.md.
npm test runs the vitest suites in packages/*/test: property tests on the accounting module
(fast-check), block parsing, RPC pool failover, spend policy, rail choice, signing, escrow mapping.
CI runs them on every push together with a ledger round-trip against a real Postgres.packages/collector/sql/NNN_*.sql and are applied in order by
packages/collector/src/db/migrate.ts (table schema_migrations), automatically when the collector
starts or via npm run db:migrate. The ledger has its own in packages/ledger/sql, applied by
PgLedger.migrate().packages/accounting..env (git-ignored) or a file with chmod 600, never in chat or in code.MIT.
No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/cra-agent)<a href="https://allmcps.com/mcp/cra-agent"><img src="https://allmcps.com/api/badge/cra-agent?style=directory" alt="CRA AGENT on AllMCPs" /></a>