Preflight, approve, and prove consequential agent actions with signed evidence and x402 tools.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)
Runnable MCP server and integration examples for Hermes Plant, the Agent Commerce Assurance layer that lets AI agents preflight, approve, and prove consequential actions. Start with a one-cent action-safety check, route only high-risk actions into signed review evidence, and pay per call over x402.
What's here: a runnable stdio MCP bridge for registry crawlers and local clients, plus drop-in examples in curl, TypeScript, Python, CrewAI, LangChain, and MCP client configs for Claude Desktop / Cline / Cursor.
Install the public, fail-closed Action Safety skill for Codex, Claude Code, Cursor, and other Agent Skills-compatible clients:
The skill calls the one-cent quick gate before an exact consequential action, binds the result to that unchanged action, and escalates high or critical risk only when the additional $0.25 is authorized. Review triage is never treated as human approval and the skill never expands the caller's permissions.
Source: skills/protect-agent-action Β· Install guide and trust boundary
For the complete production tool surface, use the canonical Hermes Plant β Agent Commerce Assurance connector on Glama. It exposes Action Safety, Spend Assurance, signed evidence, payment-policy checks, and the component x402 tools through the live Streamable HTTP endpoint.
This repository is the portable, no-secret discovery bridge. It lets registry crawlers and local clients inspect the live catalog and payment contracts without signing a wallet message or spending funds. The hosted connector is the buyer-facing path for invoking the production tools.
This repo is arranged for Glama to build and inspect the MCP server without secrets or funded wallets:
glama.json declares the GitHub maintainer.Dockerfile starts the stdio MCP server in mcp-server/.npm run smoke:mcp lists all local MCP tools and fetches the live x402 manifest.A Glama release is still an account-side action, not a GitHub release. After claiming the server in Glama, use the Dockerfile admin page to deploy the build, wait for the build test to pass, then publish a Glama release version. That release unlocks Glama's Server Coherence and Tool Definition Quality scoring.
Hermes Plant governs consequential actions and payments; these independent servers cover adjacent layers of an agent stack:
These links describe functional complementarity, not partnerships or endorsements.
| Workflow | Use it for | Tracked entrypoint |
|---|---|---|
| Action Safety | Preflight shell, Git, SQL, deploy, x402, and MCP actions; escalate high-risk work into review plus a signed receipt. | Open workflow |
| Spend Assurance | Check payment policy, wallet context, and evidence before an agent spends. | Open workflow |
| Investment Evidence | Run deterministic underwriting and return verifiable evidence in one paid call. | Open workflow |
Use the free API key for up to 250 calls/month, the $29/month Agent API Pass for regular volume, or per-call USDC on Base. Public proof and machine-readable contracts are available at hermesplant.com/proof and hermesplant.com/openapi.json.
Nineteen hosted x402 endpoints remain available as composable utilities:
| Endpoint | Use it for | Hosted path |
|---|---|---|
| DealAnalyzer | DCF, IRR, XIRR, NPV | /agent-services/dealanalyzer |
| Waterfall | LP/GP private-equity distribution waterfalls | /agent-services/waterfall |
| Options | Black-Scholes pricing + Greeks | /agent-services/options |
| Bond | Yield, duration, convexity | /agent-services/bond |
| CashflowLens | Cash-flow projection + sensitivity | /agent-services/cashflowlens |
| PortfolioGuard | Portfolio risk scoring | /agent-services/portfolioguard |
| WalletGuard | Wallet AML + sanctions screening | /agent-services/walletguard |
| EmailGuard | Email reputation + risk | /agent-services/emailguard |
| DestructGuard | Block destructive AI-agent commands | /agent-services/destructguard |
| MCP risk | Score MCP server risk before connecting | /agent-services/mcp-risk |
| Evidence | Evidence bundle for paid calls | /agent-services/evidence |
| Payment policy | Inspect/score an x402 payment policy | /agent-services/payment-policy |
| ReviewQueue | Human-in-the-loop approval routing | /agent-services/reviewqueue |
Agents discover endpoints through OpenAPI, llms.txt, the x402 manifest, the API catalog, MCP metadata, or agent skills. The workflow links above carry source-specific attribution so registry traffic can be evaluated against paid calls instead of impressions.
402 Payment Required plus a PAYMENT-REQUIRED header carrying the price, network, asset, recipient, and timeout.PAYMENT-SIGNATURE header.200 OK with the result plus a PAYMENT-RESPONSE header.The full spec lives at github.com/x402-foundation/x402.
These let any agent or human self-onboard without help:
The runnable stdio server exposes five read-only discovery tools:
| Tool | Purpose |
|---|---|
hermesplant_x402_manifest | Fetch the live x402 manifest before paid calls. |
hermesplant_llms_catalog | Fetch the agent-readable llms.txt catalog. |
hermesplant_api_catalog | Fetch the machine-readable API catalog. |
hermesplant_mcp_server_card | Fetch the hosted MCP server descriptor. |
hermesplant_list_hosted_tools | Introspect the hosted Streamable HTTP MCP endpoint and list its advertised tools. |
These local tools do not sign wallet messages, approve transactions, call paid endpoints, or spend USDC. They expose the discovery layer that clients need before invoking paid hosted tools.
Pick the runtime that matches your stack:
| Runtime | Folder | Notes |
|---|---|---|
curl / Bash | curl/ | Pure shell; useful for inspecting the 402 handshake |
| TypeScript | typescript/ | Uses @x402/fetch + @modelcontextprotocol/sdk |
| Python | python/ | Uses the x402 package |
| CrewAI | crewai/ | Finance-agent crew calling Hermes endpoints |
| LangChain | langchain/ | LangChain Tool wrapping Hermes |
| MCP config | mcp-config/ | One-paste config for Claude Desktop / Cline / Cursor |
| MCP server | mcp-server/ | Runnable stdio MCP bridge for discovery, server-card inspection, and hosted-tool listing |
This repo includes a root glama.json and root Dockerfile for MCP registry crawlers:
The container starts the stdio MCP bridge in mcp-server/, which exposes Hermes Plant discovery tools and hosted MCP metadata without requiring API keys.
The guarded paid-call examples require:
8453.EVM_PRIVATE_KEY plus the explicit opt-in HERMES_ALLOW_PAYMENT=1.The included CashflowLens clients cap payment requirements at $0.20 USDC and register only Base mainnet. Leave the opt-in unset for imports and tests. Never commit a private key. These production examples do not claim testnet support; use an x402 test resource server for testnet integration work.
These examples target the production deployment at hermesplant.com. Endpoint signatures may evolve, so cross-reference openapi.json and the /.well-known/x402 manifest before going to production.
Issues and PRs welcome. New runtime? New framework? Open a PR with one working example and a tight README.
MIT - see LICENSE.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/hermes-plant-agent-commerce-assurance)<a href="https://allmcps.com/mcp/hermes-plant-agent-commerce-assurance"><img src="https://allmcps.com/api/badge/hermes-plant-agent-commerce-assurance?style=directory" alt="Hermes Plant β Agent Commerce Assurance on AllMCPs" /></a>