Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Transports: stdio vs HTTP
  • State of MCP (stats)
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI โ†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE โ†— (opens in a new tab)
  • llms.txt โ†— (opens in a new tab)
  • Catalog JSON โ†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub โ†— (opens in a new tab)
  • Status โ†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
ยฉ 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. ๐Ÿ”’ Security
  3. Scanpay
Scanpay logo
Health: ActiveRecent health check succeeded.Last checked 10/4/2026, 8:01:49 AM

Scanpay

User RatingsBe the first to rate and review this MCP server!
View RepositoryVisit Website
securitycode-scanningmcpsolanaast

Scans Python and JavaScript/TypeScript code for 45+ vulnerability patterns through an MCP tool with optional Solana payments.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent โ€” or use 1-click editor setup below.

Add to CursorAdd to VS Code
Not yet automatically verified

We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag โ€” we're steadily working through the catalog.

Manual Client & Custom JSON ConfigExpand JSON โ–พ

Client Config & Setup

Configure Environment Variables (API Keys, Tokens, Options):
Add required secrets below โ€” values are included directly in the generated snippet so you can copy and paste with confidence.
Quick Add:
Choose your client or environment
Target File:~/Library/Application Support/Claude/claude_desktop_config.json
claude_desktop_config.json
{
  "mcpServers": {
    "scanpay": {
      "command": "npx",
      "args": [
        "-y",
        "scanpay-mcp-server"
      ],
      "env": {
        "SCANPAY_URL": "YOUR_VALUE_HERE",
        "SCANPAY_PAYMENT_MODE": "YOUR_VALUE_HERE",
        "SCANPAY_MERCHANT_WALLET": "YOUR_VALUE_HERE",
        "SCANPAY_PRICE_LAMPORTS": "YOUR_VALUE_HERE",
        "SCANPAY_RPC_URL": "YOUR_VALUE_HERE",
        "SCANPAY_PORT": "YOUR_VALUE_HERE"
      }
    }
  }
}

๐Ÿ’ก Paste the JSON block into your client's configuration file under mcpServers, then restart the application.

Install Directory Badge Claim listing Alternatives๐Ÿ”’ More in Security

Overview

The scanpay MCP server lets AI agents submit Python and JavaScript/TypeScript source for deterministic AST-based security checks. It exposes a `scan_code` tool through an npm-launched MCP process and sends scan requests to a configured ScanPay API. Reach for it when generated code needs checking before execution, review, or deployment. Payment may be required when the connected API runs in a paid Solana mode.

Use cases

โ€ขScan generated code before execution
โ€ขGate Python and JavaScript changes in CI/CD
โ€ขCheck source during code review
โ€ขDetect risky patterns in IDE workflows

Key features

โ€ข45+ deterministic vulnerability patterns
โ€ขPython and JavaScript/TypeScript AST analysis
โ€ขMCP `scan_code` tool
โ€ขSolana x402 v2 payment flow
โ€ขSARIF reports
โ€ขBatch scanning

Capabilities & Tool Schemas

Inspect callable tools, capabilities, and parameters exposed to AI agents by Scanpay.

Extracted Tool Capabilities
45+ deterministic vulnerability patterns
Python and JavaScript/TypeScript AST analysis
MCP `scan_code` tool
Solana x402 v2 payment flow
SARIF reports
Batch scanning

How Scanpay works

What scanpay does

The scanpay MCP server gives AI agents a code-scanning tool for Python, JavaScript, TypeScript, and TSX source. Its analysis is rule-based and deterministic: identical input produces the same result, and the scanner does not execute submitted code or use AI inference. Findings identify matched rules, severity, messages, and source lines, along with a count by severity.

The scanner covers more than 45 vulnerability patterns. Examples include Python eval() and exec() usage, shell-enabled subprocess calls, unsafe deserialization with pickle.loads(), os.system(), SQL injection patterns, path traversal, and hardcoded credentials. JavaScript and TypeScript checks include eval(), innerHTML, document.write(), new Function(), SQL injection patterns, and prototype pollution.

How it works

The MCP process is started with npx and configured with a SCANPAY_URL value that identifies the ScanPay HTTP API. An agent calls scan_code, and the MCP server forwards the source and language to the API's scan endpoint. The response contains a status, findings, and a summary with total, critical, high, medium, and low counts.

When the API requires payment, the request follows an x402 v2 flow on Solana. The API first returns HTTP 402 with payment information. A client pays 0.0007 SOL to the configured merchant wallet, then retries with an X-PAYMENT header containing proof of payment. The API verifies the payment before returning scan results.

Setup and configuration

Run the MCP process with the package command shown below:

config.json
{
  "mcpServers": {
    "scanpay": {
      "command": "npx",
      "args": ["-y", "scanpay-cli", "scanpay-mcp"],
      "env": {
        "SCANPAY_URL": "https://repository-nil-camcorder-divx.trycloudflare.com"
      }
    }
  }
}

The repository also documents self-hosting the API with Python: install the requirements, run python main.py, and use the resulting local address as the MCP endpoint. API configuration includes payment mode, merchant wallet, price in lamports, Solana RPC URL, and listening port. The documented default price is 700,000 lamports, equivalent to 0.0007 SOL.

Tools and capabilities

  • Calls scan_code to inspect source before an agent runs or uses it.
  • Accepts Python and JavaScript/TypeScript-family code.
  • Uses Python's AST support and tree-sitter for language parsing.
  • Returns structured vulnerability findings and severity totals.
  • Supports batch scanning through the underlying ScanPay service.
  • Provides SARIF output as an available scan format.
  • Exposes health and product-pricing endpoints through the HTTP API, although the README only documents scan_code as the MCP tool.

Limitations and notes

The MCP server is a client of the ScanPay API; it does not itself establish that the API is available or free to use. Paid deployments require Solana payment handling, and the documented live flow uses mainnet pricing of 0.0007 SOL per scan. Self-hosted configurations can disable payment according to the API configuration.

Results are limited to the scanner's implemented rules and supported languages. Static analysis can report matched patterns, but the README does not claim complete vulnerability coverage. The scanner does not execute code, and its output should therefore be treated as a security-check result rather than proof that code is safe.

The repository lists MIT licensing. The live API addresses in the README are public deployment URLs and may differ between examples, so configure SCANPAY_URL explicitly instead of assuming one endpoint.

Read the full README โ†’View source on GitHub โ†’

Related MCP Servers

View all in Security View all alternatives
  • Solana Security Standard logoSolana Security Standard

    Scan Solana/Anchor code against the Solana Security Standard and serve the ruleset to MCP clients.

    ๐Ÿ”’ Security1 views
    Compare vs Solana Security Standard โ†’
  • Agent Security Scanner MCP logoAgent Security Scanner MCP

    Security layer for AI agents: blocks prompt injection, detects fake packages, scans vulnerabilities.

    ๐Ÿ”’ Security1 views
    Compare vs Agent Security Scanner MCP โ†’
  • Dvalincode logoDvalincode

    Deterministic security scanning that needs no model or API key, plus governed coding tasks.

    ๐Ÿ”’ Security1 views
    Compare vs Dvalincode โ†’
  • MCP Fortress logoMCP Fortress

    Security scanner for MCP servers with vulnerability detection and prompt injection analysis.

    ๐Ÿ”’ Security2 views
    Compare vs MCP Fortress โ†’

Reviews

No reviews yet โ€” be the first to share how this listing worked for you.

Frequently Asked Questions about Scanpay

scanpay is an MCP server that connects AI agents to the ScanPay code security API. Its main tool, `scan_code`, analyzes Python and JavaScript/TypeScript source with deterministic AST-based rules, returning vulnerability findings and severity totals. Paid API deployments use x402 v2 Solana micropayments before scans run.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewScanpay AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/scanpay?style=directory)](https://allmcps.com/mcp/scanpay)
HTML Embed
<a href="https://allmcps.com/mcp/scanpay"><img src="https://allmcps.com/api/badge/scanpay?style=directory" alt="Scanpay on AllMCPs" /></a>

Technical Specs & Signals

Category๐Ÿ”’Security
More technical detailsExpand โ–พ
TransportSTDIO
RuntimeNode.js
LicenseMIT
ClientsClaude Desktop, Cursor, Cline / VS Code, Windsurf, Claude Code, VS Code (GitHub Copilot), Zed, OpenAI Codex CLI, Gemini CLI, JetBrains AI Assistant, Roo Code, Continue, LM Studio
Last updatedOct 8, 2026
5/5 checks healthy over the last 40d
Views0
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars0
GitHub Star CountTotal stargazers on GitHub representing community popularity (0 stars).
Last commit1mo ago
Last Repository CommitThe most recent commit or push recorded for this server's GitHub repository.Last commit on Aug 19, 2026
37Quality signal: Fair ยท 37/100How this signal is calculated โ–พ
Server availabilityNot measured

Not scored for repo-hosted servers โ€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools16/30
Adoption & activity2/15
Community engagement0/10

A guidance signal from public completeness & health data โ€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

Supply-chain signal

No high-severity advisories surfaced by our automated scan.

Critical 0High 0Medium 0Low 0

Scanned 4d ago via OSV.dev ยท scanpay-mcp-server (npm)

โ˜… Spotlight Slot

Feature Your MCP Server

Get maximum visibility for your server across our directory, search results, and detail pages.

Spotlight Your Server

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge โ€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it โ€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in ๐Ÿ”’ Security โ†’Best MCP servers for Security โ†’Alternatives to Scanpay โ†’Install in Claude DesktopInstall in CursorInstall in VS CodeSetup guides for all 13 MCP clients