Screens x402 payments before settlement for injected payee addresses and sellers who never deliver.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
A payment security firewall for x402 β screen every micropayment before it settles.
Agents that pay over x402 get drained in predictable ways: secrets leak through payment metadata, captured authorizations get replayed, quoted prices get inflated, and poisoned web content tricks agents into paying addresses they never planned to pay. TollWarden is one POST before settlement that checks for all of it and returns allow / flag / block with machine-readable, per-check reasons β in ~0.6 ms.
TollWarden is advisory and non-custodial: it never touches private keys, wallets, or funds. It wraps around whatever facilitator and wallet your agent already uses. And it's a first-class x402 seller itself β its endpoints are paid via the official x402 middleware, settle through the Coinbase CDP facilitator, and carry Bazaar discovery metadata.
New here? Protect your x402 agent in 5 minutes β
The SDK (sdk/, zero dependencies) also verifies every verdict's Ed25519 attestation against a pinned key, tracks your free-call quota, and can subscribe to plans autonomously. Wallet authors get standalone verifyAttestation() / computePaymentCommitment() β and the enforcement kit: TollWardenEnforcer.guardSigner(account) wraps any viem/ethers signer so it physically refuses to sign an x402 payment authorization without a fresh, payment-bound allow-verdict.
Building on an agent framework? TollWarden ships drop-in packages that give your agent "scan before you pay" in about two lines β a toolset plus a provenance mechanism that auto-tags what the agent reads, so the prompt-injection-triggered-payment detector works without any prompt engineering:
| Framework | Package | Install |
|---|---|---|
| LangChain | langchain-tollwarden | pip install langchain-tollwarden |
| CrewAI | crewai-tollwarden | pip install crewai-tollwarden |
| NeMo Agent Toolkit | nemo-tollwarden | pip install nemo-tollwarden |
| Coinbase AgentKit | agentkit-tollwarden | pip install agentkit-tollwarden |
| Vercel AI SDK | @tollwarden/ai-sdk | npm install @tollwarden/ai-sdk |
Each exposes the same three tools (scan / check reputation / report) plus a framework-native provenance hook β a callback (LangChain), an after-tool-call hook (CrewAI), an explicit content argument (NeMo), a wallet-aware action (AgentKit), or an onStepFinish handler (Vercel AI SDK) β and a guarded_payment / guardedPayment wrapper for enforcement by construction (the payment executor never runs on a block verdict). See each package's README for the two-line setup.
Core detectors
| Check | What it catches |
|---|---|
| PII / secret detection | EVM private keys, seed phrases, AWS/OpenAI/Anthropic/GitHub/Slack keys, JWTs, ?api_key= URL credentials, SSNs, Luhn-validated card numbers, emails, phones β in resource_url, description, reason, and metadata, before they're transmitted |
| Replay detection | Nonce reuse (stale or captured payment authorizations), scoped network:payer:nonce, configurable TTL window |
| Overpayment detection | Above a configurable multiple of expected price (flag β₯3Γ, block β₯10Γ) plus an absolute ceiling |
| Prompt-injection-triggered payments | Payments whose decision originated from content the agent just read (tool result / fetched page) rather than its own planning step; escalates on weighted injection tells in that content (override/redirect phrasing across a broad verb/object corpus and in 8 languages: English, Spanish, Portuguese, French, German, Russian, Chinese, Japanese; spoofed system/chat-template/Guidance markers, smuggled model boundary tokens, fabricated conversation turns, concealment, business-email-compromise phrasing β "our payment address has changed, no need to verify" β and urgency pressure), with extra weight when a tell sits near an address-like token. Scored the way injections are shaped: weak tells only add up when they cluster, pressure alone (urgency, transcript form, hidden characters) never blocks, and a human's own "pay X to 0xβ¦" instruction is not scored against them. Content is scanned both raw and with HTML tags, entities and markdown emphasis stripped, so **Ignore** all <b>previous</b> instructions reads as the sentence it renders as. Blocks when the pay_to address itself came from that content β even split across lines or separators, missing its 0x, or laced with invisible characters |
| Resource URL risk (incoming) | IP-literal hosts, punycode/homoglyphs, link shorteners, user@host tricks, non-HTTPS, credential demands ("send your seed phrase") |
| Counterparty reputation | Shared post-hoc report registry, cross-checked on every scan; reporting is always free. Blocked injection scans also feed it automatically: a wallet caught being planted in just-read content (or used as vanity-bait) is flagged on every agent's future scans of it β one detection becomes network-wide protection (flag-only; scan inputs are client-supplied) |
| Delivery outcomes | Measured, commitment-bound delivery history per counterparty β a clean payment to a seller who never ships still fails you. Sellers with low delivery rates or repeated no-ships get flagged (never blocked: H-2 applies to measured history too) |
Zero-latency hardening tier β checks that hold even when the calling agent's narration is compromised:
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/tollwarden)<a href="https://allmcps.com/mcp/tollwarden"><img src="https://allmcps.com/api/badge/tollwarden?style=directory" alt="TollWarden on AllMCPs" /></a>