Back to Browse

Ucash MCP Server

Developer ToolsUse Caution4.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Pay x402 resources on U.CASH from your own wallet: view the price, pay on-chain, settle by hash.

About

Pay x402 resources on U.CASH from your own wallet: view the price, pay on-chain, settle by hash.

Remote endpoints: streamable-http: https://mcp.u.cash/

Security Report

4.2
Use Caution4.2High Risk

The MCP server is well-structured with appropriate authentication for its payment processing purpose. Credentials are correctly sourced from environment variables, and the webhook verification uses constant-time HMAC comparison. Minor code quality issues around input validation and error handling do not materially impact security given the server's limited scope and straightforward operations. Supply chain analysis found 5 known vulnerabilities in dependencies (0 critical, 5 high severity).

5 files analyzed · 10 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

mcp-ucash

A merchant-side MCP server for U.CASH Pay. Let Claude Desktop, Cursor, or any MCP client manage a merchant's pay.u.cash: create checkouts, verify settlement webhooks, and read settings + integration credentials.

Tools

  • create_checkout(amount, currency, title, external_reference) → hosted checkout URL + transaction id
  • verify_webhook(raw_body, signature_header) → HMAC verify an X-Webhook-Signature
  • get_integrations() → Discord/Telegram/BigCommerce/Ecwid/Wix credentials (from /v1/integrations)
  • get_settings() → safe agent settings (from /v1/settings)

Run

# one-liner: uv installs an isolated Python 3.10+ and the deps for you
uvx --from mcp-ucash python -m mcp_ucash

Or from source:

pip install "mcp[cli]"
export UXC_API_KEY=uxc_...          # agent API key, for /v1/* reads
export UCASH_CLOUD_TOKEN=st_...     # store cloud token, for create_checkout
export UCASH_WEBHOOK_SECRET=...     # for verify_webhook
python mcp_ucash.py

Claude Desktop / Cursor config

{
  "mcpServers": {
    "ucash": {
      "command": "uvx",
      "args": ["--from", "mcp-ucash", "python", "-m", "mcp_ucash"],
      "env": {
        "UXC_API_KEY": "uxc_...",
        "UCASH_CLOUD_TOKEN": "st_...",
        "UCASH_WEBHOOK_SECRET": "..."
      }
    }
  }
}

MCP directories

This repo ships the manifests the MCP directories read:

  • mcp.json - client/registry descriptor (Glama, MCP Registry).
  • smithery.yaml - build + start spec for Smithery.

License

MIT.

Reviews

No reviews yet

Be the first to review this server!