Back to Browse

X402 MCP Server

Developer ToolsUse Caution4.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

177 crypto market intel endpoints with auto x402 USDC micropayments from your AI agent

About

177 crypto market intel endpoints with auto x402 USDC micropayments from your AI agent

Security Report

4.2
Use Caution4.2High Risk

This MCP server implements a legitimate cryptocurrency micropayment system for API access with reasonable security practices. The architecture properly isolates private keys to the local machine and implements payment signing correctly. However, there are concerns about private key exposure in the Claude Desktop config file, insufficient input validation on path parameters, and logging of potentially sensitive request details that warrant a moderate risk assessment. Supply chain analysis found 7 known vulnerabilities in dependencies (0 critical, 2 high severity). Package verification found 1 issue.

5 files analyzed · 15 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

process_spawn

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

0x-hex private key for Base/Polygon/Arbitrum USDC payments (dedicated wallet)Required

Environment variable: EVM_PRIVATE_KEY

base58 Solana keypair for Solana USDC payments (optional)Required

Environment variable: SVM_PRIVATE_KEY

Max tools exposed (1-177, default 100)Optional

Environment variable: X402_TOOL_LIMIT

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-carboncashmere-x402-mcp": {
      "env": {
        "EVM_PRIVATE_KEY": "your-evm-private-key-here",
        "SVM_PRIVATE_KEY": "your-svm-private-key-here",
        "X402_TOOL_LIMIT": "your-x402-tool-limit-here"
      },
      "args": [
        "-y",
        "@carbon-cashmere/x402-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

@carbon-cashmere/x402-mcp

MCP server that exposes Carbon & Cashmere's 177 crypto market intelligence endpoints to your AI agent — with automatic x402 USDC micropayments from your wallet.

What you get

When this MCP is installed, your AI agent can call tools like:

  • get_v1_news — analyzed crypto news with sentiment + market impact
  • get_v1_stablecoins — total market cap, per-coin supply, chain distribution
  • get_v1_onchain_btc — Bitcoin on-chain metrics (hash-rate, mempool, miner flows)
  • get_v1_bittensor_leaderboard — top-100 Bittensor miners by emission
  • get_v1_mantis_realized_accuracy — MANTIS subnet (UID 253) realized accuracy track-record
  • get_v1_intel_snapshot — aggregated market intel snapshot
  • … plus subscriptions ($10/day, $50/week, $200/month), sponsor tiers ($500–$50000), and 170+ research endpoints priced $0.003 – $0.50 per call

177 paid endpoints total. Default exposes top 100 (curated by revenue + popularity). Set X402_TOOL_LIMIT=177 to expose all incl. per-coin variants.

Each tool invocation triggers a single USDC micropayment from your configured wallet. No subscription. No API key. Pay only for what you use.

Install

Claude Desktop

Add to ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows):

{
  "mcpServers": {
    "carbon-cashmere": {
      "command": "npx",
      "args": ["-y", "@carbon-cashmere/x402-mcp"],
      "env": {
        "EVM_PRIVATE_KEY": "0x_your_evm_private_key_here",
        "SVM_PRIVATE_KEY": "your_base58_solana_private_key_here_optional"
      }
    }
  }
}

Restart Claude Desktop. The top 100 Carbon & Cashmere tools (curated by revenue + popularity) appear in your tool palette.

Cursor / Cline / Continue

Same JSON config, paste into your MCP settings panel.

Wallet setup

Security: use a dedicated spending wallet, not your main wallet. Your EVM_PRIVATE_KEY sits in plaintext in your Claude Desktop config. Any process on the host with read access to that file gets the key. Treat it as a hot wallet you would not mind losing: fund it with the small amount you plan to spend ($10–$50 in USDC), never with your main holdings.

  • EVM_PRIVATE_KEY (required for Base / Polygon / Arbitrum / World / Avalanche payments)
    • 0x-prefixed hex string (e.g. 0xac0974bec39a17e36ba4a6b4d238ff944bacb478cbed5efcae784d7bf4f2ff80)
    • Fund with USDC on Base mainnet (cheapest, fastest, ~$0.0001 gas per call)
    • One-time cost: ~$10 USDC covers 200+ tool calls
    • Hard cap = wallet balance. A runaway agent loop can spend the funded amount but no more; signing is bounded by USDC available on the chain.
  • SVM_PRIVATE_KEY (optional, for Solana payments)
    • base58-encoded Solana keypair bytes
    • Only needed if a tool routes Solana-only

Network whitelist. The MCP server only signs payments for networks that appear in the API's 402-response accepts[] array (currently Base, Polygon, Arbitrum, World Chain, Solana, Algorand, Stellar). Requests routed to any other chain are rejected at the signing layer — your key cannot be tricked into signing for an arbitrary network.

Keys never leave your machine. They live only in your Claude Desktop config and the MCP process running locally. Payment signing happens on your device; only the signed EIP-712 / SIWS payload travels to Carbon & Cashmere.

Discovery-only mode (no keys set)

If you start the MCP server without EVM_PRIVATE_KEY and without SVM_PRIVATE_KEY, it runs in discovery-only mode: tool registration works, free endpoints work, paid tool invocations surface a 402 error to the agent. Useful for: evaluating the tool catalog, MCP marketplace introspection (Glama, npm scrapers), or running in a CI/test environment without funding a wallet.

How it works

Claude Desktop          @carbon-cashmere/x402-mcp        api.carbon-cashmere.de
     |                          (your machine)                 (our server)
     |  call get_v1_news        |                                 |
     |------------------------->|  GET /v1/news                   |
     |                          |-------------------------------->|
     |                          |  402 + PAYMENT-REQUIRED         |
     |                          |<--------------------------------|
     |                          |  sign with EVM_PRIVATE_KEY      |
     |                          |  GET /v1/news + PAYMENT-SIG     |
     |                          |-------------------------------->|
     |                          |  200 OK + data                  |
     |                          |<--------------------------------|
     |  formatted data          |                                 |
     |<-------------------------|                                 |

Built on official Coinbase x402 v2 protocol. Settlement happens on Base USDC (or your chosen chain). Typical latency: ~2-3 seconds per call (one-shot payment + data).

Tool count

By default, the top 100 tools are exposed — curated server-side by a scoring that combines actual settlement volume, USD revenue, exploration weighting, and description quality (the catalog re-ranks without requiring an npm re-publish).

X402_TOOL_LIMITWhat you get
50Minimal footprint — top free + bundles + a few high-revenue endpoints
100 (default)High-revenue tier — adds $10–$50 subscriptions, sponsor tiers, weekly/daily reports, on-chain bundles
177Everything — adds per-coin specialized routes (vol-regime/{coin}, hurst/{coin}, trend/{coin}, …). Recommended only when your agent knows which coin to query.

Override:

"env": {
  "X402_TOOL_LIMIT": "177"
}

Why a default cap: too many MCP tools can degrade an agent's tool-selection accuracy. 100 is the empirical sweet spot for Claude 3.5 Sonnet and newer.

Configuration env

VariableRequiredDefaultDescription
EVM_PRIVATE_KEYone of0x-prefixed EVM key for Base/Polygon/Arbitrum
SVM_PRIVATE_KEYone ofbase58 Solana keypair
X402_API_BASEnohttps://api.carbon-cashmere.deAPI base URL
X402_TOOL_LIMITno100Max tools exposed (1-177)
X402_LOG_LEVELnoinfodebug | info | warn | error

Security

  • Keys never leave your machine. The MCP server runs locally as a child process of Claude Desktop.
  • Pay-per-call cap. Each call costs $0.003–$0.50. Even a runaway loop is bounded by wallet balance.
  • No off-chain credentials. No API keys. No OAuth. Pure on-chain settlement.
  • Open source. Audit the code yourself: github.com/CarbonCashmere/x402-mcp

License

MIT — see LICENSE.

Links

Reviews

No reviews yet

Be the first to review this server!