Back to Browse

Hermesplant MCP Server

Developer ToolsLow Risk10.0MCP RegistryRemote
Free

Server data from the Official MCP Registry

Preflight, approve, and prove consequential agent actions with signed evidence and x402 tools.

About

Preflight, approve, and prove consequential agent actions with signed evidence and x402 tools.

Remote endpoints: streamable-http: https://mcp.hermesplant.com/mcp

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (6 strong, 4 medium validity signals). No known CVEs in dependencies. Imported from the Official MCP Registry.

Endpoint verified · Open access · No issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

file_system

Check that this permission is expected for this type of plugin.

How to Connect

Remote Plugin

No local installation needed. Your AI client connects to the remote endpoint directly.

Add this to your MCP configuration to connect:

{
  "mcpServers": {
    "io-github-jessegdotio-hermes-plant": {
      "url": "https://mcp.hermesplant.com/mcp"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Hermes Plant MCP Server

Glama score CI

Runnable MCP server and integration examples for Hermes Plant, the Agent Commerce Assurance layer that lets AI agents preflight, approve, and prove consequential actions. Start with a one-cent action-safety check, route only high-risk actions into signed review evidence, and pay per call over x402.

What's here: a runnable stdio MCP bridge for registry crawlers and local clients, plus drop-in examples in curl, TypeScript, Python, CrewAI, LangChain, and MCP client configs for Claude Desktop / Cline / Cursor.

Install the Action Safety skill

Install the public, fail-closed Action Safety skill for Codex, Claude Code, Cursor, and other Agent Skills-compatible clients:

npx skills@1.5.18 add JesseGdotIO/hermesplant-mcp-server --skill protect-agent-action

The skill calls the one-cent quick gate before an exact consequential action, binds the result to that unchanged action, and escalates high or critical risk only when the additional $0.25 is authorized. Review triage is never treated as human approval and the skill never expands the caller's permissions.

Source: skills/protect-agent-action · Install guide and trust boundary

Use the hosted MCP connector

For the complete production tool surface, use the canonical Hermes Plant — Agent Commerce Assurance connector on Glama. It exposes Action Safety, Spend Assurance, signed evidence, payment-policy checks, and the component x402 tools through the live Streamable HTTP endpoint.

This repository is the portable, no-secret discovery bridge. It lets registry crawlers and local clients inspect the live catalog and payment contracts without signing a wallet message or spending funds. The hosted connector is the buyer-facing path for invoking the production tools.

Glama registry

Hermes Plant MCP Server Glama card

This repo is arranged for Glama to build and inspect the MCP server without secrets or funded wallets:

  • glama.json declares the GitHub maintainer.
  • The root Dockerfile starts the stdio MCP server in mcp-server/.
  • npm run smoke:mcp lists all local MCP tools and fetches the live x402 manifest.
  • GitHub Actions validates the MCP server, Docker image, shell examples, and no-spend TypeScript/Python client contracts with their real dependencies.

A Glama release is still an account-side action, not a GitHub release. After claiming the server in Glama, use the Dockerfile admin page to deploy the build, wait for the build test to pass, then publish a Glama release version. That release unlocks Glama's Server Coherence and Tool Definition Quality scoring.

Complementary MCP servers

Hermes Plant governs consequential actions and payments; these independent servers cover adjacent layers of an agent stack:

  • SINT Protocol — capability authorization and policy enforcement before execution.
  • AgentPay MCP — non-custodial wallet execution with spend limits and approval queues.
  • Agent Security Scanner MCP — repository, package, prompt, and skill security scanning.

These links describe functional complementarity, not partnerships or endorsements.

Start with an assurance workflow

WorkflowUse it forTracked entrypoint
Action SafetyPreflight shell, Git, SQL, deploy, x402, and MCP actions; escalate high-risk work into review plus a signed receipt.Open workflow
Spend AssuranceCheck payment policy, wallet context, and evidence before an agent spends.Open workflow
Investment EvidenceRun deterministic underwriting and return verifiable evidence in one paid call.Open workflow

Use the free API key for up to 250 calls/month, the $29/month Agent API Pass for regular volume, or per-call USDC on Base. Public proof and machine-readable contracts are available at hermesplant.com/proof and hermesplant.com/openapi.json.

Component catalog

Nineteen hosted x402 endpoints remain available as composable utilities:

EndpointUse it forHosted path
DealAnalyzerDCF, IRR, XIRR, NPV/agent-services/dealanalyzer
WaterfallLP/GP private-equity distribution waterfalls/agent-services/waterfall
OptionsBlack-Scholes pricing + Greeks/agent-services/options
BondYield, duration, convexity/agent-services/bond
CashflowLensCash-flow projection + sensitivity/agent-services/cashflowlens
PortfolioGuardPortfolio risk scoring/agent-services/portfolioguard
WalletGuardWallet AML + sanctions screening/agent-services/walletguard
EmailGuardEmail reputation + risk/agent-services/emailguard
DestructGuardBlock destructive AI-agent commands/agent-services/destructguard
MCP riskScore MCP server risk before connecting/agent-services/mcp-risk
EvidenceEvidence bundle for paid calls/agent-services/evidence
Payment policyInspect/score an x402 payment policy/agent-services/payment-policy
ReviewQueueHuman-in-the-loop approval routing/agent-services/reviewqueue

Agents discover endpoints through OpenAPI, llms.txt, the x402 manifest, the API catalog, MCP metadata, or agent skills. The workflow links above carry source-specific attribution so registry traffic can be evaluated against paid calls instead of impressions.

How an x402 call works

Client                    Hermes Plant                 Facilitator
  |                            |                            |
  | POST /endpoint             |                            |
  |--------------------------->|                            |
  | 402 Payment Required       |                            |
  | + PAYMENT-REQUIRED         |                            |
  |<---------------------------|                            |
  | sign payment locally       |                            |
  | POST /endpoint             |                            |
  | + PAYMENT-SIGNATURE        |                            |
  |--------------------------->| verify signature           |
  |                            |--------------------------->|
  |                            | ok                         |
  |                            |<---------------------------|
  | 200 OK + result            | settle payment             |
  |<---------------------------|--------------------------->|
  1. Client makes an HTTP request.
  2. Server replies with 402 Payment Required plus a PAYMENT-REQUIRED header carrying the price, network, asset, recipient, and timeout.
  3. Client parses the challenge, signs a USDC transfer authorization locally, and replays the request with a PAYMENT-SIGNATURE header.
  4. Server verifies the signature via the facilitator, runs the work, settles the payment on-chain, and returns 200 OK with the result plus a PAYMENT-RESPONSE header.

The full spec lives at github.com/x402-foundation/x402.

Discovery surfaces

These let any agent or human self-onboard without help:

MCP tools in this repo

The runnable stdio server exposes five read-only discovery tools:

ToolPurpose
hermesplant_x402_manifestFetch the live x402 manifest before paid calls.
hermesplant_llms_catalogFetch the agent-readable llms.txt catalog.
hermesplant_api_catalogFetch the machine-readable API catalog.
hermesplant_mcp_server_cardFetch the hosted MCP server descriptor.
hermesplant_list_hosted_toolsIntrospect the hosted Streamable HTTP MCP endpoint and list its advertised tools.

These local tools do not sign wallet messages, approve transactions, call paid endpoints, or spend USDC. They expose the discovery layer that clients need before invoking paid hosted tools.

Quickstart

Pick the runtime that matches your stack:

RuntimeFolderNotes
curl / Bashcurl/Pure shell; useful for inspecting the 402 handshake
TypeScripttypescript/Uses @x402/fetch + @modelcontextprotocol/sdk
Pythonpython/Uses the x402 package
CrewAIcrewai/Finance-agent crew calling Hermes endpoints
LangChainlangchain/LangChain Tool wrapping Hermes
MCP configmcp-config/One-paste config for Claude Desktop / Cline / Cursor
MCP servermcp-server/Runnable stdio MCP bridge for discovery, server-card inspection, and hosted-tool listing

Run the MCP server locally

npm install
npm run smoke:mcp
npm start

MCP server registry build

This repo includes a root glama.json and root Dockerfile for MCP registry crawlers:

docker build -t hermesplant-mcp-server .
docker run --rm -i hermesplant-mcp-server

The container starts the stdio MCP bridge in mcp-server/, which exposes Hermes Plant discovery tools and hosted MCP metadata without requiring API keys.

Wallet setup

The guarded paid-call examples require:

  • A funded wallet on Base mainnet with chain id 8453.
  • Enough USDC for the selected endpoint and a small amount of ETH for gas.
  • EVM_PRIVATE_KEY plus the explicit opt-in HERMES_ALLOW_PAYMENT=1.

The included CashflowLens clients cap payment requirements at $0.20 USDC and register only Base mainnet. Leave the opt-in unset for imports and tests. Never commit a private key. These production examples do not claim testnet support; use an x402 test resource server for testnet integration work.

Status

These examples target the production deployment at hermesplant.com. Endpoint signatures may evolve, so cross-reference openapi.json and the /.well-known/x402 manifest before going to production.

Contributing

Issues and PRs welcome. New runtime? New framework? Open a PR with one working example and a tight README.

License

MIT - see LICENSE.

Reviews

No reviews yet

Be the first to review this server!