Back to Browse

MPP32 MCP Server

by MPP32
Developer ToolsModerate7.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

Payment layer for AI agents. One MCP, five protocols, thousands of paid APIs your agent can call.

About

Payment layer for AI agents. One MCP, five protocols, thousands of paid APIs your agent can call.

Security Report

7.0
Moderate7.0Low Risk

Valid MCP server (2 strong, 4 medium validity signals). 3 known CVEs in dependencies (0 critical, 3 high severity) Package registry verified. Imported from the Official MCP Registry.

8 files analyzed · 4 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Session key from https://mpp32.org/agent-console. Unlocks the full federated catalog and attributes every call to your dashboard. Optional in legacy mode where only native services are reachable.Required

Environment variable: MPP32_AGENT_KEY

Solana private key used to sign x402 USDC payments locally. Only needed when calling paid services that prefer x402. Stays on your machine, never sent to MPP32 servers.Required

Environment variable: MPP32_SOLANA_PRIVATE_KEY

Ethereum L2 private key used to sign Tempo pathUSD payments locally. Optional fallback for paid services when x402 is not available. Stays on your machine, never sent to MPP32 servers.Required

Environment variable: MPP32_PRIVATE_KEY

Override the API base URL for custom deployments. Defaults to https://mpp32.org.Optional

Environment variable: MPP32_API_URL

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-mpp32-mpp32-mcp-server": {
      "env": {
        "MPP32_API_URL": "your-mpp32-api-url-here",
        "MPP32_AGENT_KEY": "your-mpp32-agent-key-here",
        "MPP32_PRIVATE_KEY": "your-mpp32-private-key-here",
        "MPP32_SOLANA_PRIVATE_KEY": "your-mpp32-solana-private-key-here"
      },
      "args": [
        "-y",
        "mpp32-mcp-server"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

MPP32

The payment layer for AI agents. One install. Pay any x402 endpoint on Solana or Base from your agent. Browse a federated index of thousands of machine payable APIs without a single provider account.

npm version License: MIT Website

Built and maintained by a small team using AI-augmented development. See AUTHORS.md · SECURITY.md · CONTRIBUTING.md.

Repository scope

This repository contains the full source for the four MPP32 components:

  • backend/ — Hono on Bun, Prisma, SQLite. Federated catalog, agent execute, payment proxies for all five protocols.
  • mcp-server/ — the mpp32-mcp-server package published to npm.
  • sdk/ — client SDK.
  • webapp/ — React + Vite frontend served at mpp32.org.

The hosted deployment at mpp32.org runs this source plus operational infrastructure (TLS termination, CDN, managed database, monitoring, hosted analytics, and provider API keys for third-party data sources) that is configuration, not source.

Why this exists

Most agent stacks stop at "the model can call a function." That works until the function costs money. The moment your agent needs premium data, a paid model, a trading signal, or a token analytics call, you are back to building accounts, storing API keys, watching budgets, and writing custom 402 handlers for every provider.

MPP32 replaces all of that. Your agent asks for a service by name. The proxy finds it in a federated catalog of thousands of machine payable APIs, signs payment with a key on your own machine, and returns the data. You write zero billing code. You manage zero provider accounts. Settlement lands on chain in seconds. MPP32 never touches the money.

Free Tier: 10 calls/day, no wallet required

Every agent session gets 10 free Intelligence Oracle calls per day — no wallet, no USDC, no payment setup. Just set MPP32_AGENT_KEY (free instant signup at mpp32.org/agent-console) and call get_solana_token_intelligence. Resets at midnight UTC.

Test your full MCP integration end-to-end before committing any crypto. Build working prototypes, evaluate the data quality, and ship to production — the free tier covers typical development and light usage indefinitely.

What an agent gains the moment it connects

  • 10 free Intelligence Oracle calls per day — no wallet, no USDC, no payment setup needed.
  • A live catalog of over 4,500 paid and free APIs across token intelligence, market data, web search, image generation, embeddings, DeFi analytics, wallet scoring, on chain queries, trading signals, and more.
  • Automatic x402 payment on Solana (USDC) and Base (USDC), picked per call based on which signing key you configured.
  • Real time Solana token intelligence with alpha scoring, rug risk, whale flow, smart money signals, and 24 hour pump probability.
  • A dashboard at mpp32.org that tracks every call, every dollar settled, every protocol used, every latency reading.
  • End to end audit. Every settlement comes back with an on chain signature you can verify on Solscan or Basescan.
  • Delegated Spend Keys — mint scoped, capped, revocable child keys so one agent can safely pay another. See below.

Delegated Spend Keys — the payment primitive for agents hiring agents

Everyone talks about "the agent economy where agents hire other agents." Almost nobody ships the payment rails for it. MPP32 does.

A parent agent session can mint a Delegated Spend Key — a scoped, capped, revocable child key — and hand it to a sub-agent it spawns or a third-party agent it hires. The child pays through MPP32 exactly like any session, but inside a hard boundary the parent defines:

  • Scoped. The child may only pay for services on an allowlist you set. A key issued for image generation can't be turned into a trading-signal spender. Scopes only narrow down the chain — a child can never widen what its parent allowed.
  • Capped. Each key gets its own budget, hourly velocity limit, and per-call ceiling. A single call quoted above the ceiling is refused before any money moves.
  • Rolled up. Every dollar a child settles counts against the parent's budget. An ancestor's budget is enforced against the settled spend of its entire delegation subtree, so a runaway sub-agent can never push a parent past its cap. Exhaust the parent and every key beneath it is suspended at once.
  • Revocable. Kill a key and its whole subtree stops spending immediately — cascading to every key it minted. Pause an ancestor and everything below it pauses too.
  • Auditable. Every delegated settlement still lands on chain with a signature, and every child traces back to the parent that authorized it.

MPP32 never holds custody. A delegated key only scopes and caps which paid calls a sub-agent can make — settlement is still signed by the wallet the agent controls.

# Parent mints a $3, image-only child key with a 2¢ per-call ceiling
POST /api/agent/sessions/:id/delegate
  X-Agent-Key: <parent key>
  { "label": "image-subtask", "budgetLimitUsd": 3, "maxPricePerCallUsd": 0.02, "allowedServices": ["replicate-flux"] }
→ 201 { "apiKey": "mpp32_agent_…", "childSessionId": "…", "delegationDepth": 1 }

# List what a session has delegated, with spend rolled up per key
GET  /api/agent/sessions/:id/delegations

# Revoke a key (and everything it minted) instantly
POST /api/agent/delegations/:childId/revoke   { "reason": "task complete" }

Manage it all visually in the Agent Console.

Payment rails

RailStatusSettles inNetworkVerification
x402ProductionUSDCSolana mainnetSolana facilitator
x402ProductionUSDCBaseBase facilitator
TempoProductionpathUSDTempomppx on chain verification, signers in the MPP32 SDK and MCP server
AGTPProduction (identity layer)Agent certificatesChain agnosticHMAC SHA256
AP2Envelope wired, disabled in productionVerifiable credentialsChain agnosticECDSA P-256
ACPEnvelope wired, disabled in productionCheckout sessionMulti chainDatabase backed flow

x402 on Solana and Base, Tempo, and AGTP are live in production. Tempo payments are signed client side by the MPP32 SDK (tempoPrivateKey) or the MCP server (MPP32_PRIVATE_KEY) and verified on chain by mppx. AP2 stays gated off until a trusted-issuer allowlist (AP2_TRUSTED_ISSUERS) is configured — without it, mandate verification fails closed and every request would be rejected. ACP stays gated off until its checkout session client flow is verified end to end.

Install

The MCP server is on npm and listed in the official Model Context Protocol registry.

npx -y mpp32-mcp-server@latest

Drop this into the MCP servers section of Claude Desktop, Claude Code, Cursor, Windsurf, or any MCP compatible client.

{
  "mcpServers": {
    "mpp32": {
      "command": "npx",
      "args": ["-y", "mpp32-mcp-server@latest"],
      "env": {
        "MPP32_AGENT_KEY": "mpp32_agent_…",
        "MPP32_SOLANA_PRIVATE_KEY": "<your base58 Solana secret key>"
      }
    }
  }
}

MPP32_SOLANA_PRIVATE_KEY is the base58 encoded 64 byte Solana secret key — the value Phantom exports under show private key, not the seed phrase. From a keypair.json file run node -e "console.log(require('bs58').encode(Buffer.from(JSON.parse(require('fs').readFileSync('keypair.json')))))" once and paste the result.

The wallet needs both USDC (for the payment) and a small amount of native SOL (for transaction fees). About 0.001 SOL covers many calls. A USDC only wallet returns insufficient funds for rent.

Get an MPP32_AGENT_KEY at mpp32.org/agent-console. The form returns the key and a ready to paste config snippet. With an agent key every call is attributed to your dashboard. Without it the server still works but only on free services. Private keys never leave your machine.

What the tools do

Three tools any MCP compatible agent can call.

  • list_mpp32_services browses the federated catalog. Returns native, curated free, x402 bazaar, and MCP registry entries with pricing, supported protocols, and a clear flag on every row that tells the agent whether it can actually call the service through this MCP or whether the entry is for discovery only.
  • call_mpp32_endpoint invokes any HTTP callable service. Free services return immediately. Paid services return a 402 challenge that this tool signs locally and retries automatically when a payment key is configured.
  • get_solana_token_intelligence runs the MPP32 native oracle. Pulls live data from DexScreener, Jupiter, and CoinGecko, merges it into one report, returns alpha score, rug risk, whale activity, smart money signals, 24 hour pump probability, projected ROI, and full market data. Costs $0.008 per call, paid automatically when a key is set.

Verify it without trusting us

The protocol integrations are running in production. You can confirm them against any registered endpoint without writing code.

See the 402 challenge with every protocol header:

curl -i https://mpp32.org/api/proxy/mpp32-intelligence

The response includes the x402 Payment-Required envelope, the Tempo WWW-Authenticate challenge, and an X-Payment-Methods advertisement listing every enabled rail (tempo, x402, agtp). AP2 and ACP stay gated off in production; flip the matching *_ENABLED env var in backend/.env to test them locally.

Read the full OpenAPI spec with per endpoint protocol and pricing detail:

curl https://mpp32.org/openapi.json

Read the federated catalog directly:

curl https://mpp32.org/api/agent/services

Use the single execute endpoint that wraps every protocol:

curl -X POST https://mpp32.org/api/agent/execute \
  -H 'X-Agent-Key: mpp32_agent_…' \
  -H 'Content-Type: application/json' \
  -d '{"service":"mpp32-intelligence","method":"POST","body":{"token":"SOL"}}'

For API providers

List your endpoint once and start receiving x402 payment automatically. MPP32 handles the payment negotiation, on chain verification, discovery listings via OpenAPI and A2A and MCP standards, periodic health re checks, and a full analytics dashboard. Settlement lands in USDC on Solana or Base directly to your wallet. Three consecutive verification failures suspend the listing so dead endpoints do not pollute the catalog.

Register at mpp32.org/build. Manage your listing at mpp32.org/manage using a recovery code delivered to your email.

Security posture

MPP32 was built with the assumption that everything will eventually be probed.

  • Production environment refuses to boot if the signing secret is missing or matches a known committed default.
  • All outbound URLs from user submissions and agent execute calls run through an SSRF guard that blocks private, loopback, link local, IPv6 unique local, and cloud metadata addresses.
  • Agent session API keys are hashed at rest using SHA256. A database leak does not surrender live credentials.
  • AGTP agent identity uses HMAC SHA256 with a server held salt so signatures cannot be forged from a public agent id.
  • Recovery one time codes refuse to issue in production when the email channel is not configured. Codes are never logged in plaintext when the system is configured correctly.
  • The idempotency cache is bounded with LRU eviction. Admin endpoints are rate limited per IP on top of the secret check.

Discovery endpoints

EndpointFormatPurpose
/openapi.jsonOpenAPI 3.1Full API spec with per endpoint protocol and pricing info
/.well-known/agent.jsonA2A Agent CardAgent to agent discovery with skills and auth schemes
/api/mcp-configMCP ConfigMCP compatible agent integration
/api/submissionsJSONPublic directory of all registered API providers
/api/agent/servicesJSONFederated catalog including native, curated, x402 bazaar, MCP registry

Stack

  • Frontend: React 18, Vite, React Router v6, Tailwind, shadcn/ui, Framer Motion
  • Backend: Hono on Bun, Zod validation, Prisma, SQLite
  • Protocols: Mppx SDK (Tempo), in house verification (x402, AP2, ACP, AGTP)
  • Distribution: npm (mpp32-mcp-server), official MCP registry, published agent card

Links

License

MIT

Reviews

No reviews yet

Be the first to review this server!