Back to Browse

Agentic Pay MCP Server

Developer ToolsUse Caution4.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

Non-custodial payment engine for AI agents — BTC, ETH, USDT, USDC, XRP, XMR, ZEC.

About

Non-custodial payment engine for AI agents — BTC, ETH, USDT, USDC, XRP, XMR, ZEC.

Security Report

4.0
Use Caution4.0High Risk

This MCP payment server handles cryptocurrency transfers across seven blockchains with a well-designed policy engine for spend limits and idempotency safeguards. However, several security concerns prevent a higher score: the system relies on environment variables for private keys without enforcement of secure storage practices, the MCP server uses a fixed agent ID from env vars which could lead to policy bypass if multiple agents share the same process, and there is insufficient input validation for blockchain addresses. The architecture and code quality are generally sound, but production deployment would require hardening key management and adding address validation. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 2 high severity). Package verification found 1 issue.

7 files analyzed · 14 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

HTTP Network Access

Connects to external APIs or services over the internet.

process_spawn

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Identifier for this agent, used to look up its spend-limit policy in config.json.Optional

Environment variable: AGENTIC_PAY_AGENT_ID

Absolute path to your config.json (spend limits, API keys, static prices). Defaults to config/config.json in the install directory.Optional

Environment variable: AGENTIC_PAY_CONFIG

WIF-encoded Bitcoin private key for the funding wallet. Only required if using the BTC rail.Required

Environment variable: BTC_WIF

EVM JSON-RPC endpoint URL. Only required if using the ETH/USDT/USDC rails.Optional

Environment variable: ETH_RPC_URL

0x-prefixed Ethereum private key for the funding wallet. Only required if using the ETH/USDT/USDC rails.Required

Environment variable: ETH_PRIVATE_KEY

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-shieldcubed-agentic-pay": {
      "env": {
        "BTC_WIF": "your-btc-wif-here",
        "ETH_RPC_URL": "your-eth-rpc-url-here",
        "ETH_PRIVATE_KEY": "your-eth-private-key-here",
        "AGENTIC_PAY_CONFIG": "your-agentic-pay-config-here",
        "AGENTIC_PAY_AGENT_ID": "your-agentic-pay-agent-id-here"
      },
      "args": [
        "-y",
        "@shieldcubed/agentic-pay"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

Agentic Pay

A cross-platform payment engine that lets third-party AI agents send and receive payments over seven crypto rails: BTC, ETH, USDT, USDC, XRP, XMR, ZEC.

One Node.js core runs unmodified on Linux, Windows, and macOS. The same backend is reachable from iOS and Android via an installable Progressive Web App (PWA) — there is no separate native mobile codebase to maintain.

Architecture

                     ┌───────────────────────────┐
                     │   core/railManager.js     │  <- one call-site for
                     │  (policy + ledger + auth) │     every asset
                     └─────────────┬─────────────┘
                                   │
        ┌───────────┬─────────────┼─────────────┬───────────┬──────────┐
        │            │             │             │           │          │
     rails/btc   rails/eth    rails/xrp     rails/xmr    rails/zec       │
     (bitcoinjs) (ethers.js,  (xrpl.js)   (JSON-RPC to  (JSON-RPC to     │
                  ETH+USDT+                monero-       zcashd)         │
                  USDC ERC20)              wallet-rpc)                   │
                                                                          │
        Agent-facing surfaces (both call railManager, never a rail       │
        adapter directly):                                               │
        ┌────────────────────────┐   ┌───────────────────────────┐      │
        │ server/restApi.js      │   │ server/mcpServer.mjs      │      │
        │ HTTP/JSON, API-key     │   │ MCP stdio server for       │      │
        │ auth, for any HTTP-    │   │ Claude / other MCP-        │      │
        │ capable agent stack    │   │ compatible agent clients   │      │
        └────────────────────────┘   └───────────────────────────┘      │
                                                                          │
        Human-facing surfaces:                                           │
        ┌────────────────────────┐   ┌───────────────────────────┐      │
        │ cli/index.js           │   │ web/ (PWA)                │      │
        │ Linux/Windows/macOS    │   │ served by server/          │      │
        │ terminal                │   │ staticWeb.js, installable  │      │
        │                        │   │ on iOS/Android home screen │      │
        └────────────────────────┘   └───────────────────────────┘      │

Every send, from any surface, passes through core/limits.js (per-agent spend caps + human-confirmation floor) and core/ledger.js (idempotency, so a retried tool call can never double-pay).

Quick start (any OS with Node.js 18+)

git clone <this repo>          # or unzip the delivered archive
cd agentic-pay
npm install

cp config/.env.example .env
cp config/config.example.json config/config.json
# edit both files — see docs/SETUP_<YOUR_OS>.md for exact values per rail

npm run start:rest     # REST API on :8787
npm run start:web      # PWA on :8788 (optional, for mobile/browser access)
npm run start:mcp      # MCP stdio server (for Claude Desktop / Claude Code)
node cli/index.js rails   # sanity check from the terminal

Start on testnets first. Every rail's example config defaults to a testnet or requires you to explicitly fill in mainnet values — this is intentional. Do not point real funds at this system until you've reviewed core/limits.js and set spend caps you're comfortable with.

Hosted (custodial) — skip the setup

Don't want to run your own node? Aumnium operates a hosted instance at https://api.aumnium.tech — deposit USDC, get a spendable custodial balance, and start sending across all seven rails without installing or funding anything yourself.

This is a different trust model than the self-hosted instructions above: your funds sit in a pooled wallet operated by Aumnium (not your own keys), and each send is charged a 1% fee plus network cost, deducted from your balance. The self-hosted path above remains fully non-custodial; this hosted path trades that for convenience.

# 1. Get your deposit address
curl -H "x-api-key: YOUR_KEY" https://api.aumnium.tech/v1/deposit/address

# 2. Send USDC to that address on Ethereum mainnet

# 3. Claim your deposit once it confirms
curl -X POST -H "x-api-key: YOUR_KEY" -H "Content-Type: application/json" \
  -d \'{"txHash":"0x..."}\' \
  https://api.aumnium.tech/v1/deposit/claim

# 4. Send payments (billed per-call via x402, USDC on Base)
curl -X POST -H "x-api-key: YOUR_KEY" -H "Content-Type: application/json" \
  -d \'{"asset":"USDC","to":"0x...","amount":1,"idempotencyKey":"unique-key"}\' \
  https://api.aumnium.tech/v1/send

Contact team@spacenet.network for an API key. Full endpoint list at https://api.aumnium.tech.

Where to go next

What's genuinely production-ready here vs. what's a starting point

  • Production-shaped: the policy engine (per-tx cap, daily cap, confirmation floor, address allowlisting), the idempotent ledger, and the unified rail interface.
  • Starting point, needs hardening for real money at scale: the JSON-file ledger (swap for a real database under load), the static USD price table (wire in a live price feed), and key storage (move from .env to an OS keychain or HSM/KMS for anything beyond development — see core/keystore.js for the extension point).

License

agentic-pay is licensed under the Business Source License 1.1 (see LICENSE). In plain terms:

  • You can use, modify, and self-host this freely — for yourself, your own organization, or your own agents, including production use.
  • You cannot turn around and offer it as a competing hosted/managed payments-as-a-service product to third parties without a commercial license.
  • On 2030-07-14, this version automatically converts to the Apache License 2.0 — fully open source, no restrictions.

Want a commercial license for a hosted/managed offering before then? Contact team@spacenet.network.

Reviews

No reviews yet

Be the first to review this server!

Agentic Pay MCP Server - Non-custodial payment engine for AI agents — BTC, ETH, | MCP Marketplace