Back to Browse

Hive Mcp Agent Quota MCP Server

by Srotzin
Developer ToolsLow Risk9.6MCP RegistryRemote
Free

Server data from the Official MCP Registry

Per-agent rate limits and quota enforcement for the Hive A2A economy

About

Per-agent rate limits and quota enforcement for the Hive A2A economy

Remote endpoints: streamable-http: https://hive-mcp-agent-quota.onrender.com/mcp

Security Report

9.6
Low Risk9.6Low Risk

Valid MCP server (1 strong, 1 medium validity signals). 2 known CVEs in dependencies Imported from the Official MCP Registry.

3 tools verified · Open access · 2 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

file_system

Check that this permission is expected for this type of plugin.

env_vars

Check that this permission is expected for this type of plugin.

database

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

How to Connect

Remote Plugin

No local installation needed. Your AI client connects to the remote endpoint directly.

Add this to your MCP configuration to connect:

{
  "mcpServers": {
    "io-github-srotzin-hive-mcp-agent-quota": {
      "url": "https://hive-mcp-agent-quota.onrender.com/mcp"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

hive-mcp-agent-quota

srotzin/hive-mcp-agent-quota MCP server

Per-agent quota meter for the A2A network. Each call to quota_check consumes one or more units against an agent's DID and is settled at $0.001 USDC per unit on Base L2 via the x402 envelope. Inbound only. ENABLE=true by default.

Brand color: #C08D23 (Pantone 1245 C, Hive Civilization gold).

Surface

LayerEndpointDescription
MCPPOST /mcpJSON-RPC 2.0, Streamable-HTTP, protocol 2024-11-05.
DiscoveryGET /.well-known/mcp.jsonTool list and transport metadata.
RESTPOST /v1/quota/checkConsume units for a DID. 402 if no balance and no proof.
RESTGET /v1/quota/balance?did=…Read remaining quota for a DID.
RESTGET /v1/quota/todayUTC-day ledger snapshot.
RESTGET /v1/quota/estimate?units=NAsking and floor in USDC for N units.
HealthGET /healthLiveness, pricing, recipient address.
RootGET /HTML for browsers, JSON for agents (Accept-header sniff). JSON-LD SoftwareApplication.

Tools

NameTierCostDescription
quota_check1$0.001/unitConsume N units for a DID via x402.
quota_balance0freeRemaining quota for a DID.
quota_topup_estimate0freeAsking and floor for N units.

Pricing and the barter floor

Pricing inherits the hivemorph barter pattern. Every 402 envelope advertises both amount_usd (asking) and accept_min_usd (floor). A client may submit a proof whose on-chain paid amount is anywhere in [floor, asking] and the shim accepts it.

Defaults, all overridable by environment variable:

VariableDefaultNotes
QUOTA_CHECK_PRICE_USDC0.001Per-unit asking price.
HIVE_X402_FLOOR_PCT_DEFAULT0.70Floor as fraction of asking.
HIVE_X402_FLOOR_MIN_PCT0.30Hard lower clamp.
HIVE_X402_FLOOR_MAX_PCT0.95Hard upper clamp.

So a 1-unit check at the defaults advertises asking $0.0010 and accept-min $0.0007. A 100-unit check advertises asking $0.1000 and accept-min $0.0700. The floor never falls below MIN_PCT of asking and never exceeds MAX_PCT.

Settlement

FieldValue
ChainBase L2
AssetUSDC
Contract0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913
RecipientWALLET_ADDRESS env, default 0x15184bf50b3d3f52b60434f8942b7d52f2eb436e
Verificationprovider.getTransactionReceipt(tx_hash) against BASE_RPC_URL, decode USDC Transfer logs to recipient, sum amount in 6-decimal units, compare to accept_min_usd.
Signature (optional)ethers.verifyMessage(message, signature) recovers payer; rejected if it disagrees with the on-chain from.

No mocks. The on-chain check is a real RPC read against Base mainnet.

Storage

SQLite at QUOTA_DB_PATH (default /tmp/quota.db), three tables:

  • quotas (did, units_purchased, units_consumed, first_seen, last_seen)
  • checks (id, did, unit_count, granted, remaining, tx_hash, paid_usdc, ts)
  • topups (id, did, units, paid_usdc, tx_hash UNIQUE, payer, ts)

tx_hash is UNIQUE on topups to make replay a 409.

x402 envelope

A quota_check call with no prepaid balance and no proof returns:

{
  "error": "payment_required",
  "x402_version": 1,
  "payment": {
    "nonce": "…",
    "amount_usd": 0.001,
    "accept_min_usd": 0.0007,
    "accepts": [{
      "chain": "base",
      "asset": "USDC",
      "contract": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
      "decimals": 6,
      "recipient": "0x15184bf50b3d3f52b60434f8942b7d52f2eb436e",
      "scheme": "exact"
    }],
    "expires_at": 1761600000,
    "tier": 1,
    "product": "agent_quota_check",
    "unit_count": 1,
    "price_per_unit_usd": 0.001,
    "floor_pct": 0.70
  }
}

The client sends USDC to the recipient on Base, then resubmits the same request with an X-Payment header containing the proof:

X-Payment: {"nonce":"…","chain":"base","tx_hash":"0x…","payer":"0x…","signature":"0x…","message":"hive-quota:<nonce>"}

signature and message are optional. If supplied, the recovered address must match payer and the on-chain from.

Environment

VariableDefaultNotes
PORT3000
ENABLEtrueSet to false to disable tools/call.
WALLET_ADDRESS0x15184bf50b3d3f52b60434f8942b7d52f2eb436eUSDC recipient on Base.
QUOTA_CHECK_PRICE_USDC0.001Per-unit asking.
HIVE_X402_FLOOR_PCT_DEFAULT0.70
HIVE_X402_FLOOR_MIN_PCT0.30
HIVE_X402_FLOOR_MAX_PCT0.95
BASE_RPC_URLhttps://mainnet.base.org
DEFAULT_QUOTA_UNITS0Free units credited on first sight of a DID.
QUOTA_DB_PATH/tmp/quota.db

Running locally

npm install
node server.js

Then:

curl -s http://localhost:3000/health
curl -s -X POST http://localhost:3000/mcp \
  -H 'content-type: application/json' \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'
curl -s 'http://localhost:3000/v1/quota/today'

Hard rules

  • Inbound only. The shim never originates an outbound payment.
  • No private key in the repo. Verification is read-only.
  • No custody. The recipient address belongs to the operator, not the shim.
  • Returns are advisory until the on-chain receipt is confirmed by BASE_RPC_URL.

Council provenance

Tier A position 3. 2026-04-27. Inbound metering surface, symmetric to hive-mcp-barter (outbound counter-offer) and hive-mcp-auction (inbound reverse-Dutch).

License

MIT. See LICENSE.

Hive Gamification

This MCP server is part of the Hive Civilization gamification surface (10-mechanic capability taxonomy).

Surface tags: gamification.spec.v1 · gamification.surface.public · gamification.signal.read-only · gamification.settlement.real-rails

Real rails on Base L2 (USDC 0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913). Read-only signal layer. Brand gold #C08D23.

Hive Civilization Directory

Part of the Hive Civilization — agent-native financial infrastructure.

Brand: #C08D23

Reviews

No reviews yet

Be the first to review this server!

Hive Mcp Agent Quota MCP Server - Per-agent rate limits and quota enforcement for the Hive | MCP Marketplace