Back to Browse

Payagent MCP Server

Developer ToolsUse Caution4.8MCP RegistryLocal
Free

Server data from the Official MCP Registry

Pay x402 APIs in USDC on Base, Solana, and BNB Chain with spend mandates, receipts, idempotency.

About

Pay x402 APIs in USDC on Base, Solana, and BNB Chain with spend mandates, receipts, idempotency.

Security Report

4.8
Use Caution4.8High Risk

The payagent-mcp server is well-structured with proper authentication for delegated custody mode and reasonable permission scoping aligned with its payment-facilitating purpose. The codebase demonstrates good security practices: idempotency guards prevent double-spending, credentials are env-var managed, and dangerous operations (private key handling, API calls) are appropriately isolated. Minor code quality concerns around error handling and input validation do not significantly impact security. Supply chain analysis found 4 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.

6 files analyzed · 11 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

What You'll Need

Set these up before or after installing:

ArisPay developer API key (ap_live_… / ap_test_…). Optional — the create_user tool can self-provision one from just an email, or set PAYAGENT_PRIVATE_KEY to sign locally with no account.Required

Environment variable: ARISPAY_API_KEY

EVM private key for permissionless local signing (zero-signup mode): pay_api signs x402 payments with it directly — no ArisPay account needed. Generate one with `npx payagent wallet new`. Never sent to any server.Required

Environment variable: PAYAGENT_PRIVATE_KEY

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-stevemilton-payagent-mcp": {
      "env": {
        "ARISPAY_API_KEY": "your-arispay-api-key-here",
        "PAYAGENT_PRIVATE_KEY": "your-payagent-private-key-here"
      },
      "args": [
        "-y",
        "@arispay/payagent-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

@arispay/payagent-mcp

One coherent USDC payment product for AI agents: call x402-paid APIs, with spend mandates, receipts, and idempotency. Works with Claude Desktop, Cursor, Windsurf, or any MCP client. A thin wrapper around the payagent SDK.

Two ways to hold the wallet:

  • Local key (zero signup). Set PAYAGENT_PRIVATE_KEY to a funded EOA key. pay signs EIP-3009 locally — no ArisPay account, no email. The only guardrail is the wallet balance; use a dedicated low-balance wallet.
  • Delegated custody (managed, recommended). setup({ email }) self-provisions an account, a CDP-managed wallet, and a spend mandate in one call. ArisPay enforces per-transaction, daily, and monthly limits server-side before signing; no private key ever lives in this process.

Tools

Six core tools (the default surface):

ToolWhat it doesMoney
setupCreate or recover an account + payer wallet in one call (delegated mode)moves none
discoverSearch the paid-API catalog by intent + budgetread-only
inspectRead a URL's price and payment requirements without payingread-only
payThe complete machine path: request → 402 → select variant → validate policy → pay → structured receipt. Requires an idempotencyKey; a repeated key returns the cached receipt without paying againspends real money
balanceActive identity, deposit address, on-chain USDC balance, mandate limitsread-only
historyRecent payments — server feed (delegated) or local receipts (self-custody)read-only

Wallet administration (create_agent, fund_agent, list_agents, rename_agent) loads only when the host config sets PAYAGENT_MCP_PROFILE=admin.

Every tool declares MCP safety annotations (readOnlyHint, destructiveHint, idempotentHint, openWorldHint); pay is the only destructive tool.

Support matrix

AssetNetworkLocal key (self-custody)Delegated (managed mandate)
USDCBase (default)
USDCEthereum, Polygon
USDCBase Sepolia (testnet)
USDC (SPL)Solana, Solana devnet❌ (EVM signing only)✅ (deployment-gated)
USD1BNB Chain

Notes:

  • All prices are quoted by sellers in the 402 challenge; pay prefers an EVM variant and falls back to Solana when the seller offers no EVM option.
  • Delegated mandates are integer cents, validated server-side before any signature exists. Local mode has no server-side cap.
  • Settlement is a single on-chain transferWithAuthorization (EIP-3009): it succeeds or reverts atomically. When the seller returns X-PAYMENT-RESPONSE, the receipt carries the settlement transaction hash.
  • ArisPay's own facilitator (facilitator.arispay.app) charges no facilitator fee; sellers may use any facilitator, and their fee/finality policy applies.

Setup

Add the server to your MCP client config. No environment variables are required — pick a wallet mode later, from inside the chat, or set one of the env options below.

Claude Desktop

Edit ~/Library/Application Support/Claude/claude_desktop_config.json:

{
  "mcpServers": {
    "arispay": {
      "command": "npx",
      "args": ["-y", "@arispay/payagent-mcp"]
    }
  }
}

For the zero-signup mode, add the key to the env block:

      "env": { "PAYAGENT_PRIVATE_KEY": "0x..." }

Cursor

Same server block in .cursor/mcp.json. Windsurf: same pattern in ~/.codeium/windsurf/mcp_config.json.

Cold start, from nothing

  • Zero signup: generate a key with npx payagent wallet new, put it in the host config as PAYAGENT_PRIVATE_KEY, send USDC on Base to the printed address. balance shows the deposit address; pay pays.
  • Managed: ask the agent to run setup({ email: "you@example.com" }) — it returns the wallet address and mandate. Fund the wallet with USDC, confirm with balance, then pay. Credentials persist to ~/.payagent/config.json and are shared with the payagent CLI.

Environment variables (all optional)

VariableDescription
PAYAGENT_PRIVATE_KEYFunded EOA key for local self-custody signing (zero-signup mode).
ARISPAY_API_KEYDeveloper key — usually unneeded; setup self-provisions one.
ARISPAY_URLArisPay API base URL. Default https://api.arispay.app.
PAYAGENT_MCP_PROFILEadmin additionally loads the four wallet-administration tools. Default: core (six tools).
ARISPAY_AGENT_KEY / PAYAGENT_WALLETLegacy single-agent pair for v2.0.x hosts.

Migrating from v3

v4 is a breaking release: the surface collapsed to one x402/USDC product.

v3 toolv4
create_usersetup
pay_apipay (now requires idempotencyKey, returns a structured receipt)
discover_paid_apidiscover
inspect_paid_apiinspect
check_wallet, get_balance_agentbalance
history (new)
create_agent, fund_agent, list_agents, rename_agentunchanged, behind PAYAGENT_MCP_PROFILE=admin
create_wallet, list_wallets, fund_wallet, get_balance, pay_merchant, create_enduser, attach_card_for_user, set_user_limits, get_user_statusremoved — the fiat funding and platform (end-user) surfaces left the public MCP

Receipts and idempotency

pay requires a caller-chosen idempotencyKey (min 8 chars — use a UUID). Every completed payment writes a machine-readable receipt (amount, asset, network, wallet, settlement tx, remaining mandate) to ~/.payagent/mcp-receipts.json. Re-calling pay with a key that already paid returns the stored receipt and does not pay again — including when the paid request failed mid-flight. history lists receipts in self-custody mode; delegated mode reads the authoritative server feed.

How it works

  1. The agent calls pay with a URL and an idempotencyKey; the seller answers HTTP 402 with its price.
  2. With PAYAGENT_PRIVATE_KEY set, payagent signs the EIP-3009 authorization locally. Otherwise ArisPay validates the request against the agent's mandate and signs via Coinbase CDP.
  3. payagent retries with the signed payment header; the seller's facilitator settles USDC on-chain.
  4. The tool returns the paid response plus a structured receipt.

In delegated mode, no private key lives in this process and payments that breach the mandate are rejected before any on-chain action. In local mode, the key is yours and stays in your process.

Install

npm install @arispay/payagent-mcp

Or invoke directly via npx @arispay/payagent-mcp from an MCP client config — no pre-install required. npx buyforme-mcp is the same server under the consumer brand.

Related

License

MIT

Reviews

No reviews yet

Be the first to review this server!