Back to Browse

Verdoc MCP Server

Developer ToolsLow Risk10.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

Deterministic AGENTS.md and repo analysis for coding agents, paid per call in USDC over x402.

About

Deterministic AGENTS.md and repo analysis for coding agents, paid per call in USDC over x402.

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (2 strong, 3 medium validity signals). No known CVEs in dependencies. Imported from the Official MCP Registry.

4 files analyzed · No issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

EVM private key for a wallet funded with USDC on Base, Polygon or Arbitrum. Never logged, written to disk, or transmitted anywhere except as an x402 payment signature. Leave unset to run in quote-only mode: tools still work and report price, but buy nothing.Required

Environment variable: EVM_PRIVATE_KEY

Hard per-call spending ceiling in USD, checked before any payment is signed. Defaults to 0.05 if unset.Optional

Environment variable: VERDOC_MAX_SPEND_USD

Documentation

View on GitHub

From the project's GitHub README.

verdoc-mcp

Give your coding agent the context of a repository it has never seen, for two cents, without an account or an API key.

An agent dropped into an unfamiliar codebase has to read it before it can work in it - and that costs tens of thousands of tokens every time. verdoc-mcp exposes two tools that answer the same questions directly:

toolwhat you getprice
verdoc_agents_mdan AGENTS.md ready to commit$0.02
verdoc_scanthe same analysis as structured JSON$0.01

Build and test commands are quoted from the repository's own manifests, with the file each one came from named. Every path is checked against the git tree. Anything ambiguous is marked unverified rather than guessed.

No language model runs on the server. The same commit always returns the same answer.

Install

Easiest: download the .mcpb bundle and drag it into Claude Desktop, or point any MCPB-aware client at it directly - dependencies are bundled inside, nothing to install separately.

Not on npm yet. Two other ways to install straight from this repository:

{
  "mcpServers": {
    "verdoc": {
      "command": "npx",
      "args": ["-y", "github:verdochello/verdoc-mcp"],
      "env": { "EVM_PRIVATE_KEY": "0x..." }
    }
  }
}

Or clone it and point at the file directly:

git clone https://github.com/verdochello/verdoc-mcp && cd verdoc-mcp && npm install
{
  "mcpServers": {
    "verdoc": {
      "command": "node",
      "args": ["/absolute/path/to/verdoc-mcp/index.mjs"],
      "env": { "EVM_PRIVATE_KEY": "0x..." }
    }
  }
}

Works with Claude Desktop, Claude Code, Cursor, or any MCP client.

Without a key it still runs. The tools report what they would cost and what they would return, and buy nothing. That is the intended way to try it.

Paying

The wallet needs USDC on Base, Polygon or Arbitrum. It does not need ETH - x402 payments are signed off-chain and the facilitator pays the gas.

variabledefaultmeaning
EVM_PRIVATE_KEY-wallet that pays. Omit to run in quote-only mode.
VERDOC_MAX_SPEND_USD0.05hard per-call ceiling. Nothing above it is ever signed.
VERDOC_ORIGINhttps://verdoc.devoverride the endpoint (testing).

About that private key

You are handing a program the ability to spend your money, so here is exactly what this one does and does not do.

  • The key is read from the environment. It is never logged, never written to disk, and never sent anywhere. Error messages are scrubbed of anything that looks like a key before being returned.
  • The payee and the chain are pinned in the source. Before signing anything, the client reads the live payment offer and checks it. If Verdoc ever asks to be paid at a different address, or on a chain not in the list, this refuses and tells you instead of paying. That means a compromise of our own domain or DNS cannot redirect your funds.
  • Every call is capped by VERDOC_MAX_SPEND_USD, checked before a signature exists.

Use a wallet you funded for this purpose. That is good practice with any paying agent tool, including this one.

What it will refuse to do

These are tested in selftest.mjs, and the refusals are the part worth reading:

  • pay an address other than the pinned one - even if the live endpoint asks
  • pay on a chain outside the pinned set, including testnets
  • pay more than your ceiling
  • treat a short or empty 200 response as a real answer

Limits

Public GitHub repositories only. Repositories over 20,000 tracked files are rejected: GitHub truncates the git tree above that, and every claim this service makes depends on having the complete tree.

Licence

MIT. The service it calls is at verdoc.dev - OpenAPI | x402 discovery

Reviews

No reviews yet

Be the first to review this server!

Verdoc MCP Server - Deterministic AGENTS.md and repo analysis for coding | MCP Marketplace