Back to Browse

Nagora MCP Server

by M Flex
Developer ToolsUse Caution4.8MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Buy real goods with Nano (XNO) through escrow. Search, purchase, track orders, get signed receipts.

About

Buy real goods with Nano (XNO) through escrow. Search, purchase, track orders, get signed receipts.

Remote endpoints: streamable-http: https://api.nagora.shop/mcp

Security Report

4.8
Use Caution4.8High Risk

The Nagora MCP server is well-designed with appropriate authentication, input validation via Zod, and secure credential handling. The server implements a sound security model where it never holds funds and relies on server-side spending caps. Minor code quality issues around error handling and credential file permissions do not significantly impact security given the server's purpose. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.

3 files analyzed · 9 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

env_vars

Check that this permission is expected for this type of plugin.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

Nagora MCP server

The official MCP server for nagora.shop, the P2P marketplace where everything settles in Nano (XNO).

It gives any MCP client (Claude Desktop, Claude Code, or your own agent runtime) tools to search listings, place escrow-protected purchases, track orders, and pull signed receipts. Your AI assistant can shop for you, and escrow protects you while it does: funds are held in a per-order Nano account and only released to the seller after delivery is confirmed.

Tools

ToolAuthWhat it does
search_listingsnoneFull-text search over active listings
get_listingnoneFull listing detail: variants, delivery options, Nano pricing
register_agentnoneCreate an agent + API key in one call, no account needed; key is stored locally
whoamiAPI keyVerify the key; see spending caps and webhook secret
create_purchaseAPI keyPlace an order; returns the escrow deposit address and amount
get_orderAPI keyPoll order and escrow status, tracking, receipt ID
confirm_deliveryAPI keyConfirm arrival and release escrow to the seller
cancel_orderAPI keyCancel an order that has not been funded yet
get_receiptAPI keyFetch the KMS-signed receipt with the on-chain payout block

Setup

Zero-install alternative: Nagora also hosts these same tools as a remote MCP server. claude mcp add --transport http nagora https://api.nagora.shop/mcp and you are done. The trade-off: the hosted server cannot store your key locally, so register_agent returns it once and you pass it as the apiKey tool argument or pin it with --header "Authorization: Bearer nag_agt_...". This local package keeps the key in ~/.nagora/credentials.json for you instead.

Claude Code

claude mcp add nagora -- npx -y @nagora/mcp

Claude Desktop

In claude_desktop_config.json:

{
  "mcpServers": {
    "nagora": {
      "command": "npx",
      "args": ["-y", "@nagora/mcp"]
    }
  }
}

From source (instead of npx)

cd nagora-mcp
npm install
npm run build
claude mcp add nagora -- node /path/to/nagora-mcp/dist/index.js

Let the agent register itself

That's the whole setup. No Nagora account, no key to copy. The first time your assistant needs to buy something, it calls register_agent with a name and a refund Nano address; the API key comes back once and is saved to ~/.nagora/credentials.json (mode 600). Every other tool picks it up automatically from then on.

Self-registered keys get conservative default spending caps (currently 25 XNO per transaction, 100 XNO per day), enforced server-side. Want higher caps, multiple keys, or a dashboard? Create an account at nagora.shop and manage agents under Settings → Agents; keys minted there work the same way via NAGORA_API_KEY.

Configuration

VariableDefaultNotes
NAGORA_API_KEYunsetOptional. Overrides the stored credential from register_agent
NAGORA_API_URLhttps://api.nagora.shopPoint at http://localhost:5004 for local dev

How a purchase flows

  1. search_listings / get_listing: find the item, note the Nano total.
  2. create_purchase: places the order. The response contains a depositAddress (a per-order escrow account on the Nano network) and amountNano.
  3. Fund the escrow: send exactly amountNano to depositAddress from the agent's own Nano wallet. This server deliberately holds no keys and moves no funds; pair it with a wallet tool such as xno-mcp, or fund it manually. Nano transfers are feeless and settle in under a second.
  4. The order moves to AwaitingShipment automatically when funds land. The seller ships and adds tracking.
  5. get_order (or webhooks, see below) to watch for Shipped.
  6. confirm_delivery once the goods arrive: escrow releases the funds to the seller on-chain.
  7. get_receipt: a signed, independently verifiable proof of the whole transaction, including the payout block hash.

If the seller never ships, the escrow auto-cancel timer refunds the buyer. If something is wrong with the order, open a dispute from the website; a human reviews it.

Webhooks (optional)

Instead of polling get_order, register a callbackUrl on your agent (Settings → Agents). Nagora signs every webhook with HMAC-SHA256: compute HMAC-SHA256("{X-Nagora-Timestamp}.{raw_body}", webhookSecret) and compare it against X-Nagora-Signature: sha256=<hex>. The webhookSecret comes from whoami.

Events: order.funded, order.shipped, and friends fire as the order progresses.

Safety model

  • The server is stateless and keyless: it cannot spend Nano, only request orders that you then fund (or don't).
  • Spending caps are enforced server-side per API key; a runaway agent hits a 429, not your wallet.
  • Escrow means an agent mistake is recoverable: unfunded orders can be cancelled, funded orders are protected until you confirm delivery.
  • Revoke a key at any time from Settings → Agents; revocation takes effect within 60 seconds.

Reviews

No reviews yet

Be the first to review this server!