{"_id":"@7clave/mcp-wallet","_rev":"4-68e2e39940955caffd3d9d292fdf73df","name":"@7clave/mcp-wallet","dist-tags":{"latest":"0.3.0"},"versions":{"0.2.0":{"name":"@7clave/mcp-wallet","version":"0.2.0","keywords":["mcp","wallet","custody","agent","stdio","7clave"],"author":{"name":"7clave"},"license":"Apache-2.0","_id":"@7clave/mcp-wallet@0.2.0","maintainers":[{"name":"confclave","email":"confclave@gmail.com"}],"homepage":"https://mcp.7clave.com/wallet/guide.html","bin":{"mcp-wallet":"dist/index.js"},"dist":{"shasum":"57855ca73f5d4a046e4dc919fc81d223f3490f89","tarball":"https://registry.npmjs.org/@7clave/mcp-wallet/-/mcp-wallet-0.2.0.tgz","fileCount":66,"integrity":"sha512-lLwvfKqlNVJnczOG0AVTEOloV2V7mhDp6/tU6cbTYEPcMxWB2Emg5jMPhTQFHyoyWlnMcQAHhaB0TafSz+uvZg==","signatures":[{"sig":"MEUCIQC9B9b5T5O1MGe2dNRCG0U6B3/3gMHUoCCy9kzE8Kbs0AIgBsw+l4nM1jDYo7ejV+kvSxpE4S0Tg4JYvkOYYMwn2wk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":267178},"main":"dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22"},"gitHead":"a7254d88d026dce9867778e4074b4b60c58d1b93","private":false,"scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","start":"node dist/index.js","typecheck":"tsc --noEmit"},"_npmUser":{"name":"confclave","email":"confclave@gmail.com"},"_npmVersion":"10.9.7","description":"Local MCP for 7clave custody wallet.","directories":{},"_nodeVersion":"22.22.2","dependencies":{"zod":"^4.3.6","@7clave/agent-kit":"0.2.0","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.7","typescript":"6.0.2","@types/node":"25.6.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-wallet_0.2.0_1779693169998_0.32014014026520776","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@7clave/mcp-wallet","version":"0.2.1","keywords":["mcp","wallet","custody","agent","stdio","7clave"],"author":{"name":"7clave"},"license":"Apache-2.0","_id":"@7clave/mcp-wallet@0.2.1","maintainers":[{"name":"confclave","email":"confclave@gmail.com"}],"homepage":"https://mcp.7clave.com/wallet/guide.html","bin":{"mcp-wallet":"dist/index.js"},"dist":{"shasum":"c4092ff7aae46100ed2188b5c0688f885d658b43","tarball":"https://registry.npmjs.org/@7clave/mcp-wallet/-/mcp-wallet-0.2.1.tgz","fileCount":66,"integrity":"sha512-z/22Hp1U39hU1ffoSUkmW2foK7zSAeboOzf/Izfiqp+0BGB/bXl1TpufKr3RwyK1Igo+rr3PxhKtYqQvb3p37w==","signatures":[{"sig":"MEYCIQC9pyvAIXYdutiXK2m+6t7MaKATf6wXmAfpwV8JvyFt9wIhAIajYZivBXN0OApS11iP6LhtyMhuK5erEXP17w4xtexS","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":269023},"main":"dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22"},"gitHead":"b61290da4013d54aa876df9a5997c1e38fa1a00b","private":false,"scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","start":"node dist/index.js","typecheck":"tsc --noEmit"},"_npmUser":{"name":"confclave","email":"confclave@gmail.com"},"_npmVersion":"10.9.7","description":"Local MCP for 7clave custody wallet.","directories":{},"_nodeVersion":"22.22.2","dependencies":{"zod":"^4.3.6","@7clave/agent-kit":"0.2.1","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.7","typescript":"6.0.2","@types/node":"25.6.0"},"x-7clave-severity":"recommended","x-7clave-changelog-url":"https://github.com/C7b9/custody-platform/blob/main/apps/mcp-wallet/CHANGELOG.md#021","_npmOperationalInternal":{"tmp":"tmp/mcp-wallet_0.2.1_1780375108610_0.8824553280920184","host":"s3://npm-registry-packages-npm-production"},"x-7clave-changelog-summary":"fixes empty balances and null chain_id after server ledger schema change"},"0.2.2":{"name":"@7clave/mcp-wallet","version":"0.2.2","keywords":["mcp","wallet","custody","agent","stdio","7clave"],"author":{"name":"7clave"},"license":"Apache-2.0","_id":"@7clave/mcp-wallet@0.2.2","maintainers":[{"name":"confclave","email":"confclave@gmail.com"}],"homepage":"https://mcp.7clave.com/wallet/guide.html","bin":{"mcp-wallet":"dist/index.js"},"dist":{"shasum":"3cdd7fc41a8daef3ff2405e23696b4f6d00c8ff7","tarball":"https://registry.npmjs.org/@7clave/mcp-wallet/-/mcp-wallet-0.2.2.tgz","fileCount":66,"integrity":"sha512-PWcfuAAQ9/woO0evF3skjcPkQnaZzK+mMJRCIh3fI5vOYdkeFOTb3OveDDlUWFdDvbBT/6CXtvEIocls2c4Zqg==","signatures":[{"sig":"MEYCIQCMa/zXQpJWOCywRbebDlBLNKnfFhVAyveiY+SzyTkuGQIhALBxtc6FXiGPDZrios+GeDlxEAzJgeO6GfKB9+SJihvC","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":270302},"main":"dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22"},"gitHead":"178cfec7fa6fd740250039eff72a850c1af9a84a","private":false,"scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","start":"node dist/index.js","typecheck":"tsc --noEmit"},"_npmUser":{"name":"confclave","email":"confclave@gmail.com"},"_npmVersion":"10.9.7","description":"Local MCP for 7clave custody wallet.","directories":{},"_nodeVersion":"22.22.2","dependencies":{"zod":"^4.3.6","@7clave/agent-kit":"0.2.2","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.7","typescript":"6.0.2","@types/node":"25.6.0"},"x-7clave-severity":"recommended","_npmOperationalInternal":{"tmp":"tmp/mcp-wallet_0.2.2_1780959080286_0.2997918418406451","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@7clave/mcp-wallet","version":"0.3.0","x-7clave-severity":"recommended","x-7clave-changelog-summary":"adds solana account creation and per-profile agent identities; hardens error paths","x-7clave-changelog-url":"https://github.com/C7b9/custody-platform/blob/main/apps/mcp-wallet/CHANGELOG.md#030","private":false,"type":"module","license":"Apache-2.0","author":{"name":"7clave"},"description":"Local MCP for 7clave custody wallet.","keywords":["mcp","wallet","custody","agent","stdio","7clave"],"homepage":"https://mcp.7clave.com/wallet/guide.html","main":"dist/index.js","bin":{"mcp-wallet":"dist/index.js"},"engines":{"node":">=22"},"publishConfig":{"access":"public"},"scripts":{"build":"tsc -p tsconfig.build.json","typecheck":"tsc --noEmit","test":"vitest run","start":"node dist/index.js"},"dependencies":{"@7clave/agent-kit":"0.3.0","@modelcontextprotocol/sdk":"^1.29.0","zod":"^4.3.6"},"devDependencies":{"@types/node":"25.6.0","typescript":"6.0.2","vitest":"^4.1.7"},"_id":"@7clave/mcp-wallet@0.3.0","types":"./dist/index.d.ts","_nodeVersion":"22.22.2","_npmVersion":"10.9.7","dist":{"integrity":"sha512-ioQzQxWms/N4YDrsBvd4MBjvofZNdY83E8qc+zoW4TOGhJJib+uZ5vgx9FtIZolACYJN9XvQUmc8rSINFGzOIA==","shasum":"6d60304005334a34291647f0e99fc66720cf1ea5","tarball":"https://registry.npmjs.org/@7clave/mcp-wallet/-/mcp-wallet-0.3.0.tgz","fileCount":122,"unpackedSize":458460,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDcj9mnIKZpaJVnU3dNJv0T/22KO3RXK5lr0zb+LtocNgIgI30X9huUaa+/+DJCCdKQrx8bsUZHskM5XjfCPhBr++o="}]},"_npmUser":{"name":"confclave","email":"confclave@gmail.com"},"directories":{},"maintainers":[{"name":"confclave","email":"confclave@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-wallet_0.3.0_1784597785969_0.6564457591231294"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-25T07:12:49.783Z","modified":"2026-07-21T01:36:26.279Z","0.2.0":"2026-05-25T07:12:50.129Z","0.2.1":"2026-06-02T04:38:28.764Z","0.2.2":"2026-06-08T22:51:20.424Z","0.3.0":"2026-07-21T01:36:26.121Z"},"author":{"name":"7clave"},"license":"Apache-2.0","homepage":"https://mcp.7clave.com/wallet/guide.html","keywords":["mcp","wallet","custody","agent","stdio","7clave"],"description":"Local MCP for 7clave custody wallet.","maintainers":[{"name":"confclave","email":"confclave@gmail.com"}],"readme":"# @7clave/mcp-wallet\n\nLocal stdio MCP server that exposes a 7clave custody wallet to any MCP host\n(Claude Desktop, Claude Code, Cursor, Continue, OpenCode, Hermes, …).\n\nFull setup walkthrough, deployment guide, and security notes:\n**https://mcp.7clave.com/wallet/guide.html**\n\n## Install\n\nYou don't need to install this package by hand. Every host config below\nuses `npx`, which fetches and caches the package on first run. As long as\nyou have **Node ≥ 22** on `PATH`, editing the host config is the only step.\n\nPrefer a stable global binary? Run `npm install -g @7clave/mcp-wallet` once\nand replace `\"command\": \"npx\", \"args\": [\"-y\", \"@7clave/mcp-wallet\"]` with\n`\"command\": \"mcp-wallet\"` in any config below.\n\n## Get a `CUSTODY_API_KEY`\n\nThis package does not self-serve credentials. A `CUSTODY_API_KEY` is an\n**agent enrollment key** issued by your custody operator (the team running\nthe backend). Workflow:\n\n1. Operator creates an agent in the dashboard and copies the `agent_…` key.\n2. They hand it to you out-of-band (1Password, Bitwarden, secrets manager).\n3. You paste it into the MCP host config below.\n\nTreat it like a long-lived API key. On first boot the wallet enrolls with the\nbackend and pins a per-agent identity to `~/.custody/`; that on-disk identity\nbecomes the load-bearing secret thereafter.\n\n### Enrollment trust window (security)\n\nFirst-run enrollment is trust-on-first-use: **whoever holds the\n`CUSTODY_API_KEY` at first boot gets their locally-generated P-256 key enrolled\nas the agent's signer**, with no out-of-band confirmation. This creates a window\nbetween key issuance and your first enrollment in which a stolen or shared key\ncan be used to enroll an attacker-controlled signer.\n\n- **Enroll promptly** after the key is issued — start the wallet once on the\n  intended host as soon as you receive the key, so you close the window.\n- **Treat an unexpected first-run `KEY_MISMATCH` as a compromise signal**, not\n  just \"I lost local state.\" If you boot on a fresh host and immediately hit\n  `KEY_MISMATCH` (the backend already has a *different* key enrolled) but you\n  never enrolled before, another host may have enrolled with this API key.\n  Do **not** simply Force-Re-Enroll — first **rotate the API key**, then\n  re-enroll from a trusted host. Force-Re-Enroll alone does not evict an\n  attacker who still holds the key.\n\n## Quick start — by host\n\nIn every case, `CUSTODY_API_KEY` is the only required env var.\n\n### Claude Desktop\n\nEdit `~/Library/Application Support/Claude/claude_desktop_config.json`\n(macOS) or `%APPDATA%\\Claude\\claude_desktop_config.json` (Windows):\n\n```json\n{\n  \"mcpServers\": {\n    \"7clave-wallet\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@7clave/mcp-wallet\"],\n      \"env\": { \"CUSTODY_API_KEY\": \"agent_…\" }\n    }\n  }\n}\n```\n\nRestart Claude Desktop.\n\n### Claude Code\n\n```bash\nclaude mcp add 7clave-wallet \\\n  --env CUSTODY_API_KEY=agent_… \\\n  -- npx -y @7clave/mcp-wallet\n```\n\n### Cursor\n\nSettings → MCP → Add Server:\n\n```json\n{\n  \"7clave-wallet\": {\n    \"command\": \"npx\",\n    \"args\": [\"-y\", \"@7clave/mcp-wallet\"],\n    \"env\": { \"CUSTODY_API_KEY\": \"agent_…\" }\n  }\n}\n```\n\n### Other hosts (OpenCode, Hermes, Continue, …)\n\nUse the same shape — `command: \"mcp-wallet\"` plus the env block. Consult\nyour host's MCP docs for the config file location.\n\n### Multiple agents on one machine\n\nEach agent just needs its own `CUSTODY_API_KEY`. State under `CUSTODY_AGENT_HOME`\nis partitioned per-agent by the server-issued agent UUID\n(`keys/<agent_id>/…`, `actions/<agent_id>/…`, `logs/<agent_id>/…`), so any\nnumber of agents share one `CUSTODY_AGENT_HOME` safely. A selected endpoint\nprofile adds a stable endpoint namespace before those paths:\n\n```json\n{\n  \"mcpServers\": {\n    \"7clave-alice\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@7clave/mcp-wallet\"],\n      \"env\": { \"CUSTODY_API_KEY\": \"agent_…\" }\n    },\n    \"7clave-bob\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@7clave/mcp-wallet\"],\n      \"env\": { \"CUSTODY_API_KEY\": \"agent_…\" }\n    }\n  }\n}\n```\n\n## Configuration\n\n| Var | Required | Default | Purpose |\n|---|---|---|---|\n| `CUSTODY_API_KEY` | yes | — | Agent enrollment key from your custody operator. |\n| `CUSTODY_API_URL` | no | `https://api.7clave.com` | Backend URL. HTTPS only (loopback allowed for local dev). Overrides a selected profile endpoint for one process. |\n| `CUSTODY_AGENT_HOME` | no | `~/.agent-wallet` | On-disk agent profile/state root. **Must be on persistent storage** — losing it loses the agent identity. `CUSTODY_HOME` remains a legacy override; a detected legacy `~/.custody` state tree is retained. |\n| `CUSTODY_AGENT_PROFILE` | no | active profile | Select a non-secret endpoint profile. Profile state is partitioned by the endpoint digest as well as server-issued agent UUID. |\n| `CUSTODY_DEBUG` | no | off | `1` to write a file log; `stderr` to log to stderr. |\n| `CUSTODY_LOG_FILE` | no | — | Override log target when `CUSTODY_DEBUG=1`. |\n\nThe MCP wallet pins its resolved endpoint for its lifetime. After changing a\nprofile or `CUSTODY_AGENT_PROFILE`, restart the MCP wallet process before it\nsubmits another intent.\n\n### Deployment profiles\n\nUse `custody-wallet` to persist a non-secret endpoint target, then select it\nfor subsequent processes or for one invocation:\n\n```sh\ncustody-wallet profile add staging --api-url https://staging.api.7clave.com\ncustody-wallet profile use staging\ncustody-wallet --profile staging whoami\n```\n\nProfiles store only the endpoint. Keep `CUSTODY_API_KEY` injected through the\nenvironment or a secret manager; do not add it to a profile file. Restart a\nrunning MCP wallet after changing its selected profile.\n\n## Tools\n\n| Tool | Purpose |\n|---|---|\n| `get_balance` | Token balances across the agent's wallets (flat token rows). |\n| `list_wallets` | Per-wallet view of what this agent can act on. |\n| `get_address` | Receive addresses for wallets this agent can deposit into. |\n| `transfer` | On-chain transfer to an external `0x` address. |\n| `fund` | Move tokens between two wallets the agent owns. |\n| `x402_pay` | Sign one x402 challenge term; optionally deliver the paid HTTP retry. |\n| `sign_typed_data` | Sign arbitrary EIP-712 TypedData (Polymarket, Safe, …). |\n| `get_action_status` | Poll a previously-submitted action to its terminal state. |\n| `list_actions` | List actions this agent has on disk (resume surface). |\n\nState-changing tools return an action envelope:\n`{ action_id, status, result?, message? }`. `status` is one of `completed`,\n`pending`, `requires_approval`, `approved`, `processing`, `rejected`,\n`failed`. Action IDs persist across restarts; resume with `list_actions` /\n`get_action_status`.\n\n## Versioning\n\nPre-1.0. The wire contract (tool names, env-var names, envelope shape) is\nintended to be stable; internals may shift between minor versions. Breaking\nchanges bump the minor version. See `CHANGELOG.md`.\n\n## License\n\nApache-2.0. See `LICENSE`.\n","readmeFilename":"README.md"}