{"_id":"@agentmoney/wallet-mcp","_rev":"2-02445d8a5cbd957c498cf893a2d96e78","name":"@agentmoney/wallet-mcp","dist-tags":{"latest":"0.14.0"},"versions":{"0.13.0":{"name":"@agentmoney/wallet-mcp","version":"0.13.0","keywords":["mcp","model-context-protocol","agent-payments","x402","wallet","ai-agents"],"author":{"name":"Maxwell Calkin"},"license":"Apache-2.0","_id":"@agentmoney/wallet-mcp@0.13.0","maintainers":[{"name":"isthisreality","email":"Mcalkinmusic@gmail.com"}],"homepage":"https://github.com/MaxwellCalkin/money#readme","bugs":{"url":"https://github.com/MaxwellCalkin/money/issues"},"bin":{"money-wallet-mcp":"dist/server.js"},"dist":{"shasum":"5ae6105fcf0553b3c6ffd52adbb4a5801b0faac2","tarball":"https://registry.npmjs.org/@agentmoney/wallet-mcp/-/wallet-mcp-0.13.0.tgz","fileCount":4,"integrity":"sha512-kwP0m7F5ehlVLtLnNqUbZe3pPrghNiHN2gzpGg1h22XAQVsNTzItz10od6Rq/dy/q6dRVbnJWYkqIb0jbRgM2Q==","signatures":[{"sig":"MEQCICxXR0H8/oNfdjYTWzRXsbXEaKH2F86mSfHUhGeuleAkAiBpdO111vCDRikmithkFwN54wdKsHjvyZ0CLwo1dz5BjA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":52375},"type":"module","engines":{"node":">=20"},"gitHead":"4348da7626e548dd1146680131d499f75dc132ad","scripts":{"prepack":"node ../../scripts/build-packages.mjs"},"_npmUser":{"name":"isthisreality","email":"Mcalkinmusic@gmail.com"},"repository":{"url":"git+https://github.com/MaxwellCalkin/money.git","type":"git","directory":"packages/wallet-mcp"},"_npmVersion":"12.0.2","description":"MCP wallet for AI agents on the money network: check balance, pay accounts, and auto-pay 402-gated URLs under an owner-signed mandate.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"zod":"^3.25.76","@modelcontextprotocol/sdk":"^1.29.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/wallet-mcp_0.13.0_1786048278692_0.060507916907621695","host":"s3://npm-registry-packages-npm-production"}},"0.14.0":{"name":"@agentmoney/wallet-mcp","version":"0.14.0","description":"MCP wallet for AI agents on the money network: check what the mandate allows, pay accounts, auto-pay 402-gated URLs, and request reserved virtual cards under an owner-signed spend mandate.","type":"module","scripts":{"prepack":"node ../../scripts/build-packages.mjs"},"bin":{"money-wallet-mcp":"dist/server.js"},"engines":{"node":">=20"},"dependencies":{"@modelcontextprotocol/sdk":"^1.29.0","zod":"^3.25.76"},"keywords":["mcp","model-context-protocol","agent-payments","x402","wallet","ai-agents"],"repository":{"type":"git","url":"git+https://github.com/MaxwellCalkin/money.git","directory":"packages/wallet-mcp"},"license":"Apache-2.0","author":{"name":"Maxwell Calkin"},"publishConfig":{"access":"public"},"gitHead":"0f766590968cc956d6cd789d94d90282e80435fa","_id":"@agentmoney/wallet-mcp@0.14.0","bugs":{"url":"https://github.com/MaxwellCalkin/money/issues"},"homepage":"https://github.com/MaxwellCalkin/money#readme","_nodeVersion":"24.18.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-6D3Ht5odybQZdypdoLvVjEN+p36IkQleHZ94GtV8KYN/fvyrIW0yW49ufWCR8Y2PussjezkPlDch0qCL47xu0Q==","shasum":"dff1d63c2a40473252d5e5cf2686f19bf1903fba","tarball":"https://registry.npmjs.org/@agentmoney/wallet-mcp/-/wallet-mcp-0.14.0.tgz","fileCount":4,"unpackedSize":61212,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentmoney%2fwallet-mcp@0.14.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCZl4LOei95GAgpz+eyd7qstzJkBHp5GcUrqB5RfiqibgIhAM1lFFHTajaUU7hVd2nUcvvQdWTjxQWUpQmvrrVP14S7"}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:cb298a65-5d4c-436d-ab51-572be7e7e5c1"}},"directories":{},"maintainers":[{"name":"isthisreality","email":"Mcalkinmusic@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/wallet-mcp_0.14.0_1787951593368_0.879983701773315"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-06T20:31:18.414Z","modified":"2026-08-28T21:13:13.960Z","0.13.0":"2026-08-06T20:31:18.829Z","0.14.0":"2026-08-28T21:13:13.508Z"},"bugs":{"url":"https://github.com/MaxwellCalkin/money/issues"},"author":{"name":"Maxwell Calkin"},"license":"Apache-2.0","homepage":"https://github.com/MaxwellCalkin/money#readme","keywords":["mcp","model-context-protocol","agent-payments","x402","wallet","ai-agents"],"repository":{"type":"git","url":"git+https://github.com/MaxwellCalkin/money.git","directory":"packages/wallet-mcp"},"description":"MCP wallet for AI agents on the money network: check what the mandate allows, pay accounts, auto-pay 402-gated URLs, and request reserved virtual cards under an owner-signed spend mandate.","maintainers":[{"name":"isthisreality","email":"Mcalkinmusic@gmail.com"}],"readme":"# @agentmoney/wallet-mcp\n\nAn [MCP](https://modelcontextprotocol.io) wallet that gives any agent runtime\n(Claude Code, Cursor, Codex) a spending account on a\n[money](https://github.com/MaxwellCalkin/money) network. The agent gets seven\ntools; the owner's mandate — budget, per-payment cap, daily cap, ask-me-above\nline, new-payee throttle — is enforced by the network, never by the model.\n\n| Tool | What it does |\n|---|---|\n| `money_balance` | How much this agent can still spend under its owner's mandate |\n| `money_pay` | Pay any account (agent, provider, user) by id or `@handle`, idempotency-keyed |\n| `money_fetch` | GET a URL; on HTTP 402 (network challenge or external x402 seller) pay it within the mandate and retry — exactly-once, crash-recoverable |\n| `money_card_create` | Request a reserved virtual card for an ordinary online merchant, under the same mandate; issuing reserves the full cap up front. Returns only the last4 — never the card number |\n| `money_card_status` | One card's state, cap, cleared amount, and authorizations |\n| `money_card_close` | Close a card; the unspent remainder returns to the agent's funds (mandate authority already used is not restored) |\n| `money_feed` | Recent receipts |\n\nThe card tools require a network API with the card rail (the Postgres-backed\nserver, v0.14+); against an older API they return a clear \"this API does not\nimplement /cards\" message instead of failing silently. Networks without a\nconfigured card issuer answer `503`, and the hosted sandbox runs the mock\nissuer — sandbox, no real funds;\nnothing here is a bank, card, or deposit account.\n\n## The card number never enters the conversation\n\nThere is no reveal tool. `money_card_create` returns `last4`, expiry, cap, and\nmerchant — enough to recognize the card, nothing that can leak it. When the\nnetwork runs in `token` reveal mode, a fresh activation also returns a\nsingle-use `checkoutToken` (10-minute TTL, at most 3 per card, bound to this\nagent and this card). The **fill contract**: the model hands that token to the\nhost runtime, and host code — never the model — redeems it once via\n`POST /cards/:id/reveal {checkoutToken}` on the signed network API and fills\nthe merchant's payment form outside model context. In the default `none` mode\nno reveal surface exists at all and no token is returned.\n\n## Quickstart (10 minutes)\n\n1. **Get a wallet.** Your network operator gives you three values — or run the\n   network yourself and use its onboarding, which writes the key file for you\n   and prints this exact config.\n\n2. **Add to `.mcp.json`:**\n\n```json\n{\n  \"mcpServers\": {\n    \"money\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@agentmoney/wallet-mcp\"],\n      \"env\": {\n        \"MONEY_API\": \"https://your-money-network.example\",\n        \"MONEY_AGENT_ID\": \"agt_xxxxxxxx\",\n        \"MONEY_AGENT_KEY_FILE\": \"/absolute/path/to/agent.key\"\n      }\n    }\n  }\n}\n```\n\n3. Ask your agent to check what its mandate allows.\n\n## Configuration\n\n| Env var | Meaning |\n|---|---|\n| `MONEY_API` | Network API origin. HTTPS required except on loopback. Default `http://127.0.0.1:4021`. |\n| `MONEY_AGENT_ID` | This agent's account id (required). |\n| `MONEY_AGENT_KEY_FILE` | Path to a file whose first line is the agent's base64 PKCS#8 Ed25519 private key (preferred — keeps the key out of `.mcp.json`). |\n| `MONEY_AGENT_KEY` | The key inline (fallback; treat like a password). |\n| `MONEY_FETCH_PRIVATE_ORIGINS` | Optional JSON array of exact origins (e.g. `[\"http://127.0.0.1:8080\"]`) an agent may fetch on private networks. Nothing private is reachable by default. |\n\n## Safety properties\n\n- The agent process holds only its own signing key — never the owner key, and\n  never a spending decision. Every payment is policy-checked server-side.\n- Reserved cards are policy-decided at every network authorization: merchant\n  category, merchant allowlist, merchant lock, single-use, first-merchant\n  throttle, and cap are evaluated in the network's database, outside any model\n  context. Caps above the owner's ask-me line become a durable owner approval,\n  not a purchase.\n- `money_fetch` requires HTTPS on the public internet, re-resolves DNS and pins\n  the socket to the checked address, refuses redirects (they are returned as\n  validated URLs, and receipts or one-time payment headers are never forwarded\n  across them), and caps response bodies.\n- Payments are exactly-once: retries reuse idempotency keys, paid-but-undelivered\n  fetches resume with the existing receipt, in-flight external payments are\n  recovered from the network's durable record after a crash, and a retried\n  `money_card_create` with the same idempotency key returns the original card\n  instead of reserving twice.\n\n## License\n\nApache-2.0 — see [LICENSE](./LICENSE).\n","readmeFilename":"README.md"}